buildGrantScopeShapePredicate
buildGrantScopeShapePredicate(
scopeColumn,ids):Predicate
Defined in: packages/contracts/src/supabase-rls.ts:819
The grant-scope predicate — the read-path mirror of the grant-scope select policy.
An empty id set denies all rows (DENY_ALL_PREDICATE), mirroring the policy returning no rows.
An OR of equalities, not an IN: the engine’s In leaf takes a subquery, and a grant set lives
in the JWT rather than in a table, so there is nothing to select from. This is not a workaround —
OR(=v…) is exactly what the engine’s own SQL parser desugars IN (list) to, so the two forms
compile to the same nodes.
Parameters
Section titled “Parameters”scopeColumn
Section titled “scopeColumn”AnyColumn
string[]