How much should one trust RLS? Reading PostgREST, it looks like you could use a JWT parameter to enforce a policy - whether individual user or group based.
I really love the idea of RLS, but wonder at it's provable security properties.
I really love the idea of RLS, but wonder at it's provable security properties.