Mobile Bearer-token API auth (server createClient)

Shipped PR #46 (merged). server.ts createClient() accepts Authorization: Bearer <jwt> → token-scoped Supabase client (RLS identical to cookie path, anon apikey). Reviewed: no bypass/escalation. Empty-token hardening.

Please authenticate to join the conversation.

Upvoters
Status

Completed

Board
💡

Feature Request

Date

About 3 hours ago

Author

Chris Koronowski

Subscribe to post

Get notified by email when there are changes.