Skip to content

How a Superfan Music Platform Inherited From a Previous Developer Closed an Unauthenticated Admin-Takeover Path on Day One, Fixed 15 Security Findings, and Reached Launch-Ready in 4 Days

Music Exclusive is built for artists and made for superfans: unreleased tracks, streamed through token-gated, forensically watermarked HLS, paid for in credits, with artists paid out through Stripe Connect. Joy Lewis inherited the codebase from a previous developer with a launch coming. Epiphany Dynamics audited it on day one and found three unauthenticated functions live in production, one of which could reset any user's password, including admin accounts, and return the new password in plain text. Over four days we closed 15 security findings across two audits, restored every scheduled job, walked all 27 artist and fan flow steps to green, and left CI behind.

Music Exclusive case study: DAY ONE. THE ADMIN PATH IS CLOSED.

15 security findings. Launch-ready in 4 days.

Field Note

Day one

The audit was the first thing we ran. Three unauthenticated functions were live in production, and one of them could reset any account's password, admin included, and return the new password in plain text. We deleted them the same day, along with two more functions that could mint unlimited artist and fan accounts.

The findings
  1. 01 Critical · Test account functions. Three unauthenticated functions were live in production: one reset any account's password, admin included, and returned the new password in plain text; one minted unlimited artist accounts; one minted unlimited fan accounts with 100 free credits each. Fix: deleted from production.
  2. 02 Critical · Daily report endpoint. Leaked total revenue, artist earnings, and top fans' email addresses to any caller. Fix: locked behind an admin check.
  3. 03 High · Admin report. Broken and returning wrong figures, so the numbers the team saw could not be trusted. Fix: repaired.
  4. 04 High · Checkout functions. Accepted arbitrary email addresses. Fix: bound to the real account.
  5. 05 High · Track-sharing insert. No ownership check, so a user could insert a share into another user's account. Fix: ownership enforced.
  6. 06 Medium · Function auth. Inconsistent across endpoints. Fix: normalized to one auth path.
  7. 07 Medium · Ledger match. Matched on email alone. Fix: matched on the account identity.
  8. 08 Medium · Fan-invites table. Publicly readable. Fix: locked down.
  9. 09 Medium · Draft tracks. Visible to all users. Fix: scoped to the owner.
  10. 10 Low · Cleanup. One leftover tidy-up item from the first audit. Fix: removed.
  11. 11 Critical · Vault code validation. A test-mode check returned true for everyone, so anyone could force-win the vault lottery. Fix: return false.
  12. 12 High · Member creation. Existing users' credits were reset to 0 on every login. Fix: preserve existing rows.
  13. 13 High · Superfan invites. No authentication, so anyone could mint invite links. Fix: service-role check.
  14. 14 Medium · Credit top-up. The request body was parsed twice and the second parse always threw. Fix: single parse.
  15. 15 Medium · Add-credits page. Free credits without payment by calling top-up directly. Fix: routed through Stripe Checkout.
Security findings fixed 15 Across two audits: 3 critical, every finding closed
Contract to every core flow passing 4 days Industry average to remediate a critical is 164.7 days (Source: Statista, average age of cyber vulnerabilities by severity)
Scheduled jobs running on production 0 to 4 None were running until the scheduler was enabled on production and four jobs were deployed and tested
Why this population of codebases is risky

Veracode's 2025 GenAI Code Security Report found 45% of AI-generated code contains known vulnerabilities, a rate that held at roughly 45% across 150 models in its spring 2026 update.

In May 2025, CVE-2025-48757 documented more than 170 apps exposing data through missing row-level security. In October 2025, a passive scan of 5,600 apps built on these tools found 2,000 vulnerabilities, 400 exposed secrets, and 175 PII exposures.

This codebase was a normal member of that population. The plan was to make it an exception.

Client
Music Exclusive logo

Music Exclusive

Built
Launch sprint, security audit, streaming pipeline, CI
Sector
AI Rescue / Full-Stack Build

Music Exclusive's pitch is direct: unreleased tracks from your favorite artists, before public release. The category was validated by the platforms it competes with during the year of this engagement: YouTube Music launched superfan reward tools in September 2025 and SoundCloud began letting artists drop exclusive tracks for superfans in March 2026.

Spotify pays roughly $0.003 to $0.005 per stream; a $10 direct sale on Bandcamp nets an artist about $7.90, the equivalent of roughly 1,975 Spotify streams. A platform that lets fans pay per exclusive stream is a different business.

Client Feedback

"Patrick took a complex project with several critical issues and made it launch-ready in under two weeks. His security audit caught vulnerabilities the previous developer missed. He verified every user flow, fixed full-stack bugs, delivered more than originally scoped, explained things clearly, and made the project maintainable going forward. Would hire again without hesitation."

Joy Lewis

Founder, Music Exclusive

Field Note

Leaving it better than we found it

The last phase was not a feature. It was deleting 523 lines of unrouted code, collapsing three duplicate credit-purchase pages into one, and putting lint, type checks, and tests on every pull request so the next developer inherits something cleaner than we did. That is the difference between a fix and a rescue.

FAQ
What was the worst finding?
An unauthenticated function that could reset any user's password, admin included, and return it in plain text. Deleted on day one.
How long did the fixes take?
Four days from contract to all core flows passing, against a 164.7-day industry average to remediate a critical vulnerability.
What did the platform get beyond fixes?
Four restored scheduled jobs, 523 lines of dead code removed, and lint, type checks, and tests on every pull request.

Inherited a Codebase You Are Not Sure About?

Get an audit before launch, not after.