Skip to content

fix(supabase): explain ip allow list rejections during source setup - #111495

Open
Gilbert09 wants to merge 1 commit into
masterfrom
posthog/supabase-ip-allow-list-error
Open

Gilbert09 wants to merge 1 commit into
masterfrom
posthog/supabase-ip-allow-list-error

Conversation

@Gilbert09

Copy link
Copy Markdown
Member

Problem

  • Users whose Supabase project has network restrictions enabled see a generic "Could not connect to Supabase. Please check all connection details are valid." when they set up a source.
  • The message gives them no next step, so they cannot tell that PostHog's IP addresses are blocked.
  • Why: this unmapped error was one of the more common generic failures in the new-source wizard.

Changes

  • The wizard now says the database provider rejected PostHog's IP address and asks the user to add PostHog's IP addresses to the allow list.
  • PostgresErrors maps Supavisor's (EADDRNOTALLOWED) address not in tenant allow_list to that message. Supabase validation inherits this map from the Postgres source.
  • The sync path already treats this error as non-retryable. Only setup-time validation changes.

How did you test this code?

Test rationale: one case added to test_operational_errors_map_to_friendly_messages. It fails if the mapping is removed and the error falls back to the generic message. The connection error in the fixture uses documentation-range IPs.

  • Ran that parameterized test locally, and ran ruff over both touched files.
  • Not run: the full Postgres source suite. CI runs it.

Release status

  • No feature flag controls this change
  • This change is behind a feature flag and is not available to users
  • This change makes a previously flagged feature available to everyone

Automatic notifications

  • Publish to changelog?

Docs update

None.

🤖 Agent context

Autonomy: Fully autonomous

Agent: Claude Code (PostHog Desktop cloud task), Opus 5.5 (claude-opus-5-5)

  • Came from a triage of failed source creations in the warehouse wizard. Error tracking showed that this error caused the generic Supabase fallback.
  • No duplicate: an open PR, #111259, covers a different Supabase pooler error (EAUTHQUERY) in the same map. Both PRs touch the same dict, so a small rebase may be needed.
  • Skills invoked: /writing-user-facing-copy, /writing-tests, /writing-pr-descriptions.
  • Public artifact: the test fixture is invented. No customer values appear in it.

🤖 Generated with Claude Code

Created with PostHog Desktop

Supabase's pooler rejects connections from IPs outside a project's network restrictions. Source setup did not map that error, so the wizard showed a generic "Could not connect" message. Map it to an actionable message that names the IP allow list.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Generated-By: PostHog Desktop
Task-Id: 2b67e60f-19ae-489a-97aa-ff6518095a9b
@trunk-io

trunk-io Bot commented Oct 4, 2026

Copy link
Copy Markdown

Merging to master in this repository is managed by Trunk.

  • To merge this pull request, check the box to the left or comment /trunk merge below.

After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here

@Gilbert09 Gilbert09 added the stamphog Request AI approval (no full review) label Oct 4, 2026 — with Talyn App
@parameterai

parameterai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Risk: No findings

This PR adds a validation-time error mapping so Supavisor IP-allow-list rejections during source setup show an actionable message instead of a generic fallback. The change is a static string in an existing substring-match dict plus a test; no security-relevant behavior changes.

Sentinel reviewed d3e7a7d · Review settings

@stamphog stamphog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved.

Low-risk addition of a user-facing error message mapping for setup-time validation, with a test; the author is on the owning team and no guard suppressions were added.

  • Author wrote 0% of the modified lines and has 13 merged PRs in these paths (familiarity MODERATE).
Gate mechanics and policy version
Gate Result
prerequisites ✓ all clear
deny-list ✓ no deny categories matched
size ✓ 8L, 1F substantive, 15L/2F incl. docs/generated/snapshots — within ceiling
tier ✓ T1-agent / T1a-trivial (15L, 2F, single-area, fix)
stamphog 2.3.1 .stamphog/policy.yml @ d3e7a7d · reviewed head d3e7a7d

@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (8)
.agents/security.md — configured
.agents/skills/sending-notifications/SKILL.md — configured
docs/published/handbook/engineering/type-system.md — configured
.agents/skills/writing-tests/SKILL.md — configured
docs/internal/person-data-access.md — configured
.agents/skills/adopting-generated-api-types/SKILL.md — configured
.claude/commands/conventions.md — configured
.agents/skills/writing-code-comments/SKILL.md — configured

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: PostHog/posthog/.coderabbit.yaml
  • Review profile: QUIET
  • Plan: Enterprise
  • Run ID: d45b7028-46ca-4fa1-8f2a-a4311b0d05f3
📥 Commits

Reviewing files that changed from the base of the PR and between 39cc02e and d3e7a7d.

📒 Files selected for processing (2)
  • products/warehouse_sources/backend/temporal/data_imports/sources/postgres/source.py
  • products/warehouse_sources/backend/temporal/data_imports/sources/postgres/test_postgres.py

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 10 remain after this review.


📝 Walkthrough

Walkthrough

PostgreSQL credential validation now maps Supavisor’s tenant allow-list rejection to guidance to add PostHog’s IP addresses to the database provider’s allow list. A test covers this error case.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to d3e7a

Credential checks now give actionable allow-list guidance for Supavisor’s tenant rejection, while sync handling is unchanged. No concrete merge-blocking risk is evident.

🚥 Pre-merge checks | ✅ 1
✅ Passed checks (1 passed)
Check name Status Explanation
Description check ✅ Passed The description explains the user impact, the error mapping, the test rationale, and the release status. It also reports the local test and lint checks, notes that the full suite was not run, and incl…
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@hosthog

hosthog Bot commented Oct 4, 2026

Copy link
Copy Markdown

HostHog preview — posthog-desktop-web

Latest build (d3e7a7d): https://b1cd98c786de401598d3d0d1adfe6e26.hosthog.dev

Employee-gated; every push gets a fresh URL whose content never changes. All previews stop serving when the PR closes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stamphog Request AI approval (no full review)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant