- closes https://github.com/supabase/supabase/issues/47712
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved SQL query handling so automatic row limits are no longer
added when a query already ends with `LIMIT`, even if there’s whitespace
before the semicolon.
* Preserved correct behavior for queries using `LIMIT ... OFFSET ...`.
* **Tests**
* Expanded coverage for SQL limit detection and limit-suffix behavior
around whitespace and semicolon placement.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## What
PR 3 of a stacked refactor of the SQL editor snippet state. Replaces the
two overlapping pieces of snippet lifecycle state — the `savingStates`
map (`IDLE|UPDATING|UPDATING_FAILED`) and the `isNotSavedInDatabaseYet`
boolean — with a single `SnippetStatus` enum.
## Status is attached at the data layer (never absent)
- `SnippetStatus` + `SnippetWithContent` now live in `data/content`. The
snippet queries attach `status: 'saved'` via a typed `withSavedStatus()`
helper, and `upsertContent` returns `SnippetWithContent` so move/rename
responses carry status too.
- A SQL-typed `getSqlSnippetById`/`useSqlSnippetByIdQuery` returns
`SnippetWithContent` (the generic `useContentIdQuery` stays for Reports,
which use it). `[id].tsx` loads content with **no casting**.
- `'new'` is attached on local creation (`createSqlSnippetSkeletonV2`).
## Behavior
Behavior-preserving for the existing auto-save flow (faithful mapping of
both old fields, including the replication-lag swallow). One incidental
fix: the read-only/saving indicator now also covers a brand-new
snippet's first save (previously only re-saves of persisted snippets had
distinct saving/failed states in some paths).
## Tests
New `sql-editor-lifecycle.test.ts` (29 tests) covering every predicate
and transition; existing rules tests updated. `pnpm --filter studio
typecheck` clean; 52 state/sql-editor unit tests pass.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Release Notes
* **Refactor**
* Restructured SQL snippet persistence tracking, replacing boolean flags
with a comprehensive status system for clearer visibility into save
progress.
* Enhanced saving indicator UI to reflect accurate snippet save states.
* **Tests**
* Added test coverage for snippet persistence state transitions and
lifecycle scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Mark provenance of SQL via the branded types SafeSqlFragment and
UntrustedSqlFragment. Only SafeSqlFragment should be executed;
UntrustedSqlFragments require some kind of implicit user approval (show
on screen + user has to click something) before they are promoted to
SafeSqlFragment.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Editor and RLS tester show loading states for inferred/generated SQL
and include a dedicated user SQL editor for safer edits.
* **Refactor**
* Platform-wide SQL handling tightened: snippets and AI-generated SQL
are treated as untrusted/display-only until promoted, improving safety
and consistency.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
The previous \`updateWithoutWhereRegex\` only matched bareword table
identifiers (\`messages\`, \`public.messages\`) or a fully qualified
\`"schema"."table"\` pair, so statements like \`UPDATE "messages" SET id
= 1\` skipped the pre-execution warning entirely.
**Changed:**
- Broaden each identifier slot in \`updateWithoutWhereRegex\` to accept
either a bareword or a double-quoted identifier independently — covers
\`"messages"\`, \`"public".messages\`, \`public."messages"\`, \`"my
table"\`, and \`"weird""name"\` (escaped quote).
**Added:**
- 6 unit tests covering single quoted, mixed quoted/bareword, spaces in
identifiers, and escaped quotes — both with and without \`WHERE\`.
## To test
- Run \`pnpm --filter studio test -- SQLEditor.utils.test.ts\` — should
pass 79 tests
- In the SQL editor, run \`UPDATE "messages" SET id = 1\` — warning
modal should now appear
- Same statement with \`WHERE id = 2\` appended — no warning
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved SQL UPDATE detection in the SQL Editor to handle
double-quoted identifiers, schema-qualified names, names with spaces,
and escaped quotes.
* Prevented false positives by ignoring quoted string and identifier
contents when checking for a WHERE clause.
* **Tests**
* Added comprehensive tests covering varied quoting/qualification
scenarios and quoted-content edge cases.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Adds a pre-execution warning in the SQL editor when a `CREATE TABLE`
statement is run without enabling Row Level Security on the new table.
Responds to the press call-out around SQL editor security.
<img width="708" height="498" alt="Screenshot 2026-04-18 at 4 31 07 PM"
src="https://github.com/user-attachments/assets/4f23ed5e-f32c-46f0-b0da-ac6d4c661c7c"
/>
**Added:**
- Pre-execution check in `executeQuery` that detects `CREATE TABLE`
statements without a matching `ALTER TABLE ... ENABLE ROW LEVEL
SECURITY` in the same submitted SQL.
- New "Run and enable RLS" action in the warning modal that rewrites the
SQL to append `ALTER TABLE [schema.]<table> ENABLE ROW LEVEL SECURITY;`
for each detected table before running.
- Link in the modal to the RLS docs.
**Changed:**
- `RunQueryWarningModal` now renders `Dialog` directly (instead of
`ConfirmationModal`) so it can show three buttons: Cancel / Run without
RLS / Run and enable RLS.
- `sqlEventParser` table-name regex now supports quoted identifiers
containing spaces (e.g. `"My Table"`) and escaped quotes (e.g.
`"user""table"`).
The check runs against the SQL that's actually submitted, so
partial-selection works correctly — selecting only the `CREATE TABLE`
portion will trigger the warning even if there's a matching `ENABLE RLS`
lower in the editor.
## To test
- Open the SQL editor and run `create table foo (id int8 primary key);`
→ modal should appear with the RLS warning bullet and three buttons.
- Click **Run and enable RLS** → query runs, table is created with RLS
enabled.
- Click **Run without RLS** → query runs as written, no RLS.
- Run `create table foo (id int8); alter table foo enable row level
security;` → no modal (RLS already enabled in same submission).
- Run `create table public.bar (id int8); create table baz (id int8);
alter table baz enable rls;` → modal flags only `public.bar`.
- Select only the `create table` portion of a snippet that also enables
RLS lower down and run the selection → modal should still fire.
- Run an existing destructive query (`drop table x`) → modal still works
as before with two buttons (Cancel / Run this query).
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* SQL editor now detects CREATE TABLE statements missing Row Level
Security (RLS) and shows counts and dynamic table/schema details in a
redesigned warning dialog with updated pluralization and a “Learn more”
link.
* New actions: “Run without RLS” and, when available, “Run and enable
RLS” which applies RLS and runs the query; editor can execute an
overridden SQL payload when applying RLS changes.
* **Tests**
* Added comprehensive unit and e2e tests covering RLS detection, SQL
augmentation, trigger handling, identifier parsing, and the “Run and
enable RLS” flow.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
## Context
Adds a warning if running an `ALTER DATABASE` command that prevents
connections to the database. This would lock the dashboard out of the
database, and re-configuring the setting will require a direct
connection to the DB
<img width="623" height="535" alt="image"
src="https://github.com/user-attachments/assets/4c388f4a-753b-4fd6-89c5-89dfaa52c859"
/>
## To test
- Could try running the following command in the SQL editor to check the
warning, this will show all the warnings
```
ALTER TABLE colors2 drop column sss;
update colors set name = 'test';
alter database postgres connection limit 0;
```
* Use the .sql suffix when generating ids.
* Fix a bug where a new snippet would not show up in the snippet list until refresh.
* Add API routes which serve file snippets.
* Refactor the renameSnippet and moveSnippet to work with file snippets.
* Change the link to the SQL Editor.
* Minor fixes from CodeRabbit.
* Check the file/folder name for invalid chars.
* More fixes from CodeRabbit review.
* Fix minor issues.
* Use zod to parse the snippet ids when deleting.
* Try to fix snyk issue.
* Add validation to the GET content index route.
* Minor fixes.
* Show create a new folder, it was hidden by mistake.
* Add SNIPPETS_MANAGEMENT_FOLDER env var.
* Add snippets folder in the docker-compose.
* Add error toasts if the env var is not set.
* Add snippets management folder to the generateLocalEnv script.
* Revert the docker-compose changes, will be done in a followup PR.
* Revert also the snippets volume folder.
* Remove unneeded line.
* Add a generateDeterministicUuid function and tests for it.
* Use the new function and generate an id automatically when creating a snippet.
* Clean up extra code.
* Don't pass in id when creating a snippet.
* Add generateSnippetTitle function and use it instead of fixed string.
* When SQL editor is open, generate an id form a generated snippet title.
* Add id override for SQL editor to avoid flash when saving the snippet.
* Merge the two generate functions to happen in the same useMemo block.
* Save the snippet to the API when adding it.
* Minor fixes from CodeRabbit review.
* Hide new folder CTA in sql editor for self-hosted
* Don't add the snippet for saving, just set the value.
* UpsertContentPayload always has an id.
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
* chore: paginate user content
* progress
* loading states
* add load more buttons to private snippets
* working pagination
* fix some types
* always show snippet counts
* support new api parameters
* favorite snippets
* progress
* searching
* paginate root folder
* fix renaming snippets
* fix ts
* removed unused prop
* Shift sharing/unsharing query logic outside of valtio to leverage on RQ only
* Fix invalidation on an unsaved snippet
* Clean up
* Fix
* Clean up
* Update API type
* Update API
* fix duplicate snippets error after moving a snippet
* add currently selected snippet
* Fix unsharing a snippet that has yet to be opened
* i'm dumb
* fix sharing a snippet
* fix sharing and unsharing
* show favorite or shared snippet in list even if it's in another page
* Fix wrong import for debounce
* Fix false positive toast error when creating custom report
* Update API type
* Change create new snippet CTA to link back to /new with skip flag
* Fix saving logs explorer query
* Bump page number
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
* Deprecate use of sqlFolderOrganizationFlag
* Deprecate SQLEditorNavV1
* Deprecate use of useSqlEditorStateSnapshot
* Deprecate old sql-editor valtio state
* Add warning when running update without where
* Account for quotes
* Split warnings to allow them to show independently
* Update
* Combine two modals into one
* Padding bump
* Fix padding
* Return if a query has issues
* Allow queries to run
* Small UI tweaks
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
* Init changes for sql fodlers
* Added upsert logic in sql-editor-v2 valtio, hooked up with templates and quickstarts
* Do up logic for creating new snippets by typing in /new or by clicking new query button
* Do up logic for updating and deleting snippets
* Do up logic for favourites and shared snippets
* Do up logic for favourites and shared snippets
* Fix
* Fix saving indicator, add empty states for favorites and shared snippets
* Implement sorting
* Some minor QOL improvements
* Minor fix on empty state for private snippets
* Add delete folder mutation
* Implement create and update folder
* Fix reinstate with AI renaming for new snippets under folder
* Support controlled multi select behaviour in private snippets
* Undo changes to tree-view-multi-select
* Support bulk deletes
* Support moving queries + rendering queries in folders
* Support deleting folders and creating a new folder when moving a query
* Fix bug where renaming query removes content
* Add initial loading state in sql editor nav + handle fallback if cannot retrieve content by id
* Fix some spelling
* Fix TS issue in sql folders mutation keys
* Fix toggling favorite
* Lint
* Revert fallback behaviour in ]id] for now
* Fix favorites and shared snippets not showing
* Fix moving currently opened snippet leads to loading
* Support bulk moving
* Improve multi select logic a little
* Nit lint
* Reinstate AI retitling for untitled snippets when running query
* Remove hardcode in useAFlag
* Support creating new snippet in a folder directly
* Fix sharing snippets that are within a folder
* Fix sharing snippets within a folder
* Fix favorite
* Add loading state when fetching folder contents
* Fix favoriting snippets in folders
* Add pagination to SQL editor for results longer than 100 rows
* Change pagination to automatically setting a limit
* Fix
* Address initial comments
* Compress SQL editor actions when ai assistant is open and screen is of a certain width
* Fix checking
* Add some fixes and tests
* Add a message if the query had an error and the limit was applied
* Rename to suffixWithLimit
* Small refactor and fix
* Remove feature preview for the conversational AI for SQL editor.
* Remove all code related to the previous implementation of editor ai.
* Update the snapshots for the ai commands.
* Remove unneeded code from the ai panel.
* Show the diff bar when debugging.
* Convert the updateEditor function into a callback.
* Simplify the debugging functionality by using react state instead of react context.
* Erase the AI disclaimer when formatting code as modification.
* Add a button to clear the chat history.
* Add a API endpoint for generating queries for the SQL editor.
* Merge all multiline props.
* Add a new component for diff actions.
* Copy components for the AI panel.
* Add useChat hook.
* Add a feature preview for the this feature. The preview is dependent on the feature flag.
* Reorder the nesting in the SQL editor to accomodate the AI assistant.
* Try to fit both AI assistants in the SQL editor, available via a feature preview.
* Refactor the SQL editor to make the diff work correctly in all cases.
* Minor fixes for the old AI feature.
* Fix the debug functionality to work with both assistants.
* Fix some copy-paste leftovers.
* Remove unneeded code.
* Make the icons softer.
* Fix the name of the panel component.
* Fix console.logs.
* Add overflow to the AI assistant.
* surface opt in config in ai settings button
* Skip diffing if editor is empty
* Add selected state when selecting a message to insert/replace code
* Add sample prompts
* Add SQL ai dislaimer when replacing code
* Light mode action bar nudges
* Add text for the feature preview.
* lang nudges
* Hide the command suggestions for now.
* Set the discussion url to undefined.
* Don't add the disclaimer twice.
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Terry Sutton <saltcod@gmail.com>
* feat(sql-editor): cli commands to import snippet as migration/seed
* fix(sql-editor): reword to download snippet
* chore(sql-editor): update wording
* Move to tabed ui, move download button to context menu
* Inline
* feat: add react native auth blog and quickstart. (#19006)
* feat: add react native auth blog and quickstart.
* Grammarly check
* Minor edits.
* Added og image.
* chore: add password sign in and gif.
---------
Co-authored-by: Ramiro Nuñez Dosio <ramiro@supabase.io>
* fix: duplicate eslint dependency (#19028)
* Update sveltekit.mdx (#18998)
Extended authorization section of docs to mention use of Sveltekit sequence helper function for protecting routes alongside defining Supabase session. Also provided new code.
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
* fix: add hello world example to edge functions quickstart (#19030)
* Fix project card status not showing (#19034)
* Fix project card status not showing
* Fix tooltip project card styling
* chore: update cli reference doc (#18934)
* Add docs for updating the image versions (#18160)
see #17930
* chore: fix casing of "encryption at rest" (#19032)
* chore: update self-hosted image versions (#18935)
chore: update image versions for docker/docker-compose.yml
* (docs) Update arg name that resulted from adapters release (#19024)
update arg name that resulted from adapters release
* docs: Fix an example (@supabase/ssr package) for Next.js API Route (#19009)
Update creating-a-client.mdx
replace `appendHeader` with `setHeader` for the Next.js API route example.
* chore: cleanup studio dependencies (#19040)
* Fix code text color (#19042)
* make dark: selector work again
* fix reference docs code color
* feat: remove note about tus rollout (#19007)
it has been rolled out to all projects
* docs: update language in database-size.mdx code block (#19033)
Co-authored-by: Kevin Grüneberg <k.grueneberg1994@gmail.com>
Co-authored-by: Copple <10214025+kiwicopple@users.noreply.github.com>
* Docs: Adds a page for enums (#18590)
* Adds a page for enums
* Adds some details on deleting values
* Update apps/docs/pages/guides/database/postgres/enums.mdx
Co-authored-by: Kevin Grüneberg <k.grueneberg1994@gmail.com>
* Update apps/docs/pages/guides/database/postgres/enums.mdx
Co-authored-by: Kevin Grüneberg <k.grueneberg1994@gmail.com>
* Update apps/docs/pages/guides/database/postgres/enums.mdx
Co-authored-by: Kevin Grüneberg <k.grueneberg1994@gmail.com>
* Update apps/docs/pages/guides/database/postgres/enums.mdx
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
* removes dangerous operation
---------
Co-authored-by: Kevin Grüneberg <k.grueneberg1994@gmail.com>
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
* Update hugging-face.mdx: fix example curl request (#17667)
The example request did not match the example edge function because there is used prompt and in the curl script was used query
* docs: fix syntax error in create role command (#17755)
* Update auth-sso-saml.mdx (#17856)
* docs: Update auth-google.mdx (#18119)
* fix: Bump up Realtime to 2.25.35 (#19048)
* Update llamaindex.ipynb doc_hash to hash (#18838)
* Update llamaindex.ipynb doc_hash to hash
Update `doc_hash` to `hash` since running this as-is provided an `AttributeError`.
Here's what the Python build-in `vars` gives me (truncated):
```python
{'id_': 'd94b1287-b3ef-4aba-ac6b-7a4e353b0327',
'embedding': None,
'metadata': {},
'excluded_embed_metadata_keys': [],
'excluded_llm_metadata_keys': [],
'relationships': {},
'hash': '4c702b4df575421e1d1af4b1fd50511b226e0c9863dbfffeccb8b689b8448f35',...}
```
* fix: SimpleWebPageReader & StorageContext imports
* chore: revert python version change
---------
Co-authored-by: Greg Richardson <greg.nmr@gmail.com>
* fix: add reference docs back to search index (#19054)
Reference docs weren't being indexed properly because the specs weren't
getting checked out at build time.
* docs: add RN videos and discoverability improvements. (#18633)
* docs: add RN videos and discoverability improvements.
* Apply suggestions from code review
Co-authored-by: Copple <10214025+kiwicopple@users.noreply.github.com>
* chore: run prettier.
---------
Co-authored-by: Copple <10214025+kiwicopple@users.noreply.github.com>
* docs: add getting started guide for Swift (#19044)
* docs: getting started guide for Swift
* Apply suggestions from code review
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
* Add new tutorial to menu
* Add correct image for tutorial
* style: format with-swift tutorial
* docs: add example to the repository
---------
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
Co-authored-by: Thor 雷神 Schaeff <5748289+thorwebdev@users.noreply.github.com>
* docs: Update mentions of `foreign table` to `referenced table` (#18656)
* replace foreignTable parameter with referencedTable parameter
* remove redirects
* rename any mentions of foreign table to referenced table
* fix one mention of foreign table
* update some links
* guide: add pgroonga videos to pgroonga guide (#19073)
add pgroonga videos to pgroonga guide
* docs(swift): rename `authStateChanges` and remove `File` from upload method (#19067)
docs: fix authStateChanges and upload documentation
* Small style fixes
* Style
* Update
* Update
* Update UI components positioning for DownloadSnippetModal
---------
Co-authored-by: Terry Sutton <saltcod@gmail.com>
Co-authored-by: Thor 雷神 Schaeff <5748289+thorwebdev@users.noreply.github.com>
Co-authored-by: Ramiro Nuñez Dosio <ramiro@supabase.io>
Co-authored-by: Kevin Grüneberg <k.grueneberg1994@gmail.com>
Co-authored-by: uncapped1599 <126204291+uncapped1599@users.noreply.github.com>
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
Co-authored-by: Lakshan Perera <lakshan@supabase.io>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Copple <10214025+kiwicopple@users.noreply.github.com>
Co-authored-by: Div Arora <darora@users.noreply.github.com>
Co-authored-by: Oliver Rice <github@oliverrice.com>
Co-authored-by: Taishi <taishi.k0903@gmail.com>
Co-authored-by: Francesco Sansalvadore <f.sansalvadore@gmail.com>
Co-authored-by: Inian <inian1234@gmail.com>
Co-authored-by: Joseph Yu <39754176+joseph082@users.noreply.github.com>
Co-authored-by: Maidi <mareike.haug@web.de>
Co-authored-by: Shinya Fujino <shf0811@gmail.com>
Co-authored-by: Andrei Soroker <soroker@gmail.com>
Co-authored-by: Isaac Abotsi <abotsi@users.noreply.github.com>
Co-authored-by: Filipe Cabaço <filipe@supabase.io>
Co-authored-by: Jason R. Stevens, CFA <jason@thinkjrs.dev>
Co-authored-by: Guilherme Souza <grsouza@pm.me>
Co-authored-by: Tyler <18113850+dshukertjr@users.noreply.github.com>
* Move all studio files from /studio to /apps/studio.
* Move studio specific prettier ignores.
* Fix the ui references from studio.
* Fix the css imports.
* Fix all package.json issues.
* Fix the prettier setup for the studio app.
* Add .turbo folder to prettierignore.
* Fix the github workflows.