- Code review
- Read the whole repository: frontend, six edge functions and all migrations.
- Database
- Compared schema, policies and functions in the live project with the migrations. There were no differences.
- Test accounts
- One account per role (patient, therapist, practice admin) on a copy of the project. With each one, deliberately tried to read and change other people's data.
- Shipped code
- Searched the JavaScript that ends up in the browser for keys, secrets and internal addresses.
- Tools
- npm audit, the Supabase security advisor and my own scripts that test every policy with every role.
- Configuration
- The settings of Supabase Auth, Storage, Stripe and Twilio, with read access.