[{"data":1,"prerenderedAt":922},["ShallowReactive",2],{"blog-en-infinite-recursion-in-policy-for-relation":3,"blog-index-en":568},{"id":4,"title":5,"body":6,"category":525,"cover":526,"coverAlt":527,"description":528,"draft":529,"extension":530,"faq":531,"image":546,"keywords":547,"meta":556,"navigation":557,"ogTitle":558,"path":559,"published":560,"seo":561,"stem":562,"tldr":563,"updated":560,"__hash__":567},"blog_en\u002Fblog\u002Finfinite-recursion-in-policy-for-relation.md","\"Infinite recursion detected in policy\" without disabling RLS",{"type":7,"value":8,"toc":512},"minimark",[9,13,24,32,37,40,43,60,63,67,70,78,94,100,103,107,113,119,122,126,135,141,144,147,200,210,218,222,228,231,236,239,242,294,297,300,307,315,319,322,332,335,353,369,373,376,393,396,400,406,415,433,444,461,465,504],[10,11,12],"p",{},"You turned Row Level Security on, wrote a rule so that admins can see every\nprofile and everyone else sees only their own, and now not a single screen in\nyour app loads. Every read comes back with the same line:",[14,15,20],"pre",{"className":16,"code":18,"language":19},[17],"language-text","infinite recursion detected in policy for relation \"profiles\"\n","text",[21,22,18],"code",{"__ignoreMap":23},"",[10,25,26,27,31],{},"Most of the answers you will find say the same thing, and it is the wrong thing:\n",[28,29,30],"strong",{},"turn Row Level Security off on that table until you have worked it out."," The\nerror does stop. What stops it is that the table is now readable by anyone who\nvisits your site.",[33,34,36],"h2",{"id":35},"what-infinite-recursion-detected-in-policy-for-relation-means","What \"infinite recursion detected in policy for relation\" means",[10,38,39],{},"A rule on a table had to read that same table before it could answer.",[10,41,42],{},"Picture a doorman who checks every visitor against a guest list, and the guest\nlist is kept inside the room he is guarding. To read the list he has to go in.\nTo go in he has to check the list. There is no first step, so he stands in the\ncorridor and nobody gets anywhere.",[10,44,45,46,49,50,52,53,55,56,59],{},"That is what your database ran into. It was asked for some rows from ",[21,47,48],{},"profiles",",\nwent to the rule on ",[21,51,48],{}," to find out which ones you were allowed to see,\nand the rule told it to look in ",[21,54,48],{},". Postgres spots that it is going\nround, gives up, and raises the error with the code ",[21,57,58],{},"42P17"," attached. Supabase\nhands it to your app unchanged, which is why it reads like machinery.",[10,61,62],{},"The query fails for everyone the rule applies to, so this usually arrives as a\nwhole app going blank at once rather than as one broken screen.",[33,64,66],{"id":65},"the-circle-drawn","The circle, drawn",[10,68,69],{},"The rule that does it is the one almost everybody writes first, because it says\nexactly what you mean:",[14,71,76],{"className":72,"code":74,"language":75,"meta":23},[73],"language-sql","-- Reject: this reads profiles in order to decide who may read profiles.\ncreate policy \"admins read every profile\" on profiles for select\nto authenticated\nusing (\n  exists (\n    select 1 from profiles\n    where id = (select auth.uid()) and role = 'admin'\n  )\n);\n","sql",[21,77,74],{"__ignoreMap":23},[10,79,80,81,84,85,87,88,90,91,93],{},"The ",[21,82,83],{},"exists (select 1 from profiles …)"," is the whole problem. Reading ",[21,86,48],{},"\nmeans applying the rule on ",[21,89,48],{},", which runs ",[21,92,83],{}," again.",[95,96],"diagram",{"alt":97,"caption":98,"src":99},"A visitor's read arrives at a policy, drawn as a lock. The policy sends a question to the profiles table and the table sends it back to the policy, and that pair of arrows forms a closed loop marked 42P17.","The request is fine. The loop is between the rule and the table the rule is protecting.","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fthe-circle-1600x660.png",[10,101,102],{},"Supabase's own Row Level Security guide names the two-table version of this:\npolicies on two tables that each read the other never resolve, and the query\nfails for every role the policies apply to. One table reading itself is the same\nshape with the detour removed.",[33,104,106],{"id":105},"why-does-this-always-happen-on-the-profiles-table","Why does this always happen on the profiles table?",[10,108,109,110,112],{},"Because ",[21,111,48],{}," is where \"who is this person\" is kept.",[10,114,115,116,118],{},"Any rule that treats one kind of person differently from another has to find out\nwhich kind the caller is, and that fact lives in a column on some table.\nWhatever that table is called, the rule protecting it ends up reading it. In an\napp built with Lovable, Bolt, v0 or Replit it is usually ",[21,117,48],{},", because\nthat is where the row about each signed-in person goes. A rule about teams,\norganisations or shared documents produces the same circle on whatever table\nholds the membership.",[10,120,121],{},"So the recursion comes out of writing the obvious rule about the one table that\nhas to answer a question about itself.",[33,123,125],{"id":124},"the-fix-a-helper-that-reads-the-table-from-outside-the-rules","The fix: a helper that reads the table from outside the rules",[10,127,128,129,131,132,134],{},"Move the question into a small function that runs as the database owner, so\nreading ",[21,130,48],{}," to answer it does not go through the rule on ",[21,133,48],{},".",[14,136,139],{"className":137,"code":138,"language":75,"meta":23},[73],"create schema if not exists private;\n\ncreate function private.is_admin()\nreturns boolean\nlanguage sql\nsecurity definer      -- runs as the role that created it\nset search_path = ''  -- so every name inside has to be written in full\nstable\nas $$\n  select exists (\n    select 1 from public.profiles\n    where id = (select auth.uid()) and role = 'admin'\n  );\n$$;\n\nrevoke execute on function private.is_admin() from public;\ngrant usage on schema private to authenticated;\ngrant execute on function private.is_admin() to authenticated;\n\n-- The rule now asks the function instead of the table.\ncreate policy \"admins read every profile\" on profiles for select\nto authenticated\nusing ( (select private.is_admin()) );\n",[21,140,138],{"__ignoreMap":23},[10,142,143],{},"The doorman now has the guest list on a desk in the corridor. He reads it\nwithout opening the door, and the door stays locked for everyone who is not on\nit.",[10,145,146],{},"Four lines in there are doing specific work, and three of them are the\ndifference between a fix and a new hole:",[148,149,150,163,179,188],"ul",{},[151,152,153,158,159,162],"li",{},[28,154,155],{},[21,156,157],{},"security definer"," is what breaks the circle. Supabase's guide defines it\nas a function that runs using the same role that created the function, and on\nSupabase that role is ",[21,160,161],{},"postgres",", which can read past the rules.",[151,164,165,170,171,174,175,178],{},[28,166,167],{},[21,168,169],{},"set search_path = ''"," belongs on every one of these. Supabase's guidance\nis to set it on every security definer function and write the table names out\nin full, because without a pinned ",[21,172,173],{},"search_path"," a caller can point an\nunqualified name at an object of their own and run it with the function\nowner's privileges. That is why the function writes ",[21,176,177],{},"public.profiles"," in full.",[151,180,181,187],{},[28,182,80,183,186],{},[21,184,185],{},"private"," schema"," matters for the same reason. Supabase's guide warns\nthat a security definer function sitting in an exposed schema can be called\nover the Data API with the creator's privileges, and tells you never to create\none in a schema listed under Exposed schemas in your API settings.",[151,189,190,195,196,199],{},[28,191,192],{},[21,193,194],{},"(select private.is_admin())",", wrapped in a select of its own. That lets\nPostgres work the answer out once for the whole statement instead of once per\nrow, which Supabase documents as the reason to wrap ",[21,197,198],{},"auth.uid()"," the same way.",[10,201,80,202,205,206,209],{},[21,203,204],{},"revoke"," and ",[21,207,208],{},"grant"," lines keep the function callable by signed-in users and\nnobody else.",[10,211,212,213,134],{},"That policy covers reading. If saving starts failing once your screens fill up\nagain, you have met\n",[214,215,217],"a",{"href":216},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","a different message with a different cause",[33,219,221],{"id":220},"the-fix-that-is-not-a-fix","The fix that is not a fix",[10,223,224,225,227],{},"Switching Row Level Security off on ",[21,226,48],{}," also clears the error, in one\nclick, and it hands every row in that table to anyone holding the key your app\nships to the browser.",[10,229,230],{},"That key is meant to be public. It is in your site's code, and anybody can read\nit out in a few seconds. The thing that was stopping it from returning your\nwhole user table was the rules you just switched off.",[95,232],{"alt":233,"caption":234,"src":235},"Two routes to the same table. In the first, the lock is still standing and a helper function beside it returns two of six rows. In the second, the lock's position is an empty dashed outline and all six rows come back in red.","Both of these make the error stop. Only one of them still answers the question the rule was asked.","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Ftwo-ways-out-1600x700.png",[10,237,238],{},"Your app looks the same afterwards either way, which is the part that makes this\nstick. Nothing on your screens says which of the two you chose, and the error is\ngone in both.",[10,240,241],{},"What does say so is your database, asked from outside. We have scanned 31,056\nlive apps built with Lovable, Bolt, v0, Replit and the rest, and could see a\nSupabase project behind 8,435 of them. This is what the Row Level Security\ncheck found:",[243,244,245,258],"table",{},[246,247,248],"thead",{},[249,250,251,255],"tr",{},[252,253,254],"th",{},"What we asked",[252,256,257],{},"Apps",[259,260,261,270,278,286],"tbody",{},[249,262,263,267],{},[264,265,266],"td",{},"Had a Supabase project we could see",[264,268,269],{},"8,435",[249,271,272,275],{},[264,273,274],{},"Could be asked the question at all",[264,276,277],{},"3,680",[249,279,280,283],{},[264,281,282],{},"Returned rows to a request with no login",[264,284,285],{},"2,096",[249,287,288,291],{},[264,289,290],{},"Of those, from a table named for people, orders or messages",[264,292,293],{},"394",[10,295,296],{},"The middle row is the honest one. On 4,755 of those apps the check got no answer\nand we say so rather than calling them fine. And some of the 2,096 are meant to\nbe readable, because a public table is a real thing to want; from outside, a\nmenu and a members list look identical.",[10,298,299],{},"We cannot tell you how many of those tables were opened by somebody clearing\nthis exact error. We can tell you that an open table is the ordinary end state\nof the advice at the top of the search results.",[10,301,302,303,134],{},"If you would rather not reason about it, our free scan reads your live site and\ntells you which of your tables answer a stranger. It takes about 20 seconds and\nneeds no account: ",[214,304,306],{"href":305},"\u002Fsecurity-scanner","scan your app",[10,308,309,310,314],{},"One more thing happens when you switch it off. Supabase's own advisor starts\nreporting the table, which is the warning\n",[214,311,313],{"href":312},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","RLS disabled in public",", and that\nwarning will still be there in a month.",[33,316,318],{"id":317},"how-to-tell-whether-the-circle-is-really-gone","How to tell whether the circle is really gone",[10,320,321],{},"The error stopping is not the test, because two different things make it stop.",[10,323,324,325,327,328,331],{},"There is also a way for the helper function to look right and keep recursing,\nand Supabase documents it: a security definer function only skips the rules when\nits owner is allowed to. On Supabase the owner is ",[21,326,161],{},", which has that\nprivilege, so the pattern above works. A function owned by a role without it, or\none\nreading a table set to ",[21,329,330],{},"force row level security",", goes back through the rule\nand stays in the circle.",[10,333,334],{},"Two checks, and do both:",[10,336,337,340,341,344,345,348,349,352],{},[28,338,339],{},"Write the cases down and run them."," Supabase's procedure is a ",[21,342,343],{},".sql"," file\nunder ",[21,346,347],{},"supabase\u002Ftests\u002F"," asserting allow and deny for each operation, for a\nsigned-in user and for an anonymous one, run with ",[21,350,351],{},"supabase test db",". An admin\nmust see every profile, a member must see their own, a stranger must see\nnothing. Until that passes, what you know is that the error stopped.",[10,354,355,358,359,363,364,368],{},[28,356,357],{},"Then ask from outside, with no login."," That is the question a visitor's\nbrowser asks, and it is the only one that reflects what your app actually hands\nout. ",[214,360,362],{"href":361},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Whether a stranger can read your database","\nwalks through it, and\n",[214,365,367],{"href":366},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Row Level Security can be on and the table still public","\ncovers the case where the rules exist and let everyone through anyway.",[33,370,372],{"id":371},"when-the-recursion-is-telling-you-the-schema-is-wrong","When the recursion is telling you the schema is wrong",[10,374,375],{},"Sometimes there is no circular question to remove, because the two tables really\ndo depend on each other.",[10,377,378,379,382,383,386,387,389,390,392],{},"Supabase's guide uses sharing as the example: a rule on ",[21,380,381],{},"lists"," checks\n",[21,384,385],{},"list_members"," to see who the list was shared with, and a rule on ",[21,388,385],{},"\nchecks ",[21,391,381],{}," to see who owns it. Each table's rule reads the other, and neither\ncan go first. The same helper breaks it, with one function returning the list ids\nthe caller belongs to, and both rules asking that function instead of asking each\nother.",[10,394,395],{},"The signal worth noticing is when you need three or four of these to make a\nschema work. At that point the membership is being rebuilt inside the rules\nevery time, and a single table that states plainly who may see what is usually\nless to maintain than the rules you are untangling.",[33,397,399],{"id":398},"keeping-the-table-closed-after-you-fix-it","Keeping the table closed after you fix it",[10,401,402,405],{},[28,403,404],{},"A rule you fixed today describes today's database."," The next policy, the next\ntable, and the next time somebody clears an error at midnight all happen after\nyou last looked, and none of them changes anything you can see on your screens.",[10,407,408],{},[28,409,410,414],{},[214,411,413],{"href":412},"\u002Fpricing","Reeve Monitor"," asks your app the same questions again, on a\nschedule:",[148,416,417,420,427,430],{},[151,418,419],{},"all nine checks every hour, on up to three apps",[151,421,422,423,426],{},"a message when a result ",[28,424,425],{},"changes",", so a table that opened last night does not wait for you to notice",[151,428,429],{},"whether the app is up, every 60 seconds",[151,431,432],{},"a monthly report of what it saw",[10,434,435,443],{},[28,436,437,438,442],{},"If your app keeps its data in your own Supabase project,\n",[214,439,441],{"href":440},"\u002Fsupabase-backups","Reeve Care"," also keeps a copy of that database."," A rule that\nlets a stranger read is one problem. A rule that lets a stranger write is the\nother one, and no check in this article brings deleted rows back.",[148,445,446,449,452,455,458],{},[151,447,448],{},"an encrypted copy of your Supabase database every night, kept where your project cannot reach it",[151,450,451],{},"each copy verified before it counts, by counting the rows in every table",[151,453,454],{},"a one-click restore when you need one",[151,456,457],{},"your uploaded files as well, once you connect a Storage credential",[151,459,460],{},"everything Monitor does",[33,462,464],{"id":463},"what-to-do-right-now","What to do right now",[466,467,468],"key-takeaways",{},[148,469,470,473,482,488,497],{},[151,471,472],{},"Leave Row Level Security on. The error is about one rule, and switching the rules off is a change to the whole table.",[151,474,475,476,478,479,481],{},"Move the role check into a ",[21,477,157],{}," function in a schema that is not exposed, with ",[21,480,169],{}," and every table name written out in full.",[151,483,484,485,487],{},"Point the policy at the function, wrapped as ",[21,486,194],{},", so it runs once per statement rather than once per row.",[151,489,490,491,493,494,496],{},"Write the allow and deny cases under ",[21,492,347],{}," and run ",[21,495,351],{},": an admin sees every profile, a member sees their own, a stranger sees nothing.",[151,498,499,500,134],{},"If you already switched Row Level Security off to get moving, put it back today and fix the rule properly. Supabase's advisor will keep reporting that table until you do, and ",[214,501,503],{"href":502},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","it belongs on every table you have",[10,505,506,507,511],{},"If you want the rest of the list for a newly launched app, the\n",[214,508,510],{"href":509},"\u002Fchecklist","10-minute security checklist"," covers this and the other things\nworth closing before anybody finds them.",{"title":23,"searchDepth":513,"depth":513,"links":514},3,[515,517,518,519,520,521,522,523,524],{"id":35,"depth":516,"text":36},2,{"id":65,"depth":516,"text":66},{"id":105,"depth":516,"text":106},{"id":124,"depth":516,"text":125},{"id":220,"depth":516,"text":221},{"id":317,"depth":516,"text":318},{"id":371,"depth":516,"text":372},{"id":398,"depth":516,"text":399},{"id":463,"depth":516,"text":464},"Security basics","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcover-1200x630.png","A locked table panel with its own key drawn inside it, behind the glass, and a bar across the door.","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.",false,"md",[532,535,538,541,543],{"q":533,"a":534},"What causes \"infinite recursion detected in policy for relation\"?","A rule on a table that has to read that same table before it can answer. Your rule says something like \"let this person through if their row in profiles says they are an admin\", so the database goes to read that row in profiles, which means checking the rule on profiles, which sends it back to read the row again. Postgres notices it is going round, stops, and raises error 42P17. The same thing happens across two tables whose rules each read the other one.",{"q":536,"a":537},"Is it safe to use a security definer function in a policy?","Yes, with two conditions Supabase names in its own Row Level Security guide. Set search_path to the empty string on the function and write every table name inside it in full, as public.profiles rather than profiles. Without that, somebody can point an unqualified name at an object of their own and have it run with the function owner's privileges. And create the function in a schema that is not exposed over the API, because a security definer function in an exposed schema can be called from outside with the creator's privileges.",{"q":539,"a":540},"Should I disable RLS to fix it?","It clears the error and it opens the table. With Row Level Security off, every row in that table can be read by anyone holding the key your app ships to the browser, which is a key anyone can read out of your site. Your app behaves identically either way, so nothing afterwards tells you which of the two you picked. The helper function below clears the error and keeps the table closed.",{"q":106,"a":542},"Because profiles is where the answer to \"who is this person\" usually lives. A rule that treats admins differently, or members of a team differently, needs to know which the caller is, and that fact is stored in profiles. So the rule protecting profiles ends up reading profiles. Any table that holds the caller's role or membership can produce it, and in an app built with Lovable, Bolt or v0 that table is usually the one called profiles.",{"q":544,"a":545},"How do I check my policy actually works?","Two different things make the error stop, so the error stopping tells you very little on its own. Write the allow and deny cases into a .sql file under supabase\u002Ftests\u002F and run supabase test db, which is the procedure Supabase publishes with the guide: a signed-in owner has to be allowed and a stranger has to be refused. Then ask your database the same question from outside, with no login at all, the way a visitor's browser would.","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",[548,549,550,551,552,553,554,555],"infinite recursion detected in policy for relation","supabase infinite recursion policy","infinite recursion rls supabase","supabase policy recursion error","42P17 supabase","rls policy infinite loop","supabase profiles policy recursion","supabase role check policy error",{},true,"Infinite recursion detected in policy","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","2026-10-08",{"title":5,"description":528},"blog\u002Finfinite-recursion-in-policy-for-relation",[564,565,566],"\"Infinite recursion detected in policy for relation\" is Postgres error 42P17. A Row Level Security rule on a table went and asked that same table a question, and the question has no end.","It is not a sign that Row Level Security was wrong for your app. It is a sign that one rule asked in a circle.","A small helper function reads the table from outside the rules and breaks the circle. Switching Row Level Security off on that table also clears the error, by handing every row in it to anyone holding the key that ships inside your app.","6fE-nEEpByuru6eSRlheWBmhhf2_dcyuSWSjFy0XnQA",[569,575,581,587,588,594,600,606,612,618,624,630,636,642,649,655,661,666,672,678,684,690,696,702,708,714,720,726,732,738,744,750,756,761,766,772,778,784,790,796,802,808,814,820,826,832,838,843,849,855,861,867,873,879,884,889,895,901,906,911,917],{"path":570,"title":571,"description":572,"published":573,"category":525,"image":574,"draft":529},"\u002Fblog\u002Fstorage-upload-violates-row-level-security","\"Row-level security policy for table objects\" on upload","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.","2026-10-11","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",{"path":576,"title":577,"description":578,"published":579,"category":525,"image":580,"draft":529},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":582,"title":583,"description":584,"published":585,"category":525,"image":586,"draft":529},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":559,"title":5,"description":528,"published":560,"category":525,"image":546,"draft":529},{"path":589,"title":590,"description":591,"published":592,"category":525,"image":593,"draft":529},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":595,"title":596,"description":597,"published":598,"category":525,"image":599,"draft":529},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":601,"title":602,"description":603,"published":604,"category":525,"image":605,"draft":529},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":607,"title":608,"description":609,"published":610,"category":525,"image":611,"draft":529},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":613,"title":614,"description":615,"published":616,"category":525,"image":617,"draft":529},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":619,"title":620,"description":621,"published":622,"category":525,"image":623,"draft":529},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":625,"title":626,"description":627,"published":628,"category":525,"image":629,"draft":529},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":631,"title":632,"description":633,"published":634,"category":525,"image":635,"draft":529},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":637,"title":638,"description":639,"published":640,"category":525,"image":641,"draft":529},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":643,"title":644,"description":645,"published":646,"category":647,"image":648,"draft":529},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":650,"title":651,"description":652,"published":653,"category":647,"image":654,"draft":529},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":656,"title":657,"description":658,"published":659,"category":647,"image":660,"draft":529},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":662,"title":663,"description":664,"published":659,"category":525,"image":665,"draft":529},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":667,"title":668,"description":669,"published":670,"category":525,"image":671,"draft":529},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":673,"title":674,"description":675,"published":676,"category":525,"image":677,"draft":529},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":679,"title":680,"description":681,"published":682,"category":647,"image":683,"draft":529},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":685,"title":686,"description":687,"published":688,"category":525,"image":689,"draft":529},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":691,"title":692,"description":693,"published":694,"category":525,"image":695,"draft":529},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":697,"title":698,"description":699,"published":700,"category":525,"image":701,"draft":529},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":703,"title":704,"description":705,"published":706,"category":525,"image":707,"draft":529},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":709,"title":710,"description":711,"published":712,"category":525,"image":713,"draft":529},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":715,"title":716,"description":717,"published":718,"category":525,"image":719,"draft":529},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":721,"title":722,"description":723,"published":724,"category":525,"image":725,"draft":529},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":727,"title":728,"description":729,"published":730,"category":525,"image":731,"draft":529},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":733,"title":734,"description":735,"published":736,"category":647,"image":737,"draft":529},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":739,"title":740,"description":741,"published":742,"category":647,"image":743,"draft":529},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":745,"title":746,"description":747,"published":748,"category":647,"image":749,"draft":529},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":751,"title":752,"description":753,"published":754,"category":525,"image":755,"draft":529},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":502,"title":757,"description":758,"published":759,"category":525,"image":760,"draft":529},"Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":312,"title":762,"description":763,"published":764,"category":525,"image":765,"draft":529},"Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":767,"title":768,"description":769,"published":770,"category":525,"image":771,"draft":529},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":773,"title":774,"description":775,"published":776,"category":525,"image":777,"draft":529},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":779,"title":780,"description":781,"published":782,"category":525,"image":783,"draft":529},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":785,"title":786,"description":787,"published":788,"category":525,"image":789,"draft":529},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":791,"title":792,"description":793,"published":794,"category":525,"image":795,"draft":529},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":797,"title":798,"description":799,"published":800,"category":525,"image":801,"draft":529},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":803,"title":804,"description":805,"published":806,"category":525,"image":807,"draft":529},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":809,"title":810,"description":811,"published":812,"category":647,"image":813,"draft":529},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":815,"title":816,"description":817,"published":818,"category":525,"image":819,"draft":529},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":821,"title":822,"description":823,"published":824,"category":647,"image":825,"draft":529},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":827,"title":828,"description":829,"published":830,"category":525,"image":831,"draft":529},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":833,"title":834,"description":835,"published":836,"category":525,"image":837,"draft":529},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":216,"title":839,"description":840,"published":841,"category":525,"image":842,"draft":529},"New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":844,"title":845,"description":846,"published":847,"category":525,"image":848,"draft":529},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":850,"title":851,"description":852,"published":853,"category":647,"image":854,"draft":529},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":856,"title":857,"description":858,"published":859,"category":647,"image":860,"draft":529},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":862,"title":863,"description":864,"published":865,"category":525,"image":866,"draft":529},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":868,"title":869,"description":870,"published":871,"category":525,"image":872,"draft":529},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":874,"title":875,"description":876,"published":877,"category":647,"image":878,"draft":529},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":361,"title":880,"description":881,"published":882,"category":525,"image":883,"draft":529},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":885,"title":886,"description":887,"published":882,"category":525,"image":888,"draft":529},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":890,"title":891,"description":892,"published":893,"category":525,"image":894,"draft":529},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":896,"title":897,"description":898,"published":899,"category":647,"image":900,"draft":529},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":366,"title":902,"description":903,"published":904,"category":525,"image":905,"draft":529},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":907,"title":908,"description":909,"published":904,"category":647,"image":910,"draft":529},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":912,"title":913,"description":914,"published":915,"category":647,"image":916,"draft":529},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":918,"title":919,"description":920,"published":915,"category":525,"image":921,"draft":529},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]