mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 19:05:06 +03:00
fix-realtime-getting_started-code-snippet
6020
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
47595f8ac7 |
feat(self-hosted): implement queryLogs for the MCP debugging tools (#48900)
> [!IMPORTANT] > > Only merge this when (https://github.com/supabase/platform/pull/36804) is merged, as the AI assistant will not have access to the `query_logs` tool for the remote MCP server ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature (self-hosted / CLI Studio MCP server). ## What is the current behavior? Self-hosted `getDebuggingOperations` (`apps/studio/lib/api/self-hosted/mcp.ts`) implements only `getLogs`, so the MCP `debugging` group exposes `get_logs` — a fixed per-service log dump built by `getLogQuery`. Logs are served by Logflare, which speaks BigQuery SQL. ## What is the new behavior? Bumps `@supabase/mcp-server-supabase` to `^0.10.0` (adds `query_logs` + `logsDialect`, and hides `get_logs` wherever a platform declares `queryLogs`) and moves logs over to it. - **Self-hosted `query_logs`:** declares `logsDialect: 'bigquery'` and implements `queryLogs`, passing the model's SQL straight through to the same Logflare `logs.all` endpoint (arbitrary `sql` param) — no new endpoint, no dialect translation. - **Drops `get_logs` from self-hosted:** `getLogs` throws (the server hides it once `queryLogs` exists) and the per-service `getLogQuery` builder is deleted; the model now writes its own BigQuery SQL, guided by the dialect schema hint. - **Honors no-logs mode:** `query_logs` throws when `logs:all` is disabled — the self-hosted default, enabled via the `docker-compose.logs.yml` override. - **Assistant:** switches the dashboard assistant from `get_logs` to `query_logs` (allowlist, drift guard, prompt, mocks, evals). Refs AI-1046 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * AI debugging can query recent project logs using read-only SQL. * Log queries support optional time-range filters, filtering, aggregation, and joins. * Self-hosted debugging checks whether logging is enabled before running queries. * **Bug Fixes** * Updated debugging workflows and validation to consistently use the new log-query capability. * Removed reliance on legacy service-specific log filtering and query behavior. * **Documentation** * Updated MCP debugging tool guidance to describe SQL-based log queries. * **Tests** * Expanded coverage for enabled, disabled, and unsupported logging scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
cd906a176a |
Add empty state for database connections page if preview not enabled (#48927)
## Context Just adds an empty state for the database connections page if the feature preview isn't enabled. Users can technically still land on the /connections page irregardless and the docs changes [here](https://github.com/supabase/supabase/pull/48920) references this page too - so this just adds an empty state to allow users to enable the feature preview <img width="1388" height="573" alt="image" src="https://github.com/user-attachments/assets/dfd3a0b4-11b4-42b1-b5eb-fce8c03c35e6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a feature preview experience for Database Connections. * Users with the preview enabled can view connection activity, live updates, refreshed data, and related controls. * Users without access see a preview badge, an empty state, and an option to enable the preview. * The live status indicator is hidden when the preview is inactive. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7c4872ad32 |
Add Studio ExplorerQuery shell (#48926)
## Summary Adds the Studio-owned `ExplorerQuery` shell used by notebooks, SQL snippets, dedicated query tabs, and assistant query blocks within Explorer. - provides framed embedded and full-height viewport roots - provides composable editor, results, and footer layout regions - keeps result content responsible for its own scrolling while the results region fills remaining height - remains presentational: query models, execution, source resolution, persistence, and result rendering stay external - expands the project-local Explorer agent skill with composition and sizing guidance - adds focused Studio component tests All files are scoped to `apps/studio`; this PR no longer changes `ui-patterns` or the design-system app. ## Stack - Base: #48925 - Next: #48961 - This PR targets `chore/toolbar-component`, so its review diff contains only the query shell layer. ## Validation - `pnpm --filter studio exec vitest run components/interfaces/Explorer/ExplorerQuery/ExplorerQuery.test.tsx components/interfaces/Explorer/ExplorerToolbar/ExplorerToolbar.test.tsx` — 6 tests passed - `pnpm --filter studio typecheck` - Prettier - `git diff --check` |
||
|
|
fb80d8cf86 |
Add Studio Explorer toolbar (#48925)
## Summary Adds the Studio-owned `ExplorerToolbar` composition used by Explorer notebooks, chats, SQL snippets, query cells, and tabs. - provides icon, title, actions, and compact action-button slots - follows Studio's 40px header sizing with a `--header-height` fallback - keeps resource-specific state and behavior in the consuming Explorer surface - adds focused Studio component tests - adds project-local agent guidance at `apps/studio/.claude/skills/explorer/SKILL.md` These components are intentionally scoped to Studio under `apps/studio/components/interfaces/Explorer`; this PR no longer changes `ui-patterns` or the design-system app. ## Stack - Base: `master` - Next: #48926 - This is the first PR in the Explorer query component stack. ## Validation - `pnpm --filter studio exec vitest run components/interfaces/Explorer/ExplorerToolbar/ExplorerToolbar.test.tsx` — 3 tests passed - `pnpm --filter studio typecheck` - Prettier - `git diff --check` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added shared Explorer toolbar components for icons, titles, actions, custom controls, and compact buttons. * Added accessibility defaults, configurable toolbar sizing, ref forwarding, and native property support. * Added documentation covering Explorer component usage, composition, sizing, actions, state ownership, and extensions. * **Tests** * Added comprehensive coverage for toolbar composition, styling, accessibility, refs, and configurable behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
75b90c5de1 |
Check the session's backend_start for cancelling or terminating sessions (#48929)
## Context Related to database connections - specifically for cancelling queries or terminating sessions PIDs can be re-used, so a more accurate check is to use both PID and `backend_start` to uniquely identify the session to cancel or terminate <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved query cancellation and session termination reliability by verifying the active database session before taking action. * Prevented actions from affecting a different session that reused the same process ID. * Added clearer guidance to refresh when a session has changed or is no longer available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cdfb5b310f |
Add cancel query action for database connections (#48922)
## Context Related to Database Connections - Adds a "cancel query" action for "active" sessions using `pg_cancel_backend` - Gentler alternative as the connection stays alive, unlike terminating the session - Not applicable for queries idle in transaction as there's no query running (Disabled in this case) - Rename "Terminate" to "Terminate session" - Rename "Abort query" to "Terminate session" For active queries: <img width="220" height="135" alt="image" src="https://github.com/user-attachments/assets/d6ca790d-bb6a-4582-8554-24431388483a" /> For idle in txn queries: <img width="433" height="135" alt="image" src="https://github.com/user-attachments/assets/615d0651-9f5b-4efc-a5cf-72f93727aa91" /> Also updating confirmation modal for terminating session CTA: For active queries: <img width="407" height="301" alt="image" src="https://github.com/user-attachments/assets/e5f56764-11b9-4c10-ba01-d7547aaec872" /> All other queries: <img width="410" height="212" alt="image" src="https://github.com/user-attachments/assets/8631633f-5d4a-40a7-b089-6980a5180219" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features - Added a separate **Cancel query** action for active database queries. - Added **Terminate session** to close connections and roll back active transactions. - Added safeguards based on query activity and permissions. - Added confirmation guidance for active queries, including cancellation options. - Added loading, success, and error feedback for query cancellation and session termination. - Added telemetry for query-cancellation actions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
065468f8ac |
fix(studio): reset rename form after renaming a SQL snippet (#48951)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? The SQL snippet rename modal is mounted once per nav and reused for every snippet, so a single form instance is shared across renames. On a successful rename the form was never re-baselined, leaving it dirty, and the effect that synced the form to the selected snippet bailed out whenever the form was dirty. Renaming a second snippet therefore opened the modal pre-filled with the previous snippet's name, with the submit button enabled — one careless confirm renamed the wrong query. ## What is the new behavior? The form is reset after a successful rename, and the hand-rolled sync effect is replaced with react-hook-form's `values` option so the form follows whichever snippet is selected. `keepDirtyValues` keeps a background refetch from clobbering in-progress input, which is what the old dirty guard was protecting against. It has to be disabled explicitly on the resets that discard input, since `resetOptions` on `useForm` applies to every `reset` call — not just the `values`-driven one. Adds component tests covering the submit path, the rename-then-rename regression, and discarding an abandoned edit on cancel. ## Additional context Fixes FE-4114 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved the rename query experience by ensuring the selected snippet name is displayed correctly when reopening the rename dialog. - Cancelled edits are now discarded reliably, preventing unsaved changes from persisting. - After a successful rename, the form reflects the updated query name and maintains consistent input and button behavior. - **Tests** - Added coverage for successful renaming, cancellation, reopening with a newly selected snippet, and submitted values. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
810d292121 |
feat(studio): notebook cell operations (#48940)
## Summary - Pure module (`data/content/notebooks/notebook-operations.ts`) for applying `update_notebook` cell edits client-side: `insert_cell` (`after_cell_id` incl. `'start'`), `replace_cell`, `delete_cell`, `move_cell`. - Never touches the safe-sql brands — SQL promotion still happens at the tool-execute boundary, matching `create_notebook`. - Stacked on #48938. No wiring yet — `update_notebook` tool wiring is next. Towards FE-4083 ## Test plan - [x] `pnpm vitest run data/content/notebooks/notebook-operations.test.ts` — 13 unit tests covering every op, combinations, and all three error cases. - [x] `pnpm exec tsc --noEmit` clean - [x] `pnpm exec eslint` clean on new files <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for applying notebook cell operations, including insertion, replacement, deletion, and movement. * Operations are applied in a predictable order, with support for anchoring new cells at the beginning or near existing cells. * Added validation for invalid references, conflicting operations, and self-referential moves. * Added clear handling when operations produce an empty notebook result. * **Tests** * Added comprehensive coverage for individual, combined, ordered, conflicting, invalid, and empty-result notebook operations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
99545dc03a |
chore(studio): remove mcp mention in legacy token creation (#48945)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Small bit of lingering text that was leftover. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the legacy access token description to remove an outdated reference. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ddb3e2c442 |
feat(studio): create_notebook AI tool (#48938)
## Summary - Adds a `create_notebook` AI assistant tool (`needsApproval: true`) that lets the assistant create a new notebook after explicit user approval. - Cell SQL is promoted from untrusted to safe via `acceptUntrustedSql`/`acceptUntrustedLogsSql` inside `execute`, using the approval gate as the confirming user gesture (same pattern as `execute_sql`). - Input is validated against the existing agent-writable notebook schema, which rejects any agent-supplied cell `id` at the schema level. - Threads an optional auth-headers param through `upsertContent`/`createNotebook`/`updateNotebook` so the tool can pass its own bearer token server-side. - Registers the tool in the tool-filter (`SCHEMA` category, alongside `list_notebooks`/`get_notebook`) and adds a `## Notebooks` prompt section guiding the assistant on when to use `create_notebook` vs. one-off `execute_sql`. Resolves FE-4082 ## Test plan - [x] `notebook-tools.test.ts` covers: tool registration, `needsApproval`, cell-id rejection, valid input, PUT body shape, and the returned id — all passing - [x] Typecheck clean - [x] Lint clean (no new warnings) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added AI-assisted notebook creation for saving multi-step investigations. * Added support for database and log SQL cells in newly created notebooks. * Notebook creation requires approval before saving and returns the notebook’s name and identifier. * Added support for custom request headers during notebook and content operations. * Added guidance for choosing between one-time SQL execution and reusable notebooks when Explorer is enabled. * **Improvements** * Improved validation and normalization of notebook content before saving. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e846d45ce6 |
chore(studio): retry flaky unit tests in CI (#48939)
<!-- ccr-slack-attribution --> _Requested via [Slack thread](https://supabase.slack.com/archives/C063LNYJJKS/p1786454906416269?thread_ts=1786454906.416269&cid=C063LNYJJKS)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / CI reliability. One-line config change to `apps/studio/vitest.config.ts`. ## What is the current behavior? **Before:** the `Studio Unit Tests & Build Check` workflow sometimes goes red on `master` for no reason anyone can act on. Since 2026-07-29 it failed 3 out of 82 test executions (3.7%), every time at job `test (1)`, step `Run Tests`. Every one of those three passed on a re-run with no code change: - https://github.com/supabase/supabase/actions/runs/31495760766 (`4587d177`, Aug 11) - https://github.com/supabase/supabase/actions/runs/31409667566 (`b04d1485`, Aug 10) - https://github.com/supabase/supabase/actions/runs/31203465483 (`777c02c2`, Aug 7) Each failure also posts a Slack alert to #team-frontend-alerts via `.github/workflows/studio-master-alert.yml`, so someone gets pinged, opens the run, clicks re-run, and it goes green. ## What is the new behavior? **After:** a test that fails in CI gets up to two more attempts before the job is marked failed. A genuinely broken test still fails all three attempts and still goes red. Locally nothing changes — the first failure is the result you see, so you are never waiting on retries while debugging. ## Additional context **How:** added `retry: IS_CI ? 2 : 0` to the `test` block of `apps/studio/vitest.config.ts`, with `const IS_CI = !!process.env.CI` matching the pattern already used in `e2e/studio/playwright.config.ts:51` (`retries: IS_CI ? 5 : 0`). **Known limitation — we do not know which test is flaking.** The GitHub Actions log downloads for those three runs were not retrievable, and the API only surfaces `Process completed with exit code 1`. So this treats the symptom without naming the cause. The natural follow-up is to upload a JUnit or JSON vitest report as an artifact with `if: always()`, which would name the flaking test on the next failure. That is deliberately **not** in this PR — it is a workflow change and was scoped out. One more honest caveat: per-test retry only helps if the failure is an assertion or timeout inside a test. If the real cause is a worker crash or OOM, retrying will not save the run. That is a live possibility here — the workflow sets `NODE_OPTIONS: '--max_old_space_size=3072'` with the in-repo comment "Default is 2 GB, increase to have less frequent OOM errors", which says someone has already hit memory pressure in this job. So: worth landing as a cheap reduction in false alarms, but if the 3.7% does not drop, the report artifact is the next step rather than more retries. --- _Generated by [Claude Code](https://claude.ai/code/session_01U4338RsMYAc1uGuwTFNGBD)_ Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
4587d177c3 |
Add optional title field to notebook cells (#48937)
## Summary - Adds optional `title` field to `databaseCellSchema` and `logCellSchema` in notebook schema - Allows database and logs notebook cells to carry descriptive titles - Field automatically propagates through derived schemas (wire, writable, agent, domain) via Zod inheritance <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added optional titles to database and log notebook cells. * Cell titles are now preserved across notebook editing, viewing, and agent workflows. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0f2f3e4eb7 |
fix: update storage size unit correctly after navigation (#48932)
Fixes FE-4128. ## What is the current behavior? When updating the global Storage file size limit using a unit other than MB, the selected unit displays an incorrect value after navigating away from the Storage settings page and returning. The updated file size is persisted correctly by the API, but the unit selector does not always reflect the value derived from the persisted configuration. The Save button also remains enabled after successfully saving the updated configuration. ## What is the new behavior? The file size unit selector now correctly reflects the unit derived from the persisted global file size limit after saving and navigating between pages. The form state is also correctly synchronized with the latest Storage configuration after an update, so the Save button returns to its disabled state once the changes have been persisted. ## Additional context The Storage API persists the global file size limit in bytes rather than persisting the selected display unit separately. The dashboard derives the appropriate unit (MB/GB) from the stored byte value when loading the configuration. The issue was caused by the unit Select retaining stale internal state when the form values were reset after the Storage configuration was loaded/refetched. Ensuring the Select is refreshed when the controlled unit changes keeps the displayed unit synchronized with the form state. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved storage settings form initialization when configuration and entitlements load. * Ensured storage unit selections and placeholders display consistently. * Improved form resetting to reflect the latest loaded settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7798e42435 |
feat(studio): notebook read tools (#48908)
## Summary - Adds `list_notebooks` (cursor-paginated) and `get_notebook` AI tools in `lib/ai/tools/notebook-tools.ts`, modeled directly on `report-tools.ts`: server-side `getContent`/`getNotebook` with the `authorization` header forwarded, zod-validated input. - `get_notebook` resolves every cell and exposes `unchecked_sql` as a plain `sql` field for the agent to read — display only, per the `safe-sql-execution` skill; nothing here executes SQL. - Registers both tools in `lib/ai/tools/index.ts` (same platform branch as reports) and in `lib/ai/tool-filter.ts`'s `toolSetValidationSchema` + `TOOL_CATEGORY_MAP` (`SCHEMA` tier). - Adds an optional `headers` param to `content-infinite-query.ts`'s `getContent`, mirroring the sibling `content-query.ts`, so the cursor-paginated fetch can carry the `Authorization` header from a server context. - New tools are behind the Explorer feature flag. Stacked on #48907 (1.4 — notebook query and mutation hooks), per the Notebooks implementation plan (stack 2.1). Resolves FE-4081 Resolves FE-4080 ## Test plan - [x] `pnpm exec tsc --noEmit` — no new errors - [x] `pnpm exec vitest run lib/ai/tools/notebook-tools.test.ts lib/ai/tools/index.test.ts lib/ai/tools/report-tools.test.ts data/content/notebooks` — 36/36 passing - [x] `pnpm --filter studio run lint` — no new warnings - [x] `pnpm exec prettier --check` on changed files — clean <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added AI tools to list project notebooks with pagination. * Added AI support for retrieving notebook markdown and resolved SQL cell content. * Notebook tools now respect project and authorization context. * Notebook features are available only when Explorer access is enabled. * Content requests can forward custom request headers. * **Tests** * Added coverage for notebook tools, Explorer access, feature flags, authorization, pagination, and error handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1cc0682c47 |
chore(studio): remove admonition now that mcp supports scoped pat (#48931)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This removes the pre-cautionary admonition we had before the MCP support for scoped access tokens landed. We can now remove this admonition (and anything related) as it's been merged. | Before | After | |--------|--------| | <img width="790" height="202" alt="Screenshot 2026-08-11 at 09 11 08" src="https://github.com/user-attachments/assets/8b99d93f-c398-4b86-84fe-e63a2ba40e26" /> | <img width="781" height="104" alt="Screenshot 2026-08-11 at 09 17 18" src="https://github.com/user-attachments/assets/b28b8262-ec01-4686-ace8-50065eb22822" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Changes** * Removed the MCP unsupported warning from scoped access-token creation and viewing screens. * Removed the option to switch from scoped-token creation to the legacy account-wide token flow. * MCP tools now display directly when available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b648db233b |
joshen/fe 4113 explorer markdown cells (#48846)
## Context More groundwork for the Explorer - this PR introduces the Markdown cells and some basic (non data persisting) editing Markdown cells will save either on - Save button click - Losing focus on the code editor Hitting esc will cancel the changes <img width="1387" height="674" alt="image" src="https://github.com/user-attachments/assets/f0614b37-7a11-404f-9940-8bcd4de25c57" /> <img width="1087" height="516" alt="image" src="https://github.com/user-attachments/assets/0a104168-2001-4ef7-934a-7e864956b3cb" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added editable Markdown cells to notebooks, with save and cancel controls. * Added drag-and-drop reordering for notebook cells, including keyboard support. * New notebooks now include sample Markdown content to help users get started. * **Improvements** * Improved drag-handle placement and consistency across sortable sections. * Updated notebook empty and populated states to reflect the current cell content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cb35e1f98e |
chore(library): update routes, redirects, and naming (#48668)
Our UI Library registry is expanding to include blocks that go beyond UI and in some cases focus purely on back-end. This PR is a precursor to adding more back-end related blocks. This PR includes the `ui-library -> library` rename plus redirects and small UI copy updates. Since this is a rename we'll need to update Vercel configuration. ## Vercel rollout Keep the Library project Root Directory as `apps/ui-library` 1. In the **Library** Vercel project, set: `NEXT_PUBLIC_BASE_PATH=/library` Apply it to Preview and Production, then redeploy the Library project. 2. In the **www** Vercel project, add: `NEXT_PUBLIC_LIBRARY_URL=<current value of NEXT_PUBLIC_UI_LIBRARY_URL>` Apply it to Preview and Production. Keep `NEXT_PUBLIC_UI_LIBRARY_URL` during the migration, then redeploy the www project. 3. Deploy in this order: 1. Library project 2. www project 4. Validate: - `/library` - `/library/docs/nextjs/password-based-auth` - `/ui` redirects to `/library` - `/ui/docs/nextjs/password-based-auth` redirects to `/library/docs/nextjs/password-based-auth` - `/ui/docs/ai-editors-rules/*` still uses its existing Docs redirects No Vercel dashboard redirect rules are needed. Environment-variable changes require a new deployment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Supabase UI Library has been renamed to **Supabase Library** across navigation, pages, documentation, and resource links. * The Library is now available at `/library`, with updated descriptions covering components, blocks, and developer tools. * **Bug Fixes** * Added permanent redirects from legacy `/ui` URLs to corresponding `/library` paths. * Updated links throughout the site and documentation to prevent broken navigation and references. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1296a1c745 |
feat(studio): notebook query and mutation hooks (#48907)
## Summary Implements the "notebook query and mutation hooks" step of the notebooks data layer: - `data/content/notebooks/notebook-query.ts` — `getNotebook`/`useNotebookQuery`, wrapping the existing `getContentById` and narrowing to `type: 'notebook'`. - `data/content/notebooks/notebooks-infinite-query.ts` — `useNotebooksInfiniteQuery`, a typed wrapper over `useContentInfiniteQuery` narrowing pages to notebook rows. - `data/content/notebooks/notebook-upsert-mutation.ts` — `createNotebook`/`updateNotebook` + their mutation hooks, PUTting through the existing `upsertContent`. Write-path correctness, worked out while building the mutation hooks: - Cell `id`s are always backend-generated, never client-supplied — a brand-new cell has no `id` at all; an existing cell being kept/edited in an update keeps its real id so the backend can diff it against the previous version. `notebook-schema.ts` gains `writableCellSchema`/`writableNotebookSchema` (ids optional per cell) and `WritableCell`/`WritableNotebook` types, derived from `z.infer` of those schemas rather than hand-duplicated, with only the `sql` field re-branded per cell type via a small distributive conditional type. - Cell SQL at this write boundary must already be `SafeSqlFragment`/`SafeLogSqlFragment` (proven user-authored at a save/run event handler), not `unchecked_sql` — matching the `safe-sql-execution` skill's provenance model. - `content-remap.ts`'s notebook `unmapSqlContentField` branch is simplified to a passthrough: notebook writes only ever arrive already wire-shaped via `createNotebook`/`updateNotebook`, so there's nothing left to unmap. Note: this was originally stacked on `feature/notebooks-types-convergence`, but that branch merged into `master` (#48905) while this PR was in progress, so it's rebased directly onto `master` now. ## Test plan - [x] `pnpm --filter studio run typecheck` passes - [x] `pnpm --filter studio exec vitest run data/content/notebooks data/content/content-remap.test.ts` — 38/38 passing - [x] `pnpm --filter studio exec eslint` clean on all touched files <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added notebook listing with pagination, filtering, sorting, and project-specific queries. * Added notebook retrieval for viewing individual notebooks. * Added notebook creation and editing with automatic content refresh. * Added support for preserving cell IDs and safely handling SQL content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0111aa371b |
ref(studio): converge notebook UI types with canonical content schema (#48905)
## Summary - Joshen's `state/notebooks/types.ts` (Explorer/notebook editor UI) redefined its own `TimeRange`, cell union, and `NotebookContent` shapes, duplicating the canonical schema from `data/content/notebooks/notebook-schema.ts` (#48813, #48815). - Points `Notebook.content` and `notebooksState.updateCells` at the canonical `Notebooks.Content` / `Notebooks.Cell` types (via `@/types`) instead, and fixes the handful of call sites that constructed notebook content by hand to match the real wire shape: `schema_version: 1` (not `'1.0'`) and `_tag`-discriminated cells (e.g. `{ _tag: 'markdown_cell', id, text }` instead of `{ type: 'markdown', content }`). - No behavioral changes — Joshen's state management, editor component, and hooks are untouched aside from the type-level fixes needed to compile against the canonical schema. ## Test plan - [x] `pnpm exec tsc --noEmit` — no new errors - [x] `pnpm exec vitest run state/notebooks/notebooks-state.test.ts components/interfaces/Explorer/__tests__/NotebookEditor.test.tsx` — 8/8 passing - [x] `pnpm exec eslint` on changed files — clean - [x] `pnpm exec prettier --check` on changed files — clean <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated notebook content handling to use the current schema version format. * Improved compatibility for markdown cells, including their identifiers and text. * Standardized notebook content and cell updates for more consistent behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b04d14856a |
Resolve AI opt-in and tracing settings server-side (#48855)
The AI endpoints resolved organization and project settings independently and applied them together without confirming they belonged to the same pairing. Consolidates both into a single `getAIDetails` that reconciles them and falls back to the most restrictive posture when unconfirmed, and applies the HIPAA sensitivity gate to the opt-in level, which previously only existed on the client. Fixes FE-4110 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Consolidated AI access details across organization and project settings. - AI functionality now validates project ownership and disables access for mismatched or HIPAA-sensitive projects. - AI responses include plan, region, opt-in status, sensitivity, authorization, and advanced model access information. - **Bug Fixes** - Improved fail-closed behavior when project or organization data is missing or inconsistent. - Updated AI generation, feedback, rate, and policy flows to consistently apply consolidated access settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
957e9fec67 |
feat(studio): notebook content at the API boundary (#48815)
## Summary Stacked on #48813 (1.2: notebook content schema). Part of [FE-4109](https://linear.app/supabase/issue/FE-4109/notebooks-data-model) — see that issue for the rest of the notebooks data-model stack. - Teach `content-remap.ts`'s wire↔domain dispatcher about the `notebook` content type, branding each cell's `sql` per `_tag` via the notebook schemas added in 1.2 (parses through `notebookDomainSchema` on the way in, unbrands per cell on the way out). - Add `{ type: 'notebook'; content: Notebooks.Content }` to the `Content` union in `content-query.ts`, plus a `ContentOfType<T>` helper for narrowing it. - Fix the resulting narrowing fallout at call sites that assumed `Content` only ever meant `sql`/`report`/`log_sql`: two generated-query-param casts, and four report/logs call sites now narrowed via `ContentOfType<'report'>` / `ContentOfType<'log_sql'>`. ## Test plan - [x] `pnpm --filter studio vitest run data/content/` — 35 tests pass, including new notebook coverage in `content-remap.test.ts` (per-cell brand separation, missing-field throw, remap↔unmap round-trip) - [x] `pnpm typecheck` — clean (pre-existing unrelated `ui-patterns` error aside) - [x] `pnpm --filter studio lint` — no new warnings/errors on changed files - [x] `pnpm format` — clean --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
c3742ba07f | ref(pipelines): Align handling of credentials (#48896) | ||
|
|
5b68af1720 |
feat(studio): role-aware access feedback in scoped token creation (#48858)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Remaining bits of #48714 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added role-aware access checks throughout scoped token creation. * Organization selectors now disable project-only organizations and recommend project-scoped tokens when appropriate. * Review screens highlight missing capabilities and permissions exceeding your current role. * Permission rows display indicators when access exceeds your role. * Added resource keys, labels, and summaries to improve token review clarity. * **Documentation** * Updated permission guidance with links to access-control documentation. * **Bug Fixes** * Corrected project selector behavior when no organization is selected. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6c414e363d |
Initialize notebook editor page (#48842)
## Context More groundwork for the Explorer - this PR initializes the Notebook editor page which you can access with the "New notebook" CTA As usual nothing functional just yet, but this PR also addresses some UI functionality - Creating more than 1 notebook will open multiple tabs (it wasn't previously) - Swapping between notebooks will update the URL (wasn't previously as well) Will probably start looking into the cells next, starting with MarkdownCell followed by QueryCell <img width="1390" height="894" alt="image" src="https://github.com/user-attachments/assets/a467cdb4-f99f-43db-8106-c15c26c1bfbf" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added notebook creation actions from the Explorer home and navigation areas. * Introduced a full notebook editor with title editing, rename support, and Analyze, Run, and Save controls. * Added options to create query or Markdown cells in empty notebooks. * Notebook tabs now open the corresponding notebook in the project Explorer. * **Bug Fixes** * Improved Explorer layout sizing and notebook tab navigation behavior. * Improved notebook tab labels and editing behavior, including cancellation with Escape and submission with Enter or blur. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
124ff77ad0 |
feat(studio): warn that scoped tokens don't support the MCP server (#48849)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Scoped PATs are blocked from the Supabase MCP server until AI-1025 ships FGA guard support, so surface that on the scoped review step (with a link back into legacy mode) and on the view-token sheet, sharing one warning module for easy removal. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a clear notice explaining that scoped access tokens aren’t supported by the Supabase MCP server. * Added an option to create a legacy token when applicable. * Displayed the MCP compatibility notice in token review and access views. * **UI Improvements** * Organization selectors now display their associated icons. * Standardized MCP guidance across token-related screens for a more consistent experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
33482bdc88 |
feat(studio): lifecycle and role-aware scoped token view sheet (#48848)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Extracts the token view sheet slice of #48742
(w3b6x9/scoped-pat-access-feedback, commit
|
||
|
|
3a98b0c818 |
feat(studio): add legacy token mode to scoped pat creation flow (#48844)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Replaces the scoped form's inline account-level access mode with a proper legacy-token escape hatch: "Create legacy token" switches the sheet to the classic form (name + expiry only) and creates through the legacy endpoint, skipping the two-step review. Mirrors the mode-switch links in both directions and restores the "Generate token for experimental API" split-button dropdown, extracted into a shared ExperimentalTokenDropdown. Ported from origin/w3b6x9/scoped-pat-ui-rework, excluding its expiry handling (shipped in #48811) and MCP-unsupported warnings (follow-up PR). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for creating classic account-wide access tokens alongside scoped tokens. * Added an experimental token dropdown for quick token creation. * Added links to switch between scoped and legacy token creation flows. * Classic token creation now provides dedicated warnings and simplified access settings. * **Improvements** * Updated token access messaging, descriptions, and labels for clarity. * **Tests** * Expanded coverage for token creation, navigation, validation, and clipboard behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
e8f5120dc5 |
feat(studio): enforce expiry scoped pat (#48811)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES Waiting on #48809 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added custom access-token expiration date limits, allowing dates from today through one year ahead. * Date pickers now enforce configured minimum and maximum date boundaries. * **Updates** * Removed the option to create non-expiring access tokens. * Expiration is now required when creating classic access tokens. * Improved form reset behavior and expiry tracking. * **Tests** * Added validation coverage for required, valid, and out-of-range custom expiration dates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
f8206a5f81 |
fix(studio): model scoped pat permissions as OR-of-AND alternatives - smaller version (#48809)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Breaking down #48635 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Scoped access tokens now support alternative permission requirements, enabling more precise access for APIs and tools. - Added clearer role and resource access evaluation, including project-specific permissions and partial read access. - Access reviews now identify unavailable or excessive permissions and group inaccessible resources for easier resolution. - **Bug Fixes** - Improved handling of legacy, incomplete, or invalid permission data with safer fallback behavior. - Corrected access filtering for MCP tools and API capabilities. - **Documentation** - Updated access-review wording to clarify the relationship between scopes and related MCP tools. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
0b97e37ccf |
feat: notebook content schema (#48813)
Related to FE-4109. ## Summary - **API codegen workaround**: Platform API's `notebook` content type hasn't shipped to the OpenAPI spec yet, so `pnpm api:codegen` can't be run. Locally widened `ContentBase.type` to include `'notebook'` (marked with TODO for removal once spec publishes). - **Notebook schema & type system**: Introduced Zod schemas mirroring RFC-defined notebook shape (`schema_version: 1, cells: Cell[]`). Maintains wire/domain boundary (cell `sql` → `unchecked_sql` branded for security). Agent-writable schema for `create_notebook` tool omits cell IDs (backend-generated); future update operations will require them. All TypeScript types are `z.infer`'d from schemas (no hand-written parallel interfaces). - **IsoDateTimeString moved**: Extracted ISO datetime validator from `querySource.ts` to `lib/iso-datetime.ts` (data layer shouldn't import from components layer). Needed by notebook `time_range` fields. ## Test plan - [x] Unit tests: `notebook-schema.test.ts` (9 tests), `iso-datetime.test.ts` (3 tests), `querySource.test.ts` updated and passing (26 tests) - [x] Typecheck: no new errors - [x] Prettier: formatting clean <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added support for validating and processing notebook content, including markdown, database, log cells, time ranges, and chart configurations. - Added compatibility for notebook content types in content handling. - Added reliable ISO date-time validation for notebook data and related features. - **Tests** - Expanded coverage for valid and invalid notebook structures, cell requirements, time ranges, chart settings, and date-time values. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
a515f3d81f |
fix(ui): remove extra spacing before custom reports section (#48796)
Fixes FE-4107. ## What is the current behavior? The Observability sidebar had unnecessary spacing below the Product navigation. - Extra whitespace below the last Product menu item (`Realtime`). ## What is the new behavior? Removes the global flex gap and applies spacing explicitly to the Custom Reports section. - Product navigation ends cleanly at the divider. - Spacing before the Custom Reports section is intentional and consistent. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved spacing and alignment in the observability menu. * Added vertical separation around the custom reports section for a cleaner layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3a383c87c7 |
Initialize notebooks store (#48801)
## Context More groundwork for the Explorer - this one's focused on initializing the valtio store for managing notebooks Store architecture will follow closely with the existing sql-editor-store No data persistence yet, but can test creating a new notebook <img width="195" height="143" alt="image" src="https://github.com/user-attachments/assets/8656fb5b-3a8e-4f71-b2ce-d2f34ca9b552" /> Which should open a placeholder page <img width="1387" height="527" alt="image" src="https://github.com/user-attachments/assets/4a81b1ae-a740-40e6-9d33-29fa4f83b541" /> Closing the notebook brings you back to the explorer home page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for creating and opening project notebooks from the Explorer. * Added notebook tabs alongside existing entity and SQL tabs. * Added notebook management, including loading, renaming, removing, editing cells, and tracking unsaved changes. * Added support for SQL, logs, and Markdown notebook cells. * Added dedicated notebook routes and an initial notebook editor view. * Added notebook icons throughout the Explorer interface. * **Documentation** * Documented session-scoped notebook state for query results and row limits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5944fe66f0 |
fix inconsistent product menu dividers (#48787)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Product menu section dividers use the stronger `border-overlay` colour, while the product heading divider uses `border-default`. ## What is the new behavior? Product menu section dividers use the same `border-default` token as the product heading divider in light and dark mode. | Before | After | | --- | --- | | <img width="636" height="1378" alt="CleanShot 2026-08-06 at 15 56 15@2x" src="https://github.com/user-attachments/assets/1628bef1-47c3-4f66-95a8-51b148784cac" /> | <img width="636" height="1378" alt="CleanShot 2026-08-06 at 15 55 55@2x" src="https://github.com/user-attachments/assets/82520caf-0f93-4e0e-951a-c87c9e9e8339" /> | | _Harsh borders between sections_ | _Borders match top one_ | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the product menu group separator to use the standard border color for a more consistent appearance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2a3025df25 |
feat(studio): role inference core for scoped pat (#48805)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Logic-only extraction from #48742. Scoped PATs are enforced server-side as the intersection of the token's granted scopes and the owner's live role, re-checked on every request. This lands the pure inference layer that will power advisory (never blocking) UI feedback; no UI consumes it yet. - FGA_SCOPE_MINIMUM_ROLE: all 83 permission scopes transcribed from the OpenFGA model's role unions, mapped to the lowest base role that holds them. A drift-guard test pins the key set to the scope ids published in @supabase/shared-types, so upstream additions fail CI here with re-transcription instructions. - estimateRoleLevel: derives the user's base role per org (or per project for project-invited members) from the ungated /platform/profile/ permissions rows via four discriminating ABAC probes. Works for every member type with no permission-gated endpoint. - computeTokenRoleContext + applySelectionToRoleContext: role resolution (expensive, memoized) is split from selection evaluation (cheap, re-run per permission toggle). AccessToken.permissions.ts gains only what the roles module needs: the PermissionLevel type and the catalog's `level` field (decides whether an org or project role governs a resource), plus getEntryScopes, which selectionToScopes now reuses. The UI-only additions from #48742 (risk badge/dot variants, mode labels, the OverallRisk.text -> description rename) are deliberately left out so this PR touches no .tsx. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added role-aware evaluation for scoped access-token permissions. * Added support for organization- and project-level permission scoping. * Added guidance when selected permissions exceed the current role, including read-only downgrades and inaccessible resources. * Added clearer grouping of permission access issues by resource. * **Tests** * Added comprehensive coverage for role mapping, permission evaluation, scoping, and failure scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
33008a39e5 |
chore(studio): remove scoped pat orphaned form (#48803)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? First step in breaking down #48635 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed the scoped access-token form, including token details, expiration settings, resource access, and permission configuration. * Removed resource and permission selection controls from the access-token workflow. * **Tests** * Removed automated coverage for access-token validation, permission handling, expiration logic, and resource selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
cddb430310 |
feat(studio): scoped pat root branch (#48384)
## Description This is the Scoped PAT stacked PRs root branch ## How to test ### With the `scopedPAT` enabled (default on staging) Go to https://studio-staging-git-scopedpat-merge-token-lists-supabase.vercel.app/dashboard/account/tokens. - You shouldn't see two tabs anymore - If you had classic tokens, they should have the _Legacy_ badge - You can create scoped tokens - You have a way to copy newly created tokens before closing the form side panel ### With the `scopedPAT` disabled (use the devtool to override) - You shouldn't see two tabs anymore - If you had classic tokens, they should **not** have the _Legacy_ badge - You can create classic tokens - You have a way to copy newly created tokens above the list upon form submission <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Show classic and scoped access tokens together in one list, with classic tokens labeled “Legacy” when the scoped experience is enabled. * Add scoped access token creation with a two-step configure → review → success flow (when enabled). * Add a dismissible migration notice about scoped tokens with a link to API docs. * Show “View permissions” only for scoped tokens. * **Bug Fixes** * Token deletion now supports both classic and scoped tokens with the correct confirmation and success handling. * The scoped tokens page now redirects to the unified access tokens page. * **Accessibility** * Improved accessibility by adding a label to the token “more options” action. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> Co-authored-by: kemal.earth <606977+kemaldotearth@users.noreply.github.com> |
||
|
|
2afb87af05 |
fix(ui): add bottom padding to scroll container in RLS search (#48759)
Fixes FE-4075. ## What kind of change does this PR introduce? The footer displaying the total number of RLS policies overlaps the last search result in the RLS Policy Search dialog. As a result, the last policy entry is partially hidden and cannot be fully read when scrolling to the bottom. ## What is the current behavior? The search results container now reserves space for the footer, preventing it from overlapping the last search result. All policy entries remain fully visible when scrolling to the bottom. <img width="400" height="300" alt="image" src="https://github.com/user-attachments/assets/46529ca4-bdce-4fa2-b0ba-ea87e769cc24" /> ## What is the new behavior? <img width="400" height="300" alt="CleanShot 2026-08-05 at 18 19 27@2x" src="https://github.com/user-attachments/assets/093a3f9e-fd4c-4ff6-b483-2839f3916d13" /> ## How to test - Open a project in the Supabase Dashboard. - Navigate to Database → RLS Policies. - Open the policy search dialog. - Search for a term that returns enough results to make the list scrollable - Scroll to the bottom of the results. The [database.sql](https://gist.github.com/monicakh/49b5ff201893eb43aea329395b3f635b) to create the tables/policies to test. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved scrolling in policy search results. * Added spacing at the bottom so results remain visible above the fixed footer. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
840127cd69 |
let inline error callers own mutation failures (#48640)
## What kind of change does this PR introduce? Code clean-up following #48470, #48471, #48472, #48473, and #48474. ## What is the current behavior? Mutation hooks provide fallback error toasts, so callers that already render errors inline must suppress those toasts with empty `onError` handlers. ## What is the new behavior? The affected callers own their error presentation. Inline interstitial errors remain unchanged, API authorisation retains its state-reset handlers, and Project Claim retains its combined caller-owned toast. ## To test There is no useful before-and-after visual check for this PR: the rendered error states should be identical on `master` and this branch. The change only removes the default-toast and no-op-handler pair underneath the UI. The existing [Organisation Invite](https://github.com/supabase/supabase/pull/48470), [API authorisation, AWS Marketplace](https://github.com/supabase/supabase/pull/48471), and [Stripe Projects](https://github.com/supabase/supabase/pull/48472) failure tests cover the inline errors and confirm that no duplicate toast appears. |
||
|
|
93b5ae71bf |
chore: remove unused useProjectUsageStats hook (#48792)
## Problem `useProjectUsageStats` (`apps/studio/hooks/analytics/useProjectUsageStats.tsx`) has no importers anywhere in the codebase — dead code, and it also still queries BigQuery directly (`logs.all`, no OTEL path), which would've made it another gap in the reports→ClickHouse migration if it were ever wired up. ## Fix Deletes the file. Confirmed nothing imports it, and none of its own imports (`useFillTimeseriesSorted`, `useTimeseriesUnixToIso`, `genChartQuery`, `EventChart`) become unused as a result — all are still used elsewhere. ## How to test - `pnpm tsc --noEmit` — no errors referencing the removed file. - `pnpm vitest run hooks/analytics` — 28 tests pass, no breakage. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed the project usage analytics statistics feature, including its data retrieval, time-series processing, filtering, refresh controls, and loading/error states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8618991b6f |
Initialize explorer home page (#48790)
## Context More groundwork for the Explorer - initializing the home page Note that nothing here is functional, all just visual still <img width="1387" height="960" alt="image" src="https://github.com/user-attachments/assets/d4967578-edbd-476f-8150-d9d5e9d66666" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a new Explorer landing page with an assistant chat form. * Added quick actions for creating notebooks and SQL work. * Added notebook and chat template cards for faster project exploration. * **Improvements** * Explorer content now fills the available page height. * Assistant send button styling now reflects whether submission is available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
21919ec9b8 | feat(pipelines): Use new restart endpoint (#48737) | ||
|
|
51c5b9f013 |
chore: sync ssl enforcement and temporary access (#48743)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore - fix-up ## What is the current behavior? Temporary access depends on ssl enforcement. The frontend doesn't enforce this very well or keep state between the two configs. ## What is the new behavior? This updates the two configs to be interdependent and updates to each one triggers a frontend state change on the other. ## Additional context Before: https://github.com/user-attachments/assets/8f040b62-587c-4268-9e27-27dd09b052a3 After: https://github.com/user-attachments/assets/c62e006e-6147-4c94-b6cf-375ca300b890 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added confirmation dialogs and downtime warnings before changing database SSL enforcement. - Added loading states and success or failure notifications for SSL updates. - Enabled SSL enforcement directly from temporary database access settings. - **Bug Fixes** - Prevented SSL enforcement from being disabled while temporary database access is enabled. - Improved settings refresh after SSL enforcement changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4550ee18a4 |
Initialize tabs UI for explorer (#48789)
## Context Continued ground work for Explorer - just initializes the Tab UI for Explorer as such: - Plan is to continue using the existing tabs store + EditorTabs component - Purely visual, nothing functional <img width="1389" height="556" alt="image" src="https://github.com/user-attachments/assets/d46c5ae7-01a8-4887-9452-11b98327d6bf" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an Explorer workspace with animated navigation and tab controls. * Added a home tab and a new-tab menu for creating notebooks, with chat creation shown as unavailable. * Added support for notebook tabs in the editor and Explorer navigation. * Added flexible tab layouts with custom tab content, optional new-tab actions, and configurable collapse controls. * Improved editor navigation to recognize Explorer workspaces alongside existing table and SQL editors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a7671019a8 |
Scaffold the explorer layout (#48740)
## Context Resolves FE-4074 Just adds scaffolding for the explorer UI - no data fetching yet. Initializes the page + side nav, based off Saxon's POC in `poc/explorer-prototype` <img width="1389" height="500" alt="image" src="https://github.com/user-attachments/assets/8f293992-97d9-403e-91d6-2e104cd20eb5" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features - Added a project Explorer page accessible from `/project/:ref/explorer`. - Added navigation for browsing notebooks and chats. - Added search fields, back navigation, animated transitions, and empty states for Explorer sections. - Added a conditional Explorer link to the SQL Editor menu when enabled. ## Documentation - Marked the Explorer route migration as complete in the migration checklist. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6b1fc3d11d |
recover failed Vercel deploy connections (#48474)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? A failed Vercel connection after project creation is only logged, leaving the project-creation screen in its loading state. ## What is the new behavior? The flow preserves the created project and shows the connection error with retry and open-project actions in the standard project-creation footer. Project-creation failures remain ordinary inline form errors. Connection failures are owned by this flow without a duplicate toast or a no-op error handler. | Before | After | | --- | --- | |  | <img width="1024" height="563" alt="Create Vercel Project Supabase" src="https://github.com/user-attachments/assets/b7d3fdca-d7a0-4b50-9231-3cf7dc371a87" /> | ## To test ### Before on master 1. Switch to `master`. 2. With local Studio running and while signed in, open an organisation you can access. Copy its slug from `http://localhost:8082/org/<YOUR_ORG_SLUG>`. 3. Open `apps/studio/components/interfaces/ProjectCreation/ProjectCreationForm.tsx`. 4. Find `isSuccessNewProject={isSuccessNewProject}` in the `ProjectCreationFooter` props and temporarily change it to: ```tsx isSuccessNewProject={true} ``` 5. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then open it: `http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`. 6. Confirm **Create new project** remains in its loading state and there is no error, retry action, or route to the created project. This represents the current stuck state. 7. Revert the temporary edit before switching branches. ### After on this branch 1. Switch to `dnywh/vercel-deploy-recovery`. 2. With local Studio running and while signed in, open an organisation you can access. Copy its slug from `http://localhost:8082/org/<YOUR_ORG_SLUG>`. 3. Open `apps/studio/pages/integrations/vercel/[slug]/deploy-button/new-project.tsx`. 4. Find the conditional beginning with `newProjectRef === undefined` inside `InterstitialLayout`. 5. Replace that whole conditional with: ```tsx <VercelConnectionError projectRef="abcdefghijklmnopqrst" message="Connection request failed" onRetry={() => undefined} /> ``` 6. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then open it: `http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`. 7. Confirm the admonition says **Unable to connect to Vercel** and **Your Supabase project was still created. Error: Connection request failed**. 8. Confirm **Open project** and **Retry connection** appear as compact, right-aligned footer buttons. The retry action is intentionally inert in this visual-only mock, and no project or Vercel connection is created. 9. Revert the temporary edit. ## Additional context Follows #48473. The consistency follow-up #48640 is stacked on this PR. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added inline error messages to project creation forms for integration, API, and validation failures. - Added clear Vercel connection states, including waiting, connecting, success, and error screens. - Added retry actions and links to open successfully created projects. - **Bug Fixes** - Improved error handling so Vercel connection issues remain visible in context instead of appearing only as notifications. - **Tests** - Added coverage for partial-success messaging, project links, and retry behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
a28214c236 |
feat(studio): add ClickHouse OTEL SQL for the Auth report's v2 metrics (#48750)
## Problem Part of DEBUG-73 (migrate reports queries to the OTEL/ClickHouse endpoint). The Auth report's v2 metrics (ActiveUsers, SignInAttempts, PasswordResetRequests, TotalSignUps, sign-in/sign-up processing time, error breakdowns) currently only query the BigQuery-backed logs.all endpoint. ## Fix Adds `AUTH_REPORT_SQL_OTEL`, a ClickHouse-dialect mirror of the existing `AUTH_REPORT_SQL`, covering all 10 metrics. Threads a `useOtel` parameter through `fetchLogs` and the three report config creators (`createUsageReportConfig`, `createErrorsReportConfig`, `createLatencyReportConfig`), defaulting to `false` everywhere. This PR is inert on its own: nothing yet passes `useOtel: true`, so it changes no runtime behavior. The follow-up PR (stacked on this one) wires the `otelReports` feature flag through the Auth report page to actually select the OTEL SQL. Also includes: one dataProvider now validates its raw rows with a Zod schema instead of casting to `any`, and removal of a few functions in this file that had zero callers (`AUTH_ERROR_CODE_VALUES`, `createAuthReportConfig`, an exact duplicate of a status-code color map, an unused hook). ## How to test - Unit: `cd apps/studio && npx vitest run data/reports/v2/auth.config.otel.test.ts` - No manual testing needed for this PR alone since it changes no runtime behavior (useOtel defaults to false, unwired). The follow-up PR covers manual testing of the actual flag-gated behavior. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added OpenTelemetry-backed authentication reports. * Authentication reports now include usage, errors, latency, sign-ins, sign-ups, and edge-log metrics. * Added filtering by provider, status code, action, and time range. * Added selectable telemetry sources for retrieving report logs. * **Bug Fixes** * Improved validation of authentication error codes. * Improved handling of missing report data with consistent empty results. * Improved report formatting for more consistent attribute display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8831e15fc3 |
Revert "refactor(studio): static tab kind registry and tab id codec (PR 1/9)" (#48762)
Reverts supabase/supabase#48718 |
||
|
|
aed332b663 |
feat: migrate Edge Functions report to ClickHouse OTEL logs (#48756)
## Problem
The Edge Functions report (`observability/edge-functions`) only queries
BigQuery. As part of the broader Reports→ClickHouse OTEL migration
(DEBUG-73), we need each report migrated one at a time behind the
`otelReports` flag.
## Fix
Adds a ClickHouse OTEL SQL variant (`METRIC_SQL_OTEL`) for the 4 Edge
Functions metrics (TotalInvocations, ExecutionStatusCodes,
InvocationsByRegion, ExecutionTime), querying the unified `logs` table
filtered to `source = 'function_edge_logs'`, with fields read from
`log_attributes` (`function_id`, `response.status_code`,
`response.headers.x_sb_edge_region`, `execution_time_ms`) — the same
mapping already used by `edge-functions-last-hour-stats-query.ts`.
`edgeFunctionReports()` now takes a `useOtel` flag that picks between
the BQ and OTEL query sets and forwards it to `fetchLogs`. The page
wires this up via `useFlag('otelReports')`, matching the pattern used
for the Auth report. No behavior change while the flag is off — report
still fetches from BigQuery.
Also removed two pieces of dead code spotted in `report.utils.ts` while
touching it: the unused `useEdgeFnIdToName` hook and a
`STATUS_CODE_COLORS` map that was an exact duplicate of
`REPORT_STATUS_CODE_COLORS` (the one actually imported elsewhere).
This PR is standalone — no dependency on the in-flight Auth report OTEL
stack.
## How to test
- `pnpm vitest run data/reports/v2/edge-functions.config.otel.test.ts` —
9 new tests covering the OTEL SQL shape (single logs table,
unix-microsecond timestamp bucketing, field mapping, filters).
- `pnpm vitest run data/reports` and `pnpm vitest run
data/edge-functions components/interfaces/Reports` — existing suites (46
+ 54 tests) still pass, confirming no regression to the BQ path.
- Manually: with `otelReports` flag enabled, visit a project's Edge
Functions observability report and confirm charts render from the
ClickHouse endpoint.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added OpenTelemetry support for Edge Functions observability metrics,
including invocations, status codes, regional activity, and execution
time.
* Reports can now dynamically use either the standard or OpenTelemetry
logs source.
* **Bug Fixes**
* Improved filtering and timestamp handling for OpenTelemetry-based Edge
Functions metrics.
* Added coverage for status, execution time, function, and region
filters.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
55095dcd00 |
chore: highlight totp app friendly name (#48755)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? UI update ## What is the current behavior? We only show the alternative factor's name, if one exists. ## What is the new behavior? When presenting user with the MFA screen, make the MFA factor's friendly_name appear. ## Additional context Before: <img width="456" height="371" alt="Screenshot 2026-08-05 at 15 41 07" src="https://github.com/user-attachments/assets/7d506641-6a9e-49fe-8c40-98c1eef4b384" /> After: <img width="459" height="394" alt="Screenshot 2026-08-05 at 15 38 27" src="https://github.com/user-attachments/assets/034312ba-691e-4f56-b4e3-a82df2a17273" /> <img width="468" height="434" alt="Screenshot 2026-08-05 at 15 37 43" src="https://github.com/user-attachments/assets/4c585eae-b8e2-4f93-8210-2c8ac7c20278" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved multi-factor authentication prompts with clearer formatting and more consistent factor labels. * Ensured the primary code label appears whenever a verification factor is selected. * Added a fallback label for authentication factors without a display name. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ffd6d6636d |
refactor(studio): static tab kind registry and tab id codec (PR 1/9) (#48718)
## Summary First PR in the tab/snippet decoupling stack. Purely additive: no existing call sites change behavior except the `EntityTypeIcon` rewire, which preserves its API exactly. - **`state/tabs/kinds.ts`** — static `TAB_KINDS` descriptor table (`TabKind`, `TabSurface`, `surfaceOf`, `kindsOnSurface`, `isTabKind`). Leaf-safe: its only reference to the domain `Tab` type is a type-only import, so it stays importable at module scope (needed later for the valtio store and the persistence migration reader) without creating a runtime cycle. - **`state/tabs/kinds.icons.tsx`** — per-kind icon leaf module (`ui` + `lucide-react` + `TabKind` type only), plus the preserved `LogsSnippetIcon`. - **`state/tabs/tab-id.ts`** — `createTabId` / `parseTabId` / `toUrlSegment` / `parseUrlSegment(segment, surface)` codec. `parseUrlSegment` is surface-scoped: a bare segment only resolves to a kind when the surface has exactly one bare kind (true for `sql`). The table surface has five bare kinds (`r`/`v`/`m`/`f`/`p`) with no URL disambiguator between them, matching `/editor/[id]`, which learns kind from the fetched entity rather than the URL — so a bare table segment correctly resolves to nothing. - **`components/ui/EntityTypeIcon.tsx`** — rewired to a thin wrapper delegating to `kinds.icons.tsx`, preserving its exact prop API (`type`, `size`, `strokeWidth`, `isActive`, `sqlSource`) for all existing consumers. - **`state/tabs/tab-id.test.ts`** — codec round-trips per kind, bare-vs-prefixed URL segments, the `templates`/`examples`/`new` sentinels, and surface scoping (including the table-surface ambiguity above). Full plan: `apps/studio/TABS_DECOUPLING_PLAN.md` (not included in this PR). ## Test plan - [x] `pnpm typecheck` - [x] `pnpm lint --filter=studio` (0 errors) - [x] `pnpm --filter studio run lint:ratchet` (warning counts did not increase) - [x] `pnpm test:studio` (full suite green, including 50 new/updated tests in `state/tabs/`) - [x] `pnpm format` (no-op) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added consistent icons and metadata for SQL, notebook, chat, table, view, and related tab types. * Added support for creating, parsing, and converting tab identifiers to URL segments. * Improved handling of tab types across SQL and table surfaces. * **Bug Fixes** * Invalid, empty, or ambiguous tab identifiers and URL segments are now rejected. * **Tests** * Added coverage for tab identifiers, URL conversion, supported tab types, and edge cases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |