Public Storage Buckets in Supabase
Supabase security checks · MEDIUM
Anyone with a file's URL can download it from this bucket.
What goes wrong
A public Supabase Storage bucket bypasses all access controls. Files are served by direct URL without any authentication. Anyone who knows the bucket name and the file path can guess the URL.
How it happens
The bucket has public set to true in storage.buckets.
How to find it
List the buckets in storage.buckets where public is true.
SELECT id, name FROM storage.buckets WHERE public;
How to fix it
Make the bucket private and use signed URLs for temporary access.
UPDATE storage.buckets SET public = false WHERE id = '<bucket_name>';
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.