mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 19:05:06 +03:00
cli/docs-example-how-to
19329
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
84dafb5998 | Merge branch 'master' of github.com:supabase/supabase into cli/docs-example-how-to | ||
|
|
4096267623 |
feat(api-keys): migrate last-used indicator to ClickHouse endpoint (#47458)
## Problem The "last used" indicator for the legacy `anon` / `service_role` API keys (Project API keys settings) was disabled because it ran a BigQuery `edge_logs` query. It is now re-enabled against the ClickHouse-backed `api_keys.last_used.otel` analytics endpoint. ## Current behavior - The `anon` / `service_role` "last used" indicator is off (the BigQuery-backed query was disabled). ## New behavior - New `useApiKeysLastUsedQuery` hook calls the `api_keys.last_used.otel` endpoint (timestamp params only, no SQL sent), plus its query key and the generated platform API type. - `DisplayApiSettings` reads last-used from this hook instead of posting BigQuery `edge_logs` SQL. The pure `getLastUsedAPIKeys` shaper is kept and unit-tested. Still gated by the `showApiKeysLastUsed` flag. - Removed the disabled secret-keys (`sb_secret_`) BigQuery last-used path, which has no ClickHouse endpoint to migrate to: drops the dead `useLastSeen` query, the `APIKeyRow` "Last Used" column, and the unused `showLastSeen` prop. - Reworded the delete-confirmation copy to be accurate for both secret and publishable keys. ## Additional context - Backed by the platform endpoint in supabase/platform#34892 (merged and deployed). - Scope: `anon` / `service_role` legacy keys. Secret/publishable and JWT signing-key "last used" are follow-ups, pending the endpoint returning those key types. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated API key settings to show “last used” activity for the past 24 hours using a dedicated data source and time window. * Added clearer messaging when recent API key activity fails to load. * Removed the “Last Used” column from API key management tables. * **Bug Fixes** * Improved mapping so “last used” values correctly match the intended key and role. * Updated API key deletion confirmation to explain required backend changes and resulting unauthorized behavior. * **Tests** * Added unit tests to validate “last used” computation and edge-case filtering. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
768ea1001b |
fix(studio): scope table editor introspection CTEs to target table OID (#47894)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (performance), plus a regression-guard test suite and docs. ## What is the current behavior? Studio's introspection queries in `@supabase/pg-meta` do `O(catalog)` work for per-table requests. On databases with very large catalogs (hundreds of thousands of relations/constraints — real deployments reach this) they take tens of seconds per dashboard interaction, trip `statement_timeout`, and create heavy CPU/memory pressure when several tabs open concurrently. Two instances of the same bug class: **1. Table Editor query (`getTableEditorSql`)** — fetches metadata for ONE table by OID, but five catalog scans are unscoped and only filtered at the top-level join: - `primary_keys` CTE — scans all of `pg_index` (`where i.indisprimary`) - `index_cols` CTE — scans all unique indexes - `relationships` CTE — scans every FK in `pg_constraint` (and is scanned twice by the two subplans) - `uniques` subquery (inside `columns`) — scans all single-column unique constraints - `check_constraints` subquery (inside `columns`) — scans all single-column check constraints The planner cannot push the outer join qual into grouped / `distinct on` subqueries, so each is computed over the full catalog and thrown away. `tables-paginated.ts` was previously rewritten to avoid exactly this pattern; the single-table query never got the same treatment. **2. Entity definitions (`getTableDefinitionSql` / `getEntityDefinitionsSql`)** — the vendored `pg_get_tabledef` plpgsql function scans the entire `information_schema.columns` view once **per column** (plus `information_schema.tables` once per call) just to decide whether a name needs double-quoting — a pure string property of a name it already holds — and its per-index partial-index lookup casts `relnamespace::regnamespace::text` across every `pg_class` row. On a 12K-table catalog this makes a single entity's DDL cost ~3.7s and a default 100-entity definitions page ~6 minutes. ## What is the new behavior? **Fix 1 — scope the Table Editor CTEs to the requested OID** (`id` is validated non-null and interpolated via `literal()`, same as the existing `base_table_info` filter): - `primary_keys` / `index_cols`: `and i.indrelid = <id>` - `relationships`: `and (c.conrelid = <id> or c.confrelid = <id>)` - `uniques` / `check_constraints`: `and conrelid = <id>` Semantics are unchanged: the top-level select already filtered every CTE to the target table, so rows for other tables were computed and discarded. The `pg_index`/`pg_constraint` lookups become index scans returning a handful of rows. One residual scan is structural: PostgreSQL has no index on `pg_constraint.confrelid`, so the incoming-FK half of `relationships` is a single filtered seq scan of `pg_constraint` — still one cheap pass instead of materializing every FK row twice. **Fix 2 — remove the O(catalog) scans inside `pg_get_tabledef`**: the information_schema uppercase checks are replaced with direct regex tests on the name in hand (preserving the original's `quote_ident` behavior for schemas that need quoting), and the partial-index lookup is scoped by the already-resolved table OID. Original statements are kept as comments, matching the vendored file's convention. **Regression guard** — so this bug class stays out: - `test/db/stress-catalog.ts` builds a synthetic catalog (default 2,000 tables with PKs, unique + check constraints, FK chains and an FK hub; `PG_META_STRESS_TABLES` scales it to incident size). - `test/db/plan-guard.ts` provides `EXPLAIN (ANALYZE, FORMAT JSON)`-based budget assertions: a query's plan may only seq-scan a scaling catalog if its budget entry carries a written structural justification (e.g. no index on `pg_constraint.confrelid`; no index on `pg_class.relnamespace` for per-schema listings), plus a per-query time bound (the only guard available for opaque plpgsql internals like `pg_get_tabledef`). - `test/sql/studio/catalog-plan-guard.test.ts` applies budgets to the hot-path studio queries: table editor, constraints, FK listing, entity types, tables-paginated, columns, indexes, table/entity definitions, views. Reverting either fix makes the suite fail immediately with the offending scans listed. - `test/sql/studio/table-editor.test.ts` (new — none existed) asserts the Table Editor query's semantics: primary keys, unique indexes, both FK directions, `is_unique`, check definitions, column comments. - A new package `README.md` documents the plan-guard budget entry as a requirement for any new introspection query. ### Validation (synthetic 12,000-table catalog, PostgreSQL 17.6) - **Output equivalence, fix 1:** for 12 relation types (regular, composite PK, partitioned parent + partition, view, materialized view, constraint-free table, FK hub/chain/tail, and a fixture with enums/domains/generated/identity columns and duplicate check constraints), the `entity` jsonb from the old and new query is byte-identical. - **Output equivalence, fix 2:** byte-identical DDL across 13 fixture combinations (serial/identity/generated/array columns, case-sensitive and keyword names, mixed-case schemas, partitions, unlogged + reloptions, partial/expression indexes, external PK/FK/comments/trigger variants). - **Performance, fix 1:** Table Editor query `EXPLAIN ANALYZE` ~1,630ms → ~30ms (~50×); the gap grows with catalog size since the old query is O(catalog) per call. - **Performance, fix 2:** single entity definition 3,672ms → 63ms; a 100-entity definitions page ~6min → 0.87s. The plan-guard bound for `getEntityDefinitionsSql` tightens accordingly from 15s/25 entities to 3s/100 entities (330ms measured at default test scale). Verified locally: `catalog-plan-guard` (12 tests), `table-editor`, `tables-paginated` (16 tests) pass; `typecheck` clean. ### Rollout Per review, the new behavior ships **dark** behind the `pgMetaScopedIntrospection` ConfigCat flag (default off = legacy SQL, kept as full duplicated templates in pg-meta and verified byte-identical to the pre-PR queries). Studio reads the flag in the query hooks and threads it through (flag state is part of the React Query keys). The rollout is staged in the ConfigCat dashboard via user-email targeting (like every other ConfigCat flag): target the reporting user's email first, then a percentage rollout, then 100%. Server-side AI callers of `getEntityDefinitionsSql` stay on the legacy path. Once fully rolled out, delete the legacy templates + flag in a cleanup PR. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Closes: PGMETA-122 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved table editor SQL to correctly scope primary keys, indexes, uniques, checks, and relationships to the selected table. - Optimized table definition SQL to reduce unnecessary catalog scanning for uppercase-name detection and partial-index detection. - **Tests** - Added SQL generator tests for table editor metadata (keys, indexes, relationships, comments, and constraints). - Added catalog query plan guard coverage with a stress catalog and EXPLAIN-based scoping/performance budgets. - **Documentation** - Expanded documentation on catalog query plan safeguards and how to keep new introspection queries properly scoped. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
b84aafd1a6 |
fix(ui-patterns): fix chart y-axis label clipping (#47890)
## Summary - Chart y-axis tick labels were clipped (e.g. edge function overview execution time charts) because `chart-line.tsx`/`chart-bar.tsx` hardcoded a `-40` left margin regardless of the actual `YAxisProps.width` passed in. - Margin now scales with the configured axis width. ## Test plan - [ ] Visually check edge function overview performance/usage charts render full tick labels (e.g. "195ms" instead of "ms") <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved chart layout and alignment across line and bar charts. - Adjusted Y-axis spacing so labels display more consistently when axes are shown or hidden. - Removed unnecessary fixed spacing from Edge Function performance, CPU, and memory charts. - Tightened spacing around chart timestamp rows for a more compact presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
06aafe4e0a |
Skip fetchAgentSkills for www typecheck GHA (#47907)
### Context Our TS check GHA occasionally runs into GH rate limits because of `fetchAgentSkills` ### Changes involved - Opting to omit `fetchAgentSkills` for typecheck - `generateStaticContent` is needed still afaict - Allow GITHUB_TOKEN to be passed for `generateStaticContent` - And pass that env var from `typecheck.yml` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **Improvements** - Enhanced reliability of GitHub-powered content during site builds. - GitHub API requests now use secure authentication when a token is available, improving consistency and reducing rate-limit risk. - Repository star and agent-skill loading continues to work gracefully without token access. - **Chores** - Streamlined the type-check workflow to use a leaner content build before running TypeScript checks. - Passed the GitHub token through relevant CI task environments to enable authenticated requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
+4 |
503bdb5a6f |
Fix filter button in table editor (#47867)
## Context Realised that the filter button in the table editor is broken so this PR fixes it <img width="385" height="393" alt="image" src="https://github.com/user-attachments/assets/94332f1b-cd69-4a8c-a822-3b9096d06ee3" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Updated the entity-type filter to use a clearer, labeled “Filter entity types” button with revised popover trigger and sizing. * Refreshed the table header filter controls, including the entity-type dropdown behavior and updated styling when filters are applied. * Improved handling when no entity types are currently visible by showing a dedicated empty-state within the filter menu. * **New Features** * Added a “No results based on filters” empty panel with a “Reset filters” action to restore all entity types. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <alaister@users.noreply.github.com> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: kanad <github@kanad.dev> Co-authored-by: supabase-supabase-autofixer[bot] <248690971+supabase-supabase-autofixer[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> Co-authored-by: David_C <110653663+YuDavidCao@users.noreply.github.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> Co-authored-by: Nik Richers <nrichers@gmail.com> Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
00ecb53059 |
feat(etl): ETL usage insights+pricing docs (#47873)
Adds pipeline usage insights to summary and daily breakdowns + usage billing docs |
||
|
|
99d064e754 |
fix(www): add missing partner slug redirects (#47901)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Partner slugs were renamed from underscores to hyphens, but the redirect map only got partially updated. #46264 added entries for `refine_dev` and `supabase_wrapper_stripe`. Four others were missed and still hard 404, even though their replacement pages are live: | 404s today | Replacement page (200) | |---|---| | `/partners/integrations/atomic_crm` | `/partners/integrations/atomic-crm` | | `/partners/integrations/sequin_io` | `/partners/integrations/sequin` | | `/partners/integrations/supabase_wrapper_bigquery` | `/partners/integrations/bigquery-wrapper` | | `/partners/integrations/supabase_wrapper_firebase` | `/partners/integrations/firebase-wrapper` | These are the URLs Google has indexed and that external sites link to, so that traffic lands on an error page instead of the partner. Roughly 1.3k pageviews/month. Worth flagging for the reviewer: partner slugs come from the database, not the codebase, so renaming one doesn't force a matching redirect entry and nothing catches it at build time. This will happen again. ## What is the new behavior? Four `permanent: true` redirects added to `apps/www/lib/redirects.js`, matching the two that already exist in the partners block. ## Additional context Found while [digging into a decline in /partners traffic](https://supabase.slack.com/archives/C0161K73J1J/p1783931237132339). This accounts for ~7% of that decline — the rest is happening on healthy, indexed pages and is a separate question. Not included here: a few partner URLs 404 with no replacement page (`getstream_io`, `fezto`, `trevor_io`, `zapp_run`) — those partners look genuinely gone. Pointing them at `/partners/integrations` would hold onto more link equity than a hard 404, but that's a product call rather than a bug fix. Happy to add if people want it. Verified each old URL currently 404s and each destination returns 200. No duplicate `source` entries introduced. Prettier passes. |
||
|
|
7f8fb85caf |
Joshen/fe 3879 schema not exposed warning is unnecessarily repeated in (#47868)
Just a tiny nit i came across - realised that if the schema is not exposed via the API, the warning that we show on the policies page RE data not being selectable is repeated for each table which imo seems unnecessary. Opting for a single admonition at the top instead ## Before <img width="1085" height="744" alt="image" src="https://github.com/user-attachments/assets/7bd8cf7b-f5a8-47d6-b41f-13fc4782ed8b" /> ### After <img width="1080" height="673" alt="image" src="https://github.com/user-attachments/assets/c839f502-42ff-4184-ad07-0ff2fd2d2676" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an on-screen warning for tables whose schemas aren’t exposed via the project Data APIs, including a link to Data API settings. * **UI Improvements** * Refined the “filter entity types” control’s tooltip behavior and updated the popover header text. * **Bug Fixes** * Improved Data API/RLS status messaging by removing the prior “schema not exposed” outcome and showing “unknown” when access can’t be determined. * Consolidated policy warning rendering to avoid duplicated or inconsistent messages. * **Tests** * Updated policy/admonition helper tests to match the revised status and message behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c793352036 |
Add some keyboard shortcuts for the Assistant (#47872)
## Context Part of some minor improvements to the AI Assistant - this one's about adding some keyboard shortcuts ## Changes involved - Added keyboard shortcut for "New chat" <img width="212" height="96" alt="image" src="https://github.com/user-attachments/assets/e9c3bd63-adbc-4b05-8c52-1baed67e365a" /> - Also added a small animation for the "How can I assist you?" text for visual indication when moving between chats that might not have a conversation yet - Added keyboard shortcut for "Permission settings" <img width="236" height="86" alt="image" src="https://github.com/user-attachments/assets/337da009-5979-4910-9292-73cc4d7f7cce" /> - Show keyboard shortcut for "Close Assistant" <img width="165" height="88" alt="image" src="https://github.com/user-attachments/assets/b45a4f5a-8e12-45f1-8fdb-a18c0deedb02" /> - Fix `ExpandingTextArea` height calculation logic issue - If you open and close the Assistant panel a number of times, the height of the input field isn't consistent, so this fixes that <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - Added keyboard shortcuts for starting a new AI Assistant chat and opening permission settings. - Header actions now display shortcut hints and support keyboard access. - **Improvements** - Enhanced accessibility with labels for chat edit controls (save, cancel, edit, delete). - Chat onboarding now remounts when switching active chats. - Improved chat popover alignment. - Escape now blurs the message input; textarea resizing is more reliable during content/layout changes. - **Bug Fixes** - Updated onboarding loading behavior based on the lints loading state. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6418820b0b |
docs: convert self-hosting overview to ContentListings and restructure the page (#47469)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This PR converts link sections in the self-hosting overview page to the `ContentListings` component, puts conceptual guidance before deployment options, and adds badge support for the Docker card (minor). Relates to DOCS-1137 ## Current behavior `self-hosting.mdx` uses hand-authored `<GlassPanel>` / `<Link>` JSX for two sections: - **Get started**: Docker card with a JSX title containing a `<Badge>` element (was previously deferred for this reason). - **Community-driven projects**: Two cards with trivial `<span>`-wrapped string titles. Get started and Community cards appear at the top of the page, before the conceptual overview. The Support and community section uses hand-authored bullet lists for GitHub, Discord, and Reddit links. ## New behavior - The self-hosting overview page now uses data-driven `ContentListings` instead of hand-written cards and bullet lists. - Conceptual content (how self-hosting differs, your responsibilities, telemetry) comes first; deployment options and community resources follow. - Section intro text lives in listing data rather than inline MDX. - Brand icons added to all listing cards (Docker, Kubernetes, Traefik, GitHub, Discord, Reddit). - Minor: Added support for badges to content listings, such as "Official" in the Docker tile Data lives in `self-hosting.data.ts` (5 groups, 8 links) and is registered in `content-listings/index.ts`. ## Additional context ### Icon usage rights New brand icons (Kubernetes, Traefik, Reddit) are sourced from [Simple Icons](https://simpleicons.org) (CC0 1.0). Existing icons (Docker, GitHub, Discord) reuse assets already in `apps/docs/public/img/icons/`. Use is non-commercial documentation only — consistent with existing docs icon usage and trademark fair-use for identifying linked third-party services. ### To do: - [ ] Check with @aantti if he's on board with switching the page to content listings we can lint for and the content restructure to match other overview pages ## Verification | Gate | Result | |------|--------| | `pnpm vitest run lib/content-listings.test.ts` | ✅ 12/12 passed | | `pnpm build:guides-markdown` | ✅ 744 files generated | | `pnpm lint:mdx` (self-hosting.mdx) | ✅ No warnings on changed file | ### Proof: restructured self-hosting page with ContentListings and icons | [Before (production)](https://supabase.com/docs/guides/self-hosting) | [After (PR preview)](https://docs-git-nikrichers-docs-1137-self-hosting-supabase.vercel.app/docs/guides/self-hosting) | |---|---| |  |  | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Updated the self-hosting guide to use dynamic content listings for “Get started,” community resources, support options, and sharing experiences. * Added richer listing cards with optional badges and improved icon handling. * Expanded self-hosting resource groups to surface more relevant links in docs navigation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
a9115b694f |
fix(docs) Prevent dashboard links from breaking (#47897)
Closes DOCS-1174 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem Links from docs to studio can break. There's no way to programmatically check. ## Solution Add a unit test to check that `/dashboard` relative links from docs is absolute. ## Testing 1. Pull this branch to your local machine. 1. Break the link in `apps/docs/data/content-listings/database.data.ts` — change: `href: 'https://supabase.com/dashboard/project/_/sql',` to: `href: '/dashboard/project/_/sql',` 1. Run: cd `apps/docs && pnpm exec vitest run lib/content-listings.test.ts`. You should see dashboard content listing hrefs fail. Restore the absolute URL when you’re done. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added validation to ensure dashboard links in documentation content listings use complete, canonical URLs. * Added coverage for identifying dashboard links across all content listing groups. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
652311feb5 |
fix(studio): guard Auth Performance allocation strategy select against invalid values (#47896)
## Summary - The Connection management "Allocation strategy" select on the Auth > Performance page called its `onValueChange` handler's conversion logic with whatever value it was given, with no validation. If that handler ever fired with a value outside the `'percent' | 'connections'` enum, it would silently overwrite a correctly loaded config, converting it to the wrong absolute connection count and leaving the strategy dropdown in a blank/inconsistent state. - Extracted the percent/connections conversion into a pure, unit-tested `convertPoolSize()` helper (`PerformanceSettingsForm.utils.ts`) and added a guard so `onValueChange` ignores any value that isn't a recognized allocation unit. ## How to test 1. Under **Connection management**, switch **Allocation strategy** back and forth between "Absolute number of connections" and "Percent of max connections" — the value should convert correctly each time and the dropdown should never render blank. 2. Save, then hard-reload the page — the saved strategy and value should persist as shown. ## Test plan - [x] `PerformanceSettingsForm.utils.test.ts` — unit tests covering both conversion directions, clamping, and the invalid-value guard - [x] `PerformanceSettingsForm.test.tsx` — MSW-backed component test verifying persisted percent/absolute configs render correctly on load - [x] `pnpm test:studio` - [x] `pnpm typecheck` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Switching database pool allocation strategies now automatically converts values between percentage and connection-based units. * Values are rounded and constrained appropriately to remain within supported limits. * Allocation settings now handle invalid or zero values more safely. * **Tests** * Added coverage verifying persisted allocation strategies and pool-size conversion behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c9a649cf73 |
refactor(sql-editor): extract snippet-identity/mount/prettify/title hooks (decompose 3b/6) (#47893)
## Summary Continues the SQLEditor decomposition. Pulls four cohesive concerns out of the `SQLEditorContent` composition root into co-located `use*` hooks. ## New hooks - `useSnippetIdentity` — derives `id` / `generatedNewSnippetName` / `isLoading` from the URL + snippet store (keeps the `[urlId]` memo dep verbatim). - `useEditorMount` — the editor `onMount` (scroll restore/track) + the mount counter that lets a pre-mount diff request re-run. - `usePrettifyQuery` — formats the editor SQL in place and writes it back to the store. - `useSnippetTitleGenerator` — the title-generation mutation + `setAiTitle`. |
||
|
|
f2dece5b54 |
fix(studio): added bottom margin to schema graph's Minimap that was previously colliding with SchemaGraphLegend (#47858)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (UI): fixes #47857 ## What is the current behavior? SchemaGraph's Minimap component currently collide with the SchemaGraphLegend component: <img width="710" height="357" alt="Image" src="https://github.com/user-attachments/assets/e6a7c30b-da00-455b-b224-e47898ada272" /> ## What is the new behavior? Added bottom margin, SchemaGraph's Minimap component does not collide with the SchemaGraphLegend component anymore: <img width="609" height="297" alt="Screenshot 2026-07-11 at 7 38 05 PM" src="https://github.com/user-attachments/assets/6e0c5be6-ba86-40cd-b0c7-e24ca8c16f4c" /> ## Additional context this mb-11! is consistent with the "load more tables" button below (the entire chunk looks like this): ```js <MiniMap pannable zoomable nodeColor={miniMapNodeColor} maskColor={miniMapMaskColor} className="border rounded-md shadow-xs mb-11!" /> <SchemaGraphLegend /> {hasNextPage && ( <Panel position="bottom-center" className="mb-11!"> <Button variant="default" size="tiny" loading={isFetchingNextPage} onClick={() => { fitViewOnNextLayout.current = true fetchNextPage() }} > Load more tables </Button> </Panel> )} ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Adjusted the schema graph minimap spacing to improve layout and visibility within the interface. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2ec8e3b135 |
fix: ensure sidebar has valid html (#47826)
## Problem The sidebar in both org or project pages has invalid html, preventing screen reader users to understand them. See https://dequeuniversity.com/rules/axe/4.12/list Besides, we were using some shadcn components incorrectly (groups inside menus when it should be the other way around) ## Solution - Invert group/menu relation so that we don't have `div` inside `ul` - No visual changes - No functional changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved sidebar navigation by splitting routes into clearer sections (Home/Tools, Products, Other routes, and Settings). * Updated the advisors link so its active indicator renders directly within the navigation item, while keeping the existing disabled/error/warning behavior. * Adjusted organization navigation layout for more consistent spacing and alignment. Animations remain smooth. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9726940dba |
refactor(sql-editor): own shared editor refs in SQLEditorContext (decompose 3/N) (#47837)
## Summary PR **3** in the SQLEditor decomposition stack. The keystone structural step: introduce a context provider that owns the shared, mutable Monaco state, so later PRs can extract logic hooks and presentational panes without threading the same three refs through every signature. Behavior-preserving — the characterization suite (merged in PR 1) stays green with identical assertions. ## What changed New `SQLEditorContext.tsx`: - `SQLEditorProvider` owns the shared refs (`editorRef`, `monacoRef`, `diffEditorRef`, `scrollTopRef`), the run-refocus flag, and the error-highlight decorations. - `useSQLEditorContext()` guard hook (React 19 `use()`), mirroring the canonical `PoliciesDataContext` pattern. - Stable helpers: `refocusEditor`, `clearPendingRunRefocus`, `markRefocusAfterRun`, `refocusEditorAfterRunIfNeeded`, `getEditorSql`, `clearHighlights`, `applyErrorHighlight`. `SQLEditor.tsx`: - Split into `<SQLEditorProvider><SQLEditorContent/></SQLEditorProvider>`. - `SQLEditorContent` reads refs/helpers from context instead of local `useRef`/`useCallback`. - `lineHighlights` moves from React state to a ref inside the provider (decorations are purely imperative; nothing renders off them). This also removes the stale-closure hazard the old `executeQuery` dep-array omission worked around. The context value holds only stable identities (refs + `useCallback`s, memoized once), so the provider never re-renders its consumers — it's a dependency-injection channel, not reactive state. ## Verification - `vitest` — 156 pass (characterization + utils), assertions unchanged - `pnpm --filter studio typecheck` — clean for all SQL editor files (the two `@sentry/tanstackstart-react` errors are a pre-existing local-install gap on master, unrelated) - `eslint` — 0 errors - Equivalence: single `useEffectEvent`, `drainDiffRequest` driving-effect deps `[diffRequest.pending, editorMountCount]` byte-identical, all 8 `eslint-disable` dep arrays preserved <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved SQL editor focus restoration after running or explaining queries. * Centralized run/explain highlighting so errors are highlighted consistently and old highlights are reliably cleared. * Ensured the SQL snippet used for run/explain is derived consistently from the current editor state. * **Refactor** * Restructured the SQL editor to use a shared internal context for editor UI, refs, and imperative highlight/focus helpers, keeping the external editor interface unchanged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1d89af2739 |
fix(docs) Fix broken link on Dashboard overview (#47892)
Closes [DOCS-1172](https://linear.app/supabase/issue/DOCS-1172/fix-broken-run-sql-commands-link-in-database-overview-docs) ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Fixes broken link. ## What is the current behavior? Link is broken on dashboard overview. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the “Run SQL commands” link to direct users to the fully qualified SQL editor URL. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
be35b925ca | feat: Add troubleshooting guides index markdown (#47818) | ||
|
|
7f57919318 |
[bot] Decrease ESLint ratchet baselines (#47856)
Automated weekly decrease of ESLint ratchet baselines. Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> |
||
|
|
67b17c885c |
fix(studio): allow github.com and vercel.com avatars in img-src CSP (#47885)
The TanStack build renders remote images as plain `<img>` tags — there's no Next.js image optimizer rewriting them to same-origin `/_next/image` URLs — so remote avatar origins now hit the CSP directly and were being blocked (e.g. `Loading the image 'https://github.com/alaister.png?size=96' violates the following Content Security Policy directive: "img-src 'self' ..."`). **Changed:** - Added `https://github.com` to `img-src` — GitHub profile avatars (`https://github.com/<username>.png`, used by the user dropdown, AI assistant messages, org invites, and audit logs). The URL 302s to `avatars.githubusercontent.com`, which is already allowed (CSP validates both hops of a redirect). - Moved `https://vercel.com` from the dev/staging-only `img-src` list to the unconditional list — Vercel integration account avatars (`https://vercel.com/api/www/avatar/...`) load in prod too. Audited all other `next/image` usages in studio: everything else is either a local `${BASE_PATH}/img/...` asset (`'self'`) or a marketplace image served from `NEXT_PUBLIC_MARKETPLACE_API_URL`, which is already in `img-src`. The old `remotePatterns` entry for `api-frameworks.vercel.sh` has no remaining references, so it was deliberately not ported. ## To test - On the TanStack build, sign in with a GitHub-linked account and check the user avatar renders in the top-right user dropdown (no CSP violation in the console) - Check org audit logs (`/org/_/audit`) render member avatars - With a Vercel integration installed, check the account avatar renders in org integration settings - Sanity-check the Next.js build still renders the same avatars (both builds share `getCSP()`) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * GitHub profile avatar images now display correctly. * Image loading rules for staging and development environments were refined to improve content security. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
20cb05230b |
fix site_title (#47884)
Update www `site_title`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the site title and browser metadata to describe the product as “The Postgres Development Platform.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
20649d2374 |
docs: fix confusing loader snippets in Remix and React Router SSR client guide (#47685)
## Summary
Fixes the Remix and React Router sections of the SSR "creating a client"
guide, which showed three separate `_index.tsx` snippets (Loader,
Action, Component) with two different `loader` exports that cannot
coexist in one route, leaving readers unsure which to use.
Each framework now has a short intro plus a single coherent
`_index.tsx`: one `loader` that creates the server client and returns
the env vars, one `action`, and a browser-client component that reads
those env vars via `useLoaderData`. Along the way this also fixes three
React Router bugs: the invalid `'@react-router'` import, the dropped
cookie `options` argument in `setAll`, and the incomplete `return ...`
in the component.
One thing worth a reviewer check: a loader that both sets cookies and
returns data must return through the `json` (Remix) / `data` (React
Router v7) helper with `{ headers }` rather than a plain object, so the
`Set-Cookie` headers are preserved.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Summary by CodeRabbit
* **Documentation**
* Updated the server-side “creating a client” guide for Remix and React
Router SSR examples.
* Refreshed the example structure to a single end-to-end route setup
with `loader`, `action`, and one default page component.
* Improved SSR cookie and header handling to better match practical
server/client behavior.
* Passes the required Supabase URL and publishable key from the server
to the browser so the client can be initialized with `useLoaderData`.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io>
|
||
|
|
1d29b4c5b4 |
Clean up RLS Tester artifacts (#47866)
## Context As per PR title - we're pausing the development of the RLS Tester feature preview while we re-evaluate its direction. Have also updated the GH discussion [here](https://github.com/orgs/supabase/discussions/45233) RE this! 🙏 Removes the RLS Tester UI + Sandbox functionality <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Removed Features** * Removed the RLS Tester feature preview, banner, and database policy testing workflow. * The related SQL testing, role selection, policy summaries, sandbox management, and result views are no longer available. * **Bug Fixes** * Improved accessibility on the database policies page by adding a label to the clear-filter button. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dbdbe1540b |
fix(studio): make paused project messaging easier to scan DEPR-581 (#47807)
## Problem The free-plan paused project notice was a dense paragraph, so the key points (data is safe, resume window, download-after-expiry, upgrade) were easy to skip. ## Fix Present those points as a scannable bullet list, keeping the dynamic day-count tooltip, restore-deadline timestamp, and the existing Pro-wording variant. Also adds a "Project Status" tab to the dev toolbar (local and staging only) with a select for forcing the current project's status, so the paused state and other statuses are easy to preview without touching the backend. It overrides the status in the React Query cache and reverts on close, project navigation, or reset. ## How to test - Run Studio locally against the platform API - Open the dev toolbar, go to the Project Status tab, and select INACTIVE - Navigate to a project page and confirm the paused screen renders - On a free-plan org, confirm the notice now shows the details as bullet points with the day-count tooltip and restore-deadline date intact - Click "Reset to real data" (or close the toolbar) and confirm the status reverts <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a development toolbar “Project Status” tab to simulate project status and pause states in non-production environments. * Status and pause-state overrides persist locally, can be reset, and are reflected across project detail and paused-state views. * **Style** * Refined paused-project messaging: updated the heading and reworked the free-plan explanation into bullet points, while keeping paid-plan messaging paragraph-based for readability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
05b3a6a3c0 |
Fix feature preview dialog selected (#47870)
Use bg-accent for selected state across elements. This fix is specific to the feature preview dialog. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated feature preview selection styling for clearer visual distinction between selected and unselected items. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b5ada9631d |
Update PostgreSQL config options in documentation (#47547)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the current behavior? We do not discuss the current settings in the configuration docs: - max_logical_replication_workers - max_sync_workers_per_subscription ## What is the new behavior? Shows users they can update the following pg_settings with the CLI: - max_logical_replication_workers - max_sync_workers_per_subscription <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the custom PostgreSQL configuration guide with additional CLI-supported parameters. * Added documentation for logical replication and subscription synchronization worker settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> |
||
|
|
8f82861627 |
feat(replication): Add new form for early access of replication destination (#47046)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added pre-release pages for Supabase Pipelines’ new destinations, including early-access signup, thank-you confirmation, and related resources. * Added destination options for ClickHouse, Snowflake, and DuckLake. * **Bug Fixes** * Improved form validation for grouped required checkboxes. * Added clearer checkbox labels and descriptions. * Forms now explain which required option groups still need a selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <30495040+ana1337x@users.noreply.github.com> |
||
|
|
a881220335 | Add Thanya Nitithatsanakul to humans.txt (#47834) | ||
|
|
b6cdd5cce3 |
refactor(sql-editor): extract pure SQL helpers + tighten safe-SQL boundary (decompose 2/6) (#47831)
## Summary 1. **Extract pure logic** out of the 1056-line `SQLEditor.tsx` monolith into unit-tested functions in `SQLEditor.utils.ts`. 2. **Remove `rawSql()` from the SQL editor** and tighten the untrusted→safe boundary per the `safe-sql-execution` model. ## Extracted functions (+ tests) - `getEditorSql(editor, snippetContent?)` — selection → full value → snippet fallback. Returns an **`UntrustedSqlFragment`** so editor/snippet SQL keeps its provenance. - `computeErrorHighlightLine(error, startLineNumber)` — parses the `LINE n:` marker + selection offset. - `assembleCompletionDiff(meta, text)` — before/selection/after assembly for the AI completion diff. - `buildExplainSql(sql, impersonatedRoleState)` — takes an already-safe fragment; EXPLAIN ANALYZE + role impersonation + rollback wrapping. - `buildDebugPromptText(sql, errorMessage)` — the assistant debug prompt string. ## Safe-SQL boundary - `rawSql()` is no longer used anywhere in the SQL editor. - `executeQuery` / `executeExplainQuery` now **require a `SafeSqlFragment`** — safe by construction, so they can never auto-run untrusted SQL. - `acceptUntrustedSql` promotion happens **only in the small run/explain gesture handlers** (`executeQueryFromButton`, `handleRunShortcut`, `handleRunExplain`, and the warning-modal confirm handlers), never buried in the long helpers. ## Verification - `vitest` — 156 pass (11 characterization + 145 utils, incl. new cases) - `pnpm --filter studio typecheck` — clean for all SQL editor files (two unrelated `@sentry/tanstackstart-react` module-resolution errors exist on current master pre-install; not touched by this PR) - `eslint` — 0 errors <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Enhancements** * Improved SQL execution and EXPLAIN workflows with safer handling at run and analysis actions. * Enhanced SQL selection and snippet handling in the editor. * Improved error highlighting to more accurately identify affected lines. * Refined completion previews and debugging prompts for clearer results. * EXPLAIN ANALYZE now supports rollback-wrapped execution and avoids duplicate wrapping. * **Bug Fixes** * Improved behavior when working with selected, empty, or missing SQL content. * Prevented existing EXPLAIN statements from being unnecessarily modified. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
539b66f5c4 |
fix(studio): improve unified logs checkbox hit area and align icons (#47832)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix / polish ## What is the current behavior? Unified logs row selection checkboxes only respond to clicks on the checkbox itself, so it's easy to miss. Log type icons in the table also don't match the ServiceFlow panel (16px / muted vs 14px / lighter / strokeWidth 1.5). ## What is the new behavior? - Expand the select checkbox tap target with `hit-area-2`, and add a visible `hover:border-foreground-muted` affordance (matching the older logs explorer intent; the base Checkbox hover is a no-op after the colour-system token collapse). - Align log type icons with ServiceFlow: 14px, `text-foreground-lighter`, `strokeWidth={1.5}` on both the table column and ServiceFlow section headers. ## Additional context Older logs used an `absolute inset-0` wrapper for the same hit-area problem; unified logs uses the design-system `hit-area` utility instead. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Refined unified log visuals with more consistent icon sizing, stroke weight, and muted coloring. * Improved checkbox hover styling and expanded its clickable area for easier selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e5df232b44 |
fix(studio): polish unified logs row alignment and success colours (#47829)
## What kind of change does this PR introduce? UI polish ## What is the current behavior? Unified logs row chrome is slightly misaligned (checkbox vs filter toggle, uneven gaps around the level dot), success grey is too dark and doesn’t match the Level key, and log-type icons read a bit heavy. ## What is the new behavior? - Aligns the row checkbox with the filter sidebar toggle and spaces the level dot evenly between checkbox and timestamp - Drops the checkbox `translate-y` nudge in favour of normal middle alignment - Introduces `--chart-success` so the chart and Level key/dots share a lighter grey - Softens log-type icon colour on each row | Before | After | | --- | --- | | <img width="1024" height="759" alt="1293" src="https://github.com/user-attachments/assets/af7ab83f-8917-41cb-99f3-1c1f92df769e" /> | <img width="1024" height="759" alt="52159" src="https://github.com/user-attachments/assets/9b859308-2101-4a02-bdc1-75e5750f84fa" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved Unified Logs table spacing and alignment, including narrower selection and level columns. * Refined checkbox and date-cell presentation for a cleaner layout. * Updated log type icons to use muted foreground styling. * **Bug Fixes** * Success statuses and chart indicators now consistently use the dedicated success color across light and dark themes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3fda760fe1 |
Fix R2NP disk size multiplier in FE copy (#47827)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Fixes the copy here to accurately reflect the [constant defined on the backend](https://github.com/supabase/platform/blob/7653f016838fc1bba15bbce201a1c58566f1751a/packages/api-core/src/shared/disk.ts#L32). No behavior change. https://linear.app/supabase/issue/INDATA-906/ensure-fe-r2np-disk-size-multiplier-is-accurate <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated restore guidance to accurately indicate that the restored disk size may be approximately 1.5× larger. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
17ee3e6977 |
feat(studio): add Multigres log type to unified logs FE-3785 (#47560)
## Problem The Multigres log type is available in the legacy logs collections but was missing from the new unified logs, so Multigres logs could not be selected or viewed there. ## Fix Wire the `multigres_logs` source into unified logs the same way the other single-source types (Realtime, Supavisor, PgBouncer) are: a display label, a filter condition, the derived `log_type` expression, a display-casing entry, and a sidebar icon. ## How to test - Open a project with Multigres logs and go to the new unified logs view - Open the Log Type filter and confirm "Multigres" appears as an option - Select "Multigres" and confirm rows from the `multigres_logs` source are returned and labeled "Multigres" with the network icon - Expected result: Multigres logs are filterable and display correctly, matching the legacy logs behavior ## Notes Level/severity uses the shared `severity_text` fallback that all non-HTTP sources rely on. If Multigres rows come back always classified as success, the OTEL pipeline may not populate `severity_text` for this source (legacy logs read the level from a JSON `event_message`), which would need a source-specific level branch. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for the **Multigres** log type in Unified Logs (labels, icon, and derived filtering/grouping/counting). * Unified Logs now renders Multigres **event_message** by extracting the `msg` field from valid JSON, with correct capitalization. * Unified Logs row click telemetry now recognizes **Multigres**. * The **Multigres** log type option is hidden when the selected project is not high-availability. * **Tests** * Added/updated unit tests for Multigres event-message parsing and shared event-message display behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
79b2eeb8b2 |
fix(studio): make replica pricing learn more an inline link (#47825)
## What kind of change does this PR introduce? Bug fix / polish ## What is the current behavior? On the add-destination sheet for read replicas, “Learn more” sits as a stray sibling next to the cost copy. ## What is the new behavior? Cost copy and “Learn more” are one paragraph, with the link inline and styled like `InlineLink` (underline, pointer cursor, hover colour): > New replica will cost an additional $16.25/month. Learn more | Before | After | | --- | --- | | <img width="1258" height="120" alt="CleanShot 2026-07-10 at 12 21 21@2x" src="https://github.com/user-attachments/assets/bb47461e-e856-4cf2-b81a-f8e9aa9ebf75" /> | <img width="1256" height="114" alt="CleanShot 2026-07-10 at 12 23 48@2x" src="https://github.com/user-attachments/assets/094332be-ad2e-4782-94ac-08c8775a4665" /> | _Note that the grey icon square is being fixed separately in https://github.com/supabase/supabase/pull/47794._ ## To test On the staging preview, open Database → Replication → Add destination → Read replica, and check the footer cost line in light and dark mode — “Learn more” should sit inline, show a pointer cursor, and change colour on hover. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Added estimated monthly pricing to the read replica pricing dialog trigger (“additional {cost}/month”). * **UI Improvements** * Moved the pricing/cost impact messaging from the form footer to the pricing dialog area. * Refined the “Learn more” link/button styling and layout for a cleaner presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ac7e66f215 |
docs(telemetry): add a Debugging guide and log-query best practices (#47762)
Two related docs changes for debugging Supabase, consolidated into one PR. ## 1. New "Debugging" guide (`guides/telemetry/debugging`) A methodology and entry page for debugging any Supabase issue, added next to Logging in the Telemetry nav. It covers: - **The debugging loop** — read the exact error, isolate the failing layer, gather evidence, fix, verify. - **The Supabase request stack** — the gateway fans out to PostgREST, GoTrue, Storage, and Realtime as parallel services (not a chain), with Postgres underneath. Explains why an API-layer permission or empty-result error is usually a Postgres RLS/privilege issue. - **Reading logs** — the narrow-query discipline (one source, bounded window, widen along an anchor), linking the Logs Explorer guide rather than duplicating query syntax. - **Symptom to guide routing table** — maps each symptom to its layer and the specific troubleshooting guide, acting as a front door to the troubleshooting collection. All 47 links verified live. This puts the debugging methodology in docs (owned and updatable) instead of only in the agent skill. ## 2. Log-query best practices (`guides/telemetry/logs`) Adds the three practices the existing Best practices list was missing, all engine-agnostic: query one source at a time, follow a request across sources with an anchor, and reference only confirmed field names. ## Follow-up (not in this PR) The Logs Explorer now defaults to **ClickHouse** (single `logs` table, `log_attributes` map), but `guides/telemetry/logs.mdx` and the two logs troubleshooting guides still document the legacy **BigQuery** dialect (`cross join unnest(metadata)`). They need a coordinated BigQuery to ClickHouse migration pass: - `guides/telemetry/logs.mdx` - `troubleshooting/how-to-interpret-and-explore-the-postgres-logs-OuCIOj.mdx` - `troubleshooting/discovering-and-interpreting-api-errors-in-the-logs-7xREI9.mdx` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a new “Debugging” guide with a step-by-step workflow for identifying where issues originate versus where they appear. * Added a symptom-to-layer troubleshooting mapping and linked it from Telemetry navigation. * **Documentation** * Updated Logs Explorer guidance to note its ClickHouse default and that examples use legacy BigQuery syntax. * Expanded Logs Explorer best practices, including querying one source at a time, correlating with anchors, and using only confirmed field names. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
d453e57086 |
test(sql-editor): characterization tests for SQLEditor (decompose 1/6) (#47820)
## Summary Add some tests for the SQL editor so I can refactor it without regressions. Tests are not best practice because they are intended to be temporary and improving them would require refactoring first (currently they are over-mocking and asserting on internal details). Stacked on top of #47792 (`charislam/sql-editor-top-bar-controls`). ## What this adds `apps/studio/tests/components/SQLEditor/SQLEditor.test.tsx` (11 tests): - Run success → `addResult` + Results tab; EXPLAIN-shaped result auto-switches to the explain tab; a non-EXPLAIN run switches back. - Run error with `position` → error-highlight line math + `deltaDecorations` + `revealLineInCenter`; the next run clears the highlight. - Run button refocuses the editor; disabled + short-circuits while a diff is open. - Diff request queued before mount drains exactly once (one-shot; no re-apply on remount). - Ask-AI widget renders only while the prompt is open (render-time `editorRef.current` read). - Destructive query → warning modal → confirm forces the re-run; confirm-with-RLS appends enable-RLS statements. ## Test approach Real Monaco / DiffEditor are replaced with lightweight fakes exposing a controllable editor; child panels + orthogonal context hooks are stubbed; the execute mutation runs for real against an MSW-mocked `/platform/pg-meta/:ref/query`. Tests assert on public behavior so they survive the internal refactor unchanged. ## Verification - `pnpm --filter studio exec vitest run tests/components/SQLEditor/SQLEditor.test.tsx` — 11/11 pass (stable across repeated runs) - `pnpm --filter studio typecheck` — clean - `eslint` — 0 errors <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added comprehensive coverage for SQL editor behavior, including query execution, result and explain views, error highlighting, editor focus, and diff mode. * Added validation for destructive-query confirmations, including RLS confirmation flows. * Added coverage for queued diff requests and conditional AI prompt display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0747af0afe |
Adjust PITR UI (#47821)
## Context Original intention was to fix the PITR UI for smaller viewports, but realised that the layout of the UI could be improved as well. (Tbh this UI could do with a bit of revisiting, but just making patches for now to improve what's existing) Fixes also apply to the restore to new project page since they share the same component ## Changes involved - Am opting to change the layout of the UI a little such that date selection is on the left, and time selection is up top - Fits the user flow a bit better - you select the parameters you want, and the final message at the bottom is the summary <img width="1033" height="525" alt="image" src="https://github.com/user-attachments/assets/614c0327-f5db-4e1f-a2a1-ae8a9ea89978" /> - In the confirmation dialog, we were originally showing the top label as "Local time" which I feel is inaccurate especially if the user has selected a different timezone from where they're located at. - Opting to display the full name of the selected timezone instead <img width="546" height="261" alt="image" src="https://github.com/user-attachments/assets/cd8838a1-8476-4492-bc86-cac229685e5a" /> - RE mobile layout - am currently just opting to have them in a column fashion although I feel like this isn't ideal either (requires revisiting of the UI as a whole to adjust the layout on desktop too) - e.g the Date picker here could be a popover like Unified Logs to streamline what is essentially a form <img width="507" height="831" alt="image" src="https://github.com/user-attachments/assets/c8e055bd-49c3-4d0a-9d8c-e54f53e9fcb4" /> - Also fixed the CTA URL for read replicas, was still pointing to /settings/infrastructure, should point to database/replication <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Point-in-time recovery now includes the selected timezone throughout the restore workflow. * Restore confirmations display the chosen timezone and a clear summary of the target recovery date and time. * Recovery details now show the earliest and latest available backups for the selected date, including the two-minute matching window. * **Bug Fixes** * Updated the read-replica management link to direct users to database replication settings. * **Style** * Improved restore form layout, calendar presentation, and timezone selector alignment. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3461d60aba |
feat(sql-editor): consolidate controls into a single top bar (#47792)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor / UI improvement ## What is the current behavior? SQL editor controls are split across two rows: a bar between the editor and results (tabs, download, run/save/format/db-selector/role/favorite/intellisense) and a separate footer at the very bottom (row count + limit dropdown). ## What is the new behavior? All controls are consolidated into a single top bar above the editor (⋮ overflow menu, database selector, role impersonation, limit, save, run). The bar between the editor and results now holds only result-relevant information: the Results/Explain/Chart tabs, the row-count summary, and the Export button. The limit dropdown is now always visible as a persistent query setting. |
||
|
|
93ebd8adf1 |
docs(security): remove log_connections effective date admonition — MERGE ON JULY 9 (#47253)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - docs update Scheduled follow-up to #47252 / DOCS-1080. ## What is the current behavior? - Docs include a temporary note admonition on five pages: "This default takes effect for new projects from July 9, 2026." (#47252) - The `do-not-merge` label blocks CI until this PR is ready to merge. ## What is the new behavior? - Removes the temporary effective-date admonition partial and all `$Partial` includes. - Default-behavior copy from #47199 remains unchanged. ## Additional context **Do not merge before July 9, 2026.** ### Merge instructions (July 9) 1. Rebase this branch onto `master` after #47252 has merged (should remain a clean removal-only diff) 2. Remove the `do-not-merge` label 3. Confirm CI is green and merge Review screenshots live in `.github/pr-screenshots/docs-1080/` on this branch for PR proof only. ### Test plan - [ ] After rebase, confirm the five pages no longer show the effective-date admonition - [ ] Confirm default-behavior copy from #47199 remains unchanged - [ ] Remove `do-not-merge` label and merge on July 9, 2026 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Cleaned up several security, compliance, telemetry, and PostgreSQL logging docs by removing a repeated note about when default connection logging behavior takes effect. * Streamlined the affected pages so the guidance now flows more directly without the extra embedded note. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
7141b0ae2d |
test(studio): add MSW tests for project creation flow (#47790)
Adds 21 MSW component tests covering the project creation wizard's permutations (plan/region/compute/OrioleDB/security options/GitHub/blocking states/errors). Closes FE-3883; surfaced a real empty-region submit bug tracked in FE-3884. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added a comprehensive UI/request test suite for the Studio project-creation wizard. * Validates paid vs. free plan behavior (including compute sizing rules) and that region selection submits the correct payload, including the “Recommended” option. * Covers blocking and warning states (project limits, overdue invoices with billing CTA, and feature-flagged disabled creation), plus error handling when regions fail to load. * Exercises confirmation modals, database/security option flows, client-side validation, GitHub gating/repo selection, and toast errors on API failures. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
40f39c503f |
Embed server package youtube video in release blog (#47799)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? blog update ## What is the current behavior? No embedded link for Server Package video ## What is the new behavior? Embedded link for Server Package video <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an embedded video to the “Introducing Supabase Server” blog post. * The video uses privacy-focused playback settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e007cc37c3 | docs(self-hosted): standardize on run.sh in how-to guides (#47811) | ||
|
|
4072238d90 |
Fixed the Lovable logo (#47813)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Fixes the Lovable logo in case studies and elsewhere to be the latest one. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated the customer RSS feed’s publication metadata to reflect the latest content date. * Refreshed the Lovable customer entry’s publication date and removed the outdated duplicate entry. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
373e917a99 |
feat(docs): generate server.txt reference and wire into www llms (#47782)
Add a `server` entry to the reference-markdown pipeline so it emits `public/markdown/reference/server.md`, and register the Supabase Server Library Reference as a source in the www `llms.txt` and `llms-full.txt` routes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new Supabase Server Library Reference covering server-side SDK usage. * Included the server reference in generated documentation and plaintext documentation indexes. * Made server SDK reference content available through the full documentation feed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a75a3b22b6 |
fix(studio): align PITR calendar dates in the first week (#47806)
## What Fixes misaligned day cells in the PITR calendar widget for the first week of the month. ## Why The PITR calendar draws a \`border\` on each day cell via \`classNames.day\`. The day \`<td>\` has no explicit width, so \`box-sizing: border-box\` doesn't apply and the 1px borders add to its size (36px → 38px), while the weekday header cells stay pinned at \`w-9\` (36px). Bordered day cells therefore drift right of their headers, which is most visible in the first partial week where unbordered leading cells sit flush next to the wider bordered ones. ## How Pin each day cell to a fixed \`w-9 box-border\` so the border is drawn inside the 36px box, and let the day button fill the cell (\`w-full\`). Column pitch now matches the weekday headers regardless of border state. Class-only change, no logic touched. Closes FE-3886 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved calendar day cell sizing and layout for more consistent rendering. * Ensured day buttons use full-width styling where applicable, while preserving existing hover, border, background, and corner behavior. * **Documentation** * Added documentation for “Calendar with disabled days,” including a new interactive preview. * **New Features** * Introduced a calendar example demonstrating disabled-day behavior with mid-week month start and restricted date selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
4fd5f8adf1 |
Vercel project connect layout (#47623)
Bring the Vercel project connect layout up to date with other connect screens. Follows up from https://github.com/supabase/supabase/pull/47550 which is required. | Before | After | | --- | --- | | <img width="2368" height="1680" alt="image" src="https://github.com/user-attachments/assets/f5c0b8ef-8fb5-4176-b0cf-98e33958dcc8" /> | <img width="848" height="808" alt="image" src="https://github.com/user-attachments/assets/e64c289f-0b73-4605-ad38-4552d3d6f934" /> | <img width="883" height="733" alt="image" src="https://github.com/user-attachments/assets/7ccd9b72-de6a-4c21-ac8e-abe773bb8116" /> ## Testing - Open the deploy preview or staging URL for `/dashboard/integrations/vercel/acme-production/marketplace/choose-project` with callback params from a real Vercel Marketplace install redirect (see _Vercel_ subheading below). ### Vercel - Run through the [install flow](https://github.com/supabase/supabase/pull/47550) on a real project until you get to the project connection screen, copy the url and paste into staging preview <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Introduced interstitial-style Vercel integration experiences for both install and choose-project flows, with improved page titles and clearer environment-variable guidance (including tooltip details). * **Bug Fixes** * Improved Vercel integration matching by configuration id and strengthened loading/error handling with more specific “not found” messaging. * **Refactor** * Enhanced the Vercel/GitHub project chooser with a dedicated interstitial mode. * Updated partner logo rendering to support optional styling customization. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Alaister Young <alaister@users.noreply.github.com> |
||
|
|
9858562b8b |
fix(telemetry): dedupe funnel toast error events (#47802)
## Summary Since #47293, an API failure on a signup / org-creation / project-creation form emitted `dashboard_error_created` twice: `useTrackFunnelError` fired the origin-tagged event and the global `ToastErrorTracker` independently fired the legacy untagged `source:'toast'` event for the same toast, each behind its own 10% sampling draw. I verified the twin rate empirically at 8-11% of origin-tagged funnel toasts, exactly the floor for two independent 10% draws, meaning the twin co-fires for effectively every funnel error ([Hex thread](https://app.hex.tech/supabase/thread/019f3bc1-3a5c-7200-9122-8e3439bfbe8c)). Any consumer counting funnel errors without an `origin IS NOT NULL` filter saw ~2x inflation. The fix makes `ToastErrorTracker` the sole emitter of `source:'toast'` events, so the duplicate is unrepresentable rather than suppressed. Funnel call sites pass the id returned by `toast.error()` into `trackFunnelError`, which registers the funnel properties against that toast id instead of firing its own event – the tracker then emits a single `dashboard_error_created` enriched with `origin` / `errorCategory` / `errorReason` / `errorCode` for registered toasts, and the plain untagged event otherwise. The `'toast'` overload of `trackFunnelError` requires the toast id, so a missed pairing is a compile error rather than a silent double count. Registration is unconditional and there's only one sampling draw, so suppression can't lose a sampling race. `'form'`-sourced funnel events are unchanged. ## Changes - `lib/toast-errors.tsx`: toast-id → funnel-properties registry (`registerFunnelErrorToast`); `ToastErrorTracker` emits one (optionally enriched) event per error toast under a single 10% draw, deleting entries once consumed - `lib/telemetry/use-track-funnel-error.ts`: overloaded signature – `'toast'` requires the id returned by `toast.error()` (type-enforced), `'form'` keeps direct emission with its own sampling - Update the 7 funnel `toast.error` call sites in `NewOrgForm`, `SignUpForm`, and `pages/new/[slug]` to pass the toast id - Component tests for the tracker (previously uncovered), including an end-to-end test through `useTrackFunnelError` - Code hygiene (also flagged by CodeRabbit): all four `dashboard_error_created` emitters (toast, form, `AlertError`, `ErrorMatcher`) independently encoded the 10% draw – downstream analysis assumes a uniform sampling multiplier across sources, so one site drifting would silently skew comparisons. The rate and the draw now live in one place (`isDashboardErrorSampled()` in `lib/telemetry/error-sampling.ts`). No behavior change. - Mount `ToastErrorTracker` in the TanStack root (`routes/__root.tsx`), mirroring `pages/_app.tsx`. The TanStack tree mounted `Toaster` but never the tracker, so untagged toast error telemetry has never fired in that flavour – and with the tracker now the sole emitter, the missing mount would have silently dropped funnel toast events there too. Side effect once the TanStack flavour ships: untagged `source:'toast'` volume from it goes from zero to normal. ## Testing Component-tested (`apps/studio/lib/toast-errors.test.tsx`): - [x] Unregistered error toast fires exactly one untagged `dashboard_error_created {source:'toast'}` - [x] Registered funnel toast fires exactly one event, enriched with `origin`/`errorCategory`/`errorReason`/`errorCode` - [x] `useTrackFunnelError` with a toast id routes through the tracker as a single enriched event - [x] Non-error toasts ignored; the 10% sampling gate still applies Full Studio unit suite passes (392 files / 4371 tests), plus typecheck and lint. Also verified end-to-end in a local browser (TanStack flavour, sample rate temporarily forced to 1): a failed signup produced exactly one `dashboard_error_created` with `{source:'toast', origin:'signup', errorCategory:'api', errorReason:'email_already_registered', errorCode:403}` and no untagged twin (two independent trials); an unregistered error toast produced exactly one plain `{source:'toast'}`; a client-side validation failure produced exactly one `{source:'form', origin:'signup', errorCategory:'validation', errorReason:'email_invalid'}`; success toasts produced nothing. Post-deploy I'll re-run the twin-rate query from the Hex thread; the untagged-twin rate on funnel pages should decay to ~0 as stale bundles reload over 2-3 days. ## Notes - Origin-tagged funnel toast events now ride the tracker's single 10% draw instead of their own independent draw – statistically identical volume, but the event fires on the tracker's next effect rather than synchronously at the call site (irrelevant for PostHog) - Registration must happen in the same synchronous block as `toast.error()` (documented on the `TrackFunnelError` type) – all current call sites comply - The invalid Postgres version toast in `pages/new/[slug].tsx` (~line 416) needs no special-casing: unregistered toasts keep the plain untagged event, so its telemetry is preserved - Heads-up for `dashboard_error_created` consumers: overall untagged `source:'toast'` volume will dip slightly after this deploys, since funnel-page twins disappear. A volume monitor seeing that drop is this fix landing, not a tracking regression (same class as the intended GROWTH-893 sampling-unification drop). ## Linear - fixes GROWTH-965 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enhanced error telemetry for organization creation, sign-up, payment, and project-creation flows by associating failures with toast identifiers and enriched funnel context. * Standardized dashboard error sampling logic across error handling components for consistency. * **Tests** * Added comprehensive test coverage for toast error tracking, including funnel registration, deduplication, filtering, and sampling behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
59a82c52f8 |
Fix: improve accessibility for icon button (SQL Editor menu) (#47674)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (accessibility improvement) ## What is the current behavior? Icon-only button (not visible on widescreen displays) does not have explicit accessible name for screen readers and tooltip. ## What is the new behavior? The icon-only button now has explicit accessible name using visually hidden text (sr-only), ensuring proper screen reader support. ## Additional context Tooltip text is added for visual users. No visual changes were introduced <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Added a tooltip to the SQL editor’s “More actions” dropdown button, improving discoverability. * The tooltip now shows “More actions” when hovering over the trigger. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
f55cb25b9b | docs(auth): add a section about user invites (#47774) |