mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 18:05:11 +03:00
Updates our documentation pages around the Data API to include instructions on how to grant the necessary privileges across API roles across tables and functions. Current behaviour means this is largely unnecessary as privileges are granted by default on public schema, but adding instructions will help cover scenarios where this isn't the case and expose some of the underlying magic happening. ## To test: - These updates refer to new settings that are added to the data api that give more visibility and control over what tables and functions are accessible via the api. - To view these settings you'll need enable `tableEditorApiAccessToggle ` feature flag <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new "Data API" guide and removed the old "Hardening the Data API" page * Updated navigation links to surface the new Data API guide * Expanded quickstarts, SDK install pages, and security guides with step‑by‑step Data API exposure, default‑privileges, RLS guidance, and SQL GRANT examples (including function EXECUTE notes) * Updated troubleshooting references and added redirects for legacy documentation paths <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com> Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com> Co-authored-by: SaxonF <1072756+SaxonF@users.noreply.github.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
121 lines
3.1 KiB
Plaintext
121 lines
3.1 KiB
Plaintext
---
|
|
id: installing
|
|
title: 'Installing'
|
|
slug: installing
|
|
custom_edit_url: https://github.com/supabase/supabase/edit/master/web/spec/supabase.yml
|
|
---
|
|
|
|
### Install as package
|
|
|
|
<RefSubLayout.EducationRow>
|
|
<RefSubLayout.Details>
|
|
|
|
You can install @supabase/supabase-js via the terminal.
|
|
|
|
</RefSubLayout.Details>
|
|
|
|
<RefSubLayout.Examples>
|
|
|
|
<Tabs
|
|
size="small"
|
|
type="underlined"
|
|
defaultActiveId="npm"
|
|
queryGroup="platform"
|
|
>
|
|
<TabPanel id="npm" label="npm">
|
|
|
|
```sh Terminal
|
|
npm install @supabase/supabase-js
|
|
```
|
|
|
|
</TabPanel>
|
|
<TabPanel id="yarn" label="Yarn">
|
|
|
|
```sh Terminal
|
|
yarn add @supabase/supabase-js
|
|
```
|
|
|
|
</TabPanel>
|
|
<TabPanel id="pnpm" label="pnpm">
|
|
|
|
```sh Terminal
|
|
pnpm add @supabase/supabase-js
|
|
```
|
|
|
|
</TabPanel>
|
|
</Tabs>
|
|
|
|
</RefSubLayout.Examples>
|
|
</RefSubLayout.EducationRow>
|
|
|
|
### Install via CDN
|
|
|
|
<RefSubLayout.EducationRow>
|
|
<RefSubLayout.Details>
|
|
|
|
You can install @supabase/supabase-js via CDN links.
|
|
|
|
</RefSubLayout.Details>
|
|
|
|
<RefSubLayout.Examples>
|
|
|
|
```js
|
|
<script src="https://cdn.jsdelivr.net/npm/@supabase/supabase-js@2"></script>
|
|
//or
|
|
<script src="https://unpkg.com/@supabase/supabase-js@2"></script>
|
|
```
|
|
|
|
</RefSubLayout.Examples>
|
|
</RefSubLayout.EducationRow>
|
|
|
|
### Use at runtime in Deno
|
|
|
|
<RefSubLayout.EducationRow>
|
|
<RefSubLayout.Details>
|
|
|
|
You can use supabase-js in the Deno runtime via [JSR](https://jsr.io/@supabase/supabase-js):
|
|
|
|
</RefSubLayout.Details>
|
|
|
|
<RefSubLayout.Examples>
|
|
|
|
```ts
|
|
import { createClient } from 'npm:@supabase/supabase-js@2'
|
|
```
|
|
|
|
</RefSubLayout.Examples>
|
|
</RefSubLayout.EducationRow>
|
|
|
|
### Enable Data API access
|
|
|
|
<RefSubLayout.EducationRow>
|
|
<RefSubLayout.Details>
|
|
|
|
supabase-js uses the Data API to query and mutate your Postgres data. You first need to grant Data API roles permissions to access your tables and functions.
|
|
|
|
In [Data API integrations settings](/dashboard/project/_/integrations/data_api/settings), expose the specific tables and functions you want to access. To automatically grant access for new tables and functions in `public`, enable **Default privileges for new entities**.
|
|
|
|
Alternatively, use SQL to grant the required permissions:
|
|
|
|
</RefSubLayout.Details>
|
|
|
|
<RefSubLayout.Examples>
|
|
|
|
```sql
|
|
-- Before granting access to client roles, make sure RLS is enabled
|
|
-- and create the policies required for each role's allowed operations.
|
|
alter table public.your_table enable row level security;
|
|
-- create policy ... on public.your_table ...;
|
|
|
|
-- Grant least-privilege access to tables after RLS and policies are in place
|
|
grant select on public.your_table to anon;
|
|
grant select, insert, update, delete on public.your_table to authenticated;
|
|
grant all on public.your_table to service_role;
|
|
|
|
-- Grant execute on functions after verifying any table access they rely on
|
|
grant execute on function public.your_function to authenticated, service_role;
|
|
```
|
|
|
|
</RefSubLayout.Examples>
|
|
</RefSubLayout.EducationRow>
|