The draft is written to content/blog/app-security/supabase-rls-check.mdx, on a fresh branch (content/security-blog-rls-check-2026-07-14) off origin/main so it's not tangled with the still-open PR #39 for the last post.
A few notes:
- It deliberately doesn't repeat the checklist post's content: that one covers the broad "is my Supabase secure" sweep, this one is the tactical how-to (the
pg_policies/pg_tablesqueries, readingqual, theWITH CHECKgap, Security Advisor lints, testing as a second user, the launch-week new-table gap). Links to both other cluster posts and the cornerstone once each. - Word count ~1075 excluding code blocks, ~1150 with them. No em dashes, checked.
I haven't committed or pushed this, matching the "only commit when asked" rule. Want me to commit, push, and open a PR (mirroring how PR #39 was done for the last post, never auto-merged), or would you rather review the file first?