mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 01:15:03 +03:00
chore(docs): use more restrictive RLS policies for storage in example projects (#46172)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update ## What is the current behavior? Storage RLS polices unintentionally allow list access to buckets potentially setting a bad example for people starting a new project. ## What is the new behavior? Use more restrictive RLS polices that only allow the intended operations <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated Supabase Storage access-control policies and examples across docs and starter projects. * Tightened avatar image access rules to require explicit operation checks for public reads. * Clarified guidance and added explanatory comments in migration and README examples to illustrate the updated access patterns. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46172?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
This commit is contained in:
1 parent
25fcf26c55
commit
2a8dc75e3d
11 files changed
+42
-22
No files matched your search
@@ -46,9 +46,10 @@ create policy "Users can update own profile." on profiles
|
||||
insert into storage.buckets (id, name)
|
||||
values ('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects
|
||||
for select using (bucket_id = 'avatars');
|
||||
for select using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects
|
||||
for insert with check (bucket_id = 'avatars');
|
||||
|
||||
@@ -107,9 +107,11 @@ insert into
|
||||
values
|
||||
('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects for
|
||||
select
|
||||
using (bucket_id = 'avatars');
|
||||
using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects for insert
|
||||
with
|
||||
|
||||
+3
-3
@@ -41,10 +41,10 @@ create trigger on_auth_user_created
|
||||
insert into storage.buckets (id, name)
|
||||
values ('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage.
|
||||
-- See https://supabase.com/docs/guides/storage#policy-examples for more details.
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects
|
||||
for select using (bucket_id = 'avatars');
|
||||
for select using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects
|
||||
for insert with check (bucket_id = 'avatars');
|
||||
|
||||
@@ -186,10 +186,10 @@ create trigger on_auth_user_created
|
||||
insert into storage.buckets (id, name)
|
||||
values ('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage.
|
||||
-- See https://supabase.com/docs/guides/storage#policy-examples for more details.
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects
|
||||
for select using (bucket_id = 'avatars');
|
||||
for select using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects
|
||||
for insert with check (bucket_id = 'avatars');
|
||||
|
||||
+3
-3
@@ -41,10 +41,10 @@ create trigger on_auth_user_created
|
||||
insert into storage.buckets (id, name)
|
||||
values ('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage.
|
||||
-- See https://supabase.com/docs/guides/storage#policy-examples for more details.
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects
|
||||
for select using (bucket_id = 'avatars');
|
||||
for select using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects
|
||||
for insert with check (bucket_id = 'avatars');
|
||||
|
||||
@@ -116,9 +116,11 @@ insert into
|
||||
values
|
||||
('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects for
|
||||
select
|
||||
using (bucket_id = 'avatars');
|
||||
using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects for insert
|
||||
with
|
||||
|
||||
@@ -114,9 +114,11 @@ insert into
|
||||
values
|
||||
('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects for
|
||||
select
|
||||
using (bucket_id = 'avatars');
|
||||
using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects for insert
|
||||
with
|
||||
|
||||
+3
-3
@@ -41,10 +41,10 @@ create trigger on_auth_user_created
|
||||
insert into storage.buckets (id, name)
|
||||
values ('avatars', 'avatars');
|
||||
|
||||
-- Set up access controls for storage.
|
||||
-- See https://supabase.com/docs/guides/storage#policy-examples for more details.
|
||||
-- Set up access controls for storage. Allows downloading object with public key
|
||||
-- See https://supabase.com/docs/guides/storage/security/access-control#policy-examples for more details.
|
||||
create policy "Avatar images are publicly accessible." on storage.objects
|
||||
for select using (bucket_id = 'avatars');
|
||||
for select using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));
|
||||
|
||||
create policy "Anyone can upload an avatar." on storage.objects
|
||||
for insert with check (bucket_id = 'avatars');
|
||||
|
||||
Reference in new issue
Block a user