From b1c6b8cd49e45f5ea90823bda0ef047809046e75 Mon Sep 17 00:00:00 2001 From: Stojan Dimitrovski Date: Thu, 19 Jan 2023 18:25:26 +0100 Subject: [PATCH] docs: add callout against using non-pks as fk references --- apps/docs/pages/guides/auth/managing-user-data.mdx | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/apps/docs/pages/guides/auth/managing-user-data.mdx b/apps/docs/pages/guides/auth/managing-user-data.mdx index 8d6e414eb05..fad99897e32 100644 --- a/apps/docs/pages/guides/auth/managing-user-data.mdx +++ b/apps/docs/pages/guides/auth/managing-user-data.mdx @@ -34,6 +34,14 @@ Make sure to specify the `on delete cascade` clause when referencing `auth.users + + +Only use primary keys as [foreign key references](https://www.postgresql.org/docs/current/tutorial-fk.html) to schemas and tables like `auth.users` which are managed by Supabase. + +PostgreSQL lets you specify a foreign key reference to columns which are backed by a unique index (not necessarily primary keys). Be aware that **primary keys are guaranteed not to change.** Columns, indices, constraints or other database objects managed by Supabase **may change at any time** and you should be careful when referencing them directly. + + + ## Deleting Users You may delete users directly or via the management console at Authentication > Users. Note that deleting a user from the `auth.users` table does not automatically sign out a user. As Supabase makes use of JSON Web Tokens (JWT), a user's JWT will remain "valid" until it has expired. Should you wish to immediately revoke access for a user, do considering making use of a Row Level Security policy as described below.