<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Streatix | Audits and engineering for AI-generated code</title><description>Audits and engineering for apps built with Lovable, Bolt, Cursor, v0, and Replit Agent. New post every Tuesday and Friday.</description><link>https://streatix.com/</link><language>en</language><item><title>Our reference Lovable app leaked every user&apos;s data. The culprit was an off-by-default Supabase setting.</title><link>https://streatix.com/blog/our-reference-lovable-app-leaked-every-users-data/</link><guid isPermaLink="true">https://streatix.com/blog/our-reference-lovable-app-leaked-every-users-data/</guid><description>A war story from one of our reference apps: how a Lovable-built SaaS shipped with Supabase Row-Level Security disabled, why we didn&apos;t see it immediately, and what the three-policy fix actually looks like.</description><pubDate>Tue, 26 May 2026 09:14:32 GMT</pubDate><category>security</category><category>supabase</category><category>rls</category><category>security</category><category>lovable</category><category>multi-tenancy</category><author>Streatix</author></item><item><title>Anyone Can Forge Your Stripe Webhooks. Here&apos;s the 8-Line Fix.</title><link>https://streatix.com/blog/anyone-can-forge-your-stripe-webhooks/</link><guid isPermaLink="true">https://streatix.com/blog/anyone-can-forge-your-stripe-webhooks/</guid><description>AI code generators consistently ship Stripe webhook handlers without signature verification. Here&apos;s why, what the bug looks like, and the exact code to fix it.</description><pubDate>Fri, 22 May 2026 08:53:47 GMT</pubDate><category>security</category><category>stripe</category><category>security</category><category>webhooks</category><category>lovable</category><category>bolt</category><category>cursor</category><author>Streatix</author></item></channel></rss>