docs: Data API IA (#42417)

*Summary*
- reorganize the navigation menu to highlight modules, consolidate API
security content, and move guide entries (auto-generated docs, type
generation, security topics) to the intended sections
- relocate the Data API hardening and custom claims RBAC guides into the
API subtree, updating internal references and redirects, and fixing
cross-links (including adjusting the Security reference order)
- adjust data API topic references (e.g., securing guide and role
management) to point to the new paths and ensure the helper link
ordering follows the requested layout

*Testing*
- Not run (not requested)

Change 1

<img width="1286" height="576" alt="image"
src="https://github.com/user-attachments/assets/d903e9b0-bbfc-403f-bcb9-eee540e466db"
/>

Change 2

<img width="1176" height="666" alt="image"
src="https://github.com/user-attachments/assets/82b3ea4c-b8d4-4cb9-ad90-6c39c8a1a997"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reorganized API documentation structure, consolidating REST and
GraphQL API guides under a dedicated API section.
* Moved security-related guides to API documentation paths for better
organization.
* Implemented automatic redirects for old documentation links to new
locations.
* Updated navigation menu to reflect the restructured documentation
layout.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
This commit is contained in:
authored and GitHub committed 2026-03-11 14:11:26 +01:00
1 parent 4fdab665a8
commit 973bacf783
12 files changed
+64 -56

No files matched your search

+13 -1
View File
@@ -98,6 +98,18 @@ const postgresIntegrations = [
href: '/guides/queues',
description: 'Durable Message Queues with guaranteed delivery',
},
{
title: 'Data REST API',
icon: 'rest',
href: '/guides/api',
description: 'Access your database through a RESTful API.',
},
{
title: 'GraphQL API',
icon: 'graphql',
href: '/guides/graphql',
description: 'Access your database through a GraphQL API.',
},
]
const selfHostingOptions = [
@@ -223,7 +235,7 @@ const HomePage = () => (
<div className="flex flex-col lg:grid grid-cols-12 gap-6 py-12 border-b">
<div className="col-span-4">
<h2 id="postgres-integrations" className="scroll-mt-24 m-0">
Postgres Modules
Modules
</h2>
</div>
<div className="grid col-span-8 grid-cols-12 gap-6 not-prose">
@@ -108,7 +108,13 @@ export const GLOBAL_MENU_ITEMS: GlobalMenuItems = [
},
],
[
{ label: 'Postgres Modules' },
{ label: 'Modules' },
{
label: 'Data API (REST)',
icon: 'rest',
href: '/guides/api' as `/${string}`,
level: 'api',
},
{
label: 'AI & Vectors',
icon: 'ai',
@@ -127,6 +133,12 @@ export const GLOBAL_MENU_ITEMS: GlobalMenuItems = [
href: '/guides/queues' as `/${string}`,
level: 'queues',
},
{
label: 'GraphQL API',
icon: 'graphql',
href: '/guides/graphql' as `/${string}`,
level: 'graphql',
},
],
],
},
@@ -272,21 +284,6 @@ export const GLOBAL_MENU_ITEMS: GlobalMenuItems = [
level: 'ui',
},
],
[
{ label: 'Data API' },
{
label: 'REST',
icon: 'rest',
href: '/guides/api' as `/${string}`,
level: 'api',
},
{
label: 'GraphQL',
icon: 'graphql',
href: '/guides/graphql' as `/${string}`,
level: 'graphql',
},
],
],
},
],
@@ -921,10 +918,6 @@ export const auth: NavMenuConstant = {
name: 'Column Level Security',
url: '/guides/database/postgres/column-level-security' as `/${string}`,
},
{
name: 'Custom Claims & RBAC',
url: '/guides/database/postgres/custom-claims-and-role-based-access-control-rbac' as `/${string}`,
},
],
},
],
@@ -1086,14 +1079,6 @@ export const database: NavMenuConstant = {
name: 'Column Level Security',
url: '/guides/database/postgres/column-level-security' as `/${string}`,
},
{
name: 'Hardening the Data API',
url: '/guides/database/hardening-data-api' as `/${string}`,
},
{
name: 'Custom Claims & RBAC',
url: '/guides/database/postgres/custom-claims-and-role-based-access-control-rbac' as `/${string}`,
},
{
name: 'Managing Postgres Roles',
url: '/guides/database/postgres/roles' as `/${string}`,
@@ -1471,7 +1456,7 @@ export const queues: NavMenuConstant = {
export const api: NavMenuConstant = {
icon: 'rest',
title: 'REST API',
title: 'Data REST API',
url: '/guides/api',
items: [
{ name: 'Overview', url: '/guides/api', items: [] },
@@ -1482,32 +1467,33 @@ export const api: NavMenuConstant = {
items: [],
},
{
name: 'Auto-generated Docs',
url: '/guides/api/rest/auto-generated-docs',
items: [],
},
{
name: 'Generating TypeScript Types',
url: '/guides/api/rest/generating-types',
items: [],
},
{
name: 'Generating Python Types',
url: '/guides/api/rest/generating-python-types',
items: [],
name: 'Security',
url: '/guides/api',
items: [
{ name: 'How API Keys work', url: '/guides/api/api-keys' },
{ name: 'Securing your API', url: '/guides/api/securing-your-api' },
{ name: 'Hardening the Data API', url: '/guides/api/hardening-data-api' },
{
name: 'Custom Claims & RBAC',
url: '/guides/api/custom-claims-and-role-based-access-control-rbac',
},
],
},
{
name: 'Tools',
url: '/guides/api',
items: [{ name: 'SQL to REST API Translator', url: '/guides/api/sql-to-rest' }],
items: [
{ name: 'Auto-generated Docs', url: '/guides/api/rest/auto-generated-docs' },
{ name: 'SQL to REST API Translator', url: '/guides/api/sql-to-rest' },
],
},
{
name: 'Guides',
url: '/guides/api',
items: [
{ name: 'Creating API routes', url: '/guides/api/creating-routes' },
{ name: 'How API Keys work', url: '/guides/api/api-keys' },
{ name: 'Securing your API', url: '/guides/api/securing-your-api' },
{ name: 'Generating TypeScript Types', url: '/guides/api/rest/generating-types' },
{ name: 'Generating Python Types', url: '/guides/api/rest/generating-python-types' },
{ name: 'Error Codes', url: '/guides/api/rest/postgrest-error-codes' },
],
},
@@ -2471,7 +2457,7 @@ export const security: NavMenuConstant = {
url: '/guides/deployment/shared-responsibility-model' as `/${string}`,
},
{ name: 'Row Level Security', url: '/guides/database/postgres/row-level-security' },
{ name: 'Hardening the Data API', url: '/guides/database/hardening-data-api' },
{ name: 'Hardening the Data API', url: '/guides/api/hardening-data-api' },
],
},
],
+2 -2
View File
@@ -1,7 +1,7 @@
---
id: 'api'
title: 'REST API'
description: 'Auto-generating REST API.'
title: 'Data REST API'
description: 'Auto-generating data REST API.'
sidebar_label: 'Overview'
video: 'https://www.youtube.com/v/rPAJJFdtPw0'
---
@@ -55,7 +55,7 @@ Any table **without RLS enabled** in the `public` schema will be accessible to t
## Disable the API or restrict to custom schema
If you don't use the Data API, or if you don't want to expose the `public` schema, you can either disable it entirely or change the automatically exposed schema to one of your choice. See **[Hardening the Data API](/docs/guides/database/hardening-data-api)** for instructions.
If you don't use the Data API, or if you don't want to expose the `public` schema, you can either disable it entirely or change the automatically exposed schema to one of your choice. See **[Hardening the Data API](/docs/guides/api/hardening-data-api)** for instructions.
## Enforce additional rules on each request
@@ -5,7 +5,7 @@ description: 'Managing access to your Postgres database and configuring permissi
subtitle: 'Managing access to your Postgres database and configuring permissions.'
---
Postgres manages database access permissions using the concept of roles. Generally you wouldn't use these roles for your own application - they are mostly for configuring _system access_ to your database. If you want to configure _application access_, then you should use [Row Level Security](/docs/guides/database/postgres/row-level-security) (RLS). You can also implement [Role-based Access Control](/docs/guides/database/postgres/custom-claims-and-role-based-access-control-rbac) on top of RLS.
Postgres manages database access permissions using the concept of roles. Generally you wouldn't use these roles for your own application - they are mostly for configuring _system access_ to your database. If you want to configure _application access_, then you should use [Row Level Security](/docs/guides/database/postgres/row-level-security) (RLS). You can also implement [Role-based Access Control](/docs/guides/api/custom-claims-and-role-based-access-control-rbac) on top of RLS.
## Users vs roles
@@ -28,6 +28,6 @@ Supabase and Postgres provide you with multiple ways to manage security, includi
- [Row Level Security](/docs/guides/database/postgres/row-level-security)
- [Column Level Security](/docs/guides/database/postgres/column-level-security)
- [Hardening the Data API](/docs/guides/database/hardening-data-api)
- [Hardening the Data API](/docs/guides/api/hardening-data-api)
- [Managing Postgres roles](/docs/guides/database/postgres/roles)
- [Managing secrets with Vault](/docs/guides/database/vault)
@@ -19,9 +19,9 @@ Various products at Supabase have their own hardening and configuration guides,
- [Row Level Security](/docs/guides/database/postgres/row-level-security)
- [Column Level Security](/docs/guides/database/postgres/column-level-security)
- [Hardening the Data API](/docs/guides/database/hardening-data-api)
- [Hardening the Data API](/docs/guides/api/hardening-data-api)
- [Additional security controls for the Data API](/docs/guides/api/securing-your-api)
- [Custom claims and role based access control](/docs/guides/database/postgres/custom-claims-and-role-based-access-control-rbac)
- [Custom claims and role based access control](/docs/guides/api/custom-claims-and-role-based-access-control-rbac)
- [Managing Postgres roles](/docs/guides/database/postgres/roles)
- [Managing secrets with Vault](/docs/guides/database/vault)
- [Superuser access and unsupported operations](docs/guides/database/postgres/roles-superuser)
@@ -12,7 +12,7 @@ Supabase Storage uses the same role-based access control system as any other Sup
## Create a custom role
Let's create a custom role `manager` to provide full read access to a specific bucket. For a more advanced setup, see the [RBAC Guide](/docs/guides/auth/custom-claims-and-role-based-access-control-rbac#create-auth-hook-to-apply-user-role).
Let's create a custom role `manager` to provide full read access to a specific bucket. For a more advanced setup, see the [RBAC Guide](/docs/guides/api/custom-claims-and-role-based-access-control-rbac#create-auth-hook-to-apply-user-role).
```sql
create role 'manager';
@@ -75,7 +75,7 @@ grant select, insert, update, delete on table public.your_table to anon, authent
Granting privileges allows access to your table through the Data API, so you should ensure you [enable RLS](/docs/guides/database/postgres/row-level-security) and write appropriate policies to protect your data.
For more information, see [Adjusting table-level privileges](/docs/guides/database/hardening-data-api#adjusting-table-level-privileges).
For more information, see [Adjusting table-level privileges](/docs/guides/api/hardening-data-api#adjusting-table-level-privileges).
</Admonition>
+10
View File
@@ -4,6 +4,16 @@ module.exports = [
source: '/auth/Auth',
destination: '/auth',
},
{
permanent: true,
source: '/docs/guides/database/hardening-data-api',
destination: '/docs/guides/api/hardening-data-api',
},
{
permanent: true,
source: '/docs/guides/database/postgres/custom-claims-and-role-based-access-control-rbac',
destination: '/docs/guides/api/custom-claims-and-role-based-access-control-rbac',
},
{
permanent: true,
source: '/docs/guides/platform/compute-add-ons',