Is it possible to force actual password validation in Postgres?
sirachastudio
HOBBYOP

6 days ago

Hello, is there a way to force actual password authentication (scram-sha-256) for PostgreSQL connections in order to strengthen database security? Thanks.

$10 Bounty

2 Replies

Railway
BOT

6 days ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • 6 days ago


Postgres on Railway already uses scram-sha-256.


versehard
FREE

6 days ago

Are you seeing it connect even when you enter a wrong password, or just not getting a password prompt?

Railway already uses SCRAM, as mentioned above, but the connection method matters. Connecting from inside the container can use different auth rules than connecting through the public or private hostname.

You can check the rules with an admin connection:

SHOW hba_file;
SELECT * FROM pg_hba_file_rules;

Look for a trust rule matching your connection. Postgres uses the first matching rule, so adding scram-sha-256 below it won’t override it. Also, password_encryption only controls how new passwords are stored—it doesn’t force password checks.

Try a fresh connection with an intentionally wrong password. If it still works, share the relevant rules and how you’re connecting, with credentials removed, and I can help narrow it down.


Welcome!

Sign in to your Railway account to join the conversation.

Loading...