UNPKG

ubon

Version:

Security scanner for AI-generated apps (Cursor, Lovable, Windsurf, v0). Catches hardcoded secrets, prompt injection, hallucinated imports, Server Actions / Edge runtime mistakes, and the vibe-coded vulnerabilities traditional linters miss.

38 lines 1.63 kB
"use strict"; Object.defineProperty(exports, "__esModule", { value: true }); const rule = { meta: { id: 'LOVABLE003', category: 'security', severity: 'medium', message: 'Anonymous authentication enabled without RLS policy validation', fix: 'Ensure RLS policies properly restrict anonymous users, or disable anonymous auth if not needed', helpUri: 'https://supabase.com/docs/guides/auth/auth-anonymous', impact: 'Anonymous users may access tables intended for authenticated users if RLS is not properly configured.' }, impl: { detect: (content, _file, _lines) => { const results = []; // Check for anonymous sign-in const anonymousAuthPattern = /signInAnonymously\s*\(|enableAnonymousSignIn\s*:\s*true/gi; let match; while ((match = anonymousAuthPattern.exec(content)) !== null) { const beforeMatch = content.substring(0, match.index); const lineNumber = beforeMatch.split('\n').length; // Check if RLS is mentioned anywhere in the file const hasRLSMention = /RLS|Row\s+Level\s+Security|auth\.uid\(\)/i.test(content); if (!hasRLSMention) { results.push({ line: lineNumber, match: match[0], confidence: 0.80 }); } } return results; }, fileTypes: ['js', 'jsx', 'ts', 'tsx'] } }; exports.default = rule; //# sourceMappingURL=LOVABLE003.js.map