Commit Graph
20717 Commits
Author SHA1 Message Date
Charis d22702e907 refactor(studio): extract user project regions + emergency override hooks (#51033)
## Summary
- Extracts `useUserProjectRegions` (org + project region aggregation,
fail-open on fetch errors) and `useEmergencyIncidentOverride` (the
`ongoingIncident` flag / env var check) out of
`useStatusPageBannerVisibility`, so the upcoming incident.io status-page
banner can reuse both without duplicating the org/project fan-out logic.
- No behavior change for the legacy banner except one intentional fix:
`StatusPageBanner.utils.ts` compared the incident's affected regions
(lowercased) against the user's regions (not normalized), so a
mixed-case region on either side could silently fail to match. Both
sides now go through the same `normalizeRegion` helper.
- Part of the Linear FE-4057 stack (PR 5a of 6). Base branch is PR 4
(`charis/fe-4057-pr4-project-creation-status-admonition`), not master.

Linear: FE-4057

## Test plan
- [x] `pnpm --filter studio run typecheck`
- [x] `pnpm --filter studio run lint:ratchet`
- [x] `pnpm knip --workspace apps/studio`
- [x] `pnpm test:prettier`
- [x] `pnpm --filter studio exec vitest run` on the touched test files
and the `hooks/misc/` and `components/layouts/AppLayout/` directories
(all passing, no regressions)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved status banner targeting by matching incidents against
normalized regions across the user’s projects.
* Updated banner visibility checks to handle incomplete project or
region data, including when project information fails to load.
* Improved loading behavior so the banner can be evaluated based on
user-region data rather than waiting for separate organization and
project requests.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 17:49:06 -04:00
Charis 53b20cad5e feat(studio): project creation status admonition (#51029)
## Summary

- Adds a new project-creation-form incident warning path behind the
`incidentIoStatusPage` ConfigCat flag (default off — no visible behavior
change until the flag is enabled)
- When the flag is on, reads the new `/api/status-page` endpoint (added
earlier in this stack) instead of the legacy `/api/incident-status`
endpoint, and only fetches the legacy endpoint when the flag is off
- Extracts region-matching logic into `RegionSelector.utils.ts`
(`regionMatches`, `getItemsAffectingProjectCreation`) with unit test
coverage

See Linear FE-4057 for full context and design.

## Test plan

- [x] `pnpm --filter studio run typecheck`
- [x] `pnpm --filter studio run lint:ratchet`
- [x] `pnpm knip --workspace apps/studio`
- [x] `pnpm test:prettier`
- [x] `pnpm --filter studio exec vitest run
components/interfaces/ProjectCreation/RegionSelector.utils.test.ts`
(35/35 passing)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Project creation displays a warning and links to the status page when
an incident or maintenance event may affect the selected region.
* Status notices match exact regions and broader smart-region groupings;
global project-creation notices are also shown.
* The AI assistant can report visible, active incidents and in-progress
maintenance, including affected components and update details. When
there are no active events, it reports that status.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 17:37:01 -04:00
Pamela ChiaandJoshen Lim 4a941518e3 feat(studio): track Explorer runs and saves (#51004)
I added outcome events for Explorer query runs and successful manual
notebook saves. Existing page visits and preview toggles do not show
whether users complete queries or persist notebooks.

**Changed:**
- **Query usage:** Accepted runs from query tabs and notebook cells emit
submitted and terminal outcome events with a shared run ID. Canceled
confirmations emit no run events.
- **Notebook adoption:** Successful manual saves emit created or updated
events. Recreated notebooks count as creations. Unsaved drafts and
failed saves emit neither.
- **Event metadata:** Explorer action events use `Explorer` as their
page title.

**Note:** Assistant-generated saves are outside this PR. Custom
properties omit SQL and notebook content. Page visits still carry the
browser title, which can include a notebook name.

## To test

Tested on the staging preview:
- [x] Run valid and invalid SQL from an Explorer query tab. Each run
emits one submitted event and one matching completed or failed event
with the same run ID.
- [x] Run database and Logs notebook query cells, then add a markdown
cell. The query cells emit matching event pairs; the markdown cell emits
no query event.
- [x] Save a new notebook, then edit and save it again. The successful
saves emit created and updated events.
- [x] Cancel a guarded query. It emits no query run event.
- [ ] Recreate a notebook deleted on the server after local edits. A
successful save emits created, not updated.
- [x] Inspect an Explorer action event request. Its page title is
`Explorer`; page visits still use the browser title.
- [ ] Force a notebook save failure. It should emit no save event. This
case was not tested manually.

## Linear
- fixes GROWTH-1298


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Analytics**
* Explorer query runs are tracked for database and log queries,
including whether they complete or fail.
* Query activity is associated with its location in Explorer, such as a
query tab or notebook cell.
  * Successful notebook saves are tracked as creations or updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-29 13:54:13 -07:00
Charis 13de8189c9 feat(studio): assistant get_active_incidents on status page endpoint (#50994)
## Summary

* Adds a second branch to the assistant's `get_active_incidents` tool
(`apps/studio/lib/ai/tools/incident-tools.ts`) that reads
`/api/status-page` when the global ConfigCat flag `incidentIoStatusPage`
is on, instead of the legacy `/api/incident-status` endpoint.
* Filters on `visible`, ignores `show_banner` (only the global banner
respects it), and concatenates ongoing incidents + in-progress
maintenances (not scheduled maintenances).
* Adds `isServerFlagEnabled` to `lib/server/configcat.ts` for reading
global, non-user-targeted ConfigCat flags server-side, and threads the
flag through `getTools` from `pages/api/ai/sql/generate-v4.ts`.

This is PR 3 of 6 in the
[FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured)
stack — stacked on `charis/fe-4057-pr2-support-form`. Behind the
`incidentIoStatusPage` flag (default off), so this ships no user-visible
change on its own. See Linear
[FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured)
for full context.

## Test plan

- [X] `pnpm --filter studio run typecheck`
- [X] `pnpm --filter studio run lint:ratchet`
- [X] `pnpm knip --workspace apps/studio`
- [X] `pnpm test:prettier`
- [X] `pnpm --filter studio exec vitest run
lib/ai/tools/incident-tools.test.ts` (19/19 passing, including 7 new
tests for the status-page branch)
2026-09-29 15:28:49 -04:00
Alaister YoungandAlaister Young 995f6f65c7 [FE-4483] fix(studio): disable network bans for v3 projects (#50997)
Disables network bans for v3 (`AWS_K8S`) projects and shows a specific
unsupported notice. The shared banned-IP query waits for project details
and skips unsupported projects, covering both Database Settings and
Advisor for v3 and High Availability projects.

The hook returns the standard query result and uses `skipToken` to
prevent unsupported requests, including manual refetches. Database
Settings handles project-detail errors at the call site. Open unban
confirmations are cleared when the section becomes disabled, and
submission checks eligibility.

Addresses
[FE-4483](https://linear.app/supabase/issue/FE-4483/disable-network-bans-for-v3-aws-k8s-projects).

## To test

- Open Database Settings on a v3 project. Check that Network bans shows
the v3 notice, hides the IP list and unban controls, and makes no
network-bans retrieval request on initial load or reload, including
while Advisor is mounted.
- Check that an HA project still shows its existing notice and makes no
network-bans retrieval request on initial load or reload.
- Navigate from a supported project to a v3 or HA project and check that
no banned-IP request is sent for the unsupported project and no
banned-IP signals from the previous project appear in Advisor.
- If project details fail without cached data, check that Network bans
shows an error after retries finish and does not retrieve bans. A
successful retry should restore normal behavior.
- Open an unban confirmation on a supported project, then navigate to a
v3 or HA project. Check that the dialog closes without sending an unban
request and stays closed when returning. A newly opened confirmation
should still work.
- On a supported project, check the empty state and banned IP list.
Confirm that users with permission can unban an IP and users without
permission see a disabled button with the permissions tooltip.

Validation: 17 focused tests passed, covering automatic and manual
request suppression, project-detail error display and recovery, and
navigation between supported and unsupported projects. Changed-file
ESLint, Prettier, and full Studio typecheck (without the incremental
cache) passed. Earlier local browser checks on `9912c6c` confirmed no
retrieval requests for an HA project on AWS_K8S across reloads and
Advisor, and a successful empty state on a supported project. The local
failed-project case redirected to the organization after retries, so the
inline error remains verified by the component test only. The latest
preview, standalone v3 notice, populated bans/unban, and no-permission
tooltip still need browser verification.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Banned IP settings now show an unsupported-project notice for AWS
Kubernetes projects and hide ban lists and unban actions for AWS
Kubernetes and High Availability projects.
* Banned IP data loads only after project details are available and only
for supported projects; unsupported projects do not display cached ban
data.
  * Project-detail errors are shown separately from ban-list errors.
* Unban confirmations close when a project becomes unsupported or an
unban succeeds. Unbanning is unavailable when you lack update permission
or the project is unsupported.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-29 17:51:14 +00:00
Wen Bo Xie ed6217a169 docs: clarify how owners and admins authorize MCP clients for enterprise auth (#50832)
The enterprise-managed MCP authentication guide said an organization
owner authorizes the MCP client from the Authorized Apps page. That page
only lists and revokes apps that are already approved, so readers had no
way to follow the instruction.

Approval actually happens when an owner or admin connects the MCP client
through the standard sign-in flow and approves it for the organization
on the consent screen. Both roles can grant that approval, not only
owners.

This updates the prerequisites, the validation step, the "why use it"
summary, and the security considerations to:

- Name owners and admins as the roles that can authorize the client
- Describe the consent-screen approval as the way to authorize it
- Point to Authorized Apps as the place to review or revoke approved
clients
2026-09-29 08:56:54 -07:00
Manan GuptaandJoshen Lim 6a0518dd86 fix(studio): forward HA flag to project-creation pre-flight checks (#50902)
## Summary

- Fixes MUL-1678: toggling High Availability on in the project-creation
wizard 400'd for orgs that are HA-entitled but not enrolled in the "V3
rollout ramp" feature flag on the backend, because two pre-flight
endpoints Studio calls before project creation didn't know about HA and
hit the ramp check the real create-project call already bypasses.
- Threads `highAvailability` through
`useOrganizationAvailableRegionsQuery` (`GET
/platform/projects/available-regions`, sent as
`high_availability=true|false` on the query string) and
`useProjectCreationPostgresVersionsQuery` /
`useAvailableOrioleImageVersion` (`POST
/platform/organizations/:slug/available-versions`, sent as
`high_availability` in the body), including their query-key cache keys
so HA and non-HA responses for the same org/provider/size don't collide.
- Wires the (already form-tracked) `highAvailability` value into every
call site: `ProjectCreationForm.tsx`, `RegionSelector.tsx`, and a new
`highAvailability` prop on `PostgresVersionSelector.tsx` passed from
`InternalOnlyConfiguration.tsx`.

## Problem

The project-creation wizard's HA toggle is wired into the actual
project-create request, but two pre-flight calls Studio makes before
that (available regions, available Postgres versions) had no way to
signal HA, so the backend's ramp-flag gate rejected them for HA-entitled
orgs outside the ramp.

## Solution

Add an optional `highAvailability` field end-to-end on the Studio side:
query hook variables, cache keys, request serialization, and the
components that already track the toggle via `useWatch`.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Available regions and database versions in project creation now
reflect the selected high-availability setting.
* The Create button remains disabled while available regions are
loading.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: GuptaManan100 <guptamanan100@gmail.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-29 20:39:01 +05:30
Joshen Lim fea8b8b41d Update copy RE disk configuration changes and cooldown (#50844)
## Context

Reverts copy changes from the following PRs:
- Docs: https://github.com/supabase/supabase/pull/42184
- FE: https://github.com/supabase/supabase/pull/47646

Our platform's disk management configuration limitation still follows
the 4 hour cooldown at the moment, doesn't align with AWS's 4 changes in
24 hours rule just yet. This is just to prevent any confusion for now,
and we'll need to update the copy again once behaviour matches AWS on
our BE

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* Disk changes are now subject to an approximately four-hour cooldown
after each modification, replacing the previous limit of four changes in
a rolling 24-hour period.
* Disk management screens now show the cooldown status, remaining wait
time, and next available update time.
* Updated platform guides and troubleshooting instructions to reflect
the cooldown and explain available recovery options.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 23:08:31 +08:00
Kody Jacksonandkodster28-happy-hour 708bfa7ad1 [docs] Fix broken links to '/guides/' paths (#50870)
## Problem

There are several broken links within docs that reference `/guides/...`.
These need to be updated to `/docs/guides/` to resolve correctly.

## Solution

Updated links to resolve correctly

## Preview links

If relevant, include links to changed pages for easy review access.

TBD, waiting on build (unclear if this happens for external
contributions).

## Review instructions

1. Navigate to the pages in the live/preview.
2. Click the links that were updated.

## Checklist

Check all before review:

- [x ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated internal documentation links across API, Auth, Database,
Functions, and troubleshooting guides to use the `/docs` paths.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: kodster28-happy-hour <kody@catholicestateplanning.com>
2026-09-29 10:01:00 -05:00
Gildas Garcia 529e4a5366 Hide Postgres upgrade for v3 projects (#51024)
## Problem

v3 projects do not support postgres upgrade but the option may appear.

## Solution

Hide the Postgres upgrade for v3 projects

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Projects running on AWS Kubernetes no longer display database upgrade
alerts or read-replica warnings in service version settings. Other
upgrade eligibility and warning conditions remain unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 16:33:05 +02:00
Kody Jackson f216848bd2 chore: add kody to humans.txt (#51026)
## Problem

Adding myself (new team member) to humans.txt


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Kody Jackson to the team member list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 10:30:50 -04:00
sdenham 5b18a5d1af Add Stephen Denham to humans.txt (#51025)
## Problem

My name is not in humans.txt and I am a human at Supabase!

## Solution

Add my name to humans.txt

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. For example, `Open the live and preview links side-by-side.`
2. For example, `See the issue is fixed.`

## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* The team listing has been updated to include Stephen Denham. This
change is visible in the published team information; no other updates
are included in this release.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 10:19:02 -04:00
Katerina Skroumpelou e1debe9a69 docs: add frameworks partial to the server reference (#50514)
Adds a Frameworks partial to the `@supabase/server` reference, after
Installing. It explains how to run `@supabase/middleware` entries inside
Hono, H3, Elysia, NestJS, and TanStack Start through a copyable bridge,
and how to move off the framework adapters: the auth trap
(`withRequiredClaims` versus `withClaims`), the `userClaims` to
`jwtClaims` field remap, how each framework scopes an entry array to a
group of routes, what CORS and body access cost on NestJS, the
step-by-step procedure, and a prompt to hand to a coding agent. The
bridge code for all five frameworks lives in supabase/server#168 and is
linked, not copied. Resolves
[SDK-1599](https://linear.app/supabase/issue/SDK-1599) and
[SDK-1862](https://linear.app/supabase/issue/SDK-1862): the retired
`withSupabase({ middleware })` form is gone from the text.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added integration guidance and setup examples for Hono, H3/Nuxt,
Elysia, NestJS, and TanStack Start, including framework-specific
context, response, and route-scoping behavior.
* Documented migration options for authentication requirements, changes
to context and JWT claims, and differences in response and error
handling.
* Added a TanStack Start bridge example and migration and verification
checklists.
  * Added the frameworks guide to the API reference navigation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 15:50:58 +03:00
Joshen Lim b1b2cf3e6b Update checks for showing ipv4 callout (#51018)
## Context

Updates checks for showing IPv4 add on callouts, should only be visible
if the project's provider is AWS

Involves updating 3 files:
- `ConnectionPooling.tsx` - adds check for cloud provider + enabled
features
- `ConnectStepsSection.tsx` - adds check for cloud provider + enabled
features
- `Ipv4StatusPanel.tsx` - realised this is dead code, so deleted

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* IPv4 add-on notices in connection setup and connection pooling appear
only for AWS projects with IPv4 enabled, when the existing connection
and configuration requirements are met.
* **Removals**
* The standalone IPv4 status panel has been removed from the connection
setup flow.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 20:30:14 +08:00
Isaac Dawson 247e9d41fb Add Isaac Dawson to humans.txt (#51007)
## Problem

I'm not in humans.txt

## Solution

I should be in humans.txt

## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Isaac Dawson to the team list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 14:18:10 +02:00
Charis 5573d0dfbc fix(studio): disable network restrictions for v3 (AWS_K8S) projects (#50996)
## Summary
- Network restrictions aren't supported on v3 (AWS_K8S) projects, but
the Network Restrictions settings section previously only disabled
itself for High Availability projects, leaving a fully working (but
non-functional) UI for non-HA v3 projects.
- Adds `useIsAwsK8sCloudProvider()` to the section's disabled check,
alongside a v3-specific disabled notice mirroring the existing High
Availability disabled notice pattern.

Resolves
[FE-4482](https://linear.app/supabase/issue/FE-4482/disable-network-restrictions-for-v3-aws-k8s-projects).

## Test plan
- [x] `tsc --noEmit` passes for the changed file
- [x] `eslint` passes for the changed file
- [x] `prettier --check` passes for the changed file
- [x] Mirrors the existing, already-shipped High Availability
disabled-section pattern in the same component

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Behavior Changes**
* Network restrictions are unavailable for AWS Kubernetes and High
Availability projects, and for users without update permission. AWS
Kubernetes projects display a dedicated explanation; restriction details
and management controls are hidden.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 08:16:10 -04:00
Manan Gupta 951a22183a feat: regenerate api types from production (#51019)
## Summary

- Regenerates `packages/api-types/types/{api-v2,platform}.d.ts` from the
live production OpenAPI specs (via the new `pnpm --filter=api-types run
codegen:prod`), picking up everything that's shipped to production since
the committed types were last regenerated.
- Notably includes `high_availability` on the `available-regions` and
`available-versions` project-creation pre-flight endpoints, which
unblocks the Studio-side wiring in #50902.
- Fixes one collateral typecheck break the regen surfaces: the invoice
schema's `prepaid_credits_applied_cents` field became required, and
`InvoicesSettings.test.tsx`'s mock invoice builder didn't set it.

## Description

`api-v1.d.ts` needed no changes — it was already in sync with
production. `api-v2.d.ts` and `platform.d.ts` pick up unrelated drift
that has landed on production independently of this change (a few new
fields/endpoints), verified against `pnpm api:verify-types` passing
clean and `pnpm typecheck` passing across the whole monorepo.

This PR is intentionally separate from #50902 (the Studio-side High
Availability pre-flight fix) so that PR's diff stays focused on the
actual feature work. #50902 will be rebased once this merges.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Updated the invoice test fixture to default prepaid credits applied to
zero.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: GuptaManan100 <guptamanan100@gmail.com>
2026-09-29 17:24:16 +05:30
Charis 8b8569bd1a feat(studio): status page client data layer + support form (#50984)
## Summary

* Adds the client query layer for `/api/status-page`
(`statusPageQueryOptions` in `data/platform/status-page-query.ts`) and a
shared normalization module (`lib/status-page/status-page.utils.ts`)
that maps the endpoint response into region- and project-creation-aware
`StatusItem`s — later PRs in this stack (assistant tool,
project-creation admonition, global banner) build on this same module.
* Wires the support form's status pill and incident admonition to the
new data behind the `incidentIoStatusPage` ConfigCat flag.
`useSupportStatus` branches between the new endpoint and the existing
`useIncidentStatusQuery`/`processIncidentData` path, both mapped to the
same `SupportStatus` shape.
* `IncidentAdmonition` becomes purely presentational; the status link
now points at the `pageUrl` returned by the endpoint instead of a
hardcoded URL.

Part of
[FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured)
— see Linear for full design context.

## Test plan

- [X] `pnpm --filter studio run typecheck`
- [X] `pnpm --filter studio run lint:ratchet`
- [X] `pnpm knip --workspace apps/studio`
- [X] `pnpm test:prettier`
- [X] `pnpm --filter studio exec vitest run` (touched files) — 70 tests
passing, including a flag-on case for `SupportFormPage`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Support pages now display current incident and maintenance
information, including relevant status descriptions and links to the
status page.
* Status details can reflect items affecting a user’s region or
project-creation services. Upcoming maintenance is excluded from active
alerts.
* **Bug Fixes**
* Status labels and alerts now account for loading, errors, incidents,
and maintenance consistently across support pages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 07:53:28 -04:00
Joshen Lim 9aae037dff Joshenlim/fe 4475 fdw update sql to run proper alter statements instead of (#50988)
## Context

Currently for FDWs under integrations, editing an FDW involves tearing
it down then re-creating it - which while conveniently works has a lot
of problems like:
- Blast radius is way bigger than the edit
  - Everything is recreated, including vault secrets
- Silent drops grants/comments/ownership
- Cascades on dependent objects
- Views or functions built on top of foreign tables would get dropped
along with it

Changes in this PR hence updates `getUpdateFDWSql` to diff the current
wrapper state against the form state and generate targeted `ALTER`
statements for only what actually changed

## To test
- [ ] Verify that updating an existing wrapper still works as expected

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Wrapper changes can be saved in place, including server options,
encrypted values, foreign tables, and column definitions.
* Input fields can display placeholder text, and missing server-option
values display their defaults.

* **Improvements**
* Saving is unavailable until encrypted values are ready; a waiting
message appears while they load.
* The edit panel closes after a successful save. Confirmation text
explains that table or column changes may affect dependent
functionality.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 19:47:57 +08:00
Kacper Mentel b91870b012 Add Kacper Mentel to humans.txt (#51017)
Add Kacper Mentel to `humans.txt`.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Kacper Mentel to the team list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 13:34:52 +02:00
Joshen Lim e3fec137fe Joshenlim/fe 4466 audit logs update organization logs as well (#50935)
## Context

Follows up from [this
PR](https://github.com/supabase/supabase/pull/50799) - updates the Audit
Logs UI for organization audit logs. Just differs from Account audit
logs slightly with added "Actor" + "Target" column

Reuses the same UI components from account audit logs so quite a bit of
code clean up 🙂
<img width="1451" height="955" alt="image"
src="https://github.com/user-attachments/assets/a1002cee-917f-4d9a-b977-3fab8ecd2d13"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Organization audit logs now use a sortable table with row selection
and a resizable details panel.
* Actor details show a member’s username when available, otherwise the
actor’s email; a dash appears when neither is available.
* Logs can be filtered by users and projects, with separate messages for
no logs and no matching results.
* A refresh control and loading indicators help show audit-log updates.
* **Bug Fixes**
* Organization project lists stop loading when pagination totals are
unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 17:41:54 +08:00
Kevin Shaffer-Morrison c3bb547e24 Add Kevin Shaffer-Morrison to humans.txt (#51015)
Adding Kevin Shaffer-Morrison to humans.txt as he just joined the team!

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added Kevin Shaffer-Morrison to the public team listing. No other
documentation or public-facing declarations changed.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 10:46:13 +02:00
Joshen Lim 93a262d185 Check region selection for project creation (#51012)
## Context

Previously added telemetry for `selectedRegionOption` and
`selectedRegionOptionType`
[here](https://github.com/supabase/supabase/issues/50851) if the best
available region option is available for users

Opting to extend this telemetry (still just for Free plan orgs)
irregardless if best available region was selected and include
`initialRecommendedRegion`

Main thing to understand is what regions users are spinning projects up
in outside of the recommended option

## To test
- [ ] Verify the telemetry network request after creating projects
- [ ] Non-free plan: Telemetry request doesn't have
`initialRecommendedRegion` in the payload
- [ ] Free plan: Telemetry request has `initialRecommendedRegion` in the
payload
- Sends correctly if best available region option is available (default
behaviour for staging)
- Sends correctly if best available region option is NOT available
(override with dev tools the configcat flag)
2026-09-29 16:34:03 +08:00
Jordi Enric 8f6a6f7032 fix(studio): wait for organization before loading regions (#50572)
## Problem

The new-project page can request available regions with a paid compute
size before the selected organization plan resolves. For free
organizations, this produces a failed request followed by a successful
request without the size.

## Fix

Delay both available-regions query observers until the selected
organization resolves, while preserving size-dependent refetches. Add
request-level coverage for the initial free- and paid-plan behavior.

## How to test

- Run `pnpm --filter studio exec vitest --run
'tests/pages/new/[slug].test.tsx'`.
- Open the new-project page for a free organization and inspect the
available-regions request.
- Expected result: one initial request is sent without
`desired_instance_size`; paid organizations send one initial request
with `desired_instance_size=micro`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved project creation so available regions are loaded only after
an organization is selected.
- Ensured region availability requests use the appropriate instance size
for the organization’s plan: no size parameter for free plans and
`micro` for paid plans.
- Prevented unnecessary region-availability requests when no
organization has been selected.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 10:25:32 +02:00
Pamela Chia 177ef0cdd6 fix(www): repair broken docs links and redirect /blog/rss.xml (#51002)
## Problem

Four www pages link to docs URLs that return 404:

- `/storage`: the "Learn more" links for analytics and vector buckets
(`storage/analytics-buckets`, `storage/vector-buckets`)
- `/` (frameworks grid): the Vue quickstart (`quickstarts/vuejs`)
- `/edge-functions`: the CI/CD link (`functions/cicd-workflow`; that
page was merged into the deploy guide)
- `/partners`: the Enterprise SSO link (`auth/sso`)

Feed readers also request `/blog/rss.xml`, which renders the blog 404,
while the feed lives at `/rss.xml`. Apart from prefetch requests, it is
the most-requested 404 on www.

## Solution

- Point each link at the live page: `storage/analytics/introduction`,
`storage/vector/introduction`, `quickstarts/vue`,
`functions/deploy#cicd-deployment`, `auth/enterprise-sso`.
- Redirect `/docs/guides/functions/cicd-workflow` to the deploy guide.
This also fixes the older blog post and changelog links to it. The
redirect destination has no anchor because the `.md` redirect generator
in `next.config.mjs` appends `.md` to the destination.
- Redirect `/blog/rss.xml` to `/rss.xml`.

## To test

On the www Vercel preview:
- [x] On `/storage`, click "Learn more" under analytics buckets and
vector buckets: expect the analytics and vector introduction pages. They
navigate to `/docs/guides/storage/analytics/introduction` and
`/docs/guides/storage/vector/introduction`. The www preview doesn't
serve `/docs`, so I confirmed every new docs target returns 200 on
production.
- [x] On `/`, click Vue in the frameworks grid: expect the Vue
quickstart. The Vue tab's "Read docs for Vue" link navigates to
`/docs/guides/getting-started/quickstarts/vue`.
- [x] On `/edge-functions`, click the CI/CD link: expect the deploy
guide scrolled to CI/CD deployment. Opens "Deploy to Production" in a
new tab with `#cicd-deployment` in view.
- [x] On `/partners`, click the Enterprise SSO link: expect the
enterprise SSO guide. Opens "Enterprise Single Sign-On" in a new tab.
- [x] Request `/blog/rss.xml` and
`/docs/guides/functions/cicd-workflow`: expect 308s to `/rss.xml` and
`/docs/guides/functions/deploy`. Both return 308, and `/rss.xml` serves
the feed as XML.
- [x] `/docs/guides/functions/cicd-workflow.md` returns 308 to
`/docs/guides/functions/deploy.md`.
- [x] None of the four pages still links to an old path
(`analytics-buckets`, `vector-buckets`, `quickstarts/vuejs`,
`functions/cicd-workflow`, `auth/sso`).

## Linear
- fixes GROWTH-1297


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated quickstart and integration links for Vue, Edge Functions
CI/CD, analytics and vector storage buckets, and Enterprise SSO.
* Added permanent redirects from the old RSS feed and Functions CI/CD
guide URLs to their current locations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 21:00:13 -07:00
Pamela Chia 138b654994 fix(studio): point Usage log ingest and query links at logs-* docs (#51001)
## Problem

The org Usage page links added in #50570 point to
`/docs/guides/platform/manage-your-usage/log-ingest` and `/log-query`.
Neither page exists. The docs live at `logs-ingest` and `logs-query`, so
every click from the Usage page lands on a 404. Within a day of #50570
shipping, these two paths were the top docs 404s by unique visitors.

## Solution

- Point both Usage page links at the `logs-*` pages.
- Add permanent redirects from the singular paths, because they're
already being shared: search engines and AI assistants now send people
to them. The existing generator in `apps/www/next.config.mjs` adds the
`.md` variants.

## To test

On the Vercel previews:
- [x] Open an org's Usage page on the Studio preview and click the Log
Ingestion docs link: expect the `logs-ingest` docs page, not a 404.
Opens `supabase.com/docs/guides/platform/manage-your-usage/logs-ingest`
in a new tab ("Manage Logs Ingest usage").
- [x] Click the Log Query docs link: expect the `logs-query` docs page.
Opens `.../logs-query` in a new tab ("Manage Logs Query usage").
- [x] No docs link on the Usage page still points at the singular
`log-ingest` or `log-query` paths.
- [x] On the www preview, request
`/docs/guides/platform/manage-your-usage/log-ingest` and `/log-query`:
expect a 308 to the `logs-*` pages. Both return 308 to the matching
`logs-*` path. The www preview doesn't serve `/docs`, so I confirmed
both targets return 200 on production.
- [x] `log-ingest.md` and `log-query.md` also return 308 to the matching
`logs-*.md` paths.

## Linear
- fixes GROWTH-1296


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated the Log Ingestion and Log Query documentation links to their
current pages.
* Added permanent redirects from the previous documentation paths to the
corresponding pages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 20:52:01 -07:00
Danny White 5951fb6c47 fix(studio): polish Pipelines loading and update cues (#50963)
## Problem

Pipelines loading causes layout shifts, and the update cue is hard to
connect to its menu action.

- Resolves
[PIPE-1078](https://linear.app/supabase/issue/PIPE-1078/show-destination-rows-while-details-are-loading)
- Resolves
[DEPR-688](https://linear.app/supabase/issue/DEPR-688/widen-the-update-available-modal)
- Resolves
[DEPR-691](https://linear.app/supabase/issue/DEPR-691/clarify-the-update-available-indicator-in-pipeline-actions)

## Solution

Reserve space for the graph and list while loading, show destination
rows before their details arrive, align the detail header, and stack
version values in the update dialog. Match the primary-colour dot on the
options button and its Update available menu item. Give the status
tooltip more room.

| Before | After |
| --- | --- |
| <img width="408" height="346" alt="8294"
src="https://github.com/user-attachments/assets/9a44dfe0-5473-4809-b705-fd6077efe44b"
/> | <img width="844" height="738" alt="CleanShot 2026-09-28 at 17 10
34@2x"
src="https://github.com/user-attachments/assets/4eba3f16-6dc4-4c02-83b4-9689203859bd"
/> |


| After |
| --- |
| <img width="426" height="472" alt="CleanShot 2026-09-28 at 17 11
27@2x"
src="https://github.com/user-attachments/assets/8b3c181c-b48e-4803-a24a-fb7dce3957d4"
/> |
| _Links ambiguous dot to dropdown menu item_  |
| <img width="1942" height="262" alt="CleanShot 2026-09-28 at 17 29
18@2x"
src="https://github.com/user-attachments/assets/efc047bb-a8ea-4041-bd0d-fa2cb15f4414"
/> |
| _Better alignment with nav bar above it_ |

## Review instructions

1. Reload Database > Pipelines and check the loading layout and
destination rows.
2. Open a pipeline detail page and check its header, update dialog, and
matching update dots.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Destination rows now appear while pipeline details are loading, with
controls becoming available when the details finish loading.

* **Style**
* Loading states on the replication page now use diagram and
table-shaped placeholders.
* Updated replication page spacing, version-status tooltips, update
indicators, and the version comparison layout.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 11:42:58 +10:00
Danny White c415f502ed feat(studio): show publication partition handling (#50773)
## Problem

During pipeline creation, Studio did not show how an existing Postgres
publication handles partitioned tables. The checkbox in the
new-publication sheet also made the two possible modes harder to
compare.

Resolves
[DEPR-675](https://linear.app/supabase/issue/DEPR-675/show-and-edit-postgres-partition-handling-for-publications).

## Solution

Replace the checkbox in the new-publication sheet with a two-option
dropdown. The default remains “Use parent table identity”.

For an existing publication, append its partition-handling mode to the
Publication field description in the pipeline creation sheet. This shows
the current setting without presenting it as an editable pipeline
option. Changing an existing publication’s setting is outside this PR.

| Existing Publication Selection |
| --- |
| <img width="1260" height="224" alt="CleanShot 2026-09-28 at 12 52
10@2x"
src="https://github.com/user-attachments/assets/240d7c23-d226-40b9-8d27-a359c8ae4b75"
/> |
| _Loading_ |
| <img width="1238" height="198" alt="CleanShot 2026-09-28 at 12 52
00@2x"
src="https://github.com/user-attachments/assets/36c8b1de-eb47-4f76-890d-19d0f33a75a1"
/> |
| _One of two values_ |

| New Publication Creation |
| --- |
| <img width="832" height="660" alt="CleanShot 2026-09-28 at 12 52
33@2x"
src="https://github.com/user-attachments/assets/c1108c3a-d65b-4d20-b1a8-7e0b68fe5e87"
/> |
| _One of two values_ |
| <img width="840" height="650" alt="CleanShot 2026-09-28 at 12 52
40@2x"
src="https://github.com/user-attachments/assets/6a2c23d9-12d5-4949-91b1-3867b60ccdd5"
/> |
| _Second of two values_ |

## Review instructions

1. Open the pipeline creation sheet and choose to create a new
publication. Confirm that Postgres partition handling offers “Use parent
table identity” and “Replicate each partition separately”, with the
former selected by default.
2. Select each option in turn and confirm that the new publication is
created with the selected mode.
3. Select an existing publication and confirm that its
partition-handling mode appears in the description beneath Publication.
Switch publications and confirm that the description updates.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* The replication destination form explains whether the selected
publication uses the parent table’s identity or replicates partitions
separately. It also shows when publication details are loading or
unavailable.
* When creating a publication, choose how partitioned tables are
handled: use the parent table’s identity or replicate each partition
separately.
* **Tests**
* Added coverage for publication guidance, loading and unavailable
states, and partition-handling choices.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 11:41:21 +10:00
Dongha 2c5b0a5ca0 fix(ui): fall back to writeText when clipboard.write fails (#50777)
## Problem

Safari can expose `navigator.clipboard.write()` while rejecting it with
`NotAllowedError`.
Studio's shared clipboard helper treated that rejection as a terminal
failure, so Copy buttons showed "Unable to copy to clipboard" even
though `writeText()` worked.

Fixes #50769

## Solution

- Fall back to `navigator.clipboard.writeText()` when the rich clipboard
write fails.
- Preserve the existing success callback and error behavior.
- Add regression coverage for fallback success, total failure, and
callback exceptions.

## Verification

- `pnpm exec vitest run lib/helpers.test.ts --pool=threads`
- `pnpm test:prettier`
- `pnpm --filter ui run typecheck`
- `pnpm --filter studio run typecheck`
- `pnpm --filter studio run lint`
- `npm run build -- --filter=studio`
- Rendered browser verification with `clipboard.write()` forced to
reject; `writeText()` received the expected payload and the Copy button
showed success.

## Review instructions

1. Review the fallback logic in
`packages/ui/src/lib/utils/clipboard.ts`.
2. Review the regression tests in `apps/studio/lib/helpers.test.ts`.
3. Confirm no generated or vendored files are changed.

- [x] I have read CONTRIBUTING.md
- [x] This PR does not change documentation content.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Copying now falls back to standard clipboard copying when rich
clipboard access is unavailable or denied.
* An error message is shown only when both clipboard methods fail.
Successful rich clipboard writes do not trigger a fallback if a
follow-up action fails.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 11:13:40 +10:00
3f205627e0 feat(library): redesign the site around the block catalog (#50372)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature — the visual redesign itself.

Part 5 of 6 in a stack that splits the library redesign into reviewable
pieces. The four PRs beneath it carry the build, content and Markdown
work; what's left here is layout, navigation and styling.

## What is the current behavior?

The library is laid out like a documentation site: a sidebar tree of
framework folders, a homepage that lists links, and a guide page that
opens with prose. That shape suits reference material, but the library's
job is to help someone find a block and install it — and the sidebar is
the only way to discover one.

## What is the new behavior?

The homepage is the catalog itself — blocks grouped by what they do
(authentication, database, storage, realtime, messaging, AI,
foundations) rather than by framework, each with a preview of what it
renders, filterable by category.

Navigation moves into a site header whose Explore menu opens the same
categories, so the catalog is reachable from any page and the per-page
sidebar tree is gone.

A guide opens with what the reader came for: the block's name, the
install command, and a preview pane with tabs — the running component
and its files — before any prose. The file tree that used to sit
mid-page under "Folder structure" is one of those tabs. Every guide also
offers a copy of the agent prompt that points at its Markdown.

Getting-started pages get the same treatment: the quickstart is now a
framework-tabbed walkthrough rather than a wall of setup links.

## Additional context

`BlockOverviewTabs` renders Preview and Files here. #50369, stacked on
top of this one, adds the third "What's added" tab — it is the only part
of the redesign that depends on the new resource analyzer, which is why
it sits above this PR rather than below it.

Also removes what the redesign orphaned: the table-of-contents component
and its `remark` / `mdast-util-toc` dependencies, and the sidebar nav
and command-item configuration the new header replaced.

The block source changes are typography only — auth card titles move
from `text-2xl` to `font-medium text-lg tracking-normal` — which is what
regenerates the auth registry artifacts.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a redesigned Supabase Library catalog with categorized blocks,
framework-aware navigation, previews, file views, and installation
actions.
* Added framework-specific quickstart guides for Next.js, React, Vue,
Nuxt, React Router, and TanStack Start.
* Added copy-to-clipboard prompts, “Open in v0” actions, starter
templates, and richer visual previews.

* **Improvements**
* Updated documentation layouts, FAQ content, typography, navigation,
accessibility, and responsive behavior.
* Improved mobile navigation, framework selection, and standardized
block installation guidance.
* Refined authentication and social-login block presentation with more
consistent heading styles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-29 10:45:23 +10:00
Timothy LimandClaude Sonnet 5 80761d2521 docs(troubleshooting): Add guide for NXDOMAIN errors (#50969)
## Problem

We get several tickets related to NXDOMAIN errors

## Solution

Add guide to troubleshoot the issue, providing typical scenarios and
workarounds

## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [X] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

Used `/write-the-docs` and then manually modified several things

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added troubleshooting guidance for `NXDOMAIN` errors when connecting
to a project, covering possible causes, checks, and next steps.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-29 07:08:39 +08:00
Jeremias Menichelli 7f1df457f8 feat: Create action to upsert table for new search (#50683)
## Problem

For the new search, we will scan all files present within the
public/markdown directory, extract text nodes and upsert a new Supabase
table in a new project to do FTS type search.

## Solution

In this PR:
- A new script directory is created with files to solve all the steps
described above.
 - Unit tests added for the fundamental bits of the script.
- A new workflow file is added so the action runs after push every time
content is altered, added or removed.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

Sadly, testing this work is quite complex, but in case someone wants to:

1. Create a new Supabase project ton your personal space
1. Copy the id of the project and a secret key and add it to the new
Search V2 environment variables as shown in the example file
1. Copy the content of the newly added `setup.sql` and run it on the SQL
editor of your project.
1. Fetch this branch and on the search directory, run `search-v2:ingest`
1. Your project's table should have rows corresponding to the content
from docs


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Documentation pages are now indexed for full-text search at the page
and section level.
- Search results can show the most relevant section from each page, with
its title, heading, excerpt, and relevance score.
- Search content is automatically refreshed when published Markdown
documentation changes.
- **Tests**
- Added coverage for Markdown parsing, page structure, routing, and
search-content generation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 16:34:46 -03:00
Mert YEREKAPAN 2532fab239 feat(www): note that paid projects aren't paused for inactivity on pricing (#50986)
## Summary

Adds "Projects on paid plans aren't paused for inactivity" to the
pricing page's meta and Open Graph descriptions and to the generated
`pricing.md` intro. The existing copy is unchanged.

Ref: GROWTH-1191


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated pricing descriptions to clarify that projects on paid plans
are not paused for inactivity.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 19:33:07 +00:00
Mert YEREKAPAN 49da804baa feat(www): add database-only and agent guidance to homepage and pricing markdown (#50992)
## Problem

The markdown versions of the homepage (`/index.md`) and pricing page
(`/pricing.md`) don't say that a Supabase project can be used as a
standalone Postgres database, what that costs, or how an agent should
get set up. `llms.txt` also doesn't link to the product markdown pages.

Ref: GROWTH-1191

## Solution

Markdown only. No changes to the rendered HTML pages. All changes are
additive.

- **`/pricing.md`** (`apps/www/lib/llms.ts`): new "Database-only
projects" section covering Free and Pro costs for a single database
project and that paid-plan projects are not paused. Plan prices, the
Free database size, the Pro disk size, and the Free plan pausing note
are read from `packages/shared-data/plans.ts`, so they stay in sync.
- **`/index.md`**: short note for agents, a "Use it as just a Postgres
database" section, agent setup commands (agent skills, CLI), a
goal-to-docs table, and machine interfaces (MCP, OpenAPI, agent skills
index, llms.txt, markdown negotiation). One bullet added to Key
Differentiators.
- **`/llms.txt`**: new "Product overviews" section linking the product
markdown pages.

## Review instructions

1. Open `/index.md`, `/pricing.md`, and `/llms.txt` on the preview
deployment.
2. Check the new sections read correctly and the figures in
"Database-only projects" match the pricing page.
3. Every added link returns 200 as markdown, except
`https://mcp.supabase.com/mcp`, which requires OAuth.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added product overview links for Database, Auth, Storage, Realtime,
Edge Functions, Cron, Queues, and Vector, including a note about
Database’s Postgres compatibility.
* Expanded guidance on using Supabase as a standalone Postgres database,
optional product costs, Free-plan pausing, and database-only pricing.
* Added agent setup instructions, task-specific documentation links,
machine-readable endpoints, and a Markdown pricing link.
* Added database-only project details to generated pricing content,
including plan features, compute credits, pausing, and connection
guidance.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 19:16:14 +00:00
Alaister YoungandAlaister Young 27af9ca162 chore(www): run production builds through Turbo (#50713)
www builds currently bypass Turbo. This caches Next.js compilation and
sitemap generation while keeping content refreshes and asset uploads on
every build, including cache hits.

**Changed:**

- Refresh content before Turbo hashes its inputs, and upload assets
after Turbo saves or restores the build output.
- Include generated content, shared code, environment settings,
sitemaps, and the customer RSS feed in the cache configuration.
- Remove the redundant `vercel.json` build override and consolidate
public environment settings into `NEXT_PUBLIC_*`.

Cache reuse requires the same commit and build inputs because production
CDN URLs include the commit SHA.

**Added:**

- Build lifecycle tests covering cache restoration, input invalidation,
root/app commands, and upload ordering and failure handling.

## To test

- From `apps/www`, run `pnpm exec vitest run turbo-build.test.ts
generate-sitemap.test.ts scripts/lib/githubStars.test.ts`.
- Check the Vercel preview build runs content preparation before
`build:next`, and verify the homepage, `/sitemap.xml`, and
`/customers-rss.xml` load.
- Rebuild with identical prepared content and environment settings to
check compilation is cached. Asset uploads should still run when
enabled.

Validation: 63 tests passed, along with typecheck, ESLint for the new
test, formatting, and a full local build. The local build used public
example settings and placeholder survey configuration, with asset
uploads disabled; Vercel deployment validation is still pending.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Build & Deployment**
- Production builds now reuse cached outputs and restore generated
assets when a cache is available.
- Static assets upload after a successful build, and changes to content,
documentation, configuration, or shared components trigger a fresh
build.

- **Documentation**
- Added production build guidance covering caching, CDN uploads,
overrides, and direct-build limitations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-28 12:14:33 -07:00
Joshen Lim dd02e96a17 Use common shift click helper for audit logs (#50894)
## Context

This [PR](https://github.com/supabase/supabase/pull/50462) introduced a
shared helper to handle shift click selections for tables. Changes here
just updates the account audit logs to use that shared helper

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Audit log row selection now toggles individual rows on click and uses
the last-clicked row as the anchor for Shift-click range selection. When
no rows remain selected, the range anchor is cleared.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 01:34:47 +08:00
kemal.earth ae7b9ee245 fix(www): inner border radii for homepage cards (#50987)
## Problem

Looks like they broke when something else got updated.

## Solution

Fixes width some CSS var magic that should inherit whatever the outer
radii is.

| Before | After |
|--------|--------|
| <img width="1186" height="170" alt="Screenshot 2026-09-28 at 17 36 18"
src="https://github.com/user-attachments/assets/69ba7e37-d57e-4c86-a668-fa707cf80ccb"
/> | <img width="1182" height="180" alt="Screenshot 2026-09-28 at 17 36
26"
src="https://github.com/user-attachments/assets/de23b3fe-2b92-440d-b01f-57cd71e95971"
/> |


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Updated panel corner radii to scale at medium screen sizes, with the
inner corners kept slightly smaller than the outer corners.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 18:18:37 +01:00
Matt Rossman e3a937edb0 chore(studio): pin online scorer threads to the built-in preprocessor (#50981)
Pins the online scorers' `trace.getThread()` to the built-in `thread`
preprocessor, so we can set the Assistant project's default preprocessor
to a [custom one for
Topics](https://linear.app/supabase/issue/AI-1258/add-a-topics-preprocessor-that-caps-tool-results-in-assistant-traces)
without changing scorer input. `getThread()` otherwise [uses the project
default](https://github.com/braintrustdata/braintrust-sdk-javascript/blob/cc165a4843805b531645ddb1d27969204aab9ade/js/src/trace.ts#L807).

Ref AI-1258


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Corrected thread retrieval to use Braintrust’s thread preprocessor,
ensuring evaluation traces are processed consistently.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 12:17:14 -04:00
CharisandClaude Code b2cf3693dd feat(studio): /api/status-page endpoint backed by incident.io Widget API (#50931)
## Summary

* Adds `/api/status-page` (Next route + TanStack wrapper), backed by the
[incident.io](<http://incident.io>) Widget API, annotating each item
with `visible`, `show_banner`, and (for scheduled maintenances)
`banner_lead_days`.
* Deployment-mode visibility is driven by a new
`status_page:visibility_field_ids` custom-content key.
* Widget array parsing is fault-tolerant: a malformed item in one array
is dropped and logged rather than failing the whole response, so one bad
item can't hide a real ongoing incident.
* 429s from [incident.io](<http://incident.io>) are retried with
equal-jitter exponential backoff, respecting `Retry-After`, up to 2
retries.
* Nothing consumes this endpoint yet — it replaces no existing behavior
and changes nothing user-visible. Later PRs (this is PR 1 of a stack)
wire up consumers behind the `incidentIoStatusPage` ConfigCat flag.

Part of
[FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured)
— see Linear for full design context.

## Test plan

- [X] `pnpm --filter studio run typecheck`
- [X] `pnpm --filter studio run lint:ratchet`
- [X] `pnpm knip --workspace apps/studio`
- [X] `pnpm test:prettier`
- [X] `pnpm --filter studio exec vitest run status-page` — 44 tests
passing, including a regression test built from a real production
[incident.io](<http://incident.io>) payload that initially failed to
parse, and a compile-time type-safety regression test for the
array-parsing helper

Co-authored-by: Claude Code
[charis@supabase.io](<mailto:charis@supabase.io>)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a status page that displays ongoing incidents and maintenance,
with visibility and banner settings based on linked incident details.
* Status page data is available through a new API endpoint, with caching
for successful responses and degraded results.
* **Bug Fixes**
* Status page data can still display when some linked incident details
are unavailable; affected results are marked as degraded.
* Improved handling of invalid widget entries so they don’t prevent
valid items from being processed.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Code <charis@supabase.io>
2026-09-28 11:36:29 -04:00
Monica Khoury 1b5a806963 fix: show support contact message if Studio fails to load (FE-4460) (#50872)
## Summary
- Adds a fallback message ("Taking longer than expected?... contact
support@supabase.io") shown after 7s if Studio fails to fully load, for
the Next.js runtime — mirrors the existing TanStack-only
`ShellFallback`, which had no Next.js equivalent
- Fixes the support email in the existing TanStack `ShellFallback` (was
`support@supabase.com`, should be `support@supabase.io`)
- Extracts the shared copy (message, email, delay) into one file so both
fallbacks stay in sync

## Why
Linear FE-4460: users reported the Dashboard going completely blank with
no way to reach support when a JS chunk failed to load. The Next.js
runtime (the current default) had no fallback at all for this case.

## Test plan
- [ ] Normal page load: fallback never appears
- [ ] Simulated stuck boot (mount signal disabled): fallback appears
after 7s with correct copy/email, no layout bugs
- [ ] Same two checks on the TanStack runtime
(`STUDIO_FRAMEWORK=tanstack`)
- [ ] `pnpm --filter studio run typecheck` / `lint:ratchet` pass

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a loading fallback that appears if the app takes too long to
load, with guidance to clear browser cookies and reload.
* On self-hosted platforms, the fallback includes a support contact
link.
  * The fallback is automatically hidden once the app loads.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 18:21:34 +03:00
Anthony Lio 4a9b4b0a9e feat(docs): o11y agent setup stepper (#50962)
## Problem

on monitoring agent pages the prompt lives in a "prompt" tab next to
agent ones, while each agent tab ended with "paste the prompt" users
have to work out that the prompt is sitting in that previous tab

## Solution

this pr is a proposal to set agent setup as a two stepper `1` for the
prompt panel `2` holds the agent tabs:

- extracts prompt into a first step
- moves agent tabs within their own step
- polishes agent docs to match recent ui updates
- sets `prompt` as an anchor link within agent tabs 

| state | preview |
| -------|------|
| before | <img width="823" height="452" alt="image"
src="https://github.com/user-attachments/assets/a6a01832-ea73-48c1-b31d-25a0ef970e4e"
/> |
| after | <img width="823" height="716" alt="image"
src="https://github.com/user-attachments/assets/f5014ad0-1555-4578-b4b1-5bf2733b4d37"
/> |

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. visit
[/automate-with-agents/health](https://docs-git-docs-agent-setup-stepper-supabase.vercel.app/docs/guides/observability/automate-with-agents/health#set-up-the-agent)

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Agent setup instructions are organized into prompt-copying and
scheduling steps, with links to harness documentation.
  * Code tabs support icons and controlled selection.
  * Source code samples support adjustable footer notches.
* **Bug Fixes**
  * Step numbers now display the correct shadow.
* Links to page anchors now scroll to, focus, and highlight their
targets, while respecting reduced-motion preferences.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 17:28:11 +03:00
claude[bot]andClaude f0e0865acc chore(studio): promote zero-baseline eslint ratchet rules to error (#50977)
<!-- ccr-slack-attribution -->
_Requested by **Charis Lam** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790599888647059?thread_ts=1790599888.647059&cid=C0161K73J1J)_

## Problem

The Studio ESLint "ratchet"
(`apps/studio/scripts/ratchet-eslint-rules.ts`, baseline in
`apps/studio/.github/eslint-rule-baselines.json`, tracked rules in
`apps/studio/scripts/ratchet-rules.json`) lets certain rules stay at
`warn` severity while CI blocks the *count* of violations from
increasing. Several of those tracked rules had already reached a
baseline of 0 allowed violations, meaning there's nothing left to
ratchet — they should be enforced directly instead of tracked
indirectly.

## Solution

**Before:** `no-restricted-imports`, `jsx-a11y/aria-props`,
`jsx-a11y/aria-proptypes`, `jsx-a11y/role-supports-aria-props`,
`jsx-a11y/anchor-has-content`, `jsx-a11y/aria-role`,
`jsx-a11y/no-aria-hidden-on-focusable`, `jsx-a11y/tabindex-no-positive`,
`jsx-a11y/no-distracting-elements`, and `react-hook-form/no-use-watch`
were all tracked in the ratchet baseline with a count of 0, and (apart
from `no-restricted-imports`, see below) configured as ESLint `warn` in
`apps/studio/eslint.config.cjs`.

**After:** each of those rules is removed from
`apps/studio/.github/eslint-rule-baselines.json` (both the `rules` count
and the now-empty `ruleFiles` entry) and from
`apps/studio/scripts/ratchet-rules.json`. Their severity in
`apps/studio/eslint.config.cjs` is bumped from `warn` to `error` so
they're enforced directly by lint going forward instead of being tracked
via the ratchet. `no-restricted-imports` was a special case: a later
config block in `apps/studio/eslint.config.cjs` already overrides the
shared `warn` default with `error` (confirmed via `eslint
--print-config`), so only the ratchet bookkeeping needed removing for
that rule — no severity change was needed.

Promoting `jsx-a11y/role-supports-aria-props` to `error` surfaced one
real violation that the ratchet's non-test-file filter had been hiding:
a mock `<button>` in `LocalDropdown.test.tsx` set `aria-checked`, which
that role doesn't support. Removed the unused `aria-checked` attribute
from the mock (it wasn't asserted on by any test).

Every other rule still tracked by the ratchet (e.g.
`@typescript-eslint/no-explicit-any`, `react-hooks/exhaustive-deps`,
`no-restricted-exports`, …) has a baseline above 0 and was left
untouched.

### How verified

- `pnpm --filter studio run lint:ratchet` → `Stable: No regressions for
selected rules.`
- `pnpm --filter studio run lint` → `0 errors, 2430 warnings` (no new
errors from the severity bumps)
- `npx vitest run components/interfaces/LocalDropdown.test.tsx` → 3/3
passing after the mock fix
- `npx prettier --check` on all touched files → clean
- `npx tsc --noEmit` shows one pre-existing, unrelated error in
`packages/ui-patterns` (reproduced identically on `master` before this
change)

## Review instructions

1. Confirm `apps/studio/.github/eslint-rule-baselines.json` and
`apps/studio/scripts/ratchet-rules.json` no longer list the 10 rules
named above.
2. Confirm those same rules (except `no-restricted-imports`, already
`error`) are now `'error'` in `apps/studio/eslint.config.cjs`.
3. Run `pnpm --filter studio run lint:ratchet` and `pnpm --filter studio
run lint` locally to confirm both pass.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP

---
_Generated by [Claude
Code](https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-28 14:08:30 +00:00
Katerina Skroumpelou db63b4d6a2 docs: add usage examples partial to the server reference (#50858)
## Problem

The `@supabase/server` reference goes straight from Installing to the
generated API reference. It has no worked example. The middleware
reference has a "Usage examples" page in that spot (#50461).

## Solution

A new "Usage examples" partial sits between Installing and the generated
reference. It has three examples, taken from the server repo's
`docs/getting-started.md`:

- **Protect an endpoint with a user JWT:** `withSupabase({ auth: 'user'
})`, its CORS handling, and `ctx.supabase` vs `ctx.supabaseAdmin`.
- **Serve a public endpoint:** `auth: 'none'`, plus the `verify_jwt =
false` setting Edge Functions need.
- **Build the context yourself:** `createSupabaseContext` returning `{
data, error }`.

Files:

- `spec/reference/server/v1/partials/usage-examples.mdx` and its
`docs/ref/server/` mirror
- `usage-examples` added to `partialsOrder` in
`spec/reference/server/v1/config.json`

Every claim is checked against the source code in `supabase/server`,
`supabase/middleware`, and `supabase/cli`.

## Preview links

| Site | Preview |
| ---- | ------- |
| Docs |
[/docs/reference/server/usage-examples](https://docs-git-docs-server-usage-examples-supabase.vercel.app/docs/reference/server/usage-examples)
|

## Review instructions

1. Open the preview link.
2. Check that "Usage examples" appears in the sidebar between Installing
and the generated reference.
3. Check that the three examples render with the code on the right.

## Checklist

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added server usage examples for protecting endpoints, serving public
endpoints, and creating Supabase context manually.
* Documented runtime requirements, JWT verification settings, CORS
behavior, and the differences between caller-scoped and admin access.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 16:06:58 +03:00
supabase-supabase-autofixer[bot]andgithub-actions[bot] 3d8da2d827 [bot] Decrease ESLint ratchet baselines (#48332)
Automated weekly decrease of ESLint ratchet baselines.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-28 08:49:28 -04:00
7994191e49 feat(studio): group consecutive assistant tool calls (#50893)
<img width="913" height="572" alt="image"
src="https://github.com/user-attachments/assets/e8112085-508a-49e4-abb1-7550248e611e"
/>


## Problem

A single Assistant response often produces 10+ reasoning and lookup rows
("Reasoned", "Ran search_docs", …). They push the answer down the chat,
use raw tool names, and a fast tool call flashes past before the row
goes back to "Thinking...".

## Solution

Consecutive reasoning and lookup rows fold into one collapsible group.

- **Running:** the header shows a tool only while it executes ("Checking
policies in public..."). Between calls it reads "Thinking...", however
long that lasts. Each header label stays up for at least 1 second, so
quick calls no longer flash.
- **Finished:** the header lists what the tools did, e.g. "Searched docs
and checked policies", or "…, and 2 more".
- **Expanded (any time):** every call is listed under a vertical rule.
Rows still in progress shimmer, including several at once for parallel
calls.

## How to test

1. Run `pnpm dev:studio` and open the Assistant on a project with a few
tables.
2. Ask something that needs several lookups, e.g. "What RLS policies do
I have and what do the docs recommend for them?"
3. While it streams, check the collapsed header:
- It shows each tool while it runs, then goes back to "Thinking..."
between calls.
   - Labels don't flash. Each stays up for about a second.
- Only the shimmer marks progress, with no blinking cursor underneath.
4. Expand the group mid-stream. Rows read like "Checking policies in
public..." rather than tool names, and only rows still in progress
shimmer.
5. When it finishes, the header lists the actions ("Searched docs and
checked policies") and stops shimmering.
6. Press Stop while a group is running. The unfinished row reads
"Response interrupted" and stops spinning.
7. Reload the chat. Older groups show their collapsed summaries.




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* AI assistant tool activity is grouped into collapsible sections with
progress labels while work is underway and summaries when complete.
* Expand grouped activity to review reasoning and tool details. Active
tools and reasoning are highlighted, while completed reasoning without
text is hidden.
* Progress labels remain visible briefly during transitions, and active
responses display a shimmer effect.
* **Bug Fixes**
* The loading indicator no longer appears while the assistant is
processing a tool group.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-28 16:07:20 +08:00
Gildas GarciaandDanny White 93a032c90d Design System: Improve icon button example accessibility (#50783)
## Problem

The Icon only button example lacks some accessibility features:
- no `aria-label` for screen readers
- no tooltip for sighted users

## Solution

Add both with comments explaining the reasons

## Review instructions

See
https://design-system-imfc534k0-supabase.vercel.app/design-system/docs/components/button#only-an-icon

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified icon-only button guidance: use a tooltip for sighted users
and an accessible label for screen readers. When the tooltip repeats the
button’s label, prevent it from being announced twice.
* Added guidance to use a square button container and increase the tap
target by 8px. Updated the icon-button example to demonstrate a “View
logs” tooltip and accessible labeling.
* **New Features**
* Icon-only buttons now use a compact square layout with an expanded tap
target.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-28 09:56:54 +02:00
Danny White c856de8fda fix(studio): polish pipeline creation copy and actions (#50956)
## Problem

The current pipeline creation sheet describes destination type with two
disconnected sentences. The enablement callout repeats itself, while
three Pipelines action menus have undersized triggers.

## Solution

Use a complete destination-specific description for each release stage.
Present the Enable Pipelines callout as a note with an action title, a
short explanation, and one button. Clarify the enablement dialog copy
and align the three action-menu triggers with a consistent button width
and hit area.

| Before | After |
| --- | --- |
| <img width="1024" height="759" alt="Pipelines Database Sandals Field
Lab Supabase"
src="https://github.com/user-attachments/assets/fac744dd-2701-40ae-a65d-0801a1a86e6f"
/> | <img width="1024" height="759" alt="Pipelines Database Sandals
Field Lab Supabase"
src="https://github.com/user-attachments/assets/075bf609-5b65-40ca-8aaf-d27335d48838"
/> |
| <img width="1024" height="759" alt="18436"
src="https://github.com/user-attachments/assets/92f8c63b-f9b9-4dd6-b9b6-26ede932c172"
/> | <img width="1076" height="759" alt="93893"
src="https://github.com/user-attachments/assets/3c6f26b0-130c-4508-bf6b-d2c641805426"
/> |
| <img width="1024" height="759" alt="16935"
src="https://github.com/user-attachments/assets/63e75045-412a-4bcc-9cf9-20245ac60871"
/> | <img width="1024" height="759" alt="75021"
src="https://github.com/user-attachments/assets/09771e1e-2e89-466d-8f60-22c5bacc9956"
/> |

## Review instructions

1. Open [Database > Pipelines in the Studio
preview](https://studio-staging-git-dnywh-fixpipelines-creation-polish-supabase.vercel.app/dashboard/project/_/database/pipelines),
click **Add pipeline**, and select BigQuery or Snowflake. Confirm the
Type description reads as a complete sentence.
2. On a project where Pipelines is not enabled, open the creation sheet.
Confirm the note has no extra padding or Docs link, then click
**Enable** and check the dialog copy. The list menu's **Enable
Pipelines** action opens the same dialog.
3. Check the action-menu triggers on the Pipelines list, pipeline detail
page, and table row for consistent sizing and click targets.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **User Experience**
* Replication setup now displays a loading state while access and
organization details are checked, then shows the appropriate access
request, enablement notice, or destination form.
* Access notices use clearer, responsive messaging with a primary
“Request access” link.
* Enablement messaging now reflects whether your plan includes access,
and the success notification is shorter.
* Destination-type notices now identify the selected type and clarify
that it cannot be changed after creation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 17:34:10 +10:00
Sean GeogheganandJoshen Lim f2ff4ec0e9 fix(realtime): display banner when realtime has been suspended by admin (#50497)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

If Realtime's admin_suspended_at is set we display a banner.

## What is the current behavior?

REAL-1095

## What is the new behavior?

<img width="1160" height="442" alt="Screenshot 2026-09-17 at 12 06
30 pm"
src="https://github.com/user-attachments/assets/f5abe900-a163-48c9-ab55-945fc62df0d1"
/>


## Additional context

Depends on https://github.com/supabase/platform/pull/38476


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

- **New Features**
- Added a notice to Realtime settings when the service is suspended,
with instructions to contact support.
- **Bug Fixes**
- Improved invitation resending and role updates for roles without a
linked base role.
- **Tests**
- Added coverage to verify the suspension notice appears only when
applicable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-28 15:17:24 +08:00
c75d87d5ef Add /go/ask-supabase-select Select 2026 recap page (#50889)
## Problem

Attendees at Supabase Select 2026 need a quick, linkable page that
recaps what shipped and points them to the right next step, whether
that's a theme blog post, a solution page, or the full features
directory.

## Solution

Added `/go/ask-supabase-select` using the go-page system (`GoPageInput`
config, no bespoke React):

- **Hero**: "Build in an instant. Scale to infinity." with a "Read the
Recap" CTA
- **Our announcements**: three theme cards (Build anything, Scale
without limits, Operate with confidence), each with a blurb sourced from
the drafted Select 2026 theme blog posts and a CTA to that post
- **Explore Supabase for your team**: a 2x2 grid of solution cards (AI
Builders, Startups, Developers, Enterprise), each fully clickable to its
solutions page
- **Supabase features**: closing CTA out to `/features`

Also adds `whitespace-pre-line` support to the shared go-page
`HeroSection` component so a hero description can wrap onto a second
line when the config string includes `\n`. This is additive and doesn't
change rendering for existing `/go` pages that don't use a line break.

Note: the "Read the Build/Scale/Operate Blog" and "Read the Recap" CTAs
currently point to `/docs` as a placeholder — the real blog posts are
still in progress and will be swapped in once published.

## Review instructions

1. Run `pnpm --filter www dev` and visit
`http://localhost:3000/go/ask-supabase-select`.
2. Confirm the three announcement cards, the four solution cards
(hover/click highlight, no button chrome), and the closing features CTA
all render and link correctly.

## Checklist

- [x] I have read CONTRIBUTING.md

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added the “Ask Supabase” landing page, with product resources,
documentation links, team-solution cards, and a blog post marked as
coming soon.
* **Improvements**
* Hero descriptions now preserve line breaks for clearer text
presentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 16:53:30 +10:00
Saxon FletcherandClaude Opus 5.5 5e59b6047e chore(studio): extend Assistant response time and handle timeouts (#50892)
## Problem

- Assistant responses were capped at 120 seconds and 10 steps, which is
too short for longer reasoning or multi-step tool work.
- When the hosting platform ended a request at that limit, the
connection just dropped. The user got no explanation, and "Thinking…"
and tool rows kept spinning.
- Studio's own tools ignored the request's abort signal, so a stop,
disconnect or deadline couldn't cancel their in-flight requests.
- Aborted responses never closed their Braintrust span. Under TanStack
Start, the remote MCP client was only released on `res.on('close')`,
which the adapter never emits.

## Solution

Uses AI SDK options instead of custom stream handling:

- `maxDuration` goes to 300s and the step limit to 20. `streamText({
timeout: { totalMs } })` stops the response at 270s, leaving time to
finish the stream before the platform cutoff.
- `toUIMessageStream({ messageMetadata })` marks an aborted response
`timedOut: true`. `Chat` ignores `abort` chunks, so the client reads
this flag instead and shows a timeout alert with Retry. The flag is
saved with the message, so the alert survives a reload.
- `toUIMessageStream({ onEnd })` aborts the request whenever the stream
ends, releasing the MCP client on both runtimes. `streamText({ onAbort
})` ends the Braintrust span.
- Studio tools pass the SDK's `abortSignal` to their fetches. MCP tools
already did.
- Reasoning and server-tool rows that never finished show "Response
interrupted" instead of a spinner or "Ran X ✓".

There's no per-tool timeout. Approved SQL and migrations can
legitimately run longer, and aborting the HTTP request doesn't stop the
query in Postgres.

## Review instructions

1. Run the unit tests: `cd apps/studio && pnpm vitest run
lib/api/generate-v4.test.ts lib/ai components/ui/AIAssistantPanel`
2. To see a timeout without waiting 4.5 minutes, temporarily set
`ASSISTANT_TIMEOUT_MS` in `apps/studio/lib/ai/assistant-timeout.ts` to
`15_000` and run `pnpm dev:studio`.
3. Ask the Assistant something that needs several tool calls or long
reasoning, for example "Audit my schema for missing indexes and RLS
gaps, then write the fixes."
4. After 15 seconds, check that:
- the response stops and a "Assistant response timed out" alert appears
with Retry
- any in-progress reasoning or tool row shows "Response interrupted"
instead of spinning
   - Retry starts a new response
   - reloading the page still shows the alert on that chat
5. Stop a response with the Stop button before the deadline. It should
stop without the timeout alert.
6. With the default 270s, confirm that a normal response completes as
before.

## Checklist

Check all before review:

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* AI assistant responses can now run for up to five minutes, supporting
longer requests.
* When a response times out, the assistant displays a message suggesting
you retry or ask for a smaller change.
* Incomplete responses now show a “Response interrupted” notice, and
loading indicators stop when generation ends.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 12:44:39 +10:00