Skip to content

Your first query

  1. Create a table. In the dashboard SQL editor (or a migration):

    create table public.todos (
    id bigint generated by default as identity primary key,
    user_id uuid not null default auth.uid(),
    title text not null,
    done boolean not null default false
    );
    create index on public.todos (user_id);
  2. Grant access and add policies. New tables have RLS switched on and no grants, so nobody can read them yet:

    grant select, insert, update, delete on public.todos to authenticated;
    create policy todos_select on public.todos for select to authenticated
    using (user_id = (select auth.uid()));
    create policy todos_insert on public.todos for insert to authenticated
    with check (user_id = (select auth.uid()));
    create policy todos_update on public.todos for update to authenticated
    using (user_id = (select auth.uid())) with check (user_id = (select auth.uid()));
    create policy todos_delete on public.todos for delete to authenticated
    using (user_id = (select auth.uid()));
  3. Sign in and query.

    await base.auth.signUp({ email: "ann@example.com", password: "a-strong-password" })
    const { data, error } = await base
    .from("todos")
    .insert({ title: "Buy milk" })
    .select()
    .single()
    const { data: todos } = await base.from("todos").select("id,title,done").eq("done", false).order("id")

Next: querying in depth and row level security.