Skip to content
Discussion options

You must be logged in to vote

Even if all requests go through your backend, enabling RLS is generally considered a defense-in-depth best practice.

Here's why:

Database-level security: RLS ensures that data access rules are enforced directly by PostgreSQL, regardless of which application or service is making the request.
Reduced risk of mistakes: If a new API endpoint, Edge Function, or future service accidentally bypasses an authorization check, RLS still prevents unauthorized access.
Safer client-side access: If you later decide to let your frontend query Supabase directly using the anonymous or authenticated keys, your existing RLS policies continue to protect your data without requiring major changes.
Centralized a…

Replies: 4 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by ammiyo
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
5 participants