supabase / splinter

Supabase Postgres Linter
https://supabase.github.io/splinter/
68 stars 6 forks source link

Lint for RLS referencing user_metadata #53

Closed olirice closed 2 months ago

olirice commented 2 months ago

What kind of change does this PR introduce?

Lints for RLS policies that reference Supabase Auth user_metadata

user_metadata is manipulatable by end-users and not appropriate in a security context