← Joburi

Backend Security & Architecture Audit (RLS, Auth, Edge Functions)

Buget: $1000.0 FIXED / ⭐ 5.00 (1) USA

postgresql, typescript, react-js, information-security-audit, stripe, user-authentication, amazon-web-services, web-programming, api

Preferred qualifications

  • Experience: Expert
  • English: Fluent
  • Job Success: 90%+
  • Rising Talent preferred
We run a live, production biomedical research platform (React/Vite/TypeScript on Vercel, multiple Supabase projects — Postgres with RLS, ~40 edge functions in Deno/TypeScript, Clerk authentication shared across subdomains, Stripe payments, Resend email, PostHog analytics). The product is in beta testing right now with real users, and is heading toward paid plans. Before we start charging, we want a professional second set of eyes on everything — and then we want the problems actually fixed, not just listed. This is a two-phase engagement: (1) audit → written report, (2) optionally, you fix the findings we approves. Phase 2 is not guaranteed: after the report is delivered, we either end the engagement there or — based on the quality of the findings extend it for you to implement the fixes. Phase 1 deliverable: a written audit report, severity-ranked, with reproduction steps, a recommended fix for each finding, and an effort estimate per fix. Scope: Row-Level Security coverage across all tables in 3 Supabase projects: missing policies, over-permissive policies, INSERT/UPDATE/RETURNING edge cases, SECURITY DEFINER functions. Authentication boundaries: Clerk ↔ Supabase integration, session handling across subdomains, webhook security, account-deletion data cascade. Edge function review: input validation, secret handling, rate limiting, error handling that could leak information. Payment flow: Stripe webhook verification, registration/payment sync integrity. Data integrity: destructive writes, orphaned records, migration hygiene. Anything else that would embarrass us in front of a paying customer. We want real findings, not a linter dump. Phase 2 — remediation: after the report we will reviews it with you on a call and approves or declines each finding. You then implement ONLY the approved fixes: each fix as a pull request against our repos, with tests where applicable and a plain-English description of what changed and why. Nothing merges without approval; deploys follow our process. Fixes are developed against dev/branch environments. For the audit you'll get read access to the repos and a dev/branch database environment; for approved fixes you'll get write access via pull requests only. Production credentials are not part of this engagement.
Deschide pe Upwork

AI proposal draft

Generate a short cover letter for this job. Edit before sending.

Sign in to generate an AI proposal draft.

Autentificare