Treat the new child-linked table as a security change. In its creation migration enable RLS and add policies that derive access from `current_setting('app.current_user_id')`; verify the application role cannot bypass the policy. Add indexes needed by policy predicates. Before every read/write, call the centralized `ChildrenService.validateChildAccess(childId, userId)` and expose the resource under `/children/:childId/...`, not a root ID route. Add the entity security JSDoc and document the ta...
Installs into .claude/skills of the current project.
Are you the author of Nestjs Security Isolation?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-nestjs-security-isolation-df0474ed)
Treat the new child-linked table as a security change. In its creation migration enable RLS and add policies that derive access from `current_setting('app.current_user_id')`; verify the application role cannot bypass the policy. Add indexes needed by policy predicates.
Before every read/write, call the centralized `ChildrenService.validateChildAccess(childId, userId)` and expose the resource under `/children/:childId/...`, not a root ID route. Add the entity security JSDoc and document the table/policy in `SECURITY.md`. Add negative tests for another tenant, direct-ID access, and missing context; map results to DTOs without leaking internal metadata.