The top answer mentions the conditions in which this method is safe to do. Does supabase implement these, subsequently making passing the token via query parameter ok?
If this is not the correct method, how should this be done? If possible, via method that still involves the API, and not doing client-supabase query directly.
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.