AI Fix Prompt Library for Cursor & Claude Code
Stop getting trapped in circular AI loops. When your assistant writes flawed Stripe webhooks or un-scoped database queries, paste one of these battle-tested fix prompts to resolve the issue in 30 seconds.
Fix Next.js Stripe Webhook Signature Verification
When to use: When Stripe webhooks fail with invalid signature errors because the route parses JSON before verifying HMAC.
Refactor this Next.js 15 App Router Stripe webhook handler in app/api/webhooks/stripe/route.ts:
1. Read the raw request body with "const body = await req.text();" instead of req.json().
2. Retrieve the signature with "req.headers.get('stripe-signature')".
3. Wrap "stripe.webhooks.constructEvent(body, signature, process.env.STRIPE_WEBHOOK_SECRET!)" in a try/catch block. Return a 400 response on signature failure.
4. Add a switch statement for handled events (e.g. checkout.session.completed, customer.subscription.deleted).
5. Always return a 200 response acknowledging receipt for unhandled events so Stripe does not disable the endpoint.Enforce Supabase Row Level Security & Scoped Policies
When to use: When new database tables were created without Row Level Security, allowing any user to query or mutate arbitrary rows.
Audit my Supabase SQL migrations and database schema: 1. Enable Row Level Security on every table: "ALTER TABLE <table_name> ENABLE ROW LEVEL SECURITY;". 2. Create granular RLS policies for SELECT, INSERT, UPDATE, and DELETE scoping access to "auth.uid() = user_id". 3. Ensure the anon role can only read public rows, and verify that the service_role key is never required for normal client queries. 4. Output the complete, idempotent SQL migration script.
Sanitize Leaked Secrets and Strip NEXT_PUBLIC_ Prefixes
When to use: When private API keys or database connection strings were prefixed with NEXT_PUBLIC_ to silence undefined errors in client code.
Scan my entire Next.js repository for improperly exposed secrets: 1. Inspect all environment variables prefixed with NEXT_PUBLIC_ or VITE_. 2. If any variable contains private tokens (e.g. Stripe secret keys, Supabase service_role, OpenAI/Anthropic keys, database passwords), remove the public prefix. 3. Move the client calls that required those keys into dedicated server API routes or Server Actions so the secret never touches the browser. 4. Generate a clean .env.example file containing only dummy placeholder values for every variable.
Fix Insecure Direct Object Reference (IDOR) in API Routes
When to use: When an endpoint accepts userId or accountId in the request body, allowing attackers to modify other users data.
Audit this API route handler for IDOR vulnerabilities:
1. Remove any reliance on "userId" or "accountId" passed in the request JSON body or query parameters.
2. Derive the authenticated user identity strictly from the server session (e.g. "const session = await auth(); if (!session?.user?.id) return new Response('Unauthorized', { status: 401 });").
3. Update all database queries to enforce ownership (e.g. "where: { id: resourceId, userId: session.user.id }").
4. Never return raw database error exceptions to the client.Add Production HTTP Security Headers to Next.js
When to use: When your deployment lacks Content-Security-Policy, X-Frame-Options, and MIME nosniff headers.
Update next.config.ts (or next.config.mjs) to include production HTTP security headers: 1. Add Content-Security-Policy with directives supporting our external assets (allow 'self', Stripe, Google Fonts, and Supabase connections). 2. Set "X-Frame-Options: DENY" to block clickjacking iframe attacks. 3. Set "X-Content-Type-Options: nosniff" to prevent MIME confusion attacks. 4. Set "Referrer-Policy: strict-origin-when-cross-origin". 5. Set "Permissions-Policy: camera=(), microphone=(), geolocation=()". 6. Set "Strict-Transport-Security: max-age=63072000; includeSubDomains; preload".
Break Infinite Re-render & AI Token Burning Loops
When to use: When a React useEffect hook or streaming AI call triggers infinite re-renders that exhaust API credits.
Audit this component for infinite re-render loops and runaway API calls: 1. Inspect all useEffect hooks to ensure their dependency arrays do not include objects, arrays, or functions that change identity on every render. 2. Add a request deduplication guard or AbortController so that in-flight API requests are cancelled if the component unmounts. 3. Implement a maximum retry ceiling (max 3 retries with exponential backoff) for any external AI or LLM endpoint calls. 4. Ensure error states do not trigger automatic re-fetches without user interaction.
Add Rate Limiting to AI Streaming Routes (Upstash Redis)
When to use: When an unauthenticated endpoint makes expensive OpenAI or Anthropic calls without rate limits.
Add IP and user-based rate limiting to this AI route handler using @upstash/ratelimit:
1. Initialize the Ratelimit instance with sliding window (e.g. 10 requests per 1 minute for unauthenticated IPs, 30 for logged-in users).
2. Read the client IP from req.headers.get('x-forwarded-for') or the verified session user ID.
3. If limit is exceeded, return a 429 response with a "Retry-After" header and a friendly error message.
4. Gracefully handle Redis connection timeouts so traffic is not dropped if the rate limiter is temporarily unreachable.Convert Prisma Client to a Safe Development Singleton
When to use: When Next.js hot reload creates dozens of new PrismaClient connections, exhausting database connection limits.
Refactor our database client initialization in lib/db.ts: 1. Instantiate PrismaClient as a global singleton attached to globalThis in development. 2. Prevent Next.js hot module replacement from instantiating a new database connection pool on every file edit. 3. Export a single typed "db" or "prisma" client instance across the entire application.
Validate Server Action Inputs with Zod Schemas
When to use: When Server Actions receive raw unvalidated FormData or JSON objects without type and bounds checks.
Refactor this Next.js Server Action to enforce runtime schema validation: 1. Define a strict Zod schema for all expected input fields with maximum string lengths and regex checks. 2. Parse inputs using schema.safeParse() at the beginning of the action. 3. If parsing fails, return a typed structured error object with field-level error messages instead of throwing uncaught exceptions. 4. Proceed with database mutations only after input is fully validated.
Which prompts does your codebase actually need?
Instead of guessing where your AI editor slipped up, run the complete 108 launch checks with the Founder Pass ($15 one-time). Get tailored fix prompts mapped directly to your exact file paths and line numbers.