From 0c6044d197751d08a79eb87f01a6dcaa4ab6d64a Mon Sep 17 00:00:00 2001 From: Inian Date: Mon, 7 Jun 2021 23:46:18 +0800 Subject: [PATCH] add auth.email function definition in auth deep dive --- web/docs/learn/auth-deep-dive/policies.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/web/docs/learn/auth-deep-dive/policies.md b/web/docs/learn/auth-deep-dive/policies.md index 6b2c99b4891..7c1f8026df3 100644 --- a/web/docs/learn/auth-deep-dive/policies.md +++ b/web/docs/learn/auth-deep-dive/policies.md @@ -136,6 +136,10 @@ There are some more notes here on how to structure your schema to best integrate Once you get the hang of polices you can start to get a little bit fancy. Let's say I work at Blizzard and I only want Blizzard staff members to be able to update people's high scores, I can write something like: ```sql +create or replace function auth.email() returns text as $$ + select nullif(current_setting('request.jwt.claim.email', true), '')::text; +$$ language sql; + create policy "Only Blizzard staff can update leaderboard" on my_scores for update using (