feat(cli): add stack command options and destruction - #6517
Conversation
42ab609 to
93ff6fd
Compare
| "A credential cannot be represented losslessly as dotenv. Use --env --output-format json.", | ||
| }), | ||
| ); | ||
| return Effect.succeed(`${name}=${quote}${value}${quote}`); |
There was a problem hiding this comment.
🟡 Severity: MEDIUM
A stack credential containing a single quote but no backtick is wrapped in backticks here. If a consumer sources the generated dotenv file, the shell evaluates that content as command substitution, so an attacker-controlled credential can execute commands before environment variables are set.
Helpful? Add 👍 / 👎
💡 Fix Suggestion
Suggestion: On line 84, remove the backtick from the list of candidate quote characters. Change ["'", "\"]to["'"]. With this change, any credential or value that contains a single quote will fall through to the existing quote === undefinedcheck and fail with the error message directing users to use--output-format json`, rather than falling back to backtick quoting. Backtick-delimited strings are treated as command substitution by POSIX shells (bash, sh, zsh), so sourcing a dotenv file containing backtick-quoted values with attacker-controlled content can execute arbitrary commands. Removing backtick as a quoting option entirely eliminates this risk — dotenv files produced by this function will only ever use single-quote wrapping, which is safe to source.
93ff6fd to
3e6e5e9
Compare
3e6e5e9 to
1e87f8e
Compare
Supabase CLI previewnpx --yes https://pkg.pr.new/supabase/cli/supabase@95551dda43408c6b9d74d0565f86d2addc30edfePreview package for commit |
|
/ai-review |
Add service selection, bulk stopping, environment export, and explicit destruction to the new local stack commands. These options also apply to the config-selected top-level start, stop, and status aliases.
start --excludeaccepts service names, comma-separated or repeated. It leaves the project file unchanged and records the effective start configuration in stack state.stop --allretains data and attempts every readable registered stack. Unreadable entries are skipped with warnings; skipped entries and stop failures produce a nonzero result after the remaining stacks are processed.status --envexports connection variables as dotenv or a JSON variable map, with--override-namefor application-specific names. Ordinary status does not reveal credentials. Database-only stacks can retrieve database credentials with API credentials omitted when Auth is disabled.stack destroypermanently removes one selected stack after confirmation, with--yesfor unattended execution.This follows #6516. The legacy implementations and database data remain separate.