import { Button, Dialog, DialogContent, DialogFooter, DialogHeader, DialogSection, DialogSectionSeparator, DialogTitle, DialogTrigger, } from 'ui' import { SimpleCodeBlock } from 'ui-patterns/SimpleCodeBlock' import { Entity } from '@/data/table-editor/table-editor-types' interface ExposedMaterializedViewDialogProps { table: Entity isExposedMaterializedViewDialogOpen: boolean setIsExposedMaterializedViewDialogOpen: (isExposedMaterializedViewDialogOpen: boolean) => void } export function ExposedMaterializedViewDialog({ table, isExposedMaterializedViewDialogOpen, setIsExposedMaterializedViewDialogOpen, }: ExposedMaterializedViewDialogProps) { return ( Materialized view exposed via Data API

Revoking select access from API roles anon and{' '} authenticated mitigates the risk of exposing sensitive data to all users.

{`REVOKE SELECT on "${table.schema}"."${table.name}" FROM public, anon, authenticated;`}

Note that this is a breaking change if you have code that depends on accessing the materialized view using the Data API. To reexpose the materialized view in a safe way, you can put a function in front of it and apply a security rule equivalent to RLS:

{`CREATE OR REPLACE FUNCTION get_${table.name}_secure() RETURNS SETOF "${table.schema}"."${table.name}" LANGUAGE sql SECURITY DEFINER SET search_path = '' AS $$ SELECT * FROM "${table.schema}"."${table.name}" WHERE user_id = (SELECT auth.uid()); $$;`}
) }