Security Is Your Responsibility
BaaS platforms handle infrastructure security, but application-level security is still on you.
The Checklist
1. Row-Level Security (RLS)
Ensure every table has proper RLS policies. Without them, any authenticated user can read all data.
2. API Key Exposure
Never expose service-role keys in client-side code. Use anon keys with RLS instead.
3. Input Validation
Validate all user inputs on both client and server side.
4. Authentication Flows
Test edge cases: expired tokens, concurrent sessions, password reset flows.
5. File Upload Security
Restrict file types, sizes, and scan for malware where possible.
6. Rate Limiting
Implement rate limiting on auth endpoints and API calls.
7. CORS Configuration
Restrict allowed origins to your actual domains.
8. Data Encryption
Ensure sensitive data is encrypted at rest and in transit.
9. Audit Logging
Track who accessed what and when.
10. Dependency Updates
Keep your BaaS SDK and all dependencies up to date.
Conclusion
Security isn’t a feature you add at the end — it’s a practice you maintain throughout development.