Skip to main content
File Transfer Pavan uses a multi-layered security model. Every upload is validated by the server first, protected by cryptographically secure tokens, and stored behind Supabase Row-Level Security policies. Passwords are never hashed on the client side. This guide covers the architecture, access controls, and protections you can rely on.

Security Features

Authentication

File Transfer Pavan authenticates users through Supabase Auth with email and password. Session state is managed globally by the AuthContext React context. Protected routes, including the Dashboard, Admin panel, and Profile pages, are wrapped with the AuthGuard component. If a user is not authenticated when visiting a protected route, they are redirected to the sign-in page. Once authenticated, the route renders.

Admin Access Control

The admin panel (AdminDashboard.tsx, approximately 130 KB) is reserved for users with elevated privileges. Admins can perform the following actions:
  • User management: view, edit, ban, or delete user accounts
  • File moderation: review uploaded files, quarantine suspicious items, and delete violations
  • Audit log review: inspect entries from the audit_logs table for forensic review
  • Bulk notifications: send announcements or alerts to all users or filtered subsets
Only authenticated admin users can access these features. The underlying RLS policies enforce this at the database level as well.
Never expose VITE_SUPABASE_SERVICE_KEY on the client side. This key is for server-level or admin operations only. Use it only in secure server contexts, Supabase Edge Functions, or your CI environment. Exposing it in the browser compromises your entire database.

Database Schema

The following abbreviated schema defines the core tables that enforce access control and audit behavior: uploaded_files file_collections download_history audit_logs

Next Steps