Bundles the 2026-07-12 code-audit session (Clusters A/B/C/D partial/E/F): denormalized Post/Advertisement reaction/comment/repost counters synced transactionally instead of live _count queries; real cursor-based pagination for followers/following/blocks lists; assertPetOwnership + formatRelativeTime centralized; dead r2.ts + AWS SDK deps removed; missing DB indexes added; account-deletion flow, mention notifications, pull-to-refresh feed, and mobile UI/i18n fixes from the surrounding sessions. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
43 lines
13 KiB
Markdown
43 lines
13 KiB
Markdown
| name | title | level | facing | categories | description | detail | remediation | metadata | cache\_key |
|
|
|
|
| ------------------------- | ------------------------- | ----- | -------- | ------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Notification\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Notification","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Notification |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.VideoPost\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"VideoPost","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_VideoPost |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Message\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Message","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Message |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.VetVisit\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"VetVisit","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_VetVisit |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Vaccine\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Vaccine","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Vaccine |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.WeightLog\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"WeightLog","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_WeightLog |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Reaction\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Reaction","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Reaction |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Comment\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Comment","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Comment |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Repost\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Repost","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Repost |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.PostHashtag\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"PostHashtag","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_PostHashtag |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Hashtag\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Hashtag","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Hashtag |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Conversation\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Conversation","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Conversation |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.HealthCard\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"HealthCard","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_HealthCard |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.EmergencyVet\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"EmergencyVet","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_EmergencyVet |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.Advertisement\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"Advertisement","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_Advertisement |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.ModerationLog\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"ModerationLog","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_ModerationLog |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.AdminRole\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"AdminRole","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_AdminRole |
|
|
|
|
| rls\_disabled\_in\_public | RLS Disabled in Public | ERROR | EXTERNAL | \["SECURITY"] | Detects cases where row level security (RLS) has not been enabled on tables in schemas exposed to PostgREST | Table \\`public.UserBan\\` is public, but RLS has not been enabled. | https://supabase.com/docs/guides/database/database-linter?lint=0013\_rls\_disabled\_in\_public | {"name":"UserBan","type":"table","schema":"public"} | rls\_disabled\_in\_public\_public\_UserBan |
|
|
|
|
| sensitive\_columns\_exposed | Sensitive Columns Exposed | ERROR | EXTERNAL | \["SECURITY"] | Detects tables exposed via API that contain columns with potentially sensitive data (PII, credentials, financial info) without RLS protection. | Table `public.HealthCard` is exposed via API without RLS and contains potentially sensitive column(s): token. This may lead to data exposure. | https://supabase.com/docs/guides/database/database-linter?lint=0023\_sensitive\_columns\_exposed | {"name":"HealthCard","type":"table","schema":"public","matched\_patterns":\["token"],"sensitive\_columns":\["token"]} | sensitive\_columns\_exposed\_public\_HealthCard |
|
|
|