Andei depurando vazamentos de RLS em setups multi-tenant no Supabase e queria compartilhar os 3 mais comuns que sempre encontro:
Uma política permissiva (\`using (true)\`) esquecida de um debug
RLS habilitado mas não FORÇADO — o dono da tabela contorna silenciosamente
Uma view sobre a tabela protegida sem \`security\_invoker\` — vaza mesmo com a tabela base configurada certo
Checagem rápida pro seu banco:
select relname from pg\_class
where relrowsecurity and not relforcerowsecurity;
Fiz uma ferramenta que automatiza isso + mais algumas checagens, fico à vontade pra compartilhar se alguém quiser uma auditoria gratuita do setup 🙂
The user shares insights on common Row Level Security (RLS) leaks in multi-tenant Supabase applications. They identify three frequent issues: permissive policies left from debugging, RLS enabled but not enforced, and views over protected tables without 'security_invoker'. The user offers a tool for automated checks and a free audit of setups.