Commit Graph
20627 Commits
Author SHA1 Message Date
Joshen Lim dc23320e43 Add sentry capture exception to apiWrapper (#47804)
## Context

As per PR title - also adjusts the imports for files consuming
`apiWrapper` to remove the default export for `apiWrapper`

Have tested locally by throwing an error in one of the API routes -
verified that the event shows up on Sentry

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* API errors are now captured in Sentry before returning server error
responses, improving production visibility while keeping endpoint
behavior the same.
* **Tests**
* Added coverage to confirm rejected handler executions are reported to
Sentry and return the expected HTTP 500 JSON payload.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-10 16:28:42 +08:00
Joshen Lim 66bfc5fdc3 Refactor ConnectSheet + Add unit tests to cover various logic (#47764)
## Context

PR here mainly breaks up the files under `ConnectSheet` to separate the
functional logic so that we can write unit tests.
No behavior changes intended beyond the bug fixes

## Changes involved

- **Test organization:** moved all root-level `ConnectSheet` test files
into `ConnectSheet/__tests__/` for consistency with other parts of the
codebase that use this convention.
- **Bug fix:** read replica label had a stray `}` / missing `)`,
rendering as e.g. `Read Replica (us-east-1 - abc123})` instead of `Read
Replica (us-east-1 - abc123)`.
- **`ConnectSheet.tsx`:** extracted the "hydrate sheet state on open"
`useEffect` logic (mode/field/URL param resolution from URL vs.
localStorage) into a new `ConnectSheet.utils.ts`, with unit tests
- **`useConnectServerEnv.ts`:** fixed two race conditions in the secret
reveal/hide flow:
- `toggle()` and `getValue()` could each fire a separate reveal request
if triggered close together — now deduped to share one in-flight
request.
- `getValue()` could hide a secret that had just been explicitly
revealed by a concurrent `toggle()`, due to reading a stale closure
value — now reads the live state via `useLatest`.
- Also stopped swallowing the original error on reveal failure (now
attached via `cause`).
- Added tests for the above, plus the 10s auto-hide timer (previously
untested).
- **`ConnectStepsSection.tsx`:** extracted `resolveContentPath` and the
three inline "show notice" booleans (IPv4 addon, session pooler,
self-hosted MCP) into `ConnectStepsSection.utils.ts`, matching the
existing pattern for the Data API notice. Added unit tests for all of
them.

## To test
- [ ] Just a basic smoke test of the Connect sheet should do

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Improved connect setup hydration so saved preferences and URL values
are applied more consistently when opening the sheet, including
automatic URL backfilling where needed.
* Refreshed connection guidance notices (IPv4 add-on, session pooler,
and self-hosted MCP) with more consistent logic.
* **Bug Fixes**
* Fixed secret reveal behavior to keep concurrent reveal actions in
sync, handle failures more safely, and ensure auto-hide works reliably.
  * Corrected the read-replica option label formatting.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-10 15:24:34 +08:00
Han Qiao ce81c2f6ec feat(studio): allow deleting a branch from general settings page (#47677) 2026-07-10 14:22:52 +08:00
Pamela Chia 770f1c2b06 fix(aeo): remove ua-based markdown serving (#47770)
## Summary
The `ChatGPT-User` live-fetch agent's user-facing reader hard-fails
(`(400) OK`) on pages we serve it as markdown via user-agent matching,
which made supabase.com blog and product pages unreadable in that
assistant. I root-caused this with a controlled fetch diagnostic
cross-checked against our request logs: the failing fetches never reach
our origin (the failure is cached on their side), pages served as plain
HTML read fine everywhere we tested, and the same failure reproduces on
other major sites that serve UA-matched markdown, so the reader bug is
upstream.

This PR removes user-agent-based markdown serving entirely rather than
special-casing one agent: UA sniffing is a guess about contractless
clients whose fetchers change without notice, and this incident showed
the failure mode is silent (we keep serving 200s while the user-facing
agent breaks). Markdown remains available on every explicit signal —
`Accept: text/markdown` q-value negotiation, explicit `.md` URLs, and
llms.txt — which is the same contract-driven model the Claude fetcher
already uses successfully (it sends `Accept: text/markdown, text/html,
*/*` and keeps receiving markdown after this change).

## Changes
- Remove the `LLM_USER_AGENT` regex and the `userAgent` parameter from
`negotiateMarkdown` in `packages/common/markdown-negotiation.ts`;
decisions now depend only on `Accept`, the `.md` suffix, and the
markdown-variant manifest
- Update both consuming middlewares (`apps/www`, `apps/docs`) to the new
signature; no behavior change for Accept-negotiated or `.md` requests
- Add the missing `Vary: Accept` header to docs guides-md 200 responses
(the www `api-v2/md` route already declares it)
- Fix a pre-existing www bug surfaced in review: explicit changelog
`.md` URLs rewrote to a doubled `.md.md` path (404) under a
markdown-preferring `Accept`, and 406'd on a non-matching `Accept`. The
www middleware now strips the `.md` suffix before slug lookup and passes
`isMarkdownSuffix` into `negotiateMarkdown`, folding the separate
`MD_PAGES` `.md` block into the single negotiation path (same shape as
the docs middleware)
- Rework tests: UA-independence suites replace the per-agent rewrite
tests; a probe Accept header now 406s regardless of user agent
(previously agent UAs were exempt); new changelog `.md` negotiation
coverage

## Testing
Tested locally:
- [x] www middleware suite 36/36, docs middleware suite 17/17
- [x] typecheck green for common, www, docs

Verified on the Vercel previews (www + docs) with curl:
- [x] `ChatGPT-User` and `Claude-User` UA GETs on blog/pricing/guide
pages return `text/html` with a default Accept
- [x] Claude's real Accept (`text/markdown, text/html, */*`) still
returns `text/markdown`; `Accept: text/markdown` and `.md` URLs return
`text/markdown`; probe Accept returns 406
- [x] `/changelog/<slug>.md` with `Accept: text/markdown` returns the
entry markdown as a direct 200 (production today detours through a 308
to the bare URL); changelog index `.md` and bare-entry Accept
negotiation also verified
- [x] docs guides markdown 200s carry `Vary: Accept`

The intermediate commit (ChatGPT-User-only exclusion) was already
verified on the preview: `ChatGPT-User` got HTML while
`Accept`/`.md`/other-UA markdown was unaffected.

Expected effects post-merge: UA-driven markdown volume in the request
logs (~92% of md traffic) collapses to the Accept + `.md` baseline;
named-agent page requests return to prerendered/static serving,
reversing the extra Vercel function invocations the UA rewrite
introduced; user-facing readability in the affected assistant recovers
within ~24h as its fetch cache revalidates. The md-share dashboard gets
a dated annotation; the ratio is not comparable across this change.

## Linear
- fixes GROWTH-973


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Markdown and HTML routing now depends on the request’s `Accept` header
and `.md` links, making content negotiation more predictable.
* Requests that don’t accept available content now consistently return
`406 Not Acceptable`, even for bot-like user agents.
* Guide markdown responses now include an `Accept`-based cache variation
header to improve correct caching behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-10 13:50:34 +08:00
Saxon Fletcher 75bb899f01 Fix mobile toolbar behaviour (#47800)
**Before**

<img width="340" height="104" alt="image"
src="https://github.com/user-attachments/assets/48a434de-21c2-4e3f-8cad-3c6408f7348d"
/>

**After**

<img width="508" height="317" alt="image"
src="https://github.com/user-attachments/assets/e52c6ba6-c173-4bb8-a466-1697585286c7"
/>


Fixes 
- Rendering issue of the menu toggle on mobile when menu is open
- You can now switch between panels when open (e.g. from help to
advisor). There was previously a bug that would just close the drawer
rather than switch.

**To test**
- Reduce screen size in a project view
- Click top right menu item
- Notice menu item is active in light mode
- Click "Assistant" and notice it switches vs closes the drawer
- Click close or outside the toolbar to close the drawer

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved the mobile menu button’s visual state by updating the menu
icon color when the menu is open.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-10 12:14:34 +08:00
Joshen Lim 87c5f74ceb Add CTA to update tax ID if run into tax ID issues when upgrading plan (#47767)
## Context

There's a chance users may run into tax ID issues when upgrading a plan
as such:
<img width="412" height="120" alt="image"
src="https://github.com/user-attachments/assets/4c559ae0-d942-4c10-b83a-c5944a2a49ee"
/>

Adding a CTA here to guide users and mitigate confusion on how to
proceed to remediate

<img width="399" height="147" alt="image"
src="https://github.com/user-attachments/assets/3bcaca14-bd77-4168-b9ab-cd6b75f79e24"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved billing-profile validation feedback by standardizing error
messaging for tax ID vs. billing address country mismatches.
* Added an in-toast “Update tax ID” action to guide users directly to
the fix.
* Updated the billing dialog’s close behavior so it returns users to the
relevant address section (including scrolling to it automatically).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-10 10:06:29 +08:00
Riccardo Busetti f45389138b ref(pipelines): Remove unnecessary restarts (#47732) 2026-07-10 01:34:19 +00:00
shaziya ece31da789 blog: add UTM params to CipherStash post links (#47798)
## Add UTM params to CipherStash blog post links

Follow-up to #47751. The [Notion
doc](https://app.notion.com/p/supabase/Blog-Post-CipherStash-partner-drop-3455004b775f81c68712f6a115ee43f8)
now has UTM-tagged outbound links for launch tracking. This applies them
to the three links in the published post.

All three use
`?utm_source=supabase_announcement_post&utm_medium=blog&utm_campaign=launch`:
- Intro: CipherStash integration link
- Intro: cipherstash.com link
- Get started: Add CipherStash to your Supabase project

No content or copy changes.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated CipherStash and Supabase links in the blog post with campaign
tracking parameters.
* Applied tracking to introductory links and the “Get started”
call-to-action.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 23:53:01 +00:00
949a57d285 content(www): update investor logo wall on company page (#47753)
## Summary

- Adds 8 new investor logos: Accel, Craft, Figma, Georgian, GIC, Peak
XV, Salesforce Ventures, Stripe
- Reorders lead investor grid to match design mockup (3 rows of 4)
- Adds per-logo `scale` field to control logo size within each cell
- Adds `grayscaleOnly` field for Salesforce Ventures to preserve tonal
contrast (prevents wordmark from being hidden by `contrast-0` filter)

## Test plan

- [ ] Visit /company and verify all 12 investor logos render correctly
across 3 rows
- [ ] Check logo sizing and order matches the mockup
- [ ] Verify Salesforce Ventures wordmark is visible inside the cloud
shape
- [ ] Check dark mode

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Expanded and reordered the “Our investors” lead cards with additional
entries (including Stripe, Salesforce Ventures, and others).
* Enhanced logo presentation options for lead cards with per-investor
sizing/positioning controls.

* **Bug Fixes**
* Improved lead investor card image rendering by removing internal
scrolling and using an overflow-hidden container with scale-based
sizing.
* Preserved the existing logo filter behavior (opacity-only when
configured, grayscale-only when selected, otherwise the default contrast
treatment).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-07-09 14:18:07 -05:00
Gildas Garcia 72aa214b0c fix: new project form accessibility issues (#47785)
## Problem

The new project form has accessibility issues:
- labels are not linked to inputs
- description are not linked to inputs

## How to test

Navigate through the form inputs with voice over and make sure every
input makes sense

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved form field identification consistency across project creation
screens (compute size, database password, project name, PostgreSQL
version, region, and organization).
* Enhanced selector/input accessibility by adding explicit element
identifiers to key controls.
* Updated region and repository UI structure to improve reliable
rendering without changing setup behavior.
* Preserved existing password, version, and routing logic while making
dropdowns and fields easier to locate and interact with.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 18:11:57 +02:00
Kamil Ogórek dcfffcd076 chore: post-review updates for sentry docs (#47784)
FUP to https://github.com/supabase/supabase/pull/47709

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the Next.js Sentry setup guide with clearer wording and a
step-by-step configuration flow.
* Added explicit instructions for instrumenting Supabase clients in
server, browser, and middleware contexts.
* Included guidance for enabling query and mutation data capture so
Supabase activity appears in monitoring as database spans.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 17:27:15 +02:00
Cemal Kılıç 3667601895 feat(studio): add sign in with ChatGPT (#47772)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature

## Summary
Introduce a "Sign in with ChatGPT" option gated by the new
`dashboard_auth:sign_in_with_chatgpt` feature flag and a manual
localStorage rollout switch (`SIGN_IN_CHATGPT_ENABLED`), since the
feature is still WIP.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added support for signing in with ChatGPT alongside GitHub.
* ChatGPT sign-in now depends on both a feature flag and an additional
rollout setting.
* Updated provider availability so the app can show the correct sign-in
options.

* **Bug Fixes**
* Improved validation and coverage to ensure sign-in options appear only
when fully enabled.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 16:32:31 +02:00
b198748064 docs: update Sentry integration guide for built-in SDK support (#47709)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update.

## What is the current behavior?

The Sentry monitoring guide documents the third-party
`@supabase/sentry-js-integration` package. Sentry now ships Supabase
support natively in the JavaScript SDK (v9.14.0+), and the documented
API is incompatible with current `@sentry/*`, so the snippets no longer
work as written.

Fixes #47708.

## What is the new behavior?

All snippets are updated to the built-in API
(`Sentry.supabaseIntegration({ supabaseClient })` and
`Sentry.instrumentSupabaseClient(client)`). The Next.js section is
simplified to a single instrumentation call that covers browser, server,
and edge. The span deduplication example is corrected (supabase-js uses
`fetch`, so it filters `nativeNodeFetchIntegration`). Added a note about
the v9.14.0 requirement with the community package as the fallback for
v7, and removed the now-unnecessary install section.

## Additional context

Verified end-to-end against `@sentry/node` + `@supabase/supabase-js`:
both entry points produce `db` spans for select/insert/update/delete and
capture PostgREST errors.

**Note**: This PR was created entirely through Claude Code Opus 4.8,
with code snippets tested in a sample project.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the telemetry guide to use Sentry’s built-in Supabase support
(`@sentry/*`) instead of a community integration.
  * Added explicit setup requirements for Sentry JS SDK version 9.14.0+.
* Provided two enablement options, including instrumentation when
Supabase client setup and Sentry initialization are separate.
* Refreshed guidance for span deduplication and improved Next.js setup
instructions, including operation payload capture.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Kamil Ogórek <kamil.ogorek@gmail.com>
2026-07-09 16:19:52 +02:00
Ali Waseem d949a19f97 fix(studio): extend downgrade error toast duration (#47780)
## Summary
- Downgrading to Free tier is blocked server-side when an org has an
active branch, but the resulting error toast in `ExitSurveyModal.tsx`
used the default 4s toast duration, making it easy to miss.
- Adds `duration: 10_000, dismissible: true`, matching the pattern
already used for other important billing error toasts
(`org-subscription-update-mutation.ts`, `NewOrgForm.tsx`).

Fixes FE-3882

## Test plan
- [ ] Attempt to downgrade an org with an active branch to Free tier and
confirm the error toast stays visible for 10s and can be dismissed

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved the downgrade error message to stay visible longer and be
easier to dismiss, making failures clearer for users.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 07:58:03 -06:00
Francesco Sansalvadore 532ac3638d fix(www): update customer logos from svg to pngs (#47777)
Some customer pages didn't show og-images properly because satori breaks
using svgs.

This PR replaces all customer logos from svgs to pngs. 
They're all exported at least 2x to 4x so image quality shouldn't get
worse anywhere.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated several customer story pages and related listings to use PNG
logo assets, improving logo rendering consistency across the site.
* Refreshed the customer RSS feed metadata and removed a duplicate entry
so the feed stays up to date and cleaner.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 15:33:28 +02:00
Gildas Garcia 1aa23f9f64 fix: fix several accessibility issues on the organization home page (#47769)
## Problem

- Organizations links are not accessible with keyboard
- Project list buttons are missing labels
- Headings should be sequential


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved keyboard and screen-reader accessibility for project actions
and project reference copy controls.
  * Added clearer tooltip guidance for copying a project reference.
* Updated project and organization card interactions for more consistent
click and focus behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 15:14:05 +02:00
Charis 1987f19d0a feat(sql-editor): add manual save feature preview (#47745)
## What

Adds an opt-in **SQL Editor manual save** feature preview that switches
the SQL Editor from autosaving every edit to saving only on demand, and
hardens the tab-close flow so unsaved edits are handled correctly.

## Changes

**Feature preview**
- New `sqlEditorManualSave` flag + `UI_PREVIEW_SQL_EDITOR_MANUAL_SAVE`
local-storage toggle, wired into the Feature Preview modal with an
explanatory panel.
- `useIsSqlEditorManualSaveEnabled` gates behavior on both the flag and
the user's preview opt-in.

**Editor toolbar**
- Save button (with `Cmd+S`) next to Run, plus an autosave status
indicator showing dirty/saving/saved state and a shortcut to disable
autosave (emits a `sql_editor_autosave_disable_clicked` telemetry
event).

**Discard on close**
- Closing a snippet tab with unsaved edits prompts for confirmation and,
on confirm, actually discards the local edits and evicts the cached
server copy so the snippet reopens clean.

**Decouple tab layout from SQL specifics**
- Tabs store gains a generic per-type close-handler registry
(`registerTabCloseHandler` / `getCloseConfirmation` / `closeTabs`). The
SQL editor registers its discard + confirmation behavior from the save
coordinator.
- Low-level `removeTab`/`removeTabs` (rename/move re-keying, stale
cleanup) intentionally do **not** trigger discard.
- Adds `statusOnDiscard` lifecycle transition and `clearSnippetContent`
store action.

## Testing
- `pnpm --filter=studio typecheck` — clean.
- Added unit tests for the close-handler registry (fires on single/multi
close, skips re-keying/cleanup removals, respects tab type, selects
confirmation copy, unregisters cleanly).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a SQL editor manual-save preview with a “Save” button and
`Cmd+S`, plus a modal option to disable manual-save/preview.
* Added “unsaved changes” tab status indication when manual-save is
enabled.
* Introduced tab-type-specific close confirmations (shown only when
needed).
* **Bug Fixes**
* In manual-save mode, closing a SQL tab with unsaved edits now clears
local snippet content and refreshes it on reopen.
* **Tests**
  * Added coverage for tab close handlers and confirmation behavior.
* **Chores**
* Added a persisted setting allowlist entry and tracked autosave-disable
clicks via telemetry.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 08:37:38 -04:00
a3f2c4ffc1 chore(deps): upgrade to TypeScript 7 (native compiler) (#47757)
Upgrades the monorepo to TypeScript 7.0.2, released 2026-07-08. `tsc` is
now the native Go compiler
([announcement](https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/))
— full turbo typecheck drops from ~56s to ~19s locally.

TS 7.0 ships **without a programmatic API** (it lands in 7.1), so this
uses Microsoft's recommended side-by-side setup: the `typescript` name
resolves to `@typescript/typescript6` (the 6.0 API republished) for API
consumers — typescript-eslint and Next.js build typechecking — while
`@typescript/native` (the real `typescript@7.0.2`) owns the `tsc` bin
that typecheck scripts run. Exactly one version of each is in the
lockfile; nothing imports the native package as a library. When 7.1 +
tool support lands we can collapse back to a single `typescript` dep in
the catalog.

**Changed:**
- `pnpm-workspace.yaml`: catalog aliases for `typescript` /
`@typescript/native`
- 17 package.json files: `@typescript/native` added beside each
`typescript` dep so every package's `tsc` is the native binary
- `apps/studio/tsconfig.json`: exclude `dist/` (gitignored build output)
from typechecking

**Fixed** (real type errors TS 6 under-reported):
- `packages/ui-patterns` CodeBlock: `borderLeft: null` → `undefined`
(`CSSProperties` doesn't accept null)
- `apps/www` CodeBlock: removed a JSX `@ts-ignore` comment that tsgo
doesn't honor and fixed what it masked (untyped `.js` theme objects,
possibly-undefined highlighter children)

⚠️ **Merge timing:** the new packages are inside pnpm's 3-day
`minimumReleaseAge` window until ~July 11. Installs from the committed
lockfile are unaffected (resolution is skipped), but anything that
forces a re-resolution before then will fail — hold off merging until
the window passes.

Note for editors: the compat package has no `lib/tsserver.js`, so VS
Code's "Use Workspace Version" won't work — use the bundled TS or the
TypeScript Native Preview extension.

## To test

- `pnpm install && pnpm typecheck` — all 15 tasks green, and
`./node_modules/.bin/tsc --version` prints 7.0.2
- `pnpm lint --filter=studio` — typescript-eslint still parses (resolves
the 6.0 API)
- `pnpm build --filter=design-system` (or any Next app) — Next's
tsconfig validation and build typecheck still work
- CodeBlock rendering on www (syntax highlighting, line highlights
with/without border) — the two fixes are behavior-neutral but worth an
eyeball

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements / New Features**
* Enhanced TypeScript tooling support across the workspace for smoother
development builds and checks.

* **Bug Fixes**
  * Code blocks render more reliably when content is empty or missing.
  * Highlighted code line styling applies more consistently.

* **Maintenance**
* Studio TypeScript builds now avoid including generated output (such as
`dist`) during compilation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-07-09 14:07:17 +02:00
Alaister YoungandAlaister Young 74bc0a8e27 fix(studio): initialize Sentry on the TanStack build (captures were silent no-ops) (#47666)
Stacked on #47657 (base is `alaister/tanstack-migration-fixes`; retarget
to `master` once that merges).

The TanStack runtime never ran `Sentry.init` —
`instrumentation-client.ts` is a Next-convention file nothing imports
under TanStack Start, so every `Sentry.captureException` on that build
(including the `routes/__root.tsx` error-boundary /
`routerErrorComponent` reports) was a silent no-op.

- **Shared config source**: the entire client config moves verbatim from
`instrumentation-client.ts` into `lib/sentry-client-options.ts`
(`buildSentryClientOptions`). Both runtimes build from it, so Next and
TanStack can't drift — the builds differ only in two explicit knobs.
- **TanStack init**: `sentry.tanstack.ts` initializes `@sentry/react`
from `getRouter()` (TanStack Start's real client bootstrap — the
earliest point with the router instance), wiring
`tanstackRouterBrowserTracingIntegration(router)`. Window-guarded +
idempotent; `router.tsx` is TanStack-only so the Next build is
untouched. (Named without `.client.` — Start's import-protection fails
the build for `*.client.*` in the server graph.)
- **Third-party error filter is intentionally Next-only**: without the
bundler-injected `applicationKey` metadata (only `withSentryConfig`
provides it), the SDK tags *every* event `third_party_code: true` and
`beforeSend` would drop them all — recreating the silent no-op with a
DSN set. Follow-up: add `@sentry/vite-plugin` moduleMetadata, then
enable.
- **DSN-less builds stay crash-free**: `vite.config.ts` inlines
`undefined` for unset
`NEXT_PUBLIC_SENTRY_DSN`/`NEXT_PUBLIC_SENTRY_ENVIRONMENT` (a literal
`process.env.*` in the bundle is the exact `process is not defined`
class #47657 fixed). No-DSN → disabled client, plus the existing
`IS_PLATFORM`/consent gates.
- Tests: `instrumentation-client.test.ts` moved to
`lib/sentry-client-options.test.ts` with all 36 assertions kept, plus
integration-gating and Next/TanStack parity tests. `tsc` clean; full
`vite build --mode test` passes.

Follow-up (separate): server-side Sentry for the Start handler
(`server.ts` entry + `@sentry/node`-style init).

## To test

- **Locally (no DSN set)**: load the TanStack build — no Sentry network
requests, no console errors, and crucially no `ReferenceError: process
is not defined` (the define fallback). Forcing an error must not POST to
any `/envelope` endpoint.
- **On a preview/deploy (DSN set, telemetry consent accepted)**: throw a
test error (e.g. crash a route component) → a POST to
`o…ingest.sentry.io/api/…/envelope/` fires, and the event lands in
Sentry with a `codeSampleRate` tag and **no** `third_party_code` tag.
Navigation spans named after TanStack routes appear when the 2% pageload
trace samples in.
- **Next build regression check**: the Next dev/preview still reports
errors exactly as before (`instrumentation-client.ts` now builds its
options from the same shared source).



---

### Review feedback: Sentry `/envelope` never fires on TanStack (Joshen)

Root-caused: `@sentry/core`'s `Client.sendSession` silently drops the
session when the client has no `release`. The Next build gets a release
injected by `withSentryConfig` (the Vercel commit SHA); the Vite build
runs no Sentry bundler plugin, so it had no release → session envelopes
were discarded before transport → zero `/envelope` traffic
(errors/transactions are separate). Fix: inject `release:
NEXT_PUBLIC_VERCEL_GIT_COMMIT_SHA` on the TanStack build (vite.config
re-exposes `VERCEL_GIT_COMMIT_SHA` under the `NEXT_PUBLIC_` name, same
SHA the Next release resolves to). Also switched `integrations` to the
function form so defaults are preserved by contract (not just by current
SDK behavior). 45 unit tests green.

**To test (deploys only — the SHA is unset locally, so this can't be
reproduced on a local dev build):** on this PR's Vercel preview with a
DSN + telemetry consent, load any page and watch the Network tab for a
POST to `…ingest.sentry.io/…/envelope/` — a session envelope should now
fire on load, matching the Next build.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Improved client-side error and performance monitoring for the Studio
app across both router setups.
* Added support for passing release/version information into monitoring
data.

* **Bug Fixes**
* Reduced noisy error reporting by better filtering common browser,
extension, cancellation, and load-related issues.
* Prevented browser bundles from referencing missing environment values
at runtime.
* Made monitoring initialization safer in server-rendered and
client-only environments.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-07-09 18:41:03 +08:00
Joshen Lim f34fdd6c8f Skip using count estimate function for retrieving row counts if in read only context (#47761)
## Context

Currently when retrieving row counts of a table in the Table Editor,
we're using a `COUNT_ESTIMATE` pg function
([ref](https://github.com/supabase/supabase/blob/master/packages/pg-meta/src/sql/studio/database/get-count-estimate.ts#L5))
to retrieve an estimate (instead of checking `pg_class` -> `reltuples`)
as that would theoretically provide a more accurate representation.

However, in a read only context, that function can't be used - users
will run into `cannot execute CREATE FUNCTION in a read-only
transaction`, so we need to fallback to just checking `pg_class` in this
scenario.

The logic's already set up as we were previously looking into allowing
users to use a read replica to power the dashboard, but we also need to
consider members with read-only roles within the organization, so this
PR updates the logic a little to factor that in.

## To test

- [ ] With a read-only role, open the table editor and verify that we're
not using the count estimate function to retrieve the table row counts

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Updated the invite member dialog to open in a larger size for better
usability.

* **Bug Fixes**
* Improved table row count behavior so it now respects read-only access
and permission limits more reliably.
* Count estimates should now be shown more consistently across different
database contexts.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 18:19:39 +08:00
Joshen Lim 644fe0821b Add create org CTA for authorize route if no org found (#47760)
## Context

As per PR title - also left a comment that this is a short term solution
for now, so we know where to clean up after the long term solution is
implemented

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added a clear action in the empty organizations state so users can
create an organization directly from the authorization flow.

- **Bug Fixes**
- Improved authorization error messaging for clearer, more consistent
display.
- Refined invalid authorization guidance so the retry prompt and
missing-parameter details are shown more cleanly.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 18:18:08 +08:00
Prashant Sridharan 6cac3dbe5d Fixed case study title (#47768)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

Fixed the title on one of the case studies.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Content Updates**
* Updated the Lovable customer story headline to put the focus on
Supabase first.
  * Aligned the customer RSS entry title with the new headline wording.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 10:44:30 +01:00
Joshen Lim 4901f081e5 Migrate remaining requests to pg-meta API to use query endpoint (#47758)
## Context

Migrates the remaining API requests to the pg-meta endpoint to use the
query endpoint directly with the SQL from the pg-meta package. This
touches the following:
- policies
- publications
- triggers
- views
- materialized views
- types

## To test
Just need to verify that we're still fetching the data correctly on
these pages
- Database policies
- Database publications
- Database triggers
- Database tables (views + materialized views)
- Database types

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved and stabilized loading of database metadata (views, triggers,
RLS policies, publications, materialized views, and enum types),
including more reliable schema-scoped filtering.
* Updated policy loading behavior and related UI queries to consistently
use schema arrays, improving cache correctness and consistency.
* **Tests**
* Updated end-to-end test synchronization to wait for the correct
metadata responses using more specific request identifiers.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 17:09:03 +08:00
Joshen Lim 073cada53a Fix observability custom reports menu item (#47759)
## Context

More action button should be flushed to the right here
<img width="294" height="156" alt="image"
src="https://github.com/user-attachments/assets/65017960-3edb-4268-bb0e-1e2c26937d4b"
/>

## Changes involved
- Adjust `Menu.Item` in `packages/ui` to use a `div` instead of a `span`
- Was otherwise causing HTML validation issues as we were trying to nest
a `div` within a `span`
- Having a `div` is a bit more flexible as well since `Menu.Item`
expects `children` to be of any type (e.g a react node)

<img width="279" height="149" alt="image"
src="https://github.com/user-attachments/assets/12730cef-b077-4ef4-93c9-c21def939888"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Refactor**
* Standardized the Observability menu component to use named exports,
ensuring consistent usage across the app.
* Updated the mobile observability menu registration to reference the
correct exported component.
* **Style**
* Refined Observability menu item layout, spacing, truncation, and
dropdown sizing for a cleaner presentation.
* Enhanced menu item rendering to allow custom `className` styling and
full-width content layout.
* **Accessibility**
* Added an aria-label to the “more actions” button for improved screen
reader support.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 17:08:11 +08:00
Francesco Sansalvadore 9b05afa2a3 Fix(docs): guides subheadings (#47765)
Fix docs subheading by removing the h2 html tag and adjusting styling.
Likely a result of a merge conflict resolution between #47441 and #47288

## What is the current behavior?

<img width="1168" height="641" alt="Screenshot 2026-07-09 at 10 19 00"
src="https://github.com/user-attachments/assets/c23b2e88-650c-4835-ae10-5a13c7b2e180"
/>


## What is the new behavior?

<img width="1167" height="605" alt="Screenshot 2026-07-09 at 10 32 56"
src="https://github.com/user-attachments/assets/852f208c-2b22-4bf6-ad8c-edcf5bee5991"
/>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Refined how guide subtitles are displayed for a cleaner, more
consistent layout.
* Adjusted subtitle spacing and presentation while keeping subtitle
content rendering with formatted text support intact.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 10:54:45 +02:00
shaziya 82495cb455 blog: Searchable field-level encryption on Supabase with CipherStash (#47751)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES

## What kind of change does this PR introduce?

### Blog post: Searchable field-level encryption on Supabase with
CipherStash

Partner drop announcing the CipherStash integration. **Scheduled to go
live July 9, 2026.**

- Author: `bilharmer` (title corrected to CISO)
- Category: `product`
- URL: `/blog/searchable-field-level-encryption-with-cipherstash`


### Outstanding before merge
- [x] Marketing +1 in `#team-marketing`.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Published a new blog post about searchable field-level encryption with
Supabase and CipherStash, including setup guidance, integration details,
and a video walkthrough.
* **Content Updates**
  * Updated an author profile title from “CSO” to “CISO.”

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 01:49:07 -07:00
Monica KhouryandJoshen Lim 9e17c41771 Chore: Link Delete Project doc from the Delete Project confirmation m… (#47637)
Fixes FE-3801. 

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Updated the project deletion confirmation dialog so the “learn more /
documentation” text and external link are always shown consistently.
* Paid projects now include the full warning (“All project data will be
lost, and cannot be undone.”) alongside the documentation link, while
free projects show the simplified message without the additional
warning.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-07-09 11:41:16 +03:00
fd8a37b1d0 feat: add toggle for sensitive data visibility in table columns (#46180)
## Fixes

FE-2619

## What is the new behavior?

This PR adds support for marking table columns as sensitive and masking
their values in the grid view.

Sensitive columns:

- Display an 8-dot mask instead of the underlying value
- Remain masked across page refreshes
- Can be temporarily revealed for 5 seconds via the **Show data** action
- Display a warning when copying rows containing sensitive data

This helps prevent accidental exposure of sensitive information when
sharing screens, recording demos, or taking screenshots.

## Testing

- [x] Toggle sensitivity ON → save → refresh → remains masked
- [x] Toggle sensitivity OFF → save → refresh → remains unmasked
- [x] Toggle sensitivity multiple times → state remains consistent
- [x] Copy row with sensitive columns → warning shown
- [x] Click **Show data** → value revealed for 5 seconds then re-masked
- [x] Text, Boolean, Binary, JSON, and Foreign Key columns all display a
consistent 8-dot mask

### Test data

SQL fixture covering multiple PostgreSQL data types:

https://gist.github.com/monicakh/2485e9054bf21045912359871e9a1cb4. 

### UI

<img width="1284" height="554" alt="CleanShot 2026-06-09 at 12 01 33@2x"
src="https://github.com/user-attachments/assets/4aec0ba7-c874-42d7-9442-d2c704b319cc"
/>

<img width="1200" height="560" alt="CleanShot 2026-06-07 at 10 43 40@2x"
src="https://github.com/user-attachments/assets/b9569484-6fcc-47de-bc3d-881d0edc4060"
/>

The **Show data** action is only available for sensitive columns.

<img width="450" height="400" alt="CleanShot 2026-06-07 at 10 42 18@2x"
src="https://github.com/user-attachments/assets/d48849a2-ec0b-4522-a787-561a1d204ec9"
/>

Warnings on Copy command

<img width="450" height="80" alt="CleanShot 2026-06-09 at 11 58 42@2x"
src="https://github.com/user-attachments/assets/374e7d6b-b82a-4923-b035-2ec9b2f7bb7d"
/>

<img width="450" height="80" alt="CleanShot 2026-06-09 at 11 58 58@2x"
src="https://github.com/user-attachments/assets/ecd951bb-e9e2-47ae-9ddd-d32969e01c12"
/>


<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46180?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: supabase-autofix-bot <noreply@supabase.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-07-09 10:44:42 +03:00
Saxon Fletcher 97713923f8 Revert override (#47754)
Reverts a color override which seems to be causing issues in some edge
cases

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Adjusted the light theme so its surface color now uses the default
value instead of being overridden.
* Preserved the dark theme appearance while keeping theme styling
consistent across modes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-09 09:04:57 +10:00
Ali Waseem 000bdd0684 fix(studio): trim leading whitespace in site URL form (#47748)
## Changes

- **SiteUrl.tsx**: Added `.trim()` to the Zod schema so whitespace is
stripped before validation and before the value reaches the mutation.
All-whitespace input now correctly fails with "Must have a Site URL"
instead of being silently accepted. This matches the existing pattern in
the sibling Redirect URLs form (AddNewURLModal.tsx).
- **SiteUrl.test.tsx** (new): MSW component test with two cases:
- Trims leading/trailing whitespace before submitting to PATCH
/platform/auth/:ref/config
- Shows a validation error and does not submit when the value is only
whitespace

## Test plan

- [x] `npx vitest --run
components/interfaces/Auth/SiteUrl/SiteUrl.test.tsx` — 2/2 pass
- [x] `npm run typecheck` — clean
- [x] `npx eslint` on both files — no new warnings


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved site URL validation so leading and trailing whitespace is
ignored before saving.
* Prevents whitespace-only values from being submitted and shows a
validation error instead.

* **Tests**
* Added coverage for site URL saving, including trimmed input,
validation failures, request payloads, and success feedback.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 13:06:56 -06:00
Prashant Sridharan 0675075a3c Added three new case studies (#47750)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added three new case studies:

- Lovable
- Delight.ai
- Drew's Crew

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added three new customer story pages highlighting how teams use the
product in real-world workflows.
* Published updated customer stories for delight.ai, Drew Crew, and
Lovable with richer quotes, results, and next-step narratives.
* **Chores**
* Updated the customer stories RSS feed with the latest entries and
publish date so new stories appear in syndication.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 20:06:17 +01:00
26248be753 docs: Add AI Tools to QuickStarts (#47684)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## Summary

Adds two new optional onboarding steps — **Install Agent Skills** and
**Install MCP server** — to every framework quickstart guide, right
after the "create app" step, so readers are pointed at [Agent
Skills](/docs/guides/ai-tools/ai-skills) and the [Supabase MCP
server](/docs/guides/ai-tools/mcp) early in the setup flow.

**Where each step lives:**
- **16 quickstarts that include the shared `quickstart_db_setup.mdx`
partial** (Next.js, Astro, Expo/React Native, Flask, Flutter, Hono,
iOS/SwiftUI, Kotlin, Laravel, Nuxt, React, Refine, SolidJS, SvelteKit,
TanStack Start, Vue): the partial itself now has a step 2 "Install MCP
server (optional)" (between project creation and database setup), and
each individual file gets its own "Install Agent Skills (optional)" step
right after its app-creation step.
- **RedwoodJS and Ruby on Rails** (don't use the shared partial): got
both steps added inline, in the same order (Agent Skills, then MCP
server), since they can't inherit from the partial.
- All subsequent step numbers (and the "Step N" cross-references in
prose, e.g. in RedwoodJS) were renumbered to stay sequential.

## Test plan

- Check the quickstarts locally or in preview.
- Any other ideas on how to optimise showing these items?
- Does the SQL prefill add anything?
- Other ideas on how to simplify without losing the information?
- Check the MD output too and see if that also makes sense.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Refreshed multiple getting-started quickstarts with consistent,
clearer step sequencing (including renumbering) across frameworks.
* Added an optional “Install Agent Skills” step where applicable, plus
updated placements of shared environment-variable setup content.
* Simplified the database quickstart flow: single “Create a Supabase
project” step, streamlined SQL Editor instructions for creating an
`instruments` table, enabling RLS, and granting public read access.
* Added optional “Install MCP server” steps in the relevant quickstarts.
* **Style**
* Updated MDX linting rules to allow the uppercase phrase “Agent
Skills”.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
Co-authored-by: Nik Richers <nrichers@gmail.com>
2026-07-08 18:41:39 +00:00
Joshen Lim 944c5862f3 Chore/small refactors (#47740)
## Context

Just extracting the fixes which I think are applicable from this
[PR](https://github.com/supabase/supabase/pull/47695)

Main files are
- `apps/studio/hooks/analytics/useLogsQuery.tsx`
- `packages/common/auth.tsx`
- `packages/common/feature-flags.tsx`

## Changes involved
- Adjust `useLogsQuery` to accept an object as prop, rather than 4
individual params
- This one doesn't address any Sentry issues, but is just a improvement
to the function's API imo, more readable
- Adjust how user email is retrieved in `feature-flags`
- Related Sentry issue
[here](https://supabase.sentry.io/issues/7592718607/?project=5459134)
- The error is a bit vague, but Claude's attempt to fix looks alright in
general IMO
  - Minimally verified that feature flags are loading as expected still

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved log-related screens and queries for more reliable loading and
filtering across the app.
* Fixed profile and account data handling so identity details are
retrieved more consistently.
* Improved authentication handling to better recognize missing user data
and keep the app stable.
* Updated feature flag personalization to use more accurate account
information.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 23:21:48 +08:00
Jordi Enric 982d860123 feat(functions): migrate last-hour stats query to OTEL ClickHouse (#47693)
## What

Migrates the `edge-functions-last-hour-stats` query (requests + server
error counts shown on the Edge Functions list) from the BigQuery-style
`logs.all` endpoint to the OTEL/ClickHouse `logs.all.otel` endpoint.

<img width="2378" height="958" alt="CleanShot 2026-07-07 at 16 24 43@2x"
src="https://github.com/user-attachments/assets/5bf3f04c-43e1-44a3-af28-d53feee27f68"
/>

## How

- Adds an OTEL SQL builder that reads from the single `logs` table
(`source = 'function_edge_logs'`), using `log_attributes['function_id']`
and `toInt32OrZero(log_attributes['response.status_code'])` instead of
`cross join unnest(metadata)`.
- Gated by the `otelLegacyLogs` flag, matching the rest of the logs
code. The BigQuery path is preserved when the flag is off, and the two
paths cache under separate query keys.

## Testing

- Unit tests cover both endpoints and assert the generated SQL for each
path.
- Go to edge fns list
- stats load correctly

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added support for using the OTEL logs backend for edge function
last-hour stats when enabled.
* Queries and caching now automatically distinguish between the standard
and OTEL-backed data sources.
* **Bug Fixes**
* Ensured stats results are fetched from the correct endpoint based on
the selected logging backend.
  * Added coverage to verify OTEL-specific SQL and response behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 17:16:08 +02:00
Vaibhav c070893475 fix: limit regex (#47717)
- closes https://github.com/supabase/supabase/issues/47712 

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved SQL query handling so automatic row limits are no longer
added when a query already ends with `LIMIT`, even if there’s whitespace
before the semicolon.
  * Preserved correct behavior for queries using `LIMIT ... OFFSET ...`.
* **Tests**
* Expanded coverage for SQL limit detection and limit-suffix behavior
around whitespace and semicolon placement.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 08:11:39 -06:00
Jeremias Menichelli 5066261dbd [DOCS-1148] Improve prose for LLM readability (#47653) 2026-07-08 16:00:47 +02:00
Yogeshwaran CandChris Chinchilla c84d9856ae docs: improve discoverability of custom schemas documentation (#42634)
## What kind of change does this PR introduce?
Documentation improvement

## What is the current behavior?
The documentation for using custom schemas is buried under the REST API
section (`/guides/api/using-custom-schemas`), making it hard for users
to find when they first encounter schemas in the database documentation.
Users who create custom schemas often don't realize they need to
configure API access and grant permissions, leading to confusion.

Closes #39856

## What is the new behavior?
Three improvements to make custom schemas documentation more
discoverable:

1. **Cross-reference in tables page**: Added an admonition tip after the
"Schemas" section in `/guides/database/tables` linking to both the
"Using Custom Schemas" guide and the "Hardening the Data API" guide
2. **Navigation sidebar**: Added "Using Custom Schemas" link under
"Database > Access and security" in the sidebar navigation, so users can
find it from the database section without having to navigate to the API
section
3. **service_role mention**: Updated the schema grants example in
"Hardening the Data API" to include `service_role` alongside `anon` and
`authenticated`, since users with server-side access also need this
grant

## Additional context
The issue author spent hours debugging custom schema access because the
documentation wasn't linked from where schemas are first introduced (the
database tables page). These changes create a clear path from learning
about schemas → configuring API access → security hardening.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added "Using Custom Schemas" guide to the navigation menu under
Database -> Access and security section
* Enhanced Data API hardening documentation with clarification on
service_role permissions for server-side database access
* Added instructional tips regarding custom schema exposure via Data API
and proper permission configuration

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2026-07-08 13:02:24 +00:00
Joshen LimandAli Waseem 0421b1001d Flip show tooltip to true for supavisor connections chart (#47730)
## Context

Realised that tooltips were not showing up for supavisor charts in
database reports - just needed to flip a boolean
Although - i don't have any projects with supavisor connections data
(even on prod) so I can't visually verify this atm

Also fixes a small issue in which docs url for the chart wasn't showing
if the chart had no data, e.g:
<img width="996" height="311" alt="image"
src="https://github.com/user-attachments/assets/926febe4-9e3d-4975-9278-e7582d6ae12d"
/>

Should have docs button like this
<img width="949" height="351" alt="image"
src="https://github.com/user-attachments/assets/7561c1c5-94ae-405b-bd54-6bc94be0dd0a"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Enabled tooltips for the “Shared Pooler (Supavisor) client
connections” chart so the metric can be inspected directly.
* **UI Improvements**
* Adjusted the tooltip positioning in the chart header for clearer
readability.
* When charts have no data, the “Learn more”/documentation link now
follows the provided docs URL.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-07-08 12:52:42 +00:00
Gildas Garcia 62160939a8 fix: make status hovercard trigger on focus (#47731)
## Problem

Status lists only appear on mouse hover and disappear when panning at
200%+ zoom.

## Solution

Make hover-triggered information available via click or focus in line
with WCAG 1.4.13

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved keyboard accessibility for the service status hover card by
making the trigger focusable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 14:52:36 +02:00
Yarema KertytskyandChris Chinchilla 6e4dc5df75 fix: correct typos and improve clarity in AI documentation (#42662)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?
Hello team and community! Decided that I want to start helping to
maintain supabase, and decided to open my first PR with clearing typos
and phrasing improvements for docs in AI folder.


## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Refined and corrected grammar throughout AI implementation guides,
improving readability across production deployment, Google Colab
integration, LangChain, RAG with permissions, semantic search, and
vector columns documentation. Updates include terminology consistency
improvements, punctuation refinements, and clearer phrasing to enhance
overall guide clarity.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2026-07-08 12:42:38 +00:00
shane-at-supabase 0e02b86e74 Add Shane Adams to humans.txt (#47701)
Adding myself as part of onboarding

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

doc update: added name to humans.txt



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added a new team member entry in the public site metadata.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 14:03:14 +02:00
Pamela Chia 6dfae09b6d fix(www): postgres card art overlaps text column (#47734)
Before 
<img width="588" height="439" alt="Screenshot 2026-07-08 at 7 29 07 PM"
src="https://github.com/user-attachments/assets/8a3380d3-571f-49cd-8f32-7b38650dd0e5"
/>

After 
<img width="578" height="436" alt="Screenshot 2026-07-08 at 7 29 55 PM"
src="https://github.com/user-attachments/assets/09e74c31-e131-41d5-87da-b4518514cfb5"
/>


## Summary

On the homepage, the Postgres Database product card's elephant artwork
renders over the card's description text at every viewport ≥1280px. I
traced it to #47226 (merged June 24): standardizing the marketing
container to `section-container` (`max-w-7xl` + `xl:px-24`) capped
products-grid content at 1088px, shrinking the card to ~538px while its
fixed geometry (250px text column + 398px right-anchored square artwork
box) needs ~625px. Large monitors regressed hardest: before June 24 they
got ~676px cards and no overlap. The app-router homepage move (#47228),
the color system PR (#47288), and the artwork PNGs are all unrelated
(verified against production DOM and full diffs).

Two changes to the artwork span in `DatabaseVisual.tsx`:

1. Cap the box width at `calc(100% - 280px)` from `md` up, where 280
covers the text column's `md:max-w-[250px]` cap (in `ProductCard.tsx`'s
`isDatabase` branch) plus card padding and breathing room. The art
scales down through its existing `object-contain`. At md/lg the card is
full-width (`md:col-span-12`), so the clamp never binds and rendering is
unchanged there.
2. Remove the `xl:-right-12` bleed (base `right-0` stands, matching how
2xl already rendered). The bleed used to clip only the art's transparent
canvas margin; with the clamped box the art fills its full width, so the
48px offset was cropping the elephant itself at 1280-1535px.

The hover line-art SVG scales with the box and stays aligned with the
PNG (identical aspect ratios: viewBox 390:430, PNG 585x645).

## Changes
- Add `md:max-w-[calc(100%-280px)]` to the artwork span in
`DatabaseVisual.tsx` so the Postgres card art can never cross its text
column
- Drop `xl:-right-12 2xl:right-0` from the same span so the smaller art
isn't clipped at the card's right edge

## Testing

Round 1 on the Vercel preview (commit e1ca671, measured via
getBoundingClientRect + computed styles):
- [x] Art clear of the text column at 1280/1440/1600/1920 (gap 54px at
1280/1440, 6px at 1600/1920); computed `max-width: calc(100% - 280px)`
applies
- [x] Hover at 1440 — SVG and PNG rects identical (pixel-exact
alignment)
- [x] 768/1024 — full-width card unchanged, span still a 398px square
(clamp resolves but doesn't bind)
- [x] Light theme at 1440 — same geometry, no overlap

Round 1 also surfaced that the `xl:-right-12` bleed now cropped the
elephant at 1280-1535px widths → second commit removes it. Round 2
(commit e28b408):
- [x] 1280/1440/1512/1600/1920 — art fully visible (span right edge
flush at the card's inner edge, e.g. 713 vs 714 at 1440), still clear of
the text column (span left 457 vs text right 451)
- [x] 768/1024 — unchanged (span still a right-anchored 398px square)
- [x] Hover alignment still exact (PNG and SVG rects identical:
457,452,256,398)

## Linear
- fixes GROWTH-971
2026-07-08 19:56:12 +08:00
Carel de WaalandAlaister Young 0acc0eb8b3 feat: Support Form - Sync AI assistant conversation to Front (#46778)
# Sync AI assistant conversation to Front

## What & why

When a user submits a support ticket, an AI assistant chat opens so they
get help
immediately while waiting for a human agent. This PR mirrors every turn
of that chat into
the Front conversation the support form already created, so the support
team sees the full
context and Front automations (routing, emails, CSAT) can act on it.

Studio holds no Front credentials — it calls the platform endpoints (see
the platform PR)
to do the syncing. The assistant card is gated behind the
`supportAssistantFollowUp`
ConfigCat flag.

## How it works

1. **Submit** — `SupportFormV3` generates a stable `threadRef` (via the
`uuid` package —
`crypto.randomUUID()` is `undefined` in insecure contexts like
non-localhost HTTP and
would throw, silently aborting the submit) and sends it on
`/platform/feedback/send`.
The response returns the Front `conversationId`. Both are stored on
`SubmittedSupportRequest`.
2. **Open chat** — `SupportAssistantSuccessCardContent` opens a chat
seeded with
`supportMetadata` (`threadRef`, `frontConversationId`, subject,
category, severity, …).
   The first message is a `<support>…</support>` XML block.
3. **First user message** — the chat is tagged `isSupportChat = true`;
the `onFinish` hook
   fires `syncSupportChatToFront`.
4. **Subsequent turns** — each `onFinish` slices the unsynced delta,
strips the XML
metadata block from the seed message, and posts to the platform messages
endpoint.
5. **Escalation / resolve** — the `escalate_to_human` /
`resolve_support_conversation` tools
(and manual **Escalate**/**Resolve** buttons in the assistant input)
flip lifecycle status
via `setSupportLifecycleStatus` → `syncSupportLifecycleToFront`, which
calls the
escalation/resolve endpoints. Front rules act on `ai_support_status`.
The assistant only
   resolves after the user explicitly confirms the issue is fixed.

## Key design decisions

- **`threadRef` as the shared key** — one UUID travels as `threadRef` on
submit and as
`chatId` on every sync, so all messages thread into a single Front
conversation.
- **`conversationId` from the form response** — passed to all
sync/lifecycle calls so the
  platform skips lazy derivation and PATCHes custom fields directly.
- **Delta-only sync** — `lastSyncedMessageCount` tracks what's been
sent; the boundary is
snapshotted before the async call to avoid skipping messages that arrive
mid-flight.
- **Server-side de-dup** — stable `external_id` (`chatId:msg.id`) means
retries don't
  duplicate in Front.
- **Fire-and-forget** — sync failures log to Sentry, never break the
chat; `isSyncing`
resets on rehydration so the next `onFinish` retries the same delta.
Message and lifecycle
syncs use separate guards (`isSyncing` / `isLifecycleSyncing`) so an
in-flight message
  sync can't drop an escalate/resolve.
- **Lifecycle queued until the conversation exists** — if a lifecycle
transition is requested
before the initial message sync has returned a `frontConversationId`,
it's stored as
`pendingLifecycleStatus` and flushed once the id is assigned, rather
than dropped.
- **Tools return immediately** — the lifecycle tools return a stub to
the AI SDK; the real
Front call happens in `onFinish`, keeping async I/O out of the tool
execute path.
- **XML seed stripped before sync** — only the user's actual `<message>`
is sent to Front
  (or dropped entirely if the form already created the conversation).

## Changes

| Area | File(s) |
| --- | --- |
| Support form state | `SupportForm.state.ts` — `threadRef` /
`frontConversationId` on `SubmittedSupportRequest` |
| Support form submit | `support-ticket-send.ts` — sends `threadRef`,
reads `conversationId` |
| Support form UI | `SupportFormV3.tsx` — generates `threadRef`, stores
`conversationId` |
| AI assistant state | `ai-assistant-state.tsx` — `SupportChatMetadata`,
`setSupportLifecycleStatus`, `onFinish` wiring, tool handling |
| Message sync | `state/ai-chat-front-sync.ts` — delta tracking, message
filtering, initial vs. incremental |
| API data layer | `data/feedback/ai-chat-front-sync.ts` — typed
platform-client wrappers for the three conversation endpoints |
| Support tools | `lib/ai/tools/support-tools.ts` — `escalate_to_human`,
`resolve_support_conversation` |
| Tool integration | `lib/ai/tool-filter.ts`, `tools/index.ts`,
`generate-assistant-response.ts` |
| Success card | `SupportAssistantSuccessCardContent.tsx` — tags chat on
first engagement |
| Assistant panel UI | `AIAssistant.tsx` — Escalate/Resolve buttons,
disabled input on closed chats, support placeholders |



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

- **New Features**
  - Support chats now include “Escalate to human” and “Resolve” actions.
- Support submissions can be associated with a stable Front thread via a
generated `threadRef`, preserving linkage across follow-ups.
- AI assistant responses and input hints adapt when support mode is
active.

- **Bug Fixes**
- Improved support chat state management and lifecycle handling to keep
conversation metadata and message history synchronized more reliably
with Front.

- **Chores**
- Added/updated coverage to reflect the new support-chat state and
syncing behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-07-08 12:41:53 +02:00
Guilherme SouzaandClaude 47912201e0 docs: Update documentation from Dart, and Swift SDK changes (#47583)
## Summary

Updates reference specs based on new stable releases in two SDK repos
(JS spec is auto-generated and was excluded).

## Changes analyzed

| SDK | Repo | Stable tag range |
|-----|------|-----------------|
| dart | supabase/supabase-flutter |
`supabase_flutter-v2.15.0...supabase_flutter-v2.15.4` |
| swift | supabase/supabase-swift | `v2.48.0...v2.49.0` |

## Documentation updates

### Dart (supabase_flutter-v2.15.0 → v2.15.4)
- **`supabase_dart_v2.yml`**: Updated `deleteUser()` — added
`shouldSoftDelete: bool` parameter with example
- **`supabase_dart_v2.yml`**: Updated `from.createSignedUrl()` — added
`download: DownloadBehavior?` parameter with example
- **`supabase_dart_v2.yml`**: Updated `from.getPublicUrl()` — added
`download: DownloadBehavior?` parameter with example
- **`supabase_dart_v2.yml`**: Added new `from-create-signed-upload-url`
entry with `upsert: bool` parameter (was missing from the Dart spec)

### Swift (v2.48.0 → v2.49.0)
- **`supabase_swift_v2.yml`**: Updated `explain()` — added note on
`ExplainFormat` enum (`.text`/`.json`), added JSON format example
- **`supabase_swift_v2.yml`**: Updated `createBucket()` and
`updateBucket()` examples — `BucketOptions(public:)` renamed to
`BucketOptions(isPublic:)`
- **`supabase_swift_v2.yml`**: Updated `createSignedURL()` and
`getPublicURL()` download examples — `download: Bool` replaced by
`download: DownloadBehavior?` (`.withOriginalName` / `.named()`)

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added guidance for soft-deleting users, including a new example.
* Documented download behavior for signed URLs and public URLs,
including original or custom filenames.
* Added documentation and examples for generating signed upload URLs,
with optional overwrite support.
  * Expanded query plan documentation to show JSON output.
* Updated storage examples to match the latest option names and
recommended usage.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-08 07:09:37 -03:00
Gildas Garcia 0eeeb758d8 fix: homepage accessibility fixes (#47729)
## Problem

On the organization home page:
- you can't tab to a project card and navigate to the project
- the status filter popover cannot be open with keyboard
- the feedback popover cannot be open with keyboard

## Solution

- make the project card (which is a link) accessible with Tab
- fix the popover trigger buttons

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved keyboard accessibility so project cards can be focused with
Tab navigation.
* Updated dropdown and filter popover trigger wiring for more consistent
click behavior.
* Reset the feedback flow to its starting step whenever the trigger is
clicked.
* **Bug Fixes**
* Made the home icon link explicitly focusable via keyboard navigation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 11:44:48 +02:00
hallidayo f1c8187d17 fix: api docs not found (#47304)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Supabase Studio > Integrations > Data API >
[Docs](https://supabase.com/dashboard/project/_/integrations/data_api/docs)

## What is the current behavior?

Going to a route that does not exist the user just gets a blank page and
no warning.

## What is the new behavior?

User now gets redirected back to the intro docs page and and error toast
appears

## Additional context

Closes #34721


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Improved handling of invalid Data API documentation links.
* If a requested table, view, or function can’t be found after loading,
users now see an error message and are redirected back to the main Data
API docs page.
* This helps prevent blank or broken documentation views when route
parameters are incorrect.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 10:00:40 +02:00
18431efb25 fix(studio): TanStack post-merge fixes — Monaco loader, fonts, CSP (from #46424) (#47657)
Post-merge fixes for the TanStack Start migration (#46424) — things that
broke on the TanStack build as master evolved under the migration
branches. Kept on their own branch off master rather than piling onto
the E2E-matrix PR (#47119); all land on master and cascade up to S6 +
the big PR.

Common theme: a master PR changed something the Next pipeline handles
via `next/font` / `pages/_app.tsx` / `next.config.ts`, but the
hand-rolled TanStack equivalent (`routes/__root.tsx`,
`styles/fonts.css`, `vercel.ts`) wasn't updated to match — invisible on
the Next deploy, broken only on TanStack.

---

## 1. Monaco loader path (#47182)

#47182 re-nested the served Monaco assets from a flat
`public/monaco-editor/` layout into `public/monaco-editor/vs/` and
updated `pages/_app.tsx`, but `routes/__root.tsx` still pointed
`loader.config` at the old path, so `loader.js` 404'd and **no Monaco
editor mounted anywhere in the TanStack build**. Now mirrors the Next
config (`${origin}${BASE_PATH}/monaco-editor/vs`, window-guarded for
SSR). Was failing the whole `tanstack` E2E shard on #47119.

## 2. Inter + Manrope fonts (#47306)

#47306 renamed Tailwind's sans var `--font-custom` → `--font-sans` and
added `--font-heading` (Manrope), set via `next/font` on Next.
`fonts.css` still only set the now-ignored `--font-custom`, so the body
fell back to the theme's system chain (`Circular, custom-font,
Helvetica…`) at weight 450 — that's the "Inter weights look wrong".
Manrope was missing entirely.

- Wire `--font-sans` (Inter) + `--font-heading` (Manrope) to match
`next/font`.
- **Vendor all three families** (Inter, Manrope, Source Code Pro) via
`@font-face` so nothing depends on the Google Fonts CDN — matches
`next/font` self-hosting, and (see below) `font-src` doesn't allow
`fonts.gstatic.com` anyway.

Verified in-browser: computed `body` → `Inter`, headings → `Manrope`,
all loading from local `/assets/*.woff2`.

## 3. Security headers / CSP (next.config.ts `headers()`)

The Next build sets X-Frame-Options / X-Content-Type-Options / HSTS /
**Content-Security-Policy** / Referrer-Policy via `next.config.ts`. The
TanStack build never carried these over — `vercel.ts` only set
cache-control, so **the deployed TanStack dashboard shipped with no CSP
at all**.

The TanStack deploy serves a static shell (no server to attach headers),
so they go in the Vercel config:
- `security-headers.ts` — shared source of truth, reuses `getCSP()`,
env-gated exactly like next.config.
- `vercel.ts` — apply to every response (all base-path prefixes): full
`getCSP()` + HSTS on platform.
- `scripts/serve.js` — the non-platform set (`frame-ancestors 'none'`)
for the self-hosted server.

**Tested the policy in a real browser** (temporarily enforced it on the
TanStack build via /test-supabase-local): everything passed except one
real gap — `font-src` was missing `data:`, so GraphiQL's bundled Monaco
codicon font and Stripe's payment-element fonts (both data: URIs) were
blocked (37 violations on a cold load). Added `data:` to `font-src` in
`csp.ts` → violations drop to zero, SQL editor Monaco renders clean.
That gap affects the Next build too.

---

## 4. `node:path` import crashing `/project/[ref]/merge`

Found by a full-site click-through of the TanStack build (all product
areas, ongoing — see below). `useEdgeFunctionsDiff.ts` +
`EdgeFunctionsDiffPanel.tsx` did `import { basename } from 'path'` in
client code. Webpack (Next) polyfills `path` in the browser; Vite
externalizes it, so the whole `/merge` route crashed with "Module
\"path\" has been externalized for browser compatibility". Replaced the
two `basename` call sites with a string helper. Verified in-browser:
`/merge` renders.

## 5. URL shape — Next-style search-param semantics + shim fixes

The dashboard produced malformed URLs vs the Next build (strange query
params, trailing slashes, `##` hashes). Root cause + audit verified
empirically against `@tanstack/react-router@1.170.10`; all fixed with
unit tests and browser-verified:

- **`createRouter` used TanStack's default JSON search codec** —
`?flag=true` became `?flag=%22true%22` via links, repeated
`?filter=…&filter=…` collapsed into a JSON array (breaking
multi-filter/sort table-editor URLs and the account-page round-trip,
which double-encoded), and search values arrived as numbers/booleans
where the app expects strings. New `lib/router-search-params.ts`
(Next-style: strings in, strings out, repeated keys → string[]) wired
into the router.
- **Link shim** (`compat/next/link.tsx`): `URL.hash` includes the
leading `#` while TanStack's `hash` prop adds its own → every
`href="…#section"` navigated to `##section` (hash-scroll broke);
`Object.fromEntries(searchParams)` dropped repeated query params. Both
fixed.
- **Trailing slash injected before the query** on every `?`-only
relative navigation (`/auth/providers/?provider=…`): fixed in the compat
router (prefix current pathname) and via a custom nuqs adapter
(`lib/nuqs-tanstack-adapter.tsx`) replacing the stock tanstack-router
adapter, whose `navigate({ to: '?…' })` writes hit the same TanStack
behavior (123 files use nuqs).
- **Pathname-less `router.push({ query })` leaked path params** — Next
re-consumes `ref`/`id` from `query` into the path pattern; the shim
didn't, yielding
`/editor/17597?schema=public&ref=<ref>&id=17597&filter=…` from
table-editor filter/sort, linter panels, and advisor shortcuts. The shim
now defaults the pathname to the current route pattern and backfills
omitted params.
- **Redirects dropped query + hash** (Next's `redirects()` preserves
them): `__root.tsx` `matchRedirect` and `routes/index.tsx` now carry
incoming params/hash through (consumed rule params excluded,
destination's own params win). `/?next=new-project&projectName=zzz` →
`/new/new-project?projectName=zzz`; `/sql/quickstarts?template=x#frag` →
`/sql/examples?template=x#frag`.

Browser-verified post-fix: advisors `?preset=WARN`, providers
`?provider=Google`, `?schema=auth` — all clean (no `/?`, no leaks);
repeated `filter` params survive hydration; `=true` unquoted; single
`#`.

## 6. TanStack `navigate` corrupting query values (Logs Explorer SQL
newline loss)

TanStack router-core treats a query string embedded in `navigate({ to
})` as part of the *path*: `decodePath` percent-decodes it and
`sanitizePathSegment` strips control characters, silently deleting every
`%0A`. Logs Explorer's SQL (`s` param) lost its newlines on Run/reload —
`order by timestamp desc` / `limit 5` glued into `desclimit 5`, which
then failed the LIMIT lint. Pre-existing on the TanStack build (the
stock nuqs adapter had the same shape); Next unaffected.

Fixed by never embedding query strings in `to`: the nuqs adapter and the
compat `router.push`/`replace`/`prefetch` (plus the `next/navigation`
shim) now pass search as an object through the app codec
(`splitInternalUrl` hoisted to `lib/internal-url.ts`). Guard test drives
a real `createRouter` with multi-line SQL through both producers.
Browser-verified: newlines survive the full Run → reload → re-Run cycle.

## 7. Integration overview markdown never loaded (all integrations)

`MarkdownContent` used a template-literal dynamic import
(``import(`@/static-data/integrations/${id}/overview.md`)``) — webpack
builds a context module for that, Vite can't analyze it, so every
integration detail page threw `Failed to resolve module specifier` and
rendered no overview text. Fixed with an explicit lazy registry of
literal imports (`static-data/integrations/overviews.ts`, drift-guarded
by a test) plus an `mdRawLoader()` Vite plugin mirroring next.config's
turbopack raw-loader rule. Both runtimes keep working; md stays out of
the main bundle.

## 8. GraphiQL editor never mounted (`exports is not defined`)

Our `umdAmdShortCircuit()` Vite plugin (which disarms Monaco's global
AMD loader for deps like papaparse) rewrote `typeof define ===
'function' && define.amd` to `false` inside `monaco-editor`'s bundled
copy of marked — whose UMD relies on its own *local* `define` shim — so
the whole optimized monaco chunk failed to evaluate and GraphiQL's
editor pane stayed blank. The check now only short-circuits when
`define` is the global AMD loader. Browser-verified: all four GraphiQL
Monaco panes mount, queries execute. (Known follow-up: GraphiQL's Monaco
workers fall back to the main thread under Vite — functional, worker
wiring is Next-specific `setup-workers/webpack`.)

## 9. `@sentry/nextjs` bundling Next internals — built TanStack bundle
crashed (caught by E2E)

The E2E suite against the **built** TanStack bundle (not the dev server)
found lazy chunks like `table-editor-*.js` dead on arrival:
`@sentry/nextjs` (imported by ~25 client files) drags in
`next/dist/shared/lib/constants`, whose module scope evaluates
`process?.features?.typescript` — optional chaining doesn't guard an
undeclared `process` in the browser, so the whole chunk failed at load
with `ReferenceError: process is not defined`. Dev shims `process`,
which is why weeks of dev-server testing never saw it.

Fixed by aliasing `@sentry/nextjs` → `compat/sentry-nextjs.ts`
(re-exports `@sentry/react`, same deduped 10.59.0, plus explicit
stand-ins for the three Next-only APIs) in the Vite build only.
Verified: fresh build has zero Next-internals markers in any chunk;
table editor loads clean; full E2E suite run against the built bundle.

Note for the stack: `alaister/tanstack-start` / the E2E-matrix branch
already carried a different fix for the same crash (a `next/constants`
shim) that never made it to master — the cherry-pick onto those branches
keeps **both** (the shim covers any other transitive importer; the alias
keeps Next internals out of the client bundle entirely).

**Follow-up found while fixing:** Sentry is never *initialized* in the
TanStack runtime — `instrumentation-client.ts` /
`sentry.server.config.ts` are Next-convention files nothing imports
under TanStack, so `captureException` calls are silent no-ops. Needs an
`@sentry/react` init (+ `tanstackRouterBrowserTracingIntegration`) wired
into the TanStack client entry as its own PR.

## 10. GraphiQL Monaco workers + edge-function Deno typings (Vite-only
gaps)

- **GraphiQL's Monaco workers ran on the main thread** under Vite
("Could not create web worker(s)…" — `setup-workers/webpack`'s `new
URL(...)` form isn't rewritten by Vite). A `graphiqlViteWorkers()`
plugin resolves the import to graphiql's own `setup-workers/vite`
variant for client builds (SSR untouched, Next untouched); the
setup-workers chain is `optimizeDeps.exclude`d because the Rolldown
optimizer can't load `?worker` ids.
- **Edge-function editors silently lost their Deno typings** —
`AIEditor` loaded `public/deno/*.d.ts` via `/* @vite-ignore */` imports
that always failed at runtime under Vite. The `.md` raw loader is
generalized into `rawTextLoader` (exact-path allowlist for the two
typings files, served as virtual string modules so the dep scanner never
parses `.d.ts` syntax), and the imports are now static-analyzable
literals that both bundlers handle (turbopack's raw-loader rules match
them on the Next side).

## Split out for reviewability

App-level fixes that reproduce on the Next build too (DOM-nesting
hydration errors, the ghost deleted-snippet nav, the recurring pg-meta
`migrations` 400) moved to their own PR: #47667. Sentry initialization
for the TanStack runtime (captures were silent no-ops) is #47666,
stacked on this PR.

## Full-site test campaign

Drove every dashboard product area on the local TanStack build
(Playwright, human-style) hunting migration regressions:
redirects/404/catch-alls, org, account, project home/branches/merge,
table editor CRUD, SQL editor (Monaco/run/save/templates/AI), all
database pages, all auth pages, storage CRUD, edge functions + realtime,
logs/observability, advisors, settings, integrations hub incl. nested
routes, global UI (palette/connect/switchers/theme/fonts), and a
cross-cutting sweep (document titles, back/forward chain, hard-refresh
hydration on deep URLs, trailing-slash active state). Every failure
found is fixed above and re-verified in-browser; remaining console
quirks were cross-checked against the deployed Next build and are
pre-existing (tracked separately).

## To test

Most fixes are already browser-verified + covered by unit tests and the
self-hosted E2E suite; the last two landed after the final browser pass
and still need an in-browser check:

1. **GraphiQL Monaco workers** — restart the dev server (clear
`apps/studio/node_modules/.vite` once first — the optimizer cache may
hold a stale prebundle of the worker chain). Open
`/project/<ref>/integrations/graphiql/graphiql` with the console open:
the `Could not create web worker(s). Falling back to loading web worker
code in main thread` warning must be gone, and DevTools → Sources →
Threads shows the three workers (json, editor, graphql). Autocomplete in
the query editor stays responsive.
2. **Edge-function Deno typings** — `/project/<ref>/functions/new`: no
"Failed to load … typings" console error, and typing `Deno.` in the
editor offers typed completions (e.g. `Deno.env`).

Spot-checks for the rest (all previously verified):
- `/project/<ref>/merge` renders (no "Module path" crash).
- Multi-line SQL in Logs Explorer survives Run → reload (no `desclimit`
gluing, no LIMIT-lint false failure); `s` param keeps `%0A`.
- `/auth/providers` → open a provider → `?provider=…` with no trailing
slash before `?`; table-editor filter/sort URLs carry no leaked
`ref`/`id` params; `/?next=new-project&projectName=x` lands on
`/new/new-project?projectName=x`.
- Integration detail pages (cron/queues/vault/data_api) show their
overview prose; GraphiQL query editor mounts.
- Built bundle (`MODE=test vite build` + `start:tanstack`): table editor
loads with no `process is not defined`.
- `curl -sI` any page on a platform deploy: `X-Content-Type-Options:
nosniff` (was the invalid `no-sniff`).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Centralized integration overview markdown loading with registry-based
lookup.
* Improved Monaco loading/asset path handling for smoother editor
startup.
* **Bug Fixes**
* Next-style navigation/search handling now preserves pathname, hash,
repeated query keys, and special characters (including newlines).
* Redirects now reliably carry over query and hash with correct
precedence.
* **Security/Configuration**
* Updated CSP font sourcing and unified security headers delivery across
environments; conditional HSTS behavior.
* Refreshed font CSS variables and font-face definitions to match the
theme.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->


---

### Review feedback: non-prod favicon (Joshen)

The TanStack `__root.tsx` hardcoded the prod favicon; local + hosted
staging now use the white staging favicon (`/favicon/staging`), matching
what `pages/_app.tsx` passes to `MetaFaviconsPagesRouter` for non-prod.
Rather than pull the pages-router component into the TanStack head, it
reuses the same synchronous `NEXT_PUBLIC_ENVIRONMENT` signal the file
already uses for `IS_DEV_TOOLBAR_ENABLED` (the `head()` route option
isn't a React component, so it can't run `_app`'s async CLI check — but
the env signal covers the reported local/staging case).

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-07-08 14:52:59 +08:00
Danny White fa20667ec1 fix(studio): migrate email template reset dialog to async AlertDialog (#47705)
## What kind of change does this PR introduce?

Bug fix / refactor. Resolves DEPR-573.

## What is the current behavior?

`ResetTemplateDialog` (added in #45572) confirms the Auth email template
reset using the old `AlertDialog` workaround: an `AlertDialogAction`
with `asChild` + `event.preventDefault()` and a manual loading `Button`,
driven by `mutate` plus inline callbacks. Reset failures are only
reported via a toast from the mutation's default `onError`, so the error
disappears from the dialog context.

This predates #45960, which added first-class async handling to
`AlertDialogAction` (promise-returning handlers, controlled `loading`,
and `AlertDialogBody` for inline feedback). #45960 explicitly flagged
`ResetTemplateDialog` as needing this follow-up migration.

## What is the new behavior?

`ResetTemplateDialog` now uses the async `AlertDialogAction` pattern:

- The confirm handler uses `mutateAsync` and returns the reset promise,
so the dialog stays open with a loading state while the mutation is
pending and closes only after it succeeds.
- Reset failures surface inline via a destructive `Admonition` inside
`AlertDialogBody`, and the mutation's toast-only error path is
suppressed (`onError: () => {}`). The inline error clears when the
dialog closes.
- `Cancel` is disabled while the reset is in flight.
- The `asChild` + `preventDefault()` workaround and the manual loading
`Button` are removed; `loading={isResetting}` is retained for
parent-controlled loading.

This matches the established usage in `DisablePipelinesDialog` /
`JitDbAccessDeleteDialog` and the design-system
`alert-dialog-async-error` example.

## To test

- [ ] Customise an Auth email template, click **Reset template**,
confirm the dialog shows loading until the reset succeeds and then
closes with the editor refreshed to the default subject/body.
- [ ] In DevTools → Network, block `*/templates/*/reset`, click
**Reset**, and confirm the dialog stays open with an inline destructive
admonition and no toast.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved email template reset error handling by showing reset failures
inline in the confirmation dialog (with a destructive alert message).
* The dialog remains open on reset failure so users can review the error
and retry.
* “Cancel” is disabled while resetting; success behavior and existing
success toast behavior remain unchanged.
* **Tests**
* Updated reset mutation mock to use async behavior and added coverage
for reset failure UI/error handling (including that error toasts are not
triggered).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 14:43:31 +08:00
Joshen Lim 511a7806de Joshen/fe 3789 unified logs filters click area is too small (#47675)
## Context

Increases the click area of unified logs filter

### Before
<img width="1070" height="828" alt="image"
src="https://github.com/user-attachments/assets/7e2a45de-7844-4feb-accb-fdaecfa1066c"
/>

### After
<img width="623" height="130" alt="image"
src="https://github.com/user-attachments/assets/c8310975-1f2f-42dc-aaff-fdcd112b1bee"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
  * Improved spacing and alignment in filter checkbox rows.
* Adjusted the expand/collapse control and “only” button positioning for
a cleaner layout.
* Refined nested option connector placement and sizing for better visual
consistency.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 14:16:31 +08:00
Saxon Fletcher b10ed73d66 Studio light background (#47722)
Overrides bg on Studio just to give a bit more elevation

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated the light theme’s surface styling by introducing a new theme
value (`--surface`) to improve visual consistency across the app.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-08 15:57:07 +10:00