From 11f0cae5c0be43cb1ef713e4983d1526e73caba0 Mon Sep 17 00:00:00 2001 From: Aneesh Date: Sun, 27 Apr 2025 15:32:33 +0530 Subject: [PATCH] fix: metadata security fixes #331 --- apps/web/src/app/api/[..._path]/route.ts | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/apps/web/src/app/api/[..._path]/route.ts b/apps/web/src/app/api/[..._path]/route.ts index 3e062a0e..66a0b82c 100644 --- a/apps/web/src/app/api/[..._path]/route.ts +++ b/apps/web/src/app/api/[..._path]/route.ts @@ -53,6 +53,10 @@ async function handleRequest(req: NextRequest, method: string) { if (typeof bodyText === "string" && bodyText.length > 0) { const parsedBody = JSON.parse(bodyText); parsedBody.config = parsedBody.config || {}; + parsedBody.metadata = { + ...parsedBody.metadata, + supabase_user_id: user.id + } parsedBody.config.configurable = { ...parsedBody.config.configurable, supabase_session: session,