Docs: RLS guide GRANT examples are no-op; TRUNCATE bypasses RLS and default grants expose it
The Supabase RLS documentation instructs users to grant SELECT/INSERT/UPDATE/DELETE to anon/authenticated after creating tables in the public schema, but these privileges are already granted by default. The actual required action—revoking the overbroad default grants—is missing. Additionally, TRUNCATE is included in the default grant and is not blocked by RLS, creating a silent security gap where authenticated or anonymous roles could wipe table data if a direct database path is available.
