Observed arrival · 2026-10-05
Locksoup: locked, or soup?
A read-only Supabase security audit that checks database access controls and supplies SQL fixes.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Supabase developers auditing database access
- Worth noticing
- Its checks include mass assignment and multiple permissive policies being OR'd together.
Field notes
The listed checks extend beyond disabled row-level security to include views that bypass RLS, mutable function search paths, public storage buckets, and sensitive column names. The page also describes testing whether an anonymous visitor can actually read exposed tables. It says fixes are supplied for the project owner to run, and that schema metadata—not table rows—is what reaches the AI model.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
⊠LoginAccess appeared gated
$PaidCommerce or pricing visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue