Skip to content

buildGrantScopeShapePredicate

buildGrantScopeShapePredicate(scopeColumn, ids): Predicate

Defined in: packages/contracts/src/supabase-rls.ts:819

The grant-scope predicate — the read-path mirror of the grant-scope select policy. An empty id set denies all rows (DENY_ALL_PREDICATE), mirroring the policy returning no rows.

An OR of equalities, not an IN: the engine’s In leaf takes a subquery, and a grant set lives in the JWT rather than in a table, so there is nothing to select from. This is not a workaround — OR(=v…) is exactly what the engine’s own SQL parser desugars IN (list) to, so the two forms compile to the same nodes.

AnyColumn

string[]

Predicate