fix: vercelUrl must always be https (#46193)

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Only checks the for a valid URL that has hostname of vercel.com.

## What is the new behavior?

Ensures the URL protocol is HTTPS

## Additional context

Vercel will never load over any other protocol than HTTPS
This commit is contained in:
Etienne Stalmans authored and GitHub committed 2026-05-21 09:04:12 +00:00
1 parent 16f4dae3d2
commit 1097fcaa2f
1 file changed
+2 -1
@@ -1,6 +1,7 @@
export function isVercelUrl(url: string): boolean {
try {
return new URL(url).hostname === 'vercel.com'
const u = new URL(url)
return u.protocol === 'https:' && u.hostname === 'vercel.com'
} catch {
// If the URL is invalid, return false
return false