Confirming the security boundary for supabase_admin default privileges on hosted Supabase #50264
Unanswered
cytrusai-cmd
asked this question in
Questions
Replies: 1 comment
|
If there are no docs to answer these questions then it's unlikely a team member will stumble upon this to answer these questions. I would file a ticket to Supabase support if you haven't yet |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hosted Supabase, PostgreSQL 17.6.
We removed automatic
anon/authenticatedgrants for future tables and views created bypostgresinpublic, usingALTER DEFAULT PRIVILEGES ... ON TABLES.The change was applied and verified:
service_roledefaults and function/sequence defaults were preserved.postgres; our project administrator cannot assumesupabase_admin.Default ACLs owned by the internal
supabase_adminrole still grant client privileges for future objects. The role documentation identifies it as an internal platform role, while the documented default-privilege procedure targetspostgres.Could the Supabase team confirm the intended hosted-platform boundary, ideally with a documentation reference?
publicassupabase_admin?We are seeking clarification of the supported security posture, not a way to assume or modify a managed role.
Related discussion: https://github.com/orgs/supabase/discussions/48259
All reactions