From b79a645f4fa31e8591026222371b4b0300d4e58a Mon Sep 17 00:00:00 2001 From: Etienne Stalmans Date: Tue, 17 Mar 2026 16:28:38 +0100 Subject: [PATCH] fix: escape regex control character (#43806) ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? regex control character, `.` is not escaped. ## What is the new behavior? Escapes control characters and makes regex a little stricter. Use regex literal --- apps/studio/lib/api/edgeFunctions.test.ts | 8 ++++---- apps/studio/lib/api/edgeFunctions.ts | 4 ++-- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/apps/studio/lib/api/edgeFunctions.test.ts b/apps/studio/lib/api/edgeFunctions.test.ts index 54e0af1f63e..76ac26dda3d 100644 --- a/apps/studio/lib/api/edgeFunctions.test.ts +++ b/apps/studio/lib/api/edgeFunctions.test.ts @@ -4,10 +4,10 @@ import { isValidEdgeFunctionURL } from './edgeFunctions' describe('isValidEdgeFunctionURL', () => { const validEdgeFunctionUrls = [ - 'https://projectref.supabase.co/functions/v1/hello-world', - 'https://projectref.supabase.red/functions/v1/hello-world', - 'https://projectref.supabase.red/functions/v3/hello-world', - 'https://projectref.supabase.red/functions/v3/hello-world', + 'https://uniquetwentychararef.supabase.co/functions/v1/hello-world', + 'https://uniquetwentychararef.supabase.red/functions/v1/hello-world', + 'https://uniquetwentychararef.supabase.red/functions/v3/hello-world', + 'https://uniquetwentychararef.supabase.red/functions/v3/hello-world', ] const validLocalEdgeFunctionsUrls = [ diff --git a/apps/studio/lib/api/edgeFunctions.ts b/apps/studio/lib/api/edgeFunctions.ts index 15b0138328a..4a1a4817436 100644 --- a/apps/studio/lib/api/edgeFunctions.ts +++ b/apps/studio/lib/api/edgeFunctions.ts @@ -9,14 +9,14 @@ export const isValidEdgeFunctionURL = (url: string, isPlatform: boolean) => { if (!isPlatform) { const regexValidLocalEdgeFunctionURL = new RegExp( - '^https?://[^\\s/?#]+/functions/v[0-9]{1}/.*$' + /^https?:\/\/[^\s/?#]+\/functions\/v[0-9]{1}\/.*$/ ) return regexValidLocalEdgeFunctionURL.test(url) } const regexValidEdgeFunctionURL = new RegExp( - '^https://[a-z]*.supabase.(red|co)/functions/v[0-9]{1}/.*$' + /^https:\/\/[a-z]{20}\.supabase\.(red|co)\/functions\/v[0-9]{1}\/.*$/ ) return regexValidEdgeFunctionURL.test(url)