diff --git a/apps/docs/content/guides/database/functions.mdx b/apps/docs/content/guides/database/functions.mdx index 8fb0158569b..8186c100eb4 100644 --- a/apps/docs/content/guides/database/functions.mdx +++ b/apps/docs/content/guides/database/functions.mdx @@ -62,7 +62,7 @@ At it's most basic a function has the following parts: -When naming your functions, please make the name of the function unique as overloaded functions are not supported. +When naming your functions, make the name of the function unique as overloaded functions are not supported. diff --git a/apps/docs/content/guides/functions/auth.mdx b/apps/docs/content/guides/functions/auth.mdx index 34ec98d4e36..0ade89bb3ac 100644 --- a/apps/docs/content/guides/functions/auth.mdx +++ b/apps/docs/content/guides/functions/auth.mdx @@ -19,9 +19,11 @@ Deno.serve(async (req: Request) => { const supabaseClient = createClient( Deno.env.get('SUPABASE_URL') ?? '', Deno.env.get('SUPABASE_ANON_KEY') ?? '', + // Create client with Auth context of the user that called the function. + // This way your row-level-security (RLS) policies are applied. { global: { - headers: { Authorization: req.headers.get('Authorization') }, + headers: { Authorization: req.headers.get('Authorization')! }, }, } ); @@ -38,7 +40,7 @@ Importantly, this is done _inside_ the `Deno.serve()` callback argument, so that ## Fetching the user -After initializing a Supabase client with the Auth context, you can use `getUser()` to fetch the user object, and run queries in the context of the user with [Row Level Security (RLS)](/docs/guides/database/postgres/row-level-security) policies enforced. +By getting the JWT from the `Authorization` header, you can provide the token to `getUser()` to fetch the user object to obtain metadata for the logged in user. ```js import { createClient } from 'npm:@supabase/supabase-js@2' @@ -81,9 +83,11 @@ Deno.serve(async (req: Request) => { const supabaseClient = createClient( Deno.env.get('SUPABASE_URL') ?? '', Deno.env.get('SUPABASE_ANON_KEY') ?? '', + // Create client with Auth context of the user that called the function. + // This way your row-level-security (RLS) policies are applied. { global: { - headers: { Authorization: req.headers.get('Authorization') }, + headers: { Authorization: req.headers.get('Authorization')! }, }, } );