Commit Graph
100 Commits
Author SHA1 Message Date
Hieu 4822687a64 fix: resolve mgmt api specs $refs manually to handle circular error (#48281)
## I have read the CONTRIBUTING.md file.
YES

## What kind of change does this PR introduce?
Bug fix.

## What is the current behavior?
`api_v2_openapi.json` has a circular reference (`APIErrorObject.issues`
→ `APIErrorObject`), which Redocly can't flatten with `--dereferenced`
("Detected circular reference which can't be converted to JSON"). This
breaks the [weekly docs update
workflow](https://github.com/supabase/supabase/actions/runs/29709444085/job/88251269807).

## What is the new behavior?
- Drop `--dereferenced` from `dereference.api.v1` (both v1 and v2, for
consistency)
- Add a `resolveRefs` helper in `Reference.script.ts` that manually
inlines `$refs`, leaving cycles as an unresolved `$ref` instead of
expanding infinitely
- This also fix the mgmt api update workflow so manual dispatch runs
against the selected branch, by changing checkout `ref` from hardcoded
`master` to `${{ github.ref }}`.

## Additional context
Also fixes `pnpm exec redocly` → `npx --package=@redocly/cli redocly` in
the same Makefile, an unrelated pnpm 11 recursive-exec bug hit while
debugging this workflow.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated API specification bundling and linting commands to use the
current Redocly CLI invocation style.
* Improved documentation processing behavior for dereferenced specs,
including guidance around circular references.
* Preserved existing generated specification outputs and validation
settings.
* **Chores**
* Updated the Mgmt API docs automation workflow formatting (YAML string
quoting and schedule/input values).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-27 10:35:42 +07:00
Hieu b76d04d6a0 fix: read FGA permissions from openapi spec x-fga-permissions extension (#48181)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Follow up to https://github.com/supabase/platform/pull/35940, which
moved FGA permissions off security and onto the `x-fga-permissions`
extension.

This updates the docs reference component to read from the new field.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* API documentation now supports displaying fine-grained access
permissions for endpoints.
* Endpoint security details are presented more consistently using the
documented permissions configuration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-23 12:17:45 +07:00
Hieu c713508fce fix: check token.scope for access resource display (#46603)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Scoped PAT access message checks `organization_slugs`/`project_refs` to
determine display text. This breaks when an org/project is deleted; its
tuple is removed and consequently from the token's slugs/refs, causing a
scoped token to incorrectly show "This token has access to all
resources."

## What is the new behavior?

Check the `token.scope` directly:
- `user` → "This token has access to all resources."
- `organization` → "This token has access to specific organizations."
(or "This token has no accessible organizations." if all scoped orgs
were removed)
- `project` → "This token has access to specific projects." (or "This
token has no accessible projects." if all scoped projects were removed)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved clarity of access token scope messaging. The resource access
information now displays more specific and accurate details based on
token type, distinguishing between organization-level, project-level,
and user-level access permissions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-08 16:12:17 +07:00
Hieu 4ff4cdc62d feat: expose mgmt api v2 spec on official document (#46605)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Include the v2 mgmt API spec in the official docs. This PR merges the v1
and v2 specs when generating the reference, with v2 taking precedence on
conflicts.

Fixes API-1215

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Docs now include API v2 reference: log-drain management
(list/create/update/delete) and project transfer (preview/transfer).

* **Documentation**
* Generated API reference now merges v1 and v2 specs so both appear in
the docs and section listings.
* New v2 operations added to Analytics and Projects documentation
sections.

* **Chores**
* Docs generation pipeline updated to accept and process multiple API
spec inputs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-04 14:53:26 +07:00
Hieu dac2ff0aaa feat: display FGA permission groups with OR logic (#42438)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Update API reference docs to properly render FGA permission groups,
showing the OR relationship between permission sets.

## What is the current behavior?

Right now, only the first FGA permission group is shown, missing
alternative permission sets that also grant access to an endpoint.

## What is the new behavior?

Display all FGA permission groups with "or" separator between them.

<img width="542" height="165" alt="Screenshot 2026-02-04 at 1 16 23 PM"
src="https://github.com/user-attachments/assets/adee529d-e15d-4912-98c4-1c5a8cd4c9d7"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

**Documentation**
- Improved the API reference documentation by reorganizing how endpoint
permissions are displayed. Permissions are now grouped with clear "or"
separators between groups, making it easier to understand the complete
set of permission requirements for each API endpoint.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-04 20:25:32 +11:00
HieuandChris Chinchilla e96efe695f feat: show required permissions in mgmt api docs (#41151)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Show required FGA permissions for each route in the management API docs.

Permissions are pulled from the `fga_permissions` security field in the
OpenAPI spec.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* API reference docs now extract and display fine-grained access-control
permissions per endpoint. When present, a dedicated block lists required
permissions with a clear header explaining the token requirements.
* The permissions block appears alongside existing OAuth scope
information and only shows for endpoints that declare such permissions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-03 20:56:45 +00:00
Hieu 5abafd7954 feat: improve org vs project scopes roles definition (#35920) 2025-05-26 15:43:52 +07:00
Hieu a069a1e836 feat: expose analytics OAuth scopes (#32543)
feat: expose analytics Oauth scopes
2025-01-03 15:14:46 +07:00
Hieu 38d36da300 fix: permissions check for branch projects (#28163)
* chore: remove unused event

* fix: convert useCheckPermissions to use string references

* fix: useCheckPermissions params

* fix: prettier
2024-07-25 08:50:02 +07:00
Hieu f5af2e6193 fix: mgmt api docs gha (#26985)
* fix: use sparse-checkout

* fix: always run on master
2024-06-04 14:31:38 +07:00
HieuandJoshen Lim aa9d5fe5e1 fix: remove invalid command (#26957)
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2024-06-04 13:45:18 +07:00
Hieu 40412091b4 fix: install dependencies command (#26902) 2024-05-31 09:53:54 +07:00
Hieu d855bfb3f8 feat: automate mgmt api spec update (#26655)
* fix: correct mgmt api naming

* feat: new command to generate mgmt api sections

* feat: sort section items

* chore: tidy up

* fix: add generate sections to the default command

* feat: add gha to auto update mgmt api docs

* chore: tidy up

* fix: operationId logic to support self-hosting references

* chore: update latest mgmt api specs

* chore: update latest mgmt api specs
2024-05-31 08:53:19 +07:00
Hieu d48948ba10 fix: RefSectionHandler to support mgmt-api/api sections (#26601) 2024-05-21 11:29:31 +02:00
HieuandCharis c5a88a9fc4 feat: render mgmt api body params (#26319)
* feat: render body parameters

* feat: api parameters render

* fix: update mgmt api spec to latest

* fix: body param format and support content type selection

* fix: prettier errors

* fix: use Options to render accepted enum values

* fix: prettier again

* fix: merge conflict

* fix: expose new api routes

* fix: prettier again

* refactor: ApiBodyParam

* fix: add missing apis

* chore: tidy up

* feat: improve api response with sample + schema tabs

* fix: support show/hide object param schema

* fix: show no content text

* refactor: use collapsible for hidden content

* Update apps/docs/components/reference/ApiOperationSection.tsx

Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>

* Update apps/docs/components/ApiSchemaOption.tsx

Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>

* fix: resolve comments

---------

Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com>
2024-05-21 13:30:34 +07:00
Hieu b88b3d38c7 feat: update mgmt api rate limit details (#21657) 2024-03-18 12:53:50 +07:00
Hieu 70463530ba feat: support storage OAuth scopes (#20225) 2024-01-11 17:06:38 +07:00
Hieu d5bc692d0e feat: improve fly sso flow (#18867)
* feat: improve fly sso flow

* fix: typecheck
2023-11-14 15:51:05 +07:00
HieuandInian 6416113857 feat: fly terms of service screen (#18586)
* feat: sign in with fly tos screen

* Update studio/pages/sign-in-fly-tos.tsx

Co-authored-by: Inian <inian1234@gmail.com>

* feat: support fly organization sso flow

* fix: add error message

---------

Co-authored-by: Inian <inian1234@gmail.com>
2023-11-01 16:35:05 +07:00
phamhieu 7fe3a9178d fix: update projects permission check to support resource.project_id 2023-09-07 09:46:35 +07:00
phamhieu a96993a8b9 fix: update projects permission check to support resource.project_id 2023-09-07 09:20:01 +07:00
phamhieu 1913422439 fix: members leave api 2023-06-15 10:53:28 +08:00
phamhieu ba852f2898 fix: project update api 2023-06-12 09:00:32 +07:00
phamhieu d2cf6c4c50 fix: members leave api 2023-06-12 08:27:07 +07:00
phamhieu b8dc6a10df fix: improve pgmeta tables fetchData 2023-06-07 09:31:51 +07:00
Hieu Pham b667c34dd3 Merge pull request #14789 from supabase/hi/error-544-desc
chore: add 544 error description
2023-06-05 12:12:24 +07:00
Hieu Pham a021e886e7 Merge pull request #14790 from supabase/hi/fix-swift-lib-fetch-response
fix: swift fetch data array response
2023-06-05 12:01:06 +07:00
phamhieu 48527d04a5 fix: swift fetch data array response 2023-06-05 08:01:02 +07:00
phamhieu e9896d09ea chore: add 544 error description 2023-06-05 07:54:01 +07:00
phamhieu b178faced2 feat: initial kotlin starter guides 2023-05-19 08:19:58 +07:00
Hieu Pham ee4879b3d1 Merge pull request #14361 from supabase/hi/new-profile-apis
feat: new profile apis
2023-05-18 13:44:15 +07:00
phamhieu 2db418d001 Merge branch 'master' into hi/new-profile-apis 2023-05-18 11:03:44 +07:00
phamhieu 4158fb9c6f fix: page location is sanitized server side 2023-05-15 14:58:21 +07:00
phamhieu eb057cb19b fix: use get profile api v2 2023-05-15 14:32:55 +07:00
phamhieu e83ddb92ae fix: create profile 2023-05-15 11:15:21 +07:00
phamhieu cec5d78881 fix: update update profile api 2023-05-15 11:14:50 +07:00
phamhieu 19d5216714 Merge branch 'master' into hi/new-profile-apis 2023-05-15 10:57:32 +07:00
Hieu Pham 8769f7c191 Merge pull request #14198 from supabase/hi/www-anon-session-id
fix: docs/www anon session id
2023-05-09 11:42:40 +07:00
phamhieu 00e76cd00d feat: send page params on telemetry event 2023-05-08 15:29:47 +07:00
phamhieu 5ab4f79a31 feat: send browser session on telemetry call 2023-05-08 09:47:00 +07:00
phamhieu f26d4a8232 fix: use shared useGoogleAnalyticsProps 2023-05-08 09:33:57 +07:00
phamhieu 10d52861dc feat: shared useGoogleAnalyticsProps 2023-05-08 09:27:46 +07:00
phamhieu daa9d9c9cd Merge branch 'master' into hi/www-anon-session-id 2023-05-08 09:12:08 +07:00
phamhieu 108edf4dfe fix: create new user profile 2023-05-04 12:56:24 +07:00
phamhieu 2af896b23f fix: updateConfig with allowed props 2023-04-27 16:06:04 +07:00
phamhieu f664d48aac fix: support new pgbouncer config response 2023-04-25 17:34:57 +07:00
phamhieu 2b427a4a2a Merge branch 'master' into hi/use-new-project-pgbouncer-api-route 2023-04-25 16:41:03 +07:00
phamhieu 3690d02c2c feat: use new project pgbouncer config api 2023-04-25 16:01:13 +07:00
phamhieu 6c1675129d fix: sanitizePageViewRoute to remove instead of replace 2023-04-20 18:51:52 +07:00
phamhieu b08447b424 fix: sanitize route before sending page_view event 2023-04-20 18:51:45 +07:00
phamhieu 8245595ab3 fix: page_view should use browser url 2023-04-20 18:51:38 +07:00
Hieu Pham a6f1dcf74d Merge pull request #13850 from supabase/hi/fix-page-view-again
fix: page_view event
2023-04-20 18:41:25 +07:00
phamhieu b630c81bb3 fix: sanitizePageViewRoute to remove instead of replace 2023-04-20 18:35:41 +07:00
phamhieu ec68b10672 fix: sanitize route before sending page_view event 2023-04-20 17:13:44 +07:00
phamhieu a9b4c7e339 fix: page_view should use browser url 2023-04-20 16:31:51 +07:00
phamhieu 03f6fdef0b chore: tidy up 2023-04-20 08:12:09 +07:00
phamhieu c61cbea523 chore: comments 2023-04-20 08:10:37 +07:00
phamhieu bbac7507de fix: first page_view event 2023-04-20 08:08:57 +07:00
phamhieu 7b4c48f465 Merge branch 'master' into hi/fix-page-telemetry 2023-04-20 07:48:53 +07:00
phamhieu 8a0565a386 fix: page_view should use dynamic route instead of the browser url 2023-04-20 07:44:55 +07:00
Hieu Pham d9f7d2982b Merge pull request #13800 from supabase/hi/remove-ga4-client
fix: remove ga4 client
2023-04-18 15:56:21 +07:00
phamhieu 14d1c7ebcb Merge branch 'master' into hi/remove-ga4-client 2023-04-18 15:18:50 +07:00
phamhieu 1ca102b9ac chore: clean up 2023-03-22 17:10:42 +08:00
phamhieu 0d7e59d666 feat: generate experimental api token 2023-03-22 17:10:42 +08:00
phamhieu 62436ca0bc fix: storage file download 2023-02-21 17:13:35 +07:00
phamhieu fba1c14a20 fix: remove ga4 client 2023-02-07 15:39:11 +07:00
phamhieu 90afbded45 chore: clean up again 2023-02-07 13:13:44 +08:00
phamhieu 561a6777d4 fix: handleRouteChange and condition to send initial page event 2023-02-07 13:13:44 +08:00
phamhieu 7faeb7c961 chore: clean up again 2023-02-07 13:13:44 +08:00
phamhieu 3be474b7a9 fix: send route param on page event 2023-02-07 13:13:44 +08:00
phamhieu 7af4850018 chore: clean up 2023-02-07 13:13:44 +08:00
phamhieu 595e0cf7d0 fix: default language locale format 2023-02-07 13:13:44 +08:00
phamhieu b9a6aacce1 chore: tidy up 2023-02-07 13:13:44 +08:00
phamhieu d874b146b8 chore: remove comment 2023-02-07 13:13:44 +08:00
phamhieu 4d572cbeda fix: window.gtag is not a function 2023-02-07 13:13:44 +08:00
phamhieu 35f5b6ca29 chore: clean up again 2023-02-07 13:13:44 +08:00
phamhieu 96438fe795 feat: add X-GA-Client-Id to request header 2023-02-07 13:13:44 +08:00
phamhieu 029316bf52 fix: ga props key names 2023-02-07 13:13:44 +08:00
phamhieu 4779ded07e feat: send GA4 props on telemetry call 2023-02-07 13:13:44 +08:00
phamhieu 2985c7ec9c chore: replace hardcode measurement id 2023-02-07 13:13:44 +08:00
phamhieu e2e1d15b08 feat: implement ga4 2023-02-07 13:13:44 +08:00
phamhieu 19c2249650 Merge branch 'feat/email-auth' of github.com:supabase/supabase into feat/email-auth 2022-10-25 09:25:28 +07:00
phamhieu 634ebed0f9 fix: remove username param from signup request 2022-10-25 09:25:22 +07:00
phamhieu eff4a95245 fix: prepareVercelEvns 2022-08-18 15:30:08 +07:00
Hieu Pham c8b53bb35b feat: new database envs for Vercel integration (#8462)
* feat: create SUPABASE_DB_HOST, SUPABASE_DB_PASSWORD envs for new empty database Vercel integration

* fix: prepareVercelEvns to handle missing project props

* chore: tidy up
2022-08-18 15:14:33 +07:00
Hieu Pham 3c79fec8db Merge pull request #8224 from supabase/hi/update-project-config-endpoints
fix: update project/:ref/config endpoints
2022-08-18 10:58:36 +07:00
phamhieu f69426ed6b fix: update project/:ref/config endpoints 2022-08-12 07:32:18 +07:00
Hieu Pham 819624cd06 refactor: check available payment method (#7232)
migrate from stripe/customer to /organizations/[slug]/payments
2022-06-09 18:01:12 +08:00
Hieu Pham 42eb1d7a61 chore: clean up org.project_limit (#7074)
* chore: clean up unused org.project_limit

* chore: tidy up Organization interface
2022-06-01 14:35:54 +07:00
phamhieu 0e274fc4e5 fix: update available param only
- fix #6948
2022-05-24 16:20:19 +07:00
Hieu Pham 8741052264 fix: onFilterTables for auth policy (#6953)
* fix: onFilterTables

* chore: tidy up

* chore: clean up with proper type

* fix: placeholder

* fix: input width
2022-05-24 14:25:04 +07:00
phamhieu e399b2ae18 fix: allow accessing specific pages when project postgrest ping failed 2022-05-23 18:13:11 +08:00
phamhieu 8a9b46250a refactor: auth policies page
- remove mobx local store
- filter table policies from meta.policies
- clean up
2022-05-23 18:08:24 +08:00
phamhieu 2a107b2d0c fix: iso string format 2022-05-20 15:17:36 +07:00
Hieu Pham fb8d93b4e2 Merge pull request #6878 from supabase/feat/add-felicis-logo
Feat/add felicis logo
2022-05-19 09:56:49 +07:00
phamhieu 52ecddc554 fix: unit test missing dayjs extend 2022-05-18 20:14:20 +07:00
phamhieu 899b70dbc1 fix: safari date parsing using dayjs CustomParseFormat 2022-05-18 20:14:20 +07:00
phamhieu f5c3eee5f2 refactor: extend dayjs once on _app
https://github.com/iamkun/dayjs/issues/931#issuecomment-644584535
2022-05-18 20:14:20 +07:00
phamhieu 415bd9989c fix: handle undefined dateString 2022-05-18 20:14:20 +07:00
phamhieu e2c42a0c7a fix: safari by replacing gap- by space-x- on landing page 2022-05-18 20:14:20 +07:00