DBX
DBX home
Acme ProductionPRODUCTIONExit Demo
Run Scan
Findings
Low

Anonymous role granted access to realtime.subscription

Affected:
realtime.subscription
Category:
Permissions
Confidence:
medium
First detected:
2026-08-12 11:04Z
Last verified:
2026-08-16 09:41Z

Summary

System/managed schema has anon access, which is usually expected.

Why this matters

Anyone with the publishable API key could potentially access this relation without signing in, depending on RLS.

Evidence

Role
anon
Privileges
SELECT, INSERT
RLS Enabled
false

Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.

Technical details

Supabase manages this schema. Modifying grants here may break internal platform features.

Attack path

INTERNETINTERNET✓anonymousROLE⚠authenticatedROLE!Data APIPOSTGREST✓RPC/REST/V1/RPC⚠get_invoice()SECURITY DEFINER⚠refresh_usage_total…SECURITY DEFINER!v_customer_billingDEFINER VIEW!profilesRLS ENABLED!support_ticketsRLS ENABLED!webhook_endpointsRLS ENABLED⚠pricing_plansRLS ENABLED⚠subscriptionRLS DISABLED⚠_http_responseRLS DISABLED⚠avatarsPUBLIC BUCKET!

internet → anon → rest → realtime.subscription

recommended remediation

Unlock Full Audit (Demo)

Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
Ready to scan your own database?
Buy Remediation Credits — $19

Includes 5 Activation Credits

Review anonymous privileges on realtime.subscription.

Current

Role: anon GRANTED PRIVILEGES SELECT granted INSERT granted RLS EFFECTIVE ACCESS RLS ENABLED: false Applicable policies: None

Recommended Review

Anonymous access is currently permitted. If public access is intentional: • Keep required public policies. • Verify that each policy exposes only intended rows and operations. If public access is not intentional: • Restrict or remove applicable public policies. • Revoke unnecessary anon privileges. Application intent is required before generating a migration.

Expected security effect

  • Modifying this could break legitimate public access or Supabase features.

No migration generated — application intent required.

Compatibility risk

high

Any public surface reading this relation without a session will break.

DBX never applies SQL to your database.