Skip to main content
Hostwares

How to Secure Supabase Storage with RLS Policies

sowad sheikh··1 min read

Uploading files is only half of a storage system. The other half is deciding who can access them.

Supabase Storage works with policies that can restrict operations based on authentication and file information.

Identify the Owner

A common approach is to associate uploaded files with a user ID. Your application can then use that identity when evaluating access.

Restrict Uploads

Instead of allowing every authenticated user to upload anywhere, create rules that limit where each user can place files.

Restrict Reads

Private files should only be readable by authorized users.

Restrict Deletes

Deleting files can be destructive, so make sure the delete policy is also limited. Test With Multiple Accounts Create two accounts:

User A

User B

Upload a file as User A.

Then verify that User B cannot access or delete User A's private file.

Review Before Production

Storage policies should be tested before the application goes live. A working upload button doesn't necessarily mean your storage configuration is secure.

Ready to deploy?

Launch your app on Hostwares — start for $1.00/mo with auto-scaling & global CDN.

Start for $1.00/mo

Ready to deploy? Start for $1.00/mo

Deploy now