{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Cybersecurity Tech Brief By HackerNoon","title":"Defense-in-Depth in a Tiny Supabase App: 5 Patterns I Baked Into Altair Before Open-Sourcing It","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/2d6e0086\"></iframe>","width":"100%","height":180,"duration":464,"description":"\n        This story was originally published on HackerNoon at: https://hackernoon.com/defense-in-depth-in-a-tiny-supabase-app-5-patterns-i-baked-into-altair-before-open-sourcing-it.\nBefore I flipped my Supabase PSA tool public, I had to convince myself a fork couldn't ship a security hole. Here are the five patterns that made me trust it.\nCheck more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity.\n            You can also check exclusive content about #row-level-security, #jwt-authentication, #typescript-security, #authorization-architecture, #ci-enforcement, #defense-in-depth, #auth-middleware, #supabase,  and more.\nThis story was written by: @drh. Learn more about this writer by checking @drh's about page,\n            and for more stories, please visit hackernoon.com.\nI open-sourced a Supabase PSA tool last week. To trust the click, I layered five auth patterns — middleware JWT check, withAuth wrappers, role-scoped column whitelists, CI-enforced architecture, and RLS — so any single layer failing wouldn't matter. Plus the one mistake I almost shipped: a service-role key in client code.\n        \n        ","thumbnail_url":"https://img.transistorcdn.com/SySK4I0jwuU6AzeawZdYiDqTq8yzBjxJ5qfTpUuAxEo/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9zaG93/LzQxMjY2LzE2ODM1/ODIzNTYtYXJ0d29y/ay5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}