💻 Coding
Supabase RLS Policy Map from Schema Inventory (No Invented Secrets)
Turn a Supabase schema inventory into an RLS policy map only. No invented secrets, JWT claims, or policy expressions beyond the inventory.
0Reviews
Prompt
Act as a Supabase Postgres security engineer who only uses a pasted schema inventory. You write an RLS policy map the inventory already supports. You do not invent secrets, JWT claims, service-role keys, or policy expressions. This is not a live Supabase deploy and not a penetration test. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Schema inventory I lock (table stubs, policy cues, role notes): [Inventory] - Supabase / Postgres version notes I lock: [Version] - Project or workspace label I may quote (or UNKNOWN): [Workspace] - Required table or policy names I may quote (or UNKNOWN): [SpecNames] - Words I must not use: [Banned] - What I must never invent (secrets, JWT claims, service-role keys, policy expressions): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: Inventory nouns, Version, Workspace, SpecNames, Lang. Forbidden: invented secrets, JWT claims, service-role keys, policy expressions. Banner: not a live Supabase deploy; not a penetration test. 2. RLS policy map table: one row per Inventory table stub or policy cue. Missing role notes write NOT IN INPUTS. Use Supabase RLS, auth.uid(), and roles language when Inventory supports it. 3. Spec name set: only names in SpecNames. Unnamed policies stay NOT IN INPUTS. Never print secret or JWT VALUES not in Inventory. 4. Version lock: print Version. Refuse Supabase features newer than Version if Version is named. 5. Refuse list: inventing secrets, inventing JWT claims, inventing service-role keys, inventing policy expressions. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Map from Inventory only. No invented secret VALUES. Teach Supabase RLS policy mapping, not a generic ACL swap. - Honor Version. No emojis.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
Inventory: table Harbor Quay berths as pasted policy cue select_own as pasted role note authenticated as pasted; table River Ops incidents as pasted policy cue insert_ops as pasted. Secret NOT IN INPUTS. JWT claim NONE. Version: Supabase Postgres 15 as pasted (do not invent unreleased vault APIs) Workspace: Harbor Quay Supabase Project as pasted SpecNames: berths as pasted; incidents as pasted. Audit UNKNOWN. Banned: guaranteed secret, JWT invent, service role invent, expression invent Never: invent secrets, invent JWT claims, invent service-role keys, invent policy expressions Format: ledger + table + specs + version + refuse + compliance Lang: English
Example Output
1. Ledger. Inventory: table Harbor Quay berths policy cue select_own role note authenticated; table River Ops incidents policy cue insert_ops. Secret NOT IN INPUTS. JWT claim NONE. Version Supabase Postgres 15. Workspace Harbor Quay Supabase Project. SpecNames berths; incidents; Audit UNKNOWN. Lang English. Banner: not a live Supabase deploy; not a penetration test. Forbidden: invented secrets, JWT claims, service-role keys, policy expressions, guaranteed secret, JWT invent, service role invent, expression invent. 2. RLS policy map. 1. Harbor Quay berths | policy select_own as pasted | role authenticated as pasted | secret NOT IN INPUTS | JWT NONE | Supabase RLS map only. 2. River Ops incidents | policy insert_ops as pasted | role NOT IN INPUTS | secret NOT IN INPUTS | JWT NONE. Service-role keys not printed. Policy expressions not invented. 3. Spec name set. berths; incidents as SpecNames. Audit UNKNOWN so write Audit NOT IN INPUTS. No secret VALUES printed. No third table invented. 4. Version lock. Supabase Postgres 15 as pasted. Unreleased vault APIs not used. Auth schema NOT IN INPUTS. 5. Refuse. Secret invent: refused. JWT invent: refused. Service-role invent: refused. Expression invent: refused. Guaranteed secret: refused. 6. Compliance. Banned hits none. Format ledger+table+specs+version+refuse+compliance. Gaps: role for River Ops incidents, Audit decision, USING clause, WITH CHECK, grants if any. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.