AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Fix(Realtime-Prompt): INSERT Authorization Example Uses Unsupported USING Clause

The Supabase realtime prompt documentation contains an invalid PostgreSQL row-level security policy example that uses USING with FOR INSERT. This prevents users from creating the documented private-channel write policy.

mediumConfidence 99%PostgreSQL

Origin Analysis

The documentation example incorrectly uses the USING clause in a FOR INSERT policy. PostgreSQL CREATE POLICY permits USING only for SELECT, UPDATE, and DELETE policies; INSERT policies require a WITH CHECK expression to validate new rows.
1. Open examples/prompts/use-realtime.md at lines 286-300. 2. Observe the policy 'room_members_can_write' is defined with FOR INSERT TO authenticated followed by USING (topic LIKE 'room:%'). 3. Attempt to execute the SQL in a PostgreSQL transaction: BEGIN; CREATE TABLE realtime_policy_fixture (topic text); CREATE POLICY room_members_can_write ON realtime_policy_fixture FOR INSERT USING (topic LIKE 'room:%'); ROLLBACK; The statement fails with a syntax error because USING is not allowed for INSERT policies.

Fixing Code Block

CREATE POLICY "room_members_can_write" ON public.messages FOR INSERT TO authenticated WITH CHECK (topic LIKE 'room:%');
Replace the unsupported USING clause with WITH CHECK. WITH CHECK is the correct clause for INSERT policies to evaluate the proposed new row against the room-membership predicate.

Edge Case Audit

This is a documentation-only fix; no runtime risk. However, users who already copied the invalid SQL into a migration must update their migration to use WITH CHECK. Rolling back to the previous USING version will fail to create the policy. The SELECT policy elsewhere in the same section is contractually separate and should remain unchanged.

Ecosystem Topology