Policies Defined but RLS Not Enabled in Supabase
Supabase security checks · CRITICAL
You wrote policies for this table, but row level security is off, so none of them apply. Every row is open.
What goes wrong
Your Supabase table has RLS policies, but row level security (RLS) was never enabled on it. Postgres stores the policies and never enforces them, so every row stays open. The table still looks secured in the dashboard’s policy views.
How it happens
The policies were written, but the ALTER TABLE ... ENABLE ROW LEVEL SECURITY statement was forgotten.
How to find it
Look for tables in the public schema that have policies in pg_policy while relrowsecurity is false.
SELECT c.relname AS tablename FROM pg_class c JOIN pg_namespace n ON c.relnamespace = n.oid WHERE c.relkind = 'r' AND c.relrowsecurity = false AND n.nspname = 'public' AND EXISTS (SELECT 1 FROM pg_policy p WHERE p.polrelid = c.oid);
How to fix it
Enable RLS on the table so the policies you already wrote are enforced.
ALTER TABLE public.<table_name> ENABLE ROW LEVEL SECURITY;
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.