Fixcritical riskhigh confidencemoderator reviewed
The RLS Role Confusion That Leaks Every User’s Data
Using `auth.role()` instead of `auth.uid()` in a Supabase RLS policy makes every logged-in user able to read every other user’s data.
By Contributor · published 5/30/2026
Sources
Confidence check
Authorship · HumanHas anyone checked this? · moderator reviewedConfidence · highReviewed · todayEndorsements · 0Challenges · 0Evidence · 0Related guides · 0
Evidence
No evidence linked yet.
Discussion
0 comments
Loading comments…
Sign in to join the discussion.
