Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

test new accepts parent-directory names and creates files outside supabase/tests

オープン
#6,742 コメント 0 件 リアクション 0 件 担当者 1 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@7ttp がすでに取り組んでいます。

2026年9月23日 から。

評価

この issue はまだ評価されていません。

説明

🐛 Bug supabase/cli
Affected area

Database

Supabase CLI version

v2.118.0-beta.67

Operating system

macOS 15.1 (Darwin 24.1.0)

Installation method

npm (npx)

Command
tmp="$(mktemp -d)"
mkdir -p "$tmp/project"

npx --yes [email protected] -- \
  supabase --workdir "$tmp/project" test new ../../../escaped

test -f "$tmp/escaped_test.sql" && echo "created outside supabase/tests"
Actual output
{"path":"../escaped_test.sql","template":"pgtap","message":""}
created outside supabase/tests

The command exits successfully and creates escaped_test.sql outside the configured workdir. The expected supabase/tests directory is not created.

Expected behavior

test new should reject a name whose normalized output path escapes <workdir>/supabase/tests, exit non-zero, and write nothing outside that directory.

Names containing subdirectories should remain valid if their resolved destination stays within supabase/tests.

Steps to reproduce
  1. Create an empty temporary project directory.
  2. Run supabase test new with ../../../escaped as the test name, as shown above.
  3. Observe that the command reports success.
  4. Observe that the generated file is outside both the configured workdir and supabase/tests.
Crash report ID

No response

Docker and service versions
Not applicable; this command does not use Docker or local services.
Additional context

The handler constructs the destination with path.join("supabase", "tests", name + "_test.sql"). Parent-directory segments are normalized before the write, but the result is not checked against the intended tests directory:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/new.handler.ts#L24-L29

The command's side-effect contract documents writes only under <workdir>/supabase/tests:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/SIDE_EFFECTS.md#files-written

The existing file check prevents overwriting an existing outside file, but the command can create a new file and parent directories outside its documented destination.

supabase migration new already performs an analogous containment check for migration names:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/migration/new/new.handler.ts#L36-L46

I searched the current and historical issues and pull requests and did not find an existing report or active fix. I would be happy to contribute a focused fix and integration test after maintainer triage if this is labeled open-for-contribution.

主要言語
TypeScript
スター
2.4k
フォーク
523
平均マージ
1日 2時間
マージ済み PR(30日)
293

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

supabase/cli のほかの issue

supabase/cli の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。