Supabase Backend as a Service · บทเรียน

บทนำสู่นโยบาย RLS

ทำความเข้าใจพื้นฐานของการรักษาความปลอดภัยระดับแถว ประโยชน์ของแนวทางนี้ และความแตกต่างจากการกำหนดสิทธิ์ระดับแอปพลิเคชันแบบดั้งเดิม

บทเรียน 1 จาก 311 ขั้นตอน

บทนำสู่นโยบาย RLS เป็นบทเรียน Supabase Backend as a Service ฟรีบน CoddyKit นี่คือบทเรียนที่ 1 จากทั้งหมด 3 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Supabase Backend as a Service และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Supabase Backend as a Service มีบทเรียนทั้งหมด 3 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

What is Row-Level Security?

Welcome to the world of Row-Level Security (RLS)! RLS is a powerful database feature that allows you to control which individual rows a user can access in a table.

Think of it as a bouncer for each row in your database, deciding who gets to see or interact with it based on rules you define. This is essential for building secure applications where different users need different data views.

App-Level vs. Database-Level Auth

Traditionally, applications filter data after it's retrieved from the database. This means all data is fetched, then your app decides what to show a user.

With Row-Level Security (RLS), the filtering happens directly within the database. The database itself decides which rows a user can even see or modify, before sending them to your application.

The RLS Advantage: Deeper Security

Imagine an app where users can only see their own posts. Without RLS, a bug in your application's filtering logic could accidentally expose another user's private data.

RLS prevents this by enforcing access rules at the lowest level – the database itself. Even if your application layer has a flaw, the database won't send unauthorized data, providing a critical layer of defense.

How RLS Works (Concept)

When RLS is enabled on a table, every query to that table is automatically checked against defined policies. These policies are like security guards that inspect each row.

If a row doesn't meet the policy's conditions for the current user, it's simply not returned. This applies to SELECT, INSERT, UPDATE, and DELETE operations, ensuring consistent access control.

Activating RLS in Supabase

Before you can define RLS policies, you must enable RLS on the specific table you want to protect. This is done with a simple SQL command.

Let's say you have a posts table. You'd enable RLS like this:

ALTER TABLE posts ENABLE ROW LEVEL SECURITY;

Important: Once RLS is enabled, no one can access the table until you create a policy that explicitly allows it!

ALTER TABLE posts ENABLE ROW LEVEL SECURITY;

What are RLS Policies?

An RLS policy is a set of rules that determine what actions a user can perform on specific rows within a table. You define these policies using SQL.

  • Roles: Specify which database roles the policy applies to (e.g., 'authenticated', 'anon').
  • Operations: Define what type of database operation it affects (SELECT, INSERT, UPDATE, DELETE, or ALL).
  • Conditions: Set the criteria a row must meet (e.g., user_id = auth.uid()).

A Simple RLS Policy Example

Here's an example of a policy that allows authenticated users to only view rows in the posts table where their user ID matches the author_id of the post.

CREATE POLICY "Users can view their own posts" ON posts FOR SELECT TO authenticated USING (auth.uid() = author_id);

auth.uid() is a special Supabase function that returns the ID of the current authenticated user.

CREATE POLICY "Users can view their own posts" ON posts
FOR SELECT
TO authenticated
USING (auth.uid() = author_id);

Key Advantages of RLS

Row-Level Security offers several compelling benefits for your applications:

  • Enhanced Security: Prevents unauthorized data access directly at the database level.
  • Simplified Application Logic: Reduces the need for complex, repetitive filtering code in your app.
  • Consistent Enforcement: Rules apply uniformly across all queries, regardless of the client or tool.
  • Auditability: Easier to review and manage access rules in one centralized place (the database).

RLS vs. Database Views

While database views can limit column access, RLS is designed for dynamic row-level filtering based on the current user's context. They serve different purposes:

  • Views: Predefined subsets of data, useful for simplifying complex queries or limiting column visibility. They don't change based on who is querying.
  • RLS: Filters rows dynamically based on who is querying, what their role is, or other real-time conditions. It's about 'who can see which row' and acts as a security layer.

RLS offers a much more robust and flexible solution for user-specific data access security.

Check Your Understanding

Test your knowledge on the core concept of Row-Level Security.

RLS: Your Database's Bouncer

In this lesson, we introduced Row-Level Security (RLS) and understood its core purpose: providing granular, database-level access control.

You learned that RLS filters data at the source, unlike application-level filtering, and how to enable it on a table. We also touched upon creating basic policies and the significant security and architectural benefits RLS brings.

Next, we'll dive deeper into implementing more complex RLS rules and conditions!

เริ่มต้นได้ฟรี

เรียนรู้ Supabase Backend as a Service ด้วย AI tutor — ฟรี

เขียนและเรียกใช้โค้ดจริงในเบราว์เซอร์ของคุณ รับความช่วยเหลือทันทีจาก AI tutor 24/7 และเรียนรู้ต่อจากที่คุณหยุดบนเว็บหรือในแอป

คอร์ส
11
บทเรียน
40

คำถามที่พบบ่อย

บทเรียน “บทนำสู่นโยบาย RLS” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “บทนำสู่นโยบาย RLS” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Supabase Backend as a Service ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Supabase Backend as a Service มีบทเรียนทั้งหมด 3 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “บทนำสู่นโยบาย RLS”

ทำความเข้าใจพื้นฐานของการรักษาความปลอดภัยระดับแถว ประโยชน์ของแนวทางนี้ และความแตกต่างจากการกำหนดสิทธิ์ระดับแอปพลิเคชันแบบดั้งเดิม คุณปฏิบัติ Supabase Backend as a Service ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Supabase Backend as a Service หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Supabase Backend as a Service บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 1 จากทั้งหมด 3 บทเรียน

บทเรียน “บทนำสู่นโยบาย RLS” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Supabase Backend as a Service นี้ได้ไหม

ได้ บทเรียน Supabase Backend as a Service ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. บทนำสู่นโยบาย RLS
  2. การทดสอบและการแก้จุดบกพร่องของ RLS
  3. การควบคุมการเข้าถึงตามบทบาทด้วย RLS และข้ออ้างสิทธิ์แบบกำหนดเอง
← กลับไปที่ Supabase Backend as a Service