© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabase•4mo ago•
3 replies
younessquick

RLS + Security definer ?

Hey !
I'm considering enabling RLS on all my tables without defining any policies, and then interacting with my data only through Postgres RPC functions that are marked as SECURITY DEFINER. In each function, I check at the beginning whether the requested data is accessible based on the auth.uid.

Is this a good practice, or is there a better recommended approach for handling access control in this scenario?
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

RLS 403 on Storage Upload despite valid subquery/SECURITY DEFINER
SupabaseSSupabase / help-and-questions
4w ago
Security Definer Functions - Custom Roles
SupabaseSSupabase / help-and-questions
13mo ago
RLS and security suggestions
SupabaseSSupabase / help-and-questions
3d ago
what is RLS security ... ?????
SupabaseSSupabase / help-and-questions
4y ago