Code Review That Understands Supabase
Generic review tools read Supabase code as ordinary database calls. The mistakes that actually break Supabase apps are specific: a missing row-level security policy, a service-role client reachable from a user request, a column that should never be writable from the browser.
The Supabase mistakes we look for
- Tables exposed through the Data API with row-level security disabled or no policy attached.
- Service-role or admin clients used inside endpoints a signed-in user can reach.
- Privilege escalation through fields like role written straight from the request body.
- Policies that reference user-controlled values instead of auth.uid().
- Missing grants that make a table unreachable, or grants wider than the policies intend.
- Storage buckets and edge functions left open when they should require a session.
A real example
In our sample review, a profile update endpoint writes email and role from the request body, then calls the admin auth API. The first reviewer catches the role escalation, the noisy error log and the missing input validation.
The second reviewer confirms those three and adds the one that matters most: the admin call uses the service role from a user-facing route. That finding is what the dual pass exists for.
Works alongside your Supabase workflow
Reviews run on pasted code or on GitHub pull requests, including migrations and edge functions. Findings come with before/after suggestions you can apply directly.
Frequently asked questions
Do you connect to my Supabase project?
No. CodeSightAI reviews your code, not your live database. Nothing is read from or written to your Supabase project.
Does it review SQL migrations?
Yes. Migrations in a reviewed pull request are analysed like any other change, including policy and grant statements.
Is Supabase all you support?
No. Supabase is a specialisation. The same dual-AI review works on any language or stack.
Free plan available. No credit card required.