Who your app believes
Added
- Admin rights from editable profilesFlags code that picks admins or paid plans from profile data users can change themselves, such as Supabase
user_metadataor ClerkunsafeMetadata. - Sign-ins nobody checksFlags server code that trusts
getSession()or a self-decoded token and then skips row-level security, so a made-up cookie could pose as anyone. - Fake sign-in eventsFlags Clerk webhooks that create, change or delete users in your database without checking Clerk's signature.
- Strangers on your AI billFlags endpoints that send what a visitor types to a paid AI model with no sign-in and no rate limit.
- The browser picks the modelFlags AI calls where the request chooses the model or the maximum answer length.
- A fix kit for eachEvery new finding comes with steps for Supabase, Clerk and hand-built sign-ins, code to copy, and a way to test the fix.
Improved
- Report lines for the new checksA report that ran the code checks now says in plain words when none of the five problems was found.
- The answer card names its checkOn a phone, the card under a release map names the check it answers. The 1.15 map shows the two new code checks.
- Pages and middleware are read tooThe new checks also follow Server Component pages, Next.js middleware and tRPC procedure middleware, and apps whose only server code is their Supabase migrations.
Fixed
- Clerk's default middleware is understoodRoutes protected with the matcher from Clerk's setup guide now count as protected in the access check.