Add recommendation on schema isolation (#45390)

This commit is contained in:
Saxon Fletcher authored and GitHub committed 2026-04-30 18:09:33 +10:00
1 parent 5dee242aa3
commit 3ef1c1e08c
2 files changed
+5 -1

No files matched your search

@@ -68,6 +68,10 @@ alter default privileges for role postgres in schema public
revoke execute on functions from public;
```
## Use a dedicated API schema
If you want an extra boundary around your Data API, lock down the `public` schema and expose a dedicated schema, such as `api`, instead. You can control access with grants in any schema, but this can make the surface easier to reason about: objects in `api` represent your Data API, while internal tables and helper functions stay in schemas that are not exposed. See [Using Custom Schemas](/docs/guides/api/using-custom-schemas) for setup steps.
## Disable the Data API
If your app never uses Supabase client libraries, REST, or GraphQL data endpoints, turn the Data API off:
@@ -123,7 +123,7 @@ export const HardenAPIModal = ({ visible, onClose }: HardenAPIModalProps) => {
<DocsButton
abbrev={false}
className="w-min mt-4"
href={`${DOCS_URL}/guides/database/hardening-data-api`}
href={`${DOCS_URL}/guides/api/using-custom-schemas`}
/>
</DialogSection>