mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
When the `tableEditorApiAccessToggle` feature flag is enabled, project creation now appends SQL to revoke default privileges for `anon`, `authenticated`, and `service_role` on the `public` schema. This runs after the base image init script's default grants. This is temporary while we're still using a feature flag. Eventually it'll be moved into the base image. Applies to both the main project creation flow and the Vercel deploy button flow. Part of the "Secure by Default" initiative – new projects created under this flag won't automatically expose tables/functions/sequences to the Data API via default privileges. Users can still opt in at a table level. ## Notes Reusing the existing `useDataApiGrantTogglesEnabled()` flag here rather than creating a new one – it's the same feature surface area and avoids unnecessary flag proliferation. ## To test 1. **With flag enabled:** - Enable the `tableEditorApiAccessToggle` flag in PostHog for your user - Create a new project via the dashboard - Create a new table - Confirm in `/project/_/integrations/data_api/settings` that the new table is not exposed by default 2. **With flag disabled:** - Disable the flag (or use a different user without it) - Create a new project - Verify default privileges are intact and tables are accessible via the Data API as usual 3. **With RLS event trigger enabled too:** - Enable both the feature flag and the "enable RLS event trigger" checkbox during project creation - Verify both SQL statements run correctly on the new project --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Writing pages
Rough guidelines
- Try to break down your pages into smaller building blocks - components which are tightly coupled to a page can be placed within the folder
components/interfaces/xxx/...(Refer to the README.md under the components folder) - Keep to using
useStatehooks for any UI related logic, do not create MobX local stores to handle UI logic.
Template for building pages
import { NextPage } from 'next'
import { withAuth } from 'hooks/misc/withAuth'
// Import the corresponding layout based on the page
import { Layout } from 'components/layouts'
// Import the main building blocks of the page
import { ... } from 'components/interfaces/xxx'
// Import reusable UI components if needed
import { ... } from 'components/ui/xxx'
// Name your page accordingly
const Page: NextPage = () => {
return (
<Layout>
<div>Page content</div>
</Layout>
)
}
export default withAuth(Page)