Storage Helper Functions
Learn the storage schema
Supabase Storage provides SQL helper functions which you can use to write RLS policies.
storage.filename()
Returns the name of a file. For example, if your file is stored in public/subfolder/avatar.png it would return: 'avatar.png'
Usage
This example demonstrates how you would allow any user to download a file called favicon.ico:
1create policy "Allow public downloads"2on storage.objects3for select4to public5using (6 storage.filename(name) = 'favicon.ico'7);storage.foldername()
Returns an array path, with all of the subfolders that a file belongs to. For example, if your file is stored in public/subfolder/avatar.png it would return: [ 'public', 'subfolder' ]
Usage
This example demonstrates how you would allow authenticated users to upload files to a folder called private:
1create policy "Allow authenticated uploads"2on storage.objects3for insert4to authenticated5with check (6 (storage.foldername(name))[1] = 'private'7);storage.extension()
Returns the extension of a file. For example, if your file is stored in public/subfolder/avatar.png it would return: 'png'
Usage
This example demonstrates how you would allow restrict uploads to only PNG files inside a bucket called cats:
1create policy "Only allow PNG uploads"2on storage.objects3for insert4to authenticated5with check (6 bucket_id = 'cats' and storage.extension(name) = 'png'7);