Files
supabase/apps/docs/content
Pedro RodriguesandClaude Opus 4.6 f7d2160e0c fix: correct RLS permissions for storage move and copy operations (#42777)
### Summary

- The `move` operation requires `select` + `update` permissions (not
`select` + `insert` as previously documented). The implementation was
changed in
[supabase/storage#400](https://github.com/supabase/storage/pull/400) to
update the row in-place instead of deleting and reinserting, but the
docs were never updated to reflect this.
- The `copy` operation requires `select` + `insert` by default. When the
user also has `update` permission, the copy can be performed as an
upsert, overwriting the destination if it already exists.
- Added an `update` policy example alongside the existing `select` and
`insert` examples.

### Related

Fixes https://github.com/supabase/storage/issues/807


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Enhanced guidance for storage copy operations with clarified
permissions requirements on source and destination.
  * Added upsert option details for users with update permissions.
* Clarified move operation requirements for select and update
permissions.
* Updated policy examples with explicit operation names and owner
authentication checks.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 14:52:10 +00:00
..