Module
Module 3 of 6Lesson 2 of 2~26 min

Row Level Security: everyone's own data, proven with two accounts

Lesson 2 of the module "Store the data and protect access to it" in the course "Add a database, authentication and payments to your app".

Lesson objective

By the end of this lesson, you will be able to specify and have written the Row Level Security rules for your tables (read, create, update, delete), add a plan limit to them, then prove with two test accounts that one user can neither read nor change another's data, even when the interface is bypassed.

Where it fits

Store the data and protect access to it

How do I have the agent create tables, and guarantee that everyone only sees their own data?

Lessons in this module

  1. Have the agent create your tables, then check them
  2. Row Level Security: everyone's own data, proven with two accounts (this lesson)

What you will learn in the course

This lesson is part of the course Add a database, authentication and payments to your app

  • Decide what stays in the browser and what must move to the server, and choose a back-end platform that fits your app, your budget and your data.
  • Manage environment variables and secrets (public VITE_ variables, secret keys on the server only, .env files kept out of Git, rotation after a leak).
  • Have the agent design a data model and its migrations, then check that data is actually stored and linked to the right user.
  • Write, have written and test Row Level Security rules that guarantee each user only accesses their own data and that plan limits are enforced in the database.
  • Add sign-up, sign-in, sign-out and password reset, and verify the flows, email confirmation and redirect URLs.
  • Integrate Stripe Checkout in test mode (product, price, session created on the server, test cards) without exposing the secret key.
  • Hold payment status on the server with signed, deduplicated Stripe webhooks, tested with the Stripe CLI or the Dashboard.
  • Apply GDPR basics (information, account deletion, processors) and a go-live checklist before taking real payments.