Commit Graph
20627 Commits
Author SHA1 Message Date
Miranda Limonczenko e8547352c5 docs(auth): answer the four most repeated SSR auth questions (#50289)
Closes DOCS-1313
Closes FDBKIN-4573
Closes FDBKIN-15214
Closes FDBKIN-10628

## Problem

Four asks come up repeatedly in feedback intake. The Eval is green and
this feedback cannot be included in the Eval. Using the Evals work as an
excuse to action on the feedback. 😄

Readers can't tell which auth call verifies a token and which only reads
stored state. They don't know that the response the cookies were written
to is the response they have to return, because that only ever existed
as a code comment. Nobody is warned that refreshing in two places burns
a single-use refresh token, which surfaces as users being signed out at
random. And nothing in `apps/docs` says `proxy.ts` is Next.js 16 and
later, so a reader on 15 writes a file the framework never calls.

## Solution

- Add the fact that `getClaims()` refreshes a session close to expiring
before it verifies. It was only in the typedoc remarks, and it is what
makes the double refresh warning make sense.
- Say that `setAll` rebuilds `supabaseResponse` on every write, so a
response built earlier is stale, and show how to copy the cookies onto a
different one.
- Warn that a second refresh outside the reuse window revokes the
session, linking refresh token reuse detection.
- Note that `proxy.ts` is Next.js 16 and later, and that the file is
`middleware.ts` before that.
- Name the file in the proxy fence in
`examples/prompts/nextjs-supabase-auth.md`, which gave agents the export
name and no path.

The auth methods partial is shared by five other pages, so that first
change surfaces there too.

## Manual testing

1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-feedback-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview. The Next.js panel carries the version note, the
refresh warning, and the response guidance.
2. Select the refresh token reuse detection link. It resolves to the
sessions guide.
3. Open the [Next.js Auth
prompt](https://docs-git-docs-ssr-client-feedback-supabase.vercel.app/docs/guides/ai-tools/ai-prompts/nextjs-supabase-auth).
The proxy section names the file and says it is `proxy.ts` on Next.js 16
and later.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation

- Clarified that `getClaims` refreshes sessions when access tokens are
near expiration, helping server-rendered sessions remain active.
- Expanded Next.js SSR guidance for session-refresh setup, including
file placement and version-specific naming.
- Added warnings about refresh-token reuse and session revocation after
repeated refreshes outside the reuse window.
- Added guidance for preserving authentication cookies and cache-related
headers when returning updated responses.
- Clarified that refreshed tokens should be passed to Server Components
to keep sessions active.
- Clarified the required session-refresh handler export and example
filename.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 12:48:23 -07:00
Miranda Limonczenko a4106b01f5 docs(auth): correct what getClaims verifies, and fix the Express env setup (#50288)
## Problem

These findings came from a technical audit and verification of the
claims in the doc.

I found two accuracy problems:

- **The guide said `getClaims()` is safe to trust** because it
"validates the JWT signature against the project's published public keys
every time". That only describes projects on asymmetric signing keys.
With a symmetric secret it calls the Auth server instead, which the
page's own partial already said. The advanced guide then read as a flat
contradiction: `getUser()` was "the only way" to know a session is
valid. The real distinction is revocation, not verification.

- **Running the Express sample verbatim doesn't work.** In the docs
sandbox, it printed `SUPABASE_URL = undefined`, so `createServerClient`
received undefined for both the URL and the key. The env var tab
installed dotenv twice, once inline and once through the package manager
tabs, and its "And initialize it" lead-in was followed by the second
install rather than any initialization. The route sample then required
dotenv without calling `config()`.

## Solution

- Say what `getClaims()` verifies against in each signing key mode.
- Reframe the advanced guide's `getUser()` answer around session
revocation, so the two pages stop contradicting each other.
- Switch the advanced guide's two middleware snippets from `getUser()`
to `getClaims()`, matching the guide.
- Rename its `Next.js middleware` heading and CloudFront bullet, which
the proxy rename missed.
- Load dotenv on the first line of the Express entry point, and drop the
duplicate install.
- Tag both Express fences `js`. They are CommonJS, not TypeScript.
- Update the stale "middleware refreshing user sessions" comment in the
rendered Next.js `server.ts` sample.

## Manual testing

1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-accuracy-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview, then the Express tab. dotenv is installed once,
followed by `require('dotenv').config()`.
2. Open the [advanced
guide](https://docs-git-docs-ssr-client-accuracy-supabase.vercel.app/docs/guides/auth/server-side/advanced-guide).
The Next.js heading reads `Next.js proxy` and both snippets call
`getClaims()`.

Part of DOCS-1313.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Clarified the difference between token validation and detecting
revoked server-side sessions.
  - Updated Next.js guidance and examples to use “proxy” terminology.
  - Refined CloudFront caching guidance for authenticated routes.
- Improved Express setup instructions, including dotenv loading and
JavaScript examples.
  - Expanded explanations of signing-key verification.
  - Updated Astro and Nuxt examples to forward cache headers correctly.
- Updated session-refresh guidance in the Next.js example to reference
the proxy.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 12:31:11 -07:00
Miranda Limonczenko 7bec687917 docs(auth): regroup the SSR client guide and cut repetition (#50287)
## Problem

`_partials/auth_methods.mdx` was included six times in this one page.
Radix unmounts inactive tab panels, so a browser reader sees it three
times on the default Next.js view, and the generated markdown that
agents read contained all six. That was about 25% of the 33.5 KB export,
and it put the same `Summary of the methods` heading in the table of
contents three times over.

The page is also 900+ lines with no intro outline, the per-framework
recaps were `h2` inside an `h2` section, and six of the nine panels had
no step headings at all.

## Solution

- Include the auth methods partial once, under a new `Choosing an auth
method` section grouped with `Caching considerations`, and point to it
from the procedure. This follows the mixed information types rule in
`apps/docs/CONTRIBUTING.md`.
- Add an intro outline linking the section groups and saying when to
read the two reference sections.
- Demote the eight in-tab `Congratulations` headings to `h3` so they
nest under `Create a client`.
- Add a `Create the Supabase clients` heading to Astro, Remix, Nuxt,
React Router, Express, and Hono, and the recap Hono was missing.

No claims changed here, only placement.

## Manual testing

1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-structure-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview. The table of contents lists `Summary of the
methods` once.
2. Select each of the five links in the intro paragraph. Each one
scrolls to its section.
3. Select each framework tab. Every panel has a step heading and a
recap.

Part of DOCS-1313.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added an introductory setup overview covering installation,
environment variables, client creation, authentication methods, and
caching.
  - Added dedicated guidance for choosing an authentication method.
- Added Astro SSR and client sections, along with a complete Hono recap.
  - Reorganized framework headings for clearer navigation.
- Consolidated authentication guidance by removing duplicate content
from individual framework sections.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 12:12:06 -07:00
Miranda Limonczenko 91b7df64c2 fix(ui): report clipboard write failures instead of rejecting (#50292)
Closes DOCS-1390

## Problem

Sentry [DOCS-AA](https://supabase.sentry.io/issues/7727380816/) reports
`NotAllowedError: Failed to execute 'write' on 'Clipboard': Write
permission denied.` as an unhandled promise rejection.

The error names `write`, not `writeText`, which places it in the
`ClipboardItem` branch of `copyToClipboard`. That branch has two
problems:

- The write runs inside a `setTimeout`, so the surrounding `try/catch`
has already returned by the time it executes. A denied write routes to
the promise's `reject`.
- No caller attaches a `catch`. All call sites either fire-and-forget or
`await` inside an async handler with no `try/catch`, so the rejection
surfaces as an unhandled rejection.

The user-visible effect is worse than the Sentry noise. On that branch
the copy fails with no feedback at all, because the `toast.error` in the
outer `catch` is unreachable from inside the `setTimeout`. The
`writeText` branch does show the toast, so the two paths disagree.

The issue is filed against auth docs, where it surfaced, but the fix
belongs in `packages/ui`. The same branch runs in Studio and www.

## Solution

- Handle the failure inside the `setTimeout`, where it happens: report
it and resolve.
- `copyToClipboard` no longer rejects on either path, matching what the
`writeText` branch already did. No caller relied on rejection.
- Add regression tests for a denied write on both branches.

## Manual testing

1. Run the unit tests. Four `copyToClipboard` cases pass, including the
two new denial cases.

   ```
pnpm --filter studio exec vitest run lib/helpers.test.ts -t
copyToClipboard
   ```

2. Confirm the new test is a real guard. Revert `clipboard.ts` and
rerun. The write case fails with `promise rejected ... instead of
resolving`.
3. Confirm the ratchet is unchanged.

   ```
   pnpm --filter studio run lint:ratchet
   ```

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Clipboard write failures now display an error notification instead of
causing an unhandled rejection.
* Copy operations resolve consistently when clipboard access is denied
or unavailable, including Safari clipboard support.
* Failed copy attempts no longer trigger completion callbacks,
preventing misleading success behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 19:01:21 +00:00
Miranda Limonczenko cf5bf65361 docs(auth): tighten the voice in the SSR client guide (#50286)
## Problem

The SSR client guide, like all guides, have drifted from our style rules
and writing best practices.

This PR is to do an inline edit without re-arranging any sections.

## Solution

- Open with what the guide does, then the SSR context.
- Delete the `{/* TODO: Can this be consolidated? */}` comment.
- Remove the three em dashes and the parenthetical asides in prose.
- Rewrite the Next.js danger callout to lead with the consequence:
anyone can forge the session cookie.
- Give Astro, Remix, Nuxt, React Router, and Express the same bulleted
recap Next.js, SvelteKit, and TanStack already had.

## Manual testing

1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-style-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview. The first sentence says what the guide does.
2. Select each framework tab. Every panel ends with a bulleted recap.

Part of DOCS-1313.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Updated server-side authentication guidance across supported
frameworks.
- Clarified cookie-based session storage, SSR package usage, and
cache-header handling.
- Added guidance on protecting against forged cookies and verifying
sessions with `getClaims()`.
- Expanded framework setup and authentication flow summaries for Astro,
Remix, Nuxt, React Router, Express, and TanStack Start.
- Clarified TanStack route protection, redirects, and server-side
authorization requirements.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 11:41:47 -07:00
Miranda Limonczenko 3e6b40b238 chore(docs): revise CONTRIBUTING for common pitfalls with Information types (#50357)
## Problem

Our CONTRIBUTING and WORD_LIST is doing a pretty good job at improving
contributor documentation, but I consistently see some issues:
- **Uses "This guide":** "This guide..." is no longer recommended based
on discussions with Nik. Instead, recommendation is to omit those words
while still including a value statement. I still do not recommend
including a definition of the title term as an opening sentence.
- **Mixed information types:** I still often see mixed information types
or wordy, chunky paragraphs. Without a definition in place, my agent
mistakenly thought there was just "Procedure, Context, and Reference."

## Solution

- **A new Information types section** that clearly outlines definitions
and usage with cross-references so that this guidance is not easily
missed.
- **Removed "This guide"** recommendation in favor of a value statement.

Additionally added a clear rule about how to spell numbers consistently
and gave more guidance about how to structure a large topic.

## Manual testing

1. Open
[apps/docs/CONTRIBUTING.md](https://github.com/supabase/supabase/blob/docs/value-statements-and-counts/apps/docs/CONTRIBUTING.md)
on this branch. The Information types section renders its table, the
Recommendations list, and both fenced examples.
2. Click the two `Information types` links, one in General principles
and one under Guides. Both jump to the section.
3. Open
[apps/docs/WORD_LIST.md](https://github.com/supabase/supabase/blob/docs/value-statements-and-counts/apps/docs/WORD_LIST.md).
The `numbers` entry sits under N, ahead of `numbers in product
versions`.
4. Run `npx prettier --check apps/docs/CONTRIBUTING.md
apps/docs/WORD_LIST.md` from the repo root. It reports no formatting
changes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Expanded the contribution guide with Information Mapping guidance for
procedures, processes, principles, concepts, structures, and facts.
- Clarified paragraph and section grouping, page-level classification,
recommended ordering, navigation, transitions, outcomes, and connective
prose.
- Added guidance to use value-focused introductions and bold
“Recommended” and “Not recommended” labels.
- Added number-formatting guidance, including numeral usage, ranges,
fractions, and when to omit step or item counts.
  - Updated related entries in the documentation word list.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 11:40:19 -07:00
Inder Singh 8dc9206f56 docs(self-hosted): add custom oauth providers guide (#49971) 2026-09-16 13:53:39 -03:00
Jeremias Menichelli 9bf43188f1 feat: Create first scaffolding around search v2 and feature flag addition (#50236) 2026-09-16 13:41:16 -03:00
Maksym Ionutsaandgithub-actions[bot] 795b67b611 Docs/clone project r2np clarifications (#50471)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

r2np docs clarifications to
https://supabase.com/docs/guides/platform/clone-project

## What is the new behavior?

<img width="910" height="692" alt="image"
src="https://github.com/user-attachments/assets/41026106-48c6-48bf-aca3-d2ff982c938d"
/>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated project restore guidance to clarify that binary restores copy
the entire database and may immediately run extensions, scheduled jobs,
webhooks, and wrappers.
* Added guidance for using logical restores when definitions need
inspection or removal beforehand.
* Documented that manual dead-tuple recovery is unsupported due to
potential constraint violations and data corruption.
* Added recommended recovery paths for deleted rows using physical
backups or point-in-time recovery.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-16 15:52:33 +02:00
supabase-supabase-autofixer[bot]andivasilov 127e21b926 Changes by create-pull-request action (#44860)
Automated changes by
[create-pull-request](https://github.com/peter-evans/create-pull-request)
GitHub action

Co-authored-by: ivasilov <568291+ivasilov@users.noreply.github.com>
2026-09-16 13:03:20 +00:00
Katerina Skroumpelou dca96ae929 docs: add the Deno optional peer note to the server installing page (#50412)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs, one new section on the `@supabase/server` Installing page.

## What is the current behavior?

The Deno install instructions stop at `deno add jsr:@supabase/server`. A
user who then imports `@supabase/server/middleware/postgres` on Deno or
Edge Functions passes `deno check` and fails at startup with `Could not
find package 'pg'`, because Deno resolves an optional peer only when the
user's own code imports it. Nothing on the page says so.

## What is the new behavior?

A new "Optional peer dependencies on Deno" row under the JSR section
explains why, shows the bare `import 'pg'` at the top of the entry
module, gives the `deno info` check, and notes the
`--minimum-dependency-age 0` flag for same-day releases. Both
hand-maintained copies of the partial are updated and stay identical:
the spec partial for the reference site and the `docs/ref` copy for the
markdown build.

## Additional context

`pg` is the only optional peer a user can hit today. The MCP entry will
add another once it ships and gets documented then.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added Deno installation guidance for Postgres middleware that requires
the optional `pg` dependency.
* Clarified that importing `pg` directly is necessary for Deno to
resolve it at runtime.
* Added commands for verifying package resolution and handling Deno’s
minimum dependency age checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 15:50:38 +03:00
Francesco SansalvadoreandClaude 2db6fbf410 test(studio): add e2e coverage for the storage move picker (#50460)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Tests, plus one small test hook in Studio.

## What is the current behavior?

The Storage file explorer's move dialog was recently reworked: the
free-text "Path to new directory" input was replaced with an embedded
folder picker (folder browsing, bucket-wide folder search, a responsive
breadcrumb, and a confirm button that targets the folder currently
open). That work shipped with unit and component tests, but nothing
exercises it end to end against a real bucket.

## What is the new behavior?

New `e2e/studio/features/storage-move.spec.ts` with seven tests:

| Test | What it covers |
| --- | --- |
| moves a file into a folder picked from the explorer | The core path:
open the picker, click a folder, confirm, and assert the file left the
root and landed in the destination |
| offers folders only, never files, as destinations | Files are excluded
from the listing entirely |
| blocks confirming a move into the folder the file already sits in |
The confirm button reports `aria-disabled` when the destination matches
the source |
| finds a nested folder by search and moves into it | Bucket-wide folder
search, including the "`<folder>` in `<location>`" row label |
| reports when a search matches no folders | The empty-search message
instead of a blank list |
| collapses the middle of a deep path into a breadcrumb dropdown | The
responsive breadcrumb: bucket and the two deepest folders stay inline,
the middle collapses, and picking a collapsed folder navigates to it |
| walks back up the path with the up-one-level button | Disabled at the
bucket root, and drops the deepest folder otherwise |

Supporting changes:

- `utils/storage/queries.ts` gains `uploadObject` and `seedBucket`.
Storage has no standalone folders — a folder exists because an object
sits under that prefix — so seeding a folder tree means uploading
objects at the paths a test needs. Doing this through the API keeps
setup off the UI, which is both faster and less flaky than clicking
through "Create folder" for each level.
- `utils/storage/client.ts` accepts a string body so object uploads can
send raw content alongside the existing JSON requests.
- `utils/storage-helpers.ts` gains `openMoveDialog` and `confirmMove`.
- `MoveItemsFolderPicker.tsx` gains `data-testid="folder-picker-list"`
on its list container.

## Additional context

**Why the `data-testid`.** Once a path is deep enough for the breadcrumb
to collapse, the breadcrumb renders crumb buttons whose accessible names
are folder names — so `getByRole('button', { name: 'beta' })` scoped to
the dialog can match either a folder row or a breadcrumb crumb depending
on depth. Scoping row lookups to the list container removes that
ambiguity. This follows the e2e guidance about adding explicit test
hooks where a component lacks an unambiguous accessible name.

**These tests have not been executed.** They were written against the
merged implementation and verified as far as the environment allows:

- `npx playwright test --list` collects all seven
- `tsc --noEmit` is clean for the new spec and helpers (the pre-existing
errors in `column-editor-types.spec.ts`, `table-editor.spec.ts`, and
`wait-for-response-with-timeout.ts` are untouched)
- Studio's unit and component tests (82) still pass, and typecheck,
eslint, prettier, the lint ratchet, and knip are all clean

The suite needs Docker to bring up the local Supabase stack, which
wasn't available where this was authored, so a real run in CI is the
first actual execution. Selectors were all read off the merged source
rather than guessed, but timing assumptions in particular deserve
attention on the first CI run.

**One thing this surfaced, not fixed here.** The success toast reads
`Successfully moved 1 files to docs` — it doesn't singularize. The tests
assert on `/Successfully moved/` rather than the full string so they
don't encode that, but it's worth a follow-up.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns

---
_Generated by [Claude
Code](https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns)_

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Tests**
- Expanded end-to-end coverage for moving files between folders in
Storage.
- Validated folder selection, nested-folder search, empty search
results, collapsed breadcrumbs, and navigation to parent folders.
- Confirmed files are excluded from destination choices and moving to
the current folder is prevented.
- Added coverage for creating isolated test buckets, uploading fixture
files, and confirming successful move operations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-16 14:39:22 +02:00
claude[bot]andClaude 0e7cfac721 fix(shared-data): restore sign-in testimonial with correct avatar (#50466)
<!-- ccr-slack-attribution -->
_Requested by **Alaister Young** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1789557911237269?thread_ts=1789557911.237269&cid=C0161K73J1J)_

## Before

The Studio sign-in page
(`apps/studio/components/layouts/SignInLayout/SignInLayout.tsx`) shows a
rotating testimonial next to the auth form, picking one tweet object
from `packages/shared-data/tweets.ts` and rendering its `text`,
`handle`, and `img_url` together. Two entries in the data file pointed
at the *same* avatar image file (`JwLEqyeo_400x400.jpg`): one attributed
to `orlandopedro_` and one to `pontusab`, despite being different people
with different quotes. That file was confirmed (byte-for-byte) to
actually be `pontusab`'s real photo, so `orlandopedro_` had no correct
avatar checked in.

## First attempt

The initial fix (this PR's first commit) removed the `orlandopedro_`
entry entirely, since no verified avatar was available for that handle
at the time, following this repo's precedent (PR #38500) for resolving
this class of bug by deleting the erroneous entry.

## Correction

Jordi confirmed the correct profile picture for `orlandopedro_` in the
Slack thread, so instead of leaving the entry deleted, this PR now
**restores** it with the correct avatar:
- Added `apps/www/public/images/twitter-profiles/ZjIOtCGg_400x400.jpg`
(downloaded from the user-provided URL), following the existing filename
convention used by other entries in that directory (the image's own
Twitter CDN slug + `_400x400.jpg`).
- Restored the `orlandopedro_` object in
`packages/shared-data/tweets.ts` (same quote text, handle, and URL as
originally) with `img_url` now pointing at the new, correct image file.

The `pontusab` entry is untouched throughout.

## Test plan

- Verified the restored object diffs as an exact re-add of the
originally removed entry, with only `img_url` changed to the new file.
- Verified the downloaded image is a valid 400x400 JPEG.
- Verified brace/object structure of `tweets.ts` is balanced after the
edit.
- Could not run `pnpm install` in this environment (blocked on
`npm.jsr.io`), so lint/prettier/build were not executed; verified the
diff manually instead.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01A1PbXuRBeaC7G3Mgb7X3eY

---
_Generated by [Claude
Code](https://claude.ai/code/session_01A1PbXuRBeaC7G3Mgb7X3eY)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-16 22:18:20 +10:00
Matt Rossman a133ef60a6 fix(studio): correct the Assistant's blocked-tool privacy message (#50411)
When the Assistant calls a tool that's blocked on permissions, the
response had two problems.

First, it told users their data goes to Amazon Bedrock when production
inference [routes to
OpenAI](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/pages/api/ai/sql/generate-v4.ts#L170-L172).
It now says "third-party AI providers" like the [opt-in
settings](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/components/interfaces/Organization/GeneralSettings/AIOptInLevelSelector.tsx#L84-L88)
do. I verified that was the last user-facing Bedrock mention.

Second, HIPAA-restricted projects got that same copy telling them to
change data opt-in settings, but for those projects `getAIDetails`
[forces their level to
`disabled`](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/lib/ai/ai-details.ts#L70-L73).
They get separate copy now to prevent confusion.

Closes AI-1154


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added HIPAA-aware AI controls for eligible projects.
  - AI opt-in is automatically disabled when HIPAA requirements apply.
- Privacy messages now distinguish standard AI opt-in restrictions from
HIPAA-related restrictions.
- AI-assisted SQL and tool experiences consistently apply HIPAA
restrictions when determining available capabilities.
- **Bug Fixes**
- Improved handling of AI settings for HIPAA-sensitive projects and
invalid project or organization configurations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 08:16:49 -04:00
Julian Domke 9cdd412bab feat(stripe-atlas): mock-up dashboard to enable live testing (#50327) 2026-09-16 14:16:46 +02:00
Saxon FletcherandJoshen Lim 4432a8beb4 chore(studio): update Explorer feature preview copy (#50250)
Updates the Explorer feature preview copy to explain the SQL Editor
transition, Notebooks, and Snippet migration plans. Adds feedback
questions and moves the preview image above the content.

Validation: Prettier and `git diff --check` passed.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Updated the Explorer preview layout by moving the preview image below
the introductory text.
- Replaced feedback questions with a clear overview of what enabling the
preview provides, including SQL Editor replacement and Notebooks
management through the dashboard and Assistant.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-16 11:18:01 +00:00
Alaister YoungandAlaister Young 240bfce7f6 [FE-4198] feat(studio): select a range of logs with shift-click (#50381)
Shift-clicking a log row checkbox now selects every row between the last
clicked row and the clicked one, so you can grab a consecutive block of
logs to copy without checking each one. Applies everywhere the shared
`LogTable` renders: Postgres/API/Auth/Edge Functions logs and the Logs
Explorer.

**Added:**
- `getShiftClickSelection` in `Logs.utils.ts`: pure helper that computes
the next selection from the ordered row keys, the current selection, the
anchor row, and the clicked row. Adds the inclusive range in either
direction. If the whole range is already selected it deselects the range
instead. Falls back to a plain toggle when there's no usable anchor.
Covered by unit tests, plus `LogTable` component tests for range select,
the no-anchor fallback, anchor clearing, and range deselect.

**Changed:**
- `LogTable` tracks the last toggled row as the range anchor (a ref,
since it's only read in handlers). The anchor is set by plain clicks,
shift-clicks, and the Shift+Space row toggle, and cleared whenever the
selection becomes empty (toggling off the last row, plain row click,
Escape, action bar clear, select-all then deselect-all, or a new query
loading).
- The checkbox cell handles `onClick` instead of `onCheckedChange` so
the shift key is available. Keyboard Space on a focused checkbox still
toggles it, since Radix dispatches a click for it.
- A shift mousedown on the checkbox cell is prevented so the browser
doesn't start a text selection across rows.

Unified Logs has its own row selection (TanStack Table) and is not
changed here.

## To test

- Open any log page with a decent number of rows, e.g. Postgres logs.
Click one checkbox, then shift-click a checkbox several rows below.
Every row in between should be checked and the action bar should show
the count. Repeat upward.
- Shift-click a range that's already fully selected: the range should
clear, and rows outside it stay as they were.
- Plain-click a row's message text (not the checkbox): side panel opens
and the selection clears. A following shift-click should just toggle
that one row.
- Press Escape or the action bar's clear button, then shift-click: also
just a single toggle.
- Focus a row with the arrow keys, press Shift+Space, then shift-click a
lower checkbox: the range should extend from the keyboard-toggled row.
- Tab to a checkbox and press Space: it should still toggle.
- After a shift-click, confirm no text is highlighted across the rows.
- Copy as JSON/Markdown/CSV still copies the selected rows in display
order.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added shift-click range selection to the logs table for selecting or
deselecting consecutive rows.
  - Preserved single-row selection when range selection is unavailable.
- Improved selection behavior when clearing selections or changing log
queries, preventing stale range anchors.

- **Tests**
- Added coverage for forward and reverse range selection, deselection,
partial selections, fallback behavior, and input immutability.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-16 18:18:28 +08:00
99be7f92ce feat(studio): add Privacy Policy update notice (#50397)
## Summary

Adds a compact Privacy Policy update notice for signed-in Studio users
on organization landing pages.

- Shows on `/org`, `/organizations`, and `/org/:slug`
- Opens the approved policy explanation in a dialog
- Links to the Privacy Policy and `privacy@supabase.com`
- Persists acknowledgement in a dated local storage key
- Stays off project and organization settings routes so it cannot cover
product controls

## Why

The Privacy Policy changes the data controller from Supabase, Inc. to
Supabase Pte. Ltd. User rights and protections are unchanged.

This restores the established authenticated Studio notification pattern:

- [#35923](https://github.com/supabase/supabase/pull/35923): May 2025
Privacy Policy notice
- [#43681](https://github.com/supabase/supabase/pull/43681) and
[#43889](https://github.com/supabase/supabase/pull/43889): March 2026
Privacy Policy notice and design pass
- [#45632](https://github.com/supabase/supabase/pull/45632): May 2026
Terms of Service notice
- [#48524](https://github.com/supabase/supabase/pull/48524): current
reusable Studio banner stack

## Release order

The policy content and Studio notice deploy independently. Keep this PR
in draft until [#50392](https://github.com/supabase/supabase/pull/50392)
is approved, merged, and live. The notice appears immediately when this
Studio change deploys.

## To test

1. Open Studio on `/organizations` or an organization project-list page.
2. Confirm the compact Privacy Policy notice appears.
3. Open **Learn more** and confirm the dialog copy and both links.
4. Select **Understood** or close the notice.
5. Reload and confirm the notice remains dismissed.
6. Remove `privacy-policy-update-2026-09-16-dismissed` from local
storage and confirm the notice returns.
7. Open a project route and confirm the notice is absent.

## Verification

- Prettier passes on changed files.
- ESLint passes on changed Studio files.
- Focused Vitest suites pass: 25 tests.
- Studio Unit Tests & Build Check passes.
- TypeScript & Lint, UI Tests, Studio Docker Build, dead-code, ratchet,
and validation workflows pass.
- All four self-hosted Studio E2E shards pass for both router
implementations.
- All deploy previews pass.
- The Studio preview rendered the compact notice on the organization
landing page without console errors. The dialog and dismissal flow still
need an authenticated browser pass after the session redirected to
sign-in.

A direct local Studio TypeScript check reaches one existing unrelated
error in
`packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx`;
no changed file reports an error and the required TypeScript CI workflow
passes.

## Measurement

Success means signed-in users can find the updated policy from the
organization landing experience without interrupting project work. The
dated dismissal key confirms acknowledgement locally. CI protects the
non-blocking route scope, and Privacy can monitor questions sent to
`privacy@supabase.com` after release.

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-09-16 17:51:25 +08:00
claude[bot]andClaude adca15deab chore(www): add Privacy Policy v4 (data controller entity, Freebuff cookie) (#50392)
<!-- ccr-slack-attribution -->
_Requested by **Sofia Calado** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1789462983606899)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content update — a new version (v4) of the Privacy Policy legal page,
added following the existing versioned-legal-page pattern (v1-v3 already
present, selectable via a version dropdown).

## What is the current behavior?

Before: On `/privacy`, the latest selectable version is "Version 3 — May
13, 2026". That text names "Supabase, Inc" as the entity you're dealing
with — both in the opening paragraph ("Thank you for your interest in
Supabase, Inc., ...") and again as the named data controller in the
EEA/UK/Switzerland disclosures section ("Supabase, Inc is the data
controller..."). The Section 8 cookie table (EEA cookies) lists nine
cookies/rows (Stripe x3, Cloudflare x2, Youtube, hCaptcha, Posthog,
Google Analytics 4, Google Ads, `_sb_first_referrer`) and does not
mention Freebuff anywhere.

## What is the new behavior?

After: `/privacy` gains a new "Version 4" entry in the dropdown, at the
top of the list (selected by default). Reading Version 4, the same two
passages instead name "Supabase Pte. Ltd." as the entity/data
controller. The Section 8 cookie table gains one additional row for
"Freebuff" (Type: Advertising; dropped when you visit the Site after
interacting with a Freebuff ad; 30-day duration; purpose: measuring ad
campaign performance and attributing conversions to ad clicks upon
consent; linking to the Freebuff Privacy Policy), formatted identically
to the existing rows. Versions 1-3 are unchanged and remain selectable.

## Additional context

Two changes, scoped exactly as requested:
1. **Data controller entity**: every "Supabase, Inc" / "Supabase Inc."
reference that names the data controller is replaced with "Supabase Pte.
Ltd." — at the top of the policy and in the EEA disclosures section. No
other "Supabase" references (e.g. plain brand mentions) were touched.
2. **Freebuff cookie row**: added to the Section 8 (EEA cookies) table,
matching the existing table's markdown formatting exactly.

**Open question — effective date needs Sofia/Nicole's input before
merge.** No effective date was given for v4. The version-selector
component (`LegalDocVersions`) requires a non-empty `effectiveDate`
string per version to render (used both in the dropdown label and, for a
single-version page, an on-page line) — there's no way to add the
version without wiring some string. Following the pattern's convention
of never inventing a plausible-looking date, `effectiveDate` is set to
the literal placeholder `'TBD'` for v4 in `apps/www/pages/privacy.tsx`.
**This must be replaced with a real effective date before this PR
merges** — flagging for Sofia Calado / Nicole Kramer to confirm.

**Validation**: `pnpm --filter=www build` fails in this sandbox due to
an unrelated prebuild step (`docs` app's `build:federated-content`
script needs live GitHub API credentials to fetch tags — 401 Bad
credentials — not related to this change). `tsc --noEmit` on `apps/www`
ran clean of any error touching `privacy.tsx` or the privacy `.mdx`
files (all reported errors are pre-existing, about unrelated missing
generated assets/images). As a direct substitute, all four
`apps/www/data/legal/privacy/*.mdx` files (v1-v4) were compiled through
the app's actual MDX pipeline (`@mdx-js/mdx` with the same
`remark-code-hike` + `remark-gfm` + `rehype-slug` config as
`next.config.mjs`) and all compiled successfully, confirming the new
table syntax and content are valid MDX/GFM.

Files touched:
- `apps/www/data/legal/privacy/v4.mdx` (new)
- `apps/www/pages/privacy.tsx` (added v4 to the `versions` array)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01BzHiVEUzjvrwxgnxCrrER1

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-16 17:26:21 +08:00
Pamela Chia 5e8e551e2c fix(www): include app routes in sitemap (#50277)
I added static App Router pages to the www sitemap, including the
homepage, pricing, and product pages. The generator previously scanned
only Pages Router and content files; it now strips route groups,
excludes dynamic segments, and emits these URLs without lastmod.

**Note:** The pre-existing Pages Router `/opt-out/[ref]` entry remains
outside this change.

## To test

Tested on the [www
preview](https://zone-www-dot-com-git-pamela-growth-1214-app-rou-1d4879-supabase.vercel.app/sitemap_www.xml):

- [x] Open `/sitemap_www.xml`: expect the homepage, `/pricing`, and
product routes once each, without route-group names or lastmod on those
entries.
- [x] Compare the sitemap's changelog URLs with `/changelog-rss.xml`:
expect every RSS item link to remain included, including text-slug
entries.
- [x] Open `/sitemap.xml`: expect the existing www and docs sitemap
links.

## Linear

- fixes GROWTH-1214


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Sitemap generation now includes static pages built with the Next.js
App Router.
  - Route groups are correctly omitted from generated URLs.
  - Dynamic App Router routes are excluded from the sitemap.

- **Bug Fixes**
- Improved sitemap coverage and URL accuracy for applications using both
App Router and Pages Router pages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 16:54:42 +08:00
Gildas Garcia c52fca1340 MFA Recovery codes: enforce recovery codes generation after setting up an MFA (#50343)
## What kind of change does this PR introduce?

Afters users set up an MFA, automatically generate recovery codes

## How to test

- On an account that doesn't have recovery codes generated yet, add a
new MFA
- When you finished verifying the MFA, it should automatically open the
recovery codes modal introduced in previous PRs

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved the two-factor authentication setup flow by checking the
latest recovery-code enrollment status before generating codes.
- Recovery codes are now generated and displayed after verification when
they are enabled but not yet enrolled.
- Loading indicators now reflect recovery-code status checks, providing
clearer feedback during setup.

- **Improvements**
- Updated the recovery-code confirmation message to explain how codes
can restore access after losing access to an MFA app and remind users to
store them securely.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 10:46:07 +02:00
Joshen Lim ee3fbc4e61 Joshenlim/fe 4383 consolidate tablerow no search result state (#50389)
### Context

Just some housekeeping/consolidate refactors. There's a number of places
where we render the same "no result" empty state for tables. So this PR
just consolidates that into a reusable component `TableRowNoResults` to
reduce duplication.

Opting to save this under `components/ui` instead of the `ui` package as
this is more of a derivation of `TableRow` than a primitive

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **UI Improvements**
- Standardized empty search-result messages across database, functions,
storage, and vector bucket tables.
- Search terms now appear consistently when no matching records are
found.
  - Added an accessible label to the vector bucket row actions menu.
- Improved the storage explorer loading layout so content expands to use
available vertical space.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 16:35:26 +08:00
Ali Waseem 881a7d3151 fix(studio): show only the disabled reason on the invite members button (#50426)
The invite members button sits inside two Radix tooltip roots — the
keyboard-shortcut tooltip and the disabled-reason tooltip — which both
anchor to the same element and stack on top of each other when the user
lacks invite permission.

Widened the existing `tooltipOpen` condition so the shortcut tooltip
stays closed whenever a disabled reason is showing, and hoisted that
reason into one variable so the tooltip text and the suppression
condition can't drift.

Fixes FE-4393

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Disabled member invitations now prevent the invite button and keyboard
shortcut from opening the invite dialog.
* Invite controls display the appropriate disabled-feature or permission
warning.
* Shortcut tooltips are hidden when invitations are unavailable or the
user lacks permission.

* **Tests**
* Added coverage for disabled invitations, permission warnings, dialog
prevention, and shortcut tooltip visibility.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Fixes: https://github.com/supabase/supabase/issues/49859
2026-09-16 16:33:20 +08:00
Gildas Garcia 7ab2a0d84f Fix TextConfirmModal does not reset its state (#50406)
## Problem

`TextConfirmModal` does not reset its state after closing, whether users
confirmed or not. If they would restart the action, the confirmation
text they may have entered is kept, preventing the secure confirmation.

Also fixed an accessibility issue as we didn't enable the submit button
until the form was valid

## Solution

Reset the form state whenever the dialog opens.

## How to test

- On
https://studio-staging-git-gildasgarcia-design-505-rese-196b28-supabase.vercel.app/dashboard/account/security
- Either:
  - Add an MFA if you haven't already
  - Generate recovery codes if you already have an MFA
- Click the _Regenerate recovery codes_

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- Text confirmation dialogs now reset their input whenever opened or
closed, ensuring a fresh form for each use.
- Confirmation actions remain available unless the dialog is processing
a submission.
- Copy-to-clipboard actions now provide an accessible announcement when
text has been copied.

- **Tests**
- Added coverage for successful confirmation, cancellation, invalid
submissions, input reset behavior, and recovery-code regeneration
retries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 10:24:17 +02:00
7fce0a12d9 feat(design-system): first pass at db report chart colours (#46787)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This is a first draft at introducing semantic colours to our
Observability charts. This moves away from just random colours being
assigned to prop after prop. They're only scoped to the Database reports
right now, but if it flows nice, we can open it up to the other reports
too.

This also aims to tone down some of the harsher colours in our charts,
such as the orange which sometimes can look like a warning metric/prop.

| Before | After |
|--------|--------|
| <img width="839" height="336" alt="Screenshot 2026-06-10 at 09 14 56"
src="https://github.com/user-attachments/assets/222747c5-973b-4165-aa53-df7b93412ad3"
/> | <img width="950" height="341" alt="Screenshot 2026-09-14 at 18 14
47"
src="https://github.com/user-attachments/assets/836f3ddd-4a97-4064-b8cf-3a3b435417ac"
/> |

cc @supabase/design for additional thoughts.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added semantic chart color roles with light and dark theme variants
for consistent visualizations.
* Standardized colors and fills across database, networking, storage,
and connection charts.
  * Maximum-value lines now use configured chart colors when available.
  * Added chart palette reference and stress-test examples.
* Added stacked bar charts, customizable margins, and gradient-filled
line charts.
* Improved multi-series bar chart focus and date-range footer alignment.

* **Documentation**
* Documented the chart palette, theme variants, accessibility guidance,
and usage recommendations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-09-16 09:18:40 +01:00
Francesco SansalvadoreandClaude 92fdb1d3c5 feat: update storage move UI (#50346)
Update path selection as destination where to move files in the Storage
File Explorer.

## What is the current behavior?

Currently you need to write out the entire path by hand, which is error
prone and quirky.

<img width="727" height="436" alt="Screenshot 2026-09-14 at 15 49 11"
src="https://github.com/user-attachments/assets/2bb8fc78-d973-4b17-9343-08df23b67d2a"
/>

## What is the new behavior?

This PR adds a ui that lets the user select any folder as the
destination of the file move.

<img width="923" height="606" alt="Screenshot 2026-09-15 at 11 40 00"
src="https://github.com/user-attachments/assets/2f4c50f8-3c11-4896-832e-b1e99defc9af"
/>


https://github.com/user-attachments/assets/261ac24e-ec24-4bcf-ad47-72bc48e27bab

To test:
- go to Storage File explorer and pick a file to "move" (action in the
dropdown menu)
- mov file to any other folder in the same bucket selecting destination
folder from the ui in the dialog
- both empty folder or also a folder with sub-folders can be
destinations, as any selected folder becomes the active destination
(notice the cta changing when selecting a folder)
- batch move multiple items via multi-select (already supported, but
using the updated ui now)
- only folders should appear in this ui
- destination folders can be searched using the search input

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Replaced the move-items path field with an interactive folder browser.
- Browse, select, and search folders by name or path, with pagination
and loading or empty states.
- Navigate using breadcrumbs, including collapsed-path menus for deeply
nested folders.
- Receive warnings when folder search results are incomplete for very
large buckets.
- See clearer destination labels and protection against moving items to
their current location.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-16 09:38:15 +02:00
Saxon FletcherandClaude Opus 5 32341830b3 docs: organize observability by task and move SQL logs to Explorer (#50074)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

Yes.

## What kind of change does this PR introduce?

Documentation update.

## What is the current behavior?

The observability overview and access page overlap; configuration
interrupts querying; related guides send log queries to the old editor.

## What is the new behavior?

The observability overview and navigation follow the same four sections:
Read project data, Detect and diagnose, Hire an agent, and Configure and
export. The overview absorbs the redundant access page, with permanent
redirects for both HTML and Markdown URLs.

“Query logs with SQL” owns ClickHouse querying through MCP, the
Management API, and Explorer with query source Logs. Logging
configuration moves to its own guide; sources, captured headers, and
limits live in the field reference. Inspection links to canonical
diagnostic SQL. Related Storage and database guides use the replacement
Explorer workflow and retain existing anchors where headings move.

## Additional context

Validation: Markdown generation, docs typecheck, targeted ESLint,
formatting, and content-listing tests. Browser overview/navigation
checked; old HTML and Markdown URLs return 308, and the new
configuration page returns 200 in both formats. Three ClickHouse
examples and the Postgres configuration query ran in a disposable
container sandbox. Changed pages have no MDX lint violations;
repository-wide existing failures remain.

Self-review: the Management API request was verified against its
published schema but not sent to a hosted project. Realtime ingestion
and hosted logging configuration still need a hosted smoke check. No
compatibility path for the deprecated logs engine is documented.

Stage 2 of 3; depends on stage 1.


Stack: #50073 → #50074 → #50075.

Production docs build also passes at the stack tip after standard
reference generation.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Reorganized observability guidance around reading data, detecting
issues, diagnosing problems, agent setup, and exporting data.
  - Added a guide for configuring Postgres and Realtime logging.
- Updated log investigation instructions to use Explorer, SQL queries,
and clearer filters.
  - Added log source, field, and captured-header references.
  - Improved advisor guidance and database performance troubleshooting.
  - Added redirects for moved observability content.

- **Accessibility**
- Improved screen-reader labels for copy and feature-selection controls.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-16 17:03:43 +10:00
232ce7e68c docs: focus Logs on the unified view and export queryable fields (#50073)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

Yes.

## What kind of change does this PR introduce?

Documentation update and a small Studio copy correction.

## What is the current behavior?

The Logs guide mixes unified filtering with retired SQL Explorer
instructions, and the Markdown field reference loses query semantics.

## What is the new behavior?

The Logs guide mixed filtering and event inspection with the retired SQL
Logs Explorer workflow. It now documents the unified Logs view: default
sources, filter semantics, event details, Live, sharing, bounded
exports, and missing results.

The log field reference uses one mapping for HTML and Markdown,
preserving source IDs, query expressions, and source/query types. The
Studio User-filter empty state and comments now match its Auth and API
Gateway scope.

## Additional context

Validation: shared-field mapping tests, guides Markdown generation, docs
typecheck, targeted docs/Studio ESLint, formatting, and browser
inspection of the field table. Exported Markdown includes the source IDs
and usable ClickHouse expressions. Repository-wide MDX lint has existing
failures; changed pages have no reported violations.

Self-review: hosted Studio filtering and log ingestion were checked
against the implementation, not exercised against a hosted project. The
documentation assumes the unified Logs experience is the default.

Stage 1 of 3. Review and merge from the bottom of the stack.


Stack: #50073 → #50074 → #50075.

Production docs build also passes at the stack tip after standard
reference generation.

Initial CI note: the spelling action failed while building its container
because Debian package downloads returned 404, before checking content.
The stack has no merge conflicts.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded the log field reference with ClickHouse fields, nested-field
query examples, types, schema references, and capture limits.
* Reworked the Logs guide with clearer instructions for filtering, event
inspection, live mode, sharing, exports, retention, and missing results.
* Clarified service and Postgres log behavior and updated navigation and
metadata.

* **Bug Fixes**
* Corrected user-filtering guidance and empty-state messaging to
identify Auth and API Gateway logs as supported sources.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Steven Eubank <eubank.steven88@gmail.com>
Co-authored-by: Steven Eubank <47563310+smeubank@users.noreply.github.com>
2026-09-16 16:52:03 +10:00
Joshen Lim e296d0ae4f Joshenlim/fe 4373 add ilike comparator for pathname in unified logs (#50386)
## Context

In unified logs, filtering on pathname can benefit using the `ilike`
comparator so this PR adds support for that
<img width="423" height="247" alt="image"
src="https://github.com/user-attachments/assets/31e5f09b-7506-4588-90e3-ee705f805d43"
/>


FilterBar is also updated to omit facet values if the selected
comparator is `ilike`, otherwise it doesn't really make sense to show a
dropdown of values for users to select as the value for `ilike`
filtering.
<img width="240" height="62" alt="image"
src="https://github.com/user-attachments/assets/b5fc97e7-d826-4184-8b70-bfb4875d1822"
/>

The facet values should still show if the selected comparator is an
equals comparator
<img width="391" height="154" alt="image"
src="https://github.com/user-attachments/assets/7ccded04-3db1-4406-af40-4377ffe3bd8d"
/>

Related to https://github.com/supabase/supabase/pull/50394 - am also
updating ilike comparator logic for unified logs to implicitly wrap the
provided string with `%`, but only if the string doesn't already contain
a `%` or `_` for UX convenience. (Unified logs already had this
behaviour, except the latter part RE omitting default `%` if string
already has) - this affects pathname and event_message searching



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **New Features**
* Added case-insensitive pathname filtering for logs with ILIKE and NOT
ILIKE.
* Added pathname support for comparison and pattern-matching operators.
  * Preserved user-provided `%` and `_` wildcard patterns in searches.

* **Bug Fixes**
* Corrected BigQuery pathname filtering for consistent case-insensitive
matching.
* Prevented misleading exact-value suggestions for pattern-based
searches.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 14:34:41 +08:00
Joshen Lim b1a9e072ec Update table editor ilike related comparators to implicitly wrap filter string with % if not provided (#50394)
### Context

For table editor - the `ilike` related comparators expect users to input
a `%` in the filter string, which for non-developers might not be
intuitive.

Hence opting to implicitly wrap the filter string with `%` in the query
when filtering if non provided
<img width="1182" height="755" alt="image"
src="https://github.com/user-attachments/assets/819c39f5-fcbf-4213-95b3-3ad1ee901f47"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved pattern-match filters so bare text values perform contains
matching by automatically wrapping them with wildcards.
* Preserved explicit wildcard patterns using `%` or `_` without adding
additional wildcards.
* Improved handling of empty values for non-text filters while retaining
existing numeric filter validation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 14:32:19 +08:00
Danny White 28cd7ada35 fix(www): add local KB rewrite URL (#50452)
## What kind of change does this PR introduce?

Bug fix for the local www development environment.

## What is the current behaviour?

Running `pnpm dev:www` fails Next.js rewrite validation because
`NEXT_PUBLIC_KB_URL` is missing from the tracked public environment
defaults, producing an `undefined` destination for `/kb`.

## What is the new behaviour?

The tracked public environment defines the local KB URL, matching
`.env.local.example`, so the www rewrite configuration is valid in a
fresh checkout.

## To test

1. Run `pnpm dev:www`.
2. Open http://localhost:3000.
3. Confirm www starts without the `Invalid rewrites found` error for
`/kb`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Configuration**
* Added a public URL setting for accessing the knowledge base service in
local development.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 06:21:26 +00:00
Danny White 7e9c483625 feat(ui): support bounded MultiSelector wrapping (#50439)
## What kind of change does this PR introduce?

UI component enhancement and Design System documentation update.

## What is the current behavior?

`MultiSelectorTrigger` can either limit the number of visible badges or
wrap every selected badge. Consumers cannot combine a numeric limit with
wrapping.

## What is the new behavior?

Adds `wrapBadges` so consumers can combine it with a numeric
`badgeLimit`. For example, `badgeLimit={3} wrapBadges` renders up to
three wrapped badges followed by the remaining `+n` count.

Existing `badgeLimit=\"wrap\"` behaviour remains supported.

## To test

1. Open the Design System Multi Select page.
2. Find the **Wrapped badge limit** example.
3. Confirm three selected fruit badges wrap within the trigger and the
remaining selections appear as `+2`.
4. Remove or add selections and confirm the visible badges and remaining
count update together.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a `wrapBadges` option to multi-select triggers, allowing
selected badges to wrap across multiple lines while retaining a numeric
badge limit.
- Numeric limits now show the specified badges and an overflow count for
additional selections.
  - Updated the example with controls for adjusting the badge limit.

- **Documentation**
  - Clarified multi-select badge limit and wrapping behavior.

- **Tests**
- Added coverage for badge limits, wrapping, visible selections, and
overflow counts.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 12:27:16 +10:00
Danny WhiteandJoshen Lim 229d04d65c feat(studio): give pipeline pages a standard detail header (#50253)
## What kind of change does this PR introduce?

Studio page-layout polish. This follows the merged destination-brand and
pipelines-list work in #50251 and #50252, and now targets `master`
directly.

## What is the current behaviour?

Pipeline child pages use a bespoke heading, provide limited destination
context, and shift substantially while pipeline and destination data
load.

## What is the new behaviour?

Adds standard breadcrumbs and page-header composition, destination
identity, the primary-database-to-destination path, lifecycle actions,
and child-route integration. Layout-matched loading placeholders keep
the header geometry stable until the resolved pipeline data is
available.

Removes the legacy Overview header and actions now owned by the shared
page shell, and restores standard content gutters around the existing
metrics and tables. Pipeline action errors are handled once by the
layout, avoiding duplicate notifications from the underlying mutations.
Pipeline actions are also temporarily disabled while a table reset is
running to prevent conflicting requests.

| Before | After |
| --- | --- |
| <img width="1131" height="801" alt="Replication Database ETL BigTable
ETL Team Supabase"
src="https://github.com/user-attachments/assets/3f0ebab0-7244-4aa1-81ac-8847f5f86d4a"
/> | <img width="1131" height="801" alt="Replication Database Agua
Basket Supabase"
src="https://github.com/user-attachments/assets/bcbbd150-2a3d-468d-9cb9-652a6de2040b"
/> |

## To test

1. Open a pipeline at
`/project/<ref>/database/replication/<pipeline-id>`.
2. Confirm there is one page header with one set of actions, followed by
a consistently padded Overview body.
3. Confirm the breadcrumbs, destination logo and name, status,
source-to-destination path, primary lifecycle action, and overflow
actions.
4. Start, stop, or restart the pipeline and confirm its status and
available actions update appropriately.
5. Reset a replicated table and confirm the pipeline lifecycle, update,
and overflow actions remain disabled until the reset finishes.
6. Throttle the initial pipeline and destination requests and confirm
the header retains its final geometry without showing fallback data.
7. Check the page at desktop and phone widths.

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-16 11:51:49 +10:00
Anthony LioandDanny White 38f448b01c fix(ui): tab component (#50183)
## What kind of change does this PR introduce?
bug fix on tab component + a small refactor

## What is the current behavior?

the active tab in an underline list gets border-b-2 while its siblings
get nothing, so it's 2px taller and its label sits higher than the rest
causing a smol layout shift within docs

## What is the new behavior?

- adds one absolute positioned bar that slides between tabs so nothing
moves
- favors track under an underline as an inset shadow vs a border

| state | preview |
| -------|------|
| before | <video
src="https://github.com/user-attachments/assets/b73820a6-2994-46d1-aa98-452681f0fef2"
/> |
| after | <video
src="https://github.com/user-attachments/assets/054cd67d-a50c-4aef-9340-a1e1d515047b"
/> |


## Test
1. visit [api
reference](https://docs-git-antlio-ui-components-tabs-supabase.vercel.app/docs/reference/javascript/installing?platform=npm&queryGroups=platform)
2. visit a [guide
](https://docs-git-antlio-ui-components-tabs-supabase.vercel.app/docs/guides/database/prisma)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added an animated tab indicator that follows the active tab and adapts
to layout changes.
  - Added support for customizing tab indicator styling.
- Respects reduced-motion preferences by disabling indicator transitions
when appropriate.

- **Style**
  - Streamlined tab borders, spacing, and underlined-tab styling.
- Improved tab panel spacing and standardized tab behavior in
documentation examples.
- Centralized easing behavior for smoother overlays, dropdowns, slides,
and panels.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-16 00:00:27 +03:00
Anthony Lio 6d08a747f1 fix(docs): guide reference perf enhancements (#50239)
## What kind of change does this PR introduce?

follow-up to #50235 to reduce reference page payloads and cold rendering
overhead

## What is the current behavior?

reference pages ship a large rsc payload inside the html _ most of it is
duplication rather than content along with shiki that writes ~30
character css variable name for every syntax token making the page heavy
in some cases

## What is the new behavior?

- moves repeated styles into shared css and uses compact, namespaced
token classes
- renders details icons inside the client trigger
- follows shiki’s guidance to [reuse one
highlighter](https://shiki.style/guide/best-performance#cache-the-highlighter-instance)
and [load languages on
demand](https://shiki.style/guide/best-performance#use-shorthands)

`page size`
page | before | after | change
-- | -- | -- | --
javascript | 10.61 mb | 8.28 mb | -21.9%
dart | 4.59 mb | 4.13 mb | -10.1%
python | 4.38 mb | 3.73 mb | -14.9%
swift | 2.87 mb | 2.56 mb | -10.9%
server | 1.59 mb | 1.35 mb | -15.2%
kotlin | 3.42 mb | 3.17 mb | -7.2%

`cold initialization`
language | before | after | reduction
-- | -- | -- | --
bash | 2,180 ms | 23 ms | 98.95%
javascript | 2,245 ms | 38 ms | 98.29%

## Additional context

measured on a local production build which uses the checked in generated
content _ production has larger sdk data, so absolute sizes there will
be higher

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added reusable expand/collapse controls for API reference details,
with updated icons, labels, and styling.
* Improved code block rendering with class-based syntax highlighting,
wrapped-code support, responsive layouts, and lazy language loading.

* **Style**
* Added theme-aware syntax-token colors, line-number styling, and
configurable code-block shadows.
  * Consolidated expandable reference panel and item styling.

* **Tests**
* Added coverage for syntax highlighting, code block rendering, language
support, token stability, and reference details.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 23:55:49 +03:00
Andrew ValleteauandClaude Fable 5.1 10eaab766f fix(studio): filter on every column when viewing a composite FK record (#50256)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

In the Table Editor, the "View referencing record" arrow on a foreign
key cell builds its filter from the table's `relationships` list. That
list is one entry per source-by-target column combination, and the
formatter takes the first entry whose source column matches the clicked
cell, then filters the referenced table on that single target column.

For a composite foreign key this fails in two ways:

- The value from the clicked column can be applied to the wrong target
column (whichever target column happens to be listed first for that
source column).
- Only one of the key columns is ever filtered on, so the peek and the
"Open table" link return zero rows or too many rows.

This is distinct from #41068 / #41080, which fixed the cartesian
expansion in the shared `tables.ts` introspection query. The bug
reproduces with that fix in place because the mis-pairing happens in
Studio when building the filter. Reported by a customer via support.

### Reproduction

Run this in the SQL editor. The referenced column list `(org_id,
bucket_id)` is deliberately not in the referenced table's physical
column order, which is what exposes the bug.

```sql
create schema if not exists dcs;

-- bucket_id declared first, org_id second
create table dcs.org_metering_buckets (
  bucket_id bigint not null,
  org_id    bigint not null,
  primary key (org_id, bucket_id)
);

create table dcs.machine_storage_usage_buckets (
  org_id                 bigint not null,
  org_metering_bucket_id bigint not null,
  constraint machine_storage_usage_buckets_org_metering_bucket_fkey
    foreign key (org_id, org_metering_bucket_id)
    references dcs.org_metering_buckets (org_id, bucket_id)
);

insert into dcs.org_metering_buckets (bucket_id, org_id) values
  (901, 1), (902, 1), (903, 2);

insert into dcs.machine_storage_usage_buckets (org_id, org_metering_bucket_id) values
  (1, 901), (1, 902), (2, 903);
```

1. Open `dcs.machine_storage_usage_buckets` in the Table Editor (select
the `dcs` schema).
2. Hover the `org_id` cell on the row where `org_id = 2`.
3. Click the "View referencing record" arrow.
4. Click "Open table" in the popover.

**Before this PR:** the popover shows "No results were returned". "Open
table" opens `dcs.org_metering_buckets` with a single filter `bucket_id
= 2`, which matches nothing.

**After this PR:** the popover shows the one row `(bucket_id = 903,
org_id = 2)`. "Open table" opens `dcs.org_metering_buckets` with two
filters, `org_id = 2` and `bucket_id = 903`, and the URL carries two
`filter=` params. Clicking the arrow on the `org_metering_bucket_id`
cell of the same row produces the same result.

Extra checks worth doing while you are there:

- Set one of the two key columns to NULL on a row. The arrow should
disappear for both key cells on that row, since a row with a null key
column does not reference anything under MATCH SIMPLE.
- A single-column foreign key (any existing table) should behave exactly
as before.

## What is the new behavior?

- New `ForeignKeyFormatter.utils.ts` with two pure functions.
`findColumnForeignKeyConstraint` locates the constraint on the current
table that contains the clicked column. `getReferencingRecordFilters`
pairs each source column with the target column at the same ordinal
position and builds one equality filter per pair from the row's values,
keeping the existing bytea-to-hex handling per column. It returns no
filters when any key column is null.
- `ForeignKeyFormatter` now reads the foreign key constraints query,
which returns ordinally paired source and target column arrays, instead
of the `relationships` list. The grid already fetches that query for the
same schema, so it is served from the React Query cache.
- `ReferenceRecordPeek` takes a `filters` array instead of a single
column and value. Both the peek query and the "Open table" link use the
full set, and the link emits one URI-encoded `filter=` param per column.
- Unit tests cover the reproduction above, single-column keys, bytea
values, null and missing values, falsy-but-valid values such as `0`, and
malformed constraints.

## Additional context

The table-editor introspection SQL in
`packages/pg-meta/src/sql/studio/table-editor/table.ts` and
`tables-paginated.ts` still expands composite foreign keys as a
cartesian product. #41080 only fixed the shared `tables.ts` query. The
arrow no longer depends on that data, but it can still mislabel the
referenced column elsewhere in Studio, so that is left for a follow-up
rather than widening this change into pg-meta SQL.

Before:
<img width="836" height="504" alt="Screenshot 2026-09-14 at 11 22 49"
src="https://github.com/user-attachments/assets/4645d64f-9bcb-44b0-b5b1-ab11ba7436db"
/>

After:
<img width="873" height="570" alt="Screenshot 2026-09-14 at 11 23 14"
src="https://github.com/user-attachments/assets/f2c47121-fd75-4efe-a370-28015c1b674e"
/>



🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01SkH86UV1KD4Xs5k9vt43tW

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved foreign-key record previews to correctly identify referenced
records across schemas and tables.
* Added support for composite foreign keys, ensuring previews and “Open
table” links apply all required column filters.
* Improved handling of binary values and incomplete or null foreign-key
data.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 19:22:04 +02:00
Ali Waseem 5b099ee03f chore: share Sentry browser-noise filters between studio and docs FE-4392 (#50407)
Studio and docs each kept their own Sentry `ignoreErrors` list, so
browser-extension and DOM-mutation noise that Studio already filtered
still reached Sentry from docs. Moved the app-agnostic filters (network,
extension DOM mutation, non-Error throws, cross-origin script errors)
into `packages/common/sentry.ts` and spread them into both client
configs, leaving app-specific entries local. Docs will stop reporting
extension-driven `insertBefore`/`removeChild` crashes, matching Studio's
existing behavior — `ignoreErrors` drops events before `beforeSend`
runs, so the error-boundary exemption no longer applies to them.

Fixes FE-4392

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Reduced non-actionable browser noise in error monitoring by filtering
known network, browser extension, DOM-manipulation, cross-origin, and
non-error failures.
- Applied consistent filtering across the documentation site and studio
error tracking.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 09:38:36 -06:00
Vaibhav 254da82c3a feat: surface role risks (#50410)
## TL;DR 

Bolds the consequences in the Owner and Administrator role descriptions,
and adds a confirmation step before an invite for either role is sent.


https://github.com/user-attachments/assets/c8fb53ae-66c3-4862-865e-f2ff9fb84a8e

## ref: 

- recurring in the community:
organizations losing access to their own projects after inviting someone
as owner

eg:
https://discord.com/channels/839993398554656828/1545087567706193970/1545102402871492759

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added a confirmation step when inviting members as Owners or
Administrators.
- Invitations are sent only after the elevated-role warning is
confirmed.
- Confirmation behavior is consistent for form submissions and
keyboard-triggered invitations.

- **Updates**
- Refined role permission descriptions, including clearer details about
elevated access and project deletion capabilities.
- Improved role descriptions shown during member invitations and role
selection.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 15:25:46 +00:00
Gildas Garcia 24f89f3967 MFA Recovery codes: allow users to regenerate their codes (#50336)
## What kind of change does this PR introduce?

Once users have recovery codes generated, allow them to regenerate the
codes.

This PR also automatically check the _I have copied the codes_ after
clicking the _Copy to clipboard button_.

> [!NOTE]
> The _Delete my recovery codes_ button only appear on local and staging
environments

## How to test

- On an account that already have recovery codes generated
- You should see an admonition showing the remaining codes available and
allowing you to regenerate the codes

## Screenshots

<img width="706" height="193" alt="image"
src="https://github.com/user-attachments/assets/001bfa87-74f5-4867-8564-09cb6f91adb6"
/>

<img width="425" height="277" alt="image"
src="https://github.com/user-attachments/assets/711b139c-f806-4da2-a240-fa7e7fd8acd0"
/>

<img width="548" height="353" alt="image"
src="https://github.com/user-attachments/assets/d6521a09-3a7f-4198-b162-9effc218fee6"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a recovery-code modal with copy-to-clipboard support and
confirmation before closing.
- Added an option to regenerate MFA recovery codes with a confirmation
step.
  - Recovery-code controls now appear when existing codes are available.
- Added loading, success, error, and retry states for recovery-code
generation and regeneration.

- **Bug Fixes**
- Updated the recovery-code generation error message to more accurately
describe the failed action.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 16:38:41 +02:00
Katerina Skroumpelou 68acece226 docs: drop the retired withSupabase middleware option from the intro (#50409)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs fix, one sentence removed from the `@supabase/middleware` reference
intro.

## What is the current behavior?

The alpha admonition says the `middleware` option on `withSupabase` in
`@supabase/server` is also alpha. That option was removed in
`@supabase/server` 1.6.0, where `withSupabase` became a `pipeline`
entry, so the sentence describes something that no longer exists.

## What is the new behavior?

The admonition keeps the `@supabase/middleware` alpha wording and drops
the sentence about the removed option. Both hand-maintained copies of
the intro are updated and stay identical: the spec partial that renders
the reference site, and the `docs/ref` copy that feeds the markdown
build.

## Additional context

Same two-file pattern the `@supabase/server` reference uses for its
intro and installing partials.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Updated middleware documentation to clarify that only the
`@supabase/middleware` package is in alpha.
- Removed the alpha-status notice for the `withSupabase` middleware
option in `@supabase/server`.
- Clarified that `@supabase/middleware` APIs may change between 0.x
releases.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 17:29:13 +03:00
86f38f97c8 docs: add troubleshooting entry for the Edge Function secrets limit (#50366)
## Summary
- No public doc previously covered what to do when a project hits the
100-secret cap for Edge Functions. Adds a troubleshooting entry
documenting the JSON-bundling workaround.
- Cross-links the new entry from the Secrets section of
`functions/limits.mdx`.

## Sourcing / context
- Internal Slack (Jul 2):
https://supabase.slack.com/archives/C02KMRX22NR/p1783003062600709?thread_ts=1783002978.740289&cid=C02KMRX22NR
— workaround first suggested (Kalleby).
- Internal Slack (Aug 19):
https://supabase.slack.com/archives/C0BMQHEU6N6/p1787139772204509?thread_ts=1787098919.509189&cid=C0BMQHEU6N6
— functions team reconfirms no override path exists; workaround
independently recommended again.
- The JSON-bundling pattern mirrors how Supabase's own default secrets
already work (`SUPABASE_PUBLISHABLE_KEYS` / `SUPABASE_SECRET_KEYS` in
`functions/secrets.mdx`), so this isn't a novel pattern for the
platform.
- Prompted by support ticket SU-473846.

## Test plan
- [x] `pnpm --filter docs lint:mdx` passes with no warnings on either
changed file
- [ ] New page renders correctly under `/docs/guides/troubleshooting`
- [ ] Link from `functions/limits.mdx` resolves

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added guidance for working around the 100-secret Edge Functions limit
by bundling related credentials into a single JSON secret.
- Documented JSON secret setup, parsing, replacement behavior, shell
quoting, environment files, and the 48 KiB per-secret size limit.
- Clarified that JSON bundling does not bypass the per-secret size
limit.
- Explained when to use Supabase Vault for row- or user-specific
secrets, including database round trips and potential latency.
- Linked the workaround guide from the Edge Functions limits
documentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io>
2026-09-15 10:13:46 -04:00
Joaquim Moreno Prusi b824acdfd2 feat(project-creation): support Kubernetes cluster override for internal project creation (#49956)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature, internal

## What is the current behavior?

When creating a project, the worker will use load balancing to decide
where to deploy a cluster.

## What is the new behavior?

An internal user can choose a specific cluster and even bypass the
CORDONED state by forcing deployment.


## Additional context

This PR adds kubernetesClusterId and kubernetesClusterForce to the
internal-only project creation form for K8S cloud providers, gated by
schema validation (provider-restricted; force requires an ID) and
cleared automatically on provider change. The override is a one-time
creation-time steer, not a persistent pin, and the UI copy reflects
that. Includes the matching
kubernetes_cluster_id/kubernetes_cluster_force request fields in the
generated platform API types.

<img width="1620" height="1352" alt="image"
src="https://github.com/user-attachments/assets/bd8965a1-cec8-4428-aac1-46d0bf3b89d3"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added Kubernetes cluster ID entry during project creation for
supported cloud providers.
  * Added an option to force deployment to a specified cluster.
* Clarified that eligible clusters must meet status and filesystem
requirements.

* **Bug Fixes**
* Prevented invalid or outdated Kubernetes settings from being submitted
when the provider or cluster selection changes.
  * Treated blank or whitespace-only cluster IDs as unset.
* Prevented force-deployment requests without a cluster ID or for
unsupported providers.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 13:46:49 +02:00
Alaister YoungandAlaister Young 3bac7165bd chore(studio): move the TanStack Start deploy onto Nitro (#50030)
Moves the Studio TanStack Start build off the hand-rolled Vercel setup
(an `api/server.js` function shim, rewrites in `vercel.ts`, a custom
`?dpl=` skew-protection Vite plugin, and `scripts/serve.js` for
self-hosted) and onto Nitro, which TanStack Start documents as its
deployment path. Documents are served from the static SPA shell on the
CDN; only `/api/*` and `/_serverFn/*` invoke the function.

**Removed:**
- `api/server.js`, `scripts/serve.js`, `scripts/smoke-server.mjs`
- The `skewProtectionDpl` Vite plugin, `renderBuiltUrl`, and the
`vite:preloadError` reload backstop in `router.tsx` (TanStack Router
already reloads once on a failed lazy import)
- Rewrites, `functions`, `outputDirectory`, and `cleanUrls` from
`vercel.ts` (redirects and headers stay)
- `magic-string` and `@jridgewell/remapping` devDependencies, the
`preview` script

**Added:**
- `nitro` plugin in `vite.config.ts`. Preset is auto-detected:
`.vercel/output` on Vercel, a self-contained node server in `.output`
everywhere else. `vercel.immutableStaticFiles` puts hashed chunks under
`/_vercel/immutable/` so tabs opened before a redeploy keep loading
their chunks; `functions.maxDuration: 300` carries over the old function
timeout
- `scripts/vercel-spa-routes.ts`: Nitro module that rewrites the
generated Build Output routes (documents -> `_shell.html`, allow-list ->
`__server`, missing chunk -> 404, base-path prefixes), with a unit test
- `server.ts`: TanStack Start server entry that initializes Sentry
before the route tree loads and wraps the handler with
`wrapFetchWithSentry`

**Changed:**
- `start:tanstack` runs `.output/server/index.mjs` directly with Node's
`--env-file-if-exists` for the `.env` cascade. Node doesn't expand
`$VAR` references, so `scripts/generateLocalEnv.js` now writes literal
values into `.env.test`
- Dockerfile's TanStack stage copies `.output` instead of running `pnpm
deploy`; the `server.js` shim loads `.env` and imports the Nitro server
- `NEXT_PUBLIC_BASE_PATH` (the platform's `/dashboard`) only sets the
router basepath; Vite's `base` stays at the root so chunks can use the
immutable store. The routes module emits prefixed rules for
`/dashboard/api/*` and `/dashboard/_serverFn/*` and rewrites `public/`
files requested under the prefix back to the root
- Self-hosted security headers come from a Nitro `routeRules` entry; on
Vercel they stay in `vercel.ts`
- `tslib` is inlined for the build only: Nitro's dev runner has no
interop for its CJS wrapper
- Monaco's worker chunks follow the client assets dir so they land in
the immutable store too

Verified on the `studio-staging` preview (`STUDIO_FRAMEWORK=tanstack` is
scoped to this branch there): documents come back as the static shell,
`/dashboard/api/*` hits the function, `public/` files resolve under the
prefix, a missing immutable chunk 404s. Across two deployments of this
branch, the older deployment's chunks still load from the immutable
store and requests carrying its `__vdpl` cookie are answered by that
deployment. Self-hosted path covered by the TanStack E2E job and the
Docker build job.

## To test

- On the `studio-staging` preview: `/dashboard/project/<ref>` should
show `content-disposition: inline; filename="_shell.html"` and a
single-region `x-vercel-id`; `/dashboard/api/get-utc-time` a two-region
id
- Sign in and click through a few pages, including one that opens Monaco
(SQL editor) so the worker chunks load
- After the next deploy, a tab left open on the previous one should
still navigate (lazy chunks) and call the API without errors
- Self-hosted: `STUDIO_FRAMEWORK=tanstack pnpm --filter studio build &&
pnpm --filter studio start`, then check `/api/platform/profile` and that
responses carry the security headers


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Production TanStack deployments now run on Nitro’s self-contained
server output.
* Vercel routing serves static pages first while directing API and
server-function requests appropriately.
* Server-function requests can include deployment identification for
consistent handling.
* Local environment generation now writes resolved configuration values.

* **Bug Fixes**
  * Improved handling of missing static assets and SPA fallback routing.
* Server-side error monitoring now captures request errors in the new
runtime.

* **Refactor**
* Replaced the legacy production server and smoke-test workflow with
Nitro-based startup.
  * Removed automatic reload handling for stale client assets.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-15 21:46:45 +10:00
Jordi Enric fa7c223209 fix(studio): use Compute management endpoints FUNC-896 (#50393)
## Problem

Studio still called the legacy `/workers` Management API routes and used
the old `project_worker` response contract, so Compute instances could
not be listed or retrieved after the API rename. The production API type
check also detected drift in the v1 and platform declarations.

## Fix

- Regenerate the v1, v2, and platform API declarations from the deployed
schemas.
- Update Studio list and detail queries to `/compute`.
- Align typed fixtures with the Compute response schemas and
`project_compute_instance` resource type.
- Update platform response type references to the generated `_Output`
schema names.

## How to test

- Run `pnpm api:verify-types`.
- Run `pnpm --filter api-types test`.
- Run `pnpm --filter studio test data/compute/compute.utils.test.ts
"tests/pages/project/[ref]/compute/index.test.tsx"`.
- Run `pnpm --filter studio typecheck`.
- Run `pnpm --filter common typecheck`.
- Run `pnpm --filter studio lint:ratchet`.

Expected result: production API declarations are synchronized, and
Studio requests the `/compute` list and detail endpoints and renders
`project_compute_instance` responses successfully.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Updated API response handling across profiles, backups, notifications,
integrations, warehouses, access tokens, payments, and other Studio
workflows for more accurate serialized data.
* Compute instance pages and queries now use the compute-specific API
endpoints and response data.
* Improved feature-flag type handling when disabled feature data is
unavailable.

* **Tests**
* Updated automated coverage and fixtures to reflect current compute and
API response formats.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 12:50:56 +02:00
Artur Zakirov b86b5feabd docs(orioledb): Add Configuration section (#50329)
- Add "Configuration" section into the OrioleDB docs
- Update the information about supported indexes: OrioleDB now supports
  non-btree indexes via index bridging
2026-09-15 12:07:13 +02:00
Jordi Enric c228ca4f61 fix(studio): restore function deployment annotations FE-3921 (#50362)
## Problem

The Edge Function overview converted the numeric deployment timestamp to
a string before parsing it as a date. This produced an invalid date, so
the invocations chart omitted the deployment annotation.

## Fix

Preserve the numeric timestamp returned by the API and allow the
annotation helper to parse both numeric and string timestamps. Show
deployment details in an accessible tooltip when hovering or focusing
the rocket marker, and add regression coverage for numeric timestamps
and the existing invalid, missing, and out-of-range cases.

## How to test

- Run the focused EdgeFunctionOverview utility test suite.
- Open an Edge Function whose latest deployment is within the selected
chart interval.
- Hover or focus the rocket marker.
- Expected result: the invocations chart shows the dashed deployment
line and rocket marker, and the marker tooltip shows the deployment
time.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Invocation update annotations now display correctly when function
update times are provided as numbers.
  - Timestamps at the start of the Unix epoch are now supported.
- Annotations no longer appear when update times are invalid or chart
data is incomplete.

- **Accessibility**
- Deployment markers in invocation charts are now keyboard-focusable and
include accessible labels.
  - Deployment timestamps are available in a tooltip on hover or focus.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 12:04:15 +02:00
Joshen Lim 4b24548345 Fix sync between filter bar and filter controls in unified logs (#50383)
### Context

In unified logs, adding a filter to the filter bar (e.g filtering on log
type) doesn't sync with the filter controls in the left menu (although
it does the other way around). Example here filtering on log type to
equals to edge (API Gateway)
<img width="400" alt="image"
src="https://github.com/user-attachments/assets/080aba77-3366-4530-8443-3c8902aefd20"
/>

Both filter bar and filter controls share the same URL state with nuqs,
and it comes in 2 shapes:
- a bare `string[]` for = conditions
- a wrapped `{ operator, values }` object for other operators

The filter bar didn't follow this convention for the first one as it
always wrote the wrapped object which made the checkbox appear untickets
on the filter controls (which expects the first one) - this always
caused the filter to show up as `[object Object]` if you add a log type
filter via the filter bar first, then check the same log type filter in
the filter controls.

### Changes involved
Am opting to streamline the expected data shape and have both components
always expect the wrapped object shape so we don't have to deal with 2
different shapes (feels unnecessary)

### To test
- Verify that applying a log type filter (e.g postgres) in the filter
bar should reflect the checkbox for the same log type filter in the
filter controls on the left to be checked as well
- Unchecking the checkbox in the filter controls should thereafter
remove the filter in the filter bar too

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- Unified Logs filters now use a consistent operator-and-values format
across filtering controls.
- Checkbox filters preserve operators when selecting multiple values or
using **Only**.
- Mixed filter conditions are handled more consistently, with
unsupported values ignored.
- Non-text filter values are converted consistently for reliable
filtering.
- **Bug Fixes**
- Improved consistency when applying, displaying, and updating Unified
Logs column filters.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 17:45:42 +08:00
Jordi Enric 8984305b1e feat: sample non-crash sentry errors at one percent (#50339)
## Problem

Browser Sentry reporting sends ordinary application errors at full
volume even though full-page crashes are the highest-priority signal.

## Fix

Sample eligible browser errors without `globalErrorBoundary` at 1%
across Studio, www, and docs. Keep 100% of eligible errors tagged with
`globalErrorBoundary`, preserve consent and existing noise filters, and
record the applied rate in `codeSampleRate`.

## How to test

- Run `node node_modules/vitest/vitest.mjs run
../../packages/common/sentry.test.ts lib/sentry-capture.test.tsx` from
`apps/www`.
- Run `node node_modules/vitest/vitest.mjs run
lib/sentry-client-options.test.ts` from `apps/studio`.
- Expected result: tagged page crashes bypass sampling, ordinary errors
use the 1% cutoff, and Studio applies sampling once while preserving its
existing filters.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved error reporting reliability by ensuring page-crash errors are
captured without sampling.
- Non-crash application errors are now sampled at a low rate, with
sampling metadata retained for monitoring.
- Updated filtering behavior so relevant Studio errors continue to be
reported consistently, including errors previously affected by
client-side filtering.
- Preserved filtering for third-party-only errors that do not represent
application failures.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 11:43:24 +02:00
Gildas Garcia 63bedef77f MFA Recovery codes: allow users to download their recovery codes (#50267)
## What kind of change does this PR introduce?

After users have set up a new MFA (first or not), we must:

- check whether recovery codes have already been generated
- if there are none, generate recovery codes and display them, "forcing"
users to copy them
- if already generated, show them how many are still available

> [!NOTE]
> The _Delete my recovery codes_ button in last screenshot only appear
on local and staging environments

## How to test

- On an account that doesn't have recovery codes generated yet and has
an MFA added
- You should see an admonition suggesting to generate the codes

## Screenshots

<img width="729" height="306" alt="image"
src="https://github.com/user-attachments/assets/79ba3870-4ef8-4571-9fd6-36eed20c9c24"
/>

<img width="550" height="356" alt="image"
src="https://github.com/user-attachments/assets/1632611a-996a-470d-b6cd-a4693b0f4602"
/>

<img width="719" height="205" alt="image"
src="https://github.com/user-attachments/assets/73cef611-05cf-4fac-bbd2-243f9b28e48d"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added support for generating, copying, and confirming MFA recovery
codes.
- Added recovery-code status visibility, including remaining and
exhausted codes.
  - Added the ability to delete recovery codes with confirmation.
- Added clear loading, success, and error states for recovery-code
actions.
  - Recovery-code status refreshes after codes are generated or deleted.

- **Bug Fixes**
- Recovery-code notices now remain visible when all codes have been
used.
  - Recovery-code dialogs can now be closed after generation errors.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 11:16:47 +02:00
Jordi Enric 24f8549e41 fix(studio): open edge function logs from chart clicks FE-3922 (#50364)
## Problem

Clicking an invocation bar on the Edge Function overview did not
preserve the selected chart segment, so the destination could not open a
focused investigation window.

## Fix

Forward the clicked bar timestamp and navigate to Logs or Invocations
with an encoded, focused time range. Share the existing chart range
calculation and add real Recharts interaction coverage.

## How to test

- Open an Edge Function Overview page with invocation data.
- Click a populated bar in the Total Invocations chart.
- Expected result: Logs or Invocations opens with its and ite query
parameters centered on the clicked bar.
- Repeat with unified logs enabled and disabled to verify both
destinations.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Clicking a bar in the Edge Function invocations chart now opens the
relevant logs or invocations view.
- The destination is focused on a time window surrounding the selected
invocation, making investigation faster.
- Chart bars now provide a pointer cursor to indicate they are
interactive.

- **Bug Fixes**
- Chart clicks without valid invocation data no longer trigger incorrect
navigation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 11:06:37 +02:00