This product was not featured by Product Hunt yet. It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).
Product upvotes vs the next 3
Waiting for data. Loading
Product comments vs the next 3
Waiting for data. Loading
Product upvote speed vs the next 3
Waiting for data. Loading
Product upvotes and comments
Waiting for data. Loading
Product vs the next 3
Loading
Supabase RLS Leak Demo
Reproduce a cross-tenant RLS leak and verify the fix
A tiny, runnable Supabase/Postgres security fixture that proves a policy can look correct and still leak rows across tenants. The same test suite runs red on the broken policy and green after the one-file fix. Start with npm ci && npm test—no Docker, cloud project, credentials, or production data required. Built for founders and developers who want evidence before shipping multi-tenant apps.
I built this after seeing teams treat “RLS enabled” as proof that tenant isolation works. It is not. A policy can pass happy-path checks while a relationship or ownership condition still exposes another tenant’s rows.
This repository makes the failure visible with one red/green fixture and the same test suite on both branches. You can inspect the SQL, reproduce the leak locally, and verify the minimal fix without sharing credentials.
If you find a pattern the fixture should cover, I’d genuinely like to hear it. For teams that want a second set of eyes, I also offer a fixed-scope 24-hour review of three sensitive tables. Launch offer: $15.20 total, $7.60 deposit today:
“Reproduce a cross-tenant RLS leak and verify the fix”
Supabase RLS Leak Demo was submitted on Product Hunt and earned 2 upvotes and 1 comments, placing #141 on the daily leaderboard. A tiny, runnable Supabase/Postgres security fixture that proves a policy can look correct and still leak rows across tenants. The same test suite runs red on the broken policy and green after the one-file fix. Start with npm ci && npm test—no Docker, cloud project, credentials, or production data required. Built for founders and developers who want evidence before shipping multi-tenant apps.
On the analytics side, Supabase RLS Leak Demo competes within Open Source, Developer Tools and GitHub — topics that collectively have 627.5k followers on Product Hunt. The dashboard above tracks how Supabase RLS Leak Demo performed against the three products that launched closest to it on the same day.
Who hunted Supabase RLS Leak Demo?
Supabase RLS Leak Demo was hunted by Cenk KURTOĞLU. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
For a complete overview of Supabase RLS Leak Demo including community comment highlights and product details, visit the product overview.
I built this after seeing teams treat “RLS enabled” as proof that tenant isolation works. It is not. A policy can pass happy-path checks while a relationship or ownership condition still exposes another tenant’s rows.
This repository makes the failure visible with one red/green fixture and the same test suite on both branches. You can inspect the SQL, reproduce the leak locally, and verify the minimal fix without sharing credentials.
If you find a pattern the fixture should cover, I’d genuinely like to hear it. For teams that want a second set of eyes, I also offer a fixed-scope 24-hour review of three sensitive tables. Launch offer: $15.20 total, $7.60 deposit today:
https://cengokurtoglu.gumroad.com/l/supabase-rls-3-table-review/LAUNCH20?utm_source=producthunt&utm_medium=maker_comment&utm_campaign=rls_review