Every time I presented my work,
something seemed off to my uncle he would point out another detail
I’d change it, and then uncover another flaw
It taught me my first lesson in web design: What feels “finished” to us is not the same as being truly ready.
#BuildInPublic
I was slowly learning that building a website wasn't just technical
It was visual problem-solving too
The logo was only the beginning
By the time i had reached my Final Destination
I had Created 31 Logos which were not up to the mark
Finally, I decided to present the Logo
The first thing we needed was a Proper logo
I went back to drawing Board—ChatGPT
We generated ideas, tried different colours, rejected versions and kept changing things.
It wasn't one prompt and done.
It was:
create → look → reject → change → repeat.
#BuildInPublic
Finally I had a website
But
there was an obvious problem
It looked like something I had built—not something a business should present
I had the colours, content and structure.
I just didn't know how to make it look like a Professional website
So the learning started again
I kept experimenting, changing prompts, watching what appeared on screen.
The biggest surprise?
I didn't need to know every line of code.
I needed to learn how to explain what I wanted.
I had tried Shopify Before
but
This was a completely new way of building
#BuildInPublic
The experiment worked
Lovable could actually turn my instructions into a Proper website
That was the moment things changed for me
I started thinking:
“Wait… if I can describe exactly what I want, maybe I can actually build this.”
Now I wanted to see how far I could take it
Started with my free Lovable credits
I started with something simple
No big website. No fancy features
Just basic Prompting.
Typed in whatever I wanted on the website, it was a big Paragraph of about 150 words..
I wanted to understand
Could I actually build with Lovable?
What did i do next?
Ask my guru, my mentor, my teacher
ChatGPT.
"what the hell is Lovable, and how does it work?”
Learned the basics, logged in, and got a few free credits to experiment
I wasn't trying to build a perfect website
Just wanted to see what this thing could do
Uncle already give me ideas, content and direction for the app he wanted
Now I had a completely new mountain to climb
I could understand what he wanted the website to do
But I had never built one before
Technically
I had to figure it out everything from 0.
#BuildInPublic
I had no clue how to design a website
But,
I had never built an app before either
I only heard from random reels that Lovable was good option
I tried Claude
It wasn't what I expected
I thought of putting website on hold but even my uncle said, “Build the website first”
While I was building the app,I realized something
If I wanted anyone to understand what I was actually creating, I needed somewhere to show it
So I started building a website too—with Lovable
It wasn't going to be just a website
It had to explain the product
#BuildInPublic
I had to find out how the leak happened.
The views were SECURITY DEFINER and still had public grants
We revoked anonymous access on both
The app kept working because it reads them server-side
Then we re-verified the fix
Finally, the leak was closed
Phew! Peace vibes😎
The two Problems on hands was actually
"Same-Same but Different"
“The first occurrence of a pattern is a bug;
the second and third are a process failure.”
#BuildInPublic
It exposed a process problem
A database object can be correctly protected by app's code and still be exposed if the database itself grants public access
This incident became more important later bcoz the same underlying pattern appeared again with newly created database objects
We did it on 27 July
Importantly,the app itself didn't break because it accessed these views server-side,rather than directly from the browser
Then the access was re-verified in August to make sure the exposure hadn't returned
New lesson
This wasn't about two database views
How we solved it
Spotted Supabase Security Advisor,questioned why they were flagged
Investigation caused a finding to be reclassified from medium to critical after actual access path was examined
The fix was simple and targeted
Revoke the anonymous/public grants on both views
The bigger issue was they had the default public grants Supabase applies to new database objects
The public key used by the website could read them without logging in
Exposed information had manager ids, emails, phone numbers, licences, expiry dates & risk levels across stores
The two exposed database views were
v_store_license_summary
v_alert_engine_feed
They were suppose to be used internally by the app
But both created as SECURITY DEFINER views,
meaning they ran with the owner's database privileges bypassing normal row-level security protections
The security audit found another problem
Two database views were publicly readable with just the site's public key
They exposed manager names,emails, phone numbers, licence numbers, expiry dates and risk levels for every store
No login required
I was spiraling
#BuildInPublic
After every major Built
We should Test it. Verify it. Test it again.
So we made the necessary changes, we re-verified the protection in the live code.
Ran the Security Check .
And,
We smashed it
Another vulnerability closed.
Another Bullet dodged..
#BuildInPublic