Commit Graph
6 Commits
Author SHA1 Message Date
Matt Johnston 04f4cc6c1c fix(studio): correct edge function URL validation for additional project domains
`isValidEdgeFunctionURL` guards the server-side fetch in
`pages/api/edge-functions/test.ts`. When `NIMBUS_PROD_PROJECTS_URL` is set it
built a regex by string concatenation, which had several problems:

- The branch returned early, so a deployment configured with an additional
  projects domain rejected every `*.supabase.co` / `*.supabase.red` URL, and
  rejected self-hosted URLs even when `isPlatform` was false.
- The guard was `!== undefined`, so an env var declared-but-blank took the
  branch and rejected every URL.
- The subdomain pattern `[a-z]*` matched a single label of letters only, so
  refs containing digits, nested subdomains, and explicit ports all failed.
- Only `.` was escaped before interpolation into the regex, so a value without
  the exact `https://*.` prefix or with a trailing slash silently produced a
  pattern that matched nothing.
- Reading `process.env` at module scope made the branch untestable, and it had
  no test coverage.

Parse the URL instead of pattern-matching it, and treat the additional domain
as additive to the default hosts rather than a replacement.

The default `[a-z]{20}.supabase.(co|red)` host check is deliberately unchanged.
This function doubles as an SSRF allowlist for a fetch that carries the
caller's credentials, so the default allowlist is left exactly as it was.
2026-08-25 19:45:17 -03:00
Vaibhav 05d8dd356c fix: selfhost edge URLs (#47861) 2026-07-16 14:06:40 +01:00
Etienne Stalmans b79a645f4f fix: escape regex control character (#43806)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

regex control character, `.` is not escaped.

## What is the new behavior?

Escapes control characters and makes regex a little stricter. Use regex
literal
2026-03-17 16:28:38 +01:00
Kalleby SantosandCharis Lam 70510acf5b feat(studio-local): functions management api - test functions (#42350)
Feature

## What is the current behavior?

Functions page on self-hosted differs from Platform

## What is the new behavior?

Adds the possibility to try/test functions in Self-Host version.

## Summary by CodeRabbit

* **Bug Fixes**
* Improved edge function URL validation so testing works reliably both
on-platform and off-platform, including proper URL handling for local
setups.

* **UI Improvements**
* Moved the Test button in the edge functions interface for more
consistent layout while preserving its behavior.

* **Tests**
  * Expanded tests to cover platform-aware URL validation scenarios.

---------

Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com>
2026-02-11 21:26:42 +00:00
Alaister Young ec6c90bce2 fix: support nimbus project urls for testing edge functions (#39548) 2025-10-15 15:12:35 +08:00
Jordi EnricandJoshen Lim 9e72050658 Add regex guard for edge functions test endpoint (#35688)
* Add regex guard for edge functions test endpoint

* Remove conosle log

* add tests

* empty

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-05-15 08:57:06 +00:00