Database / Supabase Intermediate to Advanced Interview Questions
Why should you avoid embedding sensitive business data directly inside JWT claims?
A JWT's payload is only signed, not encrypted, meaning anyone holding the token — including the end user themselves, since it's stored client-side — can decode and read every claim inside it without ever contacting Supabase's servers.
Putting something like a user's exact salary, an internal risk score, or another user's private data into a claim effectively hands it to the client in plain sight, even if your UI never displays it. Claims are best limited to identifiers and flags that are safe to expose (a role name, an organization ID, a subscription tier), while anything genuinely sensitive should stay server-side and be fetched through an authorized query when actually needed.
Invest now in Acorns!!! 🚀
Join Acorns and get your $5 bonus!
Acorns is a micro-investing app that automatically invests your "spare change" from daily purchases into diversified, expert-built portfolios of ETFs. It is designed for beginners, allowing you to start investing with as little as $5. The service automates saving and investing. Disclosure: I may receive a referral bonus.
Invest now!!! Get Free equity stock (US, UK only)!
Use Robinhood app to invest in stocks. It is safe and secure. Use the Referral link to claim your free stock when you sign up!.
The Robinhood app makes it easy to trade stocks, crypto and more.
Webull! Receive free stock by signing up using the link: Webull signup.
More Related questions...
