-- Migration: 20260611000001_fix_secure_all_tables.sql -- Description: Fix RLS policies to allow public insert/update since app uses custom auth, but strictly prevent delete. DO $$ DECLARE r RECORD; BEGIN FOR r IN SELECT tablename FROM pg_tables WHERE schemaname = 'public' LOOP -- Clean up the overly restrictive policies from previous migration EXECUTE 'DROP POLICY IF EXISTS "Enable insert for authenticated users only" ON public.' || quote_ident(r.tablename) || ';'; EXECUTE 'DROP POLICY IF EXISTS "Enable update for authenticated users only" ON public.' || quote_ident(r.tablename) || ';'; EXECUTE 'DROP POLICY IF EXISTS "Enable delete for authenticated users only" ON public.' || quote_ident(r.tablename) || ';'; -- Insert policy: Allow anon (app uses custom auth, no Supabase Auth) EXECUTE 'DROP POLICY IF EXISTS "Public insert access" ON public.' || quote_ident(r.tablename) || ';'; EXECUTE 'CREATE POLICY "Public insert access" ON public.' || quote_ident(r.tablename) || ' FOR INSERT WITH CHECK (true);'; -- Update policy: Allow anon EXECUTE 'DROP POLICY IF EXISTS "Public update access" ON public.' || quote_ident(r.tablename) || ';'; EXECUTE 'CREATE POLICY "Public update access" ON public.' || quote_ident(r.tablename) || ' FOR UPDATE USING (true);'; -- Delete policy: Prevent hard deletion for everyone (prevents third party deletion) EXECUTE 'DROP POLICY IF EXISTS "Prevent hard deletion" ON public.' || quote_ident(r.tablename) || ';'; EXECUTE 'CREATE POLICY "Prevent hard deletion" ON public.' || quote_ident(r.tablename) || ' FOR DELETE USING (false);'; END LOOP; END $$;