AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Self-Hosted JWT Config Applied To Wrong Database When Using Custom POSTGRES_DB

When POSTGRES_DB is set to a custom database name, the initialization script docker/volumes/db/jwt.sql hardcodes 'postgres' as the database name for ALTER DATABASE SET, causing JWT settings to be applied to the default database instead of the intended custom database. This leads to silent auth and RLS failures.

highConfidence 90%Supabase

Origin Analysis

The SQL initialization script jwt.sql contains a hardcoded database name 'postgres' in the ALTER DATABASE statement, ignoring the POSTGRES_DB environment variable. The design flaw is that initialization scripts are not parameterized to use the actual database name from the environment.
1. Set POSTGRES_DB=custom_db in .env. 2. Run docker compose up -d. 3. Connect to custom_db and check for app.settings.jwt_exp: SELECT current_setting('app.settings.jwt_exp', true); 4. Observe that the setting is missing because it was applied to the 'postgres' database instead.

Fixing Code Block

Edge Case Audit

This fix assumes the initialization script is executed while connected to the database specified by POSTGRES_DB. If the script is run while connected to a different database (e.g., always 'postgres'), the fix will not work. Verify the connection context. Additionally, this change only affects the current database; if multiple databases need the setting, additional steps are required. The dynamic SQL uses current_database(), which may be inappropriate if the script runs in a transaction that changes databases. Ensure the psql client version supports DO blocks (PostgreSQL 9.0+). To roll back, manually execute: ALTER DATABASE <your_db> RESET "app.settings.jwt_exp"; and restore the original hardcoded script if needed.

Ecosystem Topology