diff --git a/web/docs/learn/auth-deep-dive/policies.md b/web/docs/learn/auth-deep-dive/policies.md index 6b2c99b4891..7c1f8026df3 100644 --- a/web/docs/learn/auth-deep-dive/policies.md +++ b/web/docs/learn/auth-deep-dive/policies.md @@ -136,6 +136,10 @@ There are some more notes here on how to structure your schema to best integrate Once you get the hang of polices you can start to get a little bit fancy. Let's say I work at Blizzard and I only want Blizzard staff members to be able to update people's high scores, I can write something like: ```sql +create or replace function auth.email() returns text as $$ + select nullif(current_setting('request.jwt.claim.email', true), '')::text; +$$ language sql; + create policy "Only Blizzard staff can update leaderboard" on my_scores for update using (