I don't expose SQL to the client because my client apps don't have good SQL support, my database server doesn't scale connections well and it would take effort to properly lock down the SQL permissions.
That said, there are uses cases where this might be a good pattern - e.g. limited distribution internal tooling.
Direct access to SQL is a great example of something that is not an antipattern. It's just one approach of many, with strengths and weaknesses.
In my use-case adding new features and support is the majority of eng work. We find Hasura is valuable here in reducing the cost of doing so - especially compared to traditional REST implementations.