feat: add createSearchTerms#137
Merged
Merged
Conversation
calvinbrewer
commented
May 28, 2025
Contributor
- add support for createSearchTerms method on the protectClient to impove the developer experience of encrypting search terms for use with SQL queries
Contributor
There was a problem hiding this comment.
Pull Request Overview
This PR adds support for a new createSearchTerms method on the ProtectClient to simplify encrypting search terms for SQL queries. Key changes include:
- New type definitions for SearchTerm and EncryptedSearchTerm in types.ts.
- A new SearchTermsOperation in the ffi operations that encrypts an array of search terms.
- Integration of the createSearchTerms method in the ProtectClient along with corresponding tests and documentation updates.
Reviewed Changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| packages/protect/src/types.ts | Added type definitions for search term encryption. |
| packages/protect/src/ffi/operations/search-terms.ts | Implements encryption logic for search terms with special formatting based on return type. |
| packages/protect/src/ffi/index.ts | Exposes the createSearchTerms method in the ProtectClient API. |
| packages/protect/tests/search-terms.test.ts | Added tests to validate the functionality for default, composite-literal, and escaped composite literal returns. |
| docs/reference/supabase-sdk.md | Updated documentation to demonstrate the new API usage. |
| .changeset/fruity-shoes-talk.md | New changeset note documenting the minor release. |
3 tasks
This was referenced Jul 15, 2026
coderdan
added a commit
that referenced
this pull request
Jul 15, 2026
Fixes from the #658 review (10 verified findings + below-the-fold): Correctness: - Quick Start + mid-doc examples now narrow the Result union before reading .data (failure branches throw) — they previously failed strict TS (TS2339). - Supabase EQL install: docs now show `--supabase` (grants) and stop implying it is obsolete; without it encrypted queries hit permission-denied. - Removed the false "Supabase cannot ORDER BY encrypted columns" claim from stash-encryption (it contradicted stash-supabase, the README, and the shipped OPE-backed order()). - #648 rollout dead-end fixed: the Supabase skill now EMBEDS the interim v2-encrypted-twin recipe (schema + encryptedSupabase + dual-write) that backfill/cutover need today, instead of pointing at a deleted section. Reference rot & stale claims: - Removed the #602 "known type error" callout (fixed by protect-ffi 0.29; #602 closed) from stash-encryption; corrected the stale #447 citation in all three skills; fixed the "EQL v3 Typed Schema" dead cross-reference and the generate-eql-migration misattribution in stash-drizzle. - stash-cli: --eql-version default 2→3; corrected the Supabase ORDER-BY and read-path (encryptedSupabaseV3) claims. - AGENTS.md Key Concepts now teaches the v3 typed surface (rule 7). Scoping corrections: like/ilike (matches, with the untyped-only shim noted), empty-needle rejection (adapter-level, not core encryptQuery), SQL-NULL ne inclusion (both adapters), Supabase selector leaf types (JSON scalars only), null-operand handling (forwarded, not rejected), per-column (not per-query) ZeroKMS batching, #137-vs-#654 exposure attribution, drizzle operator opts (async encrypting ops + selector methods only). README polish: init flag table (--region etc.) + removed the redundant post-init eql install step; wasm-inline in Requirements; returnType values note restored; markdown `--`→`---` rules. Added the missing @cipherstash/drizzle changeset for its README fix. The doc claims about the Supabase short-needle guard, withLockContext({identityClaim}), and the StackError discriminated union are made true by the companion code PR (short-needle guard, LockContextInput widening, EncryptionErrorTypes as const) — both are RC-gated to ship together. Claude-Session: https://claude.ai/code/session_01MxTTPaPP16m6br7Hoab94w
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.