Hello emergency #51259
kdidier1981-oss
started this conversation in
Contribute to Supabase
Hello emergency
#51259
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi, I’m looking for confirmation about the default ACLs created by the pg_net extension in Supabase.
On a staging project, after enabling pg_net and pg_cron, we observed:
schema net exists;
anon and authenticated have USAGE on schema net;
has_function_privilege(..., 'EXECUTE') returns true for multiple net.* functions for both anon and authenticated;
net and cron are NOT exposed through PostgREST; only public and graphql_public are exposed.
We intend to use pg_net only server-side from a scheduled pg_cron maintenance job.
Questions:
Are these ACLs expected defaults for pg_net?
Is it recommended/supported to revoke USAGE/EXECUTE from PUBLIC, anon, and authenticated?
Which role(s) should retain privileges for a secure server-only pg_cron → pg_net workflow?
Could extension upgrades recreate those default privileges?
We want to harden the ACLs before enabling the scheduler.
All reactions