Repository navigation
fix(catalog): allow non-alphanumeric characters in product SKU validation - #708
Merged
navneetkumar-pim-webkul merged 5 commits intoSep 15, 2026
Conversation
Pint ordered_imports fixer flagged import order.
Copilot started reviewing on behalf of
navneetkumar-pim-webkul
September 15, 2026 14:10
View session
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved validation consistency, import handling, performance, and wildcard-search issues remain.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Relaxes SKU validation to allow non-alphanumeric characters while retaining length, whitespace, and CSV-delimiter safeguards.
Changes:
- Updates core SKU rules and tests.
- Revises import and create-form validation.
- Updates localized messages and changelog documentation.
File summaries
| File | Summary |
|---|---|
packages/Webkul/Core/tests/Unit/Rules/SkuTest.php |
Updates SKU validation coverage. |
packages/Webkul/Core/src/Rules/Sku.php |
Relaxes validation; LIKE wildcard escaping and variant validation gaps remain. |
packages/Webkul/Core/src/Resources/lang/zh_TW/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/zh_CN/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/vi_VN/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/uk_UA/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/tr_TR/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/tl_PH/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/sv_SE/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/ru_RU/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/ro_RO/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/pt_PT/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/pt_BR/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/pl_PL/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/no_NO/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/nl_NL/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/mn_MN/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/ko_KR/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/ja_JP/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/it_IT/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/id_ID/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/hr_HR/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/hi_IN/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/fr_FR/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/fi_FI/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/es_VE/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/es_ES/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/en_US/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/en_NZ/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/en_GB/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/en_AU/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/de_DE/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/da_DK/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/ca_ES/validation.php |
Updates localized validation messages. |
packages/Webkul/Core/src/Resources/lang/ar_AE/validation.php |
Updates localized validation messages. |
packages/Webkul/AiAgent/tests/Unit/Tools/ImportProductsValidationTest.php |
Updates import validation tests. |
packages/Webkul/AiAgent/src/Chat/Tools/ImportProducts.php |
Reuses core validation; raw padding checks and per-row validation overhead remain. |
packages/Webkul/Admin/src/Resources/views/catalog/products/index.blade.php |
Relaxes client validation, but no longer blocks invalid padded, delimited, or oversized values. |
CHANGELOG.md |
Documents the SKU validation change. |
Review details
Suppressed comments (3)
packages/Webkul/AiAgent/src/Chat/Tools/ImportProducts.php:434
- This constructs a full Laravel validator for every row.
handle()calls this method inside its per-row loop with a 100,000-row cap, and the queued DataTransfer importer validatesskuagain with the sameSkurule, replacing the previous cheap regex prefilter with up to 100,000 validator allocations plus duplicate work. Please batch the validation or expose a reusable predicate so the Core rule remains the source of truth without this per-row overhead.
return ! validator(['sku' => $sku], ['sku' => ['required', new Sku]])->fails();
packages/Webkul/Core/src/Rules/Sku.php:17
- Allowing
%here also makes it possible to store SKUs that the existing database search paths cannot search literally:ProductRepository::queryBuilderFromDatabase()andDatabase/SkuOrUniversalFilterbuildLIKE '%'.$value.'%'without escaping SQL wildcard characters. A search for a%SKU can therefore match unrelated products; escape LIKE metacharacters at those query boundaries and add a regression test.
packages/Webkul/Core/src/Rules/Sku.php:30 - The new delimiter/whitespace invariant is not enforced for API variant SKUs.
ConfigurableProductController::normalizeVariantsPayload()only requiresvariants.*.skuto be a string, thencreateVariant()persists it directly, so comma/semicolon or padded variant SKUs bypass this rule. ApplySkuto that variant validation path as well.
- Files reviewed: 39/39 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…KUs, restore client checks - Escape %, _, and backslash in SKU search LIKE clauses (ProductRepository, SkuOrUniversalFilter) so a SKU containing wildcard chars can't widen matches - Apply the Sku rule to variants.*.sku in ConfigurableProductController, closing the bypass on comma/semicolon/padded variant SKUs - Restore client-side max:255 + whitespace/delimiter regex on the create-form SKU field, matching the relaxed server contract instead of just `required` - Validate the raw (untrimmed) SKU cell in ImportProducts so padded values are rejected instead of silently normalized before the check - Invoke the Sku rule directly in ImportProducts::validateSku() instead of building a full Validator per row (up to 100k rows), keeping required-check parity
QueryString::escapeValue() already backslash-escapes Lucene-special characters (including hyphen) for the search-index paths. The prior LIKE-safety fix re-escaped that existing backslash, turning e.g. upd\-abc123 into upd\\-abc123 in the LIKE pattern — a literal backslash that never matches the real value, breaking datagrid search for any SKU containing a hyphen. Only % and _ need escaping here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixed the SKU field rejecting valid values containing characters other than letters, numbers, hyphens, and underscores (such as
%); a SKU is now only rejected for being blank, over 255 characters, padded with leading/trailing spaces, or containing a comma or semicolon (which break CSV import/export), both on the server and in the create-product form.