mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
Merge branch 'master' into chore/use-vercel-url-for-redirect
This commit is contained in:
commit
874e46db23
4 files changed
+23
-30
No files matched your search
@@ -278,10 +278,10 @@ final res = await supabase
|
||||
|
||||
### Database Functions vs Edge Functions
|
||||
|
||||
For data-intensive operations we recommend using [Database Functions](../../guides/database/functions), which are executed within your database
|
||||
For data-intensive operations, use Database Functions, which are executed within your database
|
||||
and can be called remotely using the [REST and GraphQL API](../api).
|
||||
|
||||
For use-cases which require low-latency we recommend [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript.
|
||||
For use-cases which require low-latency, use [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript.
|
||||
|
||||
### Security `definer` vs `invoker`
|
||||
|
||||
@@ -302,6 +302,18 @@ $$;
|
||||
It is best practice to use `security invoker` (which is also the default). If you ever use `security definer`, you _must_ set the `search_path`.
|
||||
This limits the potential damage if you allow access to schemas which the user executing the function should not have.
|
||||
|
||||
### Function privileges
|
||||
|
||||
By default, database functions can be executed by any role. You can restrict this by altering the default privileges and then choosing which roles can execute functions.
|
||||
|
||||
```sql
|
||||
ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC;
|
||||
|
||||
-- Choose which roles can execute functions
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO authenticated;
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO service_role;
|
||||
```
|
||||
|
||||
## Resources
|
||||
|
||||
- Official Client libraries: [JavaScript](../../reference/javascript/rpc) and [Dart](../../reference/dart/rpc)
|
||||
|
||||
@@ -441,7 +441,7 @@ import { Session } from '@supabase/supabase-js'
|
||||
setupIonicReact()
|
||||
|
||||
const App: React.FC = () => {
|
||||
const [session, setSession] = (useState < Session) | (null > null)
|
||||
const [session, setSession] = useState<Session | null>(null)
|
||||
useEffect(() => {
|
||||
setSession(supabase.auth.session())
|
||||
supabase.auth.onAuthStateChange((_event, session) => {
|
||||
|
||||
@@ -934,10 +934,8 @@ pages:
|
||||
rpc():
|
||||
title: 'Postgres functions: rpc()'
|
||||
description: |
|
||||
You can call Postgres functions as a "Remote Procedure Call".
|
||||
|
||||
That's a fancy way of saying that you can put some logic into your database then call it from anywhere.
|
||||
It's especially useful when the logic rarely changes - like password resets and updates.
|
||||
You can call Postgres functions as _Remote Procedure Calls_, logic in your database that you can execute from anywhere.
|
||||
Functions are useful when the logic rarely changes—like for password resets and updates.
|
||||
|
||||
```sql
|
||||
create or replace function hello_world() returns text as $$
|
||||
@@ -946,15 +944,14 @@ pages:
|
||||
```
|
||||
$ref: '@supabase/postgrest-js.PostgrestClient.rpc'
|
||||
examples:
|
||||
- name: Call a Postgres function
|
||||
- name: Call a Postgres function without arguments
|
||||
isSpotlight: true
|
||||
description: This is an example of invoking a Postgres function with no parameters.
|
||||
js: |
|
||||
```js
|
||||
const { data, error } = await supabase
|
||||
.rpc('hello_world')
|
||||
```
|
||||
- name: With Parameters
|
||||
- name: Call a Postgres function with arguments
|
||||
js: |
|
||||
```js
|
||||
const { data, error } = await supabase
|
||||
@@ -967,7 +964,7 @@ pages:
|
||||
const { data, error } = await postgrest
|
||||
.rpc('echo_cities', { names: ['The Shire', 'Mordor'] })
|
||||
```
|
||||
- name: With filters
|
||||
- name: Call a Postgres function with filters
|
||||
description: |
|
||||
Postgres functions that return tables can also be combined with
|
||||
[Modifiers](/docs/reference/javascript/using-modifiers) and
|
||||
@@ -979,7 +976,7 @@ pages:
|
||||
.select('name, population')
|
||||
.eq('name', 'The Shire')
|
||||
```
|
||||
- name: With count option
|
||||
- name: Call a Postgres function with a count option
|
||||
description: |
|
||||
You can specify a count option to get the row count along with your data.
|
||||
Allowed values for count option are `null`, `exact`, `planned` and `estimated`.
|
||||
@@ -989,20 +986,6 @@ pages:
|
||||
.rpc('hello_world', {}, { count: 'exact' })
|
||||
```
|
||||
|
||||
privileges:
|
||||
description: |
|
||||
By default, functions can be executed by any role. You can restrict this by
|
||||
sql: |
|
||||
```sql
|
||||
ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC;
|
||||
```
|
||||
Then, you can choose which roles can execute functions
|
||||
sql: |
|
||||
```sql
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO authenticated;
|
||||
GRANT EXECUTE ON FUNCTION hello_world TO service_role;
|
||||
```
|
||||
|
||||
subscribe():
|
||||
title: 'on().subscribe()'
|
||||
$ref: '@supabase/supabase-js.lib/SupabaseQueryBuilder.SupabaseQueryBuilder.on'
|
||||
|
||||
@@ -1838,10 +1838,8 @@ pages:
|
||||
rpc():
|
||||
title: 'Postgres functions: rpc()'
|
||||
description: |
|
||||
You can call Postgres functions as a "Remote Procedure Call".
|
||||
|
||||
That's a fancy way of saying that you can put some logic into your database then call it from anywhere.
|
||||
It's especially useful when the logic rarely changes - like password resets and updates.
|
||||
You can call Postgres functions as _Remote Procedure Calls_, logic in your database that you can execute from anywhere.
|
||||
Functions are useful when the logic rarely changes—like for password resets and updates.
|
||||
|
||||
```sql
|
||||
create or replace function hello_world() returns text as $$
|
||||
|
||||
Reference in new issue
Block a user