Journal
Personal
23 Sep 2026#sec#adr#postgres#web 1 min read

Authorisation moves back into the app

Why the rewrite trades row-level security for one data-access layer and a test suite.

FromBobinarca: PCB Component Inventory

In 2025 the inventory moved its authorisation into the database (Let RLS do the filtering). The rewrite moves it back, on purpose.

With Supabase the browser queried the database directly, so a policy was the only possible fence. With a Next.js server in between, the plan sends every query through one data-access layer: it checks the session's membership and role, scopes the query to the workspace, and answers 404, not 403, for workspaces you are not in. Composite foreign keys stop cross-workspace links in the database, and a test suite against a real Postgres is the contract.

Takeaway

The fence belongs on the one path every request must take, and the tests are what make it a fence.

Related