正在加载视频...

视频加载失败

☠️ here is why your vibe coded project is not safe when you set db rules, you think you are safe ☣️ watch how i exploit a "safe" supabase db by inserting millions of rows see the thread below to learn how to protect yours (don't just bookmark it,...

123,303 次观看 • 8 个月前 •via X (Twitter)

69 条评论

Burak Eregar 的头像
Burak Eregar8 个月前

RLS rules are go to approach by AI models... but they shouldn't be. you must do these instead: 1) enable RLS but don't put any rules this will close your database to the outside of the world. after this only service role key can reach your db

Burak Eregar 的头像
Burak Eregar8 个月前

2) ask ai model to write an edge function with proper user authentication this will authenticate the user and your decision maker will be your backend (which uses service role key) from this moment, your backend can just verify the user and ONLY let them access the relevant information and only your backend can write to your database

Burak Eregar 的头像
Burak Eregar8 个月前

3) this backend will be extracting user id from user's token which is also not static, it expires and automatically refreshed using refresh token. you don't need to worry about this. these are already handled by authentication providers (supabase auth or firebase auth in this instance)

Burak Eregar 的头像
Burak Eregar8 个月前

4) your edge function should immediately return 403 if the token is invalid

Burak Eregar 的头像
Burak Eregar8 个月前

5) after this point, no one can access your database unless you somehow manage to leak your service role token

Burak Eregar 的头像
Burak Eregar8 个月前

6) as a best practice, never let your frontend directly talk to your database with these sort of rules, never. it's a bad design

Burak Eregar 的头像
Burak Eregar8 个月前

7) another positive side of this is having the ultimate control. say you have a mobile app, if your logic lives in your backend, you can update that code without releasing your app (as we know it takes a lot of time due to apple and google's review processes) if there is an issue, you can immediately cut the access, change the logic, fix your bug. having your client talk to your db literally means leaving the keys and authority to someone else and losing all the control and speed you could have. don't do that

Rick Bakas 🏹 🅿️ 的头像
Rick Bakas 🏹 🅿️8 个月前

You have brilliantly created a “picks and shovels” place in vibe coding. Helping vibe coders with safety and security is a critical need. Your recent tweets have been incredibly helpful ✌️

Burak Eregar 的头像
Burak Eregar8 个月前

really appreciate it Rick! i am glad you found them helpful ☺️🙌

Rick Bakas 🏹 🅿️ 的头像
Rick Bakas 🏹 🅿️8 个月前

Pretty sure you already know but you’re making yourself invaluable to an exploding industry. Did a security audit on my build yesterday based on your tweets and found a bunch of holes!

Burak Eregar 的头像
Burak Eregar8 个月前

🙌🙌 that's really nice to hear! i am launching my security scanner tool tomorrow, let's see if it gets any traction 😅

Rick Bakas 🏹 🅿️ 的头像
Rick Bakas 🏹 🅿️8 个月前

👀

Hermann  的头像
Hermann 8 个月前

That barely makes any difference. If the user can write to the DB through edge function or directly through rls it’s the same thing at the end. The correct way to limit API access per second to avoid flooding. And don’t apply RLS to public, but only to authenticated users.

Burak Eregar 的头像
Burak Eregar8 个月前

how can you rate limit if the user is directly writing to the db?

Hermann  的头像
Hermann 8 个月前

It is still going through Supabase. Nonetheless even if you ignore this. The correct way is to set RLS to authenticated users, which is exactly the same what you are trying to achieve via edge functions, but it’s easier.

Burak Eregar 的头像
Burak Eregar8 个月前

i am not following. how can you rate limit direct db writes? afaik, supabase doesn’t have such functionality. with edge functions you can easily rate limit (again supabase doesn’t so this, you must implement rate limiting) another benefit of having middleware is:

Burak Builds 的头像
Burak Builds8 个月前

Great job bro, congrats! Next middleware is a good option to seperate db and frontend. extra tip: using csrf token does really matter.

Burak Eregar 的头像
Burak Eregar8 个月前

thanks man! yes, it could be next, edge functions or even a custom one

Burak Builds 的头像
Burak Builds8 个月前

Absolutely could be, but I especially wrote for vibecoders because they are only use next ecosystem.

Burak Eregar 的头像
Burak Eregar8 个月前

100% makes sense for vibe coders

Sam Padilla 的头像
Sam Padilla8 个月前

Why would you not have db talk to your backend only? I mean latency but direct Fe to db connection is just reckless

Burak Eregar 的头像
Burak Eregar8 个月前

exactly! but many inexperienced people don’t even know the difference and they are shipping like crazy with ai agents

Issac 的头像
Issac8 个月前

Supabase + RLS enabled ≠ secure database. Authenticated users can still flood your tables with millions of rows if you allow direct client inserts. Fix: Lock DB completely (RLS On + No policies), route all operations through edge functions with rate limiting + proper auth checks. Ultimate control > convenience. Protect your projects, folks

Burak Eregar 的头像
Burak Eregar8 个月前

here is another attack point that you must defend:

Thread Reader App 的头像
Thread Reader App8 个月前

Your thread is very popular today! #TopUnroll 🙏🏼@ADC_Houston for 🥇unroll

JackedBasedMgr 的头像
JackedBasedMgr8 个月前

Thanks for this, going to do an audit today. New to supabase

Burak Eregar 的头像
Burak Eregar8 个月前

my pleasure! I also built an audit tool and embedded AI for contextual analysis. releasing it tomorrow! happy to add you to the waitlist. feel free to dm if interested 🙌

Brjan | AI Builder 的头像
Brjan | AI Builder8 个月前

These are exactly the things I encountered during the development process that AI created. Many people are in this situation without even knowing it. Thanks for sharing such detailed information.

Burak Eregar 的头像
Burak Eregar8 个月前

my pleasure brjan 🙌☺️

Mega Dean 的头像
Mega Dean8 个月前

This is the second time I’m coming across your posts and I must say each time I learn a new thing thanks for this sir

Burak Eregar 的头像
Burak Eregar8 个月前

ahh, glar to hear that! that makes me happy!

Saymon Void 的头像
Saymon Void8 个月前

love your tips!

Burak Eregar 的头像
Burak Eregar8 个月前

☺️☺️ thank you!

Alec Wantoch 的头像
Alec Wantoch8 个月前

Good stuff. I’d say it’s not really RLS at fault, but rather using client side DB calls. Can’t believe that pattern became popular. I use RLS only through the backend, with middleware for session mgmt. Avoids using root-style service/secret key so less risk there too.

Burak Eregar 的头像
Burak Eregar8 个月前

exactly, i kept saying RLS cuz inexperienced vibe coders don’t really know the tech terminology. they tend to know what RLS is because it’s visible on the dashboard and also ai models ask them to enable it client-db is a bad design from day 1 the only advantage is realtime imo. it makes web socket very easy and fast to implement

Hiranmaya 的头像
Hiranmaya8 个月前

Much needed!! Absolutely gonna do this right away

Burak Eregar 的头像
Burak Eregar8 个月前

is live now if you want to use my toolkit to audit your app

Hiranmaya 的头像
Hiranmaya8 个月前

Yes brother!! Definitely gonna is it 🙌

Jan 的头像
Jan8 个月前

why not use JWT token and RLS ? from supabase website: "RLS is incredibly powerful and flexible, allowing you to write complex SQL rules that fit your unique business needs. RLS can be combined with Supabase Auth for end-to-end user security from the browser to the database."

Ander 的头像
Ander8 个月前

When I clicked on the video I thought my spotify started playing instead bc I’m always blasting the rapture llol Excellent song choice🔥🤝

Burak Eregar 的头像
Burak Eregar8 个月前

😅this track is a masterpiece i had a chance to go to black coffee’s gig last summer, i kept getting goosebumps!

Ander 的头像
Ander8 个月前

I had backstage tix to see him in NYC but Brooklyn Mirage filed for bankruptcy lol That said, I was able to see Keinemusik twice in ‘24 which was a great set both occasions. Cheers, brother🤝

Burak Eregar 的头像
Burak Eregar8 个月前

ah that’s unlucky! he has a residency at hi ibiza which is a 2.5 hours flight from london but i haven’t seen keinemusik yet and they are already way too mainstream 😅

Ander 的头像
Ander8 个月前

You have no excuse! Ibiza is a 10 to 12 hour flight out of NYC. LOL I didn’t wanna say anything, but yeah 100% mainstream. The shows I went to were super crowded with more people their to take pictures than to enjoy the musik.

Chikun 的头像
Chikun8 个月前

Surely if you can insert it means you meet RLS criteria or you’re using the secret key.

Lourenço Coelho 的头像
Lourenço Coelho8 个月前

Very nice post. Very helpful to my vibe coding journey!

Burak Eregar 的头像
Burak Eregar8 个月前

thanks 💪

ADCHouston 的头像
ADCHouston8 个月前

@threadreaderapp unroll

WASSIE 的头像
WASSIE8 个月前

your threads a great reminder to code like were on the blocklist.

ShuddaWuddaBuddha 的头像
ShuddaWuddaBuddha8 个月前

Thanks!!! Something I worry about a lot

Burak Eregar 的头像
Burak Eregar8 个月前

my pleasure, hope it helps!

Kev 的头像
Kev8 个月前

what about RBAC using this? should also be pretty secure.

Ryan 的头像
Ryan8 个月前

love when a vibecoder hacks other ai projects with there ai built "expoit"

Abdul 的头像
Abdul8 个月前

@grok create a guide in steps in order and explain it reasonably with best practices that everyone can understand and follow.

Boring Always Bored 的头像
Boring Always Bored6 个月前

this is great to fix all the mess my Claude made on my app, sad i arrived to your post this late. great stuff man!

Travis 的头像
Travis8 个月前

Great demo

Burak Eregar 的头像
Burak Eregar8 个月前

thanks travis 🙌

Scott Brabson 的头像
Scott Brabson8 个月前

thanks for sharing

Burak Eregar 的头像
Burak Eregar8 个月前

🙌🙌 my pleasure

Tristan Rhodes 的头像
Tristan Rhodes8 个月前

(Frank, taking notes before the next quarter's numbers are due)

Євгеній Піпа 的头像
Євгеній Піпа8 个月前

Not a single person asks for a song name?

Burak Eregar 的头像
Burak Eregar8 个月前

the rapture pt.III

vegun chikun nug 的头像
vegun chikun nug8 个月前

thanks

Dawid Makowski 的头像
Dawid Makowski8 个月前

exactly

かっこいい子 的头像
かっこいい子8 个月前

how do you just “insert a million” rows if you do not have the keys and only server has them? i would assume you’re logged in and you’re currently using your auth token to make the 1m insert request or how does this work?

Burak Eregar 的头像
Burak Eregar8 个月前

project id and anon keys are public if rls enforces auth, my script makes a request to supabase auth to create an account then login. upon logging in, i fetch the jwt and use that jwt to bypass that rls rule and start writing to the table

Andr11s 的头像
Andr11s8 个月前

👏🏻👏🏻👏🏻

Garry The Goat 的头像
Garry The Goat8 个月前

@grok create a summary and list of prompts to use to get Claude to follow these steps

AI Flip Monkey 的头像
AI Flip Monkey8 个月前

Interesting 🤨

相关视频