Exposed RPC Functions Without Auth in Supabase
Supabase security checks · HIGH
Anyone can call this function through your API without signing in.
What goes wrong
Supabase makes every function in an exposed schema callable at /rest/v1/rpc/<function_name>. If the function doesn’t check auth.uid() or the caller’s role itself, anyone can execute it.
How it happens
The function was added to an exposed schema without an auth check inside it, and the anon role can execute it.
How to find it
List the functions in the public schema that the anon role has the EXECUTE privilege on.
SELECT p.proname AS routine_name, p.prosecdef AS security_definer
FROM pg_proc p
JOIN pg_namespace n ON p.pronamespace = n.oid
WHERE n.nspname = 'public'
AND p.prokind = 'f'
AND has_function_privilege('anon', p.oid, 'EXECUTE');How to fix it
Revoke EXECUTE on the function from PUBLIC and anon, or move it to a private schema.
REVOKE EXECUTE ON FUNCTION public.<function_name> FROM PUBLIC, anon;
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.