github

Exposed RPC Functions Without Auth in Supabase

Supabase security checks · HIGH

Anyone can call this function through your API without signing in.

What goes wrong

Supabase makes every function in an exposed schema callable at /rest/v1/rpc/<function_name>. If the function doesn’t check auth.uid() or the caller’s role itself, anyone can execute it.

How it happens

The function was added to an exposed schema without an auth check inside it, and the anon role can execute it.

How to find it

List the functions in the public schema that the anon role has the EXECUTE privilege on.

SELECT p.proname AS routine_name, p.prosecdef AS security_definer
FROM pg_proc p
JOIN pg_namespace n ON p.pronamespace = n.oid
WHERE n.nspname = 'public'
  AND p.prokind = 'f'
  AND has_function_privilege('anon', p.oid, 'EXECUTE');

How to fix it

Revoke EXECUTE on the function from PUBLIC and anon, or move it to a private schema.

REVOKE EXECUTE ON FUNCTION public.<function_name> FROM PUBLIC, anon;

Check your own project

Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.

Check my project