mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
Add recommendation on schema isolation (#45390)
This commit is contained in:
1 parent
5dee242aa3
commit
3ef1c1e08c
2 files changed
+5
-1
No files matched your search
@@ -68,6 +68,10 @@ alter default privileges for role postgres in schema public
|
||||
revoke execute on functions from public;
|
||||
```
|
||||
|
||||
## Use a dedicated API schema
|
||||
|
||||
If you want an extra boundary around your Data API, lock down the `public` schema and expose a dedicated schema, such as `api`, instead. You can control access with grants in any schema, but this can make the surface easier to reason about: objects in `api` represent your Data API, while internal tables and helper functions stay in schemas that are not exposed. See [Using Custom Schemas](/docs/guides/api/using-custom-schemas) for setup steps.
|
||||
|
||||
## Disable the Data API
|
||||
|
||||
If your app never uses Supabase client libraries, REST, or GraphQL data endpoints, turn the Data API off:
|
||||
|
||||
@@ -123,7 +123,7 @@ export const HardenAPIModal = ({ visible, onClose }: HardenAPIModalProps) => {
|
||||
<DocsButton
|
||||
abbrev={false}
|
||||
className="w-min mt-4"
|
||||
href={`${DOCS_URL}/guides/database/hardening-data-api`}
|
||||
href={`${DOCS_URL}/guides/api/using-custom-schemas`}
|
||||
/>
|
||||
</DialogSection>
|
||||
|
||||
|
||||
Reference in new issue
Block a user