Production-Ready Rule
•
supabase/**/*.{sql,ts}, lib/supabase/**/*.{ts,tsx}
Supabase & Postgres Row Level Security .cursorrules (.mdc)
Security-focused .cursorrules and .cursor/rules/*.mdc guidelines for Supabase. Mandate Row Level Security (RLS) policies, prevent key leaks, and enforce typed queries.
.cursor/rules/supabase.mdc
---
description: Supabase database security, Row Level Security (RLS), and typed SDK standards
globs: supabase/**/*.{sql,ts}, lib/supabase/**/*.{ts,tsx}
alwaysApply: false
---
# Supabase & Database Security Standards
## Row Level Security (RLS) Discipline
- Every new public schema table MUST explicitly enable RLS:
`ALTER TABLE table_name ENABLE ROW LEVEL SECURITY;`
- Always define explicit policies for `SELECT`, `INSERT`, `UPDATE`, and `DELETE`.
- Avoid `USING (true)` unless public read access is explicitly intentional.
## SDK & Key Management
- NEVER import or reference `SUPABASE_SERVICE_ROLE_KEY` inside client-side components.
- Always use the typed Supabase client generated from `supabase gen types typescript`.
⭐
Using this rule in your open-source project? Reference in your README:
https://cursor.pacebowl.com/rules/supabase.html
Frequently Asked Questions & Implementation Notes
How do these rules protect against RLS oversights?
The rules strictly forbid creating tables without 'ALTER TABLE
How do they prevent exposing the service_role key?
The AI is forbidden from using SUPABASE_SERVICE_ROLE_KEY in client components or browser bundles, strictly reserving it for trusted backend microservices.