A private note can be
changed by another user.
The update finds a note by its ID without limiting it to the signed-in owner.
.from("notes") .update(changes) .eq("id", noteId)+ .eq("owner_id", this.ownerId)
This is an illustrative change. The hosted beta does not run application tests.