mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 10:55:06 +03:00
fix/api-keys-array-coerce
19725
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
4b8509db2b |
fix(studio): use shared EMPTY_ARR for api-keys fallback
A fresh `[]` literal on every fetch breaks referential equality for downstream consumers (the useMemo in Landing.utils.ts re-runs on every render). Use the shared EMPTY_ARR instance, matching the idiom already used by lint-query, schemas-query, fdws-query and friends. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V9mYmaGzoXkrJtTkrLKaVA |
||
|
|
61e9818599 | Merge branch 'master' into fix/api-keys-array-coerce | ||
|
|
2a3025df25 |
feat(studio): role inference core for scoped pat (#48805)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Logic-only extraction from #48742. Scoped PATs are enforced server-side as the intersection of the token's granted scopes and the owner's live role, re-checked on every request. This lands the pure inference layer that will power advisory (never blocking) UI feedback; no UI consumes it yet. - FGA_SCOPE_MINIMUM_ROLE: all 83 permission scopes transcribed from the OpenFGA model's role unions, mapped to the lowest base role that holds them. A drift-guard test pins the key set to the scope ids published in @supabase/shared-types, so upstream additions fail CI here with re-transcription instructions. - estimateRoleLevel: derives the user's base role per org (or per project for project-invited members) from the ungated /platform/profile/ permissions rows via four discriminating ABAC probes. Works for every member type with no permission-gated endpoint. - computeTokenRoleContext + applySelectionToRoleContext: role resolution (expensive, memoized) is split from selection evaluation (cheap, re-run per permission toggle). AccessToken.permissions.ts gains only what the roles module needs: the PermissionLevel type and the catalog's `level` field (decides whether an org or project role governs a resource), plus getEntryScopes, which selectionToScopes now reuses. The UI-only additions from #48742 (risk badge/dot variants, mode labels, the OverallRisk.text -> description rename) are deliberately left out so this PR touches no .tsx. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added role-aware evaluation for scoped access-token permissions. * Added support for organization- and project-level permission scoping. * Added guidance when selected permissions exceed the current role, including read-only downgrades and inaccessible resources. * Added clearer grouping of permission access issues by resource. * **Tests** * Added comprehensive coverage for role mapping, permission evaluation, scoping, and failure scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
33008a39e5 |
chore(studio): remove scoped pat orphaned form (#48803)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? First step in breaking down #48635 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed the scoped access-token form, including token details, expiration settings, resource access, and permission configuration. * Removed resource and permission selection controls from the access-token workflow. * **Tests** * Removed automated coverage for access-token validation, permission handling, expiration logic, and resource selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
1ff84a239c |
docs(auth): note that resetPasswordForEmail doesn't send email for un… (#48800)
add note on `resetPasswordForEmail` doesn't send email for unregistered emails <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that password reset requests do not reveal whether an email address is associated with an account. * Documented that requests for unrecognized email addresses complete without an error. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
cddb430310 |
feat(studio): scoped pat root branch (#48384)
## Description This is the Scoped PAT stacked PRs root branch ## How to test ### With the `scopedPAT` enabled (default on staging) Go to https://studio-staging-git-scopedpat-merge-token-lists-supabase.vercel.app/dashboard/account/tokens. - You shouldn't see two tabs anymore - If you had classic tokens, they should have the _Legacy_ badge - You can create scoped tokens - You have a way to copy newly created tokens before closing the form side panel ### With the `scopedPAT` disabled (use the devtool to override) - You shouldn't see two tabs anymore - If you had classic tokens, they should **not** have the _Legacy_ badge - You can create classic tokens - You have a way to copy newly created tokens above the list upon form submission <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Show classic and scoped access tokens together in one list, with classic tokens labeled “Legacy” when the scoped experience is enabled. * Add scoped access token creation with a two-step configure → review → success flow (when enabled). * Add a dismissible migration notice about scoped tokens with a link to API docs. * Show “View permissions” only for scoped tokens. * **Bug Fixes** * Token deletion now supports both classic and scoped tokens with the correct confirmation and success handling. * The scoped tokens page now redirects to the unified access tokens page. * **Accessibility** * Improved accessibility by adding a label to the token “more options” action. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> Co-authored-by: kemal.earth <606977+kemaldotearth@users.noreply.github.com> |
||
|
|
2afb87af05 |
fix(ui): add bottom padding to scroll container in RLS search (#48759)
Fixes FE-4075. ## What kind of change does this PR introduce? The footer displaying the total number of RLS policies overlaps the last search result in the RLS Policy Search dialog. As a result, the last policy entry is partially hidden and cannot be fully read when scrolling to the bottom. ## What is the current behavior? The search results container now reserves space for the footer, preventing it from overlapping the last search result. All policy entries remain fully visible when scrolling to the bottom. <img width="400" height="300" alt="image" src="https://github.com/user-attachments/assets/46529ca4-bdce-4fa2-b0ba-ea87e769cc24" /> ## What is the new behavior? <img width="400" height="300" alt="CleanShot 2026-08-05 at 18 19 27@2x" src="https://github.com/user-attachments/assets/093a3f9e-fd4c-4ff6-b483-2839f3916d13" /> ## How to test - Open a project in the Supabase Dashboard. - Navigate to Database → RLS Policies. - Open the policy search dialog. - Search for a term that returns enough results to make the list scrollable - Scroll to the bottom of the results. The [database.sql](https://gist.github.com/monicakh/49b5ff201893eb43aea329395b3f635b) to create the tables/policies to test. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved scrolling in policy search results. * Added spacing at the bottom so results remain visible above the fixed footer. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
840127cd69 |
let inline error callers own mutation failures (#48640)
## What kind of change does this PR introduce? Code clean-up following #48470, #48471, #48472, #48473, and #48474. ## What is the current behavior? Mutation hooks provide fallback error toasts, so callers that already render errors inline must suppress those toasts with empty `onError` handlers. ## What is the new behavior? The affected callers own their error presentation. Inline interstitial errors remain unchanged, API authorisation retains its state-reset handlers, and Project Claim retains its combined caller-owned toast. ## To test There is no useful before-and-after visual check for this PR: the rendered error states should be identical on `master` and this branch. The change only removes the default-toast and no-op-handler pair underneath the UI. The existing [Organisation Invite](https://github.com/supabase/supabase/pull/48470), [API authorisation, AWS Marketplace](https://github.com/supabase/supabase/pull/48471), and [Stripe Projects](https://github.com/supabase/supabase/pull/48472) failure tests cover the inline errors and confirm that no duplicate toast appears. |
||
|
|
93b5ae71bf |
chore: remove unused useProjectUsageStats hook (#48792)
## Problem `useProjectUsageStats` (`apps/studio/hooks/analytics/useProjectUsageStats.tsx`) has no importers anywhere in the codebase — dead code, and it also still queries BigQuery directly (`logs.all`, no OTEL path), which would've made it another gap in the reports→ClickHouse migration if it were ever wired up. ## Fix Deletes the file. Confirmed nothing imports it, and none of its own imports (`useFillTimeseriesSorted`, `useTimeseriesUnixToIso`, `genChartQuery`, `EventChart`) become unused as a result — all are still used elsewhere. ## How to test - `pnpm tsc --noEmit` — no errors referencing the removed file. - `pnpm vitest run hooks/analytics` — 28 tests pass, no breakage. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed the project usage analytics statistics feature, including its data retrieval, time-series processing, filtering, refresh controls, and loading/error states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8618991b6f |
Initialize explorer home page (#48790)
## Context More groundwork for the Explorer - initializing the home page Note that nothing here is functional, all just visual still <img width="1387" height="960" alt="image" src="https://github.com/user-attachments/assets/d4967578-edbd-476f-8150-d9d5e9d66666" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a new Explorer landing page with an assistant chat form. * Added quick actions for creating notebooks and SQL work. * Added notebook and chat template cards for faster project exploration. * **Improvements** * Explorer content now fills the available page height. * Assistant send button styling now reflects whether submission is available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
21919ec9b8 | feat(pipelines): Use new restart endpoint (#48737) | ||
|
|
51c5b9f013 |
chore: sync ssl enforcement and temporary access (#48743)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore - fix-up ## What is the current behavior? Temporary access depends on ssl enforcement. The frontend doesn't enforce this very well or keep state between the two configs. ## What is the new behavior? This updates the two configs to be interdependent and updates to each one triggers a frontend state change on the other. ## Additional context Before: https://github.com/user-attachments/assets/8f040b62-587c-4268-9e27-27dd09b052a3 After: https://github.com/user-attachments/assets/c62e006e-6147-4c94-b6cf-375ca300b890 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added confirmation dialogs and downtime warnings before changing database SSL enforcement. - Added loading states and success or failure notifications for SSL updates. - Enabled SSL enforcement directly from temporary database access settings. - **Bug Fixes** - Prevented SSL enforcement from being disabled while temporary database access is enabled. - Improved settings refresh after SSL enforcement changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4550ee18a4 |
Initialize tabs UI for explorer (#48789)
## Context Continued ground work for Explorer - just initializes the Tab UI for Explorer as such: - Plan is to continue using the existing tabs store + EditorTabs component - Purely visual, nothing functional <img width="1389" height="556" alt="image" src="https://github.com/user-attachments/assets/d46c5ae7-01a8-4887-9452-11b98327d6bf" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an Explorer workspace with animated navigation and tab controls. * Added a home tab and a new-tab menu for creating notebooks, with chat creation shown as unavailable. * Added support for notebook tabs in the editor and Explorer navigation. * Added flexible tab layouts with custom tab content, optional new-tab actions, and configurable collapse controls. * Improved editor navigation to recognize Explorer workspaces alongside existing table and SQL editors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a18ee934cd |
docs(auth): handle incoming deep link URLs on Swift (#48774)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? The Swift tab in the [Native Mobile Deep Linking guide](https://supabase.com/docs/guides/auth/native-mobile-deep-linking?platform=swift) only covers registering a custom URL scheme (Info.plist config). Unlike the React Native, Flutter, and Kotlin tabs, it never shows the runtime code that actually consumes the incoming URL and completes the sign-in, so a Swift developer following the guide is left without a working implementation. Linear: [SDK-83](https://linear.app/supabase/issue/SDK-83/swift-improve-docs-on-how-to-handle-deep-link-url) ## What is the new behavior? Added a "Handling the incoming URL" section to the Swift tab with: - SwiftUI: `onOpenURL` calling `supabase.auth.handle(url)` - UIKit app delegate lifecycle: `application(_:didFinishLaunchingWithOptions:)` and `application(_:open:options:)` - UIKit scene delegate lifecycle: `scene(_:openURLContexts:)` - A note pointing to `session(from:)` for callers that need the returned `Session` or custom error handling `handle(url)` and its usage patterns match the current `supabase-swift` reference spec (`supabase_swift_v2.yml`) and source. Also added `UIKit` to the docs spelling allowlist (`supa-mdx-lint/Rule003Spelling.toml`) since it isn't in the dictionary. ## Additional context `pnpm lint:mdx` passes on the changed file. `pnpm build:guides-markdown` fails, but on a pre-existing unrelated issue (missing generated `database-advisors.json`), not on this change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Swift guidance for handling authentication deep links in SwiftUI and UIKit apps. * Documented deep-link behavior during cold launches and scene-based URL delivery. * Clarified when to use `handle(_:)` and `session(from:)`, including error-handling considerations. * Updated the SwiftUI tutorial to pass authentication URLs directly to the recommended handler. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a7671019a8 |
Scaffold the explorer layout (#48740)
## Context Resolves FE-4074 Just adds scaffolding for the explorer UI - no data fetching yet. Initializes the page + side nav, based off Saxon's POC in `poc/explorer-prototype` <img width="1389" height="500" alt="image" src="https://github.com/user-attachments/assets/8f293992-97d9-403e-91d6-2e104cd20eb5" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features - Added a project Explorer page accessible from `/project/:ref/explorer`. - Added navigation for browsing notebooks and chats. - Added search fields, back navigation, animated transitions, and empty states for Explorer sections. - Added a conditional Explorer link to the SQL Editor menu when enabled. ## Documentation - Marked the Explorer route migration as complete in the migration checklist. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e0cc680653 |
feat(www): update Partner Day at Select 2026 go page copy (#48778)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update (marketing copy) for the `www` app. ## What is the current behavior? `/go/select-2026/partner-day` copy is a couple of revisions behind the latest Notion draft (see #48771 and #48773 for prior rounds). ## What is the new behavior? Updates the page copy to match the newest draft. ## Additional context - Verified locally in the browser against the Notion copy doc, word-for-word. - `prettier --check` passes on the changed file. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Content Updates** * Clarified Partner Day event details, including the day-before-Select note. * Improved venue information messaging. * Updated the RSVP question to reference Select on October 2 and the Partner Day invitation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d61d3533f2 |
docs: fix broken Swift example in joins-and-nesting guide (#48775)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs fix. ## What is the current behavior? Fixes [SDK-958](https://linear.app/supabase/issue/SDK-958/docs-incomplete-documentation), reported via the docs feedback widget on [joins-and-nesting](https://supabase.com/docs/guides/database/joins-and-nesting). In the "Specifying the `ON` clause for joins with multiple foreign keys" section, the Swift example was broken relative to the other language tabs (JS, Dart, Kotlin, Python, C#): - The query string aliased the second embed as `scans: scan_id_end`, which isn't valid PostgREST embed syntax (should be `end_scan:scans!scan_id_end`). - The `Shift` struct only declared a single `scans: [Scan]` property with no `CodingKeys` entry for `start_scan` or `end_scan` — so it never actually decoded either aliased relation, which is why the reporter couldn't tell where `start_scan` was supposed to come from. ## What is the new behavior? - Query now aliases both relations consistently: `start_scan:scans!scan_id_start (...)` and `end_scan:scans!scan_id_end (...)`, matching the other language examples. - `Shift` struct now declares `startScan: Scan` and `endScan: Scan`, mapped via `CodingKeys` to `start_scan` and `end_scan`. ## Additional context Docs-only change to a code sample inside `apps/docs/content/guides/database/joins-and-nesting.mdx`. Verified with `prettier --check` (mdx lint tool failed locally due to an unrelated missing native module, `node-pty`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the Swift join example to represent separate start and end scan relationships. * Revised response field selections and coding keys to match the updated relationship names. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6b1fc3d11d |
recover failed Vercel deploy connections (#48474)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? A failed Vercel connection after project creation is only logged, leaving the project-creation screen in its loading state. ## What is the new behavior? The flow preserves the created project and shows the connection error with retry and open-project actions in the standard project-creation footer. Project-creation failures remain ordinary inline form errors. Connection failures are owned by this flow without a duplicate toast or a no-op error handler. | Before | After | | --- | --- | |  | <img width="1024" height="563" alt="Create Vercel Project Supabase" src="https://github.com/user-attachments/assets/b7d3fdca-d7a0-4b50-9231-3cf7dc371a87" /> | ## To test ### Before on master 1. Switch to `master`. 2. With local Studio running and while signed in, open an organisation you can access. Copy its slug from `http://localhost:8082/org/<YOUR_ORG_SLUG>`. 3. Open `apps/studio/components/interfaces/ProjectCreation/ProjectCreationForm.tsx`. 4. Find `isSuccessNewProject={isSuccessNewProject}` in the `ProjectCreationFooter` props and temporarily change it to: ```tsx isSuccessNewProject={true} ``` 5. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then open it: `http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`. 6. Confirm **Create new project** remains in its loading state and there is no error, retry action, or route to the created project. This represents the current stuck state. 7. Revert the temporary edit before switching branches. ### After on this branch 1. Switch to `dnywh/vercel-deploy-recovery`. 2. With local Studio running and while signed in, open an organisation you can access. Copy its slug from `http://localhost:8082/org/<YOUR_ORG_SLUG>`. 3. Open `apps/studio/pages/integrations/vercel/[slug]/deploy-button/new-project.tsx`. 4. Find the conditional beginning with `newProjectRef === undefined` inside `InterstitialLayout`. 5. Replace that whole conditional with: ```tsx <VercelConnectionError projectRef="abcdefghijklmnopqrst" message="Connection request failed" onRetry={() => undefined} /> ``` 6. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then open it: `http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`. 7. Confirm the admonition says **Unable to connect to Vercel** and **Your Supabase project was still created. Error: Connection request failed**. 8. Confirm **Open project** and **Retry connection** appear as compact, right-aligned footer buttons. The retry action is intentionally inert in this visual-only mock, and no project or Vercel connection is created. 9. Revert the temporary edit. ## Additional context Follows #48473. The consistency follow-up #48640 is stacked on this PR. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added inline error messages to project creation forms for integration, API, and validation failures. - Added clear Vercel connection states, including waiting, connecting, success, and error screens. - Added retry actions and links to open successfully created projects. - **Bug Fixes** - Improved error handling so Vercel connection issues remain visible in context instead of appearing only as notifications. - **Tests** - Added coverage for partial-success messaging, project links, and retry behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
801ef21ce6 |
Add Matt Smiley to humans.txt (#48729)
Add myself (Matt Smiley) to humans.txt as part of onboarding to Supabase. ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update to add new joiner (me) ## What is the current behavior? NA ## What is the new behavior? Adds new team member ## Additional context Part of my onboarding process <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Matt Smiley to the team member list in the project credits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8d1ff7d38f |
feat(www): update Partner Day at Select 2026 go page copy (#48773)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update (marketing copy) for the `www` app. ## What is the current behavior? `/go/select-2026/partner-day` copy is one revision behind the latest draft (see #48771 for the prior round). ## What is the new behavior? Updates the page copy to match the newest Notion draft. ## Additional context - Verified locally in the browser against the Notion copy doc, word-for-word. - Verified the RSVP form's "Are you attending Select 2026?" select field opens, selects, and submits correctly. - `prettier --check` passes on the changed file. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Content Updates** - Refined Partner Day event messaging and “What to expect” descriptions. - Simplified the hero description by removing timing-specific wording. - Shortened inaugural-event messaging for clearer, more concise communication. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2736abf4c7 |
feat(www): update Partner Day at Select 2026 go page copy (#48771)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update (marketing copy) for the `www` app. ## What is the current behavior? `/go/select-2026/partner-day` has stale copy from an earlier draft of the event: a time-boxed agenda table and a "What you'll gain" feature grid that no longer match the approved messaging. ## What is the new behavior? Updated copy! :) ## Additional context - Verified the RSVP form's "Are you attending Select 2026?" select field opens, selects, and submits correctly, with no React hydration warnings on a clean `.next` build. - `pnpm --filter=www exec tsc --noEmit` and `prettier --check` both pass on the changed file. - `pnpm build --filter=www` fails locally, but this is pre-existing and unrelated to this change — it requires a `DOCS_GITHUB_APP_PRIVATE_KEY` secret (for the `docs` app's federated-content prebuild step) that isn't available in this local environment. Confirmed the identical failure occurs on `master` with no changes applied. |
||
|
|
b97ad08be5 |
docs: updating Edge Functions error codes (#48767)
<!-- ccr-slack-attribution --> _Requested by **Kalleby Santos** · [Slack thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785949561216739?thread_ts=1785949561.216739&cid=C02KMRX22NR)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. Adds two missing entries to the Edge Functions **Error codes** page (`apps/docs/content/guides/functions/error-codes.mdx`). Refs https://github.com/supabase/supabase/issues/47739 ## What is the current behavior? Neither `NOT_FOUND_FUNCTION_BLOB` nor `LOAD_FUNCTION_UNBUNDLING_ERROR` appears on the Error codes page. Someone who gets a 404 with `sb-error-code: NOT_FOUND_FUNCTION_BLOB` and searches the page finds nothing — and because the response body is the same `Requested function was not found` string that generic `NOT_FOUND` returns, the existing `NOT_FOUND` entry reads like it covers the case when it doesn't. ## What is the new behavior? Both codes are documented under `## Server Errors` with a cause and a remedy, in the page's existing `**Cause:**` / `**Solution:**` shape. - `NOT_FOUND_FUNCTION_BLOB` goes directly after `### NOT_FOUND`, since readers hitting it will scan for `NOT_FOUND` first. The cause explains the metadata/bundle version mismatch (concurrent or batched deploys double-incrementing the metadata version), notes that the message is identical to `NOT_FOUND` so the `sb-error-code` header is the distinguisher, and links the existing [Edge Function 404 error response](https://supabase.com/docs/guides/troubleshooting/edge-function-404-error-response) troubleshooting guide. Solution: redeploy with the latest CLI, avoid concurrent deploys of the same function, contact support to re-sync metadata if it persists. - `LOAD_FUNCTION_UNBUNDLING_ERROR` goes at the end, keeping the `LOAD_FUNCTION_*` cluster together. Cause: the bundle was fetched but decompression/parsing failed, which points at a corrupt or partially-written bundle. Solution: redeploy, contact support if it persists. ## Additional context Both codes are real and currently emitted by `supabase/edge-functions-ingress` (`main`): - `NOT_FOUND_FUNCTION_BLOB` — 404, declared at `src/main/errors.ts:29`, emitted at `src/main/cache.ts:180` - `LOAD_FUNCTION_UNBUNDLING_ERROR` — 503, declared at `src/main/errors.ts:27`, emitted at `src/main/cache.ts:226` Both were introduced by supabase/edge-functions-ingress#464. ### Notes for reviewer - **Scope.** The comment on #47739 asked only for `NOT_FOUND_FUNCTION_BLOB`. `LOAD_FUNCTION_UNBUNDLING_ERROR` is included because it shipped in the same ingress PR and is equally undocumented — happy to drop it if you'd rather keep this PR to exactly what was requested. - **No HTTP statuses in the copy.** The 404/503 above are deliberately left out of the page text, because the Error codes page states no HTTP status anywhere for any code. Adding them here would be a format departure. Easy to add if you'd prefer to start including them. - **Message mismatch, not fixed here.** `apps/docs/content/troubleshooting/edge-function-404-error-response.mdx` declares `message = "Function deployment bundle not found"` for `NOT_FOUND_FUNCTION_BLOB`, but the runtime actually emits `"Requested function was not found"` (`cache.ts:181`), which matches the response pasted in #47739. Left untouched in this PR — flagging it for a follow-up. ### Checks run - `prettier --check` on the changed file: passes. - `supa-mdx-lint` (v0.3.2) on the changed file: no new findings. The one remaining warning (`error-codes.mdx:11` — "Use 'view and resolve errors' instead of 'handle errors'") is pre-existing on `master` and untouched here. - The `{/* supa-mdx-lint-disable Rule001HeadingCase */}` pragma at line 8 sits above both new H3s, so the uppercase headings pass. --- _Generated by [Claude Code](https://claude.ai/code/session_01Qw5D2wdScBN5TWuA2FgnDW)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
5049f3eb81 |
docs: supabase evals note in AI tools page (#48663)
Following announcement https://supabase.com/blog/introducing-supabase-evals Adds an admonition to the [AI Tools](https://supabase.com/docs/guides/ai-tools) overview calling out the recently launched [Supabase Evals](https://supabase.com/blog/introducing-supabase-evals) project to demonstrate performance of (some of) the tools shown. Preview: https://docs-git-mattrossman-ai-969-link-to-evals-from-47d719-supabase.vercel.app/docs/guides/ai-tools <img width="3600" height="1606" alt="CleanShot 2026-08-03 at 15 13 06@2x" src="https://github.com/user-attachments/assets/8ea23f6c-fde0-4b04-bed1-035941570ac1" /> If preferred, we can move it below the fold, I just figure it's good for visibility on the recent launch and it helps sell the "why" for using these tools. Closes AI-969 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Documentation** * Added a link and note about Supabase Evals, an open-source benchmark for AI coding agents. * **Chores** * Updated spelling checks to recognize “eval” in any capitalization. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
08867f94ff |
docs: lead self-hosting overview with what/why/CTA, restructure secondary content (#48415)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs restructure of the self-hosting overview: short fit intro, Get started / community listings above the fold, parallel h2 sections for how self-hosting differs (including local development), responsibilities, and telemetry, plus a streamlined support listing with better card content. Closes DOCS-1251. ## What is the current behavior? - Linear item: Explore two PR approaches for the self-hosting page - The self-hosting overview page (`/guides/self-hosting`) is the top search hit for "supabase self-hosting," but reads as a wall of text: three full prose/bullet sections (differs / responsibilities / telemetry) come before the getting-started CTA, which is buried as one small card partway down the page. ## What is the new behavior? - Short fit intro; `self-hosting-get-started` and `self-hosting-community` listings sit directly under the intro. - Top-level h2s for how self-hosting differs, responsibilities, telemetry, and support (no "More about self-hosting" wrapper). - Under differs: rewritten single-project + platform-gap copy, plus `### Not the same as local development` (CLI stack is not a production self-host; points to Docker / community options). - Telemetry clarifies CLI local-dev telemetry vs Docker Compose (no phone-home). - Merged support into a single `self-hosting-support` listing; Enterprise subsection unchanged. - Minor a11y: `aria-hidden` on GlassPanel decorative icon background. ## Additional context - Worktree: `~/GitHub/supabase/supabase-worktrees/nikrichers/docs-1251-self-hosting-inform` - Review: removed the "More about self-hosting" grouping after feedback that it undersold differs / responsibilities. - Companion prototype PR 48416 is closed; this branch is the direction under review. - Verification: | Check | Result | | ----------------------------------------------- | ------------------------------------------------------------------ | | `pnpm lint:mdx content/guides/self-hosting.mdx` | Pass — no errors/warnings on this file | | Vercel docs preview | Pass — full-page after screenshot captured from the preview deploy | ### Proof: intro and get-started above the fold; parallel h2s for differs, responsibilities, and telemetry **Verified:** `pnpm lint:mdx content/guides/self-hosting.mdx` (pass) · Vercel docs preview (pass) ### Before & After | [Before (production)](https://supabase.com/docs/guides/self-hosting) | [After (PR preview)](https://docs-git-nikrichers-docs-1251-self-hosting-inform-supabase.vercel.app/docs/guides/self-hosting) | | ------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- | |  |  | ### Test plan - [ ] Visit the preview link and confirm the page opens with intro above the Get started listings - [ ] Confirm parallel h2s for differs / responsibilities / telemetry / support (no "More about self-hosting") - [ ] Confirm "Not the same as local development" distinguishes the CLI stack from self-hosting - [ ] Confirm Support and community is one card grid - [ ] Check mobile width — layout should still be usable - [ ] Confirm `/guides/self-hosting/docker` link still works <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Reorganized the self-hosting guide with clearer getting-started resources and community links. - Added dedicated guidance for local development, managed Supabase, telemetry, and self-hosting responsibilities. - Consolidated support resources into one section covering discussions, issues, chat, Reddit, and sharing experiences. - **Accessibility** - Marked decorative icon backgrounds as hidden from assistive technologies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
47b8660d8d |
docs(troubleshooting): troubleshooting guide so users can amend their failed migrations (#48257)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Troubleshooting guide ## What is the current behavior? NA ## What is the new behavior? Troubleshooting guide ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new troubleshooting page: “Troubleshooting MIGRATIONS_FAILED: missing tables or an incomplete schema on your branch” for Preview Branch creation. * Explained why replayed `main` migration history can fail when it no longer matches the branch’s live schema. * Included a step-by-step workflow to diagnose the failing migration via logs, repair migration status, and then recreate or rebase the branch to verify. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
a28214c236 |
feat(studio): add ClickHouse OTEL SQL for the Auth report's v2 metrics (#48750)
## Problem Part of DEBUG-73 (migrate reports queries to the OTEL/ClickHouse endpoint). The Auth report's v2 metrics (ActiveUsers, SignInAttempts, PasswordResetRequests, TotalSignUps, sign-in/sign-up processing time, error breakdowns) currently only query the BigQuery-backed logs.all endpoint. ## Fix Adds `AUTH_REPORT_SQL_OTEL`, a ClickHouse-dialect mirror of the existing `AUTH_REPORT_SQL`, covering all 10 metrics. Threads a `useOtel` parameter through `fetchLogs` and the three report config creators (`createUsageReportConfig`, `createErrorsReportConfig`, `createLatencyReportConfig`), defaulting to `false` everywhere. This PR is inert on its own: nothing yet passes `useOtel: true`, so it changes no runtime behavior. The follow-up PR (stacked on this one) wires the `otelReports` feature flag through the Auth report page to actually select the OTEL SQL. Also includes: one dataProvider now validates its raw rows with a Zod schema instead of casting to `any`, and removal of a few functions in this file that had zero callers (`AUTH_ERROR_CODE_VALUES`, `createAuthReportConfig`, an exact duplicate of a status-code color map, an unused hook). ## How to test - Unit: `cd apps/studio && npx vitest run data/reports/v2/auth.config.otel.test.ts` - No manual testing needed for this PR alone since it changes no runtime behavior (useOtel defaults to false, unwired). The follow-up PR covers manual testing of the actual flag-gated behavior. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added OpenTelemetry-backed authentication reports. * Authentication reports now include usage, errors, latency, sign-ins, sign-ups, and edge-log metrics. * Added filtering by provider, status code, action, and time range. * Added selectable telemetry sources for retrieving report logs. * **Bug Fixes** * Improved validation of authentication error codes. * Improved handling of missing report data with consistent empty results. * Improved report formatting for more consistent attribute display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d101d6f3de |
docs: document NOT_FOUND_FUNCTION_BLOB Edge Function error (#48411)
This PR addresses the documentation portion of #47739. ## What the issue means `NOT_FOUND_FUNCTION_BLOB` means the runtime cannot find the deployed bundle for an Edge Function. This differs from the existing `NOT_FOUND` error, which normally indicates that the function name in the request URL is not recognized. The dashboard status alone may not reveal this failure because the function can still appear as `ACTIVE`. ## Changes - Documented `NOT_FOUND_FUNCTION_BLOB` as an HTTP 404 error. - Explained how it differs from `NOT_FOUND`. - Added the command for redeploying one affected function. - Added the command for redeploying all functions when several are affected. - Added guidance to retry the request and contact Support if redeployment does not resolve the problem. ## Files changed - `apps/docs/content/troubleshooting/edge-function-404-error-response.mdx` ## Validation - The change uses the troubleshooting page's existing TOML frontmatter and MDX conventions. - `git diff --check` passes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded troubleshooting guidance for Edge Function 404 responses. * Added coverage of the `NOT_FOUND_FUNCTION_BLOB` error, including example responses and clarification of how it differs from `NOT_FOUND`. * Updated redeployment instructions with options for deploying a single function or all functions. * Refined retry and support guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8831e15fc3 |
Revert "refactor(studio): static tab kind registry and tab id codec (PR 1/9)" (#48762)
Reverts supabase/supabase#48718 |
||
|
|
d45e0cd3d5 |
fix(docs ci): stop Docs E2E blocking pull requests it shouldn't (#48726)
Supersedes #48725, which GitHub closed when its head branch was renamed. Same commits, same diff. Fixes [DOCS-1270](https://linear.app/supabase/issue/DOCS-1270/fail-the-e2e-pipeline-if-the-docs-preview-never-loads). `Docs E2E` is a required check on `master`, so anything that turns it red blocks a merge. It had three ways of going red that had nothing to do with whether the author's docs were correct. ## Problem **1. Every troubleshooting page could fail, with nothing actionable.** Troubleshooting entries were selected by `article.prose`. That class is not unique — `apps/docs/app/not-found.tsx` renders `<article className="prose …">` too — and nothing guaranteed it matched the entry's article at all. When it missed, the link test failed with `Page article should be present` and the a11y test failed inside axe with `No elements found for include in page Context` plus a stack trace. Neither tells the author what to do. This is what DOCS-1270 actually was. The ticket describes tests running "against a preview build that was never created", but the [failing run](https://github.com/supabase/supabase/actions/runs/30949924515/job/92132543658) for #48719 shows the preview resolved fine and `response.ok()` passed — it broke at the article assertion. **Blocked:** anyone adding or editing a troubleshooting entry. **2. Fork pull requests failed for being forks.** Fork runs get no `VERCEL_TOKEN`, so no preview URL resolves, and the base-URL step fell back to `https://supabase.com`. The page paths under test can include pages the pull request *adds*, which do not exist on production, so they 404. **Blocked:** every external contributor adding a docs page, unconditionally, with no action available to them. **3. A Vercel problem failed the docs check.** `waitForVercelDocsPreview.js` throws when Vercel reports a failed deployment, omits a `target_url`, or does not post a status within 900s. The step had no `continue-on-error`, so any of those turned `Docs E2E` red. **Blocked:** any author whose pull request coincided with a Vercel incident. This is live right now — two Vercel checks on this very pull request are failing with "unable to fetch required git information", a git-integration auth error that happens before any build runs. ## Solution **1. Select on a stable, purpose-named attribute.** Add `id="sb-docs-troubleshooting-main-article"` on the troubleshooting article, mirroring `#sb-docs-guide-main-article` on guides, and select on that instead of the class. Per review feedback, a plain id doesn't say it's a test hook, so both articles also get `data-testid` with the same value — matching the convention `apps/studio` already uses with Playwright's `getByTestId` — and the e2e selectors target that attribute instead. Guides keep their `id` — `GuidesMdx.client.tsx` and `GuidesSidebar.tsx` both query it directly for the table of contents and the "copy article" fallback — and gain `data-testid` alongside it. **2 and 3. Resolve a preview or skip — never substitute production, never fail on Vercel.** The production fallback is gone. `continue-on-error: true` on the preview wait means a Vercel failure resolves no URL instead of failing the job, which lands in the same path as a fork: `should_test=false`, so Playwright is skipped and the check passes. Both cases emit a `::warning::` and a job summary with the exact `gh workflow run` command to test the preview by hand, and manual runs against a non-production base URL now send the protection bypass so that command actually works. Skipping does not let a broken preview through: `Vercel – docs` is itself a required check on `master`, so a genuine preview failure still blocks the merge — via the check that describes the real problem. ## Manual test **1. The selector matches the markup, and it needs this pull request's preview.** `data-testid` isn't deployed anywhere yet — not on production, not on any other branch — so this is the one claim in this PR that production cannot confirm. Verified directly against this branch's own Vercel preview: ```bash curl -s https://docs-git-docs-e2e-stop-false-blocks-supabase.vercel.app/docs/guides/database/overview \ | grep -o 'data-testid="[^"]*"' curl -s https://docs-git-docs-e2e-stop-false-blocks-supabase.vercel.app/docs/guides/troubleshooting/42501--permission-denied-for-table-httprequestqueue-KnozmQ \ | grep -o 'data-testid="[^"]*"' ``` Expect `data-testid="sb-docs-guide-main-article"` and `data-testid="sb-docs-troubleshooting-main-article"` respectively. Then run the suite against that same preview — expect all page/link/a11y checks to pass: ```bash PLAYWRIGHT_BASE_URL=https://docs-git-docs-e2e-stop-false-blocks-supabase.vercel.app \ DOCS_E2E_PAGE_PATHS=/docs/guides/database/overview,/docs/guides/troubleshooting/42501--permission-denied-for-table-httprequestqueue-KnozmQ \ pnpm -C e2e/docs exec playwright test --reporter=list ``` Running the same command with `PLAYWRIGHT_BASE_URL=https://supabase.com` fails both pages right now — expected until this merges, not a regression. Once merged, exercise it through the real pipeline: ```bash gh workflow run docs-e2e.yml --ref docs-e2e/stop-false-blocks \ -f base_url=<preview-url> \ -f page_paths=/docs/guides/troubleshooting/42501--permission-denied-for-table-httprequestqueue-KnozmQ ``` **2. No preview means skip, not a run against production.** Exercise the base-URL step's three paths from the repository root: ```bash export GITHUB_OUTPUT=$(mktemp) GITHUB_STEP_SUMMARY=$(mktemp) PAGE_PATHS=/docs/guides/a script=$(python3 -c "import yaml;print([s for s in yaml.safe_load(open('.github/workflows/docs-e2e.yml'))['jobs']['e2e']['steps'] if s.get('name')=='Resolve base URL'][0]['run'])") for c in "workflow_dispatch|https://supabase.com|" "pull_request||https://docs-abc.vercel.app" "pull_request||"; do IFS='|' read -r ev url dep <<< "$c" : > "$GITHUB_OUTPUT" EVENT_NAME="$ev" BASE_URL_INPUT="${url:-https://supabase.com}" DEPLOYMENT_URL="$dep" bash -c "$script" >/dev/null 2>&1 echo "$ev deployment=[${dep:-none}] -> $(tr '\n' ' ' < "$GITHUB_OUTPUT")" done tail -4 "$GITHUB_STEP_SUMMARY" ``` Expected: ``` workflow_dispatch deployment=[none] -> url=https://supabase.com use_bypass=false should_test=true pull_request deployment=[https://docs-abc.vercel.app] -> url=https://docs-abc.vercel.app use_bypass=true should_test=true pull_request deployment=[none] -> url= use_bypass=false should_test=false ``` followed by a runnable `gh workflow run docs-e2e.yml` command in the job summary. The third line covers both the fork case and the Vercel-failure case: no base URL, no test, no block. **3. A Vercel failure no longer fails the job.** `continue-on-error: true` on the wait step is what routes a throw into that third line: ```bash python3 -c " import yaml s=[x for x in yaml.safe_load(open('.github/workflows/docs-e2e.yml'))['jobs']['e2e']['steps'] if x.get('name')=='Wait for Vercel docs preview'][0] print('continue-on-error:', s.get('continue-on-error')) for n in ('Install dependencies','Install Playwright Chromium','Run docs E2E'): print(n, '->', [x for x in yaml.safe_load(open('.github/workflows/docs-e2e.yml'))['jobs']['e2e']['steps'] if x.get('name')==n][0]['if']) " ``` Expect `continue-on-error: True` and all three run steps gated on `steps.base-url.outputs.should_test == 'true'`. **Note on this pull request's own check.** The scope resolver only maps `apps/docs/content/**` to pages, and this pull request changes none, so `Docs E2E` resolves zero pages and skips — which is correct, and why the dispatch above is the real test. 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved documentation preview checks so unavailable or delayed previews no longer cause unnecessary workflow failures. * Added clearer handling for manual documentation checks and missing preview deployments. * **Tests** * Improved end-to-end documentation testing reliability across preview and production environments. * Added stable targeting for the troubleshooting article to reduce test failures caused by page structure changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
aed332b663 |
feat: migrate Edge Functions report to ClickHouse OTEL logs (#48756)
## Problem
The Edge Functions report (`observability/edge-functions`) only queries
BigQuery. As part of the broader Reports→ClickHouse OTEL migration
(DEBUG-73), we need each report migrated one at a time behind the
`otelReports` flag.
## Fix
Adds a ClickHouse OTEL SQL variant (`METRIC_SQL_OTEL`) for the 4 Edge
Functions metrics (TotalInvocations, ExecutionStatusCodes,
InvocationsByRegion, ExecutionTime), querying the unified `logs` table
filtered to `source = 'function_edge_logs'`, with fields read from
`log_attributes` (`function_id`, `response.status_code`,
`response.headers.x_sb_edge_region`, `execution_time_ms`) — the same
mapping already used by `edge-functions-last-hour-stats-query.ts`.
`edgeFunctionReports()` now takes a `useOtel` flag that picks between
the BQ and OTEL query sets and forwards it to `fetchLogs`. The page
wires this up via `useFlag('otelReports')`, matching the pattern used
for the Auth report. No behavior change while the flag is off — report
still fetches from BigQuery.
Also removed two pieces of dead code spotted in `report.utils.ts` while
touching it: the unused `useEdgeFnIdToName` hook and a
`STATUS_CODE_COLORS` map that was an exact duplicate of
`REPORT_STATUS_CODE_COLORS` (the one actually imported elsewhere).
This PR is standalone — no dependency on the in-flight Auth report OTEL
stack.
## How to test
- `pnpm vitest run data/reports/v2/edge-functions.config.otel.test.ts` —
9 new tests covering the OTEL SQL shape (single logs table,
unix-microsecond timestamp bucketing, field mapping, filters).
- `pnpm vitest run data/reports` and `pnpm vitest run
data/edge-functions components/interfaces/Reports` — existing suites (46
+ 54 tests) still pass, confirming no regression to the BQ path.
- Manually: with `otelReports` flag enabled, visit a project's Edge
Functions observability report and confirm charts render from the
ClickHouse endpoint.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added OpenTelemetry support for Edge Functions observability metrics,
including invocations, status codes, regional activity, and execution
time.
* Reports can now dynamically use either the standard or OpenTelemetry
logs source.
* **Bug Fixes**
* Improved filtering and timestamp handling for OpenTelemetry-based Edge
Functions metrics.
* Added coverage for status, execution time, function, and region
filters.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
55095dcd00 |
chore: highlight totp app friendly name (#48755)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? UI update ## What is the current behavior? We only show the alternative factor's name, if one exists. ## What is the new behavior? When presenting user with the MFA screen, make the MFA factor's friendly_name appear. ## Additional context Before: <img width="456" height="371" alt="Screenshot 2026-08-05 at 15 41 07" src="https://github.com/user-attachments/assets/7d506641-6a9e-49fe-8c40-98c1eef4b384" /> After: <img width="459" height="394" alt="Screenshot 2026-08-05 at 15 38 27" src="https://github.com/user-attachments/assets/034312ba-691e-4f56-b4e3-a82df2a17273" /> <img width="468" height="434" alt="Screenshot 2026-08-05 at 15 37 43" src="https://github.com/user-attachments/assets/4c585eae-b8e2-4f93-8210-2c8ac7c20278" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved multi-factor authentication prompts with clearer formatting and more consistent factor labels. * Ensured the primary code label appears whenever a verification factor is selected. * Added a fallback label for authentication factors without a display name. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ffd6d6636d |
refactor(studio): static tab kind registry and tab id codec (PR 1/9) (#48718)
## Summary First PR in the tab/snippet decoupling stack. Purely additive: no existing call sites change behavior except the `EntityTypeIcon` rewire, which preserves its API exactly. - **`state/tabs/kinds.ts`** — static `TAB_KINDS` descriptor table (`TabKind`, `TabSurface`, `surfaceOf`, `kindsOnSurface`, `isTabKind`). Leaf-safe: its only reference to the domain `Tab` type is a type-only import, so it stays importable at module scope (needed later for the valtio store and the persistence migration reader) without creating a runtime cycle. - **`state/tabs/kinds.icons.tsx`** — per-kind icon leaf module (`ui` + `lucide-react` + `TabKind` type only), plus the preserved `LogsSnippetIcon`. - **`state/tabs/tab-id.ts`** — `createTabId` / `parseTabId` / `toUrlSegment` / `parseUrlSegment(segment, surface)` codec. `parseUrlSegment` is surface-scoped: a bare segment only resolves to a kind when the surface has exactly one bare kind (true for `sql`). The table surface has five bare kinds (`r`/`v`/`m`/`f`/`p`) with no URL disambiguator between them, matching `/editor/[id]`, which learns kind from the fetched entity rather than the URL — so a bare table segment correctly resolves to nothing. - **`components/ui/EntityTypeIcon.tsx`** — rewired to a thin wrapper delegating to `kinds.icons.tsx`, preserving its exact prop API (`type`, `size`, `strokeWidth`, `isActive`, `sqlSource`) for all existing consumers. - **`state/tabs/tab-id.test.ts`** — codec round-trips per kind, bare-vs-prefixed URL segments, the `templates`/`examples`/`new` sentinels, and surface scoping (including the table-surface ambiguity above). Full plan: `apps/studio/TABS_DECOUPLING_PLAN.md` (not included in this PR). ## Test plan - [x] `pnpm typecheck` - [x] `pnpm lint --filter=studio` (0 errors) - [x] `pnpm --filter studio run lint:ratchet` (warning counts did not increase) - [x] `pnpm test:studio` (full suite green, including 50 new/updated tests in `state/tabs/`) - [x] `pnpm format` (no-op) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added consistent icons and metadata for SQL, notebook, chat, table, view, and related tab types. * Added support for creating, parsing, and converting tab identifiers to URL segments. * Improved handling of tab types across SQL and table surfaces. * **Bug Fixes** * Invalid, empty, or ambiguous tab identifiers and URL segments are now rejected. * **Tests** * Added coverage for tab identifiers, URL conversion, supported tab types, and edge cases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
69b1f06152 |
docs(blog): add Enhancements for Postgres Changes launch post (#48711)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Adds the launch blog post for Enhancements for Postgres Changes, dated 2026-08-05 - Adds the social card and listing thumbnail for the post ## What is the current behavior? N/A. New post. ## What is the new behavior? - New post at `/blog/postgres-changes-filters-and-column-selection` covering AND filter composition, the expanded filter operator set, and column selection on Postgres Changes subscriptions - Authored by Filipe Cabaço, using the existing `filipe` author id, so no change to `apps/www/lib/authors.json` ## Additional context **Please do not merge before 7:00 am PT on 2026-08-05.** <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Added a product blog post covering enhanced Postgres Changes filtering, including comma-separated AND filters across multiple columns. * Documented additional filter operators and the new filter builder. * Explained optional column selection for event payloads, permissions and row-level security behavior, DELETE limitations, unsupported options, client-version requirements, usage examples, and upgrade guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <ana1337x@users.noreply.github.com> |
||
|
|
1f0fb64ce9 |
docs: CLI 'Transport error' caused by antivirus/proxy TLS interception (#48719)
## Summary - Adds a troubleshooting entry for the Supabase CLI's generic `HttpClientError: Transport error` when a Management API call (e.g. `projects list`, `link`) fails. - Root cause documented: antivirus software or corporate SSL-inspecting proxies (e.g. Norton Safe Web/Web & Mail Shield, Zscaler, Netskope) substituting their own TLS certificate, which the CLI's HTTP client rejects and reports as a generic transport error rather than a certificate error. - Includes a vendor-agnostic diagnostic method (compare `curl`/browser vs. CLI behavior, check the served certificate's Issuer field) plus the specific Norton fix confirmed via a support ticket (disabling Smart Firewall alone does not stop the interception; Safe Web/Web & Mail Shield does). ## Test plan - [ ] `pnpm --filter docs lint:mdx` passes in CI - [ ] Frontmatter renders correctly on the troubleshooting page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added troubleshooting guidance for Supabase CLI transport errors caused by antivirus software or corporate TLS inspection. * Included diagnostic steps, common error messages, and resolution guidance for Norton 360 and SSL-inspecting proxies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Rodrigo Mansueli <rodrigo@mansueli.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
af384e136f | chore(self-hosted): update tags in docker guide (#48739) | ||
|
|
9952d6f10f |
[FE-4067] fix(studio): re-allow all regions in local project creation (#48704)
Local dev stacks can run in any of the three supported regions (e.g. Bobbie's is in `ap-southeast-1`), but enabling High Availability on the project creation form pinned local to Frankfurt only. This unrestricts local so all three regions are selectable again. **Changed:** - `getHighAvailabilityRegionCode()` returns `undefined` for `local` (same as prod), so `filterHighAvailabilityRegions()` no longer collapses the list — staging stays pinned to `us-east-1` - The three-region warning in `RegionSelector` now adds a local-only recommendation: "Use Central EU (Frankfurt) unless you're on a personal dev stack." - Updated unit tests, including an `ap-southeast-1` fixture region to prove pass-through ## To test - On a local stack, open the new project form and enable High Availability — the region selector should offer all three regions (East US, Frankfurt, Southeast Asia) instead of locking to Frankfurt, and the warning should recommend Frankfurt unless you're on a personal dev stack - Confirm staging behavior is unchanged (HA still pins to East US) - `pnpm --filter studio exec vitest run components/interfaces/ProjectCreation` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Local development projects can now use high-availability regions beyond Central EU. * Region filtering and availability messaging now correctly reflect the active environment, including staging restrictions. * **User Experience** * Added guidance recommending Central EU for local projects, unless using a personal development stack. * Region selection now provides clearer environment-specific information when options are limited. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
3c811b9c29 |
fix(studio): extend SupportForm project waitFor timeout (#48211)
## What kind of change does this PR introduce?
Test flake fix.
## What is the current behavior?
`SupportFormPage` → “submits support request with attachments…” can fail
under CI load:
- expected project selector text `Project 1`
- received `No specific project`
Org is applied first; the project is filled asynchronously via
`onInitialLoad` after org projects fetch. That wait still used the
default ~1s `waitFor`, while every sibling Project 1 assertion already
uses `{ timeout: 5_000 }` (see #45852).
## What is the new behavior?
- Attachments test waits up to 5s for Organization 1 + Project 1
- Same timeout for the org-switch → Project 2 waiter (same pattern)
No production code changes.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Tests**
* Improved support form test reliability by allowing additional time for
organization and project selectors to load during asynchronous
interactions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
9b3e0a9060 |
show Vercel connection errors inline (#48473)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Vercel install and project-link failures use transient toasts. ## What is the new behavior? Failures remain visible below the relevant action and clear when the user retries or changes a selection. The Vercel mutation hooks expose errors without choosing their presentation. Interstitial callers render them inline, while existing non-interstitial callers explicitly retain their toasts. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Install Vercel Integration Supabase" src="https://github.com/user-attachments/assets/6348cdd2-220a-4ad8-89f9-7fc51de36a3c" /> | <img width="1024" height="759" alt="Install Vercel Integration Supabase" src="https://github.com/user-attachments/assets/ecc50c4e-daab-4f6d-bf86-7282e2aff92c" /> | ## To test 1. Switch to `dnywh/inline-vercel-errors` (this branch). 2. Open `apps/studio/pages/integrations/vercel/install.tsx`. 3. Find the `actionError` assignment immediately below `useVercelIntegrationCreateMutation` and replace the whole assignment with: ```tsx const actionError = 'Creating Vercel integration failed: Test error' ``` 4. With local Studio running and while signed in, open `http://localhost:8082/integrations/vercel/install?code=test&configurationId=test&source=marketplace` 5. Confirm the error remains visible below **Install integration**. No Vercel installation or real authorisation code is required. 6. Revert the temporary edit. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Bug Fixes * Improved error handling across Vercel project connection and installation flows. * Validation, duplicate-connection, and connection failures now appear inline in the relevant setup steps. * Errors clear automatically when the selected project or organization changes. * Notifications remain available in supported flows, including new project creation and side-panel setup. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
89a5d03817 |
docs: add eu-central-2 to Edge Functions regional invocation page (#48721)
<!-- ccr-slack-attribution --> _Requested by **Kalleby Santos** · [Slack thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785871243937099?thread_ts=1785871243.937099&cid=C02KMRX22NR)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update — one-line content fix. ## What is the current behavior? The [Regional Invocations](https://supabase.com/docs/guides/functions/regional-invocation) page's "Available regions" section lists every Edge Functions region **except `eu-central-2`** (AWS Europe, Zurich). The region has been live in production for a while, but it was never added to the docs. A user reading this page to pick a region for `x-region` / `FunctionRegion` had no way to know Zurich was an option — the page reads as an exhaustive list, so the omission actively implies the region doesn't exist. Reported by Kalleby Santos (Edge Functions team). Linear: [FUNC-761 — Add eu-central-2 to regional invocation docs page](https://linear.app/supabase/issue/FUNC-761/add-eu-central-2-to-regional-invocation-docs-page) ## What is the new behavior? **Before:** the Europe group listed `eu-central-1`, `eu-west-1`, `eu-west-2`, `eu-west-3`. **After:** `eu-central-2` (Zurich) is listed alongside the others, so the page reflects the regions Edge Functions actually serves. ### How One line added to `apps/docs/content/guides/functions/regional-invocation.mdx`, in the **Europe** group directly after `eu-central-1`, following the list's existing sort-by-region-code order and the surrounding `` `code` (Short location) `` label style: ```diff **Europe:** - `eu-central-1` (Frankfurt) +- `eu-central-2` (Zurich) - `eu-west-1` (Ireland) - `eu-west-2` (London) - `eu-west-3` (Paris) ``` No other files changed. This page's region list is hand-maintained in the MDX and is deliberately narrower than the project-creation region list in `packages/shared-data/regions.ts` (which also includes `us-east-2` and `eu-north-1`), so no shared constant needed updating and no other product's region list was touched. ## Additional context **Verification that `eu-central-2` is a real Edge Functions invocation region** — confirmed in three independent places: 1. `supabase/platform` → `pulumi/edge-runtime/Pulumi.prod.yaml:533` — `region: eu-central-2`, with `enabled: true` at `:531`. A fully provisioned prod region (360–540 always-on tasks), not a placeholder. Branch `develop`, HEAD `1f44167768f951c0c794313006bc2c9f9758c344`. 2. `supabase/platform` → `pulumi/edge-runtime-next/stack-config/Pulumi.prod.aws.euc2.yaml:6` — `aws:region: eu-central-2` under the `Edge-Functions/K8s-Prod` environment, tagged `product: functions`. 3. `supabase/api-gateway` → `customer-router/wrangler.toml` — `eu-central-2` is present in the `EDGE_FUNCTIONS_REGIONAL_ORIGINS` map (`eu-central-2 = "https://eu-central-2.edge-runtime.supabase.green"`). This is the table that resolves the `x-region` header, so regional invocation into Zurich is genuinely routable — not just deployed. **For a reviewer to confirm separately (intentionally not in this diff):** production infra has 16 enabled Edge Functions regions, so `us-east-2` (Ohio, `pulumi/edge-runtime/Pulumi.prod.yaml:507`, `enabled: true`) is *also* missing from this page. It's excluded here because we don't yet know whether that omission is deliberate; it's being confirmed with the team and can be a follow-up. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy --- _Generated by [Claude Code](https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
2165746784 |
fix(studio): keep SQL editor source menu open when switching sources (#48715)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? Selecting Database/Logs in the SQL Editor's query-source dropdown closes the menu (Radix's default select behavior), so switching to Logs gives no visible indication that a Time range control just became available until the dropdown is reopened. ## What is the new behavior? Selecting a source keeps the dropdown open, so the newly-available source-specific controls (e.g. Time range for Logs) are immediately visible. ## Additional context Fixes FE-4036 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved source switching in the SQL editor so the selection menu remains open while changing between database and logs sources. * Ensured source-specific controls update correctly after switching. * **Tests** * Added coverage for source selection, menu behavior, and source-specific control updates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5986fecc89 |
fix(studio): use table + card component in log retention upgrade prompt (#48713)
## Summary - Refactor the SQL Editor / Logs "Log retention" upgrade-prompt dialog to use the design system's `Card` + `Table` components instead of a custom flexbox-div table, matching the pattern in `apps/design-system/registry/default/example/table-demo.tsx` - No behavior or data change Fixes FE-4034 Non-blocking review nit from #48452 (comment: https://github.com/supabase/supabase/pull/48452#issuecomment-5128918096) ## Test plan - [x] `pnpm --filter studio typecheck` passes - [x] `pnpm --filter studio run lint:ratchet` passes (no new warnings) - [x] Prettier check passes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the upgrade prompt with a more consistent card and table layout. * Preserved existing plan names and log retention details. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b9053794a0 |
fix(studio): add tooltip explaining why Prettify SQL is disabled (#48712)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? In the SQL Editor, the Prettify SQL action (both the "More actions" dropdown menu item and the toolbar button) is disabled for logs snippets, but gives no indication why. ## What is the new behavior? The disabled Prettify menu item now uses `DropdownMenuItemTooltip` and the disabled Prettify toolbar button uses `ButtonTooltip`, both showing "Can only prettify SQL queries" while disabled. Addresses review feedback from #48452 (Linear FE-4038). ## Additional context Resolves FE-4038 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated SQL editor tooltips with clearer, consistent messaging. * Log-source users now see an explanation when SQL formatting is unavailable. * Regular users continue to see the SQL prettify keyboard shortcut. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0bf5ca584d |
docs: Update Swift/Kotlin postgrest specs and Swift Web3 sign-in (#48291)
## Summary Cross-referenced recent commits across all 6 SDK repos (supabase-js, supabase-flutter, supabase-py, supabase-swift, supabase-kt, supabase-csharp) against `apps/docs/spec/` and `apps/docs/content/guides/`. Most recent commits were CI/chore/release/patch-fix noise; the following genuine feature gaps were found and fixed. ## Changes analyzed - **supabase-swift**: `dryRun()`, `notIn()`, `maybeSingle()` (PR supabase/supabase-swift#1114) and `signInWithWeb3()` (PR supabase/supabase-swift#1138) - **supabase-kt**: `dryRun()`, `notIn()`, `maybeSingle()` (PR supabase-community/supabase-kt#1365) ## Documentation updates - `apps/docs/spec/supabase_swift_v2.yml` — added `notin`, `dry-run`, `maybe-single` filter/modifier entries and a `sign-in-with-web3` auth entry (Web3/Ethereum/Solana sign-in was already documented for JS and Dart, missing for Swift) - `apps/docs/spec/supabase_kt_v3.yml` — added `notin`, `maybe-single`, `dry-run` entries - `apps/docs/spec/common-client-libs-sections.json` — registered nav entries for the two brand-new cross-SDK ids (`notin`, `dry-run`); `sign-in-with-web3` was already registered ## Explicitly out of scope - **Kotlin `custom_claims_allowlist`** (added to `CustomOAuthProvider`/`CustomProviderBuilder` in supabase-kt) — skipped. The Kotlin spec has no admin custom-OAuth-provider section documented at all yet (create/list/get/update/delete), so adding just this one field would require authoring a whole new, currently-undocumented admin API section from scratch — too large/risky to guess correctly in this pass. Flagging for a follow-up. - Dart's recently-shipped storage features (vector buckets, analytics/Iceberg buckets, `purgeCache`, `downloadStream`, `listPaginated`) were checked and are already fully documented in `supabase_dart_v2.yml`. - Swift/Kotlin lacking Storage vector-bucket/analytics-bucket docs — out of scope, those SDKs didn't ship that feature in this commit range (Dart-only so far). ## Test plan - [x] `python3 -c "import yaml; yaml.safe_load(open(...))"` — both edited YAML specs parse cleanly - [x] `python3 -c "import json; json.load(open(...))"` — nav JSON parses cleanly - [ ] Visual check of the rendered reference pages for `notIn`/`dryRun`/`maybeSingle`/`signInWithWeb3` on Swift and Kotlin reference docs --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added documentation for `notIn()` query filtering across supported Kotlin and Swift query operations. * Documented `maybeSingle()` for safely handling zero-or-one query results without raising a single-row error. * Added guidance for `dryRun()` mutations, including rollback behavior and returned results. * Added Swift authentication documentation for Web3 sign-in with Ethereum and Solana credentials. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
89010c1649 |
fix(studio): show selected custom time range in SQL editor time range menu (#48709)
## What Display the actual selected custom date range in the Time Range dropdown's secondary text, instead of the static "Custom range" label. The range is formatted as `DD MMM, HH:mm - DD MMM, HH:mm` to match the existing format in the Logs Explorer's date-picker trigger button, ensuring visual consistency across the Logs UI. Fixes FE-4035 ## Test plan - [x] Typecheck passes: `pnpm typecheck` - [x] Manually verify: Open SQL Editor with `sqlEditorLogsSource` flag enabled, open the Time Range dropdown menu, select a Custom range, and confirm the dropdown's secondary text now displays the selected date range instead of "Custom range" <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Custom time ranges now display formatted start and end timestamps for clearer time selection. * Preset time ranges continue to show their existing helper text. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4a9b5a538b |
chore: update pg changes to add python to the code blocks (#47793)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Adds code blocks for Python and new pg changes features <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated Python code examples for Realtime Postgres Changes to use cleaner, working subscription syntax. * Fixed a missing comma in a multi-change example so the sample code is valid. * Added a missing Python example for selecting specific columns. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
0791b04eb8 |
feat(sql-editor): roll out manual saving by default (#48706)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — progresses the SQL Editor manual saving rollout, and removes a fully rolled out feature flag. ## What is the current behavior? Manual saving (snippets save only on an explicit Save / Cmd+S rather than autosaving every edit) is opt-in. It requires both the `sqlEditorManualSave` ConfigCat flag and the user turning on the "Disable snippet auto-saving" feature preview themselves. That flag is now fully rolled out. ## What is the new behavior? - `sqlEditorManualSave` is removed, so the feature preview is listed for everyone. (Delete the flag in ConfigCat after a few months.) - New `sqlEditorManualSaveForced` flag progresses the rollout. It forces manual saving on regardless of what the user stored previously, including an explicit opt-out, via a new `isForced` field on `FeaturePreview` that `initializeFlags` resolves ahead of the localStorage lookup — so the feature preview modal reflects the forced state too, not just the save behavior. Turning the flag off reverts everyone who never opted in, so it remains a working kill switch. - Users the rollout switches over get a one-time dialog on their first SQL Editor route, explaining that snippets no longer autosave. Dismissal persists in `sql-editor-manual-save-notice-dismissed` (allowlisted, so it survives sign-out). - Users who opted into the preview themselves never see the dialog — it records their dismissal up front instead, since the notice needs to outlive the feature preview and once the preview is retired there's no stored opt-in left to recognize them by. - The preview keeps its switch so users who lose their local storage can opt in early, but once the rollout reaches them the "Disable feature" button is disabled with a tooltip explaining why. ### To test Turn on `sqlEditorManualSaveForced` on via the dev toolbar. - No `supabase-ui-sql-editor-manual-save` and no dismissal key → dialog appears on `/project/<ref>/sql`, toolbar shows the Save button. Dismiss, reload → no dialog. - `supabase-ui-sql-editor-manual-save` set to `false` (previously opted out) → still forced onto manual saving, and still gets the dialog. - `supabase-ui-sql-editor-manual-save` set to `true` → no dialog, and the dismissal key is written automatically. - Flag off, no opt-in → autosave, no dialog, and the "Disable autosave" power-off button still opens the preview modal. - Preview modal while forced → "Disable feature" is disabled with a tooltip; another preview (e.g. Column-level privileges) still disables normally. ## Additional context |
||
|
|
e7d9c88cbc |
fix(docs): resolve remaining heading-order issues found in Pass 2 diagnostic (#48664)
## Problem After merging [#48456](https://github.com/supabase/supabase/pull/48456) (shared components) and [#48459](https://github.com/supabase/supabase/pull/48459) (per-page content fixes), a follow-up diagnostic pass found 22 remaining heading-order violations, logged as Pass 2 in the [triage report](https://app.notion.com/p/supabase/Playwright-E2E-Triage-Reports-3ab5004b775f81e3bc60d058fa5a02c1). None of them were caught by the earlier fixes because they came from places that scan didn't check: shared partials, raw HTML heading tags written directly in MDX, and a couple of shared/interactive components rendering hardcoded heading levels. ## Solution - `_partials/social_provider_setup.mdx`: `#### Local development` → `###`, matching the `##` that always precedes it on all 14 social-login pages. - `guides/database/functions.mdx` and `guides/integrations/vercel-marketplace.mdx`: replaced raw `<h4>`/`<h5>` tags with correctly-nested real headings (`### Planets`/`### People`; `#### Deploy a Next.js app...`) — no styling workarounds needed since they nest naturally one level below their parent section. - `auth/quickstarts/{nextjs,react-native,react,astrojs}.mdx`: these 4 pages had no heading at all before the embedded `_partials/api_settings.mdx` partial's own `### Get API details` heading, so added a `## Quickstart` heading above the walkthrough to give it a valid parent. - `packages/ui`'s `Accordion` component: Radix's `AccordionPrimitive.Header` renders as an unconditional `<h3>` regardless of where the accordion is used. That's shared across Studio, www, and design-system, not just docs, and surfaced on docs' vendor-agnostic telemetry page. Now rendered via `asChild` onto a plain `div` instead, since a generic accordion has no way to know what heading level (if any) is valid in a given page. - SQL-to-REST translator tool (`/docs/guides/api/sql-to-rest`): its `Assumptions`/`FAQs` section labels were hardcoded `<h3>` with no `h2` anywhere on the page. Converted to styled spans rather than promoting to a real `<h2>`, because real h1/h2/h3 tags in this codebase force a prose font-size that utility classes can't override — promoting the tag would have visibly changed its size. - `RealtimeLimitsEstimator` (embedded on both `postgres-changes` and `benchmarks`): its 3 section headings were hardcoded `<h4>`, but the two embedding pages need different levels (h3 vs h4) for that spot to be valid — no single correct heading level. Converted to styled spans, same pattern used throughout this project for components embedded at varying heading depths. ## Manual testing 1. Check out this branch and run `pnpm dev:docs`. 2. Visit `/docs/guides/auth/social-login/auth-github` (or any other provider page) and confirm the "Local development" callout under "Find your callback URL" still looks and reads the same. 3. Visit `/docs/guides/database/functions` → "Returning data sets" tab and confirm the "Planets" / "People" table captions still look the same. 4. Visit `/docs/guides/integrations/vercel-marketplace` → "Quickstart" → "Via template" and confirm the CTA card title still looks the same. 5. Visit `/docs/guides/auth/quickstarts/nextjs` (or react-native/react/astrojs) and confirm a "Quickstart" heading now appears above the walkthrough, and "Get API details" still renders correctly further down. 6. Run `pnpm dev:design-system` and open `/design-system/docs/components/accordion` — expand/collapse an item and confirm it still animates and looks identical; inspect the DOM and confirm the trigger's wrapper is a `div`, not an `h3`. 7. Visit `/docs/guides/api/sql-to-rest`, translate any query, and confirm the "Assumptions"/"FAQs" section labels still look the same. 8. Visit `/docs/guides/realtime/postgres-changes` and `/docs/guides/realtime/benchmarks`, scroll to the connection-limits calculator, and confirm its section labels still look the same on both pages. 9. (Optional, for a full re-check) Run `pnpm e2e:docs:a11y --all` against a deployed preview of this branch — only `/docs/guides/cli` (pre-existing 404, unrelated to headings) should fail; every other page should pass. Verified with a full Playwright run against a real preview deployment: **756 passed, 1 failed** (`/docs/guides/cli`, the pre-existing unrelated 404). Zero heading-order violations remain. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added clearly labeled Quickstart sections to Astro, Next.js, React Native, and React authentication guides. - Improved heading hierarchy and formatting across social provider setup, database functions, and deployment documentation. - Updated estimator and SQL-to-REST section presentation for more consistent content structure. - **Bug Fixes** - Improved accordion trigger layout while preserving existing behavior, styling, accessibility, and icon display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
0e71933ce3 |
[FE-4070] fix(studio): allow adding expressions to RLS policies (#48700)
A table RLS policy created via SQL without a `USING`/`WITH CHECK` clause
stores `null` for that field, and the policy editor's payload diff
skipped `null` fields entirely — so adding an expression later through
the dashboard closed the panel as if saved but persisted nothing. This
fixes the diff so those policies are editable, and cleans up adjacent
issues in the same code path.
**Changed:**
- Extracted the update-payload diff from `PolicyEditorPanel`'s submit
handler into a pure `generateUpdatePolicyPayload()` in
`PolicyEditorPanel.utils.ts`. A stored `null` definition/check now
counts as empty, so typing an expression into a previously empty editor
produces a payload field. The diff is branched by command so INSERT
policies only ever emit `WITH CHECK`, never an invalid `USING` clause.
- The required-expression validation ("Please provide a SQL
expression…") now applies only when creating a policy. When updating, a
`null` clause is valid, so rename-only and role-only saves on such
policies work; the update path instead rejects attempts to clear an
existing `USING`/`WITH CHECK` expression with an inline error (`ALTER
POLICY` can only replace an expression, not remove it).
- Saving with no changes now closes the panel without a round trip —
previously a null-vs-undefined comparison injected a
present-but-`undefined` payload key, which sent a literal `BEGIN;
COMMIT;` to the user's database.
- Fixed the unsaved-changes check comparing the form's lowercase command
against `'INSERT'` (never matched), which made closing an untouched
INSERT policy editor prompt about unsaved changes. It now compares
`selectedPolicy.command`.
**Added:**
- `PolicyEditorPanel.utils.test.ts` — 11 unit tests covering null→value
transitions for definition and check, INSERT command mapping,
value→value updates, no-op saves, and empty-value handling.
## To test
- Run in the SQL editor: `create policy "p1" on <table> for delete to
authenticated;` (no `USING` clause), then edit `p1` in Database →
Policies, add a `USING` expression, and save. Confirm via `select
pg_get_expr(polqual, polrelid) from pg_policy where polname = 'p1'` that
the expression persisted.
- Same for INSERT: `create policy "p2" on <table> for insert to
authenticated;`, then add a `WITH CHECK` expression via the editor and
confirm `polwithcheck` is set (and `polqual` stays null).
- On `p1` (still without a `USING` expression? recreate it if you added
one), rename the policy without touching the expression editors — the
rename should save successfully.
- Edit a policy that already has a `USING` expression, change it, and
confirm the new expression persists (regression).
- Open a policy and save without changing anything — the panel should
close with no `policy-update` network request.
- On a policy with an existing `USING` (or `WITH CHECK`) expression,
clear that editor and save — an inline error should appear and no
request should fire.
- Open an INSERT policy that has a `WITH CHECK` expression, change
nothing, and close the panel — it should close without an "Unsaved
changes" prompt.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Policy updates now submit only changed fields.
* Improved handling of policy expressions, including INSERT-specific
mappings.
* Prevented removal of existing `USING` or `WITH CHECK` expressions
where unsupported.
* Empty expressions are omitted from update requests.
* Updates are canceled when no changes are detected.
* **Tests**
* Added coverage for unchanged policies, expression updates, name and
role changes, and INSERT policy behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
|
||
|
|
ceace2e90b |
fix(studio): account for SQL result column headers (#48676)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? Fixes #48672. The SQL Editor results grid calculates each column's initial width from cell values only. When a long final column contains a short value such as `NULL`, scrolling to the end of a wide result set reveals a truncated header even though the full column name is needed to identify the result. ### Before <img width="760" height="370" alt="Before: final SQL result column header is truncated" src="https://github.com/user-attachments/assets/f73b7540-fc45-4ddf-91b6-996afe41807e" /> ## What is the new behavior? The initial width now accounts for both the column name and its cell values while preserving the existing minimum and maximum width constraints. ### After <img width="760" height="370" alt="After: full SQL result column header is visible" src="https://github.com/user-attachments/assets/b289ab86-4277-46fc-ae9a-35c3eac5442f" /> ## Additional context The width calculation was extracted into a utility and covered for: - short headers and values - headers longer than their values - values longer than their headers - empty result sets - maximum-width capping Verification: - `pnpm --filter studio exec vitest --run components/interfaces/SQLEditor/UtilityPanel/Results.utils.test.ts tests/components/SQLEditor/Results.test.tsx` - `pnpm --filter studio run typecheck` - `pnpm --filter studio run lint:ratchet` - `pnpm run test:prettier` - `SKIP_ASSET_UPLOAD=1 pnpm run build:studio` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - SQL query results now automatically size columns based on their headers and content. - Column widths remain within practical minimum and maximum limits for improved readability and usability. - **Tests** - Added coverage for minimum and maximum widths, content-based sizing, and empty result sets. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
469da990b6 | chore: Add Filipe to humans (#48698) |