mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 03:15:06 +03:00
Line icons are stroke-only by brand rule, but a partner's logo (Grafana,
Multigres, etc.) needs to render in ITS OWN colors — a second asset kind
alongside the existing icon system, not a replacement for it.
- supabase/migrations/0002_logo_assets.sql: add width/height to `assets`
(kind + storage_path already existed from 0001)
- lib/assets/sanitize-svg.ts: sanitizeLogoSvg() — a separate allowlist that
PRESERVES fill/stroke/gradients/style color declarations (unlike the icon
sanitizer, which strips them for the stroke-only treatment), while still
blocking scripts, event handlers, and external references (internal `#id`
refs are kept so gradient defs/<use> keep working). Unit-tested against a
mixed color+attack payload.
- lib/supabase/assets.ts: insertLogoAsset() uploads to the og-assets Storage
bucket (raster-safe, unlike inline SVG bodies) and records client-measured
width/height; rowToIcon exposes kind/url/width/height for both kinds.
- app/api/assets/route.ts: POST branches on a `kind` field ('icon', default,
or 'logo'); logo accepts SVG/PNG/JPEG/WebP up to 2MB, requires width+height.
- app/api/og/route.tsx: icon slots render logos as-is (no stroke
normalization), fit to their natural aspect ratio via a new fitBox() helper.
- app/page.tsx: a second "+ Upload logo (color)" control measures the file's
natural dimensions in-browser (Image().onload) before POSTing; the icon
picker renders logo entries as real <img> (actual colors) instead of the
forced-stroke SVG redraw.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>