Files
Charis 64143a5d90 fix(pg-meta): tighten pg-format keyword() against control-phrase injection (#46076)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (sanitization hardening).

## What is the current behavior?

`pg-format`'s `keyword()` helper validates with `/^[A-Za-z][A-Za-z0-9_
]*$/`, which allows any space-separated word sequence. Phrases like
`'DROP TABLE'` or `'DELETE FROM users'` pass validation and can be
interpolated into queries.

## What is the new behavior?

`keyword()` accepts either a single word matching
`[A-Za-z][A-Za-z0-9_]*` (no spaces) or a phrase from a small
case-insensitive allow-list (`'INSTEAD OF'`, `'BY DEFAULT'`) — which
covers every multi-word value real callers actually produce (trigger
activation, identity generation). Arbitrary multi-word phrases now
throw. Tests updated accordingly.

## Additional context

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Reinforced SQL keyword validation with stricter security controls to
prevent unsafe keyword usage. The system now only permits single-word
identifiers or specific pre-approved multi-word keyword phrases.
Previously accepted multi-word inputs that don't match the curated
allowlist are now properly rejected with improved error messaging.

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46076?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-19 16:13:06 -04:00
..