- SignalDesk1小时前
Original Summary
Something changed in our inbox over the last year. We've built MVPs for 8 years and a lot of the founders reaching out now already have one. They built it themselves in Lovable or Cursor, got it to paying users and now something's on fire and they want someone to look under the hood. We've audited 12 of these so far. First thing I'll say... getting to paying users with no dev team is impressive. Plenty of our old clients didn't manage that with one lol. But the same few things broke in almost all of them. Login worked and permissions didn't Sign up and login worked in every single one. What almost none of them had was authorization, meaning the app checks that the thing you're asking for is yours. On one tutoring marketplace, changing the number at the end of a URL showed you a different tutor's students, parents' phone numbers included. Another let you make yourself an admin by adding one extra field to your profile update request. I get why the AI misses this. When you test with one account everything works. Authorization bugs only show up once there are two of you. So make a second account and log into it in a private window. Paste in the address of something private from your main account. If it loads, you've got the problem. If you're on Supabase, check that row level security is turned on for every table including the ones you added last month. Every regenerate made the code a little worse When something broke, the founder asked the AI to fix it and it did, mostly by adding code next to the old code instead of changing it. One codebase had four different functions for formatting a date, each one added by a different fix. A couple had the same bug fixed in two places and still broken in a third. After a few months you hit the loop every vibe coder knows. Fixing A breaks B, and fixing B brings A back. By then the codebase is too big for the AI to hold in its head, so it can't see why. The habit I'd push hardest is a git commit before every prompt. When a fix makes things worse, roll back instead of asking for another fix on top of it. And if the same bug comes back twice, stop prompting and read the code, or get someone to. Payments worked exactly once Checkout worked in all of them, at least the part where someone pays and gets upgraded. Most of these apps only listened for that one event though. One gave you the paid plan forever if you cancelled, since it never heard about the cancellation. Another unlocked the paid plan if you typed the success page address straight into your browser, because loading that page was what granted access. Failed renewals were the sneaky one. A card expires, Stripe retries it for a while, and the app keeps giving access to someone who stopped paying months ago. Stripe's test mode has cards that decline on purpose, and the Stripe CLI can send a failed payment event to your app (stripe trigger invoice.payment_failed). Do both and watch what happens to the u
- 情报分类:服务器与云资源
- 分类依据:内容涉及服务器、云资源或网络线路
- 信息来源:Reddit · SaaS
- 发布时间:2026/10/8 23:41:09
- 暂无回复