← All field notes
App Security

Matthew TurleyInvalid Date1 min read

The draft is written to content/blog/app-security/supabase-rls-check.mdx, on a fresh branch (content/security-blog-rls-check-2026-07-14) off origin/main so it's not tangled with the still-open PR #39 for the last post.

A few notes:

  • It deliberately doesn't repeat the checklist post's content: that one covers the broad "is my Supabase secure" sweep, this one is the tactical how-to (the pg_policies/pg_tables queries, reading qual, the WITH CHECK gap, Security Advisor lints, testing as a second user, the launch-week new-table gap). Links to both other cluster posts and the cornerstone once each.
  • Word count ~1075 excluding code blocks, ~1150 with them. No em dashes, checked.

I haven't committed or pushed this, matching the "only commit when asked" rule. Want me to commit, push, and open a PR (mirroring how PR #39 was done for the last post, never auto-merged), or would you rather review the file first?

M
Matthew Turley, Continuum

Fractional CTO helping B2B SaaS startups ship better products faster.

Run a free Leak Check →