Skip to content

feat: add createSearchTerms#137

Merged
calvinbrewer merged 1 commit into
mainfrom
search-terms
May 28, 2025
Merged

feat: add createSearchTerms#137
calvinbrewer merged 1 commit into
mainfrom
search-terms

Conversation

@calvinbrewer

Copy link
Copy Markdown
Contributor
  • add support for createSearchTerms method on the protectClient to impove the developer experience of encrypting search terms for use with SQL queries

@calvinbrewer
calvinbrewer requested a review from Copilot May 28, 2025 15:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for a new createSearchTerms method on the ProtectClient to simplify encrypting search terms for SQL queries. Key changes include:

  • New type definitions for SearchTerm and EncryptedSearchTerm in types.ts.
  • A new SearchTermsOperation in the ffi operations that encrypts an array of search terms.
  • Integration of the createSearchTerms method in the ProtectClient along with corresponding tests and documentation updates.

Reviewed Changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
packages/protect/src/types.ts Added type definitions for search term encryption.
packages/protect/src/ffi/operations/search-terms.ts Implements encryption logic for search terms with special formatting based on return type.
packages/protect/src/ffi/index.ts Exposes the createSearchTerms method in the ProtectClient API.
packages/protect/tests/search-terms.test.ts Added tests to validate the functionality for default, composite-literal, and escaped composite literal returns.
docs/reference/supabase-sdk.md Updated documentation to demonstrate the new API usage.
.changeset/fruity-shoes-talk.md New changeset note documenting the minor release.

Comment thread packages/protect/src/ffi/operations/search-terms.ts
Comment thread packages/protect/src/ffi/operations/search-terms.ts
@calvinbrewer
calvinbrewer merged commit 1555751 into main May 28, 2025
@calvinbrewer
calvinbrewer deleted the search-terms branch May 28, 2025 15:17
coderdan added a commit that referenced this pull request Jul 15, 2026
Fixes from the #658 review (10 verified findings + below-the-fold):

Correctness:
- Quick Start + mid-doc examples now narrow the Result union before reading
  .data (failure branches throw) — they previously failed strict TS (TS2339).
- Supabase EQL install: docs now show `--supabase` (grants) and stop implying
  it is obsolete; without it encrypted queries hit permission-denied.
- Removed the false "Supabase cannot ORDER BY encrypted columns" claim from
  stash-encryption (it contradicted stash-supabase, the README, and the
  shipped OPE-backed order()).
- #648 rollout dead-end fixed: the Supabase skill now EMBEDS the interim
  v2-encrypted-twin recipe (schema + encryptedSupabase + dual-write) that
  backfill/cutover need today, instead of pointing at a deleted section.

Reference rot & stale claims:
- Removed the #602 "known type error" callout (fixed by protect-ffi 0.29; #602
  closed) from stash-encryption; corrected the stale #447 citation in all three
  skills; fixed the "EQL v3 Typed Schema" dead cross-reference and the
  generate-eql-migration misattribution in stash-drizzle.
- stash-cli: --eql-version default 2→3; corrected the Supabase ORDER-BY and
  read-path (encryptedSupabaseV3) claims.
- AGENTS.md Key Concepts now teaches the v3 typed surface (rule 7).

Scoping corrections: like/ilike (matches, with the untyped-only shim noted),
empty-needle rejection (adapter-level, not core encryptQuery), SQL-NULL ne
inclusion (both adapters), Supabase selector leaf types (JSON scalars only),
null-operand handling (forwarded, not rejected), per-column (not per-query)
ZeroKMS batching, #137-vs-#654 exposure attribution, drizzle operator opts
(async encrypting ops + selector methods only).

README polish: init flag table (--region etc.) + removed the redundant
post-init eql install step; wasm-inline in Requirements; returnType values
note restored; markdown `--`→`---` rules. Added the missing
@cipherstash/drizzle changeset for its README fix.

The doc claims about the Supabase short-needle guard, withLockContext({identityClaim}),
and the StackError discriminated union are made true by the companion code PR
(short-needle guard, LockContextInput widening, EncryptionErrorTypes as const)
— both are RC-gated to ship together.

Claude-Session: https://claude.ai/code/session_01MxTTPaPP16m6br7Hoab94w
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants