The missing permission check
Scope the delete to both the project ID and the current owner. Return 404 when no matching project exists.
api/projects/delete.tsEvery line. Worth a second look.
Understands the context. Catches what matters.
Open source. Use our cloud or host it yourself.
const user = await requireUser(req);const { projectId } = await req.json(); await db.project.delete({ where: { id: projectId }});user.idproject.ownerIdThis user is authenticated, but ownership is never checked. Someone else’s project could be deleted.
Less to sift through.
More worth your attention.
A diff tells you what changed. The surrounding code tells you what it means. Inkspect connects the two, giving you findings grounded in context and suggestions you can act on.
Take a closer lookMeet your second pair of eyes
Some issues look perfectly fine at first glance.
Pick an example. See what a closer look reveals.
export async function removeProject(req: Request) { const user = await requireUser(req); const { projectId } = await req.json(); const project = await db.project.findUnique({ where: { id: projectId }, }); await db.project.delete({ where: { id: projectId } }); return Response.json({ deleted: true });}export async function removeProject(req: Request) { const user = await requireUser(req); const { projectId } = await req.json(); const result = await db.project.deleteMany({ where: { id: projectId, ownerId: user.id }, }); if (result.count === 0) { return new Response(null, { status: 404 }); } return Response.json({ deleted: true });}Scope the delete to both the project ID and the current owner. Return 404 when no matching project exists.
api/projects/delete.tsFrom pull request to perspective
Stay in the flow. Keep the context.
Make the decision with a clearer picture.
Connect your repository and open a pull request. Inkspect brings the review directly to the conversation your team is already having.
Inkspect retrieves related code and follows the questions that emerge during review, connecting the change to the context behind it.
Get a clear explanation and a practical suggestion. You choose what changes and what ships.
Context for your whole team
Help a new teammate find their way around the project. Give an AI assistant the context behind its next task. Both use the same retrieval layer.
A new developer joins your team and opens the dashboard. They can ask how authentication works, where a feature lives, or why a module behaves a certain way. RAG retrieves relevant code and documentation to ground each answer in the project.
Where should I check workspace access for an invoice?
Check workspace membership before returning the invoice. A signed-in session alone does not grant access to its workspace.
docs/access-policy.mdsrc/auth/membership.tsA starting point for onboarding, with source references to explore.
Describe the task to the CLI context pull tool. Retrieve the relevant code, conventions, and documentation, then pass that context to your AI assistant alongside the prompt. The assistant gets a focused starting point without loading the whole codebase into every prompt.
The same project knowledge, ready for an AI teammate.
Let us run Inkspect for you, or run it on your own infrastructure. Choose what fits your team.
The code deserves a second look. Ours, too.
Why open sourceA name with a point of view
Ink leaves a mark. Inspection gives it meaning.
Inkspect brings the two together. A name for the care that goes into reading code, understanding a decision, and noticing what might have slipped past.
Our drop is the act of making. The eye inside is the attention we give it. Because a good review starts with respect for the code, and the person who wrote it.
Every line deserves a second look.A few things to know
Choose Inkspect Cloud to leave hosting and updates to us. Self-host if your team wants to run Inkspect on its own infrastructure and manage access, retention, and updates. Compare the two options.
Yes. Inkspect is an open-source code review product, with a managed cloud option and a self-hosted option. Read about our approach.
Sign in to Inkspect Cloud or your own instance, connect your repository, and open a pull request. Inkspect adds contextual findings and suggestions to your review, so your team can discuss them where the work happens.
Inkspect gives reviewers useful context and an extra set of eyes. Your team keeps ownership of the decisions, the changes, and the merge.
Issues that can change how your code behaves: missing permission checks, unhandled failures, concurrency problems, and other logic or security risks. Each finding explains what matters and why.
Inkspect provides findings and suggested changes. Your team reviews the reasoning, runs its checks, and decides what to apply and merge.
Prefer your own infrastructure? Explore self-hosting.
A little clarity, right here.
Ask about code review, pricing, or running Inkspect with your team.