Skip to content

Commit 3d1a215

Browse files
committed
feat: revoke supabase_storage_admin from postgres
Prevents Storage schema & migrations from being modified
1 parent 8510360 commit 3d1a215

File tree

2 files changed

+7
-0
lines changed

2 files changed

+7
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
-- migrate:up
2+
revoke supabase_storage_admin from postgres;
3+
revoke create on schema storage from postgres;
4+
revoke all on storage.migrations from anon, authenticated, service_role, postgres;
5+
6+
-- migrate:down

Diff for: migrations/tests/database/privs.sql

+1
Original file line numberDiff line numberDiff line change
@@ -27,3 +27,4 @@ SELECT schema_privs_are('extensions', 'service_role', array['USAGE']);
2727
-- Role memberships
2828
SELECT is_member_of('pg_read_all_data', 'postgres');
2929
SELECT is_member_of('pg_signal_backend', 'postgres');
30+
SELECT isnt_member_of('supabase_storage_admin', 'postgres');

0 commit comments

Comments
 (0)