All work
App2026

Mastterspire — Student exam platform

Mastterspire Academy

Mastterspire Kids Academy teaches five subjects to children — abacus, Vedic maths, phonics, handwriting and robotics — and needed a site that did rather more than describe them: sign-up and accounts, a student dashboard, a public practice-test tool with a timed exam runner, and an administrative dashboard for staff.

One architectural fact shapes everything else here. There is no server tier. The browser talks to the database directly, which means the database itself is the security boundary. Every access rule lives in row-level policies. That is a perfectly good way to build something this size, and it is only safe if the policies are actually correct — so they were audited against the live backend rather than by reading the code, probing the running system exactly as an anonymous visitor would.

The audit found four serious holes, all now closed and each verified afterwards rather than assumed.

Any signed-in user could set their own administrator flag, because a single permissive policy allowed it and the administrator check lived only in the browser. That policy is gone, access is scoped to owner-or-administrator, and a database trigger now refuses any change to the administrator flag that does not come from an existing administrator.

Every test-taker's name, email and phone number was readable — and editable — by anyone at all. These are children. Anonymous access is now insert-only; reading, changing and deleting are administrator-only.

The answer key was public. Question records including the correct values could be read by anyone, and grading happened in the browser. Table-level read access was revoked and re-granted only on the columns that are safe to expose, and grading moved into a server-side function that the browser calls without ever seeing the answers.

Any registered student could edit or delete the quiz content itself across four tables. Writes are now gated behind an administrator check; reading stays public.

One thing from that report deserves repeating, because it shows the difference between fixing a problem and claiming to. These are mental-arithmetic questions, so a determined person can always work out the answer themselves. Server-side grading still matters — it protects result integrity and stops the entire key being handed out at once — but it was written down as a partial defence rather than sold as a complete one.

Alongside the security work came the ordinary reliability fixes that keep a site standing: an error boundary, a leaking event listener replaced with delegation, timers cleaned up properly, and a file-casing rename that had been silently breaking builds on case-sensitive systems while working perfectly on the developer's own machine.

Built with

ReactViteSupabase

This was app development for Mastterspire. See how we approach app development, or tell us what you want to build.