fix: revoke role on public for hooks (#27077)

* fix: revoke role on public for hooks

* fix: update SQL editor queries

* fix: update examples

* fix: update RBAC doc

* fix: update description to describe why we revoke public

* fix: correct use of we

* fix: run prettier

* fix: remove unintentionally added files
This commit is contained in:
Joel Lee authored and GitHub committed 2024-06-07 22:03:12 +02:00
1 parent 5847ad54cf
commit 7547c52e4f
4 files changed
+24 -24

No files matched your search

+12 -12
View File
@@ -77,12 +77,12 @@ You also need to grant usage to `supabase_auth_admin`:
grant usage on schema public to supabase_auth_admin;
```
Also revoke permissions from the `authenticated` and `anon` roles to ensure the function is not accessible by Supabase Serverless APIs.
Also revoke permissions from the `authenticated`, `public`, and `anon` roles to ensure the function is not accessible by Supabase Serverless APIs. The `public` role has access to functions created on `public.*` by default and `anon` and `authenticated` inherit permissions from the `public` role. Permission is revoked from the`public` role in order to prevent the `anon` and `authenticated` roles from inheriting permissions to invoke the Postgres Hook.
```sql
revoke execute
on function public.custom_access_token_hook
from authenticated, anon;
from authenticated, anon, public;
```
For security, we recommend against the use the `security definer` tag. The `security definer` tag specifies that the function is to be executed with the privileges of the user that owns it. When a function is created via the Supabase dashboard with the tag, it will have the extensive permissions of the `postgres` role which make it easier for undesirable actions to occur.
@@ -258,11 +258,11 @@ grant all
revoke execute
on function public.hook_mfa_verification_attempt
from authenticated, anon;
from authenticated, anon, public;
revoke all
on table public.mfa_failed_verification_attempts
from authenticated, anon;
from authenticated, anon, public;
```
</TabPanel>
@@ -389,11 +389,11 @@ grant all
revoke execute
on function public.hook_password_verification_attempt
from authenticated, anon;
from authenticated, anon, public;
revoke all
on table public.password_failed_verification_attempts
from authenticated, anon;
from authenticated, anon, public;
```
</TabPanel>
@@ -500,7 +500,7 @@ grant execute
revoke execute
on function public.hook_notify_user_on_failed_attempts
from authenticated, anon;
from authenticated, anon, public;
grant all
on table public.password_sign_in_attempts
@@ -508,7 +508,7 @@ grant all
revoke all
on table public.password_sign_in_attempts
from authenticated, anon;
from authenticated, anon, public;
```
</TabPanel>
@@ -602,7 +602,7 @@ grant execute
revoke execute
on function public.custom_access_token_hook
from authenticated, anon;
from authenticated, anon, public;
grant all
on table public.profiles
@@ -610,7 +610,7 @@ grant all
revoke all
on table public.profiles
from authenticated, anon;
from authenticated, anon, public;
```
</TabPanel>
@@ -662,7 +662,7 @@ grant all
revoke all
on table public.profiles
from authenticated, anon;
from authenticated, anon, public;
```
</TabPanel>
@@ -706,7 +706,7 @@ grant execute
revoke execute
on function public.restrict_application_access
from authenticated, anon;
from authenticated, anon, public;
```
</TabPanel>
@@ -121,7 +121,7 @@ grant execute
revoke execute
on function public.custom_access_token_hook
from authenticated, anon;
from authenticated, anon, public;
grant all
on table public.user_roles
@@ -129,7 +129,7 @@ to supabase_auth_admin;
revoke all
on table public.user_roles
from authenticated, anon;
from authenticated, anon, public;
create policy "Allow auth admin to read user roles" ON public.user_roles
as permissive for select
@@ -179,7 +179,7 @@ grant execute
revoke execute
on function public.custom_access_token_hook
from authenticated, anon;
from authenticated, anon, public;
grant all
on table public.user_roles
@@ -187,7 +187,7 @@ to supabase_auth_admin;
revoke all
on table public.user_roles
from authenticated, anon;
from authenticated, anon, public;
create policy "Allow auth admin to read user roles" ON public.user_roles
as permissive for select
@@ -1373,11 +1373,11 @@ grant all
revoke execute
on function public.hook_mfa_verification_attempt
from authenticated, anon;
from authenticated, anon, public;
revoke all
on table public.mfa_failed_verification_attempts
from authenticated, anon;
from authenticated, anon, public;
grant usage on schema public to supabase_auth_admin;`.trim(),
},
@@ -1445,11 +1445,11 @@ grant all
revoke execute
on function public.hook_password_verification_attempt
from authenticated, anon;
from authenticated, anon, public;
revoke all
on table public.password_failed_verification_attempts
from authenticated, anon;
from authenticated, anon, public;
grant usage on schema public to supabase_auth_admin;`.trim(),
},
@@ -1499,7 +1499,7 @@ grant execute
revoke execute
on function public.custom_access_token_hook
from authenticated, anon;
from authenticated, anon, public;
grant usage on schema public to supabase_auth_admin;`.trim(),
},
@@ -1523,7 +1523,7 @@ end;
$$;
-- Permissions for the hook
grant execute on function public.custom_access_token_hook to supabase_auth_admin;
revoke execute on function public.custom_access_token_hook from authenticated, anon;
revoke execute on function public.custom_access_token_hook from authenticated, anon, public;
`,
},
]
@@ -183,7 +183,7 @@ grant execute
revoke execute
on function public.custom_access_token_hook
from authenticated, anon;
from authenticated, anon, public;
grant all
on table public.user_roles
@@ -191,7 +191,7 @@ to supabase_auth_admin;
revoke all
on table public.user_roles
from authenticated, anon;
from authenticated, anon, public;
create policy "Allow auth admin to read user roles" ON public.user_roles
as permissive for select