Vovy adds a role to your account that users can't edit, locks the admin page and its data behind it, and proves a regular user is blocked.
Make me an admin and hide the admin page from everyone else
How it works
- Pick where the role lives: Vovy explains with a card why the role goes in app_metadata, which only your server can change, and never in user_metadata, which any logged-in user can edit.
- Set your account as admin: It runs a small SQL update in the Supabase SQL Editor that adds role: admin to your user's app_metadata.
- Lock admin data with policies: Vovy adds Row Level Security policies, rules the database checks on every request, that let only tokens with the admin role read admin tables.
- Guard the admin page: In Cursor it redirects non-admins away from /admin and hides admin links in the menu.
- Prove a normal user is blocked: Vovy logs in as a test user, visits /admin, and tries the data directly, then shows a card of what was blocked.
What you provide
- Your admin account email
- A test non-admin account
What you get
- An admin role users can't fake
- Admin-only database policies
- A guarded admin page
- Proof regular users are blocked
FAQ
Isn't hiding the page enough?
No. Anyone can call your database with the public key, so the database policies are what protect admin data.
Why do I need to log out and back in?
The role is stored in your login token, which refreshes on sign-in or roughly every hour.
Can I add more roles later, like editor?
Yes. The same pattern works for any role, and larger apps often move roles into their own table.
Related tasks
All tasks