Supabase
Security & compliance
RLS disabled on a table — cross-tenant rows accessible
Part of the RLS & tenant isolation check · fix arrives as a pull request
What it is
Row-Level Security is disabled on a table in the public schema that application code reads or writes.
Why it matters
Without RLS, Postgres returns every row to anyone holding a valid key — and in a Supabase app that key is in the browser. There is no per-user filter unless every query remembers to add one.
How to fix it
Enable RLS on the table, then add policies before deploying: one per operation, scoped TO authenticated, with (select auth.uid()) = user_id as the predicate and an index on the owner column. Verify with an anon key that the table now returns nothing.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.