AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Query Builder Generates Invalid SQL For Empty In Filters

Passing an empty array to an 'in' filter in the PostgREST query builder produces invalid SQL (`in ()`), causing syntax errors. This affects vault helpers in Supabase Studio.

highConfidence 85%PostgREST

Origin Analysis

The filter serialization logic does not handle empty arrays for the 'in' operator, directly interpolating the array into SQL parentheses without checking length.
Use `new Query().from('users', 'public').select().filter('id', 'in', []).toSql()`; observe generated SQL contains `in ()` which PostgreSQL rejects.

Fixing Code Block

Edge Case Audit

This change alters semantics: previously an empty array caused a runtime error; now it silently returns no rows. Ensure no code depended on that error (unlikely). For tuple filters, use `(col1, col2) = ANY('{}'::record[])` or `false`. Keep a rollback point by tagging the version before merging; test with prepared statements and NULLs. In concurrent environments, always-false predicate may be optimized differently by the planner but is safe.

Ecosystem Topology