49 lines
1.3 KiB
SQL
49 lines
1.3 KiB
SQL
-- Create storage bucket for rich text content images
|
|
insert into storage.buckets (id, name, public)
|
|
values ('event-content-images', 'event-content-images', true)
|
|
on conflict (id) do nothing;
|
|
|
|
-- Allow public read access to content images
|
|
create policy "content_images_select_public" on storage.objects
|
|
for select
|
|
using (bucket_id = 'event-content-images');
|
|
|
|
-- Allow authenticated admins to upload content images
|
|
create policy "content_images_insert_admin" on storage.objects
|
|
for insert
|
|
with check (
|
|
bucket_id = 'event-content-images'
|
|
and auth.role() = 'authenticated'
|
|
and exists (
|
|
select 1 from public.profiles p
|
|
where p.id = auth.uid()
|
|
and p.is_admin
|
|
)
|
|
);
|
|
|
|
-- Allow authenticated admins to update content images
|
|
create policy "content_images_update_admin" on storage.objects
|
|
for update
|
|
using (
|
|
bucket_id = 'event-content-images'
|
|
and auth.role() = 'authenticated'
|
|
and exists (
|
|
select 1 from public.profiles p
|
|
where p.id = auth.uid()
|
|
and p.is_admin
|
|
)
|
|
);
|
|
|
|
-- Allow authenticated admins to delete content images
|
|
create policy "content_images_delete_admin" on storage.objects
|
|
for delete
|
|
using (
|
|
bucket_id = 'event-content-images'
|
|
and auth.role() = 'authenticated'
|
|
and exists (
|
|
select 1 from public.profiles p
|
|
where p.id = auth.uid()
|
|
and p.is_admin
|
|
)
|
|
);
|