Conversation
Supabase's pooler rejects connections from IPs outside a project's network restrictions. Source setup did not map that error, so the wizard showed a generic "Could not connect" message. Map it to an actionable message that names the IP allow list. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Generated-By: PostHog Desktop Task-Id: 2b67e60f-19ae-489a-97aa-ff6518095a9b
|
Merging to
After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here |
|
Risk: No findings This PR adds a validation-time error mapping so Supavisor IP-allow-list rejections during source setup show an actionable message instead of a generic fallback. The change is a static string in an existing substring-match dict plus a test; no security-relevant behavior changes. Sentinel reviewed |
There was a problem hiding this comment.
Approved.
Low-risk addition of a user-facing error message mapping for setup-time validation, with a test; the author is on the owning team and no guard suppressions were added.
- Author wrote 0% of the modified lines and has 13 merged PRs in these paths (familiarity MODERATE).
Gate mechanics and policy version
| Gate | Result | |
|---|---|---|
| prerequisites | ✓ | all clear |
| deny-list | ✓ | no deny categories matched |
| size | ✓ | 8L, 1F substantive, 15L/2F incl. docs/generated/snapshots — within ceiling |
| tier | ✓ | T1-agent / T1a-trivial (15L, 2F, single-area, fix) |
| stamphog 2.3.1 | .stamphog/policy.yml @ d3e7a7d · reviewed head d3e7a7d |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (8)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 10 remain after this review. 📝 WalkthroughWalkthroughPostgreSQL credential validation now maps Supavisor’s tenant allow-list rejection to guidance to add PostHog’s IP addresses to the database provider’s allow list. A test covers this error case. Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to Credential checks now give actionable allow-list guidance for Supavisor’s tenant rejection, while sync handling is unchanged. No concrete merge-blocking risk is evident. 🚥 Pre-merge checks | ✅ 1✅ Passed checks (1 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
HostHog preview —
|
Problem
Changes
PostgresErrorsmaps Supavisor's(EADDRNOTALLOWED) address not in tenant allow_listto that message. Supabase validation inherits this map from the Postgres source.How did you test this code?
Test rationale: one case added to
test_operational_errors_map_to_friendly_messages. It fails if the mapping is removed and the error falls back to the generic message. The connection error in the fixture uses documentation-range IPs.ruffover both touched files.Release status
Automatic notifications
Docs update
None.
🤖 Agent context
Autonomy: Fully autonomous
Agent: Claude Code (PostHog Desktop cloud task), Opus 5.5 (
claude-opus-5-5)EAUTHQUERY) in the same map. Both PRs touch the same dict, so a small rebase may be needed.🤖 Generated with Claude Code
Created with PostHog Desktop