Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

config push sends [auth.sms] enable_confirmations un-negated as sms_autoconfirm, so hosted projects get the opposite of local

Đang mở
#6,997 0 bình luận 0 reaction 1 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@7ttp đang làm issue này rồi.

Từ ngày 5/10/2026.

Đánh giá

Issue này chưa được đánh giá.

Mô tả

🐛 Bug supabase/cli
Affected area

Auth

Supabase CLI version

v2.98.0. The same code is on develop as of 2026-10-05.

Operating system

Ubuntu (GitHub Actions ubuntu-latest) for config push; macOS for supabase start.

Installation method

npm (via supabase/setup-cli@v3)

Command

supabase config push, compared with supabase start on the same config.toml.

Actual output

With this in supabase/config.toml:

[auth.email]
enable_confirmations = true

[auth.sms]
enable_confirmations = true

after supabase config push, the hosted project's GET /auth/v1/settings returns:

{ "mailer_autoconfirm": false, "phone_autoconfirm": true }

and the dashboard (Authentication > Sign In / Providers > Phone) shows "Enable phone confirmations" switched off.

So the email key means "require confirmation" and the identical SMS key means "skip confirmation". Locally, supabase start with the same file does require phone confirmation, so one config behaves in opposite ways on a local stack and on a hosted project.

Expected behavior

[auth.sms] enable_confirmations = true should set sms_autoconfirm = false on the hosted project, the way [auth.email] enable_confirmations = true sets mailer_autoconfirm = false, and the way supabase start already treats the SMS key.

Steps to reproduce
  1. Set [auth.sms] enable_confirmations = true in supabase/config.toml.
  2. Run supabase link --project-ref <ref> and supabase config push.
  3. Run curl https://<ref>.supabase.co/auth/v1/settings -H "apikey: <publishable key>". It returns "phone_autoconfirm": true, and the dashboard's Phone provider shows "Enable phone confirmations" off.
  4. Run supabase start with the same file. The local auth container gets GOTRUE_SMS_AUTOCONFIRM=false.
Additional context

Cause. In pkg/config/auth.go (v2.98.0; apps/cli-go/pkg/config/auth.go on develop) the email mapping negates in both directions and the SMS mapping does not:

// email
body.MailerAutoconfirm = nullable.NewNullableWithValue(!e.EnableConfirmations) // L700
e.EnableConfirmations = !ValOrDefault(remoteConfig.MailerAutoconfirm, false)   // L825

// sms
body.SmsAutoconfirm = nullable.NewNullableWithValue(s.EnableConfirmations)     // L1121
s.EnableConfirmations = ValOrDefault(remoteConfig.SmsAutoconfirm, false)       // L1170

internal/start/start.go negates both:

fmt.Sprintf("GOTRUE_MAILER_AUTOCONFIRM=%v", !utils.Config.Auth.Email.EnableConfirmations) // L1309
fmt.Sprintf("GOTRUE_SMS_AUTOCONFIRM=%v", !utils.Config.Auth.Sms.EnableConfirmations)      // L1325

Because the read-back (L1170) is un-negated as well, the pushed value round-trips and config push has no diff to show for the key, so nothing flags it.

Why it matters. With sms_autoconfirm on, a phone number is marked confirmed without an OTP, both on signup and on PUT /user {phone}. A project that sets enable_confirmations = true believes it requires phone verification and does not.

Suggested fix. Negate L1121 and L1170 to match the email mapping. That flips the hosted value for any project that has worked around this by setting false, so it needs a release note.

History. Reported before as #4413, which was closed as not planned without a fix.

Ngôn ngữ chính
TypeScript
Star
2.4k
Fork
531
Merge trung bình
1 ngày 4 giờ
Pull request đã merge (30 ngày)
351

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của supabase/cli

Tất cả issue của supabase/cli

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.