Genesis · SSR × RLS spike
Server-rendered on the Cloudflare edge. The roster count below is read with the caller’s Supabase JWT, so Postgres RLS scopes it to the caller’s org — no org filter in this code.
No session token. Send an X-Supabase-Token header (or an sb-access-token cookie).
Throwaway Phase-0 spike · not product · not committed.