User
Write something
New Resource Added: Make Money by Jack
I genuinely believe that if you read this, it will completely upgrade your mindset. This isn’t about shortcuts or hype. It’s about: - how money actually works - how value is created - and why most people stay stuck thinking small - If you’re serious about entrepreneurship, leverage, and long-term thinking — this is a must-read. 📌 Resource:👉 https://www.skool.com/shipping-vibe-coder-5394/classroom/1b315f79?md=b1241f8b29d844878e6e0f68da084b3f
0
0
New Resource Added: Make Money by Jack
Convex vs Supabase DB decision??
If you're about to build a new app, read this first. (The wrong Convex vs Supabase decision could cost you 6 months of rebuilding) The secret? These platforms solve COMPLETELY different problems. --- 𝗧𝗵𝗲 𝗽𝗿𝗼𝗯𝗹𝗲𝗺 𝗺𝗼𝘀𝘁 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿𝘀 𝗳𝗮𝗰𝗲: You spend weeks setting up real-time sync. You write custom WebSocket logic for every feature. You fight authentication bugs constantly. Still breaks in production. Still costs more than expected. Still scales worse than promised. Why? Because you picked based on a random tweet. --- 𝗛𝗲𝗿𝗲'𝘀 𝘁𝗵𝗲 𝗿𝗲𝗮𝗹 𝗱𝗶𝗳𝗳𝗲𝗿𝗲𝗻𝗰𝗲: → Convex = Real-time apps made easy → Supabase = SQL power with modern features Pick the wrong one = major technical debt. --- 𝗖𝗼𝗻𝘃𝗲𝘅 — 𝗧𝗵𝗲 𝗥𝗲𝗮𝗹-𝗧𝗶𝗺𝗲 𝗠𝗮𝗰𝗵𝗶𝗻𝗲: What you get: → Real-time updates BY DEFAULT (no WebSocket setup) → TypeScript-native everything → Custom reactive document database → Client + backend fully open source Pricing: → Free tier for hobby projects → ~$25/member/month for Pro → Startup program = up to 1 YEAR FREE Best for: Collaborative apps, TypeScript teams, real-time features. --- 𝗦𝘂𝗽𝗮𝗯𝗮𝘀𝗲 — 𝗧𝗵𝗲 𝗣𝗼𝘀𝘁𝗴𝗿𝗲𝗦𝗤𝗟 𝗣𝗼𝘄𝗲𝗿𝗵𝗼𝘂𝘀𝗲: What you get: → Full PostgreSQL database (SQL power) → Complete ecosystem: auth, storage, realtime, edge functions → 100% open source → Self-hostable Pricing: → Free tier with 2 projects → $25/month Pro plan with 8GB database → $599/month Team with SOC2/HIPAA compliance Best for: SQL-first teams, enterprise requirements, traditional database needs. --- 𝗧𝗵𝗲 𝗸𝗲𝘆 𝗱𝗲𝗰𝗶𝘀𝗶𝗼𝗻 𝗳𝗿𝗮𝗺𝗲𝘄𝗼𝗿𝗸: Choose Convex if: → Real-time is your core feature → You hate backend complexity → TypeScript-first team → Building collaborative/multiplayer apps Choose Supabase if: → You need SQL power + relations → Enterprise compliance is required → Traditional database structure preferred → Existing SQL expertise on team --- 𝗧𝗵𝗲 𝗿𝗲𝗮𝗹 𝗹𝗲𝘀𝘀𝗼𝗻: Stop picking backends based on hype. Start picking based on: → Your app's core needs → Your team's skillset → Your growth trajectory --- 95% will pick their backend based on a random tweet.
Convex vs Supabase DB decision??
Query RSS feed
I want to poll a RSS feed every minute and have it only pick up the new items since the last poll to avoid any duplicates. Is there any python library that can do this or would I need to code this on the client side itself?
8 Security Mistakes That Can Hack Your SaaS
The biggest problem with 𝘃𝗶𝗯𝗲 𝗰𝗼𝗱𝗶𝗻𝗴 isn't speed. It's 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆. (And here's how to fix it in 𝟴 𝘀𝘁𝗲𝗽𝘀) Last month, a builder launched their SaaS. Within 24 hours: → Bots hit their signup endpoint 10,000 times → Database crashed → $300 in Supabase costs All because they shipped fast but forgot security. --- 𝗧𝗵𝗲 𝗽𝗿𝗼𝗯𝗹𝗲𝗺 𝘄𝗶𝘁𝗵 𝘃𝗶𝗯𝗲 𝗰𝗼𝗱𝗶𝗻𝗴: Your MVP works great in development. But launch day is when the real world finds your weak spots. Cursor moves fast. Security doesn't come built-in. --- 𝗛𝗲𝗿𝗲'𝘀 𝘁𝗵𝗲 𝟴-𝘀𝘁𝗲𝗽 𝗹𝗮𝘂𝗻𝗰𝗵 𝗰𝗵𝗲𝗰𝗸𝗹𝗶𝘀𝘁: 𝟭. 𝗥𝗮𝘁𝗲 𝗹𝗶𝗺𝗶𝘁 𝘆𝗼𝘂𝗿 𝗲𝗻𝗱𝗽𝗼𝗶𝗻𝘁𝘀 → Supabase Edge Functions + rate limiter → Vercel Middleware → Next.js IP throttling Skip this = bots hit you 100x/second. 𝟮. 𝗘𝗻𝗮𝗯𝗹𝗲 𝗥𝗼𝘄-𝗟𝗲𝘃𝗲𝗹 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 (𝗥𝗟𝗦) → Turn on RLS on every Supabase table → Use policies: user_id = auth.uid() No RLS = users can query other people's data. 𝟯. 𝗔𝗱𝗱 𝗖𝗔𝗣𝗧𝗖𝗛𝗔 𝘁𝗼 𝗮𝘂𝘁𝗵 𝗳𝗹𝗼𝘄𝘀 → Signup forms → Login pages → Forgot password AI bots can generate 1000s of fake signups in minutes. 𝟰. 𝗘𝗻𝗮𝗯𝗹𝗲 𝗪𝗔𝗙 (𝗪𝗲𝗯 𝗔𝗽𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗙𝗶𝗿𝗲𝘄𝗮𝗹𝗹) → Vercel → Settings → Security → WAF → Enable "Attack Challenge" on all routes 1 click. No code. Blocks bad traffic instantly. 𝟱. 𝗦𝗲𝗰𝘂𝗿𝗲 𝘆𝗼𝘂𝗿 𝗔𝗣𝗜 𝗸𝗲𝘆𝘀 → Store in .env files → Use server-only functions → Scan AI-generated code (it often forgets this) If it runs on the client, assume it's public. 𝟲. 𝗩𝗮𝗹𝗶𝗱𝗮𝘁𝗲 𝗮𝗹𝗹 𝗶𝗻𝗽𝘂𝘁𝘀 𝗼𝗻 𝘁𝗵𝗲 𝗯𝗮𝗰𝗸𝗲𝗻𝗱 → Emails, passwords, uploads → Custom form inputs → API payloads Don't trust the frontend. Ever. 𝟳. 𝗖𝗹𝗲𝗮𝗻 𝘂𝗽 𝗱𝗲𝗽𝗲𝗻𝗱𝗲𝗻𝗰𝗶𝗲𝘀 → Run npm audit fix → Remove unused packages → Check for critical vulnerabilities Cursor moves fast. It doesn't clean up after itself. 𝟴. 𝗔𝗱𝗱 𝗺𝗼𝗻𝗶𝘁𝗼𝗿𝗶𝗻𝗴 + 𝗹𝗼𝗴𝘀 → Supabase Logs → Vercel Analytics → Track failed logins, traffic spikes, 500s You can't fix what you can't see. --- 𝗕𝗼𝗻𝘂𝘀: 𝗔𝗜 𝗰𝗼𝗱𝗲 𝗿𝗲𝘃𝗶𝗲𝘄𝘀 Before you push, run CodeRabbit inside Cursor. It catches security flaws, performance issues, and bad logic. Like a senior dev reviewing your entire codebase. --- 𝗧𝗵𝗲 𝗯𝗼𝘁𝘁𝗼𝗺 𝗹𝗶𝗻𝗲: Cursor lets you code fast.
1
0
8 Security Mistakes That Can Hack Your SaaS
Claude Sonnet 4.5 system prompt leaked
https://github.com/elder-plinius/CL4R1T4S/blob/main/ANTHROPIC/Claude_Sonnet-4.5_Sep-29-2025.txt
1-30 of 32
powered by
Shipping Vibe Coder
skool.com/shipping-vibe-coder-5394
Welcome to Shipping Vibe Coder.
Build your own community
Bring people together around your passion and get paid.
Powered by