mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 03:45:06 +03:00
## Problem The PostgREST observability page crashes for some projects with `URIError: URI malformed`. The route renderer calls `decodeURIComponent` directly on the request query string, which is user-controlled. A malformed percent-sequence (for example a literal `%` in `?discount=100%`) makes `decodeURIComponent` throw during render, taking down the whole page via the global error boundary. Tracked in Sentry issue 7536581822. ## Fix Add a `safeDecodeURIComponent` helper that wraps `decodeURIComponent` in a try/catch and falls back to the raw string on failure. Use it in the route renderer. The sibling `queryParamsToObject` call is unaffected since `URLSearchParams` already tolerates malformed escapes. ## How to test - Open a project's PostgREST observability report (`/project/[ref]/observability/postgrest`). - Ensure a request with a malformed query string (e.g. a path containing a bare `%`) appears in the data. - Expected result: the row renders with the raw search string instead of crashing the page. - Unit tests for `safeDecodeURIComponent` cover valid decode, malformed input, and empty string. --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>