Field notes
Practical write-ups on migrating off no-code builders, securing AI-written code, and shipping products that last.
Aug 2, 2026 · 10 min read
Every Supabase key, what it does, and which ones can be public
The legacy keys are being retired, and they can no longer be rotated. Here is what replaces them, and how to tell which one you shipped.
ReadJul 27, 2026 · 5 min read
What Bubble's Security Dashboard won't fix for you
Bubble now ships a security scanner that flags your missing privacy rules. Knowing a rule is missing and knowing the right rule are different problems, and the gap between them is where a Bubble app's database stays public.
ReadJul 26, 2026 · 7 min read
What goes wrong inside Framer code components
Exposed API keys, code imported from hosts nobody recognises, and content turned into executable markup. What I look for in Framer code components, and why the safe-looking keys matter as much as the dangerous ones.
ReadJul 6, 2026 · 5 min read
Auditing an app built to be insecure
A walkthrough of a security review of a deliberately vulnerable test app: exposed secrets, an open user list, broken access control, and the findings a scanner will never catch.
ReadJun 30, 2026 · 9 min read
The security holes in AI-built apps
The access-control flaws, exposed secrets and misconfigurations I find most often when reviewing apps built on Lovable, Base44 and Replit, with real examples of what they exposed.
Read
Get them in your inbox
Be the first to read each field note. No noise, just the good stuff.
