ยฉ 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabaseโ€ข4y agoโ€ข
14 replies
dlchet

User Management Starter allows updating all avatars?

The last two lines of the current User Management Starter:
create policy "Anyone can update an avatar." on storage.objects
  for update with check (bucket_id = 'avatars');
create policy "Anyone can update an avatar." on storage.objects
  for update with check (bucket_id = 'avatars');

Would that not allow a malicious user to update someone else's avatar? Is the security through obscurity of the object location/url? Or am I just misunderstanding something? An update doesn't produce a new URL, right? It changes the object at the referenced path so that the referenced avatar_url wouldn't change but the image at the end of the url would?
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

SOLVED User Management Starter not working
SupabaseSSupabase / help-and-questions
4y ago
Create default tables with user management starter
SupabaseSSupabase / help-and-questions
4y ago
Error 500 - user management
SupabaseSSupabase / help-and-questions
5mo ago
User management template + role
SupabaseSSupabase / help-and-questions
4y ago