Skip to main content
Hostwares

How to Create RLS Policies for User-Owned Data

sowad sheikh··1 min read

Suppose your application has a notes table. Every note belongs to a specific user. Without the correct database policy, you could accidentally expose one user's notes to another.

Add a User ID

Your table should contain a field identifying the owner. For example:

user_id

This can reference the authenticated user's ID.

Enable RLS

Turn on Row Level Security for the table.

Create a Read Policy

The read policy should compare the record owner with the authenticated user. Conceptually: record.user_id = current authenticated user

Protect Inserts

When creating a new note, make sure the inserted user_id corresponds to the current user.

Protect Updates

Users should only be able to update their own notes.

Protect Deletes

The same ownership rule should apply to deleting records.

Test the Full CRUD Flow

Test all four operations:

Create → Read → Update → Delete

Then repeat the tests with a second account.

This helps verify that your database security matches your application's intended behavior.

Ready to deploy?

Launch your app on Hostwares — start for $1.00/mo with auto-scaling & global CDN.

Start for $1.00/mo

Ready to deploy? Start for $1.00/mo

Deploy now