Skip to content

Deploy-readiness and security review (no code changes) - #15

Draft
macaddy2 wants to merge 1 commit into
mainfrom
cursor/deploy-readiness-review-c76a
Draft

Deploy-readiness and security review (no code changes)#15
macaddy2 wants to merge 1 commit into
mainfrom
cursor/deploy-readiness-review-c76a

Conversation

@macaddy2

Copy link
Copy Markdown
Owner

Defensive review of whether Fixars is ready to deploy in its current form.

Verdict: not ready to deploy as a public product. The root app is a high-fidelity mock (forced-off Supabase, localStorage auth and wallet) and GitHub Pages already publishes that prototype on every main push.

This PR adds only docs/deploy-readiness-security-review.md. No application code, exploits, or secret values.

Highlights:

  • Blockers: fake investment UI, Pages already live, mock auth, RLS/payment stubs unsafe if Supabase is flipped on
  • High: Pages vs Railway vs waitlist surface conflict, browser Gemini key pattern, waitlist Google Form PII, FTP publish
  • Recommended public posture: waitlist + static product/group sites only; keep the super-app private until auth, persistence, and money paths are real

Full findings, hardening suggestions, and open questions are in the report.

Open in Web Open in Cursor 

Documents why the Fixars prototype is not ready for a public product deploy, covering secrets, mock auth, Pages vs Railway overlap, and hardening suggestions without code changes.

Co-authored-by: macaddy <macaddy2@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants