Code & Dev Compatible: claude

Supabase Row Level Security Policy Set

Complexity Level: Expert
Prompt Code Block

Design Row Level Security for a Supabase Postgres project so a user cannot read or write another tenant's rows, including through joins. APP Product: [PRODUCT] Tenancy: [USER OWNS ROWS | ORG WITH MEMBERS | BOTH] Tables (name, important columns, who should read, who should write): [PASTE SCHEMA OR LIST] Roles in auth.jwt(): [LIST — e.g. authenticated, plus org role claim] Service role paths that must bypass RLS: [WEBHOOKS | MIGRATIONS | NONE] Storage buckets involved: [BUCKETS OR NONE] DELIVER 1) Threat list: 8 concrete leaks (select via a foreign key, insert with someone else's org_id, update a role column, storage object URL guessing, RPC defined as security definer, realtime subscription). Mark which your policies close. 2) SQL for each table: - ENABLE ROW LEVEL SECURITY - separate policies for SELECT, INSERT, UPDATE, DELETE - WITH CHECK on writes, not only USING - helper SQL function is_org_member(org_id) as security invoker, with why you chose invoker vs definer 3) A policy that blocks users from changing their own role or org_id. 4) Tests as SQL: for user A and user B, the select/insert that must succeed and the one that must return zero rows or error. Use set request.jwt.claim.sub. 5) A note on views, security_barrier, and any table you intentionally leave without RLS — those need a comment that says why. 6) Storage policies if buckets were listed, matching the same tenancy key. Do not suggest disabling RLS for "just the admin UI." Admins go through a checked claim or a server route with the service role, and you will show that route's authorization check in pseudocode. Assume the anon key is public.

🌟 Example Output / Preview

### Generated Component Preview: ```typescript // Fully validated modern structure import { z } from 'zod'; export const RequestSchema = z.object({ id: z.string().uuid(), createdAt: z.date().default(() => new Date()), data: z.record(z.string(), z.any()) }); export type ValidatedRequest = z.infer<typeof RequestSchema>; ```

Prompt Metadata

DifficultyExpert
Compatibilityclaude

Primary Use Cases:

  • •Legacy code modernization & technical refactoring
  • •Full-stack layout generation & component structuring
  • •CI/CD workflow automation & unit/E2E testing suites

Associated Tags:

#supabase #postgres #rls #auth

💡 Pro Tips & Advice

1. Use bracketed items: Be sure to fill out all [PLACEHOLDER] elements with specific details before sending the prompt to the AI model.

2. Adjust temperature: For creative tasks, set AI temperature higher (e.g., 0.8), or lower (e.g., 0.2) for strict coding/technical tasks.

🔗 Related AI Prompts

Code & Dev
★ Featured

Full SaaS Landing Page Build Spec (SEO + Conversion)

You are a Staff Product Designer + Frontend Engineer + SEO strategist. Build a complete, production-ready marketing landing page f...

Compatible:claudeDiff:Advanced
#landing-page #saas #seo #nextjs #tailwind
Code & Dev
★ Featured 🔥 Trending

SaaS Analytics Dashboard Full Build Spec

You are a Principal Product Designer + Frontend Lead. Design and specify a complete [LIGHT | DARK] analytics dashboard for [PRODUC...

Compatible:claudeDiff:Intermediate
#dashboard #saas #ui #tailwind #seo
Code & Dev

SaaS Admin Panel Dashboard Build Spec

Design a full internal Admin Dashboard for [PRODUCT_NAME] used by [ADMIN_ROLE: support | ops | super-admin]. --- 🎯 CONTEXT Adm...

Compatible:claudeDiff:Intermediate
#admin #dashboard #saas #crud #tailwind