mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 18:05:11 +03:00
Update securing-your-api.mdx to fix broken example (#30206)
The example for checking additional API keys has a security flaw and bad code. It checked current_role for anon to do security, but because it is a security definer function the role will never be anon. Added to check for the role claim in the jwt. Also the table used for keys is UUID and the type from the header is text for the key. Cast it to UUID.
This commit is contained in:
1 parent
bdce404105
commit
dce1920ee1
1 file changed
+3
-2
@@ -292,8 +292,9 @@ create function public.check_request()
|
||||
declare
|
||||
req_app_api_key text := current_setting('request.headers', true)::json->>'x-app-api-key';
|
||||
is_app_api_key_registered boolean;
|
||||
jwt_role text := current_setting('request.jwt.claims', true)::json->>'role';
|
||||
begin
|
||||
if current_role <> 'anon' then
|
||||
if jwt_role <> 'anon' then
|
||||
-- not `anon` role, allow the request to pass
|
||||
return;
|
||||
end if;
|
||||
@@ -302,7 +303,7 @@ begin
|
||||
true into is_app_api_key_registered
|
||||
from private.anon_api_keys
|
||||
where
|
||||
id = req_app_api_key
|
||||
id = req_app_api_key::uuid
|
||||
limit 1;
|
||||
|
||||
if is_app_api_key_registered is true then
|
||||
|
||||
Reference in new issue
Block a user