AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Local SMTP Should Override Auth.Email.Smtp In Local Development

When both [local_smtp].enabled and [auth.email.smtp].enabled are true in config.toml, the Supabase CLI configures the auth service to use the real SMTP server instead of the local test SMTP server.

mediumConfidence 70%Supabase CLI

Origin Analysis

The SMTP environment generation for auth checks auth.email.smtp.enabled before local_smtp.enabled, causing real SMTP settings to take precedence. Local development SMTP should be checked first when enabled.
1. In config.toml set [local_smtp] enabled = true with a port. 2. Set [auth.email.smtp] enabled = true with real SMTP credentials. 3. Run `supabase start`. 4. Trigger an auth email and observe it is sent through the real SMTP server, not the local test SMTP UI.

Fixing Code Block

func (c *config) smtpEnv() []string { // Local SMTP takes precedence during `supabase start`. if c.LocalSmtp.Enabled { return []string{ "GOTRUE_SMTP_HOST=host.docker.internal", "GOTRUE_SMTP_PORT=2500", "GOTRUE_SMTP_USER=", "GOTRUE_SMTP_PASS=", "GOTRUE_SMTP_ADMIN_EMAIL=" + c.Auth.Email.Smtp.AdminEmail, "GOTRUE_SMTP_SENDER_NAME=" + c.Auth.Email.Smtp.SenderName, } } if c.Auth.Email.Smtp.Enabled { return []string{ "GOTRUE_SMTP_HOST=" + c.Auth.Email.Smtp.Host, "GOTRUE_SMTP_PORT=" + strconv.Itoa(c.Auth.Email.Smtp.Port), "GOTRUE_SMTP_USER=" + c.Auth.Email.Smtp.User, "GOTRUE_SMTP_PASS=" + c.Auth.Email.Smtp.Pass, "GOTRUE_SMTP_ADMIN_EMAIL=" + c.Auth.Email.Smtp.AdminEmail, "GOTRUE_SMTP_SENDER_NAME=" + c.Auth.Email.Smtp.SenderName, } } return nil }
Moved the local_smtp.enabled branch above the auth.email.smtp.enabled branch in the SMTP environment generation function. This ensures that when local SMTP is enabled, it always wins during local development, while real SMTP is used only when local SMTP is disabled.

Edge Case Audit

If a developer intentionally set both enabled to use a real SMTP server locally, this change will silently redirect emails to the local test server. To opt out, set [local_smtp].enabled = false. Ensure the local SMTP container is healthy before relying on it; if it fails, auth emails will be lost. Rollback: revert this change or set local_smtp.enabled = false in config.toml.

Ecosystem Topology