DIEGO URBANEJA

CASE FILE · 2026

Evidence Atlas — Security architecture

Case study of the previous version of this website, which included a private workspace: how I separated it from the public site using server-side authorisation, row-level security (RLS) and publication snapshots without private data.

EVIDENCE RECORD

What I built and what it proves.

My role
Threat modelling and design of boundaries for identity, private data, publication, rendering and system operations.
Outcome
The browser never chooses which account or workspace it can access, public pages only read approved snapshots, and these boundaries are covered by unit and E2E tests in CI.
Validation
Unit tests for repository access, publication and sanitisation; E2E tests for caching, indexing and the public surface; lint, type checks and builds in CI.
Tools
Next.js · TypeScript · Supabase · PostgreSQL · Vitest

Project stages

  1. 01

    Threat model

    What needed protection: sessions, private notes, professional material and technical evidence. From whom: anonymous visitors, bots, the owner and an attacker with a compromised session or provider.

  2. 02

    Attack surface

    Boundaries between the browser and server, Studio (the private editing workspace) and the database, working data and public snapshots, and the website and caches or search engines. Parameters, Markdown, links and metadata are treated as untrusted input.

  3. 03

    Invariants

    Rules that must hold: all private access is authorised on the server and enforced with row-level security (RLS); the browser never decides which account or workspace it can access; public pages only display allowed fields from published snapshots.

  4. 04

    Controls

    Owner allowlist with two-factor authentication, deny-by-default row-level security, immutable publication snapshots, explicitly defined public fields, content sanitisation, Markdown without active HTML, CSP and a server-only admin key.

  5. 05

    Verification

    CI runs formatting, lint, type checks, tests, builds and public journeys in Chromium and on mobile; Dependabot checks dependencies.

  6. 06

    Residual risk

    These controls reduce exposure but cannot guarantee absolute security: compromised sessions or providers and operational mistakes remain risks that require ongoing validation.

View all projects →

Sources

Documented from the repository's code and documentation and, where available, the published site.

Source
Private repository
Status
Architecture analysis