Skip to content
Storage

存储访问控制

Supabase 存储设计得可以与 Postgres 的 行级安全 (RLS) 完美配合。

🌐 Supabase Storage is designed to work perfectly with Postgres Row Level Security (RLS).

你可以使用 RLS 创建安全访问策略,它们非常强大和灵活,允许你根据业务需求限制访问。

🌐 You can use RLS to create Security Access Policies that are incredibly powerful and flexible, allowing you to restrict access based on your business needs.

访问政策 #

🌐 Access policies

默认情况下,Storage 不允许向没有 RLS 策略的存储桶上传任何内容。你可以通过在 storage.objects 表上创建 RLS 策略,有选择地允许某些操作。

🌐 By default Storage does not allow any uploads to buckets without RLS policies. You selectively allow certain operations by creating RLS policies on the storage.objects table.

你可以在这里找到存储架构的文档,为了简化创建策略的过程,你可以使用这些辅助函数。

🌐 You can find the documentation for the storage schema here , and to simplify the process of crafting your policies, you can use these helper functions .

如果你需要针对不同的存储操作(例如列出对象和读取认证对象)使用不同的 SELECT 策略,可以使用 存储辅助函数 中文档说明的操作感知助手 storage.allow_only_operation() 和 storage.allow_any_operation()。

🌐 If you need different SELECT policies for different Storage actions, such as listing objects versus reading authenticated objects, use the operation-aware helpers storage.allow_only_operation() and storage.allow_any_operation() documented in Storage Helper Functions.

例如,上传 对象所需的唯一 RLS 策略是向 storage.objects 表授予 INSERT 权限。

🌐 For example, the only RLS policy required for uploading objects is to grant the INSERT permission to the storage.objects table.

要使用 upsert 功能覆盖文件,你还需要额外授予 SELECT 和 UPDATE 权限。

🌐 To allow overwriting files using the upsert functionality you will need to additionally grant SELECT and UPDATE permissions.

政策示例 #

🌐 Policy examples

一个简单的入门方法是为 SELECT、INSERT、UPDATE、DELETE 操作创建 RLS 策略,并限制这些策略以满足你的安全需求。例如,可以从以下 INSERT 策略开始:

🌐 An easy way to get started would be to create RLS policies for SELECT, INSERT, UPDATE, DELETE operations and restrict the policies to meet your security requirements. For example, one can start with the following INSERT policy:

1
create policy "policy_name"
2
ON storage.objects
3
for insert with check (
4
true
5
);

并将其修改为只允许经过身份验证的用户向特定存储桶上传资源,方法是将其更改为:

🌐 and modify it to only allow authenticated users to upload assets to a specific bucket by changing it to:

1
create policy "policy_name"
2
on storage.objects for insert to authenticated with check (
3
-- restrict bucket
4
bucket_id = 'my_bucket_id'
5
);

这个例子演示了如何允许经过身份验证的用户将文件上传到 my_bucket_id 里的 private 文件夹:

🌐 This example demonstrates how you would allow authenticated users to upload files to a folder called private inside my_bucket_id:

1
create policy "Allow authenticated uploads"
2
on storage.objects
3
for insert
4
to authenticated
5
with check (
6
bucket_id = 'my_bucket_id' and
7
(storage.foldername(name))[1] = 'private'
8
);

这个例子演示了如何允许认证用户将文件上传到名为他们的 users.id 的文件夹内的 my_bucket_id:

🌐 This example demonstrates how you would allow authenticated users to upload files to a folder called with their users.id inside my_bucket_id:

1
create policy "Allow authenticated uploads"
2
on storage.objects
3
for insert
4
to authenticated
5
with check (
6
bucket_id = 'my_bucket_id' and
7
(storage.foldername(name))[1] = (select auth.jwt()->>'sub')
8
);

允许用户访问之前自己上传的文件:

🌐 Allow a user to access a file that was previously uploaded by the same user:

1
create policy "Individual user Access"
2
on storage.objects for select
3
to authenticated
4
using ( (select auth.jwt()->>'sub') = owner_id );

允许任何人通过可发布密钥访问 avatars 存储桶中的对象。这里 allow_any_operation() 过滤器很关键,因为没有它,用户将能够列出存储桶的内容。

🌐 Allow anyone to access objects in the avatars bucket via publishable key. The allow_any_operation() filter is critical here as without it users would be able to list the bucket contents.

1
create policy "Avatar images are publicly accessible." on storage.objects
2
for select using (bucket_id = 'avatars' and storage.allow_any_operation(array['object.get_authenticated_info', 'object.get_authenticated']));

绕过访问控制 #

🌐 Bypassing access controls

如果你只使用来自可信客户端的存储,比如你自己的服务器,并且需要绕过 RLS 策略,你可以在 Authorization 头中使用 service key。服务密钥可以完全绕过 RLS 策略,让你无限制地访问所有存储 API。

🌐 If you exclusively use Storage from trusted clients, such as your own servers, and need to bypass the RLS policies, you can use the service key in the Authorization header. Service keys entirely bypass RLS policies, granting you unrestricted access to all Storage APIs.

记得你不应该公开分享服务密钥。

🌐 Remember you should not share the service key publicly.