Group membership model

See how default, member, and admin groups in Supabase gate CSV export, operator tools, and plan feature flags without hard-coding emails.

Home desk with laptop, external monitor, and keyboard in a living space
Household members check the same dashboard from wherever they already work. Photo: David Wellbeloved / Flickr. CC BY 2.0

Users belong to one or more groups stored in Supabase: typically default registered users, paying members with CSV access, and admins who review contact submissions. Server routes check group membership before unlocking CSV export or admin dashboard tools rather than scattering email allowlists in code.

User account linked to member and admin group nodes with feature flags
Supabase group rows determine CSV export, billing features, and admin route access.

Common groups

  • default: signed-in feeds and history browsing.
  • member: active Stripe subscription for CSV.
  • admin: user lookup and contact review.

Enforcement points

Check groups in Astro middleware and API handlers: middleware patterns. Webhooks add member group on successful checkout; cancellations remove it. Never trust client-side group claims.

Auth foundation

Registration flow in Supabase auth assigns default group. Session cookies carry JWT claims read during session lifecycle.

FAQ

What is the difference between editor and view-only?
Editors can change devices, alerts, and sharing. View-only members watch live data and history without changing household configuration.