From 4245959a0f927f7982e4fd14e6b5817f980e7353 Mon Sep 17 00:00:00 2001 From: Haewon Kam Date: Wed, 7 Oct 2026 12:11:13 +0900 Subject: [PATCH] =?UTF-8?q?docs:=20anon=20=ED=82=A4=EB=A1=9C=20=EC=8B=A4?= =?UTF-8?q?=EC=A0=9C=20=EB=B3=91=EC=9B=90=20=EB=8D=B0=EC=9D=B4=ED=84=B0?= =?UTF-8?q?=EB=A5=BC=20=EC=9D=BD=EB=8A=94=20RLS=20=EC=A0=95=EC=B1=85=20?= =?UTF-8?q?=EC=A0=95=EB=A6=AC=20=EC=B4=88=EC=95=88=20(=EC=8B=A4=ED=96=89?= =?UTF-8?q?=20=EC=95=88=20=ED=95=A8)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 5.5 --- .../2026-10-07_rls_anon_read_DRAFT.sql | 43 +++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 docs/security/2026-10-07_rls_anon_read_DRAFT.sql diff --git a/docs/security/2026-10-07_rls_anon_read_DRAFT.sql b/docs/security/2026-10-07_rls_anon_read_DRAFT.sql new file mode 100644 index 0000000..bd36b8a --- /dev/null +++ b/docs/security/2026-10-07_rls_anon_read_DRAFT.sql @@ -0,0 +1,43 @@ +-- ════════════════════════════════════════════════════════════════════════ +-- 초안 (실행하지 않음) · 2026-10-07 +-- 익명(anon) 키로 실제 병원 데이터를 읽을 수 있는 RLS 정책 정리 +-- +-- 확인한 사실 (2026-10-07, anon 키로 행 수만 조회): +-- marketing_reports 103 · clinics 12 · channel_snapshots 189 · analysis_runs 53 +-- supporter_builds 3 · supporter_inputs 2 행이 anon 키로 읽힌다. +-- anon 키는 infinith-demo 번들에 공개로 들어 있다 (webforai.kr 번들에서는 2026-10-07 c2e7d5a 로 제거). +-- +-- 실행 전 확인할 것 (haewon 결정 필요): +-- 1. infinith-demo 의 리포트·플랜·스튜디오·병원 확인 화면(/report, /plan, /clinic, /supporters, /build)은 +-- anon 키로 이 테이블을 읽는다. 아래를 실행하면 그 화면들이 빈 화면이 된다. +-- 대안: 로그인(Supabase Auth) 도입 후 authenticated 로 바꾸거나, 읽기를 Edge Function(service role) 뒤로 옮긴다. +-- 2. 운영 DB 변경이다. 실행 전에 영향 범위를 확인받고, Supabase 대시보드 SQL 편집기에서 실행한다. +-- 3. 되돌리기: 각 정책을 원래 마이그레이션의 CREATE POLICY 문으로 다시 만들면 된다 (파일명은 아래 주석). +-- ════════════════════════════════════════════════════════════════════════ + +begin; + +-- 20260330_create_tables.sql +drop policy if exists "anon_read_reports" on public.marketing_reports; + +-- 20260405_saas_schema_v3.sql +drop policy if exists "anon_read_clinics" on public.clinics; +drop policy if exists "anon_read_runs" on public.analysis_runs; +drop policy if exists "anon_read_snapshots" on public.channel_snapshots; +drop policy if exists "anon_read_screenshots" on public.screenshots; +drop policy if exists "anon_read_plans" on public.content_plans; +drop policy if exists "anon_read_performance" on public.performance_metrics; +drop policy if exists "anon_read_content_perf" on public.content_performance; +drop policy if exists "anon_read_adjustments" on public.strategy_adjustments; + +-- 20260406_clinic_registry.sql +drop policy if exists "public_read_registry" on public.clinic_registry; + +-- 20260907_supporter_builds.sql +drop policy if exists "anon can read builds" on public.supporter_builds; +drop policy if exists "anon can read inputs" on public.supporter_inputs; + +-- 스토리지 버킷의 공개 읽기(20260407_screenshots_storage.sql "public_read_screenshots")는 +-- 병원 채널 스크린샷 이미지다. 버킷 공개 여부와 함께 별도로 결정한다. + +commit;