From 7a4c654ecd2a7eb4c50d4464bbb40c67bb9fc290 Mon Sep 17 00:00:00 2001 From: Copple <10214025+kiwicopple@users.noreply.github.com> Date: Fri, 1 Jul 2022 14:37:35 -0500 Subject: [PATCH] Update web/docs/guides/database/tables.mdx --- web/docs/guides/database/tables.mdx | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/web/docs/guides/database/tables.mdx b/web/docs/guides/database/tables.mdx index 7f7ce3b5bf9..b05a196de2a 100644 --- a/web/docs/guides/database/tables.mdx +++ b/web/docs/guides/database/tables.mdx @@ -342,8 +342,7 @@ A View is a convenient shortcut to a query. Creating a view does not involve new :::caution -PostgreSQL views are called with the privileges of the role that created them. To enable Row Level Security you should change the owner to the "authenticated" role: -`alter view view_name owner to authenticated;`. +By default, PostgreSQL views bypass Row Level Security unless you change their owner (see https://github.com/supabase/supabase/discussions/901). PostgreSQL v15 (coming soon) will have a more intuitive control for this through [security invoker views](https://www.depesz.com/2022/03/22/waiting-for-postgresql-15-add-support-for-security-invoker-views/) and the previous step won't be needed. :::