Commit Graph
38 Commits
Author SHA1 Message Date
Danny WhiteandJoshen Lim 4a5db160be feat(studio): extract shared zod number input helpers (#50102)
## What kind of change does this PR introduce?

Refactor. Extracts zod number input preprocessing into a shared Studio
helper and migrates existing call sites.

## What is the current behavior?

Number input clearing logic for controlled `type="number"` fields is
duplicated across Studio forms. The pipeline destination form had local
helpers, while Auth and settings forms inline the same `z.preprocess`
pattern.

## What is the new behavior?

Adds `apps/studio/lib/forms/zod-number-input.ts` with:

- `requiredNumberInputSchema` for required `z.number()` fields (`''` →
`NaN`)
- `optionalNumberInputSchema` for optional number fields (`''`/`null` →
`undefined`)
- `preprocessEmptyNumberInput` for `z.coerce.number()` schemas

Migrates:

- Pipeline destination form
- Connection pooling settings
- Auth provider validation (email and SMS OTP fields)
- SMTP settings
- MFA settings
- Protection settings

## To test

1. Open **Authentication > Providers > Email**, clear **Email OTP
expiration** or **Minimum password length**, and confirm the field stays
empty and shows validation on save.
2. Open **Authentication > Providers > Phone**, select a provider, clear
**SMS OTP Expiry**, and confirm validation still works.
3. Open **Authentication > Emails > SMTP settings**, clear **Port** or
**Rate limit**, and confirm validation on save.
4. Open **Authentication > Multi-factor authentication**, clear **Max
enrolled factors** or **Phone OTP length**, and confirm validation on
save.
5. Open **Database > Replication**, start a new pipeline, select
**BigQuery**, expand **Advanced settings**, clear a required numeric
field, and confirm it stays empty until filled.
6. (Optional, hosted non-HA projects only) Open **Database > Settings**,
scroll to **Connection pooling**, clear **Connection pool size**, and
confirm the value does not snap back before save.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved handling of empty numeric fields across authentication, SMTP,
database replication, and connection pooling settings.
* Optional numeric settings can now be cleared without triggering
unnecessary validation errors.
* Required numeric fields continue to display appropriate validation
errors when left incomplete.
* Standardized validation behavior for OTP settings, password
requirements, SMTP limits, replication configuration, and pool sizing.
* Refined protection settings to focus on CAPTCHA and leaked-password
options.
* **Tests**
  * Added coverage for empty and optional numeric input behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-08 18:26:41 +08:00
Vaibhav 697b373b06 fix: sms hook validation (#45208)
## TL;DR


fixes a regression where sms provider creds blocked saving phone
provider settings while
 the send sms hook was enabled




## Before


https://github.com/user-attachments/assets/3d053f4a-4b14-4a91-a5c6-dcaa0c09d148

## After


https://github.com/user-attachments/assets/f24a8534-bf86-4389-8a26-564fb9886bda

## ref:

- closes https://github.com/supabase/supabase/issues/45198


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Optimized internal validation logic for SMS provider configurations to
improve code maintainability and structure.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-24 06:53:50 -06:00
Ali Waseem e63cca3b4a fix(studio): preserve EXTERNAL_PHONE_ENABLED on phone provider save (#44982)
## Summary

Toggling the Phone auth provider on in Studio appeared to save (success
toast) but snapped back to **Disabled** immediately. The backend value
never changed.

## Root cause

In `AuthProvidersFormValidation.tsx`, the phone schema's final
`.transform` replaced the parsed values with
`enabledSchema.parse(values)`:

```
.transform((values) => {
  if (values.EXTERNAL_PHONE_ENABLED === true) {
    return enabledSchema.parse(values)   // ← strips EXTERNAL_PHONE_ENABLED
  }
  return values
})
```

`enabledSchema` is a `z.discriminatedUnion('SMS_PROVIDER', [...])` whose
branch schemas (twilio / twilio_verify / messagebird / vonage /
textlocal) don't declare `EXTERNAL_PHONE_ENABLED`. Zod objects strip
unknown keys by default, so the flag was dropped from the submitted
payload. The PATCH request to `/platform/auth/{ref}/config` went out
without `EXTERNAL_PHONE_ENABLED`, the backend kept its previous value,
and `form.reset` on the response snapped the toggle back to disabled.

Regression was introduced in #44865 (zod migration). The recent #44974
fix addressed the `shouldUnregister` side of the form but not this
transform.

## Fix

Spread `enabledSchema.parse(values)` and re-add `EXTERNAL_PHONE_ENABLED:
true` so the flag survives the transform.

## Test plan

- [x] On a project with no phone provider configured, pick an SMS
provider (e.g. Twilio), fill credentials, toggle Phone on, Save → toggle
stays **Enabled**, network tab shows `EXTERNAL_PHONE_ENABLED: true` in
PATCH payload and response
- [x] Toggle Phone off → stays **Disabled** (unchanged behavior)
- [x] Change SMS provider credentials while enabled → saves correctly
- [x] With SMS hook enabled, phone provider fields remain optional as
before

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed an issue where phone authentication provider settings were not
being properly retained during form submission.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-17 09:15:25 -06:00
Gildas Garcia 16fd60134d chore: migrate auth providers form to zod (#44865)
## Problem

We currently have 2 libraries for schema validation: `yup` that was used
with `formik` and `zod` which is now the preferred one.

## Solution

- Migrate the auth providers form to `zod`
- Remove `yup`

No visual changes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Preserve empty numeric inputs in auth provider forms to avoid
unintended conversion.

* **Refactor**
* Migrated auth provider form validation to a new validation system for
more consistent rules.
* Strengthened provider-specific validation (email, phone/SMS, OAuth,
SAML, Web3), added improved SMS test-OTP/date checks, and adjusted
initial handling for password-required-characters.

* **Chores**
  * Removed an unused validation dependency from project packages.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-16 15:27:29 +02:00
d970327ef7 feat: current password enforcement (auth) and docs (#43324)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature and docs. 


## What is the new feature?

Adds a toggle to enforce current password checks for updating a user's
password (auth)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added configurable option to require the current password when
changing passwords.
* Added configurable option to require recent reauthentication before
allowing password changes.

* **Documentation**
* Added "Password security" guide sections documenting current-password
verification and reauthentication safeguards, with usage examples.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-04-03 08:09:04 +00:00
Cemal Kılıç 92692240bf fix: make Apple OAuth client secret optional for native sign-in (#44386)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

When enabling Apple Sign-in in Studio, the form requires a valid JWT
secret key whenever a client ID is provided. This blocks users who only
use Apple native sign-in (iOS, macOS, watchOS, tvOS), where only the
client ID (bundle ID) is needed and no secret is required.

Resolves AUTH-1138

## What is the new behavior?

The secret key field is now optional, matching Google's provider
behavior. JWT format validation still applies when a secret is provided,
but leaving it empty is allowed. This supports native-only Apple sign-in
configurations.

## Additional context

The validation was simplified from two `.when` clauses (dependent on
both `ENABLED` and `CLIENT_ID`) to a single `.when` (dependent only on
`ENABLED`), matching the pattern used by the Google provider.
2026-04-02 15:17:12 +02:00
4a0bb36ca8 style: require sorted imports in studio/components (#44408)
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-04-01 10:22:37 +02:00
Illia Basalaiev fabf65fa20 allow empty string in saml metadata url (#44392)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

SAML metadata URL cannot be saved with an empty string; it works through
the management API

<img width="781" height="412" alt="image"
src="https://github.com/user-attachments/assets/586d3de2-30bc-4e8a-9d4b-b039685cb455"
/>

## What is the new behavior?

Allow saving SAML 2.0 config with an empty SAML metadata URL
2026-03-31 17:04:31 +02:00
Gildas Garcia 18e4ad227e chore: add shadcn input-group components (#44282)
## Screenshots

On a number input with units:
<img width="660" height="162" alt="image"
src="https://github.com/user-attachments/assets/1758a6d9-0836-4d41-80d1-97a03292db91"
/>

focused state:
<img width="651" height="71" alt="image"
src="https://github.com/user-attachments/assets/a92a5c39-2c7e-4c5f-9e4b-eb89810cc45c"
/>

On a textarea:
<img width="989" height="294" alt="image"
src="https://github.com/user-attachments/assets/cc696cb9-3671-4719-bdd8-daa1aea4f041"
/>
2026-03-31 09:14:56 +02:00
Ali Waseem 9da28685ec fix: remove SMS validation of fields for Twilio Verify (#44198)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Investigation by claude, validated! 

- Before (Formik): The old form used `<Form
initialValues={INITIAL_VALUES} validationSchema={...}>` Formik does not
unregister hidden fields — all fields from initialValues stay in form
state with their initial values, so hidden required fields still pass
validation because they retain their default values (e.g., the OTP
expiry/length numbers from the config).

- After (react-hook-form): The new form uses useForm({ shouldUnregister:
true }). This explicitly removes fields from form state when their
components unmount. When Twilio Verify is selected, the three hidden
fields are unmounted, their values become undefined, and yup's
unconditional .required() fails silently.

this bug was introduced today by PR #44095, the
Formik-to-react-hook-form migration.
2026-03-25 17:49:27 -02:30
Gildas GarciaandDanny White 6b35cc8034 chore: refactor auth provider form to use react-hook-form (#44095)
## Problem

- The auth providers forms still use `formik` and we want to remove it
in favour of `react-hook-form` to keep only one form library
- The auth providers forms do not follow the design system guidelines

## Solution

- Migrate to `react-hook-form`
- Apply the design system guidelines

## Screenshots

<img width="1530" height="1920" alt="image"
src="https://github.com/user-attachments/assets/04627e93-2aa5-4a7f-a24e-0ae41d6e6b10"
/>

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-03-25 09:29:28 +01:00
Ignacio Dobronich ebec20f542 chore: prevention of used leaked passwords entitlement (#43410)
### Changes
- Replaces the isPaid plan-based check on the "Prevent use of leaked
passwords" (PASSWORD_HIBP_ENABLED) setting with a proper entitlement
check using the `password_hibp` entitlement key
- Adds a new `useHasEntitlementAccess` hook that returns a reusable
checker function for any entitlement key, backed by the same cached
entitlements query


### Testing
- Head to `/project/_/auth/providers?provider=Email` with an Org on the
Free Plan
- Assert that the "Prevent use of leaked passwords" toggle is disabled.
- Head to `/project/_/auth/providers?provider=Email` with an Org on the
Pro Plan
- Assert that the "Prevent use of leaked passwords" toggle is enabled
and can be toggled and saved.

<img width="612" height="496" alt="image"
src="https://github.com/user-attachments/assets/fc1ccc79-016c-4265-96ac-bdb458d2a8de"
/>
2026-03-06 11:17:57 -03:00
issuedat 1ee61059ef feat(auth): Add X v2 provider (#41276)
* feat(auth): Add X v2 provider

* chore: reuse the existing twitter docs which will include instructions for both versions
2025-12-23 12:33:29 +01:00
Danny WhiteandJoshen Lim 46ac132051 chore(studio): empty state improvements (#40807)
* migrations

* clearer value prop

* consistent verb

* migration input

* triggers

* extract trigger buttons

* database backups

* schema title

* unrelated nit

* fix

* shared component

* ui-patterns

* rename

* improve docs

* remove redundant overrides

* remove old file

* prettier fix

* fix type error

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-11-27 17:26:20 +08:00
Stojan Dimitrovski b709428112 fix: accept apple non-domain client ids (#40756) 2025-11-24 11:59:16 -07:00
issuedat 5219515c53 feat(auth): introduce toggle to make the email optional (#38788) 2025-10-03 12:22:05 +02:00
Joshen Lim 149963f168 Add callout for leaked password that its on the pro plan and above (#39102) 2025-09-30 21:25:25 +08:00
5f533247e1 Update docs url to env var (#38772)
* Update Supabase docs URLs to use env variable

Co-authored-by: a <a@alaisteryoung.com>

* Refactor: Use DOCS_URL constant for documentation links

This change centralizes documentation links using a new DOCS_URL constant, improving maintainability and consistency.

Co-authored-by: a <a@alaisteryoung.com>

* Refactor: Use DOCS_URL constant for all documentation links

This change replaces hardcoded documentation URLs with a centralized constant, improving maintainability and consistency.

Co-authored-by: a <a@alaisteryoung.com>

* replace more instances

* ci: Autofix updates from GitHub workflow

* remaining instances

* fix duplicate useRouter

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: alaister <10985857+alaister@users.noreply.github.com>
2025-09-26 10:16:33 +00:00
Donghoon Nam e1040bfe77 fix: Correct learn more link on developer.apple.com (#38174) 2025-09-18 17:11:09 +00:00
Stojan Dimitrovski 1d0d56a3f3 feat: web3 (ethereum) ui (#38623) 2025-09-15 11:57:03 +02:00
Ivan VasilovandClaude 9fda63d9ba fix: Move confirm email setting from email provider to basic auth settings (#37573)
* Move confirm email setting from email provider to basic auth settings

- Remove MAILER_AUTOCONFIRM from email provider form validation
- Add confirm email setting to BasicAuthSettingsForm with proper form validation
- Maintain existing functionality while improving UX by grouping related settings

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>

* Update BasicAuthSettingsForm.tsx

* Fix the default value of email confirm.

* Remove unnecessary comment.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-07-31 09:50:09 +02:00
Stojan DimitrovskiandIvan Vasilov 49c677dff4 feat: add sign in with solana (web3) configuration UI (#34909)
* feat: add sign in with solana (web3) configuration UI

* Regenerate the api types.

* fix tiny things

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2025-05-22 10:53:25 +02:00
Joshen Lim 6d0a742ab7 Chore/fix linkedin OIDC checking in user overview (#34690)
* Fix linkedin oidc checking in UserOverview

* Improve refactor

* Update

* Last fix
2025-04-03 13:56:30 +02:00
Charis 64bc54aa44 clarify length of recent session (#34097)
"logged in recently" is too vague a description to be useful, so added the actual time
2025-03-10 16:19:42 +01:00
GulshanandJoshen Lim 0d9be5cfac Fix/auth config update (#33459)
* fix auth config update

* add comment

* Consolidate variables

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-02-11 19:36:28 +08:00
d4e9ea0b31 Move authentication settings (#33335)
* all settings moved into the right places

* clean a few things up

* update ui for auth settings

* more updating

* rearrange settings

* Update SmtpForm.tsx

* updated styling

* add old auth page to show links

* add copy

* udpate copy

* smtp links

* auth fixes

* Smol fix

* Another smol fix

* Fix tab page menu selection

* Add missing border

* Gah one last one

* Smol improvement for redirects from settings/auth to use id

* Update apps/studio/components/layouts/AuthLayout/AuthLayout.utils.ts

Co-authored-by: Kang Ming <kang.ming1996@gmail.com>

* Update apps/studio/pages/project/[ref]/auth/mfa.tsx

Co-authored-by: Kang Ming <kang.ming1996@gmail.com>

* Update apps/studio/pages/project/[ref]/auth/mfa.tsx

Co-authored-by: Kang Ming <kang.ming1996@gmail.com>

* remove recommendation

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Kang Ming <kang.ming1996@gmail.com>
2025-02-07 14:36:11 +10:00
Joshen Lim caeb09b369 Add new regions for RR deployment (#30409) 2024-11-11 16:37:49 +08:00
3369164f96 Fix: unify Client ID handling for Google provider (#29950)
* Fix: unify Client ID handling for Google provider

* Ensure no spaces in Client IDs

* Update apps/studio/components/interfaces/Auth/AuthProvidersFormValidation.tsx

Co-authored-by: Kang Ming <kang.ming1996@gmail.com>

* Fix Apple provider client IDs

* Update apps/studio/components/interfaces/Auth/AuthProvidersFormValidation.tsx

Co-authored-by: Kang Ming <kang.ming1996@gmail.com>

* Update apps/studio/components/interfaces/Auth/AuthProvidersFormValidation.tsx

Co-authored-by: Kang Ming <kang.ming1996@gmail.com>

* Remove Secret key requirement

* Fix markdown component usage + apple client id

---------

Co-authored-by: Kang Ming <kang.ming1996@gmail.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2024-11-11 15:24:46 +08:00
Terry Sutton 110e8ed77f Chore/update url regex (#30138)
* Allow excluding options in the url regex

* Add tests for options
2024-10-29 10:05:52 -02:30
Joshen Lim 3bcbd9cae5 Fix filtering on SAML provider (#29636) 2024-10-02 15:44:10 +08:00
Joshen LimandAlaister Young 536dc37d58 Chore/user management v2 panel part 2 (#29515)
* Set up banning and unbanning user, although untested due to API CORs issue

* Update search filter UI for users management V2

* Update API types

* Minoir

* Small fix

* Update UI

* Add support for resizing and re-ordering columns

* Add google profile image url to csp

* Revert test button

* Implement toggling of columns

* Fix loading

* Fully implement banning/unbanning user

* Fix

* Update apps/studio/components/interfaces/Auth/Users/UserOverview.tsx

Co-authored-by: Alaister Young <alaister@users.noreply.github.com>

* Fallback non CSP supported avatar urls to user icon

* Fix some bugs

* Remove prism-react-renderer from studio, add to ui patterns

* Migrate users query from API to studio

* Address some feedback

---------

Co-authored-by: Alaister Young <alaister@users.noreply.github.com>
2024-10-01 14:32:46 +08:00
Monica KhouryandJoshen Lim 63f2c8916f Chore: Add links to documentation to the Auth Providers page (#29259)
* Chore: Add links to documentation to the  Auth Providers page

* Update position of documentation button in provider form

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2024-09-13 15:02:51 +08:00
Stojan Dimitrovski fc48231093 feat: add saml encrypted assertion support (#28996) 2024-09-10 12:35:14 +02:00
Kang MingandJoshen Lim 485d85fb9b fix: disable sms provider validation when sms hook is enabled (#28706)
* fix: disable sms provider validation when sms hook is enabled

* chore: add comments

* Small fixes

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2024-08-19 11:06:36 -04:00
Joel LeeandJoshen Lim 530ab69901 feat: add SAML External URL field (#27628)
* feat: add SAML External URL field

* fix: update

* feat: update package-lock.json to mirror master

* fix: patch validation

* fix:  update to default to '' instead of false

* fix: add description

* fix: re-run prettier

* Update UI

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2024-07-18 09:15:50 +02:00
Kang Ming 5e83aa3c18 fix: add new slack provider & deprecate old one (#27864) 2024-07-09 12:33:59 -07:00
Kang Ming 9963c81a26 Km/update copy (#23264)
* chore: update copy on signup and reset password links

* fix: add config for updating otp length
2024-04-25 17:48:55 +08:00
Joshen Lim 948a2390fe Final replacements of ui setNotification with toast (#21885)
* Final replacements of ui setNotification with toast

* Rip out UiStore

* Rip out UiStore

* Shift files under authConfigSchema to components/Auth

* Rip out use of observers
2024-03-12 12:56:56 +08:00