I need to generate hmac for my users using Postgres' function on Supabase. I am running the following command to generate it at runtime when the user requests for it.
create or replace function get_hmac(message text) returns varchar
as $$
SELECT ENCODE(HMAC(message,'mykey','sha256'),'hex');
$$ language sql;
However, I am unsure if this is safe because my key ('mykey') is just sitting there exposed to anyone who has access to my sql editor. How do I go about tackling this issue?