Fixes tagged Security
3 fixes · back to all fixes
Your _headers file serves 7 headers in production and 2 on a preview deployment
After adding a scoped Content-Security-Policy rule, the preview deployment served only two of seven headers. It looked exactly like a rejected _headers file. Deploying the unchanged original to a preview produced the identical result.
4 min read →
Supabase signed URL vs public URL: keep the storage bucket private
getPublicUrl on a public bucket hands a permanent, unauthenticated link to anyone who sees it once. Keep the bucket private, scope the storage policy to auth.uid(), and serve files with createSignedUrl links that expire: 900 seconds in the app, 3600 for a deliberate share.
2 min read →
Rate limiting in Postgres, no Redis
You don't need Redis or a third-party service to rate-limit a Supabase app. One table, one atomic upsert, and a security-definer function keyed to the user. Race-safe and impossible to bypass.
2 min read →