From 7547c52e4f5637e72a3cd9568f7c0efd6905dff3 Mon Sep 17 00:00:00 2001 From: Joel Lee Date: Fri, 7 Jun 2024 22:03:12 +0200 Subject: [PATCH] fix: revoke role on public for hooks (#27077) * fix: revoke role on public for hooks * fix: update SQL editor queries * fix: update examples * fix: update RBAC doc * fix: update description to describe why we revoke public * fix: correct use of we * fix: run prettier * fix: remove unintentionally added files --- apps/docs/content/guides/auth/auth-hooks.mdx | 24 +++++++++---------- ...ims-and-role-based-access-control-rbac.mdx | 8 +++---- .../interfaces/SQLEditor/SQLEditor.queries.ts | 12 +++++----- .../nextjs-slack-clone/full-schema.sql | 4 ++-- 4 files changed, 24 insertions(+), 24 deletions(-) diff --git a/apps/docs/content/guides/auth/auth-hooks.mdx b/apps/docs/content/guides/auth/auth-hooks.mdx index c6a833b30fc..336b9c950d9 100644 --- a/apps/docs/content/guides/auth/auth-hooks.mdx +++ b/apps/docs/content/guides/auth/auth-hooks.mdx @@ -77,12 +77,12 @@ You also need to grant usage to `supabase_auth_admin`: grant usage on schema public to supabase_auth_admin; ``` -Also revoke permissions from the `authenticated` and `anon` roles to ensure the function is not accessible by Supabase Serverless APIs. +Also revoke permissions from the `authenticated`, `public`, and `anon` roles to ensure the function is not accessible by Supabase Serverless APIs. The `public` role has access to functions created on `public.*` by default and `anon` and `authenticated` inherit permissions from the `public` role. Permission is revoked from the`public` role in order to prevent the `anon` and `authenticated` roles from inheriting permissions to invoke the Postgres Hook. ```sql revoke execute on function public.custom_access_token_hook - from authenticated, anon; + from authenticated, anon, public; ``` For security, we recommend against the use the `security definer` tag. The `security definer` tag specifies that the function is to be executed with the privileges of the user that owns it. When a function is created via the Supabase dashboard with the tag, it will have the extensive permissions of the `postgres` role which make it easier for undesirable actions to occur. @@ -258,11 +258,11 @@ grant all revoke execute on function public.hook_mfa_verification_attempt - from authenticated, anon; + from authenticated, anon, public; revoke all on table public.mfa_failed_verification_attempts - from authenticated, anon; + from authenticated, anon, public; ``` @@ -389,11 +389,11 @@ grant all revoke execute on function public.hook_password_verification_attempt - from authenticated, anon; + from authenticated, anon, public; revoke all on table public.password_failed_verification_attempts - from authenticated, anon; + from authenticated, anon, public; ``` @@ -500,7 +500,7 @@ grant execute revoke execute on function public.hook_notify_user_on_failed_attempts - from authenticated, anon; + from authenticated, anon, public; grant all on table public.password_sign_in_attempts @@ -508,7 +508,7 @@ grant all revoke all on table public.password_sign_in_attempts - from authenticated, anon; + from authenticated, anon, public; ``` @@ -602,7 +602,7 @@ grant execute revoke execute on function public.custom_access_token_hook - from authenticated, anon; + from authenticated, anon, public; grant all on table public.profiles @@ -610,7 +610,7 @@ grant all revoke all on table public.profiles - from authenticated, anon; + from authenticated, anon, public; ``` @@ -662,7 +662,7 @@ grant all revoke all on table public.profiles - from authenticated, anon; + from authenticated, anon, public; ``` @@ -706,7 +706,7 @@ grant execute revoke execute on function public.restrict_application_access - from authenticated, anon; + from authenticated, anon, public; ``` diff --git a/apps/docs/content/guides/database/postgres/custom-claims-and-role-based-access-control-rbac.mdx b/apps/docs/content/guides/database/postgres/custom-claims-and-role-based-access-control-rbac.mdx index 38d2ad99810..d429ad3baea 100644 --- a/apps/docs/content/guides/database/postgres/custom-claims-and-role-based-access-control-rbac.mdx +++ b/apps/docs/content/guides/database/postgres/custom-claims-and-role-based-access-control-rbac.mdx @@ -121,7 +121,7 @@ grant execute revoke execute on function public.custom_access_token_hook - from authenticated, anon; + from authenticated, anon, public; grant all on table public.user_roles @@ -129,7 +129,7 @@ to supabase_auth_admin; revoke all on table public.user_roles - from authenticated, anon; + from authenticated, anon, public; create policy "Allow auth admin to read user roles" ON public.user_roles as permissive for select @@ -179,7 +179,7 @@ grant execute revoke execute on function public.custom_access_token_hook - from authenticated, anon; + from authenticated, anon, public; grant all on table public.user_roles @@ -187,7 +187,7 @@ to supabase_auth_admin; revoke all on table public.user_roles - from authenticated, anon; + from authenticated, anon, public; create policy "Allow auth admin to read user roles" ON public.user_roles as permissive for select diff --git a/apps/studio/components/interfaces/SQLEditor/SQLEditor.queries.ts b/apps/studio/components/interfaces/SQLEditor/SQLEditor.queries.ts index ead4a507778..fd4a3b2c5a5 100644 --- a/apps/studio/components/interfaces/SQLEditor/SQLEditor.queries.ts +++ b/apps/studio/components/interfaces/SQLEditor/SQLEditor.queries.ts @@ -1373,11 +1373,11 @@ grant all revoke execute on function public.hook_mfa_verification_attempt - from authenticated, anon; + from authenticated, anon, public; revoke all on table public.mfa_failed_verification_attempts - from authenticated, anon; + from authenticated, anon, public; grant usage on schema public to supabase_auth_admin;`.trim(), }, @@ -1445,11 +1445,11 @@ grant all revoke execute on function public.hook_password_verification_attempt - from authenticated, anon; + from authenticated, anon, public; revoke all on table public.password_failed_verification_attempts - from authenticated, anon; + from authenticated, anon, public; grant usage on schema public to supabase_auth_admin;`.trim(), }, @@ -1499,7 +1499,7 @@ grant execute revoke execute on function public.custom_access_token_hook - from authenticated, anon; + from authenticated, anon, public; grant usage on schema public to supabase_auth_admin;`.trim(), }, @@ -1523,7 +1523,7 @@ end; $$; -- Permissions for the hook grant execute on function public.custom_access_token_hook to supabase_auth_admin; -revoke execute on function public.custom_access_token_hook from authenticated, anon; +revoke execute on function public.custom_access_token_hook from authenticated, anon, public; `, }, ] diff --git a/examples/slack-clone/nextjs-slack-clone/full-schema.sql b/examples/slack-clone/nextjs-slack-clone/full-schema.sql index 59486cae819..a3e294961cb 100644 --- a/examples/slack-clone/nextjs-slack-clone/full-schema.sql +++ b/examples/slack-clone/nextjs-slack-clone/full-schema.sql @@ -183,7 +183,7 @@ grant execute revoke execute on function public.custom_access_token_hook - from authenticated, anon; + from authenticated, anon, public; grant all on table public.user_roles @@ -191,7 +191,7 @@ to supabase_auth_admin; revoke all on table public.user_roles - from authenticated, anon; + from authenticated, anon, public; create policy "Allow auth admin to read user roles" ON public.user_roles as permissive for select