Friction

Pain point · Permissions & security · Causes churn

Making views respect row level security takes real heroics

3 source threads · first seen 2023-05 · last seen 2024-04

Summary

Row level security is insecure by default and it is easy to write a policy that looks valid but does not work. Views in particular are hard to get to respect it.

Affects
Developer building a front-end-only app on Supabase
Switched to or considered
Rails app on Heroku

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“And for views, you have to do some real heroics to get them to respect RBS”

“I guess my main concern is that it's hard to setup RLS correctly using SQL”

“Despite some initial pains around RLS,”

Report this item