Commit Graph
6597 Commits
Author SHA1 Message Date
Saxon FletcherandClaude Opus 5.5 5e59b6047e chore(studio): extend Assistant response time and handle timeouts (#50892)
## Problem

- Assistant responses were capped at 120 seconds and 10 steps, which is
too short for longer reasoning or multi-step tool work.
- When the hosting platform ended a request at that limit, the
connection just dropped. The user got no explanation, and "Thinking…"
and tool rows kept spinning.
- Studio's own tools ignored the request's abort signal, so a stop,
disconnect or deadline couldn't cancel their in-flight requests.
- Aborted responses never closed their Braintrust span. Under TanStack
Start, the remote MCP client was only released on `res.on('close')`,
which the adapter never emits.

## Solution

Uses AI SDK options instead of custom stream handling:

- `maxDuration` goes to 300s and the step limit to 20. `streamText({
timeout: { totalMs } })` stops the response at 270s, leaving time to
finish the stream before the platform cutoff.
- `toUIMessageStream({ messageMetadata })` marks an aborted response
`timedOut: true`. `Chat` ignores `abort` chunks, so the client reads
this flag instead and shows a timeout alert with Retry. The flag is
saved with the message, so the alert survives a reload.
- `toUIMessageStream({ onEnd })` aborts the request whenever the stream
ends, releasing the MCP client on both runtimes. `streamText({ onAbort
})` ends the Braintrust span.
- Studio tools pass the SDK's `abortSignal` to their fetches. MCP tools
already did.
- Reasoning and server-tool rows that never finished show "Response
interrupted" instead of a spinner or "Ran X ✓".

There's no per-tool timeout. Approved SQL and migrations can
legitimately run longer, and aborting the HTTP request doesn't stop the
query in Postgres.

## Review instructions

1. Run the unit tests: `cd apps/studio && pnpm vitest run
lib/api/generate-v4.test.ts lib/ai components/ui/AIAssistantPanel`
2. To see a timeout without waiting 4.5 minutes, temporarily set
`ASSISTANT_TIMEOUT_MS` in `apps/studio/lib/ai/assistant-timeout.ts` to
`15_000` and run `pnpm dev:studio`.
3. Ask the Assistant something that needs several tool calls or long
reasoning, for example "Audit my schema for missing indexes and RLS
gaps, then write the fixes."
4. After 15 seconds, check that:
- the response stops and a "Assistant response timed out" alert appears
with Retry
- any in-progress reasoning or tool row shows "Response interrupted"
instead of spinning
   - Retry starts a new response
   - reloading the page still shows the alert on that chat
5. Stop a response with the Stop button before the deadline. It should
stop without the timeout alert.
6. With the default 270s, confirm that a normal response completes as
before.

## Checklist

Check all before review:

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* AI assistant responses can now run for up to five minutes, supporting
longer requests.
* When a response times out, the assistant displays a message suggesting
you retry or ask for a smaller change.
* Incomplete responses now show a “Response interrupted” notice, and
loading indicators stop when generation ends.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 12:44:39 +10:00
Wen Bo Xie 0eb08cb9f0 docs: prepare scoped personal access tokens docs for GA (#50839)
Scoped personal access tokens are leaving alpha. Remove the pre-GA
framing
and update pages that assumed every token carries full account access.

- Personal Access Tokens guide: remove the public alpha / early access
admonition. Add a section on using a scoped token with the Supabase CLI:
  the browser flow of `supabase login` creates a classic token, while
SUPABASE_ACCESS_TOKEN or `supabase login --token` uses a scoped one, and
  commands that connect with the database password aren't limited by the
  token's permissions.
- Management API introduction: replace "PATs carry the same privileges
as
your user account" with the scoped vs. classic distinction and link to
the
  guide's permission tables.
- MCP guide: the CI setup now asks for a scoped token limited to the
  connected project and links to the MCP tool permissions table.
- API keys guide: replace the internal "fine-grained token" permission
ID
  with the names shown in the dashboard (API Keys, Read), and note that
  `reveal=true` in the example also needs API Key Secrets (Read).
- Managing environments: recommend a scoped token for the GitHub Actions
  deploy workflow.
2026-09-28 10:43:18 +09:00
Danny White fd0918833f feat(studio): refine pipeline creation copy (#50751)
## Problem

The pipeline creation sheet uses generic examples, inconsistent
destination terminology, and Advanced settings copy that does not
explain what is being overridden. Its Docs button also sends most
destinations to the general Pipelines guide.

This PR is stacked on #50719 so the shared copy builds on the focused
Snowflake field improvements.

## Solution

Adds destination-specific pipeline-name examples and field descriptions,
clarifies destination summaries and Advanced settings, uses
human-readable ClickHouse engine names, shortens the primary action to
**Start pipeline**, and links the Docs button to the selected
destination guide.

## Review instructions

1. Open **[Database
Replication](https://studio-staging-git-dnywh-studiorefine-pipeline-1eaf59-supabase.vercel.app/dashboard/project/_/database/replication)**
and click **Add pipeline**.
2. Switch between destination types and confirm the pipeline-name
example, destination summary, and field descriptions update
appropriately.
3. Open **Advanced settings** and confirm the batch wait-time default is
shown in the description while the input placeholder is `10000`.
4. Select each supported destination and confirm **Docs** opens its
matching destination guide.
5. Select ClickHouse and confirm the engine choices read
**ReplacingMergeTree** and **MergeTree**.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Clarified replication settings, destination field descriptions, and
batch wait-time guidance.
* Added destination-specific pipeline name placeholders and updated the
labels for ClickHouse engine options.
  * Clarified ClickHouse password guidance for new destinations.
* Updated new-pipeline buttons to say “Start pipeline” or “Start
pipeline anyway.”
* Added destination-specific documentation links for BigQuery,
ClickHouse, DuckLake, and Snowflake.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 10:59:27 +10:00
Danny WhiteandJoshen Lim 9fb173e827 feat(studio): improve Snowflake destination setup (#50719)
## Problem

Snowflake setup makes the public and private key files easy to confuse,
treats the optional SQL role like a primary connection field, and
requires users to paste private-key contents manually. Password managers
can also mistake the Snowflake user field for a sign-in field.

This PR is based on #50708 so its later Docs-button follow-up can use
the nested destination-guide URLs.

## Solution

Clarifies the Snowflake field copy and example values, moves **Role**
into Advanced settings, opts the service-user field out of
password-manager overlays, and adds drag-and-drop or button upload for
P8 and PEM private-key files. Public key files are rejected without
replacing the current field value.

| Before | After |
| --- | --- |
| <img width="1280" height="1323" alt="Pipelines Database Agua Basket
Supabase"
src="https://github.com/user-attachments/assets/83d91b03-34f0-479f-ba65-ad9275b28431"
/> | <img width="1280" height="1323" alt="Replication Database Agua
Basket Supabase"
src="https://github.com/user-attachments/assets/a722722c-d518-4c60-94b8-e79bab6de2ca"
/> |

## Review instructions

1. Open **[Database >
Replication](https://studio-staging-git-dnywh-studioimprove-snowflake-form-supabase.vercel.app/project/_/database/replication)**,
click **Add pipeline**, and select **Snowflake**.
2. Confirm **Role** appears under **Advanced settings** and explains the
default-role behaviour.
3. Upload or drop a valid P8 or PEM private key and confirm its contents
appear in **Private key**.
4. Select a public key file and confirm the form rejects it without
replacing the existing value.
5. Confirm 1Password (or Bitwarden etc) does _not_ add its widget to
**User**.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added Snowflake private key upload via file picker or drag-and-drop.
- Supports P8 and PEM private key files, with validation and clear error
messages.
  - Added an optional Snowflake role field in Advanced Settings.
- **Usability Improvements**
  - Preserves manual edits made while a private key file is processing.
- Improved drag-and-drop feedback and updated field guidance and
placeholders.
- Prevents password managers from automatically filling Snowflake
credentials.
- Validates private keys when submitting the Snowflake destination form.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-28 10:38:57 +10:00
Chris Opland db2242e223 fix(o11y): add connections to footer (#50928) 2026-09-25 14:23:46 -05:00
Chris Opland 509afd0bf0 fix(o11y): support partial metric loading (#50867) 2026-09-25 12:20:23 -05:00
kemal.earth de3524034f feat(studio): add ability to drag top section map (#50904)
## Problem

Top section map view on project overview wasn't very usable on smaller
window sizes. No ability to drag and see any instances on west coast
without stretching viewport or it being cut off.

## Solution

Adds dragging to map area so you can bring into view locations out of
the bounding box.

## Review instructions

1. Switch to map view and **drag the map** — it should pan, and the
previously cut-off regions should be reachable.
2. The drag should **track the cursor 1:1**, with no rubber-band lag.
(The 300ms transform transition is what caused that; it's now suppressed
mid-drag.)
3. Drag hard toward each edge — the map should **stop at the frame
bounds** rather than sliding off into empty background.
4. Cursor should read `grab`, and `grabbing` while dragging.

### Regressions to rule out

5. **Wheel/trackpad scroll over the map** must not zoom it, and the page
behind it must still scroll normally. Trackpad pinch must not zoom
either.
6. **Double-click** on the map must not zoom.
7. **Click a region marker** — still recenters, zooms to 2.0, and opens
the region detail panel bottom-right. The recenter should still animate
smoothly.
8. **Close** in that panel still resets to the default center and zoom.
9. **Hover a marker** at default zoom — the country/database tooltip
still appears; the dashed lines between primary and replicas still
render.
10. Toggle back to **flow view** — unchanged.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Map view now supports dragging to pan, with cursor changes to indicate
when panning is available or in progress.
* **Bug Fixes**
* Map zoom input is filtered based on event type, modifier keys, and
mouse-button state.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-25 17:27:54 +01:00
Anthony Lio e3febf3b63 feat(lint): add shadcn lint warnings (#50676)
## Problem

six apps had no shared lint checks for invalid tailwind classes,
off-scale values, and raw colors.

## Solution

add @shadcn/lint warnings with narrow exceptions for existing theme
colors and artwork. fix several invalid classes. the existing lint
command reports findings without blocking prs on the current warning
count.

## Review instructions

1. check the shared rules and app-specific exceptions.
2. run `pnpm --filter design-system lint` and confirm it reports shadcn
warnings without errors.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved vertical alignment of checkbox labels and supporting text in
dialogs, settings, and examples.
* Corrected alignment of organization member details and the color
styling of deprecated chart text.
* Standardized spacing in the date and time editor without changing its
appearance or behavior.

* **Developer Experience**
* Updated linting and UI configuration across several apps to support
consistent style checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-25 17:50:50 +03:00
Jordi Enric f0952fdef8 fix(studio): delete only the selected foreign server FE-4462 (#50785)
## Problem

The dashboard lists one row per foreign server, but deleting a row
dropped its foreign data wrapper with CASCADE. When multiple servers
shared a wrapper, deleting one removed all of them.

## Fix

Drop the selected server and its foreign tables. Remove the underlying
wrapper and Vault secret only when no servers still use it. Edits to a
shared wrapper now stop before making changes because the existing edit
flow recreates the underlying wrapper.

## How to test

1. Configure two BigQuery foreign servers that use the same foreign data
wrapper. Delete one from the dashboard.
2. Confirm the other server and its foreign tables still exist and work.
3. Delete the remaining server. Confirm the foreign data wrapper and its
Vault secret are removed.
4. Attempt to edit one of two servers sharing a wrapper. Confirm the
edit fails without removing either server.

Focused pg-meta tests and typecheck pass.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Shared connections are identified in the integrations list, with
guidance for editing them in the SQL Editor. Editing is disabled when a
wrapper is shared, with an explanation shown.
* Deleting a connection removes its foreign tables and removes the
wrapper and Vault secret only when no other connection uses them.
* **Bug Fixes**
* Connection deletion verifies that the selected server still belongs to
the wrapper and reports failures using connection-focused wording.
* Attempts to edit a wrapper used by another connection are blocked with
a clear explanation.
* Connection deletion and confirmation messages now consistently refer
to deleting a connection.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-25 16:49:01 +02:00
Ivan VasilovandClaude Sonnet 5 12894ddd2a feat(studio): migrate storage infinite-query hook to list-v2 (#50730)
## Problem

Storage's `list` (v1) endpoint is being deprecated in favor of
`list-v2`, which uses cursor pagination instead of numeric offset (which
degrades on large buckets) and fixes folders that differ only by case
not both being listable. This is PR 1 of the migration (parent:
FE-4423); it covers the shared infinite-query hook and its two
consumers.

## Solution

Added `listBucketObjectsV2` alongside the existing v1
`listBucketObjects` (still used elsewhere, migrated in a later PR), and
replaced the `useBucketObjectsInfiniteQuery` hook with
`bucketObjectsInfiniteQueryOptions` built on `infiniteQueryOptions`,
following the repo's preferred data-fetching pattern. Pagination now
uses `hasNext`/`nextCursor` instead of an offset multiplier, and
`queryFn` rejects a response that claims `hasNext` without advancing the
cursor so a misbehaving backend can't send `fetchNextPage` into an
infinite loop. v2 splits results into separate `folders`/`objects`
arrays and has no `search` field, so the two consumers
(`BucketFilePickerColumn`, `MoveItemsFolderPicker`) merge/sort those
arrays themselves, and search is folded into a `prefix` match instead.
Also removed "Time last accessed" from the picker's sort dropdown since
v2's `sortBy.column` doesn't support it, with a defensive fallback to
`name` in case the shared sort preference (still used by the v1 main
file explorer) carries that value over. Added the missing self-hosted
`list-v2` API proxy route (`pages/api` + the TanStack `routes/api`
wrapper) using storage-js's `listV2()`, since self-hosted Studio only
had a v1 route and every v2 request was 404ing there.

## Review instructions

1. Open the bucket file picker (e.g. via an OAuth app logo upload),
confirm folders and files both render and paginate correctly, and that
searching still filters as expected.
2. Open the "Move items" modal's folder picker, confirm you can navigate
into and back out of subfolders, and that folder search still works.
3. Run `pnpm test:studio -- MoveItemsModal`.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Storage browsing loads large bucket listings in pages, helping keep
navigation responsive.
* Folder pickers display folders and files together across paginated
results.
* Moving items between folders uses the same paginated browsing
experience.
* Search remains available in the final folder level, and folder
navigation shows the correct contents.

* **Updates**
* “Time last accessed” is no longer available as a sorting option in
storage pickers. Sorting is available by name, creation time, or update
time.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-25 16:11:24 +02:00
Saxon FletcherandClaude Opus 5 9b12165400 feat(studio): multi-select logs with click, shift, and keyboard ranges (#50689)
<img width="1454" height="786" alt="image"
src="https://github.com/user-attachments/assets/995790b1-a242-4a61-a0a0-349de7234923"
/>


Stack 4/4 · previous: #50688

## Problem

Selecting several logs to copy or send to the Assistant meant using a
separate checkbox column and a banner above the table. Clicking a row
and checking a row were two different selections.

## Solution

- Unified Logs uses `useTableRowSelection`, so a row click,
Cmd/Ctrl-click, Shift-click, and the checkbox all act on one selection.
The selection resets when the project or filters change, and a linked
`?id=` still restores its log.
- The level indicator and checkbox now share one column. The checkbox
shows on hover, focus, or when the row is selected.
- The detail panel shows every selected log: one log gets the tabs, and
two or more show their combined JSON. Copy-as-JSON and "Explain with AI"
move into the panel header (`LogSelectionActions`), replacing
`RowSelectionHeader`.
- New Shift+↑ / Shift+↓ shortcuts extend the selection, with a hint in
the panel footer. Prev/next navigation follows display order and keeps
the row in view.
- `LogTypeIcon` no longer puts a nested button inside clickable rows.

## Review instructions

1. Click a log, then Shift-click another. The range should be selected
and the panel should show the combined JSON.
2. Cmd-click to add or remove single logs. Use the copy button (or its
shortcut) and "Explain with AI".
3. With the panel open, press Shift+↑ / Shift+↓ to grow and shrink the
selection.
4. Change a filter. The selection should clear.

## Checklist

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **New Features**
* Added multi-row selection in Unified Logs, including additive, range,
checkbox, and keyboard selection.
* Added bulk JSON viewing and copying, plus AI-assisted actions for
selected logs.
* Added Shift+Arrow shortcuts to extend selections and improved row
navigation.
* **Accessibility**
* Improved labels and focus behavior for log controls and log type
indicators.
* **Bug Fixes**
* Kept single-log Overview and Raw JSON views available alongside
multi-log selection.
* Applied metadata visibility settings to selected-log actions and
disabled actions for invalid log data.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-25 19:03:01 +10:00
K-Dog (Kevin) cbd8889fc2 fix: tooltip for log query (#50898) 2026-09-25 08:43:59 +00:00
Saxon Fletcher d0135231fb chore(studio): improve assistant feed performance (#50888)
## Problem

Assistant conversations with multiple query and Edge Function blocks
repeatedly render expensive content while streaming. Scrolling past the
feed boundary can also move the surrounding layout.

## Solution

Memoize unchanged messages, blocks, and code highlighting; batch
streaming UI updates; and skip off-screen query layout while keeping
block state mounted. Preserve streamed status updates and contain
scrolling in the message viewport. The changes are shared by Next and
TanStack.

## Review instructions

1. Compare the base branch and this branch using the same saved
conversation containing 10–20 query, result/chart, and Edge Function
blocks. Keep the browser, viewport, and conversation identical.
2. In Chrome DevTools, record Performance with 4× CPU throttling while
streaming a follow-up, typing in the composer, and scrolling through the
feed. Compare scripting/layout time and long tasks. React DevTools
Profiler should show unchanged completed blocks avoiding renders during
subsequent text updates.
3. Scroll away from query blocks and return. Confirm results, display
settings, selections, and controls retain their state. Run a read-only
query such as `select 1` and check its results still update.
4. Confirm “Thinking…” finishes, Stop retains the latest streamed text,
and approval/skip, copy, edit, and branch actions still work. Repeated
scrolling at the feed boundary must leave the outer layout/composer
stationary; jump-to-latest and following new messages should still work.
5. Repeat in both runtimes: `STUDIO_FRAMEWORK=next pnpm dev:studio` and
`STUDIO_FRAMEWORK=tanstack pnpm dev:studio`. Also check the assistant
sidebar, which shares the feed.

## Validation

- 170 assistant/Explorer tests and one shared CodeBlock test passed;
formatting and Studio lint passed (two existing warnings).
- Browser checks covered both route entry points, viewport
state/geometry, and scroll behavior.
- Review fixes: 23 focused tests, lint, formatting, and full Studio
typechecking passed. Full production builds were not verified.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] No docs content changed; docs authoring skills are not applicable.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Performance**
* Improved responsiveness in the AI assistant by reducing unnecessary
updates while messages stream and conversation history is displayed.
* Optimized query previews, message rendering, and code blocks to keep
the interface smoother during use.
* **Bug Fixes**
* Improved handling of message edits and deletions during generation,
and preserved the latest response when generation is stopped.
* Improved conversation scrolling behavior while keeping conversation
content and scroll areas working as expected.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-25 18:09:34 +10:00
Alaister YoungandAlaister Young 89ae80073d [FE-4400] feat(studio): shift-click range selection in Unified Logs (#50462)
Shift-clicking a row checkbox in Unified Logs now selects every row
between the last clicked row and the clicked one, following up on
#50381. Per review, the legacy logs table now uses react-data-grid's
native shift-click selection (the same mechanism as the table editor)
instead of the custom anchor logic from #50381, and Unified Logs matches
the grid's semantics.

**Semantics (all three tables):** a shift-click applies the clicked
checkbox's new state to every row between the last clicked row and the
clicked one. The last clicked row itself is untouched. In Unified Logs a
shift-click after the selection has been cleared is a plain toggle.

**Changed:**
- `LogTable` passes `selectedRows`, `onSelectedRowsChange`, and
`rowKeyGetter` to the grid and renders the checkbox through a small
`LogSelectCell` component using `useRowSelection`. The custom anchor
ref, its resets, and the inline toggle are gone. Checking a row still
closes the single-row side panel.
- `getShiftClickSelection` moved from the Logs utils to
`apps/studio/lib/shift-click-selection.ts` and rewritten to the grid's
rule. Only Unified Logs uses it now, via a `getShiftClickRowSelection`
adapter for TanStack Table's `RowSelectionState`. Tests cover both.
- Unified Logs owns a selection anchor ref and passes it into the column
generator. The checkbox cell handles `onClick` with the shift key,
computes the range over the table's displayed row model (so it spans
sort order and infinite-scrolled pages), and writes back through the
table's own selection setter. Shift mousedown is prevented so no text
selection spans rows.
- The `LogTable` test mock of react-data-grid now implements the grid's
row selection so the component tests exercise the native path.

## To test

- Postgres logs: click one checkbox, then shift-click a checkbox further
down. Every row in between should be checked and the action bar shows
the count. Repeat upward.
- Shift-click an already-checked row: it and the rows back to the last
clicked row uncheck, the last clicked row stays as it was.
- Checking a box closes the single-row side panel. Clicking a row body
clears the selection and opens the panel.
- Tab to a checkbox and press Space: it still toggles. Arrow keys plus
Shift+Space still toggle the focused row.
- Unified Logs: same shift-click behavior. Clear the selection or change
a filter, then shift-click: only that one row toggles. Scroll to load
more rows and shift-click across the boundary.
- Copy as JSON/Markdown and Explain with AI still use the selected rows
in both tables.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Improved row selection in Settings Logs and Unified Logs.
- Shift-click now selects or deselects the range between the anchor row
and clicked row.
- Clicking an already selected row clears the relevant selection while
preserving the anchor row.
- Added more consistent checkbox, keyboard, and range-selection behavior
across log tables.
- Selecting a checkbox no longer opens the corresponding log, while
clicking the row continues to open it.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-25 15:38:23 +08:00
Alaister YoungandAlaister Young a47397d5fe fix(common): restore narrow Feature type (#50850)
The platform API now types `ProfileResponse.disabled_features` as
`string[]` (since #48981), which collapsed the `Feature` union to plain
`string`, so `isFeatureEnabled` accepted any string and typos went
uncaught.

**Changed:**
- `Feature` is now a local `RuntimeFeature` union (the profile-driven
flags) plus the keys of `enabled-features.json`, instead of deriving
from the API type
- `useIsFeatureEnabled` casts the merged runtime disabled list to
`Feature[]`, since the profile field is now `string[]`

The runtime feature list duplicates what the backend knows. Once the
enum is restored in the API spec, `Feature` can go back to deriving from
the generated type.

## To test

- `pnpm typecheck` passes
- Passing a bogus string to `useIsFeatureEnabled` / `isFeatureEnabled`
is now a type error
- Nothing behavioral changes, so a quick sanity check that the sidebar /
billing / org settings still render is enough


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **No user-facing changes**
* This update does not change the app’s visible features or behavior. It
includes internal typing adjustments only.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-25 17:21:38 +10:00
+8 e273d2b818 chore(studio): move Explorer SQL Editor link to sidebar footer (#50829)
## What

- Moves the temporary "Switch to SQL Editor" button out of the Explorer
sidebar header into a footer section ("Looking for snippets?") with a
short explanation and an **Open SQL Editor** button.
- Replaces the header slot with a menu for the Explorer startup
preference (**Start page** / **SQL query**), instead of linking out to
account preferences.

## How to test

1. Enable the Explorer feature preview and open
`/project/<ref>/explorer`.
2. **Header menu:** click the ⋮ button next to the Explorer title. Pick
**SQL query**, then check that **Explorer startup** on `/account/me`
shows the same value (and vice versa).
3. **Footer:** click **Open SQL Editor**. You should land in the SQL
Editor with the **Back to Explorer** button in its title bar.
4. Open **Notebooks** or **Chats** in the sidebar and check that the
menu and footer are hidden there, like the old button was.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Choose whether the Explorer opens to the Start page or SQL query from
the Explorer preferences menu. Your selection is saved and retained when
you reopen the menu.
  * Access the SQL Editor from the Explorer’s sidebar footer.
* Explorer preferences are available from the Explorer navigation
header.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Tyler <dshukertjr@gmail.com>
Co-authored-by: Nik Richers <nrichers@gmail.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Jordi Enric <37541088+jordienr@users.noreply.github.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Co-authored-by: Katerina Skroumpelou <mandarini@users.noreply.github.com>
Co-authored-by: Franek <franek@ferly.co.uk>
Co-authored-by: Franek Richardson <franek@supabase.io>
Co-authored-by: Michał Olszewski <35968924+charconstpointer@users.noreply.github.com>
Co-authored-by: Steven Eubank <47563310+smeubank@users.noreply.github.com>
Co-authored-by: Anthony Lio <lionnet.ant@gmail.com>
Co-authored-by: Joey Lei <6957385+leizerbeam@users.noreply.github.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
Co-authored-by: Samir Ketema <6003000+samirketema@users.noreply.github.com>
Co-authored-by: K-Dog (Kevin) <k.grueneberg1994@gmail.com>
2026-09-25 14:31:46 +08:00
K-Dog (Kevin) a5ad2ce745 feat: log query/ingest insights (#50570)
We are doing a soft rollout for log pricing including log ingest and log
querying. We currently only want to display usage/soft warnings, which
is why the metrics are filtered out in some components.
2026-09-25 11:45:46 +08:00
Samir Ketema ad5c4bb879 fix: gracefully handle 403s on org invites for project-scoped members (#50876)
## Problem

Gracefully handles 403s when getting org invitations as a project-scoped
org member. The backend currently returns an empty list with a 200
status, but that will be changing soon - so this PR aims to fix the
issue in advance.

## Solution

Pretty self explanatory - but here is a before/after (with backend
changes)

### Before
<img width="2480" height="688" alt="CleanShot 2026-09-24 at 11 02 34
AM@2x"
src="https://github.com/user-attachments/assets/13c6ed9e-7580-4962-9920-f49ede9c4592"
/>

### After
<img width="2466" height="820" alt="CleanShot 2026-09-24 at 11 07 13
AM@2x"
src="https://github.com/user-attachments/assets/248f7bb5-1743-41c9-823f-f776a608dd17"
/>


<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. Open the preview
2. Navigate to the `Team` tab in `Organization`
3. Invite a project-scoped member
4. Accept the project-scoped member invite in another browser
5. Navigate to the same `Team` tab as that project-scoped member.


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Organization member lists now load even when invitation details aren’t
accessible.
* Missing invitation data no longer prevents member lists from loading.
* Invitation errors other than access-denied errors, and errors loading
members, continue to be reported.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 12:33:23 -07:00
Ali Waseem 21df8d02e6 Rename best available region option to Auto (#50873)
The region selector's "Best available region" option now reads "Auto"
and carries the Recommended badge. Also removes the "Select the region
closest to your users for the best performance." description, which was
misleading for the auto selection.

Fixes FE-4468


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* The recommended region is now labeled “Auto” in both the selected
value and the options list; its “Recommended” badge remains.
* Removed general advice to choose a region closest to users.
High-availability and local/staging notices are unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 11:29:31 -06:00
Gildas Garcia 0381c5bc23 Fix unstable test by increasing its timeout (#50860)
## Problem

We have an unstable test that fails the CI too often.

## Solution

Increase its timeout.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Updated the automated test timing allowance for an
organization-switching scenario, helping the test complete reliably when
mocked project-list requests take longer. This is a test-only change and
does not alter the app’s behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 17:22:45 +02:00
Joshen Lim 9a60994efb Update account audit logs to follow unified logs UX (#50799)
## Context

This one's just something that I thought about while doing some
debugging - our audit logs UI is pretty outdated and hard to skim as the
information is very sparse. This is how it currently looks like
(specifically Account audit logs for this PR, there's also org audit
logs):

<img width="1450" height="957" alt="image"
src="https://github.com/user-attachments/assets/4b69511e-1d4f-4725-8ea9-78ddacf76942"
/>

<img width="1450" height="954" alt="image"
src="https://github.com/user-attachments/assets/ec099f52-adef-499c-965a-11b8404bf235"
/>

Am opting to follow the same UX as that of our Unified Logs, so opting
to update the UI as such:

<img width="1451" height="958" alt="Screenshot 2026-09-23 at 22 04 33"
src="https://github.com/user-attachments/assets/016bd26d-4078-42dc-9ff2-5bae9edbc1b2"
/>
<img width="1451" height="957" alt="Screenshot 2026-09-23 at 22 16 09"
src="https://github.com/user-attachments/assets/f038b635-1359-4710-bc84-0f32ace1fb82"
/>
<img width="1450" height="956" alt="Screenshot 2026-09-23 at 22 16 37"
src="https://github.com/user-attachments/assets/7230b94a-c7ec-4550-bb55-5405ebc074a7"
/>

More importantly, we'll allow users to copy logs as JSON so users can
eject to their own agent if needed
<img width="1201" height="350" alt="image"
src="https://github.com/user-attachments/assets/587ab881-a501-41e6-8c9b-59191a2b2047"
/>

## To test
- [ ] Mainly just need to make sure that account audit logs still works
as expected - it's all read only so just need to ensure that all
information that's available before, is still available


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Browse account activity logs with date-range and project filters,
project search, sorting, and refresh controls. Results automatically
refresh every five minutes.
* Choose preset date ranges, select individual logs or ranges of rows,
and copy selected entries as formatted JSON.
* Open a log to view request, actor, target, and action details, or
inspect and copy its raw data.
* Select log rows with a mouse or keyboard, and view loading, error,
empty-results, and filtered-empty states.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 11:07:36 +00:00
Gildas GarciaandDanny White ca28c945db Improve Table Editor design and accessibility (#50797)
## Problem

Controls in the new table sheet's Columns section had inconsistent
styling, alignment and focus states. Some icon-only actions were faint
or lacked useful accessible names and tooltips, while related controls
used different dropdown treatments.

<img width="1428" height="250" alt="image"
src="https://github.com/user-attachments/assets/9d1ad80d-2de0-4736-8ddb-0260e10ddacc"
/>

## Solution

- Align the column headers and fields on the same grid, and keep the
foreign key action inside the name field in every state.
- Give the drag, foreign key, suggestions, extra options and remove
actions consistent button styling, sizing, hover and focus states, with
accessible names and tooltips.
- Move masking into Extra options and include it in the options count.
Remove the separators around the former inline controls.
- Use the design system's ComboboxTrigger for column types and align the
Default value select's radius with it. Update the suggestions dropdown
icon.
- Tidy related field labels and update the affected table editor tests.

The underlying column values and database behaviour are unchanged.

| Original before | Original after |
| --- | --- |
| <img width="1498" height="392" alt="CleanShot 2026-09-24 at 13 33
40@2x"
src="https://github.com/user-attachments/assets/56559e72-f289-44bc-999f-c1f3158c8f65"
/> | <img width="1496" height="416" alt="CleanShot 2026-09-24 at 13 32
42@2x"
src="https://github.com/user-attachments/assets/d05340fc-a460-4b5c-aaff-41127f692592"
/> |

## Review instructions

- Open **Table Editor → New table** and inspect the Columns section.
Check that Name, Type and Default value headers align with their fields.
- Tab through the row actions. Check their focus states, accessible
names and tooltips, including the foreign key control with and without a
relation.
- Drag a column to reorder it, open Extra options and toggle masking.
Check the options count and that the other settings still work.
- Compare the closed Type and Default value dropdowns, including an enum
default value.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Updated the column editor layout and controls for naming,
sensitive-data settings, extra options, foreign-key editing, and column
removal, with clearer tooltips and more consistent interactions.
* Added accessible help tooltips for the Name and Default Value fields.
* Updated column-type and suggested-value controls, including clearer
guidance for choosing a suggested value.
  * Sensitive-data settings are now available in the extra-options menu.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-24 12:37:30 +02:00
Joshen Lim 0d3b73794b Joshenlim/fe 4465 experiment with best available region selection (#50851)
## Context

Adds a "Best available region" option in the region selector for the
project creation form
- Should only show up for free plan organizations (will be selected as
the default option instead of the recommended option from GET
`/available-regions`)
- "Recommended" badges will also be hidden in this scenario
- Behaviour should be status quo for non free plan organizations
<img width="500" alt="image"
src="https://github.com/user-attachments/assets/de0a183d-37c0-445d-98ca-c5aaf6353e73"
/>

## To test
Important to ensure that project creation still behaves as per usual
- [ ] Free plan: Creating a project with "best available region" select
creates the project if the recommended region from GET
`/available-regions`
- A quick way to check this is to swap to a paid org and see the
"recommended" general region
- [ ] Free plan: Can also create a project with other regions selected
as per usual
- [ ] Non free plan: Can create project as per usual
- [ ] Verify that everything is status quo if configcat feature flag is
off
2026-09-24 17:38:58 +08:00
Saxon FletcherandClaude Opus 5.5 d3f3903b69 feat(studio): show recent notebooks on the project homepage (#50825)
<img width="1758" height="1252" alt="image"
src="https://github.com/user-attachments/assets/6f5ff072-9b47-4265-924d-0ca22368f6cb"
/>


## What

With the Explorer feature preview on, the homepage **Reports** row
becomes a **Notebooks** row showing the four newest notebooks.

- Advisor and notebook cards share a new `HomeCard` layout: same height
and header, content anchored to the bottom, 3-line description clamp.
- Notebook cards show the cell count, the creation date, and an
**Analyze** button that starts the same chat as the Explorer notebook
tab (`useAnalyzeNotebook`, now shared by both).
- Advisor lint cards replace the assistant dropdown with two icon
buttons: **Ask Assistant** and **Copy prompt**. Copy prompt shows a
check after copying.
- The empty state matches the Reports one.

## How to test

1. Turn on the Explorer feature preview and open a project's Home page.
2. The Reports row should be replaced by Notebooks. With no notebooks,
you should see the empty state; **Create your first notebook** opens a
new notebook in Explorer.
3. Click a notebook card to open it. Click **Analyze** to start an
assistant chat. It should be disabled on a notebook with no cells.
4. On an advisor lint card, check **Ask Assistant** opens the assistant
with the lint prompt, and **Copy prompt** copies it and briefly shows a
check.
5. Turn the preview off: the Reports row comes back unchanged.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Project home now displays up to four notebooks, with options to create
a notebook, open it, and see its cell count.
* Start an AI analysis of a notebook directly from its card or from the
notebook explorer. Analysis is unavailable for notebooks without cells.
  * Advisor cards now offer a one-click AI chat and a copyable prompt.
* Project home shows notebooks when the Explorer preview is enabled;
otherwise, it continues to show custom reports.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 16:41:56 +08:00
Jordi Enric 881c124301 fix(studio): prevent API Gateway report tab crash (#50847)
## Problem

The API Gateway report initializes its request range with the Logs
Explorer helper, which leaves `iso_timestamp_end` empty. When an OTEL
chart returns sparse microsecond timestamps, the time series filler can
interpret them as milliseconds while deriving the end of the range and
attempt an unbounded fill, freezing or crashing the browser tab.

## Fix

Initialize the report with its date range helper so both request bounds
are present. Normalize microsecond timestamps before deriving fill
bounds, including the single point case. Add regression tests for sparse
OTEL data with both empty and explicit end dates.

## How to test

- Open Observability → API Gateway on a project with requests spanning
two hourly buckets. The page should render without a tab crash, and the
analytics requests should include a nonempty `iso_timestamp_end`.
- Run `pnpm --filter studio exec vitest run
tests/features/logs/Logs.utils.test.ts` and confirm the microsecond
timestamp cases pass.
- Run the Studio typecheck and lint checks.

The Vitest, typecheck, and lint commands could not run in this worktree
because Studio dependencies are not installed. The source diff passed
`git diff --check` and received a focused code review.
2026-09-24 10:30:25 +02:00
Joshen Lim 38fa40e851 Joshenlim/fe 4445 explorer export as pdf option 2 (#50786)
## Context

Another take on [this
PR](https://github.com/supabase/supabase/pull/50733), decided that it's
better UX + DX to use a PDF library (`@react-pdf/renderer`) instead for
handling exporting Notebooks to PDF. The previous method using `print`
involved a lot of sparse patching in various places + had a lot of
limitations, not to mention its awkward UX to "Print".

There's a lot of code changes in this PR but it's because we're
constructing the PDF document based on the notebook's contents using
primitives from `@react-pdf/renderer` which gives us a lot more control
over the PDF's output.

PDF output will differ slightly from the Notebook UI in the browser
- Added a custom header in the report which covers the notebook name +
project name, and when its exported
- Empty markdown cells are skipped
- Query cells will show both SQL content + results (either table or
chart)
- Opting to skip syntax highlighting for SQL content (Can consider
separately)
- Results will only be included in the PDF if the notebook's been run
(Aligns with Copy as Markdown CTA)
- For table results, _all_ rows will be rendered (Aligns with Copy as
Markdown CTA)

Feel free to give it a spin! 🙂 🙏 

<img width="248" height="207" alt="image"
src="https://github.com/user-attachments/assets/e38c14ba-7ee8-40ce-99b1-fa126453bf0f"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added an “Export as PDF” option for notebooks.
- PDFs include notebook details, Markdown content, SQL queries, query
results, tables, and charts.
- Query exports show errors, empty results, row counts, and applicable
row limits.
- Export progress is displayed while the PDF is generated, and failures
are reported via notifications.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 13:23:38 +08:00
Danny White d067e81a69 fix(ui): align primary colours across text, buttons, and controls (#50697)
## Problem

Primary colour serves readable text and selected controls, but those
uses need different shades. Light mode needs darker text, while dark
mode needs a deeper button fill. Fixed brand green on interactive chrome
also prevents a custom primary hue from carrying through the interface.
Some slider tracks and selected text are hard to read.

## Solution

- Keep `--primary` for accessible text and small selected indicators.
Use `--primary-solid` for button fills, which need a deeper shade in
dark mode.
- Add `--primary-bright` for focus rings, selected control chrome, chart
accents, and other interactive highlights. It follows `--primary-hue`;
`brand-*` stays fixed for Supabase identity.
- Make slider troughs clearer and text selection translucent with theme
foreground text.
- Document the split in the design-system colour guide.

| Before | After |
| --- | --- |
| <img width="980" height="244" alt="Before: light mode primary
controls"
src="https://github.com/user-attachments/assets/dfae325d-0dfe-4231-8bcd-3f89c4b9d793"
/> | <img width="982" height="204" alt="After: light mode primary
controls"
src="https://github.com/user-attachments/assets/5fdcb531-a6e3-4549-8a13-9d9a5ebe6e20"
/> |
| <img width="610" height="120" alt="Before: slider track"
src="https://github.com/user-attachments/assets/04f768e0-51e8-4d06-9b97-c52f4a34f122"
/> | <img width="622" height="126" alt="After: slider track"
src="https://github.com/user-attachments/assets/95127f4e-13dc-4f0f-b63c-cf5d70a28b42"
/> |
| <img width="652" height="512" alt="Before: dark mode controls"
src="https://github.com/user-attachments/assets/3f88de66-90cc-40ee-8cf1-b5f4eb87b09a"
/> | <img width="658" height="498" alt="After: dark mode controls"
src="https://github.com/user-attachments/assets/906bec30-6ca1-4614-9fb3-6cf5e5feec22"
/> |

## Review instructions

1. Compare light and dark mode in the [colour usage
guide](https://design-system-git-dnywh-fix-bright-brand-chrome-supabase.vercel.app/design-system/docs/color-usage#primary-and-brand-colors).
Check primary ink, primary-solid, primary-bright, and fixed brand
swatches.
2. In Studio, open the ‘new table’ sheet in [Table
Editor](https://studio-staging-git-dnywh-fix-bright-brand-chrome-supabase.vercel.app/dashboard/project/_/editor).
Tab through the new table sheet's fields and toggles. Check the focus
rings, selected controls, and the sheet's edges in both themes. You do
not need to save a table.
3. Select text in Studio in both themes, including a link or
primary-coloured label. The selection and text should remain legible.
4. Check the
[Field](https://design-system-git-dnywh-fix-bright-brand-chrome-supabase.vercel.app/design-system/docs/components/field)
Price Range slider: the unused track should remain visible in both
themes. The selected field card border should follow primary-bright.
5. Check the
[Button](https://design-system-git-dnywh-fix-bright-brand-chrome-supabase.vercel.app/design-system/docs/components/button)
and [Radio
Group](https://design-system-git-dnywh-fix-bright-brand-chrome-supabase.vercel.app/design-system/docs/components/radio-group)
previews. In dark mode, `primary` button fill should be deeper than
primary
[text](https://design-system-git-dnywh-fix-bright-brand-chrome-supabase.vercel.app/design-system/docs/color-usage#text);
selected radios should remain readable.
2026-09-24 09:56:31 +10:00
Saxon FletcherandJoshen Lim 76c4f2b739 feat(studio): add time range to project logs filter bar (#50685)
<img width="1079" height="566" alt="image"
src="https://github.com/user-attachments/assets/b6f360e9-dfcf-4717-86db-1fc9acc4ae6a"
/>


## Problem

Project logs only exposed time-range selection through the sidebar.

## Solution

Add a Time range property to the filter bar using the sidebar’s picker,
preset labels, and date formatting. Keep it synchronized with the
sidebar and timeline, including retention checks.

## Review instructions

1. Open Project Logs and select **Time range** in the filter bar. Choose
a preset and confirm the sidebar and logs update.
2. Select a custom range and confirm its label matches the sidebar’s
date formatting.
3. Change the range in the sidebar or timeline and confirm the filter
bar updates. Remove the time-range pill and confirm the range resets
without removing other filters.
4. Select a range beyond the plan’s log retention and confirm the
upgrade prompt appears.

Validation: 67 focused tests passed, Studio typecheck passed, and
changed Studio files passed lint.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] Docs authoring skills (not applicable: no docs-site topic changes)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added human-readable filter value labels while preserving the
underlying selections.
* Added dedicated log time-range filters with preset and custom ranges.
  * Added inline date-range picker support for flexible layouts.
* Added controls to show or hide filter properties based on
availability.
  * Added consistent date-range formatting and custom range support.

* **Bug Fixes**
  * Invalid or incomplete time-range filters are no longer applied.
  * Time-range filters remain separate from standard column filters.
* Clipboard interactions are limited to the popover date-picker variant.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-24 09:29:59 +10:00
Saxon FletcherandClaude Opus 5 a311279d66 feat(studio): add range and multi-row selection to DataTableInfinite (#50688)
Stack 3/4 · previous: #50687 · next: #50689

## Problem

`DataTableInfinite` could only open one row at a time. Multi-select
meant clicking a separate checkbox column, with no support for ranges or
modifier keys.

## Solution

This PR only adds shared primitives. Behavior stays the same until a
consumer passes `onSelectRow` (wired up in the next PR).

- `selectTableRow` (`rowSelection.utils.ts`): a pure reducer for plain,
Cmd/Ctrl-toggle, Shift-range, and additive-range selection over the
current display order, with a fixed anchor.
- `useTableRowSelection`: holds the selection state and resets it when
its `scope` (project/filters) changes.
- `DataTableProvider` gets an optional `onSelectRow`. When it's set,
`DataTableInfinite` rows use it and reflect `row.getIsSelected()`. Rows
also get `aria-selected`, Space activates them like Enter, and
shift-click no longer selects text.

## Review instructions

1. Read `rowSelection.utils.test.ts`: it covers the selection rules.
2. Open Unified Logs. Row clicks should behave the same as on master.

## Checklist

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added richer data-table row selection, including multi-select, range
selection, toggling, and keyboard support.
- Added visual and accessibility feedback for selected rows, including
pointer cursor and `aria-selected`.
- Preserved selections across paging and live updates while resetting
them when filters or projects change.
  - Added support for external row-selection callbacks.

- **Tests**
- Added comprehensive coverage for selection behavior and state
persistence.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-24 08:56:22 +10:00
Saxon FletcherandClaude Opus 5 71a252a445 feat(studio): show overview and raw JSON tabs for every log (#50687)
<img width="1086" height="810" alt="image"
src="https://github.com/user-attachments/assets/8a9f0c64-145e-4475-a3df-67bd815e2200"
/>

Stack 2/4 · previous: #50686 · next: #50688

## Problem

The detail panel only showed an Overview tab for log types that have an
inspection query. Every other type opened straight to Raw JSON. The
panel also had no header saying which log was open.

## Solution

- Adds `LogDetail`, which owns the inspection query, loading and error
states, and the Raw JSON view. Errors now use `AlertError`.
- Adds `LogOverview`, which maps each log type to its overview renderer.
Types without one fall back to the new `LogFields`, a generic tree of
expandable key/value rows built on `LogFieldRow`.
- `ServiceFlowPanel` now shows a header (level dot + event message)
above Overview / Raw JSON tabs for every log.
- Moves `getLogDataForMetadataVisibility` to `ServiceFlowPanel.utils.ts`
and adds `LogLevelDot`.

## Review instructions

1. Select a Realtime (or any other non-inspected) log. The Overview tab
should list its fields, with nested objects that expand.
2. Select a Postgres log. The overview should look as before, and Raw
JSON should still show the enriched log.
3. Switch between logs and confirm the tabs reset their scroll.

## Checklist

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added structured log overviews for Postgres, PostgREST, Auth, Storage,
and Edge Functions, with a Raw JSON view for log details.
- Added expandable log fields with filtering and copy actions, plus
visual indicators for log severity.
- **Bug Fixes**
  - Improved display of scalar, nested, date, and empty log values.
- **Privacy**
  - Raw log data respects metadata visibility settings.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-24 08:56:22 +10:00
Saxon FletcherandClaude Opus 5 eb738d2b84 feat(studio): open copy and filter actions from log detail rows (#50686)
<img width="1353" height="1046" alt="image"
src="https://github.com/user-attachments/assets/22c69de8-59ff-4318-9044-c222b01b6154"
/>


Stack 1/4 · next: #50687

## Problem

In the Unified Logs detail panel, each field row had a small kebab
button. Fields that couldn't be filtered fell back to a separate copy
button, so the actions weren't consistent. Filter labels also repeated
the column id ("Add as filter for method").

## Solution

- Adds `LogFieldRow`: the whole key/value row opens the actions menu on
click or Enter. Rows you can filter show filter + copy, and every other
row shows copy only.
- `DataTableSheetRowAction` always renders the dropdown now. `table` is
optional, copy is always available, labels read "Add filter", and the
menu aligns to the row.
- `DetailRow` is rebuilt on `LogFieldRow`. The section styling is
refreshed: bordered collapsibles, no zebra striping, and
`heading-default` section titles. The `topDivider` prop is removed.

## Review instructions

1. Open Unified Logs and select a Postgres or PostgREST log.
2. Click a filterable row (such as method or status). You should see
"Add filter" and "Copy …" in one menu.
3. Tab to a row that can't be filtered and press Enter. You should see a
copy-only menu.

## Checklist

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added consistent copy and filter actions to log detail rows.
* Added keyboard-accessible row actions, including “Add filter” for
filterable values.

* **UI Improvements**
* Updated log detail sections with clearer borders, headings, hover
states, spacing, and typography.
* Simplified detail row presentation and improved value wrapping and
readability.

* **Bug Fixes**
  * Improved handling of empty and filterable log values in detail rows.

* **Tests**
* Added coverage for copying values and applying filters from detail
rows.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-24 08:56:21 +10:00
Lukas Bernert d51ed9f451 Update Studio disk IO burst copy (#50809)
## Problem

Studio copy ties disk IO burst behavior to compute size thresholds and
says the IO budget "resets".
Burst eligibility isn't a single size cutoff
EBS burst credits refill continuously while disk usage runs below
baseline

Docs already use this framing (#50016)

Fixes PROD-665

## Solution

Three copy changes:

- `UnavailableChartBlock.tsx`: the burst balance chart placeholder no
longer names a size. It now describes sustained IO with no burst credit
pool
- `database-charts.ts`: the Disk IO Burst Balance tooltip describes the
EBS burst credit pool without referencing instance size
- `ResourceExhaustionWarningBanner.constants.ts`: the warning and
critical banners say the budget refills whenever disk usage runs below
baseline, instead of "resets"

## Review instructions

1. Read the diff. Copy changes only.
2. Optional: on a project with burstable disk IO, open Reports >
Database and hover the Disk IO Burst Balance chart title to see the new
tooltip.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation

* Updated disk I/O chart messaging to explain that some compute types
sustain disk throughput without a burst credit pool to track.
* Clarified that disk I/O burst budgets refill when demand is at or
below baseline, and that throughput remains at baseline until the budget
refills.
* Updated the burst-balance chart tooltip to describe how compute uses
the EBS burst credit pool.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 22:44:23 +02:00
Pamela Chia 1716d87f59 fix(studio): cap project name at 256 chars (#50804) 2026-09-24 02:34:53 +08:00
Ali Waseem ce0b778fec fix(studio): remove duplicate O T shortcut registration in schema visualizer (#50803)
The schema visualizer bound `schema-visualizer.find-table` (`O` then
`T`) twice — once via `useShortcut` and again through the `<Shortcut>`
wrapper around `FindTableSelector`, which registers the hotkey itself —
so every mount logged a conflict warning and fired both handlers.

Removed the redundant standalone hook; the wrapper renders under the
same `shortcutsEnabled` gate, so behavior is unchanged.

Fixes FE-4454

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Behavior Changes**
* The schema visualizer no longer registers the standalone keyboard
shortcut handler for Find Table. Find Table remains available from the
toolbar.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 11:30:31 -06:00
Joshen Lim 5b18f1d084 Allow setting null for connection pool size (#50726)
## Context

Allows users to "reset" the value for connection pool size in pooler
configuration under [database
settings](http://supabase.com/dashboard/project/_/database/settings)
<img width="500" alt="image"
src="https://github.com/user-attachments/assets/4eb98088-1898-423c-8ef6-655fd0573601"
/>

Refer to the [Linear
ticket](https://linear.app/supabase/issue/FE-4425/support-setting-null-for-pool-size-in-pooler-config)
for more details about why this change is needed - its a bit of an
explanation 😅 🙏

## To test
- [ ] Verify that you can save a pool size, and that the GET
`/config/pgbouncer` network request returns `default_pool_size` property
in its response
- [ ] Verify that you can save while leaving the pool size input field
empty, and that the GET `/config/pgbouncer` network request thereafter
doesn't return `default_pool_size` in its response

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Preserved the intended database connection pool setting when no
default pool size is specified, rather than automatically applying a
compute-size-based value.
  * Explicitly entered pool sizes continue to be saved unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 01:12:19 +08:00
Monica Khoury e143c94e5f fix(studio): clarify SMTP password field UX when a password is already saved (#50794)
## What
The custom SMTP password field showed a "Reveal" and "Copy" button next
to text saying "this password cannot be viewed once saved" —
contradictory, since those buttons implied there was something to reveal
or copy. In reality the backend never returns the saved password, so the
field was always blank and those buttons acted on an empty string.

## Why
Reported in FE-3765: users found it confusing whether saving other
fields would blank out their password, and the Reveal/Copy buttons
appeared broken.

## Fix
- Removed the non-functional Reveal/Copy buttons from the password
input.
- When a password is already saved, the field now shows a
`••••••••••••••••` placeholder and copy reading "Stored password is
hidden. Enter a new password to replace it." — matching the existing
`STORED_SECRET_PLACEHOLDER` pattern already used in the Replication
destination forms (BigQuery, ClickHouse, Snowflake, etc).
- No behavior change: leaving the field blank on save still preserves
the existing password (unchanged logic).

## Testing
- Manually verified in the running app.
- Added a component test (`SmtpForm.test.tsx`) covering both the
"password already saved" and "fresh setup" states.
- `tsc --noEmit`, `eslint`, and `prettier --check` all pass with no new
errors/warnings.

Fixes
[FE-3765](https://linear.app/supabase/issue/FE-3765/custom-smtp-password-field-ux-issues)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* Configured SMTP passwords are masked, with a notice that entering a
new password will replace the stored one.
* For new SMTP setups, the password field prompts for the SMTP server
password and does not show the stored-password notice.
* The SMTP password field no longer provides controls to reveal or copy
the password.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 16:40:53 +03:00
Ali Waseem f3094a29ce Remove cloud provider text from project cards (#50754)
Project cards and the project table showed the raw cloud provider
(`AWS`, `AWS_K8S`) alongside the region, which is an internal
implementation detail. Both now show the region only — matching the
table's existing "Region" column header.

Fixes FE-4441

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
  * Project cards now display the project’s region directly.
* Project tables show only the region in the region column, with “N/A”
when unavailable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 07:40:48 -06:00
Matt Rossman fd5ef806d6 feat(studio): enable Assistant tracing for High Compliance projects (#50759)
Assistant chats from High Compliance projects now flow to Braintrust
like any other project. The constraint that required suppressing them no
longer applies, see AI-1241 for the details.

`isTracingAllowed` now takes only the project region to maintain EU
exclusion. Traces also carry an `isHighComplianceProject` metadata
field, so the project's status at the time of the trace is recorded
rather than looked up later against a setting customers can toggle.

To verify, see [this sample
trace](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=afabbdcc-aa89-446e-aa52-78aaa90d44a4&v=Production&s=afabbdcc-aa89-446e-aa52-78aaa90d44a4&tvt=trace)
from a High Compliance project on staging which indicates that tracing
is now enabled for these projects and that it carries metadata showing
the high compliance status.

| High Compliance project setting | `isHighComplianceProject` metadata |
|--------|--------|
| <img width="1554" height="454" alt="CleanShot 2026-09-22 at 5 14 58
PM@2x"
src="https://github.com/user-attachments/assets/23901c6e-0d79-44e8-a6dd-43cdedba1799"
/> | <img width="1674" height="990" alt="CleanShot 2026-09-22 at 5 17 40
PM@2x"
src="https://github.com/user-attachments/assets/fb2fba55-bcc1-4136-a432-b33a5c7f9ca2"
/> |

Closes AI-1241


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Changes**
* AI project compliance information is now represented by a unified
high-compliance project status.
* AI response tracing is now determined by project region: tracing
remains disabled for EU and unknown regions, while known non-EU regions
are eligible.
* AI feedback and SQL generation now use the updated compliance and
regional handling.
* **Tests**
* Updated coverage to reflect the revised compliance and tracing
behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 09:39:01 -04:00
Gildas Garcia 1235245e6e Recovery codes: delete recovery codes when deleting the last MFA (#50731)
## Problem

The API prevents users from deleting their last MFA when they also have
recovery codes. However the UI doesn't and they may see an error instead
of being guided.

## Solution

Delete the recovery codes first.
<img width="1080" height="850" alt="image"
src="https://github.com/user-attachments/assets/67d999e7-06ff-4c0a-a2cc-11b864cb32f4"
/>

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. With an account that have only one MFA and recovery codes generated
2. Delete the MFA => You should see the dialog as in above screenshot.
Check the presence of _Your recovery codes will be deleted too_

After deletion, you shouldn't see the Recovery codes section anymore.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved multi-factor authentication management when recovery codes
are available.
- Users are warned that recovery codes will be deleted before removing
their last authentication factor.
- Removing the final authentication factor handles recovery-code
deletion first.
  - Cancelling deletion leaves the factor and recovery codes unchanged.
- Recovery-code handling applies only when enabled and relevant to
last-factor removal.
  - Recovery-code management is available in all environments.
- Delete actions are disabled while recovery-code status is loading, and
an error message appears if recovery codes fail to load.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 15:28:50 +02:00
Jordi EnricandJoshen Lim 3063679f1b feat(auth): restore key last-used timestamps FE-2462 FE-4315 (#50732)
## Problem

Studio expected aliased fields from the last-used API-key endpoint, but
the live endpoint returns OTEL attribute names. This kept legacy API-key
activity unavailable and prevented Studio from showing activity for new
JWT signing keys. Tracks FE-2462 and FE-4315.

## Fix

Normalize the endpoint response at the data boundary, keep the
`showApiKeysLastUsed` feature flag, and show activity from the past 24
hours for new JWT signing keys. Legacy HS256 signing keys remain blank
because the analytics response does not provide a stable signing-key
record ID for them. The request remains hosted-only, permission-gated,
and non-blocking, and the existing last-rotated column remains intact.

## How to test

- Make a request with a legacy anon or service-role API key, then open
Project Settings > API Keys and verify its last request appears.
- Make an Auth request signed by a new JWT signing key, then open JWT
Keys and verify the matching key shows a Last used timestamp.
- Verify a new key without activity shows No requests in the past 24
hours.
- Verify the legacy HS256 signing-key row leaves Last used blank.
- Expected result: legacy API keys and new JWT signing keys display
activity from the shared endpoint without changing self-hosted Studio.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a **Last used** column for JWT signing keys on supported
platforms.
* Displays usage timestamps, loading and error states, or when a key has
had no requests in the past 24 hours.
  * Usage tracking now includes both API keys and JWT signing keys.
* **Bug Fixes**
  * Improved handling of usage records for legacy and current keys.
* Usage details appear only on supported platforms and for users with
the required permissions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 13:46:00 +02:00
K-Dog (Kevin) cee7461a9a chore: allow PITR without small compute addon (#50699)
We no longer require Small Compute add-on to configure PITR.
2026-09-23 19:31:12 +08:00
Monica KhouryandJoshen Lim 4b365eb4ee fix: pass projectRef/orgSlug to support link in table grid error (#50724)
## Summary

Fixes
[FE-3987](https://linear.app/supabase/issue/FE-3987/contact-support-pre-fills-the-wrong-supabase-project-id):
the "Contact support" button shown in the Table Editor's inline error
banner (e.g. "Failed to retrieve rows from table") didn't pass the
current project or organization to the support form. This caused the
support form to fall back to the user's first organization/project
instead of the one actually affected — especially noticeable when the
Management API request used to resolve the org also fails.

## Test plan

  - [ ] Open a project in Studio, go to **Table Editor**, open a table.
- [ ] Trigger a failing table query — either block the `rest/v1/<table>`
request in DevTools, or apply a filter with a mismatched type (e.g. `id
= 'abc'` on an int column).
- [ ] On the inline red "Failed to retrieve rows from table" banner,
click **Contact support**.
- [ ] Confirm the support form pre-fills the **correct organization and
project** — the one the failing table actually belongs to.
- [ ] Repeat with a project belonging to an organization that is *not*
first in your org list, to confirm it's not coincidentally correct.
- [ ] Repeat while simulating a Management API failure (e.g. block
`api.supabase.com`/`*.supabase.co/platform/*`) to confirm the org still
resolves correctly via the `orgSlug` fallback instead of silently
defaulting to your first org.
- [ ] Sanity check other "Contact support" entry points (header Feedback
dropdown, Help sidebar) are unaffected — they use a separate,
already-correct code path.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved error handling when project details cannot be loaded,
preserving relevant project and organization context.
* Improved fallback behavior for identifying the correct organization
when project information is unavailable or unresolved.
* Support requests opened from error messages now include applicable
project and organization information.
* Error messages now consistently display available additional actions
alongside contact support options.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 10:02:32 +00:00
Jordi Enric d1d9620cdf feat(studio): migrate Auth and Realtime reports to OTEL (#50663)
## Problem

PR #50638 migrates API Gateway and Data API reports to OTEL, but the
shared Auth and Realtime metrics still select legacy BigQuery SQL and
the `logs.all` endpoint.

## Fix

Route all active hosted shared API reports through the existing OTEL
builders after feature flags load. Remove unused report variants and
their source-selection abstraction while preserving the legacy BigQuery
path for self-hosted Studio.

This PR is stacked on #50638.

## How to test

- Open the Auth observability report and confirm its seven shared metric
requests use `logs.all.otel` with a `/auth` request-path filter.
- Open the Realtime observability report and confirm its seven shared
metric requests use `logs.all.otel` with a `/realtime` request-path
filter.
- Open the Data API report and confirm its existing OTEL behavior
remains unchanged with a `/rest` request-path filter.
- Expected result: hosted reports wait for ConfigCat before querying,
while self-hosted Studio continues using the legacy BigQuery path.
- Run `./apps/studio/node_modules/.bin/vitest --run
apps/studio/components/interfaces/Reports/Reports.constants.otel.test.ts
--config apps/studio/vitest.config.ts`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Changes**
- Shared API reports now support filtering by Auth, Realtime, and
PostgREST traffic.
- Filters for Storage, GraphQL, Functions, and other previously
supported traffic types are no longer available.
- Report queries now consistently use edge log data, improving
consistency across request totals, routes, errors, response times, and
network traffic metrics.
- OpenTelemetry-backed reporting is now enabled consistently across
supported report types where available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 09:44:45 +02:00
Julian Domke 3ec2dfca44 fix(stripe-atlas): guard stripe-atlas page in self-hosted mode (#50780) 2026-09-23 09:44:04 +02:00
Saxon FletcherandClaude Opus 5.5 cf5f1545bd feat(studio): add notebook permissions to scoped access tokens (#50764)
## Problem

The Management API now has `/v2/projects/{ref}/notebooks`, gated by the
new `project_notebooks_read` / `project_notebooks_write` FGA
permissions. Studio pins `@supabase/shared-types` 0.1.95, which predates
them, so the scoped access token form can't grant them. Tokens created
with every permission selected still get `403 forbidden` on the notebook
endpoints.

## Solution

- Bump `@supabase/shared-types` to 0.1.96 (Studio and shared-data),
which publishes the notebook permissions.
- Add a **Notebooks** entry to the permission catalog (Project category,
next to SQL Snippets).
- Add minimum roles to `FGA_SCOPE_MINIMUM_ROLE`: read is `readonly`,
write is `developer`, matching the OpenFGA model.

The docs permission tables don't change yet. They're built from the
docs' checked-in v2 spec, which doesn't include the notebook endpoints,
so the row appears on the next spec sync.

## Review instructions

1. In the preview, go to **Account → Access Tokens** and create a scoped
token for a project. Check that **Notebooks** is listed under Project,
and set it to Read-write.
2. List notebooks with the new token:
   ```bash
curl -s -H "Authorization: Bearer $TOKEN"
"https://api.supabase.com/v2/projects/$REF/notebooks"
   ```
It should return `200` with `{ "links": ..., "data": [...] }`, not
`403`.
3. Optional: create a token with Notebooks set to None, repeat step 2,
and check it returns `403`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
  - Added project-level notebook permissions to access tokens.
- Access tokens can now grant read-only or developer-level access for
managing shared project notebooks.
- Project notebook permissions are displayed in the token creation
interface and supporting documentation.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 15:18:28 +08:00
ec574f3a51 fix(studio): pass Authorization header to assistant list_policies tool (#50756)
<!-- ccr-slack-attribution -->
_Requested by **Saxon Fletcher** · [Slack
thread](https://supabase.slack.com/archives/C051L8U2EJF/p1789995309253479?thread_ts=1789995309.253479&cid=C051L8U2EJF)_

Resolves AI-1246

## Problem

**Before:** The Assistant's `list_policies` tool fails in about 70% of
traces. It only "succeeds" when the org has AI opt-in disabled, because
then it returns the privacy stub and never makes a request. When opt-in
is enabled, it runs the pg-meta query server-side with no
`Authorization` header, so the request is unauthenticated and fails. The
Assistant then falls back to `execute_sql`.

**After:** `list_policies` sends the caller's `Authorization` header,
the same way `execute_sql` in `studio-tools.ts` already does, so it
returns the project's RLS policies.

## Solution

`getTools` already receives `authorization` but didn't pass it to
`getSchemaTools`. This PR passes it through. `list_policies` builds `{
Authorization }` from it, and `getDatabasePolicies` gets an optional
`headersInit` argument that it forwards to `executeSql`, the same
pattern `getDatabaseFunctions` uses. Existing client-side callers of
`getDatabasePolicies` don't change.

Files: `lib/ai/tools/index.ts`, `lib/ai/tools/schema-tools.ts`,
`data/database-policies/database-policies-query.ts`, plus tests in
`lib/ai/tools/schema-tools.test.ts` (new) and
`lib/ai/tools/index.test.ts`.

## Review instructions

1. Read `schema-tools.ts` and compare it with the `authHeaders` handling
in `studio-tools.ts` (`execute_sql`).
2. On the preview, use an org with AI opt-in set to at least "schema"
and ask the Assistant to list the RLS policies on `public`.
`list_policies` should return the policies without falling back to
`execute_sql`.

Local gates (all passed):
- `pnpm typecheck` in `apps/studio` (next typegen + `tsc --noEmit`)
- `npx eslint` on touched files: 0 errors. The 2 warnings are on lines
this PR doesn't change.
- `npx vitest run lib/ai/tools/schema-tools.test.ts
lib/ai/tools/index.test.ts lib/ai/tool-filter.test.ts`: 24/24 passed. I
also ran the new header test against the old `schema-tools.ts` and it
failed, as expected.
- `SORT_IMPORTS=false npx prettier --config prettier.config.mjs --check`
on touched files

Follow-up, not in this PR: `getRlsKnowledge` in `fallback-tools.ts`
(self-hosted path) also calls `getDatabasePolicies` without headers,
even though a `headers` object is already in scope there.

## AI disclosure

Claude Code (agent) wrote this PR from the Slack request. @SaxonF (Saxon
Fletcher) is the accountable human owner. A human needs to review it
before merge.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill (N/A, no docs changes)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK

---
_Generated by [Claude
Code](https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 14:38:40 +08:00
Saxon FletcherandDanny White cd77bebafd chore(ui): refresh shared button styles (#50197)
## What kind of change does this PR introduce?

UI polish / design system: refreshed button styles, related token
tweaks, and a shared floating-button plate.

Resolves DEPR-652.

## What is the current behavior?

Default, primary, and secondary buttons use older fills, borders, and
hover treatments. Primary still leans on brand scale utilities. Default
fills don’t always read as raised chrome across surfaces, and floating
copy / expand / scroll controls can let busy content show through
translucent fills. Call sites hand-roll `rounded-* bg-background`
wrappers for that.

## What is the new behavior?

Refreshes primary, default, and secondary buttons with medium-weight
labels, subtle shadows and inset edges, and smoother transitions.
Light-mode default buttons use a raised fill with an accent hover state,
primary text is brighter, and inline keyboard shortcuts inherit the
button’s colour.

Adds `FloatingPlate`: an opaque `bg-popover` shell for floating default
buttons (and small clusters). Migrates Studio, Docs-related patterns,
www, and `ui-patterns` floaters onto it so busy content no longer shows
through translucent fills. Positioning, z-index, and hover/focus reveal
stay on the plate’s `className`. Use `rounded="full"` for pills.

Also:

- Moves primary onto semantic `--primary` / `--primary-hover` (with a
light-theme override) instead of brand utility fills
- Tokenises button shadows as `--button-shadow-drop` /
`--button-shadow-raised` / `--button-shadow-default` on the Button base
- Aligns hover direction: darken on light mode, lighten on dark mode for
both default and primary
- Default fill stays opaque `bg-card` in light (occlusion) and
translucent `bg-muted` in dark (adapts to the local surface)
- Documents fills and `FloatingPlate` on the design-system Button page
(with a live example)
- Scales shared radius tokens in Studio and www; medium+ Button sizes
use a proportionally softer radius
- Fixes www nav CTA centering (`lg:inline-flex` instead of `lg:block`)
- Query detail Expand/Collapse wires `aria-expanded` / `aria-controls`

| Before | After |
| --- | --- |
| <img width="1074" height="438" alt="CleanShot 2026-09-18 at 15 52
51@2x"
src="https://github.com/user-attachments/assets/ef43da21-b053-4b7e-9ac4-ab8b428228ab"
/> | <img width="1090" height="464" alt="CleanShot 2026-09-18 at 15 50
59@2x"
src="https://github.com/user-attachments/assets/2ddc55fc-4c8d-499c-a280-f3db3d99023c"
/> |
| <img width="1082" height="446" alt="CleanShot 2026-09-18 at 15 52
35@2x"
src="https://github.com/user-attachments/assets/3dd5452d-325a-4e4a-a79d-26c6c6950a31"
/> | <img width="1078" height="446" alt="CleanShot 2026-09-18 at 15 51
13@2x"
src="https://github.com/user-attachments/assets/93666385-3e6e-42e0-9891-9cd6bb935b67"
/> |

## To test

### Design system

- [Button
page](https://design-system-git-chore-button-styles-supabase.vercel.app/design-system/docs/components/button):
default / primary in light and dark; hover should darken on light,
lighten on dark
- Same page: [Floating over
content](https://design-system-git-chore-button-styles-supabase.vercel.app/design-system/docs/components/button#floating-over-content)
/ [Floating
plate](https://design-system-git-chore-button-styles-supabase.vercel.app/design-system/docs/components/button#floating-plate)
example; Copy over SQL should stay opaque
- Spot-check hover on a code preview Copy control

### Docs

[Docs deploy
preview](https://docs-git-chore-button-styles-supabase.vercel.app/docs):

- [Docs
homepage](https://docs-git-chore-button-styles-supabase.vercel.app/docs):
top-right **Sign up** / **Dashboard** primary; menu icon beside it
(default icon button)
- Shrink below `lg` and open the hamburger drawer: bottom **Sign in**
(default) + **Start your project** (primary) medium block buttons
- Tab once for **Skip to content** (FloatingPlate)
- [MCP
guide](https://docs-git-chore-button-styles-supabase.vercel.app/docs/guides/ai-tools/mcp):
project picker
- [Apple
login](https://docs-git-chore-button-styles-supabase.vercel.app/docs/guides/auth/social-login/auth-apple):
**Generate Secret Key** button in the Apple Secret Generator
- Optional opacity check: any guide code block Copy control (e.g. at the
bottom of [Import data into
Supabase](https://docs-git-chore-button-styles-supabase.vercel.app/docs/guides/database/import-data))

### Studio

[Studio deploy
preview](https://studio-staging-git-chore-button-styles-supabase.vercel.app/):

- **Observability → Query Performance**: open a query detail →
Expand/Collapse pill + SQL Copy chip (dark: no bleed-through)
- **Observability → Query Insights**: select a query → Clear query pill
- **Table Editor → any table → Definition** → floating **Open in SQL
Editor**
- **Connect → Framework → Add files**: Copy on the code tabs
(FloatingPlate; light hover follow-up is DEPR-694)
- Tab once for **Skip to content**

### WWW

- [www deploy
preview](https://zone-www-dot-com-git-chore-button-styles-supabase.vercel.app/):
nav Sign in / Start your project vertical centering; hero medium CTAs
radius

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-23 03:43:00 +00:00
claude[bot]andClaude ea3a7743b1 feat(studio): default AI Assistant to GPT-6 Luna (AI-1245) (#50757)
<!-- ccr-slack-attribution -->
_Requested by **Saxon Fletcher** · [Slack
thread](https://supabase.slack.com/archives/C051L8U2EJF/p1790104861710199?thread_ts=1790104861.710199&cid=C051L8U2EJF)_

## Problem

**Before:** The Assistant's base model is `gpt-5.6-luna` at medium
reasoning effort.

**After:** The base model is `gpt-6-luna`, its direct successor, still
at medium effort. It costs half as much: $0.10/$0.50 per MTok against
$0.20/$1.20.

Resolves
[AI-1245](https://linear.app/supabase/issue/AI-1245/move-the-assistants-base-model-to-gpt-6-luna).

## Solution

This swaps `gpt-5.6-luna` for `gpt-6-luna` in
`apps/studio/lib/ai/model.utils.ts`: the model ID union, the
reasoning-support map, `ASSISTANT_MODELS`,
`DEFAULT_ASSISTANT_BASE_MODEL_ID`, and the OpenAI provider registry. The
old ID is removed, not kept next to the new one. A stored selection of
`gpt-5.6-luna` is no longer a known ID, so the client and `generate-v4`
both fall back to the new default. The eval cost table (AI-1242) and
eval experiments (AI-1243) are out of scope.

Source for the model ID and supported efforts (none/low/medium
default/high/xhigh/max): [OpenAI model docs: GPT-6
Luna](https://developers.openai.com/api/docs/models/gpt-6-luna).
`@ai-sdk/openai@4.0.41` types model IDs as a union plus `string & {}`,
so no SDK bump is needed.

## Review instructions

1. Check the diff in `model.utils.ts`. Say so if you'd rather keep
`gpt-5.6-luna` selectable as a fallback.
2. AI-1245 asks for the Assistant evals before shipping. Add the
`run-evals` label to run `braintrust-evals.yml` on this PR, or run `pnpm
--filter studio evals:run` locally. They have not been run yet because
they need OpenAI/Braintrust credentials.
3. Already run: studio `typecheck`, eslint + prettier on the changed
files, vitest for `lib/ai`, `pages/api/ai` and `state/ai-assistant` (264
passed), and `evals:preflight`.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] No docs topics changed

**AI disclosure:** Claude Code wrote this PR from start to finish. Saxon
Fletcher (@SaxonF) is the accountable human and must review it before
merge.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01W21zLTfzde6FFPyYGbGC6K


---
_Generated by [Claude
Code](https://claude.ai/code/session_01W21zLTfzde6FFPyYGbGC6K)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-23 10:03:27 +10:00
Danny WhiteandJoshen Lim 05a45dd1ed feat(studio): rename Replication to Pipelines (#50637)
## What kind of change does this PR introduce?

Feature and docs update.

## What is the current behavior?

The Dashboard lists Pipelines destinations under Database > Replication.
Read replicas have moved to Infrastructure, but the temporary notices
remain on the destinations page and new destination sheet.

Closes PIPE-1021.

## What is the new behavior?

The canonical Dashboard routes are Database > Pipelines, while legacy
Replication list and detail URLs permanently redirect to the equivalent
Pipelines routes. Navigation, command palette, shortcuts, pipeline
links, docs, and current marketing copy use Pipelines. Read-replica
notices and their obsolete dismissal state are removed.

| Before | After |
| --- | --- |
| <img width="1024" height="759" alt="Replication Database Agua Basket
Supabase"
src="https://github.com/user-attachments/assets/53f9f565-1ed1-43e9-a7d9-b66b2a47e948"
/> | <img width="1024" height="759" alt="2540"
src="https://github.com/user-attachments/assets/14ab2d61-d01c-483f-9d4f-0ac286dae159"
/> |

The Management API, pipeline behaviour, replication logs, and Postgres
replication terminology remain unchanged.

## To test

- Open `/project/<ref>/database/pipelines` and confirm the Database
navigation, page header, and pipeline breadcrumb say Pipelines.
- Open
`/project/<ref>/database/replication?source=bookmark#destinations` and a
legacy pipeline detail URL. Confirm each redirects to the matching
Pipelines URL while preserving parameters and fragments.
- From the Pipelines page, open Add destination. Confirm no read-replica
migration notice appears.
- Open the Pipelines guide and confirm its Dashboard steps lead to
Database > Pipelines.

## Before merge

- [ ] Get changelog entry reviewed
https://github.com/supabase/changelog/pull/262 and prepare to merge
simultaneously

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added dedicated **Database > Pipelines** pages for pipeline lists and
details.
- Added permanent redirects from legacy Replication URLs to their
corresponding Pipelines pages.
- Read replica management links now open **Settings > Infrastructure**.

- **Documentation**
- Updated Pipelines setup, monitoring, troubleshooting, and usage
guidance to reference the current dashboard locations.
  - Updated Realtime guidance to use **Database > Publications**.

- **Updates**
- Renamed dashboard navigation, breadcrumbs, commands, and keyboard
shortcuts from **Replication** to **Pipelines**.
  - Removed the “Read replicas have moved” notification.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 08:52:07 +10:00
Julian Domke f65ee588c1 feat(stripe-atlas): wire up redemption flow (#50575) 2026-09-22 17:57:40 +02:00