$npx -y skills add butterbase-ai/butterbase-skills --skill journey-rlsUse as the RLS build stage of the Butterbase journey, after journey-schema. Implements the RLS section of 02-plan.md by delegating to debug-rls policy patterns (for proactive creation, not debugging). Calls manage_rls (create_user_isolation, enable, create_policy). Folded into jo
| 1 | # Journey: RLS |
| 2 | |
| 3 | Stage 3b of the guided journey. Install Row-Level Security policies for user-owned tables. |
| 4 | |
| 5 | ## When to use |
| 6 | |
| 7 | - Dispatched by `journey` when `current_stage: rls`. |
| 8 | - Directly via `/butterbase-skills:journey-rls`. |
| 9 | - Folded into `journey-schema` when `hackathon_mode: true` (do not run separately). |
| 10 | |
| 11 | ## Preflight |
| 12 | |
| 13 | If `docs/butterbase/03-preflight.md` is missing, older than 24 hours, or `00-state.md` has `app_id: null`, invoke `butterbase-skills:journey-preflight` first. Wait for it to return successfully before proceeding. |
| 14 | |
| 15 | ## Inputs |
| 16 | |
| 17 | - `docs/butterbase/02-plan.md` — the RLS section. |
| 18 | - `docs/butterbase/00-state.md` — for `app_id`. |
| 19 | |
| 20 | ## Procedure |
| 21 | |
| 22 | 0. **Refresh docs.** Call `butterbase_docs` with `topic: "auth"`. For RLS-specific patterns, also WebFetch `https://docs.butterbase.ai/auth/rls`. Skip if cache is fresh. |
| 23 | |
| 24 | 1. Read the RLS section of `02-plan.md`. Print it back: `"About to install RLS policies: <list>. Proceed?"`. Wait for `yes`. |
| 25 | 2. Invoke `butterbase-skills:debug-rls` via the Skill tool with mode `proactive`, passing the RLS plan and `app_id`. For each user-isolation entry, the wrapped skill calls `manage_rls action: create_user_isolation`. For custom policies, `manage_rls action: enable` then `action: create_policy`. |
| 26 | 3. After it returns, sanity-check with `manage_rls action: list` and show the user. |
| 27 | 4. Append one line to `docs/butterbase/04-build-log.md`: |
| 28 | `<ISO timestamp> rls manage_rls ok` |
| 29 | 5. Tick `- [x] rls` in `00-state.md`, set `current_stage:` to the next unchecked stage, bump `last_updated`. |
| 30 | 6. Return to `journey` orchestrator (or ask `"Continue to the next stage? (yes/no)"`). |
| 31 | |
| 32 | ## Outputs |
| 33 | |
| 34 | - Live RLS policies in the Butterbase app. |
| 35 | - One line in `04-build-log.md`. |
| 36 | |
| 37 | ## Anti-patterns |
| 38 | |
| 39 | - ❌ Skipping `manage_rls action: list` verification — invisible policy failures are the #1 RLS gotcha. |
| 40 | - ❌ Creating policies on a table where RLS is not enabled — `enable` must come first. |