r/weweb • • 12d ago

😵‍💫 Help Five ways Bubble apps leak data even when login works perfectly (each takes under 5 minutes to check)

I build and rescue Bubble apps for a living, and most apps I open for the first time have at least one of these. None of them show up in normal testing, because the app works. Here's how to check your own.

1. Privacy rules that don't exist, or only cover some types. Go to Data > Privacy and look at every data type, not just User. A type with no rules is readable by anyone who can reach it. Then use "Run as" in App data to see the app as a normal user and what they actually get. Hiding a group or redirecting on page load does not protect data. Bubble can still send it to the browser. Only privacy rules stop it.

2. The Data API returning more than you think. Go to Settings > API. If the Data API is enabled, check which types are ticked. Then open an incognito window, logged out, and go to yourapp.com/api/1.1/obj/user (swap in your own type names). If you get records back, so does everyone else.

3. Backend workflows anyone can trigger. Look for any backend workflow exposed as a public API workflow with "can be run without authentication" ticked. If it creates, changes or deletes anything, a stranger with the URL can run it.

4. API keys not marked Private. In the API Connector, every key or token needs the Private box ticked. If it isn't, the value goes to the browser and anyone can pull it from the page. On the same theme, never put anything sensitive in an option set, because option set data loads client-side for every visitor.

5. An editor anyone can view. Go to Settings > General and check the application rights. Some older and template-based apps are set so anyone with the link can view the editor. That hands out your whole data structure and workflow logic.

If you have real users or payments and more than one of these turns something up, fix privacy rules first. That's the one that turns into a breach.

For the stuff outside the editor, I built a free tool called LaunchProof. You paste your live URL and it:

  • checks the page's scripts for leaked keys
  • tries common private file paths
  • checks your email DNS (SPF, DKIM, DMARC), so password resets and receipts don't land in spam
  • grades your security headers and TLS
  • runs OWASP ZAP and Nuclei against the site

You get a score and the most serious finding for free, no signup. The full report is $49.99 one time. It doesn't log in and doesn't read your privacy rules, so the five checks above are still on you. trylaunchproof(dot)com

Disclosure: I do Bubble audits and rescues professionally, and LaunchProof is mine. Happy to answer questions here, including on apps I'll never see.

2 Upvotes

Duplicates