מדריכיםמפתחים

מפתחים

Security overview — נהירא לי

Posture after the authz hardening work. This folder documents what is enforced today, not a wishlist.

Layers

  1. Supabase Auth — email/password sessions via cookie SSR; getUser() on the server.
  2. Postgres RLS — tenant tables scoped to workspace membership / ownership.
  3. SECURITY DEFINER RPCs — controlled join-by-code, teacher role claim, points, notifications (see authz-and-roles.md).
  4. Next.js proxy + action guards — route role checks and requireUser / requireTeacher from profiles.role only (never user_metadata).
  5. HTTP headers + CSP — set in next.config.ts (see app-hardening.md).
  6. Private storage — Havruta media in a private bucket; short-lived signed URLs.

Secrets

  • Service role key is not used in the Next.js app (scripts / admin only).
  • AI provider keys are server-only (no NEXT_PUBLIC_ prefix).
  • Client may use NEXT_PUBLIC_SUPABASE_URL and the anon key only.

Documents in this folder

FileAudience
authz-and-roles.mdMaintainers
app-hardening.mdMaintainers
teacher-safety.mdTeachers (Hebrew)

Related code

  • Migration: src/db/security-authz-hardening-migration.sql
  • Guards: src/lib/auth/guards.ts
  • Proxy: src/proxy.ts
  • Headers: next.config.ts