Database / Supabase Intermediate to Advanced Interview Questions
What is the difference between a SECURITY DEFINER and a SECURITY INVOKER Postgres function?
A SECURITY INVOKER function (the default) runs with the privileges of the role that calls it, so any Row Level Security policies on tables it touches still apply exactly as if the caller ran the query directly. A SECURITY DEFINER function instead runs with the privileges of the role that created it, regardless of who calls it.
| SECURITY INVOKER | SECURITY DEFINER |
| Runs as the calling role | Runs as the function's owner |
| RLS applies normally | Can bypass RLS if owner has that privilege |
This makes DEFINER functions useful for controlled privilege escalation — letting an authenticated user trigger an action (like inserting an audit log row) that their own RLS policy wouldn't otherwise permit — but they need careful review since a bug in one effectively grants elevated access to anyone who can call it.
Invest now in Acorns!!! 🚀
Join Acorns and get your $5 bonus!
Acorns is a micro-investing app that automatically invests your "spare change" from daily purchases into diversified, expert-built portfolios of ETFs. It is designed for beginners, allowing you to start investing with as little as $5. The service automates saving and investing. Disclosure: I may receive a referral bonus.
Invest now!!! Get Free equity stock (US, UK only)!
Use Robinhood app to invest in stocks. It is safe and secure. Use the Referral link to claim your free stock when you sign up!.
The Robinhood app makes it easy to trade stocks, crypto and more.
Webull! Receive free stock by signing up using the link: Webull signup.
More Related questions...
