Commit Graph
38857 Commits
Author SHA1 Message Date
Miranda Limonczenko 2d3cd78207 docs(functions): correct the auth guide's content listing entry
The entry called the page "With supabase-js" and described it as using the
Supabase client inside an Edge Function. The page covers @supabase/server
and which credentials a function accepts. Match the page's own title.
2026-09-30 14:36:09 -07:00
Miranda Limonczenko 7df1b930fc docs(functions): regroup the Edge Function auth guide by information type
Group the page's seven flat sections into three, so the top level fits the
5 +/- 1 chunking limit and the action path runs uninterrupted.

- Open with a concept group, Choose an auth mode, holding the mode table
- Gather the six patterns under Secure your function
- Keep Environment variables last as the fact group
- Add an intro outline linking the three groups, and a group introduction
- Move the Authorization headers link below the mode table, so the table's
  introduction sits next to the table

Every heading text is unchanged, so every slug is preserved and the
in-page link to External webhooks still resolves.
2026-09-30 14:36:09 -07:00
Miranda Limonczenko 19188ece58 docs(functions): style pass on the Edge Function auth guide (#50884)
Apply the docs style guide to Securing Edge Functions. Inline changes only.

- Open the page with a value statement
- Split the sentences that ran past the 26-word aim, and keep one
  relationship per sentence
- Replace dash-bounded asides with separate sentences
- Lift `(the default)` out of parentheses so it reads as a claim
- Name the section instead of "above" and "the sections below"
- Introduce the mode table in the sentence before it
- Raise the `auth: 'none'` admonition to `danger`, and state it in the
  positive form
- Stop restating that admonition in the Public functions section
- Spell out Row Level Security, and name `@supabase/server` rather than
  "the SDK"
- Use Supabase Dashboard and Supabase Platform consistently
- Use "function" rather than "endpoint", and spell out "db"
- Link `@supabase/server` once, and name it as a GitHub destination
- Rewrite the Secret keys alt text to describe both rows, the column
  headers, and the masked key format
2026-09-30 14:36:05 -07:00
Jeremias Menichelli 99103b3571 feat: Add edge function and hooks for search V2 (#51103) 2026-09-30 18:12:07 -03:00
salmanrf 8696762b4b fix(www): keep committed agent-skills index when fetch fails outside production (#50556)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (build resilience)

## What is the current behavior?

`apps/www/scripts/fetchAgentSkills.mjs` runs as part of `content:build`
and fails the whole `www` build (and `pnpm dev:www`) whenever the GitHub
API call fails. #50106 added `AGENT_SKILLS_GITHUB_TOKEN` to mitigate
rate limits on Vercel, but that does not cover local runs or builds
where the env var is not available (e.g. fork PRs).

Example from a local `pnpm dev:www` hitting the unauthenticated rate
limit:

```
www:dev: Error: GET https://api.github.com/repos/supabase/agent-skills/releases/latest → 403
www:dev: at fetchJson (file:///.../apps/www/scripts/fetchAgentSkills.mjs:38:22)
www:dev: at process.processTicksAndRejections (node:internal/process/task_queues:105:5)
www:dev: at async main (file:///.../apps/www/scripts/fetchAgentSkills.mjs:53:19)
```

## What is the new behavior?

`public/.well-known/agent-skills/index.json` is already committed to the
repo, so when the fetch fails and `VERCEL_ENV` is not `production`, the
script logs the error, keeps the committed file, and exits 0:

```
www:dev: Error: GET https://api.github.com/repos/supabase/agent-skills/releases/latest → 403
www:dev: ...
www:dev: Fetch failed — keeping committed public/.well-known/agent-skills/index.json
```

Production builds still fail loudly so a stale skills list is never
silently shipped.

Verified locally by forcing a 401 with a bad token:

- `VERCEL_ENV=preview` exits 0 and keeps the committed `index.json`
- `VERCEL_ENV=production` exits 1

## Additional context

Follow-up to #50106.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
  * Improved handling of skill data fetch failures outside production.
* Preserves previously available skill data when a fetch fails and a
committed fallback is available.
  * Continues to report failures when no fallback data exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 11:11:39 -07:00
Andrew ValleteauandClaude 2cb70302b0 docs(cli): recommend OrbStack as primary Docker alternative on macOS (#51101)
## Problem

The documentation currently lists Docker Desktop as the preferred option
for all platforms, but OrbStack is a superior alternative on macOS that
offers better performance (faster startup, lower CPU/memory/disk usage).
Users on macOS should be guided toward OrbStack first.

## Solution

Reordered and updated the container runtime recommendations to:
1. Highlight OrbStack as the recommended option specifically for macOS
2. Position Docker Desktop as the recommended option for Windows and
Linux
3. Moved OrbStack higher in the list to reflect its priority on macOS
4. Added a dedicated paragraph in the CLI getting started guide
explaining OrbStack's benefits and why it's recommended over Docker
Desktop on macOS

The changes improve the developer experience by directing macOS users
toward the more performant option while maintaining clear guidance for
other platforms.

## Review instructions

1. Open the preview links for the modified documentation pages
2. Verify that OrbStack is now listed first and marked as "recommended
on macOS"
3. Verify that Docker Desktop is now marked as "recommended on Windows
and Linux"
4. Check the CLI getting started guide to confirm the new paragraph
about OrbStack's benefits is clear and helpful
5. Ensure the information is consistent across both modified files

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] Documentation changes follow the docs style guide

https://claude.ai/code/session_01Nbp9LwhMkqxEvQJzEVUbwt

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated local development guidance to recommend OrbStack for macOS and
Docker Desktop for Windows and Linux.
* Clarified that OrbStack supports extended file attributes on mounted
volumes and container networking, and added startup and resource-use
comparisons with Docker Desktop.
* Listed Rancher Desktop and Podman as alternatives; the CLI guide also
lists Colima.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-30 17:04:49 +00:00
supabase-supabase-autofixer[bot]andzamotany e54394cfd8 feat: update mgmt api docs (#49743)
This PR updates Management API docs automatically.

This regenerates:

- Management API specs and sections
- Personal Access Tokens permission-to-endpoint table
- Personal Access Tokens MCP tool permissions table

Sources include the live Management API specs, MCP permission map,
and Studio's shared permission catalog.

Co-authored-by: zamotany <17573635+zamotany@users.noreply.github.com>
2026-09-30 18:34:09 +02:00
Kody Jackson c44d053aec [KB] fix: update header positioning values for KB (#51096)
## Problem

z-index issue for the KB `Topics` dropdown on the main page, where it
would get hidden behind other elements on the screen.

## Solution

Update z-index values

## Preview links


[Preview](https://kb-git-fix-kb-header-positioning-supabase.vercel.app/kb)
[Prod](https://supabase.com/kb/)

## Additional context

**Before**


https://github.com/user-attachments/assets/61216776-166a-41f9-b1b0-7b2e734ff229

**After**


https://github.com/user-attachments/assets/0c15855d-fac5-4d55-b403-b091fb48e178

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. Open the live and preview links side-by-side.
2. Expand the `Topics` dropdown and see whether or not it's covered.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated header and navigation menu layering to improve visibility when
elements overlap.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 11:20:53 -05:00
samroseandArtur Zakirov 9946747579 docs(orioledb): update OrioleDB docs for public beta (#50813)
> [!IMPORTANT]
> Don't merge until the OrioleDB public beta launches. Docs deploy on
merge.

## What

Updates the OrioleDB guide (`guides/database/orioledb`) for the public
beta:

- States that OrioleDB is in public beta and that OrioleDB projects have
access to the same paid features as other Supabase projects.
- Replaces the outdated "choose `OrioleDB Public Alpha` Postgres
version" instruction and its screenshot with text steps that match the
current project creation form (**Advanced Configuration** → **Postgres
Type** → **Postgres with OrioleDB**). It also notes that OrioleDB can't
be added to or removed from an existing project. A new screenshot will
follow once the dashboard shows the beta labels.
- Corrects the `orioledb.default_compress` range to `-1` to `22`. Values
outside that range are rejected.
- Updates the `EXPLAIN` output for the primary key lookup to match what
OrioleDB returns (`Custom Scan (o_scan)`).
- Replaces the benchmark chart's alt text with a description of the
chart.

Headings, frontmatter, and navigation are unchanged, so existing links
to this page and its sections still work.

## Checked against upstream OrioleDB

Checked the page's claims against the [OrioleDB
docs](https://github.com/orioledb/orioledb/tree/main/doc/usage) and
codebase on `main`:

- The concepts section, the `orioledb.serializable` values, and the
compression settings match.
- The limitations link still resolves (`#current-limitations`).
- Doc changes on `main` since beta17 (collations, sparse files,
concurrent unique bridged indexes) don't affect claims on this page.

## Verification (`/test-the-docs`)

| Snippet / step | Class | Sandbox | Result | Notes |
| --- | --- | --- | --- | --- |
| `create table blog_post …` | runnable-local | DinD + runner,
`supabase/postgres:17.9.0.028-orioledb` | pass | Table created with the
`orioledb` access method (default) |
| `create index …` (2 indexes) | runnable-with-setup | same | pass | |
| `insert …` + `select …` | runnable-with-setup | same | pass |
Timestamp differs, as expected |
| `explain` (3 statements) | runnable-with-setup | same | pass | Primary
key lookup output updated in this PR to match |
| `select … from pg_settings where name like 'orioledb.%'` |
runnable-local | same | pass | All 10 automatically tuned settings
present |
| `alter database … default_compress to 1` | runnable-local | same |
pass | |
| Compression range `-1`–`22` | claim check | same | pass | `23`
rejected: "outside the valid range (-1 .. 22)" |
| User-configurable settings have `user` context | claim check | same |
pass | `serializable` values match the page |
| Hidden `ctid` key when no primary key is defined | claim check | same
| pass | |
| HNSW index via index bridging | claim check | same | fail (product
bug) | Index misses rows inserted after it's created. Known upstream as
orioledb/orioledb#1118, fixed after beta17. The tested image bundles an
earlier OrioleDB release. Re-test on an image with beta18 before
merging. |
| Dashboard project creation steps | deferred | — | deferred | Needs a
hosted project; labels checked against Studio source |

**Tier A path:** every SQL block on the page, run in page order against
the Supabase OrioleDB image.

**Environment:** Docker 29.4.0 (linux/aarch64); compose sandbox from
`test-the-docs`; all SQL run inside the runner container.

**Build:** `pnpm build:guides-markdown` passes; the generated markdown
for this page includes all changes.

## Self-review

**Blockers:** none.

**Before merging:**

- [ ] Re-run the HNSW check on an image with OrioleDB beta18.
- [ ] Re-check the page against the `beta18` tag once it's published.

**Nits left for a follow-up (existing text, outside this PR's scope):**

- The page spells `pg_vector`; the extension is `pgvector`.
- Index support is described twice, in the top note and again under
"Creating indexes".
- The markdown export (`internals/markdown-schema/Admonition.ts`) drops
admonition titles on every page. This PR avoids relying on a title for
the beta status.

Linear: DOCS-1399

🤖 Generated with [Claude Code](https://claude.com/claude-code)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the OrioleDB guide with benchmark results for an 8xlarge
instance, including a 1.8x speedup and throughput data across 32–256
connections.
* Clarified that OrioleDB projects have access to the same paid features
as other Supabase projects, and added guidance to review its
limitations.
* Updated project setup instructions, noting that OrioleDB must be
selected when creating a project and cannot be added later or removed.
* Revised the query plan example and documented compression levels from
`0` through `22`.
* **Product Updates**
  * Updated OrioleDB’s availability stage to public beta.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Artur Zakirov <zaartur@gmail.com>
2026-09-30 11:42:21 -04:00
Artur Zakirov bd9a0ff4e6 feat(orioledb): rename orioledb from Public Alpha to Public Beta in dashboard (#50975)
## Problem

We need to rename orioledb in Dashboard.

## Solution

- Update Studio copy/badges referencing OrioleDB from "Public Alpha" to
"Public Beta" (project creation advanced config, restore-to-new-project,
PITR empty state)
- Remove the scheduled-backups block that hid backups for OrioleDB
projects — OrioleDB now has WAL-G scheduled backups in beta, so that
page should behave normally. PITR keeps its existing guard since PITR is
not yet supported for OrioleDB.
- Update the `useOrioleDb` telemetry property doc-comment to reflect the
beta status
- Update project-creation wizard test expectations/fixtures accordingly
(`release_channel: 'beta'`)

Marketing (`apps/www`) and docs (`apps/docs`) references to OrioleDB
alpha status are being updated separately.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* OrioleDB is now labeled as being in public beta rather than public
alpha, and project creation selects the beta release channel.
* Restore-to-new-project and Point-in-Time Recovery notices clarify that
these features are unavailable for OrioleDB projects.
* OrioleDB projects now follow the standard eligibility checks and page
flow for scheduled backups.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:39:41 +02:00
Paweł Gulbinowiczandcoderabbitai[bot] 032c71c5bf fix(docs): use summary instead of slug for webhooks api spec (#51088)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Operations names for webhooks in Organizations webhooks and Project
webhooks use titles derived from slug, which produces wrong/incoherent
titles, for example: `Organizations slug webhooks deliveries id get`.

## What is the new behavior?

For Organizations webhooks and Project webhooks use `summary` from the
OpenAPI spec as the title instead of deriving it from the operation id.

## Additional context

Once this PR is merged, an _Update Mgmt Api Docs_ workflow needs to be
run to regenerate the sections and the spec.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Management API documentation section titles for organization and
project operations now use the OpenAPI summary when one is available. If
no summary is provided, the title falls back to the existing name-based
format. Titles for other operations continue to use the existing format,
so their presentation is unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-09-30 17:25:17 +02:00
Kevin Webb 525c1de326 chore: Add Kevin Webb to humans.txt (#51093)
## Problem

Kevin Webb joined team and needs to add name to humans.txt as part of
onboarding

## Solution

Edited humans.txt and added Kevin Webb 

## Review instructions

Confirm name is correctly alphabetized.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the team listing to include Kevin Webb, keeping the published
team information current. This change is visible in the project’s public
documentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 14:39:01 +00:00
Katerina Skroumpelou 2013ebf417 docs: drop alpha labels and pin server and middleware imports to a major (#51031)
## Problem

`@supabase/middleware` ships as 1.0.0. The docs still label the
`pipeline` entry form of `withSupabase` alpha, and several snippets
import `npm:@supabase/server` and `npm:@supabase/middleware` with no
version or with a `^0.5.0` pin. A snippet without a version leaves
readers and tools to guess one, and a guessed version fails on deploy.

## Solution

- Removes the alpha wording from the middleware reference intro and
usage examples, the server frameworks partial, and the Bring your own
MCP guide. The `@supabase/server` 1.6.0 floor stays.
- Pins every `npm:@supabase/server` and `npm:@supabase/middleware`
import in the guides to a major range, `@1`, following the
`npm:@supabase/supabase-js@2` convention in Managing dependencies.
- Bumps the authenticated-mcp-server example to middleware `^1.0.0` and
server `^1.9.0`.

~~Blocked by supabase/middleware#49. The `@1` range resolves once 1.0.0
is on npm.~~




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated authentication, API key, and MCP examples to use versioned
Supabase server and middleware packages.
* Clarified that pipeline and nested composition behave the same, and
that both require `@supabase/server` 1.6.0 or later.
* Removed alpha-status labels from `withSupabase` guidance while
retaining the 1.6.0 minimum-version requirement.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:27:44 +03:00
mkaruzaandmkaruza b59447d310 chore: Add Mario Karuza to humans.txt (#50710)
## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

humans.txt doesn't list my name.

## What is the new behavior?

Add to humans.txt

## Additional context

Done as part of the onboarding tasks.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the public team information to include Mario Karuza. The
listed team members now reflect this addition.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: mkaruza <mkaruza@users.noreply.github.com>
2026-09-30 16:02:12 +02:00
Andrey A. e811d984ad docs(auth): inline the Remix code in the OAuth troubleshooting (#50854) 2026-09-30 07:44:50 -06:00
Tanun Turbo Chalermsinsuwan cd305313e4 fix(roles): Show only document-defined roles (#51087)
## Problem

As part of having `None / No Access` available to customers, we need to
start providing this role entry in `/platform/organization/:ref/roles`
endpoint. However, when making it available, the role will show up
prematurely on all the components that relies on
`useOrganizationRolesV2Query` function.

## Solution

This change is to allow us to test the behavior of the new role without
having to turn the API on/off. The UI will show only the "predefined"
entries and ignore the "extras" sent by API.

After this is merged, we will do the following

1. Unhide the None role from the API
https://github.com/supabase/platform/pull/39137 -- this will not have
any effect on the frontend as we already ignore it in this PR
2. Work and continue testing on
https://github.com/supabase/supabase/pull/50922 -- which will be easier
to verify as we no longer need to change the API side

## Review instructions

1. Modify the items in the `FIXED_ROLE_ORDER` list, remove some roles
from there
2. You will see that the role will disappear from the components like
the invitation form or managed access form.



## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Bug Fixes**
* Organization role lists now show only supported roles, in the expected
order. Roles outside the supported set are no longer displayed. This
keeps the list consistent and focused on recognized roles, making
available organization roles easier to review.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 20:40:42 +07:00
Ivan Vasilov ec6be68356 chore: Bump vulnerable deps (#50901)
This PR bumps the vulnerable dependencies `devalue`, `mermaid`,
`@faker-js/faker`, `brace-expansion`, `undici`, `fast-uri` and
`markdown-it`.

It also dedupes `rolldown`, `vite` and various `react-router` deps.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated development and build tooling for Lite Studio, Studio, and the
Vue block, along with tooling used in automated Studio checks. These
changes do not alter app features or workflows, and no new user-facing
capabilities or behavior changes are included. They are limited to the
project’s underlying development setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 14:53:28 +02:00
Luiz Felipe Machado ff80bb1499 feat(self-hosted): function worker retries (#50618) 2026-09-30 13:15:41 +02:00
Luiz Felipe Machado 3fc8af387e feat(self-hosted): add function runtime errors (#50589) 2026-09-30 12:57:27 +02:00
Kamil Ogórek c5b4fbfa11 fix: Handle NO_PROJECT_MARKER for projectRef (#51083)
Skip `NO_PROJECT_MARKER` values for projectRef in API validation.
2026-09-30 10:34:26 +00:00
Andrey A. c8b665caf2 feat(self-hosted): add api gateway logic for functions (#46810) 2026-09-30 11:14:47 +02:00
Saxon FletcherandClaude Opus 5.5 904e3c4aa0 chore(library): remove the Supabase files caption from block previews (#51077)
## Problem

The Files tab on block previews showed a "Supabase files." caption row
between the tabs and the file viewer. It doesn't add anything useful and
takes space from the code.

## Solution

Remove the caption row and render the file viewer directly in the tab
panel. The registry lookup that fed the caption is dropped from
`BlockOverview`; the markdown and agent-prompt export still lists
dependencies as before.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Interface Changes**
* Block overviews now show the generated file tree directly when file
display is enabled.
* The “Supabase files” banner and dependency details are no longer
shown, and the surrounding file layout has been removed.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 05:50:57 +00:00
Danny White 8204854986 docs(design-system): document create actions in comboboxes (#51061)
## Problem

Studio lets people create an item while selecting one, but the design
system does not document this pattern.

## Solution

Document the create action in the Combobox guide with a focused example.
The action sits below the options and leaves the current selection
unchanged. Products can connect it to their own creation flow.

| After |
| --- |
| <img width="552" height="352" alt="CleanShot 2026-09-30 at 10 57
46@2x"
src="https://github.com/user-attachments/assets/69c8069c-d4f9-45e2-b3a1-6e5431e2aff9"
/> |

## Review instructions

1. Open the design system Combobox page and find “[Create from
list](https://design-system-git-dnywh-document-select-create-action-supabase.vercel.app/design-system/docs/components/combobox#create-from-list)”.
2. Select a bucket, then choose “New bucket”. Because it’s just an
example, the selector closes without replacing the selected bucket.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a combobox example with a separate “New bucket” action. Choosing
it closes the menu without changing the current selection; choosing an
existing bucket updates the selection.
* Added documentation showing how to use this create-action pattern,
including guidance on labeling and positioning the action.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 15:40:50 +10:00
Danny White 92952bf903 fix(studio): clarify S3 access key dialogs (#51070)
## Problem

The S3 access key creation dialogs are wider than their contents, use
plural titles for one key pair, and call the name field “Description”
even though the table calls it “Name”. The save state also implies both
values disappear, although only the secret does.

## Solution

Use the small dialog size for both states. Use singular titles, label
the field “Name”, shorten the create button to “Create”, and clarify
when the secret must be copied. The API field remains `description`.

## Review instructions

1. Open a project’s **Storage > S3** page and select **New access key**.
Check the dialog width, title, Name field, and Create button.
2. Create a key and check the save dialog width, singular title, and
secret visibility guidance.

| Before | After |
| --- | --- |
| <img width="1084" height="572" alt="CleanShot 2026-09-30 at 14 37
20@2x"
src="https://github.com/user-attachments/assets/781706ee-0ecc-4535-abb5-f6ac65f02c71"
/> | <img width="844" height="584" alt="CleanShot 2026-09-30 at 14 36
56@2x"
src="https://github.com/user-attachments/assets/119df19f-2f39-4e23-94b4-26665583765c"
/> |
| <img width="1096" height="730" alt="CleanShot 2026-09-30 at 14 37
57@2x"
src="https://github.com/user-attachments/assets/00481ed7-dc05-48b9-8cbc-e76d608aa4b1"
/> | <img width="842" height="780" alt="CleanShot 2026-09-30 at 14 37
39@2x"
src="https://github.com/user-attachments/assets/8c837101-250a-474f-a0fc-cf46ce491f83"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* The credential form now labels the field “Name” and uses “Create” for
the submit button.
* Confirmation text now clarifies that the access key is bucket-wide,
bypasses RLS, and its secret is shown only once. It also refers to a
single access key instead of using S3-specific wording.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 15:21:47 +10:00
Pamela Chia 38b74af3f1 fix(studio): fall back for framework icons without an asset (#51065)
I made the connected-project framework icons fall back when no shipped
SVG exists for a framework. The three icon sites built
`/img/icons/frameworks/<framework>.svg` straight from the integration's
framework preset, which is an open-ended string. They only fell back
when the value was empty, so any preset without an asset (`express`,
`hono`, `fastapi`, `tanstack-start` and others) showed a broken image
and logged a 404.

**Changed:**
- **Broken framework icons**: `getFrameworkIconUrl` returns the asset
URL only for slugs in a set that mirrors `public/img/icons/frameworks/`.
The integration connection row, the org project linker and the
marketplace project picker now show their existing fallback icon for any
other slug. A test keeps the set equal to the directory listing.
- **Framework type**: I deleted the hand-kept `VercelFramework` union.
It listed exactly the shipped icon slugs, while the API types the field
as `string | null`, and that mismatch is what made the old empty-only
check look safe.

**Note:** I rejected an `onError` fallback because the browser still
sends the 404 request. Adding logos for common presets is left for
design.

## To test

Tested on Vercel preview (staging): no real connection there uses these
presets, so I rewrote the org integrations response in the browser to
give one integration four connections.
- [x] Open an org's Integrations page with connections whose framework
has no shipped icon (`express`, `eve`, `tanstack-start-lovable`). Expect
the fallback badge and no request under
`/dashboard/img/icons/frameworks/` for those slugs. Observed: all three
rows showed the badge and the network log had no request for their SVGs.
- [x] Same page with a `nextjs` connection. Expect its framework logo.
Observed: `nextjs.svg` loaded with a 200.
- [x] Same page with the real, unmodified response (one connection with
`framework: null`). Expect the badge, no frameworks requests, and no new
console errors. Observed: as expected.

## Linear
- fixes GROWTH-1309


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Vercel integration and project views now display framework icons when
available and fall back to the Vercel icon when no matching icon exists.
* Framework metadata now supports values beyond a fixed list, while
unsupported frameworks continue to use the fallback icon.

* **Tests**
* Added coverage for supported and unsupported framework icons,
including base-path handling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 12:59:36 +08:00
Pamela Chia 9690efeb42 fix(vault): link to current dashboard route (#51058)
I updated first-party Vault links to open the current secrets route
directly. Wrapper credentials, extension metadata, and blog posts still
linked to the retired path and relied on a redirect.

## To test

On the preview:
- [x] Inspect a Wrapper credential's Vault link. Expect
`/integrations/vault/secrets` with a `search` query for that credential.
- [x] Open the inspected target URL. Expect Vault to show the matching
secret.
- [ ] Click a Wrapper credential's Vault link. Expect the filtered Vault
view.
- [ ] Open the pgsodium extension's Vault link and a Vault blog link.
Expect `/integrations/vault/secrets` without the retired route in the
address bar.

## Linear
- fixes GROWTH-1312


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Vault secrets links now direct you to the project’s Integrations page,
including links from wrapper metadata, blog articles, and the `pgsodium`
extension listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 12:54:28 +08:00
Pamela Chia 99c6e306c7 fix(www): repair legacy reference redirects (#51059)
I repointed legacy reference redirects and first-party links to the
sections the Docs app currently serves. Old client and common-filter
URLs still targeted bare slugs, while SDK landing URLs targeted
`/start`. I preserved v1 auth destinations and linked the retired Dart
v0 migration guide to its original source.

## To test

On the www preview:
- [x] Request `/docs/client/order` with a crawler user agent. Expect a
redirect to `/docs/reference/javascript/using-modifiers-order`.
- [x] Request `/docs/common/filters/_sl` with a crawler user agent.
Expect a redirect to `/docs/reference/javascript/using-filters-rangelt`.
- [x] Request `/docs/reference/kotlin` with a crawler user agent. Expect
a redirect to `/docs/reference/kotlin/introduction`.
- [x] Open the Storage permissions section. Expect its bucket reference
link to target `/docs/reference/javascript/file-buckets-createbucket`.

## Linear
- fixes GROWTH-1293


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated links across blog posts, product pages, and feature listings
to point to current JavaScript, Flutter, and Dart documentation.
* Updated legacy documentation redirects to current reference pages,
including filter, modifier, client, and authentication guides.
* Changed reference-root redirects to lead to each language’s
introduction page.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 20:48:03 -07:00
Steven Eubank ad0ed2cdbc Update docs based on SRE Agent findings (#50910)
## Problem

SRE Agent running against a project which is read-only due to disk being
full.

## Solution

The SRE agent struggled to find the information which is now included in
this PR.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

- https://supabase.com/docs/guides/api/rest/postgrest-error-codes
- https://supabase.com/docs/guides/observability/advanced-log-filtering
- https://supabase.com/docs/guides/platform/database-size

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added guidance for recognizing platform-related PostgreSQL errors,
including read-only mode, disk exhaustion, connection-pool limits, and
database restarts or failovers.
* Added SQL queries for grouping PostgreSQL errors and reviewing recent
error events while filtering out selected platform-level codes.
* Clarified that read-write transaction settings apply only to the
current session, and that background writes resume automatically after
read-only mode ends.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 20:55:02 -05:00
Saxon FletcherandClaude Opus 5.5 a9c594a820 chore(library): rename mcp-server block to mcp (#50999)
Renames the `mcp-server` Library block to `mcp`. Installing it now
creates `supabase/functions/mcp`, so the server is served at
`/functions/v1/mcp`.

- Block, Edge Function folder, and docs page renamed
(`/docs/headless/mcp`)
- Headless App block now installs its tools into
`supabase/functions/mcp` and configures `[functions.mcp]`
- Links in the BYO MCP and MCP authentication guides updated
- Permanent redirects keep `/r/mcp-server.json` and
`/docs/headless/mcp-server` working
- `public/r` rebuilt


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* The MCP Server block is now named `mcp` across its documentation,
installation links, and setup instructions.
  * Updated function endpoints and deployment commands to use `/mcp`.
* Added permanent redirects from the previous `mcp-server` documentation
and install URLs to their new locations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 11:46:35 +10:00
Pamela Chia e0e58f8814 fix(studio): redirect moved dashboard routes (#51056)
I added permanent redirects for the moved Dashboard routes that still
send visitors to 404s. Project and organization identifiers carry
through, while the old project billing path opens the organization
picker for billing.

**Note:** The bare `/dashboard/project` path redirects straight to
Organizations instead of the `/dashboard/projects` hop named in
GROWTH-1295, since `/projects` already redirects there.

## To test

Tested on the Studio preview:
- [x] Requested the eight old Dashboard paths in GROWTH-1295 while
signed out. Each returned 308 with the specified destination.
- [ ] Request bare `/dashboard/project` while signed out on the latest
preview. Expect a single 308 to `/dashboard/organizations`.
- [x] Requested a project backup path with a query string. The
destination kept the project ref and query string.
- [x] Requested `/dashboard/project/_`. The project picker remained
reachable.

## Linear
- fixes GROWTH-1295


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Added permanent redirects for legacy Studio routes covering account
and project pages, backups, email templates, edge-function logs,
secrets, and billing settings.
* Redirects preserve incoming query parameters and URL fragments; the
project selector remains unaffected.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 23:59:31 +00:00
Danny White 68d5011514 fix(studio): hide secret visibility controls in pipeline edit forms (#51010)
## Problem

Pipeline edit forms hide stored credentials but still show visibility
controls beside their placeholders. The controls suggest that the stored
secret can be revealed.

## Solution

- Hide visibility controls in edit mode for ClickHouse, Snowflake,
DuckLake, and Analytics Bucket secret fields.
- Keep the controls available when creating a destination, with
accessible labels for the DuckLake and Analytics Bucket controls.

| Before | After |
| --- | --- |
| <img width="1024" height="196" alt="CleanShot 2026-09-29 at 16 48
56@2x"
src="https://github.com/user-attachments/assets/a9da9a32-ab17-4c07-abf3-dfa88b8c6475"
/> | <img width="1024" height="168" alt="CleanShot 2026-09-29 at 16 47
23@2x"
src="https://github.com/user-attachments/assets/fddeb880-cd23-4752-ae73-8f27348c647f"
/> |

## To test

1. Open **Database → Pipelines** and edit a destination of each type:
ClickHouse, Snowflake, DuckLake with custom parameters, and Analytics
Bucket. Check that the hidden secret fields have no eye button.
2. Start creating each destination and check that its secret fields
still offer a working visibility control.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **Improvements**
* Secret fields in replication destination forms remain masked when
editing an existing destination, and their visibility controls are
hidden. When creating a destination, supported secret fields can be
revealed.
* **Accessibility**
* Catalog-token visibility controls now use dynamic, descriptive labels.
DuckLake catalog URL and S3 secret-key reveal controls also have
descriptive labels.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:55:45 +10:00
Danny White 6b7c91a773 docs(pipelines): clarify ClickHouse setup and form copy (#51009)
## Problem

The ClickHouse destination guide leaves parts of resource setup unclear.
The pipeline form suggests the `default` ClickHouse user and database
even when a dedicated user and database are prepared.

## Solution

- Clarify the ClickHouse setup path, connection details, engine choice,
and query example in the guide.
- Align the pipeline form's labels, examples, and help text with that
setup path.
- Include **Start pipeline** in the BigQuery guide before the cost
confirmation and **Create and start pipeline**.

## Review instructions

1. Open **Database → Pipelines**, add a pipeline, and choose
**ClickHouse**. Check the endpoint label, user and database examples,
and table engine help.
2. Read the [ClickHouse destination
guide](https://supabase.com/docs/guides/database/replication/pipelines/clickhouse),
especially **Prepare ClickHouse resources** and **Configure ClickHouse
as a destination**.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the BigQuery guide to explain the pipeline validation, cost
review, and start steps.
* Expanded the ClickHouse guide with destination setup requirements,
engine behavior, and querying guidance for current-state views and
append-only history.
* **User Experience**
* Clarified ClickHouse connection field labels and descriptions,
password visibility controls, and table-engine options in the setup
form.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:44:06 +10:00
Danny White 3b1867f314 fix(studio): use neutral fallbacks for pending destination marks (#51003)
## Problem

Some Pipelines destinations should not display third-party brand marks
until their use is confirmed.

## Solution

Render neutral text monograms for destinations with pending brand marks.
Keep approved destination marks unchanged and preserve the existing
assets so they can be restored with a small configuration change.

| After |
| --- |
| <img width="1022" height="936" alt="CleanShot 2026-09-29 at 11 44
37@2x"
src="https://github.com/user-attachments/assets/d94fca61-aa02-4efb-aa78-47ada5d149d3"
/> |

## Review instructions

1. Open `/project/<ref>/database/replication`.
2. Open the destination picker and confirm destinations with pending
marks use neutral two-letter monograms.
3. Confirm the other destination marks are unchanged.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* ClickHouse and Snowflake destinations now display “CH” and “SF”
monograms instead of image marks. BigQuery and DuckLake continue to
display their image marks, while destinations without configured
branding continue to show their destination icons. These logo treatments
make the configured destination branding visible in the replication
destination interface.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:13:06 +10:00
Danny White d451bdc264 fix(studio): place pipeline arrows on horizontal edges (#50965)
## Problem

In branched Pipelines diagrams, status chips sit on the shared vertical
bend, making flow direction unclear.

- Resolves
[DEPR-689](https://linear.app/supabase/issue/DEPR-689/move-pipeline-arrows-to-horizontal-edge-segments)
- Resolves duplicate
[PIPE-1079](https://linear.app/supabase/issue/PIPE-1079/move-destination-chart-arrows-to-horizontal-edges)

## Solution

Place each chip on its destination's final horizontal edge segment. Keep
the single-destination chip centred on its straight edge.

| 1× Destination (No Change) |
| --- |
| <img width="1352" height="678" alt="CleanShot 2026-09-29 at 14 03
22@2x"
src="https://github.com/user-attachments/assets/c495318c-811b-4817-9b25-af32d12d8e08"
/> |
| _Before_ |
| <img width="1350" height="682" alt="CleanShot 2026-09-29 at 14 02
37@2x"
src="https://github.com/user-attachments/assets/da862b82-4605-48df-93cd-c035443acc9d"
/> |
| _After_ |

| 2× Destinations |
| --- |
| <img width="1354" height="680" alt="CleanShot 2026-09-29 at 14 01
15@2x"
src="https://github.com/user-attachments/assets/970aa562-1ab9-4ff1-90e0-3c0fe95d01dc"
/> |
| _Before_ |
| <img width="1354" height="674" alt="CleanShot 2026-09-29 at 14 00
50@2x"
src="https://github.com/user-attachments/assets/5501657b-32a2-485d-907f-8a0a8fae595d"
/> |
| _After_ |

## Review instructions

1. Open Database > Pipelines with one destination, then with several.
Check the chip position and arrow direction at desktop and phone widths.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved label placement in the database replication diagram when
edges are shifted, making the connections easier to read.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:12:45 +10:00
Danny White e5dde899cd fix(studio): stabilise pipeline header loading (#50964)
## Problem

The pipeline detail header shifts slightly as its loading placeholders
become text.

- Resolves
[DEPR-683](https://linear.app/supabase/issue/DEPR-683/reduce-layout-shift-in-pipeline-header-loading-states)

## Solution

Match the breadcrumb, title, status, and destination placeholders to
their loaded line heights.

## Review instructions

1. Open a pipeline detail page and reload it. Check that the header
height stays steady as its data arrives.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Increased the height of loading placeholders for replication pipeline
status, breadcrumbs, page titles, and destination names.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:11:19 +10:00
Danny White ed692f6905 feat(select): schedule livestream banners (#51006)
## Problem

The Select banners on www and Studio still promote attendance. They need
to keep serving the waitlist until the event, promote the livestream
during the requested window, and disappear after the event.

## Solution

Use a shared three-phase clock: existing promotion before 8:00am PT on 2
October, livestream promotion from 8:00am to 5:30pm PT, and no banner
afterwards. Both livestream CTAs lead to `select.supabase.com`, where
viewers can choose a stage. Separate dismissal keys let someone who
dismissed the earlier promotion see the livestream. Open pages set a
timer for the next boundary and recheck on visibility, focus, or page
restore.

| `www` |
| --- |
| <img width="736" height="136" alt="CleanShot 2026-09-29 at 16 27
38@2x"
src="https://github.com/user-attachments/assets/1281bcf0-ece4-41fc-99d2-1f9ab6e1b3f5"
/> |
| _Until Friday 8am PT_ |
| <img width="734" height="138" alt="CleanShot 2026-09-29 at 16 28
06@2x"
src="https://github.com/user-attachments/assets/05b8779a-9961-4886-ad7d-96ba31c8b4f7"
/> |
| _Friday 8am to 5:30pm PT_ |

| `studio` |
| --- |
| <img width="612" height="454" alt="CleanShot 2026-09-29 at 16 26
51@2x"
src="https://github.com/user-attachments/assets/0d9a8bbb-c636-41dc-aa76-381196c149c2"
/> |
| _Until Friday 8am PT_ |
| <img width="616" height="440" alt="CleanShot 2026-09-29 at 16 27
09@2x"
src="https://github.com/user-attachments/assets/458afdb9-6576-4699-9419-947ca5312bcd"
/> |
| _Friday 8am to 5:30pm PT_ |

## Review instructions

1. Open the [www
homepage](https://zone-www-dot-com-git-dnywh-select-2026-livestre-93dab1-supabase.vercel.app/)
and a [hosted Studio
dashboard](https://studio-staging-git-dnywh-select-2026-livestream-05b822-supabase.vercel.app/)
in separate tabs. If the Privacy Policy update card is in front in
Studio, close it (only) to reveal the Select banner.
2. In each tab's DevTools console, paste this helper:
   ```js
   window.selectRealNow = Date.now
   window.showSelectAt = (iso) => {
     Date.now = () => new Date(iso).getTime()
     window.dispatchEvent(new Event('focus'))
   }
   ```
3. Run `showSelectAt('2026-10-02T07:59:00-07:00')`: both banners keep
the existing “Apply to attend” CTA.
4. Run `showSelectAt('2026-10-02T08:00:00-07:00')`: www shows “Supabase
Select 2026” and “Watch the livestream”; Studio shows the same title,
the description “Keynote, main stage, and build stage, streamed all
day.” and “Watch livestream”. Both CTAs link to
`https://select.supabase.com/`.
5. Run `showSelectAt('2026-10-02T17:30:00-07:00')`: neither banner is
visible. Restore the clock with `Date.now = window.selectRealNow;
window.dispatchEvent(new Event('focus'))`.

The console clock override affects only the current tab and is lost on
reload.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- The Select 2026 banner switches from waitlist messaging to livestream
details and a “Watch livestream” link during the livestream period.
- Livestream banner dismissals are tracked separately from waitlist
banner dismissals.
- Promotion banners end at 5:30 p.m. Pacific on October 2, 2026, and
update when the promotion changes phase, including after returning to an
open tab.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:09:12 +10:00
Pamela Chia 07c75e84fc fix(docs): repair internal content links (#51050)
I fixed stale links in six Docs pages. Guide links now include the Docs
base path, and links to the old Database Hooks route point directly to
the Dashboard Webhooks page.

## To test

- Open the Logs ingest guide in the Docs preview and follow the updated
guide links. Each destination should load.
- Open each affected Docs page in the preview and follow its Webhooks
link. The Dashboard Webhooks page should load after sign-in.

## Linear

- fixes GROWTH-1301


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated webhook setup and troubleshooting links to point to the
Integrations Webhooks dashboard.
* Updated Postgres configuration and log-setting links to use current
documentation paths.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 16:06:18 -07:00
Pamela Chia 10445cee8e fix(www): redirect bare dashboard paths (#51052)
I added permanent www redirects for inbound Dashboard URLs that
currently reach the www 404 page. The project rule requires a path
segment and carries the full project suffix to Dashboard.

## To test

- In the www preview, open `/login`, `/support/new?category=billing`,
and `/account/tokens`. Each should redirect to its corresponding
`/dashboard` page and preserve the query string.
- Open `/project/<ref>` and
`/project/<ref>/database/migrations?source=docs`. Both should redirect
to the same path under `/dashboard`, preserving the suffix and query
string.
- Open bare `/project`. It should remain outside the new redirect rule.

## Linear

- fixes GROWTH-1302


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Other Changes**
* Visiting `/login`, `/support/new`, or `/account/tokens` now redirects
to the corresponding dashboard page.
  * Project links redirect to the matching dashboard project page.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 15:42:45 -07:00
Charis 0daafca2ca feat(studio): status page banner (incident / maintenance / upcoming) (#51044)
## Summary

* Adds a new global status banner (`StatusBanner`) driven by the
[incident.io](<http://incident.io>) status page data, showing at most
one of: an active incident, in-progress maintenance, or upcoming
maintenance, in that priority order.
* All three types are independently dismissible (persisted to a new
localStorage key, `status-banner-dismissed-keys`); dismissal hides the
banner for items still active, and a new incident reappears even if a
related item was previously dismissed.
* Only shows to users who are actually affected (based on their
projects' regions) or when region data is incomplete (fails open), and
is bypassed entirely by the existing emergency incident override.
* Behind the existing `incidentIoStatusPage` ConfigCat flag —
`AppBannerWrapper` renders this new banner instead of the legacy
`StatusPageBanner` only when the flag is on; default behavior is
unchanged.
* This is PR 5b in a stacked series for Linear
[FE-4057](https://linear.app/supabase/issue/FE-4057) — see that issue
for full design context.

## Test plan

* New unit tests (`StatusBanner.utils.test.ts`) covering
banner-selection priority, dismissal-key handling, and copy generation
* New MSW component test (`StatusBanner.test.tsx`) covering loading
state, dismiss-and-persist, and the emergency-override path
* `pnpm --filter studio run typecheck`, `lint:ratchet`, `pnpm knip
--workspace apps/studio`, `pnpm test:prettier`, and relevant vitest
suites all pass

🤖 Generated with [Claude Code](<https://claude.com/claude-code>)

Co-Authored-By: Claude
[noreply@anthropic.com](<mailto:noreply@anthropic.com>)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added status banners for relevant incidents and scheduled maintenance,
including incident details, maintenance timing, and links to the status
page.
* Banners can be dismissed, and dismissed items stay hidden while new
incidents or maintenance updates can still appear.
* Upcoming maintenance banners appear within the relevant lead time, and
maintenance timing is shown when available.
* Emergency overrides display a warning banner without a dismiss option.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 18:09:47 -04:00
Charis d22702e907 refactor(studio): extract user project regions + emergency override hooks (#51033)
## Summary
- Extracts `useUserProjectRegions` (org + project region aggregation,
fail-open on fetch errors) and `useEmergencyIncidentOverride` (the
`ongoingIncident` flag / env var check) out of
`useStatusPageBannerVisibility`, so the upcoming incident.io status-page
banner can reuse both without duplicating the org/project fan-out logic.
- No behavior change for the legacy banner except one intentional fix:
`StatusPageBanner.utils.ts` compared the incident's affected regions
(lowercased) against the user's regions (not normalized), so a
mixed-case region on either side could silently fail to match. Both
sides now go through the same `normalizeRegion` helper.
- Part of the Linear FE-4057 stack (PR 5a of 6). Base branch is PR 4
(`charis/fe-4057-pr4-project-creation-status-admonition`), not master.

Linear: FE-4057

## Test plan
- [x] `pnpm --filter studio run typecheck`
- [x] `pnpm --filter studio run lint:ratchet`
- [x] `pnpm knip --workspace apps/studio`
- [x] `pnpm test:prettier`
- [x] `pnpm --filter studio exec vitest run` on the touched test files
and the `hooks/misc/` and `components/layouts/AppLayout/` directories
(all passing, no regressions)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved status banner targeting by matching incidents against
normalized regions across the user’s projects.
* Updated banner visibility checks to handle incomplete project or
region data, including when project information fails to load.
* Improved loading behavior so the banner can be evaluated based on
user-region data rather than waiting for separate organization and
project requests.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 17:49:06 -04:00
Charis 53b20cad5e feat(studio): project creation status admonition (#51029)
## Summary

- Adds a new project-creation-form incident warning path behind the
`incidentIoStatusPage` ConfigCat flag (default off — no visible behavior
change until the flag is enabled)
- When the flag is on, reads the new `/api/status-page` endpoint (added
earlier in this stack) instead of the legacy `/api/incident-status`
endpoint, and only fetches the legacy endpoint when the flag is off
- Extracts region-matching logic into `RegionSelector.utils.ts`
(`regionMatches`, `getItemsAffectingProjectCreation`) with unit test
coverage

See Linear FE-4057 for full context and design.

## Test plan

- [x] `pnpm --filter studio run typecheck`
- [x] `pnpm --filter studio run lint:ratchet`
- [x] `pnpm knip --workspace apps/studio`
- [x] `pnpm test:prettier`
- [x] `pnpm --filter studio exec vitest run
components/interfaces/ProjectCreation/RegionSelector.utils.test.ts`
(35/35 passing)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Project creation displays a warning and links to the status page when
an incident or maintenance event may affect the selected region.
* Status notices match exact regions and broader smart-region groupings;
global project-creation notices are also shown.
* The AI assistant can report visible, active incidents and in-progress
maintenance, including affected components and update details. When
there are no active events, it reports that status.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 17:37:01 -04:00
Pamela ChiaandJoshen Lim 4a941518e3 feat(studio): track Explorer runs and saves (#51004)
I added outcome events for Explorer query runs and successful manual
notebook saves. Existing page visits and preview toggles do not show
whether users complete queries or persist notebooks.

**Changed:**
- **Query usage:** Accepted runs from query tabs and notebook cells emit
submitted and terminal outcome events with a shared run ID. Canceled
confirmations emit no run events.
- **Notebook adoption:** Successful manual saves emit created or updated
events. Recreated notebooks count as creations. Unsaved drafts and
failed saves emit neither.
- **Event metadata:** Explorer action events use `Explorer` as their
page title.

**Note:** Assistant-generated saves are outside this PR. Custom
properties omit SQL and notebook content. Page visits still carry the
browser title, which can include a notebook name.

## To test

Tested on the staging preview:
- [x] Run valid and invalid SQL from an Explorer query tab. Each run
emits one submitted event and one matching completed or failed event
with the same run ID.
- [x] Run database and Logs notebook query cells, then add a markdown
cell. The query cells emit matching event pairs; the markdown cell emits
no query event.
- [x] Save a new notebook, then edit and save it again. The successful
saves emit created and updated events.
- [x] Cancel a guarded query. It emits no query run event.
- [ ] Recreate a notebook deleted on the server after local edits. A
successful save emits created, not updated.
- [x] Inspect an Explorer action event request. Its page title is
`Explorer`; page visits still use the browser title.
- [ ] Force a notebook save failure. It should emit no save event. This
case was not tested manually.

## Linear
- fixes GROWTH-1298


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Analytics**
* Explorer query runs are tracked for database and log queries,
including whether they complete or fail.
* Query activity is associated with its location in Explorer, such as a
query tab or notebook cell.
  * Successful notebook saves are tracked as creations or updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-29 13:54:13 -07:00
Charis 13de8189c9 feat(studio): assistant get_active_incidents on status page endpoint (#50994)
## Summary

* Adds a second branch to the assistant's `get_active_incidents` tool
(`apps/studio/lib/ai/tools/incident-tools.ts`) that reads
`/api/status-page` when the global ConfigCat flag `incidentIoStatusPage`
is on, instead of the legacy `/api/incident-status` endpoint.
* Filters on `visible`, ignores `show_banner` (only the global banner
respects it), and concatenates ongoing incidents + in-progress
maintenances (not scheduled maintenances).
* Adds `isServerFlagEnabled` to `lib/server/configcat.ts` for reading
global, non-user-targeted ConfigCat flags server-side, and threads the
flag through `getTools` from `pages/api/ai/sql/generate-v4.ts`.

This is PR 3 of 6 in the
[FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured)
stack — stacked on `charis/fe-4057-pr2-support-form`. Behind the
`incidentIoStatusPage` flag (default off), so this ships no user-visible
change on its own. See Linear
[FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured)
for full context.

## Test plan

- [X] `pnpm --filter studio run typecheck`
- [X] `pnpm --filter studio run lint:ratchet`
- [X] `pnpm knip --workspace apps/studio`
- [X] `pnpm test:prettier`
- [X] `pnpm --filter studio exec vitest run
lib/ai/tools/incident-tools.test.ts` (19/19 passing, including 7 new
tests for the status-page branch)
2026-09-29 15:28:49 -04:00
Alaister YoungandAlaister Young 995f6f65c7 [FE-4483] fix(studio): disable network bans for v3 projects (#50997)
Disables network bans for v3 (`AWS_K8S`) projects and shows a specific
unsupported notice. The shared banned-IP query waits for project details
and skips unsupported projects, covering both Database Settings and
Advisor for v3 and High Availability projects.

The hook returns the standard query result and uses `skipToken` to
prevent unsupported requests, including manual refetches. Database
Settings handles project-detail errors at the call site. Open unban
confirmations are cleared when the section becomes disabled, and
submission checks eligibility.

Addresses
[FE-4483](https://linear.app/supabase/issue/FE-4483/disable-network-bans-for-v3-aws-k8s-projects).

## To test

- Open Database Settings on a v3 project. Check that Network bans shows
the v3 notice, hides the IP list and unban controls, and makes no
network-bans retrieval request on initial load or reload, including
while Advisor is mounted.
- Check that an HA project still shows its existing notice and makes no
network-bans retrieval request on initial load or reload.
- Navigate from a supported project to a v3 or HA project and check that
no banned-IP request is sent for the unsupported project and no
banned-IP signals from the previous project appear in Advisor.
- If project details fail without cached data, check that Network bans
shows an error after retries finish and does not retrieve bans. A
successful retry should restore normal behavior.
- Open an unban confirmation on a supported project, then navigate to a
v3 or HA project. Check that the dialog closes without sending an unban
request and stays closed when returning. A newly opened confirmation
should still work.
- On a supported project, check the empty state and banned IP list.
Confirm that users with permission can unban an IP and users without
permission see a disabled button with the permissions tooltip.

Validation: 17 focused tests passed, covering automatic and manual
request suppression, project-detail error display and recovery, and
navigation between supported and unsupported projects. Changed-file
ESLint, Prettier, and full Studio typecheck (without the incremental
cache) passed. Earlier local browser checks on `9912c6c` confirmed no
retrieval requests for an HA project on AWS_K8S across reloads and
Advisor, and a successful empty state on a supported project. The local
failed-project case redirected to the organization after retries, so the
inline error remains verified by the component test only. The latest
preview, standalone v3 notice, populated bans/unban, and no-permission
tooltip still need browser verification.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Banned IP settings now show an unsupported-project notice for AWS
Kubernetes projects and hide ban lists and unban actions for AWS
Kubernetes and High Availability projects.
* Banned IP data loads only after project details are available and only
for supported projects; unsupported projects do not display cached ban
data.
  * Project-detail errors are shown separately from ban-list errors.
* Unban confirmations close when a project becomes unsupported or an
unban succeeds. Unbanning is unavailable when you lack update permission
or the project is unsupported.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-29 17:51:14 +00:00
Wen Bo Xie ed6217a169 docs: clarify how owners and admins authorize MCP clients for enterprise auth (#50832)
The enterprise-managed MCP authentication guide said an organization
owner authorizes the MCP client from the Authorized Apps page. That page
only lists and revokes apps that are already approved, so readers had no
way to follow the instruction.

Approval actually happens when an owner or admin connects the MCP client
through the standard sign-in flow and approves it for the organization
on the consent screen. Both roles can grant that approval, not only
owners.

This updates the prerequisites, the validation step, the "why use it"
summary, and the security considerations to:

- Name owners and admins as the roles that can authorize the client
- Describe the consent-screen approval as the way to authorize it
- Point to Authorized Apps as the place to review or revoke approved
clients
2026-09-29 08:56:54 -07:00
Anthony Lio 8ebbfe3272 feat(chore): bump cn (#51016)
## Problem

currently using `cn` 0.2.5 makes `@shadcn/lint` lint run printed a
notice as it needs 0.3.2 or later

## Solution

- added `cn: ^0.4.0` to the pnpm catalog. `packages/ui` and `blocks/vue`
now use `catalog:` so they stay on the same version
- added `cn` to the root `devDependencies`
- runtime changes from 0.2.5 to 0.4.0

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. run `pnpm install`
2. run `pnpm --filter ui exec vitest run` and `pnpm --filter ui-patterns
exec vitest run` and see them pass
3. run `pnpm --filter @supabase/vue-blocks run typecheck` and see it
pass

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated package version management across the project to keep related
packages aligned. This maintenance change does not alter the app’s
features or behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 18:32:27 +03:00
Anthony Lio e7f0d3c04f fix(ui): popover component (#50657)
## What kind of change does this PR introduce?

fixture on the popover + command components

## What is the current behavior?

currently there is a misalignment in the command component <> searchbar
icon and items + the popover menu animation in is slightly scattered

## What is the new behavior?

- fixes icon alignment in command component
- updates popover animation in 

`command`
| state | preview |
| -------|------|
| before | <img width="881" height="542" alt="image"
src="https://github.com/user-attachments/assets/e38aa22f-5eea-4b08-8a24-254e26bf90fe"
/> |
| after | <img width="881" height="542" alt="image"
src="https://github.com/user-attachments/assets/85608e11-8415-4d47-945f-cc13772e4ad1"
/> |

`popover`
| state | preview |
| -------|------|
| before | <video
src="https://github.com/user-attachments/assets/cbb2da1a-6f73-4a8d-87d6-21e8b636c110"
/> |
| after | <video
src="https://github.com/user-attachments/assets/1b0832f5-e6ac-4e93-ae78-9e0aee31205c"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Style**
  - Adjusted command input spacing for improved visual alignment.
- Updated popover transitions with state-based fade and zoom animations,
and refined their visual origin.
  - Set a consistent size for the AI docs command icon.
- **New Features**
- Added an option to customize the command menu input wrapper’s styling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 18:17:45 +03:00
Manan GuptaandJoshen Lim 6a0518dd86 fix(studio): forward HA flag to project-creation pre-flight checks (#50902)
## Summary

- Fixes MUL-1678: toggling High Availability on in the project-creation
wizard 400'd for orgs that are HA-entitled but not enrolled in the "V3
rollout ramp" feature flag on the backend, because two pre-flight
endpoints Studio calls before project creation didn't know about HA and
hit the ramp check the real create-project call already bypasses.
- Threads `highAvailability` through
`useOrganizationAvailableRegionsQuery` (`GET
/platform/projects/available-regions`, sent as
`high_availability=true|false` on the query string) and
`useProjectCreationPostgresVersionsQuery` /
`useAvailableOrioleImageVersion` (`POST
/platform/organizations/:slug/available-versions`, sent as
`high_availability` in the body), including their query-key cache keys
so HA and non-HA responses for the same org/provider/size don't collide.
- Wires the (already form-tracked) `highAvailability` value into every
call site: `ProjectCreationForm.tsx`, `RegionSelector.tsx`, and a new
`highAvailability` prop on `PostgresVersionSelector.tsx` passed from
`InternalOnlyConfiguration.tsx`.

## Problem

The project-creation wizard's HA toggle is wired into the actual
project-create request, but two pre-flight calls Studio makes before
that (available regions, available Postgres versions) had no way to
signal HA, so the backend's ramp-flag gate rejected them for HA-entitled
orgs outside the ramp.

## Solution

Add an optional `highAvailability` field end-to-end on the Studio side:
query hook variables, cache keys, request serialization, and the
components that already track the toggle via `useWatch`.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Available regions and database versions in project creation now
reflect the selected high-availability setting.
* The Create button remains disabled while available regions are
loading.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: GuptaManan100 <guptamanan100@gmail.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-29 20:39:01 +05:30
Joshen Lim fea8b8b41d Update copy RE disk configuration changes and cooldown (#50844)
## Context

Reverts copy changes from the following PRs:
- Docs: https://github.com/supabase/supabase/pull/42184
- FE: https://github.com/supabase/supabase/pull/47646

Our platform's disk management configuration limitation still follows
the 4 hour cooldown at the moment, doesn't align with AWS's 4 changes in
24 hours rule just yet. This is just to prevent any confusion for now,
and we'll need to update the copy again once behaviour matches AWS on
our BE

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* Disk changes are now subject to an approximately four-hour cooldown
after each modification, replacing the previous limit of four changes in
a rolling 24-hour period.
* Disk management screens now show the cooldown status, remaining wait
time, and next available update time.
* Updated platform guides and troubleshooting instructions to reflect
the cooldown and explain available recovery options.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 23:08:31 +08:00
Kody Jacksonandkodster28-happy-hour 708bfa7ad1 [docs] Fix broken links to '/guides/' paths (#50870)
## Problem

There are several broken links within docs that reference `/guides/...`.
These need to be updated to `/docs/guides/` to resolve correctly.

## Solution

Updated links to resolve correctly

## Preview links

If relevant, include links to changed pages for easy review access.

TBD, waiting on build (unclear if this happens for external
contributions).

## Review instructions

1. Navigate to the pages in the live/preview.
2. Click the links that were updated.

## Checklist

Check all before review:

- [x ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated internal documentation links across API, Auth, Database,
Functions, and troubleshooting guides to use the `/docs` paths.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: kodster28-happy-hour <kody@catholicestateplanning.com>
2026-09-29 10:01:00 -05:00