Commit Graph
20627 Commits
Author SHA1 Message Date
Kanishk DudejaandJulian Domke b917b0e1bf feat(billing): adds non-dismissable modal for indirect tax declaration (#49643)
### Summary

This PR adds a blocking dashboard modal for affected Australian
customers to confirm their GST registration and business use of
Supabase.

KPMG requires us to collect this declaration from certain existing
Australian customers. The backend now identifies organizations that
still need to respond using `requires_indirect_tax_declaration` and
stores their `yes` or `no`
response in Orb customer metadata.

It also supports email links with `submit_indirect_tax_declaration=true`
and shows a dismissible confirmation when the organization has already
responded.

### Testing

#### Manual testing

- Confirmed the modal appears for an affected organization without an
existing response and cannot be dismissed.
- Submitted both `yes` and `no` and confirmed the modal remains closed
after a refresh.
- Confirmed the declaration is stored without changing the customer's
Tax ID.
- Confirmed the modal does not appear for non admins/owners or
organizations that do not require a declaration.
- Confirmed the email-link parameter shows the already-submitted
confirmation only for organizations that have responded, and is removed
when dismissed.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added an indirect tax declaration dialog for eligible Australian
organizations.
* Users with billing permissions can select “Yes” or “No” and submit
their declaration.
* Added a dismissible confirmation for declarations submitted through a
linked prompt.
* The dialog requires an explicit response and provides guidance when no
option is selected.

* **Bug Fixes**
* Declaration prompts remain visible through submission confirmation and
close when dismissed.
  * Users without billing permissions do not see the dialog.
* Success notifications no longer overlap with the confirmation dialog.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Julian Domke <68325451+juleswritescode@users.noreply.github.com>
2026-09-01 18:04:25 +05:30
Wen Bo Xie 2681a21f5c docs: add Personal Access Tokens guide with generated permission tables (#49732)
Add a guide that compares classic and scoped personal access tokens,
explains how account roles constrain token permissions, and walks
through creating and testing a project-scoped token. Include generated
tables mapping permissions to Management API endpoints and MCP tools,
and link the guide from docs navigation and Studio token sheets.

Move the scoped-token permission catalog from Studio into shared-data.
Studio and docs generation now share permission names, categories,
descriptions, risk metadata, modes, scopes, and display order.

Generate the tables from the shared catalog, OpenAPI
x-fga-permissions, and the downloaded MCP permission map. Exclude
Workers permissions until the feature is live.

Run regeneration through the docs Makefile, verify checked-in output in
CI, and refresh it in the weekly Management API workflow. Add Dashboard
and Docs ownership plus contributor guidance so permission changes stay
synchronized.
2026-09-01 12:30:56 +00:00
Charis b278b1ec8a fix(studio): Debug with Assistant and Copy prompt work (#49690)
## Summary

* Resolved hanging buttons in Explorer's QueryResultError panel that
were wired to stub no-ops (`buildPrompt={() => ''}`,
`onOpenAssistant={() => {}}`).
* "Debug with Assistant" now opens a new chat seeded with a real prompt
combining the SQL query and error context using existing
`buildDebugPromptText` util and `useCreateChat` hook.
* "Copy prompt" now copies the same real debug prompt text to clipboard.
* Threaded `sql` and query `source` props down through `QueryEditor` →
`QueryResultRenderer` → `QueryResultError` while keeping them optional
for backward compatibility with other callers like
`AssistantNotebookPreviewCell`.

## Test plan

- [X] Run `pnpm typecheck` — passes
- [X] Run `pnpm lint --filter=studio` — passes
- [X] Run `pnpm test:studio --run
apps/studio/components/interfaces/Explorer/QueryEditor` — Explorer
vitest suite (99 tests across 13 files) passes with no regressions
- [X] Manually verify in Explorer: trigger an ad-hoc SQL query that
fails, confirm "Debug with Assistant" opens a new chat with the error
prompt seeded, and "Copy prompt" copies the prompt to clipboard

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added “Debug with Assistant” to query errors using the submitted SQL
and error details.
- Added an option to copy the debugging prompt for easier
troubleshooting.
- Assistant actions are hidden when query details are unavailable or
restricted.

- **Bug Fixes**
- Ensured query errors reference the SQL that produced them, rather than
later editor changes.

- **Tests**
- Added coverage for assistant debugging, prompt copying, conditional
visibility, and self-hosted behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 08:27:38 -04:00
Ivan Vasilov 02cf09212e chore: Remove tsconfig paths (#49770)
This PR removes all `paths` in `tsconfig.json` for all apps and
packages. They were added previosly because some of the components had a
`_Shadcn` suffix because of an ongoing migration. How that the migration
is done, the paths can be removed.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Refactor**
* Standardized shared UI component, utility, and icon imports across
design-system examples and application screens.
  * Simplified shared component access and project configuration.
  * Added shared access to anchor-link helpers and animation styles.

* **Compatibility**
* Updated component exports and imports without changing existing
behavior.
  * No changes to user-facing workflows, screens, or functionality.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 13:13:30 +02:00
Jordi Enric 911a6c2482 fix(workers): rename image version label FE-4317 (#49810)
## Problem

The Workers UI exposed the internal image terminology in the displayed
version label.

## Fix

Rename the Worker detail header and Container setting label to Version
while preserving the underlying API field.

## How to test

- Open a Worker detail page with an image version.
- Expected result: the header reads Version <number> and the Container
row label reads Version.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Updated worker details labels from “Image” and “Image version” to
“Version” for clearer, more consistent terminology.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 11:55:28 +02:00
Jordi Enric 5d9f94e8cf fix(workers): update CLI call instructions FE-4316 (#49808)
## Problem

The Workers overview showed deployment CLI instructions in the How to
call section, while direct gateway calls do not require an API key.

## Fix

Add a dedicated unauthenticated cURL snippet for the overview CLI tab
and preserve the deployment CLI snippet in the deploy dialog.

## How to test

- Open a Worker overview and select the CLI tab.
- Expected result: the copied cURL request targets the gateway URL and
has no Authorization header.
- Open the deploy dialog.
- Expected result: the deployment CLI commands remain unchanged.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added a cURL example for invoking Workers.
- Updated the “How to call” section to display cURL, JavaScript, and
Python examples.
  - cURL snippets now include the worker URL and request body.

- **Bug Fixes**
- Improved snippet URL handling and clarified authorization behavior in
CLI examples.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 11:55:10 +02:00
Ayaan Gazali 6e39b17d3c Merge pull request #49543 from ayaangazali/docs/studio-tanstack-checklist-missing-routes
docs(studio): add the 8 missing routes to the TanStack migration checklist
2026-09-01 07:02:32 +00:00
Binita DhakalandAlaister Young cd34776be1 fix(studio): honor MAINTENANCE_MODE in the TanStack runtime (#48616)
## What kind of change does this PR introduce?

Bug fix.

## What is the current behavior?

Fixes #48559 (diagnosed by @ayaangazali)

The TanStack Start runtime never applies maintenance mode.

`matchRedirect` in `apps/studio/redirects.shared.ts` takes a
`maintenanceMode`
flag, and both other consumers wire it from the environment:

- `apps/studio/next.config.ts` — `process.env.MAINTENANCE_MODE ===
'true'`
- `apps/studio/vercel.ts` — same

The TanStack call site in `apps/studio/routes/__root.tsx` passed only
`pathname`, `search`, `isPlatform` and `hash`, so `maintenanceMode` fell
back
to its `= false` default. With `MAINTENANCE_MODE=true` on a TanStack
deploy
that produced two wrong behaviors:

1. No path redirected to `/maintenance` — the app served normally during
   maintenance.
2. Because the flag read false, the "not in maintenance" branch still
applied
and sent `/maintenance` → `/`, making `routes/maintenance.tsx`
unreachable.

Mainly affects self-hosted / Node-server TanStack deploys; the platform
deploy
is covered by the Vercel edge layer, which does wire the flag.

## What is the new behavior?

The TanStack runtime honors `MAINTENANCE_MODE` the same way the Next
runtime
and the edge config do.

**Design note.** The issue asked whether this needs a new `NEXT_PUBLIC_`
variable or server-side plumbing, since both would change deployment
configuration for self-hosters. Neither is needed. `MAINTENANCE_MODE` is
already a *build-time* variable in both existing consumers — Next bakes
`redirects()` into `routes-manifest.json` during `next build`, and
`vercel.ts`
reads it while emitting `vercel.json`. Toggling maintenance has always
required
a rebuild, never just a server restart. And `vite.config.ts` isn't bound
by
Next's "only `NEXT_PUBLIC_`" rule: it controls `define` directly, and
already
re-exposes unprefixed `VERCEL_*` vars the same way. So the existing
unprefixed
variable is inlined at build time, giving exact parity with **no new env
var
and no config change for self-hosters**.

Three changes:

1. `vite.config.ts` — inline `process.env.MAINTENANCE_MODE` into the
bundle.
Falls back to `''` rather than being left undefined, so the browser
bundle
never ends up with a bare `process.env` reference (the failure mode the
file
   already guards against for the Sentry vars).
2. `routes/__root.tsx` — read it into `IS_MAINTENANCE_MODE` and pass it
to
   `matchRedirect`.
3. `redirects.shared.test.ts` — 4 tests for the maintenance branches of
   `matchRedirect`, which had no coverage at all.

`turbo.jsonc` already lists `MAINTENANCE_MODE` under the build task's
`env`, so
cache invalidation is correct for the Vite build too — no change needed.
No
README or docs change either, since the env contract is unchanged.

## Additional context

Verified end-to-end, not just by unit test.

**Browser repro** — built SPA served via `scripts/serve.js`, driven in
headless
Chromium:

| `MAINTENANCE_MODE=true` | lands on | |
| --- | --- | --- |
| `/project/default` | `/maintenance` | fixes behavior 1 |
| `/` | `/maintenance` | |
| `/maintenance` | `/maintenance` | fixes behavior 2 |

The maintenance page renders real content ("Under Maintenance — We are
currently improving our services…"), so the route is genuinely
reachable.

| control, var unset | lands on | |
| --- | --- | --- |
| `/project/default` | `/project/default` | normal routing intact |
| `/` | `/project/default` | root redirect intact |
| `/maintenance` | `/project/default` | correctly bounces away |

**Bundle inspection** — the flag compiles to a literal `true` with the
variable
set and `false` without it, confirming the define reaches the client.

**Shell prerender** — checked explicitly, since the maintenance-on rule
is a
catch-all. Builds with `MAINTENANCE_MODE=true` prerender the SPA shell
and pass
the post-build smoke test; the prerenderer crawls `/` and the root
`beforeLoad`
redirect does not fire during shell generation, so no guard is required.

**Checks** — 20 unit tests pass, typecheck 8/8, ESLint ratchet passes,
Prettier
clean.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added maintenance-mode routing for unavailable pages.
  - Preserves query parameters and URL fragments during redirects.
- Allows access to maintenance and image paths while maintenance mode is
active.
- Automatically returns visitors to the home page when maintenance mode
is disabled.
  - Maintenance behavior is controlled by the deployment configuration.

- **Tests**
- Added coverage for maintenance-mode redirects, URL preservation, and
exceptions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-01 06:32:18 +00:00
Sean Geoghegan 4ab1a6cbd2 chore(docs): add Sean Geoghegan to humans.txt (#49802)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adding myself to humans.txt

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added Sean Geoghegan to the alphabetical team list in the project
credits.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 08:30:42 +02:00
bf60e6cdce feat(library): serve agent-readable markdown for each docs page (#49567)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature: agent-readable markdown pages for the UI library docs.

## What is the current behavior?

Library docs are HTML-only. `llms.txt` lists page titles, but there is
no `.md` body an agent can fetch.

## What is the new behavior?

Each docs page is also served as markdown:

- Build-time MDX → markdown (`pnpm --filter library build:markdown`)
- `GET /library/docs/{slug}.md` (and `Accept: text/markdown`)
- HTML pages advertise `rel=alternate` `text/markdown`
- `llms.txt` links to the `.md` URLs

This is the base of a stack. The prompt-tab PR sits on top:
https://github.com/supabase/supabase/pull/49566

## Additional context

Interactive previews are omitted from the markdown. `BlockItem` emits
the production `npx shadcn add` command so agents still get an install
path.

## To test

1. `pnpm --filter library dev` (generates markdown in `predev`).
2. Open http://localhost:3004/library/docs/nextjs/password-based-auth.md
— markdown with the install command, file tree, and setup steps; no
interactive previews.
3. Open the same path without `.md` — HTML docs unchanged (no prompt tab
in this PR).
4. `curl -H 'Accept: text/markdown'
http://localhost:3004/library/docs/nextjs/password-based-auth` should
also return markdown.
5. http://localhost:3004/library/llms.txt — links should end in `.md`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Documentation pages are available as Markdown through `.md` URLs and a
dedicated endpoint.
* Markdown is generated automatically during development and production
builds.
* Generated content preserves front matter, links, callouts,
installation instructions, and supported documentation elements.
* Installation commands support npm, pnpm, yarn, and bun for React and
Vue projects.

* **Bug Fixes**
* Improved Markdown file handling, link rewriting, and content
negotiation.

* **Tests**
* Added coverage for Markdown conversion, content negotiation, and
installation commands.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Saxon Fletcher <SaxonF@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-01 11:35:55 +10:00
Douglas J Hunley eea39cc316 fix(studio): register pitr_archiving_stale in the advisor lintInfoMap (#48044)
## Summary
Studio's Advisor UI reads lint metadata from a fixed `lintInfoMap`, not
from the API response. A lint name missing from that map shows a blank
title, no icon, no filter checkbox, and no remediation link. This PR
adds a `pitr_archiving_stale` entry to `lintInfoMap`, copied from the
existing `pitr_not_enabled` entry, so the new lint renders correctly in
the Advisor UI.

## Dependencies

> [!WARNING]
>
[supabase/platform#35862](https://github.com/supabase/platform/pull/35862)
defines the `pitr_archiving_stale` lint. Until it merges, the API never
sends this lint name, so the Advisor grid and the public
`/v1/projects/{ref}/advisors/security` response never show the new row
-- but the Security Rules page
(`/project/<ref>/advisors/rules/security`) renders one row per
`lintInfoMap` entry regardless of the API, so this PR's new row appears
there immediately, before the backend lint exists. See Details for what
that means in the gap between merges.

---

<details>
<summary>Details</summary>

- A lint name missing from `lintInfoMap` has these effects:
- The grid row shows a blank title and no icon. There is no fallback to
the API's own `title`.
- The row has no filter checkbox. Filter options come from
`lintInfoMap`, not from the API.
- The row has no lint-specific remediation link. The "Learn more" link
falls back to the generic database-linter page.
  - The row does not appear in the Advisor Rules enable/disable list.
- The new `pitr_archiving_stale` entry copies the existing
`pitr_not_enabled` entry's `link`, `docsLink`, and `category`, and uses
a new `title` matching
[supabase/platform#35862](https://github.com/supabase/platform/pull/35862)'s
lint definition verbatim. Its `name` also matches that lint definition
exactly.
- **Known gap, until the backend PR merges:** `AdvisorRules`
(`components/interfaces/Advisors/AdvisorRules.tsx`) filters
`lintInfoMap` by `category` alone, with no dependency on the API
returning the lint -- so this entry makes a "PITR archiving may be
broken" row appear on the Security Rules page for every project right
away, ahead of the backend lint actually existing. From that row, a user
can open `CreateRuleSheet` and submit a disable rule, which `POST`s
`lint_name: 'pitr_archiving_stale'` to the notification-exceptions
endpoint. That name is not yet in the generated
`CreateNotificationExceptionsBody` enum
(`packages/api-types/types/platform.d.ts`), so the request either errors
or stores an exception keyed to a lint name nothing will ever match,
until api-types regenerates after the backend PR ships. This window
closes on its own once
[supabase/platform#35862](https://github.com/supabase/platform/pull/35862)
merges; accepted as a short-lived tradeoff rather than gating this PR on
merge order or adding code to hide the row until then.
- The docs anchor (`#point-in-time-recovery`) explains what PITR and
WAL-G archiving are. It does not explain how to fix a stale or broken
archive. That content does not exist yet in either pull request.
INDATA-1149 tracks this as a follow-up.
- `packages/api-types/types/platform.d.ts` is a generated file. This
repo's own CLAUDE.md says never to hand-edit it. The file does not list
`pitr_archiving_stale` yet, because it regenerates only after the
backend lint ships and `pnpm api:codegen` runs. Until then,
`LintInfo['name']` stays a plain `string`. If someone misspells the new
entry's `name`, the code still compiles and the tests still pass. At
runtime, the icon and docs link fall back silently instead of failing a
build. Once
[supabase/platform#35862](https://github.com/supabase/platform/pull/35862)
merges and api-types regenerates, `LintInfo['name']` must tighten to the
generated `LINT_TYPES` union. This closes the gap for every lint entry,
not only this one.

</details>

---

<details>
<summary>Testing</summary>

- `pnpm --filter=studio test Linter.utils.test.tsx` (17 passed,
including a test that asserts the `pitr_archiving_stale` entry's shape)
- `pnpm typecheck --filter=studio` (clean)
- `pnpm exec eslint` on the touched files (clean; the `pnpm lint
--filter=studio` turbo wrapper itself errors on this machine with an
unrelated JSON-parse failure -- a tool-invocation issue, not a lint
finding)
- `prettier --check` on the touched files
- The `docsLink` assertion
(`toContain('/guides/platform/backups#point-in-time-recovery')`) is
domain-agnostic by construction, so it holds regardless of which
`NEXT_PUBLIC_DOCS_URL` value is set -- no test in this file overrides
that variable, this is a property of the assertion's own shape, not a
scenario the suite exercises

</details>

---

<details>
<summary>Misc</summary>

- Part of INDATA-979
- Changelog:
[supabase/changelog#192](https://github.com/supabase/changelog/pull/192)

</details>
2026-08-31 15:28:37 -04:00
Jordi Enric b885b69bff feat(studio): restore workers secrets page FE-4280 (#49762)
## Problem

Workers Secrets was merged in #49589 into the stacked
jordi/workers-detail branch. The parent Workers PR reached master
without that child merge, leaving the page absent from staging.

## Fix

Cherry-pick the missing Workers Secrets route, menu item, shared-secret
copy, and generated route tree onto current master. The page uses the
existing workers flag and permission gates.

## How to test

- Enable the workers flag for a project with Workers access.
- Open Workers, then select Secrets.
- Expected result: the shared project secrets page renders at
/project/:ref/workers/secrets and is not treated as a worker named
secrets.
- Add, edit, or delete a secret, then confirm the same value appears
under Edge Functions, Secrets.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added a **Secrets** page to the Workers section.
  * Added navigation to Worker secrets from the Workers menu.
* Displayed default secrets and deployment-specific guidance where
applicable.
* Clarified that platform secrets are shared between Edge Functions and
Workers.
  * Updated deletion warnings to reflect shared secret usage.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 19:17:39 +00:00
Alaister YoungandAlaister Young 5d5b3b2aa8 [FE-4278] fix(studio): allow broadcast before any realtime message arrives (#49792)
In the Realtime Inspector, the messages view — which holds every
"Broadcast a message" entry point — only rendered once at least one
message had been received. With only Broadcast enabled and no inbound
traffic, the page stayed on the "Create realtime experiences" onboarding
forever, so there was no way to send a broadcast at all.

The render gate now keys off a channel being set rather than
`logData.length`: once you join a channel, `MessagesTable` renders and
its existing empty states provide the send entry points ("Listening • No
message found yet…" toolbar + the "No Realtime messages found" panel).
The onboarding remains the pre-channel state.

Addresses
[FE-4278](https://linear.app/supabase/issue/FE-4278/realtime-inspector-cant-send-broadcast-without-incoming-messages).

## To test

- Realtime → Inspector, before joining a channel: the "Create realtime
experiences" onboarding still shows
- Join a channel (with Presence off / Broadcast only so nothing
arrives): the listening view renders immediately with "No message found
yet…" and "Broadcast a message" in both the toolbar and the empty-state
panel — previously this was stuck on the onboarding
- Click "Broadcast a message" and send with defaults: the broadcast
appears in the grid
- Stop listening: no crash, messages retained

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* The Realtime Inspector now displays the messages view as soon as a
channel is selected.
* Empty-state guidance, including the option to broadcast a message, is
now available before any messages arrive.
* Pre-channel onboarding remains visible until a channel is configured.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-31 17:27:53 +00:00
Alaister YoungandAlaister Young c5cffb6afb [FE-3716] fix(studio): restrict HA project creation to us-east-1 in prod (#49787)
`getHighAvailabilityRegionCode` had `staging` and `local` cases but no
`prod` case, so it returned `undefined` in production and the High
Availability region filtering never applied — the creation flow offered
every AWS region while HA Alpha is only live in `us-east-1`. Adds the
`prod` case returning `us-east-1`, matching staging. The region filter
and the "High Availability projects are currently limited to…" banner
both key off this value, so no other changes are needed.

This keeps the accepted hardcoded-per-environment pattern for Alpha; the
API/entitlement-driven enabled-regions design stays open on the ticket
for when the rollout expands.

**Changed:**
- `ProjectCreation.utils.ts` — `prod` → `us-east-1`
- `ProjectCreation.utils.test.ts` — the two env tables previously pinned
prod as unrestricted; now expect `us-east-1`

Addresses
[FE-3716](https://linear.app/supabase/issue/FE-3716/show-enabled-regions)
(and the folded-in MUL-1337).

## To test

- `pnpm --filter studio exec vitest run
components/interfaces/ProjectCreation/ProjectCreation.utils.test.ts`
- In prod after deploy: new project → toggle High Availability → region
select offers only East US (North Virginia) and shows the "limited to"
notice; staging/local behavior unchanged (only the `prod` env branch
changed)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- High-availability project creation now correctly uses the `us-east-1`
region for production environments.
- Region selection is now properly restricted to `us-east-1` when
creating production projects.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-01 01:01:02 +08:00
Alaister YoungandAlaister Young a14fc04937 [MUL-1475] fix(studio): show setup state on HA topology diagram during boot (#49786)
While an HA (Multigres) project is provisioning, the `/ha-admin`
topology endpoints fail or return an empty topology as a matter of
course — the cluster topology diagram rendered that as a hard "Failed to
retrieve cluster topology" error (or the "Cluster topology unavailable"
contact-support state). The diagram now checks the project status and,
while the project is building (`COMING_UP`/`UNKNOWN`, same pair
`ProjectLayout` treats as booting), shows a "Setting up project" empty
state instead. Both the project-detail query (self-polls while booting)
and the ha-admin queries (30s interval) keep refetching, so the diagram
appears on its own once boot completes.

Once the project is past provisioning, genuine errors and the
empty-topology state surface exactly as before.

<img width="1491" height="769" alt="mul1475-setting-up-state-wide"
src="https://github.com/user-attachments/assets/3f095634-9939-41cd-88c3-0849cbad7374"
/>

**Added:**
- Component tests for the four states: booting + error, booting + empty
(→ setup state), running + error (→ error alert), running + empty (→
unavailable state)

Addresses
[MUL-1475](https://linear.app/supabase/issue/MUL-1475/polish-infra-diagram).

## To test

- On an HA project mid-provisioning (or simulate: dev toolbar
project-status override → `COMING_UP`, with `/ha-admin` requests
failing), open Settings → Infrastructure — the topology panel shows
"Setting up project" with a spinner, not the error alert
- On a healthy HA project, the topology diagram renders as before; if
`/ha-admin` genuinely fails there, the error alert still shows
- `pnpm --filter studio exec vitest run
components/interfaces/Settings/Infrastructure/InfrastructureConfiguration/HaInstanceConfiguration.test.tsx`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a “Setting up project” state while projects are provisioning or
their status is unavailable.
* Prevents premature topology errors or unavailable messages during
project setup.
* Added accessible status announcements for loading and setup-state
transitions.

* **Bug Fixes**
* Active projects now correctly display topology errors when cluster
health data cannot be retrieved.
* Healthy responses with no topology data display an appropriate
unavailable state.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-01 00:53:01 +08:00
Alaister YoungandAlaister Young 8e9d6d81f2 [FE-4273] feat(studio): add Multigres to support form services (#49784)
Adds "Multigres" to the "Which services are affected?" multi-select on
the Contact Support form, so Alpha customers can tag tickets for the
Multigres Front inbox. Placed alphabetically between Edge Functions and
Realtime; the later option ids are renumbered, which is safe — they're
only used as React list keys, and the submit payload sends the lowercase
value tokens (`affectedServices: "multigres;..."`, verified with a live
submission).

Addresses
[FE-4273](https://linear.app/supabase/issue/FE-4273/add-multigres-to-support-form-services).
Front-inbox routing itself is Platform-side (SUPPORT-421) and should
match on the token `multigres`.

## To test

- Open /support/new → "Which services are affected?" → Multigres appears
between Edge Functions and Realtime, selectable alongside other
services, and the combobox search finds it
- Submit a ticket with it selected → the POST to
`/platform/feedback/send` carries `affectedServices` containing
`multigres`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added Multigres as a selectable service option in the support
interface.
  * Updated service ordering to accommodate the new option.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-01 00:52:42 +08:00
Alaister YoungandAlaister Young 47b33ebb22 [MUL-1346] chore(studio): hide metrics export banner for HA projects (#49781)
Hides the "Export Metrics to your dashboards. Get started for free!"
banner (`ObservabilityLink`) for High Availability (Multigres) projects
— the Metrics API it links to is not available for them. The check lives
inside the shared component, so it applies to every observability
sub-page that renders the banner; non-HA projects are unchanged.

Addresses
[MUL-1346](https://linear.app/supabase/issue/MUL-1346/database-observability-dashboard-remove-text-for-unsupported-feature).

## To test

- On an HA project: open Observability → Database (and any other
observability sub-page, e.g. Auth) — the "Export Metrics to your
dashboards" banner at the bottom of the page should be gone
- On a non-HA project: same pages — the banner still shows, with "Get
started for free!" linking to the metrics docs

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Metrics export links are now hidden for High Availability projects,
where the Metrics API isn’t available.
* Existing metrics export functionality remains unchanged for supported
projects.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-01 00:52:32 +08:00
058b546b56 fix(studio): send API keys on the apikey header in the edge function tester (#49650)
<!-- ccr-slack-attribution -->
_Requested by **Kalleby Santos** · [Slack
thread](https://supabase.slack.com/archives/C0AQ3UHCCKW/p1787840441551609?thread_ts=1787840441.551609&cid=C0AQ3UHCCKW)_

**Before:** you deploy the editor's default template ("Deploy a new
function" → "Via Editor"), which wraps its handler in `withSupabase({
auth: ["publishable", "secret"] })`. You click **Test** and get `401
{"message":"Invalid credentials","code":"INVALID_CREDENTIALS"}` — from
the function's own middleware, with an empty Headers section. Studio was
quietly setting `Authorization` to a legacy `service_role` JWT (and,
before that, to your dashboard session token), routed through a private
`x-test-authorization` header that the proxy route renamed to
`Authorization`. A legacy JWT is neither a publishable nor a secret key,
so the middleware rejected it. Pasting your own `Authorization` row did
not help: the route overwrote it unconditionally. On a project with
legacy keys disabled there was no `service_role` key at all and the
literal string `Bearer undefined` went out.

**After:** the tester sends your publishable key on the `apikey` header,
where new-format keys belong, and never generates an `Authorization`
header. `Authorization` only ever comes from your own header rows —
typed by hand, or prefilled for you by the role selector. The editor's
default template works on the first click, a header you paste is
actually sent, and an **Add secret key** action in the "Add header"
dropdown gives you one-click access to a secret key, the same affordance
the database webhooks and cron job screens already have.

**How:** header construction moves into `buildEdgeFunctionTestHeaders`
(`EdgeFunctionTesterSheet.utils.ts`), which sets `Content-Type` and
`apikey` and then applies the user's rows last. The
`x-test-authorization` hop is gone from both the component and
`pages/api/edge-functions/test.ts`; the route now forwards the supplied
headers as given. Both sides merge on the lowercased header name, so a
row typed `authorization` or `apikey` replaces the generated one instead
of sitting beside it and being comma-joined by `fetch`. The Headers and
Query Parameters sections now use the shared `KeyValueFieldArray`, which
is what makes `buildEdgeFunctionHeaderAddActions` reusable here.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix.

## What is the current behavior?

Fixes #42755.

- `EdgeFunctionTesterSheet.tsx` sent the legacy `service_role` JWT (or a
role-impersonation JWT) as the value of `x-test-authorization` on every
request, plus the dashboard session access token as `Authorization`.
- `pages/api/edge-functions/test.ts` then overwrote `Authorization` with
`x-test-authorization` whenever that header was present, discarding any
`Authorization` the user had entered.
- No `apikey` header was ever sent, so `withSupabase` in `publishable`
or `secret` auth mode — the modes used by the editor's own templates —
could never succeed.
- Header merging was case-sensitive on both sides of the proxy, so a row
typed in the conventional lowercase form produced two entries that
`fetch` comma-joined into one malformed value.
- The API keys query did not pass `reveal: true`, unlike the webhooks
and cron job UIs.

## What is the new behavior?

- `apikey` carries the publishable key, falling back to the legacy
`anon` key. This mirrors the example snippets on the function details
page, which already prefer `publishableKey ?? anonKey`. Defaulting to
the least-privileged key means a secret key is only ever sent when the
user explicitly adds it.
- `Authorization` is never generated. The `useSessionAccessTokenQuery`
call is removed from this component entirely — the dashboard user's own
session token has no business being forwarded to a project's function.
- `x-test-authorization` is removed from both files. The proxy route
stays, because it is what reads the raw upstream response for the
response panel (`redirect: 'manual'`, full status/header/body capture),
keeps the request off the browser's CORS path, and holds the
`isValidEdgeFunctionURL` guard and the local-dev URL rewrite. Only the
header rewriting is gone.
- Role impersonation keeps working, but as a visible, editable
`Authorization` row rather than a hidden injected header, so what is
sent is always what is displayed. Two details worth reviewing: the
selector tracks the value it last wrote, so clearing the role removes
only that row and leaves an `Authorization` row you typed by hand alone;
and an incrementing request id discards a JWT that resolves after a
newer role has already been picked.
- Headers merge case-insensitively, user rows winning.
- `reveal: true` is passed on the API keys query, matching
`Database/Hooks/HTTPHeaders.tsx`.

## Additional context

**Relationship to #47159.** #47159 identified the same root cause
independently and got the important part right: the key belongs on
`apikey`, and neither the legacy service-role JWT nor the dashboard
session token should be forwarded. Its extraction of a testable header
builder is a good shape, and this PR keeps it — including the spirit of
its test suite. The differences are in scope rather than direction. This
PR also removes the `x-test-authorization` hop and the route's
unconditional `Authorization` overwrite (#47159 leaves the route
untouched); drops the remaining legacy service-role fallback rather than
keeping it for projects without a publishable key; adds `reveal: true`,
secret-key support and the shared "Add secret key" affordance; and
normalizes header casing for every header rather than only
`x-test-authorization`. Whether to land that PR first and layer this on
top, or take this one, is the maintainers' call — either way the credit
for spotting it belongs there too.

**Overlap with #48143.** That open PR fixes the same case-sensitivity
defect for `Content-Type` in these two files. It is not addressed
separately here, but the case-insensitive merge in this PR covers
`Content-Type` as a side effect, so the two will conflict textually.
Happy to rebase on whichever lands first.

**A note on `verify_jwt`.** The gateway creates a temporary token when
`apikey` is present, so `verify_jwt` does not affect this path and a
request with `apikey` and no `Authorization` reaches the function
normally. No deploy defaults are changed here.

**Compatibility.** One behaviour gets worse and is worth an explicit
decision: a function that expects a legacy JWT on `Authorization` used
to "just work" in the tester because Studio injected the service-role
key. It now needs an `Authorization` row, which the **Add secret key**
action produces in one click — the shared helper already emits an
`Authorization: Bearer` row for legacy-format keys. Projects with legacy
keys disabled strictly improve: they used to receive `Bearer undefined`.
Functions using `auth: "user"` are unchanged — the tester never had a
real end-user JWT, only the impersonation token.

## Testing

`apps/studio` dependencies could not be installed in the environment
this was written in (`pnpm install` fails on a 403 from `npm.jsr.io`),
so `vitest`, `tsc --noEmit` and `eslint` were not run. What was run
instead:

- Prettier with the repo's config, including
`@ianvs/prettier-plugin-sort-imports`: clean on all five files.
- `tsc` parse of the changed files: no syntax or type errors beyond
pre-existing unresolved-module noise.
- Both new test suites transpiled and executed as plain Node assertions:
7/7 for `buildEdgeFunctionTestHeaders`, 4/4 driving the API route
handler with a stubbed `fetch`.

Please run the real suites in CI. `pnpm --filter studio exec vitest
--run tests/components/Functions/EdgeFunctionTesterSheet.utils.test.ts
tests/pages/api/edge-functions/test.test.ts` covers the added tests. A
component-level test of the impersonation prefill is not included and
would be a reasonable follow-up.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Kalleby Santos <105971119+kallebysantos@users.noreply.github.com>
2026-08-31 13:43:01 -03:00
Jeremias Menichelli 143f141e0f feat: initial kb scaffolding (#49601) 2026-08-31 14:55:04 +00:00
Joshen Lim c0409b38b4 joshenlim/fe 4285 explorer missing prettify in query toolbar actions (#49675)
## Context

Adds the prettify SQL CTA to Explorer Notebook and Query Tab

Query tab: Prettify CTA is within the dropdown menu here
<img width="1092" height="272" alt="image"
src="https://github.com/user-attachments/assets/3b4f3514-69cc-4c24-a127-da1555ee905e"
/>

Query cell: Prettify CTA sits between the buttons in the toolbar
<img width="1085" height="306" alt="image"
src="https://github.com/user-attachments/assets/e503ad6c-5dda-4c2b-a824-8c1049d5e9fb"
/>

Also added shortcut tooltip for the run button
<img width="183" height="103" alt="image"
src="https://github.com/user-attachments/assets/729055b8-8e2c-4cf7-8f2e-c5726e828644"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added SQL prettification to Explorer query editors through the
overflow menu, query toolbar, editor action, and keyboard shortcut.
* Displays the configured formatting shortcut alongside the prettify
action.
  * Prevents formatting while an AI proposal is pending.
  * Added a keyboard shortcut hint to the query run action.
  * Enhanced toolbar tooltips to support richer formatted content.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 23:44:42 +09:00
Gildas Garcia 6cb08304d9 Fix: RadioGroupCard accessibility issues (#48527)
## Problem

The `<RadioGroupCard>` component has an accessibility issue: duplicate
ids on the items.
Besides, its usage in the Design System app has additional issue: no
label on the group itself when used outside a react-hook-form.
Finally, the form example wrap each item in a `FormField` and
`FormControl` which is unnecessary and causes another accessibility
issue as all items are then injected the same `id` prop.

## Solution

- Fix the duplicate ids issue
- Fix all design system example
- Fix the only wrong usage we have in studio

No visual changes

## Notes

When used outside a form, I added aria-label attributes on the group and
they are announced by Mac Voice Over.
However, when used in a form, our components adds a label with the
correct for attribute but it seems that Mac Voice Over does not announce
it.

Not sure about how this should be handled.

## How to test

On
https://design-system-git-fix-radio-group-card-a11y-supabase.vercel.app/design-system/docs/components/radio-group-card,
with Voice Over enabled:
- tab to the first radio group, it should announce the value and the
label of group itself, _Size_
- tab to the second, same but label is _Theme_

On
https://design-system-git-fix-radio-group-card-a11y-supabase.vercel.app/design-system/docs/components/radio-group-card#form
(Form example):
- select any option and submit
- check the correct option is submitted

On
https://studio-staging-git-fix-radio-group-card-a11y-supabase.vercel.app:
- Go to your organization settings, Audit Log Drains, open your devtool
network tab
- Create a new custom endpoint and select the HTTP version
- Check in the network tab that the correct http version is passed

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Accessibility**
* Improved labeling for radio card groups, including size, spacing,
theme, and webhook version selections.
* Radio options now use stable or automatically generated identifiers
with reliable label associations.

* **Bug Fixes**
* Simplified radio option structure in forms for more consistent
behavior.
* Improved ID handling across radio card, stacked, and large radio
options.
* Updated the themed radio card example to use the dark theme by
default.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 16:14:09 +02:00
Ayaan Gazali 2632d88850 chore(docs): remove the codemod:frontmatter script whose file is gone (#49723) 2026-08-31 12:46:38 +02:00
Alaister YoungandAlaister Young e73811f1c8 fix(studio): restore useTrackExperimentExposure hook (#49763)
Restores `hooks/misc/useTrackExperimentExposure.ts`, fixing the
typecheck failure on master that broke the latest Studio production
deploy.

The hook was deleted as dead code in #49719 (it was genuinely unused on
master at the time), but #49534 was in flight and reintroduced a usage
in `plan-presentation.ts`. The two PRs merged cleanly with no textual
conflict, so nothing typechecked the combination until the deploy off
master failed with:

```
plan-presentation.ts(5,44): error TS2307: Cannot find module '@/hooks/misc/useTrackExperimentExposure'
```

**Added:**
- `apps/studio/hooks/misc/useTrackExperimentExposure.ts` — restored
verbatim from before #49719; no longer dead code since
`plan-presentation.ts` imports it

## To test

- `pnpm --filter studio typecheck` passes (verified locally)
- `pnpm knip --workspace apps/studio` no longer flags the hook (verified
locally)
- Studio production deploy succeeds once merged

https://claude.ai/code/session_01XZGr2n1dBzJ7m3DYsGu852

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-31 10:10:30 +00:00
claude[bot] fda58a4b38 docs: clarify that new API keys are accepted in the Authorization header (#49700) 2026-08-31 10:57:10 +01:00
kemal.earthandClaude Opus 5 839c7a9cbb feat(studio): full-screen pricing panel variants (#49640)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Incorporating the parent PR.

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 11:53:16 +02:00
Mert YEREKAPANandkemal d11705ded0 feat(studio): add plan-change panel presentation experiment (#49534)
## What

A/B test for the plan-change side panel
(`/org/_/billing?panel=subscriptionPlan`) — gated behind PostHog flag
`pricingPanelPlanPresentation` (multivariate, 3 arms).

The current panel drops `description`, `preface`, and `footer` from
`shared-data/plans.ts` and uses a much smaller type scale than the www
pricing page, so the two surfaces look unrelated and plan differences
are hard to reason about. This experiment tests whether matching the www
style and surfacing plan gaps improves upgrade conversion.

| Variant | Surface |
| --- | --- |
| `control` | Current panel — no change (baseline cohort, still tracked)
|
| `parity` | www pricing page style: mono uppercase heading,
description, CTA above price, large mono price, preface ("Everything in
the Free Plan, plus:"), 13px features |
| `gaps` | `parity` + gap rows at the bottom showing what the plan is
missing (✗ Daily backups, ✗ Email support, dimmed ✓ 1-day log retention)
|

## Variants

Control
<img width="3520" height="2394" alt="Arc 2026-08-26 16 14 09"
src="https://github.com/user-attachments/assets/95464e83-b377-4754-85ee-c65dce0206c7"
/>

Parity
<img width="3520" height="2394" alt="Arc 2026-08-26 16 14 01"
src="https://github.com/user-attachments/assets/f50e66e2-7cbe-4e65-b1fb-083efd79ff00"
/>

Gaps
<img width="3520" height="2394" alt="Arc 2026-08-26 16 29 48"
src="https://github.com/user-attachments/assets/fbb08a12-1b76-4ce5-9247-20a6e8399be3"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a refreshed subscription plan selector with pricing,
descriptions, features, exclusions, and plan-specific messaging.
* Added upgrade and downgrade actions with loading states and
eligibility-based controls.
* Added plan comparison views highlighting missing and lower-tier
features.
* Added tailored handling for enterprise plans and supported billing
arrangements.
* Improved accessibility by respecting reduced-motion preferences during
plan highlights.

* **Tests**
* Expanded coverage for plan eligibility, feature comparisons, and
presentation variants.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: kemal <hello@kemal.earth>
2026-08-31 11:53:16 +02:00
Jordi Enric 537f09be0f fix(studio): label omitted worker runtime as custom FE-4314 (#49757)
## Problem

Workers with an omitted runtime are displayed as Unknown, even though an
omitted runtime represents a custom worker image.

## Fix

Display Custom when the runtime is omitted. Preserve friendly labels for
known runtimes and raw values for explicit unrecognized runtimes.

## How to test

- Run `node_modules/.bin/vitest --run
components/interfaces/Workers/Workers.utils.test.ts` from `apps/studio`.
- Open a worker whose API response omits `spec.runtime`.
- Expected result: the runtime badge displays Custom.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Worker runtimes without available metadata are now labeled
**“Custom”** instead of **“Unknown.”**
- Updated the related behavior validation to reflect the corrected
runtime label.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 10:55:23 +02:00
Saxon FletcherandCursor 78bd0e066b chore(studio): align query results grid typography with table editor (#49752)
## Summary
- Match Explorer/SQL query results table typography to Table Editor:
sans cells at `text-grid`, headers at `text-xs` / `text-foreground`
- Reuse Table Editor `NullValue` for null cells so empty results read
the same way
- When the Explorer feature preview is on, the inline editor "expand"
action opens a new Explorer query tab (same pattern as the assistant)
instead of the SQL Editor

## Test plan
- [ ] Run a query in Explorer and confirm header/cell font, size, and
color match Table Editor
- [ ] Confirm `NULL` cells use the same faded treatment as Table Editor
- [ ] Check the SQL Editor results pane (shared `DataGridResults`) still
looks correct
- [ ] With Explorer feature preview on, expand the inline editor and
confirm it creates an Explorer query tab with the current SQL, then
closes the panel
- [ ] With Explorer feature preview off, expand the inline editor and
confirm it still opens a SQL Editor snippet

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## New Features
- Added the ability to open SQL directly in Explorer from the editor
panel.
- Run SQL actions now create a query draft and navigate to the query
tab.

## Style
- Improved data grid readability with clearer text, left-aligned
headers, truncated labels, and selectable content.
- Added dedicated styling for null values.
- Updated empty-results messaging with standard sans-serif text.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 18:38:30 +10:00
Saxon FletcherandCursor 516ef0320f chore(studio): refine Explorer toolbar, chat, and home actions (#49748)
## Summary
- Unify Explorer toolbar actions: 16px / 2px Lucide icons,
`text-tertiary-foreground` that becomes `text-foreground` on hover
(Analyze icon goes brand on hover).
- Soften chat scroll edges with top/bottom fades, and align the composer
width with the conversation content (`px-7` + `max-w-3xl`).
- Put **Run SQL** first on Explorer home, and rename the tab-bar new-tab
item from “New query” to **Run SQL** so it matches.

## Test plan
- [ ] Open Explorer and check query, notebook, and chat toolbars: icons
are 16px, muted by default, and go to foreground on hover. Analyze on a
notebook with cells: icon goes brand on hover; empty notebook still
disables Analyze.
- [ ] Open a query tab: source menu, result settings, save, and
more-options all look like the other toolbar actions (including while
the dropdown is open).
- [ ] Open Explorer chat: scroll a long thread and confirm top/bottom
fades sit on the chat surface. Composer lines up with message width (not
inset extra).
- [ ] On Explorer home, **Run SQL** is the first card; clicking it still
opens a SQL tab.
- [ ] From the tab bar **+** menu, the first item is **Run SQL** (not
“New query”); it still creates a SQL tab. **New notebook** and **New
chat** still work.

Made with [Cursor](https://cursor.com)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **UI Improvements**
* Standardized Explorer toolbar icons for consistent sizing and visual
weight.
* Updated toolbar action colors, hover states, and keyboard-focus
visibility.
  * Reordered Explorer home actions so “Run SQL” appears first.
  * Renamed “New query” to “Run SQL” in the new-tab menu.
  * Improved query source and settings toolbar controls.
* Refined AI assistant chat layout with centered content, decorative
gradients, and improved focus styling.
  * Added hover styling for the notebook Analyze action.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 18:36:01 +10:00
Gildas Garcia 4f92790587 fix: FormItemLayout does not apply item id correctly (#49637)
## Problem

`<FormItemLayout>` does not apply item id correctly. This can be seen on
https://supabase.com/design-system/docs/ui-patterns/forms: open the
devtool and check the form items labels. They have no `for` attribute.
This makes it harder to correctly test and is an accessibility issue.

Axe devtool actually report it

## Solution

When inside React Hook Form, `<FormItemLayout>` actually generate an
`id` (via `<FormItem>`). However, this `id` is overridden in
`<FormLayout>` and read from context by `<FormLabel>`. Ensure we use the
generated id unless one was provided.

Also updated the paths filters for the CI check so that any changes in
either `ui` or `ui-patterns` triggers the studio unit and e2e tests.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved form accessibility by ensuring labels consistently connect to
their corresponding input fields.
- React-based forms now correctly preserve field-specific identifiers
when associating labels with inputs.
- Added support for explicitly specifying a label’s input target,
improving compatibility with customized form layouts.
- Updated Studio forms to use consistent control identifiers and
labeling behavior.

- **Quality Improvements**
- Automated validation now also runs when shared UI components and
patterns are updated.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 10:32:45 +02:00
Pamela Chia 8aade77966 fix(www): gate changelog md alternate on slug set (#49754)
Changelog entry pages advertised a `.md` alternate tag unconditionally
while the page is ISR, so an entry published in the changelog repo
between www deploys pointed agents at a `.md` sibling that 404s until
the next build (the static file and `CHANGELOG_PAGES` are both
build-time artifacts). PR #49357 made bare-URL negotiation fail closed
for those entries; I gate the advertising side here the same way.

**Changed:**
- **No more dead `.md` links on freshly published entries**:
`getStaticProps` passes a `hasMarkdownVariant` flag computed from
`CHANGELOG_PAGES` membership and the page renders the alternate tag only
when true. An entry published between deploys carries no tag until the
build that ships its `.md` file; the set reference stays inside
`getStaticProps`, so the generated module stays out of the client
bundle.
- **Drift coverage**: `md-alternates.test.ts` gains the changelog
direction, source-level like the existing `_app.tsx` drift test; the
assertion pins the full `CHANGELOG_PAGES.has(` +
backtick-`changelog/${entry.slug}`-backtick + `)` expression so a
dropped key prefix fails the suite, and removing the gate fails it too.

**Note:** without changelog sync secrets `CHANGELOG_PAGES` is empty, so
the tag never renders in local dev. Preview and prod are the
verification surface.

## To test
Tested on Vercel preview:
- [x] Open a published changelog entry page and view source: expect
`<link rel="alternate" type="text/markdown"
href="/changelog/<slug>.md">` in the head — observed exact href
`/changelog/19669-supavisor-1-0.md`
- [x] Fetch that href: expect 200 with `content-type: text/markdown` —
observed 200, `text/markdown; charset=utf-8`
- [x] (added) Client-side nav from `/changelog` into an entry: alternate
tag appears with that entry's slug; hopping to a second entry updates
the href (no stale tag)
- [x] (added) Navigating back to `/changelog`: entry tag gone; the index
shows its own pre-existing `/changelog.md` alternate (hardcoded in
`pages/changelog.tsx`, outside this diff), and `/changelog.md` returns
200 `text/markdown`
- [x] (added) Console: zero new errors across all scenarios vs page-load
baseline

## Linear
- fixes GROWTH-1120


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Changelog pages now advertise a Markdown alternate link only when a
Markdown version is available.
* Prevented links to unavailable Markdown content from appearing on
changelog entries.

* **Tests**
* Added coverage to verify correct Markdown alternate detection and
rendering.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 16:25:06 +08:00
5b01b5a9c7 fix(studio): report advisorCategory consistently across advisor telemetry surfaces (#49746)
<!-- ccr-slack-attribution -->
_Requested by **Pam Chia** · [Slack
thread](https://supabase.slack.com/archives/C076KTY11DF/p1788139328573799?thread_ts=1788139328.573799&cid=C076KTY11DF)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (telemetry correctness). No user-visible change.

## What is the current behavior?

Linear:
[GROWTH-1153](https://linear.app/supabase/issue/GROWTH-1153/telemetry-advisorcategory-omitted-for-health-lints-on-two-of-five)

**Before:** five surfaces emit the optional `advisorCategory` property
on `advisor_detail_opened` and `advisor_assistant_button_clicked`, and
they disagree about how to derive it. Three pass the lint's category
straight through as `categories[0]`. Two compute it with a hardcoded
ladder — `categories.includes('SECURITY') ? 'SECURITY' :
categories.includes('PERFORMANCE') ? 'PERFORMANCE' : undefined` — which
predates the `HEALTH` category and falls through to `undefined` for
anything it does not name. Because the property is optional, those two
surfaces ship the event with `advisorCategory` silently absent: no type
error, no runtime error, just a hole in the data. A reader querying a
category breakdown of either event gets numbers that depend on which
surface the user happened to click, and `HEALTH` is under-counted. The
split is clearest in `AdvisorSection.tsx`, where a single advisor card
emits both events — the card click through the ladder (L83) and the
Assistant button through the pass-through (L206) — so one card can
report two different categories for the same lint.

The cause is that `AdvisorCategory` in
`packages/common/telemetry-constants.ts` is schema-derived:

```ts
type AdvisorCategory =
  components['schemas']['GetProjectLintsResponse'][number]['categories'][number]
```

The API-types regeneration in supabase/supabase #49646 (merged
2026-08-27, `26e89b36c349893540f8efbd45613921be0a4d18`) widened
`categories` from `('PERFORMANCE' | 'SECURITY')[]` to `('PERFORMANCE' |
'SECURITY' | 'HEALTH')[]`. `AdvisorCategory` picked up the third value
incidentally and the two ladders were never updated — a union widening
is invisible to a hardcoded ladder, so nothing broke loudly.

| Event | Surface | HEALTH behavior before |
| --- | --- | --- |
| `advisor_detail_opened` |
`apps/studio/components/ui/AdvisorPanel/AdvisorPanel.tsx` (L203) |
ladder → property absent |
| `advisor_detail_opened` |
`apps/studio/components/interfaces/ProjectHome/AdvisorSection.tsx` (L83)
| ladder → property absent |
| `advisor_detail_opened` |
`apps/studio/components/interfaces/Linter/LinterDataGrid.tsx` (L163) |
pass-through → `'HEALTH'` |
| `advisor_assistant_button_clicked` |
`apps/studio/components/interfaces/Linter/LintDetail.tsx` (L38) |
pass-through → `'HEALTH'` |
| `advisor_assistant_button_clicked` |
`apps/studio/components/interfaces/ProjectHome/AdvisorSection.tsx`
(L206) | pass-through → `'HEALTH'` |

The two `advisorCategory` property doc comments in
`telemetry-constants.ts` (L2949, L2980) also still read "Category of the
advisor (SECURITY or PERFORMANCE)", which the widening made false.

## What is the new behavior?

**After:** all five surfaces derive `advisorCategory` the same way, so a
category breakdown of these two events is consistent regardless of which
surface produced the event, and `HEALTH` is reported wherever it can
occur. The two ladder sites now read `item.original.categories[0]`,
matching the three sites that already did. The `signal` branch (which
reports `'SECURITY'`) and the `notification` branch (`undefined`) of
those two expressions are unchanged, so nothing about non-lint advisor
items moves. The stale parenthetical is cut from both doc comments.

Net diff is 3 files, -12/+4 lines. No behavior change outside the value
of one optional telemetry property.

## Additional context

**How.** The fix is the pass-through, not an extended ladder. Per the
two options considered:

1. **No lint carries more than one category in practice.** Every lint
fixture in `apps/studio` uses a single-element array (`['SECURITY']`,
`['PERFORMANCE']`). The API type permits a multi-element array, but
nothing in the repo produces one, so the ladder's
SECURITY-over-PERFORMANCE priority is not load-bearing.
2. **The advisors UI already treats the first element as canonical** —
`LinterDataGrid.tsx` L196 renders `<LintCategoryBadge
category={selectedLint.categories[0]} />`.
3. **Extending the ladder would not actually produce agreement.** In the
one reachable multi-category case, a ladder with a `HEALTH` branch
appended still reports the higher-priority category while the three
pass-through sites report `categories[0]`. Only `categories[0]` makes
all five agree, which is the point of the change.

**Reviewers should look at this first — how much data is actually
affected.** Narrower than the headline suggests, and worth stating
precisely. Every surface feeding these events filters lints upstream by
category, and all three filters still admit only `SECURITY` or
`PERFORMANCE`:

- `AdvisorPanel.utils.ts` `createAdvisorLintItems` drops any lint that
resolves to no tab (`if (!tab) return null`), and it is the item source
for **both** ladder surfaces
- `pages/project/[ref]/advisors/security.tsx` filters
`categories.includes('SECURITY')`
- `pages/project/[ref]/advisors/performance.tsx` filters
`categories.includes('PERFORMANCE')`

So a HEALTH-**only** lint is not surfaced anywhere in Studio today and
cannot currently reach any of the five emit sites. The divergence
reachable today is a lint carrying `HEALTH` alongside another category:
it passes the filters, and then the ladder sites and the pass-through
sites disagree. The HEALTH-only omission is latent, and becomes live
data loss the moment HEALTH lints are surfaced — presumably the point of
the API adding the category. Practical consequence: **no backfill or
historical-data caveat is needed**, because no HEALTH-only event was
ever emitted. This is a correctness fix that gets the emit surfaces
right ahead of the category being shown, not a response to an active
data incident.

**How it was tested.** Honest caveat up front: `pnpm install` cannot
complete in this sandbox, so the Studio-scoped checks could not be run
here. `apps/studio` depends on `@std/path` → `npm:@jsr/std__path`, and
the JSR registry is network-blocked in this environment (`GET
https://npm.jsr.io/~/11/@jsr/std__path/1.0.8.tgz` → `403`, both direct
and proxied; `registry.npmjs.org` returns `200`, so it is JSR
specifically). CI on this PR is the real signal for Studio lint,
typecheck, and tests. What did run clean:

- `prettier --config prettier.config.mjs --check` on all three changed
files — clean
- `tsc --noEmit` in `packages/common` (installed via `pnpm install
--filter=common...`) — clean, and `--listFiles` confirms it genuinely
covers both `telemetry-constants.ts` and the widened
`packages/api-types/types/platform.d.ts`
- the changed expression typechecked in a standalone harness against the
real generated `components['schemas']['GetProjectLintsResponse']`,
confirming `categories[0]` is assignable to `AdvisorCategory |
undefined` — with a negative control that correctly errored (`Type
'"HEALTH"' is not assignable to type '"PERFORMANCE" | "SECURITY" |
undefined'`) to prove the harness had teeth

No tests are added. There is no existing test coverage of
`handleItemClick` / `handleCardClick` in either ladder component, and
the change is a narrowing of one expression to match three existing call
sites rather than new logic. Asserting an emitted property value would
require standing up component tests for two components that have none,
which is a larger piece of work than this fix and better done as its own
change.

**Suggested follow-up, deliberately not in this PR.**
`createAdvisorLintItems` and the two advisors pages filter HEALTH lints
out entirely, so the category the API now returns is invisible in
Studio. Whether to surface it is a product decision about a new advisor
category, not a telemetry fix. Also out of scope by request:
`Linter.utils.tsx` badge styling (HEALTH falling back to PERFORMANCE's
badge is harmless).

---
_Generated by [Claude
Code](https://claude.ai/code/session_01Xwj2SotnaHByjbTfqF4Kdm)_

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-08-31 15:48:01 +08:00
5e8a83e11a feat(studio): add explorer_banner_exposed impression event (#49747)
<!-- ccr-slack-attribution -->
_Requested by **Pam Chia** · [Slack
thread](https://supabase.slack.com/archives/C076KTY11DF/p1788139328573799?thread_ts=1788139328.573799&cid=C076KTY11DF)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature (telemetry). Adds one PostHog event.

Linear issue:
[GROWTH-1154](https://linear.app/supabase/issue/GROWTH-1154/telemetry-explorer-feature-preview-banner-has-no-exposure-event-so)

## What is the current behavior?

The Explorer feature preview banner emits
`explorer_banner_dismiss_button_clicked` and
`explorer_banner_cta_button_clicked` (both from
`apps/studio/components/ui/BannerStack/Banners/BannerExplorer.tsx`,
shipped in #49606), and nothing else. With no impression event there is
no denominator, so no click-through or dismiss rate can be reported.

## What is the new behavior?

`explorer_banner_exposed` fires when the banner content is rendered, at
most once per page load.

The event is declared in `packages/common/telemetry-constants.ts` next
to the two existing Explorer banner events and added to the
`TelemetryEvent` union, following the existing `*_exposed` family. It
carries no custom properties; `project` and `organization` groups are
attached by `apps/studio/lib/telemetry/track.ts`.

**Verification:**

- `prettier --check` on both changed files: passing
- `tsc --noEmit` in `packages/common`, which covers the new event
interface and the `TelemetryEvent` union: passing
- Studio-scoped lint, typecheck, and tests: green on CI
- Browser-tested on the studio-staging preview (Playwright): the
exposure event fires exactly once per page load (201 on the wire), does
not re-fire on client-side navigation or banner hover within the same
page load, fires again after a full reload, and does not fire after
dismissal; the CTA and dismiss click events are unchanged and carry the
`project`/`organization` groups

**Out of scope:**

- Pre-consent drops: every telemetry event waits for consent, so this
event degrades the same way the rest of the `*_exposed` family does
(transient, recovers on the next page load). A family-wide fix is a
separate issue.
- Mirroring the `explorer` flag state into event properties: redundant
once exposure exists.
- The CTA handler not dismissing the banner: raised separately, both
click handlers untouched.
-
[GROWTH-1153](https://linear.app/supabase/issue/GROWTH-1153/telemetry-advisorcategory-omitted-for-health-lints-on-two-of-five)
and its draft PR #49746: separate issue, no overlap.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01Xwj2SotnaHByjbTfqF4Kdm); reworked
per Pam's review._

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-08-31 15:47:43 +08:00
Alaister YoungandAlaister Young 2c76bb371b chore(studio): gate dead code with knip in CI (#49721)
Makes knip a CI gate for Studio so dead files and unused dependencies
fail the PR instead of piling up. Third PR in the stack, on top of
#49719 (dead code) and #49720 (unused deps), which get Studio to a clean
run.

**Changed:**
- knip `pnpx knip@~5.50.0` → root devDependency `knip@6.32.3`, `pnpm
knip` now runs it. The old `pnpx` form was actually broken: it resolved
knip's `typescript` peer to TS 7 and crashed with
`ts.getDefaultLibFilePath is not a function`. (6.33.0 is newer but
blocked by `minimumReleaseAge`.)
- `knip.jsonc` rewritten for v6 with a `workspaces["apps/studio"]`
block. Framework-convention files (`router.tsx`, `start.ts`,
`routes/**`, `compat/**`, `api/server.js`) are `entry` rather than
`ignore` — an ignored file's imports aren't traced, which is how
`ShellFallback.tsx` (only imported from `routes/__root.tsx`) was being
reported as dead. knip 6's Next.js plugin already covers
`instrumentation*.ts`, `proxy.ts`, `pages/**`; its tanstack-router
plugin only looks under `src/`, hence the manual entries. Narrow
`ignoreIssues` for graphql-codegen output and the `CONSTRAINT_TYPE`
enum; `ignoreDependencies` for the five implicit deps from #49720, each
with a comment; `ignoreBinaries: ["vercel"]`.
- `apps/studio/CLAUDE.md`: one bullet on the gate and where framework
files go.

**Added:**
- `.github/workflows/studio-knip.yml` — path-filtered to
`apps/studio/**` + knip/pnpm config, mirrors `studio-lint-ratchet.yml`'s
setup (no sparse checkout: knip needs every workspace's `package.json`
to resolve the graph). Runs `pnpm knip --workspace apps/studio
--reporter symbols --reporter github-actions` so findings show up as
inline PR annotations. ~5s locally.

Scope notes: the gate is Studio-only — the full-monorepo run still has
~400 dead files in `www`/`docs`/`blocks`, which is a separate effort.
`exclude: ["types", "exports"]` is kept, so unused exports aren't gated
yet, but `enumMembers`/`duplicates` are (they caught real things in
#49719).

## To test

- `pnpm knip --workspace apps/studio` exits 0 on this branch
- The `Studio Dead Code (knip)` workflow runs on this PR and is green
- Sanity-check the gate bites: add a throwaway
`apps/studio/lib/unused.ts`, run `pnpm knip --workspace apps/studio` →
reports it and exits 1


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **CI**
* Added automated dead-code and unused-dependency checks for the Studio
workspace on relevant pushes and pull requests.
* Results appear in workflow summaries and as inline pull request
annotations.

* **Maintenance**
  * Improved analysis of framework-convention files and Studio code.
* Standardized the local code-quality check and updated its
configuration support.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-31 11:28:55 +08:00
Alaister YoungandAlaister Young 3260053e52 chore(studio): remove unused dependencies found by knip (#49720)
Removes the Studio dependencies knip reports as unused, and declares one
it reports as unlisted. Second PR in the stack (on top of #49719,
followed by #49721 which adds the CI gate).

**Removed:**
- `@ai-sdk/provider`, `@ai-sdk/provider-utils` — zero references
- `eslint-plugin-jsx-a11y` — the `jsx-a11y/*` rules resolve through the
plugin registered by `eslint-config-next` (via
`eslint-config-supabase/next`); verified 259 a11y warnings still fire
after removal
- `common`, `config` from `devDependencies` — duplicates of the
`dependencies` entries

**Added:**
- `@tailwindcss/postcss` as a Studio devDependency —
`apps/studio/postcss.config.cjs` loads it (through
`config/postcss.config`), but only `packages/config` declared it, so
under pnpm's strict isolation it was never resolvable from Studio's own
`node_modules`

**Kept deliberately** (nothing imports them by a specifier knip can
follow, but removing them breaks things — they get `ignoreDependencies`
entries in #49721): `lodash-es` (string-resolved in `vite.config.ts`),
`raw-loader` (loader string in `next.config.ts`), `import-in-the-middle`
/ `require-in-the-middle` (Sentry/OTel runtime hooks, #35030),
`@babel/core` (resolution pin, #45876).

Heads-up on the lockfile: ~500 of the lines are pnpm re-resolving
`apps/www`'s stale auto-installed vitest peer from `vite@6.4.3` →
`8.2.1` (www doesn't depend on vite directly; Studio already runs vitest
on vite 8). Any dependency change triggers it — not specific to this PR.

## To test

- `pnpm install --frozen-lockfile` succeeds
- `pnpm dev:studio` — Tailwind styles still apply (the postcss plugin
now resolves from Studio)
- `pnpm lint --filter=studio` still reports `jsx-a11y/*` warnings, no
"Definition for rule not found"
- `pnpm --filter www test` (www's vitest now runs on vite 8)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated Studio’s development tooling configuration.
  * Removed unused package dependencies and development tools.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-31 11:17:51 +08:00
Danny White 0b27205ae4 fix(studio): clarify fast database reboot (#49741)
## What kind of change does this PR introduce?

Bug fix. Resolves DEPR-657.

## What is the current behavior?

The Fast database reboot description suggests the action may fail to
recover from some failure modes, which can be read as a risk of the
reboot itself.

## What is the new behavior?

The description clearly explains that the faster option restarts only
the database service, has less downtime than a full project restart, and
leaves other project services running.

| Before | After |
| --- | --- |
| <img width="1460" height="512" alt="CleanShot 2026-08-31 at 09 24
49@2x"
src="https://github.com/user-attachments/assets/2d4a940c-4d66-4753-99d8-9d0d2b4951af"
/> | <img width="1458" height="500" alt="CleanShot 2026-08-31 at 09 31
18@2x"
src="https://github.com/user-attachments/assets/f58aa351-5c8c-4a9a-b31d-b771659defd3"
/> |

## To test

1. Open a project's **Settings > General** page.
2. Under **Project availability**, tab to **Restart project**, then tab
again to the adjacent chevron button.
3. Press Enter and confirm focus moves to **Fast database reboot**.
4. Confirm its description reads: “Restarts only the database service,
with less downtime than a full project restart. Other project services
remain running.”
5. Confirm the project availability descriptions appear as secondary
text beneath their action labels.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Accessibility Improvements**
* Improved keyboard navigation with separate tab stops for restart
actions and restart-type selection.
* Added clearer labeling and focus behavior when choosing a restart
type.

* **UI Improvements**
* Clarified that fast database restarts affect only PostgreSQL while
other services continue running.
  * Improved text contrast on the project settings page.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 13:01:17 +10:00
Alaister YoungandAlaister Young b0e31be89a chore(studio): remove dead code found by knip (#49719)
Removes Studio code that nothing imports, as reported by knip. First PR
in a stack of three: this one is pure deletions, #49720 removes the
unused dependencies, #49721 upgrades knip and adds the CI gate so this
doesn't accumulate again.

Every file was verified with a repo-wide grep for its basename, exported
symbols, and string/dynamic imports before deletion — none are reachable
via `next/dynamic`, a barrel file, or a config.

**Removed:**
-
`Billing/Usage/UsageWarningAlerts/{CPU,RAM,DiskIOBandwidth}Warnings.tsx`
(whole directory)
- `DataWarehouse/FormFooterChangeBadge.tsx` (whole directory)
- `Database/Replication/ReplicationDiagram/EmptyReplicationDiagram.tsx`
- `Integrations/Vercel/OrganizationPicker.tsx`
- `QueryInsights/QueryInsightsTable/QueryInsightsTableRow.tsx`
- `hooks/misc/useTrackExperimentExposure.ts`
- `data/ai/{parse-client-code,sql-policy}-mutation.ts`,
`data/misc/parse-query-mutation.ts`,
`data/database/table-check-rls-mutation.ts`
-
`data/notifications/notifications-v2-{archive-all-mutation,summary-query}.ts`
+ their two now-unused keys in `notifications/keys.ts` (`listV2` kept)
-
`data/platform-apps/platform-app-{update,signing-key-delete}-mutation.ts`
- `DateTimeFormats.DATE_ONLY` and the unused
`Notebooks.{MarkdownCell,LogCell,ChartConfig}` types

**Changed:**
- `ReportPadding` no longer has a duplicate default export; its 9
default importers (observability pages) now use the named export

Not removed: `CONSTRAINT_TYPE`'s unused members mirror the closed set of
`pg_constraint.contype` values, so they're documentation rather than
dead code — suppressed narrowly in #49721's knip config instead.

## To test

- `pnpm --filter studio run typecheck` and `lint:ratchet` pass
- Observability pages (`/project/[ref]/observability/*`) still render
with padding — they're the only code touched, via the `ReportPadding`
import change
- Notifications popover still loads and marks-as-read (the removed keys
weren't used for invalidation)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Removed Features**
  - Removed CPU, memory, and disk usage warning alerts.
- Removed the Vercel organization picker and empty replication diagram.
  - Removed query insights row actions and several SQL assistance tools.
  - Removed notification summary and archive-all capabilities.
  - Removed platform app update and signing-key deletion actions.
- Removed the form change-count badge and experiment exposure tracking.

- **Refactor**
- Updated observability reports to use the revised report layout export.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-31 10:55:23 +08:00
Danny White 8439b0c77e fix(www): prevent Safari publicity logo clipping (#49742)
## What kind of change does this PR introduce?

Bug fix for
[DEPR-658](https://linear.app/supabase/issue/DEPR-658/fix-clipped-v0-and-langchain-logos-in-safari).

## What is the current behavior?

Inline publicity logos reuse the same SVG clip-path ID. Safari can
resolve v0 and LangChain against another logo's clipping rectangle,
causing the artwork to appear cropped or letterboxed.

## What is the new behavior?

Each publicity logo uses a namespaced clip-path ID. A focused regression
test verifies that SVG IDs are unique and every `url(#...)` reference
has a matching definition.

| Figure |
| --- |
| Before |
| <img width="2200" height="388" alt="CleanShot 2026-08-31 at 09 58
44@2x"
src="https://github.com/user-attachments/assets/99ef02e4-e436-4155-880a-6291364ea4cd"
/> |
| After |
| <img width="2196" height="370" alt="CleanShot 2026-08-31 at 09 58
00@2x"
src="https://github.com/user-attachments/assets/d36a9b83-737b-47f1-9f12-a110b3c82f23"
/> |

## To test

1. Open the deploy preview homepage in Safari.
2. Scroll to “Trusted by fast-growing companies worldwide”.
3. Confirm the v0 and LangChain logos are fully visible and the other
publicity logos are unchanged.
2026-08-31 10:12:33 +10:00
Charis 86c813ec03 fix(notebooks): reset insert offset when anchor cell moves (#49694)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

When a cell gets moved via `move_cell` operation in
`deriveNotebookDiff`, the `insertedAfter` offset map is not cleared for
that anchor cell. This causes later `insert_cell` operations anchored on
the same (now-moved) cell to apply the stale offset on top of the
correct current-position lookup, resulting in the new cell landing after
the wrong position.

## What is the new behavior?

The offset for an anchor cell is now cleared from `insertedAfter` when
it gets moved, since cells previously inserted after it stay behind at
its old location and should not affect subsequent inserts at its new
position.

A regression test has been added that reproduces the exact ticket
scenario (insert after cell-1, move cell-1 after cell-3, insert after
cell-1 again) and verifies the correct final cell order.

## Additional context

Fixes:
https://linear.app/supabase/issue/FE-4308/insert-anchored-to-a-previously-moved-cell-lands-after-the-wrong-cell

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed notebook cell insertions after moving an anchor cell, ensuring
new inserts appear relative to the anchor’s updated position.
* Preserved the placement of inserts made before the anchor cell was
moved.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 12:12:04 -04:00
claude[bot]andClaude 8790e657e9 feat(ai): include org slug in Assistant Braintrust span metadata (#49692)
<!-- ccr-slack-attribution -->
_Requested by **Matt Rossman** · [Slack
thread](https://supabase.slack.com/archives/D0A79RYJKRB/p1787926891744399)_


# Problem

Assistant spans in Braintrust record only the numeric `orgId`, whereas
support tickets show org slug.

This incurs an extra manual step to resolve the ID through admin studio
before the trace can be found.

# Fix

Adds `orgSlug` to spans, sourced from the same verified org lookup that
produces `orgId`.

Renamed the request body's `orgSlug` to `rawOrgSlug` to distinguish the
verified slug from getAIDetails, following the existing
rawRequestedModel / requestedModel pattern.

## How to review

See sample trace
[94863b6d-aaa9-449a-a9c9-981ad40e614a](https://www.braintrust.dev/app/supabase.io/p/Assistant/trace?object_type=project_logs&object_id=5a8d02e5-b3b6-40cc-ba76-ecee286478f4&r=223112cd-33f4-45c4-a273-8d3781689448&s=223112cd-33f4-45c4-a273-8d3781689448)
produced from sending a chat from the
[Preview](https://studio-staging-git-mattrossman-ai-1149-include-698a5f-supabase.vercel.app/dashboard/org)
on this PR.

Note it now includes the org slug in span metadata:

<img width="873" height="548" alt="CleanShot 2026-08-28 at 10 59 49@2x"
src="https://github.com/user-attachments/assets/bcf47a94-6782-434a-9006-c7b9c95f1c37"
/>

If desired you can test yourself too by chatting with Assistant in the
preview and looking up the corresponding Chat ID from Braintrust
[logs](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs).

Closes AI-1149

---
_Generated by [Claude
Code](https://claude.ai/code/session_01N2ziJech9dV19pJ9MisYdX)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-28 11:48:38 -04:00
Kamil Ogórek 95954ab81b fix: attempt project wake only if its in ACTIVE_HEALTHY state (#49693)
There is no point in trying to wake up a project that is not
`ACTIVE_HEALTHY` as it will always fail.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved project wake-up behavior by limiting automatic wake-ups to
hibernating projects with a healthy active status.
  * Prevented unnecessary wake-up attempts for projects in other states.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 11:31:32 -04:00
Joshen Lim f1e0808223 Disable analyze button for notebooks if notebook is empty (#49674)
## Context

As per PR title - just disables the analyze button if the notebook is
empty

<img width="1077" height="323" alt="image"
src="https://github.com/user-attachments/assets/f8da8bd4-eb0c-43ae-85c7-b60c1c7dcfed"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Disabled the Analyze action for empty notebooks.
* Added guidance prompting users to add a cell before starting analysis.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 09:47:36 -04:00
Joshen Lim c4fe153fd8 Joshenlim/fe 4290 add save to notebook button in query tabs (#49667)
## Context

Adds a "Save" action for query tabs in the explorer, which opts for 2
options to either add to an existing notebook, or create a new notebook.
Both of these actions just opens the notebook in a new tab with unsaved
changes - the changes will only be persisted in the DB when the user
hits "Save" on the notebook.

For adding to an existing notebook, the snippet will be appended to the
bottom of the notebook - UI will scroll to the bottom after navigating
to the notebook.
<img width="469" height="368" alt="image"
src="https://github.com/user-attachments/assets/19d16940-89e2-4d10-b71e-8d501f749668"
/>
2026-08-28 08:21:16 -04:00
Alaister YoungandAlaister Young 29493e02d0 [FE-4010] feat(studio): add read-only replica connection option for HA projects (#49485)
For Multigres (HA) projects you can't connect to read replicas directly
— reads go through a read-only load balancer on the primary's host at
port 5433. Since #44695 stripped the pooler UI, HA projects showed no
source option at all in the Connect dialog and still prompted for the
IPv4 add-on. This surfaces it as a first-class, clearly-labeled
read-only source. In the UI it's labeled `Replica (read-only)` rather
than "load balancer" — the primary goes through the same gateway, so
"load balancer" would be confusing from a product perspective
(internally the `load-balancer` source identifier and
`HIGH_AVAILABILITY_LOAD_BALANCER_PORT` constant keep their names).

<img width="883" height="342" alt="Screenshot 2026-08-24 at 11 32 26 PM"
src="https://github.com/user-attachments/assets/3716f6dd-0325-4b9d-adbc-9ece9244de62"
/>

**Added:**
- Source select for HA projects in the Direct tab: `Primary database` +
`Replica (read-only)` (individual replica rows are filtered out —
they're only reachable via the load balancer)
- Replica (load balancer) connection strings on all 9 connection types:
primary host, port `5433`, with the Multigres-required
`sslmode=require&sslnegotiation=direct` params (JDBC gets the
`sslNegotiation` spelling, .NET gets `SSL Negotiation=Direct`)
- `Read-only` badge on the connection code block + note pointing writes
at the primary
- Programmatic labels for the ConnectSheet select/switch/multi-select
fields (the Source combobox previously had no accessible name)

**Changed:**
- The generated-file step (Node.js/Golang/.NET/Python/SQLAlchemy) is now
source-aware — it previously ignored the Source selection entirely (also
affected read replicas on normal projects) and silently rendered the
primary's connection info
- .NET template now emits `Port=` (Npgsql defaults to 5432 when omitted)
and the install step actually installs Npgsql (pinned 9.0.5 — `SSL
Negotiation` requires 9+)
- SQLAlchemy `DATABASE_URL` merges `sslmode=require` into the string's
existing query params instead of a hardcoded suffix that could drop TLS
- Source option labels normalized to sentence case (`Primary database`,
`Read replica (…)`)
- `MultipleCodeBlock` (ui-patterns) accepts an optional `className`
- HA coercion in `useConnectState` extended: a stale replica
`connectionSource` restored from URL/localStorage falls back to the
primary

**Removed:**
- IPv4 add-on admonition for HA projects (the forced-direct method was
tripping it; the add-on doesn't apply to Multigres)

Out of scope (needs platform work): SQL editor / Data API / other
`DatabaseSelector` surfaces — executing against the load balancer
requires a platform-issued connection string, and the load-balancers API
only returns a REST endpoint today. The `5433` port is a client-side
constant (`HIGH_AVAILABILITY_LOAD_BALANCER_PORT`) until the API exposes
it.

## To test

On an HA (Multigres) project:
- Open Connect → Direct: Source shows exactly `Primary database` and
`Replica (read-only)`; selecting the replica shows
`…@<primary-host>:5433/postgres?sslmode=require&sslnegotiation=direct`,
a `Read-only` badge, and the read-only note
- Cycle all 9 connection types with the replica selected — every snippet
carries port 5433 (`.NET` includes `Port=5433;…;SSL
Negotiation=Direct`), badge/note persist
- No "Enable IPv4 add-on" admonition anywhere in the Direct tab
- Switch tabs / hard-reload: source resets to primary with no stale
badge/string combos

On a normal project:
- Direct tab unchanged: no `Replica (read-only)` option, pooler badges
and IPv4 admonitions behave as before, `.NET` now shows `Port=5432` and
no `SSL Negotiation`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added read-only load-balancer connection options for high-availability
projects.
- Added .NET and SQLAlchemy connection examples with required SSL
settings.
- Added clear read-only labels and notices explaining write
restrictions.
- **Bug Fixes**
  - Suppressed IPv4 add-on notices for high-availability connections.
  - Improved connection-source selection and restored-setting handling.
  - Improved connection form identification and accessibility.
- **Style**
  - Added customizable styling support for multi-code-block displays.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-28 10:43:55 +01:00
59c8ea3ddc docs(BRA-282): clarify that branches are created as clones of the base project (#49594)
## What kind of change does this PR introduce?

Docs update.


## What is the new behavior?

The branching docs now state consistently that every branch, preview or
persistent, is created as a clone of the base project, starting with
that project's schema, Edge Functions, and configuration. Data and
storage objects are not cloned by default.

## Additional context

This documents new branch-creation behavior. Two automated reviewers
flagged the clone wording and argued for a migration-replay description;
that reflects the previous implementation, so their findings don't apply
here and the clone framing stands.

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
2026-08-28 17:35:24 +08:00
Jordi Enric 5fd2023708 feat(studio): worker detail page (FE-4189, FE-4197) (#49195)
## What

The worker detail page at `/project/[ref]/workers/[name]`, reading `GET
/v2/projects/{ref}/workers/{name}`. Base: #49194.

## How to test

Only on the **Mockamaster** project in staging — it is the one project
in the alpha allow-list.

1. Staging dashboard → Mockamaster → **Workers** → click
`dashboard-test`
2. Overview: instances read 1 declared / 1 live / 1 ready / 0 stale, no
error alerts
3. Settings: Deno 2, `denoland/deno:latest`, 2 GB · 1 vCPU, private, US
West (locked)
4. **How to call** in the header → the snippets name the real worker URL

No write actions. Delete (FE-4190) is deliberately out.

Closes FE-4189
Closes FE-4197

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added worker detail pages with overview, requests, logs, builds, and
settings tabs.
* Added worker metadata, runtime details, invocation examples, and local
development commands.
* Added worker log streams with refresh, row selection, loading, empty,
and error states.
* Added worker-specific log formatting and clearer instance status
information.
* **Documentation**
  * Updated migration tracking to mark the worker route as complete.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 11:30:35 +02:00
Pamela ChiaandAleksi Immonen 35531ea2f4 feat(www): serve openapi spec at /openapi.json (#49587)
Agent-readiness scanners and agent fetchers look for an OpenAPI spec at
conventional same-origin paths, but the Management API spec is only
served on api.supabase.com and linked from the /.well-known/api-catalog
linkset, which scanners do not read. I added a rewrite so
supabase.com/openapi.json proxies the spec from its source of truth at
api.supabase.com/api/v1-json, using the same fall-through proxy
mechanism as /humans.txt and /evals.

**Note:** no cache or CORS headers on purpose: no consumer needs them
today, and the upstream response's set-cookie header defeats edge
caching regardless. I rejected a checked-in copy of the spec in favor of
proxying live (staleness). The /.well-known/api-catalog linkset already
points at the spec (PR #44880) and is untouched here; this PR only adds
the conventional same-origin path.

**Merge order:** merge only after supabase/platform#37571 deploys. The
spec currently ships `servers: []`, so OpenAPI consumers resolve
relative paths against the fetch origin; without the platform fix this
proxy would point spec-compliant clients at supabase.com/v1/*.

## To test
Tested on Vercel preview:
- [x] `curl -s https://<preview-url>/openapi.json | head -c 40` returns
`{"openapi":"3.0.0"`
- [x] `curl -sI https://<preview-url>/openapi.json` returns 200 with
`content-type: application/json`
- [x] `curl -sI https://<preview-url>/humans.txt` returns 200 (control:
rewrite fall-through chain intact)

## Linear
- fixes GROWTH-1138


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added access to the OpenAPI specification at `/openapi.json`.
  * Requests are automatically routed to the API specification endpoint.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Aleksi Immonen <aleksi@supabase.io>
2026-08-28 17:26:43 +08:00
Danny White 27dba8d02d fix(studio): group pipeline destinations by release stage (#49669)
## What kind of change does this PR introduce?

UI clarity improvement for the current pipeline creation sheet.

## What is the current behavior?

All destination types appear under a generic Pipelines heading, with
release-stage badges repeated beside each option.

## What is the new behavior?

Destination types are grouped under Public Alpha, Early Access, and
Deprecated headings. The selected value stays compact, while its
release-stage guidance remains below the field.

| Before | After |
| --- | --- |
| <img width="1280" height="750" alt="CleanShot 2026-08-28 at 15 45
29@2x"
src="https://github.com/user-attachments/assets/5be32928-21fa-4911-bc68-3376c068703f"
/> | <img width="1280" height="888" alt="CleanShot 2026-08-28 at 15 44
49@2x"
src="https://github.com/user-attachments/assets/2046d174-dd4f-41f1-98da-3d8d48af8a1c"
/> |

## To test

1. Open a project, then go to Database → Replication and select Add
destination.
2. Open the Type selector.
3. Confirm available destinations are grouped by Public Alpha, Early
Access, and Deprecated.
4. Select BigQuery and confirm the field still explains that it is in
public alpha.
5. Edit an existing destination and confirm the Type selector remains
disabled.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **UI Improvements**
* Destination options are now organized into clear release-stage groups:
Public Alpha, Early Access, and Deprecated.
* Added group headings and separators to make destination selection
easier to scan.
* Removed individual stage badges from destination labels for a cleaner,
more consistent layout.

* **Tests**
* Updated coverage to verify grouping and visibility across supported
destination types.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 17:37:44 +10:00
Danny White 19e3844a0e feat(studio): upload BigQuery pipeline credentials (#49668)
## What kind of change does this PR introduce?

Feature improvement for BigQuery pipeline creation and editing.

## What is the current behavior?

Users must paste the complete service-account JSON into a text area.

## What is the new behavior?

Users can paste, upload, or drag and drop a service-account JSON file.
Imported credentials remain editable, and unreadable or oversized files
show an inline form error.

## To test

1. Open a project, then go to Database → Replication and select Add
destination.
2. Select BigQuery.
3. Under Service account key, select Upload JSON file and choose a
service-account `.json` file.
4. Confirm its contents appear in the editable text area.
5. Drag and drop a JSON file onto the same field and confirm it replaces
the contents.
6. Confirm pasting credentials manually still works.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added support for uploading BigQuery service account key JSON files.
  * Added drag-and-drop support for service account key files.
  * Updated guidance to clarify that keys can be pasted or uploaded.
  * Constrained the service account key field to 5,000 characters.

* **Bug Fixes**
  * Added clear validation when keys exceed the character limit.
* Improved handling of unreadable files while preserving the existing
key.
  * Improved editing of imported service account key content.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 17:37:31 +10:00
Danny White 02bb456647 fix(studio): clarify pipeline form guidance (#49666)
## What kind of change does this PR introduce?

UI copy improvement for the current pipeline creation sheet.

## What is the current behavior?

Several pipeline fields use ambiguous labels or omit useful guidance.
Validation messages also use inconsistent punctuation.

## What is the new behavior?

- Explains how the pipeline name is used
- Clarifies invalidated replication slot behaviour
- Explains that BigQuery maximum staleness is optional
- Makes pipeline validation messages consistent

## To test

1. Open a project, then go to Database → Replication and select Add
destination.
2. Confirm Name explains that it identifies the pipeline in Supabase.
3. Expand Advanced settings and confirm Invalidated slot behaviour uses
Block startup and Recreate slot.
4. Select BigQuery and confirm Maximum staleness explains that leaving
it blank gives the freshest results.
5. Submit incomplete destination settings and confirm validation
messages end with full stops.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Replication slot behavior options now use clearer labels: “Block
startup” and “Recreate slot.”
* Added guidance explaining that the pipeline name identifies the
pipeline in Supabase.
  * Improved the BigQuery maximum-staleness description and display.

* **Bug Fixes**
* Standardized replication destination validation messages with
consistent punctuation.
  * Clarified the ClickHouse HTTPS validation message.
  * Updated validation tests to reflect the improved error messages.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 17:37:08 +10:00