I’m building Boundary, an experimental local checker for a specific file and document record in a supported Supabase staging project.
The workflow is deliberately narrow: check access as the owner, another customer and someone signed out, then rerun the same checks after changes. It requires two ordinary test accounts, synthetic data and Node.js 22+. It is not a full security audit or a guarantee that an application is secure.
Try the two-customer demo. The demo uses synthetic data; it is not evidence from a customer deployment.
If you already maintain these tests, what does your current setup handle well, and what is still tedious? I’d especially appreciate examples where another tool like this would add nothing. Existing pgTAP or integration tests may already cover your needs.
Please keep examples non-sensitive—no credentials, private records or production access needed.
Lians is developing Boundary, a tool for performing repeatable file-access checks in Supabase staging projects. The tool checks access as different user roles and reruns checks after changes. Lians seeks feedback on existing setups and how this tool might complement or duplicate current testing methods.