MONDAY, JULY 20, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 19h ago

Prisma and Drizzle bypass Supabase RLS: here's the fix

By Meridian48 News Desk · Summarised from DEV Community ·

Prisma and Drizzle connect as the postgres role, which owns tables and has BYPASSRLS, so Row Level Security is skipped on ORM queries. The Supabase JS client uses unprivileged roles through PostgREST, enforcing RLS. To fix, point your app's connection at a dedicated non-owner role with NOBYPASSRLS and keep auth checks in code.

Meridian48 take
This is a critical security gotcha for any Supabase user adopting an ORM — the assumption that RLS protects all access is false, and the fix is straightforward but easy to miss.
Read the full reporting
Does Prisma respect Supabase RLS? No — here's why →
DEV Community
supabaseprisma
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan