From a3273689e1e12929bf4d96a946ea1de38d1ccf50 Mon Sep 17 00:00:00 2001 From: dannykng Date: Tue, 4 Oct 2022 16:18:30 -0700 Subject: [PATCH] Move function priv info to db functions guide --- .../reference/docs/guides/database/functions.mdx | 16 ++++++++++++++-- spec/supabase_js_v1_legacy.yml | 11 ----------- spec/supabase_js_v2_legacy.yml | 11 ----------- 3 files changed, 14 insertions(+), 24 deletions(-) diff --git a/apps/reference/docs/guides/database/functions.mdx b/apps/reference/docs/guides/database/functions.mdx index 9e2b4e407d6..8a108157bc3 100644 --- a/apps/reference/docs/guides/database/functions.mdx +++ b/apps/reference/docs/guides/database/functions.mdx @@ -278,10 +278,10 @@ final res = await supabase ### Database Functions vs Edge Functions -For data-intensive operations we recommend using [Database Functions](../../guides/database/functions), which are executed within your database +For data-intensive operations, use Database Functions, which are executed within your database and can be called remotely using the [REST and GraphQL API](../api). -For use-cases which require low-latency we recommend [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript. +For use-cases which require low-latency, use [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript. ### Security `definer` vs `invoker` @@ -302,6 +302,18 @@ $$; It is best practice to use `security invoker` (which is also the default). If you ever use `security definer`, you _must_ set the `search_path`. This limits the potential damage if you allow access to schemas which the user executing the function should not have. +### Function privileges + +By default, database functions can be executed by any role. You can restrict this by altering the default privileges and then choosing which roles can execute functions. + +```sql +ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; + +-- Choose which roles can execute functions +GRANT EXECUTE ON FUNCTION hello_world TO authenticated; +GRANT EXECUTE ON FUNCTION hello_world TO service_role; +``` + ## Resources - Official Client libraries: [JavaScript](../../reference/javascript/rpc) and [Dart](../../reference/dart/rpc) diff --git a/spec/supabase_js_v1_legacy.yml b/spec/supabase_js_v1_legacy.yml index c021d01134f..75a165f10e4 100644 --- a/spec/supabase_js_v1_legacy.yml +++ b/spec/supabase_js_v1_legacy.yml @@ -943,17 +943,6 @@ pages: $$ language sql; ``` $ref: '@supabase/postgrest-js.PostgrestClient.rpc' - notes: | - By default, functions can be executed by any role. - You can restrict this by altering the default prvivileges and then choosing which roles can execute functions. - - ```sql - ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; - - -- Choose which roles can execute functions - GRANT EXECUTE ON FUNCTION hello_world TO authenticated; - GRANT EXECUTE ON FUNCTION hello_world TO service_role; - ``` examples: - name: Call a Postgres function without arguments isSpotlight: true diff --git a/spec/supabase_js_v2_legacy.yml b/spec/supabase_js_v2_legacy.yml index 455e15f86c6..3b75c261ad6 100644 --- a/spec/supabase_js_v2_legacy.yml +++ b/spec/supabase_js_v2_legacy.yml @@ -1847,17 +1847,6 @@ pages: $$ language sql; ``` $ref: '@supabase/postgrest-js.PostgrestClient.rpc' - notes: | - By default, functions can be executed by any role. - You can restrict this by altering the default prvivileges and then choosing which roles can execute functions. - - ```sql - ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; - - -- Choose which roles can execute functions - GRANT EXECUTE ON FUNCTION hello_world TO authenticated; - GRANT EXECUTE ON FUNCTION hello_world TO service_role; - ``` examples: - name: Call a Postgres function without arguments description: |