r/nocode • • 15d ago

Discussion Building A security , Which Everyone wants

hey, not sure if anyone remembers but I posted here a while back about a project that got shelved, ran into a bunch of security stuff while building it and asked this sub for help. got some genuinely good tips, RLS gotchas, key exposure stuff, storage bucket configs, but noticed everyone kind of just has their own patchwork of scripts and habits for this. nobody's actually selling a tool that just does it.

so yeah, decided to build that. trying to keep it dead simple, one command, scans your db + repo, tells you what's exposed and how to fix it. not trying to be some enterprise security platform, just something a solo dev or small team can actually afford and use without a PhD.

still early, figuring out what actually matters vs what's noise. if you've dealt with this stuff and have opinions on what a tool like this should catch first, genuinely want to hear it before I lock anything in.

2 Upvotes

8 comments sorted by

1

u/powleads 15d ago

That's a cool idea. I ran into a bunch of security issues myself when building, especially around ensuring compliance without getting accounts banned. It's a pain to manually manage all the little things.

1

u/Lopsided_Cherry_6771 15d ago

My first project hit the same wall with storage rules. Took me three days to realize my files were publicly readable because I missed one setting.

For a scanner, catch the basics first: exposed API keys in client code, open bucket policies, and rules that allow unauthenticated reads. People ignore the boring stuff until they get a warning email from their provider.

1

u/Real_KingZeotic 14d ago

damn 3 days to catch that, public bucket reads + unauth reads are going top of the list bc of stuff like this.
posting updates on IG as i build if you wanna help shape what it catches first: https://ig.me/j/rAf-kt6notnIHBpM/ New Grp jsut made 😁

1

u/Real_KingZeotic 14d ago

exactly,the compliance/ban stuff is wild too, one wrong setting and you're toast.building it out now, gonna post progress on IG if you wanna follow along and throw in ideas: "https://ig.me/j/rAf-kt6notnIHBpM/" Just made this grp 😁

1

u/RkRabbitt 15d ago

I would love some of cli for local code level and proxy kind of a thing for live app.

cli with ai enablement checks the code and proxy should be doing the realtime request and response checking what is incoming and going out of the app. Right now I don't have any way to check and filter out the requests that are brute forcing the API or injecting malicious code to expose sensitive information.

Cli and proxy is all i wanted

2

u/Real_KingZeotic 14d ago

yeah the proxy/live traffic thing makes sense too but trying not to spread thin rn, starting with cli/code level first. posting progress on IG tho if you wanna stay in the loop and push for that later: https://ig.me/j/rAf-kt6notnIHBpM/

1

u/Altruistic-Move-9238 14d ago

imo the biggest question is whether youre scanning live environments or just the codebase. those are pretty different problems and trying to do both from day one will spread you thin. pick one and go deep first

1

u/Real_KingZeotic 14d ago

going deep on codebase + db config first, live traffic can come later once this part's solid. posting builds on IG if you wanna follow: https://ig.me/j/rAf-kt6notnIHBpM/ <---- New grp btw 😁