mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
Merge branch 'master' into chore/rename-spec-files
This commit is contained in:
commit
2fbac400a6
3 files changed
+14
-24
No files matched your search
@@ -278,10 +278,10 @@ final res = await supabase
|
||||
|
||||
### Database Functions vs Edge Functions
|
||||
|
||||
For data-intensive operations we recommend using [Database Functions](../../guides/database/functions), which are executed within your database
|
||||
For data-intensive operations, use Database Functions, which are executed within your database
|
||||
and can be called remotely using the [REST and GraphQL API](../api).
|
||||
|
||||
For use-cases which require low-latency we recommend [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript.
|
||||
For use-cases which require low-latency, use [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript.
|
||||
|
||||
### Security `definer` vs `invoker`
|
||||
|
||||
@@ -302,6 +302,18 @@ $$;
|
||||
It is best practice to use `security invoker` (which is also the default). If you ever use `security definer`, you _must_ set the `search_path`.
|
||||
This limits the potential damage if you allow access to schemas which the user executing the function should not have.
|
||||
|
||||
### Function privileges
|
||||
|
||||
By default, database functions can be executed by any role. You can restrict this by altering the default privileges and then choosing which roles can execute functions.
|
||||
|
||||
```sql
|
||||
ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC;
|
||||
|
||||
-- Choose which roles can execute functions
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO authenticated;
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO service_role;
|
||||
```
|
||||
|
||||
## Resources
|
||||
|
||||
- Official Client libraries: [JavaScript](../../reference/javascript/rpc) and [Dart](../../reference/dart/rpc)
|
||||
|
||||
@@ -943,17 +943,6 @@ pages:
|
||||
$$ language sql;
|
||||
```
|
||||
$ref: '@supabase/postgrest-js.PostgrestClient.rpc'
|
||||
notes: |
|
||||
By default, functions can be executed by any role.
|
||||
You can restrict this by altering the default prvivileges and then choosing which roles can execute functions.
|
||||
|
||||
```sql
|
||||
ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC;
|
||||
|
||||
-- Choose which roles can execute functions
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO authenticated;
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO service_role;
|
||||
```
|
||||
examples:
|
||||
- name: Call a Postgres function without arguments
|
||||
isSpotlight: true
|
||||
|
||||
@@ -1847,17 +1847,6 @@ pages:
|
||||
$$ language sql;
|
||||
```
|
||||
$ref: '@supabase/postgrest-js.PostgrestClient.rpc'
|
||||
notes: |
|
||||
By default, functions can be executed by any role.
|
||||
You can restrict this by altering the default prvivileges and then choosing which roles can execute functions.
|
||||
|
||||
```sql
|
||||
ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC;
|
||||
|
||||
-- Choose which roles can execute functions
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO authenticated;
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO service_role;
|
||||
```
|
||||
examples:
|
||||
- name: Call a Postgres function without arguments
|
||||
description: |
|
||||
|
||||
Reference in new issue
Block a user