The exact mechanism that ships secret keys to the browser in AI-built apps, and the 5-minute grep that catches it before launch.
Someone found your anon key in the bundle. Is that a breach? Here's what the anon key actually grants, and the RLS mistake that turns it into one.
A working checklist for Supabase security: RLS policies, anon keys, service role leaks, and the mistakes I keep finding in AI-built apps.