Skip to content

fix: validate parsed user metadata shape - #1455

Open
kekekuli wants to merge 1 commit into
supabase:masterfrom
kekekuli:master
Open

kekekuli wants to merge 1 commit into
supabase:masterfrom
kekekuli:master

Conversation

@kekekuli

Copy link
Copy Markdown

What kind of change does this PR introduce?

Bug fix.

What is the current behavior?

parseUserMetadata casts the result of JSON.parse to Record<string, string> without runtime validation.

Valid JSON values such as null, arrays, and primitives can therefore be treated as user metadata even though callers expect a metadata object.

What is the new behavior?

parseUserMetadata now validates that the decoded value is a non-null, non-array JSON object before returning it.

Additional context

This completes the validation follow-up noted in getSignedUploadURL.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant