Skip to content

Scan rule · RSC-SEC-103

Paid server function without access control

SecuritySeverity: MediumCWE-770OWASP A04-2021

Finds edge functions that call an AI model, SMS or email sending without verifying the caller or limiting volume — anyone can trigger costs on your bill.

Why this matters

AI features in Lovable, Bolt and v0 apps almost always run as a Supabase edge function: the browser calls it with the public key from the bundle, the function calls the model with your secret key. Anyone who reads the bundle can repeat that call in a loop.

Supabase's token check (`verify_jwt`) does not help: the classic public key is itself a valid token. Supabase does not rate-limit incoming edge function calls, and the Lovable AI Gateway limits per workspace, not per end user. The only barrier is the function code.

Fix: for functions behind a login, verify the user with `supabase.auth.getUser()` and return 401 without one. For public functions (a chatbot on the landing page, a contact form) add a per-IP limit and a captcha. Also set a spending limit with the provider.

Scan tier

Repo access (deep scan)

How to fix it

Verify supabase.auth.getUser() with the Authorization header at the start of the function and add a per-user or per-IP limit; protect public forms with a captcha as well.

Scan your own app for free