01Writing · Tag
Articles tagged "supabase".
- Articles
- 11Articles
- Published
- Mar→Jul 2026Published
- Reading time
- 111 minReading time
- In series
- 3In series
Articles tagged supabase
11 articles
· 40 min · lovablesupabasevercel
How I migrated a live app off Lovable onto my own Supabase and Vercel: the full runbook
Step-by-step runbook to move a live app from Lovable to your own Supabase and Vercel, with rollback gates, real incidents, and fixes.
Read the post → Supabase Production Hardening 8/8
· 7 min · supabasesupabase-vaultpostgres
How to encrypt API keys and client secrets in Supabase
Store client secrets in Supabase Vault, keep searchable metadata in Postgres, and gate every decrypt behind one checked SECURITY DEFINER function. Step-by-step SQL with the gotchas.
Read the post → Supabase Production Hardening 7/8
· 7 min · chrome-extensionmanifest-v3supabase
How to build a Chrome extension popup with Supabase Auth (step by step)
Wire Supabase Auth into an MV3 popup: bundle the UMD, persist sessions in chrome.storage, recover state on reopen. Working code included.
Read the post → Chrome Extension Lifecycle 2/3
· 7 min · supabasesupabase-authsupabase-publishable-key
Migrating to Supabase publishable keys broke my Chrome extension. Here is the fix.
sb_publishable_* keys return 401 from hand-rolled fetch. Migration to @supabase/supabase-js plus a chrome.storage.local session adapter for Manifest V3. 158 lines of HTTP became 67.
Read the post → Claude Code Engineering 7/9
· 9 min · lovablelovable-securitysupabase
How to audit a Lovable app after the BOLA disclosure: a 6-hour rotation playbook
Audit a Lovable app after the BOLA disclosure: exposure checks, Supabase key rotation, Chrome extension SDK migration, and pre-revoke verification.
Read the post → Claude Code Engineering 6/9
· 7 min · supabasesupabase-realtimesecurity
Realtime broadcast scope is a security boundary, not a routing convenience
Default-public Realtime broadcasts leak message bodies to every subscriber. The private-channel flag plus RLS is the fix.
Read the post → Supabase Production Hardening 6/8
· 6 min · securitysupabaseauth-jwt
User enumeration via password reset: the bug in default forgot-password flows
Most forgot-password endpoints leak whether an email exists. Fix: return the same response always, regardless of account status.
Read the post → Supabase Production Hardening 5/8
· 7 min · securitysupabaseedge-functions
Origin validation in edge functions: the open redirect you ship by default
Edge functions that trust the Origin or Referer header for redirect URLs are open-redirect vulnerable. One allowlist helper closes the gap.
Read the post → Supabase Production Hardening 4/8
· 8 min · postgressupabasepostgres-triggers
How to build a tamper-evident audit log in Postgres with one trigger
Build an audit log table, attach a SECURITY DEFINER trigger that captures every UPDATE and DELETE, lock it down with RLS. Forty lines of SQL.
Read the post → Supabase Production Hardening 3/8
· 6 min · supabasepostgrestpostgres
How a Postgres constraint rename silently broke production via PostgREST
PostgREST resolves onConflict against real constraint names at runtime. Rename a constraint and the upsert silently fails with a 400 nobody notices.
Read the post → Supabase Production Hardening 2/8
· 7 min · supabasesupabase-authpostgres
Two-layer identity models in Supabase: when auth and authorization disagree
Supabase Auth creates identities, not roles. Use a user_roles table, RLS policies, and one trigger migration so signups never strand users without permissions.
Read the post → Supabase Production Hardening 1/8
No articles match that filter
Try a broader term, turn off “Under 10 min”, or browse a related tag below.
02Narrow it down
Tags that appear alongside this one.
03Read in order