From 5e8bd8ed46eff58eda0083afff31bc71b65b29cf Mon Sep 17 00:00:00 2001 From: Joel Lee Date: Mon, 20 Mar 2023 16:15:10 +0800 Subject: [PATCH] docs: add note about using a service key with rls (#13100) docs: add note about service key with rls Co-authored-by: joel@joellee.org --- apps/docs/pages/guides/auth/row-level-security.mdx | 3 +++ 1 file changed, 3 insertions(+) diff --git a/apps/docs/pages/guides/auth/row-level-security.mdx b/apps/docs/pages/guides/auth/row-level-security.mdx index 473bbb154d3..1987e8acbea 100644 --- a/apps/docs/pages/guides/auth/row-level-security.mdx +++ b/apps/docs/pages/guides/auth/row-level-security.mdx @@ -328,6 +328,9 @@ Tip: Make sure to enable RLS for all your tables, so that your tables are inacce Supabase provides special "Service" keys, which can be used to bypass all RLS. These should never be used in the browser or exposed to customers, but they are useful for administrative tasks. + +Initializing a client with a Service Key will not override RLS if a user token is set. If a user is signed in with a client, Supabase will adhere to the RLS policy of the user. + ### Testing policies