Game guide · source of truth
Ledger

WEB-028

Spike: site_server / job_worker JWT roles through Kong + PostgREST (api.health), anon cannot impersonate

← Ledger

donestatus · web-db
1✓ 1✗tests passed / failed
4.60Mtokens · 1 min
0evidence files

Evidence

From logs/evidence/WEB-028/. Click a thumbnail for the full image.

No evidence files in logs/evidence/WEB-028/.

Tests

fail server-role JWTs via Kong/PostgREST · 0.9 s · raw log$ pnpm --filter @zoen/db test:int
pass server-role JWTs via Kong/PostgREST · 0.6 s · raw log$ pnpm --filter @zoen/db test:int

Notes

2026-10-04 14:07 UTC · Spike OK (no fallback needed): HS256 JWTs with role site_server / job_worker signed with the local JWT secret reach PostgREST through Kong as those roles (api.health returns current_user); wrong-secret token → 401; site_server sees no admin tables. Exposing new schemas needs a stack restart (supabase stop/start keeps data). packages/db test:int (4 tests).