`config push` sets `external_email_enabled = false` when `[auth.email] enable_signup = false`, disabling password sign-in for all users
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- postgresql, typescript
- Domain
- authentication, cli
Research direction
The bad mapping is the boolRow call at packages/config/src/project-config/registry-auth.ts:597, which ties [auth.email] enable_signup to external_email_enabled. Read the config schema parsing that rejects an enabled key under [auth.email], and the config push path that writes the auth config. Done means signup can be disabled without flipping external_email_enabled, with a test covering the config push mapping. The issue offers two fixes, so confirm the approach with a maintainer before writing code.
Written by the indexing model from the issue text.
Description
Summary
Running supabase config push against a remote project whose config.toml has [auth.email] enable_signup = false sets the project's external_email_enabled to false. Email/password sign-in then fails for every user with 422 email_provider_disabled, while the CLI reports the auth config as updated / up to date.
Version
Reproduced on CLI 2.109.1 (2026-07-17). The mapping is still on main at 753520f (2026-10-06): packages/config/src/project-config/registry-auth.ts:597, boolRow(["auth","email","enable_signup"], "external_email_enabled"). Latest release checked: v2.120.0.
Steps to reproduce
- A remote project with the email provider enabled; email/password sign-in works.
supabase/config.tomlcontains:
The intent is no public self-signup: accounts are created by admins through the Admin API.[auth] enable_signup = false [auth.email] enable_signup = falsesupabase config push --project-ref <ref>POST /auth/v1/token?grant_type=passwordwith valid credentials.
Expected
[auth.email] enable_signup = false disables email signup only. Existing users can still sign in, and external_email_enabled stays true.
Actual
external_email_enabled flips true -> false (read back from GET /v1/projects/{ref}/config/auth). Sign-in returns 422 email_provider_disabled for everyone. The CLI prints no warning.
No workaround in config.toml
Adding enabled = true under [auth.email] is rejected ('auth.email' has invalid keys: enabled), and that parse error also breaks supabase db push. So a project that wants signup disabled cannot use config push at all.
Recovery
curl -X PATCH https://api.supabase.com/v1/projects/<ref>/config/auth \
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN" -H 'Content-Type: application/json' \
-d '{"external_email_enabled": true}'
Related
- supabase/supabase#40582 (open, no replies)
- supabase/cli#4469 (closed unmerged)
Suggested fix
Do not map [auth.email] enable_signup onto the provider toggle external_email_enabled, or accept [auth.email] enabled in the schema so the provider can be kept on explicitly.
- Dominant language
- TypeScript
- Stars
- 2.4k
- Forks
- 533
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 346
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from supabase/cli
-
db schema declarative sync: no way to fail (non-zero exit) when the generated migration is destructiveMay be free again A pull request for this issue was closed without being merged. Open✨ Feature supabase/cli
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
stack: the HTTP gateway closes idle keep-alive connections after 5 s, so a client whose event loop is blocked gets ECONNRESET (`fetch failed`) on its next requestPossibly taken @7ttp claimed this 7 days ago. Open🐛 Bug supabase/cli
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
supabase/cli#6975 · 1 assignee ·
Maintainers usually reply within 1 day
-
📘 Docs supabase/cli
Difficulty 1/5 Under an hour Newbie friendliness 88/100
supabase/cli#6974 · 1 comment ·
Maintainers usually reply within 1 day
-
🐛 Bug supabase/cli
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
config push sends [auth.sms] enable_confirmations un-negated as sms_autoconfirm, so hosted projects get the opposite of localPossibly taken @7ttp claimed this 5 days ago. Open🐛 Bug supabase/cli
supabase/cli#6997 · 1 assignee ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
cameri/nostream#811 · 1 comment ·
Maintainers usually reply within 1 day
-
bug p3 triaged
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
-
bug javascript P2-medium python release:v3.1
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
adrirubio/claude-deck#546 ·
Maintainers usually reply within 1 day
-
area: desktop area: website priority: P2 type: feature
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
appandflow/stim#3411 · 1 comment ·
Maintainers usually reply within 1 day
-
needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
rjsf-team/react-jsonschema-form#5485 ·
Maintainers usually reply within 2 days