Goal
Design Supabase Storage usage that is secure, maintainable, and aligned with data ownership rules.
When to Use
- Files or objects are part of a Supabase feature.
- Bucket boundaries and access patterns are unclear.
- Uploads or downloads cross trust boundaries.
Instructions
- Define stored object types, ownership, and lifecycle.
- Choose bucket layout and metadata strategy.
- Define upload, read, and delete access patterns.
- Clarify where signed URLs, processing, and privileged operations happen.
Constraints
- Do not trust client-supplied metadata blindly.
- Do not place privileged storage operations in untrusted contexts.
- Keep storage rules aligned with the auth model.
Output Format
- storage model
- bucket and metadata plan
- access strategy
- security notes
Examples
- "Design Supabase Storage for user-uploaded reports."
- "How should signed downloads work for private files?"