Skip to content

fix(catalog): allow non-alphanumeric characters in product SKU validation - #708

Merged
navneetkumar-pim-webkul merged 5 commits into
unopim:3.xfrom
vipinkutthi-webkul:fix/sku-rule-notblank-length
Sep 15, 2026
Merged

navneetkumar-pim-webkul merged 5 commits into
unopim:3.xfrom
vipinkutthi-webkul:fix/sku-rule-notblank-length

Conversation

@vipinkutthi-webkul

Copy link
Copy Markdown
Contributor

Fixed the SKU field rejecting valid values containing characters other than letters, numbers, hyphens, and underscores (such as %); a SKU is now only rejected for being blank, over 255 characters, padded with leading/trailing spaces, or containing a comma or semicolon (which break CSV import/export), both on the server and in the create-product form.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved validation consistency, import handling, performance, and wildcard-search issues remain.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Relaxes SKU validation to allow non-alphanumeric characters while retaining length, whitespace, and CSV-delimiter safeguards.

Changes:

  • Updates core SKU rules and tests.
  • Revises import and create-form validation.
  • Updates localized messages and changelog documentation.
File summaries
File Summary
packages/Webkul/Core/tests/Unit/Rules/SkuTest.php Updates SKU validation coverage.
packages/Webkul/Core/src/Rules/Sku.php Relaxes validation; LIKE wildcard escaping and variant validation gaps remain.
packages/Webkul/Core/src/Resources/lang/zh_TW/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/zh_CN/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/vi_VN/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/uk_UA/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/tr_TR/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/tl_PH/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/sv_SE/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/ru_RU/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/ro_RO/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/pt_PT/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/pt_BR/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/pl_PL/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/no_NO/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/nl_NL/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/mn_MN/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/ko_KR/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/ja_JP/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/it_IT/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/id_ID/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/hr_HR/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/hi_IN/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/fr_FR/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/fi_FI/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/es_VE/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/es_ES/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/en_US/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/en_NZ/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/en_GB/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/en_AU/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/de_DE/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/da_DK/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/ca_ES/validation.php Updates localized validation messages.
packages/Webkul/Core/src/Resources/lang/ar_AE/validation.php Updates localized validation messages.
packages/Webkul/AiAgent/tests/Unit/Tools/ImportProductsValidationTest.php Updates import validation tests.
packages/Webkul/AiAgent/src/Chat/Tools/ImportProducts.php Reuses core validation; raw padding checks and per-row validation overhead remain.
packages/Webkul/Admin/src/Resources/views/catalog/products/index.blade.php Relaxes client validation, but no longer blocks invalid padded, delimited, or oversized values.
CHANGELOG.md Documents the SKU validation change.
Review details

Suppressed comments (3)

packages/Webkul/AiAgent/src/Chat/Tools/ImportProducts.php:434

  • This constructs a full Laravel validator for every row. handle() calls this method inside its per-row loop with a 100,000-row cap, and the queued DataTransfer importer validates sku again with the same Sku rule, replacing the previous cheap regex prefilter with up to 100,000 validator allocations plus duplicate work. Please batch the validation or expose a reusable predicate so the Core rule remains the source of truth without this per-row overhead.
        return ! validator(['sku' => $sku], ['sku' => ['required', new Sku]])->fails();

packages/Webkul/Core/src/Rules/Sku.php:17

  • Allowing % here also makes it possible to store SKUs that the existing database search paths cannot search literally: ProductRepository::queryBuilderFromDatabase() and Database/SkuOrUniversalFilter build LIKE '%'.$value.'%' without escaping SQL wildcard characters. A search for a % SKU can therefore match unrelated products; escape LIKE metacharacters at those query boundaries and add a regression test.
    packages/Webkul/Core/src/Rules/Sku.php:30
  • The new delimiter/whitespace invariant is not enforced for API variant SKUs. ConfigurableProductController::normalizeVariantsPayload() only requires variants.*.sku to be a string, then createVariant() persists it directly, so comma/semicolon or padded variant SKUs bypass this rule. Apply Sku to that variant validation path as well.
  • Files reviewed: 39/39 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/Webkul/Admin/src/Resources/views/catalog/products/index.blade.php Outdated
Comment thread packages/Webkul/AiAgent/src/Chat/Tools/ImportProducts.php Outdated
…KUs, restore client checks

- Escape %, _, and backslash in SKU search LIKE clauses (ProductRepository,
  SkuOrUniversalFilter) so a SKU containing wildcard chars can't widen matches
- Apply the Sku rule to variants.*.sku in ConfigurableProductController,
  closing the bypass on comma/semicolon/padded variant SKUs
- Restore client-side max:255 + whitespace/delimiter regex on the create-form
  SKU field, matching the relaxed server contract instead of just `required`
- Validate the raw (untrimmed) SKU cell in ImportProducts so padded values
  are rejected instead of silently normalized before the check
- Invoke the Sku rule directly in ImportProducts::validateSku() instead of
  building a full Validator per row (up to 100k rows), keeping required-check
  parity
QueryString::escapeValue() already backslash-escapes Lucene-special
characters (including hyphen) for the search-index paths. The prior
LIKE-safety fix re-escaped that existing backslash, turning e.g.
upd\-abc123 into upd\\-abc123 in the LIKE pattern — a literal backslash
that never matches the real value, breaking datagrid search for any
SKU containing a hyphen. Only % and _ need escaping here.
@navneetkumar-pim-webkul
navneetkumar-pim-webkul merged commit a604a30 into unopim:3.x Sep 15, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants