AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Studio Policy Editor Emits Invalid Empty `WITH CHECK` Clause For Non-INSERT Policies

The Supabase Studio RLS policy editor generated a PostgreSQL policy with a trailing `with check ( )` clause for a SELECT policy, causing a syntax error and preventing the policy from being created.

mediumConfidence 90%React

Origin Analysis

The policy editor SQL builder unconditionally appends a `WITH CHECK` clause after `USING` for all commands. PostgreSQL only permits `WITH CHECK` for INSERT and UPDATE policies, and when no CHECK expression is supplied the builder emits empty parentheses, which is a parse error.
1. Open Supabase Studio and navigate to Authentication > Policies. 2. On the `realtime.messages` table, create a new policy using the template `Allow listening for broadcasts for authenticated users only`. 3. Save the policy and observe the generated SQL contains `with check ( )`. 4. The backend returns HTTP 400 with `syntax error at or near ")"`. 5. Removing the trailing `with check ( )` clause makes the statement succeed.

Fixing Code Block

export function generateCreatePolicySql( command: 'select' | 'insert' | 'update' | 'delete', tableName: string, policyName: string, roleName: string, usingExpr?: string, checkExpr?: string, ): string { const normalizedRole = roleName.trim().toLowerCase() const normalizedCommand = command.trim().toLowerCase() let sql = `create policy "${policyName}" on "${tableName}" as permissive for ${normalizedCommand} to ${normalizedRole}` if (usingExpr && usingExpr.trim()) { sql += ` using (${usingExpr.trim()})` } if ((normalizedCommand === 'insert' || normalizedCommand === 'update') && checkExpr && checkExpr.trim()) { sql += ` with check (${checkExpr.trim()})` } return sql }
The fix only appends a `WITH CHECK` clause when the policy command is `INSERT` or `UPDATE`, which are the only PostgreSQL commands that accept it. It also checks that the CHECK expression is non-empty before emitting the clause, preventing empty parentheses.

Edge Case Audit

Do not remove `WITH CHECK` from UPDATE policies where it is legally required, as this would weaken RLS enforcement on updated rows. After applying, run a regression test against existing INSERT and UPDATE policy templates to ensure their CHECK clauses remain intact. Rollback by restoring the previous SQL builder function if any existing policy SQL generation regresses.

Ecosystem Topology