Skip to content

test new accepts parent-directory names and creates files outside supabase/tests #6742

Description

@kavyabhand

Affected area

Database

Supabase CLI version

v2.118.0-beta.67

Operating system

macOS 15.1 (Darwin 24.1.0)

Installation method

npm (npx)

Command

tmp="$(mktemp -d)"
mkdir -p "$tmp/project"

npx --yes --package=supabase@2.118.0-beta.67 -- \
  supabase --workdir "$tmp/project" test new ../../../escaped

test -f "$tmp/escaped_test.sql" && echo "created outside supabase/tests"

Actual output

{"path":"../escaped_test.sql","template":"pgtap","message":""}
created outside supabase/tests

The command exits successfully and creates escaped_test.sql outside the configured workdir. The expected supabase/tests directory is not created.

Expected behavior

test new should reject a name whose normalized output path escapes <workdir>/supabase/tests, exit non-zero, and write nothing outside that directory.

Names containing subdirectories should remain valid if their resolved destination stays within supabase/tests.

Steps to reproduce

  1. Create an empty temporary project directory.
  2. Run supabase test new with ../../../escaped as the test name, as shown above.
  3. Observe that the command reports success.
  4. Observe that the generated file is outside both the configured workdir and supabase/tests.

Crash report ID

No response

Docker and service versions

Not applicable; this command does not use Docker or local services.

Additional context

The handler constructs the destination with path.join("supabase", "tests", name + "_test.sql"). Parent-directory segments are normalized before the write, but the result is not checked against the intended tests directory:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/new.handler.ts#L24-L29

The command's side-effect contract documents writes only under <workdir>/supabase/tests:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/SIDE_EFFECTS.md#files-written

The existing file check prevents overwriting an existing outside file, but the command can create a new file and parent directories outside its documented destination.

supabase migration new already performs an analogous containment check for migration names:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/migration/new/new.handler.ts#L36-L46

I searched the current and historical issues and pull requests and did not find an existing report or active fix. I would be happy to contribute a focused fix and integration test after maintainer triage if this is labeled open-for-contribution.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions