Skip to content

Fix security review findings: anonymous rating leak, Data API lockdown - #26

Merged
MacroMaster101 merged 2 commits into
devfrom
fix/security-review-findings
Sep 28, 2026
Merged

MacroMaster101 merged 2 commits into
devfrom
fix/security-review-findings

Conversation

@MacroMaster101

Copy link
Copy Markdown
Owner

Fixes both findings from the full-project security review.

1. Anonymous reviewers could be identified (Medium, confirmed)

POST /api/ratings/flag returned the whole PageRating row, including the author's real userId.

  • Any signed-in user could flag an anonymous review and read the author's id from the response.
  • The public Crew Wall (GET /api/members) shows that same id next to a name, so the author was identified.
  • The route now returns only { success, message }. The rating UI only checks whether the request succeeded, so nothing else changes.

2. App tables open through Supabase's public Data API (High if the project uses Supabase defaults)

Prisma creates every table in public. By default, Supabase exposes public over its REST API and grants the anon role access. So the public anon key could read or write tables directly, for example inserting a row into AdminEmail to become an admin.

New file prisma/security/lock-down-data-api.sql:

  • Turns on row-level security for every table in public, with no policies.
  • Revokes anon and authenticated access, including for tables created later.
  • Ends with a verification query.

Prisma connects as the table owner, so the app isn't affected. The browser only uses Auth, Storage and a Realtime presence channel, none of which touch these tables. The README setup steps now include running this script.

⚠️ Merging this PR does not change the database. Run the SQL once in the Supabase dashboard (SQL Editor → New query). The last query should show rls = true and false for every access column on every table.

Test plan

  • tsc --noEmit, npm run lint
  • Run lock-down-data-api.sql in Supabase and confirm the verification output
  • After running it, sign in on the site and check that profile, ratings, favorites and the admin panel still work

POST /api/ratings/flag returned the full PageRating row, including the
author's real userId. Any signed-in user could flag an anonymous review
and match that id against the public Crew Wall to de-anonymize the
author. Return only a success message.
Prisma creates tables in the public schema, which Supabase exposes over
PostgREST to the anon and authenticated roles by default. Enable row
level security and revoke those grants (including default privileges for
future tables) so the public anon key can't read or write them. Prisma
connects as the table owner and is unaffected. Document running it in
the README.
@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
just-for-fun-website Ready Ready Preview Sep 28, 2026 11:11pm UTC

@MacroMaster101
MacroMaster101 merged commit 1acc9a6 into dev Sep 28, 2026
5 checks passed
@MacroMaster101
MacroMaster101 deleted the fix/security-review-findings branch September 28, 2026 23:12

This branch was successfully deployed

1 active deployment
Preview — c13be365 Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant