Skip to content

Confirm the password-token hook is on, and correct the connected-app docs #441

Description

@HMarzban

Summary

A connected app (an MCP client) holds a user's OAuth token. The database refuses that token on the Data API, Storage and Realtime. The Supabase Auth API is not covered. There, the token can set a password on a Google or email-link account, and password sign-in then gives a full session that survives Disconnect. The repo already has the defense, hook_block_password_tokens, but it works only when the hook is turned on in the Supabase dashboard. The public docs also claim more than the gate does.

  • Severity: Medium if the hook is off; Low if it is on
  • Area: Supabase Auth, connected apps, docs
  • Source: security review of 2026-10-06, finding M9

Where

  • The token gate covers only the Data API, Storage and Realtime: packages/supabase/migrations/20260928120000_refuse_connected_app_tokens.sql.
  • The defense: packages/supabase/migrations/20260928130000_reject_password_sign_in_hook.sql (public.hook_block_password_tokens).
  • Local config leaves the hook commented out: packages/supabase/config.toml:265-267. secure_password_change = false at :208.
  • Docs claim: docs/mcp/reference.md:26 says the project refuses a client_id token, with no mention of the Auth API.
  • Self-host docs require the hook in production: docs/self-hosting/configuration.md (search for hook_block_password_tokens).

Fix plan

  1. Maintainer, Supabase dashboard (production): Authentication → Hooks. Confirm the custom access token hook points to public.hook_block_password_tokens and is enabled. Turn on "Secure password change" (the dashboard name for secure_password_change).
  2. docs/mcp/reference.md:26: say that the Auth API is not gated by the database, and that the password hook closes the password path. Link docs/self-hosting/configuration.md.
  3. packages/supabase/config.toml: set secure_password_change = true, so local matches production.

Acceptance criteria

  • The production dashboard shows the hook enabled on public.hook_block_password_tokens.
  • Secure password change is on in production.
  • docs/mcp/reference.md no longer claims a gate the Auth API does not have.

Verify

  • Dashboard check by the maintainer (no API access from CI).
  • Locally: with the hook enabled in config.toml, a password sign-in for a user who only had Google sign-in is refused.

Related

Activity

  1. added theissue type on Oct 6, 2026
  2. HMarzban commented on Oct 7, 2026

    @HMarzban
    CollaboratorAuthor

    One more docs line for this issue: docs/mcp/reference.md:26 says the docs.plus Supabase project refuses a token with client_id. The gate (migration 20260928120000) covers the Data API, Storage and Realtime only. Please make the sentence name those three.

  3. HMarzban commented on Oct 9, 2026

    @HMarzban
    CollaboratorAuthor

    Docs are live (2d666bd88): the MCP reference scopes the Supabase token gate and names the password hook.

    Left before closing (maintainer, Supabase dashboard): confirm the Customize Access Token hook is on as a Postgres hook on public.hook_block_password_tokens, test Google sign-in, email-link sign-in and a token refresh, then turn on Secure password change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    AuthSecuritySecurity, access control, and data exposure

    Type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions