Files
Matt Johnston 04f4cc6c1c fix(studio): correct edge function URL validation for additional project domains
`isValidEdgeFunctionURL` guards the server-side fetch in
`pages/api/edge-functions/test.ts`. When `NIMBUS_PROD_PROJECTS_URL` is set it
built a regex by string concatenation, which had several problems:

- The branch returned early, so a deployment configured with an additional
  projects domain rejected every `*.supabase.co` / `*.supabase.red` URL, and
  rejected self-hosted URLs even when `isPlatform` was false.
- The guard was `!== undefined`, so an env var declared-but-blank took the
  branch and rejected every URL.
- The subdomain pattern `[a-z]*` matched a single label of letters only, so
  refs containing digits, nested subdomains, and explicit ports all failed.
- Only `.` was escaped before interpolation into the regex, so a value without
  the exact `https://*.` prefix or with a trailing slash silently produced a
  pattern that matched nothing.
- Reading `process.env` at module scope made the branch untestable, and it had
  no test coverage.

Parse the URL instead of pattern-matching it, and treat the additional domain
as additive to the default hosts rather than a replacement.

The default `[a-z]{20}.supabase.(co|red)` host check is deliberately unchanged.
This function doubles as an SSRF allowlist for a fetch that carries the
caller's credentials, so the default allowlist is left exactly as it was.
2026-08-25 19:45:17 -03:00
..
2026-08-20 20:05:35 +10:00