mirror of
https://github.com/supabase/supabase.git
synced 2026-10-07 18:35:07 +03:00
`isValidEdgeFunctionURL` guards the server-side fetch in
`pages/api/edge-functions/test.ts`. When `NIMBUS_PROD_PROJECTS_URL` is set it
built a regex by string concatenation, which had several problems:
- The branch returned early, so a deployment configured with an additional
projects domain rejected every `*.supabase.co` / `*.supabase.red` URL, and
rejected self-hosted URLs even when `isPlatform` was false.
- The guard was `!== undefined`, so an env var declared-but-blank took the
branch and rejected every URL.
- The subdomain pattern `[a-z]*` matched a single label of letters only, so
refs containing digits, nested subdomains, and explicit ports all failed.
- Only `.` was escaped before interpolation into the regex, so a value without
the exact `https://*.` prefix or with a trailing slash silently produced a
pattern that matched nothing.
- Reading `process.env` at module scope made the branch untestable, and it had
no test coverage.
Parse the URL instead of pattern-matching it, and treat the additional domain
as additive to the default hosts rather than a replacement.
The default `[a-z]{20}.supabase.(co|red)` host check is deliberately unchanged.
This function doubles as an SSRF allowlist for a fetch that carries the
caller's credentials, so the default allowlist is left exactly as it was.