Repository navigation
Commit 776ee2b
Grant table privileges to the API roles in the initial migration
RLS policies only filter rows on top of table-level privileges —
Postgres checks the table ACL first and rejects with 42501 before RLS
is ever consulted. Supabase's stock default privileges normally paper
over this by auto-granting DML to the API roles, but that's a database
setting that can be hardened away, and then every query from the app
dies at the gate.
authenticated gets SELECT/UPDATE/DELETE on users (inserts happen via
the SECURITY DEFINER trigger on auth.users) and full DML on devices;
service_role gets full DML on both (it bypasses RLS, not the ACL).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>1 parent 61bb0a9 commit 776ee2b
1 file changed
Lines changed: 23 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
104 | 104 | | |
105 | 105 | | |
106 | 106 | | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
107 | 130 | | |
108 | 131 | | |
109 | 132 | | |
| |||
0 commit comments