-- QA-027: it_service_attachments delete was open to any signed-in user. -- -- The bucket stays public for reads (per product decision), but the DELETE -- policy allowed ANY authenticated user to delete ANY file in the bucket -- (USING (bucket_id = 'it_service_attachments')). Tighten it to the uploader -- (storage sets objects.owner to the uploader's auth.uid) plus the privileged -- IT-request roles that manage requests, so users can't delete each other's -- attachments. Read/upload policies are left unchanged. DROP POLICY IF EXISTS "Authenticated users can delete it_service_attachments" ON storage.objects; CREATE POLICY "Authenticated users can delete it_service_attachments" ON storage.objects FOR DELETE TO authenticated USING ( bucket_id = 'it_service_attachments' AND ( owner = auth.uid() OR EXISTS ( SELECT 1 FROM public.profiles p WHERE p.id = auth.uid() AND p.role IN ('admin', 'programmer', 'dispatcher', 'it_staff') ) ) );