AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Missing Verification Hook For Custom SMS OTP Providers

Supabase Custom SMS Hook only supports sending an OTP with a known code; it lacks a hook to verify OTPs handled externally (e.g., Twilio Verify, Plivo Verify). This prevents integration with verification providers that do not expose the raw OTP to the developer.

mediumConfidence 75%GoTrue

Origin Analysis

The GoTrue authentication service's SMS OTP verification logic assumes the OTP is generated and stored by GoTrue; the send-sms hook receives the OTP to relay. There is no extension point at the verification step to delegate OTP validation to an external provider.
1. Configure Send SMS Hook for Supabase Auth. 2. Implement hook to call Twilio Verify or Plivo Verify for sending OTP (the code is not known to this hook). 3. Attempt to sign in with phone OTP. 4. User receives OTP and enters it in the app. 5. Supabase verifyOtp endpoint fails because it compares against internally stored OTP, which was not the one actually sent.

Fixing Code Block

// In GoTrue internal/api/verify.go or similar token verification logic // Add a new optional verify-sms hook that can be called during OTP verification. func (a *API) verifySMSOTP(ctx context.Context, user *models.User, otp string) error { config := a.config if config.Hooks.VerifySMS.Enabled { input := hooks.VerifySMSInput{ User: user, SMS: struct { OTP string `json:"otp"` }{ OTP: otp, }, } output, err := a.hookInvoker.InvokeVerifySMSHook(ctx, input) if err != nil { return err } if !output.Valid { return errors.New("invalid OTP") } return nil } // Fallback to default internal hash comparison return user.VerifyOtp(otp) }
This patch introduces a conditional check for a new VerifySMS hook in the GoTrue verification flow. When the hook is configured, GoTrue delegates OTP validation to the external verification provider (e.g., Twilio Verify) instead of comparing against an internally stored hash. If the hook is not enabled, existing behavior remains unchanged, ensuring backward compatibility.

Edge Case Audit

This is a core authentication flow change and must be thoroughly tested across SMS OTP sign-in, sign-up, password reset, and rate limiting. Concurrency issues may arise if hook calls are not idempotent or if provider API latency affects response times. Rolling back requires disabling the VerifySMS hook configuration and redeploying the previous version. Ensure the external hook validates the OTP exactly once and does not allow replay across multiple attempts.

Ecosystem Topology