Identity and access are separate
Members sign in through Supabase Auth with a verified email address and password or a secure email link. Google sign-in is available when the society has configured its OAuth provider. EFDS makes a separate server-side authorization decision from the authenticated identity and EFDS profile.
EFDS member
↓
Email or Google identity
↓
Supabase Auth
↓
EFDS Next.js application on Vercel
↓
Supabase PostgreSQLNon-Imperial addresses require an approved EFDS access exception. Authentication never bypasses the same authorization boundary.
Authentication is not privileged access
EFDS supports the hierarchy:
viewer → EFDS member → EFDS student → committee → admin
Eligible new accounts start as EFDS members. EFDS student access requires verification of enrolment on Imperial’s BSc Economics, Finance and Data Science. EFDS Union society membership alone does not grant it.
- Access is checked server-side after authentication.
- Imperial domains are checked case-insensitively; unauthorized domains require an approved exception.
- Inactive profiles can be denied.
- Private committee/admin knowledge is not public.
- The browser does not supply a trusted role or authorization decision.
Supabase PostgreSQL with RLS
The EFDS backend uses Supabase PostgreSQL. The backend migration enables Row Level Security on profiles, access exceptions, officers, knowledge and operational tables, and uses role-aware policies. The Next.js server authorization layer applies the same separation before private reads.
Public content is kept separate from private records. The site does not publish RLS policy SQL, internal identifiers, database connection details, or secrets on this page.
Sign-in identity only
Google sign-in requests the basic OpenID Connect identity scopes needed by Supabase Auth: openid, email and profile. It does not request Google Drive, Gmail or Calendar permissions. Website sign-in does not use Microsoft Graph.
For an ICT or security review
- Application name
- EFDS Society
- Purpose
- Authentication and member access for the Economics, Finance & Data Science Society website.
- Authentication
- Supabase email and password or secure email link; Google OAuth when configured.
- Production URL
- https://www.imperial-efds.com
- Identity data
- Authenticated user ID, email, confirmation state, and available name metadata used to link an EFDS profile.
- Hosting
- Vercel / Next.js application.
- Database and auth
- Supabase Auth and Supabase PostgreSQL.
- Organisation
- Economics, Finance & Data Science Society, Imperial College London.
Server-side boundaries
Supabase service-role credentials, database credentials, and any OAuth client secrets are server-side configuration. They are not exposed through browser code or public NEXT_PUBLIC_* variables. This page intentionally does not display credentials or internal IDs.
Please tell us about a concern
To report a suspected security issue, unsafe disclosure, access problem, or privacy concern, use the current contact route. EFDS does not claim to operate a formal bug bounty.