Skip to the card

Card 838 of 9752026-09-24 issue

Observed arrival · 2026-09-24

Tenantcheck’s shape-blind Postgres audit

tenantcheck.dev Visit website
Editorial interest 83/100 Selection signal · not a rating of the site

A tool for checking whether one customer in a multi-tenant Postgres app can read another customer’s rows.

Landing page captured for the 2026-09-24 issue.
For
Teams running multi-tenant applications on Postgres
Worth noticing
A supervisor helper function lacked an organisation check; twelve policies across ten tables inherited the flaw.

Field notes

Postgres combines permissive row-level-security policies with OR, so a valid tenant-scoped policy does not neutralize a second, broader grant. The write-up traces twelve policies across ten tables to a SECURITY DEFINER helper that returned assigned users without checking organisation boundaries. The author reports testing a supervisor linked across tenants inside a transaction that was rolled back; the test measured four-figure cross-tenant row access before the fix and zero afterward.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
⊠LoginAccess appeared gated
$PaidCommerce or pricing visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use

One card from the complete issue

The Busker’s Compute Bill

314,149 arrived 1,000 judged 975 catalogued Enter the complete issue
tenantcheck.dev

Landing page observed 2026-09-24. The live site may have changed.