mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 01:15:03 +03:00
65 lines
2.0 KiB
Plaintext
65 lines
2.0 KiB
Plaintext
import Layout from '~/layouts/DefaultGuideLayout'
|
|
|
|
export const meta = {
|
|
id: 'securing-your-api',
|
|
title: 'Securing your API',
|
|
description: 'Securing your Serverless API with Postgres Row Level Security.',
|
|
}
|
|
|
|
The Serverless APIs are designed to work with Postgres Row Level Security (RLS). If you use [Supabase Auth](/docs/guides/auth), you can restrict data based on the logged-in user.
|
|
To control access to your data, you can use [Policies](/docs/guides/auth#policies).
|
|
|
|
## Enabling Row Level Security
|
|
|
|
If you create a table through the Dashboard, RLS will be enabled by default. This is not the case, however, if you create a table or view using SQL.
|
|
To enable RLS on any table:
|
|
|
|
<Tabs
|
|
scrollable
|
|
size="small"
|
|
type="underlined"
|
|
defaultActiveId="dashboard"
|
|
>
|
|
<TabPanel id="dashboard" label="Dashboard">
|
|
|
|
1. Go to the [Authentication](https://supabase.com/dashboard/project/_/auth/users) page in the Dashboard.
|
|
2. Click on **Policies** in the sidebar.
|
|
3. Select **Enable RLS** to enable Row Level Security.
|
|
|
|
</TabPanel>
|
|
<TabPanel id="sql" label="SQL">
|
|
|
|
```sql
|
|
alter table
|
|
todos enable row level security;
|
|
```
|
|
|
|
</TabPanel>
|
|
</Tabs>
|
|
|
|
With RLS enabled, you can create Policies that allow or disallow users to access and update data. We provide a detailed guide for creating Row Level Security Policies in our [Authorization documentation](/docs/guides/auth/row-level-security).
|
|
|
|
## Safeguards towards accidental deletes and updates
|
|
|
|
By default, all projects have the [safeupdate](https://github.com/eradman/pg-safeupdate) Postgres extension enabled for API queries.
|
|
This ensures that `delete()` and `update()` requests will fail if there are no filters provided.
|
|
To confirm that safeupdate is enabled for API queries, run the following query:
|
|
|
|
```sql
|
|
select
|
|
usename,
|
|
useconfig
|
|
from pg_shadow
|
|
where usename = 'authenticator';
|
|
```
|
|
|
|
The expected value for `useconfig` should be:
|
|
|
|
```sql
|
|
['session_preload_libraries=supautils, safeupdate']
|
|
```
|
|
|
|
export const Page = ({ children }) => <Layout meta={meta} children={children} />
|
|
|
|
export default Page
|