4 ms·
PostgREST seems super cool. I'm curious so know if anyone here is using it in production, for a commercial project?
by joss82 5y ago
PostgREST seems super cool.
I'm curious so know if anyone here is using it in production, for a commercial project?
- kiwicopple 5y agoPostgREST is used inside every Supabase project. We have >50K projects now[0], some of them making (tens of) millions of API requests through PostgREST daily. It's a fantastic piece of tech, especially when coupled with PostgreSQL Row Level Security. We have some benchmarks here in case you're concerned about performance: https://github.com/supabase/benchmarks/issues/2 https://github.com/supabase/benchmarks/issues/2 [0] hosted platform. We don't add telemetry to self-hosting
- joss82 5y agoThanks, it's good to know! I was not concerned about performance at all. Actually, Postgresql's performance is one of its strong points to me (up to a point when scaling up). I guess there is a point where it all breaks down but I didn't reach it yet.
- smoe 5y agoSorry to hijack the thread a bit, but yesterday I watched a supabase tutorial on row level security and I'm very intrigued to try out more. But what I couldn't figure on quick search is, what the best practices are in order to know what the current users permissions are before hitting a permission denied. E.g to show/hide certain actions in the frontend. Do I have to duplicate the logic somewhere else or am I missing something to get them from Postgres/Supabase easily?
- kiwicopple 5y agoI see what you mean - yes these rules would live separately from RLS. However we are also about to add this functionality to the Supabase Dashboard, and we will open source our solution to every Supabase project. (We will come on with a very general RBAC/ABCA solution)