# Supabase auth auth.uid() doesn't work but user\_id does?

**URL:** <https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246>\
**Category:** Ask us anything\
**Tags:** supabase\
**Created:** [September 7, 2023, 4:05am UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246 "2023-09-07T04:05:29Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![chocpretz](https://avatars.discourse-cdn.com/v4/letter/c/ac8455/32.png) [@chocpretz](https://community.weweb.io/u/chocpretz)\
**Post date:** [September 7, 2023, 4:05am UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/1 "2023-09-07T04:05:29Z")

</div>

I’m a bit confused here with Supabase row level security policies (RLS) and how Weweb is passing the auth data. Most of the RLS i’ve seen suggest to use `auth.uid() = user_id` but I get an error `Error: new row violates row-level security policy for table "XXXXXXX"` I can only grant Weweb access by using `user_id = user_id` as it looks like `user_id` is what’s being passed in the payload to Supabase. Can anyone more experienced shed some light? I can’t find a good way to query or debug auth.uid(). Thanks.

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [September 7, 2023, 7:22am UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/2 "2023-09-07T07:22:50Z")

</div>

Are you logged in on WeWeb and do you have all set up properly? Do you have the user\_id in the table that you’re hitting?

_What you’re doing with this policy is actually saying, if the user\_id sent by the logged in user who is calling this query matches the user\_id on the records stored in this table, then it is okay._

I’d need to see your table setup and your query in WeWeb to tell you more. Also make sure you have RLS set up for the action you’re doing, in your case you’re doing INSERT I guess, so you need to have RLS for INSERT, also I think there is a tricky RLS somewhere, where you need to have INSERT and ALSO update to do certain tasks, but I’m not sure which one it is now.

Would really help to see your setup

---

<div class="post-metadata">

**Author:** ![chocpretz](https://avatars.discourse-cdn.com/v4/letter/c/ac8455/32.png) [@chocpretz](https://community.weweb.io/u/chocpretz)\
**Post date:** [September 7, 2023, 4:59pm UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/3 "2023-09-07T16:59:36Z")

</div>

@Broberto yeah, logged into WeWeb as a user and all set up properly with the user\_id in the table I’m hitting. Yeah I believe if you have RLS for INSERT, you also need the same policy for SELECT.

Here’s the relevant field from my table which contains user\_id which is a foreign key to auth.users.id

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/3/3c898c366bd564962f54b8916ee8a34352d8294d.png)

Here’s the payload which contains the user\_id.  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/1/14bbb31dbbde67412ac5cad6a6f7abc5af59fa70.png)

My insert action where I’m inserting the Supabase Auth - [‘user’].id into user\_id

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/d/d540576c90f428d5a228a6b556bf3d107b245422.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/0/0409b4c830bf2ce487e3a3d950485b6ebfecaad0.png)

My understanding was that auth.uid() = user\_id would grab the Supabase Auth - [‘user’].id and only allow that user to select, insert, update etc rows for their own user\_id. Not sure where’ I’m going wrong here.

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [September 7, 2023, 5:01pm UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/4 "2023-09-07T17:01:20Z")

</div>

Yes, I just answered it in an another topic, with the current Supabase Plugin for WeWeb version, you need to have the same SELECT RLS as well.

Check this out

> [@Help with Supabase RLS policies](https://community.weweb.io/t/help-with-supabase-rsl-policies/4251/11):
>
> Yes, the answer to why is in this thread, it is not optimal, but it is how the plugin works underneath. @Alexis you might want to check the { returning: 'minimal' }) for your Supabase Plugin Update, it’s mentioned as a thing that could solve the issue.

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [September 7, 2023, 5:08pm UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/5 "2023-09-07T17:08:31Z")

</div>

If you want authenticated users see **all the rows** , then set the policy like this,

 ![Screenshot 2023-09-07 at 19.08.07](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/5/5a6c660456effcce245547b4ebb842c868a4d24a.png)

and

 ![Screenshot 2023-09-07 at 19.08.20](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/a/a7d55920921269afce2e3755d07c49c9d681d2ba.png)

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [September 7, 2023, 5:12pm UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/6 "2023-09-07T17:12:02Z")

</div>

If you want to do that only auth.uid() = user\_id then yeah, you gotta do it for the both though. Or do Select for all auth users. So you’re right, but you need to just add select either true for authenticated users too, or do the same policy for the select.

---

<div class="post-metadata">

**Author:** ![chocpretz](https://avatars.discourse-cdn.com/v4/letter/c/ac8455/32.png) [@chocpretz](https://community.weweb.io/u/chocpretz)\
**Post date:** [September 7, 2023, 5:12pm UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/7 "2023-09-07T17:12:25Z")

</div>

I definitely don’t want users to be able to see all rows - just the rows that belong to their user\_id. I just updated all my RLS to be “(auth.uid() = user\_id)” and it seems to be working now. It’s possible that I was missing a RLS UPDATE policy on a different table that watches my first table for an update. Can’t really confirm, but in any event, I seem to have this working now lol 🙂 Thank you!

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [September 7, 2023, 5:13pm UTC](https://community.weweb.io/t/supabase-auth-auth-uid-doesnt-work-but-user-id-does/4246/8 "2023-09-07T17:13:57Z")

</div>

It seems like in the other thread, we found that you can’t do INSERT without having a SELECT too, if it was the update policy, then nice, glad you solved the issue)
