BE-M0-24 · Storage: private buckets, files through their rows, and the P15 guards
ID BE-M0-24 · Level L0 · Pack Pack D · Seed and Storage · Run order row 21 · Issue #13
The four private buckets, the file policies that ask the owning row (D14) and the P15 guards pass their tests with every earlier test (275 in 13 files). The rules pack D proves are marked built, and pack D is merged into main.
Before
Section titled “Before”- BE-M0-23 is Done. You are on the branch supabase/seed-storage in ~/opleet-v2/opleet,
git status --shortprints nothing, and the stack is running.
1 · Copy this step's files in
Section titled “1 · Copy this step's files in”cp -R ~/opleet-v2/packs/be-pack-d/BE-M0-24/. .git status --short2 · Rebuild the local database from every migration, then run every test
Section titled “2 · Rebuild the local database from every migration, then run every test”pnpm supabase db resetpnpm supabase test db3 · Mark the rules pack D proves as built, then run the rule check
Section titled “3 · Mark the rules pack D proves as built, then run the rule check”node ~/opleet-v2/packs/be-pack-d/mark-built.mjs ~/opleet-v2/packs/be-pack-d/BUILT-IDS.txtpnpm docs:rulesgit status --short apps/docs4 · Commit
Section titled “4 · Commit”git add supabase apps/docsgit commit -m "feat(supabase): private buckets, file paths through their rows and the P15 guards"5 · Push, open the pull request and wait for its checks
Section titled “5 · Push, open the pull request and wait for its checks”git push -u origin supabase/seed-storagegh pr create --title "feat(supabase): system rows, the E2E seed and Storage" --body "BE pack D (BE-M0-22 to BE-M0-24), timeline row 21. Closes #13."gh pr checks --watch6 · Log the run on #13, then merge
Section titled “6 · Log the run on #13, then merge”Comment on #13 with the date, what you ran in BE-M0-22 to BE-M0-24 and the output of each test run. Then:
gh pr merge --squash --delete-branchgit switch maingit pullExpect
Section titled “Expect”- Block 1:
?? supabase/migrations/20261006001300_storage.sqland?? supabase/tests/database/24_storage.test.sql. - Block 2: db reset applies 20261006001300_storage.sql last, then seeds, and ends with “Finished supabase db reset”; test db ends with “All tests successful.”, “Files=13, Tests=275” and “Result: PASS”.
- Block 3: “Marked built: 7. Already built: 0.”, then the rule check's “Rules: …” line with no line under it, then a
Mline for each rule page that changed. - Block 4: ✔️ commitlint, then the commit line.
- Block 5: the pull request's URL; checks and pr-title pass.
- Block 6: “✓ Squashed and merged pull request #…”, and main moves to that commit.
docker exec supabase_db_opleet psql -U postgres -At -c "select id, public from storage.buckets order by id" -c "select policyname, cmd from pg_policies where schemaname = 'storage' and tablename = 'objects' order by 1"git log --oneline -1documents|f, inspections|f, payments|f, screening|f, then opleet_files_insert|INSERT and opleet_files_read|SELECT, then “feat(supabase): system rows, the E2E seed and Storage (#…)” on main.
If it fails
Section titled “If it fails”- db reset stops at 20261006001300_storage.sql with “permission denied” on the storage schema: paste the error and the output of
pnpm supabase --version; don't edit the file. - test db prints “not ok”: paste every “not ok” line and the lines under it. Don't commit.
- Block 3 prints “Not found in apps/docs” or “Retired”, or docs:rules prints a line under its “Rules:” line: paste the output; BE rebuilds the pack.
- A check fails on the pull request: paste the failing job's log.
Before merging: gh pr close --delete-branch, then git switch main and pnpm supabase db reset. After merging: revert it with a new pull request.
Not run yet. Log each run as a comment on #13.