Original Summary

i've been building a scanner for AI-built apps, so i end up looking at a lot of Lovable and Bolt sites. the same few problems show up over and over, and none of them need you to be a security person to fix. RLS on every table. the anon key sits in your frontend bundle, that's normal. but if a table has RLS off, anyone can grab the key from devtools and read the whole table with one request. go through Supabase table editor and check every table, especially ones you added later with SQL. a policy like using (true) is basically no RLS. search your policies for it. secret keys in the frontend. open your live site, look through the JS files, search for sk_ and service_role. if anything shows up, rotate it today. source maps in production. if yoursite.com/assets/index-xxxx.js.map loads, anyone can read your original code, comments included. no security headers. no CSP, no X-Frame-Options. not a disaster alone, but it's the first thing anyone poking at your site will check. open CORS on your API routes. Access-Control-Allow-Origin: * on routes that touch user data. you can check most of this by hand in about 20 min with devtools. if you'd rather not, i made a tool that does it: clarseal.com , one free scan a day, no signup, passive checks only (so only scan your own stuff). full disclosure, it's mine, and i'd really like feedback, especially if it flags something you think is wrong. what's the worst thing you found in your own app after it went live?   submitted by   /u/arsm2016 [link]   [comments]


  • 情报分类:商业与市场研究
  • 分类依据:内容涉及商业、投资或市场动态
  • 信息来源:Reddit · SideProject
  • 发布时间:2026/10/4 15:18:57