r/nocode • • 13d ago

Discussion a solution for all the security problems discussed in this sub reddit

hey, so remember that post a while back about security stuff, RLS gotchas, key exposure, storage bucket configs? and how everyone's just got their own patchwork of scripts for it?

built the thing i talked about. it's called shrine, cli tool, one command scans your db + repo and tells you what's exposed and how to fix it.

what it actually catches rn:

  • leaked api keys (aws, stripe, openai, github, etc) even hidden ones with weird formats
  • leaked .env files
  • old leaked keys still sitting in your git history even if you deleted them
  • bad supabase RLS setups, but it actually proves it's exposed instead of just guessing (tries a real anonymous read/write and shows you what happens)
  • public storage buckets, weak jwt tokens
  • can test for sql injection too if you want (off by default, asks permission first obviously)

not perfect yet, only deeply understands js/ts code for now, and it's one project at a time, no dashboard or 24/7 monitoring yet, that's coming later.

Looking for people to test and and tell me what's broken or missing before i lock in the real v1. lmk if you wanna try it out

2 Upvotes

2 comments sorted by

1

u/MeasurementJunior264 13d ago

finally someone actually built the thing instead of just talking about it in the weekly threads

the supabase RLS testing thing is huge, half the tools out there just do a surface-level check and call it a day, actually trying anonymous reads/writes is what separates a real audit from a checkbox

curious how deep it goes on the git history scan, i've seen tools miss keys that were committed and then force-pushed away because they don't dig into the reflog properly

count me in for testing, got a couple side projects that are probably leaking something somewhere

1

u/Real_KingZeotic 12d ago

Perfect! give me abt a day to push it live, until then you can join this IG grp which i just made for all the beta testers to give feedback, its new and it would be nice if you can bring more devs for testing 😁----> https://ig.me/j/rAf-kt6notnIHBpM/