Journal
Personal
27 Nov 2025#sec#db#supabase#postgres 1 min read

Let RLS do the filtering

Moving authorisation from the client into the database, and the code that disappeared.

FromBobinarca: PCB Component Inventory
Update, Sep 2026

The Next.js rewrite moves authorisation back into the application, for reasons in Authorisation moves back into the app.

Every query in the app filtered by the current user's id on the client. Supabase row-level security already did that on the server, so the client filters were both redundant and a false sense of safety.

They were removed, the policies became the only authorisation, and a friendly message replaced the raw denial for non-admin users. The commit is mostly deletions.

Takeaway

Authorisation belongs where the data is, and a client that cannot be trusted should not be the one deciding what it sees.