Secure account access
Authentication, dashboard protection, confirmation flows and redirects were reviewed. Login and signup authentication errors were also changed to use generic messages rather than exposing raw authentication errors in redirect URLs.
User-scoped financial data
Supabase Row Level Security policies were reviewed across accounts, categories, transactions, financial profiles, expenses, credit cards and loans. Update policies also prevent ownership reassignment.
Protected PDF processing
The authenticated extraction endpoint checks the PDF extension and file signature, limits uploads to 25 MB, uses temporary processing directories, restricts the child process environment, limits extractor output and applies a 120-second timeout.
Extraction concurrency is limited to two processes per server process, with cleanup performed in a finalization path.
Controlled extraction results
Extracted data is bounded before downstream processing, including limits on transaction count, description length, raw source lines and diagnostic notes. These controls reduce the risk of oversized extraction results consuming excessive resources.
Secrets and environment protection
The security review found no service-role, admin or secret Supabase key references in the reviewed app, library or script code. Environment files are ignored by Git, with only the example environment file tracked.
Browser security headers
Baseline browser security headers are applied, including X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
Dependency and code checks
The review included TypeScript checking, a production build, dependency auditing and scans for dangerous runtime execution, HTML injection and exposed secret-key references. The reported dependency audit found zero vulnerabilities.
Redirect safety
Authentication confirmation redirects restrict the destination to permitted internal paths and reject external-style paths beginning with double slashes.