RLS enabled isn't proof: how do you verify Supabase privacy after every migration?

Real_KingZeotic · reddit · 2026-10-02

A developer asks how to prove Supabase data stays private as AI agents keep adding tables and migrations. "RLS enabled" in the dashboard is a status, not evidence — past leaks involved anon users reading whole tables, service keys bundled in frontends, and policies left as true.

His current workflow is manually curling tables as anon, which is tedious and error-prone. He's looking for tools or repos that retest anon and wrong-user access after every migration and ideally block deploys when a table opens up, rather than alerting after the fact.

Original post →

More from coding & agent

coding & agent channel →