OU

/claim #71

Summary

  • Match schema-qualified RLS policy tables such as public.users against unqualified SQL tables like users without leaking across differently qualified schemas.
  • Apply injected RLS predicates through table aliases and nested FROM (...) SELECT subqueries.
  • Tighten RLS regression coverage for SELECT, DELETE, UPDATE, INSERT, explicit deny behavior, alias handling, subqueries, and schema mismatch handling.

Proof / Verification

This is backend RLS logic, so the demo is command-based rather than UI/video. The behavior is covered by focused regression tests and the full suite.

$ npx vitest src/rls/index.test.ts --run
✓ src/rls/index.test.ts (13 tests)
Test Files 1 passed (1)
Tests 13 passed (13)
$ npx vitest --run
Test Files 19 passed (19)
Tests 157 passed (157)
$ npx prettier --check src/rls/index.ts src/rls/index.test.ts
All matched files use Prettier code style!

I also checked coverage locally: all tests pass under coverage collection, and the touched RLS module is covered at 88.31% statements / 89.44% lines / 74.41% branches. The repo-wide branch threshold remains below the configured global threshold before/after this PR, so the focused and full test-suite proof above are the reliable verification signals for this backend-only change.

Claim

Total prize pool $250
Total paid $0
Status Pending
Submitted May 11, 2026
Last updated May 11, 2026

Contributors

IL

Ilhyun Cho

@INDICUMA

100%

Sponsors

OU

Outerbase (YC W23)

@outerbase

$250