I want to restrict the user to only be able to edit their own data. Right now I have a basic RLS policy set up, but I am also passing the user session id to make sure it matches the one in the table. Is this really needed or are they already blocked out?