mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 03:15:06 +03:00
chore/function-recent-errors
20627
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
6edef9f067 |
chore(www): unpublish the Launch Week 6 page (#49281)
Closes [FE-4100](https://linear.app/supabase/issue/FE-4100/www-remove-httpssupabasecomlaunch-week6) ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content removal. ## What is the current behavior? `/launch-week/6` is still published. Launch Week 6 ran in December 2022. The page carries its own 1,085-line component, two CSS modules, and a Supabase client that reads the `lw6_creators` and `lw6_tickets` tables. ## What is the new behavior? - Delete the `/launch-week/6` page, its CSS modules, its day data, and its types. - Redirect `/launch-week/6` to `/blog/launch-week-6-wrap-up`, which holds the same content. - Drop the Launch Week 6 card from the archive section on `/launch-week/8`, leaving Launch Week 7. ## Additional context Scope is Launch Week 6 only. Whether the other launch week pages come down is still open with marketing. Assets under `public/images/launchweek/` are untouched. Several are shared across launch weeks, so they need their own audit. ## Manual testing 1. Open [https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/6](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/6) on the deploy preview. It returns a 308 and lands on `/blog/launch-week-6-wrap-up`. 2. Open [the Launch Week 7 page](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/7). It still loads. 3. Open [the Launch Week 8 page](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/8) and scroll to "Previous Launch Weeks". Only the Launch Week 7 card shows. Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
7d28bcc26b |
joshenlim/fe 4204 notebooks intellisense toggle (#49300)
## Context Adds an intellisense toggle for explorer notebooks similar to SQL editor + have QueryEditor render definitions via `useAddDefinition` <img width="259" height="162" alt="image" src="https://github.com/user-attachments/assets/278fdabd-1a24-4769-972e-1bce29060463" /> So intellisense will be running in the QueryEditor if intellisense is enabled + source selected is database, otherwise will not run. <img width="982" height="411" alt="image" src="https://github.com/user-attachments/assets/19497aa0-36fc-49ab-853d-cb938b5b18e7" /> Also updated `useAddDefinition` logic to flush the table columns + functions cache in react query - For context in the past we had users run into browser performance issues when definitions were loaded if their database is really big - Hence why we originally added this intellisense toggle - But we previously also required users to refresh the browser after disabling intellisense, as a manual way to flush the cache - So this change should remove the need to refresh the browser after disabling intellisense <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added PostgreSQL IntelliSense with definitions, formatting, and code completions in SQL editors. * Added a notebook option to enable or disable IntelliSense, with the preference saved between sessions. * Improved the notebook’s empty-state appearance. * **Bug Fixes** * Improved IntelliSense cleanup and prevented duplicate registrations when disabled. * Improved query execution state handling while background IntelliSense data loads. * **Tests** * Added coverage for shared registration, cleanup, preference persistence, and IntelliSense-related query handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9738035fec |
Hook up recently updated list (#49296)
## Context As per PR title: recently updated list just comprises of notebooks and chats Note: known API issue that save a notebook doesn't update its `updated_at` value, so you'll notice that if you save a notebook it doesn't move up the recently updated list <img width="281" height="270" alt="image" src="https://github.com/user-attachments/assets/f637a593-09a7-4df4-85b7-43637f04738d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a home view displaying recently updated notebooks and chats. * Recent items are sorted by update time and limited to five entries. * Added relative timestamps in minutes, hours, or days. * Chat entries open directly, while notebook entries link to their explorer view. * Added an empty state when no recent items are available. * **Bug Fixes** * Excluded unsupported chat types from recent-item results. * Improved handling of unavailable timestamps. * **Tests** * Added coverage for sorting, filtering, limits, and relative-time formatting. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e7c3cad8de |
feat(evals): add notebook eval cases and forbiddenTools scorer capability (#49104)
## Summary - Added ~11 new eval cases for Notebooks AI assistant evals, including: basic notebook cell creation, multi-cell composition (markdown+database+log), log cell time ranges, row_limit defaults, chart config, destructive SQL safety warnings, and hallucination guards for nonexistent tables - Extended `toolUsageScorer` with deterministic `forbiddenTools` field to score both required and forbidden tool usage, enabling eval cases to assert tool choice (e.g., `execute_sql` vs `create_notebook`) without LLM-as-judge - Extended SQL validators (`sqlSyntaxScorer`/`sqlIdentifierQuotingScorer`) to validate SQL inside `create_notebook` database cells (log cells deliberately excluded as they use ClickHouse dialect) - Fixed two real assistant issues in `NOTEBOOKS_PROMPT`: (a) reuse `CLICKHOUSE_LOGS_COMPLETION_INSTRUCTIONS` and schema section to prevent incorrect BigQuery-style SQL in logs queries, (b) require schema verification before writing `database_cell` to prevent queries against nonexistent tables Resolves FE-4087 ## Test plan - All 11 new eval cases run live against OpenAI via Braintrust; traces inspected and validated - Existing unit tests, lint, and typecheck pass <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for creating notebooks with database, Markdown, chart, and log cells. * Improved handling of reusable notebook requests versus one-off SQL queries. * Added guidance for modern ClickHouse SQL and absolute log time ranges. * **Bug Fixes** * Improved SQL validation, row-limit enforcement, and destructive-query safety. * Prevented invalid or nonexistent-table queries from being accepted. * Improved validation of notebook cell types and tool usage. * Improved handling of ClickHouse log queries and database-cell SQL. * Improved evaluation reliability by limiting concurrent test execution. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2e65e82ef4 |
docs(platforms): query logs via the ClickHouse endpoint (#49299)
The `logs.all` Management API endpoint runs BigQuery SQL and is being
retired next month. The Platforms guide was the only hand-written doc
still pointing at it.
Repoints the debugging example at `GET
/v1/projects/{ref}/analytics/endpoints/logs`, which serves the same data
as a single `logs` table keyed by `source`, with structured fields in
the `log_attributes` map, and converts the query to the ClickHouse
dialect.
Verified by running the example's exact SQL and curl shape against a
real project on the OTEL logs endpoint: 100 rows, with `status_code` and
`path` populated.
The generated API specs still list `logs.all`; those regenerate from the
platform side.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Documentation**
- Updated the Supabase for Platforms integration guide’s
debugging-projects example.
- Revised the example to use the analytics logs endpoint and unified
logs table.
- Added ClickHouse SQL filtering for edge logs, structured log
attributes, and HTTP errors.
- Improved the example’s alignment with current log query and analytics
capabilities.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
6c6ac567b1 |
feat(studio): workers list behind the workers flag (FE-4188) (#49193)
## What
The Workers list page at `/project/[ref]/workers`, behind
`useFlag('workers')`. Reads `GET /v2/projects/{ref}/workers`.
- Sidebar and command-menu entries, both hidden when the flag is off
- Name search, state and access filters, pagination
- Read-only
Gating, in order: flag off redirects to the project home; a 404 from the
API means the project is outside the alpha allow-list ("not enabled for
this project"); a 403 means the caller lacks the permission
(`NoPermission`); anything else is an `AlertError`.
`parseWorker` in `data/workers/workers.utils.ts` is the only place the
API shape becomes the view model. It validates with zod, so a drifted
response fails the query instead of half-rendering a row.
## How to test
Only on the **Mockamaster** project in staging — it is the one project
in the alpha allow-list, and standing a worker up anywhere else is
involved right now.
1. Staging dashboard → Mockamaster → **Compute** in the sidebar
2. Expect the `dashboard-test` worker: state `Active`, runtime Deno,
private, US West, 2 GB · 1 vCPU · 1 inst
3. Open any other project's `/workers` URL → "Compute is not enabled for
this project"
4. Turn the `workers` flag off → the sidebar entry disappears and the
URL redirects to the project home
Closes FE-4188
|
||
|
|
01d12e83c1 |
docs: migrate logs queries to ClickHouse and link to the SQL Editor (#49273)
The 47 BigQuery-era logs queries across these 20 pages error on the
ClickHouse-backed logs engine ("Backend error! Retry your query."). This
converts them per the rules in `apps/studio/lib/ai/clickhouse-logs.ts`
and repoints every Logs Explorer link at the SQL Editor with the query
source set to **Logs**, since the Logs Explorer is being retired. Also
fixes two stale PostgreSQL 12 links in the tables guide.
Each of the 14 prefilled links was verified to decode back to exactly
the SQL shown on its page. One caveat for review:
`response.headers.proxy_status` in `postgrest-error-codes.mdx` is
unverified — it isn't in the published field reference, and the test
project had no `edge_logs` traffic to confirm against.
Fixes DOCS-1331
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Documentation**
- Updated database, storage, API, and Edge Function logging guides to
use the SQL Editor and current Logs interface.
- Replaced legacy Log Explorer and BigQuery examples with current query
syntax and structured log fields.
- Refreshed troubleshooting queries for error diagnosis, filtering,
aggregation, and performance analysis.
- Improved examples with clearer source filters, status handling,
request details, joins, and result limits.
- Updated PostgreSQL documentation links and clarified how API error
codes appear in responses.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Jordi Enric <jordi.err@gmail.com>
|
||
|
|
344656edc5 |
fix(auth): add limits to session timouts and reuse inverval (#49312)
Currently, sessions timeouts and reuse interval inputs accepted any values. This PR caps: - absolute session timeout to 1 year - inactivity timeout to 1 year - refresh token reuse interval to 300 seconds Since these maximums are introduced _after_ some projects have values that exceed the new limits, we allow the users to save the form if their values exceed the max but are unchanged. However, if they decide to change the value, it must fit within the limits. <img width="1195" height="402" alt="Screenshot 2026-08-20 at 15 45 49" src="https://github.com/user-attachments/assets/192420e8-4878-4e4b-9d82-0d1cc4074728" /> <img width="1194" height="512" alt="Screenshot 2026-08-20 at 15 46 06" src="https://github.com/user-attachments/assets/bb333c54-daa3-46ac-b144-96263428f4d7" /> <img width="1168" height="323" alt="Screenshot 2026-08-20 at 15 46 35" src="https://github.com/user-attachments/assets/ae38fcf6-bc73-453f-a61b-2d6f2d0ecfee" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Added clear maximum-value guidance for session and refresh-token settings. * Existing projects with previously configured values above new limits can retain those values while making unrelated changes. * Removed session-related settings from the protection authentication form. * **Bug Fixes** * Improved validation for session timeouts, JWT expiration, and refresh-token reuse intervals. * Added clearer validation messages and support for reducing previously over-limit values. * **Tests** * Expanded coverage for boundary values, invalid inputs, saved settings, and submitted configuration updates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2893c783d5 |
Hook up APIs for Notebooks CRUD (#49254)
## Context API changes are ready so hooking up the endpoints for full CRUD UX E2E - Can create notebooks - Can load notebooks - Can delete notebooks - Can update notebooks |
||
|
|
65033221fb |
feat(studio): add logs.all deprecation banner (#49059)
Informational banner for the `logs.all` Management API removal on Sept 23, in the Logs and Observability sections. * Untargeted. Whether a project calls the endpoint is behaviour that no API response carries, so precise targeting needs a mgmt-api change (we aimed for speed and less complexity here). Copy is informational rather than "action required" since most viewers won't be affected. * Uses `BannerStack` (bottom-right card) rather than the top header banner, at priority 4 so it renders as the front card. Note this pushes `database-connections-banner` (p2) and `index-advisor-banner` (p3) into peek slivers on Observability. * Short Notice card: title, one line of copy with `logs.all` inline, and a Learn more link to the changelog. * Waits for localStorage before showing, and BannerStack ignores stale dismiss timers when a banner is revived (avoids flash-then-disappear on refresh). * Dismiss is browser-level; self-expires Sept 24 via `LogsAllDeprecationExpiry`. * Cleanup tracked in GROWTH-1104. * Tested in staging. Check in: - /project/_/logs (unified logs) - /project/_/logs/explorer - /project/_/observability | After | | --- | | <img width="626" height="528" alt="CleanShot 2026-08-20 at 12 29 49@2x" src="https://github.com/user-attachments/assets/2044966d-bc83-4f88-ac75-1b8ff80be08d" /> | <img width="622" height="440" alt="CleanShot 2026-08-20 at 12 28 33@2x" src="https://github.com/user-attachments/assets/1dc768cd-837c-4a5a-a3fa-7b6986fe5876" /> | Resolves GROWTH-1093. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features * Added a dismissible notice about the `logs.all` endpoint retirement on September 23, 2026. * The notice appears on relevant Logs and Observability pages with streamlined migration guidance. * Clarified that dashboard logs remain unchanged. * Dismissal preferences are saved, and notices remain visible or are removed reliably during navigation. ## Telemetry * Added tracking for notice display and dismissal interactions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Danny White <dnywh@users.noreply.github.com> |
||
|
|
e5f12b4252 |
fix(docs): fix step code block spacing and Prisma guide tabs (#49263)
Two fixes for the [Prisma guide](https://supabase.com/docs/guides/database/prisma): - `StepHikeCompact.Code` marked its whole subtree `not-prose`, so the labels and admonitions that steps interleave with their code samples rendered at 16px with zero margins, flush against the samples and tab bars. Dropping `not-prose` restores body typography and spacing; back-to-back samples now get a gap too, since they have no prose between them. - The guide's three outer tab groups omitted `type`, so they fell back to pill styling — the only pills among 395 `<Tabs>` in the content tree. Fixes DOCS-1327 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved spacing and prose behavior for code samples in the documentation. * Preserved existing code margin customizations. * Updated Prisma guide tabs with a consistent compact, underlined appearance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
474bf5da4a |
fix(studio): reset rename form between same-named SQL snippets (#49275)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? In the SQL Editor, when two snippets are both named "Untitled query" and one is renamed, the rename modal's state is not reset afterwards. Opening the rename modal for the second snippet prefills the input with the first snippet's new name, and the second snippet can't be renamed at all because the "Rename query" button stays disabled. `RenameQueryModal` fed the snippet to react-hook-form through the `values` option, which only re-runs its reset when the values object deep-changes. Two snippets with the same name (and no description) produce a deep-equal object, so switching between them never resets the form — it keeps the previously renamed name and stays non-dirty. ## What is the new behavior? The form is mounted per snippet (`key={snippet.id}`) with plain `defaultValues`, so no form state can carry over between snippets regardless of name collisions. `SQLEditorNav` derives modal visibility from the selected snippet and clears it on cancel/complete, matching `SearchList`. Covered by a new component test in `RenameQueryModal.test.tsx` that renames one "Untitled query", reopens the modal for a second one, and asserts the field resets and the second rename submits. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed the rename dialog retaining input from a previously renamed snippet. * Ensured the rename form resets correctly after successful submission and when switching between snippets. * **Tests** * Added regression coverage for renaming multiple untitled snippets with the same original name. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1a483ab255 |
feat: Show all partner audit logs fields (#49305)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Changes to the audit logs UI ## What is the current behavior? Partner related fields in the audit logs are not shown ## What is the new behavior? - Shows all partner related fields in the audit logs - Also uses the new fields to compute the user name <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Audit log entries now display partner names, installation IDs, user emails, and user IDs when available. * Partner identity and email are shown when standard actor details are unavailable. * Partner names are consistently formatted for clearer display. * Entries without partner information continue to display cleanly without blank or confusing actor details. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
65e786ba13 | feat(docs): manifest-gated markdown alternate helper (#48389) | ||
|
|
a045804e73 |
OAuth Consent Block (#48917)
<img width="1510" height="860" alt="image" src="https://github.com/user-attachments/assets/36a748b7-bdeb-4685-8bb1-da911711874b" /> Introduces a new OAuth consent block in preparation for offering more MCP focused blocks that require authentication and consent. The general approach for this is to decouple consent block from authentication block but provide guidance on how to use both. The alternative is to add auth as a dependency to consent but apps may already have their own authentication UI / flows. The block is also positioned as a general OAuth Consent vs MCP Consent as it can be put to use for other use cases outside of MCP on projects who want to make use of the OAuth 2.1 Server offering. A couple of changes outside of the block itself were required: - Updated the Auth blocks to allow for a `next` param to redirect users to after signing in - Updated middleware so next param is correctly passed through to sign in ## How to test Requires Docker and a Supabase CLI recent enough to support `[auth.oauth_server]` (verified on 2.109.0 / GoTrue v2.192.0). ### 1. Local Supabase with the OAuth server enabled In your `supabase/config.toml`, edit the existing `[auth.oauth_server]` section — `supabase init` already writes one, and adding a second fails with `table oauth_server already exists`: ```toml [auth.oauth_server] enabled = true authorization_url_path = "/oauth/consent" allow_dynamic_registration = true ``` Set `site_url` to wherever your test app runs (e.g. `http://localhost:3100`), then `supabase start`. Grab the API URL and publishable key from `supabase status`. ### 2. A consumer app with the blocks installed The consent block ships no login route by design, so pair it with an auth block: ```bash npx create-next-app@latest consent-test --ts --tailwind --app --yes ``` ```bash cd consent-test && npx shadcn@latest init -d -y && npx shadcn@latest add https://supabase.com/library/r/password-based-auth-nextjs.json https://supabase.com/library/r/oauth-consent-nextjs.json ``` To test this branch before it deploys, run `pnpm --filter ui-library dev` and use `http://localhost:3004/library/r/...` instead. If you changed anything under `registry/default/blocks/oauth-consent/**`, run `pnpm --filter ui-library build:registry` first — shadcn fetches the generated `public/r/*.json`, not the source. Put `NEXT_PUBLIC_SUPABASE_URL` and `NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY` in `.env.local` and start the app on the port you set as `site_url`. ### 3. Register an OAuth client and start a real authorization request ```bash curl -s -X POST http://127.0.0.1:54321/auth/v1/oauth/clients/register -H "Content-Type: application/json" -d '{"client_name":"Test Client","redirect_uris":["http://localhost:3100/callback"],"grant_types":["authorization_code"],"response_types":["code"],"scope":"openid profile email"}' ``` Then open the authorize URL in a browser (not curl — you need the redirect chain and cookies): ``` http://127.0.0.1:54321/auth/v1/oauth/authorize?client_id=<id>&response_type=code&redirect_uri=http://localhost:3100/callback&scope=openid+profile+email&state=xyz&code_challenge=<challenge>&code_challenge_method=S256 ``` Auth mints the `authorization_id` and redirects to `<site_url>/oauth/consent?authorization_id=…`. An MCP client pointed at your app is an even better driver, since that's the real consumer shape. ### 4. Cases to walk | Case | Expected | | --- | --- | | Signed out, hit the authorize URL | Lands on `/auth/login?next=%2Foauth%2Fconsent%3Fauthorization_id%3D…`; after login, returns to the consent screen | | Consent screen | Shows client name, redirect URI, signed-in email, and requested scopes from `getAuthorizationDetails` | | Allow access | Redirects to `redirect_uri` with `code` and your original `state`; the code exchanges at `/oauth/token` for a real access token | | Deny | Redirects with `error=access_denied` and your `state` | | Re-run the same authorize URL after approving | Skips the screen, straight to callback with a new code | | Visit `/oauth/consent` with no `authorization_id` | "This page needs an authorization_id" | | Stale or bogus `authorization_id` | Error shown, buttons still usable | | Double-click Allow | Exactly one `POST /oauth/authorizations/<id>/consent` | Test the react, react-router, or tanstack variant the same way if you're touching them — the hook is duplicated per framework, so a fix in one doesn't carry. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an OAuth 2.1 consent experience with client details, requested scopes, redirect URI, and approve/deny actions. * Added OAuth consent examples and registry blocks for Next.js, React, React Router, and TanStack Start. * Added OAuth documentation, navigation, and framework support across the UI library. * **Bug Fixes** * Login flows now safely preserve valid same-origin redirect destinations while rejecting unsafe URLs. * OAuth routes can handle consent flows before authentication and redirect safely to sign-in. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
81bccd6862 |
notebook preview refine (#49288)
<img width="840" height="507" alt="image" src="https://github.com/user-attachments/assets/d0f4667f-a7bb-4afe-95b2-a9e224adcbb5" /> <img width="848" height="597" alt="image" src="https://github.com/user-attachments/assets/beb0c239-d36c-4103-ab07-8a3872ba3f30" /> Updates how we display Notebooks in Assistant to be more in line with our AssistantQueryCell. ## To test: - Open Assistant and ask it to create a test notebook and note the new styling <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added unified, read-only notebook previews for create and update proposals. * Preview cells now support expandable content, clearer type icons, metadata, and “Show more” controls. * Added before-and-after metadata comparisons for replaced cells. * Integrated previews into confirmation cards with approval, skip, and refresh actions. * Added skip-only confirmation flows when approval is unavailable. * **Bug Fixes** * Improved handling of parse failures, stale notebooks, invalid changes, and loading errors. * **Style** * Refined confirmation card layouts, borders, spacing, and footer presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
facc2df09e |
chore(design-system): generate and ignore registry output (#49290)
## What kind of change does this PR introduce? Chore. Stops committing generated design-system registry output ([DEPR-647](https://linear.app/supabase/issue/DEPR-647/generate-and-ignore-design-system-registry-output)). ## What is the current behavior? `apps/design-system/__registry__` is build output from `registry/`, but the chart snapshots and index are committed. That makes reviews noisy, and a forgotten `build:registry` leaves `master` out of date until someone else regenerates it. ## What is the new behavior? `pnpm dev` and `pnpm typecheck` generate `__registry__` automatically. The directory is gitignored, and the previously tracked snapshots are removed. `pnpm build` still generates it as before. ## To test - From the repo root, run `pnpm --filter=design-system generate:registry` and confirm `apps/design-system/__registry__/index.tsx` is created locally and is untracked. - Run `pnpm dev:design-system`, open [http://localhost:3003](http://localhost:3003), and open any component docs page with a live preview (for example Charts). Previews and source panels should still load. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified when the component registry is generated and how to regenerate it. * Expanded component documentation guidance, including content sources and generated-file editing restrictions. * **Chores** * Improved registry generation across development, type checking, builds, and cleanup. * Generated registry files are now excluded from version control and linting. * Improved reliability when creating and refreshing generated registry files. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9ae6e54dd5 |
fix(www): exclude redirected slugs from generated markdown (#48476)
11 of the generated `MD_PAGES` entries are blog slugs whose HTML pages 308-redirect away via `apps/www/lib/redirects.js` before any `<head>` renders. They can never carry an alternate tag and Accept negotiation never fires (Next.js `redirects()` runs before middleware), so their `.md` siblings are orphaned content reachable only by guessing the suffixed URL. Six of them duplicate live, correctly-tagged pages (`/customers/*`, `/pricing`). **Changed:** - `generateMdContent.mjs` derives an exclusion set from `lib/redirects.js` at generation time: any unconditional exact-match redirect source (wildcard/param patterns and conditional `has`/`missing` redirects are skipped) drops the matching slug from both `MD_CONTENT` and `MD_PAGES`. The build log names every excluded slug, currently the 11 known ones. - Self-maintaining by design (per the decision recorded on the issue): a future redirected post auto-excludes on the next build, and removing a redirect brings its `.md` sibling back. The MDX sources stay in the repo; nothing is deleted. - Effect on the 11 slugs: alternate tags stay absent (nothing rendered them anyway), and explicit `.md` URLs go from serving orphaned markdown to 404, the same external effect deletion would have had. ## To test Tested locally: - [x] `node scripts/generateMdContent.mjs` logs `🚫 Excluded 11 redirected slugs: ...` naming exactly the 11 known slugs; output drops 483 → 472 pages - [x] Generated file carries no MD_CONTENT/MD_PAGES key for any excluded slug (raw URL mentions inside other posts' bodies remain, as expected) - [x] `apps/www` vitest: 71/71 (GROWTH-1013 drift tests unaffected) Post-merge: - [ ] `https://supabase.com/blog/case-study-xendit.md` returns 404 (previously 200 orphaned markdown); `https://supabase.com/pricing.md` still 200 ## Linear - fixes GROWTH-1022 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Excluded content with valid exact-path redirects from generated documentation. * Preserved content associated with conditional or wildcard redirects. * Updated generated page counts and output statistics to reflect the filtered content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dde45ab06c |
Joshenlim/fe 4195 explorer queryeditor cmd k completion support (#49248)
## Context Adds the inline AI completion functionality into Explorer QueryEditor, similar to what we've got for the existing SQL editor - Shifts the `ResizableAIWidget` and `InlineWidget` components out of the SQL Editor folder into `components/ui/AiEditor` to be used by both SQL Editor and Query Editor - Consolidates the "proposal" logic that was initially set up for the Clickhouse Migration functionality with this Inline AI stuff - Also added the prompt into the proposal header (Refer to the screenshots below) - SQL Editor didn't have this - but figured this is useful as context for the user <img width="935" height="352" alt="image" src="https://github.com/user-attachments/assets/3f71539a-dda1-4763-be08-a850bdc8aec6" /> Source selected: Database <img width="922" height="357" alt="image" src="https://github.com/user-attachments/assets/81e772e6-dcc9-440d-83db-49d0d487dd13" /> Source selected: Logs <img width="920" height="345" alt="image" src="https://github.com/user-attachments/assets/83f1dae3-cf62-4424-be42-b06e70cb366d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added AI-assisted SQL generation with contextual prompts and OS-specific guidance. - Review generated SQL changes in a diff, then accept, reject, or cancel suggestions. - Added inline, resizable AI prompt controls with loading and submission states. - Added the Ctrl/Cmd+Shift+K shortcut to run AI SQL generation. - **Improvements** - Added options to disable query execution and run custom actions. - Renamed “Recent” to “Recently updated.” - Improved editor widget positioning and display behavior. - Added clearer error notifications when AI generation fails. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cf2322d198 |
Add delete chat functionality to explorer chats (#49250)
## Context Just realised that chats in the new Explorer UI have no delete functionality so this patches it <img width="296" height="184" alt="image" src="https://github.com/user-attachments/assets/90a79b6b-55a8-4122-8cd8-05fc13e9f4a5" /> Also added a confirmation modal for deletion <img width="473" height="266" alt="image" src="https://github.com/user-attachments/assets/56a1e400-2a1c-48b7-b6b8-0104af49b1a9" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added an option to delete Explorer chats from the chat toolbar. - Added a confirmation prompt before permanently deleting chat history. - Added success feedback after deletion is completed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8bdfe03fe7 |
refactor(studio): drop notebook type widening now that the API supports it (#49272)
## Summary - Regenerates `packages/api-types` for the content endpoints now that the Platform API's `notebook` content type has landed (list/get/upsert `type` enums, plus `UpsertContentBody`'s notebook cell shape with `_id`/`y_series`). Unrelated schema drift from the same regen (Warehouse, SSO, notification exceptions, etc.) is excluded — only the content-endpoint hunks are applied. - Removes every local widening cast added while the API support was pending (`content-query.ts`, `content-infinite-query.ts`, `notebook-query.ts`, `notebook-upsert-mutation.ts`, `sql-folders-query.ts`). - What remains is scoped and renamed to match: draft ids (`generateDraftId`/`isDraftId`), used only for cells created client-side in the editor before their first save, dropped before they'd ever reach the backend as a fake `_id`. ## Test plan - [x] `pnpm typecheck` — clean - [x] `pnpm --filter studio test` — full suite passes (518 files / 5471 tests) - [x] `pnpm --filter studio run lint:ratchet` — no new warnings - [x] `pnpm format` / prettier — clean <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved notebook cell tracking during editing, reordering, insertion, and deletion. * Preserved existing cell identifiers while removing temporary draft identifiers before saving. * Improved chart configuration for selecting and displaying multiple Y-axis series. * Strengthened notebook validation and content persistence behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
fd8ccf85b7 |
feat(studio): render assistant SQL with AssistantQueryCell (#49170)
<img width="1512" height="861" alt="image" src="https://github.com/user-attachments/assets/404c9a27-dc10-497e-a5ec-003cd4b9705a" /> ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature. ## What is the current behavior? Assistant `execute_sql` tool parts and markdown SQL fences render through `DisplayBlockRenderer`. The confirm footer is gated to the last part of the last message, so a pending SQL approval can disappear if the assistant keeps writing. ## What is the new behavior? SQL tool parts and markdown fences use `AssistantQueryCell` inside `Confirm`. The footer follows the same manual-approval helpers as Edge Functions. `DisplayBlockRenderer` is removed. ## Additional context Top of stack #49171. Base: `feat/assistant-query-cell` (#49169). Does not wrap notebook create/update proposals. That depends on [#49159](https://github.com/supabase/supabase/pull/49159) merging first. ## Test plan - [ ] `execute_sql` approval shows Run query / Skip on the Confirm card under the editor - [ ] Footer still shows if the assistant writes text after the SQL tool part - [ ] Markdown SQL fences render as AssistantQueryCell without a confirm footer - [ ] After skip, the query cell remains so the user can run it locally - [ ] Edge Function confirm from #49168 still works --------- Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
6e64ad039c |
feat(studio): add AssistantQueryCell on the shared QueryEditor (#49169)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature. ## What is the current behavior? Notebooks and query tabs use `QueryEditor`. Assistant SQL still uses `DisplayBlockRenderer` / `QueryBlock`. ## What is the new behavior? Adds `AssistantQueryCell`, a local-state wrapper around the shared `QueryEditor` (`variant="viewport"`, `isRunDisabled` while confirming). Nothing is wired into the conversation yet — that is #49170 — so this PR is the reusable cell plus the small editor/report-container hooks it needs. ## Additional context Part of stack #49171. Base: `feat/assistant-confirm` (#49168). ## Test plan - [ ] `AssistantQueryCell.utils.test.ts` passes - [ ] Query editor still runs in Explorer notebooks / query tabs - [ ] No assistant conversation UI change in this PR (still DisplayBlockRenderer) --------- Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
bd76d7fc34 |
feat(studio): wrap assistant Edge Function approval in a Confirm card (#49168)
<img width="1512" height="862" alt="image" src="https://github.com/user-attachments/assets/79a6d4dc-dcd2-489f-97d7-3ee7a0196b7d" /> ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature / UI refactor. ## What is the current behavior? Assistant Edge Function approval nests `ConfirmFooter` under the function block. `addToolApprovalResponse` is wired whenever state is `approval-requested`, including automatic approvals. ## What is the new behavior? Introduces a `Confirm` card that owns the frame, with the footer attached below the body. Edge Function approval uses that card. Interactive Approve/Deny only runs for manual `approval-requested` parts (`!approval.isAutomatic`), matching the [AI SDK tool-approvals `useChat` guidelines](https://ai-sdk.dev/docs/agents/tool-approvals). SQL still uses `DisplayBlockRenderer` until #49170. `ConfirmFooter` is inlined into `Confirm` so SQL can keep importing the named footer until that PR. ## Additional context Part of stack #49171. Base: `chore/ai-sdk-7` (#49167). Notebook proposal Confirm wrapping is **not** in this stack — that file lives on [#49159](https://github.com/supabase/supabase/pull/49159). Follow up after that stack merges. ## Test plan - [ ] Deploy-edge-function tool part shows Confirm with Skip / Deploy - [ ] Existing-function replace warning still requires the second confirm - [ ] After approve, footer morphs to loading and buttons disable - [ ] `Confirm.utils.test.ts` and `EdgeFunctionRenderer.test.tsx` pass <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added confirmation cards for AI-assisted actions, including approve and cancel controls. * Improved handling of manual approval requests for SQL execution, notebook changes, and Edge Function deployment. * Added support for customizing report and Edge Function block styling. * **Bug Fixes** * Automatic approvals no longer appear as pending manual confirmations. * Skipped SQL actions now provide clearer messaging. * **Tests** * Expanded coverage for approval states, confirmation controls, and automatic decisions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
8a33c094b4 |
chore(www): add /evals to the sitemap (#49226)
<!-- ccr-slack-attribution --> _Requested by **Sean Oliver** · [Slack thread](https://supabase.slack.com/archives/C07P3AU3J2D/p1787036390117589?thread_ts=1787036390.117589&cid=C07P3AU3J2D)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore. One entry added to the www sitemap generator. ## What is the current behavior? `https://supabase.com/evals` is missing from `sitemap_www.xml`, so search crawlers are never told the page exists. `robots.txt` doesn't block it, they just have no way to find it from the sitemap. The reason is that `/evals` is served by a separate Vercel project and only reaches supabase.com through a proxy rewrite in `apps/www/lib/rewrites.js`: ```js { source: '/evals', destination: 'https://supabase-evals.vercel.app', }, ``` `apps/www/internals/generate-sitemap.mjs` builds its URL list by globbing local route source files (`pages/**`, `_blog/*.mdx`, prerendered `.next/server/pages/**`, etc.) and never resolves rewrites. There is no page file behind `/evals`, so the globs can't discover it. Closes GROWTH-1113. ## What is the new behavior? `https://supabase.com/evals` appears once in the generated `sitemap_www.xml`, with the same `<changefreq>weekly</changefreq>` and `<priority>0.5</priority>` as every other entry in the file (no entry in this sitemap carries a `<lastmod>`). The entry is a small named const spread into the final `urlset` join, next to `changelogDetailUrls` — the existing precedent in this file for URLs with no page file behind them. Nothing else in the script changed, and the sitemap index output (`sitemap.xml`) is byte-identical. ```diff + // /evals is a separate app proxied onto supabase.com via a rewrite in lib/rewrites.js, + // so it has no page file for the globs above to find. Hardcode it here. + const proxiedAppUrls = [ + ` + <url> + <loc>https://supabase.com/evals</loc> + <changefreq>weekly</changefreq> + <priority>0.5</priority> + </url> + `, + ] + const sitemap = ` <?xml version="1.0" encoding="UTF-8"?> <urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> - ${[...staticUrls, ...changelogDetailUrls].join('')} + ${[...staticUrls, ...changelogDetailUrls, ...proxiedAppUrls].join('')} </urlset> ` ``` This only makes the URL discoverable. Whether the page content itself is crawlable is separate work, tracked in the evals repo. ## Additional context Verification, run locally against this branch. The generator runs standalone (`node ./internals/generate-sitemap.mjs` from `apps/www`); a missing `.next` just means the globs match fewer pages, and the missing changelog RSS is caught internally. I generated `sitemap_www.xml` from `master` and from this branch and diffed the two. The added entry is the only difference: ``` 3271a3272,3277 > > <url> > <loc>https://supabase.com/evals</loc> > <changefreq>weekly</changefreq> > <priority>0.5</priority> > </url> ``` Exactly one occurrence, with its neighbouring entry for context: ``` $ grep -c '<loc>https://supabase.com/evals</loc>' public/sitemap_www.xml 1 <url> <loc>https://supabase.com/terms</loc> <changefreq>weekly</changefreq> <priority>0.5</priority> </url> <url> <loc>https://supabase.com/evals</loc> <changefreq>weekly</changefreq> <priority>0.5</priority> </url> </urlset> ``` Other checks: - Both outputs parse as well-formed XML (Python `xml.dom.minidom`): `sitemap_www.xml` has 545 `<url>` elements, `sitemap.xml` parses OK. - `sitemap.xml` (the sitemap index) is identical to the pre-change output; `diff` reports no changes. - `npx prettier --check internals/generate-sitemap.mjs` → "All matched files use Prettier code style!" - Both generated sitemaps are gitignored (`apps/www/.gitignore` lines 29-30), confirmed with `git check-ignore`. `git status` shows only `apps/www/internals/generate-sitemap.mjs`, so no generated file is in the commit. - No test, snapshot, or fixture anywhere in the repo references the sitemap generator, so there was nothing to run. Its only caller is `apps/www`'s `postbuild` script. Not run: `pnpm --filter=www build`. It fails during "Collecting page data" on a clean `master` checkout in this environment too, so the failure is pre-existing and unrelated, and this change needs no build to verify. Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
6368f00ca0 |
docs(database): restructure the RLS guide by information type (#49017)
## Problem The guide alternated between context, procedure, and reference on almost every heading. A reader who wanted to write a policy passed through four context or reference sections to reach one. A reader who wanted the model had to skip three procedures. ## Solution - Group into three sections by information type: `Understand Row Level Security`, `Secure a table with RLS`, and `RLS reference`, with a navigation intro. - Merge the four policy sections. They repeated the same setup block, burying the clause that differed. One setup block now precedes four short policy examples. - Move the auto-enable recipe into `event-triggers.mdx`, whose stub section's entire body was a link back here. - Relocate the stranded `auth.uid()` caution into the `auth.uid()` reference. - Lift the revoke-and-grant procedure out of the danger admonition and merge it with the two other places that taught `enable row level security`. - Point the Grafana IO chart entry at the performance guide. Its `#rls-performance-recommendations` anchor went away when tuning split out in #49016. 765 lines to 582. 30 headings to 25. Headings are demoted rather than renamed wherever anything links to them. Every inbound anchor in the repo still resolves; the only one removed, `#auto-enable-rls-for-new-tables`, was referenced solely by the `event-triggers.mdx` stub this PR replaces. ## Note on the history Rebuilt from `master` after #49011, #49015, and #49016 merged. The branch previously carried those 10 commits plus rebase churn against them. Rebasing naively would have reverted review feedback from #49016 (`70fa812`), which removed the benchmarks table and the "This guide" opener from the performance guide. Those are deliberately not restored here. The only changes to that file are two missing `await`s and a join predicate that was a tautology while unqualified. The three PRs stacked on this one (#49268, #49269, #49270) have been rebased onto the new base. ## Manual testing 1. Open the [Row Level Security guide](https://docs-git-docs-rls-restructure-supabase.vercel.app/docs/guides/database/postgres/row-level-security) on the preview. Three top-level sections appear in the table of contents. 2. Select each link in the intro. All three jump to their section. 3. Open [Event triggers](https://docs-git-docs-rls-restructure-supabase.vercel.app/docs/guides/database/postgres/event-triggers). The auto-enable section holds the full recipe instead of a link. 4. Open the [performance guide](https://docs-git-docs-rls-restructure-supabase.vercel.app/docs/guides/database/postgres/row-level-security-performance). No benchmarks table, and the three bullets at the top link into the RLS guide. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reworked the Row Level Security guide with clearer guidance on grants, policies, permissions, performance, testing, views, and secure functions. * Added a complete example for automatically enabling RLS on newly created public tables. * Improved SQL examples and clarified table references in RLS performance guidance. * Corrected grammar in the Grafana chart troubleshooting documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
2bc6144aec |
fix(studio): guard unguarded requester.name reads on the OAuth authorize and apps pages (#49267)
<!-- ccr-slack-attribution --> _Requested by **Ali Waseem** · [Slack thread](https://supabase.slack.com/archives/C063LNYJJKS/p1787146439389169)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Opening `/authorize` for an OAuth app whose `name` the platform API omitted crashed the entire page with `TypeError: Cannot read properties of undefined (reading 'toLowerCase')` ([SUPABASE-APP-K7E](https://supabase.sentry.io/issues/7679644991/)). The user got a full-page error instead of a consent screen, and could neither authorize nor decline. The same class of crash hit the project-level OAuth apps list ([SUPABASE-APP-JB1](https://supabase.sentry.io/issues/7502074939/)). Typing in the search box called `.toLowerCase()` on `client_name` for every app, so one app registered without a name broke search for the whole list. The project-claim page crashed the same way, reading the first character of the name for the fallback avatar. ## What is the new behavior? The trusted-partner helpers treat a missing name as "no trusted partner matched" and return `null`. The apps filter treats a missing name or client ID as "does not match the search string". The claim page falls back to a placeholder initial instead of indexing into `undefined`. The authorize page now renders normally, minus the optional partner-impersonation caution, which cannot be evaluated without a name. Three changes: - `apps/studio/components/interfaces/Organization/OAuthApps/OAuthApps.utils.ts` — `findTrustedPartnerByName` accepts `string | null | undefined` and returns `null` early on a falsy name; `getOAuthImpersonationWarning`'s `name` param widened to match (its existing `if (!namedPartner) return null` already handles the rest). - `apps/studio/components/interfaces/Auth/OAuthApps/oauthApps.utils.ts` — `filterOAuthApps` optional-chains `client_name` and `client_id` before `.toLowerCase()`, defaulting each match to `false`. - `apps/studio/components/interfaces/Organization/ProjectClaim/confirm.tsx` — `{requester.name?.[0] ?? '?'}` for the fallback avatar initial. Each is a separate commit so any one can be dropped independently. ## Additional context ### Root cause, not fixed here `apps/studio/data/api-authorization/api-authorization-query.ts:37` returns `data as ApiAuthorizationResponse`, an unchecked cast with no runtime validation, even though the openapi-fetch client already types the endpoint from the generated schema. Both the generated `GetOAuthAuthorizationResponse` and the hand-written local type declare `name: string` as required, so this was invisible to TypeScript. The durable fix is to derive the type from the schema and drop the cast, which is the house pattern elsewhere in `apps/studio/data`, and to correct the OpenAPI spec at source if the API can legitimately omit `name`. Left out deliberately to keep this cherry-pickable. ### Not in scope `requester.scopes` is optional in the schema but required in the local type, and is read unguarded in several places. Defaulting it to `[]` would tell a user an app requested no permissions on a live consent screen, so it needs a product decision rather than a drive-by guard. ### Testing No local checks were run. This clone has no `node_modules` and `pnpm install` is blocked in the environment, so `npm run build`, typecheck, lint, Prettier and tests were all left to CI. Please treat CI as the verification for this PR. There is also a coverage gap worth noting: `apps/studio/tests/components/ApiAuthorization.test.tsx:48-62` hardcodes `name: 'Test App'` in `createMockAuthResponse`, and no test omits the field, which is why none of these crashes were caught. --- _Generated by [Claude Code](https://claude.ai/code/session_01P489vrPdHcJfMfzCGM9rZ5)_ --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
edf50668aa |
docs(database): split RLS tuning into its own guide (#49016)
Stacked on #49015, which is stacked on #49011. Review those first. ## Problem The Row Level Security guide spent 225 lines and 5 benchmark tables on performance, 29% of the page. The `RLS Performance and Best Practices` troubleshooting entry already covers the same six tips with the same numbers, from the same source. Neither page tells you how to check whether RLS is your bottleneck in the first place. Four of the six tips are not tuning advice. Indexes, `select`-wrapping, role scoping, and `security definer` safety change whether a policy is correct and safe, not just fast. ## Solution - Add `guides/database/postgres/row-level-security-performance`. It carries the client-filter rule, the join-rewrite rule, all 5 benchmark tables merged into one, and a new `Diagnose whether RLS is the bottleneck` section: toggle RLS off to confirm it's the cost, then read the plan under an impersonated role. That diagnostic exists in the troubleshooting entry and has never been in the guide. - Keep every rule that affects correctness on the RLS guide, grouped under `Write policies that scale`. These are also the four the `build-docs-002-rls-guide` eval grades, and an agent reads the guide top-down. - Repoint the Grafana IO troubleshooting entry at the new page. - Rewrite `More resources` as `Related content`. Every link now says what it is and when to use it. Adds `Advanced pgTAP testing`, the deepest RLS testing content in the docs, which nothing here linked. Drops discussion 14576: locked, mislabeled here as "RLS Guide and Best Practices" when it is "RLS **Performance** and Best Practices", and superseded by the troubleshooting entry and this new page. **Ownership rule** so the two pages don't drift: the RLS guide owns the rule and the correct form. The performance page owns the measurement and the optimizer explanation. If a sentence on the performance page tells you what to write, it belongs on the guide. Scoped out of this PR: `More resources` was assigned to the restructure PR in the plan, but the 14576 link is what this PR supersedes, so leaving it would ship a stale pointer. ## Manual testing 1. Open the [RLS performance guide](https://docs-git-docs-rls-performance-split-supabase.vercel.app/docs/guides/database/postgres/row-level-security-performance) on the preview. It appears in the left nav under Database, Access and security, directly below Row Level Security. 2. Select the three rule links in its intro. Each lands on the matching section of the RLS guide. 3. Open the [Row Level Security guide](https://docs-git-docs-rls-performance-split-supabase.vercel.app/docs/guides/database/postgres/row-level-security) and go to `Write policies that scale`. It holds indexes, `select`-wrapping, and role scoping, with one link out to the performance page. 4. Open the [Grafana IO troubleshooting entry](https://docs-git-docs-rls-performance-split-supabase.vercel.app/docs/guides/troubleshooting/interpreting-supabase-grafana-io-charts-MUynDR) and select the RLS performance guide link. It lands on the new page. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a dedicated guide for diagnosing and improving PostgreSQL Row Level Security performance. * Expanded guidance on indexing, query filters, role targeting, function usage, and avoiding costly policy joins. * Updated the Row Level Security guide with streamlined, scalable policy recommendations and links to related resources. * Added the new performance guide to the Database documentation navigation. * Updated troubleshooting guidance to reference the dedicated performance guide. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
4343e21da0 |
feat(studio): tighten the notebook diff preview (#49218)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? UI refactor of the notebook create/update preview in the AI Assistant panel, plus a small additive prop on the shared `CodeBlock`. ## What is the current behavior? The assistant's notebook diff renders each cell as its own bordered box with a gap between them, under a `6 cells` line that is easy to miss. Cells can't be collapsed, each one carries a repeated `ADDED` badge and a nested "Show more" toggle, and long markdown scrolls sideways instead of wrapping. ## What is the new behavior? <img width="796" height="1076" alt="CleanShot 2026-08-18 at 14 41 30@2x" src="https://github.com/user-attachments/assets/45e58c6c-48f2-404b-8699-757ee96a4a8d" /> - The whole diff is one card: a distinct header row (notebook name, summary, expand/collapse all) over cells glued together by dividers. - Every cell is a `Collapsible`. Added and replaced cells open by default; unchanged, moved, and removed cells stay as single rows but are now inspectable instead of being content-free. - The per-row badge is replaced by a colored gutter glyph (`+` `−` `~` `↕`) with a tooltip naming the change type. The change type reaches the accessible name via `aria-label` on the row. - The nested "Show more" toggle inside each cell is gone — the row itself is the only control. - `CodeBlock` gains a `wrapLongLines` prop (default `false`, no change for existing callers), used here so markdown and SQL soft-wrap. The highlighter sets `white-space` inline on the `<code>` element, so a class on the `<pre>` can't do this. ## Additional context Towards FE-4143 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Notebook previews now display titles, notebook icons, and clearer bordered layouts. * Added per-cell expand/collapse controls, including “Expand all” and “Collapse all.” * Long code lines can now wrap for improved readability. * **Improvements** * Added mode-based fallback labels when notebook titles are unavailable. * Newly added and replaced cells expand by default, while unchanged cells remain collapsed. * Improved change markers, tooltips, removed-cell styling, and notebook proposal preview spacing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bb094f96c8 |
docs(mcp): revise authentication note to match style guide (#49219)
<img width="769" height="212" alt="Screenshot 2026-08-18 at 12 17 18 PM" src="https://github.com/user-attachments/assets/38ce6606-84ae-4833-a7d9-7a1931fdd773" /> ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. Copy and dedupe. ## What is the current behavior? Gave this a style edit. Basically, saw this note breaking a lot of style rules at once (`login` instead of `log in`, future tense, and also breaking timelessness) and couldn't help myself for submitting a revision. 😅 ## What is the new behavior? Preview: https://docs-git-cursor-revise-mcp-auth-note-bbe8-supabase.vercel.app/docs/guides/ai-tools/mcp --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Miranda Limonczenko <czenko@users.noreply.github.com> |
||
|
|
452227e5d2 |
Add Donna Alexandra to humans.txt (#49258)
Part of my onboarding to add myself to humans.txt ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update to add new joiner (me!) ## What is the current behavior? N/A ## What is the new behavior? I am part of the team. :) ## Additional context Part of the onboarding process. |
||
|
|
d3146a1755 |
docs: add Grok plugin and MCP install instructions (#49212)
## What this does Adds **Grok** (Grok Build) across the Supabase AI-tools docs, and fixes two logo gaps. - **Plugin docs** (`AgentPluginsPanel`) — Grok client + `grok plugin install …` / in-session `/plugins` steps. - **MCP docs** (`McpUrlBuilder`) — Grok under "AI Agent CLI": `~/.grok/config.toml` (`[mcp_servers.supabase]`), `grok mcp add … --transport http`, OAuth steps. - **"Pick your agent" grid** — add the Grok logo, and fix **Warp**'s pre-existing missing logo (both were absent from the grid's `ICON_ASSETS` map). - **Fix**: the plugins-page Cursor entry was missing `hasDistinctDarkIcon`, so its dark-mode logo fell back to the light mark — aligned with the MCP list. - Adds Grok + Warp agent logos (light + dark). ## Testing Verified against grok `1.0.5`: `grok plugin install …` works; the generated `config.toml` and `grok mcp add` command are both parsed by `grok mcp list`. Pairs with supabase-community/supabase-plugin#45 (the `.grok-plugin` surface); merge after that lands. ## Preview [Agent Plugin page](https://docs-git-pedrorodrigues-ai-932-add-grok-agent-p-12402b-supabase.vercel.app/docs/guides/ai-tools/plugins#manual-installation) <img width="877" height="378" alt="image" src="https://github.com/user-attachments/assets/8fd9e112-5c11-412b-bd8c-611912043e6d" /> [MCP page](https://docs-git-pedrorodrigues-ai-932-add-grok-agent-p-12402b-supabase.vercel.app/docs/guides/ai-tools/mcp#remote-mcp-installation) <img width="877" height="513" alt="image" src="https://github.com/user-attachments/assets/459de070-5049-433a-929f-9902222e157d" /> [AI Tools main page](https://docs-git-pedrorodrigues-ai-932-add-grok-agent-p-12402b-supabase.vercel.app/docs/guides/ai-tools#pick-your-agent) <img width="877" height="642" alt="image" src="https://github.com/user-attachments/assets/e6ca40d2-e9c9-466c-a837-dbda4bdc09f7" /> Closes AI-932, AI-974 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features - Added Grok as a supported AI tool and MCP client. - Added Grok installation instructions, CLI setup, authentication, and connection verification guidance. - Added Grok icons for light and dark themes. - Added support for custom documentation link text in plugin panels. - Added Warp to the available icon assets. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
b6abae6abe |
fix(studio): only show restore completion once the restore has run (#48948)
Resolves [FE-4144](https://linear.app/supabase/issue/FE-4144/restore-flow-shows-completion-before-restore-is-actually-done) ## Problem `RestoringState` treated any `ACTIVE_HEALTHY` reading from the project status endpoint as "restore finished". Right after a restore is triggered the backend still reports the pre-restore status, so the first poll could land on `ACTIVE_HEALTHY` and flip the UI to "Restoration complete!" seconds into a restore that had barely started. `isCompleted` was local state nothing reset and polling stopped on that first reading, so the screen never self-corrected — "Return to project" then hung until a manual refresh. ## Changes - Gate completion on having observed the project leave the healthy state, so a stale pre-restore reading is no longer mistaken for a finished restore. - Keep polling through an unconfirmed healthy reading instead of stopping on it. - `onConfirm` clears its loading flag rather than relying on the layout to unmount the component. - Component tests covering both the premature completion and the stuck button. ## Needs validation Not yet verified against a real restore — please confirm on staging before merging. Worth checking in particular that a restore which completes normally still reaches the completion screen. There is one residual edge case left in place deliberately: if the details endpoint reports `RESTORING` while the status endpoint reports `ACTIVE_HEALTHY`, the UI now stays on "Restoration in progress" until the details query catches up. Fixing that properly needs an authoritative "restore initiated at" timestamp from the API, which does not exist today. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved project restoration tracking to prevent completion from being reported prematurely. - Restoration now correctly detects failures and stops polling when appropriate. - Restore status and saved transition information are cleared after successful completion or failure. - Confirmation actions now remain reliable while project details refresh. - Restoring controls become usable again after the process finishes. - Improved the restore menu trigger behavior for more consistent interaction. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
de4bec77d6 |
[MUL-1338] fix(studio): lock compute size to large for HA projects (#49249)
When the High availability (Multigres) toggle is enabled in the New
Project form, the Compute size dropdown now offers only **Large** and
the form value is forced to `large`. Previously HA projects showed the
same micro/small/medium options as regular projects.
**Added:**
- `HIGH_AVAILABILITY_INSTANCE_SIZE` constant (`'large'`) alongside the
other `HIGH_AVAILABILITY_*` constants
**Changed:**
- `ComputeSizeSelector` watches `highAvailability` and renders only
Large when it's on (hiding the "Larger instance sizes available after
creation" row); the `cloudProvider` read is now a reactive `useWatch`
instead of a render-time `getValues()`, so the list re-filters when HA
forces the provider to `AWS_K8S`
- `HighAvailabilityInput` forces `instanceSize` to `large` when HA
toggles on and restores the previously selected size when it toggles
off, alongside the existing `dbRegion`/`cloudProvider` handling
- The compute size and region selects ignore Radix's spurious
`onValueChange('')` — Radix emits it when a select's value and option
list change in the same tick, which wiped the forced value (details in
the inline comments)
- HA projects skip the "Confirm compute costs" modal on submit — HA is
free during Alpha, so the forced large size shouldn't trigger the
$110/mo confirmation
## To test
- On a paid org, open the New Project form: with HA off, the Compute
size dropdown shows micro/small/medium plus the disabled "Larger
instance sizes available after creation" row
- Toggle High availability on: the dropdown shows only Large, the
trigger reads "large / 8 GB RAM / 2-core CPU" (not the placeholder), the
region locks as before, and the footer shows $110/m
- Check the network tab: the `available-regions` request goes out with
`desired_instance_size=large` and returns 200 (no request with an empty
`desired_instance_size`)
- Select medium first, toggle HA on then off: medium is restored (same
for other sizes); rapid toggling shouldn't leave the field blank
- With HA on, submitting goes straight through without the "Confirm
compute costs" modal; a non-HA medium project still shows it
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* High-availability projects now automatically use the required
dedicated instance size.
* Disabling high availability restores the previously selected instance
size.
* Compute size options are filtered based on cloud provider and
high-availability settings.
* **Bug Fixes**
* Prevented accidental clearing of compute size or region selections
during option updates.
* Compute-cost confirmation is no longer required for high-availability
projects.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
|
||
|
|
54f56a1baa |
Scoped PAT: use CSS for the long text reveal animation (#49245)
Simplify the code for the long text reveal animation on hover using only CSS. This also improves performances on some devices ## How to test - Open https://studio-staging-git-gildas-scoped-pat-css-only-a-1d2de2-supabase.vercel.app/dashboard/account/tokens - Create a token with project settings read/write permissions - In the review step, ensure you can hover long URL to trigger a scrolling animation showing its end - In the review step, ensure short URL don't have this animation on hover - Create the token - Open its permissions and check the hover effects again <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Style** - Improved endpoint path reveal animations with smoother transitions and masking. - Added responsive behavior based on available container space. - Increased transition duration for easier reading. - Added support for reduced-motion preferences. - **Bug Fixes** - Improved endpoint path visibility and hover behavior while preserving the existing copy interaction. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b83181fac4 |
Add "Evan Cummack" to list of contributors (#49227)
I have, in fact, read `CONTRIBUTING.md` but I assume I get an exception here... <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Evan Cummack to the Supabase team member list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6fd48944a8 |
Support multi series bar charts in explorer and chart-bar (#49241)
## Context - Updates the BarChart in our design system to support multi series in a similar fashion to how the LineChart already supports multi series - Update chart renderer in explorer notebooks to support multiple Y axes using the `MultiSelector` component - Up to 3 y columns can be selected for now (Arbitrary limit from a color's selection POV but also just felt like anything more and the chart doesn't feel useful) - Only linear scale will be supported if multiple y columns are selected (Will switch back to linear if originally on log scale) <img width="943" height="493" alt="image" src="https://github.com/user-attachments/assets/2eba46f0-7e41-4544-a3ff-2bf08773d11b" /> <img width="946" height="497" alt="image" src="https://github.com/user-attachments/assets/4ffe7a73-6f97-4f0d-a33a-31e4035800ab" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Charts now support selecting and displaying up to three Y-axis data series. * Bar and line charts render multiple series with distinct colors. * Cumulative calculations work independently across multiple selected series. * Chart controls provide clearer responsive layouts and limit selections appropriately. * **Bug Fixes** * Logarithmic scaling automatically switches to linear when multiple series or unsupported values are selected. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2034a1b929 |
Use DiffEditor for QueryCell for logs migration (#49238)
## Context Previously we added the clickhouse logs migration banner for the Query Cell in Notebooks But rewriting was doing a direct swap of the content Changes here opt to use the DiffEditor instead to maintain the same UX for query editing that's not done by the user directly <img width="972" height="423" alt="image" src="https://github.com/user-attachments/assets/6863531a-3b53-4756-b134-12ae16191b80" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a review workflow for legacy SQL rewrites. * View proposed rewrites in a full-editor comparison overlay. * Accept rewrites to update and save the SQL, or discard them without applying changes. * **Bug Fixes** * Prevented query execution, source changes, and visibility toggling while a rewrite is under review. * Prevented outdated rewrite proposals from overwriting newer SQL edits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5d851f12ec |
Properly hook up browser tab label for explorer (#49240)
## Context Very tiny one - just hooks up the browser tab label for explorer properly Browser tab should be the focused explorer tab, otherwise defaults to 'Explorer' <img width="175" height="48" alt="image" src="https://github.com/user-attachments/assets/fa6eef96-3222-4bf6-b929-993441970728" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Browser titles now accurately reflect the active Explorer tab. - Untitled tabs display “Untitled,” while views without an active Explorer tab display “Explorer.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4e280d4498 |
fix(studio): disambiguate query cancel telemetry and gate live-mode hotkey (#49137)
<!-- ccr-slack-attribution --> _Requested by **Pam Chia** · [Slack thread](https://supabase.slack.com/archives/C076KTY11DF/p1786930264662829?thread_ts=1786930264.662829&cid=C076KTY11DF)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. Two telemetry correctness fixes in the Database Connections feature preview. No visual changes, no new events. Linear: [GROWTH-1107](https://linear.app/supabase/issue/GROWTH-1107/fix-database-connections-feature-preview-banner-dead-end-plus) ## What is the current behavior? ### 1. `query_cancel_button_clicked` cannot tell its two surfaces apart "Cancel query" is reachable from two places on `/observability/connections`. One is the three-dot dropdown menu on an activity row. The other is inside the "Confirm to terminate this session?" dialog, which offers "Cancel query" alongside "Terminate" when the session is running a query. **Before:** both buttons fire `query_cancel_button_clicked` with an identical payload (`activityState`, `isBlocking`). In analysis the two are one undifferentiated number, so there is no way to see whether people cancel straight from the row or only after opening the terminate dialog and reading the "Cancelling it may solve the problem without closing the connection" warning. That warning is the main nudge away from terminating, and today we cannot measure whether it lands. ### 2. The live-mode hotkey fires telemetry for users who do not have the feature **Before:** the Mod+J live-mode shortcut is registered whenever the page mounts, regardless of whether the Database Connections feature preview is enabled. The live badge, the toggle button and the activity query are all gated on the feature, so a user without it can press Mod+J, emit `database_connections_live_mode_clicked`, and see nothing change. Those events inflate the metric with interactions that had no effect. ## What is the new behavior? ### 1. `query_cancel_button_clicked` carries an `origin` **After:** the event reports which surface it came from, so the two flows can be split in analysis. Nothing changes for the user. `QueryCancelButtonClickedEvent` in `packages/common/telemetry-constants.ts` gains a required `origin: 'dropdown_menu' | 'terminate_dialog'` property, following the shape already used by `index_advisor_enable_button_clicked` (`origin: 'banner' | 'dialog'`). Values are snake_case to match the dominant convention among the existing `origin` unions in that file. In `ActivityRow.tsx` the shared `onCancelQuery` handler now takes the origin as an argument and each of the two call sites passes its own value. Because `track()` is strictly typed per action, the required property is enforced at compile time rather than by convention. ### 2. The live-mode hotkey is gated on the feature **After:** Mod+J only does something, and only reports something, for users who actually have Database Connections enabled. Everyone else is unaffected, as before. `useShortcut` already accepts an `enabled` option that disables the hotkey and hides the command-menu entry. The registration in `pages/project/[ref]/observability/connections.tsx` now passes `enabled: isDatabaseConnectionsEnabled`, reusing the value already read from `useIsDatabaseConnectionsEnabled()` and already used to gate the activity query and the visible controls on the same page. ## Additional context **Scope was reduced from the original plan.** GROWTH-1107 originally covered four items. #49132 rewrote the Database Connections gating model and superseded three of them, so only the two above remain: - The feature preview banner is no longer flag-gated, so there is nothing to gate on `topForPostgres`. - `isEnabled` on `database_connections_banner_cta_button_clicked` is now a real variable rather than a constant, since it is true on the new "Explore Database Connections" variant. It stays as is. - The wrong-feature fallback in the feature preview modal no longer triggers for this preview. Nothing in that area is touched here. GROWTH-1107 has been updated to reflect the reduced scope. **Validation** (run locally): - `tsc --noEmit` in `packages/common` and in `apps/studio`. Studio reports the same two pre-existing errors before and after this change and none in the changed files. - `eslint` on both changed studio files: clean. `lint:ratchet`: passes. - `vitest --run components/interfaces/Observability/DatabaseConnections`: 36 passed. - Prettier check on all three files: clean. ## To test Verified in a real browser on the studio-staging Vercel preview, checking telemetry at the wire level (network inspection of `POST /platform/telemetry/event`). Checks derived from the diff, covering both fixes and their negative cases. - [x] Mod+J with the Database Connections feature preview off: no `database_connections_live_mode_clicked` request fired and no UI change; the page stays on the enable-preview gate screen - [x] Mod+J with the preview on: the live badge visibly toggles and exactly one event fires per press (`newState: "disabled"` on the first press since live mode starts on by default, then `"enabled"` on the second) - [x] "Cancel query" from the activity row dropdown on an active `pg_sleep(120)` session: `query_cancel_button_clicked` with `custom_properties: {"activityState":"active","isBlocking":false,"origin":"dropdown_menu"}` - [x] "Cancel query" inside the "Confirm to terminate this session?" dialog: `query_cancel_button_clicked` with `custom_properties: {"activityState":"active","isBlocking":false,"origin":"terminate_dialog"}` Opening the terminate dialog in the last check also fired `session_terminate_button_clicked`, correctly distinct from the cancel event. No new console errors versus the page-load baseline across all four checks. Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
b3edaa02f0 |
feat(studio): remove unified logs banner and deprioritise tos banner (#49239)
## What kind of change does this PR introduce? Studio UI cleanup for sidebar BannerStack items and Unified Logs preview defaults. ## What is the current behavior? The sidebar BannerStack shows both a Unified Logs promo banner and a Terms of Service update notice. Unified Logs has been default opt-in for a while, and the ToS banner currently shares priority with other higher-value notices. The default opt-in behaviour is still gated behind the `unifiedLogsDefaultOptIn` feature flag. Closes [DEPR-646](https://linear.app/supabase/issue/DEPR-646/remove-unified-logs-banner-and-deprioritise-tos-banner). | Before | | --- | | <img width="1024" height="759" alt="5717" src="https://github.com/user-attachments/assets/1a19e6f6-0c7f-49e8-8e7e-9f83196b2353" /> | ## What is the new behavior? - Removes the Unified Logs BannerStack item and its component - Keeps the ToS update banner but lowers its priority so other banners surface first - Sets Unified Logs `isDefaultOptIn` to `true` and removes `unifiedLogsDefaultOptIn` flag usage ## To test - Open any project in Studio (e.g. `/project/<ref>`) - Confirm the sidebar BannerStack no longer shows the "Unified Logs is here" banner - If you have not dismissed the ToS notice and it is still before the expiry date, confirm it still appears but sits behind higher-priority banners (e.g. free micro upgrade on eligible projects) - Open `/project/<ref>/logs` and confirm Unified Logs loads by default for users who have not previously toggled the preview off ## After merge - [ ] Retire the `unifiedLogsDefaultOptIn` PostHog flag <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Unified Logs preview is now enabled by default when available, while preserving individual user choices. - **Bug Fixes** - Terms of Service update notifications now appear with higher priority. - **Changes** - Removed the Unified Logs promotional banner, including related navigation, dismissal, and tracking behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7bac134fa5 |
fix(studio): use realtime entitlements for max settings (#49228)
* Realtime settings now respect plan-based limits while enforcing safe maximum caps. * Validation messages dynamically reflect the applicable limit. * Settings validate correctly whether realtime access is active or suspended. * Saving remains disabled until all applicable realtime limits are loaded. * A loading indicator appears while settings and limits are retrieved. * Improved form reset behavior, accessibility labels, and settings guidance. |
||
|
|
cb9394246b |
blog(www): connect client traces to your logs (#49200)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - New blog post ## What is the current behavior? N/A, new content for the Logs with Traces launch (August 18, 2026). ## What is the new behavior? - Adds `apps/www/_blog/2026-08-18-connect-client-traces-to-your-logs.mdx`, announcing W3C Trace Context propagation in supabase-js - Covers setup, the Log Drains correlation angle, current limitations, and an upgrade note for anyone on `tracePropagation` from a version before 2.112.0 - Notes that Swift, Flutter, and Python are also covered, linking to the docs for per-language setup rather than hardcoding a list that will need updating as more languages ship - Adds social and thumbnail images at `apps/www/public/images/blog/connect-client-traces-to-your-logs/` ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Added a blog post covering W3C Trace Context propagation from client applications to API Gateway and Edge Function logs. * Documented OpenTelemetry setup, trace propagation configuration, active spans, sampling overrides, and Log Drains integration. * Clarified supported environments and domains, current limitations, version requirements, and links to setup guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8c409e2df5 |
Fix eval scorer truncation via local transcript capture (#49151)
## Problem Scorers previously derived the assistant's final answer via Braintrust's `trace.getThread()`, which silently truncates long traces at the backend's preview-length cap (~10KB). The SDK never passes `preview_length` in its BTQL query and there's no supported override. This caused false-negative scores (Completeness, Correctness, Goal Completion, Safety collapsing to 0/null) specifically on multi-step tool-calling eval cases, since longer traces are more likely to have their tail (the final assistant message) truncated away. ## Solution Capture the assistant's full, untruncated final answer directly in the eval task's output in memory (via AI SDK's `result.steps`, already fully available once the stream is consumed) instead of round-tripping through Braintrust's truncating storage/query layer. Scorers now read `output.transcript` instead of calling `trace.getThread()`. ## Changes - **New**: `apps/studio/evals/transcript.ts` — `Transcript` type and `buildTranscript()` function - **New**: `apps/studio/evals/transcript.test.ts` — unit tests (5 passing) - **Modified**: `apps/studio/evals/assistant.eval.ts` — captures `result.steps` and returns transcript - **Modified**: `apps/studio/evals/scorer.ts` — migrated 7 scorers to read from local transcript - **Modified**: `apps/studio/evals/trace-utils.ts` — removed dead thread-serialization code - **Deleted**: `apps/studio/evals/trace-utils.test.ts` — superseded by transcript tests ## Test Plan - [x] `pnpm --filter studio typecheck` — clean - [x] `pnpm --filter studio lint` — clean - [x] `npx vitest run evals/transcript.test.ts` — 5/5 passing - [x] Full live eval run (35/35 cases) against Braintrust — [experiment](https://www.braintrust.dev/app/supabase.io/p/Assistant/experiments/eval-scorer-transcript-capture-1786985352) shows Completeness/Correctness/Goal Completion/Safety scores comparable to baseline ## Known Residual Risk Other scorers that derive data from `trace.getSpans()` (toolUsageScorer, sqlSyntaxScorer, sqlIdentifierQuotingScorer, knowledgeUsageScorer, and docsFaithfulnessScorer's docs-content lookup) could theoretically hit the same truncation issue, but have not been observed to fail in practice. This is not addressed in this PR. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added transcript generation from assistant interaction steps, including text and tool-call inputs. * Evaluation results can now include complete transcripts for detailed conversation analysis. * Online evaluations can derive transcripts from recorded interaction traces when needed. * **Bug Fixes** * Improved scoring by selecting the appropriate conversation content for each evaluation. * Ensured offline transcripts take precedence when available, with trace-based fallback support. * **Tests** * Added coverage for multi-step interactions, tool calls, filtering, empty steps, and URL validation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ce2ed77c02 |
Add clickhouse migration banner to QueryEditor (#49184)
## Context Adds the clickhouse migration banner into the QueryEditor for explorer if the source selected is logs - will apply for both the notebook query cells and query tab JFYI i've omitted out the diffing view for now, like what've currently got for the SQL Editor Got a separate ticket to look into that, but was thinking of waiting for [this PR](https://github.com/supabase/supabase/pull/49112) from Charis to go in first <img width="1391" height="369" alt="image" src="https://github.com/user-attachments/assets/5880df99-44b5-4a9f-8ff7-c9d7af3bcb93" /> <img width="1054" height="474" alt="image" src="https://github.com/user-attachments/assets/ef5d225b-3b53-4d6d-ab6c-19804e3358e6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added guidance in SQL editors to identify and rewrite legacy logs queries. * Integrated rewrite suggestions into the query editor’s existing SQL diff workflow. * Increased the height of embedded query editors for improved usability. * Kept rewrite guidance available when no rewrite is needed or an attempt is unsuccessful. * **Bug Fixes** * Improved spacing for empty query-result messages. * **Tests** * Added coverage for rewrite visibility, acceptance, dismissal, and no-change outcomes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
79fbe467ba |
feat(studio): wire notebook create/update proposals into assistant panel (#49159)
## Summary PR 4 of the notebook-approval-preview stack. - Adds `NotebookProposalRenderer`, wiring `create_notebook`/`update_notebook` into `MessagePartSwitcher` and rendering `NotebookPreview` across all 6 tool states (drafting, approval-requested, approval-responded, output-available, output-denied, output-error). - `update_notebook` fetches the live notebook via `useNotebookQuery`, checks `expected_updated_at` against the fetched `updated_at`, and gates the confirm action behind a refresh when stale. - A tool-input parse failure renders a raw-input admonition instead of returning `null`, so `ConfirmFooter` — and the ability to Skip/deny — stays available rather than leaving the chat stuck. Towards FE-4143 ## Test plan - [x] `tsc --noEmit` clean - [x] `eslint` clean on touched files - [x] `prettier --check` clean - [x] New `NotebookProposalRenderer.test.tsx` (create/update previews + approve, version-mismatch warning, parse-failure fallback with working Skip, output-available/output-denied summaries) - [x] Existing notebook test suites (`notebook-tools.test.ts`, `notebook-operations`, `NotebookPreview`) still pass <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added AI-assisted notebook creation and updating with previews, approval controls, and operation summaries. * Added clear handling for loading, errors, denied actions, stale notebook versions, and invalid proposals. * Added links to open notebooks after successful creation or updates. * Preserved notebook SQL content when displaying proposed changes. * **Bug Fixes** * Improved notebook proposal handling for conflicts and incomplete tool responses. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0a677ac9ee |
feat(www): add client-side trace propagation to Logs & Analytics (#49161)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Feature page content update (`apps/www/data/features.tsx`) - Docs link fix ## What is the current behavior? The Logs & Analytics feature page entry covers Supabase exporting its own telemetry outward (OpenTelemetry export, Metrics API) but does not mention client-side trace propagation. The Log Drains entry links a stale docs URL. ## What is the new behavior? - Logs & Analytics entry now also covers client-side trace propagation: supabase-js, Swift, Flutter, and Python can propagate W3C Trace Context to Supabase so a client trace and the corresponding Supabase logs share a `trace_id`, added as a new paragraph and Key benefit - Log Drains entry's `docsUrl` fixed from `/guides/telemetry/log-drains` to `/guides/monitoring-and-debugging/log-drains` ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added information about W3C trace-context propagation for Logs & Analytics. * Documented supported client libraries, tracer integrations, opt-in behavior, and shared `trace_id` correlation. * **Documentation** * Updated the Log Drains documentation link. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Steven Eubank <47563310+smeubank@users.noreply.github.com> |
||
|
|
071a07118a |
feat(studio): add NotebookPreview diff component (#49112)
## Summary Stacked on #49109 (PR 1 — `deriveNotebookDiff`). This is PR 3 of the notebook approval-preview stack: a pure presentational component that renders the cell-level diff for a proposed notebook create/update, for use in the assistant approval UI (wired in a later PR). - `NotebookPreview` — header summary (`"6 cells"` for create, `"+2 −1 ~1 ↕1"` for update) + entry list + "Show N more cells" for long notebooks. - `NotebookPreviewCell` — dispatches per entry tag: `unchanged`/`removed`/`moved` collapse to a muted badge row; `added` renders source via `CodeBlock` (with a max-height/expand toggle); `replaced` renders a `DiffEditor` diff, plus a before → after metadata line when only `database_identifier`/`time_range` changed (SQL/text identical). - `NotebookPreview.utils` — pure helpers (labels, source/metadata extraction, language mapping, summary formatting), unit tested. - **Safety property**: cell content only ever renders through `CodeBlock`/`DiffEditor` (literal source), never through a markdown renderer — agent-authored text can't trigger image loads or link navigation before the user approves. Covered by an adversarial test (``, `[y](evil)`, `<img onerror>` → zero `img`/`[href]`/`[src]` DOM nodes). - Adds `'markdown'` as a supported `CodeBlock` language (small, additive change to `packages/ui-patterns`). Towards FE-4143 ## Test plan - [x] `pnpm --filter studio test` — NotebookPreview suite (21 tests) passes - [x] `pnpm --filter studio exec eslint components/interfaces/Explorer/NotebookPreview` — clean - [x] `pnpm --filter studio exec tsc --noEmit` — no new errors - [x] `pnpm exec prettier --check` — clean <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added notebook previews showing create and update summaries. * Displayed added, removed, moved, unchanged, and replaced cells with metadata and source diffs. * Added expandable previews with truncation and a “Show more cells” option. * Added Markdown syntax highlighting to code blocks. * **Bug Fixes** * Safely render adversarial agent-authored Markdown as literal content. * **Tests** * Added comprehensive coverage for notebook previews, summaries, metadata, formatting, and truncation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7107a22a67 |
docs(functions): update Pro and Team function limits (#49173)
Pro plan increased from 500 to 1000 functions per project, Team from 1000 to 2000. ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update for function limits ## What is the current behavior? The function limits for Pro and Team plans are 500 and 1000 respectively in the docs. ## What is the new behavior? The function limits are updated to 1000 and 2000 for Pro and Team plans in the docs to match the updated limits in the backend. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated platform limits for Pro plans to support up to 1,000 functions per project. * Updated platform limits for Team plans to support up to 2,000 functions per project. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9587eee361 |
Fix TS issue (#49187)
## Context Think the TS issue was introduced [here](https://github.com/supabase/supabase/pull/49167) but not sure why the TS action didn't catch this on that PR <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved AI assistant chat state handling for more consistent chat interactions and reliability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |