- SignalDesk2小时前
Original Summary
I’m looking for someone experienced with Supabase, Postgres, Next.js, and auth/referral systems to audit a production project. The main thing I’m trying to figure out is whether there’s any way users, bots, or another site could be manipulating signup attribution, referral codes, affiliate parameters, or account creation flows . I’ve already found one issue with an external platform where a referral code is visible/autofilled during signup, but using Google OAuth appears to create the account without actually attaching the referrer. That got me wondering whether I could have similar attribution issues or exploitable flows on my own site. I’d want the audit to look at: Supabase Auth signup/login flows Google/OAuth callbacks Referral code handling before and after signup Whether referral parameters can be changed, stripped, overwritten, or spoofed Whether someone can create accounts in a way that bypasses referral attribution Whether another site could call my public Supabase endpoints directly Whether outbound affiliate URLs/parameters can be manipulated RLS policies and anon / authenticated permissions Public /rest/v1/ exposure SECURITY DEFINER RPC functions Anonymous inserts / click tracking Bots, scraping, fake signups, or automated account creation Any obvious way someone could hijack attribution or make signups appear unattributed General Supabase security issues I’ve also had unusually high Supabase API/egress usage, so I’d like to determine whether that’s normal traffic, bots/scrapers, or someone consuming my API externally. I can provide relevant code, schema, RLS policies, logs, and auth flow details privately. I will not share service-role keys, database passwords, or production secrets. If you’ve specifically audited Supabase auth/referral/affiliate systems , comment or DM me with your experience and what you’d want access to. Paid audit is fine.   submitted by   /u/Mvcko [link]   [comments]
- 情报分类:商业与市场研究
- 分类依据:内容涉及商业、投资或市场动态
- 信息来源:Reddit · SaaS
- 发布时间:2026/9/20 20:44:00
- 暂无回复