-- Required when login/sign-up run in the browser against public."User" (Supabase anon key). -- Run in SQL Editor after your "User" table exists. grant usage on schema public to anon, authenticated; grant select, insert on table public."User" to anon; -- Production: prefer hashed passwords + RPC/Edge Function instead of plain Password in the client.