Row-level security
The database refuses rows the current user is not entitled to, verified with two accounts.
- Applies to
- apps
- Standard references
- CWE-285
A finding here is not a failure
Software of any size carries something. A listing that raises findings on this check is still sold, with the findings published and their severity and reachability stated. A badge that only ever said pass would teach people to stop reading it.
Explainer · 2026-09-30
Row-level security: making the database refuse rows a user is not entitled to
If an application's database is reachable with a public key, row-level security is the only thing standing between one user and another user's rows. It has to be on, and it has to be right.
What this row checks
That the database itself refuses rows the current user is not entitled to, verified with two accounts: one account creates data, the other tries to read and change it, and every attempt that should fail does.
How it works in Postgres
Row security is switched on per table, and policies say which rows each role may see or change. With it switched on and no policy at all, Postgres denies everything by default. Superusers and roles with the bypass attribute always skip it, and table owners normally do too unless the table is set to force it.
Platforms built on Postgres, Supabase among them, hand browsers a public key and rely on row-level security to decide what that key can reach. A table with it switched off is readable by anybody holding the public key.
The usual mistakes
Leaving a new table without row security because the first one had it. A policy that trusts a value the user can edit. A view that runs with its owner's rights and quietly reads past the policies on the tables beneath it. Each passes a test with one account and fails the moment a second account tries.
How apps and templates are read for this row
On an app or a template, this row is also answered every night by a reading of the package's published files, never by running it. The rules are app check set v1.0, each with its mapping, an example, the nearest writing it leaves alone, a hand count across every app and template listing, and what a reading of files does not cover.
In the glossary: RLS.
What this check has found
Nothing in the catalogue has raised a finding on this check. That is a fact about what has been tested so far rather than a guarantee about what is out there, and it is printed because a check that never fires is worth knowing about too.
Every listing in the catalogue shows its result on this check, with the findings summarised in public and the full report to whoever bought it. Open the catalogue.