-- Allow anonymous uploads into the public 'gallery' bucket. -- The bucket is public, so direct object GETs bypass RLS for display. -- These policies only grant INSERT to anon for this bucket. ALTER TABLE storage.objects ENABLE ROW LEVEL SECURITY; DROP POLICY IF EXISTS storage_objects_gallery_insert ON storage.objects; CREATE POLICY storage_objects_gallery_insert ON storage.objects FOR INSERT TO anon WITH CHECK (bucket = 'gallery'); GRANT INSERT ON storage.objects TO anon; GRANT USAGE ON SCHEMA storage TO anon;