Skip to content

Search is only available in production builds. Try building and previewing the site to test it out locally.

Security

Row-level security is enabled and forced on tenant tables that ship with the server, and that is the pattern for tables you add. The default, with no policy, is deny. The service role is the only bypass.

Tokens are verified in one place. The database role does the rest. anon, authenticated, and service are the roles PostgREST will assume. A console token is not one of them.

API keys and user tokens carry ref. When the host also names a project, the two must match.

Postgres is not exposed to clients. They speak HTTP to Reactor, and to PostgREST through /data/v1.

A function process starts with a cleared environment. It receives the caller JSON and its own variables. It does not receive the server database URL or the service key unless you stored those as that function’s variables. Do not do that.

Zip entries that contain .. or start with / are rejected.

Presign checks the project prefix before it issues a URL. The signed URL expires in 300 seconds. Filesystem URLs are HMAC’d with storage.sign_secret.

POST /platform/v1/projects, migrate, and POST /fn/v1/_internal/cron require the operator token. That token is not a project key. Console routes require a console session and a membership. Rotating keys and deleting a project are limited to admin and owner.

Magic-link and recovery responses are { "ok": true } whether or not the address exists and whether or not the message was sent. Invite is the exception: it needs the service key, and it fails when email is not configured.

Challenge tokens are stored hashed. A magic link or recovery token lasts 15 minutes. An invite lasts 7 days. Repeating a send inside 60 seconds does not create another challenge.

Reactor does not write your policies for you. A table without ENABLE and FORCE ROW LEVEL SECURITY, or a policy of USING (true) granted to anon, is public. The console grid bypasses user policies on purpose. It is not a test of them.

The operator token, the service key, the JWT private key, and storage credentials are cluster secrets. They do not belong in a client or in git.