Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

test new accepts parent-directory names and creates files outside supabase/tests

Aperta
#6,742 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@7ttp ci sta già lavorando.

Dal 23/9/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

🐛 Bug supabase/cli
Affected area

Database

Supabase CLI version

v2.118.0-beta.67

Operating system

macOS 15.1 (Darwin 24.1.0)

Installation method

npm (npx)

Command
tmp="$(mktemp -d)"
mkdir -p "$tmp/project"

npx --yes --package=supabase@2.118.0-beta.67 -- \
  supabase --workdir "$tmp/project" test new ../../../escaped

test -f "$tmp/escaped_test.sql" && echo "created outside supabase/tests"
Actual output
{"path":"../escaped_test.sql","template":"pgtap","message":""}
created outside supabase/tests

The command exits successfully and creates escaped_test.sql outside the configured workdir. The expected supabase/tests directory is not created.

Expected behavior

test new should reject a name whose normalized output path escapes <workdir>/supabase/tests, exit non-zero, and write nothing outside that directory.

Names containing subdirectories should remain valid if their resolved destination stays within supabase/tests.

Steps to reproduce
  1. Create an empty temporary project directory.
  2. Run supabase test new with ../../../escaped as the test name, as shown above.
  3. Observe that the command reports success.
  4. Observe that the generated file is outside both the configured workdir and supabase/tests.
Crash report ID

No response

Docker and service versions
Not applicable; this command does not use Docker or local services.
Additional context

The handler constructs the destination with path.join("supabase", "tests", name + "_test.sql"). Parent-directory segments are normalized before the write, but the result is not checked against the intended tests directory:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/new.handler.ts#L24-L29

The command's side-effect contract documents writes only under <workdir>/supabase/tests:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/SIDE_EFFECTS.md#files-written

The existing file check prevents overwriting an existing outside file, but the command can create a new file and parent directories outside its documented destination.

supabase migration new already performs an analogous containment check for migration names:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/migration/new/new.handler.ts#L36-L46

I searched the current and historical issues and pull requests and did not find an existing report or active fix. I would be happy to contribute a focused fix and integration test after maintainer triage if this is labeled open-for-contribution.

Lingua principale
TypeScript
Stelle
2.4k
Fork
523
Merge medio
1g 1h
PR unite (30g)
268

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di supabase/cli

Tutte le issue di supabase/cli

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.