Commit Graph
37869 Commits
Author SHA1 Message Date
Ali Waseem b84f5c69f6 Merge branch 'master' into fix-realtime-getting_started-code-snippet 2026-08-12 07:18:52 -06:00
Jordi Enric 1440cb81ab docs: update database inspect page title DOCS-1300 (#48972)
## Problem

The database debugging and monitoring guide had the generic title
"Debugging and monitoring", which lacked product context and made it
unclear in search results or breadcrumbs which area it covered.

## Fix

Changed the page title to "Database debugging and monitoring". The
sidebar entry keeps its shorter "Debugging and monitoring" label since
it already has database section context.

## How to test

- Navigate to the database debugging and monitoring guide in the docs
- Confirm the page H1 reads "Database debugging and monitoring"
- Confirm the sidebar entry still reads "Debugging and monitoring"

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the guide title to “Database debugging and monitoring” for
clearer navigation and context.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 07:15:23 -06:00
narudesigns 2fbc2b8736 fixed code snippet for realtime getting started guide docs 2026-08-12 14:08:44 +01:00
Julien GouxandClaude Opus 5 7066aa6513 chore: add Matt Robinson to humans.txt (#48987)
## What kind of change does this PR introduce?

Chore — adds Matt Robinson to `apps/docs/public/humans.txt`, inserted in
alphabetical order (between Matt Johnston and Matt Rossman).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 12:26:13 +00:00
Pedro RodriguesandClaude Opus 4.8 47595f8ac7 feat(self-hosted): implement queryLogs for the MCP debugging tools (#48900)
> [!IMPORTANT]  
>
> Only merge this when (https://github.com/supabase/platform/pull/36804)
is merged, as the AI assistant will not have access to the `query_logs`
tool for the remote MCP server

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature (self-hosted / CLI Studio MCP server).

## What is the current behavior?

Self-hosted `getDebuggingOperations`
(`apps/studio/lib/api/self-hosted/mcp.ts`) implements only `getLogs`, so
the MCP `debugging` group exposes `get_logs` — a fixed per-service log
dump built by `getLogQuery`. Logs are served by Logflare, which speaks
BigQuery SQL.

## What is the new behavior?

Bumps `@supabase/mcp-server-supabase` to `^0.10.0` (adds `query_logs` +
`logsDialect`, and hides `get_logs` wherever a platform declares
`queryLogs`) and moves logs over to it.

- **Self-hosted `query_logs`:** declares `logsDialect: 'bigquery'` and
implements `queryLogs`, passing the model's SQL straight through to the
same Logflare `logs.all` endpoint (arbitrary `sql` param) — no new
endpoint, no dialect translation.
- **Drops `get_logs` from self-hosted:** `getLogs` throws (the server
hides it once `queryLogs` exists) and the per-service `getLogQuery`
builder is deleted; the model now writes its own BigQuery SQL, guided by
the dialect schema hint.
- **Honors no-logs mode:** `query_logs` throws when `logs:all` is
disabled — the self-hosted default, enabled via the
`docker-compose.logs.yml` override.
- **Assistant:** switches the dashboard assistant from `get_logs` to
`query_logs` (allowlist, drift guard, prompt, mocks, evals).

Refs AI-1046


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * AI debugging can query recent project logs using read-only SQL.
* Log queries support optional time-range filters, filtering,
aggregation, and joins.
* Self-hosted debugging checks whether logging is enabled before running
queries.

* **Bug Fixes**
* Updated debugging workflows and validation to consistently use the new
log-query capability.
* Removed reliance on legacy service-specific log filtering and query
behavior.

* **Documentation**
* Updated MCP debugging tool guidance to describe SQL-based log queries.

* **Tests**
* Expanded coverage for enabled, disabled, and unsupported logging
scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-12 13:11:23 +01:00
Chase Cresgy b5462a9609 Chore: Offboarding update for humans.txt (#48919)
Removed Dustin Keib from the list of contributors.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Doc update




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Removed a former team member from the publicly displayed team
information.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 07:46:22 +02:00
Wendie CheungandWendie Cheung beee91b9c2 fix(www): restore monochrome customer logos for QA.tech and Lovable (#48964)
## What kind of change does this PR introduce?

Bug fix for the two visual bugs flagged in
[#customers-page-feedback](https://supabase.slack.com/archives/C072FL5KKKP/p1786496881213419):

- QA.tech was missing its light-mode logo
- Lovable's logo was coloured, inconsistent with the monochrome
convention used by every other customer logo

## What is the current behavior?

- `on-light/qa-tech.png` is a white wordmark, so it's invisible against
the light-mode background.
- `on-light/lovable.png` and `on-dark/lovable.png` both use Lovable's
gradient heart mark instead of a monochrome one.

## What is the new behavior?

- `on-light/qa-tech.png` recolored to a black wordmark, transparent
background — visible in light mode, matches the existing white
`on-dark/qa-tech.png` used in dark mode.
- `on-light/lovable.png` recolored to solid black, `on-dark/lovable.png`
recolored to solid white — both transparent background, no brand colour,
consistent with the other customer logos.

No code changes; only the three PNG assets.

Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io>
2026-08-12 14:42:27 +10:00
Danny White 2e7a8a3362 chore(www): rename customer logo folders to on-dark and on-light (#48962)
## What kind of change does this PR introduce?

Chore: rename customer logo folders and document the theme contract. No
intended visual change, aside from Phoenix Energy whose two marks were
in the wrong folders.

## What is the current behavior?

Customer logos live at:

- `/images/customers/logos/{slug}.png` (`logo`, light mode)
- `/images/customers/logos/light/{slug}.png` (`logo_inverse`, dark mode)

`light/` actually means “use me on a dark background”.

## What is the new behavior?

Same assets, clearer paths:

- `/images/customers/logos/on-light/{slug}.png` → dark/black mark →
`logo` → light mode
- `/images/customers/logos/on-dark/{slug}.png` → light/white mark →
`logo_inverse` → dark mode

Icon chips stay at `/images/customers/logos/{slug}-icon.svg`. Old
`/images/customers/logos/light/*` URLs redirect to `on-dark`. www README
now has the contract.

# To test

Use the [www
preview](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app).
Toggle light/dark from the site header on each page. Logos should stay
readable (no white-on-white or black-on-black).

1. [Customers
grid](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/customers)
— main `logo` / `logo_inverse` surface. Spot-check Juniver, Phoenix
Energy, and one other card.
2. [Phoenix Energy
story](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/customers/phoenix-energy)
— story header uses `logo` only (on-light, plus a dark-mode brightness
filter). We swapped this pair.
3.
[Homepage](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/)
— “How industry leaders…” section. Icon chips only (`*-icon.svg`); the
wordmark `logo` field is unused here.
4. [Solutions /
Agents](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/agents)
— Chatbase quote near the top shows both theme variants. Same pattern on
[/healthcare](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/healthcare),
[/finserv](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/finserv),
and
[/b2b-saas](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/b2b-saas).
5. [Contact
sales](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/contact/sales)
— Good Tape / Xendit / Chatbase wordmarks (`on-light`). Same logos on
the demo form at
[/solutions/enterprise](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/enterprise).
6.
[Enterprise](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/enterprise)
— Mozilla / Epsilon3 / Pebblely icons in the use-cases section
(`on-dark`).
7.
[Vector](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/modules/vector)
— customer quotes. This is the only page that builds `on-light` /
`on-dark` paths at runtime from the customer slug.
8. [Mobbin
event](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/events/migrating-from-firebase-mobbin)
— company logo uses event `logo` / `logo_light` (dark vs light).
Optional second:
[/events/scale-to-millions-goodtape-auth](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/events/scale-to-millions-goodtape-auth).

Quick extra: hover **Product** in the site nav. The customer story
thumbnail uses `imgUrl` (`on-light`).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation
- Clarified customer logo requirements, including separate light and
dark asset locations, monochrome formats, and dark PNG assets for image
generation.

## Updates
- Standardized customer logos across stories, events, sales pages,
solution pages, testimonials, and generated images.
- Improved logo rendering across light and dark themes with dedicated
variants.
- Added permanent redirects for legacy logo URLs while preserving
filename suffixes.

## Tests
- Added coverage verifying legacy logo redirects resolve correctly,
including supported exceptions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 03:49:21 +00:00
Joshen Lim cd906a176a Add empty state for database connections page if preview not enabled (#48927)
## Context

Just adds an empty state for the database connections page if the
feature preview isn't enabled. Users can technically still land on the
/connections page irregardless and the docs changes
[here](https://github.com/supabase/supabase/pull/48920) references this
page too - so this just adds an empty state to allow users to enable the
feature preview

<img width="1388" height="573" alt="image"
src="https://github.com/user-attachments/assets/dfd3a0b4-11b4-42b1-b5eb-fce8c03c35e6"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added a feature preview experience for Database Connections.
* Users with the preview enabled can view connection activity, live
updates, refreshed data, and related controls.
* Users without access see a preview badge, an empty state, and an
option to enable the preview.
  * The live status indicator is hidden when the preview is inactive.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 10:27:14 +07:00
Saxon Fletcher 7c4872ad32 Add Studio ExplorerQuery shell (#48926)
## Summary

Adds the Studio-owned `ExplorerQuery` shell used by notebooks, SQL
snippets, dedicated query tabs, and assistant query blocks within
Explorer.

- provides framed embedded and full-height viewport roots
- provides composable editor, results, and footer layout regions
- keeps result content responsible for its own scrolling while the
results region fills remaining height
- remains presentational: query models, execution, source resolution,
persistence, and result rendering stay external
- expands the project-local Explorer agent skill with composition and
sizing guidance
- adds focused Studio component tests

All files are scoped to `apps/studio`; this PR no longer changes
`ui-patterns` or the design-system app.

## Stack

- Base: #48925
- Next: #48961
- This PR targets `chore/toolbar-component`, so its review diff contains
only the query shell layer.

## Validation

- `pnpm --filter studio exec vitest run
components/interfaces/Explorer/ExplorerQuery/ExplorerQuery.test.tsx
components/interfaces/Explorer/ExplorerToolbar/ExplorerToolbar.test.tsx`
— 6 tests passed
- `pnpm --filter studio typecheck`
- Prettier
- `git diff --check`
2026-08-12 13:21:13 +10:00
Saxon Fletcher fb80d8cf86 Add Studio Explorer toolbar (#48925)
## Summary

Adds the Studio-owned `ExplorerToolbar` composition used by Explorer
notebooks, chats, SQL snippets, query cells, and tabs.

- provides icon, title, actions, and compact action-button slots
- follows Studio's 40px header sizing with a `--header-height` fallback
- keeps resource-specific state and behavior in the consuming Explorer
surface
- adds focused Studio component tests
- adds project-local agent guidance at
`apps/studio/.claude/skills/explorer/SKILL.md`

These components are intentionally scoped to Studio under
`apps/studio/components/interfaces/Explorer`; this PR no longer changes
`ui-patterns` or the design-system app.

## Stack

- Base: `master`
- Next: #48926
- This is the first PR in the Explorer query component stack.

## Validation

- `pnpm --filter studio exec vitest run
components/interfaces/Explorer/ExplorerToolbar/ExplorerToolbar.test.tsx`
— 3 tests passed
- `pnpm --filter studio typecheck`
- Prettier
- `git diff --check`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added shared Explorer toolbar components for icons, titles, actions,
custom controls, and compact buttons.
* Added accessibility defaults, configurable toolbar sizing, ref
forwarding, and native property support.
* Added documentation covering Explorer component usage, composition,
sizing, actions, state ownership, and extensions.

* **Tests**
* Added comprehensive coverage for toolbar composition, styling,
accessibility, refs, and configurable behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 13:21:13 +10:00
Joshen Lim 75b90c5de1 Check the session's backend_start for cancelling or terminating sessions (#48929)
## Context

Related to database connections - specifically for cancelling queries or
terminating sessions

PIDs can be re-used, so a more accurate check is to use both PID and
`backend_start` to uniquely identify the session to cancel or terminate

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved query cancellation and session termination reliability by
verifying the active database session before taking action.
* Prevented actions from affecting a different session that reused the
same process ID.
* Added clearer guidance to refresh when a session has changed or is no
longer available.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 10:14:59 +07:00
Joshen Lim cdfb5b310f Add cancel query action for database connections (#48922)
## Context

Related to Database Connections
- Adds a "cancel query" action for "active" sessions using
`pg_cancel_backend`
- Gentler alternative as the connection stays alive, unlike terminating
the session
- Not applicable for queries idle in transaction as there's no query
running (Disabled in this case)
- Rename "Terminate" to "Terminate session"
- Rename "Abort query" to "Terminate session"

For active queries:
<img width="220" height="135" alt="image"
src="https://github.com/user-attachments/assets/d6ca790d-bb6a-4582-8554-24431388483a"
/>

For idle in txn queries:
<img width="433" height="135" alt="image"
src="https://github.com/user-attachments/assets/615d0651-9f5b-4efc-a5cf-72f93727aa91"
/>

Also updating confirmation modal for terminating session CTA:

For active queries:
<img width="407" height="301" alt="image"
src="https://github.com/user-attachments/assets/e5f56764-11b9-4c10-ba01-d7547aaec872"
/>

All other queries:
<img width="410" height="212" alt="image"
src="https://github.com/user-attachments/assets/8631633f-5d4a-40a7-b089-6980a5180219"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## New Features
- Added a separate **Cancel query** action for active database queries.
- Added **Terminate session** to close connections and roll back active
transactions.
- Added safeguards based on query activity and permissions.
- Added confirmation guidance for active queries, including cancellation
options.
- Added loading, success, and error feedback for query cancellation and
session termination.
- Added telemetry for query-cancellation actions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 09:56:49 +07:00
supabase-supabase-autofixer[bot]andphamhieu cd4223e128 feat: update mgmt api docs (#48628)
This PR updates mgmt api docs automatically.

Co-authored-by: phamhieu <689843+phamhieu@users.noreply.github.com>
2026-08-11 18:12:57 -06:00
Miranda LimonczenkoandClaude Opus 5 f10f00ae69 fix(e2e): install e2e-shared when CI filters to a single suite (#48960)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix. Unblocks the WWW E2E check on `master`.

## What is the current behavior?

The WWW E2E job fails before running any test:

```
Error: Cannot find package '@axe-core/playwright' imported from /home/runner/_work/supabase/supabase/e2e/shared/axe.ts
Error: No tests found
```

Both E2E workflows install with a filter:

```
pnpm install --frozen-lockfile --filter=e2e-www...
```

The `...` suffix pulls in a package's declared dependencies. Neither
`e2e-www` nor `e2e-docs` declared `e2e-shared`; both reach it through
relative imports such as `../../shared/axe.ts`, which pnpm's dependency
graph cannot see. So the filter selected one project,
`e2e/shared/node_modules` was never created, and Node resolving
`@axe-core/playwright` from `e2e/shared/axe.ts` walked up to a root that
does not carry it under pnpm's isolated layout.

`e2e-docs` is broken the same way. It had not run against the shared
module yet, so it has not gone red.

## What is the new behavior?

`e2e-shared` is declared as a workspace dependency of both suites, so
the filter installs it.

| | Filter scope | Importing `e2e/shared/axe.ts` |
| --- | --- | --- |
| Before | 1 of 28 projects | `Cannot find package
'@axe-core/playwright'` |
| After | 2 of 28 projects | Imports cleanly |

The lockfile gains two `link:../shared` entries and no new downloads.

## Manual Testing

1. Check out this branch and delete the shared package's modules: `rm
-rf e2e/shared/node_modules`
2. Run the command CI runs: `pnpm install --frozen-lockfile
--filter=e2e-www...`
3. Confirm the output reports `Scope: 2 of 28 workspace projects` and
that `e2e/shared/node_modules` exists again.
4. Repeat steps 1 - 3 with `--filter=e2e-docs...`.

## Additional context

Fixing only the workflow lines, by adding a second
`--filter=e2e-shared`, would work as well. Declaring the dependency was
chosen instead because the dependency is real and every consumer of the
filter gets it, not just the two workflow files.

The imports stay relative. Declaring the workspace dependency is enough
to get the package installed, so no import paths change in this PR.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated end-to-end test packages to use shared testing utilities at
runtime.
  * Improved consistency between documentation and website test suites.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 16:17:29 -07:00
Miranda LimonczenkoandClaude Opus 5 6d3a4bcc48 feat(www) Add scaffolding for WWW E2E tests and CI check (#48861)
Closes DOCS-1278

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature. Adds E2E test scaffolding and a CI check for the marketing
site.

## What is the current behavior?

Closes [FE-4047](https://linear.app/supabase/issue/FE-4047).

The marketing site has no E2E coverage. Docs has a suite in `e2e/docs`,
but its
runner, git helpers and axe reporting are private to that package, so a
second
site cannot reuse them.

## What is the new behavior?

* **A www suite scoped to changed content.** Changed `.mdx` files in
`_blog`,
`_events`, `_customers` and `_alternatives` map to the URLs they render.
Pages
with `disable_page_build: true` are skipped because they 404 by design.
Capped
at 20 pages. Enforces `heading-order` and `page-has-heading-one`,
matching docs.
* **`e2e/shared` The docs site is also static with similar needs. This
folder shares the docs logic with www.
* **A CI check that is safe to mark required.** Path scoping lives in a
`Detect changed paths` step rather than a `paths:` trigger, so the check
  reports on every pull request instead of being skipped.
`waitForVercelDocsPreview.js` becomes `waitForVercelPreview.js`, shared
by both
  workflows.

## How the check behaves

The job always reports a check run, so it is safe to mark required. Path
scoping
happens in a step rather than a `paths:` trigger, which would leave
non-www pull
requests waiting on a check that never reports.

| Case | Behavior |
| --- | --- |
| Fork pull request adds new pages | Passes without testing. The Vercel
wait is gated on `head.repo.full_name == github.repository`, so forks
resolve no preview URL. The job emits a `::warning` and a job summary
containing a ready-to-run `gh workflow run www-e2e.yml` command with the
resolved page paths, so a maintainer can run it against the preview. |
| Vercel preview times out or fails | Passes without testing. The wait
step is `continue-on-error: true`, so a 900s timeout or a failed
deployment leaves the URL unset and the suite skips. Vercel's own
`Vercel – zone-www-dot-com` check already reports the failure. |
| Draft pull request | Job does not run at all, gated at the job level
on `pull_request.draft == false`. `ready_for_review` is in the trigger's
`types`, so marking it ready runs the check. |
| Another app changed, www untouched | Job runs and every step skips.
The `www` filter matches only the four content directories, `e2e/www`,
`e2e/shared`, the lockfile, and this workflow. |
| Only the harness changed | Passes without testing. Scope resolves to
zero pages, and the Vercel wait is additionally gated on `www_app`, so
it does not wait for a preview Vercel skipped. |
| No preview resolves, any reason | Skips rather than falling back to
production. Production does not serve pages the pull request adds, so
testing it would fail a valid change. |

### Not covered

Changes to `apps/www` components and routes do not trigger this check —
only the
four content directories do. A follow-up can check global components
such as the navigation and the footer.

## Manual testing

1. Start the site: `pnpm dev:www`
2. Run `pnpm e2e:www` with no www content changed. It should resolve
zero pages
   and skip Playwright, not fail.
3. Touch a post, then run `pnpm e2e:www` again:
`echo "" >> apps/www/_blog/2024-01-01-some-post.mdx`. The resolved
`/blog/...`
   path should be listed before Playwright starts.
4. Run against production with no local server:
`PLAYWRIGHT_BASE_URL=https://supabase.com
WWW_E2E_PAGE_PATHS=/blog/postgres-language-server pnpm e2e:www`
5. Point step 4 at a page with a known heading problem. The failure
should name
   the rule, the CSS selector and the markup.
6. Confirm docs still passes on the shared runner: `pnpm dev:docs`, then
   `pnpm e2e:docs`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added WWW end-to-end testing for affected content pages, including
accessibility checks.
* Added standard and full-site test commands, configurable preview
testing, and failure reports.
* Added shared utilities for page discovery, accessibility scanning, and
test execution.

* **Documentation**
* Documented WWW test setup, coverage, debugging, CI behavior, and
running checks against production or preview environments.

* **Improvements**
* Updated documentation test workflows to better identify affected
changes and handle preview environments.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 22:06:51 +00:00
Charis 065468f8ac fix(studio): reset rename form after renaming a SQL snippet (#48951)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

The SQL snippet rename modal is mounted once per nav and reused for
every snippet, so a single form instance is shared across renames. On a
successful rename the form was never re-baselined, leaving it dirty, and
the effect that synced the form to the selected snippet bailed out
whenever the form was dirty.

Renaming a second snippet therefore opened the modal pre-filled with the
previous snippet's name, with the submit button enabled — one careless
confirm renamed the wrong query.

## What is the new behavior?

The form is reset after a successful rename, and the hand-rolled sync
effect is replaced with react-hook-form's `values` option so the form
follows whichever snippet is selected.

`keepDirtyValues` keeps a background refetch from clobbering in-progress
input, which is what the old dirty guard was protecting against. It has
to be disabled explicitly on the resets that discard input, since
`resetOptions` on `useForm` applies to every `reset` call — not just the
`values`-driven one.

Adds component tests covering the submit path, the rename-then-rename
regression, and discarding an abandoned edit on cancel.

## Additional context

Fixes FE-4114

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved the rename query experience by ensuring the selected snippet
name is displayed correctly when reopening the rename dialog.
- Cancelled edits are now discarded reliably, preventing unsaved changes
from persisting.
- After a successful rename, the form reflects the updated query name
and maintains consistent input and button behavior.
- **Tests**
- Added coverage for successful renaming, cancellation, reopening with a
newly selected snippet, and submitted values.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 20:05:46 +00:00
David_CandPamela Chia 6bda113bf0 fix(www): fix duplicate row level security key (#48325)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (fixes #48324)

## What is the current behavior?

Detailed in #48324, there's a duplicate row-level-security section. Line
369 to 392 (right above the change) already have this row-level-security
section, seems like a simple forget to change the copy pasted content
mistake

## What is the new behavior?

Fixed based on the title and image name



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Content Updates**
* Replaced the “Row Level Security” feature card with “Full SQL access”
in the Postgres platform features section.
  * Updated the associated image description to “SQL Editor.”
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-08-12 02:25:37 +08:00
Ayaan GazaliandPamela Chia 0cf543add9 docs(blog): point dead docs links at their current pages (#48683)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs fix (broken links in blog posts).

## What is the current behavior?

Three links in two published blog posts 404:

| link | post |
| --- | --- |
| `/docs/guides/platform/log-drain#generic-http-endpoints` |
`2024-08-15-log-drains.mdx` |
| `/docs/reference/javascript/storage-from-download` |
`2022-12-13-storage-image-resizing-smart-cdn.mdx` |
| `/docs/reference/dart/storage-from-list` | same post |

The log drains guide is at `log-drains` (plural) now, and the JavaScript
and Dart Storage references were reorganized under `file-buckets-*` ids.

## What is the new behavior?

- `guides/platform/log-drain#generic-http-endpoints` becomes
`guides/platform/log-drains#custom-endpoint`
- `reference/javascript/storage-from-download` becomes
`reference/javascript/file-buckets-download`
- `reference/dart/storage-from-list` becomes
`reference/dart/file-buckets-list`

All three destinations return 200.

On the log drains one, the old `#generic-http-endpoints` heading is gone
too, so I checked what replaced it rather than just fixing the path and
leaving a dead fragment. The `#custom-endpoint` section on that page is
the same thing the blog paragraph is describing: "Logs are delivered as
a JSON array via HTTP POST", with a URL, HTTP version, gzip and headers
configuration. That matches "the HTTP Endpoint drain can be used to send
logs to any destination that supports ingestion via HTTP POST requests"
in the post, so I pointed it there. Happy to change it if you would
rather it went to the page top or somewhere else.

## Additional context

Files:

- `apps/www/_blog/2024-08-15-log-drains.mdx` (1)
- `apps/www/_blog/2022-12-13-storage-image-resizing-smart-cdn.mdx` (2)

Verification: all three old URLs confirmed 404, all three replacements
confirmed 200. For the fragment I fetched the log drains page and
confirmed `#generic-http-endpoints` is not among its heading ids while
`#custom-endpoint` is, then read that section's text to check it is the
right one.

I did not touch `apps/www/app/api-v2/md/content.generated.ts`, which
mirrors blog content, since it is generated and will pick this up on its
next build.

Gates run locally: `test:prettier` passes repo wide and the www vitest
suite passes (6 files, 73 tests). I did not run `pnpm build`, which
cannot complete in my environment because the docs
`build:federated-content` step needs `DOCS_GITHUB_APP_PRIVATE_KEY`.

This came out of checking every absolute `supabase.com/docs` link in
`apps/www` and `apps/docs/content` against the live site. Two related
things I found in the same sweep but deliberately left alone, because
the target is a content decision rather than a rename: a few links into
`elevenlabs/examples` whose examples were removed when that repo
restructured by language, and `redwoodjs/redwoodjs-supabase-quickstart`,
whose repo no longer exists.

Freshman contributor, worked through this with Claude Code's help and
checked each URL and heading id myself.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated JavaScript and Dart getting-started links to their current
client-library pages.
* Corrected the custom HTTP endpoint documentation link for log drains.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-08-12 01:00:46 +08:00
Leonardo SantiagoandKaterina Skroumpelou 34c29f0b98 docs(python): add python docs for otel instrumention (#48898)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds a new tab section for the `client-side-tracing.mdx` document file,
explaining how to setup OTel context propagation in the `supabase-py`
library.

## What is the current behavior?

No documentation.

## What is the new behavior?

Documentation.

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the client-side tracing guide to document W3C trace-context
propagation support in the Python SDK.
* Added Python setup instructions for OpenTelemetry HTTPX
instrumentation, tracer configuration, and tracing Supabase queries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Katerina Skroumpelou <sk.katherine@gmail.com>
2026-08-12 01:00:24 +08:00
Ayaan GazaliandPamela Chia 279e577fac fix(www): correct broken product carousel and partner logo image paths (#48822)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (broken images on the database product page and the agencies
solutions page).

## What is the current behavior?

Five image paths point at files that are not in the repo, so they 404 in
production. Four of them are carousel slides on the database product
page, which means those slides render with a broken image.

| referenced | actually committed |
| --- | --- |
| `sql-view/manaco-editor.png` | `sql-view/monaco-editor.png` |
| `table-view/spreadsheet-interface.png` | `table-view/spreadsheet.png`
|
| `table-view/create-table.png` | `table-view/create-tables.png` |
| `table-view/export.png` | `table-view/export-csv.png` |
| `logos/publicity/sj-innovation.svg` |
`logos/publicity/sjinnovation.svg` |

All five confirmed 404 on production, and all five replacements
confirmed 200.

## What is the new behavior?

Each path points at the file that is actually committed. No assets
added, renamed or deleted.

The mapping is not guesswork, each slide's own title and text names the
image:

- the `manaco-editor` slide is titled "Monaco editor" with the text
"Built in Monaco editor, with rich validation and autocomplete", so that
is a plain spelling slip for `monaco-editor.png`
- the `create-table` slide is titled and labelled "Create tables",
plural, matching `create-tables.png`
- the `export` slide is "Select and Export" with the text "Pick the rows
you want and export them into a CSV", matching `export-csv.png`
- the `spreadsheet-interface` slide is "The simplicity of a
spreadsheet", matching `spreadsheet.png`

I also checked the dark and light convention before picking: every other
slide in both carousels uses the plain filename rather than the `-light`
variant, so I stayed consistent with that and did not switch any slide
to a `-light` asset.

## Additional context

Files:

- `apps/www/data/products/database/sql-view-carousel.json` (1)
- `apps/www/data/products/database/table-view-carousel.json` (3)
- `apps/www/data/solutions/agencies.tsx` (1)

How I found it: compared every `/images/...` reference across `apps/www`
(2152 distinct paths) against `apps/www/public`, then for each miss
looked for a near match in the same directory before deciding anything,
and finally live-checked both the broken path and the proposed
replacement.

One in the same file I could not fix:
`apps/www/data/solutions/agencies.tsx` also references
`logos/publicity/imaginary-space.svg`, which 404s and has no similarly
named asset anywhere in that directory. That one needs the actual logo,
so it is not something I can resolve from the repo.

Gates run locally: `test:prettier` passes repo wide, `typecheck` passes
16/16, and the www vitest suite passes (6 files, 73 tests). I did not
run `pnpm build`, which cannot complete in my environment because the
docs `build:federated-content` step needs `DOCS_GITHUB_APP_PRIVATE_KEY`
and fails before Next compiles.

Freshman contributor, found these with a local asset scan and verified
every status code myself, with Claude Code's help along the way.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Corrected image references in the SQL view and table view carousels.
* Updated illustration paths for spreadsheet editing, table creation,
and CSV export content.
  * Fixed the SJ Innovation testimonial logo so it displays correctly.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-08-12 00:50:16 +08:00
Charis 810d292121 feat(studio): notebook cell operations (#48940)
## Summary
- Pure module (`data/content/notebooks/notebook-operations.ts`) for
applying `update_notebook` cell edits client-side: `insert_cell`
(`after_cell_id` incl. `'start'`), `replace_cell`, `delete_cell`,
`move_cell`.
- Never touches the safe-sql brands — SQL promotion still happens at the
tool-execute boundary, matching `create_notebook`.
- Stacked on #48938. No wiring yet — `update_notebook` tool wiring is
next.

Towards FE-4083

## Test plan
- [x] `pnpm vitest run
data/content/notebooks/notebook-operations.test.ts` — 13 unit tests
covering every op, combinations, and all three error cases.
- [x] `pnpm exec tsc --noEmit` clean
- [x] `pnpm exec eslint` clean on new files

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added support for applying notebook cell operations, including
insertion, replacement, deletion, and movement.
* Operations are applied in a predictable order, with support for
anchoring new cells at the beginning or near existing cells.
* Added validation for invalid references, conflicting operations, and
self-referential moves.
* Added clear handling when operations produce an empty notebook result.

* **Tests**
* Added comprehensive coverage for individual, combined, ordered,
conflicting, invalid, and empty-result notebook operations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 12:35:27 -04:00
Jordi Enric 68ac0e319b docs: link query optimization guide from monitoring page (#48935)
Adds a Query optimization card to the Monitoring listing on
/docs/guides/monitoring-and-debugging, pointing at
/docs/guides/database/query-optimization.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added a “Query optimization” entry to the telemetry monitoring
content.
* Links readers to guidance on analyzing database indexes and query
plans.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 00:31:14 +08:00
kemal.earth 99545dc03a chore(studio): remove mcp mention in legacy token creation (#48945)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Small bit of lingering text that was leftover.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the legacy access token description to remove an outdated
reference.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 17:13:18 +01:00
Ayaan Gazali 0925218294 fix(www): point Infinite Query announcement at its live docs page (#48946)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (broken link on the Wrapped product announcements page).

## What is the current behavior?

`ProductAnnouncements.tsx` links the "Supabase UI Library now includes
Infinite Query block" entry to
`https://supabase.com/library/docs/infinite-query-hook`, which returns
404.

The docs page for that block is framework scoped, and the slug does not
carry the `-hook` suffix. The content only exists for two frameworks:

| URL | status |
| --- | --- |
| `/library/docs/infinite-query-hook` (current) | 404 |
| `/library/docs/react/infinite-query` | 200 |
| `/library/docs/vue/infinite-query` | 200 |
| `/library/docs/nextjs/infinite-query` | 404 |

Those two match the content tree exactly,
`apps/ui-library/content/docs/{react,vue}/infinite-query.mdx`, and there
is no `nextjs` variant.

## What is the new behavior?

The entry points at `/library/docs/react/infinite-query`, confirmed 200.

I picked React rather than Vue deliberately. That page is the original,
added in #34650 ("Infinite query hook block"), and its front matter is
`title: Infinite Query Hook` with `description: React hook for infinite
lists, fetching data from Supabase`, which is what the announcement is
describing. Vue and Nuxt came later in #44426. The `-hook` in the old
URL matches the registry item name (`<RegistryBlock
itemName="infinite-query-hook" />`), not the docs slug, which is
probably how the two drifted apart.

## Additional context

This one was already stale before the recent rename. #48668 moved `/ui`
to `/library` and rewrote this line mechanically from
`/ui/docs/infinite-query-hook` to `/library/docs/infinite-query-hook`,
so the dead path was carried across rather than introduced. Both
spellings 404 today, so it reproduces on current master either way.

The rename itself looks correct, and I checked rather than assumed:

- every other `/library` URL referenced anywhere in the repo returns
200, including the sibling `nextjs/social-auth` entry immediately below
this one
- the two specific `/ui/docs/ai-editors-rules/*` redirects sit above the
new `/ui/:path*` catch all in `redirects.js`, so first match wins keeps
them working
- `https://supabase.com/library/docs` also 404s, but that is a
`BASE_URL` constant in the two `build-llms-txt.ts` scripts that gets
concatenated with a page path, not a link anyone follows, so I left it
alone

One file, one line.

Verification: every status code above was checked against production,
including a deliberate nonsense URL to confirm the check was actually
running. Gates on this branch: `test:prettier` passes repo wide,
`typecheck --filter=www --force` passes 8/8, the www vitest suite passes
(6 files, 74 tests), and `next.config.test.ts` passes. I did not run
`pnpm build`, which cannot finish in my environment because the docs
`build:federated-content` step needs `DOCS_GITHUB_APP_PRIVATE_KEY`.

Freshman contributor here. Found this with Claude Code's help while
checking the URLs touched by the `/ui` to `/library` rename, and I
verified every status code and the page history myself.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated the April 2025 Infinite Query announcement link to point to
the React-specific documentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 00:07:49 +08:00
Charis ddb3e2c442 feat(studio): create_notebook AI tool (#48938)
## Summary
- Adds a `create_notebook` AI assistant tool (`needsApproval: true`)
that lets the assistant create a new notebook after explicit user
approval.
- Cell SQL is promoted from untrusted to safe via
`acceptUntrustedSql`/`acceptUntrustedLogsSql` inside `execute`, using
the approval gate as the confirming user gesture (same pattern as
`execute_sql`).
- Input is validated against the existing agent-writable notebook
schema, which rejects any agent-supplied cell `id` at the schema level.
- Threads an optional auth-headers param through
`upsertContent`/`createNotebook`/`updateNotebook` so the tool can pass
its own bearer token server-side.
- Registers the tool in the tool-filter (`SCHEMA` category, alongside
`list_notebooks`/`get_notebook`) and adds a `## Notebooks` prompt
section guiding the assistant on when to use `create_notebook` vs.
one-off `execute_sql`.

Resolves FE-4082

## Test plan
- [x] `notebook-tools.test.ts` covers: tool registration,
`needsApproval`, cell-id rejection, valid input, PUT body shape, and the
returned id — all passing
- [x] Typecheck clean
- [x] Lint clean (no new warnings)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added AI-assisted notebook creation for saving multi-step
investigations.
* Added support for database and log SQL cells in newly created
notebooks.
* Notebook creation requires approval before saving and returns the
notebook’s name and identifier.
* Added support for custom request headers during notebook and content
operations.
* Added guidance for choosing between one-time SQL execution and
reusable notebooks when Explorer is enabled.

* **Improvements**
* Improved validation and normalization of notebook content before
saving.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 11:54:49 -04:00
Han Qiao 433175e79a Clarify behavior of preview branches in documentation (#48744)
Update the description of preview branches to clarify that they are
automatically deleted when a PR is merged or closed.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Clarified that preview branches are temporary and automatically
deleted when a pull request is merged or closed.
- Removed outdated guidance stating that preview branches pause after
inactivity.
- Clarified that persistent branches remain available long-term and are
not automatically paused or deleted due to inactivity or pull request
closure.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 22:44:31 +08:00
e846d45ce6 chore(studio): retry flaky unit tests in CI (#48939)
<!-- ccr-slack-attribution -->
_Requested via [Slack
thread](https://supabase.slack.com/archives/C063LNYJJKS/p1786454906416269?thread_ts=1786454906.416269&cid=C063LNYJJKS)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore / CI reliability. One-line config change to
`apps/studio/vitest.config.ts`.

## What is the current behavior?

**Before:** the `Studio Unit Tests & Build Check` workflow sometimes
goes red on `master` for no reason anyone can act on. Since 2026-07-29
it failed 3 out of 82 test executions (3.7%), every time at job `test
(1)`, step `Run Tests`. Every one of those three passed on a re-run with
no code change:

- https://github.com/supabase/supabase/actions/runs/31495760766
(`4587d177`, Aug 11)
- https://github.com/supabase/supabase/actions/runs/31409667566
(`b04d1485`, Aug 10)
- https://github.com/supabase/supabase/actions/runs/31203465483
(`777c02c2`, Aug 7)

Each failure also posts a Slack alert to #team-frontend-alerts via
`.github/workflows/studio-master-alert.yml`, so someone gets pinged,
opens the run, clicks re-run, and it goes green.

## What is the new behavior?

**After:** a test that fails in CI gets up to two more attempts before
the job is marked failed. A genuinely broken test still fails all three
attempts and still goes red. Locally nothing changes — the first failure
is the result you see, so you are never waiting on retries while
debugging.

## Additional context

**How:** added `retry: IS_CI ? 2 : 0` to the `test` block of
`apps/studio/vitest.config.ts`, with `const IS_CI = !!process.env.CI`
matching the pattern already used in
`e2e/studio/playwright.config.ts:51` (`retries: IS_CI ? 5 : 0`).

**Known limitation — we do not know which test is flaking.** The GitHub
Actions log downloads for those three runs were not retrievable, and the
API only surfaces `Process completed with exit code 1`. So this treats
the symptom without naming the cause.

The natural follow-up is to upload a JUnit or JSON vitest report as an
artifact with `if: always()`, which would name the flaking test on the
next failure. That is deliberately **not** in this PR — it is a workflow
change and was scoped out.

One more honest caveat: per-test retry only helps if the failure is an
assertion or timeout inside a test. If the real cause is a worker crash
or OOM, retrying will not save the run. That is a live possibility here
— the workflow sets `NODE_OPTIONS: '--max_old_space_size=3072'` with the
in-repo comment "Default is 2 GB, increase to have less frequent OOM
errors", which says someone has already hit memory pressure in this job.

So: worth landing as a cheap reduction in false alarms, but if the 3.7%
does not drop, the report artifact is the next step rather than more
retries.


---
_Generated by [Claude
Code](https://claude.ai/code/session_01U4338RsMYAc1uGuwTFNGBD)_

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-11 13:57:01 +00:00
Katerina Skroumpelouandgithub-actions[bot] fc5db9bb03 docs: update client-side tracing and Edge Function CORS guides (#48924)
Updates the client-side tracing and Edge Function CORS docs for changes
shipping in `@supabase/supabase-js` v2.112.3 (supabase/supabase-js#2603,
supabase/supabase-js#2604). The tracing guide gains a vendor
compatibility table (plain OpenTelemetry works as is, Sentry needs
`propagateTraceparent: true`, Datadog RUM needs `allowedTracingUrls`),
the new `respectSamplingDecision` semantics (non-sampled requests now
carry `traceparent` only, so logs stay correlatable), a troubleshooting
entry for the SDK's new propagator warning, and a note that browser
calls to Edge Functions need the trace headers in the function's CORS
allow-list. The CORS guide now states explicitly that trace headers are
sent only when trace propagation is opted in (never by default), adds a
table of when each SDK header is actually sent, and the hardcoded
`corsHeaders` examples are updated to the full header list. Should merge
after the v2.112.3 release is published, since it documents that
version's behavior.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded CORS guidance with trace-propagation requirements and SDK
version considerations.
* Added browser and Edge Function setup guidance for client-side
tracing.
* Documented updated sampling behavior, advanced configuration, vendor
setup examples, and troubleshooting.

* **Bug Fixes**
* Updated CORS configurations to allow retry and tracing headers
required for supported requests.
* Improved compatibility for browser requests that transmit distributed
tracing context.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-11 16:43:26 +03:00
Charis 4587d177c3 Add optional title field to notebook cells (#48937)
## Summary

- Adds optional `title` field to `databaseCellSchema` and
`logCellSchema` in notebook schema
- Allows database and logs notebook cells to carry descriptive titles
- Field automatically propagates through derived schemas (wire,
writable, agent, domain) via Zod inheritance

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added optional titles to database and log notebook cells.
* Cell titles are now preserved across notebook editing, viewing, and
agent workflows.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 09:21:33 -04:00
Monica Khoury 0f2f3e4eb7 fix: update storage size unit correctly after navigation (#48932)
Fixes FE-4128. 

## What is the current behavior?

When updating the global Storage file size limit using a unit other than
MB, the selected unit displays an incorrect value after navigating away
from the Storage settings page and returning.

The updated file size is persisted correctly by the API, but the unit
selector does not always reflect the value derived from the persisted
configuration.

The Save button also remains enabled after successfully saving the
updated configuration.

## What is the new behavior?

The file size unit selector now correctly reflects the unit derived from
the persisted global file size limit after saving and navigating between
pages.

The form state is also correctly synchronized with the latest Storage
configuration after an update, so the Save button returns to its
disabled state once the changes have been persisted.

## Additional context

The Storage API persists the global file size limit in bytes rather than
persisting the selected display unit separately. The dashboard derives
the appropriate unit (MB/GB) from the stored byte value when loading the
configuration.

The issue was caused by the unit Select retaining stale internal state
when the form values were reset after the Storage configuration was
loaded/refetched. Ensuring the Select is refreshed when the controlled
unit changes keeps the displayed unit synchronized with the form state.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved storage settings form initialization when configuration and
entitlements load.
* Ensured storage unit selections and placeholders display consistently.
  * Improved form resetting to reflect the latest loaded settings.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 07:17:06 -06:00
Joshen Lim 5b301e1ffa Add docs for diagnosing stuck and blocked queries (#48920)
## Context

Related to the dashboard work for [Database
Connections](https://github.com/orgs/supabase/discussions/48639) -
updates the "Connection Management" docs page to include a section about
"Diagnosing stuck and blocked queries". Content is intentionally
agnostic to the UI, but more focused on Postgres.

Preview:
https://docs-cdukolvgy-supabase.vercel.app/docs/guides/database/connection-management

Covers the following sub-topics:
- Reading a session's state
- Finding out what's blocking a query
- How to stop the session responsible
- Small footer to link to the dashboard's Database Connections page

Also adding a cross-reference in 2 areas
- Troubleshooting: How to check if my queries are being blocked by other
queries
- Monitoring and Debugging MDX -> Related to observability skills

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded connection-management guidance with clearer explanations of
session states.
* Added instructions for diagnosing stuck or blocked queries,
identifying blocking sessions and chains, and choosing when to cancel or
terminate them.
* Documented required permissions and available dashboard tools for
managing sessions.
* Added cross-references and telemetry updates to make troubleshooting
guidance easier to discover.
* Clarified how to use PostgreSQL activity information when
investigating blocked queries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 07:09:43 -06:00
Charis 7798e42435 feat(studio): notebook read tools (#48908)
## Summary
- Adds `list_notebooks` (cursor-paginated) and `get_notebook` AI tools
in `lib/ai/tools/notebook-tools.ts`, modeled directly on
`report-tools.ts`: server-side `getContent`/`getNotebook` with the
`authorization` header forwarded, zod-validated input.
- `get_notebook` resolves every cell and exposes `unchecked_sql` as a
plain `sql` field for the agent to read — display only, per the
`safe-sql-execution` skill; nothing here executes SQL.
- Registers both tools in `lib/ai/tools/index.ts` (same platform branch
as reports) and in `lib/ai/tool-filter.ts`'s `toolSetValidationSchema` +
`TOOL_CATEGORY_MAP` (`SCHEMA` tier).
- Adds an optional `headers` param to `content-infinite-query.ts`'s
`getContent`, mirroring the sibling `content-query.ts`, so the
cursor-paginated fetch can carry the `Authorization` header from a
server context.
- New tools are behind the Explorer feature flag.

Stacked on #48907 (1.4 — notebook query and mutation hooks), per the
Notebooks implementation plan (stack 2.1).

Resolves FE-4081
Resolves FE-4080

## Test plan
- [x] `pnpm exec tsc --noEmit` — no new errors
- [x] `pnpm exec vitest run lib/ai/tools/notebook-tools.test.ts
lib/ai/tools/index.test.ts lib/ai/tools/report-tools.test.ts
data/content/notebooks` — 36/36 passing
- [x] `pnpm --filter studio run lint` — no new warnings
- [x] `pnpm exec prettier --check` on changed files — clean

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added AI tools to list project notebooks with pagination.
* Added AI support for retrieving notebook markdown and resolved SQL
cell content.
  * Notebook tools now respect project and authorization context.
* Notebook features are available only when Explorer access is enabled.
  * Content requests can forward custom request headers.

* **Tests**
* Added coverage for notebook tools, Explorer access, feature flags,
authorization, pagination, and error handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 08:40:51 -04:00
Andrey A. 241bb11c06 chore(self-hosted): update 2026-08-11 - 0.8.0 (#48899) self-hosted/v0.8.0 2026-08-11 11:55:43 +02:00
Andrey A. 5a8eecf509 feat(self-hosted): envoy is the default api gateway (#48153) 2026-08-11 11:55:26 +02:00
Andrey A. 9596b5f3ed docs(self-hosted): add a separate architecture diagram (#48763) 2026-08-11 11:48:22 +02:00
kemal.earth 1cc0682c47 chore(studio): remove admonition now that mcp supports scoped pat (#48931)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This removes the pre-cautionary admonition we had before the MCP support
for scoped access tokens landed. We can now remove this admonition (and
anything related) as it's been merged.

| Before | After |
|--------|--------|
| <img width="790" height="202" alt="Screenshot 2026-08-11 at 09 11 08"
src="https://github.com/user-attachments/assets/8b99d93f-c398-4b86-84fe-e63a2ba40e26"
/> | <img width="781" height="104" alt="Screenshot 2026-08-11 at 09 17
18"
src="https://github.com/user-attachments/assets/b28b8262-ec01-4686-ace8-50065eb22822"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Changes**
* Removed the MCP unsupported warning from scoped access-token creation
and viewing screens.
* Removed the option to switch from scoped-token creation to the legacy
account-wide token flow.
  * MCP tools now display directly when available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 09:48:02 +01:00
supabase-supabase-autofixer[bot]andsupabase-workflow-trigger[bot] a6a12c40a9 feat: update @supabase/*-js libraries to v2.112.3 (#48928)
This PR updates @supabase/*-js libraries to version 2.112.3.

**Source**: manual

**Changes**:
- Updated @supabase/supabase-js to 2.112.3
- Updated @supabase/auth-js to 2.112.3
- Updated @supabase/realtime-js to 2.112.3
- Updated @supabase/postgest-js to 2.112.3
- Refreshed pnpm-lock.yaml

---

## Release Notes

## v2.112.3

## 2.112.3 (2026-08-11)

### 🩹 Fixes

- **supabase:** add trace context headers to canonical CORS allow-list
([#2603](https://github.com/supabase/supabase-js/pull/2603))
- **supabase:** improve trace propagation sampling and diagnostics
([#2604](https://github.com/supabase/supabase-js/pull/2604))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini
## v2.112.2

## 2.112.2 (2026-08-06)

### 🩹 Fixes

- **realtime:** prevent duplicate on bindings
([#2594](https://github.com/supabase/supabase-js/pull/2594))
- **realtime:** clear stale join payload on sign-out
([#2597](https://github.com/supabase/supabase-js/pull/2597))

### ❤️ Thank You

- Filipe Cabaço @filipecabaco
- Vaibhav @7ttp
## v2.112.1

## 2.112.1 (2026-08-05)

### 🩹 Fixes

- **auth:** preserve 5xx error message
([#2587](https://github.com/supabase/supabase-js/pull/2587))
- **realtime:** ensure setAuth doesn't disable token refresh
([#2592](https://github.com/supabase/supabase-js/pull/2592))

### ❤️ Thank You

- Eduardo Gurgel
- Vaibhav @7ttp
## v2.112.0

## 2.112.0 (2026-08-03)

### 🚀 Features

- **supabase:** move OpenTelemetry tracing to opt-in /tracing subpath
([#2583](https://github.com/supabase/supabase-js/pull/2583))

### 🩹 Fixes

- **auth:** accept uppercase UUIDs in validateUUID
([#2467](https://github.com/supabase/supabase-js/pull/2467))
- **postgrest:** honour throwOnError when maybeSingle finds multiple
rows ([#2580](https://github.com/supabase/supabase-js/pull/2580))
- **storage:** resolve createSignedUrls return type mismatch
([#2474](https://github.com/supabase/supabase-js/pull/2474))
- **storage:** expose service error code on StorageApiError
([#2537](https://github.com/supabase/supabase-js/pull/2537))
- **supabase:** forward db retry option
([#2571](https://github.com/supabase/supabase-js/pull/2571))

### ❤️ Thank You

- Anubhav Anand @i-anubhav-anand
- Gourab Singha @gourabsingha1
- Juhef @juheff
- Katerina Skroumpelou @mandarini
- Thribhuvan
- Vaibhav @7ttp
- Zuhef Ahmed @Zuhef
## v2.111.0

## 2.111.0 (2026-07-28)

### 🚀 Features

- **auth:** store PKCE verifiers in per-flow slots to survive
overlapping flows
([#2569](https://github.com/supabase/supabase-js/pull/2569))

### ❤️ Thank You

- Katerina Skroumpelou @mandarini

This PR was created automatically.

Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
2026-08-11 11:32:52 +03:00
Joshen Lim b648db233b joshen/fe 4113 explorer markdown cells (#48846)
## Context

More groundwork for the Explorer - this PR introduces the Markdown cells
and some basic (non data persisting) editing

Markdown cells will save either on
- Save button click
- Losing focus on the code editor

Hitting esc will cancel the changes

<img width="1387" height="674" alt="image"
src="https://github.com/user-attachments/assets/f0614b37-7a11-404f-9940-8bcd4de25c57"
/>

<img width="1087" height="516" alt="image"
src="https://github.com/user-attachments/assets/0a104168-2001-4ef7-934a-7e864956b3cb"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added editable Markdown cells to notebooks, with save and cancel
controls.
* Added drag-and-drop reordering for notebook cells, including keyboard
support.
* New notebooks now include sample Markdown content to help users get
started.
* **Improvements**
* Improved drag-handle placement and consistency across sortable
sections.
* Updated notebook empty and populated states to reflect the current
cell content.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 10:41:59 +07:00
Saxon Fletcher cb35e1f98e chore(library): update routes, redirects, and naming (#48668)
Our UI Library registry is expanding to include blocks that go beyond UI
and in some cases focus purely on back-end. This PR is a precursor to
adding more back-end related blocks. This PR includes the `ui-library ->
library` rename plus redirects and small UI copy updates. Since this is
a rename we'll need to update Vercel configuration.

## Vercel rollout

Keep the Library project Root Directory as `apps/ui-library`

1. In the **Library** Vercel project, set:

   `NEXT_PUBLIC_BASE_PATH=/library`

Apply it to Preview and Production, then redeploy the Library project.

2. In the **www** Vercel project, add:

`NEXT_PUBLIC_LIBRARY_URL=<current value of NEXT_PUBLIC_UI_LIBRARY_URL>`

Apply it to Preview and Production. Keep `NEXT_PUBLIC_UI_LIBRARY_URL`
during the migration, then redeploy the www project.

3. Deploy in this order:

   1. Library project
   2. www project

4. Validate:

   - `/library`
   - `/library/docs/nextjs/password-based-auth`
   - `/ui` redirects to `/library`
- `/ui/docs/nextjs/password-based-auth` redirects to
`/library/docs/nextjs/password-based-auth`
- `/ui/docs/ai-editors-rules/*` still uses its existing Docs redirects

No Vercel dashboard redirect rules are needed. Environment-variable
changes require a new deployment.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Supabase UI Library has been renamed to **Supabase Library** across
navigation, pages, documentation, and resource links.
* The Library is now available at `/library`, with updated descriptions
covering components, blocks, and developer tools.
* **Bug Fixes**
* Added permanent redirects from legacy `/ui` URLs to corresponding
`/library` paths.
* Updated links throughout the site and documentation to prevent broken
navigation and references.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 13:37:32 +10:00
Charis 1296a1c745 feat(studio): notebook query and mutation hooks (#48907)
## Summary

Implements the "notebook query and mutation hooks" step of the notebooks
data layer:

- `data/content/notebooks/notebook-query.ts` —
`getNotebook`/`useNotebookQuery`, wrapping the existing `getContentById`
and narrowing to `type: 'notebook'`.
- `data/content/notebooks/notebooks-infinite-query.ts` —
`useNotebooksInfiniteQuery`, a typed wrapper over
`useContentInfiniteQuery` narrowing pages to notebook rows.
- `data/content/notebooks/notebook-upsert-mutation.ts` —
`createNotebook`/`updateNotebook` + their mutation hooks, PUTting
through the existing `upsertContent`.

Write-path correctness, worked out while building the mutation hooks:

- Cell `id`s are always backend-generated, never client-supplied — a
brand-new cell has no `id` at all; an existing cell being kept/edited in
an update keeps its real id so the backend can diff it against the
previous version. `notebook-schema.ts` gains
`writableCellSchema`/`writableNotebookSchema` (ids optional per cell)
and `WritableCell`/`WritableNotebook` types, derived from `z.infer` of
those schemas rather than hand-duplicated, with only the `sql` field
re-branded per cell type via a small distributive conditional type.
- Cell SQL at this write boundary must already be
`SafeSqlFragment`/`SafeLogSqlFragment` (proven user-authored at a
save/run event handler), not `unchecked_sql` — matching the
`safe-sql-execution` skill's provenance model.
- `content-remap.ts`'s notebook `unmapSqlContentField` branch is
simplified to a passthrough: notebook writes only ever arrive already
wire-shaped via `createNotebook`/`updateNotebook`, so there's nothing
left to unmap.

Note: this was originally stacked on
`feature/notebooks-types-convergence`, but that branch merged into
`master` (#48905) while this PR was in progress, so it's rebased
directly onto `master` now.

## Test plan

- [x] `pnpm --filter studio run typecheck` passes
- [x] `pnpm --filter studio exec vitest run data/content/notebooks
data/content/content-remap.test.ts` — 38/38 passing
- [x] `pnpm --filter studio exec eslint` clean on all touched files

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added notebook listing with pagination, filtering, sorting, and
project-specific queries.
  * Added notebook retrieval for viewing individual notebooks.
  * Added notebook creation and editing with automatic content refresh.
* Added support for preserving cell IDs and safely handling SQL content.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-10 15:32:46 -04:00
Charis 0111aa371b ref(studio): converge notebook UI types with canonical content schema (#48905)
## Summary
- Joshen's `state/notebooks/types.ts` (Explorer/notebook editor UI)
redefined its own `TimeRange`, cell union, and `NotebookContent` shapes,
duplicating the canonical schema from
`data/content/notebooks/notebook-schema.ts` (#48813, #48815).
- Points `Notebook.content` and `notebooksState.updateCells` at the
canonical `Notebooks.Content` / `Notebooks.Cell` types (via `@/types`)
instead, and fixes the handful of call sites that constructed notebook
content by hand to match the real wire shape: `schema_version: 1` (not
`'1.0'`) and `_tag`-discriminated cells (e.g. `{ _tag: 'markdown_cell',
id, text }` instead of `{ type: 'markdown', content }`).
- No behavioral changes — Joshen's state management, editor component,
and hooks are untouched aside from the type-level fixes needed to
compile against the canonical schema.

## Test plan
- [x] `pnpm exec tsc --noEmit` — no new errors
- [x] `pnpm exec vitest run state/notebooks/notebooks-state.test.ts
components/interfaces/Explorer/__tests__/NotebookEditor.test.tsx` — 8/8
passing
- [x] `pnpm exec eslint` on changed files — clean
- [x] `pnpm exec prettier --check` on changed files — clean

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated notebook content handling to use the current schema version
format.
* Improved compatibility for markdown cells, including their identifiers
and text.
* Standardized notebook content and cell updates for more consistent
behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-10 13:39:02 -04:00
Ali Waseem b04d14856a Resolve AI opt-in and tracing settings server-side (#48855)
The AI endpoints resolved organization and project settings
independently and applied them together without confirming they belonged
to the same pairing. Consolidates both into a single `getAIDetails` that
reconciles them and falls back to the most restrictive posture when
unconfirmed, and applies the HIPAA sensitivity gate to the opt-in level,
which previously only existed on the client.

Fixes FE-4110

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Consolidated AI access details across organization and project
settings.
- AI functionality now validates project ownership and disables access
for mismatched or HIPAA-sensitive projects.
- AI responses include plan, region, opt-in status, sensitivity,
authorization, and advanced model access information.

- **Bug Fixes**
- Improved fail-closed behavior when project or organization data is
missing or inconsistent.
- Updated AI generation, feedback, rate, and policy flows to
consistently apply consolidated access settings.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-10 10:34:31 -06:00
CharisandJoshen Lim 957e9fec67 feat(studio): notebook content at the API boundary (#48815)
## Summary

Stacked on #48813 (1.2: notebook content schema). Part of
[FE-4109](https://linear.app/supabase/issue/FE-4109/notebooks-data-model)
— see that issue for the rest of the notebooks data-model stack.

- Teach `content-remap.ts`'s wire↔domain dispatcher about the `notebook`
content type, branding each cell's `sql` per `_tag` via the notebook
schemas added in 1.2 (parses through `notebookDomainSchema` on the way
in, unbrands per cell on the way out).
- Add `{ type: 'notebook'; content: Notebooks.Content }` to the
`Content` union in `content-query.ts`, plus a `ContentOfType<T>` helper
for narrowing it.
- Fix the resulting narrowing fallout at call sites that assumed
`Content` only ever meant `sql`/`report`/`log_sql`: two
generated-query-param casts, and four report/logs call sites now
narrowed via `ContentOfType<'report'>` / `ContentOfType<'log_sql'>`.

## Test plan

- [x] `pnpm --filter studio vitest run data/content/` — 35 tests pass,
including new notebook coverage in `content-remap.test.ts` (per-cell
brand separation, missing-field throw, remap↔unmap round-trip)
- [x] `pnpm typecheck` — clean (pre-existing unrelated `ui-patterns`
error aside)
- [x] `pnpm --filter studio lint` — no new warnings/errors on changed
files
- [x] `pnpm format` — clean

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-10 10:15:24 -04:00
Riccardo Busetti c3742ba07f ref(pipelines): Align handling of credentials (#48896) 2026-08-10 14:40:02 +02:00
Pedro RodriguesandClaude Opus 4.8 6594f412f9 docs: add Warp as a supported MCP client (#48838)
Adds [Warp](https://www.warp.dev/) as a supported client in the Supabase
MCP docs. Because [Warp speaks the native remote (Streamable HTTP)
transport](https://docs.warp.dev/agents/capabilities/mcp/), the standard
config connects to the hosted server directly, no `mcp-remote` proxy
needed:

```json
{ "mcpServers": { "supabase": { "url": "https://mcp.supabase.com/mcp" } } }
```

The MCP client list is data-driven, so this single addition surfaces in
the docs MCP panel, the generated markdown, and Studio's Connect panel.
Concretely: registers the `warp` client (config file
`~/.warp/.mcp.json`, docs link) under the IDE group, adds setup
instructions (auto-load + Settings → AI → MCP Servers, automatic OAuth),
and adds the official Warp logo in light and dark variants.

## What is Warp?

Warp is an agentic development environment built from the terminal: a
Rust-based, GPU-accelerated app that runs coding agents (Claude Code,
Codex, Gemini) directly in the terminal. It has first-class MCP support
with native remote (Streamable HTTP / SSE) transport and automatic OAuth
(no PAT required).

## Why add support for the Supabase MCP server?

Warp is a mainstream, widely-adopted client
([warpdotdev/warp](https://github.com/warpdotdev/warp) has 64k+ ⭐ on
GitHub) that natively supports MCP. Documenting it lets Warp users
connect the hosted Supabase MCP server with a copy-paste config,
matching the coverage we already provide for Cursor, VS Code, Windsurf,
and others.

## How to test

1. Run the docs app (`pnpm dev:docs`) and open the MCP guide
(`apps/docs/content/guides/ai-tools/mcp.mdx`). Warp appears under
**IDE** with its logo (verify both light and dark themes) and the config
snippet.
2. In Warp, add the shown config to `~/.warp/.mcp.json` (or **Settings →
Agents → MCP Servers → + Add**). Warp auto-spawns the `supabase` server.
4. Click **Start** on the `supabase` server → complete the Supabase
OAuth in the browser → the Supabase tools load.

<img width="859" height="606" alt="image"
src="https://github.com/user-attachments/assets/8c931ded-4ffe-4495-b4c8-183f93be812a"
/>


Verified end-to-end on Warp v0.2026.07.29 (macOS): the config auto-loads
and connects over Warp's native remote transport, and the OAuth flow
completes without a PAT.

Refs
[AI-1031](https://linear.app/supabase/issue/AI-1031/docs-add-warp-as-a-supported-mcp-client)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added Warp as a supported MCP client.
* Added setup guidance for connecting remote MCP servers in Warp,
including OAuth authentication and secure credential storage.
  * Added light and dark Warp icons to the client selection interface.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-10 08:09:17 +01:00
kemal.earth ae9042ceb4 feat(docs): scoped pat update (#48802)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Updates docs around scoped PAT's. 


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified that temporary database access uses a Personal Access Token
as the Postgres role password.
* Updated API documentation to explain that Personal Access Tokens
support custom expiration rather than being described as long-lived.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-10 08:07:24 +01:00
kemal.earth 5b68af1720 feat(studio): role-aware access feedback in scoped token creation (#48858)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Remaining bits of #48714


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added role-aware access checks throughout scoped token creation.
* Organization selectors now disable project-only organizations and
recommend project-scoped tokens when appropriate.
* Review screens highlight missing capabilities and permissions
exceeding your current role.
  * Permission rows display indicators when access exceeds your role.
* Added resource keys, labels, and summaries to improve token review
clarity.

* **Documentation**
* Updated permission guidance with links to access-control
documentation.

* **Bug Fixes**
* Corrected project selector behavior when no organization is selected.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-08 08:19:35 +01:00
Joshen Lim 6c414e363d Initialize notebook editor page (#48842)
## Context

More groundwork for the Explorer - this PR initializes the Notebook
editor page which you can access with the "New notebook" CTA

As usual nothing functional just yet, but this PR also addresses some UI
functionality
- Creating more than 1 notebook will open multiple tabs (it wasn't
previously)
- Swapping between notebooks will update the URL (wasn't previously as
well)

Will probably start looking into the cells next, starting with
MarkdownCell followed by QueryCell

<img width="1390" height="894" alt="image"
src="https://github.com/user-attachments/assets/a467cdb4-f99f-43db-8106-c15c26c1bfbf"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added notebook creation actions from the Explorer home and navigation
areas.
* Introduced a full notebook editor with title editing, rename support,
and Analyze, Run, and Save controls.
  * Added options to create query or Markdown cells in empty notebooks.
* Notebook tabs now open the corresponding notebook in the project
Explorer.

* **Bug Fixes**
* Improved Explorer layout sizing and notebook tab navigation behavior.
* Improved notebook tab labels and editing behavior, including
cancellation with Escape and submission with Enter or blur.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-08 10:48:47 +07:00
Miranda LimonczenkoandClaude Opus 5 777c02c205 test(docs): scan changed pages for WCAG 2.1 A/AA in warn mode (#48727)
Closes DOCS-1233

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Test coverage. The docs accessibility check now covers the full WCAG 2.1
A/AA rule set instead of two rules.

**Note:** This PR tests _only_ the main article of changed pages
(meaning, the content itself). A follow-up Linear issue is to address
scanning the pieces outside of that: header, navigation, and interactive
elements.

## What is the current behavior?

The `@a11y` test in `e2e/docs` runs two axe rules against each in-scope
page, `heading-order` and `page-has-heading-one`. Both already pass
everywhere, so the check only guards a result we have. Nothing else in
WCAG A/AA is checked.

## What is the new behavior?

The same test runs the full WCAG 2.1 A/AA rule set.

- **Existing debt does not block PRs.** Only the two heading rules fail.
Everything else reports.
- **The check stays fast.** It scans the article only and skips nine
rules that cannot fire there. Scan time drops from 2405ms to 981ms.
- **Findings belong to us.** Legacy mode excludes cross-origin frames.
YouTube embeds were counting against us, 11 of 15 violations on one
page.
- **A pass carries meaning.** A 404 reports as a load failure, not an
a11y bug. A page scanned before it hydrates warns instead of quietly
reporting clean.

## How the findings appear

The test is named `has no blocking accessibility violations`, so a
failure listed by CI is always something to fix. It is not named for the
full rule set, because a green check would then claim more than the
check verifies.

| | Rules | Where you see it |
| --- | --- | --- |
| Blocking | `heading-order`, `page-has-heading-one` | Test failure, so
the runner reports it on the PR |
| Reported | Everything else in WCAG A/AA | `::warning` annotation on
the run |

An annotation looks like this, on a run that still passes:

```
::warning title=Accessibility::/docs/guides/database/functions has 1 non-blocking accessibility finding(s): frame-title (4)
```

The full axe result for each page is attached to the report as
`axe-results.json`.

## Matching the Studio ratchet

This follows the ESLint ratchet in `apps/studio`. That pattern warns on
pre-existing debt rather than blocking on it, surfaces findings as
annotations rather than PR comments, and promotes a rule to an error
once its violations reach zero.

The mechanism here is `ENFORCED_RULES` in `utils/axe-helpers.ts`. The
two heading rules are on it because the heading-hierarchy work drove
them to zero site-wide.

The intent is to migrate rules into that list one at a time. Pick a
rule, fix its violations, then move it into `ENFORCED_RULES` so it
cannot come back. An exhaustive scan of the site groups the current
backlog by root cause to sequence that work, and two fixes cover 99.1%
of it.

Studio keeps per-file baseline counts, which this does not. A whole-rule
list is coarser, and it works here because docs violations reach zero
across the site rather than per file.

## Manual testing

Install the browser once, then run each step from the repo root. Every
command scans production, so you do not need a local docs server.

```bash
pnpm -C e2e/docs exec playwright install chromium
```

1. Confirm a reported finding does not fail the check.

   ```bash
DOCS_E2E_PAGE_PATHS=/docs/guides/database/functions
PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y
   ```

Expect `1 passed`, and the `::warning` annotation above in the output.

2. Confirm the scan finds that violation. Same page, now failing on
every rule.

   ```bash
A11Y_ENFORCE_ALL=1 DOCS_E2E_PAGE_PATHS=/docs/guides/database/functions
PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y
   ```

Expect `1 failed`, reporting `frame-title (serious, 4 node(s))`. Steps 1
and 2 together are the point of this PR.

3. Confirm the skipped rules stay skipped.

   ```bash
A11Y_ENFORCE_ALL=1
DOCS_E2E_PAGE_PATHS=/docs/guides/getting-started/quickstarts/nextjs
PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y
   ```

Expect `button-name (critical, 2 node(s))` and `label (critical, 2
node(s))`, and no `color-contrast`.

4. Confirm a page that does not load reports a load failure.

   ```bash
DOCS_E2E_PAGE_PATHS=/docs/guides/does-not-exist-xyz
PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y
   ```

Expect `Expected a successful response for
/docs/guides/does-not-exist-xyz, got 404`, and no axe assertion.

5. Confirm the link checker still passes alongside the a11y test.

   ```bash
DOCS_E2E_PAGE_PATHS=/docs/guides/auth/passwords
PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs
   ```

   Expect `3 passed`.

## Known gaps

- `/docs/reference/*` is not scanned. Those routes render client-side
into tens of thousands of elements, where axe exceeds its timeout and
results depend on whether the scan caught the page mid-render.
- Shared chrome is outside the article scope, so nav, sidebar, footer,
menus, and drawers are not covered.
- axe catches roughly 30-40% of WCAG issues. Keyboard navigation, focus
management, and screen reader behavior still need manual testing.

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:41:23 -07:00