github

Public Storage Buckets in Supabase

Supabase security checks · MEDIUM

Anyone with a file's URL can download it from this bucket.

What goes wrong

A public Supabase Storage bucket bypasses all access controls. Files are served by direct URL without any authentication. Anyone who knows the bucket name and the file path can guess the URL.

How it happens

The bucket has public set to true in storage.buckets.

How to find it

List the buckets in storage.buckets where public is true.

SELECT id, name
FROM storage.buckets
WHERE public;

How to fix it

Make the bucket private and use signed URLs for temporary access.

UPDATE storage.buckets SET public = false WHERE id = '<bucket_name>';

Check your own project

Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.

Check my project