# userRoles is SupaBroken

**URL:** <https://community.weweb.io/t/userroles-is-supabroken/1612>\
**Category:** Ask us anything\
**Tags:** authentication, supabase\
**Created:** [December 16, 2022, 6:59pm UTC](https://community.weweb.io/t/userroles-is-supabroken/1612 "2022-12-16T18:59:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![justifi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/justifi/32/2846_2.png) [@justifi](https://community.weweb.io/u/justifi)\
**Post date:** [December 16, 2022, 6:59pm UTC](https://community.weweb.io/t/userroles-is-supabroken/1612/1 "2022-12-16T18:59:02Z")

</div>

[Using Supabase Auth Plugin]  
[I made a video demonstrating this bug.](https://share.getcloudapp.com/p9uLrzyn)  
When you create a new userRoles within the WeWeb UI, WeWeb is posting with the following body -

```auto
{
    "id": <role.id>,
    "userId": <user_id>,
    "roleId":<role.id>
}

```

That means that you can’t assign a role to more than 1 person. Which is not what a role is meant to do.

I was very surprised to see no one else had reported this already? Is no one else using the supabase auth plugin? or does no one actually have any users?

I can’t onboard anyone until this gets cleared up - luckily its probably 1 line of code in the plugin. thanks

---

<div class="post-metadata">

**Author:** ![justifi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/justifi/32/2846_2.png) [@justifi](https://community.weweb.io/u/justifi)\
**Post date:** [December 16, 2022, 9:33pm UTC](https://community.weweb.io/t/userroles-is-supabroken/1612/2 "2022-12-16T21:33:19Z")

</div>

**Context**  
assigning a role to a user generates a row in userRoles

 ![Editor - WeWeb 2022-12-16 at 4.32.54 PM](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/a/ab197d44cf232f4ffe5e075084a254d60efb29f1.png)

**What should happen**  
a new and random `userRole.id` is generated by postgres default function `uuid_generate_v4()`

 ![supamkt Supabase 2022-12-16 at 4.28.50 PM](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/3/31e9a117faac25b409560117ad6a0b6752acbc2d.png)

**What actually happens**  
weWeb passes `userRoles.roleld` as an argument for `userRole.id` when constructing `userRoles`

 ![Screen Recording 2022-12-16... 2022-12-16 at 4.16.50 PM](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/9/9f3fe15bd9b72fd72de6493f9a83e3c3b4c999f2.jpeg)

---

<div class="post-metadata">

**Author:** ![Matthieu](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/matthieu/32/1288_2.png) [@Matthieu](https://community.weweb.io/u/Matthieu)\
**Post date:** [December 17, 2022, 12:10pm UTC](https://community.weweb.io/t/userroles-is-supabroken/1612/3 "2022-12-17T12:10:29Z")

</div>

Hey @flo

Is this linked to the bug we found this week where you can only give a role to one user.  
When I gave your user an admin role, my user lost it.

Available for testing.

Matth-

---

<div class="post-metadata">

**Author:** ![IdeaGarage](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/ideagarage/32/1350_2.png) [@IdeaGarage](https://community.weweb.io/u/IdeaGarage)\
**Post date:** [December 22, 2022, 5:06am UTC](https://community.weweb.io/t/userroles-is-supabroken/1612/4 "2022-12-22T05:06:21Z")

</div>

Same for me. I do not use this configure meanwhile.
