1
0 Comments

PostgreSQL Row-Level Security caught bugs my AI-written code missed

Hey! Quick update on Nokos.

When you have AI writing all your code (Claude Code writes everything for Nokos), authorization bugs are inevitable. A missing WHERE user_id = ... somewhere, and one user sees another's data.

My safety net: PostgreSQL Row-Level Security (RLS). The database enforces "users can only see their own data" on every query — even if the application code forgets.

It already caught a real bug: an async embedding update ran outside our auth transaction. Without RLS, the query would have "worked" with no authorization check. With RLS, it silently matched zero rows. Bug showed up in monitoring, fixed in 5 minutes.

The key setting: FORCE ROW LEVEL SECURITY — applies policies even to the table owner (which is what most ORMs connect as). Default deny. If code skips the auth wrapper, it gets nothing instead of leaking data.

If you're building multi-tenant SaaS — especially with AI writing your queries — this is the cheapest security layer you can add.

Full breakdown:
https://dev.to/tomokiikeda/postgresql-row-level-security-saved-my-saas-from-bugs-i-didnt-know-i-had-1bb5

Anyone else using RLS? Did it catch anything unexpected?

posted toAvatar for product Nokos
Nokos