Gestion des accès avec des politiques
Mettre en œuvre un contrôle d’accès précis pour vos fichiers à l’aide des politiques de stockage Supabase, afin de garantir la sécurité des données.
Gestion des accès avec des politiques est une leçon Supabase Backend as a Service gratuite sur CoddyKit. Ceci est la leçon 2 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage Supabase Backend as a Service, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours Supabase Backend as a Service comprend 4 leçons au total.
Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.
Intro to Storage Policies
Welcome! In this lesson, we'll dive into Supabase Storage Policies. These policies are your key to controlling who can access, upload, or delete files in your buckets.
Think of them as security guards for your cloud files, ensuring only authorized actions happen.
Why Storage Security Matters
Without proper policies, your files could be vulnerable. Anyone could potentially upload malicious content, or sensitive user data might be publicly exposed.
- Prevent unauthorized access: Keep private files secure.
- Control uploads: Ensure only legitimate users can add files.
- Manage deletions: Prevent accidental or malicious file removal.
Policies are essential for building secure applications.
Enabling RLS for Buckets
Just like with database tables, Supabase Storage uses Row-Level Security (RLS) for buckets. Before you can apply any policies, RLS must be enabled for your storage bucket.
You can do this in the Supabase dashboard under 'Storage' by clicking on a bucket and toggling 'Enable RLS', or directly with SQL:
ALTER TABLE storage.buckets
ENABLE ROW LEVEL SECURITY;Understanding Policy Syntax
Storage policies are written using SQL, similar to database RLS. They specify what actions are allowed (SELECT, INSERT, UPDATE, DELETE) and under what conditions.
Key parts of a policy:
- CREATE POLICY: Starts the policy definition.
- ON storage.objects: Specifies the table policies apply to.
- FOR [action]: Defines the operation (SELECT, INSERT, UPDATE, DELETE).
- USING / WITH CHECK: Sets the conditions for the policy.
Policy: Public Read Access
Let's create a policy to allow anyone to read files from a specific bucket, for example, a 'public-images' bucket. This is common for assets like profile pictures or product images.
The auth.role() = 'anon' part means unauthenticated users, and auth.role() = 'authenticated' means logged-in users. We'll allow both here.
CREATE POLICY "Allow public read access"
ON storage.objects FOR SELECT
TO public
USING (bucket_id = 'public-images');Policy: Authenticated User Uploads
Now, let's create a policy that allows only authenticated users to upload files to a 'user-uploads' bucket. Crucially, we want them to only upload into a folder named after their own user ID.
We use auth.uid() to get the current user's ID and path_tokens[1] to check the first part of the file path.
CREATE POLICY "Allow authenticated user upload"
ON storage.objects FOR INSERT
TO authenticated
WITH CHECK (bucket_id = 'user-uploads' AND auth.uid()::text = path_tokens[1]);Policy: Authenticated User Read Their Own
To complement the upload policy, let's ensure authenticated users can *only* read files that they themselves own within the 'user-uploads' bucket.
This policy uses auth.uid() to match the owner of the file (which is stored in the owner column of storage.objects) and also checks the file path.
CREATE POLICY "Allow authenticated user read their own"
ON storage.objects FOR SELECT
TO authenticated
USING (bucket_id = 'user-uploads' AND auth.uid() = owner);The storage.objects Table
Storage policies operate on the hidden storage.objects table. This table stores metadata about every file in your buckets. Understanding its columns is vital for writing effective policies.
- id: Unique identifier for the object.
- bucket_id: The ID of the bucket the object belongs to.
- name: The full path and filename.
- owner: The
auth.uid()of the user who uploaded the file. - path_tokens: An array of strings representing the path segments.
Policy: Admin-Only Delete
Sometimes, only specific users (like administrators) should be able to delete files. Let's create a policy that allows deletion only if the user has a specific role, for example, an 'admin' role.
This requires a custom function to check user roles, or you can simplify by checking a specific `owner` UID if only one admin account exists.
CREATE POLICY "Allow admins to delete"
ON storage.objects FOR DELETE
TO authenticated
USING (bucket_id = 'sensitive-data' AND auth.jwt() ->> 'user_role' = 'admin');Testing Policies Effectively
After creating policies, it's crucial to test them thoroughly. You can do this by:
- Logging in as different users: Test with authenticated users, unauthenticated users, and users with different roles.
- Attempting forbidden actions: Try to upload, read, or delete files that your policies should prevent.
- Using the Supabase client: Make API calls with
supabase-jsor other client libraries and observe the responses (e.g., expecting 403 Forbidden errors).
Always verify your policies work as intended before deploying to production.
Quick Policy Check
You've learned how to create various Storage policies. Which of the following conditions would allow an authenticated user to insert a file into a bucket named 'private-docs' ONLY if the file is placed in a folder matching their user ID?
Recap: Storage Policies
Great job! You've learned how to secure your Supabase Storage with policies. We covered:
- The importance of RLS for storage buckets.
- Creating policies for various actions (read, insert, delete).
- Using
auth.uid()andpath_tokensfor granular control. - Understanding the
storage.objectstable.
Implementing strong storage policies is crucial for the security and integrity of your application's file management.
Apprends Supabase Backend as a Service avec un tuteur IA — gratuit
Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.
- Cours
- 11
- Leçons
- 40
Questions Fréquemment Posées
La leçon « Gestion des accès avec des politiques » est-elle gratuite ?
Oui — le texte complet de « Gestion des accès avec des politiques » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours Supabase Backend as a Service, passe à CoddyKit PRO. Le cours Supabase Backend as a Service comprend 4 leçons au total.
Qu'est-ce que j'apprendrai dans « Gestion des accès avec des politiques » ?
Mettre en œuvre un contrôle d’accès précis pour vos fichiers à l’aide des politiques de stockage Supabase, afin de garantir la sécurité des données. Tu pratiques Supabase Backend as a Service avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.
Dois-je avoir de l'expérience pour commencer Supabase Backend as a Service ?
Aucune expérience préalable n'est requise. Supabase Backend as a Service sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 2 sur 4.
Combien de temps prend la leçon « Gestion des accès avec des politiques » ?
La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.
Peux-tu écrire et exécuter du code dans cette leçon Supabase Backend as a Service ?
Oui. Chaque leçon Supabase Backend as a Service inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.
Toutes les leçons de ce cours
- Stockage de fichiers dans les compartiments Supabase
- Gestion des accès avec des politiques
- Téléversement et récupération de contenus multimédias
- Transformations d’images et URL signées