Files
supabase/apps
Arshdeep SinghandJeremias Menichelli e478aabb80 Clarify pg_net net schema grants (#49472)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

Yes

## What kind of change does this PR introduce?

Documentation update — adds a new "Permissions" section to the pg_net
guide.

## What is the current behavior?

The pg_net docs don't explain the default permission model for the net
schema. Customers running security reviews flag that net schema objects
(net.http_request_queue, net._http_response) are readable by
anon/authenticated via inherited PUBLIC grants, and some have run their
own REVOKE scripts to lock this down. This breaks the pg_net background
worker, since postgres (the role the worker runs as) inherits its own
access through that same PUBLIC grant.

## What is the new behavior?

Adds a "Permissions" section clarifying that the default grants are safe
as-is, net isn't exposed through the Data API, and anon/authenticated
are NOLOGIN roles with no direct database connection.

## Additional context

For background and reviewer discussion on the accuracy of this, see the
https://supabase.slack.com/archives/C02FHG9QQAF/p1787299415288589.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added permissions guidance for the `net` schema.
  * Clarified access available to `anon` and `authenticated` roles.
* Explained why these permissions do not expose request data through the
Data API or direct database connections.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
2026-08-24 17:29:48 +05:30
..
2026-08-20 20:05:35 +10:00