Service role
Full data access for trusted Base44 backend code that skips row-level security entirely, so it has to be handled carefully.
Also called asServiceRole.
Inside a backend function, base44.asServiceRole.entities ignores every access rule you wrote. Scary, and useful.
A real one from my old site: anyone could sign up to the newsletter, but nobody outside could read the subscriber list. Good. Except then how do you stop duplicate sign-ups? The sign-up function used the service role to check the list on the server, without ever opening it to the public.
The rules I stick to:
- Only in backend functions. It isn't available in the browser, and that's on purpose.
- Check who's calling before touching anything. That means a signed-in user with the right role, or a verified webhook signature.
- Validate input yourself, because the access rules aren't there to catch bad data any more.
- Send back only what the caller needs.
The security scan flags functions anyone can run. On a function that uses the service role, take that warning seriously.
Related:Backend function, Row-level security and Security scan.
Where I've used it: