All stacks

Cursor · Supabase RLS check

Does your Cursor app protect its Supabase data with real RLS rules?

Cursor is an AI-native code editor. It writes and edits code fast, but you're still the one wiring up hosting, environment variables, and deployment.

Database rules are flagged as not-tested on every URL scan — a connected repo scan reviews your migrations and policy files directly instead.

What we look at for Cursor

The checks that matter most for Cursor apps.

Wardloom always runs the full catalogue — these are the ones Cursor projects most often get wrong, based on how the tool tends to generate and deploy code.

Auth and session flaws

We review weak JWT secrets, missing rate limits, and insecure session patterns that show up in code and config.

Login is the front door. Soft session handling is how accounts get guessed, replayed, or shared without you noticing.

CORS and origin policy

We check whether your cross-origin rules are wide open, especially wildcards paired with credentials.

Loose CORS lets other sites call your APIs as if they were yours. Tight origin policy keeps browser traffic on the paths you meant to allow.

Env and config exposure

We look for server-only secrets used in the client, exposed dotfiles, and keys that belong behind the server wall.

AI scaffolds often put REACT_APP_ or NEXT_PUBLIC_ in front of secrets by habit. Config exposure is how private settings become public pages.

Common Cursor mistakes

What builders miss with Cursor.

  • Cursor can write correct-looking RLS policy SQL that still has a subtle logic gap a reviewer would catch by hand.
  • Auth middleware and database policies are written in different files, so a change to one is easy to forget for the other.
  • A locally-tested policy can behave differently once real user roles exist in production.

What a scan like this can't see

Wardloom is honest about its limits. Database rules (Firestore RLS, Supabase RLS) is not something a read-only scan can verify from the outside — it requires a connected repo scan or a manual review. A clean result means nothing visible was wrong, not that everything was checked.

FAQ

Questions Cursor builders ask.