mirror of
https://github.com/supabase/supabase.git
synced 2026-10-07 10:25:06 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (sanitization hardening). ## What is the current behavior? `pg-format`'s `keyword()` helper validates with `/^[A-Za-z][A-Za-z0-9_ ]*$/`, which allows any space-separated word sequence. Phrases like `'DROP TABLE'` or `'DELETE FROM users'` pass validation and can be interpolated into queries. ## What is the new behavior? `keyword()` accepts either a single word matching `[A-Za-z][A-Za-z0-9_]*` (no spaces) or a phrase from a small case-insensitive allow-list (`'INSTEAD OF'`, `'BY DEFAULT'`) — which covers every multi-word value real callers actually produce (trigger activation, identity generation). Arbitrary multi-word phrases now throw. Tests updated accordingly. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Reinforced SQL keyword validation with stricter security controls to prevent unsafe keyword usage. The system now only permits single-word identifiers or specific pre-approved multi-word keyword phrases. Previously accepted multi-word inputs that don't match the curated allowlist are now properly rejected with improved error messaging. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46076?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->