Original Summary

So I've been building Shrine, a CLI that scans repos for exposed secrets, leaked JWTs, and Supabase misconfigurations. Small side project, a few weeks of nights. Once the core scanner worked, I ran it against my own codebase as a sanity check. 95 findings, 12 high severity. Turned out most were old test fixtures and debug scripts I'd left lying around. Fake keys from building the JWT detector. But a few were real: a service-role key sitting in a public HTML file, and stale RLS policies on the Supabase backend that would've let anyone read the whole access-key table if I hadn't caught it. That one stung a bit. The tool built to catch this stuff almost shipped with the exact problem it's supposed to find. Fixed it by moving key validation behind a single RPC function that only returns yes/no plus tier, instead of exposing the raw table to anon. Also cleaned out the leftover test/debug files before publishing. Lesson: "scan your own product before anyone else does" sounds obvious, but I nearly skipped that step rushing to ship. Its Barebones, Its FREE and i just want users to give feedback on it. 😁   submitted by   /u/Real_KingZeotic [link]   [comments]


  • 情报分类:综合情报
  • 分类依据:内容未命中明确的垂直分类规则,归入综合情报
  • 信息来源:Reddit · SaaS
  • 发布时间:2026/9/29 23:40:23