Find tables with Row Level Security off, write policies so users only see their own rows, and test that strangers get nothing.
Check my Supabase tables and turn on Row Level Security the right way
How it works
- Scan for unprotected tables: Vovy opens Supabase's Security Advisor and lists every table where RLS is disabled. Anyone with your public key can read those.
- Explain RLS in one card: Row Level Security is a rule on each table saying who can see or change which rows. With RLS on and no policies, nobody gets anything.
- Draft policies per table: Vovy reads how your app uses each table and drafts policies, like "users can read rows where user_id equals auth.uid()". You review them in plain English.
- Turn on RLS and apply policies: Vovy asks, then enables RLS and adds the policies in one migration, so your app doesn't break between the two steps.
- Test as a stranger and as a user: Vovy queries each table as a logged-out visitor and as a test user, then shows a table of who can read and write what.
What you provide
- Access to your Supabase project
- Who should see what, in your words
What you get
- RLS on for every table
- Policies you understand
- A tested access table
- Security Advisor warnings cleared
FAQ
My app broke after turning on RLS. Why?
RLS with no policies blocks everything. You need at least one policy per action your app does, like select and insert.
Is my data really exposed without RLS?
Yes. Your publishable key is in your site's code, and without RLS anyone can use it to read or change those tables.
Does my server code need policies too?
Server code using the secret key skips RLS entirely. That's why that key must never reach the browser.
Related tasks
All tasks