Supabase Storage

File and image storage with the same Row Level Security model as the database.

adds it to an existing project · no account needed
Currentas published in v1.5.1

The rule

This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.

Buckets

  • Private by default. A public bucket serves every object to anyone holding the URL, permanently and without an auth check. Make one public only when the content genuinely is.
  • Set size limits and allowed MIME types on the bucket. A client-side check is a convenience, not a control.

Paths

  • Namespace by owner: {userId}/avatar.png. RLS policies are written against the path, so without a convention they cannot be expressed at all.
  • Decide the convention before the first upload; renaming later means moving every object.

Access

  • Private objects are read through createSignedUrl with the shortest lifetime the use allows. Generate on demand — never store a signed URL, it expires.
  • Store the object path, not a URL.

Uploads

  • Resize and compress before uploading. Camera originals are multi-megabyte and cost the user data and battery for pixels nobody sees.
  • Always check the returned error — the client returns it rather than throwing.
  • Set contentType explicitly.

Never

  • Never put user content in a public bucket "for now".
  • Never rely on an unguessable path as security — that is not access control.
  • Never leave a user's objects behind when their account is deleted.

6 formats, one per tool

Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.

.cursor/rules/supabase-storage.mdchand-written
---
description: Supabase Storage conventions
globs: ["src/services/storage/**", "src/services/supabase/**"]
alwaysApply: false
---

# Supabase Storage

## Buckets

- **Private by default.** A public bucket serves every object to anyone holding
  the URL, permanently and without an auth check. Make one public only when the
  content genuinely is.
- Set size limits and allowed MIME types on the bucket. A client-side check is a
  convenience, not a control.

## Paths

- Namespace by owner: `{userId}/avatar.png`. RLS policies are written against
  the path, so without a convention they cannot be expressed at all.
- Decide the convention before the first upload; renaming later means moving
  every object.

## Access

- Private objects are read through `createSignedUrl` with the shortest lifetime
  the use allows. Generate on demand — never store a signed URL, it expires.
- Store the object **path**, not a URL.

## Uploads

- Resize and compress before uploading. Camera originals are multi-megabyte and
  cost the user data and battery for pixels nobody sees.
- Always check the returned `error` — the client returns it rather than throwing.
- Set `contentType` explicitly.

## Never

- Never put user content in a public bucket "for now".
- Never rely on an unguessable path as security — that is not access control.
- Never leave a user's objects behind when their account is deleted.

Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.

What else this module writes

The rule is one file of several. Selecting Supabase Storage contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.

Environment
{{envPrefix}}STORAGE_BUCKEToptionalDefault bucket for user uploads. Keep it private and namespace objects by user id.
Dependencies
Depends on the rest of the stack — this module installs different packages depending on what else you select, so there is no single list to show.
Folders
src/services/storage/

Advisory history

Every time this rule turned out to be wrong, and what we did about it.

No corrections yet

This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.

Pro tells you the day a correction lands that affects a repo you actually have.

See what Pro adds →

Rules people add alongside this one

Put this rule in a real project

The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.