Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Cinnamoroll Soft Toy – Cute & Cuddly Plush
anil1961
Updated:
Yesterday at 4:59 AM
Google Pixel 9 Pro
vgp
Updated:
Thursday at 5:57 PM
Ad icon
Jobreceive.com for sale
Blogerwiki
Updated:
Sep 29, 2026
Post Your Vehicle for Sale — FREE! - https://libro.lk
Kalu_Puth
Updated:
Sep 29, 2026
ඔයාගෙ Assignment හෝ Thesis එක හරියට හදාගමු
ErMurazor
Updated:
Sep 26, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
ට ඉකෙන AI prompt එකක්
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="topkollek" data-source="post: 31582790" data-attributes="member: 510150"><p>Vibe-coded apps වල security එක ගැන කතාවක්. මේක “AI එකෙන් app එකක් හදන එක භයානකයි” කියන panic post එකක් නෙවෙයි. ප්රශ්නය මෙහෙමයි: prompt කරලා run වුණාම ඒක secureද කියලා බලන්නේ නැතුව deploy කරනවා නම්, vulnerable apps internet එකට යනවද?කෙටියෙන් කිව්වොත් — ඔව්. දැනටමත් යනවා.Vibe coding කියන්නේ මොකක්ද කියලා දන්නේ නැත්නම්: Cursor, Claude Code, Lovable, Replit, Bolt වගේ tools වලින් “මේක හදපන්” කියලා කියලා, code එක හොඳට කියවලා review කරන්නේ නැතුව, වැඩ කරනකම් prompt කරලා ship කරන style එක. Model එකට ඕනේ “it works.” ඒකට “මේ data එක ownerට විතරක් පේනවද” කියන එක automatically එන්නේ නැහැ.ඒ නිසා නැවත නැවත එන issues:</p><ul> <li data-xf-list-type="ul">Authentication නැති endpoints</li> <li data-xf-list-type="ul">Broken access control (අනිත් userගේ data බලන්න/වෙනස් කරන්න පුළුවන්)</li> <li data-xf-list-type="ul">Frontend එකේ හෝ repo එකේ hardcoded API keys, JWT secrets, DB passwords</li> <li data-xf-list-type="ul">Supabase/Firebase tables වල row-level security නැතිව public</li> </ul><p>මේක තවම theory එකක් නෙවෙයි.RedAccess කණ්ඩායම Lovable, Replit, Base44, Netlify වගේ platforms වල vibe-coded apps scan කරලා බැලුවා. දහස් ගාණක් apps තියෙනවා authentication එකක් වගේ දෙයක්ම නැතිව. ඒකෙන් 5,000කට වගේ sensitive දේවල් leak වෙනවා — medical records, financials, strategy decks, chatbot transcripts, hospital staffing data වගේ. WIRED සහ Axios ඒ examples කිහිපයක් verify කරලා තියෙනවා.2026 academic audit එකක deployed vibe-coded web apps manually review කරලා බැලුවා. Sample එකේ 90%ක vulnerabilities තිබුණා. වැඩිම category එක broken access control. ඒ apps වලින් තුනෙන් දෙකකට වඩා ඒ issue එක තිබුණා.වෙන scans වලත් එකම ලේසි අඩුපාඩු පේනවා: එකම default JWT secret එක දහස් ගාණක් apps වල reuse වෙන එක, auth නැතුව delete/update කරන්න පුළුවන් APIs, public database tables.Companies ටත් මේක දන්නවා. ඒත් ship කරනවා. Checkmarx 2026 survey එකේ කියන්නේ AI වලින් code ගොඩක් generate කරන teams, අඩුවෙන් use කරන teams වලට වඩා vulnerable code ship කරන එක ගොඩක් වැඩියි කියලා. Delivery pressure එකට known-bad code එකක් deploy කරනවා කියලා කියන අයත් ඉන්නවා.මේක elite hacking කතාවක් නෙවෙයි. පරණ open S3 bucket wave එකට ලංවෙන දෙයක්. Marketing හෝ ops කෙනෙක් internal tool එකක් හදලා real data connect කරලා URL එක web එකේ තියනවා. /api/users එකේ auth නැත්නම් attackerට අලුත් exploit එකක් ඕනේ නැහැ.ඒ කියන්නේ AI use කරලා app හදන හැම කෙනෙක්ම අවුල් කියලා නෙවෙයි. අදහස මෙහෙමයි: “tool එක කිව්වා නේද වැඩ කරනවා කියලා” කියලා ඒක security review එකක් වගේ හිතන එක භයානකයි. Auth, tenancy, secrets බලන human review එක තාම gate එක. Model එක ඒක ඔයා වෙනුවෙන් කරන්නේ නැහැ.Deploy කරන්න කලින් අඩුම ගානේ මේ තුන බලන්න:</p><ol> <li data-xf-list-type="ol">මේ endpoint එකට login නැතුව hit කරන්න පුළුවන්ද?</li> <li data-xf-list-type="ol">User Aට User Bගේ record එක වෙනස් කරන්න පුළුවන්ද?</li> <li data-xf-list-type="ol">API keys / DB passwords source එකේ හෝ browser bundle එකේ තියෙනවද?</li> </ol><p>ඒ තුන pass උනේ නැත්නම්, app එක “වැඩ කරනවා” විතරයි. Safe නෙවෙයි.</p><p></p><p>මම ගොරොක්</p></blockquote><p></p>
[QUOTE="topkollek, post: 31582790, member: 510150"] Vibe-coded apps වල security එක ගැන කතාවක්. මේක “AI එකෙන් app එකක් හදන එක භයානකයි” කියන panic post එකක් නෙවෙයි. ප්රශ්නය මෙහෙමයි: prompt කරලා run වුණාම ඒක secureද කියලා බලන්නේ නැතුව deploy කරනවා නම්, vulnerable apps internet එකට යනවද?කෙටියෙන් කිව්වොත් — ඔව්. දැනටමත් යනවා.Vibe coding කියන්නේ මොකක්ද කියලා දන්නේ නැත්නම්: Cursor, Claude Code, Lovable, Replit, Bolt වගේ tools වලින් “මේක හදපන්” කියලා කියලා, code එක හොඳට කියවලා review කරන්නේ නැතුව, වැඩ කරනකම් prompt කරලා ship කරන style එක. Model එකට ඕනේ “it works.” ඒකට “මේ data එක ownerට විතරක් පේනවද” කියන එක automatically එන්නේ නැහැ.ඒ නිසා නැවත නැවත එන issues: [LIST] [*]Authentication නැති endpoints [*]Broken access control (අනිත් userගේ data බලන්න/වෙනස් කරන්න පුළුවන්) [*]Frontend එකේ හෝ repo එකේ hardcoded API keys, JWT secrets, DB passwords [*]Supabase/Firebase tables වල row-level security නැතිව public [/LIST] මේක තවම theory එකක් නෙවෙයි.RedAccess කණ්ඩායම Lovable, Replit, Base44, Netlify වගේ platforms වල vibe-coded apps scan කරලා බැලුවා. දහස් ගාණක් apps තියෙනවා authentication එකක් වගේ දෙයක්ම නැතිව. ඒකෙන් 5,000කට වගේ sensitive දේවල් leak වෙනවා — medical records, financials, strategy decks, chatbot transcripts, hospital staffing data වගේ. WIRED සහ Axios ඒ examples කිහිපයක් verify කරලා තියෙනවා.2026 academic audit එකක deployed vibe-coded web apps manually review කරලා බැලුවා. Sample එකේ 90%ක vulnerabilities තිබුණා. වැඩිම category එක broken access control. ඒ apps වලින් තුනෙන් දෙකකට වඩා ඒ issue එක තිබුණා.වෙන scans වලත් එකම ලේසි අඩුපාඩු පේනවා: එකම default JWT secret එක දහස් ගාණක් apps වල reuse වෙන එක, auth නැතුව delete/update කරන්න පුළුවන් APIs, public database tables.Companies ටත් මේක දන්නවා. ඒත් ship කරනවා. Checkmarx 2026 survey එකේ කියන්නේ AI වලින් code ගොඩක් generate කරන teams, අඩුවෙන් use කරන teams වලට වඩා vulnerable code ship කරන එක ගොඩක් වැඩියි කියලා. Delivery pressure එකට known-bad code එකක් deploy කරනවා කියලා කියන අයත් ඉන්නවා.මේක elite hacking කතාවක් නෙවෙයි. පරණ open S3 bucket wave එකට ලංවෙන දෙයක්. Marketing හෝ ops කෙනෙක් internal tool එකක් හදලා real data connect කරලා URL එක web එකේ තියනවා. /api/users එකේ auth නැත්නම් attackerට අලුත් exploit එකක් ඕනේ නැහැ.ඒ කියන්නේ AI use කරලා app හදන හැම කෙනෙක්ම අවුල් කියලා නෙවෙයි. අදහස මෙහෙමයි: “tool එක කිව්වා නේද වැඩ කරනවා කියලා” කියලා ඒක security review එකක් වගේ හිතන එක භයානකයි. Auth, tenancy, secrets බලන human review එක තාම gate එක. Model එක ඒක ඔයා වෙනුවෙන් කරන්නේ නැහැ.Deploy කරන්න කලින් අඩුම ගානේ මේ තුන බලන්න: [LIST=1] [*]මේ endpoint එකට login නැතුව hit කරන්න පුළුවන්ද? [*]User Aට User Bගේ record එක වෙනස් කරන්න පුළුවන්ද? [*]API keys / DB passwords source එකේ හෝ browser bundle එකේ තියෙනවද? [/LIST] ඒ තුන pass උනේ නැත්නම්, app එක “වැඩ කරනවා” විතරයි. Safe නෙවෙයි. මම ගොරොක් [/QUOTE]
Insert quotes…
Verification
Nawa warak dahaya keeyada? (Namaya wadi kireema dahaya)
Post reply
Top
Bottom