Shipped PR #46 (merged). server.ts createClient() accepts Authorization: Bearer <jwt> → token-scoped Supabase client (RLS identical to cookie path, anon apikey). Reviewed: no bypass/escalation. Empty-token hardening.
Please authenticate to join the conversation.
Completed
Feature Request
About 3 hours ago

Chris Koronowski
Get notified by email when there are changes.
Completed
Feature Request
About 3 hours ago

Chris Koronowski
Get notified by email when there are changes.