What to test
That contrast is itself the clue: the SQL editor runs as a privileged role that bypasses RLS entirely (the same is true of a server-side call using the service_role key), so it proves nothing about whether a real app-facing policy exists — it will 'work' even with zero policies on the table.