mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 11:25:06 +03:00
chore/function-recent-errors
20627
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
fff5928056 |
fix: scroll to required fields on support form submit (#49147)
Fixes FE-4130. ## What is the current behavior? When submitting the support form with required fields missing, the form does not scroll to or focus the required empty field. Users have to manually find which field they missed. ## What is the new behavior? On submit, the form automatically scrolls to and focuses the first required field that's missing a value - including "What issue are you having?" and "Which library are you having issues with?". ## Additional context The scroll wasn't working due to a Chrome bug where scrollIntoView is blocked when overflow-x: hidden and overflow-y: auto are on the same element (the sidebar scroll container). The fix manually walks the DOM to find the scrollable parent and calls scrollTo() directly. Dropdown fields (Radix Selects) were also unfindable via the usual name attribute, so data-support-field attributes are used as a stable DOM hook for those. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Bug Fixes * Improved support form validation by automatically scrolling to the first invalid or missing required field. * Added smooth scrolling and focus behavior to help users quickly correct form errors. * Ensured the client library field is brought into view when required information is missing. * Improved field targeting for category and client library validation messages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
ce27b4ee5b |
chore(studio): scoped pat mcp tool ui improvement (#49188)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Follow on from view permissions sheet and review step tidy up to show a clear list of available mcp tools. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an “Available MCP tools” section to scoped token reviews and token details. * Displays enabled tools as badges, with a clear empty state when none are available. * **Improvements** * Simplified capability cards to focus on enabled API endpoints. * Removed per-permission MCP tool details and ungranted capability listings. * Updated endpoint count formatting for clearer singular and plural labels. * **Tests** * Updated capability and token detail tests to reflect the new MCP tool summary presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2440b06cb7 |
fix(docs/oauth-server): add plain for code_challenge_method (#49180)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that OAuth authorization requests support both `S256` and `plain` code challenge methods. * Recommends `S256` for improved security. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
dbb153042e |
feat(studio): cleaned up view permissions sheet (#49144)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Breaking down #49007 into smaller PR's. Part 1 merged in. More to follow... <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Redesigned token capability details with expandable cards and dense views for larger permission sets. * Added filtering by all, read, and read-write capabilities. * Improved endpoint and MCP tool attribution, display, and endpoint copying. * Added risk banners with permission and access warnings. * Enhanced resource badges, responsive layouts, relative timestamps, and dismissible creation guidance. * **Bug Fixes** * Corrected MCP tool attribution across alternative permission scopes. * Improved handling and display of inaccessible resources. * **Tests** * Expanded coverage for capability views, filtering, risk messaging, and permission evaluation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
e0ee774c74 | fix(docs): point the Management API nav entry at the Management API reference (#49165) | ||
|
|
c80f8ad78d |
chore(studio): upgrade AI SDK to v7 (#49167)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / dependency upgrade. ## What is the current behavior? Studio is on AI SDK 6 (`ai` ^6.0.174, `@ai-sdk/react` ^3). Tool approvals still use the v6 `needsApproval` flag on individual tools. ## What is the new behavior? Upgrades Studio to AI SDK 7 (`ai` 7.0.59) and the matching `@ai-sdk/*` packages. Aligns call sites with v7 names (`instructions`, `isStepCount`, `onEnd`, `ToolExecutionOptions`). This is the bottom of stack #49171. Later layers add a shared Confirm card and AssistantQueryCell. ## Additional context - Stack: #49167 → #49168 → #49169 → #49170 - `needsApproval` on tools is left as-is in this PR so the upgrade can land independently. A follow-up can move those gates to `streamText({ toolApproval })` and `experimental_toolApprovalSecret`. - Independent of the notebook preview stack ([#49112](https://github.com/supabase/supabase/pull/49112), [#49159](https://github.com/supabase/supabase/pull/49159)), which should merge first before we wrap notebook proposals in Confirm. ## Test plan - [ ] `pnpm --filter studio test` for `lib/ai/tools/*` and assistant generate path - [ ] Assistant chat still streams and tool-approval SQL / Edge Function still pause for confirm - [ ] Evals still run with mock tools (`needsApproval: false` overrides) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated AI-powered chat, onboarding, SQL, code completion, and recipe generation workflows for more reliable responses. * Streaming responses now better preserve reasoning and source information where available. * Improved tool privacy notices while preserving dynamically generated tool descriptions. * Refined AI response handling, including step limits and structured policy results. * **Bug Fixes** * Improved compatibility across AI-powered tool interactions and execution scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
81507e37bb | fix(Search): Add server sources for search (#49148) | ||
|
|
cb8a609607 | feat(studio): focus column name input after adding a column (#49183) | ||
|
|
6073c7a7e7 |
[FE-4193] fix(studio): show proper names for custom identity providers (#49182)
Unregistered `custom:*` identity providers (e.g. white-label deployments' own OAuth providers) rendered their raw id — the account preferences "Sign-in methods" list showed something like `Custom:Acme` instead of `Acme`. `getProviderDisplay()` now derives a proper title-cased name from any `custom:*` id, so this works generically for every custom provider. **Changed:** - `getProviderDisplay()` derives a title-cased display name for unregistered `custom:*` providers (`custom:acme` → "Acme", `custom:my_provider` → "My Provider"), case-insensitively. Registered ones (e.g. `custom:openai` → ChatGPT) are unaffected. - `SignInWithCustom` reuses `getProviderDisplay()` instead of its own `formatProviderName`, which only stripped a lowercase `custom:` prefix — the display name also now flows into its error toast. - Added unit tests for the new fallback branch. ## To test - On a deployment with a custom provider (or by temporarily hardcoding an identity with `provider: 'custom:acme'` in `AccountIdentities`), check `/account/me` → Sign-in methods shows "Acme", not "Custom:Acme" - Unlink dialog/toast for that identity should also say "Acme" - Sign-in page with a custom provider configured should show "Continue with Acme" - `pnpm vitest run lib/external-identity-providers.test.ts` in `apps/studio` passes Addresses [FE-4193](https://linear.app/supabase/issue/FE-4193) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for unregistered custom identity providers. * Custom provider names are now displayed in a clearer, title-cased format with underscores converted to spaces. * Matching providers use the SAML icon while preserving their configured display names. * **Bug Fixes** * Improved sign-in error messages and button labels for custom providers. * Provider identifiers are now handled case-insensitively. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
7adc83ee39 |
Implement run notebook functionality (#49178)
## Context Implements the "Run notebook" functionality which will run all database or logs cells within the notebook. <img width="206" height="110" alt="image" src="https://github.com/user-attachments/assets/703f4f78-1e3c-43b8-8c7e-771720ac3464" /> Am opting to do some via `useImperativeHandle` in `QueryEditor` to expose the `run` method, then having `ExplorerNotebookTab` calling `run` on each database / logs cells for the run notebook action. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a “Run notebook” action to execute all database and log query cells together. - The action displays a loading state and is disabled while running or when no executable cells are available. - Query results continue to update after execution, including when individual queries encounter errors. - **Tests** - Added coverage for running executable cells and handling notebooks without runnable queries. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5f9ce727c0 |
fix(ui): systematise control surface fills and hover borders (#48887)
## What kind of change does this PR introduce? Bug fix / design-system token hygiene for form and selector chrome. ## What is the current behavior? After opaque default-button fills, text fields, selects, and selector tiles drifted apart: inputs and selects mixed ad-hoc washes, hover borders bounced between `border-stronger` / `border-foreground-muted`, invalid fields had no hover step, and composites like InputGroup leaked inner hover borders. Follow-up to #48837 (opaque button fills) where Select rest still felt darker than Input on forms such as scoped access tokens. ## What is the new behavior? Named control roles and one interactive border: | Role | Fill | Rest border | Hover / focus / open | | --- | --- | --- | --- | | Field (sunk) | `bg-field` | `border-control` | `border-control-hover` | | Raised control | `bg-control-raised` | `border-strong` | `border-control-hover` | | Overlaying action | card → popover | `border-strong` | `border-control-hover` | | Invalid field | `bg-destructive-200` | `border-destructive-400` | `border-destructive` | - `--field` / `--control-raised` / `--border-control-hover` live in `semantic.css` (source of truth for roles; README points there) - Input / Textarea / InputGroup / legacy TextArea use the field ladder (incl. invalid hover) - Select and empty MultiSelect use raised; filled MultiSelect sinks to field - Default + dashed Button, CommandMenu trigger, and radio card/stacked/large use `border-control-hover` - Studio selector tiles aligned: Connect mode, role impersonation, DuckLake modes, compute “Contact us” | Before and After | | --- | | <img width="1576" height="759" alt="Access Tokens Account Supabase" src="https://github.com/user-attachments/assets/4bbe8b2b-a31a-4d63-80ba-04a1a8a5609d" /> | | <img width="1576" height="759" alt="Access Tokens Account Supabase" src="https://github.com/user-attachments/assets/92271223-4103-4cc6-a7c0-9e4ff71cce30" /> | ## Additional context `--control-raised` aliases `--card` today (role name so fill can diverge later). Rest `border-control` / `border-strong` both still map to `--input` via compat; the shared interactive step is `--border-control-hover`. ## To test 1. **[Account → Access Tokens](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/account/tokens)** Open Generate / New scoped token. Side-by-side Input, Select, RadioGroupStacked, MultiSelect. Confirm sunk vs raised fills, shared hover border, MultiSelect flips to sunk once a value is selected. Leave a required field empty to check invalid rest → hover → focus. 2. **[Org → Projects](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/org/_)** Hover the dashed Status filter. Hover default / filled filter buttons when active. Confirm hover/open borders match. 3. **[Project → Connect](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/project/_)** Open Connect from the header. Mode grid tiles: hover + selected borders match radio cards (no old muted-foreground ring). 4. **[Project → Compute](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/project/_/settings/infrastructure)** (optional) Compute size radios + “Contact us” tile hover. |
||
|
|
b6e43311d3 |
Reorganize explorer folder structure (#49172)
## Context Just reorganizing the files under the Explorer folder as details are a bit more clearer Mainly shifting related and exclusive files into their own folder and tests into `__tests__` folder + renaming some files <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added query result display settings for switching between table and chart views. - Added chart configuration options for chart type, axes, scaling, cumulative mode, and labels. - Automatically prevents invalid logarithmic scaling when chart data is incompatible. - **Refactor** - Standardized Explorer tab and query source naming across the interface without changing existing behavior. - Updated Explorer navigation, routing, and page wiring to use the standardized components. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4760c1af77 |
feat(studio): polish PrivateLink connection UI (#49164)
## What kind of change does this PR introduce? Polish for the AWS PrivateLink integrations UI. ## What is the current behavior? The add/view sheet labels the optional nickname field as "Description", delete confirmation always shows the AWS account ID, list admonitions use generic copy, and delete uses a fire-and-forget mutation. ## What is the new behavior? - Rename the optional nickname field to **Name**, with helper copy explaining it appears on the connections list - Tighten list admonition copy to reference connections below and pluralise share wording - Rename `showAcceptLink` to `shouldShowAcceptLink` - Delete confirmation uses the connection name (or account ID when unnamed) and clearer read replica fallback copy - Delete uses `mutateAsync` so the dialog can await the mutation | Before | After | | --- | --- | | <img width="828" height="515" alt="Integrations Settings Chisel Toolshed Supabase" src="https://github.com/user-attachments/assets/9e255d4b-a048-459c-87ff-ee1b65f42f9a" /> | <img width="828" height="515" alt="Integrations Settings Chisel Toolshed Supabase" src="https://github.com/user-attachments/assets/500e3922-912f-4e3b-a875-295ac7bd689e" /> | ## To test 1. Open **Project settings → Integrations → AWS PrivateLink** on a project with PrivateLink access 2. Click **Add connection** and confirm the optional field is labelled **Name** with helper copy underneath 3. Add a connection with a name (e.g. `Production VPC`) and confirm the list row shows that title 4. If you have a waiting or expired connection, confirm the list admonition copy references shares below 5. Open a named connection, click **Delete**, and confirm the dialog uses the connection name rather than always showing the raw account ID 6. Cancel delete and confirm the sheet stays open <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated AWS PrivateLink connection messages with clearer singular and plural wording. * Improved guidance for expired and pending connections, including acceptance-instruction links. * Renamed the account field to “Name,” marked it optional, and clarified its purpose and default behavior. * Enhanced deletion confirmations with clearer connection names and AWS account identifiers. * Improved deletion handling to provide more reliable feedback. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bfab3090f5 |
QueryTab: Scope role impersonation to each tab instead of global (#49139)
## Context Previous PR [here](https://github.com/supabase/supabase/pull/49101) introduced role impersonation to the Explorer -> Query Tab, but the setting was global (e.g selected role would be the same despite switching query tabs) Changes here shifts the scope of the role impersonation into the query draft so that the value is tied to each individual query tab instead <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Query drafts now remember selected impersonated roles when switching between drafts or returning later. * Added support for clearing saved impersonated roles. * Impersonation state remains isolated across query tabs. * **Bug Fixes** * Prevented impersonation settings from carrying over between unrelated drafts. * Invalid saved role data is safely ignored during restoration. * Logs drafts no longer persist or update impersonated roles. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cfde341c31 |
QueryTab: Scope row limit to each tab instead of global (#49138)
## Context Previous PR [here](https://github.com/supabase/supabase/pull/49098) introduced row limits to the Explorer -> Query Tab, but the setting was global (e.g selected row limit value would be the same despite switching query tabs) Changes here shifts the scope of row limit into the query draft so that the value is tied to each individual query tab instead Also added a logic as CodeRabbit suggested [here](https://github.com/supabase/supabase/pull/49138#discussion_r3795525802) - to default invalid row limit values to 100 if the persisted data is mutated incorrectly <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Query tabs now retain row-limit settings independently for each database draft. * Row-limit preferences are restored when reopening Studio, with older drafts defaulting to 100 rows. * **Bug Fixes** * Changing the row limit now persists immediately and no longer affects other query drafts. * Invalid saved row limits are safely normalized to a supported value. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fba3733148 |
test(studio): allow scoped token creation in CI (#49163)
## What kind of change does this PR introduce? Test reliability fix. ## What is the current behavior? The two longest scoped access token creation tests can exceed Vitest's default five-second timeout when they run under the full Studio CI shard, despite passing locally. ## What is the new behavior? The project-scoped and organisation-scoped token creation tests each use a targeted ten-second timeout. The global timeout and production code remain unchanged. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Increased test timeouts for project- and organization-scoped token creation scenarios to improve test reliability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
45bb7c30ce |
docs(database): fix RLS guide copy and two SQL examples (#49015)
Stacked on #49011. Base is `docs/rls-revision`, so review that one first. ## Problem An audit of the Row Level Security guide against `apps/docs/CONTRIBUTING.md` and `WORD_LIST.md` turned up 4 lint warnings and 3 things that are wrong rather than just untidy. - Two SQL examples contradict the guide's own advice. The own-profile `SELECT` policy has no `TO` clause. The `security definer` example has no `set search_path`. - `## Bypassing Row Level Security` says Service Keys bypass RLS, then a note says Supabase adheres to the signed-in user's policy anyway. The condition that separates the two is never stated. - `#using-functions` is linked twice from the RBAC guide and has never existed on the RLS page. ## Solution Copy and correctness only. No section moves, no heading renames. - Replace the italic emphasis on `never` with bold. CONTRIBUTING permits **bold** for a term the reader must not miss, not italics for general emphasis. The matching fix for `must` lives in #49011, which rewrites that line anyway. - Drop marketing language from the opener, the Supabase intro, and the policies and performance leads. Removes the idiom "get the hang of them" and the filler `just`. - Replace `we` with second person in two places. - Scope the own-profile `SELECT` example with `to authenticated`. - Pin `search_path = ''` on the `security definer` example, schema-qualify its body to match, and state the requirement in prose. - State when a Service Key actually bypasses RLS. - Repoint the two RBAC links to `#use-security-definer-functions` and `#helper-functions`. `supa-mdx-lint` on the RLS guide goes from 4 warnings to 0. ## Manual testing 1. Open the [Row Level Security guide](https://docs-git-docs-rls-copy-fixes-supabase.vercel.app/docs/guides/database/postgres/row-level-security) on the preview. The own-profile SELECT example shows `to authenticated`, and the security definer example shows `set search_path = ''`. 2. Open the [RBAC guide](https://docs-git-docs-rls-copy-fixes-supabase.vercel.app/docs/guides/api/custom-claims-and-role-based-access-control-rbac) and select the "RLS helper functions" link near the end. It lands on the Helper functions section instead of the top of the page. 3. From `apps/docs`, run `pnpm lint:mdx`. The RLS guide reports no warnings. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated access-control guidance with clearer links for security-definer functions and RLS helper functions. - Clarified that exposed tables require Row Level Security (RLS), while table grants and row policies provide separate controls. - Added least-privilege and grant-revocation examples, plus explanations for authorization errors. - Expanded testing guidance for CRUD policies, identity switching, and denied operations. - Improved recommendations for service keys, policy performance, indexing, and secure function configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
d2ccbe5d46 |
docs(database): close the RLS guide gaps the eval flagged (#49011)
Closes DOCS-1274 ## Problem The `build-docs-002-rls-guide` eval points an agent at the Row Level Security guide with a vibe-coder prompt that never says RLS, policy, role, or test. It failed 6 of 35 checks. Each failure traces to something the guide doesn't say. - **Grants.** `anon` kept insert, update, and delete on all four to-do tables. Both client roles kept writes on the weather feed. 24 privileges untouched. - **Indexes.** Missing on `list_members.user_id`. The agent indexed the other three, so it missed the composite-primary-key case specifically. - **Tests.** No pgTAP files. `Result: NOTESTS`, so the coverage judge never ran. ## Solution - **Add a `Grants and policies` section.** - **Rewrite the opening danger admonition around revoke-then-grant.** It previously showed `grant` only, which reads as though privileges start from nothing. - **Drop the `(or primary keys)` carve-out from `Add indexes`.** A column counts as indexed only when it leads a `btree` index, shown with a composite-primary-key example. - **Add a `Test your policies` section.** Covers file location under `supabase/tests/`, `supabase test db`, role and identity switching, which assertion matches which denial, and an 11-assertion example spanning allow and deny for all four operations across `anon` and `authenticated`. Used the supacademy RLS course as a second reference. Its framing of grants running before RLS shaped the new section. ## Manual testing 1. Open the [Row Level Security guide](https://docs-git-docs-rls-revision-supabase.vercel.app/docs/guides/database/postgres/row-level-security) on the preview. `Grants and policies` and `Test your policies` appear in the table of contents. 2. Select the `Grants and policies` link at the end of the first admonition. It jumps to the new section. 3. Open the [markdown version](https://docs-git-docs-rls-revision-supabase.vercel.app/docs/guides/database/postgres/row-level-security.md), which is what agents fetch. Both new sections and the revised `Add indexes` text are present. 4. From `apps/docs`, run `pnpm lint:mdx`. The 4 warnings on this file match `master`, with no new ones. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Clarified that exposed tables must enable row-level security. * Explained the distinction between database grants and row-level security policies. * Added least-privilege examples for client roles, including read-only access. * Added pgTAP testing guidance with a complete `profiles` example. * Clarified that composite indexes support policy filters only on their leading columns. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
ff6c8d4b30 |
fix(log-drains): add UK1 and US2-FED Datadog regions (#49156)
## Summary - Add `UK1` and `US2-FED` to the Datadog region dropdown in the log drains studio UI - Add the same two regions to the Datadog region list in the log-drains docs page The Logflare backend added support for these two Datadog regions in [Logflare/logflare#3790](https://github.com/Logflare/logflare/pull/3790) (shipped in v1.50.1), but the studio dropdown and docs were never updated, so customers on UK1 or US2-FED couldn't actually select their region when setting up a Datadog log drain. ## Test plan - [ ] Open Project Settings → Log Drains → add a Datadog destination and confirm UK1 and US2-FED appear in the Region dropdown - [ ] Confirm a log drain configured with `UK1`/`US2-FED` saves and sends events successfully <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for configuring Datadog log drains in the UK1 and US2-FED regions. * **Documentation** * Updated the monitoring and debugging guide with the UK1 Datadog region. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
04ddc6bef8 |
chore: update cors for pg routes (#49136)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix - config hardening ## What is the current behavior? CORS is applied at the global level in a permissive mode ## What is the new behavior? Self-hosted envoy config should apply CORS to the `/pg` routes. These should only be called from the studio dashboard (when called via a browser). uses `SUPABASE_PUBLIC_URL`, which should mean this isn't a breaking change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Security & Access** * Added stricter CORS controls for the `/pg/` route. * Requests are limited to the configured public URL and localhost origins. * Standard HTTP methods and headers are supported, with preflight responses cached for one hour. * **Documentation** * Updated self-hosting guidance to describe the `/pg/` route’s CORS policy. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2e68f2bf6e |
refactor(studio): derive notebook diff entries (#49109)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor, plus one bug fix. Groundwork for showing the user a preview of what they are approving when the AI Assistant creates or edits a notebook. No UI in this PR. Towards FE-4143 ## What is the current behavior? `applyNotebookOperations` resolves an ordered list of notebook operations into the resulting cells and nothing else. Rendering a diff for the approval gate needs to know *what happened* to each cell position, not just where things landed, so there is no way to build the preview on top of it. Separately, replacing a cell dropped its id, so `[replace cell-2, insert after cell-2]` failed with a spurious `unknown_cell_id`. ## What is the new behavior? `deriveNotebookDiff` resolves operations into one annotated entry per cell position (`unchanged`, `added`, `removed`, `replaced`, `moved`). `applyNotebookOperations` becomes a thin projection over its result, so there is a single interpreter of notebook operations and the diff a user approves cannot disagree with the cells that get written. The pre-existing tests pass untouched, which is the evidence that the projection is faithful. Notes on the annotations: - `removed` entries stay in the position the cell used to hold so the list reads as a diff. This does not perturb insert-anchor arithmetic: prior inserts still sit contiguously after their anchor. - Moves that cancel out are downgraded to `unchanged`, since two moves can anchor on each other and leave every cell where it started. Badging those as moved would make the preview lie. - `fromIndex` is the cell's position in the original notebook rather than in the shifted working order, so `was #3` means what a reader expects. A replaced cell now stays addressable as an anchor. Anchoring and targeting are separate lookups: a replaced cell can be anchored on, but is never a legitimate target. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Notebook changes now provide a structured view of added, removed, replaced, moved, and unchanged cells. * Replaced cells can be used as insertion anchors, while invalid or duplicate targets are rejected. * No-op moves are handled as unchanged cells. * Notebook edits preserve operation ordering and original cell positions for more predictable results. * **Bug Fixes** * Improved notebook operation handling and error reporting for complex cell edits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7c46793a3f |
docs: mention MCP debugging tools and Supabase agent skill in debugging docs (#48978)
## What - Adds a **Debug with AI tools** section to the debugging guide, covering the MCP debugging tools (`get_logs`, `query_logs`, `get_advisors`, `execute_sql`), the Supabase agent skill, and the combined plugin install, with a pointer to the MCP security best practices. - Adds a one-line pointer to it from the Monitoring and Debugging overview. - Adds the missing `query_logs` entry to the MCP server's Debugging tool group. Note: `pnpm lint:mdx` couldn't run locally (Node version), Prettier passes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added guidance for debugging with AI tools, including MCP tools and the Supabase agent skill for reading logs and advisors. * Documented plugin installation and security considerations when connecting AI agents through MCP. * Added links from monitoring and debugging guidance to the new AI tools documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
60be899fdb |
Selecting a PID from the overview card should clear filters if not visible in the UI (#49135)
## Context For Database Connections - the PIDs on the overview cards are selectable such that clicking on them should scroll the browser down to where the row is. However, if the selected PID isn't rendered due to the applied filters, clicking on it will seemingly do nothing. Changes here hence opt to remove all filters then scroll to the selected PID into view, so that users can always quickly find which PID the overview card is referencing. Also chucked in some refactors to centralize the management of filters, and functionality of selecting a PID into their own hooks <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added shared filtering for database activity by state, role, application, search text, and view. * Activity filters are now preserved in the URL for easier navigation and sharing. * Selecting activity metrics or process IDs now automatically reveals the relevant activity row. * Blocker view highlights root activities that are blocking other queries. * **Bug Fixes** * Improved selection behavior when the chosen activity is hidden by active filters. * **Tests** * Added coverage for individual, combined, case-insensitive, and blocker-specific filtering scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
397965cfae |
[FE-4186] fix(studio): endless region selector loading for AWS_NIMBUS orgs (#49131)
On the new-project form, the Region select's trigger label and inline
spinner were driven by `isLoadingAvailableRegions` — the `isPending`
state of `useOrganizationAvailableRegionsQuery`. For `AWS_NIMBUS` orgs
that query is permanently disabled (`smartRegionEnabled` is false), and
a disabled query stays `isPending` forever, so the trigger showed
"Loading available regions..." with a spinner indefinitely even though
the default region was actually selected underneath and the form still
worked.
**Changed:**
- The trigger label and spinner now use the provider-aware `isLoading`
(`smartRegionEnabled ? isLoadingAvailableRegions :
isLoadingDefaultRegion`), which the component already used for the
select's `disabled` state and placeholder. For non-Nimbus providers the
two values are identical, so the normal path is unaffected.
## To test
- Emulate a Nimbus deployment locally by setting
`"infra:cloud_providers": ["AWS_NIMBUS"]` in
`apps/studio/hooks/custom-content/custom-content.json`, then open the
new-project form: the Region field should show the default region (name
+ flag) within a moment — not an endless "Loading available regions..."
spinner — and the dropdown should open with the specific-regions list
- Restore the normal provider list and reload: the field should briefly
load, then show smart regions ("General regions") plus specific regions
with Recommended badges, as before
- Toggle High Availability on/off in either config: the selector should
transition between region lists without getting stuck loading
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved loading indicators in the region selector.
* The selector now consistently shows the correct loading state while
regions are being loaded.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
|
||
|
|
b044408e79 |
[FE-4185] feat(studio): custom content key for auth page logo link (#49130)
Adds a `dashboard_auth:logo_link_url` custom content key so white-labeled deployments can point the logged-out logo link at their own marketing site instead of the hardcoded `https://supabase.com`. **Added:** - `dashboard_auth:logo_link_url` custom content key (schema, types, default `null`, sample value) **Changed:** - `SignInLayout` and `ForgotPasswordLayout` now resolve the marketing-site logo href from custom content, falling back to `https://supabase.com` — these two shared layouts cover all auth pages (sign-in, sign-in-sso, sign-in-mfa, sign-in-partner, forgot/reset password) in both the Next and TanStack runtimes ## To test - On a normal deployment (key `null`): visit `/sign-in` and `/forgot-password` logged out — the logo should still link to `https://supabase.com` - Set `"dashboard_auth:logo_link_url": "https://example.com"` in `apps/studio/hooks/custom-content/custom-content.json` locally — the logo on those pages should link to `https://example.com` - Signed-in contexts (`logoLinkToMarketingSite` unset) still link to `/organizations` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for configuring the URL linked from authentication-page logos. * Authentication logos now use the configured destination when available. * Added a default destination to ensure logo links remain functional when no custom URL is set. * **Documentation** * Added sample configuration for the customizable authentication logo link. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
dfb0603a36 |
Joshenlim/fe 4063 set up incremental default opt in for database connections (#49132)
## Context As per PR title - sets up incremental default opt in for the Database Connections feature preview Database Connections preview banner should still only show up if it's never been dismissed before, but the CTA's changed to "Explore" rather than "Enable" if the user's default opted in Related discussion here: https://github.com/orgs/supabase/discussions/48639 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Database Connections preview is now enabled by default. * Added clearer handling for preview state and initialization. * Banner actions open Database Connections when enabled, or the feature preview when disabled. * **Bug Fixes** * Improved banner and menu visibility while preview settings initialize. * Preserved banner dismissal behavior after a previous preference change. * Improved navigation consistency across Database Connections entry points. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
14fe0c0cc8 |
fix(studio): slightly round split-button corners on focus (#49129)
## What kind of change does this PR introduce? UI polish for split buttons (primary action + dropdown chevron). Follow-up to #49055. ## What is the current behavior? The focus ring sits above the neighbouring half, but the inner edge stays square, so the ring has two sharp corners at the join. ## What is the new behavior? On keyboard focus, the squared-off edge uses a slight radius so the ring matches the outer corners more closely. Resting state is unchanged. Split-button callsites now share the same join classes as the design-system example. | Before | After | | --- | --- | | <img width="1030" height="296" alt="43471" src="https://github.com/user-attachments/assets/9df3bd72-c7ac-4419-ae18-a7e649dc2d66" /> | <img width="1056" height="276" alt="CleanShot 2026-08-17 at 10 45 09@2x" src="https://github.com/user-attachments/assets/52e8a4dc-9c52-45ce-b4d0-f0e7b1b75935" /> | ## To test Tab to each half (labelled button, then chevron). Inner corners of the focus ring should be slightly rounded, not square. 1. [Split with dropdown](https://design-system-git-fix-split-button-focus-radius-supabase.vercel.app/design-system/docs/components/button#split-with-dropdown) (no login) 2. [Access Tokens](https://studio-staging-git-fix-split-button-focus-radius-supabase.vercel.app/dashboard/account/tokens) → Generate new token 3. Any project on [studio staging](https://studio-staging-git-fix-split-button-focus-radius-supabase.vercel.app/dashboard/_/settings/general) → Settings → General → Restart project <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Accessibility** - Added accessible labels to dropdown and export controls. - Improved keyboard-focus visibility, layering, and rounded edge treatment across joined buttons and menus. - Removed misleading or redundant screen-reader text and titles. - **Bug Fixes** - Prevented split-button controls from shrinking or displaying awkward borders and corners. - Refined hover and focus behavior for action buttons throughout settings, database, storage, account, and documentation interfaces. - **Documentation** - Clarified guidance for using overflow menus and responsive split-button actions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
65a5e593ca |
feat(studio): tighten Integrations layout (#49088)
## What kind of change does this PR introduce? UI ## What is the current behavior? GitHub’s empty state and Integrations icon spacing do not match the PrivateLink list. Add connection has no plus. PrivateLink rows use a kebab instead of click-to-view. ## What is the new behavior? GitHub empty state matches the connections list. **Connect GitHub** is tiny and asks you to connect before choosing a repo. Section icons align. **Add connection** has a plus. PrivateLink rows are clickable; delete stays in the sheet. | Before | After | | --- | --- | | <img width="1456" height="1508" alt="CleanShot 2026-08-14 at 12 48 48@2x" src="https://github.com/user-attachments/assets/27485e35-c24f-478e-8328-aad03ebb1dfb" /> | <img width="1468" height="1494" alt="CleanShot 2026-08-14 at 14 22 19@2x" src="https://github.com/user-attachments/assets/056e3b48-4542-4be5-9b21-4b5abd726e8e" /> | ## Additional context Stacked on #49087. No Vercel card work in this PR. See #49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations.** Check GitHub, Vercel, and PrivateLink icon alignment. - GitHub not connected: description should say **Connect GitHub to link a repository to this project.** Button should be tiny. - If GitHub has no repo (org page), the empty state should ask you to add a connection. - PrivateLink **Add connection** should show a plus. Click a connection row to view it. No kebab. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * AWS PrivateLink connections now display clearer titles, status, replica details, and database visibility. * GitHub organization integrations now provide improved empty states and clearer connection actions. * Added plus icons to connection buttons. * **Improvements** * Updated GitHub guidance based on authorization and repository selection status. * Standardized connection labels and refined integration page layouts. * Improved AWS integration icon presentation and responsive upgrade prompts. * **Bug Fixes** * Simplified default connection button wording across integrations. * Improved AWS account title fallback behavior when a nickname is unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fe347d8876 |
feat(studio): show PrivateLink accept guidance on the list (#49087)
## What kind of change does this PR introduce? Feature ## What is the current behavior? Accept-in-AWS guidance lives only in the view sheet, as a per-status essay with a nested button/link. Delete is easy to miss and does not name the database. ## What is the new behavior? The list warns when any connection is Waiting or Expired. View connection uses that same admonition. Delete uses a confirm dialog that names the database, including from **View connection**. | Before | After | | --- | --- | | <img width="1444" height="480" alt="CleanShot 2026-08-14 at 12 46 23@2x" src="https://github.com/user-attachments/assets/015b261b-0bee-48f4-8f2d-d0d23293e120" /> | <img width="1456" height="676" alt="CleanShot 2026-08-14 at 12 47 17@2x" src="https://github.com/user-attachments/assets/0a12371b-553a-4e52-b042-7498af722f4a" /> | | <img width="844" height="560" alt="CleanShot 2026-08-14 at 12 46 49@2x" src="https://github.com/user-attachments/assets/f664b165-d351-4572-8536-27f4a9749975" /> | <img width="842" height="452" alt="CleanShot 2026-08-14 at 12 47 09@2x" src="https://github.com/user-attachments/assets/a387c294-5814-451b-9359-e70c73de2cb2" /> | ## Additional context Stacked on #49086. See #49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink → Add connection.** Leave it unaccepted in AWS. The list should show the 12-hour accept warning. - **View connection** on that row. Same warning, **View instructions**, not a status essay. - **⋯ → Delete** on a row, and **Delete** inside **View connection.** The dialog should name the database. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added clearer AWS PrivateLink connection alerts for pending and expired connections, including guidance and acceptance links when applicable. * Existing PrivateLink connections can now be deleted directly from the connection form. * Added confirmation dialogs with loading and completion states for deletion. * Added more specific descriptions for primary databases and read replicas. * **Bug Fixes** * Improved connection status messaging and handling for AWS PrivateLink integrations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
097a105663 |
joshenlim/fe 4176 add role impersonation to explorerquerysourcemenu (#49101)
## Context Stacked off from https://github.com/supabase/supabase/pull/49098 - adds role impersonation for both Notebook Query cell + Explorer Query tab Note that this refactors the role impersonation state a little to decouple some stuffs to make this work, since the role impersonation state is global and we need a local state to support this UX Similarly to row limit, for query tab its intentional that for now that the role impersonation isn't scoped to the query draft atm as I wanna avoid making changes to explorer-query given there was a couple of PRs in flux that adjusts that file - will handle that separately <img width="1117" height="577" alt="image" src="https://github.com/user-attachments/assets/9bfd6287-efff-418b-a1c0-934ee2c840cb" /> <img width="1917" height="436" alt="image" src="https://github.com/user-attachments/assets/bfd1be82-8f77-4764-bd3a-4b9c63169b82" /> ## To test - [ ] Verify that role impersonation works in notebook query cell - [ ] Verify that role impersonation works in notebook query tab <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added role impersonation support to SQL Explorer queries. * Users can select an impersonated role directly from database query menus. * Query execution now applies the selected role when configured. * Added local role selection state for individual query tabs and cells. * Improved reuse and consistency of role impersonation controls across the interface. * Role selections and impersonation details remain synchronized across supported query components. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4433d9ddaf |
feat(studio): mark PrivateLink waiting as a warning (#49086)
## What kind of change does this PR introduce? UI ## What is the current behavior? Waiting (still labelled Ready in #49085) is green. Creating is orange. Deleting is red. ## What is the new behavior? Waiting is orange. Creating is grey. Deleting is orange. Connected stays the only green state. | Before | After | | --- | --- | | <img width="1448" height="492" alt="CleanShot 2026-08-14 at 12 43 59@2x" src="https://github.com/user-attachments/assets/c0d95b51-7841-4714-a01b-47e5587c3efb" /> | <img width="1434" height="470" alt="CleanShot 2026-08-14 at 12 44 59@2x" src="https://github.com/user-attachments/assets/3ba10dc5-5fdd-464a-a748-5085d2d65df3" /> | | <img width="842" height="440" alt="CleanShot 2026-08-14 at 12 44 21@2x" src="https://github.com/user-attachments/assets/757db647-4b7c-4f77-8dcf-1eb289c40cc1" /> | <img width="842" height="432" alt="CleanShot 2026-08-14 at 12 44 49@2x" src="https://github.com/user-attachments/assets/1311a6d2-4712-4cb9-a6f2-f39387f0a953" /> | ## Additional context Stacked on #49085. See #49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink.** A connection that AWS has not accepted yet should show an orange **Waiting** badge, not green Ready. - Creating should be grey. Deleting orange. Expired and Failed stay red. - **Docs preview → Platform → PrivateLink.** Should say Waiting, not Ready. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated AWS PrivateLink connection statuses to accurately show “Waiting” while the AWS Resource Share is pending acceptance. * Refined status badge styling for creating, waiting, and deleting connections. * Clarified that Resource Shares must be accepted within 12 hours. * **Documentation** * Updated PrivateLink setup instructions to reflect the revised connection status flow. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d61477085e |
Joshenlim/fe 4175 add row limit in explorerquerysourcemenu (#49098)
## Context Related to Explorer/Notebook - builds on the ExplorerQuerySourceMenu by adding an option for row limit in both Notebook Query cell + Query Tab ## Side note RE persistence of the selected row limit value Note that for QueryTab - its intentional that for now that the row limit isn't scoped to the query draft atm as I wanna avoid making changes to `explorer-query` atm as there's a couple of PRs in flux that touches that file. So will handle that separately ^ This means that switching between query tabs will not change nor persist the row limit <img width="931" height="335" alt="image" src="https://github.com/user-attachments/assets/d1d52ee7-7c1d-42aa-a6ae-1d7d99ab95c9" /> <img width="1381" height="486" alt="image" src="https://github.com/user-attachments/assets/689368c9-c0fc-4000-a09e-f59bfa7afa97" /> ## To test - [ ] Verify that row limit behaviour works in notebooks - [ ] Verify that row limit behaviour works in explorer query tab |
||
|
|
0c1da8fd09 |
feat(studio): tighten PrivateLink sheet fields (#49085)
## What kind of change does this PR introduce? Feature ## What is the current behavior? Add connection field order and nickname handling are harder to scan. Empty description can still show up as a blank name. ## What is the new behavior? Add connection is AWS account ID, then database, then optional description. An empty description is omitted from the list title. | Before | After | | --- | --- | | <img width="846" height="874" alt="CleanShot 2026-08-14 at 12 42 33@2x" src="https://github.com/user-attachments/assets/abfc4f37-a401-4bba-9408-c2530b0ac09b" /> | <img width="844" height="794" alt="CleanShot 2026-08-14 at 12 43 01@2x" src="https://github.com/user-attachments/assets/0cadeaea-583d-4c2b-9336-3d0fe6a1415b" /> | ## Additional context Stacked on #49084. See #49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink → Add connection.** Confirm field order: account ID, database, description. - Save once with a description and once without. Without one, the row title should fall back to the account ID. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added AWS account ID and database target fields to the PrivateLink setup form. - Added validation and improved preservation of entered values while editing. - Made the connection description optional. - Updated connection status labels and badges for clearer status visibility. - **Documentation** - Updated PrivateLink setup instructions to reflect the revised field order and optional description. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
44292c0996 |
feat(studio): extract PrivateLink status copy (#49084)
## What kind of change does this PR introduce? Refactor ## What is the current behavior? Status labels and sheet copy are inline switches in the list and form. ## What is the new behavior? One status lookup drives the badge and the view-sheet copy. No intended visual change. Ready is still green. | Before and After | | --- | | <img width="1460" height="486" alt="CleanShot 2026-08-14 at 12 37 13@2x" src="https://github.com/user-attachments/assets/0c6c0b03-25f7-4e64-a0cd-72e7ef966454" /> | | _No visual changes_ | ## Additional context Stacked on #48967. See https://github.com/supabase/supabase/pull/49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink.** Look at a connection row badge, then **View** it. Labels should match today’s statuses. Ready should still be green. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added clear status messaging for AWS PrivateLink connections, including accepted, ready, creating, deleting, expired, and failed states. * Added fallback messaging for unavailable or unrecognized connection statuses. * **Bug Fixes** * Improved consistency of PrivateLink status badges, labels, descriptions, and visual styles. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c15a8b6739 |
chore(studio): lighten FormLayout descriptions and tighten GitHub copy (#49091)
## What kind of change does this PR introduce? UI nits ## What is the current behavior? `FormLayout` descriptions that are not in a react-hook-form field use `text-foreground-light`, which fights the component’s `text-foreground-lighter` variant. New-project GitHub helper copy is one long colon sentence. ## What is the new behavior? Those `FormLayout` descriptions use the shared description variant (`foreground-lighter`). New-project GitHub copy is two short sentences. | Figure | | --- | | <img width="820" height="798" alt="CleanShot 2026-08-14 at 14 33 32@2x" src="https://github.com/user-attachments/assets/7703a01d-efcb-41c2-8f6a-e96fc8a7187d" /> | | _Example call site of **before** the `FormLayout` fix._ | | <img width="1384" height="582" alt="CleanShot 2026-08-14 at 14 53 39@2x" src="https://github.com/user-attachments/assets/1bce1ee7-befd-4f53-881c-bbc7a87dd467" /> | | _**After** New-project copy shortening._ | ## To test - **Organization → New project.** GitHub (optional): “Ideal for agent-first workflows. Update your schema in code and push it to GitHub. Supabase deploys the changes.” - **Project Settings → Database → SSL configuration.** “Reject non-SSL connections to your database” should look more muted (`foreground-lighter`), not the brighter `foreground-light`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Simplified the GitHub repository field description while preserving deployment guidance and the “Learn more” link. * **Style** * Lightened the color of descriptive text in form layouts for improved visual hierarchy. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3d966e3709 |
feat(studio): show PrivateLink resource IDs and use connection copy (#48967)
## What kind of change does this PR introduce? Feature and docs ## What is the current behavior? PrivateLink is labelled as an AWS account, and there is no way to tell which resource configuration belongs to the primary vs a read replica. Put simply: you’re not adding an AWS account. You’re adding a connection. One AWS account can have multiple PrivateLink connections, just to different databases, with more fields also coming soon. Part of PRODSEC-238 and fixes SEC-939. ## What is the new behavior? Each connection shows resource configuration IDs so primary and replica are distinguishable. Customer-facing copy says **connection**. API paths and AWS console labels still say association. | Before | After | | --- | --- | | <img width="1452" height="496" alt="CleanShot 2026-08-14 at 12 33 49@2x" src="https://github.com/user-attachments/assets/3b295136-0325-4587-9291-b5f01fc07806" /> | <img width="1440" height="434" alt="CleanShot 2026-08-14 at 12 34 30@2x" src="https://github.com/user-attachments/assets/dd6ba064-18e4-4969-9c76-e3b79ac9d288" /> | | <img width="846" height="912" alt="CleanShot 2026-08-14 at 12 33 28@2x" src="https://github.com/user-attachments/assets/c4c6caca-a2f6-4516-99c7-ad7cf865f8ac" /> | <img width="844" height="880" alt="CleanShot 2026-08-14 at 12 34 39@2x" src="https://github.com/user-attachments/assets/f3874c6b-abdc-4ef8-84fa-141cd9150871" /> | | <img width="1448" height="560" alt="CleanShot 2026-08-14 at 12 33 10@2x" src="https://github.com/user-attachments/assets/8ae734cb-ec1f-4e4e-acf7-f4de459296d1" /> | <img width="1460" height="496" alt="CleanShot 2026-08-14 at 12 32 15@2x" src="https://github.com/user-attachments/assets/883050d5-a6f1-44bd-8ebd-1513a2c41e9f" /> | ## Additional context First PR in a stacked PrivateLink series (#49084 onwards). See https://github.com/supabase/supabase/pull/49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink.** Open **Add connection**, or **View** an existing one. Confirm the UI says connection, and that resource config IDs are copyable. - **Docs preview → Platform → PrivateLink.** Procedure steps should say Add connection / View connection. --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
89cd156e39 |
fix(studio): clarify MFA backup authenticator copy (#49083)
## What kind of change does this PR introduce? Bug fix (copy and layout) ## What is the current behavior? After setting up a single MFA factor, Account > Security warns you to add a "backup sign-in method". That reads like another account identity (email / Google / SSO), not a second authenticator app. The add action also sits at the bottom of the MFA card, so the callout has no nearby control. Fixes [FE-4171](https://linear.app/supabase/issue/FE-4171/clarify-backup-sign-in-method-after-mfa-setup) ## What is the new behavior? The MFA block is a `PageSection` with **Add app** in the aside. When one factor is configured, a danger callout above the card tells you to add a backup authenticator app, with **Add another app** opening the same modal. | Before | After | | --- | --- | | <img width="1482" height="896" alt="CleanShot 2026-08-14 at 10 27 33@2x" src="https://github.com/user-attachments/assets/7a8f3737-8e11-49c4-8f8e-3fda527a8c40" /> | <img width="1468" height="802" alt="CleanShot 2026-08-14 at 10 57 06@2x" src="https://github.com/user-attachments/assets/b2f6060e-b6c1-49e4-ae5c-99553ea3e60a" /> | ## To test 1. Open **Account > Security** (`/account/security`). 2. **0 apps:** empty card, **Add app** in the section aside. Click it. The add-factor modal should open. 3. **1 app:** danger callout under the section title. Copy should mention a backup authenticator app, not a sign-in method. **Add another app** and **Add app** should both open the same modal. 4. **2 apps:** callout and add buttons gone. Remove still works. Add or remove an authenticator app on that page to hit each state. If you already have one factor, step 3 is the important check. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved the multi-factor authentication interface with clearer sections, cards, and guidance. * Added an empty state when no authenticator apps are configured. * Added a warning when only one authenticator remains to help prevent account lockout. * Limited authenticator app setup to two configured factors. * **Bug Fixes** * Improved loading and error-state presentation for authentication factor management. * Simplified the security page to provide a more consistent MFA experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9be60cab63 |
refactor(studio): add optimistic locking to update_notebook (#49111)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor / hardening ## What is the current behavior? The `update_notebook` AI tool re-fetches the notebook right before applying operations, but concurrent edits are last-write-wins: the model has no way to detect that the notebook changed since it planned the edit, so a stale diff can silently overwrite someone else's changes. ## What is the new behavior? - `get_notebook` now returns the notebook's `updated_at` timestamp. - `update_notebook` requires a new `expected_updated_at` input field (the `updated_at` the model got from `get_notebook`). - At execute time, after the existing re-fetch and before applying operations, `update_notebook` compares the fetched `updated_at` against `expected_updated_at` and throws a descriptive error if they don't match, telling the model to re-read the notebook and reissue the update. - The notebook system prompt and mock tools (used by the eval harness) are updated to match. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Notebook retrieval now includes the latest update timestamp. * Notebook edits require confirmation that the content is current before saving. * **Bug Fixes** * Prevented stale edits from overwriting newer notebook changes. * Conflicting updates are rejected, allowing the latest content to be fetched before retrying. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
628473b3eb |
refactor(studio): extract notebook query-cell logic and give log cells display settings (#49075)
Final PR of the stack. #49069, #49070, #49072 and #49074 have merged, so this now targets `master` directly. **Rebased onto latest `master`**, which includes the centralized result-rendering work (#49096). See "Conflict resolution" below. ## What's left after master's own fixes `QueryCell` was written for database cells and adapted to log cells afterwards. Master has since fixed most of it directly: `handleUpdateCell` no longer bails on a non-database cell, the cell's own binding is read via `getQuerySourceBinding`, and `database_identifier` / `time_range` propagate across a source change. What remains: - **`display` was only passed for database cells**, so the `view` field on `log_cell` stayed unreachable and a logs query could never be charted. That is the one behavioral fix left in this PR. - The per-backend branching is inline and untested. ## What changed Per-backend logic moves into `QueryCell.utils.ts`, where it is unit-tested: `changeCellSource`, `setCellSql`, `cloneQueryCell`, `getCellDisplay`, `toQueryModel`. Each narrows on the cell tag exactly once, so the SQL brand and the backend's parameters stay correlated rather than being re-derived at each call site. `cloneQueryCell` also rebuilds the chart's series array, which valtio hands over as `readonly string[]`. `NotebookEditor` renders through `isQueryCell` (#49069) rather than a tag switch, so a new backend gets picked up by classifying it in `CELL_KINDS` instead of by remembering to add a `case`. ## Conflict resolution Two rounds of master's work landed in this file set. **`QueryCell/index.tsx` (master's own rework).** `changeCellSource` **subsumes the four source-change branches** master had inline, each covered by a test: | Master's branch | Test | |---|---| | database → database (replica change) | `keeps the query when only the database changes` | | logs → logs (time-range change) | `keeps the query when only the log time range changes` | | database → logs | `carries the query text over when moving from the database to logs` | | logs → database | `carries the query text over and restores a default row limit …` | Two improvements fall out of consolidating them: - A **logs → database** move now keeps the selected replica; pinned by `applies the selected database when moving from logs to the database`. - The row-limit default is **named** rather than a hard-coded `100`. `Explorer/utils.ts` now shares `DEFAULT_CELL_ROW_LIMIT` with `createQueryCellSkeleton`, so cell creation and backend conversion can't drift. Untouched from master: `snap.updateCell`, `AddCellDropdown`, `MoveCellDropdownContent`, the `SortableSection` grip props, and `NotebookEditor`'s add-cell buttons, skeletons, `reorderCells` and `insertCellAfter`. **Centralized result rendering (#49096).** That PR moved `QueryCell/QueryResultChart.tsx` up to `Explorer/`, split `QueryResultTable` into `QueryResultError`, and added `QueryResultRenderer`. Since this PR removes `QueryChartConfig`, the type swap had to follow the move and also reach `QueryResultRenderer`, which is new and referenced the removed type. `QueryResultRenderer`, `QueryResultError` and `DataGridResults` are otherwise untouched — the empty/error-state centralization is fully preserved, and `QueryEditor` still renders through it. ## Behavior worth a second opinion `changeCellSource` **carries the query text across a backend change** and rebrands it. This is probably not what a user wants — Postgres SQL and logs SQL are separate dialects over separate schemas, so a carried-over query will usually fail to run, and the rebrand asserts a dialect the text was never written in. Keeping it for now because it destroys nothing and needs no confirmation prompt. The tradeoff is written up at the function. Worth revisiting once we know whether people switch source to port an existing query or to start a fresh one — if it's the latter, clearing the body behind a confirmation is the better answer. Results *are* dropped on a backend change, since another engine returns unrelated columns. ## Incidental `Explorer/types.ts` drops `QueryChartConfig`, which duplicated the wire schema's `ChartConfig` field for field. `chart` stays persisted alongside `view`, so switching to the table and back returns the user's chart settings rather than rebuilding them. ## Verification Typecheck, Prettier, and the lint ratchet clean. 1013 tests pass across `state/`, the Explorer surfaces, notebooks, query sources, `data/sql`, the SQL editor, and `components/ui`; 13 of them are new coverage for the extracted helpers. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Improved notebook cell rendering with more consistent handling of query and markdown cells. - Query cells now preserve SQL, source settings, display preferences, chart configuration, and query results when edited or switched between sources. - Added a default limit of 100 rows for applicable database queries. - **Bug Fixes** - Prevented stale query results from carrying over when changing query sources. - Improved chart configuration consistency across query results and display settings. - **Tests** - Added comprehensive coverage for query-cell updates, source transitions, SQL changes, display state, and chart data. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bddb806b57 |
Joshenlim/fe 4174 project creation ignores selected us east 1 region (#49092)
## Context
Addresses a bug on local only whereby when toggling HA in the project
creation form, the database region was getting fixed to eu-central-1
irregardless of the region that was chosen on the UI. Was a result of
old code that wasn't cleaned up when we introduced region selection for
HA locally.
Added regression test to cover this case as well 🙏
## To test
Can only be tested locally
- [ ] On the project creation form, toggle HA and create a project in
us-east-1 - the project should be created in the selected region, and
not eu-central-1
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Bug Fixes**
- Fixed project creation so high-availability settings no longer replace
a manually selected database region.
- Smart-region providers continue using the selected smart or specific
region.
- **Tests**
- Added regression coverage to verify that manually selected regions are
submitted correctly in local high-availability environments.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
ee1eb5dbca |
docs: standardize quickstart guides (#48950)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the new behavior? - All 19 guides follow one step order: create project → set up database → create app → AI tooling → add keys → create client → query data → run it → go to production. Added _template.mdx with structure requirements; it is not enforced with a lint check for now - this will be a separate PR before adding new guides. - 4 new partials replace copy-pasted blocks (AI tooling, connection strings, mobile env vars, going to production). - Error handling: return a message instead of a blank page when a query fails. - All guides verified and tested separately - all work as described. What was fixed: wrong env var names in the Hono sample, a Next.js page that redirected to login, missing database permissions in Refine and Hono, and stale file paths and APIs in SvelteKit, Refine, and TanStack. - Astro, Expo, Python, Laravel, and Rails were live but missing from the quickstart grid or listing page. Added, with two new icons. ## Quick links for review Base preview: https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs **Quickstart discovery**: new Astro/Expo/Python/Laravel/Rails entries and icons - [Docs homepage grid](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs) <img width="1998" height="882" alt="CleanShot 2026-08-12 at 12 06 31@2x" src="https://github.com/user-attachments/assets/942eb7e2-1e85-4b20-a6a7-c2b127d31b2b" /> - [Getting started overview](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started) <img width="856" height="878" alt="CleanShot 2026-08-12 at 12 13 30@2x" src="https://github.com/user-attachments/assets/d48091a9-7daf-4796-a521-14116b7479c9" /> ### New shared files: **[apps/docs/content/guides/getting-started/quickstarts/_template.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/guides/getting-started/quickstarts/_template.mdx?plain=1)** A reference contract the other 19 quickstart guides are checked against. Documents the required frontmatter, the canonical 10-step section order, every guide's deviation from that order (and why), the direct-Postgres exception (Laravel/Rails/RedwoodJS/Spring Boot), and the discovery-surface/icon requirements for adding a new guide. No lint rule enforces it yet; that's a follow-up PR. **[apps/docs/content/_partials/quickstart_ai_tooling.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_ai_tooling.mdx?plain=1)** Example: [Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#4-set-up-ai-tooling-optional) → "Set up AI tooling" section Shared by all 19 guides: astrojs, expo-react-native, flask, flutter, hono, ios-swiftui, kotlin, laravel, nextjs, nuxtjs, reactjs, redwoodjs, refine, ruby-on-rails, solidjs, spring-boot, sveltekit, tanstack, vue **[apps/docs/content/_partials/quickstart_going_to_production.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_going_to_production.mdx?plain=1)** Example: [Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#going-to-production) → "Going to production" section Shared by all 19 guides: same full list as above **[apps/docs/content/_partials/quickstart_connection_string.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_connection_string.mdx?plain=1)** Example: [Laravel](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#5-set-up-the-postgres-connection-details) → connection string setup step Shared by 3 guides: laravel, ruby-on-rails, spring-boot – the ORM/backend frameworks that connect directly to Postgres rather than through the Data API **[apps/docs/content/_partials/quickstart_mobile_env_note.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_mobile_env_note.mdx?plain=1)** Example: [iOS SwiftUI](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ios-swiftui#get-api-details:~:text=This%20guide%20substitutes%20your%20project%20URL%20and%20key%20directly) → environment variables step Shared by 3 guides: ios-swiftui, flutter, kotlin – note Expo React Native is mobile too but doesn't use this partial, since it has its own `EXPO_PUBLIC_` prefix convention inline instead. ## Per guide changes **[Astro](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/astrojs#9-query-supabase-data-from-astro)** Typed query error in the server client sample. **[Expo React Native](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/expo-react-native#8-query-data-from-the-app)** Added an `error` state alongside instruments. Also removed the broken [`--web` verification path](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/expo-react-native#9-start-the-app): expo-sqlite needs Metro wasm + COEP/COOP config the guide never had (CodeRabbit finding). **[Flask](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flask#7-create-the-supabase-client)** Split "Create the Supabase client" and ["Query data"](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flask#8-query-data-from-the-app) into their own steps. **[Flutter](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flutter#9-setup-deep-links-optional)** Reworded the deep-links section; keeps the framework-specific [Android `INTERNET` permission subsection](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flutter#android) under "Going to production." **[Hono](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/hono#6-declare-supabase-environment-variables)** Split into "Install dependencies," "Declare environment variables," "Set up anonymous sign-ins," and "Query data" as separate steps. Fixes wrong env var names from the previous sample. **[iOS SwiftUI](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ios-swiftui#8-query-data-from-the-app)** Added an `isLoading` state so the loading overlay doesn't hang forever on a successful empty result (CodeRabbit fix). **[Kotlin](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/kotlin#5-install-dependencies)** Fixed the Compose compiler plugin declaration: `apply false` was missing from the app module (CodeRabbit finding). **[Laravel](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#5-set-up-the-postgres-connection-details)** Now uses the shared `quickstart_connection_string.mdx` partial for the session-pooler/SSL guidance instead of inline copy. **[Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#6-allow-public-access-to-the-instruments-page)** New step fixing the page that previously redirected to login. Its middleware path check is also now segment-aware so it doesn't over-match paths like `/instruments-private` (CodeRabbit finding). **[Nuxt](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nuxtjs#7-create-the-supabase-client)** "Create the Supabase client" and ["Query data"](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nuxtjs#8-query-data-from-the-app) split out as their own steps. **[React](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/reactjs#7-create-the-supabase-client)** Same client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/reactjs#8-query-data-from-the-app) split as the other Vite-based guides. **[RedwoodJS](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/redwoodjs#2-gather-database-connection-strings)** Expanded into explicit transaction-mode/session-mode connection strings, Prisma schema, migration, seed, and scaffold steps; fixes stale file paths and APIs from the previous version. **[Refine](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/refine#8-allow-writes-to-the-instruments-table)** New step fixing the missing RLS grants that made the scaffolded create/edit pages fail. **[Ruby on Rails](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#4-set-up-the-postgres-connection-details)** Now uses `quickstart_connection_string.mdx`; added a [reminder to save the database password](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#1-create-a-supabase-project) before it's needed for the connection string. **[SolidJS](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/solidjs#7-create-the-supabase-client)** Same client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/solidjs#8-query-data-from-the-app) split, adapted to Solid's `resource.error`. **[Spring Boot](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/spring-boot#4-set-up-the-postgres-connection-details)** Connection-string section now uses the shared partial instead of a duplicated inline caution. **[SvelteKit](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/sveltekit#8-query-data-from-the-app)** Updated `load` functions (both `+page.js` and `+page.server.ts` variants) with explicit query-error typing; fixes stale file paths and APIs from the previous version. **[TanStack](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/tanstack#8-query-supabase-data-from-tanstack-start)** `fetchInstruments` now returns and renders the query error instead of silently returning an empty list (CodeRabbit finding); fixes stale file paths and APIs from the previous version. **[Vue](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/vue#7-create-the-supabase-client)** Same client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/vue#8-query-data-from-the-app) split as the other Vite-based guides. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added SolidJS, RedwoodJS, Refine, Laravel, and Ruby on Rails quickstarts. * Added framework discovery entries for Astro, Expo React Native, Python, Laravel, and Rails. * Added optional AI tooling, MCP setup, connection-string, mobile configuration, and production-readiness guidance. * Added a Hono authentication example with anonymous sign-in, user details, and instrument data. * **Documentation** * Expanded setup, environment, authentication, RLS, migration, SSL, and deployment guidance. * **Bug Fixes** * Improved sample error handling for failed data requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
ebb8e2336e |
Centralize empty state + error handling for query results (#49096)
## Context Related to Explorer/Notebook - currently with the chart view, if the query has any errors, there's no error UI being shown Mainly because the error UI handlers are all within the table view Changes here hence opt to extract the empty state + error UI into a centralized renderer <img width="936" height="366" alt="image" src="https://github.com/user-attachments/assets/437891dc-241e-4c43-97a6-6eef52472ee7" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added unified query result display for prompts, errors, empty results, tables, and charts. * Query results now switch consistently between table and chart views. * **Bug Fixes** * Improved empty-result layout centering across views. * Expanded error display to use the available width. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
17dde3d324 |
feat(account): let OAuth-only users add a password to their account (#49057)
Allows a user to add a password which automatically creates and email identity to enable email + password authentication for OAuth-only accounts. Gated behind a feature flag: `enableAccountPassword` When a user does not have an email identity, allow them to set a password: <img width="762" height="284" alt="Screenshot 2026-08-13 at 14 52 53" src="https://github.com/user-attachments/assets/70b4883a-ed38-488a-a1b7-908caa112a0b" /> Password modal: <img width="519" height="423" alt="Screenshot 2026-08-13 at 14 56 57" src="https://github.com/user-attachments/assets/56ac370d-9e6c-4b05-986f-3aa9a51826c2" /> Email identity has been created, allow unlinking and/or updating email address or password: <img width="764" height="285" alt="Screenshot 2026-08-13 at 14 55 04" src="https://github.com/user-attachments/assets/5d9d7692-f4e3-4638-958d-15fefad01333" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * OAuth-only accounts can set a password from Sign-in methods. * Added password visibility controls, validation guidance, and success or error feedback. * Sign-in methods display the account email when available. * **Updates** * Renamed “Account identities” to “Sign-in methods” throughout account preferences. * Standardized password requirements across password setup and reset forms. * Setting a password refreshes the current session and signs out other sessions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b5bfc70c06 |
fix(studio): correlate a query's SQL brand with the backend it runs against (#49074)
Fourth of the stack; PRs 1–3 (#49069, #49070, #49072) have merged, so this now targets `master` directly. **Rebased onto latest `master`.** See "Conflict resolution" at the bottom for what was reconciled. ## The bug `QueryEditor` took `sql: string`, so a query's dialect brand died at the prop boundary and the component re-branded whatever it was handed based on a separately-passed `source`. Nothing tied the two together, which meant nothing stopped Postgres SQL from reaching the analytics endpoint. Explorer query drafts made it concrete. `explorer-query.ts` branded **every** draft with `untrustedSql` regardless of source: ```ts uncheckedSql: untrustedSql(sql) // even for a logs draft ``` and the editor then re-branded that same text with `untrustedLogSql` at run time for a logs draft — laundering a Postgres-branded value straight through the boundary that `safe-analytics-sql.ts` exists to defend. The brands are deliberately disjoint precisely so this can't happen; passing plain strings around defeated it. ## The fix Both carriers are now tagged by backend, so one `_tag` check narrows the SQL brand and that backend's parameters together. - **`ExplorerQueryDraft`** becomes `DatabaseQueryDraft | LogsQueryDraft`, and `toDraft` is the single place a persisted string re-enters the type system — branded for the backend its binding names. The draft is rebuilt rather than mutated in place, since a backend change changes which brand its SQL carries. - **`QueryEditor`** takes one discriminated `query` prop instead of `sql` + `source` + `rowLimit`. The tag picks both the brander at the editor boundary and the execution endpoint, so the mismatch is no longer expressible. - The two `acceptUntrusted*` promotions stay **inlined** in the run handler rather than factored into a shared helper, so each stays visible next to the user gesture that authorizes it, per the safe-SQL model. - **`rowLimit` moves onto the database member.** Logs execution has no use for it — `applyAutoLimit` is Postgres-specific — so it no longer sits on a shared type where it reads as meaningful for both. ## Local storage Existing query drafts shape-mismatch and fall back to a database binding via the existing `safeParse` guard — harmless, and notebooks are still behind the `explorer` flag so there is no saved server content in play. ## Conflict resolution `master` moved inside every file this PR touches. The type change is applied on top of that work; nothing was reverted. | Preserved from `master` | Where | |---|---| | zod parsing of persisted drafts (`persistedDraftsSchema`, `persistedDraftSchema`) | `explorer-query.ts` | | `MAX_PERSISTED_EXPLORER_QUERY_DRAFTS` cap, retaining most-recently-updated | `explorer-query.ts` | | debounced SQL persistence + `flushPendingPersistence`, immediate write-through for rename/source | `explorer-query.ts` | | `removeDraft` clearing pending timers | `explorer-query.ts` | | `getQuerySourceBinding(cell)` and the four source-change branches, incl. `database_identifier` / `time_range` propagation | `QueryCell/index.tsx` | | `restoredQueryKey` per `ref:id` and the `role="status"` loader | `QueryTab.tsx` | | `applyAutoLimit` relocated to `@/data/sql/utils` | `QueryEditor.tsx` | Two adaptations were needed: - `updateDraft` rebuilds the draft through `toDraft` instead of mutating it in place — required, because the object's shape depends on its tag. The debounced `persist` closure still re-reads `state.drafts[id]` at fire time, so behavior is unchanged. - Master's new test `falls back to the database source when persisted source data is invalid` asserted `draft.source`, which the tagged union replaces. Rewritten to assert the same intent against `_tag`. **Dropped from this PR's original description:** it previously claimed to fix a log cell always running against a synthesized default time range. Master fixed that itself by adopting `getQuerySourceBinding` (from #49072), so the claim no longer applies. ## Verification Typecheck, Prettier, and the lint ratchet clean. 736 tests pass across `state/`, the Explorer surfaces, notebooks, query sources, `data/sql`, and the SQL editor — including master's new `QueryTab.test.tsx`, `ExplorerQuerySourceMenu.test.tsx`, `ExplorerQueryTabCoordinator.test.tsx`, and the five draft-store tests added since this branch was cut. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved Explorer query handling across database and logs backends. - Preserved query text when switching backends while clearing incompatible results. - Retained results when changing parameters within the same backend. - Improved restoration of saved drafts, including fallback handling for legacy or invalid sources. - Added validation before executing edited SQL to help prevent invalid requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a5afb3dd22 |
feat(docs): add enterprise managed MCP auth (#47691)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Added docs for enterprise managed MCP auth <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added guidance for Enterprise-Managed Authentication for MCP. * Documented setup requirements, authorization flow, configuration steps, and security considerations. * Expanded the SSO guide and navigation with links to the new MCP authentication documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
344dc26a5e |
Fixed the event classifier for the events page (#49095)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Modified the events page so that it reads the correct category from the Notion database and displays if it's a hackathon, meetup, etc. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Events now display categories based on their Notion type and category information. * Hackathon events can be identified through category data. * Duplicate categories are automatically removed. * **Bug Fixes** * Events with unrecognized types now default to the conference category for consistent display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
773b388f25 |
chore(docs): correct api for temporary access (#48741)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated temporary access guidance to require SSL-enforced incoming connections. * Updated Management API examples to use the `/jit-access` endpoint for checking, enabling, and disabling temporary access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9ef9f1b8c1 |
feat(self-host): use @supabase/server in functions template and docs (#48996)
Updates the self-host Edge Functions template to use `@supabase/server`, matching the CLI's `supabase functions new` templates (part of SDK-1150, follows up on #45635 which exposed `SUPABASE_JWKS` to the functions container). The `hello` example function now wraps its handler in `withSupabase({ auth: 'none' })` and resolves the package through a per-function `deno.json` import map, which the runtime auto-discovers, so no dispatcher changes are needed. The self-hosted functions guide is updated to match: the create-a-function snippet, a `ctx.supabaseAdmin` example replacing the manual esm.sh `createClient` wiring, and a note that `auth: 'user'` requires `SUPABASE_JWKS`. Verified on `supabase/edge-runtime:v1.74.0` with the compose environment variables: `curl /functions/v1/hello` returns the same response body as before, so existing docs and troubleshooting pages stay accurate. The `docker/.gitignore` change: `volumes/functions/**` ignores self-hosters' own functions, but it also hid the new `deno.json`, which must ship with the repo for the `hello` import to resolve. The allowlist entries follow the existing `main/index.ts` pattern. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Edge Functions now support authenticated invocation with publishable or secret API keys. * Function handlers can access authenticated and administrative Supabase clients through the request context. * Added automatic environment configuration and JWT verification support. * **Documentation** * Updated the self-hosting guide with the new function setup and authentication workflow. * Improved local function examples for supported access patterns and privileged operations. * **Tests** * Updated self-hosted smoke tests to validate publishable-key function access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Kalleby Santos <kalleby_santos@hotmail.com> Co-authored-by: Kalleby Santos <105971119+kallebysantos@users.noreply.github.com> |
||
|
|
0ed49231b7 |
refactor(studio): unify CellSource and the SQL editor's QuerySource into QuerySourceBinding (#49072)
Third of a stack. **Stacked on #49070** (which is stacked on #49069) — review those first. Base retargets automatically as each merges. Mechanical throughout; no behavior change. ## The problem Three types described where a query runs, and no two agreed: | | shape | |---|---| | `CellSource` (registry) | `{ id, type, parameters: { … } }` — `id` and `type` always held the same literal | | `QuerySource` (SQL editor) | `{ type: 'database' } \| { type: 'logs', dateRange }` | | notebook cells | flat per-backend fields, neither of the above | Anything crossing between them needed a translation that dropped fields on the way — which is how a notebook cell's replica selection had nowhere to go. ## What changed One `QuerySourceBinding`: a backend `_tag` with that backend's parameters spread flat beside it, borrowed from the wire schema (#49069) so the binding and the persisted cell agree by construction. - **`QuerySource` is deleted.** `useRunSource` returns the shared binding, so `runSource.type`/`dateRange` become `_tag`/`time_range` across the SQL editor — that is most of the file count here. - **`getQuerySourceBinding`** projects a notebook cell onto a binding; **`toQuerySourceBinding`** does the same for any backend-tagged carrier. Both overloaded so an already-narrowed caller gets the matching binding back rather than the union, which keeps the result spreadable without re-narrowing. - **`ExplorerQuerySourceMenu`** drops its inline copy of the custom-range and upgrade-prompt logic in favor of `useLogsCustomRange`, which the SQL editor menu already used. The registry keeps only what is genuinely runtime: endpoints, labels, icons, availability, defaults. What a query *is* stays in the wire schema. ## Verification Typecheck, Prettier, and the lint ratchet clean. 405 tests pass across the notebook schema, query sources, the logs components, the SQL editor, and the Explorer surfaces. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated query source handling across Explorer and SQL Editor for a more consistent selection experience. * Database and log sources now preserve identifiers and time ranges more reliably when switching or editing queries. * Source menus, labels, icons, validation, and query execution now reflect the selected source more accurately. * **Bug Fixes** * Invalid or outdated saved source settings now safely fall back to a database source. * Improved log-source detection and time-range handling throughout query editing and execution. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
7bfc45cc7b |
Update pg_net schema (#48694)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the current behavior? The create extension snippet defaults to public which trips the Security Advisor check "0014_extension_in_public". The extension either way creates its own "net" schema. ## What is the new behavior? Register pg_net in the extensions schema. This is also the default when installing the extension from the dashboard. <img width="425" height="224" alt="image" src="https://github.com/user-attachments/assets/160309c0-9d35-4de7-b583-32f5db310a96" /> ## Additional context When no schema is specified, defaults to public which trips the Security Advisor check: <img width="1084" height="250" alt="image" src="https://github.com/user-attachments/assets/ac5f2859-17bf-4763-9880-453b0f414b4f" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the pg_net installation example to place the extension in the `extensions` schema. * Clarified that this configuration keeps pg_net out of `public` and satisfies the Security Advisor check. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |