RLS Enabled but No Policies in Supabase
Supabase security checks · MEDIUM
Row level security is on but no policy allows anything, so your own app can't read this table either.
What goes wrong
Row level security (RLS) is enabled on your Supabase table, but it has no policies. RLS with zero policies denies all access. Your app fails silently when it uses the table.
How it happens
RLS was enabled and the policies were forgotten. It is usually a development oversight, not a deliberate security choice.
How to find it
List the tables in the public schema where relrowsecurity is true and pg_policy has no policy for them.
SELECT c.relname AS tablename FROM pg_class c JOIN pg_namespace n ON c.relnamespace = n.oid WHERE c.relkind = 'r' AND c.relrowsecurity = true AND n.nspname = 'public' AND NOT EXISTS (SELECT 1 FROM pg_policy p WHERE p.polrelid = c.oid);
How to fix it
Create policies that match how the table is accessed, one per operation. The example lets signed-in users read their own rows.
CREATE POLICY "Users can read own <table_name>" ON public.<table_name> FOR SELECT TO authenticated USING ((SELECT auth.uid()) = <user_id_column>);
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.