Commit Graph
4 Commits
Author SHA1 Message Date
Charis 64143a5d90 fix(pg-meta): tighten pg-format keyword() against control-phrase injection (#46076)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (sanitization hardening).

## What is the current behavior?

`pg-format`'s `keyword()` helper validates with `/^[A-Za-z][A-Za-z0-9_
]*$/`, which allows any space-separated word sequence. Phrases like
`'DROP TABLE'` or `'DELETE FROM users'` pass validation and can be
interpolated into queries.

## What is the new behavior?

`keyword()` accepts either a single word matching
`[A-Za-z][A-Za-z0-9_]*` (no spaces) or a phrase from a small
case-insensitive allow-list (`'INSTEAD OF'`, `'BY DEFAULT'`) — which
covers every multi-word value real callers actually produce (trigger
activation, identity generation). Arbitrary multi-word phrases now
throw. Tests updated accordingly.

## Additional context

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Reinforced SQL keyword validation with stricter security controls to
prevent unsafe keyword usage. The system now only permits single-word
identifiers or specific pre-approved multi-word keyword phrases.
Previously accepted multi-word inputs that don't match the curated
allowlist are now properly rejected with improved error messaging.

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46076?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-19 16:13:06 -04:00
Charis c372e77c8b feat: introduce safeSql function to pg-meta (#44467)
* **New Features**
* Added new SQL formatting utilities including keyword validation and
safe SQL composition functions
* Introduced type-safe SQL fragment handling with branded types to
prevent SQL injection vulnerabilities
* Expanded available exports for improved code organization and
accessibility
* Enhanced SQL query building capabilities with improved validation and
composition support
2026-04-02 08:54:25 -04:00
Ivan Vasilov 1cd1ebfc7f chire: Sort imports in all packages, cms, design-system and ui-library apps (#41610)
Sorted all imports in all packages, `cms`, `design-system` and
`ui-library` apps by running `pnpm format` on them.

All changes in this PR are done by the script.
2026-02-05 13:54:10 +01:00
Andrew Valleteau 3221a38596 fix(pgmeta): table editor fails with reserved keyword column names (#41226)
* fix(pg-format): update reserved words list

* test: add more test

* fix: tests
2025-12-10 11:32:57 +01:00