Skip to content

stash-supabase skill lacks raw-pg / no-ORM guidance (only covers the encryptedSupabase JS wrapper) #601

Description

@coderdan

Summary

The stash-supabase agent skill only documents the encryptedSupabase (Supabase JS SDK) wrapper. For a Supabase app whose data layer is plain pg / raw SQL (no ORM, no supabase-js), there is no guidance on the actual EQL SQL surface, so an integrating agent has to reverse-engineer it from pg_operator / pg_cast / the EQL SQL. This is the lowest-level (and most foot-gun-prone) integration path, and it's undocumented.

What's missing

A raw-SQL reference for reading/querying eql_v2_encrypted columns:

  • Binding an encrypted query term: $n::jsonb::eql_v2_encrypted
  • Operator → index mapping:
    • ~~ / ~~* → free-text match (bloom filter)
    • = → equality (hmac)
    • < <= > >= → order/range (ORE)
  • Reading a value back: col::jsonb, then decrypt in app code
  • abs() over ORE: ORE can't express abs(), so an absolute-value bucket must be decomposed into signed ranges, e.g. ((c >= min AND c < max) OR (c <= -min AND c > -max))

Suggestion

Add a raw-pg / no-ORM section to the Supabase skill (or a general encryption skill), and ideally ship a thin term → SQL operator helper — analogous to the Drizzle / Supabase adapters — so the no-ORM path isn't hand-written EQL SQL. Two independent agents (implementer + assessor) both flagged this as the largest DX gap for this surface.


Found via a CipherStash integration eval on cipherstash/supabase-nextjs-starter (hono-pg surface, plain pg). Full report: https://github.com/cipherstash/supabase-nextjs-starter/blob/feat/multi-surface-starters/docs/evals/hono-pg/2026-07-09-self-assessment.md (see "Docs gaps").

Activity

  1. self-assigned this
    on Jul 9, 2026
  2. tobyhede commented on Sep 17, 2026

    @tobyhede
    Contributor

    Verified against current main: stash-supabase now routes hand-written SQL and RPC users to the canonical stash-postgres skill. That guide covers EQL v3 over plain pg and postgres-js, including query-domain operand casts, operator mapping, parameter binding, reads/decryption, signed-range decomposition, indexing handoff, and troubleshooting. The suggested thin term-to-operator helper was not built; it was an optional API suggestion rather than required documentation, and any new helper should be evaluated as a separate API proposal. Closing the documented guidance gap as completed.

  3. tobyhede commented on Sep 17, 2026

    @tobyhede
    Contributor

    Audit correction: the Run 2 closing comment overstated the then-current stash-postgres coverage. The guide did not yet contain the signed-range decomposition for an abs() bucket.

    That missing recipe is now added in the pending stash patch changeset stash-postgres-signed-range: it expresses min <= abs(column) < max as positive and negative signed ranges, encrypts all four bounds, and documents the reversed inequalities on the negative branch. The rest of the closing disposition is unchanged.

  4. tobyhede commented on Sep 17, 2026

    @tobyhede
    Contributor

    The signed-range documentation fix is now publicly reviewable in #975. That PR is on its own branch from main and carries the stash patch changeset referenced above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions