Neeraj L

Neeraj L

tinkering ⛏️

Badges

Tastemaker
Tastemaker
Gone streaking 10
Gone streaking 10
Gone streaking
Gone streaking
Gone streaking 5
Gone streaking 5

Maker History

  • prisma-firewallA security firewall for Prisma
    Apr 2026
  • 🎉
    Joined Product HuntApril 11th, 2026

Forums

Neeraj L

2mo ago

prisma-firewall - A security firewall for Prisma

Every Prisma developer has a silent risk in their codebase. A single deleteMany() with no where clause wipes an entire table. A findMany() with no limit dumps your entire database to the client. And there's a lesser known attack called operator injection, where an attacker sends { "not": "" } as a password value instead of a plain string, and Prisma accepts it as a valid query operator, bypassing authentication entirely. When tested, Prisma did not block it. prisma-firewall does.
View more