AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Security Advisor Falsely Flags Extension-Managed Tables As RLS Disabled And Unresolvable

The Security Advisor incorrectly reports public.spatial_ref_sys (and potentially other extension-owned tables) as critical RLS disabled, but users cannot enable RLS because they are not the table owner, creating a false positive and confusing warning.

mediumConfidence 90%Supabase

Origin Analysis

The Security Advisor's RLS check queries all public tables without excluding tables owned by extensions or supabase_admin; spatial_ref_sys is owned by supabase_admin as part of PostGIS, so the check flags it, but the user lacks ownership to alter it.
1. Create Supabase project; 2. Enable PostGIS extension; 3. Open Security Advisor; 4. Observe critical warning for public.spatial_ref_sys; 5. Attempt ALTER TABLE public.spatial_ref_sys ENABLE ROW LEVEL SECURITY; 6. Receive error must be owner of table spatial_ref_sys.

Fixing Code Block

-- Corrected Security Advisor query to exclude extension-owned and supabase_admin-owned tables SELECT schemaname, tablename FROM pg_tables WHERE schemaname = 'public' AND tablename NOT IN ( SELECT ext_table.relname FROM pg_class ext_table JOIN pg_depend dep ON dep.objid = ext_table.oid JOIN pg_extension ext ON dep.refobjid = ext.oid WHERE dep.deptype = 'e' AND ext_table.relkind = 'r' ) AND tableowner <> 'supabase_admin' AND tablename NOT IN ('spatial_ref_sys', 'geometry_columns', 'geography_columns', 'raster_columns', 'raster_overviews') AND EXISTS ( SELECT 1 FROM pg_class c JOIN pg_namespace n ON n.oid = c.relnamespace WHERE c.relname = tablename AND n.nspname = schemaname AND c.relrowsecurity = false );
This query modification excludes tables that are part of extensions (via pg_depend) or owned by supabase_admin, preventing false positives while still flagging user-defined tables lacking RLS. It also explicitly lists known PostGIS system tables for clarity.

Edge Case Audit

Excluding extension-owned tables may hide real security risks if an extension exposes sensitive data without RLS; ensure only trusted extensions are exempted. Applying this change requires updating the Security Advisor service and may need rollback if other tables are inadvertently excluded. For rollback, revert the query to the original version.

Ecosystem Topology