Is exposing the ID from the auth.users table of one user to another user a security concern? - Supabase