- SignalDesk2026-09-11
I spent the last couple weeks pointing a security scanner at real apps built with AI tools (Lovable, Bolt, v0, that whole world), just to see what's actually exposed versus what people panic about. The gap between those two turned out to be the whole story. The thing almost everyone worries about: "someone said my Supabase key is visible in the browser, am I hacked?" Nine times out of ten, no. That's the anon key, and it's supposed to be public. It's how your frontend talks to your backend. Seeing it in your page source is normal and on its own means nothing. The thing almost nobody checks, and the one that actually burns people: whether your Row Level Security is set up right. In plain English, can a logged-in user read other users' data? "RLS is enabled
- 情报分类:技术价值、商业价值
- 命中依据:AI建站工具实测分析,有参考价值
- 来源:Reddit · SaaS
- 原作者:/u/ViG_ProSec1104 https://www.reddit.com/user/ViG_ProSec1104
- 发布时间:2026/9/11 13:07:30
- 暂无回复