diff --git a/apps/docs/content/guides/api/securing-your-api.mdx b/apps/docs/content/guides/api/securing-your-api.mdx index 6b54463d0fe..c106c2bbded 100644 --- a/apps/docs/content/guides/api/securing-your-api.mdx +++ b/apps/docs/content/guides/api/securing-your-api.mdx @@ -292,8 +292,9 @@ create function public.check_request() declare req_app_api_key text := current_setting('request.headers', true)::json->>'x-app-api-key'; is_app_api_key_registered boolean; + jwt_role text := current_setting('request.jwt.claims', true)::json->>'role'; begin - if current_role <> 'anon' then + if jwt_role <> 'anon' then -- not `anon` role, allow the request to pass return; end if; @@ -302,7 +303,7 @@ begin true into is_app_api_key_registered from private.anon_api_keys where - id = req_app_api_key + id = req_app_api_key::uuid limit 1; if is_app_api_key_registered is true then