github

RLS Enabled but No Policies in Supabase

Supabase security checks · MEDIUM

Row level security is on but no policy allows anything, so your own app can't read this table either.

What goes wrong

Row level security (RLS) is enabled on your Supabase table, but it has no policies. RLS with zero policies denies all access. Your app fails silently when it uses the table.

How it happens

RLS was enabled and the policies were forgotten. It is usually a development oversight, not a deliberate security choice.

How to find it

List the tables in the public schema where relrowsecurity is true and pg_policy has no policy for them.

SELECT c.relname AS tablename
FROM pg_class c
JOIN pg_namespace n ON c.relnamespace = n.oid
WHERE c.relkind = 'r'
  AND c.relrowsecurity = true
  AND n.nspname = 'public'
  AND NOT EXISTS (SELECT 1 FROM pg_policy p WHERE p.polrelid = c.oid);

How to fix it

Create policies that match how the table is accessed, one per operation. The example lets signed-in users read their own rows.

CREATE POLICY "Users can read own <table_name>"
  ON public.<table_name> FOR SELECT
  TO authenticated
  USING ((SELECT auth.uid()) = <user_id_column>);

Check your own project

Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.

Check my project