From 1097fcaa2f4e7954f7636eb8bbdc04c8060affc0 Mon Sep 17 00:00:00 2001 From: Etienne Stalmans Date: Thu, 21 May 2026 11:04:12 +0200 Subject: [PATCH] fix: vercelUrl must always be https (#46193) ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? Only checks the for a valid URL that has hostname of vercel.com. ## What is the new behavior? Ensures the URL protocol is HTTPS ## Additional context Vercel will never load over any other protocol than HTTPS --- .../interfaces/Integrations/Vercel/VercelIntegration.utils.ts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/apps/studio/components/interfaces/Integrations/Vercel/VercelIntegration.utils.ts b/apps/studio/components/interfaces/Integrations/Vercel/VercelIntegration.utils.ts index cf4a7f0c93b..3c55db6f9e6 100644 --- a/apps/studio/components/interfaces/Integrations/Vercel/VercelIntegration.utils.ts +++ b/apps/studio/components/interfaces/Integrations/Vercel/VercelIntegration.utils.ts @@ -1,6 +1,7 @@ export function isVercelUrl(url: string): boolean { try { - return new URL(url).hostname === 'vercel.com' + const u = new URL(url) + return u.protocol === 'https:' && u.hostname === 'vercel.com' } catch { // If the URL is invalid, return false return false