highaccess-controlconnected project
Write policy without WITH CHECK
MISSING_WITH_CHECKAn INSERT policy with no WITH CHECK clause does not constrain the rows being written, so a caller can insert rows attributed to other users. On UPDATE and ALL, Postgres uses the USING expression as the write check when WITH CHECK is omitted, and that fallback is not itself an ownership bypass. This rule reports an INSERT that omits WITH CHECK, and an UPDATE or ALL policy only when it also has no USING expression to fall back on.
What the finding looks like
highPolicy "invoices_insert" on public.invoices allows INSERT with no WITH CHECK clause
How to fix it
This is real generator output, not a template — a scan substitutes your schema, table and inferred ownership column.
-- Generated by RowShield. Review before running in production. -- Constrain what policy invoices_insert is allowed to write. -- The policy has no USING clause to reuse, so an owner check is proposed. -- Adjust it to match your data model. ALTER POLICY invoices_insert ON public.invoices WITH CHECK (user_id = (SELECT auth.uid()));
Related guides
What people search for
supabase missing with check policycursor generated supabase missing with checksupabase insert policy without with check
Check your own project
This rule needs a connected project. Start with the free probe to see what is exposed publicly.
Run the free audit