Skip to content

πŸ” Wishlist: Enable Supabase Leaked Password Protection (Pro Plan)Β #4

@welshDog

Description

@welshDog

πŸ’‘ Wish List Item β€” Enable When Funded

What it is

Supabase's Leaked Password Protection checks user passwords against HaveIBeenPwned.org on sign-up/login. Blocks compromised passwords automatically.

Why it matters

  • Students creating accounts won't be able to use known-breached passwords
  • Protects the course platform and student accounts
  • Supabase security scanner currently flags this as a WARN

Blocker

πŸ”’ Requires Supabase Pro plan β€” not available on free tier

When to action

  • Upgrade to Supabase Pro
  • Go to: Auth β†’ Password Security β†’ Enable Leaked Password Protection toggle
  • Done βœ…

Cost reference

Supabase Pro is ~$25/month per project


Added 8 May 2026 β€” post birthday-drop security audit πŸŽ‚

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions