Vovy finds every private page in your app, adds a login check that redirects visitors, and tests each one while logged out.
Make my dashboard pages only work when you're logged in
How it works
- List every route: Vovy reads your router in Cursor and shows a table of pages, marking which should be public and which private. You adjust the list.
- Add a login guard: It wraps private routes in a check that reads the Supabase session and sends logged-out visitors to /login, remembering where they were going.
- Guard the server side too: For Next.js apps it adds middleware using @supabase/ssr so private pages are blocked before they render, not just hidden.
- Check the data is locked: Vovy checks your tables have Row Level Security on, since a page guard alone doesn't stop someone reading data with your public key.
- Test every page logged out: It opens each private URL in a private Chrome window and shows a pass or fail table.
What you provide
- Your app open in Cursor
- A list of pages that should be private
What you get
- Private pages that redirect to login
- Return to the page after login
- A pass or fail table per page
- A flag on any table without RLS
FAQ
Why does my page flash before redirecting?
The browser checks the session after loading. Vovy adds a loading state, or server middleware, so nothing private shows.
Is a redirect real security?
It protects the screen, not the data. Row Level Security on your tables is what stops data leaks.
Does this work with Lovable apps?
Yes. Lovable apps use React Router, and the guard wraps those routes.
Related tasks
All tasks