The Firestore vulnerability found in Arc is likely widespread
venki.dev
venki.dev
Supabase support's defense is "well, if you read the manual you'll understand how to set this up properly", but that's not how bootcamp developers tend to work.
I spent 10 minutes seeing if I could convince google or kagi to search for sites like these, but unfortunately js isn't searchable in either.
https://supabase.com/docs/guides/database/postgres/row-level...
ie: The "Update Policies" DSL ensures that the user does not change the user id of a row
IMO, the easiest and most secure thing is to not do direct DB reads and writes from your client. Use a traditional client-server architecture and have your server talk to the DB.
The times I do use the Firestore client library, it's only for reading and only for the realtime updates. My security rules disallow all writes.
Of course, that was 2021 and I had barely started programming. Not sure if I’d make the same mistake now (of using Firestore in the first place :)
Making all your documents have a `owner_uid` or `userId` field is just a convention they recommend, because it helps you write rules.
So rather: they have no default system for handling documents that can only be accessed by a given user, but rather you have to construct it using `firestore.rules`, and you end up with something oddly default-insecure.