Ledger
WEB-028
Spike: site_server / job_worker JWT roles through Kong + PostgREST (api.health), anon cannot impersonate
Evidence
From logs/evidence/WEB-028/. Click a thumbnail for the full image.
No evidence files in logs/evidence/WEB-028/.
Tests
Notes
2026-10-04 14:07 UTC · Spike OK (no fallback needed): HS256 JWTs with role site_server / job_worker signed with the local JWT secret reach PostgREST through Kong as those roles (api.health returns current_user); wrong-secret token → 401; site_server sees no admin tables. Exposing new schemas needs a stack restart (supabase stop/start keeps data). packages/db test:int (4 tests).
