Your Supabase service role key is one NEXT_PUBLIC_ away from a full database breach
The Supabase service_role key bypasses every Row Level Security policy, so if it reaches the browser — most often via a NEXT_PUBLIC_ prefix — anyone who opens devtools can read and write every row in
guardlayer.hashnode.dev5 min read