Reviewing row-level security in a Supabase application

Test Supabase row-level security with real roles, tenant boundaries, API paths, and privileged exceptions.

On this page

Review policies as application controls

Row-level security controls database operations for the role and request context that reaches PostgreSQL. Review it with schema, identity claims, API behaviour, and privileged server paths. A policy that passes under an administrator connection says little about a browser user.

Inventory tables and actors

List tables, operations, tenant keys, ownership fields, user roles, service credentials, views, functions, and API routes. For each operation, state who may read, insert, update, and delete. Include background jobs and support tools that can bypass ordinary client policy.

Test allowed and denied actions

Use normal accounts to test an allowed action, another tenant's record, ownership-field manipulation, guessed identifiers, bulk reads, and direct API requests. Test inserts and updates separately: a policy that allows creation can still permit a user to assign a record to another tenant if checks are incomplete.

Review changes and exceptions

Treat policy, schema, role, and API changes as a single review set. Keep privileged service keys only in trusted server paths, document every exception, and rerun a regression suite after migrations. OWASP guidance supports testing authorisation at every sensitive operation, not only the user interface.

RLS review record

Keep a testable decision per table.

OperationAllowed actorDenial test
ReadTenant memberOther tenant ID.
InsertAuthorised creatorForged tenant or owner.
UpdateRecord owner or roleOwnership reassignment.
DeleteDefined ownerGuessed record ID.

Questions to resolve

Can frontend hiding enforce access?

No. Test the database and API route with a normal identity.

Do service keys bypass policies?

Treat privileged credentials as a distinct server-only exception and review their use.

What is acceptance evidence?

A repeatable suite showing allowed and cross-tenant denied operations for each important table.

Review cycle

Inventory tables, roles, policies, and privileged paths.

Review checks

Keep results beside migrations.

Role matrix

Operations and actors are stated.

Cross-tenant test

A normal account cannot retrieve or change another tenant's data.

Privileged path

Server-only exceptions are inventoried and tested.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.