<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Added C# examples across API, authentication, database, Realtime, and
Storage guides.
* Expanded authentication coverage for passwordless, phone, anonymous,
identity linking, SSO, sign-out, and social login providers.
* Added database examples for queries, functions, joins, JSON, arrays,
search, PostGIS, and custom schemas.
* Added Realtime examples for broadcasts, presence, subscriptions, and
database changes.
* Added Storage examples for buckets, uploads, downloads,
transformations, CDN purging, and resumable transfers.
* Included C# error-handling guidance and relevant reference links.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
The [User Management → Deleting
users](https://supabase.com/docs/guides/auth/managing-user-data) section
warned that deleting a user does not sign them out, but did not say what
to do about it. Adds a **Removing account access** subsection: revoke
sessions before deleting, why a soft-delete flag or
[ban](https://supabase.com/docs/reference/javascript/auth-admin-updateuserbyid)
is not a substitute, and the residual [access-token
window](https://supabase.com/docs/guides/auth/sessions) after
revocation.
Fills a docs gap surfaced by
[supabase/agent-skills#194](https://github.com/supabase/agent-skills/pull/194)
while investigating the
[`investigate-auth-001-deleted-user-access`](https://github.com/supabase/evals/blob/main/evals/investigate-auth-001-deleted-user-access/PROMPT.md)
eval scenario.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated the “Deleting users” guidance to specify deleting via
`auth.admin.deleteUser()` (with `shouldSoftDelete: false`) and clarify
that this cascades to sessions, invalidates refresh tokens, and blocks
new access-token minting.
* Rewrote the explanation to emphasize that it does not substitute for
temporary bans or application-level “deleted” states.
* Clarified the access-token window: already-issued stateless JWTs
remain valid until `exp`, and recommended mitigations include short JWT
expiry and enforcing session validation (via `session_id`) for sensitive
actions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Instructed granting least-privilege table permissions for anon,
authenticated, and service roles prior to enabling Row Level Security
across multiple guides and quickstarts.
* Clarified SQL examples and inline comments, added explicit GRANT steps
and RLS SELECT policies, rephrased policy guidance, and adjusted example
ordering and section numbering for clearer setup and testing.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
The purpose of this change is to reduce the bounce back rate of
the default email provider at Supabase. This change will allow
users to continue copying examples from the docs. Without it, an
upcoming change in supabase/auth[1] will begin rejecting these
invalid emails.
[1] https://github.com/supabase/auth/pull/1845
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
* docs: Adds Dart sample code into using custom schemas guide
* Add Flutter code to OAuth docs
* docs: Add sign out Flutter code to the OAuth guides
* Add Flutter code samples to the auth guides
* docs: Add Flutter code samples to storage docs
* docs: align all Flutter sample code to say Flutter instead of Dart
* docs: sort clean up Flutter and Dart labels
* docs: minor sample code fix
* run prettier
* chore(docs): add Swift guides
* chore(docs): add Swift guides for postgres changes
* chore: fix link identity swift method
* chore(docs): add Swift guides for realtime and storage
* chore: run npm run format
* chore(docs): add Swift example for passing params to `rpc` function
Begin the process of moving our MDX files into their own content directory.
Fixed a few minor bugs re: ToC and tabs not rerendering consistently on page navigation. (The ToC thing wasn't a problem before the refactor, the tabs thing is a problem on prod.)
Moved MDX files can't import their own components, so everything they require needs to be back in the component prop for mdx-remote's serializer. Cleaned this up a bit and lazy-loaded heavy/rare stuff. Also, the component prop doesn't take arbitrary objects (only actual components), so imported data has to be wrapped in a component.