DBX
DBX home
Acme ProductionPRODUCTIONExit Demo
Run Scan
Findings
Medium

Policy "Users can view profiles" does not constrain rows to a tenant

Affected:
public.profiles
Category:
Tenant Isolation
Confidence:
high
First detected:
2026-08-12 11:04Z
Last verified:
2026-08-16 09:41Z

Summary

The SELECT policy on public.profiles admits every authenticated caller and never references organization_id.

Why this matters

Any signed-in user can read rows belonging to other organizations, because the policy only proves that a session exists — not that it owns the row.

Evidence

Relation
public.profiles
Policy
Users can view profiles
Command
SELECT
Roles
authenticated
USING
auth.uid() IS NOT NULL
Tenant column present
organization_id
Tenant validation
No qualifying ownership constraint detected

Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.

Technical details

pg_policies.qual evaluates to a session-existence check. The table exposes organization_id, which the evaluated path never references.

recommended remediation

Unlock Full Audit (Demo)

Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
Ready to scan your own database?
Buy Remediation Credits — $19

Includes 5 Activation Credits

Scope the policy to organization_id using the tenant resolver.

Current

Policy: Users can view profiles Command: SELECT USING: auth.uid() IS NOT NULL

Recommended Review

This policy allows reading rows without verifying tenant ownership. DBXray cannot automatically generate the missing tenant constraint because it requires application-specific authorization logic. Review this policy and add a USING clause that binds a tenant column to the caller's identity.

Expected security effect

  • Authentication required
  • Tenant ownership enforced
  • Cross-tenant read path removed

No migration generated — application intent required.

Compatibility risk

high

Callers relying on reading records outside their organization will start receiving zero rows. Verify admin tooling uses a privileged path.

DBX never applies SQL to your database.