Add regex guard for edge functions test endpoint (#35688)

* Add regex guard for edge functions test endpoint

* Remove conosle log

* add tests

* empty

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
This commit is contained in:
Jordi EnricandJoshen Lim authored and GitHub committed 2025-05-15 08:57:06 +00:00
1 parent dc2f1270db
commit 9e72050658
3 files changed
+48

No files matched your search

+31
View File
@@ -0,0 +1,31 @@
import { expect, describe, it } from 'vitest'
import { isValidEdgeFunctionURL } from './edgeFunctions'
describe('isValidEdgeFunctionURL', () => {
const validEdgeFunctionUrls = [
'https://projectref.supabase.co/functions/v1/hello-world',
'https://projectref.supabase.red/functions/v1/hello-world',
'https://projectref.supabase.red/functions/v3/hello-world',
'https://projectref.supabase.red/functions/v3/hello-world',
]
const invalidEdgeFunctionUrls = [
'https://notsupabase.com/functions/v1/test',
'https://projectref.notsupabase.com/functions/v1/test',
'https://localhost?https://aaaa.supabase.co/functions/v1/xxx',
'https://localhost:3000/?https://aaaa.supabase.co/functions/v1/xxx',
'http://localhost:3000/?https://aaaa.supabase.co/functions/v1/xxx',
]
it('should match valid edge function URLs', () => {
for (const url of validEdgeFunctionUrls) {
expect(isValidEdgeFunctionURL(url), `Expected ${url} to be valid`).toBe(true)
}
})
it('should not match invalid edge function URLs', () => {
for (const url of invalidEdgeFunctionUrls) {
expect(isValidEdgeFunctionURL(url), `Expected ${url} to be invalid`).toBe(false)
}
})
})
+7
View File
@@ -0,0 +1,7 @@
export const isValidEdgeFunctionURL = (url: string) => {
const regexValidEdgeFunctionURL = new RegExp(
'^https://[a-z]*.supabase.(red|co)/functions/v[0-9]{1}/.*$'
)
return regexValidEdgeFunctionURL.test(url)
}
@@ -1,3 +1,4 @@
import { isValidEdgeFunctionURL } from 'lib/api/edgeFunctions'
import { NextApiRequest, NextApiResponse } from 'next'
export default async function handler(req: NextApiRequest, res: NextApiResponse) {
@@ -21,6 +22,15 @@ async function handlePost(req: NextApiRequest, res: NextApiResponse) {
try {
const { url, method, body: requestBody, headers: customHeaders } = req.body
const validEdgeFnUrl = isValidEdgeFunctionURL(url)
if (!validEdgeFnUrl) {
return res.status(400).json({
status: 400,
error: { message: 'Provided URL is not a valid Supabase edge function URL' },
})
}
// Remove any undefined or null values from custom headers
const sanitizedCustomHeaders = Object.entries(customHeaders || {}).reduce(
(acc, [key, value]) => {