Files
supabase/apps
David WhittingtonandClaude Opus 5.5 f8fcdb0c27 fix(logs): route the unified logs export through the safe SQL boundary
`retrieveUnifiedLogs` built its SQL with a plain template literal, which
stringifies the `SafeLogSqlFragment` returned by the query builder and
drops the brand, then posted it with a raw `post()` call. It was the one
place in the logs data layer that bypassed `executeAnalyticsSql`, the
wire boundary that rejects unbranded SQL at compile time.

Composes with `safeSql` and runs through `executeAnalyticsSql` instead,
matching the row-list query in `unified-logs-infinite-query.ts`. Like the
row list, it now also raises an error the endpoint reports inside a
successful response, instead of silently exporting an empty file.

No behaviour change for valid input. The limit goes through
`analyticsLiteral`, which rejects a non-finite value rather than emitting
`LIMIT NaN` — not reachable from the download dialog, which offers
100/500/1000, but the previous code would have sent it verbatim.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 13:12:24 -05:00
..