Urgent.News

What's breaking now, across thousands of outlets.

Tech

Supabase's October 30 change: fix error 42501 without opening your data

On October 30, 2026, Supabase stops exposing new tables to its Data API by default in existing projects. If your app was built with Lovable, Bolt or Cursor, you'll likely meet this the first time you add a table, and the quickest fix your AI tool offers can make that table readable by anyone. What changes From October 30, new tables you create in the public schema of an existing project can't be…

On October 30, 2026, Supabase made a significant change to its Data API. From this date forward, new tables created in the public schema of existing projects will not be accessible via the Data API (supabase-js, /rest/v1, GraphQL) unless explicit access is granted. This update aims to enhance security and control over data access within Supabase projects.

For most new projects, these changes have been in effect since late May. Existing tables retain their access permissions and continue to function as usual. Applications that interact with PostgreSQL directly remain unaffected by this modification.

When attempting to query a new table, developers will encounter an error with the following details:

- **Error code:** 42501

- **Message:** "permission denied for table your_table"

- **Hint:** Grant the required privileges to the current role using the command: GRANT SELECT ON public.your_table TO anon;

To address this issue, Supabase recommends the following three-step solution:

1. **Grant necessary privileges:** Use the command `grant select, insert, update, delete on public.your_table to authenticated;` to grant limited access to the table. If the app requires server-side access, include `to service_role;` in the command.

2. **Enable row-level security (RLS):** Use the command `alter table public.your_table enable row level security;` to enforce RLS on the table.

3. **Create policies:** Use the command `create policy "owners manage their rows" on public.your_table for all to authenticated using (auth.uid() = user_id);` to ensure that only authenticated users can access their own rows.

These steps should be executed together in a single migration to ensure consistency and effectiveness. Developers should avoid granting unrestricted access using AI tools and should specifically check the existing tables in their Supabase projects for any RLS issues. The Supabase SQL Editor can be used to run a query that checks for tables with RLS disabled and identifies if anonymous or authenticated users can read the tables.

It is crucial to ensure that the policies implemented do not use a universally true condition on user data.

This change underscores Supabase's commitment to improving data security and providing developers with clear guidelines to manage data access effectively. For more detailed information and step-by-step SQL commands, developers can refer to the guide available at liftoffreview.com/supabase-oct-30.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Long live the mechanical keyboard

Keychron made a name for itself after launching on Kickstarter in 2017. Today, it offers the value K2 model as well as a variety of other versions, including one with an all-wood body.

More from Friday 9 October →