|
|
|
|
|
by steve-chavez
126 days ago
|
|
> PostgREST translates HTTP straight into SQL, so if you get a policy wrong (or forget one), game over Do note that by default in PostgreSQL/PostgREST, RLS is the third layer of AuthZ defense, you have table and column level security before and these are closed by default. > In Supabase's model, it's a breach. Supabase is currently working on being closed by default. |
|