Supabase security checks
Every Supabase security check Locksoup runs on your Postgres database: what each one means, how to find it yourself, and the SQL to fix it.
CRITICAL
RLS Disabled on Public TablesRow level security is off, so anyone holding your public anon key can read and change every row in this table.
Policies Defined but RLS Not EnabledYou wrote policies for this table, but row level security is off, so none of them apply. Every row is open.
Service Role Key in Frontend CodeYour service role key is in frontend code. Anyone with it skips every policy.
HIGH
JWT Secret ExposureYour JWT secret is exposed. Anyone with it can sign in as any user.
Overly Permissive Policies (USING true)A policy lets every matching user through, not only the owner of each row.
Views Bypassing RLSThis view runs with its creator's rights, so it skips the row level security on the tables underneath.
SECURITY DEFINER Functions in Exposed SchemasThis function runs with elevated rights and can be called through your API.
Exposed RPC Functions Without AuthAnyone can call this function through your API without signing in.
Mass Assignment via Column UpdatesUsers can update every column of their own rows, including ones they shouldn't touch, like roles or balances.
RLS Policies Referencing user_metadataA policy trusts user_metadata, which users can edit themselves.
MEDIUM
RLS Enabled but No PoliciesRow level security is on but no policy allows anything, so your own app can't read this table either.
Multiple Permissive Policies OR'd TogetherSeveral permissive policies combine with OR, so the loosest one wins.
Policies Not Scoped to Correct RolesA policy applies to every role, including anonymous visitors.
Function Search Path MutableThe function has no fixed search_path, so it can be tricked into calling the wrong objects.
Materialized Views in APIA materialized view is reachable through the API, and row level security doesn't apply to it.
Public Storage BucketsAnyone with a file's URL can download it from this bucket.
Sensitive Column Names ExposedA column that looks like personal data is reachable through the API. Check that policies really limit it.
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.