mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
fix: revoke role on public for hooks (#27077)
* fix: revoke role on public for hooks * fix: update SQL editor queries * fix: update examples * fix: update RBAC doc * fix: update description to describe why we revoke public * fix: correct use of we * fix: run prettier * fix: remove unintentionally added files
This commit is contained in:
1 parent
5847ad54cf
commit
7547c52e4f
4 files changed
+24
-24
No files matched your search
@@ -77,12 +77,12 @@ You also need to grant usage to `supabase_auth_admin`:
|
||||
grant usage on schema public to supabase_auth_admin;
|
||||
```
|
||||
|
||||
Also revoke permissions from the `authenticated` and `anon` roles to ensure the function is not accessible by Supabase Serverless APIs.
|
||||
Also revoke permissions from the `authenticated`, `public`, and `anon` roles to ensure the function is not accessible by Supabase Serverless APIs. The `public` role has access to functions created on `public.*` by default and `anon` and `authenticated` inherit permissions from the `public` role. Permission is revoked from the`public` role in order to prevent the `anon` and `authenticated` roles from inheriting permissions to invoke the Postgres Hook.
|
||||
|
||||
```sql
|
||||
revoke execute
|
||||
on function public.custom_access_token_hook
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
```
|
||||
|
||||
For security, we recommend against the use the `security definer` tag. The `security definer` tag specifies that the function is to be executed with the privileges of the user that owns it. When a function is created via the Supabase dashboard with the tag, it will have the extensive permissions of the `postgres` role which make it easier for undesirable actions to occur.
|
||||
@@ -258,11 +258,11 @@ grant all
|
||||
|
||||
revoke execute
|
||||
on function public.hook_mfa_verification_attempt
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
revoke all
|
||||
on table public.mfa_failed_verification_attempts
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
```
|
||||
|
||||
</TabPanel>
|
||||
@@ -389,11 +389,11 @@ grant all
|
||||
|
||||
revoke execute
|
||||
on function public.hook_password_verification_attempt
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
revoke all
|
||||
on table public.password_failed_verification_attempts
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
```
|
||||
|
||||
</TabPanel>
|
||||
@@ -500,7 +500,7 @@ grant execute
|
||||
|
||||
revoke execute
|
||||
on function public.hook_notify_user_on_failed_attempts
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant all
|
||||
on table public.password_sign_in_attempts
|
||||
@@ -508,7 +508,7 @@ grant all
|
||||
|
||||
revoke all
|
||||
on table public.password_sign_in_attempts
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
```
|
||||
|
||||
</TabPanel>
|
||||
@@ -602,7 +602,7 @@ grant execute
|
||||
|
||||
revoke execute
|
||||
on function public.custom_access_token_hook
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant all
|
||||
on table public.profiles
|
||||
@@ -610,7 +610,7 @@ grant all
|
||||
|
||||
revoke all
|
||||
on table public.profiles
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
```
|
||||
|
||||
</TabPanel>
|
||||
@@ -662,7 +662,7 @@ grant all
|
||||
|
||||
revoke all
|
||||
on table public.profiles
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
```
|
||||
|
||||
</TabPanel>
|
||||
@@ -706,7 +706,7 @@ grant execute
|
||||
|
||||
revoke execute
|
||||
on function public.restrict_application_access
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
```
|
||||
|
||||
</TabPanel>
|
||||
|
||||
+4
-4
@@ -121,7 +121,7 @@ grant execute
|
||||
|
||||
revoke execute
|
||||
on function public.custom_access_token_hook
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant all
|
||||
on table public.user_roles
|
||||
@@ -129,7 +129,7 @@ to supabase_auth_admin;
|
||||
|
||||
revoke all
|
||||
on table public.user_roles
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
create policy "Allow auth admin to read user roles" ON public.user_roles
|
||||
as permissive for select
|
||||
@@ -179,7 +179,7 @@ grant execute
|
||||
|
||||
revoke execute
|
||||
on function public.custom_access_token_hook
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant all
|
||||
on table public.user_roles
|
||||
@@ -187,7 +187,7 @@ to supabase_auth_admin;
|
||||
|
||||
revoke all
|
||||
on table public.user_roles
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
create policy "Allow auth admin to read user roles" ON public.user_roles
|
||||
as permissive for select
|
||||
|
||||
@@ -1373,11 +1373,11 @@ grant all
|
||||
|
||||
revoke execute
|
||||
on function public.hook_mfa_verification_attempt
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
revoke all
|
||||
on table public.mfa_failed_verification_attempts
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant usage on schema public to supabase_auth_admin;`.trim(),
|
||||
},
|
||||
@@ -1445,11 +1445,11 @@ grant all
|
||||
|
||||
revoke execute
|
||||
on function public.hook_password_verification_attempt
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
revoke all
|
||||
on table public.password_failed_verification_attempts
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant usage on schema public to supabase_auth_admin;`.trim(),
|
||||
},
|
||||
@@ -1499,7 +1499,7 @@ grant execute
|
||||
|
||||
revoke execute
|
||||
on function public.custom_access_token_hook
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant usage on schema public to supabase_auth_admin;`.trim(),
|
||||
},
|
||||
@@ -1523,7 +1523,7 @@ end;
|
||||
$$;
|
||||
-- Permissions for the hook
|
||||
grant execute on function public.custom_access_token_hook to supabase_auth_admin;
|
||||
revoke execute on function public.custom_access_token_hook from authenticated, anon;
|
||||
revoke execute on function public.custom_access_token_hook from authenticated, anon, public;
|
||||
`,
|
||||
},
|
||||
]
|
||||
@@ -183,7 +183,7 @@ grant execute
|
||||
|
||||
revoke execute
|
||||
on function public.custom_access_token_hook
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
grant all
|
||||
on table public.user_roles
|
||||
@@ -191,7 +191,7 @@ to supabase_auth_admin;
|
||||
|
||||
revoke all
|
||||
on table public.user_roles
|
||||
from authenticated, anon;
|
||||
from authenticated, anon, public;
|
||||
|
||||
create policy "Allow auth admin to read user roles" ON public.user_roles
|
||||
as permissive for select
|
||||
|
||||
Reference in new issue
Block a user