mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 11:55:05 +03:00
chore/tailwind-3-reference
4125
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
f4abe3fca7 |
chore: migrate MultiSelectDeprecated to Shadcn multi-select (#45377)
## Problem We want to reduce the code we ship and maintain. ## Solution - Migrate old `MultiSelectDeprecated` usage to the new Shadcn `multi-select` - Fix `multi-select` background color to align it with other inputs - Fix `multi-select` popover content alignment (now align to its input start) ## Screenshots ### RLS policies Before: <img width="618" height="705" alt="image" src="https://github.com/user-attachments/assets/098504fc-21a9-4386-9390-e69f929189c1" /> After: <img width="549" height="704" alt="image" src="https://github.com/user-attachments/assets/06842e31-90bf-4d24-8c19-78f74941cd65" /> ### Storage policies Before: <img width="1177" height="664" alt="image" src="https://github.com/user-attachments/assets/3cf1afb4-9604-4ee9-b7b6-8371f94bcfcc" /> After: <img width="1170" height="653" alt="image" src="https://github.com/user-attachments/assets/e3b235d3-5890-45ff-9658-82c6612ac82a" /> ### Database indexes Before: <img width="675" height="496" alt="image" src="https://github.com/user-attachments/assets/84c0d3b6-45af-49dc-b4f4-274abed4cea7" /> After: <img width="674" height="498" alt="image" src="https://github.com/user-attachments/assets/697ceafc-256f-4106-9193-8697bc3d9d8e" /> ### Contact support Before: <img width="643" height="534" alt="image" src="https://github.com/user-attachments/assets/ee7fc790-622d-4c09-afab-269271a31af4" /> After: <img width="645" height="457" alt="image" src="https://github.com/user-attachments/assets/db0b9a32-95e0-4864-a12a-88828c431aab" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Replaced legacy multi-select controls with a unified selector UI: dynamic trigger labels, per-item disable support, explicit item rendering, deletable badges, and improved search/selection behavior. * **Chores** * Removed deprecated multi-select badge and legacy picker implementations; adjusted exports/types to align with the new selector components. * **Style** * Minor UI text and inline code styling improvements and modal spacing tweaks. * **Tests** * Updated end-to-end flows to wait and interact with the new pickers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
16db81cc9c |
chore(studio): clarify Stripe Projects connect flow (#44797)
## What kind of change does this PR introduce? Studio UI copy and visual polish for the Stripe Projects connect flow. - Resolves DEPR-428 - Resolves DEPR-429 ## What is the current behaviour? - The Stripe Projects connect flow copy is awkward in request, linked, wrong-account, and success states. - The API authorisation layout logo is slightly misaligned. - The bundled Stripe icon is outdated. ## What is the new behaviour? - Tightens Stripe Projects copy and CTA text around authorising the request. - Keeps the real `ar_id` account-request flow intact without local preview shortcuts. - Centres the logo link in `APIAuthorizationLayout`. - Updates the Stripe icon SVG. - Note that this affects other areas too, such as Stripe integrations ([more](https://supabase.slack.com/archives/C0429V78ACX/p1777268209661729)). - Fixes CLI login copy capitalisation. | Before | After | | --- | --- | | <img width="1380" height="856" alt="CleanShot 2026-04-29 at 15 10 26@2x" src="https://github.com/user-attachments/assets/4ad242c2-1e9e-4128-9661-ef8deee111c1" /> | <img width="1486" height="892" alt="CleanShot 2026-04-29 at 15 10 36@2x" src="https://github.com/user-attachments/assets/f6aa4d0a-e5a7-40ff-87b7-845a22ef1c50" /> | ## Verification - `pnpm exec eslint pages/partners/stripe/projects/login.tsx` - `git diff --check` --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
3ef1c1e08c | Add recommendation on schema isolation (#45390) | ||
|
|
5dee242aa3 |
chore(studio): remove project usage settings callout (#45393)
## What kind of change does this PR introduce? Dashboard cleanup and docs update. ## What is the current behaviour? Project Settings > General still shows a legacy "Project usage" section explaining that usage statistics moved to organisation settings. One troubleshooting page also links to the old project billing usage page. ## What is the new behaviour? The legacy Project Settings usage callout is removed, while the existing old usage route redirect remains in place for stale links. The MAU troubleshooting page now points users to the organisation usage page and tells them to select a specific project from the dropdown. | Before | After | | --- | --- | | <img width="1450" height="1314" alt="CleanShot 2026-04-30 at 16 11 16@2x" src="https://github.com/user-attachments/assets/3ad8c41f-2eab-406c-bfd8-f5737ae9a5a3" /> | <img width="1474" height="1004" alt="CleanShot 2026-04-30 at 16 11 04@2x-7CACB175-B6A9-4811-968F-030745F685AE" src="https://github.com/user-attachments/assets/f541ee60-0c24-49e4-9446-3bd58c516797" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated Monthly Active Users (MAU) documentation to reflect accessing usage data from the organization-level page instead of project settings * **Refactor** * Removed project-level usage viewing option from project settings interface <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a34c299344 |
chore(studio): clarify pause project flow (#45392)
## What kind of change does this PR introduce? Minor UI and copywriting change. ## What is the current behavior? - Vague dialog copy for pausing a project - Plain pause icon looks like two Tim Tams ## What is the new behavior? - Clearer dialog copy - More standard pause button ## Additional context | Before | After | | --- | --- | | <img width="912" height="502" alt="11317" src="https://github.com/user-attachments/assets/55a64d01-8171-498e-a03f-2e0060995400" /> | <img width="850" height="476" alt="67001" src="https://github.com/user-attachments/assets/054a8ca0-e06c-417c-9668-c3847013bbe2" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enhanced pause project confirmation dialog to clearly communicate the 90-day resume timeframe and backup availability after this period. * **Style** * Updated pause icon display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
151a1792d9 | feat(studio): add support for new ducklake destination in replication UI (#45370) | ||
|
|
49ff97af06 |
feat: add global feature preview badge for enabled preview features (#45373)
## What kind of change does this PR introduce? Fixes FE-2526. Adds a global Feature Preview badge to pages enabled via Feature Previews, improving visibility and making it clearer to users that the feature can be managed (or disabled) from the Feature Previews settings. ## Why Previously, once a feature preview was enabled, there was no clear indication within the UI that: - the feature was still in preview, or - where to go to disable it This lead to confusion and made the feature feel “permanent”. ## What’s included New FeaturePreviewBadge UI component <img width="417" height="80" alt="CleanShot 2026-04-29 at 17 20 10" src="https://github.com/user-attachments/assets/6fbc96e3-35ef-46d1-893a-2188c4d237a3" /> </br> Added badge across pages enabled via Feature Previews: - Webhooks - Unified Logs - JIT DB Access - Column Privileges - Policies - Merge page - Advisor Rules Consistent placement and styling. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Feature preview badges now appear across the platform on preview features, including Platform Webhooks, Database functionality, Unified Logs, Advisor Rules, and other features, providing quick identification and access to manage preview settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a5b36d91de |
chore: migrate <Toggle> to <Switch> (#45314)
## Screenshots ### Row editor Before: <img width="683" height="74" alt="image" src="https://github.com/user-attachments/assets/0416859b-e471-4f11-be28-33e1e0e03415" /> After: <img width="675" height="65" alt="image" src="https://github.com/user-attachments/assets/57ff796e-a67d-42f5-9fe0-f7be831aabc6" /> ### Studio lite Before: <img width="673" height="400" alt="image" src="https://github.com/user-attachments/assets/51ff1cd3-3cc5-4aa2-befb-4f345a933186" /> After: <img width="644" height="402" alt="image" src="https://github.com/user-attachments/assets/4605ad0b-656f-4da2-86d7-8ec32dc54855" /> ### Database function Before: <img width="745" height="949" alt="image" src="https://github.com/user-attachments/assets/49fba21d-0d28-4037-beb7-9ecb13f12fe7" /> After: <img width="746" height="949" alt="image" src="https://github.com/user-attachments/assets/d6755b04-df97-4195-b473-98a0269923d9" /> ### Privacy settings (`www`) Before: <img width="1122" height="808" alt="image" src="https://github.com/user-attachments/assets/02f82691-f045-4d59-b5a4-1ce635e3d9af" /> After: <img width="1110" height="768" alt="image" src="https://github.com/user-attachments/assets/ef2ee049-4cbe-4209-851a-2f024ab0063b" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Replaced legacy toggle controls across the app with a unified Switch component for consistent interaction. * Improved labels, sizes, spacing and aria relationships for clearer UI, better accessibility, and more predictable behavior (settings, filters, editors, realtime controls, privacy modal). * Removed the old Toggle implementation, styles, and top-level exports from the UI package to standardize controls. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
fa8f49b261 |
feat(studio): add keyboard shortcuts to the SQL editor (#45335)
## Summary Adds the first batch of keyboard shortcuts for the SQL editor, following the registry pattern established for the table editor. ## Shortcuts | Shortcut | Action | Notes | | --- | --- | --- | | `Esc` | Blur the SQL editor | Registered as a Monaco command with a context-key precondition so inline widgets keep owning `Esc` (suggest, find, parameter hints, snippet/rename mode, accessibility help, inline suggestions, and selection cancellation). | | `Shift+E` | Focus the SQL editor | Pairs with `Esc` for mouse-free round-trip. | | `Alt+Shift+F` | Prettify SQL | Now wired through the registry; the tooltip and dropdown badge in `UtilityActions` read the keybind from the same source of truth. Works from inside the editor (Monaco action) and from anywhere on the page (`useShortcut`). | | `Mod+Shift+Enter` | Run EXPLAIN ANALYZE | Routes results into the Explain tab. Surfaces in the Monaco context menu next to "Run Query". | | `Shift+N` | Open a new SQL snippet | Navigates to `/sql/new?skip=true` to avoid the redirect-to-last-visited effect that fires on plain `/sql/new`. | All entries appear in the command menu (`Mod+P`) under "Shortcuts" while their host components are mounted. None are surfaced in Account → Preferences → Keyboard shortcuts yet (`showInSettings: false`), matching how the table editor shortcuts shipped. ## Notes - The blur shortcut intentionally lives on the Monaco instance rather than the document-level hotkey listener — the document listener can't preempt Monaco's own `Esc` handling. Other shortcuts that need to fire while the editor has focus (run, save, format, explain) are registered as Monaco actions; everything else uses `useShortcut`. - Format and explain are double-registered (Monaco action + `useShortcut`) so they fire whether the editor is focused or not. The Monaco actions don't read the user's enable/disable preference yet — same asymmetry as the existing run/save actions. - `Shift+N` is scoped to the SQL editor route. To make it work globally we'd register it at a higher layout level. ## Test plan - [x] Inside editor: `Esc` blurs; suggest/find/parameter hints still close on `Esc`; multi-cursor selection collapses on first `Esc`, blurs on second. - [x] Outside editor: `Shift+E` returns focus to the editor. - [x] `Alt+Shift+F` formats from inside and outside the editor; tooltip + dropdown badge show the correct keybind. - [x] `Mod+Shift+Enter` runs EXPLAIN ANALYZE and switches to the Explain tab. - [x] `Shift+N` opens a fresh snippet without bouncing back to the previous one. - [x] All five shortcuts appear in `Mod+P` with the right badges. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Keyboard shortcuts for SQL editor: format SQL, run EXPLAIN ANALYZE, focus/blur editor, and open a new SQL snippet. * Added "Prettify SQL" and "Run EXPLAIN ANALYZE" actions to the editor context menu with shortcuts. * Centralized registration of SQL editor shortcuts so they appear across the app. * **UX Improvements** * Escape key blurs editor focus when appropriate to allow easy exit without disrupting editor widgets. * **Style** * Adjusted success toast capitalization for copied Markdown. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
45ffa97240 |
[FE-3096] feat(studio): split edge function secrets into custom and default sections (#45355)
Splits the Edge Function secrets page into two sections so reserved Supabase env vars are always visible, even on new projects without any user secrets created. <img width="1605" height="1006" alt="Screenshot 2026-04-29 at 12 20 43 PM" src="https://github.com/user-attachments/assets/fc74f10e-557d-45bb-b0f0-66a706a9facb" /> **Added:** - `DefaultEdgeFunctionSecrets` component — a read-only reference list (Name + Description) of every `SUPABASE_*`, `SB_*`, and `DENO_*` env var available in every project, sourced from [the docs](https://supabase.com/docs/guides/functions/secrets#default-secrets) - `isInternalEdgeFunctionSecret` helper used to filter the custom secrets table **Changed:** - The custom secrets section now renders first (more actionable), with the educational default secrets section below it - Custom secrets table now filters out anything matching `SUPABASE_*` or any of the hardcoded default names **Removed:** - `isReservedSecret` regex check + its tooltip branches in `EdgeFunctionSecret.tsx` — dead code now that the custom table never receives an internal secret Addresses [FE-3096](https://linear.app/supabase/issue/FE-3096/split-edge-function-secrets-into-internal-and-user-defined-views). ## To test - Open `/project/_/functions/secrets` on a fresh project (no custom secrets) - "Default secrets" section is visible and lists all 9 env vars with descriptions - "Custom secrets" section shows the empty state - Create a custom secret — appears in the Custom section, not the Default section - Edit/delete dropdown still works on custom secrets - Search input only filters the custom secrets table <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a "Default secrets" section showing built-in edge-function secrets with names, descriptions, and a "Deprecated" badge where applicable. * Secret names are clickable to copy to clipboard with a success notification; secret names/values use inline code styling. * UI now separates "Custom secrets" and "Default secrets" with distinct empty states. * **Bug Fixes** * Edit/Delete controls reflect actual permission state (no longer disabled for default/reserved secrets). * **Tests** * Added tests for default-secret detection and visibility rules. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
05fc4aca13 |
chore(studio): clean up temporary access response typing (#45354)
## What kind of change does this PR introduce? Cleanup. ## What is the current behavior? Temporary access still has a couple of leftover JIT fallback messages and an unnecessary local unavailable-reason type after the Platform response types were split into `JitAccessResponse` and `JitStateResponse`. ## What is the new behavior? Studio relies on the generated `JitStateResponse` discriminated union for the toggle warning and uses temporary access copy consistently in the remaining fallback toasts. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Refined error messaging for temporary database access grant and revoke operations. * Enhanced condition detection for toggle failure warnings in database access configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3b756e4d9f |
Chore/project secure (#45108)
<img width="2652" height="830" alt="image" src="https://github.com/user-attachments/assets/3c3921e7-c255-4e59-a9c3-c5f97da87788" /> Adds a full screen alert behind a feature flag `projectNeedsSecuring` that prompts for fixing RLS issues. Adjusts a few other small styles to add more prominence to critical advisor issues. To test: - Enable the flag - Make sure you have a table with RLS disabled - Open project home and note the fade in of full page review - Click "copy prompt" or "fix" and note the prompt - Click skip to home and refresh the page, note it doesn't appear anymore <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Project-level security gate on project home with AI assistant prompts, table details, per-project dismissible notice, and a new telemetry event for CTA interactions. * **Improvements** * Stronger visual treatment for critical advisor items and advisor CTA when critical issues exist. * Assistant dropdown supports a copy-prompt callback; added local-storage key and utilities/types to support project security workflows. * **Tests** * Added tests covering gate behavior, navigation, and dismissal logic. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
ad331c5813 |
[FE-3081] fix(studio): remove false "schema not exposed" warning in Realtime policies editor (#45325)
The Realtime policies editor was showing a warning banner on `realtime.messages` saying the schema isn't exposed through PostgREST. This is incorrect — the `realtime` schema is intentionally excluded from PostgREST (it's in `INTERNAL_SCHEMAS` and filtered out of the exposed schema picker), so the warning is always false in this context. **Changed:** - Removed `useProjectPostgrestConfigQuery` from `RealtimePolicies` — it was only used to derive `exposedSchemas` - Hardcode `exposedSchemas` as `['realtime']` since this editor is for Realtime auth, not PostgREST access ## To test - Go to the Realtime policies editor (`/project/_/realtime/policies`) - Confirm the yellow "schema not exposed" warning banner no longer appears on `realtime.messages` - Confirm policy rows still render correctly and other admonitions (e.g. publicly-readable if RLS is off) still show as expected <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved stability of Realtime Policies schema handling by simplifying configuration logic to consistently use the realtime schema. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
2930b9b6cd |
feat(studio): wire up database advisor rule 12 (auth_allow_anonymous_sign_ins) (#45343)
## Summary Wires up database advisor rule `0012_auth_allow_anonymous_sign_ins` in the Studio Linter so it shows up with the right title, icon, action link, and docs link instead of falling back to a generic display. The rule entry navigates to `/auth/providers` (where the "Allow anonymous sign-ins" toggle lives), modeled after rule 0019 (`auth_otp_long_expiry`) which uses the same target. ## Test plan - [x] Trigger rule 0012 on a test project (enable anonymous sign-ins on a project with RLS-protected tables) - [x] Verify the lint appears in Security Advisor with title "Anonymous Sign-Ins Allowed" and User icon - [x] Verify the "View settings" CTA navigates to `/project/<ref>/auth/providers` - [x] Verify the "Learn more" link points to the 0012 docs section <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a new authentication lint rule that identifies anonymous sign-in configuration issues and provides integrated guidance to the auth providers settings page with relevant documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6fe0ad442b |
fix(studio): drive compute card cores/memory from infra_compute_size (#45334)
## Summary Fixes [FE-3095](https://linear.app/supabase/issue/FE-3095/compute-size-hover-card-shows-badge-and-cpumemory-from-out-of-sync). The compute size hover card on the project home dashboard was sourcing its badge and its CPU/memory rows from two different cached responses, which can disagree: | Field shown | Previous source | |---|---| | Badge ("XLARGE") | `project.infra_compute_size` (project-detail query) | | Cores / memory | `selected_addons[compute_instance].variant.meta` (project-addons query) | A customer reported seeing an **XLARGE** badge next to **2-core ARM (Shared) / 1 GB** — the micro-tier specs — and asked whether their upgrade had actually been applied. The upgrade was applied; only the rendered card was contradictory. ## Fix Source both the badge and the CPU/memory rows from the same logical fact: look up the variant in `available_addons` whose identifier matches `ci_${infra_compute_size}` and read its `meta`. `available_addons` is essentially a static catalog of variant specs, so once it's loaded the card cannot show specs that disagree with the badge. This also collapses the special-cased `INSTANCE_MICRO_SPECS` fallback into the existing `getAvailableComputeOptions` helper (which already provides micro/nano fallbacks). The nano UX text ("Shared / Up to 0.5 GB") is preserved by switching that JSX branch to key on `computeSize === 'nano'`. ## Out of scope - `useProjectAddonUpdateMutation` does not invalidate `projectKeys.detail`. That's hygiene worth doing later, but project-detail has a 30s `staleTime` and the resize already drives 5s polling via the `RESIZING` status path, so the badge refreshes naturally and this fix doesn't depend on it. ## Test plan - [ ] Hover the compute badge on a project at each compute size (nano, micro, small, ..., 16xlarge) and confirm CPU and memory rows match the badge. - [ ] Resize a project from micro → large; on completion, confirm the hover card shows large specs (no transient micro values). - [ ] Open the dashboard for a free-tier project on micro that has no `compute_instance` entry in `selected_addons` and confirm the card still shows micro specs (i.e. `getAvailableComputeOptions` micro fallback is engaged). - [ ] Confirm the "Unlock more compute" CTA still appears for non-highest sizes and disappears at the highest size. |
||
|
|
89d08a2505 |
Remove feature flag for RLS tester (#45332)
## Context As per PR title - will make the RLS tester available for CLI / self-host (still as a feature preview) ## To test - [x] Verify briefly locally that the RLS tester is available for use, and works as expected <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved user search error handling to display appropriate failure messages when search encounters issues. * **Refactor** * Simplified RLS Tester feature availability logic by consolidating enablement checks across components and removing redundant feature flag dependencies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e7c33bf580 |
feat(studio): add insert, filter, sort, refresh shortcuts to the table editor (#45191)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — a second batch of table editor shortcuts, stacked on top of #45178. ## What is the current behavior? Inserts / filters / sort / refresh are all mouse-only. No keyboard access, and no affordance for discovering what keybinds might exist. ## What is the new behavior? ### New shortcuts | Keybind | Action | Surface | |---|---|---| | `I` then `R` | Insert row | hotkey + Cmd+K + inline keybind in Insert dropdown | | `I` then `C` | Insert column | hotkey + Cmd+K + inline keybind in Insert dropdown | | `I` then `U` | Import data from CSV | hotkey + Cmd+K + inline keybind in Insert dropdown | | `Shift+F` | Focus filters | hotkey + Cmd+K — focuses the new filter bar's freeform input | | `F` then `C` | Clear filters | hotkey + Cmd+K — gated on `filters.length > 0` | | `S` then `C` | Clear sort | hotkey + Cmd+K — gated on `sorts.length > 0` | | `Shift+R` | Refresh table | hotkey + Cmd+K + hover tooltip on the Refresh button | All are `ignoreInputs: true` so they don't fire while typing. The insert / clear-filters / clear-sort shortcuts use two-step chords so they don't clobber single-letter keys users might reach for elsewhere; Focus filters and Refresh keep their Shift-prefixed single-step bindings. ### Infrastructure - **New `<ShortcutBadge>`** (`components/ui/ShortcutBadge.tsx`) — inline keybind display. Reads the sequence straight from the registry, so the ID is the single source of truth. Renders multi-step chords with a "then" separator between steps. Defaults to `variant="inline"` (the flat `text-foreground/40` style used across the app in `RunButton`, `ActionBar`, `OperationQueueSidePanel`, etc.) with `variant="pill"` available if someone needs the boxed style. - **Insert dropdown restyled** — each `DropdownMenuItem` in `HeaderNew`'s Insert menu now shows its keybind inline on the right (centered vertically, with `pr-4` + `shrink-0` so long table names in the description never crowd the badge). - **`RefreshButton`** swapped from `ButtonTooltip` to `<Shortcut>` so the keybind tooltip renders automatically from the registry. - **`FilterPopoverPrimitive` untouched** — the old filter bar is being deleted, so Shift+F is scoped to the new filter bar only. The handler focuses `[data-testid="filter-bar-freeform-input"]` (the existing freeform input in the ui-patterns `FilterBar` → `FilterGroup`). ## Additional context Stacked on #45178 (FE-3057 — initial table editor shortcuts). Rebase after that one merges. ### Test plan - [x] Open a table → Insert dropdown shows keybind to the right of each item, no wrap encroachment even with long table names - [x] `I` then `R` opens the Row editor; `I` then `C` opens the Column editor; `I` then `U` opens the CSV import flow - [x] `Shift+F` focuses the new filter bar's freeform input - [x] Add a filter → `F` then `C` clears it; shortcut disabled in Cmd+K when no filters are applied - [x] Sort a column → `S` then `C` clears sort; shortcut disabled when no sorts - [x] `Shift+R` refreshes the table (spinner shows on the Refresh button); hover the button → keybind tooltip - [x] All seven new entries show up in Cmd+K when their gates are satisfied <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added keyboard shortcuts for table actions: insert row, insert column, import CSV, refresh, focus filters, clear filters, and clear sorts. * Shortcuts are available in the command menu and show visual keyboard hints. * **UI** * Menu entries now display shortcut badges. * Refined dropdown spacing/layout and updated the refresh control to surface its shortcut. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fe928ad76d |
feat(studio): link edge function errors to troubleshooting docs (#45326)
## Summary Improve the "Errors since last deploy" panel on the new edge function overview page. - **Error column**: stop showing the function URL. Pull the actual error from the related runtime logs, trim the stack trace to a one-line summary, and use that for the cell text and tooltip. - **Troubleshoot column**: rename "Assistant" to "Troubleshoot" and add a "View troubleshooting guide" item to the dropdown that opens `supabase.com/docs/guides/troubleshooting` prefilled with `edge function <ErrorType> <statusCode>`. - **Runtime log block**: restyle the expanded per-row log section. Monospace rows with structured timestamp / level badge / count / message, a divider between entries, and destructive tinting only on error rows. The previous layout ran text together with no separation. ## Test plan - [x] `pnpm test:studio` for `EdgeFunctionRecentErrors.utils.test.ts` (10 passing, including new cases for `summarizeErrorMessage`, `getDisplayErrorMessage`, and `buildTroubleshootingDocsUrl`) - [x] `pnpm typecheck` clean - [x] `eslint` clean for changed files - [ ] Visual check of the panel: Error cell shows the runtime error summary, Troubleshoot dropdown opens docs in a new tab, log rows render with the new structure 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a "View troubleshooting guide" action that opens a status-code-specific docs page for each recent error. * Errors now show level badges and repetition counts in the logs for clearer scanning. * **Bug Fixes** * Error text is summarized and normalized for concise, single-line display with clearer per-line styling. * **Tests** * New tests validate error-summary, display-fallback, and troubleshooting-URL behaviors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
42b431a270 |
feat(studio): add keyboard shortcuts to the table editor (#45178)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — a set of new keyboard shortcuts for the table editor, along with infrastructure to register, gate, and surface them. ## What is the current behavior? Clicking into the grid "traps" the keyboard: Escape doesn't pop out, there are no shortcuts for row selection / deletion / navigation, and the search-tables input grabs focus on page load. ## What is the new behavior? ### New shortcuts (all scoped to the table editor) | Keybind | Action | Surface | |---|---|---| | `Esc` | Exit grid selection — clears the highlighted cell and drops focus back to the page | hotkey | | `↑` / `↓` | Start grid navigation from the first cell when no cell is selected | hotkey | | `Shift+Space` | Toggle selection on the current row | hotkey + checkbox tooltip | | `Mod+A` | Toggle selection on all displayed rows (matches Excel) | hotkey + header-checkbox tooltip + Cmd+K | | `Mod+Shift+A` | Toggle selection on all rows in the table | hotkey + "Select all rows in table" button tooltip + Cmd+K | | `Mod+Backspace` | Delete selected rows | hotkey + delete-button tooltip + Cmd+K | ### Infrastructure - **Split registry** — table-editor shortcuts moved to `state/shortcuts/registry/table-editor.ts`, spread into `SHORTCUT_IDS`. Makes it easy to scope a runtime check to a specific surface. - **`eventMatchesAnyShortcut`** (`state/shortcuts/matchEvent.ts`) — queries the hotkey library's live `SequenceManager` so gated shortcuts (`enabled: false`) are correctly excluded. Covered by `matchEvent.test.ts`. - **`handleCellKeyDown`** now calls `event.preventGridDefault()` whenever the keystroke matches an active table-editor shortcut, so rdg's "start editing on key press" default doesn't compete with shortcut actions (e.g. typing `Shift+X` no longer opens edit mode with `X` as input). - **`<Shortcut>` / `<ShortcutTooltip>`** used on the header checkbox, the per-row checkbox, the "Select all rows in table" button, and the delete button — keybinds show up on hover (Linear-style) so users can discover them without reading docs. - **CSS** — `.rdg:not(:focus-within) .rdg-cell[aria-selected='true']` drops the selected-cell outline whenever focus leaves the grid, reinforcing the "you're out" feedback after `Esc`. - **`useShortcut`** wraps the Cmd+K-registered action to close the command menu after firing (previously menu stayed open after selecting an action). - **Search-tables input** no longer auto-focuses on load, so arrow shortcuts work immediately without clicking out first. ## Additional context Linear: FE-3057 ### Test plan - [x] Open any table → `↓` selects the first cell; subsequent arrows navigate rows - [x] `Esc` drops focus out of the grid and re-enables `↓` to re-enter - [x] Click a cell → `Shift+Space` toggles that row's selection (checkbox) - [x] `Mod+A` toggles all displayed rows - [x] With pagination + some rows selected → `Mod+Shift+A` toggles "Select all rows in table" - [x] With rows selected → `Mod+Backspace` deletes them (existing confirmation flow) - [x] Hover the header checkbox / per-row checkbox / delete button → keybind tooltip after ~500ms - [x] Cmd+K with selection → the relevant action shows up; selecting it closes the palette and runs <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added table editor keyboard shortcuts for navigation, row selection, and cell actions, with command-menu integration and visible shortcut tooltips. * **Improvements** * Better keyboard handling in grid cells allowing external shortcuts to override default behavior. * Select-all/deselect-all toggle and improved select-row UX; selected-cell styling no longer shows when grid loses focus. * Command menu now reliably closes before executing shortcut actions. * Removed autofocus on the table editor search input for consistent focus behavior. * **Tests** * Added unit tests covering shortcut matching and command-menu shortcut behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
072006ba0f | chore(studio): remove mobile toolbar flag (#45317) | ||
|
|
718021fc7b |
chore: migrate Listbox to Shadcn components (#45279)
## Problem We want to reduce the code we ship and maintain. ## Solution Migrate old `<Listbox />` usage to the new Shadcn component. ## Screenshots ### Billing Before: <img width="536" height="458" alt="image" src="https://github.com/user-attachments/assets/c8883bd8-cbbd-47cd-84a4-e37a36c05cd6" /> After: <img width="541" height="451" alt="image" src="https://github.com/user-attachments/assets/9c848b1b-e72a-413c-b264-48340ce0c7ef" /> ### Foreign Key Editor Before: <img width="463" height="995" alt="image" src="https://github.com/user-attachments/assets/4debeeeb-94bd-439d-8f57-a84a2ed5230a" /> <img width="428" height="241" alt="image" src="https://github.com/user-attachments/assets/81a21d58-c023-445a-a6e8-c9be22b53075" /> After: <img width="451" height="1007" alt="image" src="https://github.com/user-attachments/assets/18c781c0-4f52-4ca2-99e6-1fc34dc857e3" /> <img width="434" height="240" alt="image" src="https://github.com/user-attachments/assets/13fbb3ad-ef3c-499d-a27e-26cfae89ae44" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Replaced legacy dropdowns with a unified Select component and consistent form layout across payment method, org transfer, foreign-key/column selectors, region selection, and other dropdowns. * **Chores** * Removed the legacy listbox implementation and its public exports from the UI package. * **Tests** * Removed old listbox unit tests and updated e2e selectors to target the new Select-based controls. * **Style** * Deleted obsolete listbox-specific styles. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
65365213af |
feat(studio): logs header improvements (#45275)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? A little bit of tidy up here so the header area of unified logs isn't so dominant. Moved actions to the same line as search bar and made other parts a little more subtle, so the focus reamains on the logs themselves. | Before | After | |--------|--------| | <img width="980" height="213" alt="Screenshot 2026-04-27 at 11 47 37" src="https://github.com/user-attachments/assets/ae22e7dd-272f-4433-a270-67b550a00536" /> | <img width="893" height="153" alt="Screenshot 2026-04-27 at 12 27 17" src="https://github.com/user-attachments/assets/87b8cfc9-66a4-4634-a3c6-c45e4b8fc486" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Keyboard shortcut to toggle filter visibility in logs. * Consolidated top bar with refresh, view options, download, and live controls—desktop and mobile optimized. * **Style** * More compact, organized header with tooltips showing live status and shortcut hints. * Reduced filter input typography and streamlined mobile filter trigger. * **Other** * Side panel sizing and logs area layout refined for clearer visuals and consistent header/body styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
202c085cf7 |
Merge rls tester callouts (#45312)
## Context Just merging the callouts - only show one at a time, instead of both ### Before <img width="610" height="518" alt="image" src="https://github.com/user-attachments/assets/58567f7e-99bf-4c84-8392-35573c646af6" /> ### After <img width="605" height="428" alt="image" src="https://github.com/user-attachments/assets/975a5a30-2b36-4602-af8f-b79c2383f38b" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enhanced RLS Tester to prevent conflicting policy status messages from appearing simultaneously. The interface now properly displays only the relevant message about policy configuration and evaluation status, improving clarity when reviewing row-level security results. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
308cd791a2 |
chore: Prep work for migrating to Tailwind v4 (#45285)
This PR preps the monorepo for a migration to Tailwind v4: - Bump all Tailwind dependencies and libraries to the latest possible version, while still compatible with Tailwind 3. - Cleans up obsolete Tailwind 3 specific options and configs. - Cleans up unused CSS files and fixes the CSS imports. - Migrates all `important` uses in `@apply` lines to using the `!` prefix. - Move `typography.css` to the `config` package and import it from the apps. - Migrated all occurrences of `flex-grow`, `flex-shrink`, `overflow-clip` and `overflow-ellipsis` since they're deprecated and will be removed in Tailwind 4. - Make the default theme object typesafe in the `ui` package. - Migrate all `bg-opacity`, `border-opacity`, `ring-opacity` and `divider-opacity` to the new format where they're declared as part of the property color. - Bump and unify all imports of `postcss` dependency. |
||
|
|
2d92563b57 |
fix(studio): add resume project flow to project settings (#45078)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. Resolves DEPR-511. ## What is the current behavior? Paused projects in `Project Settings > General > Project availability` still present restart/pause maintenance controls, but no resume affordance. That makes the resume path hard to discover from Settings and pushes users back to the project dashboard to find the correct action. The paused state also keeps showing a redundant disabled `Pause project` row, and the pause confirmation uses a more flexible modal than this flow needs. DEPR-519 already covered the unhealthy-project restart guard, but not this paused-project discoverability path. ## What is the new behavior? Project Settings is now paused-project aware. It shows a shared `Resume project` action when the project can still be restored, falls back to the project dashboard when the restore window has expired or pause status cannot be confirmed, and reuses the same resume flow, permission checks, and free-tier guardrails as the paused dashboard. While a project is already paused, the redundant `Pause project` row is hidden so the section stays focused on the real next action. For active projects, the pause row remains in place, including the useful disabled tooltip states for plans that cannot pause. The pause confirmation now uses `AlertDialog` with shorter, more accurate copy about the restore window, and the restart controls now behave more consistently on smaller breakpoints. The Project Settings command-menu entry is also searchable via `resume project`. | Before | After | | --- | --- | | <img width="1602" height="566" alt="CleanShot 2026-04-24 at 18 05 25@2x" src="https://github.com/user-attachments/assets/bd8f4095-0360-443c-a179-185da69eb9e8" /> | <img width="1538" height="408" alt="CleanShot 2026-04-24 at 18 06 12@2x" src="https://github.com/user-attachments/assets/7ac26529-4b54-460e-89c3-927891d873d8" /> | | <img width="1524" height="524" alt="CleanShot 2026-04-24 at 18 08 53@2x" src="https://github.com/user-attachments/assets/f3c49c46-b389-4324-b982-f557b159623e" /> | <img width="1528" height="550" alt="CleanShot 2026-04-24 at 18 08 30@2x" src="https://github.com/user-attachments/assets/4021e2bb-f22f-40db-be43-de6d0fb571b3" /> | | <img width="896" height="558" alt="CleanShot 2026-04-24 at 17 41 40@2x" src="https://github.com/user-attachments/assets/31569aec-89a6-4984-8011-39d8b102c90f" /> | <img width="912" height="502" alt="CleanShot 2026-04-24 at 18 10 34@2x" src="https://github.com/user-attachments/assets/f19dcd27-12e6-4a2f-8eed-ca709e77dfa1" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a tooltip-enabled "Resume project" button that handles permissions, free-plan member gating, optional Postgres version selection, and navigates to the project after restore. * **UX** * Pause confirmation migrated to an alert-style dialog with updated copy and disabled controls during pausing. * Restart controls updated for improved responsive layout and refreshed button visuals. * Project settings now show appropriate resume/dashboard actions based on pause/restore eligibility. * **Tests** * Added tests for active, resumable-paused, and non-resumable-paused states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
dab1512fe9 |
Add callout for feature preview rls tester (#45307)
## Context Adds a banner on the auth policies page for the new RLS tester feature preview <img width="307" height="310" alt="image" src="https://github.com/user-attachments/assets/6864c2cb-c3b8-4c1f-8dce-57411425e17d" /> Also adds a Give feedback button in the RLS Tester sheet footer <img width="616" height="73" alt="image" src="https://github.com/user-attachments/assets/64755f56-4e27-4b54-92b2-a894badc0b88" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * RLS Tester preview banner added to the policies page with animated content and a locally persisted dismissed state. * Enabling the RLS Tester via the preview also dismisses and records the banner dismissal. * New feedback link added to the RLS Tester UI that opens in a new tab. * **Layout/Providers** * Banner stack context moved so banner state is available more broadly across the app. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bedb2efb87 |
chore(studio): JIT access UI improvements (#44161)
## What kind of change does this PR introduce? UI and copywriting improvements for temporary access. ## What is the current behavior? The temporary access UI still used older JIT/ephemeral naming in some places, did not clearly explain the setup requirements, and had to infer unavailable states from Platform error message text. ## What is the new behavior? The settings UI now uses temporary access naming consistently, explains that temporary access uses short-lived tokens for manual database connections, and renders clearer unavailable states for projects that require either a Postgres upgrade or a platform migration. The Studio query now consumes Platform’s structured `unavailableReason` contract instead of parsing human-readable error strings, so the UI owns the copy while Platform owns the eligibility reason. Validation: - `pnpm eslint components/interfaces/Settings/Database/JitDatabaseAccess/JitDbAccessConfiguration.tsx data/jit-db-access/jit-db-access-query.ts` - `pnpm tsc --noEmit --pretty false` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * IP range input now supports one CIDR range per row with add/remove rows and form integration. * **Documentation** * Replaced “JIT” wording with “Temporary” / “Ephemeral token-based” access across UI, dialogs, toasts, and help links. * Added minimum PostgreSQL version requirement (17.6.1.081+). * **Improvements** * Per-row CIDR validation with precise nested error messages. * Refined layout spacing and moved the temporary-access configuration earlier in Database settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Etienne Stalmans <etienne@supabase.io> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
96939829bc |
change to useFlag not usePHFlag (#45265)
Just replace PH flag with ConfigCat flag for edge functions index error rates <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Switched how the feature flag for edge functions request metrics is read, affecting whether last-hour metrics columns are displayed. * **Bug Fix** * Fixed table layout so the "No results found" row correctly spans the appropriate number of columns depending on whether last-hour stats are shown, preventing misaligned table rows and improving display consistency. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
a1cdfaeca1 |
feat: open oauth apps in new tab to avoid losing studio context (#45304)
Currently when a user clicks the **Install integration** button on an OAuth integration like Grafana, they are redirected to the partner website in the same tab in which they clicked the button. This makes them lose context in the Supabase Studio. This PR changes the behaviour such that the partner website will be opened in a new tab. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * OAuth integration installation now opens the redirect URL in a new browser tab instead of redirecting the current window, allowing users to remain in the application while completing the integration process. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5f867e5f6c |
Feature Preview: RLS Tester (#45121)
## Context Resolves FE-3077 Related discussion: https://github.com/orgs/supabase/discussions/45233 Verifying the correctness of your RLS policies set up has always been a gap, as highlighted by a number of GitHub discussions like [here](https://github.com/orgs/supabase/discussions/12269) and [here](https://github.com/orgs/supabase/discussions/14401). As such, we're piloting a dedicated UI for RLS testing (using role impersonation as the base), in which you'll be able to - Run a SQL query as a user (not logged in / logged in - this is the role impersonation part) - See which RLS policies are being evaluated as part of the query - And hopefully be able to debug which policies are not set up correctly Changes are currently set as a feature preview - and we'll iterate as we get feedback from everyone 🙂 🙏 <img width="613" height="957" alt="image" src="https://github.com/user-attachments/assets/83c37f8a-28fc-43b3-b0ff-e28571d8710c" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * RLS Tester: run queries as anon or authenticated users, view inferred SQL, per-table policy summaries, and data previews of accessible rows. * UI preview: new RLS Tester preview card and modal with opt-in toggle; RLS Tester sheet with role/user selector and query editor. * SQLEditor: “Explain” tab is always visible. * **Chores** * Added supporting API endpoints, background checks for table RLS status, and a local-storage flag to persist the preview opt-in. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
aa674dd536 |
fix(studio): unused credit card expiry label in test (#45300)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? PR #44965 introduced an unused `cardExpiryLabel` constant in `CreditCard.tsx`, which causes `studio#typecheck` to fail with `TS6133` after the branch is merged into `master`. ## What is the new behavior? Removes the unused constant so Studio typecheck passes again without changing payment method behaviour. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed unused code to improve code quality and maintainability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9e3a10d557 |
feat(studio): payment method states for Stripe Projects orgs (#44965)
## What kind of change does this PR introduce? UI changes for Stripe-managed billing surfaces. - Resolves DEPR-537 - Related to DEPR-538 ## What is the current behaviour? Stripe-connected organisations still look too self-serve in Studio. - Payment Methods still reads mostly like ordinary Supabase card management, even though billing is handled through a Shared Payment Token via Stripe Projects - invoice messaging still implies support is the path to changing payment methods, even for Stripe-managed orgs - the Subscription Plan flow still needs Stripe-specific guardrails so users are redirected to the correct upgrade path rather than trying to self-serve everything in Studio - the base branch now correctly separates `integration_source` from `billing_partner`, but this stacked work still needs to carry that split through the Stripe billing-token surfaces ## What is the new behaviour? This PR makes the Stripe-managed billing surfaces behave like Stripe-managed billing surfaces, while leaving AWS and Vercel on the existing `billing_partner` path. - Payment Methods now keeps the familiar saved-card row, but augments Stripe-managed rows with Shared Payment Token context, token status, and Stripe Projects affordances - Stripe-managed invoice messaging now points users to Stripe Projects rather than to support for payment-method changes - the Subscription Plan flow keeps the existing managed-billing shape, with Stripe-specific guardrails layered in where plan changes should be handled outside Studio - AWS and Vercel continue to use the existing partner-managed alerts and CTAs driven by `billing_partner` / `billing_via_partner` | Subscription plan sheet | | --- | | <img width="1780" height="448" alt="CleanShot 2026-04-24 at 17 21 43@2x" src="https://github.com/user-attachments/assets/34c0f3ba-fc42-4d07-97a2-0e4f4cefc55e" /> | | _Upgrade instructions_ | | <img width="1786" height="460" alt="CleanShot 2026-04-24 at 17 20 12@2x" src="https://github.com/user-attachments/assets/bb67c835-b9b2-4648-b0e1-9c2f8d2317d3" /> | | _Downgrade instructions_ | > [!NOTE] > The below screenshots are outdated. The _Shared Payment Token_ terminology has been removed in favour of more generic copy such as _Stripe Projects token_. | Stripe payment method states | | --- | | <img width="1436" height="234" alt="CleanShot 2026-04-23 at 19 03 49@2x" src="https://github.com/user-attachments/assets/52ed7a00-dfba-4b66-9a07-a6346692d3c8" /> | | _Healthy_ | | <img width="1434" height="224" alt="CleanShot 2026-04-23 at 19 04 50@2x" src="https://github.com/user-attachments/assets/94efd943-b7bf-4da2-9e1b-1828aae97126" /> | | _Card expiring soon_ | | <img width="1436" height="236" alt="CleanShot 2026-04-23 at 19 06 51@2x" src="https://github.com/user-attachments/assets/272cb707-c724-4629-890e-853972e53a18" /> | | _Card expired_ | | <img width="1308" height="238" alt="CleanShot 2026-04-23 at 19 07 21@2x" src="https://github.com/user-attachments/assets/3eadd2a9-def3-4f43-850e-7d82adfb0b57" /> | | _Token expired_ | ## Dependencies This PR is stacked on: - #44328 It also depends on the private platform work that exposes Stripe project connection state and SPT details: - https://github.com/supabase/platform/pull/31874 - https://github.com/supabase/platform/pull/31940 ## Platform dependency status Most of the remaining platform work for this stack is now covered by the private dependency below: - https://github.com/supabase/platform/pull/31940 That PR is expected to provide the SPT details and paid-flow fixes this Studio work depends on. In practice, the main caveat here is less “Studio still needs a bunch of new platform work” and more “do not merge this until `platform#31940` has landed and the end-to-end Stripe-managed flow has been rechecked”. ## Local testing Use the same local Stripe setup as the base branch, with `integration_source: 'stripe_projects'` returned consistently for: - `/platform/organizations` - `/platform/organizations/:slug/projects` - `/platform/projects/:ref` For payment method demos, the temporary local mock currently lives in private `platform` on: - `/platform/organizations/:slug/payments` That mock can be flipped between: - healthy token + healthy underlying card - healthy token + card expiring soon - healthy token + expired card - expired token Then verify: - the org and project connection affordances from #44328 still render correctly - Payment Methods shows Stripe-managed token context rather than implying ordinary self-serve card management - regression test ordinary non-Stripe payment methods too, to confirm the standard saved-card row still renders with the existing `Expires:` copy and no Shared Payment Token affordances - invoice messaging points Stripe-managed orgs to Stripe Projects rather than support - Subscription Plan keeps the managed-billing guardrails for Stripe - AWS and Vercel orgs still show the existing partner-managed messaging rather than the Stripe-specific notices <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Stripe-managed organizations show Stripe Projects billing guidance, replace in-app payment management with Stripe links, and adjust billing copy. * Payment methods support Shared Payment Tokens (SPTs): token expiry/status badges with tooltips, “Handled via Stripe Projects” indicator, token last4/expiry display, and disabled local update/delete actions for SPTs. * **API** * Payments response now includes optional shared payment token details for payment methods. * **Documentation** * Added links to Stripe Projects billing docs in relevant flows. * **Tests** * Updated and added tests covering Stripe-managed and SPT behaviors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Raúl Barroso <code@raulb.dev> |
||
|
|
98211ed3dc | feat: update CreditTopUp to mention pre-tax credits (#45255) | ||
|
|
4763ac8374 |
fix: show plan name on empty orgs (#45247)
## Summary - Show the plan name row in the monthly invoice estimate tooltip even when the organization has no projects, so the section no longer appears headerless next to the tax line. ## Test plan - [ ] Open an org with no projects → Subscription plan update dialog → hover the "Monthly invoice estimate" tooltip → verify the plan name + price row is visible. - [ ] Repeat on an org with projects → verify plan, Compute row, and project breakdown all still render as before. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved rendering of the Monthly invoice estimate table in the subscription plan update dialog, with reorganized display logic for plan and project billing rows. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7dcf677a95 |
feat: add loading indicator and ChargeBreakdown in NewOrgForm (#45236)
## Summary - Show a `ShimmeringLoader` skeleton in the new-org form while the creation preview is fetching for the first time, so users see feedback after entering their billing address. - Disable the **Create organization** button while the preview is refetching, to prevent submitting on stale totals. - Replace the inline charge summary with the shared `ChargeBreakdown` component, extending it with an optional `subtotalLabel` prop (defaults to `"Subtotal"`, `"Plan price"` here) to preserve the existing copy. ## Test plan - [ ] Navigate to `/new` → pick Pro/Team → enter a billing address → confirm shimmer shows until the first preview resolves. - [ ] Change address/tax ID → confirm existing totals fade to 50% while refetching and the submit button is disabled during the fetch. - [ ] Confirm the breakdown still renders "Plan price", "Tax (x%)", and "Total due today" correctly - [ ] FREE plan path unaffected — no preview request, submit button behaves as before. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Organization creation form now displays loading placeholders while billing preview data is being fetched, providing clearer visual feedback during the calculation process * Submit button is now properly disabled during billing information retrieval * Billing breakdown display has been refined for improved consistency <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
43e437140b |
feat(studio): add disable action for custom OAuth providers (#45221)
## Summary - Adds an Enable/Disable dropdown action in each row of the custom OAuth providers list. - Disabling opens a confirmation modal that calls the existing update API with `enabled: false`; enabling is immediate (restorative, no confirmation). - Removes the hardcoded `enabled: true` from the edit sheet's update payload so editing a disabled provider no longer silently re-enables it. Closes [FE-3067](https://linear.app/supabase/issue/FE-3067/add-disable-button-for-custom-oauth-providers). ## Test plan - [x] Create a custom OAuth provider — it is enabled by default. - [x] Click the row menu → "Disable". Confirm in the modal. Row shows `Disabled` badge. - [x] Click the row menu → "Enable". Row immediately flips back to `Enabled`. - [x] Edit a disabled provider via the "Update" action, save. Verify it remains `Disabled` (no silent re-enable). - [x] Delete action still works. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Added enable/disable toggle controls for individual custom OAuth providers in the provider list * Added confirmation dialog when disabling a provider to prevent accidental changes <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5f6060197e |
[COM-205] feat(studio): add logs:all flag to hide all logs (#45202)
Adds a top-level `logs:all` flag (default `true`) so self-hosted and local setups can hide the logs pages in Studio when Logflare isn't configured — no separate Studio build required. The flag itself works everywhere; the additional `ENABLED_FEATURES_LOGS_ALL` env-var override (from FE-3036) is the self-hosted escape hatch so deployers can flip it without a custom build — that part is a no-op on `IS_PLATFORM` because hosted feature gating flows through `profile.disabled_features` instead. Addresses [COM-205](https://linear.app/supabase/issue/COM-205/add-feature-flag-to-disable-all-logs-in-studio). **Added:** - `logs:all` feature flag in `enabled-features.json` + schema **Changed:** - Sidebar "Logs" nav entry is hidden when `logs:all` is off (same pattern as `reports:all` / `billing:all`) - Cmd-K "Logs Explorer" / "Auth Logs" / etc. routes are hidden when the flag is off - `LogsLayout` renders `<UnknownInterface />` (soft-404) when the flag is off — covers all ~18 logs pages in one spot - `/logs/index.tsx` applies the same soft-404 for the unified-logs entry point ## To test Needs to be tested locally (preview doesn't let you flip the flag — hosted gating is profile-driven, not env-driven). Two ways: - Temporarily edit `"logs:all": false` in `packages/common/enabled-features/enabled-features.json` and run `pnpm dev:studio`, or - Run Studio locally with `ENABLED_FEATURES_LOGS_ALL=false` (env-var path, same as how self-hosted deployers would use it) With the flag **off**: - Sidebar "Logs" entry is hidden - Cmd-K search for "Logs" / "Auth Logs" / "Postgres Logs" etc. returns nothing - Direct navigation to `/project/<ref>/logs`, `/project/<ref>/logs/explorer`, `/project/<ref>/logs/auth-logs`, `/project/<ref>/logs/postgres-logs` (etc.) all render the "Looking for something?" soft-404 with a Head back button With the flag **on** (default): everything works as it does today. **Check on the preview deploy too** — nothing should change, no behaviour difference on hosted. Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
32071e75e1 |
fix(studio): unblock advisor panel loading state on self-hosted (#45283)
## Summary Fixes [FE-3080](https://linear.app/supabase/issue/FE-3080/self-hosted-studio-advisors-toolbar-shows-blank-panel). On self-hosted Studio, opening the Advisors panel rendered an infinite skeleton with no network traffic. ## Root cause `useBannedIPsQuery` is gated by `IS_PLATFORM`. On self-hosted that disables the query — and a disabled React Query v5 query keeps `isPending: true` forever (only `isFetching` / `isLoading` go false). `useAdvisorSignals` re-exports that `isPending`, and `AdvisorPanel` folded it into its `isLoading` aggregate, pinning the panel into the skeleton state in `AdvisorPanelBody`. The other consumers were already designed around this — `AdvisorSection` on the home page explicitly does not wait on signals, and `AdvisorButton` only reads `data`. Only `AdvisorPanel` had the regression, introduced in #44372. ## Fix Drop `isSignalsActuallyLoading` from the panel's `isLoading` aggregate, mirroring the existing `[Joshen]` "ignore signal errors" exclusion two lines below and matching the home-page pattern. ## Test plan - [x] Existing unit + integration tests pass (`AdvisorPanel.utils`, `useAdvisorSignals`, `AdvisorSignals.integration` — 6/6) - [x] Verify on self-hosted Studio: open the Advisors sidebar and confirm lints render (or "no issues" empty state appears) instead of an infinite skeleton - [x] Verify on hosted Studio: lints, banned-IP signals, and notifications still render together; loading skeleton still appears while lints/notifications are in flight <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved loading state behavior in the Advisor Panel by excluding signal queries from blocking the panel's display. The loading indicator now only appears when actively fetching lints or notifications, allowing faster visibility of available content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
049909632e |
fix: remove unused import (#45281)
#45232 reintroduced an unused variable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Cleaned up unused code dependencies to improve code quality and maintainability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bc3dc73240 |
chore: migrate old <Select /> usage to the new Shadcn component (#45232)
## Problem We want to reduce the code we ship and maintain. ## Solution Migrate old `<Select />` usage to the new Shadcn component. ## Screenshots ### `www` Pricing Before: <img width="637" height="697" alt="image" src="https://github.com/user-attachments/assets/b6f261de-e587-411b-9408-faf94d709f1c" /> After: <img width="644" height="756" alt="image" src="https://github.com/user-attachments/assets/8cc4894c-64da-4e6a-960c-77cd162ac71d" /> ### Observability Before: <img width="1015" height="452" alt="image" src="https://github.com/user-attachments/assets/3d7e8613-e7a6-461d-a50d-e66c7c85fef1" /> After: <img width="833" height="467" alt="image" src="https://github.com/user-attachments/assets/98ace34f-25ec-48b5-aad3-fe812307b01d" /> ### Docs Realtime Used in pages: - https://supabase.com/docs/guides/realtime/postgres-changes - https://supabase.com/docs/guides/realtime/benchmarks Before: <img width="578" height="437" alt="image" src="https://github.com/user-attachments/assets/22fa0048-be07-42e0-9153-65171fa3ccb9" /> After: <img width="571" height="423" alt="image" src="https://github.com/user-attachments/assets/e0adbde9-0c6f-48da-b377-516392185fb0" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Updated dropdown/select controls across the app to a consistent, composable implementation * Replaced advanced JWT generator in docs with a simplified JWT generator component * **Chores** * Removed legacy select component, associated styles and exports * Updated theme and tests to align with the new select implementation <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dfd3eec8e9 |
feat(studio): compute metrics on project diagram Primary Database card (#45274)
## Problem The Primary Database card in the project homepage diagram showed region and instance size, but no live health data. Users had no quick way to spot a high-disk or high-CPU situation without navigating to the database report. ## Fix Added a clickable metrics row at the bottom of the Primary Database card showing CPU, Disk, and RAM as percentages, plus active/max connections when available. Each metric is color-coded (warning at 80%, destructive at 90%). Clicking the row navigates to the database observability report. The metrics are powered by a new \`useComputeMetrics\` hook that wraps the existing \`useInfraMonitoringAttributesQuery\` and \`useMaxConnectionsQuery\`, reusing the parse utilities already used by the database infrastructure section. The \`metricColor\` threshold logic is extracted into a separate util with unit tests. ## How to test - Open the project homepage for a running project - The Primary Database card should show a new bottom row: "CPU X% · Disk X% · RAM X% · Y/Z conns" - Values above 80% should appear in amber, above 90% in red - Click the metrics row and confirm it navigates to \`/project/<ref>/observability/database\` - While metrics are loading, a spinner should appear in the row - If the infra monitoring API is unavailable, the row should show "Metrics unavailable" instead of zeroes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Infrastructure configuration page now displays real-time compute metrics (CPU, disk, memory usage) with color-coded usage indicators based on thresholds. * Connection information is displayed when available. * Includes loading states and error handling for metric retrieval. * **Tests** * Added test coverage for metric color-coding logic. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
67deabf67e |
fix: create etl publication as postgres (#45043)
## What kind of change does this PR introduce? Bug fix ## What is the current behavior? Creating a schema only branch fails because ETL publication is owned by `supabase_etl_admin` which users have no access. ## What is the new behavior? Since ETL supports user managed publications, create them through pgmeta so it's owned by `postgres` role instead. ## Additional context mirrors [upstream etl](https://github.com/supabase/etl/blob/main/etl-api/src/db/publications.rs#L22-L51) implementation <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Added guards to prevent creating publications when project or connection info is missing, with clearer error logging. * Ensure the project connection string is explicitly passed so publications target the correct database. * **Refactor** * Publication creation now executes generated SQL directly against the database, with correct handling of empty or selected table lists and proper identifier quoting for reliability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: CodeRabbit <noreply@coderabbit.ai> |
||
|
|
7f5865872a |
Enforce noUnusedLocals and noUnusedParameters in tsconfig.json + fix all related issues (#45264)
## Context Enforce `noUnusedLocals` and `noUnusedParameters` in tsconfig.json + fix all related issues |
||
|
|
416210d666 |
chore: remove _Shadcn_ suffix for Checkbox and Radio components (#45263)
## Problem With #45211 and #45218 merged, we don't need the `_Shadcn_` suffix anymore ## Solution - [x] Remove the `_Shadcn_` suffix - [x] Update exports and imports <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized UI component exports by removing legacy naming conventions and providing direct imports for checkbox and radio group components throughout the design system. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7f4b02f2a7 |
chore: update radix (#45111)
## Problem In order to update to react 19, we need to update several dependencies ## Solution - migrate to the `radix` umbrella package to ease upgrade - update some dependencies <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Consolidated Radix UI usage to a single unified package across apps and packages, updated package manifests and workspace catalog entries. No user-facing behavior, visuals, or public APIs changed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
819ce91f1a |
fix: org slug filter (#45262)
missing a filter on org slug in org-level audit logs, causing events to be matched to the first org in the array. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed organization label display in audit logs to correctly show the organization associated with each log entry. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4afbe9c2b2 |
feat: lint integration for pg_graphql introspection + SECURITY DEFINER functions (#45260)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — wires up three new advisor lints landed in splinter, and updates the self-hosted SQL bundle for the existing `pg_graphql_anon_table_exposed` lint to track splinter's correctness fixes. Companion to `supabase/splinter` #160 (already merged) and #162 (test fix in flight). ## What is the current behavior? Splinter's `main` now exposes four lints in the pg_graphql / SECURITY DEFINER family: - `pg_graphql_anon_table_exposed` (0026, existing) — wired into Studio in #45253; SQL in `packages/pg-meta` is the original version that uses `has_table_privilege` and the relkind set `('r','p','v','m')`. - `pg_graphql_authenticated_table_exposed` (0027, new) — paired check against the `authenticated` role. Studio renders any new finding without a `lintInfoMap` entry as a row with no icon, no title mapping, and no "Fix" CTA. Self-hosted users do not see the lint at all because `packages/pg-meta` does not include it. - `anon_security_definer_function_executable` (0028, new) — `SECURITY DEFINER` function executable by `anon`. Same Studio + self-hosted gaps as 0027. - `authenticated_security_definer_function_executable` (0029, new) — same against `authenticated`. Splinter has also updated 0026 itself (PR #160) in two ways that need to flow into the self-hosted SQL bundle: 1. **`relkind` filter:** `('r','p','v','m')` → `('r','v','m','f')`. Drops partitioned table roots (pg_graphql does not expose them; their leaf partitions are still covered as `'r'`) and adds foreign tables, which pg_graphql does expose. 2. **Privilege predicate:** `has_table_privilege(role, oid, 'SELECT')` → `EXISTS` over `pg_attribute` calling `has_column_privilege`. Catches column-level grants such as `GRANT SELECT (col) ON t TO anon`, which pg_graphql's introspection exposes but `has_table_privilege` missed. Cloud projects auto-fetch `splinter.sql` via the platform mgmt-api's `getLintSql` (1-hour cache TTL), so they pick up #160's lint and SQL changes independently of this PR. This PR is about the Studio display mapping and the self-hosted SQL bundle. ## What is the new behavior? Two minimal additions, mirroring the integration shape of #45253. ### `apps/studio/components/interfaces/Linter/Linter.utils.tsx` Three new entries appended to `lintInfoMap`: - `pg_graphql_authenticated_table_exposed` — `Eye` icon (paired with the existing `pg_graphql_anon_table_exposed` entry); link points to the Table Editor scoped to `metadata.schema` + `metadata.name`; `linkText: 'View object'`; `category: 'security'`. - `anon_security_definer_function_executable` — `Unlock` icon (signals "this thing is callable when it shouldn't be"); link points to the Database Functions browser scoped to `metadata.schema` + `metadata.name`; `linkText: 'View function'`; `category: 'security'`. - `authenticated_security_definer_function_executable` — same as 0028 against `authenticated`. Each entry's `docsLink` points at the splinter-hosted lint doc. ### `packages/pg-meta/src/sql/studio/advisor/lints.ts` The existing `pg_graphql_anon_table_exposed` SQL block is updated in place to match the new splinter version: new `relkind` set, `case` statement for `'f'`, and the `EXISTS` over `pg_attribute` privilege check. Three new `union all` blocks are appended for 0027/0028/0029. The function lints (0028/0029) include the `pgrst.db_schemas` filter (mirroring lint `0023_sensitive_columns_exposed`) so findings are scoped to schemas PostgREST actually exposes; the self-hosted query wrapper already sets the GUC when `exposedSchemas` is passed (`enrichLintsQuery`). ## Coverage of the four exposure paths | Role | Tables/views/MVs/foreign tables | SECURITY DEFINER functions | |------|---------|----------| | `anon` | 0026 (existing, updated) | 0028 (new) | | `authenticated` | 0027 (new) | 0029 (new) | The 0026/0027 pair covers `pg_graphql` introspection visibility; the 0028/0029 pair covers RLS bypass via privileged function execution through `/rest/v1/rpc` (and `/graphql/v1` for compatible return types). Each lint's doc cross-references its sibling so an operator hitting one is steered toward the others. ## Verification - `cd packages/pg-meta && npx tsc --noEmit` — clean. - `cd apps/studio && npx tsc --noEmit` — clean for the changed file. (Other unrelated TS errors exist in the working tree but are pre-existing and not introduced by this PR.) - `cd apps/studio && npx eslint components/interfaces/Linter/Linter.utils.tsx` — clean. ## Files - `apps/studio/components/interfaces/Linter/Linter.utils.tsx` — adds three `lintInfoMap` entries (0027, 0028, 0029). - `packages/pg-meta/src/sql/studio/advisor/lints.ts` — updates the 0026 SQL block to match splinter's correctness fixes, appends 0027/0028/0029 SQL blocks. ## Related - supabase/splinter#160 — adds 0027/0028/0029 and rewrites 0026 (merged). - supabase/splinter#162 — fixes test setup for 0028/0029 (in flight; does not affect the SQL shipped here). - supabase/supabase#45253 — original 0026 Studio integration. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added security linting to detect authenticated-table exposure and executable SECURITY DEFINER functions. * Added signed-in visibility checks alongside anonymous checks. * **Bug Fixes / Improvements** * Improved relation type handling for accurate table/foreign/partition classification. * Switched to column-level privilege analysis for visibility. * Improved entity naming shown in lints (includes function argument display). <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
801b912fc8 |
feat: lint for pg_graphql introspection fix (#45253)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — wires up the new advisor lint `pg_graphql_anon_table_exposed` so it renders properly in Studio and ships with self-hosted Supabase. The lint itself was added to splinter in supabase/splinter#158 (already merged). ## What is the current behavior? Splinter's `main` exposes lint `0026_pg_graphql_anon_table_exposed`, which detects tables, views, and materialized views whose schema is visible through the public `/graphql/v1` introspection endpoint when the `anon` role has `SELECT` on them. The hosted advisor (mgmt-api) auto-fetches `splinter.sql` from raw.githubusercontent.com, so the lint will start firing on cloud projects, but: - Studio has no `lintInfoMap` entry for it, so the row renders without an icon, title mapping, "Fix" CTA, or category classification. - Self-hosted Supabase ships with a vendored copy of the lint SQL in `packages/pg-meta`; without an update there, self-hosted users never see the lint at all. ## What is the new behavior? Two minimal additions: - **`apps/studio/components/interfaces/Linter/Linter.utils.tsx`** — adds a `lintInfoMap` entry for `pg_graphql_anon_table_exposed`: title `"pg_graphql Anon Role Exposes Objects in Introspection"`, `Eye` icon, `security` category, `"View object"` CTA pointing at the table editor scoped by `metadata.schema` and `metadata.name`, docs link to the splinter docs page. - **`packages/pg-meta/src/sql/studio/advisor/lints.ts`** — vendors the lint's SQL block into `getLintsSQL()` so self-hosted deployments include it. Follows the file's documented copy-paste convention from splinter: every backtick inside SQL string literals is escaped (`` ` `` → `` \` ``), and the hardcoded docs URL is replaced with `${literal(\`${docsUrl}/...\`)}`. No changes to the OpenAPI surface, no changes to the `LINT_TYPES` literal union (auto-generated; matches the precedent of how lints 0023–0025 were added — Studio's `LintInfo.name` is typed as `string`, not the strict enum). ## Additional context - Splinter PR (merged): https://github.com/supabase/splinter/pull/158 - Splinter lint source: https://github.com/supabase/splinter/blob/main/lints/0026_pg_graphql_anon_table_exposed.sql - Splinter docs page: https://github.com/supabase/splinter/blob/main/docs/0026_pg_graphql_anon_table_exposed.md - The hosted advisor flow that fetches splinter.sql automatically lives in the platform mgmt-api (`getLintSql` in `advisors-utils.ts`), with a 1-hour cache TTL — cloud projects will pick up the new lint independently of this PR; this PR is about the Studio display mapping and the self-hosted SQL bundle. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a new security linter check that identifies tables and views exposed to anonymous GraphQL access, with warnings and remediation guidance to help resolve the issue. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
07d75d4e79 |
feat: add TaxDisclaimer for addons (#45235)
## Summary
Adds a reusable `TaxDisclaimer` component ("Prices shown do not include
applicable taxes.") and places it on surfaces where users see a price
before confirming a billable action.
## Where it appears
- **Disk resize review
dialog** — `DiskManagementReviewAndSubmitDialog` (below the before/after
price comparison)
- **Add-on side panels** — PITR, Custom Domain, IPv4 (below the price
options)
- **Log drain destination form** — stacked under "See full pricing
breakdown here" in the footer
- **SMS MFA confirmation modal** — below the $75/$10 billing copy
- **Read replica pricing dialog** — at the end of the cost breakdown
- **Create branch modal** — below the disk/compute cost estimates
## Test plan
- [ ] Open disk/compute resize review dialog — disclaimer appears below
the before/after panel
- [ ] Open each add-on side panel (PITR / Custom Domain / IPv4) —
disclaimer appears below the price options
- [ ] Open log drain destination sheet — disclaimer stacks under the
pricing breakdown link in the footer
- [ ] Trigger SMS MFA confirmation — disclaimer appears below the
billing copy
- [ ] Open read replica pricing dialog ("Learn more" from deploy
replica) — disclaimer at the bottom
- [ ] Open create branch modal — disclaimer appears after the compute
cost block
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added tax disclaimers across multiple billing and pricing interfaces
throughout the platform. Users will now see notices regarding applicable
taxes displayed in various authentication settings, branch creation
workflows, database disk management dialogs, database replica pricing
screens, log drain configuration panels, custom domain settings, IPv4
address configuration, and Point-in-Time Recovery options.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
429f1ccd32 |
fix: don't reset payment method form on backend error (#45230)
## Problem When creating a new paid organization, if the backend rejects the request (e.g. invalid tax ID, invalid billing address, name conflict, rate-limit), the Stripe payment UI was torn down and remounted empty. ## Solution - Remove `resetPaymentMethod()` from the org-create mutation's `onError`. Server-side validation failures don't consume or invalidate the Stripe payment method, so there's no reason to tear down the Elements. - Collapse the paid-plan submit flow so that `createPaymentMethod()` is called on every attempt (not just the first). This materializes a fresh `PaymentMethod` from whatever is currently in the Stripe Elements - correctly capturing edits the user made between attempts (including card number changes), and guaranteeing the latest address/tax ID are sent. ## Test plan - [ ] Go to `/new`, pick **Pro**, fill a valid card (`4242 4242 4242 4242`) and address, tick "I'm purchasing as a business", select a tax ID type and enter an **invalid** tax ID value → submit - [ ] Confirm: error toast appears, card number + address fields + tax ID selector + tax ID value remain populated, loading state clears - [ ] Correct the tax ID and resubmit → confirm the network request contains the **corrected** `tax_id` (not `undefined`) and succeeds - [ ] Regression: create a Free org still works - [ ] Regression: a 3DS failure on a paid org still resets the payment method (that path goes through `PaymentConfirmation.onError`, unchanged). Use card `4000002760003184` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved payment method handling during organization creation for paid plans. The system now consistently attempts to create payment methods and properly handles failures. Payment information is preserved on errors, providing a more reliable organization setup experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |