mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 03:45:06 +03:00
- lib/assets/sanitize-svg.ts: conservative allowlist sanitizer → {viewBox, body}
for line-art SVGs; strips script/foreignObject/image/event-handlers/hrefs and
rejects DOCTYPE/entity and non-drawing input
- lib/supabase/assets.ts: listAssets() + resolveIcon() (seed → DB) via the anon
client; insertAsset() via the admin (secret) client
- app/api/assets/route.ts: GET the library; POST an SVG (multipart) → sanitize →
insert. Returns a clear 503 when SUPABASE_SECRET_KEY isn't configured
- /api/og: resolve the icon param through resolveIcon so uploaded assets render
in OG + Thumb
- Editor Assets panel: load /api/assets, merge seed + uploaded in the grid, and
replace the disabled button with a real file upload (loading + error states)
Reads work with the publishable key; uploads (writes) go through our server
route with the secret key, keeping the publishable key read-only.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>