Antelier/ journeys
2026-09-08 11:39 UTC
JOURNEY REPORT · QuickNotes · https://swift-note-gem.lovable.app · 2026-09-08 11:39 UTC

5 of 5 journeys passed · no high findings in a partial access audit · no repair prepared yet

No action is needed for these 5 journeys. The access audit at 2026-09-08 04:14 UTC found no high findings; it could not check live database permissions, and says what it left out under Access findings. Every line below links to what was observed. Deterministic, re-runnable, no model involved.

Since the last run

Compared with 2026-09-08 11:18 UTC.

Finding resolution not checked: audit coverage is incomplete, unrecorded or changed.

Screenshot pixels differ from the previous run on 26 steps (dates, cursors and avatars change between runs; not counted as changes).

Journeys

passeda new customer signs up and lands on their notesnewly passing
as user d · 7 steps
1 · open /auth
passed
2 · click Sign up
passed
3 · fill Email
passed
4 · fill Password
passed
5 · click Continue
passed
6 · url matches /notes
passed
7 · text "Your first note is one line away"
passed
Step 1 of 7
passeda note is saved and still there after a reload
as user a · 12 steps
1 · open /auth
passed
2 · fill Email
passed
3 · fill Password
passed
4 · click Continue
passed
5 · url matches /notes
passed
6 · click New note
passed
7 · fill Title
passed
8 · fill Text
passed
9 · click Save
passed
10 · text "Antelier check 20260908113957"
passed
11 · reload page
passed
12 · exactly 1 visible matches for "Antelier check 20260908113957"
passed
Step 1 of 12
passeda signed-out visitor is sent to sign in
as a signed-out visitor · 2 steps
1 · open /notes
passed
2 · url matches /auth
passed
Step 1 of 2
passedanother user does not see that note
as user b · 7 steps
1 · open /auth
passed
2 · fill Email
passed
3 · fill Password
passed
4 · click Continue
passed
5 · url matches /notes
passed
6 · text "Your first note is one line away"
passed
7 · no visible text "Antelier check 20260908113957"
passed
Step 1 of 7
passedthe new customer deletes their account and cannot sign in again
as user d · 18 steps
1 · open /auth
passed
2 · fill Email
passed
3 · fill Password
passed
4 · click Continue
passed
5 · url matches /notes
passed
6 · open /settings
passed
7 · click Delete account
passed
8 · fill Type DELETE to confirm
passed
9 · click Delete forever
passed
10 · path is exactly /
passed
11 · sign out (clear local session)
passed
12 · open /auth
passed
13 · fill Email
passed
14 · fill Password
passed
15 · click Continue
passed
16 · text "Invalid login credentials"
passed
17 · open /notes
passed
18 · url matches /auth
passed
Step 1 of 18

Access findings

Audit receipt · migrations · migration revision not recorded
SeverityWhereWhat we foundEvidence
The access audit at 2026-09-08 04:14 UTC found no findings. Anonymous reads returned no rows on 1 of 1 table probed. It could not check: The access token cannot read project abwpvwqvfdmqznzauhpz (Management API status 403); live policies were not inspected. Live policies were not inspected: RLS findings come from the committed migrations in Git HEAD, not the live database. Grants, runtime SQL and effective user access are not established.

Finding → Repair → Verified

Finding

No finding run attached to this repair.

Repair

no repair prepared

No migration was prepared by this journey run; run antelier repair to prepare one from the findings above.

Verified rerun

no rerun since the repair

What this did not check

Access findings come from the audit at 2026-09-08T04-14-19-142Z; the audit was not re-run with these journeys. · Only the configured journeys and assertions were checked. Browser visibility does not prove API isolation or physical data erasure. · Payments, other devices, third-party origins and unlisted workflows were not checked. · No migration was applied. Screenshots may contain app data; keep reports private. · Supabase access audits check public-table RLS and policy patterns, anonymous reads when a public key is supplied, and exposed keys in committed files or authorized app bundles. A migration audit cannot establish live policies; neither audit proves every user's effective access. · Stack: lovable; backend: supabase. Repository fingerprints do not prove the deployed stack or project ownership. · Access audit source: migrations. RLS findings come from the committed migrations, not the live database; live policies were not inspected.