mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 19:05:06 +03:00
alaister/tanstack-start
19540
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
59f7ce8db4 |
chore(studio): drop redundant next/constants stub — superseded by the @sentry/nextjs compat alias
The stub's only real-world importer was @sentry/nextjs's isBuild.js, which the @sentry/nextjs -> compat/sentry-nextjs.ts alias (already on master via #47657) removes from the browser graph entirely. Dropping it brings this branch to a zero diff against master. |
||
|
|
5d000c9e43 |
Merge remote-tracking branch 'origin/master' into alaister/tanstack-start
# Conflicts: # apps/studio/vite.config.ts |
||
|
|
9858562b8b |
fix(telemetry): dedupe funnel toast error events (#47802)
## Summary Since #47293, an API failure on a signup / org-creation / project-creation form emitted `dashboard_error_created` twice: `useTrackFunnelError` fired the origin-tagged event and the global `ToastErrorTracker` independently fired the legacy untagged `source:'toast'` event for the same toast, each behind its own 10% sampling draw. I verified the twin rate empirically at 8-11% of origin-tagged funnel toasts, exactly the floor for two independent 10% draws, meaning the twin co-fires for effectively every funnel error ([Hex thread](https://app.hex.tech/supabase/thread/019f3bc1-3a5c-7200-9122-8e3439bfbe8c)). Any consumer counting funnel errors without an `origin IS NOT NULL` filter saw ~2x inflation. The fix makes `ToastErrorTracker` the sole emitter of `source:'toast'` events, so the duplicate is unrepresentable rather than suppressed. Funnel call sites pass the id returned by `toast.error()` into `trackFunnelError`, which registers the funnel properties against that toast id instead of firing its own event – the tracker then emits a single `dashboard_error_created` enriched with `origin` / `errorCategory` / `errorReason` / `errorCode` for registered toasts, and the plain untagged event otherwise. The `'toast'` overload of `trackFunnelError` requires the toast id, so a missed pairing is a compile error rather than a silent double count. Registration is unconditional and there's only one sampling draw, so suppression can't lose a sampling race. `'form'`-sourced funnel events are unchanged. ## Changes - `lib/toast-errors.tsx`: toast-id → funnel-properties registry (`registerFunnelErrorToast`); `ToastErrorTracker` emits one (optionally enriched) event per error toast under a single 10% draw, deleting entries once consumed - `lib/telemetry/use-track-funnel-error.ts`: overloaded signature – `'toast'` requires the id returned by `toast.error()` (type-enforced), `'form'` keeps direct emission with its own sampling - Update the 7 funnel `toast.error` call sites in `NewOrgForm`, `SignUpForm`, and `pages/new/[slug]` to pass the toast id - Component tests for the tracker (previously uncovered), including an end-to-end test through `useTrackFunnelError` - Code hygiene (also flagged by CodeRabbit): all four `dashboard_error_created` emitters (toast, form, `AlertError`, `ErrorMatcher`) independently encoded the 10% draw – downstream analysis assumes a uniform sampling multiplier across sources, so one site drifting would silently skew comparisons. The rate and the draw now live in one place (`isDashboardErrorSampled()` in `lib/telemetry/error-sampling.ts`). No behavior change. - Mount `ToastErrorTracker` in the TanStack root (`routes/__root.tsx`), mirroring `pages/_app.tsx`. The TanStack tree mounted `Toaster` but never the tracker, so untagged toast error telemetry has never fired in that flavour – and with the tracker now the sole emitter, the missing mount would have silently dropped funnel toast events there too. Side effect once the TanStack flavour ships: untagged `source:'toast'` volume from it goes from zero to normal. ## Testing Component-tested (`apps/studio/lib/toast-errors.test.tsx`): - [x] Unregistered error toast fires exactly one untagged `dashboard_error_created {source:'toast'}` - [x] Registered funnel toast fires exactly one event, enriched with `origin`/`errorCategory`/`errorReason`/`errorCode` - [x] `useTrackFunnelError` with a toast id routes through the tracker as a single enriched event - [x] Non-error toasts ignored; the 10% sampling gate still applies Full Studio unit suite passes (392 files / 4371 tests), plus typecheck and lint. Also verified end-to-end in a local browser (TanStack flavour, sample rate temporarily forced to 1): a failed signup produced exactly one `dashboard_error_created` with `{source:'toast', origin:'signup', errorCategory:'api', errorReason:'email_already_registered', errorCode:403}` and no untagged twin (two independent trials); an unregistered error toast produced exactly one plain `{source:'toast'}`; a client-side validation failure produced exactly one `{source:'form', origin:'signup', errorCategory:'validation', errorReason:'email_invalid'}`; success toasts produced nothing. Post-deploy I'll re-run the twin-rate query from the Hex thread; the untagged-twin rate on funnel pages should decay to ~0 as stale bundles reload over 2-3 days. ## Notes - Origin-tagged funnel toast events now ride the tracker's single 10% draw instead of their own independent draw – statistically identical volume, but the event fires on the tracker's next effect rather than synchronously at the call site (irrelevant for PostHog) - Registration must happen in the same synchronous block as `toast.error()` (documented on the `TrackFunnelError` type) – all current call sites comply - The invalid Postgres version toast in `pages/new/[slug].tsx` (~line 416) needs no special-casing: unregistered toasts keep the plain untagged event, so its telemetry is preserved - Heads-up for `dashboard_error_created` consumers: overall untagged `source:'toast'` volume will dip slightly after this deploys, since funnel-page twins disappear. A volume monitor seeing that drop is this fix landing, not a tracking regression (same class as the intended GROWTH-893 sampling-unification drop). ## Linear - fixes GROWTH-965 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enhanced error telemetry for organization creation, sign-up, payment, and project-creation flows by associating failures with toast identifiers and enriched funnel context. * Standardized dashboard error sampling logic across error handling components for consistency. * **Tests** * Added comprehensive test coverage for toast error tracking, including funnel registration, deduplication, filtering, and sampling behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
59a82c52f8 |
Fix: improve accessibility for icon button (SQL Editor menu) (#47674)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (accessibility improvement) ## What is the current behavior? Icon-only button (not visible on widescreen displays) does not have explicit accessible name for screen readers and tooltip. ## What is the new behavior? The icon-only button now has explicit accessible name using visually hidden text (sr-only), ensuring proper screen reader support. ## Additional context Tooltip text is added for visual users. No visual changes were introduced <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Added a tooltip to the SQL editor’s “More actions” dropdown button, improving discoverability. * The tooltip now shows “More actions” when hovering over the trigger. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
f55cb25b9b | docs(auth): add a section about user invites (#47774) | ||
|
|
ad181489b1 |
feat(studio): adopt @sentry/tanstackstart-react server instrumentation on the TanStack build (#47724)
Stacked on #47666 (base `alaister/tanstack-sentry-init`; retarget to `master` when that merges). **Supersedes #47721** (the manual `@sentry/node` wrapper). Client stays on #47666's `@sentry/react` setup. Adopts the official `@sentry/tanstackstart-react` SDK **on the server only**, after a spike (#47723) evaluating the full unified client+server SDK. The spike found the SDK's **browser** `tanstackRouterBrowserTracingIntegration` is a broken no-op stub at 10.59.0/10.64.0 — so the client stays on `@sentry/react` (whose equivalent integration is a real, working implementation, already shipped in #47666). The **server** exports, however, are a clear upgrade and slot in cleanly. ### What this adds (server-side, TanStack build only) - **`instrument.server.mjs`** — `Sentry.init` from `@sentry/tanstackstart-react`, mirroring `sentry.server.config.ts` + `release: VERCEL_GIT_COMMIT_SHA`. - **`start.ts`** — `sentryGlobalRequestMiddleware` + `sentryGlobalFunctionMiddleware` at the front of the existing `createStart(...)` middleware. **This is the win**: it captures request- and server-function errors *including the ones swallowed into 500s* — the exact class the manual wrapper (and the Next server SDK) miss. - **`api/server.js` / `scripts/serve.js`** — gated (`STUDIO_FRAMEWORK==='tanstack'`) instrument init + `wrapFetchWithSentry` on the handler. - **`vite.config.ts`** — `sentryTanstackStart({ …, autoInstrumentMiddleware: false })` as the last plugin: source-map upload + release injection (skips gracefully without an auth token). Middleware is wired explicitly rather than via the plugin's string-rewrite. ### Guarantees - **Client untouched** — the `@sentry/nextjs`→`@sentry/react` alias and #47666's client init are unchanged. - **Next untouched** — `instrumentation.ts` / `sentry.server.config.ts` etc. stay as-is; all new code is TanStack-gated. - **No server SDK in the client bundle** — verified after build: no `@sentry/node` / server middleware / `wrapFetchWithSentry` in `dist/client/assets` (`start.ts`'s server import is tree-shaken out). ### Verified TanStack build exit 0 (past `assertNoChunkCycles`), post-build server boot served `/api/get-utc-time → 200`, `tsc --noEmit` clean, prettier/eslint clean. Node smoke: no-DSN init is a clean no-op; wrapped handler returns 200. ### To test (deploy with a server DSN) Throw a server error from an `/api/*` route (or a `/_serverFn/*`) — including one that gets turned into a 500 without rethrowing — and confirm a server event in Sentry with `release` = the deploy SHA. Compared to #47721, the swallowed-500 case should now be captured via the middleware. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Sentry integration for the Studio app’s TanStack Start runtime, including request and server-function instrumentation. * Wrapped server request handling to capture errors reliably, with tracing enabled. * Updated build tooling to conditionally upload source maps when credentials are present. * **Bug Fixes** * Improved resilience by safely falling back to a no-op Sentry setup if instrumentation cannot be loaded. * Ensured existing request protection remains enabled while adding observability middleware. * **Chores / Config** * Added `SKIP_ASSET_UPLOAD` to the build environment list to control cache/build behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
dc23320e43 |
Add sentry capture exception to apiWrapper (#47804)
## Context As per PR title - also adjusts the imports for files consuming `apiWrapper` to remove the default export for `apiWrapper` Have tested locally by throwing an error in one of the API routes - verified that the event shows up on Sentry <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * API errors are now captured in Sentry before returning server error responses, improving production visibility while keeping endpoint behavior the same. * **Tests** * Added coverage to confirm rejected handler executions are reported to Sentry and return the expected HTTP 500 JSON payload. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
66bfc5fdc3 |
Refactor ConnectSheet + Add unit tests to cover various logic (#47764)
## Context PR here mainly breaks up the files under `ConnectSheet` to separate the functional logic so that we can write unit tests. No behavior changes intended beyond the bug fixes ## Changes involved - **Test organization:** moved all root-level `ConnectSheet` test files into `ConnectSheet/__tests__/` for consistency with other parts of the codebase that use this convention. - **Bug fix:** read replica label had a stray `}` / missing `)`, rendering as e.g. `Read Replica (us-east-1 - abc123})` instead of `Read Replica (us-east-1 - abc123)`. - **`ConnectSheet.tsx`:** extracted the "hydrate sheet state on open" `useEffect` logic (mode/field/URL param resolution from URL vs. localStorage) into a new `ConnectSheet.utils.ts`, with unit tests - **`useConnectServerEnv.ts`:** fixed two race conditions in the secret reveal/hide flow: - `toggle()` and `getValue()` could each fire a separate reveal request if triggered close together — now deduped to share one in-flight request. - `getValue()` could hide a secret that had just been explicitly revealed by a concurrent `toggle()`, due to reading a stale closure value — now reads the live state via `useLatest`. - Also stopped swallowing the original error on reveal failure (now attached via `cause`). - Added tests for the above, plus the 10s auto-hide timer (previously untested). - **`ConnectStepsSection.tsx`:** extracted `resolveContentPath` and the three inline "show notice" booleans (IPv4 addon, session pooler, self-hosted MCP) into `ConnectStepsSection.utils.ts`, matching the existing pattern for the Data API notice. Added unit tests for all of them. ## To test - [ ] Just a basic smoke test of the Connect sheet should do <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved connect setup hydration so saved preferences and URL values are applied more consistently when opening the sheet, including automatic URL backfilling where needed. * Refreshed connection guidance notices (IPv4 add-on, session pooler, and self-hosted MCP) with more consistent logic. * **Bug Fixes** * Fixed secret reveal behavior to keep concurrent reveal actions in sync, handle failures more safely, and ensure auto-hide works reliably. * Corrected the read-replica option label formatting. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ce81c2f6ec | feat(studio): allow deleting a branch from general settings page (#47677) | ||
|
|
770f1c2b06 |
fix(aeo): remove ua-based markdown serving (#47770)
## Summary The `ChatGPT-User` live-fetch agent's user-facing reader hard-fails (`(400) OK`) on pages we serve it as markdown via user-agent matching, which made supabase.com blog and product pages unreadable in that assistant. I root-caused this with a controlled fetch diagnostic cross-checked against our request logs: the failing fetches never reach our origin (the failure is cached on their side), pages served as plain HTML read fine everywhere we tested, and the same failure reproduces on other major sites that serve UA-matched markdown, so the reader bug is upstream. This PR removes user-agent-based markdown serving entirely rather than special-casing one agent: UA sniffing is a guess about contractless clients whose fetchers change without notice, and this incident showed the failure mode is silent (we keep serving 200s while the user-facing agent breaks). Markdown remains available on every explicit signal — `Accept: text/markdown` q-value negotiation, explicit `.md` URLs, and llms.txt — which is the same contract-driven model the Claude fetcher already uses successfully (it sends `Accept: text/markdown, text/html, */*` and keeps receiving markdown after this change). ## Changes - Remove the `LLM_USER_AGENT` regex and the `userAgent` parameter from `negotiateMarkdown` in `packages/common/markdown-negotiation.ts`; decisions now depend only on `Accept`, the `.md` suffix, and the markdown-variant manifest - Update both consuming middlewares (`apps/www`, `apps/docs`) to the new signature; no behavior change for Accept-negotiated or `.md` requests - Add the missing `Vary: Accept` header to docs guides-md 200 responses (the www `api-v2/md` route already declares it) - Fix a pre-existing www bug surfaced in review: explicit changelog `.md` URLs rewrote to a doubled `.md.md` path (404) under a markdown-preferring `Accept`, and 406'd on a non-matching `Accept`. The www middleware now strips the `.md` suffix before slug lookup and passes `isMarkdownSuffix` into `negotiateMarkdown`, folding the separate `MD_PAGES` `.md` block into the single negotiation path (same shape as the docs middleware) - Rework tests: UA-independence suites replace the per-agent rewrite tests; a probe Accept header now 406s regardless of user agent (previously agent UAs were exempt); new changelog `.md` negotiation coverage ## Testing Tested locally: - [x] www middleware suite 36/36, docs middleware suite 17/17 - [x] typecheck green for common, www, docs Verified on the Vercel previews (www + docs) with curl: - [x] `ChatGPT-User` and `Claude-User` UA GETs on blog/pricing/guide pages return `text/html` with a default Accept - [x] Claude's real Accept (`text/markdown, text/html, */*`) still returns `text/markdown`; `Accept: text/markdown` and `.md` URLs return `text/markdown`; probe Accept returns 406 - [x] `/changelog/<slug>.md` with `Accept: text/markdown` returns the entry markdown as a direct 200 (production today detours through a 308 to the bare URL); changelog index `.md` and bare-entry Accept negotiation also verified - [x] docs guides markdown 200s carry `Vary: Accept` The intermediate commit (ChatGPT-User-only exclusion) was already verified on the preview: `ChatGPT-User` got HTML while `Accept`/`.md`/other-UA markdown was unaffected. Expected effects post-merge: UA-driven markdown volume in the request logs (~92% of md traffic) collapses to the Accept + `.md` baseline; named-agent page requests return to prerendered/static serving, reversing the extra Vercel function invocations the UA rewrite introduced; user-facing readability in the affected assistant recovers within ~24h as its fetch cache revalidates. The md-share dashboard gets a dated annotation; the ratio is not comparable across this change. ## Linear - fixes GROWTH-973 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Markdown and HTML routing now depends on the request’s `Accept` header and `.md` links, making content negotiation more predictable. * Requests that don’t accept available content now consistently return `406 Not Acceptable`, even for bot-like user agents. * Guide markdown responses now include an `Accept`-based cache variation header to improve correct caching behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
75bb899f01 |
Fix mobile toolbar behaviour (#47800)
**Before** <img width="340" height="104" alt="image" src="https://github.com/user-attachments/assets/48a434de-21c2-4e3f-8cad-3c6408f7348d" /> **After** <img width="508" height="317" alt="image" src="https://github.com/user-attachments/assets/e52c6ba6-c173-4bb8-a466-1697585286c7" /> Fixes - Rendering issue of the menu toggle on mobile when menu is open - You can now switch between panels when open (e.g. from help to advisor). There was previously a bug that would just close the drawer rather than switch. **To test** - Reduce screen size in a project view - Click top right menu item - Notice menu item is active in light mode - Click "Assistant" and notice it switches vs closes the drawer - Click close or outside the toolbar to close the drawer <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved the mobile menu button’s visual state by updating the menu icon color when the menu is open. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
87c5f74ceb |
Add CTA to update tax ID if run into tax ID issues when upgrading plan (#47767)
## Context There's a chance users may run into tax ID issues when upgrading a plan as such: <img width="412" height="120" alt="image" src="https://github.com/user-attachments/assets/4c559ae0-d942-4c10-b83a-c5944a2a49ee" /> Adding a CTA here to guide users and mitigate confusion on how to proceed to remediate <img width="399" height="147" alt="image" src="https://github.com/user-attachments/assets/3bcaca14-bd77-4168-b9ab-cd6b75f79e24" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved billing-profile validation feedback by standardizing error messaging for tax ID vs. billing address country mismatches. * Added an in-toast “Update tax ID” action to guide users directly to the fix. * Updated the billing dialog’s close behavior so it returns users to the relevant address section (including scrolling to it automatically). <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f45389138b | ref(pipelines): Remove unnecessary restarts (#47732) | ||
|
|
ece31da789 |
blog: add UTM params to CipherStash post links (#47798)
## Add UTM params to CipherStash blog post links Follow-up to #47751. The [Notion doc](https://app.notion.com/p/supabase/Blog-Post-CipherStash-partner-drop-3455004b775f81c68712f6a115ee43f8) now has UTM-tagged outbound links for launch tracking. This applies them to the three links in the published post. All three use `?utm_source=supabase_announcement_post&utm_medium=blog&utm_campaign=launch`: - Intro: CipherStash integration link - Intro: cipherstash.com link - Get started: Add CipherStash to your Supabase project No content or copy changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated CipherStash and Supabase links in the blog post with campaign tracking parameters. * Applied tracking to introductory links and the “Get started” call-to-action. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
949a57d285 |
content(www): update investor logo wall on company page (#47753)
## Summary - Adds 8 new investor logos: Accel, Craft, Figma, Georgian, GIC, Peak XV, Salesforce Ventures, Stripe - Reorders lead investor grid to match design mockup (3 rows of 4) - Adds per-logo `scale` field to control logo size within each cell - Adds `grayscaleOnly` field for Salesforce Ventures to preserve tonal contrast (prevents wordmark from being hidden by `contrast-0` filter) ## Test plan - [ ] Visit /company and verify all 12 investor logos render correctly across 3 rows - [ ] Check logo sizing and order matches the mockup - [ ] Verify Salesforce Ventures wordmark is visible inside the cloud shape - [ ] Check dark mode 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Expanded and reordered the “Our investors” lead cards with additional entries (including Stripe, Salesforce Ventures, and others). * Enhanced logo presentation options for lead cards with per-investor sizing/positioning controls. * **Bug Fixes** * Improved lead investor card image rendering by removing internal scrolling and using an overflow-hidden container with scale-based sizing. * Preserved the existing logo filter behavior (opacity-only when configured, grayscale-only when selected, otherwise the default contrast treatment). <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
72aa214b0c |
fix: new project form accessibility issues (#47785)
## Problem The new project form has accessibility issues: - labels are not linked to inputs - description are not linked to inputs ## How to test Navigate through the form inputs with voice over and make sure every input makes sense <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved form field identification consistency across project creation screens (compute size, database password, project name, PostgreSQL version, region, and organization). * Enhanced selector/input accessibility by adding explicit element identifiers to key controls. * Updated region and repository UI structure to improve reliable rendering without changing setup behavior. * Preserved existing password, version, and routing logic while making dropdowns and fields easier to locate and interact with. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dcfffcd076 |
chore: post-review updates for sentry docs (#47784)
FUP to https://github.com/supabase/supabase/pull/47709 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the Next.js Sentry setup guide with clearer wording and a step-by-step configuration flow. * Added explicit instructions for instrumenting Supabase clients in server, browser, and middleware contexts. * Included guidance for enabling query and mutation data capture so Supabase activity appears in monitoring as database spans. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3667601895 |
feat(studio): add sign in with ChatGPT (#47772)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature ## Summary Introduce a "Sign in with ChatGPT" option gated by the new `dashboard_auth:sign_in_with_chatgpt` feature flag and a manual localStorage rollout switch (`SIGN_IN_CHATGPT_ENABLED`), since the feature is still WIP. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for signing in with ChatGPT alongside GitHub. * ChatGPT sign-in now depends on both a feature flag and an additional rollout setting. * Updated provider availability so the app can show the correct sign-in options. * **Bug Fixes** * Improved validation and coverage to ensure sign-in options appear only when fully enabled. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b198748064 |
docs: update Sentry integration guide for built-in SDK support (#47709)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? The Sentry monitoring guide documents the third-party `@supabase/sentry-js-integration` package. Sentry now ships Supabase support natively in the JavaScript SDK (v9.14.0+), and the documented API is incompatible with current `@sentry/*`, so the snippets no longer work as written. Fixes #47708. ## What is the new behavior? All snippets are updated to the built-in API (`Sentry.supabaseIntegration({ supabaseClient })` and `Sentry.instrumentSupabaseClient(client)`). The Next.js section is simplified to a single instrumentation call that covers browser, server, and edge. The span deduplication example is corrected (supabase-js uses `fetch`, so it filters `nativeNodeFetchIntegration`). Added a note about the v9.14.0 requirement with the community package as the fallback for v7, and removed the now-unnecessary install section. ## Additional context Verified end-to-end against `@sentry/node` + `@supabase/supabase-js`: both entry points produce `db` spans for select/insert/update/delete and capture PostgREST errors. **Note**: This PR was created entirely through Claude Code Opus 4.8, with code snippets tested in a sample project. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the telemetry guide to use Sentry’s built-in Supabase support (`@sentry/*`) instead of a community integration. * Added explicit setup requirements for Sentry JS SDK version 9.14.0+. * Provided two enablement options, including instrumentation when Supabase client setup and Sentry initialization are separate. * Refreshed guidance for span deduplication and improved Next.js setup instructions, including operation payload capture. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Kamil Ogórek <kamil.ogorek@gmail.com> |
||
|
|
d949a19f97 |
fix(studio): extend downgrade error toast duration (#47780)
## Summary - Downgrading to Free tier is blocked server-side when an org has an active branch, but the resulting error toast in `ExitSurveyModal.tsx` used the default 4s toast duration, making it easy to miss. - Adds `duration: 10_000, dismissible: true`, matching the pattern already used for other important billing error toasts (`org-subscription-update-mutation.ts`, `NewOrgForm.tsx`). Fixes FE-3882 ## Test plan - [ ] Attempt to downgrade an org with an active branch to Free tier and confirm the error toast stays visible for 10s and can be dismissed <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved the downgrade error message to stay visible longer and be easier to dismiss, making failures clearer for users. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
532ac3638d |
fix(www): update customer logos from svg to pngs (#47777)
Some customer pages didn't show og-images properly because satori breaks using svgs. This PR replaces all customer logos from svgs to pngs. They're all exported at least 2x to 4x so image quality shouldn't get worse anywhere. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated several customer story pages and related listings to use PNG logo assets, improving logo rendering consistency across the site. * Refreshed the customer RSS feed metadata and removed a duplicate entry so the feed stays up to date and cleaner. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1aa23f9f64 |
fix: fix several accessibility issues on the organization home page (#47769)
## Problem - Organizations links are not accessible with keyboard - Project list buttons are missing labels - Headings should be sequential <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved keyboard and screen-reader accessibility for project actions and project reference copy controls. * Added clearer tooltip guidance for copying a project reference. * Updated project and organization card interactions for more consistent click and focus behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1987f19d0a |
feat(sql-editor): add manual save feature preview (#47745)
## What Adds an opt-in **SQL Editor manual save** feature preview that switches the SQL Editor from autosaving every edit to saving only on demand, and hardens the tab-close flow so unsaved edits are handled correctly. ## Changes **Feature preview** - New `sqlEditorManualSave` flag + `UI_PREVIEW_SQL_EDITOR_MANUAL_SAVE` local-storage toggle, wired into the Feature Preview modal with an explanatory panel. - `useIsSqlEditorManualSaveEnabled` gates behavior on both the flag and the user's preview opt-in. **Editor toolbar** - Save button (with `Cmd+S`) next to Run, plus an autosave status indicator showing dirty/saving/saved state and a shortcut to disable autosave (emits a `sql_editor_autosave_disable_clicked` telemetry event). **Discard on close** - Closing a snippet tab with unsaved edits prompts for confirmation and, on confirm, actually discards the local edits and evicts the cached server copy so the snippet reopens clean. **Decouple tab layout from SQL specifics** - Tabs store gains a generic per-type close-handler registry (`registerTabCloseHandler` / `getCloseConfirmation` / `closeTabs`). The SQL editor registers its discard + confirmation behavior from the save coordinator. - Low-level `removeTab`/`removeTabs` (rename/move re-keying, stale cleanup) intentionally do **not** trigger discard. - Adds `statusOnDiscard` lifecycle transition and `clearSnippetContent` store action. ## Testing - `pnpm --filter=studio typecheck` — clean. - Added unit tests for the close-handler registry (fires on single/multi close, skips re-keying/cleanup removals, respects tab type, selects confirmation copy, unregisters cleanly). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a SQL editor manual-save preview with a “Save” button and `Cmd+S`, plus a modal option to disable manual-save/preview. * Added “unsaved changes” tab status indication when manual-save is enabled. * Introduced tab-type-specific close confirmations (shown only when needed). * **Bug Fixes** * In manual-save mode, closing a SQL tab with unsaved edits now clears local snippet content and refreshes it on reopen. * **Tests** * Added coverage for tab close handlers and confirmation behavior. * **Chores** * Added a persisted setting allowlist entry and tracked autosave-disable clicks via telemetry. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a3f2c4ffc1 |
chore(deps): upgrade to TypeScript 7 (native compiler) (#47757)
Upgrades the monorepo to TypeScript 7.0.2, released 2026-07-08. `tsc` is now the native Go compiler ([announcement](https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/)) — full turbo typecheck drops from ~56s to ~19s locally. TS 7.0 ships **without a programmatic API** (it lands in 7.1), so this uses Microsoft's recommended side-by-side setup: the `typescript` name resolves to `@typescript/typescript6` (the 6.0 API republished) for API consumers — typescript-eslint and Next.js build typechecking — while `@typescript/native` (the real `typescript@7.0.2`) owns the `tsc` bin that typecheck scripts run. Exactly one version of each is in the lockfile; nothing imports the native package as a library. When 7.1 + tool support lands we can collapse back to a single `typescript` dep in the catalog. **Changed:** - `pnpm-workspace.yaml`: catalog aliases for `typescript` / `@typescript/native` - 17 package.json files: `@typescript/native` added beside each `typescript` dep so every package's `tsc` is the native binary - `apps/studio/tsconfig.json`: exclude `dist/` (gitignored build output) from typechecking **Fixed** (real type errors TS 6 under-reported): - `packages/ui-patterns` CodeBlock: `borderLeft: null` → `undefined` (`CSSProperties` doesn't accept null) - `apps/www` CodeBlock: removed a JSX `@ts-ignore` comment that tsgo doesn't honor and fixed what it masked (untyped `.js` theme objects, possibly-undefined highlighter children) ⚠️ **Merge timing:** the new packages are inside pnpm's 3-day `minimumReleaseAge` window until ~July 11. Installs from the committed lockfile are unaffected (resolution is skipped), but anything that forces a re-resolution before then will fail — hold off merging until the window passes. Note for editors: the compat package has no `lib/tsserver.js`, so VS Code's "Use Workspace Version" won't work — use the bundled TS or the TypeScript Native Preview extension. ## To test - `pnpm install && pnpm typecheck` — all 15 tasks green, and `./node_modules/.bin/tsc --version` prints 7.0.2 - `pnpm lint --filter=studio` — typescript-eslint still parses (resolves the 6.0 API) - `pnpm build --filter=design-system` (or any Next app) — Next's tsconfig validation and build typecheck still work - CodeBlock rendering on www (syntax highlighting, line highlights with/without border) — the two fixes are behavior-neutral but worth an eyeball <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements / New Features** * Enhanced TypeScript tooling support across the workspace for smoother development builds and checks. * **Bug Fixes** * Code blocks render more reliably when content is empty or missing. * Highlighted code line styling applies more consistently. * **Maintenance** * Studio TypeScript builds now avoid including generated output (such as `dist`) during compilation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
74bc0a8e27 |
fix(studio): initialize Sentry on the TanStack build (captures were silent no-ops) (#47666)
Stacked on #47657 (base is `alaister/tanstack-migration-fixes`; retarget to `master` once that merges). The TanStack runtime never ran `Sentry.init` — `instrumentation-client.ts` is a Next-convention file nothing imports under TanStack Start, so every `Sentry.captureException` on that build (including the `routes/__root.tsx` error-boundary / `routerErrorComponent` reports) was a silent no-op. - **Shared config source**: the entire client config moves verbatim from `instrumentation-client.ts` into `lib/sentry-client-options.ts` (`buildSentryClientOptions`). Both runtimes build from it, so Next and TanStack can't drift — the builds differ only in two explicit knobs. - **TanStack init**: `sentry.tanstack.ts` initializes `@sentry/react` from `getRouter()` (TanStack Start's real client bootstrap — the earliest point with the router instance), wiring `tanstackRouterBrowserTracingIntegration(router)`. Window-guarded + idempotent; `router.tsx` is TanStack-only so the Next build is untouched. (Named without `.client.` — Start's import-protection fails the build for `*.client.*` in the server graph.) - **Third-party error filter is intentionally Next-only**: without the bundler-injected `applicationKey` metadata (only `withSentryConfig` provides it), the SDK tags *every* event `third_party_code: true` and `beforeSend` would drop them all — recreating the silent no-op with a DSN set. Follow-up: add `@sentry/vite-plugin` moduleMetadata, then enable. - **DSN-less builds stay crash-free**: `vite.config.ts` inlines `undefined` for unset `NEXT_PUBLIC_SENTRY_DSN`/`NEXT_PUBLIC_SENTRY_ENVIRONMENT` (a literal `process.env.*` in the bundle is the exact `process is not defined` class #47657 fixed). No-DSN → disabled client, plus the existing `IS_PLATFORM`/consent gates. - Tests: `instrumentation-client.test.ts` moved to `lib/sentry-client-options.test.ts` with all 36 assertions kept, plus integration-gating and Next/TanStack parity tests. `tsc` clean; full `vite build --mode test` passes. Follow-up (separate): server-side Sentry for the Start handler (`server.ts` entry + `@sentry/node`-style init). ## To test - **Locally (no DSN set)**: load the TanStack build — no Sentry network requests, no console errors, and crucially no `ReferenceError: process is not defined` (the define fallback). Forcing an error must not POST to any `/envelope` endpoint. - **On a preview/deploy (DSN set, telemetry consent accepted)**: throw a test error (e.g. crash a route component) → a POST to `o…ingest.sentry.io/api/…/envelope/` fires, and the event lands in Sentry with a `codeSampleRate` tag and **no** `third_party_code` tag. Navigation spans named after TanStack routes appear when the 2% pageload trace samples in. - **Next build regression check**: the Next dev/preview still reports errors exactly as before (`instrumentation-client.ts` now builds its options from the same shared source). --- ### Review feedback: Sentry `/envelope` never fires on TanStack (Joshen) Root-caused: `@sentry/core`'s `Client.sendSession` silently drops the session when the client has no `release`. The Next build gets a release injected by `withSentryConfig` (the Vercel commit SHA); the Vite build runs no Sentry bundler plugin, so it had no release → session envelopes were discarded before transport → zero `/envelope` traffic (errors/transactions are separate). Fix: inject `release: NEXT_PUBLIC_VERCEL_GIT_COMMIT_SHA` on the TanStack build (vite.config re-exposes `VERCEL_GIT_COMMIT_SHA` under the `NEXT_PUBLIC_` name, same SHA the Next release resolves to). Also switched `integrations` to the function form so defaults are preserved by contract (not just by current SDK behavior). 45 unit tests green. **To test (deploys only — the SHA is unset locally, so this can't be reproduced on a local dev build):** on this PR's Vercel preview with a DSN + telemetry consent, load any page and watch the Network tab for a POST to `…ingest.sentry.io/…/envelope/` — a session envelope should now fire on load, matching the Next build. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved client-side error and performance monitoring for the Studio app across both router setups. * Added support for passing release/version information into monitoring data. * **Bug Fixes** * Reduced noisy error reporting by better filtering common browser, extension, cancellation, and load-related issues. * Prevented browser bundles from referencing missing environment values at runtime. * Made monitoring initialization safer in server-rendered and client-only environments. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
f34fdd6c8f |
Skip using count estimate function for retrieving row counts if in read only context (#47761)
## Context Currently when retrieving row counts of a table in the Table Editor, we're using a `COUNT_ESTIMATE` pg function ([ref](https://github.com/supabase/supabase/blob/master/packages/pg-meta/src/sql/studio/database/get-count-estimate.ts#L5)) to retrieve an estimate (instead of checking `pg_class` -> `reltuples`) as that would theoretically provide a more accurate representation. However, in a read only context, that function can't be used - users will run into `cannot execute CREATE FUNCTION in a read-only transaction`, so we need to fallback to just checking `pg_class` in this scenario. The logic's already set up as we were previously looking into allowing users to use a read replica to power the dashboard, but we also need to consider members with read-only roles within the organization, so this PR updates the logic a little to factor that in. ## To test - [ ] With a read-only role, open the table editor and verify that we're not using the count estimate function to retrieve the table row counts <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Updated the invite member dialog to open in a larger size for better usability. * **Bug Fixes** * Improved table row count behavior so it now respects read-only access and permission limits more reliably. * Count estimates should now be shown more consistently across different database contexts. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
644fe0821b |
Add create org CTA for authorize route if no org found (#47760)
## Context As per PR title - also left a comment that this is a short term solution for now, so we know where to clean up after the long term solution is implemented <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a clear action in the empty organizations state so users can create an organization directly from the authorization flow. - **Bug Fixes** - Improved authorization error messaging for clearer, more consistent display. - Refined invalid authorization guidance so the retry prompt and missing-parameter details are shown more cleanly. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6cac3dbe5d |
Fixed case study title (#47768)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES Fixed the title on one of the case studies. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Content Updates** * Updated the Lovable customer story headline to put the focus on Supabase first. * Aligned the customer RSS entry title with the new headline wording. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4901f081e5 |
Migrate remaining requests to pg-meta API to use query endpoint (#47758)
## Context Migrates the remaining API requests to the pg-meta endpoint to use the query endpoint directly with the SQL from the pg-meta package. This touches the following: - policies - publications - triggers - views - materialized views - types ## To test Just need to verify that we're still fetching the data correctly on these pages - Database policies - Database publications - Database triggers - Database tables (views + materialized views) - Database types <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved and stabilized loading of database metadata (views, triggers, RLS policies, publications, materialized views, and enum types), including more reliable schema-scoped filtering. * Updated policy loading behavior and related UI queries to consistently use schema arrays, improving cache correctness and consistency. * **Tests** * Updated end-to-end test synchronization to wait for the correct metadata responses using more specific request identifiers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
073cada53a |
Fix observability custom reports menu item (#47759)
## Context More action button should be flushed to the right here <img width="294" height="156" alt="image" src="https://github.com/user-attachments/assets/65017960-3edb-4268-bb0e-1e2c26937d4b" /> ## Changes involved - Adjust `Menu.Item` in `packages/ui` to use a `div` instead of a `span` - Was otherwise causing HTML validation issues as we were trying to nest a `div` within a `span` - Having a `div` is a bit more flexible as well since `Menu.Item` expects `children` to be of any type (e.g a react node) <img width="279" height="149" alt="image" src="https://github.com/user-attachments/assets/12730cef-b077-4ef4-93c9-c21def939888" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized the Observability menu component to use named exports, ensuring consistent usage across the app. * Updated the mobile observability menu registration to reference the correct exported component. * **Style** * Refined Observability menu item layout, spacing, truncation, and dropdown sizing for a cleaner presentation. * Enhanced menu item rendering to allow custom `className` styling and full-width content layout. * **Accessibility** * Added an aria-label to the “more actions” button for improved screen reader support. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9b05afa2a3 |
Fix(docs): guides subheadings (#47765)
Fix docs subheading by removing the h2 html tag and adjusting styling. Likely a result of a merge conflict resolution between #47441 and #47288 ## What is the current behavior? <img width="1168" height="641" alt="Screenshot 2026-07-09 at 10 19 00" src="https://github.com/user-attachments/assets/c23b2e88-650c-4835-ae10-5a13c7b2e180" /> ## What is the new behavior? <img width="1167" height="605" alt="Screenshot 2026-07-09 at 10 32 56" src="https://github.com/user-attachments/assets/852f208c-2b22-4bf6-ad8c-edcf5bee5991" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Refined how guide subtitles are displayed for a cleaner, more consistent layout. * Adjusted subtitle spacing and presentation while keeping subtitle content rendering with formatted text support intact. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
82495cb455 |
blog: Searchable field-level encryption on Supabase with CipherStash (#47751)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? ### Blog post: Searchable field-level encryption on Supabase with CipherStash Partner drop announcing the CipherStash integration. **Scheduled to go live July 9, 2026.** - Author: `bilharmer` (title corrected to CISO) - Category: `product` - URL: `/blog/searchable-field-level-encryption-with-cipherstash` ### Outstanding before merge - [x] Marketing +1 in `#team-marketing`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Published a new blog post about searchable field-level encryption with Supabase and CipherStash, including setup guidance, integration details, and a video walkthrough. * **Content Updates** * Updated an author profile title from “CSO” to “CISO.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9e17c41771 |
Chore: Link Delete Project doc from the Delete Project confirmation m… (#47637)
Fixes FE-3801. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated the project deletion confirmation dialog so the “learn more / documentation” text and external link are always shown consistently. * Paid projects now include the full warning (“All project data will be lost, and cannot be undone.”) alongside the documentation link, while free projects show the simplified message without the additional warning. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
fd8a37b1d0 |
feat: add toggle for sensitive data visibility in table columns (#46180)
## Fixes FE-2619 ## What is the new behavior? This PR adds support for marking table columns as sensitive and masking their values in the grid view. Sensitive columns: - Display an 8-dot mask instead of the underlying value - Remain masked across page refreshes - Can be temporarily revealed for 5 seconds via the **Show data** action - Display a warning when copying rows containing sensitive data This helps prevent accidental exposure of sensitive information when sharing screens, recording demos, or taking screenshots. ## Testing - [x] Toggle sensitivity ON → save → refresh → remains masked - [x] Toggle sensitivity OFF → save → refresh → remains unmasked - [x] Toggle sensitivity multiple times → state remains consistent - [x] Copy row with sensitive columns → warning shown - [x] Click **Show data** → value revealed for 5 seconds then re-masked - [x] Text, Boolean, Binary, JSON, and Foreign Key columns all display a consistent 8-dot mask ### Test data SQL fixture covering multiple PostgreSQL data types: https://gist.github.com/monicakh/2485e9054bf21045912359871e9a1cb4. ### UI <img width="1284" height="554" alt="CleanShot 2026-06-09 at 12 01 33@2x" src="https://github.com/user-attachments/assets/4aec0ba7-c874-42d7-9442-d2c704b319cc" /> <img width="1200" height="560" alt="CleanShot 2026-06-07 at 10 43 40@2x" src="https://github.com/user-attachments/assets/b9569484-6fcc-47de-bc3d-881d0edc4060" /> The **Show data** action is only available for sensitive columns. <img width="450" height="400" alt="CleanShot 2026-06-07 at 10 42 18@2x" src="https://github.com/user-attachments/assets/d48849a2-ec0b-4522-a787-561a1d204ec9" /> Warnings on Copy command <img width="450" height="80" alt="CleanShot 2026-06-09 at 11 58 42@2x" src="https://github.com/user-attachments/assets/374e7d6b-b82a-4923-b035-2ec9b2f7bb7d" /> <img width="450" height="80" alt="CleanShot 2026-06-09 at 11 58 58@2x" src="https://github.com/user-attachments/assets/ecd951bb-e9e2-47ae-9ddd-d32969e01c12" /> <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46180?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: supabase-autofix-bot <noreply@supabase.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
97713923f8 |
Revert override (#47754)
Reverts a color override which seems to be causing issues in some edge cases <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Adjusted the light theme so its surface color now uses the default value instead of being overridden. * Preserved the dark theme appearance while keeping theme styling consistent across modes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
000bdd0684 |
fix(studio): trim leading whitespace in site URL form (#47748)
## Changes - **SiteUrl.tsx**: Added `.trim()` to the Zod schema so whitespace is stripped before validation and before the value reaches the mutation. All-whitespace input now correctly fails with "Must have a Site URL" instead of being silently accepted. This matches the existing pattern in the sibling Redirect URLs form (AddNewURLModal.tsx). - **SiteUrl.test.tsx** (new): MSW component test with two cases: - Trims leading/trailing whitespace before submitting to PATCH /platform/auth/:ref/config - Shows a validation error and does not submit when the value is only whitespace ## Test plan - [x] `npx vitest --run components/interfaces/Auth/SiteUrl/SiteUrl.test.tsx` — 2/2 pass - [x] `npm run typecheck` — clean - [x] `npx eslint` on both files — no new warnings <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved site URL validation so leading and trailing whitespace is ignored before saving. * Prevents whitespace-only values from being submitted and shows a validation error instead. * **Tests** * Added coverage for site URL saving, including trimmed input, validation failures, request payloads, and success feedback. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0675075a3c |
Added three new case studies (#47750)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Added three new case studies: - Lovable - Delight.ai - Drew's Crew <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added three new customer story pages highlighting how teams use the product in real-world workflows. * Published updated customer stories for delight.ai, Drew Crew, and Lovable with richer quotes, results, and next-step narratives. * **Chores** * Updated the customer stories RSS feed with the latest entries and publish date so new stories appear in syndication. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
26248be753 |
docs: Add AI Tools to QuickStarts (#47684)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Summary Adds two new optional onboarding steps — **Install Agent Skills** and **Install MCP server** — to every framework quickstart guide, right after the "create app" step, so readers are pointed at [Agent Skills](/docs/guides/ai-tools/ai-skills) and the [Supabase MCP server](/docs/guides/ai-tools/mcp) early in the setup flow. **Where each step lives:** - **16 quickstarts that include the shared `quickstart_db_setup.mdx` partial** (Next.js, Astro, Expo/React Native, Flask, Flutter, Hono, iOS/SwiftUI, Kotlin, Laravel, Nuxt, React, Refine, SolidJS, SvelteKit, TanStack Start, Vue): the partial itself now has a step 2 "Install MCP server (optional)" (between project creation and database setup), and each individual file gets its own "Install Agent Skills (optional)" step right after its app-creation step. - **RedwoodJS and Ruby on Rails** (don't use the shared partial): got both steps added inline, in the same order (Agent Skills, then MCP server), since they can't inherit from the partial. - All subsequent step numbers (and the "Step N" cross-references in prose, e.g. in RedwoodJS) were renumbered to stay sequential. ## Test plan - Check the quickstarts locally or in preview. - Any other ideas on how to optimise showing these items? - Does the SQL prefill add anything? - Other ideas on how to simplify without losing the information? - Check the MD output too and see if that also makes sense. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Refreshed multiple getting-started quickstarts with consistent, clearer step sequencing (including renumbering) across frameworks. * Added an optional “Install Agent Skills” step where applicable, plus updated placements of shared environment-variable setup content. * Simplified the database quickstart flow: single “Create a Supabase project” step, streamlined SQL Editor instructions for creating an `instruments` table, enabling RLS, and granting public read access. * Added optional “Install MCP server” steps in the relevant quickstarts. * **Style** * Updated MDX linting rules to allow the uppercase phrase “Agent Skills”. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> Co-authored-by: Nik Richers <nrichers@gmail.com> |
||
|
|
944c5862f3 |
Chore/small refactors (#47740)
## Context Just extracting the fixes which I think are applicable from this [PR](https://github.com/supabase/supabase/pull/47695) Main files are - `apps/studio/hooks/analytics/useLogsQuery.tsx` - `packages/common/auth.tsx` - `packages/common/feature-flags.tsx` ## Changes involved - Adjust `useLogsQuery` to accept an object as prop, rather than 4 individual params - This one doesn't address any Sentry issues, but is just a improvement to the function's API imo, more readable - Adjust how user email is retrieved in `feature-flags` - Related Sentry issue [here](https://supabase.sentry.io/issues/7592718607/?project=5459134) - The error is a bit vague, but Claude's attempt to fix looks alright in general IMO - Minimally verified that feature flags are loading as expected still <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved log-related screens and queries for more reliable loading and filtering across the app. * Fixed profile and account data handling so identity details are retrieved more consistently. * Improved authentication handling to better recognize missing user data and keep the app stable. * Updated feature flag personalization to use more accurate account information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
982d860123 |
feat(functions): migrate last-hour stats query to OTEL ClickHouse (#47693)
## What Migrates the `edge-functions-last-hour-stats` query (requests + server error counts shown on the Edge Functions list) from the BigQuery-style `logs.all` endpoint to the OTEL/ClickHouse `logs.all.otel` endpoint. <img width="2378" height="958" alt="CleanShot 2026-07-07 at 16 24 43@2x" src="https://github.com/user-attachments/assets/5bf3f04c-43e1-44a3-af28-d53feee27f68" /> ## How - Adds an OTEL SQL builder that reads from the single `logs` table (`source = 'function_edge_logs'`), using `log_attributes['function_id']` and `toInt32OrZero(log_attributes['response.status_code'])` instead of `cross join unnest(metadata)`. - Gated by the `otelLegacyLogs` flag, matching the rest of the logs code. The BigQuery path is preserved when the flag is off, and the two paths cache under separate query keys. ## Testing - Unit tests cover both endpoints and assert the generated SQL for each path. - Go to edge fns list - stats load correctly <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for using the OTEL logs backend for edge function last-hour stats when enabled. * Queries and caching now automatically distinguish between the standard and OTEL-backed data sources. * **Bug Fixes** * Ensured stats results are fetched from the correct endpoint based on the selected logging backend. * Added coverage to verify OTEL-specific SQL and response behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c070893475 |
fix: limit regex (#47717)
- closes https://github.com/supabase/supabase/issues/47712 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved SQL query handling so automatic row limits are no longer added when a query already ends with `LIMIT`, even if there’s whitespace before the semicolon. * Preserved correct behavior for queries using `LIMIT ... OFFSET ...`. * **Tests** * Expanded coverage for SQL limit detection and limit-suffix behavior around whitespace and semicolon placement. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5066261dbd | [DOCS-1148] Improve prose for LLM readability (#47653) | ||
|
|
c84d9856ae |
docs: improve discoverability of custom schemas documentation (#42634)
## What kind of change does this PR introduce? Documentation improvement ## What is the current behavior? The documentation for using custom schemas is buried under the REST API section (`/guides/api/using-custom-schemas`), making it hard for users to find when they first encounter schemas in the database documentation. Users who create custom schemas often don't realize they need to configure API access and grant permissions, leading to confusion. Closes #39856 ## What is the new behavior? Three improvements to make custom schemas documentation more discoverable: 1. **Cross-reference in tables page**: Added an admonition tip after the "Schemas" section in `/guides/database/tables` linking to both the "Using Custom Schemas" guide and the "Hardening the Data API" guide 2. **Navigation sidebar**: Added "Using Custom Schemas" link under "Database > Access and security" in the sidebar navigation, so users can find it from the database section without having to navigate to the API section 3. **service_role mention**: Updated the schema grants example in "Hardening the Data API" to include `service_role` alongside `anon` and `authenticated`, since users with server-side access also need this grant ## Additional context The issue author spent hours debugging custom schema access because the documentation wasn't linked from where schemas are first introduced (the database tables page). These changes create a clear path from learning about schemas → configuring API access → security hardening. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added "Using Custom Schemas" guide to the navigation menu under Database -> Access and security section * Enhanced Data API hardening documentation with clarification on service_role permissions for server-side database access * Added instructional tips regarding custom schema exposure via Data API and proper permission configuration <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> |
||
|
|
0421b1001d |
Flip show tooltip to true for supavisor connections chart (#47730)
## Context Realised that tooltips were not showing up for supavisor charts in database reports - just needed to flip a boolean Although - i don't have any projects with supavisor connections data (even on prod) so I can't visually verify this atm Also fixes a small issue in which docs url for the chart wasn't showing if the chart had no data, e.g: <img width="996" height="311" alt="image" src="https://github.com/user-attachments/assets/926febe4-9e3d-4975-9278-e7582d6ae12d" /> Should have docs button like this <img width="949" height="351" alt="image" src="https://github.com/user-attachments/assets/7561c1c5-94ae-405b-bd54-6bc94be0dd0a" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Enabled tooltips for the “Shared Pooler (Supavisor) client connections” chart so the metric can be inspected directly. * **UI Improvements** * Adjusted the tooltip positioning in the chart header for clearer readability. * When charts have no data, the “Learn more”/documentation link now follows the provided docs URL. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
62160939a8 |
fix: make status hovercard trigger on focus (#47731)
## Problem Status lists only appear on mouse hover and disappear when panning at 200%+ zoom. ## Solution Make hover-triggered information available via click or focus in line with WCAG 1.4.13 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved keyboard accessibility for the service status hover card by making the trigger focusable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6e4dc5df75 |
fix: correct typos and improve clarity in AI documentation (#42662)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Hello team and community! Decided that I want to start helping to maintain supabase, and decided to open my first PR with clearing typos and phrasing improvements for docs in AI folder. ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Refined and corrected grammar throughout AI implementation guides, improving readability across production deployment, Google Colab integration, LangChain, RAG with permissions, semantic search, and vector columns documentation. Updates include terminology consistency improvements, punctuation refinements, and clearer phrasing to enhance overall guide clarity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> |
||
|
|
0e02b86e74 |
Add Shane Adams to humans.txt (#47701)
Adding myself as part of onboarding ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? doc update: added name to humans.txt <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new team member entry in the public site metadata. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6dfae09b6d |
fix(www): postgres card art overlaps text column (#47734)
Before <img width="588" height="439" alt="Screenshot 2026-07-08 at 7 29 07 PM" src="https://github.com/user-attachments/assets/8a3380d3-571f-49cd-8f32-7b38650dd0e5" /> After <img width="578" height="436" alt="Screenshot 2026-07-08 at 7 29 55 PM" src="https://github.com/user-attachments/assets/09e74c31-e131-41d5-87da-b4518514cfb5" /> ## Summary On the homepage, the Postgres Database product card's elephant artwork renders over the card's description text at every viewport ≥1280px. I traced it to #47226 (merged June 24): standardizing the marketing container to `section-container` (`max-w-7xl` + `xl:px-24`) capped products-grid content at 1088px, shrinking the card to ~538px while its fixed geometry (250px text column + 398px right-anchored square artwork box) needs ~625px. Large monitors regressed hardest: before June 24 they got ~676px cards and no overlap. The app-router homepage move (#47228), the color system PR (#47288), and the artwork PNGs are all unrelated (verified against production DOM and full diffs). Two changes to the artwork span in `DatabaseVisual.tsx`: 1. Cap the box width at `calc(100% - 280px)` from `md` up, where 280 covers the text column's `md:max-w-[250px]` cap (in `ProductCard.tsx`'s `isDatabase` branch) plus card padding and breathing room. The art scales down through its existing `object-contain`. At md/lg the card is full-width (`md:col-span-12`), so the clamp never binds and rendering is unchanged there. 2. Remove the `xl:-right-12` bleed (base `right-0` stands, matching how 2xl already rendered). The bleed used to clip only the art's transparent canvas margin; with the clamped box the art fills its full width, so the 48px offset was cropping the elephant itself at 1280-1535px. The hover line-art SVG scales with the box and stays aligned with the PNG (identical aspect ratios: viewBox 390:430, PNG 585x645). ## Changes - Add `md:max-w-[calc(100%-280px)]` to the artwork span in `DatabaseVisual.tsx` so the Postgres card art can never cross its text column - Drop `xl:-right-12 2xl:right-0` from the same span so the smaller art isn't clipped at the card's right edge ## Testing Round 1 on the Vercel preview (commit |
||
|
|
0acc0eb8b3 |
feat: Support Form - Sync AI assistant conversation to Front (#46778)
# Sync AI assistant conversation to Front ## What & why When a user submits a support ticket, an AI assistant chat opens so they get help immediately while waiting for a human agent. This PR mirrors every turn of that chat into the Front conversation the support form already created, so the support team sees the full context and Front automations (routing, emails, CSAT) can act on it. Studio holds no Front credentials — it calls the platform endpoints (see the platform PR) to do the syncing. The assistant card is gated behind the `supportAssistantFollowUp` ConfigCat flag. ## How it works 1. **Submit** — `SupportFormV3` generates a stable `threadRef` (via the `uuid` package — `crypto.randomUUID()` is `undefined` in insecure contexts like non-localhost HTTP and would throw, silently aborting the submit) and sends it on `/platform/feedback/send`. The response returns the Front `conversationId`. Both are stored on `SubmittedSupportRequest`. 2. **Open chat** — `SupportAssistantSuccessCardContent` opens a chat seeded with `supportMetadata` (`threadRef`, `frontConversationId`, subject, category, severity, …). The first message is a `<support>…</support>` XML block. 3. **First user message** — the chat is tagged `isSupportChat = true`; the `onFinish` hook fires `syncSupportChatToFront`. 4. **Subsequent turns** — each `onFinish` slices the unsynced delta, strips the XML metadata block from the seed message, and posts to the platform messages endpoint. 5. **Escalation / resolve** — the `escalate_to_human` / `resolve_support_conversation` tools (and manual **Escalate**/**Resolve** buttons in the assistant input) flip lifecycle status via `setSupportLifecycleStatus` → `syncSupportLifecycleToFront`, which calls the escalation/resolve endpoints. Front rules act on `ai_support_status`. The assistant only resolves after the user explicitly confirms the issue is fixed. ## Key design decisions - **`threadRef` as the shared key** — one UUID travels as `threadRef` on submit and as `chatId` on every sync, so all messages thread into a single Front conversation. - **`conversationId` from the form response** — passed to all sync/lifecycle calls so the platform skips lazy derivation and PATCHes custom fields directly. - **Delta-only sync** — `lastSyncedMessageCount` tracks what's been sent; the boundary is snapshotted before the async call to avoid skipping messages that arrive mid-flight. - **Server-side de-dup** — stable `external_id` (`chatId:msg.id`) means retries don't duplicate in Front. - **Fire-and-forget** — sync failures log to Sentry, never break the chat; `isSyncing` resets on rehydration so the next `onFinish` retries the same delta. Message and lifecycle syncs use separate guards (`isSyncing` / `isLifecycleSyncing`) so an in-flight message sync can't drop an escalate/resolve. - **Lifecycle queued until the conversation exists** — if a lifecycle transition is requested before the initial message sync has returned a `frontConversationId`, it's stored as `pendingLifecycleStatus` and flushed once the id is assigned, rather than dropped. - **Tools return immediately** — the lifecycle tools return a stub to the AI SDK; the real Front call happens in `onFinish`, keeping async I/O out of the tool execute path. - **XML seed stripped before sync** — only the user's actual `<message>` is sent to Front (or dropped entirely if the form already created the conversation). ## Changes | Area | File(s) | | --- | --- | | Support form state | `SupportForm.state.ts` — `threadRef` / `frontConversationId` on `SubmittedSupportRequest` | | Support form submit | `support-ticket-send.ts` — sends `threadRef`, reads `conversationId` | | Support form UI | `SupportFormV3.tsx` — generates `threadRef`, stores `conversationId` | | AI assistant state | `ai-assistant-state.tsx` — `SupportChatMetadata`, `setSupportLifecycleStatus`, `onFinish` wiring, tool handling | | Message sync | `state/ai-chat-front-sync.ts` — delta tracking, message filtering, initial vs. incremental | | API data layer | `data/feedback/ai-chat-front-sync.ts` — typed platform-client wrappers for the three conversation endpoints | | Support tools | `lib/ai/tools/support-tools.ts` — `escalate_to_human`, `resolve_support_conversation` | | Tool integration | `lib/ai/tool-filter.ts`, `tools/index.ts`, `generate-assistant-response.ts` | | Success card | `SupportAssistantSuccessCardContent.tsx` — tags chat on first engagement | | Assistant panel UI | `AIAssistant.tsx` — Escalate/Resolve buttons, disabled input on closed chats, support placeholders | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - Support chats now include “Escalate to human” and “Resolve” actions. - Support submissions can be associated with a stable Front thread via a generated `threadRef`, preserving linkage across follow-ups. - AI assistant responses and input hints adapt when support mode is active. - **Bug Fixes** - Improved support chat state management and lifecycle handling to keep conversation metadata and message history synchronized more reliably with Front. - **Chores** - Added/updated coverage to reflect the new support-chat state and syncing behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
47912201e0 |
docs: Update documentation from Dart, and Swift SDK changes (#47583)
## Summary Updates reference specs based on new stable releases in two SDK repos (JS spec is auto-generated and was excluded). ## Changes analyzed | SDK | Repo | Stable tag range | |-----|------|-----------------| | dart | supabase/supabase-flutter | `supabase_flutter-v2.15.0...supabase_flutter-v2.15.4` | | swift | supabase/supabase-swift | `v2.48.0...v2.49.0` | ## Documentation updates ### Dart (supabase_flutter-v2.15.0 → v2.15.4) - **`supabase_dart_v2.yml`**: Updated `deleteUser()` — added `shouldSoftDelete: bool` parameter with example - **`supabase_dart_v2.yml`**: Updated `from.createSignedUrl()` — added `download: DownloadBehavior?` parameter with example - **`supabase_dart_v2.yml`**: Updated `from.getPublicUrl()` — added `download: DownloadBehavior?` parameter with example - **`supabase_dart_v2.yml`**: Added new `from-create-signed-upload-url` entry with `upsert: bool` parameter (was missing from the Dart spec) ### Swift (v2.48.0 → v2.49.0) - **`supabase_swift_v2.yml`**: Updated `explain()` — added note on `ExplainFormat` enum (`.text`/`.json`), added JSON format example - **`supabase_swift_v2.yml`**: Updated `createBucket()` and `updateBucket()` examples — `BucketOptions(public:)` renamed to `BucketOptions(isPublic:)` - **`supabase_swift_v2.yml`**: Updated `createSignedURL()` and `getPublicURL()` download examples — `download: Bool` replaced by `download: DownloadBehavior?` (`.withOriginalName` / `.named()`) --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added guidance for soft-deleting users, including a new example. * Documented download behavior for signed URLs and public URLs, including original or custom filenames. * Added documentation and examples for generating signed upload URLs, with optional overwrite support. * Expanded query plan documentation to show JSON output. * Updated storage examples to match the latest option names and recommended usage. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude <noreply@anthropic.com> |