In recent video theo gave example against storing user permissions in database as done in firebase and supabase.
Can someone please provide me with some more resources so that I can read why that is a bad practice and what are better practices around it.