Application security architecture

Security should hold at every boundary.

A deliberately small learning-management application built to demonstrate layered authentication, authorization, resource ownership, and database-level access control.

Gate 01

Private demo access

Enter the application

Use the invite code supplied with the portfolio link. This gate only opens the hosted demo; authentication and application roles remain separate.

Required
Invite only

Don't have a valid invite? Request access

Invite codes are verified server-side using a secure cryptographic check without storing the original codes.

Request lifecycle

Independent enforcement across four boundaries

  1. 01

    Invite gate

    Controls access to the hosted portfolio environment.

    01
  2. 02

    Authentication

    Supabase Auth establishes the signed-in application user.

    02
  3. 03

    Authorization

    Server handlers enforce roles and resource ownership.

    03
  4. 04

    Database policy

    PostgreSQL RLS independently enforces data access.

    04
Version 2.7.3