prompts.title and prompts.prompt are plain text columns with no constraint. The form caps title at 100 characters and the prompt textarea has no limit at all.
The anon key is public so the form is not a control. Anyone can post a multi megabyte prompt straight to the API, repeatedly.
Where
supabase/migrations/20260101000000_initial_schema.sql:33-52 both columns are text not null, no check
- we already cap
feedback.subject, feedback.message and prompt_reports.details in 20260905120000_add_indexes_and_column_constraints.sql:89-95
src/pages/Upload.tsx:432 caps the title in the UI only
- the prompt textarea has no maxLength
We did this thinking for feedback and reports and then skipped the table holding the most text.
Fix
Add check constraints above the UI limits so they are an abuse backstop, not a second copy of form validation. Follow the not valid then validate pattern already used in 20260905120000_add_indexes_and_column_constraints.sql:89-107 so old rows cannot fail the migration.
Add a maxLength to the textarea while we are in there.
Done when
Both columns have constraints, the migration applies cleanly to an empty database, and going over the limit gives a readable message instead of a Postgres error.
prompts.titleandprompts.promptare plain text columns with no constraint. The form caps title at 100 characters and the prompt textarea has no limit at all.The anon key is public so the form is not a control. Anyone can post a multi megabyte prompt straight to the API, repeatedly.
Where
supabase/migrations/20260101000000_initial_schema.sql:33-52both columns aretext not null, no checkfeedback.subject,feedback.messageandprompt_reports.detailsin20260905120000_add_indexes_and_column_constraints.sql:89-95src/pages/Upload.tsx:432caps the title in the UI onlyWe did this thinking for feedback and reports and then skipped the table holding the most text.
Fix
Add check constraints above the UI limits so they are an abuse backstop, not a second copy of form validation. Follow the
not validthen validate pattern already used in20260905120000_add_indexes_and_column_constraints.sql:89-107so old rows cannot fail the migration.Add a maxLength to the textarea while we are in there.
Done when
Both columns have constraints, the migration applies cleanly to an empty database, and going over the limit gives a readable message instead of a Postgres error.