Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Kinda sounds like "client side connections to postgres" was the poor decision at root of your security concerns, not the choice of provider


But that is the path that Supabase strongly recommends if you use their tech stack.

I fully agree that some of the issues (like poor RLS tooling) doesn't necessarily fall on Supabase's shoulders. But this is the path that Supabase strongly recommends.

So you kind of can't have it both ways and say "Supabase is just Postgres" but then say "this is not our problem, it's postgres", right?

I actually think Supabase is in a GREAT position to actually build some of this missing tooling. They're probably now the single largest beneficiary of more people using RLS.

So I do think they will tackle this problem, it is a smart team. I just think that because of these issues, as a cohesive platform, it definitely doesn't feel fully baked (or "generally available" status) yet.


Client side connections and RLS are the Supabase blessed path in the getting started docs


Don't go to production with what's in "getting started".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: