From dce1920ee13d5fc38beaaa1de17a23de9252fef7 Mon Sep 17 00:00:00 2001 From: GaryAustin1 <54564956+GaryAustin1@users.noreply.github.com> Date: Thu, 31 Oct 2024 14:46:46 -0500 Subject: [PATCH] Update securing-your-api.mdx to fix broken example (#30206) The example for checking additional API keys has a security flaw and bad code. It checked current_role for anon to do security, but because it is a security definer function the role will never be anon. Added to check for the role claim in the jwt. Also the table used for keys is UUID and the type from the header is text for the key. Cast it to UUID. --- apps/docs/content/guides/api/securing-your-api.mdx | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/apps/docs/content/guides/api/securing-your-api.mdx b/apps/docs/content/guides/api/securing-your-api.mdx index 6b54463d0fe..c106c2bbded 100644 --- a/apps/docs/content/guides/api/securing-your-api.mdx +++ b/apps/docs/content/guides/api/securing-your-api.mdx @@ -292,8 +292,9 @@ create function public.check_request() declare req_app_api_key text := current_setting('request.headers', true)::json->>'x-app-api-key'; is_app_api_key_registered boolean; + jwt_role text := current_setting('request.jwt.claims', true)::json->>'role'; begin - if current_role <> 'anon' then + if jwt_role <> 'anon' then -- not `anon` role, allow the request to pass return; end if; @@ -302,7 +303,7 @@ begin true into is_app_api_key_registered from private.anon_api_keys where - id = req_app_api_key + id = req_app_api_key::uuid limit 1; if is_app_api_key_registered is true then