Row Level Security disabled on realtime.subscription
- Affected:
- realtime.subscription
- Category:
- RLS Security
- Confidence:
- high
- First detected:
- 2026-08-12 11:04Z
- Last verified:
- 2026-08-16 09:41Z
Summary
realtime.subscription is granted to API roles but has no row filtering.
Why this matters
Any caller holding the granted role can read or modify every row in the table, regardless of ownership.
Evidence
- Relation
- realtime.subscription
- relrowsecurity
- false
- Granted roles
- anon
Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.
Technical details
pg_class.relrowsecurity is false while table privileges are granted to a Data API role.
recommended remediation
Unlock Full Audit (Demo)
Enable Row Level Security to deny access by default, then add policies to grant access.
Current
Recommended Review
Expected security effect
- Denies all access by default via the API
- Forces explicit access through policies
No migration generated — application intent required.
Compatibility risk
high
Any API client attempting to read or write to this table without a valid policy will instantly be denied. Ensure policies are created before or immediately after enabling RLS.
