- SignalDesk1小时前
Original Summary
I've been working on a B2B SaaS template built on Next.js 16, Supabase, and Stripe. Before launching it, I paused feature work and wrote a bunch of adversarial tests to see if I could break the backend—stuff like tenant data leaks, RBAC bypasses, webhook drops, and SECURITY DEFINER view issues. The tests caught 3 actual production bugs I definitely would've missed: Out-of-order Stripe webhooks. If an older subscription.updated event fired late, it could overwrite newer billing state in the DB. Fixed it with timestamp validation before updating rows. Bricked webhook retries. If a webhook failed halfway through processing, the partial DB state blocked Stripe's retry attempts. Wrapped the whole handler in a single idempotent transaction so retries clean up after themselves. Cross-tenant RPC leak. A usage-tracking RPC was executing without double-checking the tenant ID on the target row, opening a privilege escalation hole between organizations. Fixed all three and locked them down with regression tests in CI so they don't pop up again. I also put together a quick free check for anyone using Next.js + Supabase to test their own setup for these kinds of leaks: andrady.co/check If you just want the full code, I turned the hardened stack into a starter kit called B2B SaaS OS ($249) over at andrady.co. Curious what’s the dumbest production edge-case bug that’s caught you off guard lately?   submitted by   /u/Pale_Ferret_8241 [link]   [comments]
- 情报分类:商业与市场研究
- 分类依据:内容涉及商业、投资或市场动态
- 信息来源:Reddit · SideProject
- 发布时间:2026/10/7 03:38:06
- 暂无回复