Explore EFDS
EFDS / SecurityImperial College London

Security & access.

This page gives users and reviewers a plain-language view of the current EFDS authentication, authorization, database, and hosting boundaries.

Authentication

Identity and access are separate

Members sign in through Supabase Auth with a verified email address and password or a secure email link. Google sign-in is available when the society has configured its OAuth provider. EFDS makes a separate server-side authorization decision from the authenticated identity and EFDS profile.

EFDS member
    ↓
Email or Google identity
    ↓
Supabase Auth
    ↓
EFDS Next.js application on Vercel
    ↓
Supabase PostgreSQL

Non-Imperial addresses require an approved EFDS access exception. Authentication never bypasses the same authorization boundary.

Authorization

Authentication is not privileged access

EFDS supports the hierarchy:

viewer → EFDS member → EFDS student → committee → admin

Eligible new accounts start as EFDS members. EFDS student access requires verification of enrolment on Imperial’s BSc Economics, Finance and Data Science. EFDS Union society membership alone does not grant it.

  • Access is checked server-side after authentication.
  • Imperial domains are checked case-insensitively; unauthorized domains require an approved exception.
  • Inactive profiles can be denied.
  • Private committee/admin knowledge is not public.
  • The browser does not supply a trusted role or authorization decision.
Database security

Supabase PostgreSQL with RLS

The EFDS backend uses Supabase PostgreSQL. The backend migration enables Row Level Security on profiles, access exceptions, officers, knowledge and operational tables, and uses role-aware policies. The Next.js server authorization layer applies the same separation before private reads.

Public content is kept separate from private records. The site does not publish RLS policy SQL, internal identifiers, database connection details, or secrets on this page.

Provider permissions

Sign-in identity only

Google sign-in requests the basic OpenID Connect identity scopes needed by Supabase Auth: openid, email and profile. It does not request Google Drive, Gmail or Calendar permissions. Website sign-in does not use Microsoft Graph.

Application information

For an ICT or security review

Application name
EFDS Society
Purpose
Authentication and member access for the Economics, Finance & Data Science Society website.
Authentication
Supabase email and password or secure email link; Google OAuth when configured.
Production URL
https://www.imperial-efds.com
Identity data
Authenticated user ID, email, confirmation state, and available name metadata used to link an EFDS profile.
Hosting
Vercel / Next.js application.
Database and auth
Supabase Auth and Supabase PostgreSQL.
Organisation
Economics, Finance & Data Science Society, Imperial College London.
Secrets

Server-side boundaries

Supabase service-role credentials, database credentials, and any OAuth client secrets are server-side configuration. They are not exposed through browser code or public NEXT_PUBLIC_* variables. This page intentionally does not display credentials or internal IDs.

Reporting

Please tell us about a concern

To report a suspected security issue, unsafe disclosure, access problem, or privacy concern, use the current contact route. EFDS does not claim to operate a formal bug bounty.