VVibeFix

Guide

Data won't save: "new row violates row-level security policy"

A user fills in a form, presses Save, and nothing happens. Or the console shows new row violates row-level security policy for table "…". Sometimes it's the opposite and more dangerous: one user can see another user's data.

What's going on

Supabase protects each table with row-level security (RLS): rules that say who may read or write which rows. With RLS on and no matching rule, the database refuses the save. That's the error. With rules that are too loose, it hands everyone's data to anyone.

Confirm it

  1. Open the page, press F12 → Console, and try to save again.
  2. If you see row-level security in a red error, it's RLS.
  3. Also test the reverse: log in as a second user and check you can't see the first user's items.

Fix it the right way

Don't switch RLS off. That makes the error go away by making your data public.

Instead, give the table a rule that matches what the app does. For a typical "users own their rows" table:

You can ask your builder: "Saving to [table] fails with a row-level security error. Add policies so each user can insert, read, update and delete only their own rows, and make sure the app sets user_id on insert. Don't disable RLS."

Check both directions

Fixing the save is half the job. Make sure a second account can't read the first account's data.

Paste your app's link at vibe-fixer.com: an AI agent uses it like a first customer and tells you how many problems it finds, including data a stranger can reach. Free, no account.

Still stuck?

Paste your app’s link for a free test — no account. Your AI agent goes through it like a first customer, shows you what breaks, then fixes it while you watch.

Test my app — free

More guides · Real repairs