Files
supabase/apps
GaryAustin1 dce1920ee1 Update securing-your-api.mdx to fix broken example (#30206)
The example for checking additional API keys has a security flaw and bad code.

It checked current_role for anon to do security, but because it is a security definer function the role will never be anon.

Added to check for the role claim in the jwt.

Also the table used for keys is UUID and the type from the header is text for the key.  Cast it to UUID.
2024-10-31 15:46:46 -04:00
..
2024-10-31 13:58:47 +08:00