正在加载视频...
视频加载失败
☠️ here is why your vibe coded project is not safe when you set db rules, you think you are safe ☣️ watch how i exploit a "safe" supabase db by inserting millions of rows see the thread below to learn how to protect yours (don't just bookmark it,... show more
69 条评论

RLS rules are go to approach by AI models... but they shouldn't be. you must do these instead: 1) enable RLS but don't put any rules this will close your database to the outside of the world. after this only service role key can reach your db

2) ask ai model to write an edge function with proper user authentication this will authenticate the user and your decision maker will be your backend (which uses service role key) from this moment, your backend can just verify the user and ONLY let them access the relevant information and only your backend can write to your database

3) this backend will be extracting user id from user's token which is also not static, it expires and automatically refreshed using refresh token. you don't need to worry about this. these are already handled by authentication providers (supabase auth or firebase auth in this instance)

4) your edge function should immediately return 403 if the token is invalid

5) after this point, no one can access your database unless you somehow manage to leak your service role token

6) as a best practice, never let your frontend directly talk to your database with these sort of rules, never. it's a bad design

7) another positive side of this is having the ultimate control. say you have a mobile app, if your logic lives in your backend, you can update that code without releasing your app (as we know it takes a lot of time due to apple and google's review processes) if there is an issue, you can immediately cut the access, change the logic, fix your bug. having your client talk to your db literally means leaving the keys and authority to someone else and losing all the control and speed you could have. don't do that

You have brilliantly created a “picks and shovels” place in vibe coding. Helping vibe coders with safety and security is a critical need. Your recent tweets have been incredibly helpful ✌️

really appreciate it Rick! i am glad you found them helpful ☺️🙌

Pretty sure you already know but you’re making yourself invaluable to an exploding industry. Did a security audit on my build yesterday based on your tweets and found a bunch of holes!

🙌🙌 that's really nice to hear! i am launching my security scanner tool tomorrow, let's see if it gets any traction 😅

👀

That barely makes any difference. If the user can write to the DB through edge function or directly through rls it’s the same thing at the end. The correct way to limit API access per second to avoid flooding. And don’t apply RLS to public, but only to authenticated users.

how can you rate limit if the user is directly writing to the db?

It is still going through Supabase. Nonetheless even if you ignore this. The correct way is to set RLS to authenticated users, which is exactly the same what you are trying to achieve via edge functions, but it’s easier.

i am not following. how can you rate limit direct db writes? afaik, supabase doesn’t have such functionality. with edge functions you can easily rate limit (again supabase doesn’t so this, you must implement rate limiting) another benefit of having middleware is:

Great job bro, congrats! Next middleware is a good option to seperate db and frontend. extra tip: using csrf token does really matter.

thanks man! yes, it could be next, edge functions or even a custom one

Absolutely could be, but I especially wrote for vibecoders because they are only use next ecosystem.

100% makes sense for vibe coders

Why would you not have db talk to your backend only? I mean latency but direct Fe to db connection is just reckless

exactly! but many inexperienced people don’t even know the difference and they are shipping like crazy with ai agents

Supabase + RLS enabled ≠ secure database. Authenticated users can still flood your tables with millions of rows if you allow direct client inserts. Fix: Lock DB completely (RLS On + No policies), route all operations through edge functions with rate limiting + proper auth checks. Ultimate control > convenience. Protect your projects, folks

here is another attack point that you must defend:

Your thread is very popular today! #TopUnroll 🙏🏼@ADC_Houston for 🥇unroll

Thanks for this, going to do an audit today. New to supabase

my pleasure! I also built an audit tool and embedded AI for contextual analysis. releasing it tomorrow! happy to add you to the waitlist. feel free to dm if interested 🙌

These are exactly the things I encountered during the development process that AI created. Many people are in this situation without even knowing it. Thanks for sharing such detailed information.

my pleasure brjan 🙌☺️

This is the second time I’m coming across your posts and I must say each time I learn a new thing thanks for this sir

ahh, glar to hear that! that makes me happy!

love your tips!

☺️☺️ thank you!

Good stuff. I’d say it’s not really RLS at fault, but rather using client side DB calls. Can’t believe that pattern became popular. I use RLS only through the backend, with middleware for session mgmt. Avoids using root-style service/secret key so less risk there too.

exactly, i kept saying RLS cuz inexperienced vibe coders don’t really know the tech terminology. they tend to know what RLS is because it’s visible on the dashboard and also ai models ask them to enable it client-db is a bad design from day 1 the only advantage is realtime imo. it makes web socket very easy and fast to implement

Much needed!! Absolutely gonna do this right away

is live now if you want to use my toolkit to audit your app

Yes brother!! Definitely gonna is it 🙌

why not use JWT token and RLS ? from supabase website: "RLS is incredibly powerful and flexible, allowing you to write complex SQL rules that fit your unique business needs. RLS can be combined with Supabase Auth for end-to-end user security from the browser to the database."

When I clicked on the video I thought my spotify started playing instead bc I’m always blasting the rapture llol Excellent song choice🔥🤝

😅this track is a masterpiece i had a chance to go to black coffee’s gig last summer, i kept getting goosebumps!

I had backstage tix to see him in NYC but Brooklyn Mirage filed for bankruptcy lol That said, I was able to see Keinemusik twice in ‘24 which was a great set both occasions. Cheers, brother🤝

ah that’s unlucky! he has a residency at hi ibiza which is a 2.5 hours flight from london but i haven’t seen keinemusik yet and they are already way too mainstream 😅

You have no excuse! Ibiza is a 10 to 12 hour flight out of NYC. LOL I didn’t wanna say anything, but yeah 100% mainstream. The shows I went to were super crowded with more people their to take pictures than to enjoy the musik.

Surely if you can insert it means you meet RLS criteria or you’re using the secret key.

Very nice post. Very helpful to my vibe coding journey!

thanks 💪

@threadreaderapp unroll

your threads a great reminder to code like were on the blocklist.

Thanks!!! Something I worry about a lot

my pleasure, hope it helps!

what about RBAC using this? should also be pretty secure.

love when a vibecoder hacks other ai projects with there ai built "expoit"

@grok create a guide in steps in order and explain it reasonably with best practices that everyone can understand and follow.

this is great to fix all the mess my Claude made on my app, sad i arrived to your post this late. great stuff man!

Great demo

thanks travis 🙌

thanks for sharing

🙌🙌 my pleasure

(Frank, taking notes before the next quarter's numbers are due)

Not a single person asks for a song name?

the rapture pt.III

thanks

exactly

how do you just “insert a million” rows if you do not have the keys and only server has them? i would assume you’re logged in and you’re currently using your auth token to make the 1m insert request or how does this work?

project id and anon keys are public if rls enforces auth, my script makes a request to supabase auth to create an account then login. upon logging in, i fetch the jwt and use that jwt to bypass that rls rule and start writing to the table

👏🏻👏🏻👏🏻

@grok create a summary and list of prompts to use to get Claude to follow these steps

Interesting 🤨

