CASE FILE · 2026
Evidence Atlas — Security architecture
Case study of the previous version of this website, which included a private workspace: how I separated it from the public site using server-side authorisation, row-level security (RLS) and publication snapshots without private data.
EVIDENCE RECORD
What I built and what it proves.
- My role
- Threat modelling and design of boundaries for identity, private data, publication, rendering and system operations.
- Outcome
- The browser never chooses which account or workspace it can access, public pages only read approved snapshots, and these boundaries are covered by unit and E2E tests in CI.
- Validation
- Unit tests for repository access, publication and sanitisation; E2E tests for caching, indexing and the public surface; lint, type checks and builds in CI.
- Tools
- Next.js · TypeScript · Supabase · PostgreSQL · Vitest
Project stages
- 01
Threat model
What needed protection: sessions, private notes, professional material and technical evidence. From whom: anonymous visitors, bots, the owner and an attacker with a compromised session or provider.
- 02
Attack surface
Boundaries between the browser and server, Studio (the private editing workspace) and the database, working data and public snapshots, and the website and caches or search engines. Parameters, Markdown, links and metadata are treated as untrusted input.
- 03
Invariants
Rules that must hold: all private access is authorised on the server and enforced with row-level security (RLS); the browser never decides which account or workspace it can access; public pages only display allowed fields from published snapshots.
- 04
Controls
Owner allowlist with two-factor authentication, deny-by-default row-level security, immutable publication snapshots, explicitly defined public fields, content sanitisation, Markdown without active HTML, CSP and a server-only admin key.
- 05
Verification
CI runs formatting, lint, type checks, tests, builds and public journeys in Chromium and on mobile; Dependabot checks dependencies.
- 06
Residual risk
These controls reduce exposure but cannot guarantee absolute security: compromised sessions or providers and operational mistakes remain risks that require ongoing validation.
Sources
Documented from the repository's code and documentation and, where available, the published site.
- Source
- Private repository
- Status
- Architecture analysis