Files
supabase/apps
ShaneandClaude Opus 4.8 a582df7c7f feat(og-generator): custom SVG icon uploads (asset library)
- lib/assets/sanitize-svg.ts: conservative allowlist sanitizer → {viewBox, body}
  for line-art SVGs; strips script/foreignObject/image/event-handlers/hrefs and
  rejects DOCTYPE/entity and non-drawing input
- lib/supabase/assets.ts: listAssets() + resolveIcon() (seed → DB) via the anon
  client; insertAsset() via the admin (secret) client
- app/api/assets/route.ts: GET the library; POST an SVG (multipart) → sanitize →
  insert. Returns a clear 503 when SUPABASE_SECRET_KEY isn't configured
- /api/og: resolve the icon param through resolveIcon so uploaded assets render
  in OG + Thumb
- Editor Assets panel: load /api/assets, merge seed + uploaded in the grid, and
  replace the disabled button with a real file upload (loading + error states)

Reads work with the publishable key; uploads (writes) go through our server
route with the secret key, keeping the publishable key read-only.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-01 14:26:30 -05:00
..