Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Server Reads

ASecurity

The browser reads the database only through server functions. A read checks its arguments, verifies the caller with `requireReader`, applies who may see the rows itself, and is registered with `readOnly`. Applies whenever adding or changing something the browser reads, or a table the browser follows live.

5 stars
0 votes
0 copies
0 views
Added 9/28/2026
databasesgodatabase

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add lxsmnsyc/overwander --skill server-reads --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Server Reads?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Server Reads
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lxsmnsyc-server-reads/badge)](https://www.skillsdirectory.com/skills/lxsmnsyc-server-reads)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: server-reads
description: The browser reads the database only through server functions. A read checks its arguments, verifies the caller with `requireReader`, applies who may see the rows itself, and is registered with `readOnly`. Applies whenever adding or changing something the browser reads, or a table the browser follows live.
---

# Reads go through the server

Nothing in the browser talks to the database. Every read is a `'use server'` function in `src/auth/`, calling a read in `src/server/` over the owner connection. There are no row policies behind it, so the function is the only thing that decides what a player may see.

## The shape

```ts
export async function listTrades(uid: string): Promise<[string, TradeRecord][]> {
  // ...
  for (const row of await listTradesOnServer(await getIdToken(), uid)) {
  // ...
}

async function listTradesOnServer(token: string, player: string): Promise<Record<string, unknown>[]> {
  'use server';
  check(TOKEN, token);
  check(UID, player);
  const uid = await requireReader(token);

  return player === uid ? readTradeRows(uid) : [];
}
readOnly(listTradesOnServer);
```

## The rules

- **`requireReader`, not `requireUid`.** A read moves nothing, so it skips the pace bucket's write, the ban and the switches. `requireUid` is for writes.
- **Decide visibility in the function.** A row only its owner may see is read for the uid the token names. When the browser passes a uid, another player's answers empty. A row every signed-in player may see is read for any uid.
- **Register it with `readOnly(fn)`** on the line after the function. Every server call marks the kept bag stale, and a registered read does not.
- **Batch in the browser** with `batchedQuery`, and read the batch with one query on the server (see `batched-queries`). A batched id list is checked with `ID_BATCH` or `UID_BATCH`.

## Following a table live

`watchRow` and `watchTable` in `src/auth/watch.ts` read once, then again whenever the live feed says the table changed. A table the browser follows needs two things:

- the `live_changes` trigger, added in a migration under `db/migrations`;
- an entry in `src/server/live/rules.ts` saying who may read its rows whole. A follower who may not gets the row's keys and reads again through the server.

`test/live-feed.test.ts` fails when the two lists disagree.

Attribution

lxsmnsyclxsmnsyc
View sourceMore from lxsmnsyc →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Mysql Best Practices

MySQL development best practices for schema design, query optimization, and database administration

2481 votes

Jpa Patterns

Spring Boot中的JPA/Hibernate实体设计、关系、查询优化、事务、审计、索引、分页和连接池模式。

2456590 votes

Clickhouse Io

ClickHouse数据库模式、查询优化、分析和数据工程最佳实践,适用于高性能分析工作负载。

2456590 votes

Postgres Patterns

基于Supabase最佳实践的PostgreSQL数据库模式,用于查询优化、架构设计、索引和安全。

2456590 votes

Sql Optimization Patterns

Diagnose slow SQL with query plans, preserve query results, and verify indexing or query changes against representative data.

458250 votes
View all in databases →