Supabase RLS Is Enabled but No Policies Exist — What Actually Happens?
Enabling Row Level Security without defining policies does not leave a PostgreSQL table open. It creates a default-deny state for normal access — and in Supabase that often looks like missing data or failed application operations.