Deep check · specimenHullCheck
saltmarsh-tasks.example
- FAILTable
profilesreadable without login RLS disabled · 3 of 9 tables open - FAIL
service_rolekey in/assets/index-4c1e.js - PASSNo source maps published
- PASSStorage bucket
avatarsnot listable - FAILNo Content-Security-Policy header
Fix prompt · finding 1 · paste into your agent
Enable Row Level Security on public.profiles. Add a SELECT policy so a signed-in user can read only the row where id = auth.uid(). Don't change the app's queries.