Back to Glossary

What is Row-Level Security (RLS)?

Definition

A database feature (primarily in PostgreSQL and Supabase) that restricts which rows a user can access based on their identity, enforced at the database layer.

Security Impact

Missing or misconfigured RLS policies allow any authenticated user to read, modify, or delete other users' data by simply changing an ID in the API request.

How to Remediate

Enable RLS on every table, write explicit SELECT/INSERT/UPDATE/DELETE policies using auth.uid(), and test policies with different user roles.

Want to automatically detect and block Row-Level Security (RLS) vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →