From bea9372985a92fb640f68bce3596c07a705d7445 Mon Sep 17 00:00:00 2001 From: Johannes Charra Date: Tue, 4 Oct 2022 11:04:39 +0200 Subject: [PATCH 1/3] Update with-ionic-react.mdx fix incorrect useState line --- apps/reference/docs/guides/with-ionic-react.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/reference/docs/guides/with-ionic-react.mdx b/apps/reference/docs/guides/with-ionic-react.mdx index 6885fd6fbac..c35d521e159 100644 --- a/apps/reference/docs/guides/with-ionic-react.mdx +++ b/apps/reference/docs/guides/with-ionic-react.mdx @@ -441,7 +441,7 @@ import { Session } from '@supabase/supabase-js' setupIonicReact() const App: React.FC = () => { - const [session, setSession] = (useState < Session) | (null > null) + const [session, setSession] = useState(null) useEffect(() => { setSession(supabase.auth.session()) supabase.auth.onAuthStateChange((_event, session) => { From af8ef572e7a5e3c5a25c7b7975c8239782fc5a82 Mon Sep 17 00:00:00 2001 From: dannykng Date: Tue, 4 Oct 2022 12:52:52 -0700 Subject: [PATCH 2/3] Update function privileges ref docs --- spec/supabase_js_v1_legacy.yml | 40 +++++++++++++++------------------- spec/supabase_js_v2_legacy.yml | 17 +++++++++++---- 2 files changed, 30 insertions(+), 27 deletions(-) diff --git a/spec/supabase_js_v1_legacy.yml b/spec/supabase_js_v1_legacy.yml index 785be77887c..c021d01134f 100644 --- a/spec/supabase_js_v1_legacy.yml +++ b/spec/supabase_js_v1_legacy.yml @@ -934,10 +934,8 @@ pages: rpc(): title: 'Postgres functions: rpc()' description: | - You can call Postgres functions as a "Remote Procedure Call". - - That's a fancy way of saying that you can put some logic into your database then call it from anywhere. - It's especially useful when the logic rarely changes - like password resets and updates. + You can call Postgres functions as _Remote Procedure Calls_, logic in your database that you can execute from anywhere. + Functions are useful when the logic rarely changes—like for password resets and updates. ```sql create or replace function hello_world() returns text as $$ @@ -945,16 +943,26 @@ pages: $$ language sql; ``` $ref: '@supabase/postgrest-js.PostgrestClient.rpc' + notes: | + By default, functions can be executed by any role. + You can restrict this by altering the default prvivileges and then choosing which roles can execute functions. + + ```sql + ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; + + -- Choose which roles can execute functions + GRANT EXECUTE ON FUNCTION hello_world TO authenticated; + GRANT EXECUTE ON FUNCTION hello_world TO service_role; + ``` examples: - - name: Call a Postgres function + - name: Call a Postgres function without arguments isSpotlight: true - description: This is an example of invoking a Postgres function with no parameters. js: | ```js const { data, error } = await supabase .rpc('hello_world') ``` - - name: With Parameters + - name: Call a Postgres function with arguments js: | ```js const { data, error } = await supabase @@ -967,7 +975,7 @@ pages: const { data, error } = await postgrest .rpc('echo_cities', { names: ['The Shire', 'Mordor'] }) ``` - - name: With filters + - name: Call a Postgres function with filters description: | Postgres functions that return tables can also be combined with [Modifiers](/docs/reference/javascript/using-modifiers) and @@ -979,7 +987,7 @@ pages: .select('name, population') .eq('name', 'The Shire') ``` - - name: With count option + - name: Call a Postgres function with a count option description: | You can specify a count option to get the row count along with your data. Allowed values for count option are `null`, `exact`, `planned` and `estimated`. @@ -989,20 +997,6 @@ pages: .rpc('hello_world', {}, { count: 'exact' }) ``` - privileges: - description: | - By default, functions can be executed by any role. You can restrict this by - sql: | - ```sql - ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; - ``` - Then, you can choose which roles can execute functions - sql: | - ```sql - GRANT EXECUTE ON FUNCTION hello_world TO authenticated; - GRANT EXECUTE ON FUNCTION hello_world TO service_role; - ``` - subscribe(): title: 'on().subscribe()' $ref: '@supabase/supabase-js.lib/SupabaseQueryBuilder.SupabaseQueryBuilder.on' diff --git a/spec/supabase_js_v2_legacy.yml b/spec/supabase_js_v2_legacy.yml index aeeed1d11c1..455e15f86c6 100644 --- a/spec/supabase_js_v2_legacy.yml +++ b/spec/supabase_js_v2_legacy.yml @@ -1838,10 +1838,8 @@ pages: rpc(): title: 'Postgres functions: rpc()' description: | - You can call Postgres functions as a "Remote Procedure Call". - - That's a fancy way of saying that you can put some logic into your database then call it from anywhere. - It's especially useful when the logic rarely changes - like password resets and updates. + You can call Postgres functions as _Remote Procedure Calls_, logic in your database that you can execute from anywhere. + Functions are useful when the logic rarely changes—like for password resets and updates. ```sql create or replace function hello_world() returns text as $$ @@ -1849,6 +1847,17 @@ pages: $$ language sql; ``` $ref: '@supabase/postgrest-js.PostgrestClient.rpc' + notes: | + By default, functions can be executed by any role. + You can restrict this by altering the default prvivileges and then choosing which roles can execute functions. + + ```sql + ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; + + -- Choose which roles can execute functions + GRANT EXECUTE ON FUNCTION hello_world TO authenticated; + GRANT EXECUTE ON FUNCTION hello_world TO service_role; + ``` examples: - name: Call a Postgres function without arguments description: | From a3273689e1e12929bf4d96a946ea1de38d1ccf50 Mon Sep 17 00:00:00 2001 From: dannykng Date: Tue, 4 Oct 2022 16:18:30 -0700 Subject: [PATCH 3/3] Move function priv info to db functions guide --- .../reference/docs/guides/database/functions.mdx | 16 ++++++++++++++-- spec/supabase_js_v1_legacy.yml | 11 ----------- spec/supabase_js_v2_legacy.yml | 11 ----------- 3 files changed, 14 insertions(+), 24 deletions(-) diff --git a/apps/reference/docs/guides/database/functions.mdx b/apps/reference/docs/guides/database/functions.mdx index 9e2b4e407d6..8a108157bc3 100644 --- a/apps/reference/docs/guides/database/functions.mdx +++ b/apps/reference/docs/guides/database/functions.mdx @@ -278,10 +278,10 @@ final res = await supabase ### Database Functions vs Edge Functions -For data-intensive operations we recommend using [Database Functions](../../guides/database/functions), which are executed within your database +For data-intensive operations, use Database Functions, which are executed within your database and can be called remotely using the [REST and GraphQL API](../api). -For use-cases which require low-latency we recommend [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript. +For use-cases which require low-latency, use [Edge Functions](../../guides/functions), which are globally-distributed and can be written in Typescript. ### Security `definer` vs `invoker` @@ -302,6 +302,18 @@ $$; It is best practice to use `security invoker` (which is also the default). If you ever use `security definer`, you _must_ set the `search_path`. This limits the potential damage if you allow access to schemas which the user executing the function should not have. +### Function privileges + +By default, database functions can be executed by any role. You can restrict this by altering the default privileges and then choosing which roles can execute functions. + +```sql +ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; + +-- Choose which roles can execute functions +GRANT EXECUTE ON FUNCTION hello_world TO authenticated; +GRANT EXECUTE ON FUNCTION hello_world TO service_role; +``` + ## Resources - Official Client libraries: [JavaScript](../../reference/javascript/rpc) and [Dart](../../reference/dart/rpc) diff --git a/spec/supabase_js_v1_legacy.yml b/spec/supabase_js_v1_legacy.yml index c021d01134f..75a165f10e4 100644 --- a/spec/supabase_js_v1_legacy.yml +++ b/spec/supabase_js_v1_legacy.yml @@ -943,17 +943,6 @@ pages: $$ language sql; ``` $ref: '@supabase/postgrest-js.PostgrestClient.rpc' - notes: | - By default, functions can be executed by any role. - You can restrict this by altering the default prvivileges and then choosing which roles can execute functions. - - ```sql - ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; - - -- Choose which roles can execute functions - GRANT EXECUTE ON FUNCTION hello_world TO authenticated; - GRANT EXECUTE ON FUNCTION hello_world TO service_role; - ``` examples: - name: Call a Postgres function without arguments isSpotlight: true diff --git a/spec/supabase_js_v2_legacy.yml b/spec/supabase_js_v2_legacy.yml index 455e15f86c6..3b75c261ad6 100644 --- a/spec/supabase_js_v2_legacy.yml +++ b/spec/supabase_js_v2_legacy.yml @@ -1847,17 +1847,6 @@ pages: $$ language sql; ``` $ref: '@supabase/postgrest-js.PostgrestClient.rpc' - notes: | - By default, functions can be executed by any role. - You can restrict this by altering the default prvivileges and then choosing which roles can execute functions. - - ```sql - ALTER DEFAULT PRIVILEGES REVOKE EXECUTE ON FUNCTIONS FROM PUBLIC; - - -- Choose which roles can execute functions - GRANT EXECUTE ON FUNCTION hello_world TO authenticated; - GRANT EXECUTE ON FUNCTION hello_world TO service_role; - ``` examples: - name: Call a Postgres function without arguments description: |