c/backend › command
0votes

Cursor rules for Supabase

Template
submitted by u/client to c/backend · 0 copies

A .cursor/rules/supabase.mdc covering row-level security, migrations, auth and safe client usage.

Template · 1 variable
---
description: Supabase conventions
globs: ["supabase/**","src/**/*.ts","app/**/*.ts"]
alwaysApply: false
---

# Supabase

- Every table: `enable row level security` plus explicit policies in the same migration. Use `(select auth.uid())` in policies.
- Schema changes only through migrations in `supabase/migrations` (`supabase migration new <name>`); never edit the remote database by hand.
- The anon key is public; the service-role key is server-only and never logged or sent to the browser.
- Security definer functions set `search_path = ''` and are revoked from anon/authenticated unless meant to be called.
- Index every foreign key and every column used in filters or sorting.
- Generate types with `supabase gen types typescript` after schema changes.

## When you change code
- Follow the patterns in the nearest existing file before inventing new ones.
- Add or update a test for behavior changes; run `{{test_command}}`.
- Keep diffs small; explain anything surprising in your reply.
0 commentsreport

How to use this command

  1. Fill in the blanks. Type your details into the boxes above. This command has 1 blank:
    • {{test_command}} Test command
  2. Copy itwith the Copy button. Your answers are filled in automatically. Use “copy raw” to keep the blanks for later.
  3. Paste it into Cursor, Claude, ChatGPT or Codex and send it.
  4. Tip: This produces a file or document. Save the filled-in result in your project (for example as CLAUDE.md or AGENTS.md) so you can reuse it.
  5. Careful: this one is marked medium risk. Review what the AI suggests before you run it on real systems or data.

More from c/backend

See all of c/backend →
0 comments

Log in to join the discussion.