[{"data":1,"prerenderedAt":964},["ShallowReactive",2],{"blog-en-storage-upload-violates-row-level-security":3,"blog-index-en":607},{"id":4,"title":5,"body":6,"category":563,"cover":564,"coverAlt":565,"description":566,"draft":567,"extension":568,"faq":569,"image":585,"keywords":586,"meta":594,"navigation":595,"ogTitle":596,"path":597,"published":598,"seo":599,"stem":600,"tldr":601,"updated":598,"__hash__":606},"blog_en\u002Fblog\u002Fstorage-upload-violates-row-level-security.md","\"Row-level security policy for table objects\" on upload",{"type":7,"value":8,"toc":550},"minimark",[9,13,24,31,39,44,51,57,70,74,77,87,99,105,109,112,118,121,129,133,136,142,154,157,174,181,264,267,272,276,279,282,288,294,297,303,317,324,331,335,338,344,353,360,367,370,376,389,394,400,404,407,410,413,423,427,430,439,459,468,485,488,492,537],[10,11,12],"p",{},"Your app uploads a file. It worked in your builder's preview, or it worked last\nweek, and now every attempt comes back with a sentence about row-level security:",[14,15,20],"pre",{"className":16,"code":18,"language":19},[17],"language-text","new row violates row-level security policy for table \"objects\"\n","text",[21,22,18],"code",{"__ignoreMap":23},"",[10,25,26,27,30],{},"Most of that sentence will look familiar if you have already been through this\non one of your own tables. The last word is the part that is different, because\n",[21,28,29],{},"objects"," is not a table you made.",[10,32,33,34,38],{},"Here is the part that guide after guide gets wrong: ",[35,36,37],"strong",{},"the first fix you will\nfind is to make the bucket public, and it does nothing to uploads."," Supabase's\nown documentation says as much in one line. Flipping that toggle leaves the\nupload refused and opens the files that were already in there.",[40,41,43],"h2",{"id":42},"what-new-row-violates-row-level-security-policy-for-table-objects-means","What \"new row violates row-level security policy for table objects\" means",[10,45,46,47,50],{},"Your upload reached Supabase Storage, Storage asked the rules on a table called\n",[21,48,49],{},"storage.objects"," whether that file was allowed in, found none that said yes,\nand refused.",[10,52,53,54,56],{},"The row in the message is real. Storage keeps one row in ",[21,55,49],{}," for\nevery file it holds, carrying the file's name, which bucket it is in and who put\nit there. Writing a file means writing that row, so the rules on that table\ndecide whether the upload happens at all. Nothing was lost: no file was stored,\nand the rest of the bucket sits exactly as it did a minute ago.",[10,58,59,60,63,64,69],{},"The wording comes from Postgres, the database engine underneath Supabase, which\nis why it reads like machinery. It carries the code ",[21,61,62],{},"42501",", the same code\nyou get when\n",[65,66,68],"a",{"href":67},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","a save into one of your own tables is refused",".",[40,71,73],{"id":72},"why-the-message-names-objects-and-not-your-bucket","Why the message names \"objects\" and not your bucket",[10,75,76],{},"Because Storage keeps the rules for every bucket in your project on that one\ntable.",[10,78,79,80,82,83,86],{},"A bucket organises files. It does not hold rules of its own, and there is no\npolicy editor attached to it. ",[21,81,49],{}," is where the rules live, for all\nof your buckets at once, and ",[21,84,85],{},"bucket_id"," is a column on it. So a rule that says\n\"only in the avatars bucket\" is written as a condition on that column.",[10,88,89,90,93,94,96,97,69],{},"This is also why the table rule you wrote last week did not help. A rule on\n",[21,91,92],{},"profiles"," is a rule about rows in ",[21,95,92],{},", and a file is a row in\n",[21,98,49],{},[100,101],"diagram",{"alt":102,"caption":103,"src":104},"Three buckets side by side, each with an arrow running down into one wide panel labelled storage.objects that carries three policy chips and a column name. Across a dashed divider on the left, a dimmer card labelled profiles holds its own rows and its own insert chip, with no line joining it to anything.","Every bucket in your project is governed from the same table. The rules you wrote on your own tables sit on the other side of that divider and never meet a file.","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fone-table-every-bucket-1600x720.png",[40,106,108],{"id":107},"do-i-need-to-make-the-bucket-public-to-upload","Do I need to make the bucket public to upload?",[10,110,111],{},"No. Two different questions sit behind one bucket, and the toggle only answers\none of them. Who may take a file out is what public decides. Who may put a file\nin is what your error is about, and Supabase's documentation is explicit that\nthe setting does not reach it. From the page describing the two kinds of bucket,\nread on 11 October 2026:",[113,114,115],"blockquote",{},[10,116,117],{},"Access control is still enforced for other types of operations including\nuploading, deleting, moving, and copying.",[10,119,120],{},"What public does do is just as plainly stated on that page: anyone who has the\naddress of a file can open it without signing in. That is the whole of the\nsetting.",[10,122,123,124,128],{},"So flipping it leaves you in the one state nobody wants. The upload is still\nrefused, because uploading was never what the setting controlled, and the files\nthat were already in the bucket can now be opened by anybody who has their\naddresses. ",[65,125,127],{"href":126},"\u002Fblog\u002Fsupabase-storage-bucket-public","What a public bucket actually costs you","\nis a separate question from this error, and worth reading before you touch the\nswitch.",[40,130,132],{"id":131},"what-a-bucket-actually-checks-when-you-upload","What a bucket actually checks when you upload",[10,134,135],{},"One rule, and its name is insert.",[10,137,138,139,141],{},"Supabase's access-control page puts the default plainly: Storage does not allow\nany uploads to buckets without policies, and you allow operations selectively by\nwriting them on ",[21,140,49],{},". Then it names the one you need:",[113,143,144],{},[10,145,146,147,150,151,153],{},"For example, the only RLS policy required for uploading objects is to grant\nthe ",[21,148,149],{},"INSERT"," permission to the ",[21,152,49],{}," table.",[10,155,156],{},"There is a second half to that, and it is the commonest reason an insert rule\ndoes not clear the error:",[113,158,159],{},[10,160,161,162,165,166,169,170,173],{},"To allow overwriting files using the ",[21,163,164],{},"upsert"," functionality you will need to\nadditionally grant ",[21,167,168],{},"SELECT"," and ",[21,171,172],{},"UPDATE"," permissions.",[10,175,176,177,180],{},"If your upload passes ",[21,178,179],{},"upsert: true",", which asks Storage to replace a file of\nthe same name when one is already there, then an insert rule on its own is not\nenough. Replacing a file is three questions rather than one: may you add this\nrow, may you see the row that is there, and may you change it.",[182,183,184,199],"table",{},[185,186,187],"thead",{},[188,189,190,194],"tr",{},[191,192,193],"th",{},"What your app asks Storage to do",[191,195,196,197],{},"What it needs on ",[21,198,49],{},[200,201,202,215,235,245,254],"tbody",{},[188,203,204,208],{},[205,206,207],"td",{},"upload a new file",[205,209,210,211,214],{},"an ",[21,212,213],{},"insert"," rule",[188,216,217,223],{},[205,218,219,220,222],{},"replace a file of the same name (",[21,221,164],{},")",[205,224,225,227,228,169,231,234],{},[21,226,213],{},", and ",[21,229,230],{},"select",[21,232,233],{},"update"," as well",[188,236,237,240],{},[205,238,239],{},"open a file in a private bucket",[205,241,242,243,214],{},"a ",[21,244,230],{},[188,246,247,250],{},[205,248,249],{},"list what is in a bucket",[205,251,242,252,214],{},[21,253,230],{},[188,255,256,259],{},[205,257,258],{},"delete a file",[205,260,242,261,214],{},[21,262,263],{},"delete",[10,265,266],{},"You do not have to write all five. Write the ones your app actually does, which\nfor most uploads is the first row and sometimes the second.",[100,268],{"alt":269,"caption":270,"src":271},"A lidded store of files with two openings in its right wall. The upper opening has a bar across it, and a document approaching from outside is turned back by a cross. The lower opening has its bar lifted clear, and a file passes out through it to a waiting figure beside a tick. A toggle switch below is joined by a single line to the lower opening and to nothing else.","One store, two openings. The toggle is wired to the lower one. An upload arrives at the upper one, where a rule nobody has written yet decides whether it goes in.","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Ftwo-counters-1600x720.png",[40,273,275],{"id":274},"the-rule-that-lets-your-app-upload-and-only-your-app","The rule that lets your app upload, and only your app",[10,277,278],{},"Name the bucket, and say who the rule is for.",[10,280,281],{},"The documentation's own starting point restricts an upload to one bucket and to\nsigned-in visitors:",[14,283,286],{"className":284,"code":285,"language":19},[17],"create policy \"Allow authenticated uploads\"\non storage.objects\nfor insert\nto authenticated\nwith check (bucket_id = 'my_bucket_id');\n",[21,287,285],{"__ignoreMap":23},[10,289,290,293],{},[21,291,292],{},"to authenticated"," is the part worth not skipping. It means the rule applies to\nvisitors who are signed in; leave it out and the rule applies to everybody,\nstrangers included.",[10,295,296],{},"For anything belonging to one particular person, the version Supabase publishes\nputs each person's files in a folder named after them:",[14,298,301],{"className":299,"code":300,"language":19},[17],"create policy \"Allow authenticated uploads\"\non storage.objects\nfor insert\nto authenticated\nwith check (\n  bucket_id = 'my_bucket_id' and\n  (storage.foldername(name))[1] = (select auth.jwt()->>'sub')\n);\n",[21,302,300],{"__ignoreMap":23},[10,304,305,308,309,312,313,316],{},[21,306,307],{},"storage.foldername(name)"," splits a stored file's path into its folders, so\n",[21,310,311],{},"[1]"," is the first one. ",[21,314,315],{},"auth.jwt()->>'sub'"," is the id of whoever is signed in\nand making the request. Read together, the two lines say that you may put a file\nin the folder named after you, in that bucket, and nowhere else.",[10,318,319,320,323],{},"Both of those are Supabase's examples rather than ours, read on 11 October 2026,\nwith ",[21,321,322],{},"my_bucket_id"," left where they left it so you can see which part is the\nname of your own bucket.",[10,325,326,327,69],{},"If you would rather see the result from outside, our free scan asks your live\nproject which of your buckets will hand their contents to a stranger. It takes\nabout 20 seconds and needs no account: ",[65,328,330],{"href":329},"\u002Fsecurity-scanner","scan your app",[40,332,334],{"id":333},"what-a-read-rule-hands-over-without-being-asked","What a read rule hands over without being asked",[10,336,337],{},"Listing a bucket and downloading from it are the same privilege, so a rule\nwritten to make your downloads work also makes the bucket's contents listable.",[10,339,340,341,343],{},"Supabase's helper-function page says it directly: a single SQL privilege such as\n",[21,342,168],{}," is used by multiple Storage actions. The access-control page then warns\nabout the specific case, under an example that opens a bucket of avatars to\neverybody:",[113,345,346],{},[10,347,348,349,352],{},"The ",[21,350,351],{},"allow_any_operation()"," filter is critical here as without it users would\nbe able to list the bucket contents.",[10,354,355,356,359],{},"That is the gap we measure from outside. We have scanned 8,435 live apps that\nname a Supabase project. The bucket check got an answer out of 4,703 of them,\nand ",[35,357,358],{},"792 of those answered a list request from us with the names of what was\ninside",", with nobody signed in. That is about one in six of the apps we could\nask.",[10,361,362,363,366],{},"A name is often all somebody needs, because a bucket that lists saves a stranger\nfrom guessing filenames. ",[21,364,365],{},"invoice-2026-03-hannah.pdf"," says who the file belongs\nto before anybody opens it.",[10,368,369],{},"The fix Supabase documents is to say which Storage action the rule is for:",[14,371,374],{"className":372,"code":373,"language":19},[17],"create policy \"Allow users to list their own objects\"\non storage.objects\nfor select\nto authenticated\nusing (\n  storage.allow_only_operation('object.list')\n  and owner_id = (select auth.uid()::text)\n);\n",[21,375,373],{"__ignoreMap":23},[10,377,378,381,382,385,386,388],{},[21,379,380],{},"storage.allow_only_operation"," and its sibling ",[21,383,384],{},"storage.allow_any_operation"," are\nhow a ",[21,387,230],{}," rule narrows itself to one of the actions that share the\nprivilege. Without one of them, a rule you wrote so that your app could show a\npicture is also a rule that will read out everything in the bucket.",[100,390],{"alt":391,"caption":392,"src":393},"One box labelled select with two branches leaving it. The upper branch reaches a single document, which is handed on to a figure beside a tick. The lower branch passes a narrow plate drawn as a dashed outline and reaches a stack of six lit rows, marked with a cross.","One rule, two different Storage actions. The plate on the lower route is the operation filter, and the dashes are what it looks like when nobody wrote one.","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fone-rule-two-actions-1600x700.png",[10,395,396,399],{},[65,397,398],{"href":126},"Whether a listable bucket is a problem for your app","\ndepends on what is in it, which is a question the scan result cannot answer for\nyou.",[40,401,403],{"id":402},"when-public-is-the-right-answer","When public is the right answer",[10,405,406],{},"When the files are meant to be seen by anybody who asks, which is a real\ncategory, and Supabase lists its own examples of it.",[10,408,409],{},"Supabase's own example use cases for a public bucket are profile pictures,\npublic media and blog post content. Those are files your app shows to a visitor\nwho has not signed in, and serving them from a public bucket is faster as well,\nbecause the two kinds of bucket are cached differently.",[10,411,412],{},"For the other kind, the documentation names two ways to get a file out of a\nprivate bucket: a download carrying the signed-in person's token, or a signed\nlink that works for a limited time. Both of those keep the decision with your\nrules rather than with whoever found the address.",[414,415,417],"callout",{"type":416},"warn",[10,418,419,422],{},[35,420,421],{},"Buckets are private by default."," A bucket you created and never thought about\nagain is already in the stricter of the two states, which means the error you are\nreading is the default behaving as designed. Write the rule and the upload goes\nthrough; the toggle has no say in that question either way.",[40,424,426],{"id":425},"keeping-the-bucket-right-after-today","Keeping the bucket right after today",[10,428,429],{},"Two things move after the rules are correct: somebody flips the toggle while\nchasing an unrelated bug, and a file goes missing.",[10,431,432],{},[35,433,434,438],{},[65,435,437],{"href":436},"\u002Fpricing","Reeve Monitor"," runs the nine outside checks again for you:",[440,441,442,446,449,456],"ul",{},[443,444,445],"li",{},"all nine checks every hour, on up to three apps, including the bucket listing one",[443,447,448],{},"whether the app is up, every 60 seconds",[443,450,451,452,455],{},"a message when a result ",[35,453,454],{},"changes",", so a bucket that opened last night does not wait for you to look",[443,457,458],{},"a monthly report of what it saw",[10,460,461],{},[35,462,463,467],{},[65,464,466],{"href":465},"\u002Fsupabase-backups","Reeve Care"," keeps a copy of what is in there:",[440,469,470,473,476,479,482],{},[443,471,472],{},"an encrypted copy of your Supabase database every night, kept where your project cannot reach it",[443,474,475],{},"each copy verified before it counts, by counting the rows in every table",[443,477,478],{},"your uploaded files as well, once you connect a Storage credential",[443,480,481],{},"a one-click restore when you need one",[443,483,484],{},"everything Monitor does",[10,486,487],{},"Both are on the pricing page, which is sometimes below the list figure and never\nabove it.",[40,489,491],{"id":490},"what-to-do-today","What to do today",[493,494,495],"key-takeaways",{},[440,496,497,500,516,526,529],{},[443,498,499],{},"Read the message as a refusal. The file was not stored, the bucket is unchanged, and nothing needs recovering.",[443,501,502,503,505,506,508,509,511,512,515],{},"Add an ",[21,504,213],{}," rule on ",[21,507,49],{}," that names your bucket in ",[21,510,85],{}," and carries the ",[21,513,514],{},"TO"," clause you meant.",[443,517,176,518,520,521,169,523,525],{},[21,519,179],{},", add ",[21,522,230],{},[21,524,233],{}," as well, or the insert rule alone will not clear the error.",[443,527,528],{},"Leave the public toggle where it is while you do this. It has no say over uploads and it does have a say over who can open what is already stored.",[443,530,531,532,505,534,536],{},"Read every ",[21,533,230],{},[21,535,49],{}," and ask what it allows besides the download you wrote it for. Listing shares that privilege.",[10,538,539,540,544,545,549],{},"Start with the bucket the error came from, then look at the other buckets in the\nsame project, because a rule written broadly once tends to have been pasted\ntwice. The ",[65,541,543],{"href":542},"\u002Fchecklist","10-minute security checklist"," covers what else is\nusually left open in a newly launched app, and the\n",[65,546,548],{"href":547},"\u002Fis-your-supabase-app-safe","Supabase safety guide"," goes through the rest of\nwhat a stranger can reach.",{"title":23,"searchDepth":551,"depth":551,"links":552},3,[553,555,556,557,558,559,560,561,562],{"id":42,"depth":554,"text":43},2,{"id":72,"depth":554,"text":73},{"id":107,"depth":554,"text":108},{"id":131,"depth":554,"text":132},{"id":274,"depth":554,"text":275},{"id":333,"depth":554,"text":334},{"id":402,"depth":554,"text":403},{"id":425,"depth":554,"text":426},{"id":490,"depth":554,"text":491},"Security basics","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcover-1200x630.png","A barred delivery slot with a document held outside it, and behind it a shelf of files with a lid drawn across the top.","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.",false,"md",[570,573,576,579,582],{"q":571,"a":572},"Why does my Supabase upload fail with a row-level security error?","Because Supabase Storage asked the rules on a table called storage.objects whether your file was allowed in, and found no rule that said yes. Storage writes one row into that table for every file it keeps, and row-level security applies to that row exactly as it applies to a row in any other table. No file was stored and nothing already in the bucket changed. The message carries the Postgres code 42501, the same code you get when a save into your own table is refused.",{"q":574,"a":575},"Do I need to make my bucket public to upload?","No, and making it public will not help. Supabase documents that access control is still enforced for uploading, deleting, moving and copying whichever setting the bucket is on. Public changes one thing: whether somebody holding a file address can open that file without signing in. So the toggle leaves your upload refused and makes the files already in there openable by anyone who has their address.",{"q":577,"a":578},"What policies does a bucket need?","An upload needs one insert rule on storage.objects. If your code replaces files of the same name, which is what upsert does, Supabase says you also need select and update. Opening a file in a private bucket needs a select rule, and so does listing what is in the bucket, because both of those Storage actions run on the same SQL privilege. Deleting needs a delete rule. There is no requirement to write all four, only the ones your app actually does.",{"q":580,"a":581},"Is a public bucket dangerous?","It depends entirely on what is in it. Public is the correct setting for profile pictures, logos and anything else your app shows to a visitor who has not signed in, which is what Supabase lists as its own example use cases. It is the wrong setting for invoices, exports or anything belonging to one particular person, and for those a private bucket with a signed link is the shape you want. The question was never whether public is bad.",{"q":583,"a":584},"How do I check whether my bucket is listable?","Ask it from outside, with no account signed in, exactly as a stranger would. Listing is granted by a select rule rather than by the public toggle, so neither the dashboard toggle nor a glance at your policy list answers it. Our free scan does this on your live project and tells you which of your buckets answered with the names of what was inside.","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",[587,588,589,590,591,592,593],"new row violates row-level security policy for table objects","supabase storage upload rls error","supabase storage policy upload","supabase bucket upload 403","storage objects rls supabase","supabase upload permission denied","supabase storage policy example",{},true,"\"Row-level security policy for table objects\"","\u002Fblog\u002Fstorage-upload-violates-row-level-security","2026-10-11",{"title":5,"description":566},"blog\u002Fstorage-upload-violates-row-level-security",[602,603,604,605],"\"New row violates row-level security policy for table objects\" means your upload reached Supabase Storage and no rule on storage.objects allowed it in. The file was not stored, and the rest of the bucket is untouched.","Storage keeps its rules on one table for every bucket in your project, which is why the message names a table you never made.","Making the bucket public does not clear it. Supabase checks uploads either way, and public only decides who can open a file they already have the address of.","The rule an upload needs is an insert rule on storage.objects. If your code saves with upsert, it needs select and update as well.","Ji-qq29yz7nrYsiCLw5Fyyo3srdFVakt_HJ1zDrqNJs",[608,609,615,621,627,633,639,645,651,657,663,669,675,681,688,694,700,705,711,717,723,729,735,741,747,753,759,765,771,777,783,789,795,801,807,813,819,825,831,837,843,849,855,861,867,873,879,884,890,896,902,907,913,919,925,930,936,942,948,953,959],{"path":597,"title":5,"description":566,"published":598,"category":563,"image":585,"draft":567},{"path":610,"title":611,"description":612,"published":613,"category":563,"image":614,"draft":567},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":616,"title":617,"description":618,"published":619,"category":563,"image":620,"draft":567},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":622,"title":623,"description":624,"published":625,"category":563,"image":626,"draft":567},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":628,"title":629,"description":630,"published":631,"category":563,"image":632,"draft":567},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":634,"title":635,"description":636,"published":637,"category":563,"image":638,"draft":567},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":640,"title":641,"description":642,"published":643,"category":563,"image":644,"draft":567},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":646,"title":647,"description":648,"published":649,"category":563,"image":650,"draft":567},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":652,"title":653,"description":654,"published":655,"category":563,"image":656,"draft":567},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":658,"title":659,"description":660,"published":661,"category":563,"image":662,"draft":567},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":664,"title":665,"description":666,"published":667,"category":563,"image":668,"draft":567},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":670,"title":671,"description":672,"published":673,"category":563,"image":674,"draft":567},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":676,"title":677,"description":678,"published":679,"category":563,"image":680,"draft":567},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":682,"title":683,"description":684,"published":685,"category":686,"image":687,"draft":567},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":689,"title":690,"description":691,"published":692,"category":686,"image":693,"draft":567},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":695,"title":696,"description":697,"published":698,"category":686,"image":699,"draft":567},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":701,"title":702,"description":703,"published":698,"category":563,"image":704,"draft":567},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":706,"title":707,"description":708,"published":709,"category":563,"image":710,"draft":567},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":712,"title":713,"description":714,"published":715,"category":563,"image":716,"draft":567},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":718,"title":719,"description":720,"published":721,"category":686,"image":722,"draft":567},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":724,"title":725,"description":726,"published":727,"category":563,"image":728,"draft":567},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":730,"title":731,"description":732,"published":733,"category":563,"image":734,"draft":567},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":736,"title":737,"description":738,"published":739,"category":563,"image":740,"draft":567},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":742,"title":743,"description":744,"published":745,"category":563,"image":746,"draft":567},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":748,"title":749,"description":750,"published":751,"category":563,"image":752,"draft":567},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":754,"title":755,"description":756,"published":757,"category":563,"image":758,"draft":567},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":760,"title":761,"description":762,"published":763,"category":563,"image":764,"draft":567},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":766,"title":767,"description":768,"published":769,"category":563,"image":770,"draft":567},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":772,"title":773,"description":774,"published":775,"category":686,"image":776,"draft":567},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":778,"title":779,"description":780,"published":781,"category":686,"image":782,"draft":567},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":784,"title":785,"description":786,"published":787,"category":686,"image":788,"draft":567},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":790,"title":791,"description":792,"published":793,"category":563,"image":794,"draft":567},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":796,"title":797,"description":798,"published":799,"category":563,"image":800,"draft":567},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":802,"title":803,"description":804,"published":805,"category":563,"image":806,"draft":567},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":808,"title":809,"description":810,"published":811,"category":563,"image":812,"draft":567},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":814,"title":815,"description":816,"published":817,"category":563,"image":818,"draft":567},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":820,"title":821,"description":822,"published":823,"category":563,"image":824,"draft":567},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":826,"title":827,"description":828,"published":829,"category":563,"image":830,"draft":567},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":832,"title":833,"description":834,"published":835,"category":563,"image":836,"draft":567},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":838,"title":839,"description":840,"published":841,"category":563,"image":842,"draft":567},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":844,"title":845,"description":846,"published":847,"category":563,"image":848,"draft":567},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":850,"title":851,"description":852,"published":853,"category":686,"image":854,"draft":567},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":856,"title":857,"description":858,"published":859,"category":563,"image":860,"draft":567},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":862,"title":863,"description":864,"published":865,"category":686,"image":866,"draft":567},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":868,"title":869,"description":870,"published":871,"category":563,"image":872,"draft":567},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":874,"title":875,"description":876,"published":877,"category":563,"image":878,"draft":567},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":67,"title":880,"description":881,"published":882,"category":563,"image":883,"draft":567},"New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":885,"title":886,"description":887,"published":888,"category":563,"image":889,"draft":567},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":891,"title":892,"description":893,"published":894,"category":686,"image":895,"draft":567},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":897,"title":898,"description":899,"published":900,"category":686,"image":901,"draft":567},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":126,"title":903,"description":904,"published":905,"category":563,"image":906,"draft":567},"Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":908,"title":909,"description":910,"published":911,"category":563,"image":912,"draft":567},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":914,"title":915,"description":916,"published":917,"category":686,"image":918,"draft":567},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":920,"title":921,"description":922,"published":923,"category":563,"image":924,"draft":567},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":926,"title":927,"description":928,"published":923,"category":563,"image":929,"draft":567},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":931,"title":932,"description":933,"published":934,"category":563,"image":935,"draft":567},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":937,"title":938,"description":939,"published":940,"category":686,"image":941,"draft":567},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":943,"title":944,"description":945,"published":946,"category":563,"image":947,"draft":567},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":949,"title":950,"description":951,"published":946,"category":686,"image":952,"draft":567},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":954,"title":955,"description":956,"published":957,"category":686,"image":958,"draft":567},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":960,"title":961,"description":962,"published":957,"category":563,"image":963,"draft":567},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]