Commit Graph
37273 Commits
Author SHA1 Message Date
Charis 333175b17b refactor: switch to @ imports and enforce sorting for studio/state (#44523)
* **Refactor**
* Updated internal module import paths to use standardized alias
conventions across the codebase.
  * Reorganized import statement ordering for improved code consistency.
2026-04-06 13:36:05 +00:00
a020be54c0 fix(studio): use hook for org in NoProjectsOnPaidOrgInfo (#44572)
Follow-up to #44562 – the org prop wasn't actually being passed in, so
`NoProjectsOnPaidOrgInfo` was always returning null. Switched to
`useSelectedOrganizationQuery` hook instead.

## To test

- Go to an org on a paid plan with no projects
- Verify the admonition banner appears on the general settings page

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Simplified component architecture by replacing prop-based organization
retrieval with hook-based approach, reducing component coupling and
improving maintainability.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 19:05:24 +09:00
e7bec24021 [FE-2913] feat(studio): restrict cloud provider to AWS (Revamped) for HA projects (#44569)
When high availability is enabled during project creation, automatically
switch to AWS (Revamped) and disable other cloud providers –
multigres/HA is only supported on v3.

<img width="778" height="390" alt="Screenshot 2026-04-06 at 5 09 55 PM"
src="https://github.com/user-attachments/assets/c458f345-497e-4963-9c2f-b4b1eafd030b"
/>

**Changed:**
- Cloud provider selector now watches `highAvailability` form state
- Non-`AWS_K8S` providers (Fly.io, AWS, AWS Nimbus) are disabled when HA
is on
- Warning description shown in orange when HA restricts the provider
choice

**Added:**
- `useEffect` in project creation form to auto-switch cloud provider to
`AWS_K8S` when HA is toggled on

## To test

- Enable the HA toggle on the new project page (requires
`instances.high_availability` entitlement)
- Verify cloud provider auto-switches to AWS (Revamped)
- Verify other providers are greyed out in the dropdown
- Verify orange warning text appears below the cloud provider label
- Toggle HA off and confirm all providers become selectable again
- Ensure project creation still works for both HA and non-HA projects

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* When high availability is enabled, cloud provider selection is
restricted to AWS.
* A warning appears when high availability is enabled, noting AWS-only
support.
* The cloud provider selection automatically switches to AWS if high
availability is toggled on.

* **Bug Fixes**
* Improved form validation to prevent incompatible high-availability and
provider combinations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-04-06 19:05:09 +09:00
K-Dog (Kevin) b2d8772d75 chore: do not preload plan change data on page load (#44562)
The data is preloaded even though the modal is never visible
2026-04-06 09:26:02 +00:00
K-Dog (Kevin) 5ca6182d1e chore: cleanup redeemCodeEnabled flag (#44563) 2026-04-06 09:09:30 +00:00
Alaister YoungandAlaister Young 421eaedd50 fix(studio): skip project count query for platform orgs (#44566)
Platform orgs can have very high project cardinality (>1M projects),
making the project count query expensive. This disables the query across
all count-only usages for platform plan orgs.

**Changed:**
- `OrgSelector` — disable query, show "Platform" label instead of count
- `OrganizationCard` — disable query, hide project count for platform
orgs
- `NoProjectsOnPaidOrgInfo` — disable query (component already returned
null for platform orgs)

**Not changed:**
- `TeamSettings` — also uses the count, but the warning it powers is
specifically relevant for orgs with a lot of projects, and it's tucked
away on the team settings page rather than on every page load.

## To test

- On a platform org, verify no `/organizations/{slug}/projects` requests
fire from the org selector, org cards, or billing info
- For regular orgs, verify the project count still displays normally
everywhere

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Organization selector now shows a dedicated "Platform" label for
platform organizations instead of a project count.
* Reduced unnecessary network activity by skipping project fetching when
a platform organization is selected, improving load performance.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-04-06 18:05:12 +09:00
4814672f6f [FE-2946] fix(studio): skip available-versions request when dbRegion is empty (#44561)
Don't fire the `available-versions` request when `dbRegion` is falsy
(undefined or empty string). Fixes race condition where the request
fires before a region is selected.

## To test

- Confirm no invalid `available-versions` request in the network tab
- Confirm create new project still works

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved database region validation during project creation to
consistently handle empty or undefined values.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 18:02:11 +09:00
Alaister YoungandAlaister Young b5326ce3b2 fix(studio): only render MobileNavigationBar on mobile viewports (#44565)
MobileNavigationBar was always mounted on desktop, triggering
unnecessary org/project queries even though it's visually hidden with
`md:hidden`. Now only rendered when the viewport is at or below the md
breakpoint.

**Changed:**
- Conditionally render `MobileNavigationBar` using `useBreakpoint('md')`
so it only mounts on mobile

## To test

- Open Studio on a desktop viewport – verify the mobile nav bar is not
in the DOM and no unnecessary requests fire
- Resize to a mobile viewport – verify the mobile nav bar appears and
works normally

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Bug Fixes
* Mobile navigation bar now correctly displays only on mobile devices
based on screen size, improving responsive design behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-04-06 18:01:03 +09:00
Pamela Chia bb66ba884c docs(billing-faq): add paused/deleted project usage note (#44570)
## Summary
- Add an Admonition note to the Fair Use Policy section clarifying that
pausing or deleting a project does not remove accumulated usage from the
current billing cycle
- Addresses a common source of confusion identified in #team-support
thread (2026-04-02)

## Test plan
- [ ] Preview the MDX locally to confirm Admonition renders correctly

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated billing FAQ to clarify that pausing or deleting a project
stops new usage from accruing but does not remove usage already incurred
in the current billing cycle; quota-based usage remains counted until
the billing period resets.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-06 17:42:22 +09:00
Pamela Chia 4c10f65de7 feat(tracking): add compute_badge_upgrade_clicked event (#44560)
## Summary

The `compute_badge_upgrade_clicked` event had zero fires since Apr 1
because the PostHog tracking call was never wired up on the "Upgrade
compute" button in the compute badge hover card. This adds the missing
`useTrack` call using the existing event definition in
`telemetry-constants.ts`.

## Changes
- Add `useTrack` hook and `onClick` handler to the upgrade button in
`ComputeBadgeWrapper.tsx`
- Fires `compute_badge_upgrade_clicked` with `computeSize`, `planId`,
and `upgradeType` properties
- Preserves existing `asChild` + `<Link>` navigation pattern

## Testing

Tested on Vercel preview:
- [x] Hover compute badge on a project with non-max compute, click
"Upgrade compute", verify `compute_badge_upgrade_clicked` event appears
in PostHog live events with correct properties
- [x] Verify navigation to compute settings page still works
(client-side, no full reload)
- [x] Test with paid-plan nano project: `upgradeType` should be
`free_micro_upgrade`
- [x] Test with paid-plan non-nano project: `upgradeType` should be
`compute_upgrade`

## Linear
- fixes GROWTH-751

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Added analytics tracking for compute upgrade button clicks to record
upgrade type (free micro vs. paid), selected compute size (with
fallback), and plan identifier. This ensures upgrade interactions are
captured for product insights without changing visible UI behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-06 17:11:48 +09:00
K-Dog (Kevin) 6841db7792 fix: do not query backups for project in unknown state (#44559)
Unknown state is explicitly set before a project is coming up, leading
to a bunch of invalid backups list requests
2026-04-06 13:12:43 +08:00
Mert YEREKAPAN b9e83b25e1 feat(studio): adding upgrade button to header experiment (#44494)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Add an always-visible "Upgrade to Pro" button in the dashboard header
for free-plan users (GROWTH-615)
- Button is gated behind a PostHog experiment (`headerUpgradeCta`) with
`control` and `test` variants
- Experiment exposure is tracked for both variants; click events are
tracked when the button is clicked
- Button reuses existing `UpgradePlanButton` component for routing,
permissions, and billing logic

## What is the current behavior?

<img width="3840" height="2160" alt="Arc 2026-04-02 16 36 22"
src="https://github.com/user-attachments/assets/8a94db0c-06c8-4237-8ba5-6ac1fe111a56"
/>

## What is the new behavior?

<img width="3840" height="2160" alt="Arc 2026-04-02 16 36 12"
src="https://github.com/user-attachments/assets/0e60d834-028b-49fd-845e-ce1b4cbcc960"
/>


## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added an upgrade call-to-action in the header and mobile navigation
(visible on medium+ screens in platform builds) shown to free-plan users
as part of a controlled experiment.
* The CTA records experiment exposures and sends analytics for
impressions and clicks, including the user's current plan, to measure
engagement and upgrade interest.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-03 20:51:54 +02:00
Ivan VasilovandClaude Opus 4.6 cccae29569 refactor(studio): extract storage preferences into useStoragePreference hook (#44519)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Refactor

## What is the current behavior?

Storage explorer preferences (`view`, `sortBy`, `sortByOrder`,
`sortBucket`) are managed inline within the Valtio proxy state in
`storage-explorer.tsx`, which reads/writes localStorage directly.

## What is the new behavior?

Preferences are extracted into a dedicated `useStoragePreference` hook
backed by `useLocalStorage`. A companion `getStoragePreference` function
allows the Valtio state to read sort options imperatively for API calls
without holding preference data itself. Consumers import the hook
directly instead of reading preferences from the snapshot.

## Additional context

No behavioral or visual changes — localStorage key and data shape are
unchanged.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Storage view and sorting preferences now persist per project and drive
the explorer UI.
* Changing view or sort preferences refreshes folder contents and clears
the open file preview.

* **Chores**
* Centralized preference handling for consistent behavior across the
storage explorer.

* **Tests**
  * Updated tests to exercise the new preference-backed behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-03 17:28:56 +02:00
Giuseppe Mandato 2335906d08 feat(read-replicas): bump up max read replicas for small instances (#44027)
INDATA-193
BACKEND: <https://github.com/supabase/platform/pull/30575>

<img width="1199" height="1005" alt="Screenshot 2026-04-03 at 11 54 29"
src="https://github.com/user-attachments/assets/38e9d676-449f-45c0-9e07-f273312a812f"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Consolidated read replica limit configuration to provide more
consistent behavior across different compute tiers.

* **Tests**
* Added comprehensive test coverage for read replica eligibility checks
and replica limit calculations based on compute tier.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-03 13:04:49 +00:00
bf90f5d034 [FE-2942] feat(studio): add partner icon to org selection cards (#44513)
Show Vercel/AWS partner badge on organization selection cards, matching
the existing behaviour in the org dropdown switcher. Uses the existing
`PartnerIcon` component.

**Added:**
- `PartnerIcon` to `OrganizationCard` – renders alongside the MFA lock
icon on the right side of each card

<img width="626" height="275" alt="Screenshot 2026-04-03 at 5 36 54 PM"
src="https://github.com/user-attachments/assets/f3cd2eb4-bf9d-4b42-b94c-e4636ebf7303"
/>

## To test
- Verify Vercel-managed orgs show the Vercel triangle badge


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Partner icon now appears in the organization card header next to the
MFA/security indicator.

* **Style**
* Improved alignment and spacing of header elements; MFA tooltip now
appears alongside the icon with consistent sizing.
* Cleaner grouping of header metadata for easier scanning and visual
clarity.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-03 18:03:33 +08:00
d970327ef7 feat: current password enforcement (auth) and docs (#43324)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature and docs. 


## What is the new feature?

Adds a toggle to enforce current password checks for updating a user's
password (auth)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added configurable option to require the current password when
changing passwords.
* Added configurable option to require recent reauthentication before
allowing password changes.

* **Documentation**
* Added "Password security" guide sections documenting current-password
verification and reauthentication safeguards, with usage examples.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-04-03 08:09:04 +00:00
Charis 3b7052b5a9 cleanup: fix import order and prefixes for studio/data (#44501) 2026-04-03 09:15:57 +02:00
Prashant Sridharan 423efe4ee0 Added participant logos to Stripe party page (#44509)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added sponsor and participant logos to the party page.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added hosts section displaying event partners with logos and
descriptions.
  * Updated event page branding and messaging throughout.
  * Revised call-to-action button text and styling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-03 08:03:39 +01:00
Prashant Sridharan dc953e3fe5 Stripe party go page (#44503) 2026-04-02 21:54:16 +01:00
Ignacio Dobronich 4189e76341 fix: round currency value to 2 decimal places in subscription upgrade preview (#44502)
This PR removes the `Math.round` from the `Totals` in the subscription
upgrade preview.

| Before | After |
|--------|-------|
| <img width="388" height="397" alt="image"
src="https://github.com/user-attachments/assets/f0f63ad5-c7c0-44b2-9ebc-59c9e4ad66c0"
/> | <img width="422" height="457" alt="image"
src="https://github.com/user-attachments/assets/98a7f69f-429a-42eb-98ce-20de4974c29e"
/> |
| <img width="563" height="401" alt="image"
src="https://github.com/user-attachments/assets/083942f5-90b2-4c91-b195-4526694e365d"
/> | <img width="766" height="467" alt="image"
src="https://github.com/user-attachments/assets/854e127d-db45-48d4-b3a9-fdb010748f71"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved precision of billing calculations in subscription plans, with
monthly invoice estimates and plan totals now displaying more accurate
currency amounts.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 17:22:50 -03:00
Matt Rossman 82deff37de feat(assistant): lazy load topic knowledge via load_knowledge tool (#44296)
Moves knowledge (RLS, Edge Functions, PostgreSQL best practices,
Realtime) out of the static system prompt and into a `load_knowledge`
tool the model calls on demand, reducing prompt bloat. This is a
temporary stopgap until the [standard Supabase
agent-skills](https://github.com/supabase/agent-skills) are ready for
integration in Assistant.

- New always-available `load_knowledge` tool added to
`rendering-tools.ts`
- Updated `Message.Parts.tsx` so the "Ran load_knowledge" chip renders
in chat
- System prompt replaces the four knowledge blobs with an `## Available
Knowledge` block and is hardened to load knowledge for given topics
- New "Knowledge Usage" scorer and `requiredKnowledge` assertions check
that knowledge loads as expected in test scenarios
- Filters GraphQL error responses out of `output.docs` before
faithfulness scoring to reduce noise


See "Knowledge Usage" scoring 100% in evals with no major regressions:
https://github.com/supabase/supabase/pull/44296#issuecomment-4145760236

Sample trace showing the tool in action
([Braintrust](https://www.braintrust.dev/app/supabase.io/p/Assistant/trace?object_type=project_logs&object_id=5a8d02e5-b3b6-40cc-ba76-ecee286478f4&r=351a11c8-9cb7-4945-93ad-d11e8cc2e3e1&s=351a11c8-9cb7-4945-93ad-d11e8cc2e3e1))

<img width="2192" height="1730" alt="CleanShot 2026-03-30 at 13 53
59@2x"
src="https://github.com/user-attachments/assets/f483767c-34e0-401c-8089-5b9834fe696a"
/>


**References**
- https://ai-sdk.dev/cookbook/guides/agent-skills

Closes AI-508

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added dynamic knowledge loading capability enabling the AI assistant
to retrieve on-demand information about PostgreSQL best practices, Row
Level Security, Edge Functions, and Realtime.

* **Bug Fixes**
* Improved search results filtering to exclude error responses in tool
outputs.

* **Tests**
  * Enhanced evaluation metrics with knowledge usage scoring.
* Expanded test dataset cases to validate knowledge requirement
handling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 16:09:06 -04:00
Prashant Sridharan 83ccf44461 Added a link to Pedro's slides (#44500)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Modified event landing page to point to Pedro's slides.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated the slides download link for the MCP Dev Summit NYC event.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 20:34:35 +01:00
Ali Waseem a1c8587808 fix(studio): respect deselected columns in CSV import compatibility check (#44497) 2026-04-02 12:59:19 -06:00
Prashant Sridharan 73d972ba29 Added blog post draft (#44485)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added a blog post and og/thumb images for the GitHub 100,000 stars
announcement.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Embedded an interactive Developer Growth chart into the new blog post
announcing the milestone.

* **Documentation**
* Published a blog celebrating 100,000 GitHub stars with historical
context, a product principles excerpt, links to related projects, and a
community thank-you.
* Updated the site RSS feed to include the new post and other recent
entries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 19:49:28 +01:00
Charis 5c1cf1a6ea fix: tsconfig auto-import resolution (#44496)
Ever since the update to TypeScript 6, IDE auto-imports are suggesting
"node_modules/package_name/...." rather than the correct "package_name".
This is due to our deprecated bare specifier wildcard in paths,
replacing this with a listing of all bare specifiers we currently
support (while migrating away) to restore auto-import suggestions.
2026-04-02 14:38:14 -04:00
Chris Chinchillaandfadymak a725766e6a docs: Update key usage in QuickStarts (#44434)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated all quickstart guides and tutorials to reference publishable
keys instead of anon keys for Supabase client initialization.
* Simplified environment variable setup instructions across multiple
framework guides by removing anon key configuration requirements.
* Clarified usage of publishable keys in step-by-step setup
documentation for various frameworks and platforms.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: fadymak <dev@fadymak.com>
2026-04-02 15:53:26 +00:00
Ivan Vasilov 30c16da0e1 chore: Split turbo configs for apps into their own files (#44085)
This pull request refactors the Turbo build configuration by moving each
app's build settings from the root `turbo.json` file into their own
dedicated `turbo.jsonc` files within each app's directory. The root
configuration is simplified to only include generic tasks, improving
maintainability and clarity.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
  * Updated Turbo to v2.9.3 to improve build performance and stability.
* Reorganized and added per-app build pipeline configurations to
streamline builds and caching across the workspace.
* Removed a Tailwind container-queries plugin from one app's styling
setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 15:51:16 +02:00
Luiz Felipe Machado 792c26aadf docs(self-hosting): fix SSO endpoint path in SAML login flow example (#44491) 2026-04-02 13:46:55 +00:00
Ali Waseem a70264c8ad fix(studio): coerce index advisor cost values to numbers (#44397)
## Summary

- Coerces `before`/`after` cost values to `Number()` in
`QueryPanelScoreSection` and `calculateImprovement` before any
comparison or arithmetic
- Fixes contradictory index advisor display where correct cost numbers
showed 0% improvement and wrong arrow direction

## Root Cause

When `index_advisor_result` is prefetched from the Reports SQL query
(via `json_build_object`), cost values can arrive as strings instead of
numbers. JavaScript string comparison is lexicographic, producing wrong
results:

| Expression | Numbers | Strings |
|---|---|---|
| `after > before` (arrow) | `50 > 100` → `false` ✅ | `"50" > "100"` →
`true` ❌ |
| `costBefore <= costAfter` (improvement calc) | `100 <= 50` → `false` ✅
| `"100" <= "50"` → `true` ❌ |

The direct fetch path (`retrieve-index-advisor-result-query.ts`)
validates through Zod and is unaffected. Only the prefetched path lacks
validation.




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved numeric value handling in query performance calculations to
ensure more accurate and reliable improvement metrics.

* **Refactor**
* Enhanced type safety and numeric coercion for query performance score
comparisons, resulting in more consistent and robust metric
calculations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 13:30:00 +00:00
Cemal Kılıç 92692240bf fix: make Apple OAuth client secret optional for native sign-in (#44386)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

When enabling Apple Sign-in in Studio, the form requires a valid JWT
secret key whenever a client ID is provided. This blocks users who only
use Apple native sign-in (iOS, macOS, watchOS, tvOS), where only the
client ID (bundle ID) is needed and no secret is required.

Resolves AUTH-1138

## What is the new behavior?

The secret key field is now optional, matching Google's provider
behavior. JWT format validation still applies when a secret is provided,
but leaving it empty is allowed. This supports native-only Apple sign-in
configurations.

## Additional context

The validation was simplified from two `.when` clauses (dependent on
both `ENABLED` and `CLIENT_ID`) to a single `.when` (dependent only on
`ENABLED`), matching the pattern used by the Google provider.
2026-04-02 15:17:12 +02:00
Cemal Kılıç ca5f8d66f1 fix(studio): show legacy API keys toggle for project-level admins (#44382)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## Summary

- Fix `ToggleLegacyApiKeysPanel` being permanently hidden for users with
project-level admin access but no org-level access
- The `useAuthorizedAppsQuery` calls an org-level endpoint
(`/platform/organizations/{slug}/oauth/apps`) which returns 403 for
project-only admins, causing `isAuthorizedAppsSuccess` to never become
`true` and
  the entire panel to never render
- When the authorized apps query fails, show a fallback warning
directing users to verify their org's OAuth apps before disabling legacy
keys

  ## What changed

- Removed `isAuthorizedAppsSuccess` from the rendering guard, the panel
now renders once legacy keys status and permissions resolve
- When the authorized apps query errors (e.g. 403), the button still
opens a warning dialog with appropriate copy before proceeding to the
confirmation modal

  ## Behavior

  | User type | Authorized apps query | Button click |
  |---|---|---|
| Org-level access, has apps | Success, apps > 0 | Warning → confirm
modal |
| Org-level access, no apps | Success, apps = 0 | Confirm modal directly
|
  | Project-only admin | 403 error | Fallback warning → confirm modal |

## Current behavior


<img width="1461" height="707" alt="image-IcxHfCX0"
src="https://github.com/user-attachments/assets/2fd124cd-02eb-46c0-816e-178fe3ce99b0"
/>

Project admins can't view the button

## Changed behaaviour

<img width="1455" height="704" alt="image-YW1k6GQe"
src="https://github.com/user-attachments/assets/8c428c63-f1de-4b84-a1f2-6af7ff064e50"
/>


Projects admins can view the disable button and when clicked views a
warning about oauth apps:

<img width="451" height="250" alt="image-yu4bux3l"
src="https://github.com/user-attachments/assets/5a314329-350b-4207-b8e4-311d0c827e6f"
/>

and when they visit oauth apps, there is warning to contact with project
owner

<img width="1453" height="578" alt="image-pppzfksn"
src="https://github.com/user-attachments/assets/489ba3ba-c94e-4efb-923b-a989eebb2fc4"
/>
2026-04-02 15:16:21 +02:00
Ali Waseem db281bd1d1 feat: alert in Slack when master breaks (#44456)
## Summary
- Adds a new GitHub Actions workflow that sends a Slack alert when
Studio E2E tests or unit tests fail on master
- Uses `workflow_run` trigger so no changes needed to existing CI
workflows
- Reuses the existing `SLACK_DASHBOARD_WEBHOOK_URL` secret

Closes FE-2883

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Implemented automated Slack notifications to alert when master branch
build failures occur, including build run details, commit information,
and commit author.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 07:16:06 -06:00
Charis c372e77c8b feat: introduce safeSql function to pg-meta (#44467)
* **New Features**
* Added new SQL formatting utilities including keyword validation and
safe SQL composition functions
* Introduced type-safe SQL fragment handling with branded types to
prevent SQL injection vulnerabilities
* Expanded available exports for improved code organization and
accessibility
* Enhanced SQL query building capabilities with improved validation and
composition support
2026-04-02 08:54:25 -04:00
Ivan Vasilov 52e670e7b0 chore: Bump next version for ui-library and design-system (#41313)
This PR changes the `next` version in the main catalog which switches
`design-system` and `ui-library` apps to next v16.
2026-04-02 14:43:40 +02:00
Dimitrios Liappis 6dded5753f chore(docs): add Dimitrios Liappis to humans.txt (#44483)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update to `humans.txt` to add `Dimitrios Liappis`

## What is the current behavior?

`Dimitrios Liappis` does not exist in `humans.txt`

## What is the new behavior?

`Dimitrios Liappis` exists in `humans.txt`


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated contributor information.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 14:54:41 +03:00
Ivan Vasilov 681f0db4f2 feat: Add an app lite studio (#44272)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **New Features**
* Introduced new Lite Studio application with project management
dashboard
  * Added project overview page with status monitoring and quick actions
  * Added database browser and project settings management interfaces

* **Chores**
  * Added Docker support for containerized deployment
  * Added comprehensive project documentation
  * Updated workspace configuration

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 09:51:59 +02:00
Danny White 3a72b128de chore(studio): standardise key-value field array partial-row validation (#44411)
## What kind of change does this PR introduce?

Design system and validation consistency update.

## What is the current behaviour?

`KeyValueFieldArray` already renders per-cell form messages, but each
consumer still decides its own validation rules. At the moment, some
consumers allow partially filled rows to submit silently, while Log
Drains now treats them as inline validation errors.

## What is the new behaviour?

This PR standardises the recommended partial-row behaviour for the
current `KeyValueFieldArray` consumers by introducing a shared
validation helper and using it from each form schema.

- adds `getKeyValueFieldArrayValidationIssues` alongside
`KeyValueFieldArray`
- keeps `KeyValueFieldArray` presentation-only and leaves validation in
consumer schemas
- shows inline errors when one side of a key/value row is filled and the
other is empty
- keeps fully empty rows as draft rows
- keeps duplicate-key validation in Log Drains, where it already applies
- updates the design-system docs and examples to describe the validation
pattern explicitly


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added reusable key/value validation utilities and public export; forms
now trim header/key/value inputs, show inline errors for partially
filled rows, and remove fully empty draft rows on submit.

* **Documentation**
* Clarified the field-array is rendering-only and added guidance for
placing validation in form schemas and handling draft rows.

* **Tests**
* Added unit and integration tests covering validation rules, duplicate
keys, trimming, draft-row stripping, and payload behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 12:49:25 +11:00
Danny White 16308ad286 chore(studio): reuse key-value field array for log drains (#44060)
## What kind of change does this PR introduce?

Chore that resolves FE-2785.

## What is the current behavior?

The Log Drains headers section still uses a bespoke add-header mini form
and stores headers directly as a record in form state.

That makes it inconsistent with the shared `KeyValueFieldArray` pattern
already adopted elsewhere in Studio.

## What is the new behavior?

- reuses the shared `KeyValueFieldArray` in the Log Drains destination
sheet
- keeps the external submit contract unchanged by converting between:
  - form-only `headerEntries: { key, value }[]`
  - submitted `headers: Record<string, string>`
- preserves type-specific defaults:
  - webhook starts with `Content-Type: application/json`
  - OTLP starts with `Content-Type: application/x-protobuf`
- moves header validation into standard form errors for:
  - max 20 headers
  - duplicate header names
  - partially filled rows, while still allowing fully empty draft rows
- adds focused utility and sheet tests for the new adapter and
validation behaviour

| Before | After |
| --- | --- |
| <img width="1728" height="997" alt="Log Drains Settings Mallet
Toolshed Supabase-027E4669-8B02-4C43-8771-794E13799FA3"
src="https://github.com/user-attachments/assets/43ed6334-28ef-4d47-9747-dfb3221462ec"
/> | <img width="1728" height="997" alt="Log Drains Settings Mallet
Toolshed Supabase-68477EA1-6F56-4BE2-9355-C121896F11E4"
src="https://github.com/user-attachments/assets/9391bccd-3a50-4468-91e7-05059d41543c"
/> |

## Additional context

This is PR 4 of the DEPR-394 field-array stack.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Bug Fixes**
* Enhanced header validation with specific error messages for duplicate
headers and missing values.
  * Improved form behavior for edge cases in header entry management.

* **New Features**
* Added destination-specific default headers for clearer initial
configuration.

* **Tests**
* Added comprehensive test suite validating header management and form
submission behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-02 11:14:34 +11:00
Danny White 73692b0a4d feat(studio): add stuck pausing and restoring escalations (#43368)
## What kind of change does this PR introduce?

Bug fix / UX improvement for long-running project transitions. Resolves
DEPR-362.

## What is the current behaviour?

- `PausingState` does not preserve elapsed time across refreshes, so the
stuck escalation can disappear for the same user.
- `RestoringState` relies on weaker frontend heuristics and always
showed a support CTA in the footer even before the restore was clearly
long-running.

## What is the new behaviour?

- `PausingState`
- Persists a per-project pause start time in local storage so the stuck
CTA survives refreshes in the same browser.
  - Escalates after 10 minutes.
  - Clears the stored timer when pausing succeeds or fails.

- `RestoringState`
- Persists a per-project restore start time in local storage so the
stuck CTA survives refreshes in the same browser.
- Removes the always-visible footer CTA and only escalates once
restoration is genuinely long-running.
- Computes the long-running threshold from volume size using a shared
restore estimate: `max(10, ceil(estimateRestoreTime(sizeGb) * 1.5))`.
  - Clears the stored timer when restoration succeeds or fails.

- Shared changes
- Extracts reusable transition timing helpers and restore estimate
helpers with unit tests.
- Reuses the same restore estimate formula for branch restore timing and
restore escalation, so the two do not drift.

| `PausingState` | `RestoringState` |
| --- | --- |
| <img width="1570" height="906" alt="Krosno Toolshed
Supabase-C6D7E29F-C38D-43E1-8AF9-C612B6A2FD8D"
src="https://github.com/user-attachments/assets/e0bd9434-09b6-4cf6-bffa-07a0ddcdf5db"
/> | <img width="1570" height="906" alt="Krosno Toolshed
Supabase-51F4763D-B798-4B41-A92D-43B3CF8ECDAF"
src="https://github.com/user-attachments/assets/d0e47356-dcc3-42aa-b602-802a35249a16"
/> |

## Additional context

- This PR intentionally stays frontend-only.
- We are not exposing backend lifecycle timestamps here; local storage
is the stopgap to improve the same-browser experience now.
- If you need to test the frontend blocker states locally, use
[`dnywh/chore/depr-362-blocker-preview-mocks`](https://github.com/supabase/supabase/tree/dnywh/chore/depr-362-blocker-preview-mocks)
and append one of the following query params to a project URL:
  - `?mockProjectBlockingState=pausing`
  - `?mockProjectBlockingState=pausing-long-running`
  - `?mockProjectBlockingState=restoring`
  - `?mockProjectBlockingState=restoring-long-running`
- I know these two views are quite differently stylistically, and will
consolidate later
  - References DEPR-434
2026-04-02 11:09:18 +11:00
Nedunchezhiyan-MandClaude Sonnet 4.6 6cca908e5b fix(studio): escape SQL literals in queue message queries (#44451)
## What

Escapes user-controlled string values before interpolating them into SQL
in `apps/studio/data/database-queues/`.

## Why

Several queue message queries were constructing SQL via direct string
interpolation without sanitization:

| File | Value | Risk |
|------|-------|------|
| `database-queue-messages-send-mutation.ts` | `payload` | **High** —
arbitrary user-provided JSON; a single quote breaks the query and a
crafted payload could execute arbitrary SQL |
| `database-queue-messages-infinite-query.ts` | `afterTimestamp` |
Medium — sourced from a previous DB result, but still unsafe to
interpolate |
| `database-queue-messages-delete-mutation.ts` | `messageId` | Low —
typed `number`, but truncated for safety |
| `database-queue-messages-archive-mutation.ts` | `messageId` | Low —
same as above |

## Fix

- Escape string literals with the standard PostgreSQL approach (doubling
single quotes `'` → `''`) before interpolation
- Wrap numeric `messageId` values with `Math.trunc()` to prevent
floating-point edge cases
- `queueName` was already validated via `isQueueNameValid` regex
(alphanumeric/underscore/hyphen only) — no change needed

Fixes #44375

## Test plan

- [x] Open Queue Messages panel in Studio
- [x] Send a message with a payload containing single quotes (e.g.
`{"key": "it's a value"}`) — verify it sends without error
- [x] Verify pagination still works correctly after fix

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved safety of queue operations by ensuring message IDs, payloads,
timestamps, and queue names are handled securely to prevent injection
and formatting issues.
* Normalized numeric message fields (IDs/delays) for consistent
processing.
* Increased stability and correctness of archive, delete, query, and
send operations; no public APIs were changed.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-01 17:29:11 -04:00
Sean Oliver 273102323d feat(growth): filter OAuth/SSO redirect referrers from attribution (#44405)
## Problem

GitHub OAuth redirects and Google SSO set the browser's Referer header
to their domain when redirecting back to supabase.com. Our attribution
pipeline treats these as genuine referral traffic, inflating the
`github` channel by ~20K orgs/week. The internal referrer fix
(GROWTH-647) surfaced this by reducing `unknown-internal` — it didn't
cause the issue, it revealed OAuth noise that was previously hidden.

## What happened

When users sign in with GitHub, the browser sends `Referer:
https://github.com/`. GitHub's login pages use
`origin-when-cross-origin` Referrer-Policy, which strips the path. So
OAuth redirects arrive as bare `github.com/` — indistinguishable from a
direct visit to github.com. Meanwhile, genuine GitHub referrals from
repos/READMEs always include the full path because those pages use
`no-referrer-when-downgrade`.

We validated against `mart_marketing_organization_attribution`: 98.5% of
GitHub-attributed orgs have bare `github.com/` as the referrer. Only
~250/week have specific paths (genuine referrals).

## Changes

- Added `isOAuthRedirectReferrer()` to `first-referrer-cookie.ts` —
identifies auth provider redirects:
  - `accounts.google.com` blocked entirely (dedicated SSO subdomain)
  - Bare `github.com/` blocked (OAuth redirect signature)
- `github.com/<specific-path>` preserved (genuine repo/README referrals)
- Wired into `shouldRefreshCookie()` so OAuth referrers never get
stamped into cookies
- Wired into `handlePageTelemetry()` referrer overrides as
defense-in-depth
- 17 new tests covering all OAuth patterns and edge cases

## Testing

All 52 tests pass. New tests cover Google SSO (bare + with path), GitHub
bare domain (with/without trailing slash), genuine GitHub referrals
(repo, README, discussion, blob), explicit OAuth path, non-OAuth
domains, empty/malformed URLs. Verified TDD — tests failed red before
implementation, green after.

Companion dbt PR in data-engineering handles historical data.

GROWTH-732
2026-04-01 11:25:39 -07:00
Ali WaseemandJoshen Lim 91a8d59e43 chore: add unit test for regression of webhooks (#44409)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

We had some bugs where webhooks were not able to be turned on for
projects. This is to ensure that doesn't happen again

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Tests**
* Added UI tests for integration overview and installation flows: verify
action enablement/disablement (aria-disabled and visual opacity)
depending on required extensions, ensure the "Install integration"
button is disabled when no installation command or required extensions
are missing, and confirm the installation command is invoked (without
executing SQL) when appropriate.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-04-01 11:52:30 -06:00
Greg Richardson 38d012a232 feat: link repo in supabase.sh post (#44449)
Adds a link to the [OSS
repo](https://github.com/supabase-community/supabase-ssh) in the
supabase.sh blog post.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Updated blog post with refined introductory messaging
* Redirected community feedback links to the open-source repository for
issue reporting
* Added repository information to facilitate user access and
contributions

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-01 10:50:45 -06:00
Andrey A. b34d8e6609 add routes for saml sso to self-hosted proxy configs (#44440) 2026-04-01 18:18:50 +02:00
Andrey A. 26880c4b9b chore: add cli to codeowners for ./docker (#44446)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

dev-workflows => cli


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated code ownership configuration for Docker-related files.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-01 18:03:51 +02:00
Gildas GarciaandCopilot 875216d485 chore: update legacy jwt settings form to use react-hook-form (#44179)
## Problem

- The legacy jwt settings still uses `formik` and we want to remove it
in favour of `react-hook-form` to keep only one form library
- The legacy jwt settings does not follow the design system guidelines

## Solution

- Migrate to `react-hook-form`
- Apply the design system guidelines

## How to test

To test the custom JWT secret, I haven't found a better way than
inverting the condition at L337 (`!legacyKey` to `legacyKey`). This
allowed me to ensure the process worked at least up to the API call
which fails with my local instance as legacy tokens aren't supported
anymore.

## Screenshots

Before:
<img width="1199" height="599" alt="image"
src="https://github.com/user-attachments/assets/1c6e0bb1-0698-4238-847f-d2c72adf3462"
/>

After:
<img width="1228" height="646" alt="image"
src="https://github.com/user-attachments/assets/3b2a45a9-aa43-4c3e-9653-2b2610616889"
/>

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-04-01 17:56:03 +02:00
Charis 180ce515f6 style: require @ imports and sort imports for studio/hooks (#44444)
* **Chores**
* Updated internal module import paths across hook files to use
standardized path aliases for improved code consistency and
maintainability.
2026-04-01 11:48:02 -04:00
Ali Waseem a2229d84b0 test(studio): add E2E integration tests for queues (#44398)
## Summary
- Adds 6 Playwright E2E tests for queue integration: view page, create
basic queue, create unlogged queue, delete queue, purge messages, and
send test message
- Adds `aria-label` to icon-only Purge and Delete buttons in
`QueueTab.tsx` for reliable test selectors
- Follows existing `cron-jobs.spec.ts` patterns for setup/teardown and
API helpers

## Test plan
- [x] All 6 queue integration tests pass locally against self-hosted
Supabase
- [x] Tests run stably in parallel (3 workers)
- [x] Cleanup via `withSetupCleanup` ensures no leftover test queues
2026-04-01 09:02:41 -06:00
Jordi EnricandClaude Sonnet 4.6 9c5fabcc7b fix(project-list): remove duplicate resource exhaustion badge DEBUG-48 (#44174)
## Problem

Project cards on the home page showed resource exhaustion warnings
twice: once as a badge in the card header, and again as an alert in the
card footer. This created a confusing, redundant UI as seen when a
project has disk IO, CPU, or other resource warnings active.

## Fix

Removed `resourceWarnings` from the footer `ProjectCardStatus` render in
`ProjectCard.tsx`. Resource exhaustion state now only appears as the
header badge (which already shows a tooltip with the description on
hover). Project status indicators such as paused or restarting still
appear in the footer since those do not depend on resource warnings.

Also removed the dead `showResourceExhaustionWarnings = false` flag from
`ProjectCardStatus.tsx`, which was hardcoded to false and only gated
description text that was no longer reachable.

## How to test

- Navigate to the org home page with a project that has an active
resource warning (disk IO, disk space, CPU, memory, or read-only mode).
- Confirm the warning badge appears in the card header with the correct
color (warning or critical).
- Confirm no duplicate alert appears in the card footer area.
- Confirm that paused or restarting projects still show the status alert
in the footer.
- Confirm the table view still shows the badge correctly in the status
column.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

**Style**
- Project status information now displays exclusively in the project
card footer, removing redundant header display for a cleaner interface.
- Simplified resource warning notification logic for more consistent and
straightforward warning presentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-01 17:01:04 +02:00
Greg Richardson c5f524800c Blog: supabase.sh (#44419)
Adds blog post for supabase.sh.

## Preview

https://zone-www-dot-com-git-blog-supabase-ssh-supabase.vercel.app/blog/supabase-docs-over-ssh

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a new blog post, "Supabase docs over SSH," describing SSH-based
browsing of Supabase docs, agent setup commands, and navigation tips.
* Updated the site RSS feed to include the new post and refreshed the
feed build date.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-01 08:59:53 -06:00