100% Free Developer Utility
Supabase Row Level Security (RLS) Policy Generator
AI scaffolding tools love creating Supabase tables without enabling Row Level Security. That leaves your database tables completely open to any browser with an anon key. Generate clean, battle-tested PostgreSQL RLS migrations in seconds.
Select Access Pattern
The Missing Index Trap
When you enable RLS on a table with 20,000 rows without an index on user_id, PostgreSQL has to scan all 20,000 rows on every single query to verify ownership.
Adding CREATE INDEX makes policy lookups instantaneous (under 2ms).
Generated PostgreSQL Migration
-- Step 1: Enable Row Level Security (RLS) on projects
ALTER TABLE public.projects ENABLE ROW LEVEL SECURITY;
-- Step 2: Policy: Users can view only their own records
CREATE POLICY "Users can view own projects"
ON public.projects
FOR SELECT
TO authenticated
USING (auth.uid() = user_id);
-- Step 3: Policy: Users can insert rows scoped to their auth.uid()
CREATE POLICY "Users can insert own projects"
ON public.projects
FOR INSERT
TO authenticated
WITH CHECK (auth.uid() = user_id);
-- Step 4: Policy: Users can update their own records
CREATE POLICY "Users can update own projects"
ON public.projects
FOR UPDATE
TO authenticated
USING (auth.uid() = user_id)
WITH CHECK (auth.uid() = user_id);
-- Step 5: Policy: Users can delete their own records
CREATE POLICY "Users can delete own projects"
ON public.projects
FOR DELETE
TO authenticated
USING (auth.uid() = user_id);
-- Step 6: Critical Performance Index (stops sequential table scan on every RLS check)
CREATE INDEX IF NOT EXISTS idx_projects_user_id ON public.projects (user_id);1-Click Cursor Prompt to Apply
Apply this PostgreSQL migration in Supabase to secure table "projects": ```sql -- Step 1: Enable Row Level Security (RLS) on projects ALTER TABLE public.projects ENABLE ROW LEVEL SECURITY; -- Step 2: Policy: Users can view only their own records CREATE POLICY "Users can view own projects" ON public.projects FOR SELECT TO authenticated USING (auth.uid() = user_id); -- Step 3: Policy: Users can insert rows scoped to their auth.uid() CREATE POLICY "Users can insert own projects" ON public.projects FOR INSERT TO authenticated WITH CHECK (auth.uid() = user_id); -- Step 4: Policy: Users can update their own records CREATE POLICY "Users can update own projects" ON public.projects FOR UPDATE TO authenticated USING (auth.uid() = user_id) WITH CHECK (auth.uid() = user_id); -- Step 5: Policy: Users can delete their own records CREATE POLICY "Users can delete own projects" ON public.projects FOR DELETE TO authenticated USING (auth.uid() = user_id); -- Step 6: Critical Performance Index (stops sequential table scan on every RLS check) CREATE INDEX IF NOT EXISTS idx_projects_user_id ON public.projects (user_id); ``` Please verify: 1. Ensure the migration runs cleanly and idempotently. 2. Confirm Row Level Security is active and verified for authenticated clients. 3. Test that queries from unauthenticated users or different user IDs are properly rejected.
Did your AI assistant forget RLS on other tables?
Supabase RLS is Check 14 of our 108 launch criteria. The Founder Pass ($15 one-time) scans your migration files and database schemas to ensure zero tables leak data to unauthorized anon keys.