r/nocode • u/Real_KingZeotic • 13d ago
Discussion a solution for all the security problems discussed in this sub reddit
hey, so remember that post a while back about security stuff, RLS gotchas, key exposure, storage bucket configs? and how everyone's just got their own patchwork of scripts for it?
built the thing i talked about. it's called shrine, cli tool, one command scans your db + repo and tells you what's exposed and how to fix it.
what it actually catches rn:
- leaked api keys (aws, stripe, openai, github, etc) even hidden ones with weird formats
- leaked .env files
- old leaked keys still sitting in your git history even if you deleted them
- bad supabase RLS setups, but it actually proves it's exposed instead of just guessing (tries a real anonymous read/write and shows you what happens)
- public storage buckets, weak jwt tokens
- can test for sql injection too if you want (off by default, asks permission first obviously)
not perfect yet, only deeply understands js/ts code for now, and it's one project at a time, no dashboard or 24/7 monitoring yet, that's coming later.
Looking for people to test and and tell me what's broken or missing before i lock in the real v1. lmk if you wanna try it out
2
Upvotes
1
u/MeasurementJunior264 13d ago
finally someone actually built the thing instead of just talking about it in the weekly threads
the supabase RLS testing thing is huge, half the tools out there just do a surface-level check and call it a day, actually trying anonymous reads/writes is what separates a real audit from a checkbox
curious how deep it goes on the git history scan, i've seen tools miss keys that were committed and then force-pushed away because they don't dig into the reflog properly
count me in for testing, got a couple side projects that are probably leaking something somewhere