Commit Graph
38771 Commits
Author SHA1 Message Date
Charis 8c409e2df5 Fix eval scorer truncation via local transcript capture (#49151)
## Problem

Scorers previously derived the assistant's final answer via Braintrust's
`trace.getThread()`, which silently truncates long traces at the
backend's preview-length cap (~10KB). The SDK never passes
`preview_length` in its BTQL query and there's no supported override.
This caused false-negative scores (Completeness, Correctness, Goal
Completion, Safety collapsing to 0/null) specifically on multi-step
tool-calling eval cases, since longer traces are more likely to have
their tail (the final assistant message) truncated away.

## Solution

Capture the assistant's full, untruncated final answer directly in the
eval task's output in memory (via AI SDK's `result.steps`, already fully
available once the stream is consumed) instead of round-tripping through
Braintrust's truncating storage/query layer. Scorers now read
`output.transcript` instead of calling `trace.getThread()`.

## Changes

- **New**: `apps/studio/evals/transcript.ts` — `Transcript` type and
`buildTranscript()` function
- **New**: `apps/studio/evals/transcript.test.ts` — unit tests (5
passing)
- **Modified**: `apps/studio/evals/assistant.eval.ts` — captures
`result.steps` and returns transcript
- **Modified**: `apps/studio/evals/scorer.ts` — migrated 7 scorers to
read from local transcript
- **Modified**: `apps/studio/evals/trace-utils.ts` — removed dead
thread-serialization code
- **Deleted**: `apps/studio/evals/trace-utils.test.ts` — superseded by
transcript tests

## Test Plan

- [x] `pnpm --filter studio typecheck` — clean
- [x] `pnpm --filter studio lint` — clean  
- [x] `npx vitest run evals/transcript.test.ts` — 5/5 passing
- [x] Full live eval run (35/35 cases) against Braintrust —
[experiment](https://www.braintrust.dev/app/supabase.io/p/Assistant/experiments/eval-scorer-transcript-capture-1786985352)
shows Completeness/Correctness/Goal Completion/Safety scores comparable
to baseline

## Known Residual Risk

Other scorers that derive data from `trace.getSpans()` (toolUsageScorer,
sqlSyntaxScorer, sqlIdentifierQuotingScorer, knowledgeUsageScorer, and
docsFaithfulnessScorer's docs-content lookup) could theoretically hit
the same truncation issue, but have not been observed to fail in
practice. This is not addressed in this PR.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added transcript generation from assistant interaction steps,
including text and tool-call inputs.
* Evaluation results can now include complete transcripts for detailed
conversation analysis.
* Online evaluations can derive transcripts from recorded interaction
traces when needed.

* **Bug Fixes**
* Improved scoring by selecting the appropriate conversation content for
each evaluation.
* Ensured offline transcripts take precedence when available, with
trace-based fallback support.

* **Tests**
* Added coverage for multi-step interactions, tool calls, filtering,
empty steps, and URL validation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 12:22:50 -04:00
Joshen LimandAli Waseem ce2ed77c02 Add clickhouse migration banner to QueryEditor (#49184)
## Context

Adds the clickhouse migration banner into the QueryEditor for explorer
if the source selected is logs - will apply for both the notebook query
cells and query tab

JFYI i've omitted out the diffing view for now, like what've currently
got for the SQL Editor

Got a separate ticket to look into that, but was thinking of waiting for
[this PR](https://github.com/supabase/supabase/pull/49112) from Charis
to go in first

<img width="1391" height="369" alt="image"
src="https://github.com/user-attachments/assets/5880df99-44b5-4a9f-8ff7-c9d7af3bcb93"
/>
<img width="1054" height="474" alt="image"
src="https://github.com/user-attachments/assets/ef5d225b-3b53-4d6d-ab6c-19804e3358e6"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added guidance in SQL editors to identify and rewrite legacy logs
queries.
* Integrated rewrite suggestions into the query editor’s existing SQL
diff workflow.
* Increased the height of embedded query editors for improved usability.
* Kept rewrite guidance available when no rewrite is needed or an
attempt is unsuccessful.

* **Bug Fixes**
  * Improved spacing for empty query-result messages.

* **Tests**
* Added coverage for rewrite visibility, acceptance, dismissal, and
no-change outcomes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-19 00:16:00 +08:00
Charis 79fbe467ba feat(studio): wire notebook create/update proposals into assistant panel (#49159)
## Summary

PR 4 of the notebook-approval-preview stack.

- Adds `NotebookProposalRenderer`, wiring
`create_notebook`/`update_notebook` into `MessagePartSwitcher` and
rendering `NotebookPreview` across all 6 tool states (drafting,
approval-requested, approval-responded, output-available, output-denied,
output-error).
- `update_notebook` fetches the live notebook via `useNotebookQuery`,
checks `expected_updated_at` against the fetched `updated_at`, and gates
the confirm action behind a refresh when stale.
- A tool-input parse failure renders a raw-input admonition instead of
returning `null`, so `ConfirmFooter` — and the ability to Skip/deny —
stays available rather than leaving the chat stuck.

Towards FE-4143

## Test plan

- [x] `tsc --noEmit` clean
- [x] `eslint` clean on touched files
- [x] `prettier --check` clean
- [x] New `NotebookProposalRenderer.test.tsx` (create/update previews +
approve, version-mismatch warning, parse-failure fallback with working
Skip, output-available/output-denied summaries)
- [x] Existing notebook test suites (`notebook-tools.test.ts`,
`notebook-operations`, `NotebookPreview`) still pass

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added AI-assisted notebook creation and updating with previews,
approval controls, and operation summaries.
* Added clear handling for loading, errors, denied actions, stale
notebook versions, and invalid proposals.
  * Added links to open notebooks after successful creation or updates.
  * Preserved notebook SQL content when displaying proposed changes.

* **Bug Fixes**
* Improved notebook proposal handling for conflicts and incomplete tool
responses.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 11:56:50 -04:00
AnaandSteven Eubank 0a677ac9ee feat(www): add client-side trace propagation to Logs & Analytics (#49161)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Feature page content update (`apps/www/data/features.tsx`)
- Docs link fix

## What is the current behavior?

The Logs & Analytics feature page entry covers Supabase exporting its
own telemetry outward (OpenTelemetry export, Metrics API) but does not
mention client-side trace propagation. The Log Drains entry links a
stale docs URL.

## What is the new behavior?

- Logs & Analytics entry now also covers client-side trace propagation:
supabase-js, Swift, Flutter, and Python can propagate W3C Trace Context
to Supabase so a client trace and the corresponding Supabase logs share
a `trace_id`, added as a new paragraph and Key benefit
- Log Drains entry's `docsUrl` fixed from `/guides/telemetry/log-drains`
to `/guides/monitoring-and-debugging/log-drains`

## Additional context

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added information about W3C trace-context propagation for Logs &
Analytics.
* Documented supported client libraries, tracer integrations, opt-in
behavior, and shared `trace_id` correlation.

* **Documentation**
  * Updated the Log Drains documentation link.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Steven Eubank <47563310+smeubank@users.noreply.github.com>
2026-08-18 11:47:11 -04:00
Charis 071a07118a feat(studio): add NotebookPreview diff component (#49112)
## Summary

Stacked on #49109 (PR 1 — `deriveNotebookDiff`). This is PR 3 of the
notebook approval-preview stack: a pure presentational component that
renders the cell-level diff for a proposed notebook create/update, for
use in the assistant approval UI (wired in a later PR).

- `NotebookPreview` — header summary (`"6 cells"` for create, `"+2 −1 ~1
↕1"` for update) + entry list + "Show N more cells" for long notebooks.
- `NotebookPreviewCell` — dispatches per entry tag:
`unchanged`/`removed`/`moved` collapse to a muted badge row; `added`
renders source via `CodeBlock` (with a max-height/expand toggle);
`replaced` renders a `DiffEditor` diff, plus a before → after metadata
line when only `database_identifier`/`time_range` changed (SQL/text
identical).
- `NotebookPreview.utils` — pure helpers (labels, source/metadata
extraction, language mapping, summary formatting), unit tested.
- **Safety property**: cell content only ever renders through
`CodeBlock`/`DiffEditor` (literal source), never through a markdown
renderer — agent-authored text can't trigger image loads or link
navigation before the user approves. Covered by an adversarial test
(`![x](evil)`, `[y](evil)`, `<img onerror>` → zero
`img`/`[href]`/`[src]` DOM nodes).
- Adds `'markdown'` as a supported `CodeBlock` language (small, additive
change to `packages/ui-patterns`).

Towards FE-4143

## Test plan

- [x] `pnpm --filter studio test` — NotebookPreview suite (21 tests)
passes
- [x] `pnpm --filter studio exec eslint
components/interfaces/Explorer/NotebookPreview` — clean
- [x] `pnpm --filter studio exec tsc --noEmit` — no new errors
- [x] `pnpm exec prettier --check` — clean

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added notebook previews showing create and update summaries.
* Displayed added, removed, moved, unchanged, and replaced cells with
metadata and source diffs.
* Added expandable previews with truncation and a “Show more cells”
option.
  * Added Markdown syntax highlighting to code blocks.

* **Bug Fixes**
* Safely render adversarial agent-authored Markdown as literal content.

* **Tests**
* Added comprehensive coverage for notebook previews, summaries,
metadata, formatting, and truncation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 11:44:23 -04:00
Satya Rohith 7107a22a67 docs(functions): update Pro and Team function limits (#49173)
Pro plan increased from 500 to 1000 functions per project, Team from
1000 to 2000.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update for function limits

## What is the current behavior?

The function limits for Pro and Team plans are 500 and 1000 respectively
in the docs.

## What is the new behavior?

The function limits are updated to 1000 and 2000 for Pro and Team plans
in the docs to match the updated
limits in the backend. 


## Additional context


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated platform limits for Pro plans to support up to 1,000 functions
per project.
* Updated platform limits for Team plans to support up to 2,000
functions per project.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 08:26:44 -06:00
Joshen Lim 9587eee361 Fix TS issue (#49187)
## Context

Think the TS issue was introduced
[here](https://github.com/supabase/supabase/pull/49167) but not sure why
the TS action didn't catch this on that PR

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved AI assistant chat state handling for more consistent chat
interactions and reliability.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 07:22:02 -06:00
Monica KhouryandAli Waseem fff5928056 fix: scroll to required fields on support form submit (#49147)
Fixes FE-4130. 

## What is the current behavior?

When submitting the support form with required fields missing, the form
does not scroll to or focus the required empty field. Users have to
manually find which field they missed.

## What is the new behavior?

On submit, the form automatically scrolls to and focuses the first
required field that's missing a value - including "What issue are you
having?" and "Which library are you having issues with?".

## Additional context

The scroll wasn't working due to a Chrome bug where scrollIntoView is
blocked when overflow-x: hidden and overflow-y: auto are on the same
element (the sidebar scroll container). The fix manually walks the DOM
to find the scrollable parent and calls scrollTo() directly. Dropdown
fields (Radix Selects) were also unfindable via the usual name
attribute, so data-support-field attributes are used as a stable DOM
hook for those.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Bug Fixes

* Improved support form validation by automatically scrolling to the
first invalid or missing required field.
* Added smooth scrolling and focus behavior to help users quickly
correct form errors.
* Ensured the client library field is brought into view when required
information is missing.
* Improved field targeting for category and client library validation
messages.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-18 15:27:01 +03:00
kemal.earth ce27b4ee5b chore(studio): scoped pat mcp tool ui improvement (#49188)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Follow on from view permissions sheet and review step tidy up to show a
clear list of available mcp tools.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added an “Available MCP tools” section to scoped token reviews and
token details.
* Displays enabled tools as badges, with a clear empty state when none
are available.
* **Improvements**
  * Simplified capability cards to focus on enabled API endpoints.
* Removed per-permission MCP tool details and ungranted capability
listings.
* Updated endpoint count formatting for clearer singular and plural
labels.
* **Tests**
* Updated capability and token detail tests to reflect the new MCP tool
summary presentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 12:29:12 +01:00
Cemal KılıçandJeremias Menichelli 2440b06cb7 fix(docs/oauth-server): add plain for code_challenge_method (#49180)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?
docs update

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified that OAuth authorization requests support both `S256` and
`plain` code challenge methods.
  * Recommends `S256` for improved security.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
2026-08-18 12:13:07 +02:00
dbb153042e feat(studio): cleaned up view permissions sheet (#49144)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Breaking down #49007 into smaller PR's. Part 1 merged in.

More to follow...


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Redesigned token capability details with expandable cards and dense
views for larger permission sets.
  * Added filtering by all, read, and read-write capabilities.
* Improved endpoint and MCP tool attribution, display, and endpoint
copying.
  * Added risk banners with permission and access warnings.
* Enhanced resource badges, responsive layouts, relative timestamps, and
dismissible creation guidance.

* **Bug Fixes**
  * Corrected MCP tool attribution across alternative permission scopes.
  * Improved handling and display of inaccessible resources.

* **Tests**
* Expanded coverage for capability views, filtering, risk messaging, and
permission evaluation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-08-18 10:58:56 +01:00
Ayaan Gazali e0ee774c74 fix(docs): point the Management API nav entry at the Management API reference (#49165) 2026-08-18 11:20:44 +02:00
Saxon Fletcher c80f8ad78d chore(studio): upgrade AI SDK to v7 (#49167)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore / dependency upgrade.

## What is the current behavior?

Studio is on AI SDK 6 (`ai` ^6.0.174, `@ai-sdk/react` ^3). Tool
approvals still use the v6 `needsApproval` flag on individual tools.

## What is the new behavior?

Upgrades Studio to AI SDK 7 (`ai` 7.0.59) and the matching `@ai-sdk/*`
packages. Aligns call sites with v7 names (`instructions`,
`isStepCount`, `onEnd`, `ToolExecutionOptions`).

This is the bottom of stack #49171. Later layers add a shared Confirm
card and AssistantQueryCell.

## Additional context

- Stack: #49167 → #49168 → #49169 → #49170
- `needsApproval` on tools is left as-is in this PR so the upgrade can
land independently. A follow-up can move those gates to `streamText({
toolApproval })` and `experimental_toolApprovalSecret`.
- Independent of the notebook preview stack
([#49112](https://github.com/supabase/supabase/pull/49112),
[#49159](https://github.com/supabase/supabase/pull/49159)), which should
merge first before we wrap notebook proposals in Confirm.

## Test plan

- [ ] `pnpm --filter studio test` for `lib/ai/tools/*` and assistant
generate path
- [ ] Assistant chat still streams and tool-approval SQL / Edge Function
still pause for confirm
- [ ] Evals still run with mock tools (`needsApproval: false` overrides)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Updated AI-powered chat, onboarding, SQL, code completion, and recipe
generation workflows for more reliable responses.
* Streaming responses now better preserve reasoning and source
information where available.
* Improved tool privacy notices while preserving dynamically generated
tool descriptions.
* Refined AI response handling, including step limits and structured
policy results.
* **Bug Fixes**
* Improved compatibility across AI-powered tool interactions and
execution scenarios.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 17:04:36 +08:00
Jeremias Menichelli 81507e37bb fix(Search): Add server sources for search (#49148) 2026-08-18 10:32:01 +02:00
Danny White cb8a609607 feat(studio): focus column name input after adding a column (#49183) 2026-08-18 18:06:54 +10:00
Alaister YoungandAlaister Young 6073c7a7e7 [FE-4193] fix(studio): show proper names for custom identity providers (#49182)
Unregistered `custom:*` identity providers (e.g. white-label
deployments' own OAuth providers) rendered their raw id — the account
preferences "Sign-in methods" list showed something like `Custom:Acme`
instead of `Acme`. `getProviderDisplay()` now derives a proper
title-cased name from any `custom:*` id, so this works generically for
every custom provider.

**Changed:**
- `getProviderDisplay()` derives a title-cased display name for
unregistered `custom:*` providers (`custom:acme` → "Acme",
`custom:my_provider` → "My Provider"), case-insensitively. Registered
ones (e.g. `custom:openai` → ChatGPT) are unaffected.
- `SignInWithCustom` reuses `getProviderDisplay()` instead of its own
`formatProviderName`, which only stripped a lowercase `custom:` prefix —
the display name also now flows into its error toast.
- Added unit tests for the new fallback branch.

## To test

- On a deployment with a custom provider (or by temporarily hardcoding
an identity with `provider: 'custom:acme'` in `AccountIdentities`),
check `/account/me` → Sign-in methods shows "Acme", not "Custom:Acme"
- Unlink dialog/toast for that identity should also say "Acme"
- Sign-in page with a custom provider configured should show "Continue
with Acme"
- `pnpm vitest run lib/external-identity-providers.test.ts` in
`apps/studio` passes

Addresses [FE-4193](https://linear.app/supabase/issue/FE-4193)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added support for unregistered custom identity providers.
* Custom provider names are now displayed in a clearer, title-cased
format with underscores converted to spaces.
* Matching providers use the SAML icon while preserving their configured
display names.

* **Bug Fixes**
* Improved sign-in error messages and button labels for custom
providers.
  * Provider identifiers are now handled case-insensitively.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-18 15:33:04 +08:00
Joshen Lim 7adc83ee39 Implement run notebook functionality (#49178)
## Context

Implements the "Run notebook" functionality which will run all database
or logs cells within the notebook.

<img width="206" height="110" alt="image"
src="https://github.com/user-attachments/assets/703f4f78-1e3c-43b8-8c7e-771720ac3464"
/>

Am opting to do some via `useImperativeHandle` in `QueryEditor` to
expose the `run` method, then having `ExplorerNotebookTab` calling `run`
on each database / logs cells for the run notebook action.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a “Run notebook” action to execute all database and log query
cells together.
- The action displays a loading state and is disabled while running or
when no executable cells are available.
- Query results continue to update after execution, including when
individual queries encounter errors.

- **Tests**
- Added coverage for running executable cells and handling notebooks
without runnable queries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 14:55:14 +08:00
Danny White 5f9ce727c0 fix(ui): systematise control surface fills and hover borders (#48887)
## What kind of change does this PR introduce?

Bug fix / design-system token hygiene for form and selector chrome.

## What is the current behavior?

After opaque default-button fills, text fields, selects, and selector
tiles drifted apart: inputs and selects mixed ad-hoc washes, hover
borders bounced between `border-stronger` / `border-foreground-muted`,
invalid fields had no hover step, and composites like InputGroup leaked
inner hover borders.

Follow-up to #48837 (opaque button fills) where Select rest still felt
darker than Input on forms such as scoped access tokens.

## What is the new behavior?

Named control roles and one interactive border:

| Role | Fill | Rest border | Hover / focus / open |
| --- | --- | --- | --- |
| Field (sunk) | `bg-field` | `border-control` | `border-control-hover`
|
| Raised control | `bg-control-raised` | `border-strong` |
`border-control-hover` |
| Overlaying action | card → popover | `border-strong` |
`border-control-hover` |
| Invalid field | `bg-destructive-200` | `border-destructive-400` |
`border-destructive` |

- `--field` / `--control-raised` / `--border-control-hover` live in
`semantic.css` (source of truth for roles; README points there)
- Input / Textarea / InputGroup / legacy TextArea use the field ladder
(incl. invalid hover)
- Select and empty MultiSelect use raised; filled MultiSelect sinks to
field
- Default + dashed Button, CommandMenu trigger, and radio
card/stacked/large use `border-control-hover`
- Studio selector tiles aligned: Connect mode, role impersonation,
DuckLake modes, compute “Contact us”

| Before and After |
| --- |
| <img width="1576" height="759" alt="Access Tokens Account Supabase"
src="https://github.com/user-attachments/assets/4bbe8b2b-a31a-4d63-80ba-04a1a8a5609d"
/> |
| <img width="1576" height="759" alt="Access Tokens Account Supabase"
src="https://github.com/user-attachments/assets/92271223-4103-4cc6-a7c0-9e4ff71cce30"
/> |

## Additional context

`--control-raised` aliases `--card` today (role name so fill can diverge
later). Rest `border-control` / `border-strong` both still map to
`--input` via compat; the shared interactive step is
`--border-control-hover`.

## To test

1. **[Account → Access
Tokens](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/account/tokens)**
Open Generate / New scoped token. Side-by-side Input, Select,
RadioGroupStacked, MultiSelect. Confirm sunk vs raised fills, shared
hover border, MultiSelect flips to sunk once a value is selected. Leave
a required field empty to check invalid rest → hover → focus.

2. **[Org →
Projects](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/org/_)**
Hover the dashed Status filter. Hover default / filled filter buttons
when active. Confirm hover/open borders match.

3. **[Project →
Connect](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/project/_)**
Open Connect from the header. Mode grid tiles: hover + selected borders
match radio cards (no old muted-foreground ring).

4. **[Project →
Compute](https://studio-staging-git-dnywh-fixcontrol-surface-tokens-supabase.vercel.app/dashboard/project/_/settings/infrastructure)**
(optional)
   Compute size radios + “Contact us” tile hover.
2026-08-18 16:54:25 +10:00
Joshen Lim b6e43311d3 Reorganize explorer folder structure (#49172)
## Context

Just reorganizing the files under the Explorer folder as details are a
bit more clearer

Mainly shifting related and exclusive files into their own folder and
tests into `__tests__` folder + renaming some files

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added query result display settings for switching between table and
chart views.
- Added chart configuration options for chart type, axes, scaling,
cumulative mode, and labels.
- Automatically prevents invalid logarithmic scaling when chart data is
incompatible.

- **Refactor**
- Standardized Explorer tab and query source naming across the interface
without changing existing behavior.
- Updated Explorer navigation, routing, and page wiring to use the
standardized components.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 14:40:53 +08:00
Danny White 4760c1af77 feat(studio): polish PrivateLink connection UI (#49164)
## What kind of change does this PR introduce?

Polish for the AWS PrivateLink integrations UI.

## What is the current behavior?

The add/view sheet labels the optional nickname field as "Description",
delete confirmation always shows the AWS account ID, list admonitions
use generic copy, and delete uses a fire-and-forget mutation.

## What is the new behavior?

- Rename the optional nickname field to **Name**, with helper copy
explaining it appears on the connections list
- Tighten list admonition copy to reference connections below and
pluralise share wording
- Rename `showAcceptLink` to `shouldShowAcceptLink`
- Delete confirmation uses the connection name (or account ID when
unnamed) and clearer read replica fallback copy
- Delete uses `mutateAsync` so the dialog can await the mutation

| Before | After | 
| --- | --- |
| <img width="828" height="515" alt="Integrations Settings Chisel
Toolshed Supabase"
src="https://github.com/user-attachments/assets/9e255d4b-a048-459c-87ff-ee1b65f42f9a"
/> | <img width="828" height="515" alt="Integrations Settings Chisel
Toolshed Supabase"
src="https://github.com/user-attachments/assets/500e3922-912f-4e3b-a875-295ac7bd689e"
/> |

## To test

1. Open **Project settings → Integrations → AWS PrivateLink** on a
project with PrivateLink access
2. Click **Add connection** and confirm the optional field is labelled
**Name** with helper copy underneath
3. Add a connection with a name (e.g. `Production VPC`) and confirm the
list row shows that title
4. If you have a waiting or expired connection, confirm the list
admonition copy references shares below
5. Open a named connection, click **Delete**, and confirm the dialog
uses the connection name rather than always showing the raw account ID
6. Cancel delete and confirm the sheet stays open

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Updated AWS PrivateLink connection messages with clearer singular and
plural wording.
* Improved guidance for expired and pending connections, including
acceptance-instruction links.
* Renamed the account field to “Name,” marked it optional, and clarified
its purpose and default behavior.
* Enhanced deletion confirmations with clearer connection names and AWS
account identifiers.
  * Improved deletion handling to provide more reliable feedback.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 14:25:42 +10:00
Joshen Lim bfab3090f5 QueryTab: Scope role impersonation to each tab instead of global (#49139)
## Context

Previous PR [here](https://github.com/supabase/supabase/pull/49101)
introduced role impersonation to the Explorer -> Query Tab, but the
setting was global (e.g selected role would be the same despite
switching query tabs)

Changes here shifts the scope of the role impersonation into the query
draft so that the value is tied to each individual query tab instead

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Query drafts now remember selected impersonated roles when switching
between drafts or returning later.
  * Added support for clearing saved impersonated roles.
  * Impersonation state remains isolated across query tabs.

* **Bug Fixes**
* Prevented impersonation settings from carrying over between unrelated
drafts.
  * Invalid saved role data is safely ignored during restoration.
  * Logs drafts no longer persist or update impersonated roles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 11:27:09 +08:00
Joshen Lim cfde341c31 QueryTab: Scope row limit to each tab instead of global (#49138)
## Context

Previous PR [here](https://github.com/supabase/supabase/pull/49098)
introduced row limits to the Explorer -> Query Tab, but the setting was
global (e.g selected row limit value would be the same despite switching
query tabs)

Changes here shifts the scope of row limit into the query draft so that
the value is tied to each individual query tab instead

Also added a logic as CodeRabbit suggested
[here](https://github.com/supabase/supabase/pull/49138#discussion_r3795525802)
- to default invalid row limit values to 100 if the persisted data is
mutated incorrectly

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **New Features**
* Query tabs now retain row-limit settings independently for each
database draft.
* Row-limit preferences are restored when reopening Studio, with older
drafts defaulting to 100 rows.

* **Bug Fixes**
* Changing the row limit now persists immediately and no longer affects
other query drafts.
  * Invalid saved row limits are safely normalized to a supported value.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 10:44:32 +08:00
Danny White fba3733148 test(studio): allow scoped token creation in CI (#49163)
## What kind of change does this PR introduce?

Test reliability fix.

## What is the current behavior?

The two longest scoped access token creation tests can exceed Vitest's
default five-second timeout when they run under the full Studio CI
shard, despite passing locally.

## What is the new behavior?

The project-scoped and organisation-scoped token creation tests each use
a targeted ten-second timeout. The global timeout and production code
remain unchanged.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Increased test timeouts for project- and organization-scoped token
creation scenarios to improve test reliability.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 11:40:40 +10:00
45bb7c30ce docs(database): fix RLS guide copy and two SQL examples (#49015)
Stacked on #49011. Base is `docs/rls-revision`, so review that one
first.

## Problem

An audit of the Row Level Security guide against
`apps/docs/CONTRIBUTING.md` and `WORD_LIST.md` turned up 4 lint warnings
and 3 things that are wrong rather than just untidy.

- Two SQL examples contradict the guide's own advice. The own-profile
`SELECT` policy has no `TO` clause. The `security definer` example has
no `set search_path`.
- `## Bypassing Row Level Security` says Service Keys bypass RLS, then a
note says Supabase adheres to the signed-in user's policy anyway. The
condition that separates the two is never stated.
- `#using-functions` is linked twice from the RBAC guide and has never
existed on the RLS page.

## Solution

Copy and correctness only. No section moves, no heading renames.

- Replace the italic emphasis on `never` with bold. CONTRIBUTING permits
**bold** for a term the reader must not miss, not italics for general
emphasis. The matching fix for `must` lives in #49011, which rewrites
that line anyway.
- Drop marketing language from the opener, the Supabase intro, and the
policies and performance leads. Removes the idiom "get the hang of them"
and the filler `just`.
- Replace `we` with second person in two places.
- Scope the own-profile `SELECT` example with `to authenticated`.
- Pin `search_path = ''` on the `security definer` example,
schema-qualify its body to match, and state the requirement in prose.
- State when a Service Key actually bypasses RLS.
- Repoint the two RBAC links to `#use-security-definer-functions` and
`#helper-functions`.

`supa-mdx-lint` on the RLS guide goes from 4 warnings to 0.

## Manual testing

1. Open the [Row Level Security
guide](https://docs-git-docs-rls-copy-fixes-supabase.vercel.app/docs/guides/database/postgres/row-level-security)
on the preview. The own-profile SELECT example shows `to authenticated`,
and the security definer example shows `set search_path = ''`.
2. Open the [RBAC
guide](https://docs-git-docs-rls-copy-fixes-supabase.vercel.app/docs/guides/api/custom-claims-and-role-based-access-control-rbac)
and select the "RLS helper functions" link near the end. It lands on the
Helper functions section instead of the top of the page.
3. From `apps/docs`, run `pnpm lint:mdx`. The RLS guide reports no
warnings.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Updated access-control guidance with clearer links for
security-definer functions and RLS helper functions.
- Clarified that exposed tables require Row Level Security (RLS), while
table grants and row policies provide separate controls.
- Added least-privilege and grant-revocation examples, plus explanations
for authorization errors.
- Expanded testing guidance for CRUD policies, identity switching, and
denied operations.
- Improved recommendations for service keys, policy performance,
indexing, and secure function configuration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-17 23:40:09 +00:00
Miranda LimonczenkoandClaude Opus 5 d2ccbe5d46 docs(database): close the RLS guide gaps the eval flagged (#49011)
Closes DOCS-1274

## Problem

The `build-docs-002-rls-guide` eval points an agent at the Row Level
Security guide with a vibe-coder prompt that never says RLS, policy,
role, or test. It failed 6 of 35 checks. Each failure traces to
something the guide doesn't say.

- **Grants.** `anon` kept insert, update, and delete on all four to-do
tables. Both client roles kept writes on the weather feed. 24 privileges
untouched.
- **Indexes.** Missing on `list_members.user_id`. The agent indexed the
other three, so it missed the composite-primary-key case specifically.
- **Tests.** No pgTAP files. `Result: NOTESTS`, so the coverage judge
never ran.

## Solution

- **Add a `Grants and policies` section.**
- **Rewrite the opening danger admonition around revoke-then-grant.** It
previously showed `grant` only, which reads as though privileges start
from nothing.
- **Drop the `(or primary keys)` carve-out from `Add indexes`.** A
column counts as indexed only when it leads a `btree` index, shown with
a composite-primary-key example.
- **Add a `Test your policies` section.** Covers file location under
`supabase/tests/`, `supabase test db`, role and identity switching,
which assertion matches which denial, and an 11-assertion example
spanning allow and deny for all four operations across `anon` and
`authenticated`.

Used the supacademy RLS course as a second reference. Its framing of
grants running before RLS shaped the new section.

## Manual testing

1. Open the [Row Level Security
guide](https://docs-git-docs-rls-revision-supabase.vercel.app/docs/guides/database/postgres/row-level-security)
on the preview. `Grants and policies` and `Test your policies` appear in
the table of contents.
2. Select the `Grants and policies` link at the end of the first
admonition. It jumps to the new section.
3. Open the [markdown
version](https://docs-git-docs-rls-revision-supabase.vercel.app/docs/guides/database/postgres/row-level-security.md),
which is what agents fetch. Both new sections and the revised `Add
indexes` text are present.
4. From `apps/docs`, run `pnpm lint:mdx`. The 4 warnings on this file
match `master`, with no new ones.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation

* Clarified that exposed tables must enable row-level security.
* Explained the distinction between database grants and row-level
security policies.
* Added least-privilege examples for client roles, including read-only
access.
* Added pgTAP testing guidance with a complete `profiles` example.
* Clarified that composite indexes support policy filters only on their
leading columns.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:05:39 -07:00
David Whittington ff6c8d4b30 fix(log-drains): add UK1 and US2-FED Datadog regions (#49156)
## Summary
- Add `UK1` and `US2-FED` to the Datadog region dropdown in the log
drains studio UI
- Add the same two regions to the Datadog region list in the log-drains
docs page

The Logflare backend added support for these two Datadog regions in
[Logflare/logflare#3790](https://github.com/Logflare/logflare/pull/3790)
(shipped in v1.50.1), but the studio dropdown and docs were never
updated, so customers on UK1 or US2-FED couldn't actually select their
region when setting up a Datadog log drain.

## Test plan
- [ ] Open Project Settings → Log Drains → add a Datadog destination and
confirm UK1 and US2-FED appear in the Region dropdown
- [ ] Confirm a log drain configured with `UK1`/`US2-FED` saves and
sends events successfully

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added support for configuring Datadog log drains in the UK1 and
US2-FED regions.

* **Documentation**
* Updated the monitoring and debugging guide with the UK1 Datadog
region.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 15:22:13 -05:00
Etienne Stalmans 04ddc6bef8 chore: update cors for pg routes (#49136)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix - config hardening

## What is the current behavior?

CORS is applied at the global level in a permissive mode

## What is the new behavior?

Self-hosted envoy config should apply CORS to the `/pg` routes. These
should only be called from the studio dashboard (when called via a
browser).

uses `SUPABASE_PUBLIC_URL`, which should mean this isn't a breaking
change.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Security & Access**
  * Added stricter CORS controls for the `/pg/` route.
* Requests are limited to the configured public URL and localhost
origins.
* Standard HTTP methods and headers are supported, with preflight
responses cached for one hour.

* **Documentation**
* Updated self-hosting guidance to describe the `/pg/` route’s CORS
policy.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 10:28:09 -07:00
Charis 2e68f2bf6e refactor(studio): derive notebook diff entries (#49109)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Refactor, plus one bug fix.

Groundwork for showing the user a preview of what they are approving
when the AI Assistant creates or edits a notebook. No UI in this PR.

Towards FE-4143

## What is the current behavior?

`applyNotebookOperations` resolves an ordered list of notebook
operations into the resulting cells and nothing else. Rendering a diff
for the approval gate needs to know *what happened* to each cell
position, not just where things landed, so there is no way to build the
preview on top of it.

Separately, replacing a cell dropped its id, so `[replace cell-2, insert
after cell-2]` failed with a spurious `unknown_cell_id`.

## What is the new behavior?

`deriveNotebookDiff` resolves operations into one annotated entry per
cell position (`unchanged`, `added`, `removed`, `replaced`, `moved`).
`applyNotebookOperations` becomes a thin projection over its result, so
there is a single interpreter of notebook operations and the diff a user
approves cannot disagree with the cells that get written. The
pre-existing tests pass untouched, which is the evidence that the
projection is faithful.

Notes on the annotations:

- `removed` entries stay in the position the cell used to hold so the
list reads as a diff. This does not perturb insert-anchor arithmetic:
prior inserts still sit contiguously after their anchor.
- Moves that cancel out are downgraded to `unchanged`, since two moves
can anchor on each other and leave every cell where it started. Badging
those as moved would make the preview lie.
- `fromIndex` is the cell's position in the original notebook rather
than in the shifted working order, so `was #3` means what a reader
expects.

A replaced cell now stays addressable as an anchor. Anchoring and
targeting are separate lookups: a replaced cell can be anchored on, but
is never a legitimate target.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Notebook changes now provide a structured view of added, removed,
replaced, moved, and unchanged cells.
* Replaced cells can be used as insertion anchors, while invalid or
duplicate targets are rejected.
  * No-op moves are handled as unchanged cells.
* Notebook edits preserve operation ordering and original cell positions
for more predictable results.

* **Bug Fixes**
* Improved notebook operation handling and error reporting for complex
cell edits.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 13:11:40 -04:00
Jordi EnricandMiranda Limonczenko 7c46793a3f docs: mention MCP debugging tools and Supabase agent skill in debugging docs (#48978)
## What

- Adds a **Debug with AI tools** section to the debugging guide,
covering the MCP debugging tools (`get_logs`, `query_logs`,
`get_advisors`, `execute_sql`), the Supabase agent skill, and the
combined plugin install, with a pointer to the MCP security best
practices.
- Adds a one-line pointer to it from the Monitoring and Debugging
overview.
- Adds the missing `query_logs` entry to the MCP server's Debugging tool
group.

Note: `pnpm lint:mdx` couldn't run locally (Node version), Prettier
passes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added guidance for debugging with AI tools, including MCP tools and
the Supabase agent skill for reading logs and advisors.
* Documented plugin installation and security considerations when
connecting AI agents through MCP.
* Added links from monitoring and debugging guidance to the new AI tools
documentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io>
2026-08-17 12:22:49 +02:00
Joshen Lim 60be899fdb Selecting a PID from the overview card should clear filters if not visible in the UI (#49135)
## Context

For Database Connections - the PIDs on the overview cards are selectable
such that clicking on them should scroll the browser down to where the
row is.

However, if the selected PID isn't rendered due to the applied filters,
clicking on it will seemingly do nothing. Changes here hence opt to
remove all filters then scroll to the selected PID into view, so that
users can always quickly find which PID the overview card is
referencing.

Also chucked in some refactors to centralize the management of filters,
and functionality of selecting a PID into their own hooks

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added shared filtering for database activity by state, role,
application, search text, and view.
* Activity filters are now preserved in the URL for easier navigation
and sharing.
* Selecting activity metrics or process IDs now automatically reveals
the relevant activity row.
* Blocker view highlights root activities that are blocking other
queries.

* **Bug Fixes**
* Improved selection behavior when the chosen activity is hidden by
active filters.

* **Tests**
* Added coverage for individual, combined, case-insensitive, and
blocker-specific filtering scenarios.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 17:45:02 +08:00
Alaister YoungandAlaister Young 397965cfae [FE-4186] fix(studio): endless region selector loading for AWS_NIMBUS orgs (#49131)
On the new-project form, the Region select's trigger label and inline
spinner were driven by `isLoadingAvailableRegions` — the `isPending`
state of `useOrganizationAvailableRegionsQuery`. For `AWS_NIMBUS` orgs
that query is permanently disabled (`smartRegionEnabled` is false), and
a disabled query stays `isPending` forever, so the trigger showed
"Loading available regions..." with a spinner indefinitely even though
the default region was actually selected underneath and the form still
worked.

**Changed:**
- The trigger label and spinner now use the provider-aware `isLoading`
(`smartRegionEnabled ? isLoadingAvailableRegions :
isLoadingDefaultRegion`), which the component already used for the
select's `disabled` state and placeholder. For non-Nimbus providers the
two values are identical, so the normal path is unaffected.

## To test

- Emulate a Nimbus deployment locally by setting
`"infra:cloud_providers": ["AWS_NIMBUS"]` in
`apps/studio/hooks/custom-content/custom-content.json`, then open the
new-project form: the Region field should show the default region (name
+ flag) within a moment — not an endless "Loading available regions..."
spinner — and the dropdown should open with the specific-regions list
- Restore the normal provider list and reload: the field should briefly
load, then show smart regions ("General regions") plus specific regions
with Recommended badges, as before
- Toggle High Availability on/off in either config: the selector should
transition between region lists without getting stuck loading

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Improved loading indicators in the region selector.
* The selector now consistently shows the correct loading state while
regions are being loaded.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-17 17:20:05 +08:00
b044408e79 [FE-4185] feat(studio): custom content key for auth page logo link (#49130)
Adds a `dashboard_auth:logo_link_url` custom content key so
white-labeled deployments can point the logged-out logo link at their
own marketing site instead of the hardcoded `https://supabase.com`.

**Added:**
- `dashboard_auth:logo_link_url` custom content key (schema, types,
default `null`, sample value)

**Changed:**
- `SignInLayout` and `ForgotPasswordLayout` now resolve the
marketing-site logo href from custom content, falling back to
`https://supabase.com` — these two shared layouts cover all auth pages
(sign-in, sign-in-sso, sign-in-mfa, sign-in-partner, forgot/reset
password) in both the Next and TanStack runtimes

## To test

- On a normal deployment (key `null`): visit `/sign-in` and
`/forgot-password` logged out — the logo should still link to
`https://supabase.com`
- Set `"dashboard_auth:logo_link_url": "https://example.com"` in
`apps/studio/hooks/custom-content/custom-content.json` locally — the
logo on those pages should link to `https://example.com`
- Signed-in contexts (`logoLinkToMarketingSite` unset) still link to
`/organizations`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added support for configuring the URL linked from authentication-page
logos.
* Authentication logos now use the configured destination when
available.
* Added a default destination to ensure logo links remain functional
when no custom URL is set.
* **Documentation**
* Added sample configuration for the customizable authentication logo
link.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-17 09:15:53 +00:00
Joshen Lim dfb0603a36 Joshenlim/fe 4063 set up incremental default opt in for database connections (#49132)
## Context

As per PR title - sets up incremental default opt in for the Database
Connections feature preview

Database Connections preview banner should still only show up if it's
never been dismissed before, but the CTA's changed to "Explore" rather
than "Enable" if the user's default opted in

Related discussion here:
https://github.com/orgs/supabase/discussions/48639

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Database Connections preview is now enabled by default.
  * Added clearer handling for preview state and initialization.
* Banner actions open Database Connections when enabled, or the feature
preview when disabled.
* **Bug Fixes**
* Improved banner and menu visibility while preview settings initialize.
* Preserved banner dismissal behavior after a previous preference
change.
* Improved navigation consistency across Database Connections entry
points.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 16:11:07 +08:00
Danny White 14fe0c0cc8 fix(studio): slightly round split-button corners on focus (#49129)
## What kind of change does this PR introduce?

UI polish for split buttons (primary action + dropdown chevron).
Follow-up to #49055.

## What is the current behavior?

The focus ring sits above the neighbouring half, but the inner edge
stays square, so the ring has two sharp corners at the join.

## What is the new behavior?

On keyboard focus, the squared-off edge uses a slight radius so the ring
matches the outer corners more closely. Resting state is unchanged.
Split-button callsites now share the same join classes as the
design-system example.

| Before | After |
| --- | --- |
| <img width="1030" height="296" alt="43471"
src="https://github.com/user-attachments/assets/9df3bd72-c7ac-4419-ae18-a7e649dc2d66"
/> | <img width="1056" height="276" alt="CleanShot 2026-08-17 at 10 45
09@2x"
src="https://github.com/user-attachments/assets/52e8a4dc-9c52-45ce-b4d0-f0e7b1b75935"
/> |

## To test

Tab to each half (labelled button, then chevron). Inner corners of the
focus ring should be slightly rounded, not square.

1. [Split with
dropdown](https://design-system-git-fix-split-button-focus-radius-supabase.vercel.app/design-system/docs/components/button#split-with-dropdown)
(no login)
2. [Access
Tokens](https://studio-staging-git-fix-split-button-focus-radius-supabase.vercel.app/dashboard/account/tokens)
→ Generate new token
3. Any project on [studio
staging](https://studio-staging-git-fix-split-button-focus-radius-supabase.vercel.app/dashboard/_/settings/general)
→ Settings → General → Restart project

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Accessibility**
  - Added accessible labels to dropdown and export controls.
- Improved keyboard-focus visibility, layering, and rounded edge
treatment across joined buttons and menus.
  - Removed misleading or redundant screen-reader text and titles.

- **Bug Fixes**
- Prevented split-button controls from shrinking or displaying awkward
borders and corners.
- Refined hover and focus behavior for action buttons throughout
settings, database, storage, account, and documentation interfaces.

- **Documentation**
- Clarified guidance for using overflow menus and responsive
split-button actions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 17:28:22 +10:00
Danny White 65a5e593ca feat(studio): tighten Integrations layout (#49088)
## What kind of change does this PR introduce?

UI

## What is the current behavior?

GitHub’s empty state and Integrations icon spacing do not match the
PrivateLink list. Add connection has no plus. PrivateLink rows use a
kebab instead of click-to-view.

## What is the new behavior?

GitHub empty state matches the connections list. **Connect GitHub** is
tiny and asks you to connect before choosing a repo. Section icons
align. **Add connection** has a plus. PrivateLink rows are clickable;
delete stays in the sheet.

| Before | After |
| --- | --- |
| <img width="1456" height="1508" alt="CleanShot 2026-08-14 at 12 48
48@2x"
src="https://github.com/user-attachments/assets/27485e35-c24f-478e-8328-aad03ebb1dfb"
/> | <img width="1468" height="1494" alt="CleanShot 2026-08-14 at 14 22
19@2x"
src="https://github.com/user-attachments/assets/056e3b48-4542-4be5-9b21-4b5abd726e8e"
/> |

## Additional context

Stacked on #49087. No Vercel card work in this PR. See #49030 for the
end state, as it may already include fixes you might propose.

## To test

- **Project Settings → Integrations.** Check GitHub, Vercel, and
PrivateLink icon alignment.
- GitHub not connected: description should say **Connect GitHub to link
a repository to this project.** Button should be tiny.
- If GitHub has no repo (org page), the empty state should ask you to
add a connection.
- PrivateLink **Add connection** should show a plus. Click a connection
row to view it. No kebab.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* AWS PrivateLink connections now display clearer titles, status,
replica details, and database visibility.
* GitHub organization integrations now provide improved empty states and
clearer connection actions.
  * Added plus icons to connection buttons.

* **Improvements**
* Updated GitHub guidance based on authorization and repository
selection status.
  * Standardized connection labels and refined integration page layouts.
* Improved AWS integration icon presentation and responsive upgrade
prompts.

* **Bug Fixes**
  * Simplified default connection button wording across integrations.
* Improved AWS account title fallback behavior when a nickname is
unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 17:11:52 +10:00
Danny White fe347d8876 feat(studio): show PrivateLink accept guidance on the list (#49087)
## What kind of change does this PR introduce?

Feature

## What is the current behavior?

Accept-in-AWS guidance lives only in the view sheet, as a per-status
essay with a nested button/link. Delete is easy to miss and does not
name the database.

## What is the new behavior?

The list warns when any connection is Waiting or Expired. View
connection uses that same admonition. Delete uses a confirm dialog that
names the database, including from **View connection**.

| Before | After |
| --- | --- |
| <img width="1444" height="480" alt="CleanShot 2026-08-14 at 12 46
23@2x"
src="https://github.com/user-attachments/assets/015b261b-0bee-48f4-8f2d-d0d23293e120"
/> | <img width="1456" height="676" alt="CleanShot 2026-08-14 at 12 47
17@2x"
src="https://github.com/user-attachments/assets/0a12371b-553a-4e52-b042-7498af722f4a"
/> |
| <img width="844" height="560" alt="CleanShot 2026-08-14 at 12 46
49@2x"
src="https://github.com/user-attachments/assets/f664b165-d351-4572-8536-27f4a9749975"
/> | <img width="842" height="452" alt="CleanShot 2026-08-14 at 12 47
09@2x"
src="https://github.com/user-attachments/assets/a387c294-5814-451b-9359-e70c73de2cb2"
/> |

## Additional context

Stacked on #49086. See #49030 for the end state, as it may already
include fixes you might propose.

## To test

- **Project Settings → Integrations → AWS PrivateLink → Add
connection.** Leave it unaccepted in AWS. The list should show the
12-hour accept warning.
- **View connection** on that row. Same warning, **View instructions**,
not a status essay.
- **⋯ → Delete** on a row, and **Delete** inside **View connection.**
The dialog should name the database.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added clearer AWS PrivateLink connection alerts for pending and
expired connections, including guidance and acceptance links when
applicable.
* Existing PrivateLink connections can now be deleted directly from the
connection form.
* Added confirmation dialogs with loading and completion states for
deletion.
* Added more specific descriptions for primary databases and read
replicas.

* **Bug Fixes**
* Improved connection status messaging and handling for AWS PrivateLink
integrations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 16:41:27 +10:00
Joshen Lim 097a105663 joshenlim/fe 4176 add role impersonation to explorerquerysourcemenu (#49101)
## Context

Stacked off from https://github.com/supabase/supabase/pull/49098 - adds
role impersonation for both Notebook Query cell + Explorer Query tab

Note that this refactors the role impersonation state a little to
decouple some stuffs to make this work, since the role impersonation
state is global and we need a local state to support this UX

Similarly to row limit, for query tab its intentional that for now that
the role impersonation isn't scoped to the query draft atm as I wanna
avoid making changes to explorer-query given there was a couple of PRs
in flux that adjusts that file - will handle that separately

<img width="1117" height="577" alt="image"
src="https://github.com/user-attachments/assets/9bfd6287-efff-418b-a1c0-934ee2c840cb"
/>

<img width="1917" height="436" alt="image"
src="https://github.com/user-attachments/assets/bfd1be82-8f77-4764-bd3a-4b9c63169b82"
/>


## To test
- [ ] Verify that role impersonation works in notebook query cell
- [ ] Verify that role impersonation works in notebook query tab

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added role impersonation support to SQL Explorer queries.
* Users can select an impersonated role directly from database query
menus.
  * Query execution now applies the selected role when configured.
* Added local role selection state for individual query tabs and cells.
* Improved reuse and consistency of role impersonation controls across
the interface.
* Role selections and impersonation details remain synchronized across
supported query components.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 14:22:50 +08:00
Danny White 4433d9ddaf feat(studio): mark PrivateLink waiting as a warning (#49086)
## What kind of change does this PR introduce?

UI

## What is the current behavior?

Waiting (still labelled Ready in #49085) is green. Creating is orange.
Deleting is red.

## What is the new behavior?

Waiting is orange. Creating is grey. Deleting is orange. Connected stays
the only green state.

| Before | After |
| --- | --- |
| <img width="1448" height="492" alt="CleanShot 2026-08-14 at 12 43
59@2x"
src="https://github.com/user-attachments/assets/c0d95b51-7841-4714-a01b-47e5587c3efb"
/> | <img width="1434" height="470" alt="CleanShot 2026-08-14 at 12 44
59@2x"
src="https://github.com/user-attachments/assets/3ba10dc5-5fdd-464a-a748-5085d2d65df3"
/> |
| <img width="842" height="440" alt="CleanShot 2026-08-14 at 12 44
21@2x"
src="https://github.com/user-attachments/assets/757db647-4b7c-4f77-8dcf-1eb289c40cc1"
/> | <img width="842" height="432" alt="CleanShot 2026-08-14 at 12 44
49@2x"
src="https://github.com/user-attachments/assets/1311a6d2-4712-4cb9-a6f2-f39387f0a953"
/> |

## Additional context

Stacked on #49085. See #49030 for the end state, as it may already
include fixes you might propose.

## To test

- **Project Settings → Integrations → AWS PrivateLink.** A connection
that AWS has not accepted yet should show an orange **Waiting** badge,
not green Ready.
- Creating should be grey. Deleting orange. Expired and Failed stay red.
- **Docs preview → Platform → PrivateLink.** Should say Waiting, not
Ready.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated AWS PrivateLink connection statuses to accurately show
“Waiting” while the AWS Resource Share is pending acceptance.
* Refined status badge styling for creating, waiting, and deleting
connections.
  * Clarified that Resource Shares must be accepted within 12 hours.

* **Documentation**
* Updated PrivateLink setup instructions to reflect the revised
connection status flow.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 16:19:10 +10:00
Joshen Lim d61477085e Joshenlim/fe 4175 add row limit in explorerquerysourcemenu (#49098)
## Context

Related to Explorer/Notebook - builds on the ExplorerQuerySourceMenu by
adding an option for row limit in both Notebook Query cell + Query Tab

## Side note RE persistence of the selected row limit value
Note that for QueryTab - its intentional that for now that the row limit
isn't scoped to the query draft atm as I wanna avoid making changes to
`explorer-query` atm as there's a couple of PRs in flux that touches
that file. So will handle that separately

^ This means that switching between query tabs will not change nor
persist the row limit

<img width="931" height="335" alt="image"
src="https://github.com/user-attachments/assets/d1d52ee7-7c1d-42aa-a6ae-1d7d99ab95c9"
/>

<img width="1381" height="486" alt="image"
src="https://github.com/user-attachments/assets/689368c9-c0fc-4000-a09e-f59bfa7afa97"
/>

## To test
- [ ] Verify that row limit behaviour works in notebooks
- [ ] Verify that row limit behaviour works in explorer query tab
2026-08-17 13:36:31 +08:00
Danny White 0c1da8fd09 feat(studio): tighten PrivateLink sheet fields (#49085)
## What kind of change does this PR introduce?

Feature

## What is the current behavior?

Add connection field order and nickname handling are harder to scan.
Empty description can still show up as a blank name.

## What is the new behavior?

Add connection is AWS account ID, then database, then optional
description. An empty description is omitted from the list title.

| Before | After |
| --- | --- |
| <img width="846" height="874" alt="CleanShot 2026-08-14 at 12 42
33@2x"
src="https://github.com/user-attachments/assets/abfc4f37-a401-4bba-9408-c2530b0ac09b"
/> | <img width="844" height="794" alt="CleanShot 2026-08-14 at 12 43
01@2x"
src="https://github.com/user-attachments/assets/0cadeaea-583d-4c2b-9336-3d0fe6a1415b"
/> |

## Additional context

Stacked on #49084. See #49030 for the end state, as it may already
include fixes you might propose.

## To test

- **Project Settings → Integrations → AWS PrivateLink → Add
connection.** Confirm field order: account ID, database, description.
- Save once with a description and once without. Without one, the row
title should fall back to the account ID.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added AWS account ID and database target fields to the PrivateLink
setup form.
- Added validation and improved preservation of entered values while
editing.
  - Made the connection description optional.
- Updated connection status labels and badges for clearer status
visibility.

- **Documentation**
- Updated PrivateLink setup instructions to reflect the revised field
order and optional description.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 11:46:41 +10:00
Danny White 44292c0996 feat(studio): extract PrivateLink status copy (#49084)
## What kind of change does this PR introduce?

Refactor

## What is the current behavior?

Status labels and sheet copy are inline switches in the list and form.

## What is the new behavior?

One status lookup drives the badge and the view-sheet copy. No intended
visual change. Ready is still green.

| Before and After |
| --- |
| <img width="1460" height="486" alt="CleanShot 2026-08-14 at 12 37
13@2x"
src="https://github.com/user-attachments/assets/0c6c0b03-25f7-4e64-a0cd-72e7ef966454"
/> |
| _No visual changes_ |

## Additional context

Stacked on #48967. See https://github.com/supabase/supabase/pull/49030
for the end state, as it may already include fixes you might propose.

## To test

- **Project Settings → Integrations → AWS PrivateLink.** Look at a
connection row badge, then **View** it. Labels should match today’s
statuses. Ready should still be green.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added clear status messaging for AWS PrivateLink connections,
including accepted, ready, creating, deleting, expired, and failed
states.
* Added fallback messaging for unavailable or unrecognized connection
statuses.

* **Bug Fixes**
* Improved consistency of PrivateLink status badges, labels,
descriptions, and visual styles.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 11:32:18 +10:00
Danny White c15a8b6739 chore(studio): lighten FormLayout descriptions and tighten GitHub copy (#49091)
## What kind of change does this PR introduce?

UI nits

## What is the current behavior?

`FormLayout` descriptions that are not in a react-hook-form field use
`text-foreground-light`, which fights the component’s
`text-foreground-lighter` variant. New-project GitHub helper copy is one
long colon sentence.

## What is the new behavior?

Those `FormLayout` descriptions use the shared description variant
(`foreground-lighter`). New-project GitHub copy is two short sentences.

| Figure |
| --- |
| <img width="820" height="798" alt="CleanShot 2026-08-14 at 14 33
32@2x"
src="https://github.com/user-attachments/assets/7703a01d-efcb-41c2-8f6a-e96fc8a7187d"
/> |
| _Example call site of **before** the `FormLayout` fix._ |
| <img width="1384" height="582" alt="CleanShot 2026-08-14 at 14 53
39@2x"
src="https://github.com/user-attachments/assets/1bce1ee7-befd-4f53-881c-bbc7a87dd467"
/> |
| _**After** New-project copy shortening._ |

## To test

- **Organization → New project.** GitHub (optional): “Ideal for
agent-first workflows. Update your schema in code and push it to GitHub.
Supabase deploys the changes.”
- **Project Settings → Database → SSL configuration.** “Reject non-SSL
connections to your database” should look more muted
(`foreground-lighter`), not the brighter `foreground-light`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Simplified the GitHub repository field description while preserving
deployment guidance and the “Learn more” link.

* **Style**
* Lightened the color of descriptive text in form layouts for improved
visual hierarchy.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 11:29:59 +10:00
Stephen Morgan 3d966e3709 feat(studio): show PrivateLink resource IDs and use connection copy (#48967)
## What kind of change does this PR introduce?

Feature and docs

## What is the current behavior?

PrivateLink is labelled as an AWS account, and there is no way to tell
which resource configuration belongs to the primary vs a read replica.

Put simply: you’re not adding an AWS account. You’re adding a
connection. One AWS account can have multiple PrivateLink connections,
just to different databases, with more fields also coming soon.

Part of PRODSEC-238 and fixes SEC-939.

## What is the new behavior?

Each connection shows resource configuration IDs so primary and replica
are distinguishable. Customer-facing copy says **connection**. API paths
and AWS console labels still say association.

| Before | After |
| --- | --- |
| <img width="1452" height="496" alt="CleanShot 2026-08-14 at 12 33
49@2x"
src="https://github.com/user-attachments/assets/3b295136-0325-4587-9291-b5f01fc07806"
/> | <img width="1440" height="434" alt="CleanShot 2026-08-14 at 12 34
30@2x"
src="https://github.com/user-attachments/assets/dd6ba064-18e4-4969-9c76-e3b79ac9d288"
/> |
| <img width="846" height="912" alt="CleanShot 2026-08-14 at 12 33
28@2x"
src="https://github.com/user-attachments/assets/c4c6caca-a2f6-4516-99c7-ad7cf865f8ac"
/> | <img width="844" height="880" alt="CleanShot 2026-08-14 at 12 34
39@2x"
src="https://github.com/user-attachments/assets/f3874c6b-abdc-4ef8-84fa-141cd9150871"
/> |
| <img width="1448" height="560" alt="CleanShot 2026-08-14 at 12 33
10@2x"
src="https://github.com/user-attachments/assets/8ae734cb-ec1f-4e4e-acf7-f4de459296d1"
/> | <img width="1460" height="496" alt="CleanShot 2026-08-14 at 12 32
15@2x"
src="https://github.com/user-attachments/assets/883050d5-a6f1-44bd-8ebd-1513a2c41e9f"
/> |

## Additional context

First PR in a stacked PrivateLink series (#49084 onwards). See
https://github.com/supabase/supabase/pull/49030 for the end state, as it
may already include fixes you might propose.

## To test

- **Project Settings → Integrations → AWS PrivateLink.** Open **Add
connection**, or **View** an existing one. Confirm the UI says
connection, and that resource config IDs are copyable.
- **Docs preview → Platform → PrivateLink.** Procedure steps should say
Add connection / View connection.

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-08-17 11:06:26 +10:00
Danny White 89cd156e39 fix(studio): clarify MFA backup authenticator copy (#49083)
## What kind of change does this PR introduce?

Bug fix (copy and layout)

## What is the current behavior?

After setting up a single MFA factor, Account > Security warns you to
add a "backup sign-in method". That reads like another account identity
(email / Google / SSO), not a second authenticator app. The add action
also sits at the bottom of the MFA card, so the callout has no nearby
control.

Fixes
[FE-4171](https://linear.app/supabase/issue/FE-4171/clarify-backup-sign-in-method-after-mfa-setup)

## What is the new behavior?

The MFA block is a `PageSection` with **Add app** in the aside. When one
factor is configured, a danger callout above the card tells you to add a
backup authenticator app, with **Add another app** opening the same
modal.

| Before | After |
| --- | --- |
| <img width="1482" height="896" alt="CleanShot 2026-08-14 at 10 27
33@2x"
src="https://github.com/user-attachments/assets/7a8f3737-8e11-49c4-8f8e-3fda527a8c40"
/> | <img width="1468" height="802" alt="CleanShot 2026-08-14 at 10 57
06@2x"
src="https://github.com/user-attachments/assets/b2f6060e-b6c1-49e4-ae5c-99553ea3e60a"
/> |

## To test

1. Open **Account > Security** (`/account/security`).
2. **0 apps:** empty card, **Add app** in the section aside. Click it.
The add-factor modal should open.
3. **1 app:** danger callout under the section title. Copy should
mention a backup authenticator app, not a sign-in method. **Add another
app** and **Add app** should both open the same modal.
4. **2 apps:** callout and add buttons gone. Remove still works.

Add or remove an authenticator app on that page to hit each state. If
you already have one factor, step 3 is the important check.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Improved the multi-factor authentication interface with clearer
sections, cards, and guidance.
  * Added an empty state when no authenticator apps are configured.
* Added a warning when only one authenticator remains to help prevent
account lockout.
  * Limited authenticator app setup to two configured factors.

* **Bug Fixes**
* Improved loading and error-state presentation for authentication
factor management.
* Simplified the security page to provide a more consistent MFA
experience.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 10:47:50 +10:00
Charis 9be60cab63 refactor(studio): add optimistic locking to update_notebook (#49111)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Refactor / hardening

## What is the current behavior?

The `update_notebook` AI tool re-fetches the notebook right before
applying operations, but concurrent edits are last-write-wins: the model
has no way to detect that the notebook changed since it planned the
edit, so a stale diff can silently overwrite someone else's changes.

## What is the new behavior?

- `get_notebook` now returns the notebook's `updated_at` timestamp.
- `update_notebook` requires a new `expected_updated_at` input field
(the `updated_at` the model got from `get_notebook`).
- At execute time, after the existing re-fetch and before applying
operations, `update_notebook` compares the fetched `updated_at` against
`expected_updated_at` and throws a descriptive error if they don't
match, telling the model to re-read the notebook and reissue the update.
- The notebook system prompt and mock tools (used by the eval harness)
are updated to match.

## Additional context

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Notebook retrieval now includes the latest update timestamp.
* Notebook edits require confirmation that the content is current before
saving.

* **Bug Fixes**
  * Prevented stale edits from overwriting newer notebook changes.
* Conflicting updates are rejected, allowing the latest content to be
fetched before retrying.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-14 13:20:27 -04:00
Charis 628473b3eb refactor(studio): extract notebook query-cell logic and give log cells display settings (#49075)
Final PR of the stack. #49069, #49070, #49072 and #49074 have merged, so
this now targets `master` directly.

**Rebased onto latest `master`**, which includes the centralized
result-rendering work (#49096). See "Conflict resolution" below.

## What's left after master's own fixes

`QueryCell` was written for database cells and adapted to log cells
afterwards. Master has since fixed most of it directly:
`handleUpdateCell` no longer bails on a non-database cell, the cell's
own binding is read via `getQuerySourceBinding`, and
`database_identifier` / `time_range` propagate across a source change.

What remains:

- **`display` was only passed for database cells**, so the `view` field
on `log_cell` stayed unreachable and a logs query could never be
charted. That is the one behavioral fix left in this PR.
- The per-backend branching is inline and untested.

## What changed

Per-backend logic moves into `QueryCell.utils.ts`, where it is
unit-tested: `changeCellSource`, `setCellSql`, `cloneQueryCell`,
`getCellDisplay`, `toQueryModel`. Each narrows on the cell tag exactly
once, so the SQL brand and the backend's parameters stay correlated
rather than being re-derived at each call site. `cloneQueryCell` also
rebuilds the chart's series array, which valtio hands over as `readonly
string[]`.

`NotebookEditor` renders through `isQueryCell` (#49069) rather than a
tag switch, so a new backend gets picked up by classifying it in
`CELL_KINDS` instead of by remembering to add a `case`.

## Conflict resolution

Two rounds of master's work landed in this file set.

**`QueryCell/index.tsx` (master's own rework).** `changeCellSource`
**subsumes the four source-change branches** master had inline, each
covered by a test:

| Master's branch | Test |
|---|---|
| database → database (replica change) | `keeps the query when only the
database changes` |
| logs → logs (time-range change) | `keeps the query when only the log
time range changes` |
| database → logs | `carries the query text over when moving from the
database to logs` |
| logs → database | `carries the query text over and restores a default
row limit …` |

Two improvements fall out of consolidating them:

- A **logs → database** move now keeps the selected replica; pinned by
`applies the selected database when moving from logs to the database`.
- The row-limit default is **named** rather than a hard-coded `100`.
`Explorer/utils.ts` now shares `DEFAULT_CELL_ROW_LIMIT` with
`createQueryCellSkeleton`, so cell creation and backend conversion can't
drift.

Untouched from master: `snap.updateCell`, `AddCellDropdown`,
`MoveCellDropdownContent`, the `SortableSection` grip props, and
`NotebookEditor`'s add-cell buttons, skeletons, `reorderCells` and
`insertCellAfter`.

**Centralized result rendering (#49096).** That PR moved
`QueryCell/QueryResultChart.tsx` up to `Explorer/`, split
`QueryResultTable` into `QueryResultError`, and added
`QueryResultRenderer`. Since this PR removes `QueryChartConfig`, the
type swap had to follow the move and also reach `QueryResultRenderer`,
which is new and referenced the removed type. `QueryResultRenderer`,
`QueryResultError` and `DataGridResults` are otherwise untouched — the
empty/error-state centralization is fully preserved, and `QueryEditor`
still renders through it.

## Behavior worth a second opinion

`changeCellSource` **carries the query text across a backend change**
and rebrands it. This is probably not what a user wants — Postgres SQL
and logs SQL are separate dialects over separate schemas, so a
carried-over query will usually fail to run, and the rebrand asserts a
dialect the text was never written in.

Keeping it for now because it destroys nothing and needs no confirmation
prompt. The tradeoff is written up at the function. Worth revisiting
once we know whether people switch source to port an existing query or
to start a fresh one — if it's the latter, clearing the body behind a
confirmation is the better answer.

Results *are* dropped on a backend change, since another engine returns
unrelated columns.

## Incidental

`Explorer/types.ts` drops `QueryChartConfig`, which duplicated the wire
schema's `ChartConfig` field for field. `chart` stays persisted
alongside `view`, so switching to the table and back returns the user's
chart settings rather than rebuilding them.

## Verification

Typecheck, Prettier, and the lint ratchet clean. 1013 tests pass across
`state/`, the Explorer surfaces, notebooks, query sources, `data/sql`,
the SQL editor, and `components/ui`; 13 of them are new coverage for the
extracted helpers.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Improved notebook cell rendering with more consistent handling of
query and markdown cells.
- Query cells now preserve SQL, source settings, display preferences,
chart configuration, and query results when edited or switched between
sources.
  - Added a default limit of 100 rows for applicable database queries.

- **Bug Fixes**
- Prevented stale query results from carrying over when changing query
sources.
- Improved chart configuration consistency across query results and
display settings.

- **Tests**
- Added comprehensive coverage for query-cell updates, source
transitions, SQL changes, display state, and chart data.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-14 09:42:18 -04:00
Joshen Lim bddb806b57 Joshenlim/fe 4174 project creation ignores selected us east 1 region (#49092)
## Context

Addresses a bug on local only whereby when toggling HA in the project
creation form, the database region was getting fixed to eu-central-1
irregardless of the region that was chosen on the UI. Was a result of
old code that wasn't cleaned up when we introduced region selection for
HA locally.

Added regression test to cover this case as well 🙏 

## To test
Can only be tested locally
- [ ] On the project creation form, toggle HA and create a project in
us-east-1 - the project should be created in the selected region, and
not eu-central-1

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Fixed project creation so high-availability settings no longer replace
a manually selected database region.
- Smart-region providers continue using the selected smart or specific
region.

- **Tests**
- Added regression coverage to verify that manually selected regions are
submitted correctly in local high-availability environments.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-14 20:38:00 +07:00
Illia BasalaievandMiranda Limonczenko ee1eb5dbca docs: standardize quickstart guides (#48950)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## What is the new behavior?

- All 19 guides follow one step order: create project → set up database
→ create app → AI tooling → add keys → create client → query data → run
it → go to production. Added _template.mdx with structure requirements;
it is not enforced with a lint check for now - this will be a separate
PR before adding new guides.
- 4 new partials replace copy-pasted blocks (AI tooling, connection
strings, mobile env vars, going to production).
- Error handling: return a message instead of a blank page when a query
fails.
- All guides verified and tested separately - all work as described.
What was fixed: wrong env var names in the Hono sample, a Next.js page
that redirected to login, missing database permissions in Refine and
Hono, and stale file paths and APIs in SvelteKit, Refine, and TanStack.
- Astro, Expo, Python, Laravel, and Rails were live but missing from the
quickstart grid or listing page. Added, with two new icons.

## Quick links for review

Base preview:
https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs

**Quickstart discovery**: new Astro/Expo/Python/Laravel/Rails entries
and icons

- [Docs homepage
grid](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs)
<img width="1998" height="882" alt="CleanShot 2026-08-12 at 12 06 31@2x"
src="https://github.com/user-attachments/assets/942eb7e2-1e85-4b20-a6a7-c2b127d31b2b"
/>


- [Getting started
overview](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started)
<img width="856" height="878" alt="CleanShot 2026-08-12 at 12 13 30@2x"
src="https://github.com/user-attachments/assets/d48091a9-7daf-4796-a521-14116b7479c9"
/>

### New shared files:


**[apps/docs/content/guides/getting-started/quickstarts/_template.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/guides/getting-started/quickstarts/_template.mdx?plain=1)**
A reference contract the other 19 quickstart guides are checked against.
Documents the required frontmatter, the canonical 10-step section order,
every guide's deviation from that order (and why), the direct-Postgres
exception (Laravel/Rails/RedwoodJS/Spring Boot), and the
discovery-surface/icon requirements for adding a new guide. No lint rule
enforces it yet; that's a follow-up PR.


**[apps/docs/content/_partials/quickstart_ai_tooling.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_ai_tooling.mdx?plain=1)**
Example:
[Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#4-set-up-ai-tooling-optional)
→ "Set up AI tooling" section
Shared by all 19 guides: astrojs, expo-react-native, flask, flutter,
hono, ios-swiftui, kotlin, laravel, nextjs, nuxtjs, reactjs, redwoodjs,
refine, ruby-on-rails, solidjs, spring-boot, sveltekit, tanstack, vue


**[apps/docs/content/_partials/quickstart_going_to_production.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_going_to_production.mdx?plain=1)**
Example:
[Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#going-to-production)
→ "Going to production" section
Shared by all 19 guides: same full list as above


**[apps/docs/content/_partials/quickstart_connection_string.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_connection_string.mdx?plain=1)**
Example:
[Laravel](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#5-set-up-the-postgres-connection-details)
→ connection string setup step
Shared by 3 guides: laravel, ruby-on-rails, spring-boot – the
ORM/backend frameworks that connect directly to Postgres rather than
through the Data API


**[apps/docs/content/_partials/quickstart_mobile_env_note.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_mobile_env_note.mdx?plain=1)**
Example: [iOS
SwiftUI](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ios-swiftui#get-api-details:~:text=This%20guide%20substitutes%20your%20project%20URL%20and%20key%20directly)
→ environment variables step
Shared by 3 guides: ios-swiftui, flutter, kotlin – note Expo React
Native is mobile too but doesn't use this partial, since it has its own
`EXPO_PUBLIC_` prefix convention inline instead.

## Per guide changes

**[Astro](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/astrojs#9-query-supabase-data-from-astro)**
Typed query error in the server client sample.

**[Expo React
Native](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/expo-react-native#8-query-data-from-the-app)**
Added an `error` state alongside instruments. Also removed the broken
[`--web` verification
path](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/expo-react-native#9-start-the-app):
expo-sqlite needs Metro wasm + COEP/COOP config the guide never had
(CodeRabbit finding).


**[Flask](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flask#7-create-the-supabase-client)**
Split "Create the Supabase client" and ["Query
data"](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flask#8-query-data-from-the-app)
into their own steps.


**[Flutter](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flutter#9-setup-deep-links-optional)**
Reworded the deep-links section; keeps the framework-specific [Android
`INTERNET` permission
subsection](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flutter#android)
under "Going to production."


**[Hono](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/hono#6-declare-supabase-environment-variables)**
Split into "Install dependencies," "Declare environment variables," "Set
up anonymous sign-ins," and "Query data" as separate steps. Fixes wrong
env var names from the previous sample.

**[iOS
SwiftUI](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ios-swiftui#8-query-data-from-the-app)**
Added an `isLoading` state so the loading overlay doesn't hang forever
on a successful empty result (CodeRabbit fix).


**[Kotlin](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/kotlin#5-install-dependencies)**
Fixed the Compose compiler plugin declaration: `apply false` was missing
from the app module (CodeRabbit finding).


**[Laravel](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#5-set-up-the-postgres-connection-details)**
Now uses the shared `quickstart_connection_string.mdx` partial for the
session-pooler/SSL guidance instead of inline copy.


**[Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#6-allow-public-access-to-the-instruments-page)**
New step fixing the page that previously redirected to login. Its
middleware path check is also now segment-aware so it doesn't over-match
paths like `/instruments-private` (CodeRabbit finding).


**[Nuxt](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nuxtjs#7-create-the-supabase-client)**
"Create the Supabase client" and ["Query
data"](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nuxtjs#8-query-data-from-the-app)
split out as their own steps.


**[React](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/reactjs#7-create-the-supabase-client)**
Same
client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/reactjs#8-query-data-from-the-app)
split as the other Vite-based guides.


**[RedwoodJS](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/redwoodjs#2-gather-database-connection-strings)**
Expanded into explicit transaction-mode/session-mode connection strings,
Prisma schema, migration, seed, and scaffold steps; fixes stale file
paths and APIs from the previous version.


**[Refine](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/refine#8-allow-writes-to-the-instruments-table)**
New step fixing the missing RLS grants that made the scaffolded
create/edit pages fail.

**[Ruby on
Rails](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#4-set-up-the-postgres-connection-details)**
Now uses `quickstart_connection_string.mdx`; added a [reminder to save
the database
password](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#1-create-a-supabase-project)
before it's needed for the connection string.


**[SolidJS](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/solidjs#7-create-the-supabase-client)**
Same
client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/solidjs#8-query-data-from-the-app)
split, adapted to Solid's `resource.error`.

**[Spring
Boot](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/spring-boot#4-set-up-the-postgres-connection-details)**
Connection-string section now uses the shared partial instead of a
duplicated inline caution.


**[SvelteKit](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/sveltekit#8-query-data-from-the-app)**
Updated `load` functions (both `+page.js` and `+page.server.ts`
variants) with explicit query-error typing; fixes stale file paths and
APIs from the previous version.


**[TanStack](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/tanstack#8-query-supabase-data-from-tanstack-start)**
`fetchInstruments` now returns and renders the query error instead of
silently returning an empty list (CodeRabbit finding); fixes stale file
paths and APIs from the previous version.


**[Vue](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/vue#7-create-the-supabase-client)**
Same
client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/vue#8-query-data-from-the-app)
split as the other Vite-based guides.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added SolidJS, RedwoodJS, Refine, Laravel, and Ruby on Rails
quickstarts.
* Added framework discovery entries for Astro, Expo React Native,
Python, Laravel, and Rails.
* Added optional AI tooling, MCP setup, connection-string, mobile
configuration, and production-readiness guidance.
* Added a Hono authentication example with anonymous sign-in, user
details, and instrument data.

* **Documentation**
* Expanded setup, environment, authentication, RLS, migration, SSL, and
deployment guidance.

* **Bug Fixes**
  * Improved sample error handling for failed data requests.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io>
2026-08-14 15:03:37 +02:00
Joshen Lim ebb8e2336e Centralize empty state + error handling for query results (#49096)
## Context

Related to Explorer/Notebook - currently with the chart view, if the
query has any errors, there's no error UI being shown
Mainly because the error UI handlers are all within the table view

Changes here hence opt to extract the empty state + error UI into a
centralized renderer

<img width="936" height="366" alt="image"
src="https://github.com/user-attachments/assets/437891dc-241e-4c43-97a6-6eef52472ee7"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added unified query result display for prompts, errors, empty results,
tables, and charts.
  * Query results now switch consistently between table and chart views.

* **Bug Fixes**
  * Improved empty-result layout centering across views.
  * Expanded error display to use the available width.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-14 19:57:36 +07:00
fadymak 17dde3d324 feat(account): let OAuth-only users add a password to their account (#49057)
Allows a user to add a password which automatically creates and email
identity to enable email + password authentication for OAuth-only
accounts.

Gated behind a feature flag: `enableAccountPassword`

When a user does not have an email identity, allow them to set a
password:

<img width="762" height="284" alt="Screenshot 2026-08-13 at 14 52 53"
src="https://github.com/user-attachments/assets/70b4883a-ed38-488a-a1b7-908caa112a0b"
/>

Password modal:

<img width="519" height="423" alt="Screenshot 2026-08-13 at 14 56 57"
src="https://github.com/user-attachments/assets/56ac370d-9e6c-4b05-986f-3aa9a51826c2"
/>

Email identity has been created, allow unlinking and/or updating email
address or password:

<img width="764" height="285" alt="Screenshot 2026-08-13 at 14 55 04"
src="https://github.com/user-attachments/assets/5d9d7692-f4e3-4638-958d-15fefad01333"
/>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * OAuth-only accounts can set a password from Sign-in methods.
* Added password visibility controls, validation guidance, and success
or error feedback.
  * Sign-in methods display the account email when available.

* **Updates**
* Renamed “Account identities” to “Sign-in methods” throughout account
preferences.
* Standardized password requirements across password setup and reset
forms.
* Setting a password refreshes the current session and signs out other
sessions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-14 14:56:23 +02:00