3 min read
Permissions belong in the database
Gudi has four roles and two client applications. Putting the access rules in Postgres row-level security instead of the clients removed an entire category of bug — and one naming convention did most of the work.