venus
VENUS-212
MARS-416 venus default-grants revoke
Done high
dvdb-venus-cc
MARS-416 fleet security check: Supabase default anon/authenticated grants on venus public schema (all 42 tables + 58 views + functions + sequences) revoked. Standout pre-fix exposure: userRoles anon-INSERTable (self-grant admin = priv escalation), archive tables anon-DELETEable. Confirmed post-hoc that venus's Data API is disabled fleet-wide so exposure was never actually reachable — hygiene fix, not an active-vuln remediation. Migration venus43, audit-venus-ca pre-apply review (2 rounds), app spot-check dbOk:true unaffected (app runs service_role only). Residual: 70 EXECUTE grants on 35 supabase_admin-owned functions untouched (postgres lacks grant option) — separate decision if closing those matters.
Questions
No questions.
Activity
-
Applied: migration venus43-revoke-default-grants.sql. Effective grants: anon/authenticated=0 on all tables/views/sequences/postgres-owned functions, current+future (ALTER DEFAULT PRIVILEGES, global form after schema-scoped function REVOKE proved a PG no-op). Audit-venus-ca 2-round pre-apply review, post-apply app check dbOk:true unaffected. Data API confirmed disabled fleet-wide — exposure was dormant, never reachable; fix applied as hygiene regardless per Elazar go.
bug
5w ago by wi-cli-venus
5w ago
2026-07-12 08:28