mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 10:55:06 +03:00
chore/function-recent-errors
38771
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
a46170aa76 |
feat(workers): add log filters FE-4322 (#49893)
## Problem Workers log views were limited to the most recent 24 hours and could not be narrowed by event text or HTTP method. ## Fix Adds selectable time ranges, event-message search, and an HTTP-method filter for invocation logs. Filters are applied in the analytics query and included in the cache key. ## How to test - Open a worker and select the Invocations tab. - Change the time range, enter an event message, and select a method. - Expected result: only matching invocation logs are shown. - Open Logs or Activity. - Expected result: message and time filters are available; the method filter is hidden. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added worker log filtering by date range and event message. * Applied a default 24-hour time range to log searches. * Improved filter controls and updated empty-state messaging to reflect the selected range. * **Bug Fixes** * Improved filtering accuracy and safer handling of special characters in event messages. * **Tests** * Added coverage for date-range and message-filter query behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e7d91dbd06 |
fix(studio): display diff for view-only notebook cell edits (#49901)
## Summary Fixed a bug in the AI Assistant notebook-update proposal preview where a `replace_cell` operation that only changed a cell's view (table ↔ chart) or chart parameters (type, x/y columns, cumulative, scale, labels) would show as a "Replaced" row but the expanded diff would appear empty. **Root cause:** The diff editor only compared the cell's SQL text; view and chart configuration were never considered, so changes to those aspects showed no diff. **Solution:** * Refactored `getCellMetadata` to return structured `NotebookCellFields` with separate `source` (database/time range) and `view` (table/chart) fields instead of a single concatenated string * Added `formatChartConfig` and `formatCellView` helpers to describe chart cells * Updated `getEntryMetadata` to diff source and view independently, showing only the fields that actually changed (e.g., "Table → Chart (bar, ...)" when only the view changed, with the unchanged database omitted) * If neither field changed, metadata is hidden entirely ## Test plan * Added test cases for: chart-view cells reporting a `view` field, view-only changes surfacing without the unchanged database, chart-parameter-only changes surfacing without the unchanged database, database-only changes surfacing without the unchanged view, and fully-unchanged replacements hiding metadata entirely * All 43 tests in the touched test file pass * `tsc --noEmit` on apps/studio shows no new type errors ## Summary by CodeRabbit * **Enhancements** * Improved AI Assistant notebook previews with clearer cell details, including source content and table or chart views. * Chart previews now show key configuration details, such as chart type and selected dimensions * Replacement previews highlight only the fields that changed and hide entries with no visible changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Notebook previews now distinguish cell content from its view, including table and chart details. * Chart previews display relevant configuration, such as chart type and axes. * Log previews include their formatted time range. * Replacement previews now show only the fields that changed. * **Bug Fixes** * Unchanged replacements are now hidden instead of displaying misleading content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c6435f1cbe |
fix(studio): hide shared pooler chart for high availability projects (#49904)
High Availability projects run Multigres and don't have Supavisor, so the Shared Pooler (Supavisor) client connections chart in the database report only ever rendered an "Unable to load data" error for them. This hides the chart for HA projects, following the same pattern as the Disk IO Burst Balance chart. **Changed:** - `supavisor-connections-active` chart is now hidden when `project.high_availability` is true **Added:** - Unit tests covering the shared pooler chart's visibility for standard, HA, and unentitled projects ## To test - Open Reports → Database on a High Availability project – the Shared Pooler (Supavisor) client connections chart should no longer appear - Open the same report on a standard Pro project – the chart should still render as before <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * The active connection chart is now hidden for High Availability projects and projects without the database entitlement, preventing empty or unavailable data from being displayed. * **Tests** * Added coverage to verify the chart appears only for eligible standard projects. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
9aaa753306 |
feat(studio): add telemetry for explorer/sql editor temporary switch buttons (#49898)
## Summary Add PostHog event tracking for the two new buttons introduced in PR supabase/supabase#49698 that allow users to temporarily switch between the Explorer and SQL Editor: * **Explorer button**: "Back to SQL Editor" button in the Explorer sidebar title bar now fires `explorer_temp_access_sql_editor_clicked` event * **SQL Editor button**: "Back to Explorer" button in the SQL Editor title bar (shown during temporary visits) now fires `sql_editor_back_explorer_clicked` event Both event interfaces follow the repo's telemetry-standards conventions, carrying only `groups: TelemetryGroups` property with no additional custom properties. ## Test plan - [X] Verify `explorer_temp_access_sql_editor_clicked` event fires in PostHog when clicking "Back to SQL Editor" button in Explorer - [X] Verify `sql_editor_back_explorer_clicked` event fires in PostHog when clicking "Back to Explorer" button in SQL Editor - [X] Run typecheck: `pnpm typecheck` passes without errors - [X] Run lint: `pnpm lint --filter=studio` passes ## Issue Resolves [FE-4213](https://linear.app/supabase/issue/FE-4213/explorer-set-up-telemetry-for-metrics-where-appropriate) ## Summary by CodeRabbit * **Analytics** * Added tracking for navigation from the Explorer to the SQL Editor. * Added tracking for returning from the SQL Editor to the Explorer. |
||
|
|
343dee6bac | chore: Add rewrites to kb vercel config (#49900) | ||
|
|
abb7f3ede2 |
fix(workers): refresh Workers view FE-4323 (#49887)
## Problem The Workers view can remain stale after a worker is deployed through the CLI, because the dashboard has no deployment mutation to invalidate its list query. ## Fix Add a manual Refresh action to the Workers header and force the Workers list query to refetch whenever the browser regains focus. ## How to test - Open a project’s Workers view and select Refresh. - Expected result: the list requests current worker data and renders it. - Deploy a worker through the CLI, then return focus to the Workers view. - Expected result: the Workers list refreshes even when its cached data is fresh. Closes FE-4323. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added Refresh buttons to the Workers page and worker list. - Refreshing displays the latest worker information and shows a loading state while data is retrieved. - Worker data now automatically refreshes when the browser window regains focus. - Added a Refresh action to unexpected-error messages, allowing failed requests to be retried without leaving the page. - **Bug Fixes** - Improved recovery from failed worker data requests through in-page retry support. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
47fbf26e4b |
fix: sync Bucket state when bucket public/private setting changes (#49891)
### What is the current behavior? Fixes FE-4056. In the Storage Explorer, if you edit a bucket's access level (public/private) via "Edit bucket", the "Get URL" action keeps generating the old signed/public URL type. Clicking the in-explorer refresh button doesn't fix it either, since it only re-lists objects and never refetches bucket metadata. Only a full browser reload resolves it. ### What is the new behavior? selectedBucket in the Storage Explorer's Valtio store is now kept in sync with the bucket query on every change, not just on project switch. "Get URL" now always reads the current public/private state, so it correctly returns a public URL or a signed URL immediately after the bucket's access level is changed - no reload required. ### Additional context Added a second effect to sync selectedBucket whenever the bucket query value changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated bucket selection state when bucket settings change, preventing stale bucket information in actions such as “Get URL.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ffe10b8cf3 |
Add Tomohiro Mitani to humans.txt (#49882)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Bug fix, feature, docs update, ... ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Tomohiro Mitani to the project’s team listing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6e83f71a56 |
docs: wire middleware sdk docs (#49854)
Wire middleware sdk docs (`@supabase/middleware`) https://github.com/supabase/middleware Preview ref here: https://docs-git-docs-supabase-middleware-sdk-supabase.vercel.app/docs/reference/middleware/introduction <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Middleware SDK reference section to the documentation. * Added installation guidance for npm, Yarn, pnpm, Deno, and Bun. * Documented framework-agnostic middleware composition, typed shared context, ordering, trust, and environment access across supported runtimes. * Added Middleware documentation to navigation and search. * Identified the Middleware SDK as an alpha release. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5db8a0e960 |
feat(studio): instrument sign-in attempts and failures (#49853)
The /sign-in page emitted only a pageview on entry and the success-side `sign_in` event on exit: failed or abandoned attempts were invisible, so "never interacted" and "tried and failed silently" could not be told apart in the sign-in funnel. I added an unsampled `sign_in_submitted` event at every initiation point and classified failure capture via `dashboard_error_created` with a new `signin` origin. **Changed:** - **Submit attempts observable**: `sign_in_submitted` (method: `email`, provider id, `sso`, or partner) fires from the DOM submit handler on the password and SSO forms (so submits that fail client-side validation still count), and from the OAuth, custom-provider, and partner initiation handlers. - **Failures classified**: each sign-in error path feeds the existing funnel-error pipe with origin `signin` and a controlled reason slug (`invalid_credentials`, `email_not_confirmed`, `captcha_failed`, `sso_provider_not_found`, ...). GoTrue auth errors now classify via their numeric `status`, guarded so transport failures (`status: 0`) stay `network_error`. - **Attempt events survive the OAuth redirect**: the telemetry event POST sends with `keepalive` (scoped to `sign_in_submitted`, since keepalive requests share a per-page in-flight body quota), so a dispatched request is no longer aborted by the provider navigation; send rejections are caught centrally instead of surfacing as unhandled rejections. The fetch still dispatches after an async token lookup, so preview testing verifies the GitHub-path event actually lands on the wire. - **Captcha rejection is no longer silent**: a rejected hCaptcha challenge resolves the stuck loading toast with an error message, emits `captcha_challenge_failed` (distinct from `captcha_failed`, which stays reserved for the auth server rejecting a submitted token), reports to error monitoring, and resets the captcha widget (previously: unhandled promise rejection and a spinner that never resolved). - **Partner method validated**: the partner sign-in page resolves the URL-hash value against the provider registry and forwards the canonical provider id into `method` on both `sign_in_submitted` and `sign_in`; anything unregistered records as `unregistered_partner`, so a crafted link can't poison the breakdown on either event. **Note:** failure events stay on the shared 10% `dashboard_error_created` sampling rate (a per-origin carve-out would break cross-source volume comparability); the unsampled attempt event carries the tried-vs-never-interacted signal at full volume. ## To test Tested on Vercel preview (studio-staging, wire-level network capture + staging ingestion check): - [x] On `/sign-in`, submit a bogus email + password: expect a `POST */platform/telemetry/event` request with `action: sign_in_submitted`, `method: email` in the network tab, plus an error toast. Observed: 201, auth returned 400 as expected. - [x] Submit with an empty password: expect `sign_in_submitted` to still fire (validation failures count as attempts). Observed: event fired with 201 and no auth call followed. - [x] Click "Continue with GitHub": expect `sign_in_submitted` with `method: github` on the wire before the provider redirect. Observed: the POST completed (201) before the browser landed on github.com, so the keepalive path holds. - [x] Negative case: fresh page load with no interaction fires no `sign_in_submitted`. - [x] Ingestion: all fired events (methods `email`, `github`, plus organic `sso` submits from a real login on the same preview) arrived in the staging project with the expected properties. - [x] Re-ran the email and GitHub paths on the scoped-keepalive build (`129bf8d`): both `sign_in_submitted` POSTs returned 201 (the GitHub one completed despite the provider redirect), and both events ingested into the staging project with the expected `method`/`category` properties. ## Linear - GROWTH-1165 (no `fixes` keyword on purpose: the evidence checks run on prod data post-deploy, and the issue closes manually after they pass) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved sign-in protection with more reliable invisible CAPTCHA handling. * Added sign-in submission tracking across password, SSO, partner, custom OAuth, and external-provider flows. * Added detailed classification for authentication, validation, CAPTCHA, provider, and network errors. * **Bug Fixes** * Sign-in now stops safely and resets CAPTCHA when verification fails. * Improved error reporting for failed sign-in attempts, including redirects and OAuth flows. * Ensured sign-in telemetry is delivered reliably during OAuth redirects. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
afeba62c7c |
feat: Show min / max for integers in mgmt api docs (#49884)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Improvement in docs ## What is the current behavior? Not shown ## What is the new behavior? Displays min / max when available in OpenAPI specs for integers and numbers ## Additional context <img width="630" height="183" alt="image" src="https://github.com/user-attachments/assets/eb4e917a-d961-456c-810a-cba6aa2b0388" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * API reference documentation now displays minimum and maximum constraints for numeric schema parameters, including `number` and `integer` types. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dd57c1476f | chore: Add redirects to www for kb project (#49780) | ||
|
|
c7e181357c |
Add Dion Zeneli to humans.txt (#49878)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Dion Zeneli to the alphabetical list of Supabase team members in the project’s public team information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fdc2b45f82 |
add Warda Bibi to humans.txt (#49823)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Bug fix, feature, docs update, ... ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Warda Bibi to the team member list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cecb328120 |
feat(studio): clean up free tier upgrade box (#49851)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Small update of the Projects overview UI to resolve the competing CTA's as well as alignment. Open to tweak a little more here. | Before | After | |--------|--------| | <img width="1287" height="346" alt="Screenshot 2026-09-01 at 15 08 33" src="https://github.com/user-attachments/assets/a0911d8c-7be9-4a70-ab37-8842093423c9" /> | <img width="1252" height="430" alt="Screenshot 2026-09-01 at 15 05 40" src="https://github.com/user-attachments/assets/cd75a8bd-9378-483b-96b8-2272a9990b4c" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Refined the plan usage card layout with larger metric values and cleaner labels. * Added dividers between usage metrics for improved readability. * Simplified card and loading-state styling by removing unnecessary borders, backgrounds, and padding. * Updated the upgrade button’s visual treatment. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d088ec6259 |
fix(studio): project selector fetch on scoped pat (#49865)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? The scoped-access-token project selector fetched a single page of the user's projects across all orgs and filtered client-side, so switching to an org whose projects weren't in that page left the list empty with no way to load more. Use the org-scoped projects query instead, keyed on the selected org, and fix project search to match by name. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Project selection now displays projects belonging to the currently selected organization. * Switching organizations refreshes the available project list, preventing projects from another organization from appearing. * **Tests** * Added coverage for organization-specific project loading, organization switching, pagination, and empty project lists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b04e26872b |
feat(ui-library): add MCP server block (#49573)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — a new UI Library block. Bottom of a two-PR stack; #49579 builds on it. ## What is the new behavior? Adds an `mcp-server` block: a Supabase Edge Function that exposes MCP tools scoped to the signed-in user. It is backend-only, so every file has an explicit target and no `components.json` is needed. - `withSupabase({ auth: 'user' })` verifies the access token and gives each tool an RLS-scoped client. Both product session tokens and OAuth tokens work; only the latter carry `client_id`. - `withOAuthProtectedResource` serves RFC 9728 metadata and adds a `WWW-Authenticate` challenge to `401`s, so external MCP clients can discover the authorization server. - Tools are composed in `tools/index.ts`. One is included, `whoami`, which shows the caller's identity and OAuth client. Docs at `/library/docs/headless/mcp-server`, under a new MCP group in the sidebar. `BlockItem` gained a `showOpenInV0` flag (v0 cannot take Deno functions), and the file-tree viewer now picks a language per file instead of always TypeScript. ## To test 1. `npx shadcn@latest add http://localhost:3004/library/r/mcp-server.json` into a Supabase project or empty directory. 2. Add `[functions.mcp-server] verify_jwt = false` to `supabase/config.toml`, then: ```bash supabase start supabase functions serve mcp-server --env-file supabase/functions/.env ``` 3. **Unauthenticated:** `curl -i localhost:54321/functions/v1/mcp-server` returns `401` with a `WWW-Authenticate` header, and `/functions/v1/mcp-server/oauth-protected-resource` returns the metadata document. 4. **Product session:** sign up a user, then call the endpoint with `Authorization: Bearer <their access token>`. `tools/list` shows `whoami`; calling it returns that user's id and `client_id: null`. 5. **External client:** enable `[auth.oauth_server]` with `allow_dynamic_registration = true`, install the OAuth Consent block, point an MCP client (Claude Code, Codex) at the function URL, approve the consent screen, and call `whoami` again. `client_id` is now populated. 6. Confirm RLS holds: add a table with a user-scoped policy and a tool that reads it, then check a second user cannot see the first user's rows. 7. Docs page renders at `/library/docs/headless/mcp-server`, and `deno.json` / `.env.example` in the folder tree highlight as JSON and bash rather than TypeScript. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added an installable Supabase MCP Server block with user-scoped authentication and a read-only identity tool. - Added MCP Blocks to documentation navigation and setup guidance. - Code blocks now automatically detect syntax highlighting from file names. - Added an option to hide the “Open in v0” button. - **Documentation** - Expanded MCP Server guidance covering installation, configuration, validation, deployment, OAuth, and security. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Saxon Fletcher <SaxonF@users.noreply.github.com> |
||
|
|
924b3f5793 |
feat(ui-patterns): add async selection feedback (#49843)
## What kind of change does this PR introduce? Shared UI pattern and Studio UX improvement. ## What is the current behavior? Async selectors use bespoke loading and error layouts. Some replace the entire field while fetching, and opening a selector does not consistently refresh its options. ## What is the new behavior? Adds shared loading, error, and empty states for Select, command, and MultiSelector lists, including a persistent polite live region and reduced-motion support. Analytics Bucket and DuckLake selectors keep their controls in place, retain populated options during background refreshes, and refresh when reopened. ## To test Open the [Replication preview](https://studio-staging-git-dnywh-featasync-selection-feedback-supabase.vercel.app/dashboard/project/_/database/replication?destinationType=Analytics%20Bucket). The destination sheet should already be open on **Analytics Bucket**. You do not need to create a bucket, configure a destination, or start a pipeline. Open **Select a bucket**, then review these outcomes: 1. **The trigger stays put.** Opening the picker must not replace the form field with a full-width loading placeholder. 2. **Loading belongs inside the menu.** While options are fetched, the open menu shows a compact skeleton list. 3. **No resources has a clear explanation.** If the project has no Analytics Buckets, the menu says **No buckets available**. It still offers **Create a new bucket** beneath that message. 4. **Existing options do not disappear on refresh.** If the project does have buckets, close and reopen the picker. Its current options remain visible while the refresh happens in the background, rather than flashing back to skeletons. 5. **The pattern is consistent.** If convenient, select a bucket and open the namespace or access-key picker. The same in-menu loading, empty, and error treatment applies there too. The deterministic request-error and reduced-motion cases are covered by focused unit tests because the deploy preview cannot reliably force those states. |
||
|
|
9b17ce8f2c |
chore(studio): default assistant to GPT-5.6 Luna (#49749)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature / chore: hide assistant model selection in the UI and default chats to GPT-5.6 Luna. ## What is the current behavior? The assistant composer exposes a model picker. Paid orgs default to `gpt-5.3-codex`; everyone else defaults to `gpt-5.4-nano`. ## What is the new behavior? - The model picker is hidden in the assistant composer and Explorer home. - Chats default to `gpt-5.6-luna` with `reasoningEffort: medium`. - Model selection plumbing is kept (registry, entitlements, `setModel`, generate-v4 request body) so a requested model can still be honored when provided. - Other completion endpoints still use `gpt-5.4-nano`. ## Additional context Model selector UI can be re-enabled by passing `selectedModel` / `onSelectModel` to `AssistantChatForm`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for the GPT-5.6 Luna model with medium reasoning capability. * Made GPT-5.6 Luna the default assistant model. * **Improvements** * Simplified assistant chat by removing model selection from the primary chat experience. * Updated model fallback behavior to use the standard assistant model. * Chat forms can now optionally display model selection when configured. * **Tests** * Updated model coverage and assistant chat tests for the new defaults and behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
4d2bd0eacf |
docs: add the missing API key decision information (#49799)
Closes DOCS-1311 Closes FDBKIN-2926 Closes DOCS-694 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. Corrections and new content. This is the PR that is to bring the Eval to green. ## What is the current behavior? Two statements are wrong, and the gaps behind most logged confusion about this page are unfilled. - The Availability column marks publishable and secret keys Platform-only. `supabase start` prints both. - The page says Edge Functions only verify the legacy keys and to use `--no-verify-jwt`. #49700 updated `guides/functions/auth-headers` to document that `verify_jwt` accepts the new keys on either header, but left this page and the migration guide stating the old behavior. - The page has no code samples, so it never shows how a key reaches code. An agent reading it falls back on `SUPABASE_SERVICE_ROLE_KEY`, the legacy key this same page deprecates. - Nothing maps `anon` and `service_role` to their replacements, or says the replacements aren't `eyJ`-prefixed JWTs. - The Postgres role table covers only publishable keys. ## What is the new behavior? Corrections: - Mark all four key types available on Platform and CLI, and note that the local secret key takes the place of the local `service_role` key. - Point the Edge Functions guidance at the `@supabase/server` SDK instead of `--no-verify-jwt`. Fix the same bullet in the migration guide. Additions: - "Coming from `anon` and `service_role`" gives the legacy-to-new mapping and says the replacements aren't JWTs. - Extend the Postgres role table to cover secret keys, and note that grants are evaluated before Row Level Security, so a missing grant fails even for `service_role`. - State who does what. Copying a key needs a signed-in Dashboard session, so it is a person's step, while code only refers to the variable name. Add a `.env` sample naming the variables. - Add the two `createClient` samples the page lacked, plus an "Inside an Edge Function" subsection using `withSupabase`, which reads no key from the environment. - Cross-reference from the key decision to retrieving a value, wiring it into code, or migrating an application that ships legacy keys. ## Additional context PR 4 of 4. Base is #49797. ## Manual testing 1. Open the API keys guide on the deploy preview. 2. Check the Key types table. All four rows read "Platform, CLI". 3. Check Known limitations. It no longer mentions `--no-verify-jwt`. 4. Open the migration guide and check Known limitations. The Edge Functions bullet matches. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated API key guidance with clearer instructions for finding, selecting, and using publishable and secret keys. * Added examples for environment variables, client applications, backend code, and Edge Functions. * Clarified key formats, CLI availability, local development output, Postgres role mappings, and authorization behavior. * Expanded guidance on `apikey` headers, RLS errors, and Edge Function API key authorization. * Refined migration guidance for API key authentication in Edge Functions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5bd0b90cf0 |
docs: add all ways to get an API key (not just Studio) (#49797)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? "Find your keys" offers only the Dashboard. Readers working from a script, a preview branch, or a local stack have no path, which accounts for several logged reports of people unable to locate a key. ## What is the new behavior? Replace the procedure with a tabbed selector so a reader picks the path that matches where they work: - Dashboard, through the Connect dialog or Settings > API Keys. - Supabase CLI, `supabase projects api-keys --project-ref`, including the note that a preview branch has its own keys and needs its own ref. - Management API, `GET /v1/projects/{ref}/api-keys?reveal=true`, for deploy scripts and provisioning tooling. - Local stack, from `supabase start` output or `supabase status`. `queryGroup="retrieval-method"` makes each tab deep-linkable, so a reader can be sent straight to one path. ## Additional context PR 3 of 4. Base is #49796. ## Manual testing 1. Open the API keys guide on the deploy preview and find "Find your keys". 2. Select each tab. One panel shows at a time, and the URL gains `?retrieval-method=<tab>`. 3. Open that URL in a new tab. It restores the same selection. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated the API key deprecation guidance to link to the “Find your keys” guide. - Expanded the guide with instructions for retrieving keys through the Dashboard, CLI, Management API, and local stack. - Added guidance to create keys in the Dashboard when none are available. - Reworded the table of contents entry for improved clarity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d7f1a44e53 |
docs: restructure the API keys guide by information type (#49796)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. Restructure, mostly moved lines, plus a tense fix in a shared partial. ## What is the current behavior? Context, procedure, and reference material are interleaved, so background reading interrupts the action path. - The page never states which key to use as an answer. You infer it from a five-column reference table. - Finding a key is a fragment inside an admonition, placed above the page's own definition of an API key. - Rotating a leaked key, the only procedure on the page, is the last H3. - The "Changes to API keys" notice narrates a past change in future tense, and "They will be deprecated" has no antecedent in its paragraph. ## What is the new behavior? Group the guide into context, procedure, and reference sections, per CONTRIBUTING § Guides on mixed information types. - Lead with "Which key do you use?", a decision table keyed on where the code runs. Section navigation sits directly below the intro. - Collect the conceptual sections under "How API keys work" and give publishable and secret keys parallel headings. - Promote both procedures into "Find and use your keys". Rotation is now an ordered procedure. - Move the enumerated secret key rules into "Security reference", grouped under bold labels by the kind of mistake each prevents, and leave a short danger admonition where secret keys are introduced. - Promote the five-sentence coexistence admonition to its own section. Admonitions are for short warnings. - Rewrite the shared deprecation partial for timeless documentation: present tense, no dangling "They", no "now". The partial renders on five pages. - Pin a stable anchor on the rotation heading and update the one inbound link, in the rotating-anon-service-and-jwt-secrets troubleshooting entry. - Align link text across docs for this guide. Twenty-one links pointed at it under fourteen labels, including two that named the wrong destination. Rule: when a link means the guide, the text is "API keys"; when it means a specific key or section, the specific text stays. Twelve now share "API keys", up from three. Review with `git diff --color-moved=zebra`. ## Additional context PR 2 of 4. Base is #49795. Includes the link-text alignment previously opened as #49866. ## Manual testing 1. Open the API keys guide on the deploy preview. 2. Check the table of contents. It shows three groups: How API keys work, Find and use your keys, Security reference. 3. Open the rotating-anon-service-and-jwt-secrets troubleshooting entry and follow "Rotate a leaked or compromised key" under Further readings. It lands on the renamed heading. 4. Open the Realtime Broadcast guide and check the "Changes to API keys" notice. It reads in present tense there too. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated API key guidance to explain the transition from legacy `anon` and `service_role` keys to publishable and secret keys by the end of 2026. - Reorganized the API keys guide with clearer key-selection guidance, security recommendations, usage examples, and rotation steps. - Updated troubleshooting references to point to the revised leaked-key rotation guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2f31010a18 |
docs: style edit for the API keys guide (#49795)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. Style only. ## What is the current behavior? The API keys guide has drifted from `WORD_LIST.md` and `CONTRIBUTING.md`. It also carries two defects: - The rotation steps tell you to replace the new key with the compromised one, rather than the reverse. - The secret key caution list opens with "Do not:" but several items read "Never use" and "Do not pass", which inverts them into the opposite instruction. ## What is the new behavior? Word-level edit. No section is added, moved, or reordered, so the restructure in the next PR of this stack lands as a readable set of moved lines. - Fix the reversed rotation instruction. - Rewrite the caution list so every item completes its "Don't:" stem. - Replace the Silicon Valley character names and trailing ellipses in the responsibility table. - Drop italics used for plain emphasis, parenthetical asides, `etc.`, `&`, the lint-flagged "easy", and existential sentence openers. - Replace "since" and "as" used for cause, and future tense used for current product behavior. ## Additional context PR 1 of 4. Base is `master`. ## Manual testing 1. Open [Understanding API keys](https://docs-git-docs-api-keys-style-edit-supabase.vercel.app/docs/guides/getting-started/api-keys) on the deploy preview. 2. Read the secret key caution list. Every item completes the "Don't:" stem. 3. Read "What to do if a secret key or `service_role` has been leaked or compromised". The order is: create the new key, then replace the compromised key with it. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Rewritten the API keys guide with clearer wording and improved structure. * Clarified how to access API keys through the Connect dialog and distinguished API keys from Supabase Auth. * Updated explanations of publishable and secret keys, including cautions, security best practices, and steps for responding to leaked keys. * Refined guidance on known limitations and compatibility differences. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
27a4421d6e |
fix(docs): stop sidebar from jumping on scroll (#49807)
## What kind of change does this PR introduce? bug fix to stop sidebar jump on scroll within docs ## What is the current behavior? the docs sidebar shifts up by 1px as soon as scrolling start as the top bar height include bottom border causing the jump as height token differ from the whole height ## What is the new behavior? favor box shadow instead of a border for the bottom line, so height matches the token and nothing needs to compensate any more which allows to remove some `+1px` elsewhere + also drops a nested `lg:sticky` in the sidebar that did nothing inside an already-sticky parent | state | preview | | -------|------| | before | <video src="https://github.com/user-attachments/assets/b4bbfa2d-6595-4711-bb2b-bd2bf3aded8a" /> | | after | <video src="https://github.com/user-attachments/assets/f044aebc-ef14-42c1-8564-3b290399d00b" /> | ## Additional context - header now uses the existing `subhighlight-border` utility, which was not used anywhere else it seems, could also be renamed? - could be down the other way by keeping border and fixing the jump <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved documentation navigation alignment by removing unnecessary spacing from sticky sidebars, table of contents, and section headings. * Updated desktop navigation behavior for more consistent scrolling and viewport layout. * Refined the top navigation bar’s border styling for a cleaner appearance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8af724806e |
feat(www): add Deepthi to Select VIP experience and remove dinner pages (#49858)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature / cleanup for Select 2026 go pages. ## What is the current behavior? The unused VIP dinner RSVP pages are still registered. The VIP experience page only lists Paul, Ant, and Sugu as hosts, and Deepthi's author photo comes from GitHub. ## What is the new behavior? - Removes `select-2026/vip-dinner` and its thank-you page - Adds Deepthi Sigireddi as a host on the VIP experience page - Overrides Deepthi's GitHub avatar with a local headshot ## Additional context Prettier was run on the changed files with the repo config (`SORT_IMPORTS=false` check matches CI). Made with [Cursor](https://cursor.com) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added Deepthi Sigireddi to the VIP experience hosts section. - Updated the host layout to display all hosts in a responsive grid. - Updated Deepthi Sigireddi’s profile image. - **Removed** - Removed the VIP dinner RSVP page and attendance confirmation page. - Removed these pages from the event site navigation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
8d4a16beea |
fix: ESLint errors relating to accessibility in database section (#49638)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Improving accessibility by adding `aria-label` and associating the switches with their labels in database section. Adding `Tooltip` for icon only buttons. ## What is the current behavior? `Switch` components are not connected with their labels, `aria-label` and some `Tooltip` are missing. ## What is the new behavior? Icon-only buttons have now buttons and `aria-label` have been added. `Switch` components are connected to their labels. ## Additional context No visual changes have been made. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Accessibility Improvements** - Added descriptive labels and tooltips to database management actions, including remove, delete, and “More options” controls. - Improved screen reader support for function editor maximize/minimize controls, privilege switches, publication switches, and column actions. - Connected privilege labels with their corresponding controls for clearer navigation. - Clarified permission-related messaging when deleting columns. - Reduced duplicate announcements from tooltips and accessible descriptions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
121332c1ac |
feat(www): add service json-ld to homepage (#49849)
Follow-up to #49768. Agent-readiness scanners grade schema breadth by extended schema.org types (Service, FAQPage, Product); SoftwareApplication alone doesn't register, so I added a Service block whose offer catalog mirrors the products already rendered on the homepage. I also brought `/.well-known/api-catalog` up to the RFC 9727 API-catalog profile. **Changed:** - **Homepage emits Service JSON-LD**: new `serviceSchema` builder in `lib/json-ld.ts`; the offer catalog lists the six products the homepage products section renders (Database, Authentication, Storage, Edge Functions, Realtime, Vector). - **api-catalog leads with the catalog context**: `linkset[0]` now anchors the catalog URL and carries an `item` link to the Management API base, per the RFC 9727 profile; the existing service-desc context moves to `linkset[1]` unchanged. ## To test Tested on Vercel preview: - [ ] View source on the preview homepage: expect a fourth `application/ld+json` script with `"@type":"Service"` and six offerings - [ ] `curl <preview>/.well-known/api-catalog`: expect `linkset[0]` to contain an `item` array pointing at `https://api.supabase.com/v1` ## Linear - fixes GROWTH-1175 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added structured service information to the home page, including Supabase’s platform offerings. * Added an API catalog entry linking to the Supabase API endpoint. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
55385adad5 |
fix(docs): fix tab bar overlapping code blocks (#49775)
## What kind of change does this PR introduce? bug fix: removes `<$CodeTabs>` from [declarative-database-schemas.mdx](https://github.com/supabase/supabase/blob/master/apps/docs/content/guides/local-development/declarative-database-schemas.mdx) following up with #49263 ## What is the current behavior? on [/declarative-database-schemas](https://supabase.com/docs/guides/local-development/declarative-database-schemas#declaring-your-schema) the tab bar above each step code block overlaps the code below it every step wraps code in `<$CodeTabs>` but carries a `-mb-6` expecting the code default margin to absorb it, while `StepHikeCompact` zeroes™ it note: it's the only page nesting `<$CodeTabs>` inside a step ## What is the new behavior? | state | preview | | -------|------| | before | <img width="795" height="417" alt="image" src="https://github.com/user-attachments/assets/d3d65f57-d621-4d5a-a3f9-229f5908cdf7" /> | | after | <img width="795" height="417" alt="image" src="https://github.com/user-attachments/assets/f3dc9f2d-fd4b-4ebd-95b4-63de587604fb" /> | ## Additional context could go the other way and add `<$CodeTabs>` to those two guides for consistency but that would need StepHikeCompact to take another ! utility to restore it, but not against it if feels better. |
||
|
|
17d15ee1e2 |
fix(studio): confirm destructive notebook queries (#49658)
## What - add a second notebook-level confirmation for destructive SQL before forced batch execution - reuse the shared SQL safety detector for stored and live cell SQL - cover destructive confirmation, cancellation, non-destructive mutations, and live SQL ## Testing - pnpm --filter studio exec vitest run components/interfaces/Explorer/ExplorerNotebookTab.utils.test.ts components/interfaces/Explorer/__tests__/ExplorerNotebookTab.test.tsx --coverage.enabled=false - pnpm --filter studio exec eslint components/interfaces/Explorer/ExplorerNotebookTab.tsx components/interfaces/Explorer/ExplorerNotebookTab.utils.ts apps/studio/components/interfaces/Explorer/ExplorerNotebookTab.utils.test.ts apps/studio/components/interfaces/Explorer/__tests__/ExplorerNotebookTab.test.tsx Closes FE-4284 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Simplified notebook execution into a single confirmation step for mutating queries. * Destructive queries, including operations such as `DROP` or `TRUNCATE`, are clearly marked with a **Destructive** badge. * The confirmation dialog lists affected queries and lets you proceed or cancel. * Detection uses the latest SQL from the editor and ignores destructive keywords in comments. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
39c39a9e47 |
feat: add 'Other' option to support form category dropdown (#49846)
## What is the current behavior? The "What issue are you having?" dropdown in the contact support form has a fixed set of categories. There's no catch-all option, so users with an issue that doesn't cleanly match any category are forced to pick an inaccurate one. Fixes [FE-4145](https://linear.app/supabase/issue/FE-4145/add-other-to-what-issue-are-you-having-in-contact-support-form) — reported case: a user had to select "Database Unresponsive" for an issue that only affected one user's connection, not the database itself. ## What is the new behavior? Added an "Other" option to the category dropdown. ## Additional context - Category value must stay `Others` (plural) rather than `Other` — Front's `Type` custom field is a fixed, case-sensitive enum that only contains`others`; sending `Other` would silently fail to set the field in Front (ticket still submits, but shows as `unknown` category). - Traced end-to-end (frontend zod → network call → backend DTO → controller → Front custom field mapping) to confirm no fixed enum or switch statement elsewhere breaks on an unrecognized category value. - Open item, not blocking this PR: following up with Front admin access to confirm no routing rule explicitly lists `Type` values in a way that would leave `others` unmatched (worst case is a missed auto-route, not a lost ticket). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified the handling of the “Other” support category for improved internal reference. * Documented that the category’s value is normalized consistently during processing. * No changes were made to the category’s behavior or the end-user support experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
eba2aeb517 |
chore: remove stale references to the removed build:llms pipeline (#49848)
## What The `build:llms` script no longer exists in apps/docs (its output, `apps/docs/public/llms/*.txt`, is superseded by `apps/www/app/llms/[slug]/route.ts` serving the generated reference markdown directly). Four stale references remained: - `apps/docs/.gitignore`: removed the `public/llms/` entry and its comment referencing the dead script. Nothing writes to that directory anymore; if you have leftover local files there, delete them. - `apps/docs/spec/reference/README.md`: the react-server `tsx` warning cited `pnpm build:llms` as the consumer. Replaced with `pnpm embeddings`, a live script that runs under `tsx --conditions=react-server`. I verified the constraint still holds: importing `Reference.utils.ts` crashes under `--conditions=react-server` (in `next/navigation`) and loads fine under plain `tsx`. - `apps/www/pages/modules/vector.tsx`: the maintenance comment pointed at `public/llms/vector.txt`, which doesn't exist in www. The hand-maintained markdown sibling lives at `content/md/modules/vector.md`. - `.agents/skills/ask-the-docs/reference/llm-agent-parity.md`: the "In-flux / stale wiring" bullet asserted the exact `.gitignore` line this PR deletes (and its "generation path is unclear" caveat no longer holds; per-source links resolve live via `apps/www/app/llms/[slug]/route.ts`). Removed the bullet so the ask-the-docs skill doesn't report a gitignore entry that no longer exists. No behavior change; docs and comments only (plus a gitignore entry). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated the embeddings documentation to use the current `pnpm embeddings` command. - Clarified where vector module content should be maintained alongside the corresponding page. - Removed outdated references to generated per-source LLM files and retired documentation describing stale generation paths. - Improved consistency between reference documentation and the current content-generation workflow. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3338be76f0 |
fix(studio): emit sign_in on totp challenge (#49755)
The dashboard's `sign_in` event never fires when a user completes a TOTP challenge: `SignInForm` only tracks when no MFA challenge is needed, and the /sign-in-mfa page only tracks on mount when the assurance level is already satisfied (OAuth/SSO returns). Sign-ins that go through the actual MFA form were invisible to analytics, and the login audit event was missing on the same path. **Changed:** - **MFA-challenged sign-ins now tracked**: `SignInMfaForm` fires `sign_in` (reading the same `method` query param the page mount site reads) plus the login audit event on successful TOTP verification, in the sign-in context only. The forgot-password flow stays untracked: it is a reset, not a sign-in. - **Password+MFA sign-ins report `method: email`**: `SignInForm` now passes `?method=email` when routing to /sign-in-mfa instead of falling through to `unknown`. - **Partner TOTP sign-ins carry their provider**: `SignInPartner` now passes `?method=<partner>` when routing to /sign-in-mfa, matching the raw-provider-name convention the other entry points use. - **Join caveat documented**: the `SignInEvent` doc comment now notes the event is captured server-side and races the identify call, so it is not a valid funnel join key across the auth boundary. ## Linear - fixes GROWTH-1156 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added sign-in method details to MFA redirects for email and partner authentication, improving sign-in flow tracking. * Added telemetry and login auditing for successful MFA sign-ins while keeping forgot-password flows untracked. * **Documentation** * Clarified sign-in event tracking coverage, including OAuth providers, server-side capture, anonymous identifiers, and the sign-in page. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3146650a5a |
Fix FormItemLayout usages for a11y (#49761)
Follow up of #49637. Usages that impacted tests were fixed in the previous PR. This PR fixes the other usages so that label are correctly linked to their inputs. No visual changes ## How to test 1. Design system: [Form examples](https://design-system-git-fix-form-item-layout-usages-supabase.vercel.app/design-system/docs/ui-patterns/forms): moved `FormControl` around the `SelectTrigger` so that the label is linked to the button (It's actually done like this in the [Select Form example](https://design-system-git-fix-form-item-layout-usages-supabase.vercel.app/design-system/docs/components/select#form) and Radix recommend targeting the button too in their [documentation](https://www.radix-ui.com/primitives/docs/components/select#labelling)) 2. [Access tokens](https://studio-staging-463111oii-supabase.vercel.app/dashboard/account/tokens): updated usage to fallback on generated ids and fixed the select just like _1_ 3. [New TOTP factor](https://studio-staging-463111oii-supabase.vercel.app/dashboard/account/security): updated usage to fallback on generated ids 4. _Studio/Database/Extensions_ (`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/database/extensions`): updated the extension enabling modal to fallback on generated ids 5. _Studio/Integrations/Vault (`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/integrations/vault/secrets`): updated the secret edition modal to fallback on generated ids 6. _Studio/Observability(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/observability`): updated the report creation and edition modals to fallback on generated ids 7. _Studio/SQL Editor(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/sql/new`): updated the query renaming modal to fallback on generated ids 8. _Studio/Storage/Analytics(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/storage/analytics`): updated the table creation sheet to fallback on generated ids (you must have a bucket first) 9. _Studio/Workers(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/workers`): updated the worker creation modal to fallback on generated ids (you must have a bucket first) 10. Updated [Signup](https://studio-staging-463111oii-supabase.vercel.app/dashboard/sign-up?returnTo=%2Fnew), [Signin](https://studio-staging-463111oii-supabase.vercel.app/dashboard/sign-in) and [SSO Signin](https://studio-staging-463111oii-supabase.vercel.app/dashboard/sign-in-sso) forms to fallback on generated ids <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Standardized form field presentation across access tokens, authentication, reports, integrations, database extensions, SQL editor, storage, and worker deployment workflows. - Updated password fields and visibility toggles for more consistent input behavior. - Refined token expiration selection, verification code entry, and dropdown layouts. - Preserved existing labels, validation, options, and form functionality while simplifying the interface structure. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8db7368ccf |
feat(studio): clarify quick query as temporary space (#49695)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature ## What is the current behavior? Standalone queries in the Explorer "Quick Query" surface have editable titles (defaulting to "Untitled query") without clear indication that they are temporary and not saved, similar to the old SQL Editor snippet model. ## What is the new behavior? The Quick Query tab now clearly indicates that standalone queries are temporary. The title is no longer editable and displays "Temporary space for one-off queries" as static muted italic text. The default query name has been changed from "Untitled query" to "Quick query" for clarity. ## Additional context Resolves FE-4297. Notebook cells (variant === 'embedded') remain unchanged with editable titles. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Renamed new one-off queries from **“Quick query”** to **“Run SQL”** when no title is provided. * Updated viewport query editor toolbars to display the fixed **“Run SQL”** label. * Preserved editable titles for embedded query editors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4b1f93bb99 |
feat(explorer): add path back to SQL Editor for snippet access (#49698)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature ## What is the current behavior? Users who have opted into the Explorer feature preview have no way back to the SQL Editor from within Explorer, so they can't easily check their old snippets. ## What is the new behavior? - The Explorer sidebar title bar now has a button (using the same icon as the SQL Editor/Explorer nav entry) that links to the SQL Editor, with a tooltip explaining it's a temporary switch to access snippets. - Clicking it marks the visit as temporary in localStorage, which surfaces a matching "Back to Explorer" button in the SQL Editor title bar. Clicking that button clears the temporary flag and returns to Explorer. - Fixed the product menu title bar badge slot to sit flush right instead of directly next to the title text. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a quick switch from the Explorer to the project’s SQL Editor. * Added a “Back to Explorer” option in the SQL Editor when opened from Explorer. * Added tooltips to clarify these navigation actions. * Navigation state is preserved per project for a smoother return experience. * **UI Improvements** * Improved product menu spacing and title truncation for better layout handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3dddb60149 |
feat(www): publish agent discovery catalog and complete json-ld (#49768)
I added the agent-discovery surfaces the www app was missing: a resource catalog at `/.well-known/ard.json` plus completed structured data on the homepage. I scoped this from the agent-readiness gaps that are truthfully closable on the www side; the catalog lists only resources that already exist and serve 200 (MCP OAuth metadata, Management API OpenAPI spec, llms.txt, agent-skills index). **Changed:** - **Agents can discover our machine-readable resources from one document**: new static catalog at `/.well-known/ard.json` (Agentic Resource Discovery format); the legacy `/.well-known/ai-catalog.json` path serves the same file via rewrite, keeping a single source artifact. - **Organization JSON-LD carries verifiable company details**: adds `legalName`, a support `contactPoint`, and the registered address already public on our Terms of Service. - **Homepage declares the product as an application entity**: emits `SoftwareApplication` JSON-LD via the existing `softwareApplicationSchema` builder, same pattern as the vector module page. ## To test Tested on Vercel preview: - [ ] `curl <preview-url>/.well-known/ard.json`: expect 200 with a JSON catalog of 5 entries - [ ] `curl <preview-url>/.well-known/ai-catalog.json`: expect the same document with status 200 (rewrite, not a redirect) - [ ] View homepage page source: expect three `application/ld+json` scripts: Organization now includes `address` and `contactPoint`, and a `SoftwareApplication` block is present ## Linear - fixes GROWTH-1164 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added an Agent Resource Description catalog listing Supabase’s MCP, API, documentation, and agent skill resources. - Added support for the legacy AI Catalog URL through a canonical redirect. - Enhanced website structured data with software application details, legal information, support contact details, and business address. - **Tests** - Added validation ensuring discoverable `.well-known` resources are cataloged and resolve correctly. - **Chores** - Updated marketing site test coverage for `.well-known` resource changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0c8dc73bf4 |
feat(upgrade): surface btree_gist NaN reindex warning (#49684)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — studio counterpart of supabase/platform#37696 (PG 15.19/17.11 release, PSQL-1247). ## What is the current behavior? The pre-upgrade warnings panel handles `ltree_reindex_required` and `operator_estimator_gate` only. ## What is the new behavior? Adds the `btree_gist_nan_reindex` warning (title, description, docs link) emitted by the eligibility endpoint when a project has btree_gist indexes on float columns and the upgrade crosses the 15.19/17.11 NaN-handling fix. Non-blocking, same pattern as #47003. `api-v1.d.ts` union extended to match the platform spec. ## Additional context Docs anchor targets the section added in #49621 — merge that first (or together). Refs PSQL-1247. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an upgrade warning for the `btree_gist_nan_reindex` requirement. * Included a description and link to relevant documentation for guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b917b0e1bf |
feat(billing): adds non-dismissable modal for indirect tax declaration (#49643)
### Summary This PR adds a blocking dashboard modal for affected Australian customers to confirm their GST registration and business use of Supabase. KPMG requires us to collect this declaration from certain existing Australian customers. The backend now identifies organizations that still need to respond using `requires_indirect_tax_declaration` and stores their `yes` or `no` response in Orb customer metadata. It also supports email links with `submit_indirect_tax_declaration=true` and shows a dismissible confirmation when the organization has already responded. ### Testing #### Manual testing - Confirmed the modal appears for an affected organization without an existing response and cannot be dismissed. - Submitted both `yes` and `no` and confirmed the modal remains closed after a refresh. - Confirmed the declaration is stored without changing the customer's Tax ID. - Confirmed the modal does not appear for non admins/owners or organizations that do not require a declaration. - Confirmed the email-link parameter shows the already-submitted confirmation only for organizations that have responded, and is removed when dismissed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an indirect tax declaration dialog for eligible Australian organizations. * Users with billing permissions can select “Yes” or “No” and submit their declaration. * Added a dismissible confirmation for declarations submitted through a linked prompt. * The dialog requires an explicit response and provides guidance when no option is selected. * **Bug Fixes** * Declaration prompts remain visible through submission confirmation and close when dismissed. * Users without billing permissions do not see the dialog. * Success notifications no longer overlap with the confirmation dialog. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Julian Domke <68325451+juleswritescode@users.noreply.github.com> |
||
|
|
2681a21f5c |
docs: add Personal Access Tokens guide with generated permission tables (#49732)
Add a guide that compares classic and scoped personal access tokens, explains how account roles constrain token permissions, and walks through creating and testing a project-scoped token. Include generated tables mapping permissions to Management API endpoints and MCP tools, and link the guide from docs navigation and Studio token sheets. Move the scoped-token permission catalog from Studio into shared-data. Studio and docs generation now share permission names, categories, descriptions, risk metadata, modes, scopes, and display order. Generate the tables from the shared catalog, OpenAPI x-fga-permissions, and the downloaded MCP permission map. Exclude Workers permissions until the feature is live. Run regeneration through the docs Makefile, verify checked-in output in CI, and refresh it in the weekly Management API workflow. Add Dashboard and Docs ownership plus contributor guidance so permission changes stay synchronized. |
||
|
|
b278b1ec8a |
fix(studio): Debug with Assistant and Copy prompt work (#49690)
## Summary
* Resolved hanging buttons in Explorer's QueryResultError panel that
were wired to stub no-ops (`buildPrompt={() => ''}`,
`onOpenAssistant={() => {}}`).
* "Debug with Assistant" now opens a new chat seeded with a real prompt
combining the SQL query and error context using existing
`buildDebugPromptText` util and `useCreateChat` hook.
* "Copy prompt" now copies the same real debug prompt text to clipboard.
* Threaded `sql` and query `source` props down through `QueryEditor` →
`QueryResultRenderer` → `QueryResultError` while keeping them optional
for backward compatibility with other callers like
`AssistantNotebookPreviewCell`.
## Test plan
- [X] Run `pnpm typecheck` — passes
- [X] Run `pnpm lint --filter=studio` — passes
- [X] Run `pnpm test:studio --run
apps/studio/components/interfaces/Explorer/QueryEditor` — Explorer
vitest suite (99 tests across 13 files) passes with no regressions
- [X] Manually verify in Explorer: trigger an ad-hoc SQL query that
fails, confirm "Debug with Assistant" opens a new chat with the error
prompt seeded, and "Copy prompt" copies the prompt to clipboard
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Added “Debug with Assistant” to query errors using the submitted SQL
and error details.
- Added an option to copy the debugging prompt for easier
troubleshooting.
- Assistant actions are hidden when query details are unavailable or
restricted.
- **Bug Fixes**
- Ensured query errors reference the SQL that produced them, rather than
later editor changes.
- **Tests**
- Added coverage for assistant debugging, prompt copying, conditional
visibility, and self-hosted behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
02cf09212e |
chore: Remove tsconfig paths (#49770)
This PR removes all `paths` in `tsconfig.json` for all apps and packages. They were added previosly because some of the components had a `_Shadcn` suffix because of an ongoing migration. How that the migration is done, the paths can be removed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized shared UI component, utility, and icon imports across design-system examples and application screens. * Simplified shared component access and project configuration. * Added shared access to anchor-link helpers and animation styles. * **Compatibility** * Updated component exports and imports without changing existing behavior. * No changes to user-facing workflows, screens, or functionality. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
911a6c2482 |
fix(workers): rename image version label FE-4317 (#49810)
## Problem The Workers UI exposed the internal image terminology in the displayed version label. ## Fix Rename the Worker detail header and Container setting label to Version while preserving the underlying API field. ## How to test - Open a Worker detail page with an image version. - Expected result: the header reads Version <number> and the Container row label reads Version. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated worker details labels from “Image” and “Image version” to “Version” for clearer, more consistent terminology. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5d9f94e8cf |
fix(workers): update CLI call instructions FE-4316 (#49808)
## Problem The Workers overview showed deployment CLI instructions in the How to call section, while direct gateway calls do not require an API key. ## Fix Add a dedicated unauthenticated cURL snippet for the overview CLI tab and preserve the deployment CLI snippet in the deploy dialog. ## How to test - Open a Worker overview and select the CLI tab. - Expected result: the copied cURL request targets the gateway URL and has no Authorization header. - Open the deploy dialog. - Expected result: the deployment CLI commands remain unchanged. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a cURL example for invoking Workers. - Updated the “How to call” section to display cURL, JavaScript, and Python examples. - cURL snippets now include the worker URL and request body. - **Bug Fixes** - Improved snippet URL handling and clarified authorization behavior in CLI examples. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6e39b17d3c |
Merge pull request #49543 from ayaangazali/docs/studio-tanstack-checklist-missing-routes
docs(studio): add the 8 missing routes to the TanStack migration checklist |
||
|
|
cd34776be1 |
fix(studio): honor MAINTENANCE_MODE in the TanStack runtime (#48616)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Fixes #48559 (diagnosed by @ayaangazali) The TanStack Start runtime never applies maintenance mode. `matchRedirect` in `apps/studio/redirects.shared.ts` takes a `maintenanceMode` flag, and both other consumers wire it from the environment: - `apps/studio/next.config.ts` — `process.env.MAINTENANCE_MODE === 'true'` - `apps/studio/vercel.ts` — same The TanStack call site in `apps/studio/routes/__root.tsx` passed only `pathname`, `search`, `isPlatform` and `hash`, so `maintenanceMode` fell back to its `= false` default. With `MAINTENANCE_MODE=true` on a TanStack deploy that produced two wrong behaviors: 1. No path redirected to `/maintenance` — the app served normally during maintenance. 2. Because the flag read false, the "not in maintenance" branch still applied and sent `/maintenance` → `/`, making `routes/maintenance.tsx` unreachable. Mainly affects self-hosted / Node-server TanStack deploys; the platform deploy is covered by the Vercel edge layer, which does wire the flag. ## What is the new behavior? The TanStack runtime honors `MAINTENANCE_MODE` the same way the Next runtime and the edge config do. **Design note.** The issue asked whether this needs a new `NEXT_PUBLIC_` variable or server-side plumbing, since both would change deployment configuration for self-hosters. Neither is needed. `MAINTENANCE_MODE` is already a *build-time* variable in both existing consumers — Next bakes `redirects()` into `routes-manifest.json` during `next build`, and `vercel.ts` reads it while emitting `vercel.json`. Toggling maintenance has always required a rebuild, never just a server restart. And `vite.config.ts` isn't bound by Next's "only `NEXT_PUBLIC_`" rule: it controls `define` directly, and already re-exposes unprefixed `VERCEL_*` vars the same way. So the existing unprefixed variable is inlined at build time, giving exact parity with **no new env var and no config change for self-hosters**. Three changes: 1. `vite.config.ts` — inline `process.env.MAINTENANCE_MODE` into the bundle. Falls back to `''` rather than being left undefined, so the browser bundle never ends up with a bare `process.env` reference (the failure mode the file already guards against for the Sentry vars). 2. `routes/__root.tsx` — read it into `IS_MAINTENANCE_MODE` and pass it to `matchRedirect`. 3. `redirects.shared.test.ts` — 4 tests for the maintenance branches of `matchRedirect`, which had no coverage at all. `turbo.jsonc` already lists `MAINTENANCE_MODE` under the build task's `env`, so cache invalidation is correct for the Vite build too — no change needed. No README or docs change either, since the env contract is unchanged. ## Additional context Verified end-to-end, not just by unit test. **Browser repro** — built SPA served via `scripts/serve.js`, driven in headless Chromium: | `MAINTENANCE_MODE=true` | lands on | | | --- | --- | --- | | `/project/default` | `/maintenance` | fixes behavior 1 | | `/` | `/maintenance` | | | `/maintenance` | `/maintenance` | fixes behavior 2 | The maintenance page renders real content ("Under Maintenance — We are currently improving our services…"), so the route is genuinely reachable. | control, var unset | lands on | | | --- | --- | --- | | `/project/default` | `/project/default` | normal routing intact | | `/` | `/project/default` | root redirect intact | | `/maintenance` | `/project/default` | correctly bounces away | **Bundle inspection** — the flag compiles to a literal `true` with the variable set and `false` without it, confirming the define reaches the client. **Shell prerender** — checked explicitly, since the maintenance-on rule is a catch-all. Builds with `MAINTENANCE_MODE=true` prerender the SPA shell and pass the post-build smoke test; the prerenderer crawls `/` and the root `beforeLoad` redirect does not fire during shell generation, so no guard is required. **Checks** — 20 unit tests pass, typecheck 8/8, ESLint ratchet passes, Prettier clean. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added maintenance-mode routing for unavailable pages. - Preserves query parameters and URL fragments during redirects. - Allows access to maintenance and image paths while maintenance mode is active. - Automatically returns visitors to the home page when maintenance mode is disabled. - Maintenance behavior is controlled by the deployment configuration. - **Tests** - Added coverage for maintenance-mode redirects, URL preservation, and exceptions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
4ab1a6cbd2 |
chore(docs): add Sean Geoghegan to humans.txt (#49802)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Adding myself to humans.txt ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Sean Geoghegan to the alphabetical team list in the project credits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bf60e6cdce |
feat(library): serve agent-readable markdown for each docs page (#49567)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature: agent-readable markdown pages for the UI library docs. ## What is the current behavior? Library docs are HTML-only. `llms.txt` lists page titles, but there is no `.md` body an agent can fetch. ## What is the new behavior? Each docs page is also served as markdown: - Build-time MDX → markdown (`pnpm --filter library build:markdown`) - `GET /library/docs/{slug}.md` (and `Accept: text/markdown`) - HTML pages advertise `rel=alternate` `text/markdown` - `llms.txt` links to the `.md` URLs This is the base of a stack. The prompt-tab PR sits on top: https://github.com/supabase/supabase/pull/49566 ## Additional context Interactive previews are omitted from the markdown. `BlockItem` emits the production `npx shadcn add` command so agents still get an install path. ## To test 1. `pnpm --filter library dev` (generates markdown in `predev`). 2. Open http://localhost:3004/library/docs/nextjs/password-based-auth.md — markdown with the install command, file tree, and setup steps; no interactive previews. 3. Open the same path without `.md` — HTML docs unchanged (no prompt tab in this PR). 4. `curl -H 'Accept: text/markdown' http://localhost:3004/library/docs/nextjs/password-based-auth` should also return markdown. 5. http://localhost:3004/library/llms.txt — links should end in `.md`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Documentation pages are available as Markdown through `.md` URLs and a dedicated endpoint. * Markdown is generated automatically during development and production builds. * Generated content preserves front matter, links, callouts, installation instructions, and supported documentation elements. * Installation commands support npm, pnpm, yarn, and bun for React and Vue projects. * **Bug Fixes** * Improved Markdown file handling, link rewriting, and content negotiation. * **Tests** * Added coverage for Markdown conversion, content negotiation, and installation commands. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Saxon Fletcher <SaxonF@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
eea39cc316 |
fix(studio): register pitr_archiving_stale in the advisor lintInfoMap (#48044)
## Summary Studio's Advisor UI reads lint metadata from a fixed `lintInfoMap`, not from the API response. A lint name missing from that map shows a blank title, no icon, no filter checkbox, and no remediation link. This PR adds a `pitr_archiving_stale` entry to `lintInfoMap`, copied from the existing `pitr_not_enabled` entry, so the new lint renders correctly in the Advisor UI. ## Dependencies > [!WARNING] > [supabase/platform#35862](https://github.com/supabase/platform/pull/35862) defines the `pitr_archiving_stale` lint. Until it merges, the API never sends this lint name, so the Advisor grid and the public `/v1/projects/{ref}/advisors/security` response never show the new row -- but the Security Rules page (`/project/<ref>/advisors/rules/security`) renders one row per `lintInfoMap` entry regardless of the API, so this PR's new row appears there immediately, before the backend lint exists. See Details for what that means in the gap between merges. --- <details> <summary>Details</summary> - A lint name missing from `lintInfoMap` has these effects: - The grid row shows a blank title and no icon. There is no fallback to the API's own `title`. - The row has no filter checkbox. Filter options come from `lintInfoMap`, not from the API. - The row has no lint-specific remediation link. The "Learn more" link falls back to the generic database-linter page. - The row does not appear in the Advisor Rules enable/disable list. - The new `pitr_archiving_stale` entry copies the existing `pitr_not_enabled` entry's `link`, `docsLink`, and `category`, and uses a new `title` matching [supabase/platform#35862](https://github.com/supabase/platform/pull/35862)'s lint definition verbatim. Its `name` also matches that lint definition exactly. - **Known gap, until the backend PR merges:** `AdvisorRules` (`components/interfaces/Advisors/AdvisorRules.tsx`) filters `lintInfoMap` by `category` alone, with no dependency on the API returning the lint -- so this entry makes a "PITR archiving may be broken" row appear on the Security Rules page for every project right away, ahead of the backend lint actually existing. From that row, a user can open `CreateRuleSheet` and submit a disable rule, which `POST`s `lint_name: 'pitr_archiving_stale'` to the notification-exceptions endpoint. That name is not yet in the generated `CreateNotificationExceptionsBody` enum (`packages/api-types/types/platform.d.ts`), so the request either errors or stores an exception keyed to a lint name nothing will ever match, until api-types regenerates after the backend PR ships. This window closes on its own once [supabase/platform#35862](https://github.com/supabase/platform/pull/35862) merges; accepted as a short-lived tradeoff rather than gating this PR on merge order or adding code to hide the row until then. - The docs anchor (`#point-in-time-recovery`) explains what PITR and WAL-G archiving are. It does not explain how to fix a stale or broken archive. That content does not exist yet in either pull request. INDATA-1149 tracks this as a follow-up. - `packages/api-types/types/platform.d.ts` is a generated file. This repo's own CLAUDE.md says never to hand-edit it. The file does not list `pitr_archiving_stale` yet, because it regenerates only after the backend lint ships and `pnpm api:codegen` runs. Until then, `LintInfo['name']` stays a plain `string`. If someone misspells the new entry's `name`, the code still compiles and the tests still pass. At runtime, the icon and docs link fall back silently instead of failing a build. Once [supabase/platform#35862](https://github.com/supabase/platform/pull/35862) merges and api-types regenerates, `LintInfo['name']` must tighten to the generated `LINT_TYPES` union. This closes the gap for every lint entry, not only this one. </details> --- <details> <summary>Testing</summary> - `pnpm --filter=studio test Linter.utils.test.tsx` (17 passed, including a test that asserts the `pitr_archiving_stale` entry's shape) - `pnpm typecheck --filter=studio` (clean) - `pnpm exec eslint` on the touched files (clean; the `pnpm lint --filter=studio` turbo wrapper itself errors on this machine with an unrelated JSON-parse failure -- a tool-invocation issue, not a lint finding) - `prettier --check` on the touched files - The `docsLink` assertion (`toContain('/guides/platform/backups#point-in-time-recovery')`) is domain-agnostic by construction, so it holds regardless of which `NEXT_PUBLIC_DOCS_URL` value is set -- no test in this file overrides that variable, this is a property of the assertion's own shape, not a scenario the suite exercises </details> --- <details> <summary>Misc</summary> - Part of INDATA-979 - Changelog: [supabase/changelog#192](https://github.com/supabase/changelog/pull/192) </details> |
||
|
|
b885b69bff |
feat(studio): restore workers secrets page FE-4280 (#49762)
## Problem Workers Secrets was merged in #49589 into the stacked jordi/workers-detail branch. The parent Workers PR reached master without that child merge, leaving the page absent from staging. ## Fix Cherry-pick the missing Workers Secrets route, menu item, shared-secret copy, and generated route tree onto current master. The page uses the existing workers flag and permission gates. ## How to test - Enable the workers flag for a project with Workers access. - Open Workers, then select Secrets. - Expected result: the shared project secrets page renders at /project/:ref/workers/secrets and is not treated as a worker named secrets. - Add, edit, or delete a secret, then confirm the same value appears under Edge Functions, Secrets. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a **Secrets** page to the Workers section. * Added navigation to Worker secrets from the Workers menu. * Displayed default secrets and deployment-specific guidance where applicable. * Clarified that platform secrets are shared between Edge Functions and Workers. * Updated deletion warnings to reflect shared secret usage. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5d5b3b2aa8 |
[FE-4278] fix(studio): allow broadcast before any realtime message arrives (#49792)
In the Realtime Inspector, the messages view — which holds every
"Broadcast a message" entry point — only rendered once at least one
message had been received. With only Broadcast enabled and no inbound
traffic, the page stayed on the "Create realtime experiences" onboarding
forever, so there was no way to send a broadcast at all.
The render gate now keys off a channel being set rather than
`logData.length`: once you join a channel, `MessagesTable` renders and
its existing empty states provide the send entry points ("Listening • No
message found yet…" toolbar + the "No Realtime messages found" panel).
The onboarding remains the pre-channel state.
Addresses
[FE-4278](https://linear.app/supabase/issue/FE-4278/realtime-inspector-cant-send-broadcast-without-incoming-messages).
## To test
- Realtime → Inspector, before joining a channel: the "Create realtime
experiences" onboarding still shows
- Join a channel (with Presence off / Broadcast only so nothing
arrives): the listening view renders immediately with "No message found
yet…" and "Broadcast a message" in both the toolbar and the empty-state
panel — previously this was stuck on the onboarding
- Click "Broadcast a message" and send with defaults: the broadcast
appears in the grid
- Stop listening: no crash, messages retained
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* The Realtime Inspector now displays the messages view as soon as a
channel is selected.
* Empty-state guidance, including the option to broadcast a message, is
now available before any messages arrive.
* Pre-channel onboarding remains visible until a channel is configured.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
|