Knowledge base

Supabase Row Level Security and Storage

Apps built on Supabase ship the project URL and the anon key to every visitor. That is normal: what protects your data is Row Level Security (RLS) on each table and the policies on Storage buckets. Vigavo uses only the anon key it finds in your site, like any visitor could:

  • supabase_table_public_read (critical): a table returns rows to anyone with the anon key. RLS is off on that table, or a policy allows everyone.
  • supabase_table_public_write (critical): a table accepts inserts from anyone. This is only tested for your own project, after you opt in: Vigavo inserts one marked test row and deletes it again (the finding says whether the cleanup was confirmed). Tables that look like payments or orders are never write-tested.
  • supabase_bucket_public_list: a Storage bucket lets anyone list its files.
  • supabase_service_key_in_bundle (critical): the service-role key is in the front-end code. It bypasses RLS completely: rotate it now.

The report shows table names and column names, never the content of rows.

Fixing

Enable RLS on every table in public and add policies that match who should read or write each row (for example auth.uid() = user_id). Each critical finding has a fix prompt with a ready migration. Then verify the fix.

Last reviewed Oct 7, 2026, 12:00:00 AM

Still stuck? Send a ticket

Feedback
Type