Policy "Users can view profiles" does not constrain rows to a tenant
- Affected:
- public.profiles
- Category:
- Tenant Isolation
- Confidence:
- high
- First detected:
- 2026-08-12 11:04Z
- Last verified:
- 2026-08-16 09:41Z
Summary
The SELECT policy on public.profiles admits every authenticated caller and never references organization_id.
Why this matters
Any signed-in user can read rows belonging to other organizations, because the policy only proves that a session exists — not that it owns the row.
Evidence
- Relation
- public.profiles
- Policy
- Users can view profiles
- Command
- SELECT
- Roles
- authenticated
- USING
- auth.uid() IS NOT NULL
- Tenant column present
- organization_id
- Tenant validation
- No qualifying ownership constraint detected
Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.
Technical details
pg_policies.qual evaluates to a session-existence check. The table exposes organization_id, which the evaluated path never references.
recommended remediation
Unlock Full Audit (Demo)
Scope the policy to organization_id using the tenant resolver.
Current
Policy: Users can view profiles Command: SELECT USING: auth.uid() IS NOT NULL
Recommended Review
This policy allows reading rows without verifying tenant ownership. DBXray cannot automatically generate the missing tenant constraint because it requires application-specific authorization logic. Review this policy and add a USING clause that binds a tenant column to the caller's identity.
Expected security effect
- Authentication required
- Tenant ownership enforced
- Cross-tenant read path removed
No migration generated — application intent required.
Compatibility risk
high
Callers relying on reading records outside their organization will start receiving zero rows. Verify admin tooling uses a privileged path.
