Urgent.News

What's breaking now, across thousands of outlets.

Tech

3 Supabase RLS Leaks I Found in Production Apps This Week (and the 30-Second Check for Each)

3 Supabase RLS Leaks I Found in Production Apps This Week (and the 30-Second Check for Each) I audit Supabase apps for a living. This week I read the public source of three real, live products — a university dorm-management system, a freelancing marketplace, and an embedded product configurator — and every single one had a Row Level Security hole that its developer did not know was there. None of…

Three Supabase apps with Row Level Security (RLS) vulnerabilities were discovered this week. Each app had a different issue, but all were due to common mistakes in implementing RLS policies.

Pattern 1 involved a helper function that checks if an email exists in the table, effectively opening the entire table to anyone with the anon key. The fix is to wrap the lookup in a function that only returns what's needed, and revoke access to the table for the anon user.

Pattern 2 was a policy named "Users can read all profiles" that unintentionally granted access to all users, including anon. The issue is that policies without a TO clause apply to public, which includes anon. The solution is to explicitly state the roles the policy applies to.

Pattern 3 involved committing the Supabase service role key into the codebase, which made it vulnerable to anyone with access to the code. The recommendation is to rotate the service role key immediately, remove it from the repository, and delete any references to it in the code.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Is the spreadsheet warrior a dying breed?

Love it or hate it, Excel is one of those skills everyone claims to be proficient in on their CV. No one checks what it even means, but it feels weird not to have it there, like people will assume you…

More from Monday 5 October →