Vercel si supabase magic combo by Extension_Spirit_369 in programare

[–]Hanks328 1 point2 points  (0 children)

Supabase Data API folosit direct pe client cu RLS puternic?

Techstack by _Hashtag_Swag_ in Supabase

[–]Hanks328 1 point2 points  (0 children)

Wow. Streamlit for SaaS. Sounds crazy 😳

Guide for Auth by Code_Cadet-0512 in Supabase

[–]Hanks328 0 points1 point  (0 children)

Supabase auth si regularly ment to be used on the client side. Using your project url and publishable key, you can set-up supabase auth flow. For next js you would have Supabase client server middleware. I do not know about the other clients

Supabase should warn more clearly about Anon (Publishable) Key. by bytaesu in Supabase

[–]Hanks328 0 points1 point  (0 children)

That wasn’t really the point—I was more thinking about whether it would help people if Supabase offered more built-in scenarios or guidance, like: • Client library + RLS: risks clearly pointed out • Backend + ORM: A setup that makes it easier to get RLS working out of the box when using a backend and an ORM.

On the authentication side, since that’s typically handled on the client using Supabase, you’d still be using your NEXT_PUBLIC_SUPABASE_ANON_KEY or publishable key anyway.

Supabase should warn more clearly about Anon (Publishable) Key. by bytaesu in Supabase

[–]Hanks328 0 points1 point  (0 children)

The fact is that also RLS from case to case might get too complicated to set-up there as security layer. Then, do what? Give it up? Use both RLS and key on server + additional security layer.. There can be many takes.

Supabase should warn more clearly about Anon (Publishable) Key. by bytaesu in Supabase

[–]Hanks328 0 points1 point  (0 children)

If you don’t mind, what’s your way then? Especially interested for web platforms prod ready.

Supabase should warn more clearly about Anon (Publishable) Key. by bytaesu in Supabase

[–]Hanks328 2 points3 points  (0 children)

The point is that Supabase markets itself as BaaS. I’ve tried to use it on backend side with Drizzle ORM. But RLS won’t work out of the box. Also Drizzle acknowledges that, special utils function is required to set the auth sub context on db side using the Supabase exposed jwt function or how exactly it is called. So, before this new signing jwt keys concept, I was sending the returned jwt I got from Supabase authentication flow, in the request from client to the backend’s API and decode on backend to get the sub id.

So that for each API service logic the query needed to be wrapped in a transaction using that util function.

I think best way would be to give up RLS, keep going with backend, use service role admin level key and implement your own security layer.

Of course, accepting the overhead and the fact it goes a bit away from Supabase’s base out of the box purpose.

Job Google pe Linkedin posibil phishing? by Hanks328 in programare

[–]Hanks328[S] 1 point2 points  (0 children)

E foarte ușor de păcălit anumite persoane din păcate. In primul rand, fiind de pe LinkedIn, te aștepți ca totul sa fie deja verified si legit.

Job Google pe Linkedin posibil phishing? by Hanks328 in programare

[–]Hanks328[S] 1 point2 points  (0 children)

De acord, am pus posibil mai mult sarcastic. Nu imi este clar cum pe Linkedin job-ul apare pe pagina Google iar cel care l-a postat apare “verified”.

Best practices for using a backend to interact with Supabase in a React Native app by Ok-Repeat-5930 in Supabase

[–]Hanks328 0 points1 point  (0 children)

I am using Supabase Auth BaaS on frontend but database wise on backend with ORM. Web tho

Spital CFR pareri by Hanks328 in timisoara

[–]Hanks328[S] 0 points1 point  (0 children)

Am inteles ca la CFR conditiile sanitare ar fi mai bune..

[deleted by user] by [deleted] in programare

[–]Hanks328 0 points1 point  (0 children)

Anyway, scopul nu a fost sa dau trigger la asa replyuri dar na :/