Blog
18 posts on what Supabase and PostgREST actually mean when they refuse your query, on the fix that makes each error disappear by removing the thing that was protecting your data — and on what we found when we scanned a few thousand repositories to see how often that has already happened.
We scanned 2,144 AI-built Supabase repos. 40.6% had a critical exposure.
Luca Urti
new row violates row-level security policy — cause and fix (Supabase)
Luca Urti
More posts
permission denied for table — GRANT, not RLS (Supabase)
Luca Urti
infinite recursion detected in policy for relation — fix without disabling RLS
Luca Urti
RLS Disabled in Public — what the Supabase advisor is telling you
Luca Urti
RLS Enabled No Policy — why your queries return an empty array
Luca Urti
Invalid API key (Supabase) — which key belongs where
Luca Urti
JWT expired (PGRST301) — refresh handling in Supabase
Luca Urti
Storage upload blocked by RLS — policies on storage.objects
Luca Urti
permission denied for schema public — usage grants in Supabase
Luca Urti
Could not find the table in the schema cache (PGRST205) — Supabase
Luca Urti
PGRST116: JSON object requested, multiple (or no) rows returned
Luca Urti
Supabase request blocked by CORS — what it actually means
Luca Urti
PGRST200: could not find a relationship in the schema cache (Supabase)
Luca Urti
duplicate key value violates unique constraint — and what it leaks
Luca Urti
permission denied for sequence — serial columns and Supabase grants
Luca Urti
Auth session missing! — and why getSession is not the fix
Luca Urti
Invalid login credentials — why the message is deliberately vague
Luca Urti
Or find out which of these your own app has
Every shortcut named in these posts is something Sentris looks for in the repository itself — the policy text, the environment variables, the client bundle. A scan needs no account and no card, and the measured false-positive rate is on /precision.
Scan my app