AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Dashboard Auth Hooks Change Silently Wipes Custom SMTP Config And Resets Rate_limit_email_sent

Creating or deleting a Send Email hook in the Supabase dashboard silently nullifies all custom SMTP fields and resets rate_limit_email_sent to default, leading to complete silent auth email failure when the hook is later disabled.

highConfidence 80%React

Origin Analysis

Dashboard Auth Hooks update sends an incomplete auth config object with null/undefined SMTP fields, causing the backend to overwrite existing SMTP settings and reset rate_limit_email_sent to its default value.
1. Open Supabase dashboard and navigate to Authentication > Hooks. 2. Create or delete a Send Email hook. 3. Go to Authentication > SMTP settings or inspect the auth config API. 4. Observe that smtp_host, smtp_user, smtp_pass, smtp_port, smtp_admin_email, smtp_sender_name are null and rate_limit_email_sent is reset to 2.

Fixing Code Block

Edge Case Audit

This frontend fix assumes the backend supports receiving the full config with preserved fields. Concurrent admin edits could still cause lost updates unless optimistic concurrency or field-level patch is implemented. If the user intentionally wants to clear SMTP, the current patch prevents that; a separate explicit SMTP update UI should be used. Rollback: revert to previous dashboard version and restore SMTP values from backup or environment variables.

Ecosystem Topology