r/webdev 🛠 Dev 👁 0

supabase auth: your captcha, rate limiting, and email validation are all useless if someone curls the endpoint directly. learned this the hard way

built my SaaS. added turnstile captcha. added email validation. added rate limiting. felt secure. then someone created 200 accounts by curling supabase's /auth/v1/signup with my anon key. which is public. in my frontend

📄

This source provides headlines only. Use the button below to read the complete article on the original site.

📰 Read the original article on r/webdev

Originally published by r/webdev. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.