From 830c06d494d6692d0a37e64aa56c77dbdca3752d Mon Sep 17 00:00:00 2001 From: Sean Geoghegan Date: Sat, 26 Sep 2026 03:07:24 +0930 Subject: [PATCH] docs: clarify authorisation window when policies change (#50695) ## Solution Clarifying the authorisation window for RLS/access checks on channels in Realtime. ## Review instructions Provide a clear numbered procedure that the PR reviewer can walk through. 1. For example, `Open the live and preview links side-by-side.` 2. For example, `See the issue is fixed.` ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide ## Summary by CodeRabbit * **Documentation** * Clarified that Realtime authorization policy changes may not affect already-connected clients until their JWT expires or a new JWT is provided. --- apps/docs/content/guides/realtime/authorization.mdx | 2 ++ 1 file changed, 2 insertions(+) diff --git a/apps/docs/content/guides/realtime/authorization.mdx b/apps/docs/content/guides/realtime/authorization.mdx index 7b8cd831b9b..7dc0410d29c 100644 --- a/apps/docs/content/guides/realtime/authorization.mdx +++ b/apps/docs/content/guides/realtime/authorization.mdx @@ -402,6 +402,8 @@ Realtime updates the access policy cache for a client based on your RLS policies - A client connects to Realtime and subscribes to a Channel - A new JWT is sent to Realtime from a client via the [`access_token` message](/docs/guides/realtime/protocol#access-token) +This means that if you revoke a user's access (for example, by removing a row an RLS policy uses to grant it) while they're still connected, they'll keep receiving messages until their JWT expires or a new one is sent. + If a new JWT is never received on the Channel, the client will be disconnected when the JWT expires. Make sure to keep the JWT expiration window short.