mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
docs: remove unused user_id param (#21939)
* docs: remove unused user_id param * mark fn STABLE not IMMUTABLE * chore: update throughout. --------- Co-authored-by: thorwebdev <thor@supabase.io> Co-authored-by: Thor 雷神 Schaeff <5748289+thorwebdev@users.noreply.github.com>
This commit is contained in:
4 files changed
+12
-15
No files matched your search
@@ -87,7 +87,7 @@ The [Custom Access Token Auth Hook](/docs/guides/auth/auth-hooks#hook-custom-acc
|
||||
create or replace function public.custom_access_token_hook(event jsonb)
|
||||
returns jsonb
|
||||
language plpgsql
|
||||
immutable
|
||||
stable
|
||||
as $$
|
||||
declare
|
||||
claims jsonb;
|
||||
@@ -216,8 +216,7 @@ To utilize Role-Based Access Control (RBAC) in Row Level Security (RLS) policies
|
||||
|
||||
```sql supabase/migrations/init.sql
|
||||
create function public.authorize(
|
||||
requested_permission app_permission,
|
||||
user_id uuid
|
||||
requested_permission app_permission
|
||||
)
|
||||
returns boolean as $$
|
||||
declare
|
||||
@@ -243,8 +242,8 @@ You can read more about using functions in RLS policies in the [RLS guide](/docs
|
||||
You can then use the `authorize` method within your RLS policies. For example, to enable the desired delete access, you would add the following policies:
|
||||
|
||||
```sql
|
||||
create policy "Allow authorized delete access" on public.channels for delete using ( authorize('channels.delete', auth.uid()) );
|
||||
create policy "Allow authorized delete access" on public.messages for delete using ( authorize('messages.delete', auth.uid()) );
|
||||
create policy "Allow authorized delete access" on public.channels for delete using ( authorize('channels.delete') );
|
||||
create policy "Allow authorized delete access" on public.messages for delete using ( authorize('messages.delete') );
|
||||
```
|
||||
|
||||
## Accessing custom claims in your application
|
||||
|
||||
@@ -55,8 +55,7 @@ comment on table public.role_permissions is 'Application permissions for each ro
|
||||
|
||||
-- authorize with role-based access control (RBAC)
|
||||
create function public.authorize(
|
||||
requested_permission app_permission,
|
||||
user_id uuid
|
||||
requested_permission app_permission
|
||||
)
|
||||
returns boolean as $$
|
||||
declare
|
||||
@@ -84,12 +83,12 @@ create policy "Allow individual update access" on public.users for update using
|
||||
create policy "Allow logged-in read access" on public.channels for select using ( auth.role() = 'authenticated' );
|
||||
create policy "Allow individual insert access" on public.channels for insert with check ( auth.uid() = created_by );
|
||||
create policy "Allow individual delete access" on public.channels for delete using ( auth.uid() = created_by );
|
||||
create policy "Allow authorized delete access" on public.channels for delete using ( authorize('channels.delete', auth.uid()) );
|
||||
create policy "Allow authorized delete access" on public.channels for delete using ( authorize('channels.delete') );
|
||||
create policy "Allow logged-in read access" on public.messages for select using ( auth.role() = 'authenticated' );
|
||||
create policy "Allow individual insert access" on public.messages for insert with check ( auth.uid() = user_id );
|
||||
create policy "Allow individual update access" on public.messages for update using ( auth.uid() = user_id );
|
||||
create policy "Allow individual delete access" on public.messages for delete using ( auth.uid() = user_id );
|
||||
create policy "Allow authorized delete access" on public.messages for delete using ( authorize('messages.delete', auth.uid()) );
|
||||
create policy "Allow authorized delete access" on public.messages for delete using ( authorize('messages.delete') );
|
||||
create policy "Allow individual read access" on public.user_roles for select using ( auth.uid() = user_id );
|
||||
|
||||
-- Send "previous data" on change
|
||||
@@ -150,7 +149,7 @@ alter publication supabase_realtime add table public.users;
|
||||
create or replace function public.custom_access_token_hook(event jsonb)
|
||||
returns jsonb
|
||||
language plpgsql
|
||||
immutable
|
||||
stable
|
||||
as $$
|
||||
declare
|
||||
claims jsonb;
|
||||
|
||||
@@ -55,8 +55,7 @@ comment on table public.role_permissions is 'Application permissions for each ro
|
||||
|
||||
-- authorize with role-based access control (RBAC)
|
||||
create function public.authorize(
|
||||
requested_permission app_permission,
|
||||
user_id uuid
|
||||
requested_permission app_permission
|
||||
)
|
||||
returns boolean as $$
|
||||
declare
|
||||
@@ -84,12 +83,12 @@ create policy "Allow individual update access" on public.users for update using
|
||||
create policy "Allow logged-in read access" on public.channels for select using ( auth.role() = 'authenticated' );
|
||||
create policy "Allow individual insert access" on public.channels for insert with check ( auth.uid() = created_by );
|
||||
create policy "Allow individual delete access" on public.channels for delete using ( auth.uid() = created_by );
|
||||
create policy "Allow authorized delete access" on public.channels for delete using ( authorize('channels.delete', auth.uid()) );
|
||||
create policy "Allow authorized delete access" on public.channels for delete using ( authorize('channels.delete') );
|
||||
create policy "Allow logged-in read access" on public.messages for select using ( auth.role() = 'authenticated' );
|
||||
create policy "Allow individual insert access" on public.messages for insert with check ( auth.uid() = user_id );
|
||||
create policy "Allow individual update access" on public.messages for update using ( auth.uid() = user_id );
|
||||
create policy "Allow individual delete access" on public.messages for delete using ( auth.uid() = user_id );
|
||||
create policy "Allow authorized delete access" on public.messages for delete using ( authorize('messages.delete', auth.uid()) );
|
||||
create policy "Allow authorized delete access" on public.messages for delete using ( authorize('messages.delete') );
|
||||
create policy "Allow individual read access" on public.user_roles for select using ( auth.uid() = user_id );
|
||||
|
||||
-- Send "previous data" on change
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@
|
||||
create or replace function public.custom_access_token_hook(event jsonb)
|
||||
returns jsonb
|
||||
language plpgsql
|
||||
immutable
|
||||
stable
|
||||
as $$
|
||||
declare
|
||||
claims jsonb;
|
||||
|
||||
Reference in new issue
Block a user