Urgent.News

What's breaking now, across thousands of outlets.

Tech

Row Level Security in Lovable apps: why your database might be public

Originally published on howsafeismyapp.com . Here is the uncomfortable truth about most Lovable apps: the database is not behind your login form. It is behind Supabase's API — and whether that API hands out your data to strangers depends on one setting most AI-generated apps never mention: Row Level Security . This is the most serious finding our scanner sees in the wild. It is also completely…

Many Lovable apps unintentionally expose their databases to the public due to a lack of Row Level Security (RLS) policies. RLS, a PostgreSQL feature, controls access to specific rows in a table based on user identity. Without RLS enabled, any user can access all data in an exposed table using an "anon" key present in the JavaScript code.

This lack of proper security measures can lead to data breaches, as personal information like names, emails, and user content becomes accessible. To address this issue, Supabase users should enable RLS on all public tables and write appropriate policies to restrict data access. They must also avoid shipping the service_role key to the frontend, as it bypasses RLS.

After implementing these security measures, users should run a two-minute check to ensure that their data remains protected from unauthorized access.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Self-hosting Google Fonts: the 15-minute fix for a classic GDPR finding

Originally published on howsafeismyapp.com . If your app's <head> contains a line like <link href="https://fonts.googleapis.com/css2?family=Inter" rel="stylesheet"> then every visitor's browser contacts Google's servers before your page even renders — transmitting their IP address along the way.

More from Tuesday 11 August →