© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabase•4y ago•
7 replies
thoughtvoyage

Create function for RLS that cannot be called by users

I've created some utility functions that I use in my RLS and they seem to work but some of them could be abused by users to learn about other users. How do I ensure that an authenticated user cannot just call one of these functions on their own? I basically want to restrict the functions to only being called by the backend itself to check the details of a user.
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

Cannot create public.users
SupabaseSSupabase / help-and-questions
3y ago
RLS that a table can only be modified by a certain postgres function
SupabaseSSupabase / help-and-questions
3y ago
Cannot create new users — auth.users.id default missing and cannot be altered
SupabaseSSupabase / help-and-questions
4mo ago
Select RLS for admins and users
SupabaseSSupabase / help-and-questions
5mo ago