github

Policies Defined but RLS Not Enabled in Supabase

Supabase security checks · CRITICAL

You wrote policies for this table, but row level security is off, so none of them apply. Every row is open.

What goes wrong

Your Supabase table has RLS policies, but row level security (RLS) was never enabled on it. Postgres stores the policies and never enforces them, so every row stays open. The table still looks secured in the dashboard’s policy views.

How it happens

The policies were written, but the ALTER TABLE ... ENABLE ROW LEVEL SECURITY statement was forgotten.

How to find it

Look for tables in the public schema that have policies in pg_policy while relrowsecurity is false.

SELECT c.relname AS tablename
FROM pg_class c
JOIN pg_namespace n ON c.relnamespace = n.oid
WHERE c.relkind = 'r'
  AND c.relrowsecurity = false
  AND n.nspname = 'public'
  AND EXISTS (SELECT 1 FROM pg_policy p WHERE p.polrelid = c.oid);

How to fix it

Enable RLS on the table so the policies you already wrote are enforced.

ALTER TABLE public.<table_name> ENABLE ROW LEVEL SECURITY;

Check your own project

Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.

Check my project