Row Level Security in Lovable apps: why your database might be public
Originally published on howsafeismyapp.com . Here is the uncomfortable truth about most Lovable apps: the database is not behind your login form. It is behind Supabase's API — and whether that API hands out your data to strangers depends on one setting most AI-generated apps never mention: Row Level Security . This is the most serious finding our scanner sees in the wild. It is also completely…
Many Lovable apps unintentionally expose their databases to the public due to a lack of Row Level Security (RLS) policies. RLS, a PostgreSQL feature, controls access to specific rows in a table based on user identity. Without RLS enabled, any user can access all data in an exposed table using an "anon" key present in the JavaScript code.
This lack of proper security measures can lead to data breaches, as personal information like names, emails, and user content becomes accessible. To address this issue, Supabase users should enable RLS on all public tables and write appropriate policies to restrict data access. They must also avoid shipping the service_role key to the frontend, as it bypasses RLS.
After implementing these security measures, users should run a two-minute check to ensure that their data remains protected from unauthorized access.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.