Files
pwap/web/supabase/migrations/20260225000000_fix_admin_roles_rls_policy.sql
T
pezkuwichain 1c6ff3d578 fix(web): correct asset IDs/decimals + chain routing, string-BigInt amounts, presale signer
Fund-logic hardening (audit remediation):
- TransferModal: source asset id/decimals from the canonical MINTABLE_ASSETS
  (wUSDT=1000, wDOT=1001, wETH=1002, wBTC=1003) instead of the wrong hardcoded
  ids (BTC=3 was the deprecated "Old USDT", ETH=4, DOT=5). Route every non-native
  asset through the Asset Hub api; only native HEZ uses the relay balances pallet.
  Removes the latent wrong-asset / wrong-chain transfer.
- Replace BigInt(parseFloat(x)*10**dec) with string-based parseTokenInput in
  TransferModal + 3 DEX init modals; BigInt(float) threw RangeError on common
  fractional amounts (e.g. 100.3 HEZ), breaking sends and pool/bridge init.
- Presale.contribute now resolves a signer via getSigner and passes { signer }
  to signAndSend (was signer-less -> broken for all users).
- presale.ts contribute/refund/claimVested now reject on dropped/invalid/usurped/
  retracted tx states instead of hanging the UI forever.
2026-07-24 22:55:54 -07:00

11 lines
378 B
SQL

ALTER TABLE admin_roles ENABLE ROW LEVEL SECURITY;
DROP POLICY IF EXISTS "Admins can view admin roles" ON admin_roles;
DROP POLICY IF EXISTS "Super admins can manage admin roles" ON admin_roles;
DROP POLICY IF EXISTS "authenticated_read_admin_roles" ON admin_roles;
CREATE POLICY "authenticated_read_admin_roles"
ON admin_roles FOR SELECT
TO authenticated
USING (true);