How one developer enforced free-plan limits inside Postgres instead of the UI
A developer building a release-tracker app moved free-plan enforcement from the frontend into a PostgreSQL database trigger, arguing that UI-side checks are easily bypassed via extra tabs, stale sessions, or direct API calls. The trigger fires before each insert into the follows table, counting existing rows for the user and rejecting any attempt to exceed 10 followed technologies on the free plan. A PostgreSQL advisory lock keyed to the user ID prevents race conditions where two simultaneous inserts could both pass the count check independently. Custom SQLSTATE error codes are returned through PostgREST directly to the browser, allowing the frontend to display precise, code-driven rejection messages without parsing error strings. The author notes the trigger also blocks follows of retired technologies and is designed to accommodate future paid-plan logic in a single, authoritative location.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in