Access Control Demo
Full-stack security portfolio
Application security architecture
Security should hold at every boundary.
A deliberately small learning-management application built to demonstrate layered authentication, authorization, resource ownership, and database-level access control.
Request lifecycle
Independent enforcement across four boundaries
- 0101
Invite gate
Controls access to the hosted portfolio environment.
- 0202
Authentication
Supabase Auth establishes the signed-in application user.
- 0303
Authorization
Server handlers enforce roles and resource ownership.
- 0404
Database policy
PostgreSQL RLS independently enforces data access.
Private demo access
Enter the application
Use the invite code supplied with the portfolio link. This gate only opens the hosted demo; authentication and application roles remain separate.
Invite codes are verified server-side using a secure cryptographic check without storing the original codes.
Request lifecycle
Independent enforcement across four boundaries
- 0101
Invite gate
Controls access to the hosted portfolio environment.
- 0202
Authentication
Supabase Auth establishes the signed-in application user.
- 0303
Authorization
Server handlers enforce roles and resource ownership.
- 0404
Database policy
PostgreSQL RLS independently enforces data access.