You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Supabase:超级管理员创建组织的行级安全策略配置问题排查

Supabase超级管理员组织操作策略问题修正

你的策略主要存在两个问题:

  • 缺少写入权限验证:for all覆盖所有操作,但仅用using子句只能控制读取、更新、删除时的行可见性,无法授权INSERT(创建)操作,需要补充with check子句来验证写入权限。
  • 条件写法可优化:原查询用auth.uid() in (...)逻辑可行,但直接匹配user_id = auth.uid()更直观,同时结合exists查询性能更优。

修正后的完整策略(支持所有操作)

create policy "Superadmins can do all operations on orgs" on organisations
    for all using (
        exists (
            select 1
            from organisations_members
            where user_id = auth.uid()
              and role = 'superadmin'
        )
    )
    with check (
        exists (
            select 1
            from organisations_members
            where user_id = auth.uid()
              and role = 'superadmin'
        )
    );

仅允许创建操作的精简策略

如果只需要授权超级管理员创建组织,可将范围限定为for insert:

create policy "Superadmins can create orgs" on organisations
    for insert with check (
        exists (
            select 1
            from organisations_members
            where user_id = auth.uid()
              and role = 'superadmin'
        )
    );

内容的提问来源于stack exchange,提问作者Sventies

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 07:05:08