docs: move inspect and advisors into observability (#49503)

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Stack

Draft stack extracted from `docs/monitoring`. Merge bottom-up.
Troubleshooting / debugging-guide rewrite is out of scope.

1. **#49503** move inspect and advisors ← **this PR**
2. #49501 split Studio logs from ClickHouse queries
3. #49500 treat reports as signal dashboards
4. #49502 add Observe the data hub
5. #49506 add agent setup components
6. #49504 add hire-an-agent templates
7. #49505 restructure observability nav and overview

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update. First layer in the observability stack.

## What is the current behavior?

Inspect and advisors live under Database (`/guides/database/inspect`,
`/guides/database/database-advisors`). Observability readers have to
leave the monitoring section to find them.

## What is the new behavior?

- Moves inspect into `/guides/monitoring-and-debugging/inspect`
- Adds `/guides/monitoring-and-debugging/advisors` (replaces the
Database Advisors page)
- Adds redirects and updates Studio/docs links so old URLs keep working
- Adds both pages to the existing Monitoring nav so they are
discoverable before the later IA PR

## Additional context

Inspect and advisors pages render as standard MDX. Redirects cover
`/docs/guides/database/inspect`,
`/docs/guides/database/database-advisors`, and
`/docs/guides/database/database-linter`. Debugging-guide content is
unchanged except the inspect URL.

## Self-review

- No leftover `/guides/database/inspect` or
`/guides/database/database-advisors` links in docs guides or Studio
linter/AI surfaces (historical blog posts left as-is)
- Smoke test path updated to
`/docs/guides/monitoring-and-debugging/advisors`
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-a3cb5ece-925b-4046-b58a-5d69e9a9d794?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-a3cb5ece-925b-4046-b58a-5d69e9a9d794&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a centralized Advisors guide for security and performance
checks.
- Updated database inspection guidance with live Postgres statistics,
cache hit-rate context, and query-analysis resources.

- **Documentation**
- Reorganized Advisors and database inspection content under Monitoring
and Debugging.
- Updated navigation, cross-references, in-product help links, and CLI
documentation links.
- Added permanent redirects from previous documentation URLs to preserve
access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Saxon Fletcher <SaxonF@users.noreply.github.com>
Co-authored-by: Nik Richers <nik@validmind.ai>
This commit is contained in:
authored and GitHub committed 2026-09-04 13:38:36 +10:00
1 parent 8a41a74e36
commit 0bbd64743c
20 files changed
+103 -103

No files matched your search

@@ -93,17 +93,17 @@ flowchart TB
## Federated sources (inventory)
| Local path | Source repo | Ref / branch | Pattern |
| ---------------------------------------- | -------------------------------------- | ------------------------------ | ------------------------------------------------- |
| `/guides/graphql/*` | `supabase/pg_graphql` | `master` | Fully federated; `pageMap` per page |
| `/guides/ai/python/*` | `supabase/vecs` | `main` | Fully federated |
| `/guides/deployment/ci/*` | `supabase/setup-cli` | `gh-pages` | Fully federated |
| `/guides/deployment/terraform/*` | `supabase/terraform-provider-supabase` | branch in `terraformConstants` | Federated prose pages |
| `/guides/deployment/terraform/reference` | same | same | Federated **JSON schema** (not MDX) |
| `/guides/database/extensions/wrappers/*` | `supabase/wrappers` | **release tag** `docs_v*.*.*` | **Hybrid** — local MDX + federated catalog |
| `/guides/database/database-advisors` | `supabase/splinter` | `main` | **Dynamic listing** — all `docs/*.md` files |
| AI Skills index | `supabase/agent-skills` | `main` | Lists `skills/*/SKILL.md` at runtime |
| `$CodeSample` directive | various | commit SHA only | Snippets via `getGitHubFileContentsImmutableOnly` |
| Local path | Source repo | Ref / branch | Pattern |
| ------------------------------------------- | -------------------------------------- | ------------------------------ | ------------------------------------------------- |
| `/guides/graphql/*` | `supabase/pg_graphql` | `master` | Fully federated; `pageMap` per page |
| `/guides/ai/python/*` | `supabase/vecs` | `main` | Fully federated |
| `/guides/deployment/ci/*` | `supabase/setup-cli` | `gh-pages` | Fully federated |
| `/guides/deployment/terraform/*` | `supabase/terraform-provider-supabase` | branch in `terraformConstants` | Federated prose pages |
| `/guides/deployment/terraform/reference` | same | same | Federated **JSON schema** (not MDX) |
| `/guides/database/extensions/wrappers/*` | `supabase/wrappers` | **release tag** `docs_v*.*.*` | **Hybrid** — local MDX + federated catalog |
| `/guides/monitoring-and-debugging/advisors` | `supabase/splinter` | `main` | **Dynamic listing** — all `docs/*.md` files |
| AI Skills index | `supabase/agent-skills` | `main` | Lists `skills/*/SKILL.md` at runtime |
| `$CodeSample` directive | various | commit SHA only | Snippets via `getGitHubFileContentsImmutableOnly` |
### Related patterns (not quite "federated docs")
@@ -1,13 +0,0 @@
import { GuideTemplate } from '~/features/docs/GuidesMdx.template'
import { genGuideMeta, getGuidesMarkdown } from '~/features/docs/GuidesMdx.utils'
const DatabaseAdvisorDocs = async () => {
const data = await getGuidesMarkdown(['database', 'database-advisors'])
return <GuideTemplate {...data!} />
}
const generateMetadata = genGuideMeta(() => getGuidesMarkdown(['database', 'database-advisors']))
export default DatabaseAdvisorDocs
export { generateMetadata }
@@ -1161,7 +1161,7 @@ export const database: NavMenuConstant = {
},
{
name: 'Database Advisors',
url: '/guides/database/database-advisors' as `/${string}`,
url: '/guides/monitoring-and-debugging/advisors' as `/${string}`,
},
{ name: 'Testing your database', url: '/guides/database/testing' },
{
@@ -1179,8 +1179,8 @@ export const database: NavMenuConstant = {
url: '/guides/database/postgres/timeouts' as `/${string}`,
},
{
name: 'Debugging and monitoring',
url: '/guides/database/inspect' as `/${string}`,
name: 'Inspect the database',
url: '/guides/monitoring-and-debugging/inspect' as `/${string}`,
},
{
name: 'Debugging performance issues',
@@ -3097,6 +3097,14 @@ export const telemetry: NavMenuConstant = {
name: 'Tracing with the client SDKs',
url: '/guides/monitoring-and-debugging/client-side-tracing' as `/${string}`,
},
{
name: 'Inspect the database',
url: '/guides/monitoring-and-debugging/inspect' as `/${string}`,
},
{
name: 'Advisors',
url: '/guides/monitoring-and-debugging/advisors' as `/${string}`,
},
],
},
],
@@ -1,14 +0,0 @@
---
title: Performance and Security Advisors
subtitle: Check your database for performance and security issues
---
You can use the Database Performance and Security Advisors to check your database for issues such as missing indexes and improperly set-up RLS policies.
## Using the advisors
In the dashboard, navigate to [Security Advisor](/dashboard/project/_/database/security-advisor) and [Performance Advisor](dashboard/project/_/database/performance-advisor) under Database. The advisors run automatically. You can also manually rerun them after you've resolved issues.
## Available checks
<DatabaseAdvisorsIndex />
@@ -200,6 +200,6 @@ The most efficient way to reclaim disk space, without locks, is to use [pg_repac
## Related links
- [Safe Cascading Deletes](/docs/guides/database/postgres/cascade-deletes)
- [Inspecting your Database](/docs/guides/database/inspect)
- [Inspect the database](/docs/guides/monitoring-and-debugging/inspect)
- [Understanding Database and Disk Size](/docs/guides/platform/database-size)
- [Bloat in Postgres](/blog/postgres-bloat)
@@ -0,0 +1,22 @@
---
id: 'advisors'
title: 'Advisors'
description: 'Deterministic security and performance findings you or an agent can pull as part of ongoing observability.'
---
Advisors are programmatic checks that ship with the platform. They inspect the live schema and return deterministic findings, such as missing indexes or incorrectly configured RLS policies.
Use them as part of ongoing observability, together with [logs](/docs/guides/monitoring-and-debugging/advanced-log-filtering). A finding is not a fix. Confirm it against recent log evidence, then search [troubleshooting](/docs/guides/troubleshooting) for the check name or the object it names.
You or an agent can pull the same checks from:
- Studio: [Security Advisor](/dashboard/project/_/advisors/security) and [Performance Advisor](/dashboard/project/_/advisors/performance)
- MCP: `get_advisors`
- CLI: [`supabase db advisors`](/docs/reference/cli/supabase-db-advisors)
- Management API: [security advisors](/docs/reference/api/v1-get-security-advisors) and [performance advisors](/docs/reference/api/v1-get-performance-advisors)
The advisors run automatically in Studio. Rerun them after you resolve an issue.
## Available checks
<DatabaseAdvisorsIndex />
@@ -92,7 +92,7 @@ Debugging is complete only once you've re-run the failing operation, confirmed i
Each Supabase product has its own debugging resources. Use these as a starting point when the error originates in a specific service.
- [Database — Debugging and monitoring](/docs/guides/database/inspect)
- [Database — Inspect the database](/docs/guides/monitoring-and-debugging/inspect)
- [Auth — Error codes](/docs/guides/auth/debugging/error-codes)
- [Storage — Debugging](/docs/guides/storage/debugging/logs)
- [Edge Functions — Local debugging](/docs/guides/functions/debugging-tools)
@@ -1,25 +1,23 @@
---
title: 'Database debugging and monitoring'
description: 'Inspecting your Postgres database for common issues around disk, query performance, index, locks, and more using the terminal.'
id: 'inspect'
title: 'Inspect the database'
description: 'Read live Postgres statistics such as bloat, cache hit rate, locks, and slow queries from the CLI, SQL Editor, or MCP.'
---
Database performance is a large topic and many factors can contribute. Some of the most common causes of poor performance include:
Database performance is a large topic and many factors can contribute. Common causes of poor performance include inefficient schemas or queries, missing or unused indexes, insufficient memory, lock contention, and table bloat.
- An inefficiently designed schema
- Inefficiently designed queries
- A lack of indexes causing slower than required queries over large tables
- Unused indexes causing slow `INSERT`, `UPDATE` and `DELETE` operations
- Not enough compute resources, such as memory, causing your database to go to disk for results too often
- Lock contention from multiple queries operating on heavily used tables
- Large amount of bloat on your tables causing poor query planning
Use the live Postgres statistics in this guide to check for those conditions. The same checks run as `supabase inspect db` commands, as SQL in the [SQL Editor](/dashboard/project/_/sql), or as MCP `execute_sql`.
You can examine your database and queries for these issues using either the [Supabase CLI](/docs/guides/local-development/cli/getting-started) or SQL.
Use this page to:
- Run [CLI inspection commands](#using-the-cli)
- Copy the matching [SQL](#using-sql)
If you are checking whether something is wrong, start with the [debugging guide](/docs/guides/monitoring-and-debugging/debugging). For project logs and metrics, see the [Monitoring and Debugging overview](/docs/guides/monitoring-and-debugging).
## Using the CLI
The Supabase CLI comes with a range of tools to help inspect your Postgres instances for potential issues. The CLI gets the information from <a href="https://www.postgresql.org/docs/current/internals.html" target="_blank">Postgres internals</a>. Therefore, most tools provided are compatible with any Postgres databases regardless if they are a Supabase project or not.
You can find installation instructions for the Supabase CLI <a href="/docs/guides/local-development" target="_blank">here</a>.
The [Supabase CLI](/docs/guides/local-development/cli/getting-started) reads live statistics from [Postgres internals](https://www.postgresql.org/docs/current/internals.html). Most commands work on any Postgres database, not only a Supabase project.
### The `inspect db` command
@@ -58,7 +56,7 @@ Working with Supabase, you can link the Supabase CLI with your project:
supabase link --project-ref <project-id>
```
Then the CLI will automatically connect to your Supabase project whenever you are in the project folder and you no longer need to provide `—db-url`.
Then the CLI will automatically connect to your Supabase project whenever you are in the project folder and you no longer need to provide `--db-url`.
### Inspection commands
@@ -108,7 +106,7 @@ Following commands require `pg_stat_statements` to be enabled: calls, locks, cac
When using `pg_stat_statements` also take note that it only stores the latest 5,000 statements. Moreover, consider resetting the analysis after optimizing any queries by running `select pg_stat_statements_reset();`
Learn more about pg_stats [here](/docs/guides/database/extensions/pg_stat_statements).
Learn more about [`pg_stat_statements`](/docs/guides/database/extensions/pg_stat_statements).
## Using SQL
@@ -124,7 +122,7 @@ $ grant pg_read_all_stats to postgres;
### Postgres cumulative statistics system
Postgres collects data about its own operations using the [cumulative statistics system](https://www.postgresql.org/docs/current/monitoring-stats.html). In addition to this, every Supabase project has the [pg_stat_statements extension](/docs/guides/database/extensions/pg_stat_statements) enabled by default. This extension records query execution performance details and is the best way to find inefficient queries. This information can be combined with the Postgres query plan analyzer to develop more efficient queries.
Postgres collects data about its own operations using the [cumulative statistics system](https://www.postgresql.org/docs/current/monitoring-stats.html). In addition to this, every Supabase project has the [pg_stat_statements extension](/docs/guides/database/extensions/pg_stat_statements) enabled by default. This extension records query execution performance details.
Here are some example queries to get you started.
@@ -238,28 +236,8 @@ select
from pg_statio_user_tables;
```
This shows the ratio of data blocks fetched from the Postgres [shared_buffers](https://www.postgresql.org/docs/15/runtime-config-resource.html#RUNTIME-CONFIG-RESOURCE-MEMORY) cache against the data blocks that were read from disk/OS cache.
This shows the ratio of data blocks fetched from the Postgres [shared_buffers](https://www.postgresql.org/docs/15/runtime-config-resource.html#RUNTIME-CONFIG-RESOURCE-MEMORY) cache against the data blocks that were read from disk or the OS cache.
If either of your index or table hit rate are < 99% then this can indicate your compute plan is too small for your current workload and you would benefit from more memory. [Upgrading your compute](/docs/guides/platform/compute-and-disk#compute) can be done from your [project dashboard](/dashboard/project/_/settings/infrastructure).
A ratio below 99% means more than 1% of observed block accesses missed `shared_buffers`. Postgres cannot distinguish whether those reads were served by the operating system cache or physical disk. Treat that as a performance signal in the [debugging guide](/docs/guides/monitoring-and-debugging/debugging), then search [troubleshooting](/docs/guides/troubleshooting).
### Optimizing poor performing queries
Postgres has built in tooling to help you optimize poorly performing queries. You can use the [query plan analyzer](https://www.postgresql.org/docs/current/sql-explain.html) on any expensive queries that you have identified:
```sql
explain analyze <query-statement-here>;
```
When you include `analyze` in the explain statement, the database attempts to execute the query and provides a detailed query plan along with actual execution times. So, be careful using `explain analyze` with `insert`/`update`/`delete` queries, because the query will run, and could have unintended side-effects.
If you run `explain` without the `analyze` keyword, the database will only perform query planning without executing the query. This approach can be beneficial when you want to inspect the query plan without affecting the database or if you encounter timeouts in your queries.
Using the query plan analyzer to optimize your queries is a large topic, with a number of online resources available:
- [Official docs.](https://www.postgresql.org/docs/current/using-explain.html)
{/* supa-mdx-lint-disable-next-line Rule004ExcludeWords */}
- [The Art of PostgreSQL.](https://theartofpostgresql.com/explain-plan-visualizer/)
- [Postgres Wiki.](https://wiki.postgresql.org/wiki/Using_EXPLAIN)
- [Enterprise DB.](https://www.enterprisedb.com/blog/postgresql-query-optimization-performance-tuning-with-explain-analyze)
You can pair the information available from `pg_stat_statements` with the detailed system metrics available [via your metrics endpoint](../telemetry/metrics) to better understand the behavior of your DB and the queries you're executing against it.
When a check names a slow statement, get a query plan with [`explain`](/docs/guides/database/query-optimization#analyze-the-query-plan) in SQL, or [`explain()`](/docs/guides/database/debugging-performance) on the Data API. Pair `pg_stat_statements` with the [Metrics API](/docs/guides/monitoring-and-debugging/metrics) to read the same window from Postgres stats and host metrics.
@@ -8,7 +8,7 @@ The Supabase platform automatically optimizes your Postgres database to take adv
## Examining query performance
Unoptimized queries are a major cause of poor database performance. To analyze the performance of your queries, see the [Debugging and monitoring guide](/docs/guides/database/inspect).
Unoptimized queries are a major cause of poor database performance. To analyze the performance of your queries, see [Inspect the database](/docs/guides/monitoring-and-debugging/inspect).
## Optimizing the number of connections
@@ -239,7 +239,7 @@ height={625}
| Check logs | Investigate replication errors or performance issues in your project dashboard | [Realtime Logs Dashboard](/dashboard/project/_/database/realtime-logs) |
| Monitor database | Review database resource utilization, connection counts, and query performance that may affect replication | [Database Observability Dashboard](/dashboard/project/_/observability/database) |
| Review replication metrics | Use `pg_stat_subscription`, `pg_replication_slots`, and other Postgres views to diagnose replication issues | [manual replication monitoring guide](/docs/guides/database/replication/manual-replication-monitoring) |
| Debug database issues | Use CLI inspection tools to identify bloat, lock contention, and long-running queries affecting replication | [Database Inspection Tools Guide](/docs/guides/database/inspect) |
| Debug database issues | Use CLI inspection tools to identify bloat, lock contention, and long-running queries affecting replication | [Inspect the database](/docs/guides/monitoring-and-debugging/inspect) |
| Optimize performance | Optimize query performance and connection management to reduce database load | [Performance Tuning Guide](/docs/guides/platform/performance) |
| Configure timeouts | Configure statement timeouts to prevent long-running transactions from blocking replication | [Database Timeouts Guide](/docs/guides/database/postgres/timeouts) |
| Learn broadcast from DB | Understand how broadcast from database works and best practices for implementation | [Broadcast from Database Guide](/docs/guides/realtime/broadcast#trigger-broadcast-messages-from-your-database) |
@@ -22,7 +22,7 @@ The cache in Postgres is important because the database will store frequently ac
Most data in a database is idle, but in cases where there is little available memory or uncached data is rapidly accessed, [thrashing](<https://en.wikipedia.org/wiki/Thrashing_(computer_science)>) can occur.
Ideally, you want queries to hit the cache 99% of the time. You can use the [Supabase CLI](/docs/guides/database/inspect) `inspect db cache hit` command to check your cache hit rate. Alternatively, you can run the [query](https://github.com/supabase/cli/blob/c9cce58025fded16b4c332747f819a44f45c3b83/internal/inspect/bloat/bloat.go#L17) found in the CLI's GitHub repo in the [SQL Editor](/dashboard/project/_/sql/)
Ideally, you want queries to hit the cache 99% of the time. You can use the [Supabase CLI](/docs/guides/monitoring-and-debugging/inspect) `inspect db cache hit` command to check your cache hit rate. Alternatively, you can run the [query](https://github.com/supabase/cli/blob/c9cce58025fded16b4c332747f819a44f45c3b83/internal/inspect/bloat/bloat.go#L17) found in the CLI's GitHub repo in the [SQL Editor](/dashboard/project/_/sql/)
```sh
# login to the CLI
+10
View File
@@ -187,6 +187,16 @@ const nextConfig = {
destination: '/guides/database/replication/pipelines-faq',
permanent: true,
},
{
source: '/guides/database/inspect',
destination: '/guides/monitoring-and-debugging/inspect',
permanent: true,
},
{
source: '/guides/database/database-advisors',
destination: '/guides/monitoring-and-debugging/advisors',
permanent: true,
},
]
},
typescript: {
+1 -1
View File
@@ -140,7 +140,7 @@ export async function fetchCliLibReferenceSource() {
export async function fetchLintWarningsGuideSources() {
return new LintWarningsGuideLoader(
'guide',
'/guides/database/database-advisors',
'/guides/monitoring-and-debugging/advisors',
'supabase',
'splinter',
'main',
@@ -202,9 +202,10 @@ export const lintInfoMap: LintInfo[] = [
name: 'materialized_view_in_api',
title: 'Materialized View in API',
icon: <Eye className="text-foreground-muted" size={15} strokeWidth={1.5} />,
link: () => `${DOCS_URL}/guides/database/database-advisors?lint=0016_materialized_view_in_api`,
link: () =>
`${DOCS_URL}/guides/monitoring-and-debugging/advisors?lint=0016_materialized_view_in_api`,
linkText: 'View docs',
docsLink: `${DOCS_URL}/guides/database/database-advisors?lint=0016_materialized_view_in_api`,
docsLink: `${DOCS_URL}/guides/monitoring-and-debugging/advisors?lint=0016_materialized_view_in_api`,
category: 'security',
},
{
@@ -221,9 +222,9 @@ export const lintInfoMap: LintInfo[] = [
title: 'Unsupported reg types',
icon: <Table2 className="text-foreground-muted" size={15} strokeWidth={1.5} />,
link: () =>
`${DOCS_URL}/guides/database/database-advisors?lint=0018_unsupported_reg_types&queryGroups=lint`,
`${DOCS_URL}/guides/monitoring-and-debugging/advisors?lint=0018_unsupported_reg_types&queryGroups=lint`,
linkText: 'View docs',
docsLink: `${DOCS_URL}/guides/database/database-advisors?lint=0018_unsupported_reg_types&queryGroups=lint`,
docsLink: `${DOCS_URL}/guides/monitoring-and-debugging/advisors?lint=0018_unsupported_reg_types&queryGroups=lint`,
category: 'security',
},
{
@@ -87,7 +87,7 @@ export const LinterPageFooter = ({
<Markdown
className="text-xs"
content={`The Supabase CLI comes with a range of tools to help inspect your Postgres instances for
potential issues. [Learn more here](${DOCS_URL}/guides/database/inspect).`}
potential issues. [Learn more here](${DOCS_URL}/guides/monitoring-and-debugging/inspect).`}
/>
</div>
)}
@@ -297,7 +297,7 @@ export const WithStatements = ({
<Markdown
className="text-xs"
content={`The Supabase CLI comes with a range of tools to help inspect your Postgres instances for
potential issues. [Learn more here](${DOCS_URL}/guides/database/inspect).`}
potential issues. [Learn more here](${DOCS_URL}/guides/monitoring-and-debugging/inspect).`}
/>
</div>
</div>
+2 -2
View File
@@ -371,11 +371,11 @@ export const PG_BEST_PRACTICES = `
- After creating a table, check and configure Data API access and RLS before use (see the "Exposing a Table to the Data API" section in RLS knowledge for the full workflow).
- Define foreign key references within the \`CREATE TABLE\` statement.
- Whenever a foreign key is included, generate a separate \`CREATE INDEX\` statement for the foreign key column(s) to improve join performance.
- **Foreign Tables:** Place foreign tables in a schema named \`private\` (create the schema if needed). Explain the security risk (RLS bypass) and include a link: https://supabase.com/docs/guides/database/database-advisors?queryGroups=lint&lint=0017_foreign_table_in_api.
- **Foreign Tables:** Place foreign tables in a schema named \`private\` (create the schema if needed). Explain the security risk (RLS bypass) and include a link: https://supabase.com/docs/guides/monitoring-and-debugging/advisors?queryGroups=lint&lint=0017_foreign_table_in_api.
### Views
- Add \`with (security_invoker=on)\` immediately after \`CREATE VIEW view_name\`.
- **Materialized Views:** Store materialized views in the \`private\` schema (create if needed). Explain the security risk (RLS bypass) and reference: https://supabase.com/docs/guides/database/database-advisors?queryGroups=lint&lint=0016_materialized_view_in_api.
- **Materialized Views:** Store materialized views in the \`private\` schema (create if needed). Explain the security risk (RLS bypass) and reference: https://supabase.com/docs/guides/monitoring-and-debugging/advisors?queryGroups=lint&lint=0016_materialized_view_in_api.
### Extensions
- Always install extensions in the \`extensions\` schema or a dedicated schema; never in \`public\`.
+2 -2
View File
@@ -92,7 +92,7 @@ const MOCK_ADVISORIES_DATA = [
category: 'security',
message: 'Materialized views in API schema can bypass RLS. Move them to private schema.',
remediationUrl:
'https://supabase.com/docs/guides/database/database-advisors?queryGroups=lint&lint=0016_materialized_view_in_api',
'https://supabase.com/docs/guides/monitoring-and-debugging/advisors?queryGroups=lint&lint=0016_materialized_view_in_api',
},
{
id: '0031_functions_no_rls_guard',
@@ -100,7 +100,7 @@ const MOCK_ADVISORIES_DATA = [
category: 'security',
message: 'Function api.health_check should verify auth context before querying tables.',
remediationUrl:
'https://supabase.com/docs/guides/database/database-advisors?queryGroups=lint&lint=0031_functions_no_rls_guard',
'https://supabase.com/docs/guides/monitoring-and-debugging/advisors?queryGroups=lint&lint=0031_functions_no_rls_guard',
},
{
id: '1012_slow_query',
+11 -1
View File
@@ -2756,10 +2756,20 @@ module.exports = [
source: '/docs/guides/database/sql-to-api',
destination: '/docs/guides/api/sql-to-api',
},
{
permanent: true,
source: '/docs/guides/database/inspect',
destination: '/docs/guides/monitoring-and-debugging/inspect',
},
{
permanent: true,
source: '/docs/guides/database/database-linter',
destination: '/docs/guides/database/database-advisors',
destination: '/docs/guides/monitoring-and-debugging/advisors',
},
{
permanent: true,
source: '/docs/guides/database/database-advisors',
destination: '/docs/guides/monitoring-and-debugging/advisors',
},
{
permanent: true,
+3 -5
View File
@@ -25,15 +25,13 @@ test.describe('docs dev runs locally without credentials', () => {
expect(errors.some((message) => SUPABASE_URL_ERROR.test(message))).toBeFalsy()
})
test('database-advisors page renders (full content or graceful fallback, never a crash)', async ({
test('advisors page renders (full content or graceful fallback, never a crash)', async ({
page,
}) => {
const response = await page.goto('/docs/guides/database/database-advisors')
const response = await page.goto('/docs/guides/monitoring-and-debugging/advisors')
expect(response?.ok(), `expected 200, got ${response?.status()}`).toBeTruthy()
await expect(
page.getByRole('heading', { name: 'Performance and Security Advisors' })
).toBeVisible()
await expect(page.getByRole('heading', { name: 'Advisors' })).toBeVisible()
})
test('a troubleshooting article page renders without Supabase credentials', async ({ page }) => {