From 09ca836d6cc1965853ed4fc6773f10e13da70a39 Mon Sep 17 00:00:00 2001 From: Qiao Han Date: Fri, 11 Nov 2022 13:12:07 +0800 Subject: [PATCH] chore: document service role use case and grants --- apps/docs/docs/guides/api.mdx | 6 ++++++ apps/reference/docs/guides/api.mdx | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/apps/docs/docs/guides/api.mdx b/apps/docs/docs/guides/api.mdx index 4b4686d1d7e..9896a65128b 100644 --- a/apps/docs/docs/guides/api.mdx +++ b/apps/docs/docs/guides/api.mdx @@ -349,6 +349,12 @@ alter table todos enable row level security; Never expose the `service_role` key in a browser or anywhere where a user can see it. This Key is designed to bypass Row Level Security - so it should only be used on a private server. +A common use case for the `service_role` key is to run data analytics jobs on the backend. To support joins on user id, it is often useful to grant the service role read access to `auth.users` table. + +```sql +grant select on table auth.users to service_role; +``` + We have [partnered with GitHub](https://github.blog/changelog/2022-03-28-supabase-is-now-a-github-secret-scanning-partner/) to scan for Supabase `service_role` keys pushed to public repositories. If they detect any keys with service_role privileges being pushed to GitHub, they will forward the API key to us, so that we can automatically revoke the detected secrets and notify you, protecting your data against malicious actors. diff --git a/apps/reference/docs/guides/api.mdx b/apps/reference/docs/guides/api.mdx index 863bc7eb780..d3c4ebed05a 100644 --- a/apps/reference/docs/guides/api.mdx +++ b/apps/reference/docs/guides/api.mdx @@ -385,6 +385,12 @@ alter table todos enable row level security; Never expose the `service_role` key in a browser or anywhere where a user can see it. This Key is designed to bypass Row Level Security - so it should only be used on a private server. +A common use case for the `service_role` key is to run data analytics jobs on the backend. To support joins on user id, it is often useful to grant the service role read access to `auth.users` table. + +```sql +grant select on table auth.users to service_role; +``` + We have [partnered with GitHub](https://github.blog/changelog/2022-03-28-supabase-is-now-a-github-secret-scanning-partner/) to scan for Supabase `service_role` keys pushed to public repositories. If they detect any keys with service_role privileges being pushed to GitHub, they will forward the API key to us, so that we can automatically revoke the detected secrets and notify you, protecting your data against malicious actors.