I audited two AI-generated apps on the same backend. The outcomes weren’t close.
中文摘要
审计发现,使用相同后端的两个AI生成应用安全性差异巨大:一个默认安全,另一个却允许匿名用户删除生产数据。
English Summary
Auditing two AI-generated apps on the same backend revealed a huge security gap: one was secure, but the other allowed anonymous users to delete production data.
原文节选
Two AI coding tools. Same Supabase backend. One shipped secure-by-default. One allowed anonymous users to delete production data. Continue reading on Medium »