Policies Not Scoped to Correct Roles in Supabase
Supabase security checks · MEDIUM
A policy applies to every role, including anonymous visitors.
What goes wrong
A Supabase RLS policy without a TO clause, or with TO public, applies to all roles, including anon. Anonymous visitors get the same access as signed-in users.
How it happens
The policy was created without a TO clause.
How to find it
List the policies in pg_policies whose roles are {public}.
SELECT tablename, policyname, cmd, roles
FROM pg_policies
WHERE schemaname = 'public'
AND roles = '{public}';How to fix it
Add TO authenticated, or a custom role, so the policy applies only to the roles you mean.
ALTER POLICY "<policy_name>" ON public.<table_name> TO authenticated;
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.