github

Policies Not Scoped to Correct Roles in Supabase

Supabase security checks · MEDIUM

A policy applies to every role, including anonymous visitors.

What goes wrong

A Supabase RLS policy without a TO clause, or with TO public, applies to all roles, including anon. Anonymous visitors get the same access as signed-in users.

How it happens

The policy was created without a TO clause.

How to find it

List the policies in pg_policies whose roles are {public}.

SELECT tablename, policyname, cmd, roles
FROM pg_policies
WHERE schemaname = 'public'
  AND roles = '{public}';

How to fix it

Add TO authenticated, or a custom role, so the policy applies only to the roles you mean.

ALTER POLICY "<policy_name>" ON public.<table_name> TO authenticated;

Check your own project

Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.

Check my project