Commit Graph
38871 Commits
Author SHA1 Message Date
Miranda Limonczenko 7012ba4a55 docs(functions): regroup the secrets guide by information type (#50419)
Moves and heading levels only. No claims changed.

Studio renders a Docs button at
apps/studio/pages/project/[ref]/functions/secrets.tsx:43 pointing at
#using-the-cli, but "Using the CLI" was bold text rather than a heading, so the
anchor had no target and the button dropped the reader at the top of the page.
It and "Using the Dashboard" are now real headings, which repairs it.

Local secrets and Production secrets were h3 under "Accessing environment
variables", but neither is about accessing one. Both are now h2 siblings, and
the reference list moved to the end, so the page runs procedures first and facts
last.

Sections are ordered by what the reader is doing, not by subject: set a secret
locally, read it in code, then set it in production. "Accessing environment
variables" sat after production, which put the reading step after the shipping
step.

Local secrets held a two-item list of the loading mechanisms, which is a fact
sitting inside a procedure. It is now the section's opening sentence, where a
one-line fact can qualify the procedure without interrupting it.

Every existing heading text is unchanged, so #default-secrets, #local-secrets,
#production-secrets and #accessing-environment-variables all still resolve.

Added a value statement opener, and an outcome after the production procedure.
No intro outline: the page is short and its headings already scan.

The frontmatter title was title case. Renaming it to sentence case moves a
navigation label and a search entry, so the nav entry and the three pages that
used the old title as link text change with it. The slug is untouched.
2026-09-18 15:55:32 -07:00
Miranda Limonczenko 82e9f6fb0e docs(functions): tighten the voice in the secrets guide (#50418)
Style only. No heading moves and no claim changes.

The page carried the same caution admonition twice, word for word, and
explained the local .env loading rules twice more: once as a list of the two
mechanisms, then again as a pair of serve commands with the same prose around
them. Both copies are gone, along with the trailing line about managing
different environments that restated the --env-file bullet.

The rest is voice. First person became second, future tense became present,
and "allows you to" became a sentence with the reader as its subject. SB_REGION
and SB_EXECUTION_ID had lost words. The two NEVER shouts became bold, per the
emphasis rule.

The alt text named the topic the heading already names. It now describes the
Key and Value fields, the reveal and remove controls, and the Add another and
Save buttons, which is what a reader who can't see the screenshot needs.

Dropped the item count ahead of the local loading list, and made that list
unordered, because the two mechanisms are alternatives rather than steps.
2026-09-18 13:45:30 -07:00
Tina Ha f69195f9df docs: fix numbered list rendering in secrets-limit troubleshooting doc (#50479)
## Summary
- #50366 added a numbered "How to fix" list, but the fenced code blocks
and follow-up paragraphs between items 1/2/3 weren't indented under
their list markers, so each numbered item parses as its own single-item
list per CommonMark's list-continuation rules — the rendered doc shows
"1, 1, 1" instead of "1, 2, 3".
- Indents the code fences and paragraphs so they attach to their list
item, keeping the whole "How to fix" section as one ordered list.

No content changes — purely a list-structure/indentation fix so the doc
renders correctly.

## Test plan
- [ ] Preview the docs page and confirm "How to fix" renders as 1, 2, 3

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Updated the troubleshooting guide with clearer Markdown and TypeScript
code formatting for secret configuration and retrieval examples.
- Clarified how to set grouped credentials, handle missing secret
values, and access parsed keys individually.
- Documented behavior remains unchanged: grouped credentials count as
one secret, and missing `API_KEYS` values produce an error.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 15:20:30 -04:00
Anthony Lio 5918a69398 feat(docs): agent prompt block (#50565)
## What kind of change does this PR introduce?

docs ui polish for the prompt panel on the docs homepage and in the
quickstarts

## What is the current behavior?

agent prompt renders as one run on paragraph steps read as "1. ... 2.
... 3. ..." inline making it hard to read

## What is the new behavior?

- sets prompt bodies as markdown for easier readability
- adds long prompts collapse
- removes panel tab icons
- uses panel code block ui
- makes active tab has an underline on first paint
 
 `home`
| state | preview |
| -------|------|
| before | <img width="709" height="344" alt="image"
src="https://github.com/user-attachments/assets/ba3a0948-efff-4144-8eba-9065e1f140d9"
/> |
| after | <img width="709" height="344" alt="image"
src="https://github.com/user-attachments/assets/e63e71e9-86d2-4d9a-ac2d-925e197d69f9"
/> |

`quickstart`
| state | preview |
| -------|------|
| before | <img width="862" height="344" alt="image"
src="https://github.com/user-attachments/assets/96faf012-a9f1-4ee9-8a98-3ec6de24d2de"
/> |
| after | <img width="862" height="344" alt="image"
src="https://github.com/user-attachments/assets/7a41a259-e181-4a32-949f-de095d8bb66c"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Prompts now support Markdown formatting, inline code chips, expandable
content, and improved hover-reveal behavior.
* Code-copy controls support customizable labels and clearer
screen-reader announcements.
* Prompt tabs and panels have updated styling, spacing, and
active-content handling.

* **UI Improvements**
* Setup and agent prompts now use consistent Markdown-rendered
presentation.
  * Prompt headings now display “Agent Prompt.”
  * Home page setup code blocks use a more compact layout.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 21:54:31 +03:00
Anthony Lio 986931184c fix(docs): kotlin codeblock sticky collision (#50566)
## What kind of change does this PR introduce?

bug fix in kotlin documentation

## What is the current behavior?

on scroll within the kotlin documentation, in the installing section a
codeblock collide with the one below

## What is the new behavior?

- fixes by updating mdx markup

| state | preview |
| -------|------|
| before | <img width="862" height="344" alt="image"
src="https://github.com/user-attachments/assets/29332b51-dd88-458c-be12-c450ae6d32f1"
/> |

## Test
1. visit [kotlin
documentation](https://supabase.com/docs/reference/kotlin/installing)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Improved the layout of Ktor installation guidance by separating engine
setup instructions from the multiplatform example.
- Applied the updated structure consistently across Kotlin installation
documentation versions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 21:43:08 +03:00
shaziya 3ac4e77bd3 chore(www): update Partner Day venue address and schedule (#50587)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content update to the `/go/select-2026/partner-day` landing page.

## What is the current behavior?

The Details section lists the location as "San Francisco, CA" with a
"Venue details will be shared soon" placeholder, and the schedule only
lists doors and happy hour times.

## What is the new behavior?

- Location now shows the confirmed venue address: 580 20th St, San
Francisco, CA (placeholder line removed)
- Schedule now includes the program time: doors at 2:30 PM, program from
3:00 to 4:30 PM, happy hour from 4:30 PM

## Additional context

Verified locally on the www dev server.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the Partner Day landing page with the full venue address in
San Francisco.
* Added event timing details: doors open at 2:30 PM, with the program
running from 3:00–4:30 PM.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 10:41:36 -07:00
Prashant Sridharan 170cda1295 Changed a brand on the State of Startups page (#50583)
Replace Datapods with General Evidence and update its link to
https://www.generalevidence.com in the State of Startups 2026
participant list. Keep the list in alphabetical order.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content correction.

## What is the current behavior?

The participant list displays Datapods and links to
https://datapods.app.

## What is the new behavior?

The participant list displays General Evidence and links to
https://www.generalevidence.com.

## Additional context

Validation:

- All 149 tests passed across 11 test files.
- Prettier and git diff checks passed.
- App lint completed with zero errors and 1,173 warnings.
- Local build stopped during the docs prebuild step because GitHub
credentials were missing from the build environment.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Replaced the Datapods participant with General Evidence in the State
of Startups survey participant list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 18:11:30 +01:00
claude[bot]andClaude 3a11d78c6f Revert source-map disable from #50579 (re-enable Sentry source maps for studio) (#50581)
<!-- ccr-slack-attribution -->
_Requested by **Ali Waseem** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1789738618897549?thread_ts=1789738618.897549&cid=C0161K73J1J)_

**Before:** #50579 disabled Sentry source-map generation and upload for
`apps/studio` (`sourcemaps: { disable: true }` in
`apps/studio/next.config.ts`), as a same-day attempt to fix Vercel
Preview builds OOMing during compilation.

**After:** Sentry source maps are re-enabled for `apps/studio` by
removing that option, restoring the file to its exact pre-#50579 state
for this line.

Disabling source maps turned out not to fix the OOM issue after all —
builds still hung. The actual fix was switching Vercel to Elastic Build
Machines (an infrastructure setting, not a code change), which brought
build times down to ~4 minutes. Since source maps are valuable for
Sentry crash visibility and are no longer needed to work around the OOM,
this PR re-enables them.

Note on scope: `output: 'standalone'` in `apps/studio/next.config.ts` is
left untouched by this PR. It was removed and then re-added within
#50579 itself (net no change on merge), and it remains present (`output:
'standalone'`) on the current default branch HEAD. Any further
discussion about removing `output: 'standalone'` (raised separately in
the Slack thread) is intentionally out of scope here.

This is a minimal, surgical revert of only the sourcemaps-disable line
from #50579 — it does not touch #50578 (an unrelated Next.js/dependency
version bump) or any other change.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01UqvBiopu7KUqAkQNvEnkoJ


---
_Generated by [Claude
Code](https://claude.ai/code/session_01UqvBiopu7KUqAkQNvEnkoJ)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-18 15:59:53 +00:00
Jordi Enric 823d4d0991 build: disable sentry source maps for deployment test (#50579)
## Problem

Next.js deployments can stall after compilation while Sentry performs
post-compile source-map processing. We need a controlled deployment test
to isolate that phase.

## Fix

Disable Sentry source-map generation and upload for Studio, Docs, and
WWW without changing Sentry logging, dependencies, or other build
configuration.

## How to test

- Deploy Preview builds for Studio, Docs, and WWW.
- Confirm each build passes the post-compile phase.
- Expected result: the builds complete without running Sentry source-map
processing.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated production build configuration to use the default output mode.
  * Continued disabling source map handling in production.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 14:39:24 +00:00
Ivan Vasilov c5f0ba4034 fix(docs): redirect monitoring-and-debugging to observability (#50576)
This PR will also fix the markdown redirects. 

There's no need to list markdown redirects, `.md` is automatically added
when building the redirects in `www` `next.config.mjs`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Updated observability documentation redirects to use extension-free
URLs.
- Removed the outdated redirect from the observability access-data page.
- Updated the monitoring and debugging redirect to point to the
extension-free observability guide.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 15:29:10 +02:00
Victor Farazdagi a536a8fdd0 docs(pipelines): add Snowflake materialization examples (#50571)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Documentation update.

## What is the current behavior?

The Snowflake destination guide describes its append-only change
history, but does not include SQL examples for querying current state or
maintaining a materialized result.

## What is the new behavior?

Add a "Query and materialize current state" section with:

- A query and reusable view that select the latest event per identity
before filtering deletes.
- An incremental dynamic-table example with a configurable freshness
target.
- Guidance on stable keys, permissions, change tracking, refresh costs,
and recovery after table resets or schema changes.
- Links to official Snowflake documentation, including the
streams-and-tasks alternative.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Expanded Snowflake replication guidance for deriving current state
from append-only change history.
* Added examples for identity selection, `QUALIFY`-based filtering,
reusable views, dynamic tables, streams, and tasks.
* Documented considerations for mutable identity columns, delete
handling, change tracking permissions, refresh settings, target lag, and
DDL effects.
* Clarified that change tracking must be enabled before altering managed
objects.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 07:19:20 -06:00
Ali Waseem 45a80b5685 fix(studio): price nano compute at the micro rate in restore to new project (#50546)
Restore to new project showed $0 Additional Monthly Compute for nano
projects on paid plans, because the cost estimate hardcoded nano and
pico to $0 regardless of plan. It now prices them at the micro rate on
paid plans, matching how they're billed (and how Disk Management already
displays them).

Fixes FE-4427

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Corrected monthly pricing estimates when restoring a project with pico
or nano compute sizes on paid plans.
  - Free plans continue to show no compute charge.
- Pricing for micro and small compute sizes remains calculated using
their expected rates.

- **Tests**
- Added coverage for compute pricing across free and paid plans and
multiple instance sizes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 07:16:18 -06:00
Ali WaseemandJoshen Lim d72a29852c fix(studio): reject custom log time ranges outside the Date range (#50539)
Typing a 9-digit amount into the logs date picker's custom field built a
"Last N days" helper that subtracted past the representable `Date`
range, so `toISOString()` threw `RangeError: Invalid time value` while
rendering the helper list — crashing both Unified Logs and Logs
Explorer.

`parseCustomInput` now rejects those amounts, so oversized input behaves
like any other invalid input (empty helper list) instead of producing a
helper that throws.

Fixes FE-4426

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Logs date filters now reject excessively large day values outside the
supported date range.
  - Invalid date inputs no longer generate unusable date filter options.
- The date picker now displays guidance when an invalid custom format
produces no matching options.

- **Tests**
- Added coverage for out-of-range values and confirmed valid large date
ranges continue to work correctly.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-18 07:15:59 -06:00
Matt RossmanandJoshen Lim 4bb36b944f feat(studio): let High Compliance projects opt-in to Assistant data access (#50548)
Orgs with the HIPAA add-on had the Assistant's opt-in level forced to
`disabled` on any project marked High Compliance, regardless of what the
org picked in its AI settings. The restriction predated our AI provider
BAAs. The consequence is those users see the Assistant failing to answer
questions about their data w/ no clear path how to fix it, even though
the LLM provider supports this use case.

This PR removes these Assistant restrictions on the server and client so
those projects honor the org's chosen level. Braintrust conversation
tracing is unchanged and still blocked for these projects, see [this
test
case](https://github.com/supabase/supabase/blob/b9800ccf16/apps/studio/lib/ai/braintrust-logger.test.ts#L16-L20).
See
[comments](https://linear.app/supabase/issue/AI-1153/allow-hipaa-orgs-to-opt-in-to-assistant-data-access-for-high#comment-485a0d46)
for legal approval and conditions.

The client-side changes enable features like "Debug with AI" on SQL
query failures, “Generate/Rename with AI” for snippet titles, and
generated Assistant chat titles for these customers.

The AI opt-in copy now adds a reminder to obtain consent from data
subjects, linking the [shared responsibility
model](https://supabase.com/docs/guides/deployment/shared-responsibility-model)
based also on [this
comment](https://linear.app/supabase/issue/AI-1153/allow-hipaa-orgs-to-opt-in-to-assistant-data-access-for-high#comment-f81ee610).

<img width="400" alt="CleanShot 2026-09-17 at 5 01 02 PM@2x"
src="https://github.com/user-attachments/assets/d02123f2-3e32-4d83-9f98-7d15e59222ef"
/>

To test with a HIPAA-enabled project in staging, you can use this [Plan
Change
[Staging]](https://app.hex.tech/supabase/app/Plan-Change-Staging-032BD32jo1EaisCS85qunf/latest)
Hex to add the HIPAA add-on. Once the add-on is present, you can turn on
High Compliance from a project's settings. Also in org settings, crank
up the Assistant data opt-in level and verify the Assistant is able to
answer questions about the project's data.

My results testing with opt-in level "Schema, Logs & Database Data":

| High compliance setting | Data opt-in working |
|--------|--------|
| <img width="1302" height="422" alt="CleanShot 2026-09-17 at 5 03 36
PM@2x"
src="https://github.com/user-attachments/assets/c416371b-2eb8-49df-9c07-6d8eababb443"
/> | <img width="1566" height="1516" alt="CleanShot 2026-09-17 at 5 05
14 PM@2x"
src="https://github.com/user-attachments/assets/39624355-7f8f-46ce-9f08-a8acfb9da830"
/> |

Closes AI-1153


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## New Features

- AI-assisted query renaming, snippet title generation, debugging, and
tools now follow organization AI opt-in settings rather than project
HIPAA status.
- Debugging assistance and AI actions remain available for eligible
users without additional HIPAA-based blocking.
- AI metadata warnings consistently show standard opt-in messaging and
permission settings.
- AI settings remind users to obtain consent before entering personal
data and link to shared responsibility guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-18 08:21:50 -04:00
Jordi Enric ef527f447a chore(studio): enable Sentry build diagnostics (#50474)
## Problem

Studio Vercel builds can stall after compilation inside the Sentry
production compile hook. Sentry currently suppresses its build output,
so the deployment log does not show which operation stalls.

## Change

Enable Sentry build diagnostics for Studio platform builds on Vercel by
setting silent to false and debug to true. Source-map generation, upload
behavior, and runtime reporting remain unchanged.

## How to test

- Deploy this branch to the Studio Vercel project.
- Inspect the log after Next.js compilation completes.
- Confirm that Sentry reports its post-compile progress and exposes the
operation that stalls or fails.

The diagnostic build may still time out; this change is intended to
reveal the cause before applying a workaround.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Chores**
- Enabled additional diagnostic logging for platform builds to improve
visibility into build-time error monitoring configuration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 09:46:09 +00:00
Francesco SansalvadoreandClaude 47a532eef7 feat(studio): add copy path and copy link row actions (#50480)
| | PR | Base | Branch |
| --- | --- | --- | --- |
| 1 | #50476 | `master` | pre-existing correctness fixes |
| 2 | #50413 | `fix/storage-explorer-listing-and-scroll` |
`?path`/`?preview` deep-linking |
| 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link
test |
| 4 | **this PR** | `test/storage-deep-link-e2e` | copy path / copy link
row actions |

To read the whole change in one view:

```bash
git diff master...feat/storage-copy-row-actions -- apps/studio e2e
```

## What is the new behavior?

Both row menus now offer two actions:

- **Copy relative path** — the bucket-relative object key, i.e. what
`storage.from(bucket)` takes
- **Copy link** — the dashboard URL that reopens the item in the
explorer

**Copy path to folder** is replaced by **Copy relative path**. It
produces the same value for a folder and now works for files too, so
nothing is lost.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Storage Explorer now provides separate actions to copy a relative path
or a direct link for files and folders.
* Copied links open the relevant storage location, including folder
navigation and file preview details.
  * Success notifications appear after clipboard copying completes.

* **Tests**
* Added coverage for file and folder copy actions, generated paths and
links, URL encoding, and clipboard behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-18 11:38:38 +02:00
Joshen Lim cdbe2963fa Add DownloadResultsButton to explorer query editor (#50563)
## Context

Adds the `DownloadResultsButton` component to the footer of the
explorer's query editor - will show up in notebook + query tab

<img width="1147" height="907" alt="image"
src="https://github.com/user-attachments/assets/141278a8-1e00-424e-84ec-8ddb7cf0a96b"
/>
<img width="1152" height="913" alt="image"
src="https://github.com/user-attachments/assets/0e4a48b0-ebc3-473e-8bc0-19ab633e1904"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a results footer displaying row counts and optional row limits.
  - Added download and export actions when query results are available.
  - Standardized the results footer across query and notebook previews.
- Added keyboard shortcut hints to export options when shortcuts are
enabled.

- **Improvements**
- Export actions now support read-only result sets without changing
displayed output.
- Export menu sizing and shortcut labels adapt to the enabled shortcut
configuration.
  - Improved accessibility with a label for refreshing logs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 17:13:44 +08:00
Katerina Skroumpelou c92ed0b219 docs: add usage examples and build-your-own middleware partials (#50461)
## See the changes

*
https://docs-git-docs-middleware-usage-examples-supabase.vercel.app/docs/reference/middleware/usage-examples
*
https://docs-git-docs-middleware-usage-examples-supabase.vercel.app/docs/reference/middleware/build-your-own

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update.

## What is the current behavior?

The `@supabase/middleware` reference has two hand-written pages,
Introduction and Installing, followed directly by the generated API
reference. There is no worked example of composing middleware and no
guidance on writing one. The authoring guide lives only in the
[middleware
repo](https://github.com/supabase/middleware/blob/main/docs/authoring-guide.md).

## What is the new behavior?

Two new partials sit between Installing and the generated reference:

- **Usage examples**: two `pipeline` examples. The first composes
`withCors` and `withFeatureFlag` from `@supabase/middleware`. The second
adds `withSupabase` from `@supabase/server`: `withCors` first,
`withSupabase({ auth: 'user', cors: 'disabled' })` second, and an
environment-driven flag last. The prose explains why a CORS layer must
precede the auth gate, what `withSupabase` does for CORS on its own, and
that the entry form of `withSupabase` is alpha and needs
`@supabase/server` 1.6.0 or later.
- **Build your own middleware**: the `defineMiddleware` shape (four type
arguments, when `run` receives the config, contribute vs short-circuit,
reading `getEnv` inside the per-request function), composing a custom
entry in `pipeline`, what `pipeline` checks at compile time, and when
`satisfies FetchHandler` matters. It links to the full authoring guide
for tests, packaging, and the variants.

`partialsOrder` in `spec/reference/middleware/v1/config.json` registers
both partials. The `docs/ref/middleware/` mirrors were generated with
`pnpm codegen:references:new`.

## Additional context

- Every snippet typechecks against `@supabase/middleware` and
`@supabase/server` source on `main`. The "fails to compile" statements
were confirmed with negative typechecks (duplicate key, unmet
prerequisite, in both the `pipeline` and nested forms).
- The second example's request flow was exercised end to end with a
local JWKS: preflight `204`, missing credentials `401`, flag off `404`,
flag on `200`, and the reversed order producing a `401` with no CORS
headers.
- The generated `sections.json` lists the four partials in order:
Introduction, Installing, Usage examples, Build your own middleware. No
local render check was done.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added usage examples for composing middleware pipelines with CORS,
feature flags, authentication, and Supabase.
* Added guidance for creating custom middleware, contributing request
context, handling responses, and accessing runtime environment
variables.
* Documented middleware ordering, validation, preflight handling, and
authentication behavior.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 11:40:10 +03:00
09f36316a7 test(studio): cover storage explorer deep links end to end (#50478)
| | PR | Base | Branch |
| --- | --- | --- | --- |
| 1 | #50476 | `master` | pre-existing correctness fixes |
| 2 | #50413 | `fix/storage-explorer-listing-and-scroll` |
`?path`/`?preview` deep-linking |
| 3 | **this PR** | `feat/storage-nav-improvement` | end-to-end
deep-link test |
| 4 | #50480 | `test/storage-deep-link-e2e` | copy path / copy link row
actions |

## What is the current behavior?

The `?path` / `?preview` deep-linking added in #50413 has no end-to-end
coverage. It is exercised by unit and component tests, but nothing
verifies the real round trip through a browser and a live Storage
backend.

## What is the new behavior?

One spec that drills into a nested folder and asserts `?path`, opens a
file and asserts `?preview`, reloads to confirm the deep link restores
the same location rather than dropping back to the bucket root, then
goes Back to confirm it walks up one level.

Assertions go through `toHaveURL((url) => url.searchParams.get(...) ===
...)` rather than a regex over the whole URL, so dots and other regex
metacharacters in file names are compared literally.

## Additional context

Kept on its own branch for one reason: **this spec has never been
executed.** It was written without a local Supabase stack available to
run it against, so its first real run is here in CI
(`studio-e2e-test.yml`, `framework: [next, tanstack]` × 2 shards).
Isolating it means iterating on it cannot hold up the feature work in
#50413 below.

Expect this one to need a pass or two.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01DB6KEERERPWtLL4SY2RX4Q

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Tests**
* Improved end-to-end coverage for storage workflows, including bucket
management, file and folder operations, uploads, downloads, search, and
deep links.
* Added reliable cleanup for test-created storage data, including when
navigation, uploads, or assertions fail.
* Continued verification of storage navigation and file and folder
management behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-09-18 10:28:45 +02:00
d9cfdcd741 feat(studio): deep-link folders and files in the storage explorer (#50413)
| | PR | Base | Branch |
| --- | --- | --- | --- |
| 1 | #50476 | `master` | pre-existing correctness fixes |
| 2 | **this PR** | `fix/storage-explorer-listing-and-scroll` |
`?path`/`?preview` deep-linking |
| 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link
test |
| 4 | #50480 | `test/storage-deep-link-e2e` | copy path / copy link row
actions |

## What is the current behavior?
The file explorer doesn't keep track of folder navigation.
Files and folders paths aren't shareable

## What is the new behavior?
With this PR:
- nav state is stored via params
  - "path" to store folder path (if nested folder paths)
  - "preview" to store the selected filename
- back/forward nav history
- file url opens correct folder/file


[https://github.com/user-attachments/assets/](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[0cfb7fcc-2c6e](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[528d5c1d-a1b9](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[-](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[4f5a-950d](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[4061-9b67](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[-](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[060c8eb2027b](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[a41dd98716e0](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)

## Steps to review
- Open bucket in Storage File Explorer
- navigate between files and folders and notice url params change
- reload page, it should reopen where you left off
- hitting back/forward on the browser history should follow file/folder
navigation history

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-09-18 09:45:32 +02:00
Anthony Lio 222127b5c2 fix(ui-patterns): multi select cropped caret + extra padding (#50323)
## What kind of change does this PR introduce?

bug fix on multi select ui patterns component following up with #49986

## What is the current behavior?

- extra left padding on medium size
- cropped caret on tiny size

## What is the new behavior?

- updates multi select style padding + caret
- refactors test

`caret`
| state | preview |
| -------|------|
| before | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/14af14f6-348a-44be-b0ae-42fdb9a4f4ce"
/> |
| after | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/44dab5ae-944d-43fe-8c4e-0af44a0e1fc7"
/> |

`padding`
| state | preview |
| -------|------|
| before | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/b1ad7f66-9952-463d-aebb-01fee8748aef"
/>|
| after | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/a5891c45-67b3-4926-97c5-a2ad7027bd5c"
/> |


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Multi-select triggers now display the selected value while retaining
the placeholder when empty.
* Improved sizing, spacing, and minimum widths across multi-select
controls for more consistent layouts.
* Delete controls now provide clearer click targets and hover feedback.
* Decorative chevron icons are hidden from assistive technologies for
improved accessibility.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 10:38:27 +03:00
Joshen Lim 45381bf857 Double clicking items in explorer nav should persist their tabs (#50558)
## Context

As per PR title - this behaviour exists in the Table Editor and SQL
Editor but was just missing in the Explorer

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Double-click chats or notebooks in the Explorer to pin their tabs as
permanent.
  * Pin recent chats and notebooks directly from the Home view.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 14:51:59 +08:00
Saxon FletcherandClaude Opus 5 252f69e451 chore(studio): refine Explorer sidebar, onboarding, and notebooks (#50555)
## Summary

A round of small Explorer refinements.

**Sidebar**
- Adds a **Run SQL** row (with a `+` icon) above Notebooks in the
Explorer sidebar; opens a new query tab.

**Assistant**
- Assistant query cells now have the same **Save** dropdown as query
tabs (add to an existing notebook or create a new one). It shows only
when Explorer is enabled, and not while the query is still streaming.
- `SaveQueryDropdown` takes an optional `source`, so logs queries are
saved as log cells (keeping their time range) instead of database cells.
This also fixes saving logs queries from query tabs.
- The "Drafting notebook..." notice (and the notebook loading/status
rows) now span the full message width; `delete_notebook` parts use the
wide layout like create/update.

**Onboarding**
- Replaces the single page with a four-step walkthrough: Welcome to
Explorer (with a **Preview** badge), Run SQL, Notebooks, and Chat with
your project. Each step has an icon, heading, and short description,
with step dots and **Skip** / **Back** / **Next** buttons; the last step
ends with **Continue to Explorer**.
- Removes the "Choose how Explorer opens" choice (still available in
Account preferences) and the collapsible "Learn more" section. Skipping
or finishing still respects the saved startup preference.
- Deletes `ExplorerOnboardingLearnMore`, `ExplorerHomePreference`, and
`ExplorerHomePreview`, which were only used by onboarding.

**Notebooks**
- Query cells use the same max width as markdown cells (`48rem`, was
`72rem`).
- "Add query cell" / "Add markdown cell" are now **Add query** / **Add
markdown** everywhere; the buttons at the bottom of a notebook are
larger (34px, 18px icons).

## Test plan

- [ ] Explorer sidebar: **Run SQL** opens a new query tab
- [ ] Assistant: generate SQL, use **Save** to add it to a new and an
existing notebook; repeat with a logs query and confirm a log cell is
created
- [ ] Assistant: ask for a notebook and confirm the drafting notice is
full width
- [ ] Clear `hasCompletedOnboarding` in Explorer preferences and step
through onboarding (Next / Back / Skip); finishing or skipping respects
the startup preference set in Account preferences
- [ ] Notebook: query cells line up with markdown cell width; bottom add
buttons are larger


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added a **Run SQL** shortcut to Explorer navigation.
- Assistant query results can now be saved to notebooks, including log
queries.

- **Improvements**
- Updated Explorer onboarding with guided steps, progress navigation,
and visual previews.
  - Shortened Explorer action labels and refined control sizing.
- Reduced notebook query layout width and adjusted assistant notebook
displays.

- **Changes**
- Removed the Explorer startup preference selector and onboarding “Learn
more” section.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-18 14:38:29 +08:00
Joshen Lim 501666e504 Explorer home chat to present a Run SQL secondary action if value is detected to be a SQL query (#50560)
## Context

We previously introduced a behaviour for the explorer home tab's chat
form to run a SQL Query if the input is detected to be a SQL query.

Adjusting it to shift that behaviour into a secondary action instead

<img width="740" height="210" alt="image"
src="https://github.com/user-attachments/assets/d4b1fec1-f38c-426f-8108-b50ead1a61ca"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* SQL statements entered in Explorer can be run directly with a
dedicated “Run SQL” action.
* Assistant forms support context-specific submit icons, labels,
tooltips, and accessibility text.

* **Bug Fixes**
  * Improved SQL detection for multi-statement queries.
* Prevented mixed SQL and conversational text from being treated as
executable SQL.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 14:35:35 +08:00
Anthony Lio 85f19367ec fix(ui): button popup layout shift on click (#50468)
## What kind of change does this PR introduce?

Bug fix on ui button component

## What is the current behavior?

button scale transition is applied when a popup get displayed causing a
slight layout shift (popup position change on active state)

## What is the new behavior?

- prevents scale transition on button displaying popup

| state | preview |
| -------|------|
| before | <video
src="https://github.com/user-attachments/assets/d736f27c-0d0e-4dfa-877f-6b22a09db15e"
/> |
| before | <video
src="https://github.com/user-attachments/assets/762de503-ac54-48cb-b689-8a0f8e83cc4c"
/> |

## Test
1. visit `/project/default/explorer/query/${id}` or `
/docs/guides/ai-tools/mcp`


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Dropdown and other menu-trigger buttons no longer shrink when clicked.
  * The press-scale animation remains available for standard buttons.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 08:51:09 +03:00
Saxon FletcherandClaude Opus 5 e7c76aad99 fix(docs): redirect monitoring-and-debugging.md to observability.md (#50561)
## What

Adds an explicit redirect from
`/docs/guides/monitoring-and-debugging.md` to
`/docs/guides/observability.md`.

## Why

The catch-all `/docs/guides/monitoring-and-debugging/:match*` rule
handles the bare path and subpages, but the root `.md` URL currently
ends up at `/docs/guides/observability/.md`, which 404s:

| URL | Before |
| --- | --- |
| `/docs/guides/monitoring-and-debugging.md` | 308 →
`/docs/guides/observability/.md` (404) |
| `/docs/guides/monitoring-and-debugging` | 308 →
`/docs/guides/observability/` ✓ |
| `/docs/guides/monitoring-and-debugging/logs.md` | 308 →
`/docs/guides/observability/logs.md` ✓ |

The new rule sits before the catch-all so it matches first, mirroring
the existing `observability/access-data.md` rule.

## Testing

- [ ] On the preview, `/docs/guides/monitoring-and-debugging.md`
redirects to `/docs/guides/observability.md` and returns 200

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Added a permanent redirect from the legacy monitoring and debugging
guide URL to the observability guide.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-18 13:15:29 +08:00
edec85d1ca fix(pipelines): Make pipeline actions and status updates reliable (#50085)
## Summary

Make pipeline actions and status feedback reliable while requests are
running or fail. Let the backend coordinate table resets and restarts,
keep stopped pipelines stopped after resets or settings changes, and
refresh the UI from confirmed backend state.

## Pipeline actions and recovery

- Reset one table, all errored tables, or all tables through the
rollback endpoint without separate frontend stop/start requests. Explain
which destination data is deleted, which rows are copied again, initial
sync charges, and the skip-initial-sync setting.
- Keep pending feedback until the action and a fresh status read finish,
including across navigation and polling errors. Prevent overlapping
actions and disable start/stop controls when status is unavailable or
transitioning.
- Close the creation form once the pipeline is created. If its initial
start fails, users can retry Start on the existing pipeline without
creating a duplicate.
- Wait for confirmed shutdown before deletion; a shutdown error or
timeout leaves deletion retryable. Keep failed version updates open and
avoid reporting success.
- Clarify recovery guidance and pending labels, suppress duplicate error
toasts, and hide stale table errors during transitions.

## Status updates and shared UI

- Poll pipeline status and table metrics one second after each response,
share in-flight reads, pause dashboard polling in background tabs, and
respect rate-limit backoff. The shutdown waiter continues in the
background.
- Refresh metadata after mutations even when an older read is in flight,
while preserving shared polling requests. Refresh affected data after
failures that may follow a committed reset or settings change.
- Move pending request state into the shared, project-keyed
`DatabaseLayout` so the list, detail page, and diagram stay consistent.
The surrounding database-page changes update named imports in both
Next.js and TanStack routes.
- Simplify action, status, and form rendering; announce status changes
to assistive technology; and sort table statuses without mutating cached
data.

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-18 11:32:48 +08:00
Saxon FletcherandClaude Opus 5 b1d2efd99e feat(library): add starter app guides (#50368)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature, docs.

Part 2 of 6 in a stack that splits the library redesign into reviewable
pieces.

## What is the current behavior?

The library documents individual blocks. Nothing answers "I have no
project yet" — a reader who wants a working app has to assemble one from
block guides and figure out the scaffolding themselves.

## What is the new behavior?

Four starter guides under `/docs/starters`, each starting from an empty
directory and ending with a running app on Supabase:

- **Next.js starter** — composes the library's own password-based auth
block.
- **SaaS starter** — the community subscription-payments template, with
Stripe setup.
- **AI chat app** — the community Vercel AI SDK template.
- **Flutter starter** — the user-management example, with profiles and
avatar uploads.

They reuse the existing doc route, so the sidebar, command menu,
Markdown export and `llms.txt` pick them up with no new plumbing. The
framework selector already renders nothing for pages that declare no
framework variants, so a starter page shows none.

## Additional context

The starter pages are added here in the current site's page layout; the
last PR in the stack converts them to the new one along with every other
guide.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a Starter Apps section to the side navigation and command menu.
- Added links for Next.js, SaaS, AI Chat, and Flutter starter projects,
marked as new.

- **Documentation**
  - Added setup and deployment guides for the Next.js and SaaS starters.
- Added an AI Chat App guide covering configuration, local verification,
and deployment.
- Added a Flutter starter guide covering authentication, profiles,
avatars, deep links, and hosted setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-18 10:38:49 +10:00
Ivan Vasilov 7fd37e6150 chore: Bump shadcn (#50517)
This PR bumps `shadcn` and regenerates all blocks with the latest CLI.
The blocks have no meaningful change (only a json property reorder).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated internal development tooling used by the UI library and Vue
blocks.
* **Tests**
* Improved type consistency in registry-related test utilities,
supporting more reliable validation without changing user-facing
behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 10:38:49 +10:00
abbac3b852 refactor(library): resolve registry dependencies from one source of truth (#50367)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Refactor, bug fix.

Part 1 of 6 in a stack that splits the library redesign into reviewable
pieces. This one is the foundation the rest build on and has no visual
change.

## What is the current behavior?

Three build steps each reimplement "where does this registry file land
in the user's project": `process-registry`'s `getDefaultPath`,
`registry/utils`' `uniqBy` on `file.path`, and the Markdown exporter.
They disagree, which produces real bugs:

- A Vue block whose files come from `node_modules/@supabase/vue-blocks/`
keeps its package path, so the installer writes the package folder into
the user's project.
- `registryItemAppend` builds its `docs` string from `(item.docs,
items.flatMap(...))` — a comma expression, so the item's own docs are
discarded.
- A name collision between a block file and its client's file silently
keeps one of the two.
- Install commands guess the CLI family from substrings in the item
name, so `infinite-query-composable` — a Vue block with neither "vue"
nor "nuxtjs" in its name — gets the React CLI.
- Production Vue installs use `@supabase/<name>`, but the `@supabase`
namespace is registered with shadcn, not shadcn-vue.
- `build:registry`, `build:content`, `build:markdown` and `build:llms`
run in parallel, but the last three read `public/r`.

## What is the new behavior?

`lib/registry-resolution.ts` owns installed-path derivation, first-party
dependency naming, deduplication, and cycle detection, and every
consumer calls it. `build-registry` validates the whole registry against
shadcn's schema and resolves every item, so a broken reference fails the
build instead of shipping. `clean-registry` throws rather than logging
past a failure.

Pages declare their install `framework` explicitly instead of it being
inferred, and production Vue installs use the absolute registry URL.

The build steps are serialized behind `build:prepare`, and a new
`library-tests.yml` workflow runs the library's tests, checks the
generated registry is committed, and builds the app.

## Additional context

Regenerated registry artifacts are the mechanical result of the
resolution fix — the Vue client items and the OAuth consent items that
gained their client's docs.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added explicit React and Vue framework selection for library blocks
and installation commands.
* Improved registry resolution, dependency handling, path validation,
and Vue file normalization.
* Added support for reliable local, preview, and production registry
URLs.

* **Documentation**
* Updated Vue and Nuxt installation documentation to identify the Vue
framework explicitly.

* **Bug Fixes**
* Preserved combined documentation and validated generated registry
content more consistently.

* **Tests**
* Added coverage for installation commands, registry resolution,
dependency handling, and generated artifacts.

* **Chores**
  * Added automated pull-request checks for library tests and builds.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-09-18 10:38:48 +10:00
51b6908236 tsguide(realtime): add guide to isolate client vs server issues (#49933)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Troubleshooting docs addition.

## What is the current behavior?

This is troubleshooting documentation on how to diagnose missing
real-time messages and isolate whether it is a client-side or
server-side issue.

## What is the new behavior?

Adds a step-by-step troubleshooting guide for Realtime. This helps check
isolate connection and message delivery issues using:?

Realtime Inspector: to confirm server-side dispatch.
Browser DevTools: to confirm client-side receipt via WebSockets.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a Supabase Realtime troubleshooting guide for isolating
server-side, client-side, and network-related subscription issues.
* Covers Realtime Inspector checks for subscriptions, broadcasts, and
presence; authorization and RLS validation; client configuration;
WebSocket traffic in browser developer tools; network connection
verification; and preparing diagnostic details for Support.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: krishnasaivandavasi <241076000+krishnasaivandavasi@users.noreply.github.com>
2026-09-17 15:02:21 -06:00
Pamela Chia 64ab76262e feat(studio): exhaustion banner links to metrics (#50276) 2026-09-17 22:23:10 +02:00
AnaandAna 57197ad800 chore(www): update Select Hackathon schedule page (#50543)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Content updates to the Select Hackathon go page
(`/go/select-2026/hackathon-2026-schedule`)

## What is the current behavior?

The page shows placeholder wifi/help-desk details and an earlier
schedule.

## What is the new behavior?

- Section heading `RUN OF SHOW` renamed to `SCHEDULE`
- Demos moved from 6:15 PM to 6:30 PM
- Wifi network set to `Y Combinator`, password set to `makesomething`
- Help desk location set to `booth and mentors`

## Additional context

N/A

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Updated the Hackathon 2026 day-of schedule with revised demo timing.
  * Added Wi-Fi access details for attendees.
  * Updated the help desk location information.
  * Renamed the schedule section header for clarity.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Ana <ana1337x@users.noreply.github.com>
2026-09-17 15:18:43 -04:00
ŁUKASZ KORBASIEWICZ 804e7cda5c docs: add pg_net schema troubleshooting (#50390)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

It adds a new troubleshooting section to the `pg_net` extension
documentation.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Added troubleshooting guidance for resolving a Security Advisor
warning when `pg_net` is installed in the `public` schema.
- Documented that `pg_net` must be dropped and recreated in the
`extensions` schema.
- Added a warning that this process deletes queued requests and stored
responses, including requests that have not yet been sent.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 21:10:44 +02:00
Roman Fernando Cuellar b9800ccf16 Add Roman Cuellar to the list of contributors (#50416)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds new employee as part of onboarding

## What is the current behavior?

N/A

## What is the new behavior?

N/A

## Additional context

N/A


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Román Cuellar to the team member listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 11:36:26 -06:00
Pamela Chia 66d4b4c19b chore(studio): remove expired tos update banner (#50533) 2026-09-18 00:52:40 +08:00
Francesco SansalvadoreandClaude Opus 5 c8a9a7a630 fix(studio): correct storage explorer listing pagination and column scroll (#50476)
| | PR | Base | Branch |
| --- | --- | --- | --- |
| 1 | **this PR** | `master` | pre-existing correctness fixes |
| 2 | #50413 | `fix/storage-explorer-listing-and-scroll` |
`?path`/`?preview` deep-linking + copy row actions |
| 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link
test |
| 4 | #50480 | `test/storage-deep-link-e2e` | copy path / copy link row
actions |

To read the whole change in one view:

```bash
git diff master...test/storage-deep-link-e2e -- apps/studio e2e
```

## What is the current behavior?

Four independent bugs in the storage explorer, all pre-existing on
`master`:

- `hasMoreItems` is derived from the *formatted* listing, but
`formatFolderItems` drops the `.emptyFolderPlaceholder` — so a full page
can format to `LIMIT - 1` and stop pagination a page early.
- A failed listing is indistinguishable from an empty folder, so a fetch
error reads as "this folder has nothing in it".
- `fetchFoldersByPath` commits its result against whichever bucket is
selected when the requests resolve. Switching buckets mid-flight files
the old bucket's items under the new bucket's name — and because
`columns[0].name` then matches, nothing downstream notices and
refetches.
- The horizontal auto-scroll never runs its guard (`if
(fileExplorerRef)` is always truthy), scrolls relatively so repeated
runs drift, and depends on the `columns` array identity — so a
background refetch yanks the view back to the right. It also scrolls in
list view, where there is nothing to scroll.

## What is the new behavior?

Each of the above is fixed at its source. Pagination and the
exhaustiveness check now compare the raw page length; listings carry an
`isComplete` flag; `fetchFoldersByPath` captures the bucket id at entry
and discards a stale result; the scroll is absolute, guarded, keyed on
`columns.length`, and skipped in list view.

Two new test files cover the parts that were silently wrong before:
`state/storage-explorer.test.ts` (MSW, the bucket race) and
`FileExplorer.test.tsx` (scroll geometry, with the container's layout
defined by hand since jsdom reports everything as zero-sized). Both were
checked by reverting the fix and confirming they fail.

## Additional context

`fetchFoldersByPath` also starts returning `{ missingPaths }` here.
Nothing reads it yet — the first consumer is in PR 2 — but it shares a
hunk with the `isComplete` work, so separating it would mean two PRs
editing the same lines. It is backward-compatible: all three existing
call sites ignore the return value.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Bug Fixes

- Improved Storage Explorer column-view scrolling so the newest column
remains visible, including when the preview pane opens.
- Prevented folder results from a previously selected bucket from
appearing after switching buckets during loading.
- Improved handling of incomplete or partial folder listings to avoid
incorrectly treating failed results as empty folders.
- Preserved the correct scroll position when using list view.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 17:05:23 +02:00
kemal.earth 24e8333c54 feat(studio): flag for unavailable regions (#50473)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds feature flag for controlling region unavailability.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Region options now display availability badges, tooltips, and
status-specific notices.
* Restricted regions remain selectable so users can review their
availability status.
* Project creation provides a clear field-level message when a selected
region is unavailable and prompts users to choose another region.

* **Bug Fixes**
* Region availability messaging now consistently reflects platform
status and configured restrictions.
  * Availability warnings clear after selecting an eligible region.
  * Region checks now cover both dynamic and static provider regions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 14:42:58 +01:00
Inder Singh 7b4e3aba01 fix(studio): show service role key in ConnectSheet for projects using legacy keys (#50516)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix #50515

## What is the new behavior?

ConnectSheet now falls back to the legacy `service_role` key for
projects using legacy JWT keys.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved secret-key resolution by falling back to the service key when
a secret key is unavailable.
* Prevented attempts to reveal a secret when no secret key identifier
exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 07:36:30 -06:00
Joshen Lim 337ffaeb22 Reset pooling size value to default size if field left blank and saved (#50524)
## Context

As per PR title - for the Database Settings -> Connection Pool
Just sends the default value (as per the placeholder) to the PATCH
request when saving while leaving the pool size field blank
<img width="724" height="391" alt="image"
src="https://github.com/user-attachments/assets/448c1bf9-4857-467e-8180-637f291321dd"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved connection pooling updates when a project reference or high
availability setting is unavailable.
- Ensured the default pool size is correctly submitted when no explicit
value is provided.
- Restored the maximum client connection setting accurately after
successful updates.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 13:22:13 +00:00
Anthony LioandAli Waseem 7fb2e8cd42 fix(docs): repeated shiki grammar registration (#50501)
## What kind of change does this PR introduce?

bug fix alternative to #50492

## What is the current behavior?

[#50239](https://github.com/supabase/supabase/pull/50239) introduced
repeated shiki grammar registration. duplicate injection rules
accumulate between code blocks, slowing later tutorials enough to hit
the 60-second build timeout

## What is the new behavior?
- reuses one highlighter with all languages loaded once
- restores previous highlighting approach + startup cost while keeping
the page-size savings

replay | before #50239 | after #50239 | this pr
-- | -- | -- | --
cold, including initialization | 2.99 s | 6.96 s | 2.94 s
warm | 0.37 s | 5.90 s | 0.36 s




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Enhancements

* Code blocks now preload syntax highlighting for all supported bundled
languages, including SQL, Markdown, and TypeScript.
* Highlighting uses a shared configuration and theme for consistent
rendering across code blocks.
* Concurrent code block renders share a single highlighter
initialization.
* Language handling and syntax-highlighted output are more consistent
across supported, unsupported, aliased, and plain-text code blocks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-17 07:07:35 -06:00
Maksym Ionutsaandcoderabbitai[bot] b5f174a6f9 docs: warn against installing PostGIS in the public schema (#50509)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

Gap in the docs that agents misinterpret

## What is the new behavior?

<img width="1566" height="718" alt="CleanShot 2026-09-17 at 12 13 59@2x"
src="https://github.com/user-attachments/assets/d50b4228-b0ec-4cca-94d3-ec083720a04a"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added guidance to install PostGIS in a dedicated schema rather than
`public`.
- Clarified that installing PostGIS in `public` exposes the
`spatial_ref_sys` table through the Data API.
- Explained that related security advisor warnings are expected and do
not indicate user data exposure.
- Added steps for moving PostGIS to another schema, including backup
precautions and an option to contact Support.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-09-17 15:06:39 +02:00
Maksym Ionutsa fe0afd66b8 docs(cron): document how to clean up cron.job_run_details (#50211)
cron.job_run_details grows unbounded and is never pruned automatically,
even after a job is unscheduled. Add an example that schedules a daily
cleanup job, and link it from the existing disk-usage caution.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

No mention of the _necessary_ regular cleanups

## What is the new behavior?

This is now explicitly called out with a weekly clean-up example

<img width="1620" height="654" alt="CleanShot 2026-09-10 at 11 41 25@2x"
src="https://github.com/user-attachments/assets/2f78a051-5994-4f8a-95c2-c96c64679bed"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Updated the cron quickstart guide with guidance on cleaning up job run
history.
- Added an example showing how to schedule a daily cleanup job that
removes records older than seven days.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 15:06:23 +02:00
Ivan Vasilov 68d7387e94 chore: Update tanstack icons (#50504)
Update the icons for Tanstack in studio and docs. See:
- https://docs-git-chore-update-tanstack-icons-supabase.vercel.app/docs
-
https://studio-staging-git-chore-update-tanstack-icons-supabase.vercel.app/dashboard/project/_?showConnect=true&framework=tanstack
2026-09-17 06:53:29 -06:00
Joshen Lim 71d58cba7f Joshenlim/fe 4401 re sql editor silently points to the primary instead of (#50513)
## Context

Fixes the following 2 issues with the database selection in the SQL
Editor
- An errant `useEffect` was resetting the `selectedDatabaseId` back to
the primary every time the `databases` list from `useReadReplicasQuery`
changed reference (not just on first load).
- `QuerySourceMenu` kept showing "Read Replica" even after selection had
reverted
- Was using local storage value as the `identifier` for
`DatabaseParametersSubMenu`, when it should use the valtio store as the
source of truth

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- The SQL Editor now remembers the last selected database between
sessions.
- Your saved database selection is restored when available; otherwise,
the project’s primary database is selected automatically.
- Query source settings now stay synchronized with the database
currently selected in the SQL Editor.

- **Bug Fixes**
- Background database refreshes no longer unexpectedly reset your
selected read replica to the primary database.
- Database selection now waits for saved preferences to load, preventing
a brief incorrect selection.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 12:34:13 +00:00
Lukas BernertandClaude Fable 5 459436e87f docs: update compute size descriptions (CPU column, pg_restore guidance) (#49996)
## What kind of change does this PR introduce?

Docs update: aligns compute descriptions with the current compute
options.

Fixes PROD-655

## What is the new behavior?

- compute-and-disk: CPU column now shows "Shared" (Nano–Medium) and
"Dedicated · N vCPUs" (Large and above), matching the pricing page
- migrating-to-supabase/postgres: pg_restore -j guidance keyed to the
vCPU count per compute size
- which-version-of-postgres: uses show server_version;, which gives
simpler, architecture-agnostic output
- High-CPU troubleshooting guide: recommends upgrading compute size
instead of naming specific instance types
billing-on-supabase: "64 cores" → "64 vCPUs"
- Section anchors unchanged (deep-linked from other pages)

## Self-review

Content-only MDX change:

- pnpm lint:mdx: no findings in the changed files (all reported
errors/warnings are pre-existing in unrelated files)
- pnpm build:guides-markdown: builds clean; generated .md exports for
the changed pages verified
- All pages verified rendering in the local dev app on current master
- Swept apps/docs for remaining core-count / instance-type mentions in
compute descriptions

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated PostgreSQL version-checking instructions to use `show
server_version;` with simplified output.
* Clarified compute sizing terminology using shared and dedicated CPU
allocations and vCPU-based descriptions.
  * Updated billing guidance to describe scaling up to 64 vCPUs.
* Revised database restore guidance with current compute tiers and
recommended parallelization settings.
* Simplified high-CPU troubleshooting guidance to recommend temporarily
scaling CPU capacity.
* Added writing guidance to consistently use “vCPU” and “vCPUs” for
Supabase compute resources.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-17 14:34:01 +02:00
Joshen Lim be9ec25270 Update unified logs queries to fetch status, method and pathname properly for storage logs (#50465)
## Context

As per PR title - those 3 properties (status, method, and pathname) were
missing from the table view but available in the detailed panel view

### Before
<img width="1118" height="575" alt="image"
src="https://github.com/user-attachments/assets/e6d3bb70-8ce9-4a7b-9e07-eae7acb6896d"
/>


### After
<img width="988" height="555" alt="image"
src="https://github.com/user-attachments/assets/309b4e5a-88e1-41d9-8cee-4ae56a1afa15"
/>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Unified Logs now correctly displays HTTP methods, paths, and status
codes for storage-service entries.
* Updated log filters to support storage-service values for equality,
inequality, wildcard, LIKE, and ILIKE searches.
  * Improved pathname prefix matching across supported log backends.
* Preserved correct handling of authentication statuses and worker
Compute fields.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 20:04:07 +08:00
Jordi Enric 6434c48999 feat(studio): migrate Auth reports to OTEL (#50469)
## Problem

Auth observability charts always queried the legacy logs.all endpoint,
even when the OTEL reports rollout was enabled. The existing OTEL SQL
also had ClickHouse correctness and parity gaps around timestamp
aliasing, JSON types, provider paths, missing values, and error-code
attributes.

## Fix

Route the ten Auth-specific charts through the OTEL query builders and
logs.all.otel endpoint when otelReports is enabled. Preserve the
BigQuery fallback, partition React Query caches by backend, and leave
the shared API gateway charts on the legacy endpoint.

Correct the OTEL queries by qualifying source timestamps, using typed
and nullable JSON extraction, preserving missing actor and duration
semantics, selecting the right provider path for each event shape,
preferring the canonical Auth error-code attribute with a legacy
fallback, and applying bounded result limits. Two-minute report
intervals now use minute-level SQL buckets instead of falling through to
hourly buckets.

## How to test

- Run `CI=1 pnpm --filter studio exec vitest run
data/reports/v2/auth.config.otel.test.ts
hooks/misc/__tests__/useReportDateRange.test.ts`
- Run `pnpm --filter studio run lint:ratchet`
- Run `pnpm --filter studio run typecheck`
- Expected result: all checks pass and generated OTEL SQL preserves
legacy report semantics.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Auth observability charts can now use OpenTelemetry data when enabled,
while retaining the existing reporting source otherwise.
- Switching the data source automatically refreshes the relevant charts.

- **Bug Fixes**
- Improved Auth observability accuracy for provider, duration, actor,
and error-code reporting.
- Added safeguards to keep report queries within the supported result
limit.
- Corrected minute-level grouping for two-minute analytics intervals and
three-hour date ranges.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 13:44:39 +02:00
Lukas Bernert 055cc7b956 docs: state disk limits as per-size minimums, align burst copy (#50016)
## What kind of change does this PR introduce?

Docs update: states disk limits as per-size minimums and aligns burst
copy across pages. Follow-up to #49996 (compute descriptions).

Fixes PROD-658

## What is the current behavior?

- The disk limits table and surrounding prose describe a narrower set of
configurations than a compute size can run on
- Burst thresholds are inconsistent across pages (three different
variants), and one section contradicts itself
- Burst is described as CPU behavior, when the burst users observe is
disk IO

## What is the new behavior?

- `shared-data/compute-disk-limits.ts`: Medium baseline throughput
adjusted to 39 MB/s: the lowest value across configurations
- `compute-and-disk`: disk limits presented as minimums ("at least");
burst described as disk IO drawing on a disk IO budget; consistent
thresholds: burst available up to 2XL, baseline equals maximum from 8XL
- Troubleshooting guides (`exhaust-disk-io`,
`failed-to-retrieve-tables`, `interpreting-supabase-grafana-io-charts`)
aligned to the same threshold; `failed-to-retrieve-tables` keeps the
~30-minutes-per-day burst window with the corrected size range
- Section anchors unchanged

## Self-review

- Values verified against the AWS EBS-optimized performance data
(`describe-instance-types`) for every configuration per size; content
cross-checked with the internal runbooks (linked in PROD-658)
- `supa-mdx-lint`: no findings in changed files
- `pnpm build:guides-markdown` clean; generated `.md` exports show the
new values and prose
- All changed pages verified rendering in the local dev app
- `pnpm typecheck` passes (shared-data + docs)
- Note: `compute-disk-limits.ts` also feeds Studio (disk validation, IO
budget tooltips). The only value change (Medium 43 → 39 MB/s) surfaces
there as one chart tooltip label; conservative direction.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Clarified the differences between shared and dedicated CPU resources.
- Updated disk I/O guidance to explain baseline and burst limits as
minimums.
- Documented disk I/O bursting for compute sizes up to 2XL, including
expected duration and limitations.
- Clarified that 8XL and larger compute sizes have consistent
performance without burst capacity.
- Updated the documented baseline throughput for medium compute
resources.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 12:26:45 +02:00
Lukas Bernert 593e95345a www: update compute size descriptions (Compute column, vCPU units) (#49998)
## What kind of change does this PR introduce?

www update: aligns compute descriptions on the pricing surfaces with the
current compute options. Counterpart to the docs update in #49996.

Fixes PROD-654

## What is the new behavior?

- Pricing compute table: the CPU and Dedicated columns are merged into a
single Compute column — "Shared compute" for Micro–Medium, "Dedicated ·
N vCPUs" for Large and above (the `dedicated` key is removed from
`PricingAddOnTable.json`)
- Pricing calculator: the instance summary line uses the new Compute
value directly
- Pricing compute section headline: "64 cores" → "64 vCPUs"
- `/pricing.md`, `/llms-full.txt`, `/llms/pricing.txt`: generated
markdown mirrors the new table
- `/database.md`: describes the compute range as Micro to 16XL+


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Pricing Updates**
- Compute pricing tables now label the column “Compute” and show shared
compute or dedicated vCPU counts.
  - Removed the separate “Dedicated” column from compute add-on tables.
- Dedicated-plan values now display consistently across desktop and
mobile layouts.
- Compute instance details no longer repeat the “CPU” label after the
CPU value.
  - Updated scaling language to refer to “64 vCPUs.”
- Simplified technical details by removing specific core-count examples
while retaining configurable sizing and autoscaling information.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 12:22:07 +02:00