DBX
DBX home
Acme ProductionPRODUCTIONExit Demo
Run Scan
Findings
Critical

Row Level Security disabled on realtime.subscription

Affected:
realtime.subscription
Category:
RLS Security
Confidence:
high
First detected:
2026-08-12 11:04Z
Last verified:
2026-08-16 09:41Z

Summary

realtime.subscription is granted to API roles but has no row filtering.

Why this matters

Any caller holding the granted role can read or modify every row in the table, regardless of ownership.

Evidence

Relation
realtime.subscription
relrowsecurity
false
Granted roles
anon

Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.

Technical details

pg_class.relrowsecurity is false while table privileges are granted to a Data API role.

recommended remediation

Unlock Full Audit (Demo)

Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
Ready to scan your own database?
Buy Remediation Credits — $19

Includes 5 Activation Credits

Enable Row Level Security to deny access by default, then add policies to grant access.

Current

Recommended Review

Expected security effect

  • Denies all access by default via the API
  • Forces explicit access through policies

No migration generated — application intent required.

Compatibility risk

high

Any API client attempting to read or write to this table without a valid policy will instantly be denied. Ensure policies are created before or immediately after enabling RLS.

DBX never applies SQL to your database.