mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 12:25:05 +03:00
chore/function-recent-errors
4673
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
7880c2f079 |
fix(studio): explorer chat and notebook layout refinements (#50453)
Five layout fixes across Explorer chat, notebooks, and the sidebar. ### Chat - **Conversation fade overlapped the scrollbar.** The top and bottom gradients are positioned against the conversation's padding box, which includes the scroll container's scrollbar gutter, so `inset-x-0` painted them over the scrollbar. They now stop at the conversation's content gutter, which `Conversation` owns for both the content and the fades. - **Composer background bled past the input's radius.** The form paints the surface behind the textarea but had no radius of its own, so its square corners showed outside the `rounded-lg` input. It now shares the radius. - **Message parts used two different widths.** Wide parts come down to `max-w-3xl` so every part shares a column, matching `AssistantQueryCell` and `AssistantNotebookPreview`. `isWide` / `isWideMessagePart` stay in place with both widths equal, so a part can diverge again later without rebuilding the mechanism. ### Notebooks - **Cell controls sat at the container edge.** Each cell centred itself at its own max width while the grip and add-cell button stayed at the far left of the full-width row, leaving a large gap. `SortableSection` takes a `sectionWidth` and carries its control gutter twice — once as the controls, once as padding on the other side — so the section stays centred with its controls immediately beside it. Cell widths are unchanged (prose `48rem`, query `72rem`); set them equal and the two cell types' controls line up on their own. The controls stay in flow rather than floating in an outside gutter, so on a viewport narrower than the cap the row just fills the space instead of clipping the controls into the padding. ### Sidebar - **Search icon didn't line up with the menu row icons.** The row box already sits flush with the search input's box, so rows moved from `pl-3` to `pl-2` to put their icons on the same 8px offset the search icon uses. Spacing between the input and the list now matches the 12px side padding. ### Testing `pnpm --filter studio run typecheck`, Prettier, and 378 tests across `Explorer`, `ProjectHome`, `AIAssistantPanel`, and `ExplorerLayout` pass. ESLint warning counts are unchanged from master. These were reasoned from layout rather than checked in a browser, so they're worth a look on a preview before merge. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Updated Explorer layouts with flexible, configurable widths for notebook and query sections. * Refined navigation spacing and padding across Explorer views. * Centered and standardized AI Assistant preview, query, and message content widths. * Improved chat form styling with rounded corners. * Adjusted conversation spacing and fade overlays to avoid overlapping the scrollbar. * Preserved full-width behavior where appropriate while keeping controls aligned. * **Tests** * Updated layout tests to reflect revised width and alignment behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
c15b0836d8 |
fix(studio): bump realtime max_concurrent_users soft limit (#50438)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bump realtime max_concurrent_users soft limit to 300k <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Increased the maximum supported concurrent clients from 50,000 to 300,000 when plan entitlements allow it. * **Bug Fixes** * Improved validation for concurrent-client limits, including clearer handling of entitlement-based and unlimited limits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
babebc959c |
fix(studio): improve pipeline destination logo legibility (#50496)
## What kind of change does this PR introduce? UI polish for Pipeline destination logos. ## What is the current behavior? The Snowflake mark does not use the available SVG canvas, and destination marks appear overly inset in the pipeline detail header. ## What is the new behavior? The Snowflake asset uses more of its canvas, and the large `DestinationLogo` variant renders a 32px mark inside its existing 56px frame. Small logos used in lists, diagrams, and destination pickers remain unchanged. | Before | After | | --- | --- | | <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 46 51@2x" src="https://github.com/user-attachments/assets/83e7ab5e-c9f3-4410-99c1-4f3596b9e027" /> | <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 48 33@2x" src="https://github.com/user-attachments/assets/d354dd46-80be-48f6-b2d9-277ee930eaaa" /> | ## To test 1. Open `/project/<ref>/database/replication` with a Snowflake pipeline and confirm its logo renders clearly in the list. 2. Open that pipeline's child route and confirm the destination logo fills more of the header square without changing the square itself. 3. Check another destination's child route and confirm its large logo uses the same sizing. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Increased the size of the large destination logo mark for improved visibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e21e0c73bb |
refactor(studio): simplify pipeline error details (#50444)
## What kind of change does this PR introduce? Studio UI refactor. ## What is the current behavior? Failed replicated tables spread retry timing and error details across several visually heavy blocks. ## What is the new behavior? Condenses retry timing and failure details into a clearer table-level presentation without changing retry behaviour or pipeline mutations. | Before | After | | --- | --- | | <img width="1842" height="594" alt="CleanShot 2026-09-16 at 12 55 52@2x" src="https://github.com/user-attachments/assets/fb6f6a3f-2e81-411e-9d49-ed4cf8cc66e7" /> | <img width="1824" height="328" alt="CleanShot 2026-09-16 at 15 16 21@2x" src="https://github.com/user-attachments/assets/bad558c4-2d4c-4d1b-bb68-32ad4d5b348f" /> | | _Not applicable._ | <img width="832" height="662" alt="CleanShot 2026-09-16 at 15 16 29@2x" src="https://github.com/user-attachments/assets/540a5d55-f99f-4c1e-9a57-5ab2ac31e44e" /> | This is an independent slice extracted from #49630. The related review series is #50443, this PR, #50445, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline with a failed table. 2. Confirm the table row presents its failure and retry timing without expanding the row unnecessarily. 3. Open the error details dialog and confirm the underlying error remains available. This is difficult to test unless you have a properly-failing table. You can instead do the following locally: 1. Check out `dnywh/tmp/pipelines-running-fixture`. 2. Open `/project/<ref>/database/replication/<pipelineId>`. 3. Use the floating pipeline-state switcher in the bottom-right. 4. Select _Running, some tables errored_. |
||
|
|
0b002892d7 |
refactor(studio): simplify pipeline reset dialogs (#50443)
## What kind of change does this PR introduce? Studio UI refactor. ## What is the current behavior? Pipeline table reset dialogs repeat explanatory content and use more layout than the reset decision needs. ## What is the new behavior? Simplifies the single-table and batch reset confirmations while preserving their cost estimate, destructive consequences, and existing reset mutations. | Before | After | | --- | --- | | <img width="854" height="1090" alt="CleanShot 2026-09-16 at 12 54 36@2x" src="https://github.com/user-attachments/assets/f9eef09b-89d1-4747-bc4c-e81fb64c584b" /> | <img width="840" height="742" alt="CleanShot 2026-09-16 at 17 01 11@2x" src="https://github.com/user-attachments/assets/fa45728c-ec66-45c8-9fef-9d2eb8310d4d" /> | This is an independent slice extracted from #49630. The related review series is this one, #50444, #50445, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline. 2. Reset one replicated table and confirm the dialog explains that destination data will be deleted and resynchronised. 3. Choose **Reset all tables** and confirm the batch dialog shows the same concise treatment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## UI Updates * **UI Updates** * Renamed replication “restart” actions to “reset” across dialogs, buttons, notifications, and cost estimates. * Updated messaging to clarify whether the pipeline will start or restart automatically after resetting. * Added clearer initial-sync guidance for all, some, or none of the affected tables. * Improved reset cost estimate messaging, including when no additional initial-sync charge applies. * Updated reset dialogs with clearer titles, descriptions, loading states, and error messages. * Disabled reset actions when pipeline status is unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cc540ff302 |
feat(studio): add safe theme colour controls (#49804)
## What kind of change does this PR introduce? Feature. ## What is the current behaviour? Studio Appearance preferences only select a theme mode. The underlying theme colours cannot be adjusted, and the existing proof of concept allowed unsafe combinations and introduced a bespoke Slider variant. ## What is the new behaviour? - Preserves the existing System, Dark, Light, and Classic Dark theme options. Classic Dark remains a fixed preset. - Adds four theme colour controls using the existing Supabase Slider unchanged. Each control presents a consistent 0 to 100 scale mapped to bounded light and dark ranges. - Previews colour changes while dragging and persists them once the interaction finishes, including rapid pointer gestures. - Stores light and dark overrides separately, validates stored values, clamps legacy values, and removes overrides that return to their shipped defaults. - Adds concise descriptions for Chroma, Contrast, Surface, and Elevation step, with a scoped Reset action shown only when the active theme differs from its defaults. - Keeps Slider in a stable shared chunk so production builds do not create a circular dependency between generated UI chunks. | Before | After | | --- | --- | | <img width="1448" height="1284" alt="CleanShot 2026-09-15 at 14 33 53@2x" src="https://github.com/user-attachments/assets/d55151c7-b2a9-40c6-9468-e77ae685ac38" /> | <img width="1454" height="1958" alt="CleanShot 2026-09-15 at 17 48 47@2x" src="https://github.com/user-attachments/assets/9d302e67-76cc-4341-948c-81713dea2e93" /> | ## To test 1. Open `/account/me` and scroll to Appearance. 2. Switch between System, Dark, Light, and Classic Dark. Confirm the same four modes remain available in the account theme menu. 3. Confirm Classic Dark retains its existing appearance and does not show theme colour controls. 4. In System, Dark, or Light, move each Theme colors slider to both ends. Confirm the dashboard previews the change, remains readable, and the theme cards do not shift or remount. 5. Reload the page and confirm colour changes persist separately for Light and Dark. 6. Return all sliders to their defaults, or select Reset, and confirm the Reset action disappears. 7. In System mode, change the operating system theme and confirm each resolved mode restores its own colour settings. --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
2db6fbf410 |
test(studio): add e2e coverage for the storage move picker (#50460)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Tests, plus one small test hook in Studio. ## What is the current behavior? The Storage file explorer's move dialog was recently reworked: the free-text "Path to new directory" input was replaced with an embedded folder picker (folder browsing, bucket-wide folder search, a responsive breadcrumb, and a confirm button that targets the folder currently open). That work shipped with unit and component tests, but nothing exercises it end to end against a real bucket. ## What is the new behavior? New `e2e/studio/features/storage-move.spec.ts` with seven tests: | Test | What it covers | | --- | --- | | moves a file into a folder picked from the explorer | The core path: open the picker, click a folder, confirm, and assert the file left the root and landed in the destination | | offers folders only, never files, as destinations | Files are excluded from the listing entirely | | blocks confirming a move into the folder the file already sits in | The confirm button reports `aria-disabled` when the destination matches the source | | finds a nested folder by search and moves into it | Bucket-wide folder search, including the "`<folder>` in `<location>`" row label | | reports when a search matches no folders | The empty-search message instead of a blank list | | collapses the middle of a deep path into a breadcrumb dropdown | The responsive breadcrumb: bucket and the two deepest folders stay inline, the middle collapses, and picking a collapsed folder navigates to it | | walks back up the path with the up-one-level button | Disabled at the bucket root, and drops the deepest folder otherwise | Supporting changes: - `utils/storage/queries.ts` gains `uploadObject` and `seedBucket`. Storage has no standalone folders — a folder exists because an object sits under that prefix — so seeding a folder tree means uploading objects at the paths a test needs. Doing this through the API keeps setup off the UI, which is both faster and less flaky than clicking through "Create folder" for each level. - `utils/storage/client.ts` accepts a string body so object uploads can send raw content alongside the existing JSON requests. - `utils/storage-helpers.ts` gains `openMoveDialog` and `confirmMove`. - `MoveItemsFolderPicker.tsx` gains `data-testid="folder-picker-list"` on its list container. ## Additional context **Why the `data-testid`.** Once a path is deep enough for the breadcrumb to collapse, the breadcrumb renders crumb buttons whose accessible names are folder names — so `getByRole('button', { name: 'beta' })` scoped to the dialog can match either a folder row or a breadcrumb crumb depending on depth. Scoping row lookups to the list container removes that ambiguity. This follows the e2e guidance about adding explicit test hooks where a component lacks an unambiguous accessible name. **These tests have not been executed.** They were written against the merged implementation and verified as far as the environment allows: - `npx playwright test --list` collects all seven - `tsc --noEmit` is clean for the new spec and helpers (the pre-existing errors in `column-editor-types.spec.ts`, `table-editor.spec.ts`, and `wait-for-response-with-timeout.ts` are untouched) - Studio's unit and component tests (82) still pass, and typecheck, eslint, prettier, the lint ratchet, and knip are all clean The suite needs Docker to bring up the local Supabase stack, which wasn't available where this was authored, so a real run in CI is the first actual execution. Selectors were all read off the merged source rather than guessed, but timing assumptions in particular deserve attention on the first CI run. **One thing this surfaced, not fixed here.** The success toast reads `Successfully moved 1 files to docs` — it doesn't singularize. The tests assert on `/Successfully moved/` rather than the full string so they don't encode that, but it's worth a follow-up. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns --- _Generated by [Claude Code](https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns)_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Tests** - Expanded end-to-end coverage for moving files between folders in Storage. - Validated folder selection, nested-folder search, empty search results, collapsed breadcrumbs, and navigation to parent folders. - Confirmed files are excluded from destination choices and moving to the current folder is prevented. - Added coverage for creating isolated test buckets, uploading fixture files, and confirming successful move operations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
9cdd412bab | feat(stripe-atlas): mock-up dashboard to enable live testing (#50327) | ||
|
|
4432a8beb4 |
chore(studio): update Explorer feature preview copy (#50250)
Updates the Explorer feature preview copy to explain the SQL Editor transition, Notebooks, and Snippet migration plans. Adds feedback questions and moves the preview image above the content. Validation: Prettier and `git diff --check` passed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated the Explorer preview layout by moving the preview image below the introductory text. - Replaced feedback questions with a clear overview of what enabling the preview provides, including SQL Editor replacement and Notebooks management through the dashboard and Assistant. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
240bfce7f6 |
[FE-4198] feat(studio): select a range of logs with shift-click (#50381)
Shift-clicking a log row checkbox now selects every row between the last clicked row and the clicked one, so you can grab a consecutive block of logs to copy without checking each one. Applies everywhere the shared `LogTable` renders: Postgres/API/Auth/Edge Functions logs and the Logs Explorer. **Added:** - `getShiftClickSelection` in `Logs.utils.ts`: pure helper that computes the next selection from the ordered row keys, the current selection, the anchor row, and the clicked row. Adds the inclusive range in either direction. If the whole range is already selected it deselects the range instead. Falls back to a plain toggle when there's no usable anchor. Covered by unit tests, plus `LogTable` component tests for range select, the no-anchor fallback, anchor clearing, and range deselect. **Changed:** - `LogTable` tracks the last toggled row as the range anchor (a ref, since it's only read in handlers). The anchor is set by plain clicks, shift-clicks, and the Shift+Space row toggle, and cleared whenever the selection becomes empty (toggling off the last row, plain row click, Escape, action bar clear, select-all then deselect-all, or a new query loading). - The checkbox cell handles `onClick` instead of `onCheckedChange` so the shift key is available. Keyboard Space on a focused checkbox still toggles it, since Radix dispatches a click for it. - A shift mousedown on the checkbox cell is prevented so the browser doesn't start a text selection across rows. Unified Logs has its own row selection (TanStack Table) and is not changed here. ## To test - Open any log page with a decent number of rows, e.g. Postgres logs. Click one checkbox, then shift-click a checkbox several rows below. Every row in between should be checked and the action bar should show the count. Repeat upward. - Shift-click a range that's already fully selected: the range should clear, and rows outside it stay as they were. - Plain-click a row's message text (not the checkbox): side panel opens and the selection clears. A following shift-click should just toggle that one row. - Press Escape or the action bar's clear button, then shift-click: also just a single toggle. - Focus a row with the arrow keys, press Shift+Space, then shift-click a lower checkbox: the range should extend from the keyboard-toggled row. - Tab to a checkbox and press Space: it should still toggle. - After a shift-click, confirm no text is highlighted across the rows. - Copy as JSON/Markdown/CSV still copies the selected rows in display order. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added shift-click range selection to the logs table for selecting or deselecting consecutive rows. - Preserved single-row selection when range selection is unavailable. - Improved selection behavior when clearing selections or changing log queries, preventing stale range anchors. - **Tests** - Added coverage for forward and reverse range selection, deselection, partial selections, fallback behavior, and input immutability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
99be7f92ce |
feat(studio): add Privacy Policy update notice (#50397)
## Summary Adds a compact Privacy Policy update notice for signed-in Studio users on organization landing pages. - Shows on `/org`, `/organizations`, and `/org/:slug` - Opens the approved policy explanation in a dialog - Links to the Privacy Policy and `privacy@supabase.com` - Persists acknowledgement in a dated local storage key - Stays off project and organization settings routes so it cannot cover product controls ## Why The Privacy Policy changes the data controller from Supabase, Inc. to Supabase Pte. Ltd. User rights and protections are unchanged. This restores the established authenticated Studio notification pattern: - [#35923](https://github.com/supabase/supabase/pull/35923): May 2025 Privacy Policy notice - [#43681](https://github.com/supabase/supabase/pull/43681) and [#43889](https://github.com/supabase/supabase/pull/43889): March 2026 Privacy Policy notice and design pass - [#45632](https://github.com/supabase/supabase/pull/45632): May 2026 Terms of Service notice - [#48524](https://github.com/supabase/supabase/pull/48524): current reusable Studio banner stack ## Release order The policy content and Studio notice deploy independently. Keep this PR in draft until [#50392](https://github.com/supabase/supabase/pull/50392) is approved, merged, and live. The notice appears immediately when this Studio change deploys. ## To test 1. Open Studio on `/organizations` or an organization project-list page. 2. Confirm the compact Privacy Policy notice appears. 3. Open **Learn more** and confirm the dialog copy and both links. 4. Select **Understood** or close the notice. 5. Reload and confirm the notice remains dismissed. 6. Remove `privacy-policy-update-2026-09-16-dismissed` from local storage and confirm the notice returns. 7. Open a project route and confirm the notice is absent. ## Verification - Prettier passes on changed files. - ESLint passes on changed Studio files. - Focused Vitest suites pass: 25 tests. - Studio Unit Tests & Build Check passes. - TypeScript & Lint, UI Tests, Studio Docker Build, dead-code, ratchet, and validation workflows pass. - All four self-hosted Studio E2E shards pass for both router implementations. - All deploy previews pass. - The Studio preview rendered the compact notice on the organization landing page without console errors. The dialog and dismissal flow still need an authenticated browser pass after the session redirected to sign-in. A direct local Studio TypeScript check reaches one existing unrelated error in `packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx`; no changed file reports an error and the required TypeScript CI workflow passes. ## Measurement Success means signed-in users can find the updated policy from the organization landing experience without interrupting project work. The dated dismissal key confirms acknowledgement locally. CI protects the non-blocking route scope, and Privacy can monitor questions sent to `privacy@supabase.com` after release. --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com> |
||
|
|
c52fca1340 |
MFA Recovery codes: enforce recovery codes generation after setting up an MFA (#50343)
## What kind of change does this PR introduce? Afters users set up an MFA, automatically generate recovery codes ## How to test - On an account that doesn't have recovery codes generated yet, add a new MFA - When you finished verifying the MFA, it should automatically open the recovery codes modal introduced in previous PRs <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved the two-factor authentication setup flow by checking the latest recovery-code enrollment status before generating codes. - Recovery codes are now generated and displayed after verification when they are enabled but not yet enrolled. - Loading indicators now reflect recovery-code status checks, providing clearer feedback during setup. - **Improvements** - Updated the recovery-code confirmation message to explain how codes can restore access after losing access to an MFA app and remind users to store them securely. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ee3fbc4e61 |
Joshenlim/fe 4383 consolidate tablerow no search result state (#50389)
### Context Just some housekeeping/consolidate refactors. There's a number of places where we render the same "no result" empty state for tables. So this PR just consolidates that into a reusable component `TableRowNoResults` to reduce duplication. Opting to save this under `components/ui` instead of the `ui` package as this is more of a derivation of `TableRow` than a primitive <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **UI Improvements** - Standardized empty search-result messages across database, functions, storage, and vector bucket tables. - Search terms now appear consistently when no matching records are found. - Added an accessible label to the vector bucket row actions menu. - Improved the storage explorer loading layout so content expands to use available vertical space. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
881a7d3151 |
fix(studio): show only the disabled reason on the invite members button (#50426)
The invite members button sits inside two Radix tooltip roots — the keyboard-shortcut tooltip and the disabled-reason tooltip — which both anchor to the same element and stack on top of each other when the user lacks invite permission. Widened the existing `tooltipOpen` condition so the shortcut tooltip stays closed whenever a disabled reason is showing, and hoisted that reason into one variable so the tooltip text and the suppression condition can't drift. Fixes FE-4393 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Disabled member invitations now prevent the invite button and keyboard shortcut from opening the invite dialog. * Invite controls display the appropriate disabled-feature or permission warning. * Shortcut tooltips are hidden when invitations are unavailable or the user lacks permission. * **Tests** * Added coverage for disabled invitations, permission warnings, dialog prevention, and shortcut tooltip visibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Fixes: https://github.com/supabase/supabase/issues/49859 |
||
|
|
7ab2a0d84f |
Fix TextConfirmModal does not reset its state (#50406)
## Problem `TextConfirmModal` does not reset its state after closing, whether users confirmed or not. If they would restart the action, the confirmation text they may have entered is kept, preventing the secure confirmation. Also fixed an accessibility issue as we didn't enable the submit button until the form was valid ## Solution Reset the form state whenever the dialog opens. ## How to test - On https://studio-staging-git-gildasgarcia-design-505-rese-196b28-supabase.vercel.app/dashboard/account/security - Either: - Add an MFA if you haven't already - Generate recovery codes if you already have an MFA - Click the _Regenerate recovery codes_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Text confirmation dialogs now reset their input whenever opened or closed, ensuring a fresh form for each use. - Confirmation actions remain available unless the dialog is processing a submission. - Copy-to-clipboard actions now provide an accessible announcement when text has been copied. - **Tests** - Added coverage for successful confirmation, cancellation, invalid submissions, input reset behavior, and recovery-code regeneration retries. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7fce0a12d9 |
feat(design-system): first pass at db report chart colours (#46787)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This is a first draft at introducing semantic colours to our Observability charts. This moves away from just random colours being assigned to prop after prop. They're only scoped to the Database reports right now, but if it flows nice, we can open it up to the other reports too. This also aims to tone down some of the harsher colours in our charts, such as the orange which sometimes can look like a warning metric/prop. | Before | After | |--------|--------| | <img width="839" height="336" alt="Screenshot 2026-06-10 at 09 14 56" src="https://github.com/user-attachments/assets/222747c5-973b-4165-aa53-df7b93412ad3" /> | <img width="950" height="341" alt="Screenshot 2026-09-14 at 18 14 47" src="https://github.com/user-attachments/assets/836f3ddd-4a97-4064-b8cf-3a3b435417ac" /> | cc @supabase/design for additional thoughts. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added semantic chart color roles with light and dark theme variants for consistent visualizations. * Standardized colors and fills across database, networking, storage, and connection charts. * Maximum-value lines now use configured chart colors when available. * Added chart palette reference and stress-test examples. * Added stacked bar charts, customizable margins, and gradient-filled line charts. * Improved multi-series bar chart focus and date-range footer alignment. * **Documentation** * Documented the chart palette, theme variants, accessibility guidance, and usage recommendations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
92fdb1d3c5 |
feat: update storage move UI (#50346)
Update path selection as destination where to move files in the Storage File Explorer. ## What is the current behavior? Currently you need to write out the entire path by hand, which is error prone and quirky. <img width="727" height="436" alt="Screenshot 2026-09-14 at 15 49 11" src="https://github.com/user-attachments/assets/2bb8fc78-d973-4b17-9343-08df23b67d2a" /> ## What is the new behavior? This PR adds a ui that lets the user select any folder as the destination of the file move. <img width="923" height="606" alt="Screenshot 2026-09-15 at 11 40 00" src="https://github.com/user-attachments/assets/2f4c50f8-3c11-4896-832e-b1e99defc9af" /> https://github.com/user-attachments/assets/261ac24e-ec24-4bcf-ad47-72bc48e27bab To test: - go to Storage File explorer and pick a file to "move" (action in the dropdown menu) - mov file to any other folder in the same bucket selecting destination folder from the ui in the dialog - both empty folder or also a folder with sub-folders can be destinations, as any selected folder becomes the active destination (notice the cta changing when selecting a folder) - batch move multiple items via multi-select (already supported, but using the updated ui now) - only folders should appear in this ui - destination folders can be searched using the search input <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Replaced the move-items path field with an interactive folder browser. - Browse, select, and search folders by name or path, with pagination and loading or empty states. - Navigate using breadcrumbs, including collapsed-path menus for deeply nested folders. - Receive warnings when folder search results are incomplete for very large buckets. - See clearer destination labels and protection against moving items to their current location. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
232ce7e68c |
docs: focus Logs on the unified view and export queryable fields (#50073)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. Yes. ## What kind of change does this PR introduce? Documentation update and a small Studio copy correction. ## What is the current behavior? The Logs guide mixes unified filtering with retired SQL Explorer instructions, and the Markdown field reference loses query semantics. ## What is the new behavior? The Logs guide mixed filtering and event inspection with the retired SQL Logs Explorer workflow. It now documents the unified Logs view: default sources, filter semantics, event details, Live, sharing, bounded exports, and missing results. The log field reference uses one mapping for HTML and Markdown, preserving source IDs, query expressions, and source/query types. The Studio User-filter empty state and comments now match its Auth and API Gateway scope. ## Additional context Validation: shared-field mapping tests, guides Markdown generation, docs typecheck, targeted docs/Studio ESLint, formatting, and browser inspection of the field table. Exported Markdown includes the source IDs and usable ClickHouse expressions. Repository-wide MDX lint has existing failures; changed pages have no reported violations. Self-review: hosted Studio filtering and log ingestion were checked against the implementation, not exercised against a hosted project. The documentation assumes the unified Logs experience is the default. Stage 1 of 3. Review and merge from the bottom of the stack. Stack: #50073 → #50074 → #50075. Production docs build also passes at the stack tip after standard reference generation. Initial CI note: the spelling action failed while building its container because Debian package downloads returned 404, before checking content. The stack has no merge conflicts. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded the log field reference with ClickHouse fields, nested-field query examples, types, schema references, and capture limits. * Reworked the Logs guide with clearer instructions for filtering, event inspection, live mode, sharing, exports, retention, and missing results. * Clarified service and Postgres log behavior and updated navigation and metadata. * **Bug Fixes** * Corrected user-filtering guidance and empty-state messaging to identify Auth and API Gateway logs as supported sources. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Steven Eubank <eubank.steven88@gmail.com> Co-authored-by: Steven Eubank <47563310+smeubank@users.noreply.github.com> |
||
|
|
e296d0ae4f |
Joshenlim/fe 4373 add ilike comparator for pathname in unified logs (#50386)
## Context In unified logs, filtering on pathname can benefit using the `ilike` comparator so this PR adds support for that <img width="423" height="247" alt="image" src="https://github.com/user-attachments/assets/31e5f09b-7506-4588-90e3-ee705f805d43" /> FilterBar is also updated to omit facet values if the selected comparator is `ilike`, otherwise it doesn't really make sense to show a dropdown of values for users to select as the value for `ilike` filtering. <img width="240" height="62" alt="image" src="https://github.com/user-attachments/assets/b5fc97e7-d826-4184-8b70-bfb4875d1822" /> The facet values should still show if the selected comparator is an equals comparator <img width="391" height="154" alt="image" src="https://github.com/user-attachments/assets/7ccded04-3db1-4406-af40-4377ffe3bd8d" /> Related to https://github.com/supabase/supabase/pull/50394 - am also updating ilike comparator logic for unified logs to implicitly wrap the provided string with `%`, but only if the string doesn't already contain a `%` or `_` for UX convenience. (Unified logs already had this behaviour, except the latter part RE omitting default `%` if string already has) - this affects pathname and event_message searching <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Added case-insensitive pathname filtering for logs with ILIKE and NOT ILIKE. * Added pathname support for comparison and pattern-matching operators. * Preserved user-provided `%` and `_` wildcard patterns in searches. * **Bug Fixes** * Corrected BigQuery pathname filtering for consistent case-insensitive matching. * Prevented misleading exact-value suggestions for pattern-based searches. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
229d04d65c |
feat(studio): give pipeline pages a standard detail header (#50253)
## What kind of change does this PR introduce? Studio page-layout polish. This follows the merged destination-brand and pipelines-list work in #50251 and #50252, and now targets `master` directly. ## What is the current behaviour? Pipeline child pages use a bespoke heading, provide limited destination context, and shift substantially while pipeline and destination data load. ## What is the new behaviour? Adds standard breadcrumbs and page-header composition, destination identity, the primary-database-to-destination path, lifecycle actions, and child-route integration. Layout-matched loading placeholders keep the header geometry stable until the resolved pipeline data is available. Removes the legacy Overview header and actions now owned by the shared page shell, and restores standard content gutters around the existing metrics and tables. Pipeline action errors are handled once by the layout, avoiding duplicate notifications from the underlying mutations. Pipeline actions are also temporarily disabled while a table reset is running to prevent conflicting requests. | Before | After | | --- | --- | | <img width="1131" height="801" alt="Replication Database ETL BigTable ETL Team Supabase" src="https://github.com/user-attachments/assets/3f0ebab0-7244-4aa1-81ac-8847f5f86d4a" /> | <img width="1131" height="801" alt="Replication Database Agua Basket Supabase" src="https://github.com/user-attachments/assets/bcbbd150-2a3d-468d-9cb9-652a6de2040b" /> | ## To test 1. Open a pipeline at `/project/<ref>/database/replication/<pipeline-id>`. 2. Confirm there is one page header with one set of actions, followed by a consistently padded Overview body. 3. Confirm the breadcrumbs, destination logo and name, status, source-to-destination path, primary lifecycle action, and overflow actions. 4. Start, stop, or restart the pipeline and confirm its status and available actions update appropriately. 5. Reset a replicated table and confirm the pipeline lifecycle, update, and overflow actions remain disabled until the reset finishes. 6. Throttle the initial pipeline and destination requests and confirm the header retains its final geometry without showing fallback data. 7. Check the page at desktop and phone widths. --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
254da82c3a |
feat: surface role risks (#50410)
## TL;DR Bolds the consequences in the Owner and Administrator role descriptions, and adds a confirmation step before an invite for either role is sent. https://github.com/user-attachments/assets/c8fb53ae-66c3-4862-865e-f2ff9fb84a8e ## ref: - recurring in the community: organizations losing access to their own projects after inviting someone as owner eg: https://discord.com/channels/839993398554656828/1545087567706193970/1545102402871492759 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a confirmation step when inviting members as Owners or Administrators. - Invitations are sent only after the elevated-role warning is confirmed. - Confirmation behavior is consistent for form submissions and keyboard-triggered invitations. - **Updates** - Refined role permission descriptions, including clearer details about elevated access and project deletion capabilities. - Improved role descriptions shown during member invitations and role selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
24f89f3967 |
MFA Recovery codes: allow users to regenerate their codes (#50336)
## What kind of change does this PR introduce? Once users have recovery codes generated, allow them to regenerate the codes. This PR also automatically check the _I have copied the codes_ after clicking the _Copy to clipboard button_. > [!NOTE] > The _Delete my recovery codes_ button only appear on local and staging environments ## How to test - On an account that already have recovery codes generated - You should see an admonition showing the remaining codes available and allowing you to regenerate the codes ## Screenshots <img width="706" height="193" alt="image" src="https://github.com/user-attachments/assets/001bfa87-74f5-4867-8564-09cb6f91adb6" /> <img width="425" height="277" alt="image" src="https://github.com/user-attachments/assets/711b139c-f806-4da2-a240-fa7e7fd8acd0" /> <img width="548" height="353" alt="image" src="https://github.com/user-attachments/assets/d6521a09-3a7f-4198-b162-9effc218fee6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a recovery-code modal with copy-to-clipboard support and confirmation before closing. - Added an option to regenerate MFA recovery codes with a confirmation step. - Recovery-code controls now appear when existing codes are available. - Added loading, success, error, and retry states for recovery-code generation and regeneration. - **Bug Fixes** - Updated the recovery-code generation error message to more accurately describe the failed action. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b824acdfd2 |
feat(project-creation): support Kubernetes cluster override for internal project creation (#49956)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature, internal ## What is the current behavior? When creating a project, the worker will use load balancing to decide where to deploy a cluster. ## What is the new behavior? An internal user can choose a specific cluster and even bypass the CORDONED state by forcing deployment. ## Additional context This PR adds kubernetesClusterId and kubernetesClusterForce to the internal-only project creation form for K8S cloud providers, gated by schema validation (provider-restricted; force requires an ID) and cleared automatically on provider change. The override is a one-time creation-time steer, not a persistent pin, and the UI copy reflects that. Includes the matching kubernetes_cluster_id/kubernetes_cluster_force request fields in the generated platform API types. <img width="1620" height="1352" alt="image" src="https://github.com/user-attachments/assets/bd8965a1-cec8-4428-aac1-46d0bf3b89d3" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Kubernetes cluster ID entry during project creation for supported cloud providers. * Added an option to force deployment to a specified cluster. * Clarified that eligible clusters must meet status and filesystem requirements. * **Bug Fixes** * Prevented invalid or outdated Kubernetes settings from being submitted when the provider or cluster selection changes. * Treated blank or whitespace-only cluster IDs as unset. * Prevented force-deployment requests without a cluster ID or for unsupported providers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fa7c223209 |
fix(studio): use Compute management endpoints FUNC-896 (#50393)
## Problem Studio still called the legacy `/workers` Management API routes and used the old `project_worker` response contract, so Compute instances could not be listed or retrieved after the API rename. The production API type check also detected drift in the v1 and platform declarations. ## Fix - Regenerate the v1, v2, and platform API declarations from the deployed schemas. - Update Studio list and detail queries to `/compute`. - Align typed fixtures with the Compute response schemas and `project_compute_instance` resource type. - Update platform response type references to the generated `_Output` schema names. ## How to test - Run `pnpm api:verify-types`. - Run `pnpm --filter api-types test`. - Run `pnpm --filter studio test data/compute/compute.utils.test.ts "tests/pages/project/[ref]/compute/index.test.tsx"`. - Run `pnpm --filter studio typecheck`. - Run `pnpm --filter common typecheck`. - Run `pnpm --filter studio lint:ratchet`. Expected result: production API declarations are synchronized, and Studio requests the `/compute` list and detail endpoints and renders `project_compute_instance` responses successfully. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated API response handling across profiles, backups, notifications, integrations, warehouses, access tokens, payments, and other Studio workflows for more accurate serialized data. * Compute instance pages and queries now use the compute-specific API endpoints and response data. * Improved feature-flag type handling when disabled feature data is unavailable. * **Tests** * Updated automated coverage and fixtures to reflect current compute and API response formats. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c228ca4f61 |
fix(studio): restore function deployment annotations FE-3921 (#50362)
## Problem The Edge Function overview converted the numeric deployment timestamp to a string before parsing it as a date. This produced an invalid date, so the invocations chart omitted the deployment annotation. ## Fix Preserve the numeric timestamp returned by the API and allow the annotation helper to parse both numeric and string timestamps. Show deployment details in an accessible tooltip when hovering or focusing the rocket marker, and add regression coverage for numeric timestamps and the existing invalid, missing, and out-of-range cases. ## How to test - Run the focused EdgeFunctionOverview utility test suite. - Open an Edge Function whose latest deployment is within the selected chart interval. - Hover or focus the rocket marker. - Expected result: the invocations chart shows the dashed deployment line and rocket marker, and the marker tooltip shows the deployment time. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Invocation update annotations now display correctly when function update times are provided as numbers. - Timestamps at the start of the Unix epoch are now supported. - Annotations no longer appear when update times are invalid or chart data is incomplete. - **Accessibility** - Deployment markers in invocation charts are now keyboard-focusable and include accessible labels. - Deployment timestamps are available in a tooltip on hover or focus. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4b24548345 |
Fix sync between filter bar and filter controls in unified logs (#50383)
### Context In unified logs, adding a filter to the filter bar (e.g filtering on log type) doesn't sync with the filter controls in the left menu (although it does the other way around). Example here filtering on log type to equals to edge (API Gateway) <img width="400" alt="image" src="https://github.com/user-attachments/assets/080aba77-3366-4530-8443-3c8902aefd20" /> Both filter bar and filter controls share the same URL state with nuqs, and it comes in 2 shapes: - a bare `string[]` for = conditions - a wrapped `{ operator, values }` object for other operators The filter bar didn't follow this convention for the first one as it always wrote the wrapped object which made the checkbox appear untickets on the filter controls (which expects the first one) - this always caused the filter to show up as `[object Object]` if you add a log type filter via the filter bar first, then check the same log type filter in the filter controls. ### Changes involved Am opting to streamline the expected data shape and have both components always expect the wrapped object shape so we don't have to deal with 2 different shapes (feels unnecessary) ### To test - Verify that applying a log type filter (e.g postgres) in the filter bar should reflect the checkbox for the same log type filter in the filter controls on the left to be checked as well - Unchecking the checkbox in the filter controls should thereafter remove the filter in the filter bar too <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Unified Logs filters now use a consistent operator-and-values format across filtering controls. - Checkbox filters preserve operators when selecting multiple values or using **Only**. - Mixed filter conditions are handled more consistently, with unsupported values ignored. - Non-text filter values are converted consistently for reliable filtering. - **Bug Fixes** - Improved consistency when applying, displaying, and updating Unified Logs column filters. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
63bedef77f |
MFA Recovery codes: allow users to download their recovery codes (#50267)
## What kind of change does this PR introduce? After users have set up a new MFA (first or not), we must: - check whether recovery codes have already been generated - if there are none, generate recovery codes and display them, "forcing" users to copy them - if already generated, show them how many are still available > [!NOTE] > The _Delete my recovery codes_ button in last screenshot only appear on local and staging environments ## How to test - On an account that doesn't have recovery codes generated yet and has an MFA added - You should see an admonition suggesting to generate the codes ## Screenshots <img width="729" height="306" alt="image" src="https://github.com/user-attachments/assets/79ba3870-4ef8-4571-9fd6-36eed20c9c24" /> <img width="550" height="356" alt="image" src="https://github.com/user-attachments/assets/1632611a-996a-470d-b6cd-a4693b0f4602" /> <img width="719" height="205" alt="image" src="https://github.com/user-attachments/assets/73cef611-05cf-4fac-bbd2-243f9b28e48d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added support for generating, copying, and confirming MFA recovery codes. - Added recovery-code status visibility, including remaining and exhausted codes. - Added the ability to delete recovery codes with confirmation. - Added clear loading, success, and error states for recovery-code actions. - Recovery-code status refreshes after codes are generated or deleted. - **Bug Fixes** - Recovery-code notices now remain visible when all codes have been used. - Recovery-code dialogs can now be closed after generation errors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
24f8549e41 |
fix(studio): open edge function logs from chart clicks FE-3922 (#50364)
## Problem Clicking an invocation bar on the Edge Function overview did not preserve the selected chart segment, so the destination could not open a focused investigation window. ## Fix Forward the clicked bar timestamp and navigate to Logs or Invocations with an encoded, focused time range. Share the existing chart range calculation and add real Recharts interaction coverage. ## How to test - Open an Edge Function Overview page with invocation data. - Click a populated bar in the Total Invocations chart. - Expected result: Logs or Invocations opens with its and ite query parameters centered on the clicked bar. - Repeat with unified logs enabled and disabled to verify both destinations. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Clicking a bar in the Edge Function invocations chart now opens the relevant logs or invocations view. - The destination is focused on a time window surrounding the selected invocation, making investigation faster. - Chart bars now provide a pointer cursor to indicate they are interactive. - **Bug Fixes** - Chart clicks without valid invocation data no longer trigger incorrect navigation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
56820eb048 |
fix(studio): use configured gp3 max-throughput ceiling (#50355)
`calculateMaxThroughput` still hard-capped at 1000 MB/s while `DISK_LIMITS.gp3.maxThroughput` moved to 2000, so large gp3 disks were rejected with a misleading "Need at least N IOPS to support X MB/s" error even when IOPS and compute were already sufficient. Now reads the configured ceiling, mirroring the IOPS fix in #50269 that missed this sibling. Fixes FE-4385 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - GP3 storage configurations can now support throughput scaling up to 2,000 MB/s when sufficient compute capacity is available. - Larger GP3 configurations, including up to 4,096 GB with 80,000 IOPS and 2,000 MB/s throughput, are now recognized as valid when capacity requirements are met. - **Bug Fixes** - Corrected the maximum GP3 throughput calculation to honor the supported service limit. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ad5202d53d |
Joshenlim/fe 4378 update editorpanel save cta when explorer is enabled (#50324)
## Context Swaps out the "Save as snippet" CTA in the `EditorPanel` to the "Save to notebook" dropdown CTA if explorer is enabled <img width="488" height="147" alt="image" src="https://github.com/user-attachments/assets/915017a1-c416-4904-8146-b0695244d2bd" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a save-query dropdown in Explorer for creating a new notebook or adding a query to an existing notebook. * Added notebook search, loading states, and empty-state messaging when selecting an existing notebook. * Saved queries now open in the selected notebook after insertion. * **Improvements** * Added an accessible label to the query title input. * Updated query-saving controls to appear appropriately when Explorer is enabled. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
17280319f0 | chore(billing): remove invoice type casts (#50338) | ||
|
|
558bee9ebf |
Improve SQL Editor auto completion for column names (#48734)
## Context Currently with the SQL Editor, the auto-completion via intellisense only works nicely with the `.` operator - e.g after keying in a schema and trying to find a table as such: <img width="500" alt="image" src="https://github.com/user-attachments/assets/86ec8455-47b9-43d3-925a-c13d0fd6ac44" /> But lacks support for finding the columns of a table after a `where` clause - so the changes here addresses that by mainly adjust the `PgSQLCompletionProvider` Also addresses a number of type fixes (replaces all the `any` types) <img width="500" alt="image" src="https://github.com/user-attachments/assets/e23672a6-2b48-4a98-b300-69f822d12b38" /> <img width="415" height="319" alt="image" src="https://github.com/user-attachments/assets/e6ee64d2-90dd-47d6-9fd2-e8b07821ebb6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved PostgreSQL SQL editor suggestions with table, column, alias, schema, and join-aware completions. * Added context-aware support for statements, quoted identifiers, subqueries, and qualified columns. * Enhanced PostgreSQL function signature assistance. * Added safer behavior when database metadata is incomplete or unavailable. * **Bug Fixes** * Prioritized relevant columns and removed duplicate suggestions. * **Tests** * Added comprehensive coverage for SQL parsing, metadata handling, and completion behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1755580dcf |
feat(studio): move Warehouse setup into Integrations (#50247)
## What kind of change does this PR introduce? Feature and information architecture change. Builds on #50246. ## What is the current behaviour? Warehouse setup, progress, errors, table selection, and connection details all live in the transient Connect sheet. Closing the sheet hides the current replication state, and the integration is absent from the Integrations page. ## What is the new behaviour? Warehouse now has a persistent Overview page at `/project/{ref}/integrations/warehouse/overview`: - Before setup, the existing schema and table picker enables Warehouse. - During setup, the page shows the current phase and per-table backfill state where available. - Setup and status failures remain visible on the page with retry actions where possible. - Once complete, the page shows Status, Tables, then Connect. - The Connect sheet becomes read-only. Before Warehouse is ready, it links directly to the Overview page for setup, progress, or recovery. | Before | After | | --- | --- | | <img width="1200" height="907" alt="Chives Pantry Supabase" src="https://github.com/user-attachments/assets/82dc7fb0-3859-499e-96ab-56f70a5c7325" /> | <img width="1200" height="907" alt="Chives Pantry Supabase" src="https://github.com/user-attachments/assets/7428e301-27f8-48fe-91e0-6880b132920d" /> | | <img width="1200" height="907" alt="Chives Pantry Supabase" src="https://github.com/user-attachments/assets/82dc7fb0-3859-499e-96ab-56f70a5c7325" /> | <img width="1200" height="907" alt="54709" src="https://github.com/user-attachments/assets/0c589e5b-e13c-4554-a6ee-6730d0e95c07" /> | | <img width="1200" height="907" alt="ETL BigTable ETL Team Supabase" src="https://github.com/user-attachments/assets/18ec9f6c-3724-453f-bbbb-c7149758246e" /> | <img width="1200" height="907" alt="Regular AWS Teamer Supabase" src="https://github.com/user-attachments/assets/3819c9fe-e56d-4cec-988d-5e724f8d990a" /> | ## To test Use a project whose organisation is included in the Warehouse allow-list. 1. Open `/project/{ref}/integrations`, filter by **Data platform**, and open Warehouse. 2. Before setup, confirm the existing schema and table picker appears and starts with no tables selected. 3. Start setup and confirm the Status section polls through setup and table backfill phases. 4. Confirm setup failures remain visible and expose Retry when the API returns affected tables. 5. After setup, confirm the section order is Status, Tables, Connect. 6. Confirm existing replicated tables are selected and locked, while additional tables can be added. 7. Open `/project/{ref}?showConnect=true&connectTab=warehouse` and confirm it links to the Overview page before setup, during setup, and after a setup failure. 8. Once setup is complete, confirm the Connect sheet shows the FlightSQL and DuckDB connection controls from #50246. 9. Repeat the Overview checks with **One-Click Integrations** turned off. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Supabase Warehouse to the integrations catalog, with overview documentation and availability-aware display. * Added Warehouse setup and management flows, including schema and table selection, replication progress, status details, connection options, and retry actions. * Added DuckDB and FlightSQL engine selection with Connect sheet URL and preference synchronization. * Added table replication status, lag, timestamps, and size information. * **Bug Fixes** * Warehouse setup status requests no longer retry automatically after failures. * Improved recovery messaging and retry behavior for setup and connection errors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
ad198b15ab |
Joshenlim/fe 4376 improve storage log overview and field filtering (#50337)
## Context Updates the `getValue` for retrieving data from `enrichedData` in `serviceFlowFields` to pull the appropriate fields for storage logs. ### Before <img width="403" height="342" alt="image" src="https://github.com/user-attachments/assets/b9a8e501-79bc-4ed2-ad1e-dd57f55a091e" /> ### After <img width="413" height="411" alt="image" src="https://github.com/user-attachments/assets/8e87c352-ecf8-4246-b5b7-3b4d16274b06" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Expanded log details to display more network, location, technology, and storage information from available request and response data. * Added support for additional response-time formats, including valid zero-duration values. * **Bug Fixes** * Improved truncation and alignment of log detail values. * Enhanced accessibility for the “More options” control. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2e435986c9 |
feat(studio): polish the Replication pipelines list (#50252)
## What kind of change does this PR introduce? Studio UI and interaction polish. This is the second PR in the Pipelines review stack and depends on #50251. ## What is the current behaviour? Pipeline rows require a separate view action, cannot be sorted, and present lifecycle, lag, and destination terminology inconsistently. ## What is the new behaviour? Makes rows navigable with link-like mouse and keyboard behaviour, adds Name and Status sorting, reuses cached status queries, and moves row actions into the overflow menu. It also clarifies pipeline terminology, adds Docs and feedback actions, and standardises state, error, lag, and loading presentation with accessible announcements. | Before | After | | --- | --- | | <img width="1280" height="1323" alt="Replication Database ETL BigTable ETL Team Supabase" src="https://github.com/user-attachments/assets/53a62283-0e58-4408-8409-2b87a38af159" /> | <img width="1280" height="1323" alt="Replication Database Agua Basket Supabase" src="https://github.com/user-attachments/assets/ba4de1e0-4a84-43b4-8975-ca05a3056bcf" /> | ## To test 1. Open `/project/<ref>/database/replication`. 2. Sort by Name and Status, then confirm failed and stopped pipelines surface first when Status is ascending. 3. Click a row, use Enter or Space, and modifier-click or middle-click to verify link behaviour. 4. Open the row overflow menu and confirm it does not navigate. 5. Check loading, initial sync, caught up, numeric lag, unavailable lag, and table-error states where available. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added sortable pipeline lists with clearer loading, empty, and error states. - Pipeline rows now support direct navigation, detail viewing, status indicators, lag progress, and table error summaries. - Added initial-sync progress indicators and accessible status announcements. - Added documentation and feedback links. - Improved pipeline version update and enable/disable dialogs. - **Bug Fixes** - Prevented right-clicks from triggering navigation. - Improved unavailable lag and initial-sync handling. - **Style** - Standardized replication terminology and confirmation messaging around pipelines. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
74c116de74 |
docs: add Multigres Public Alpha documentation — MERGE ON SEP 14, 2026 (#49020)
## I have read the CONTRIBUTING.md file. YES ## What kind of change does this PR introduce? This PR adds Public Alpha documentation for Multigres, Supabase's multi-node Postgres high-availability integration. It introduces an overview guide, a compatibility stub, Database sidebar navigation, a Features table row, and a "What you get" card grid. ContentListings items can now omit `href` so those cards are not forced to be links. Linear: MUL-452. ~~🚨 **DO NOT MERGE UNTIL THE PUBLIC ALPHA GOES LIVE** 🚨~~ [@jhydra12 OK'ed merging, FYI] ## What is the current behavior? - Linear item: Documentation for Multigres - Production has no Multigres guides. `https://supabase.com/docs/guides/database/multigres` and `https://supabase.com/docs/guides/database/multigres/compatibility` return 404 - The Database sidebar has no Multigres section - The Features status table does not list Multigres - ContentListings items required a link (`href` was mandatory) ## What is the new behavior? - Overview guide at `/docs/guides/database/multigres` covering alpha status, eligibility, enablement, and what is not included - Compatibility stub at `/docs/guides/database/multigres/compatibility` - Database sidebar: Multigres → Overview, Compatibility (after OrioleDB) - Features table: Database / Multigres / `public alpha` - "What you get" renders as three non-link ContentListings cards - `href` is optional on ContentListings items; markdown export renders unlinked entries when it is omitted ## Additional context - Worktree: ~/GitHub/supabase/supabase-worktrees/nikrichers/mul-452-documentation-for-multigres-ready - Branch commits: Initial Multigres docs draft; Edits (cards, copy, MDX comments); merge master; spelling allow-list for Multigres, Vitess, and sharding - Verification: | Check | Result | | --------------------------------------- | --------------- | | Preview overview | 200 | | Preview compatibility | 200 | | Production overview | 404 (expected) | | Production compatibility | 404 (expected) | | `supa-mdx-lint` on changed MDX | pass | | `vitest` `lib/content-listings.test.ts` | pass (21 tests) | ### Proof: Multigres docs pages render, including non-link What you get cards **Verified:** production 404 · Vercel docs preview 200 #### Overview [(PR preview)](https://docs-git-nikrichers-mul-452-documentation-for-m-6f8a59-supabase.vercel.app/docs/guides/database/multigres) <img width="1388" height="2272" alt="image" src="https://github.com/user-attachments/assets/2780f728-07c0-4320-9826-8f6e68df21e6" /> #### Compatibility [(PR preview)](https://docs-git-nikrichers-mul-452-documentation-for-m-6f8a59-supabase.vercel.app/docs/guides/database/multigres/compatibility) <img width="1388" height="852" alt="image" src="https://github.com/user-attachments/assets/1f8f7181-5b7d-4d01-b376-a2eac923626b" /> ### Test plan - [ ] [Production overview](https://supabase.com/docs/guides/database/multigres) (404) vs [preview overview](https://docs-git-nikrichers-mul-452-documentation-for-m-6f8a59-supabase.vercel.app/docs/guides/database/multigres) - [ ] [Production compatibility](https://supabase.com/docs/guides/database/multigres/compatibility) (404) vs [preview compatibility](https://docs-git-nikrichers-mul-452-documentation-for-m-6f8a59-supabase.vercel.app/docs/guides/database/multigres/compatibility) - [ ] Database sidebar shows Multigres → Overview and Compatibility after OrioleDB - [ ] Overview shows Public Alpha caution, three What you get cards (not links), eligibility, and one-way-migration caution - [ ] Compatibility page is a placeholder that links back to the overview - [ ] Features table lists Database / Multigres / `public alpha` - [ ] `supa-mdx-lint` on `apps/docs/content/guides/database/multigres.mdx`, `apps/docs/content/guides/database/multigres/compatibility.mdx`, and `apps/docs/content/guides/getting-started/features.mdx` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Multigres documentation covering availability, setup, compatibility, limitations, migration behavior, and external resources. * Added Multigres to database navigation and feature-status listings. * Added an overview of Multigres benefits, including automatic failover, unchanged connection strings, and consensus-backed write durability. * **Improvements** * Content listings now support informational items without links across layouts. * Improved listing rendering and click tracking for linked and non-linked items. * **Documentation** * Added spelling support for Multigres, Vitess, and sharding terminology. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> Co-authored-by: Cursor Agent <cursoragent@cursor.com> |
||
|
|
8bbd1d3048 |
fix(studio): fall back to unified preset for an unrecognized query-performance preset (#50348)
## Summary
- `useIndexInvalidation()` resolves the `preset` URL param through
`QUERY_PERFORMANCE_PRESET_MAP` with no fallback.
- A value that isn't one of the four known
`QUERY_PERFORMANCE_REPORT_TYPES` (stale bookmark, hand-edited URL, a
renamed/removed preset) resolves to `undefined`.
- That `undefined` preset flows into `generateQueryPerformanceSql()`,
which indexes `queryPerfQueries.queries[preset]` with it, producing
`undefined` for `baseSQL` — and the very next line reads
`baseSQL.queryType`, crashing the whole page via `globalErrorBoundary`.
- Fix: fall back to the `unified` preset when the URL value doesn't map
to a known preset, mirroring the `parseAsString.withDefault('unified')`
intent already expressed a few lines above for the case where the param
is entirely absent.
## Evidence (Sentry, past week)
- [SUPABASE-APP-K9Z](https://supabase.sentry.io/issues/7721026586/) —
`TypeError: Cannot read properties of undefined (reading 'queryType')`
on `/dashboard/project/[ref]/observability/query-performance`.
## Test plan
- [ ] Existing `useQueryPerformanceQuery.test.ts` suite still passes
- [ ] Manually confirmed
`QUERY_PERFORMANCE_PRESET_MAP[QUERY_PERFORMANCE_REPORT_TYPES.UNIFIED]`
resolves to `'unified'`, a valid key in
`PRESET_CONFIG[Presets.QUERY_PERFORMANCE].queries`
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM
---
_Generated by [Claude
Code](https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM)_
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
|
||
|
|
32f17f994d |
fix(studio): key query chart series by position, not column name (#50270)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. Hardening ahead of any decision to enable session replay. ### What's inside - ~47 lines of logic: positional series keys, the X-key collision guard, and the rewiring of rows, cumulative results and axis width ([QueryResultChart.tsx](https://github.com/supabase/supabase/pull/50270/changes#diff-dae994728613498678bcc06a3ea5176b36708e06b531cfc7eddae3e588fff528)) - ~123 lines of tests, one case per chart type, cumulative setting and edge case ([QueryResultChart.test.tsx](https://github.com/supabase/supabase/pull/50270/changes#diff-6e1c92ad725bac0324db4d079f3d0cd061b8f6e2aecdc21bcdc5969c90dc3c59)) ## What is the current behavior? Session replay is disabled in every environment, and no recordings exist. This is about what a recording *would* contain if it were ever switched on: charting a query result would put the customer's own column names into it. `ChartContainer` writes every chart config key into a `<style>` element as `--color-<key>`. rrweb records `<style>` text verbatim: ```js u = "STYLE" === parentTagName || void 0 h = "SCRIPT" === parentTagName || void 0 !u && !h && o && r && (o = maskTextFn ? maskTextFn(o, parent) : o.replace(/\S/g, "*")) ``` The `!u` guard means `maskTextFn` never sees stylesheet text. It is a text node, so `maskAttributeFn` does not see it either. CSS written into the DOM is a channel no masking hook reaches. `QueryResultChart` keyed its config by the column names picked for the Y axis, which come from the customer's own SQL results. With recording enabled, a query charting a column named `customer_email` would produce `--color-customer_email` in the captured DOM. Linear [GROWTH-1229](https://linear.app/supabase/issue/GROWTH-1229). #48818 masks the attribute channel. This channel is text, so that PR does not reach it. ## What is the new behavior? Y series are keyed by position (`series_0`, `series_1`), so no customer string reaches the config keys. The column name still goes through as `config[key].label`, which `chart.tsx` renders into the tooltip and legend as text. Text nodes outside `<style>` are masked by `maskReplayText`, so the name is safe there and the chart stays readable. The X column keeps its own name. Only config keys reach the `<style>` and the X column is never one, so renaming it would buy nothing, and it would cost the `timestamp` handling: `ChartBar` and `ChartLine` branch on `xKey === 'timestamp'` to format tooltip dates and render the date-range footer. Keeping the original name needs one guard, since an X column literally named `series_0` would share a row key with the first Y series. `xKeyFor` appends underscores until the two are distinct. ## Additional context ### Testing Eleven tests. They assert the rendered `<style>` contains `--color-series_0` and does not contain the column name, across both chart types and both cumulative settings, plus the two-series case, the `timestamp` column and the collision guard. Three are verified to catch the defect they cover: the style-key assertion fails against the unfixed component, the `timestamp` assertion fails when the X key is pinned to a constant, and the `xKeyFor` cases fail when the guard's body is removed. `vitest run components/interfaces/Explorer` passes: 170 tests across 16 files. The tooltip and legend path isn't asserted, because recharts doesn't render either one at the 0x0 size jsdom gives the container. That the label is what renders there comes from reading `chart.tsx`. It is unverified at runtime. ### Remaining exposure Every other `ChartContainer` caller passes literal keys (`--color-error`, `--color-ok_count`), and `UnifiedLogs` filters a static config by a fixed level set, so this was the only caller feeding it customer strings. `chart-bar.tsx:119-124` and `chart-line.tsx` still fall back to building a config from whatever `dataKeys` they're given, so a future caller can reintroduce this without touching `QueryResultChart`. A general guard would have to live in `ChartContainer` or in the replay config. CSSOM writes (`insertRule`, `replace`, `replaceSync`, adopted stylesheets) also emit CSS outside both masking hooks. This PR does not close that path. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved query result charts to preserve the source column name used for the X-axis. - Prevented X-axis names from conflicting with generated series identifiers. - Ensured bar and line charts consistently bind data to the correct X-axis and series. - Preserved timestamp-based chart behavior, including the date-range footer. - Chart series styling now uses stable positional identifiers, ensuring colors remain correctly assigned across configured series. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4aa34f556a |
feat(studio): mcp secrets interstitial polish (#50351)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - We made the Next step copy a bit more generic so it doesn't read like it's pointing you back to Inspector UI. - Added CTA on key stored screen to send you to Edge Function Secrets directly. - Tidies up footer area to always be centrally aligned across all states. ### 1. Enable the feature flag ### 2. Preview states via URL Mock mode is enabled automatically in local/staging. Navigate to `/mcp/secrets` with a `state` query param: http://localhost:8082/mcp/secrets?state=<state> States that need no other params: | `state` value | What it shows | | ----------------- | --------------------------------------- | | `loading` | Loading skeleton | | `expired` | Link expired | | `cancelled` | Request cancelled | | `paused` | Storing keys paused | | `wrong-account` | Signed in as the wrong account | | `error` | Generic failure | States that need a real project —ame=<KEY_NAME>`: | `state` value | What it sh | | -------------------- | ---------------------- | | `form` | The "st | | `stored` | Success | | `stored-timeout` | Successopped waiting | | `already-stored` | Key was already stored, nothing to do | Example: http://localhost:8082/mcp/secretsJECT_REF&name=OPENAI_API_KEY ### 3. What to check - [ ] `stored` / `already-stored`tions secrets"** button linking to `/project/<ref>/functions/secrets - [ ] States without a project re `paused`, `error`) don't show that button - [ ] Footer text is centered on - [ ] `wrong-account` → **Switch its footer is centered - [ ] The provider-dashboard link` state, use a `name` like`OPENAI_API_KEY` or `RESEND_API_Khint) is centered too <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a project-specific link to Edge Functions secrets from the MCP setup screen when a project is available. * Added a separator to distinguish the secrets link from the remaining setup guidance. * **Improvements** * Updated completion guidance to tell users to return to their agent and confirm the setup is finished. * Standardized interstitial footer content with centered guidance and consistent provider dashboard instructions. * **Tests** * Added coverage for displaying the project-specific secrets link and hiding it when no project is associated. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
c9e035910d |
Add HA toggle to enabled features (#50344)
## Context As per PR title - flags the HA toggle in project creation form behind a flag in enabled-features Behaviour should be status quo for both staging and prod <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a high-availability option to the project creation flow for eligible accounts when the feature is enabled. * The option is available through controlled feature configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5104754018 |
Fix types master (#50345)
## Context Just needed to adjust the API types import - the name likely changed somewhere `AnalyticsResponse` -> `AnalyticsResponse_Output` Verified the typecheck locally <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Updated analytics test typing to align with the current analytics response schema. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
35f2eeefcf |
fix(observability): replace egress chart with usage link FE-4310 (#49850)
## Problem The Network Traffic egress chart is derived from request logs and can substantially undercount billed traffic. Showing it beside diagnostic ingress data left customers with an untrustworthy egress number. ## Fix Remove the log-derived egress chart, retain ingress, and add a Billable egress callout that links to the selected organization’s Usage page. The callout is shown only on hosted Studio, where organization billing data is available. ## How to test - Open API, Storage, Auth, or PostgREST observability. - Confirm Network Traffic shows only the ingress chart. - Confirm the Billable egress callout links to the organization Usage page’s egress section. - Expected result: diagnostic traffic and billable usage are no longer presented as competing egress totals. - Automated checks: git diff --check and final code review passed. Focused lint could not run because missing dependencies require registry access, and DNS for registry.npmjs.org is unavailable. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Clarified Network Traffic report tooltips to explain that ingress is measured from request logs. * Platform deployment reports now display ingress data only; egress charts are no longer shown. * Added a notice linking to the Usage page for billable egress details. * Applied the updated Network Traffic explanation consistently across API overview, storage, and shared report views. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d2ed60da27 |
fix(auth): migrate overview errors to clickhouse (#50174)
## Problem
Auth overview error tables call the legacy logs endpoint through
fetchLogs defaults, even with the ClickHouse migration enabled.
Success-rate cards also show zero when there are no requests and
misleading relative changes between small rates.
## Fix
Select matching BigQuery or ClickHouse queries with otelLegacyLogs,
separate caches by engine, and normalize numeric results.
Show No data for success rates without requests and omit comparisons
when either period has no requests. Show success-rate changes in
percentage points: 0% to 0.2% displays +0.2 pp. Omit undefined relative
changes from a zero baseline for activity and sign-up counts. Show
explicit errors for failed log requests, including error payloads
returned with HTTP 200, instead of empty tables.
## Validation
- Auth overview error tables compared against staging with matching
data.
- 84 focused tests passed across four suites, including 25 direct
formatter tests.
- 12 MSW integration tests exercise both endpoint/SQL pairs, HTTP and
embedded API failures, and rendered No data, genuine 0%, and +0.2 pp
states.
- Unit tests cover missing periods, zero requests, percentage-point and
relative changes, SQL structure, and numeric result parsing.
- Formatting and diff checks passed; code review found no actionable
issues.
- Full local lint/typecheck are limited by shared checkout dependencies.
Browser comparison confirmed the deployed rate display uses percentage
points and shows No data without a comparison for absent server
requests; populated error rows match staging. The final formatter
extraction (
|
||
|
|
38e8f12b1b |
fix(studio): gate homepage health advisor (#50328)
## Problem Health Advisor results appear on the project homepage whenever the main `healthAdvisor` flag is enabled, so the homepage cannot be rolled out separately. The existing gates also contain redundant boolean and platform checks. ## Fix Require both `healthAdvisor` and `healthAdvisorInHomepage` before fetching or displaying health advisories on the homepage. Simplify all Health Advisor gates to use the boolean ConfigCat flag directly, including the cleanup requested in the review of #50326. ## How to test - Enable only `healthAdvisor` and verify Health Advisor remains available outside the homepage while health results do not appear or load on the homepage. - Enable both flags and verify health results appear on the homepage. - Disable `healthAdvisor` and verify Health Advisor remains unavailable everywhere. - Existing targeted tests pass: 5 tests across Advisor menu and panel integration suites. - Prettier and whitespace checks pass. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Health Advisor is now available in non-platform environments when enabled. * Navigation, filtering, lint checks, and project pages consistently follow the Health Advisor feature setting. * Self-hosted environments can use the Health Advisor category. * **Bug Fixes** * Homepage Health Advisor visibility now follows both the Health Advisor and homepage-specific settings. * Updated empty states and health lint results to match the configured availability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6f15081892 |
Scoped PAT: show dependencies between permissions (#50271)
## Problem Some permissions require others to actually have an effect, for instance: - `api_gateway_keys_secret_read` requires `api_gateway_keys_read` or `api_gateway_keys_write` - `data_api_config_secret_read` requires `data_api_config_read` or `data_api_config_write` This is not obvious from a user perspective. ## Solution We decided to make these requirements explicit by: - Adding a line in the permission item stating the dependency - Disabling the permission if its dependency isn't met - Resetting the permission if it was selected but the dependencies aren't met anymore ## How to test - On [staging](https://studio-staging-git-gildasgarcia-fe-4380-dashboa-b2a227-supabase.vercel.app/dashboard/account/tokens) - Create a new token - Check that _API Key Secrets_ is greyed out and disabled - Select _API Key_ read or read-write - _API Key Secrets_ shouldn't be greyed out and disabled - Select a value for _API Key Secrets_ - Set _API Key_ to none - Check that _API Key Secrets_ is greyed out, disabled and reset to none too <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added dependency-aware permissions for scoped access tokens. - Permission descriptions now show required dependencies and permission levels. - Dependent permissions automatically reset to “None” when requirements are not met. - Permission controls and unavailable selections reflect dependency requirements. - **Accessibility** - Screen readers now receive an announcement when a permission is reset to “None” due to unmet dependencies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
519a3a5644 |
fix(studio): gate health advisor behind feature flag (#50326)
## Problem Health Advisor runs checks and displays health alerts without a dedicated rollout flag. ## Fix Gate Health Advisor behind the ConfigCat `healthAdvisor` flag, defaulting to off when missing or loading. This covers the navigation and shortcut, command menu, direct page access, homepage alerts, Advisor panel filters and details, and health-check requests. Cached health results and saved Health filters no longer surface health content when disabled. Existing platform-only restrictions remain. The `healthAdvisor` flag will be created separately in ConfigCat. ## How to test - With `healthAdvisor` off, verify Health Advisor is absent from navigation, command search, homepage alerts, and Advisor panel categories. Opening `/project/<ref>/advisors/health` shows an unavailable message. No health-check POST requests should run. - With the flag on for an active platform project, verify these surfaces return and health checks load. - Disable the flag after loading health results and selecting the Health filter or an alert. Verify cached health alerts disappear and the panel remains usable. - Existing menu tests pass. No new feature flag tests are included. Formatting and whitespace checks passed. - Local lint could not start because the available dependency installation is missing `@eslint/compat`. Full TypeScript validation failed with missing dependencies and incompatible workspace types in the reused local dependency installation; it did not provide a clean validation result. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Health Advisor availability is now controlled by a feature flag on the platform. * When enabled, health advisories appear in advisor menus, filters, project checks, and empty-state messaging. * When unavailable, the Health Advisor page clearly indicates that it isn’t available for the project. * **Bug Fixes** * Health advisory data is no longer requested when the feature is disabled, preventing unavailable health results and errors from appearing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4dd8a95f0b |
feat(studio): polish Warehouse connection methods (#50246)
## What kind of change does this PR introduce? Feature polish and a connection behaviour change. ## What is the current behaviour? The Warehouse Connect sheet presents FlightSQL and DuckDB configuration together. Enabling Warehouse also enables DuckDB catalogue access automatically, even when the user only needs FlightSQL. ## What is the new behaviour? The Connect sheet now starts with a query engine selector: - FlightSQL shows the endpoint, connection string, user, password action, and command-line example. - DuckDB shows a persistent catalogue access switch. When enabled, credentials and the attach script appear as the same numbered "Follow these steps" flow used by other connection methods. - Switching back to FlightSQL removes the DuckDB instructions. > [!NOTE] > This is an incremental change towards [this UI](https://linear.app/supabase/project/warehouse-core-mvp-b85711dc2eff/activity#project-update-4e3183e1), where the Integrations page is the control plane and Connect sheet is simply for read-only connect values. https://github.com/supabase/supabase/pull/50247 and https://github.com/supabase/supabase/pull/50195 are subsequent PRs that get us there. > [!IMPORTANT] > Enabling Warehouse no longer enables DuckDB catalogue access automatically. DuckDB users must enable it explicitly from the connection details. FlightSQL is unaffected. This keeps global Warehouse provisioning separate from optional credentials for one query engine. It also prevents successful Warehouse setup from being followed by a secondary catalogue mutation that can fail independently. | Before | After | | --- | --- | | <img width="1280" height="1323" alt="10752" src="https://github.com/user-attachments/assets/83b1069b-a262-4068-a5e3-b7f49860fdb2" /> | <img width="1280" height="1323" alt="Regular AWS Teamer Supabase" src="https://github.com/user-attachments/assets/86ff1fe4-6513-44a8-88e1-1c7985f4910e" /> | | <img width="1280" height="1323" alt="10752" src="https://github.com/user-attachments/assets/83b1069b-a262-4068-a5e3-b7f49860fdb2" /> | <img width="1280" height="1323" alt="31254" src="https://github.com/user-attachments/assets/733f074d-a52a-44a6-8898-a8f3c2b68294" /> | | _Unable to replicate._ | <img width="1280" height="1323" alt="Regular AWS Teamer Supabase" src="https://github.com/user-attachments/assets/c7d4ee59-b3f0-48b0-a6d7-2202ef5c2609" /> | ## To test 1. Open `/project/{ref}?showConnect=true&connectTab=warehouse` on a project. Enable Warehouse on 1+ table. 2. Confirm FlightSQL is selected initially and its connection fields are visible. 3. Select DuckDB and confirm the catalogue switch is always visible. 4. Enable catalogue access and confirm the environment variables and SQL appear below in two numbered steps. 5. Switch back to FlightSQL and confirm the DuckDB steps disappear. 6. Set up Warehouse on a project where it is not yet enabled and confirm DuckDB catalogue access is not enabled automatically. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a query-engine selector for FlightSQL and DuckDB connection setups. * Added guided DuckDB setup steps, copy-to-clipboard support, and reveal/hide controls for secrets. * Added a catalog access toggle with confirmation feedback. * Catalog details load only when DuckDB is selected. * **Updates** * Streamlined warehouse connection layouts with consistent spacing. * Catalog access is now controlled separately from the initial warehouse setup. * Excluded sensitive setup details from copied prompts and added copy-status announcements. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
ffc76c1e36 |
feat(studio): give replication destinations a brand mark (#50251)
## What kind of change does this PR introduce? Studio UI polish. This is the first PR in the Pipelines review stack and targets `master`. Resolves DEPR-674. ## What is the current behaviour? Replication destinations use generic line icons across the destination picker, pipelines list, and replication diagram. The existing shared ClickHouse and Snowflake assets also use older artwork. ## What is the new behaviour? Adds a reusable `DestinationLogo` treatment and uses it consistently across Replication surfaces. BigQuery, ClickHouse, DuckLake, and Snowflake now use their colour brand marks, while destinations without a dedicated asset retain their existing line icon in the same frame. The refreshed ClickHouse and Snowflake artwork replaces the canonical shared assets, so existing consumers such as the Wrappers catalogue receive the updated marks too. | Light | Dark | | --- | --- | | <img width="572" height="804" alt="CleanShot 2026-09-11 at 16 48 42@2x" src="https://github.com/user-attachments/assets/5c2eaef3-8714-4c0a-8bcc-7c8618abd677" /> | <img width="552" height="788" alt="CleanShot 2026-09-11 at 16 47 30@2x" src="https://github.com/user-attachments/assets/2aff8775-cdc1-4d6b-9f78-7b40d42e102a" /> | | Add Pipeline form | | --- | | <img width="1252" height="730" alt="CleanShot 2026-09-11 at 16 48 57@2x" src="https://github.com/user-attachments/assets/025a158c-57ee-495e-8356-00ed1717d09d" /> | ## To test 1. Open `/project/<ref>/database/replication` and start adding a pipeline. 2. Confirm the BigQuery, ClickHouse, DuckLake, and Snowflake marks appear consistently in the destination picker, pipelines list, and replication diagram. 3. Open the ClickHouse and Snowflake entries in the Wrappers catalogue and confirm they use the refreshed artwork. 4. Confirm Analytics Bucket retains its existing fallback icon within the same frame. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Visual Updates** * Destination logos now display dedicated brand marks for ClickHouse, DuckLake, Snowflake, and BigQuery. * Updated replication destination selectors, rows, and diagrams to use consistent destination logos. * Adjusted the destination type column width for improved layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
15a7b0ab18 |
docs(database): correct the dashboard_user and storage admin role descriptions (#50274)
Closes DOCS-1387 ## Problem The Postgres roles guide describes `dashboard_user` as "For running commands via the Supabase UI." That was the original intent, not current behavior. Dashboard queries run as `postgres` and carry a `-- source: dashboard` comment, which the [Postgres logs troubleshooting guide](https://supabase.com/docs/guides/troubleshooting/how-to-interpret-and-explore-the-postgres-logs-OuCIOj) already documents. The two pages contradict each other. Two smaller problems in the same list: - `supabase_storage_admin` is described as an Auth middleware role, copied from the `supabase_auth_admin` entry above it. - Studio ships both stale strings in its own role tooltips. The docs list and `QUERY_PERFORMANCE_ROLE_DESCRIPTION` are near-verbatim copies of each other. ## Solution - Replace the `dashboard_user` description with what the Dashboard connects as instead, and point readers to the `-- source: dashboard` comment for finding Dashboard queries in the logs. - Attribute `supabase_storage_admin` to the Storage middleware. - Apply both corrections to the Query Performance and Query Insights role tooltips. ## Manual testing 1. Open the [roles guide on the deploy preview](https://docs-git-docs-dashboard-user-role-supabase.vercel.app/docs/guides/database/postgres/roles). 2. Scroll to `dashboard_user`. It states that the Dashboard doesn't connect as the role, and that Dashboard queries execute as `postgres` with a `-- source: dashboard` comment. 3. Select **find them in the Postgres logs**. The Postgres logs troubleshooting guide loads. 4. Scroll to `supabase_storage_admin`. It reads "Used by the Storage middleware," not "Auth middleware." 5. In Studio, open **Observability > Query Performance** and hover a `dashboard_user` or `supabase_storage_admin` value in the **Role** column. The tooltip shows the same two corrected descriptions. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Corrected the description of the `supabase_storage_admin` role to reference Storage middleware. - Clarified that the Dashboard does not connect using the `dashboard_user` role. - Documented that Dashboard queries run as `postgres` and can be identified in Postgres logs with a `source: dashboard` comment. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ea203f70df |
fix(studio): use configured gp3 max-IOPS ceiling (#50269)
## Summary * GP3 IOPS calculation was hardcoded to 16,000 instead of reading from DISK_LIMITS config * AWS updated the real ceiling to 80,000, making the hardcoded constant stale * Users with large multi-TB GP3 disks were incorrectly blocked from provisioning above 16,000 IOPS ## Test plan - [X] Updated unit tests for `calculateMaxIopsAllowedForDiskSizeWithGp3` now assert correct behavior: scaling linearly (100 GB → 50,000 IOPS) and capping at new 80,000 ceiling (1000 GB → 80,000 IOPS) - [X] All 26 tests in DiskManagement.test.ts pass locally - [X] Manually verify Infrastructure Settings > Disk IOPS field no longer blocks GP3 disks above 16,000 IOPS up to 80,000 Closes [FE-4379](https://linear.app/supabase/issue/FE-4379/update-iops-limits-for-new-aws-disk-capacity) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Updated GP3 disk performance calculations to support up to 80,000 IOPS. - Disk sizes below the minimum threshold continue to receive the correct 3,000 IOPS floor. - Larger disks now scale linearly until reaching the updated maximum IOPS limit. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |