Pain point · Permissions & security · Causes churn
Making views respect row level security takes real heroics
3 source threads · first seen 2023-05 · last seen 2024-04
Summary
Row level security is insecure by default and it is easy to write a policy that looks valid but does not work. Views in particular are hard to get to respect it.
- Affects
- Developer building a front-end-only app on Supabase
- Switched to or considered
- Rails app on Heroku
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“And for views, you have to do some real heroics to get them to respect RBS”
“I guess my main concern is that it's hard to setup RLS correctly using SQL”
“Despite some initial pains around RLS,”