Self-initiated demo by Flow Lab. Walkwren and Kettleby Dog Walks are invented.
Kettleby Dog Walks booked walks through Walkwren, a React and Supabase app made with an AI app builder. It worked, and it also let anyone read every customer’s home address. This is the review: ten problems, seven reproduced on a real PostgreSQL database and three found in the code. Each one was fixed and checked again.
Each finding says who could do what, shows what happened when the attack was tried before and after the fix, and shows the fix itself.
Locking things down is easy if you break the app. These actions were run on the fixed database as the people who need them, and the fix was also run on data the old app could have produced.
The fix also leaves the owner a list of bookings that suggest the old holes were already used: a price that differs from the price list, or a booking filed under someone else’s customer record. Only the server and the Supabase dashboard can read it.
Left for the owner to decide: how late a walk can be cancelled, the hours bookings are open, whether 10 upcoming walks per customer is the right limit, and whether edits other than cancelling should be possible in the app. For now those go through the Supabase dashboard.
The database checks run on real PostgreSQL (PostgreSQL, in memory). Supabase’s anon, authenticated and service_role roles, its default grants on new tables and its auth.uid() and auth.jwt() functions are recreated, so the row level security rules apply as they would behind Supabase. The HTTP layer (PostgREST) is not recreated, and the test database has one connection, so the “one booking at a time” lock is checked as a rule, not under a real race. “Before” is the generated migration. “After” is the same database with the fix migration applied on top of existing rows, which is how it would ship. If the old data holds something the fix can’t convert safely, such as a slot typed as “tomorrow 10am”, a date that doesn’t exist, or a walker already booked for two walks at once, the migration stops, names the rows and changes nothing. The three frontend findings (F2, F8, F9) are checked by reading the code, not by running the app. Walkwren and Kettleby Dog Walks are invented, and the “before” code was written for this demo to show problems that are common in generated Supabase apps.
Read the code and the Supabase setup, try every finding as an attack, and send a report like this one. You decide what to fix.
Fix migrations that keep your data, code changes, and the attack suite re-run until nothing gets through and the app still works.
Rotate any key that leaked, move server-only work to edge functions, and deploy with you watching.
The app builder keeps generating code. Each month the attack suite runs again on what changed, and new findings go into a short report.