{"podcast":{"title":"Cybersecurity Tech Brief By HackerNoon","slug":"cybersecurity-tech-brief-by-hackernoon-6365646","podcast_index_feed_id":6365646,"rss_url":"https://feeds.transistor.fm/cybersecurity-tech-brief-by-hackernoon","website_url":"https://hackernoon.com/c/cybersecurity","image_url":"https://img.transistorcdn.com/FGIwueC9IDCZTR6LxgKkyddWnFNh4fbI5rAnEZblWk8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9zaG93/LzQxMjY2LzE2ODM1/ODIzNTYtYXJ0d29y/ay5qcGc.jpg","author":"HackerNoon","episode_count":100,"summary":"Learn the latest Cybersecurity updates in the tech world.","last_synced_at":"2026-07-18T18:18:14.433062+00:00","page_url":"https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646"},"episode":{"title":"Defense-in-Depth in a Tiny Supabase App: 5 Patterns I Baked Into Altair Before Open-Sourcing It","slug":"defense-in-depth-in-a-tiny-supabase-app-5-patterns-i-baked-into-altair-before-open-sourcing-it","published_at":"2026-05-11T16:01:23+00:00","page_url":"https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646/defense-in-depth-in-a-tiny-supabase-app-5-patterns-i-baked-into-altair-before-open-sourcing-it","show_page_url":"https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646","url":"https://share.transistor.fm/s/2d6e0086","audio_url":"https://media.transistor.fm/2d6e0086/0d74f2d4.mp3","summary":"This story was originally published on HackerNoon at: https://hackernoon.com/defense-in-depth-in-a-tiny-supabase-app-5-patterns-i-baked-into-altair-before-open-sourcing-it . Before I flipped my Supabase PSA tool public, I had to convince myself a fork couldn't ship a security hole. Here are the five patterns that made me trust it. Check more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity . You can also check exclusive content about #row-level-security , #jwt-authentication , #typescript-security , #authorization-architecture , #ci-enforcement , #defense-in-depth , #auth-middleware , #supabase , and more. This story was written by: @drh . Learn more about this writer by checking @drh's about page, and for more stories, please visit hackernoon.com . I open-sourced a Supabase PSA tool last week. To trust the click, I layered five auth patterns — middleware JWT check, withAuth wrappers, role-scoped column whitelists, CI-enforced architecture, and RLS — so any single layer failing wouldn't matter. Plus the one mistake I almost shipped: a service-role key in client code.","meta_description":"This story was originally published on HackerNoon at: https://hackernoon.com/defense-in-depth-in-a-tiny-supabase-app-5-patterns-i-baked-into-altair-before…","key_points":[],"chapters":[],"topics":[],"duration_seconds":464,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybersecurity-tech-brief-by-hackernoon-6365646/episodes/defense-in-depth-in-a-tiny-supabase-app-5-patterns-i-baked-into-altair-before-open-sourcing-it/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybersecurity-tech-brief-by-hackernoon-6365646/defense-in-depth-in-a-tiny-supabase-app-5-patterns-i-baked-into-altair-before-open-sourcing-it.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}