Commit Graph
19725 Commits
Author SHA1 Message Date
Claude 4b8509db2b fix(studio): use shared EMPTY_ARR for api-keys fallback
A fresh `[]` literal on every fetch breaks referential equality for
downstream consumers (the useMemo in Landing.utils.ts re-runs on every
render). Use the shared EMPTY_ARR instance, matching the idiom already
used by lint-query, schemas-query, fdws-query and friends.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V9mYmaGzoXkrJtTkrLKaVA
2026-08-06 16:57:23 +00:00
Ali Waseem 61e9818599 Merge branch 'master' into fix/api-keys-array-coerce 2026-08-06 10:55:13 -06:00
2a3025df25 feat(studio): role inference core for scoped pat (#48805)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Logic-only extraction from #48742. Scoped PATs are enforced server-side
as the intersection of the token's granted scopes and the owner's live
role, re-checked on every request. This lands the pure inference layer
that will power advisory (never blocking) UI feedback; no UI consumes it
yet.

- FGA_SCOPE_MINIMUM_ROLE: all 83 permission scopes transcribed from the
OpenFGA model's role unions, mapped to the lowest base role that holds
them. A drift-guard test pins the key set to the scope ids published in
@supabase/shared-types, so upstream additions fail CI here with
re-transcription instructions.
- estimateRoleLevel: derives the user's base role per org (or per
project for project-invited members) from the ungated /platform/profile/
permissions rows via four discriminating ABAC probes. Works for every
member type with no permission-gated endpoint.
- computeTokenRoleContext + applySelectionToRoleContext: role resolution
(expensive, memoized) is split from selection evaluation (cheap, re-run
per permission toggle).

AccessToken.permissions.ts gains only what the roles module needs: the
PermissionLevel type and the catalog's `level` field (decides whether an
org or project role governs a resource), plus getEntryScopes, which
selectionToScopes now reuses. The UI-only additions from #48742 (risk
badge/dot variants, mode labels, the OverallRisk.text -> description
rename) are deliberately left out so this PR touches no .tsx.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added role-aware evaluation for scoped access-token permissions.
* Added support for organization- and project-level permission scoping.
* Added guidance when selected permissions exceed the current role,
including read-only downgrades and inaccessible resources.
  * Added clearer grouping of permission access issues by resource.

* **Tests**
* Added comprehensive coverage for role mapping, permission evaluation,
scoping, and failure scenarios.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Wen Bo Xie <wenbox323@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 17:31:41 +01:00
33008a39e5 chore(studio): remove scoped pat orphaned form (#48803)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

First step in breaking down #48635


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Removed the scoped access-token form, including token details,
expiration settings, resource access, and permission configuration.
* Removed resource and permission selection controls from the
access-token workflow.

* **Tests**
* Removed automated coverage for access-token validation, permission
handling, expiration logic, and resource selection.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Wen Bo Xie <wenbox323@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 17:20:55 +01:00
Cemal KılıçandJeremias Menichelli 1ff84a239c docs(auth): note that resetPasswordForEmail doesn't send email for un… (#48800)
add note on `resetPasswordForEmail` doesn't send email for unregistered
emails

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified that password reset requests do not reveal whether an email
address is associated with an account.
* Documented that requests for unrecognized email addresses complete
without an error.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
2026-08-06 15:41:35 +02:00
cddb430310 feat(studio): scoped pat root branch (#48384)
## Description

This is the Scoped PAT stacked PRs root branch

## How to test

### With the `scopedPAT` enabled (default on staging)

Go to
https://studio-staging-git-scopedpat-merge-token-lists-supabase.vercel.app/dashboard/account/tokens.
- You shouldn't see two tabs anymore
- If you had classic tokens, they should have the _Legacy_ badge
- You can create scoped tokens
- You have a way to copy newly created tokens before closing the form
side panel

### With the `scopedPAT` disabled (use the devtool to override)
- You shouldn't see two tabs anymore
- If you had classic tokens, they should **not** have the _Legacy_ badge
- You can create classic tokens
- You have a way to copy newly created tokens above the list upon form
submission

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Show classic and scoped access tokens together in one list, with
classic tokens labeled “Legacy” when the scoped experience is enabled.
* Add scoped access token creation with a two-step configure → review →
success flow (when enabled).
* Add a dismissible migration notice about scoped tokens with a link to
API docs.
  * Show “View permissions” only for scoped tokens.
* **Bug Fixes**
* Token deletion now supports both classic and scoped tokens with the
correct confirmation and success handling.
* The scoped tokens page now redirects to the unified access tokens
page.
* **Accessibility**
* Improved accessibility by adding a label to the token “more options”
action.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
Co-authored-by: kemal.earth <606977+kemaldotearth@users.noreply.github.com>
2026-08-06 07:40:56 -06:00
Monica Khoury 2afb87af05 fix(ui): add bottom padding to scroll container in RLS search (#48759)
Fixes FE-4075. 

## What kind of change does this PR introduce?

The footer displaying the total number of RLS policies overlaps the last
search result in the RLS Policy Search dialog. As a result, the last
policy entry is partially hidden and cannot be fully read when scrolling
to the bottom.

## What is the current behavior?

The search results container now reserves space for the footer,
preventing it from overlapping the last search result. All policy
entries remain fully visible when scrolling to the bottom.

<img width="400" height="300" alt="image"
src="https://github.com/user-attachments/assets/46529ca4-bdce-4fa2-b0ba-ea87e769cc24"
/>

## What is the new behavior?

<img width="400" height="300" alt="CleanShot 2026-08-05 at 18 19 27@2x"
src="https://github.com/user-attachments/assets/093a3f9e-fd4c-4ff6-b483-2839f3916d13"
/>

## How to test

- Open a project in the Supabase Dashboard.
- Navigate to Database → RLS Policies.
- Open the policy search dialog.
- Search for a term that returns enough results to make the list
scrollable
- Scroll to the bottom of the results.

The
[database.sql](https://gist.github.com/monicakh/49b5ff201893eb43aea329395b3f635b)
to create the tables/policies to test.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Improved scrolling in policy search results.
* Added spacing at the bottom so results remain visible above the fixed
footer.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 17:00:28 +07:00
Danny White 840127cd69 let inline error callers own mutation failures (#48640)
## What kind of change does this PR introduce?

Code clean-up following #48470, #48471, #48472, #48473, and #48474.

## What is the current behavior?

Mutation hooks provide fallback error toasts, so callers that already
render errors inline must suppress those toasts with empty `onError`
handlers.

## What is the new behavior?

The affected callers own their error presentation. Inline interstitial
errors remain unchanged, API authorisation retains its state-reset
handlers, and Project Claim retains its combined caller-owned toast.

## To test

There is no useful before-and-after visual check for this PR: the
rendered error states should be identical on `master` and this branch.
The change only removes the default-toast and no-op-handler pair
underneath the UI.

The existing [Organisation
Invite](https://github.com/supabase/supabase/pull/48470), [API
authorisation, AWS
Marketplace](https://github.com/supabase/supabase/pull/48471), and
[Stripe Projects](https://github.com/supabase/supabase/pull/48472)
failure tests cover the inline errors and confirm that no duplicate
toast appears.
2026-08-06 16:06:38 +07:00
Jordi Enric 93b5ae71bf chore: remove unused useProjectUsageStats hook (#48792)
## Problem

`useProjectUsageStats`
(`apps/studio/hooks/analytics/useProjectUsageStats.tsx`) has no
importers anywhere in the codebase — dead code, and it also still
queries BigQuery directly (`logs.all`, no OTEL path), which would've
made it another gap in the reports→ClickHouse migration if it were ever
wired up.

## Fix

Deletes the file. Confirmed nothing imports it, and none of its own
imports (`useFillTimeseriesSorted`, `useTimeseriesUnixToIso`,
`genChartQuery`, `EventChart`) become unused as a result — all are still
used elsewhere.

## How to test

- `pnpm tsc --noEmit` — no errors referencing the removed file.
- `pnpm vitest run hooks/analytics` — 28 tests pass, no breakage.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Removed the project usage analytics statistics feature, including its
data retrieval, time-series processing, filtering, refresh controls, and
loading/error states.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 16:02:56 +07:00
Joshen Lim 8618991b6f Initialize explorer home page (#48790)
## Context

More groundwork for the Explorer - initializing the home page

Note that nothing here is functional, all just visual still

<img width="1387" height="960" alt="image"
src="https://github.com/user-attachments/assets/d4967578-edbd-476f-8150-d9d5e9d66666"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added a new Explorer landing page with an assistant chat form.
  * Added quick actions for creating notebooks and SQL work.
* Added notebook and chat template cards for faster project exploration.

* **Improvements**
  * Explorer content now fills the available page height.
* Assistant send button styling now reflects whether submission is
available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 16:02:44 +07:00
Riccardo Busetti 21919ec9b8 feat(pipelines): Use new restart endpoint (#48737) 2026-08-06 09:02:10 +00:00
Etienne Stalmans 51c5b9f013 chore: sync ssl enforcement and temporary access (#48743)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore - fix-up

## What is the current behavior?

Temporary access depends on ssl enforcement. The frontend doesn't
enforce this very well or keep state between the two configs.

## What is the new behavior?

This updates the two configs to be interdependent and updates to each
one triggers a frontend state change on the other.

## Additional context

Before:



https://github.com/user-attachments/assets/8f040b62-587c-4268-9e27-27dd09b052a3



After:



https://github.com/user-attachments/assets/c62e006e-6147-4c94-b6cf-375ca300b890



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added confirmation dialogs and downtime warnings before changing
database SSL enforcement.
- Added loading states and success or failure notifications for SSL
updates.
- Enabled SSL enforcement directly from temporary database access
settings.

- **Bug Fixes**
- Prevented SSL enforcement from being disabled while temporary database
access is enabled.
  - Improved settings refresh after SSL enforcement changes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 10:52:37 +02:00
Joshen Lim 4550ee18a4 Initialize tabs UI for explorer (#48789)
## Context

Continued ground work for Explorer - just initializes the Tab UI for
Explorer as such:
- Plan is to continue using the existing tabs store + EditorTabs
component
- Purely visual, nothing functional
<img width="1389" height="556" alt="image"
src="https://github.com/user-attachments/assets/d46c5ae7-01a8-4887-9452-11b98327d6bf"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added an Explorer workspace with animated navigation and tab controls.
* Added a home tab and a new-tab menu for creating notebooks, with chat
creation shown as unavailable.
* Added support for notebook tabs in the editor and Explorer navigation.
* Added flexible tab layouts with custom tab content, optional new-tab
actions, and configurable collapse controls.
* Improved editor navigation to recognize Explorer workspaces alongside
existing table and SQL editors.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 15:39:26 +07:00
Guilherme Souza a18ee934cd docs(auth): handle incoming deep link URLs on Swift (#48774)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update.

## What is the current behavior?

The Swift tab in the [Native Mobile Deep Linking
guide](https://supabase.com/docs/guides/auth/native-mobile-deep-linking?platform=swift)
only covers registering a custom URL scheme (Info.plist config). Unlike
the React Native, Flutter, and Kotlin tabs, it never shows the runtime
code that actually consumes the incoming URL and completes the sign-in,
so a Swift developer following the guide is left without a working
implementation.

Linear:
[SDK-83](https://linear.app/supabase/issue/SDK-83/swift-improve-docs-on-how-to-handle-deep-link-url)

## What is the new behavior?

Added a "Handling the incoming URL" section to the Swift tab with:
- SwiftUI: `onOpenURL` calling `supabase.auth.handle(url)`
- UIKit app delegate lifecycle:
`application(_:didFinishLaunchingWithOptions:)` and
`application(_:open:options:)`
- UIKit scene delegate lifecycle: `scene(_:openURLContexts:)`
- A note pointing to `session(from:)` for callers that need the returned
`Session` or custom error handling

`handle(url)` and its usage patterns match the current `supabase-swift`
reference spec (`supabase_swift_v2.yml`) and source.

Also added `UIKit` to the docs spelling allowlist
(`supa-mdx-lint/Rule003Spelling.toml`) since it isn't in the dictionary.

## Additional context

`pnpm lint:mdx` passes on the changed file. `pnpm build:guides-markdown`
fails, but on a pre-existing unrelated issue (missing generated
`database-advisors.json`), not on this change.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added Swift guidance for handling authentication deep links in SwiftUI
and UIKit apps.
* Documented deep-link behavior during cold launches and scene-based URL
delivery.
* Clarified when to use `handle(_:)` and `session(from:)`, including
error-handling considerations.
* Updated the SwiftUI tutorial to pass authentication URLs directly to
the recommended handler.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 08:37:47 +00:00
Joshen Lim a7671019a8 Scaffold the explorer layout (#48740)
## Context

Resolves FE-4074

Just adds scaffolding for the explorer UI - no data fetching yet.
Initializes the page + side nav, based off Saxon's POC in
`poc/explorer-prototype`

<img width="1389" height="500" alt="image"
src="https://github.com/user-attachments/assets/8f293992-97d9-403e-91d6-2e104cd20eb5"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## New Features
- Added a project Explorer page accessible from
`/project/:ref/explorer`.
- Added navigation for browsing notebooks and chats.
- Added search fields, back navigation, animated transitions, and empty
states for Explorer sections.
- Added a conditional Explorer link to the SQL Editor menu when enabled.

## Documentation
- Marked the Explorer route migration as complete in the migration
checklist.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 12:11:35 +07:00
shaziya e0cc680653 feat(www): update Partner Day at Select 2026 go page copy (#48778)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content update (marketing copy) for the `www` app.

## What is the current behavior?

`/go/select-2026/partner-day` copy is a couple of revisions behind the
latest Notion draft (see #48771 and #48773 for prior rounds).

## What is the new behavior?

Updates the page copy to match the newest draft.

## Additional context

- Verified locally in the browser against the Notion copy doc,
word-for-word.
- `prettier --check` passes on the changed file.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Content Updates**
* Clarified Partner Day event details, including the day-before-Select
note.
  * Improved venue information messaging.
* Updated the RSVP question to reference Select on October 2 and the
Partner Day invitation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 01:08:56 +00:00
Guilherme Souza d61d3533f2 docs: fix broken Swift example in joins-and-nesting guide (#48775)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs fix.

## What is the current behavior?

Fixes
[SDK-958](https://linear.app/supabase/issue/SDK-958/docs-incomplete-documentation),
reported via the docs feedback widget on
[joins-and-nesting](https://supabase.com/docs/guides/database/joins-and-nesting).

In the "Specifying the `ON` clause for joins with multiple foreign keys"
section, the Swift example was broken relative to the other language
tabs (JS, Dart, Kotlin, Python, C#):

- The query string aliased the second embed as `scans: scan_id_end`,
which isn't valid PostgREST embed syntax (should be
`end_scan:scans!scan_id_end`).
- The `Shift` struct only declared a single `scans: [Scan]` property
with no `CodingKeys` entry for `start_scan` or `end_scan` — so it never
actually decoded either aliased relation, which is why the reporter
couldn't tell where `start_scan` was supposed to come from.

## What is the new behavior?

- Query now aliases both relations consistently:
`start_scan:scans!scan_id_start (...)` and `end_scan:scans!scan_id_end
(...)`, matching the other language examples.
- `Shift` struct now declares `startScan: Scan` and `endScan: Scan`,
mapped via `CodingKeys` to `start_scan` and `end_scan`.

## Additional context

Docs-only change to a code sample inside
`apps/docs/content/guides/database/joins-and-nesting.mdx`. Verified with
`prettier --check` (mdx lint tool failed locally due to an unrelated
missing native module, `node-pty`).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the Swift join example to represent separate start and end
scan relationships.
* Revised response field selections and coding keys to match the updated
relationship names.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 21:50:31 -03:00
Danny WhiteandJoshen Lim 6b1fc3d11d recover failed Vercel deploy connections (#48474)
## What kind of change does this PR introduce?

Bug fix.

## What is the current behavior?

A failed Vercel connection after project creation is only logged,
leaving the project-creation screen in its loading state.

## What is the new behavior?

The flow preserves the created project and shows the connection error
with retry and open-project actions in the standard project-creation
footer.

Project-creation failures remain ordinary inline form errors. Connection
failures are owned by this flow without a duplicate toast or a no-op
error handler.

| Before | After |
| --- | --- |
| ![Create Vercel Project
Supabase](https://github.com/user-attachments/assets/18dfb6d1-614a-4298-bf28-8399d86c7bca)
| <img width="1024" height="563" alt="Create Vercel Project Supabase"
src="https://github.com/user-attachments/assets/b7d3fdca-d7a0-4b50-9231-3cf7dc371a87"
/> |

## To test

### Before on master

1. Switch to `master`.
2. With local Studio running and while signed in, open an organisation
you can access. Copy its slug from
`http://localhost:8082/org/<YOUR_ORG_SLUG>`.
3. Open
`apps/studio/components/interfaces/ProjectCreation/ProjectCreationForm.tsx`.
4. Find `isSuccessNewProject={isSuccessNewProject}` in the
`ProjectCreationFooter` props and temporarily change it to:
   ```tsx
   isSuccessNewProject={true}
   ```
5. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then
open it:
`http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`.
6. Confirm **Create new project** remains in its loading state and there
is no error, retry action, or route to the created project. This
represents the current stuck state.
7. Revert the temporary edit before switching branches.

### After on this branch

1. Switch to `dnywh/vercel-deploy-recovery`.
2. With local Studio running and while signed in, open an organisation
you can access. Copy its slug from
`http://localhost:8082/org/<YOUR_ORG_SLUG>`.
3. Open
`apps/studio/pages/integrations/vercel/[slug]/deploy-button/new-project.tsx`.
4. Find the conditional beginning with `newProjectRef === undefined`
inside `InterstitialLayout`.
5. Replace that whole conditional with:
   ```tsx
   <VercelConnectionError
     projectRef="abcdefghijklmnopqrst"
     message="Connection request failed"
     onRetry={() => undefined}
   />
   ```
6. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then
open it:
`http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`.
7. Confirm the admonition says **Unable to connect to Vercel** and
**Your Supabase project was still created. Error: Connection request
failed**.
8. Confirm **Open project** and **Retry connection** appear as compact,
right-aligned footer buttons. The retry action is intentionally inert in
this visual-only mock, and no project or Vercel connection is created.
9. Revert the temporary edit.

## Additional context

Follows #48473. The consistency follow-up #48640 is stacked on this PR.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added inline error messages to project creation forms for integration,
API, and validation failures.
- Added clear Vercel connection states, including waiting, connecting,
success, and error screens.
  - Added retry actions and links to open successfully created projects.

- **Bug Fixes**
- Improved error handling so Vercel connection issues remain visible in
context instead of appearing only as notifications.

- **Tests**
- Added coverage for partial-success messaging, project links, and retry
behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-06 10:49:50 +10:00
Matt Smiley 801ef21ce6 Add Matt Smiley to humans.txt (#48729)
Add myself (Matt Smiley) to humans.txt as part of onboarding to
Supabase.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update to add new joiner (me)

## What is the current behavior?

NA

## What is the new behavior?

Adds new team member

## Additional context

Part of my onboarding process


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Matt Smiley to the team member list in the project credits.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 16:37:21 -07:00
shaziya 8d1ff7d38f feat(www): update Partner Day at Select 2026 go page copy (#48773)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content update (marketing copy) for the `www` app.

## What is the current behavior?

`/go/select-2026/partner-day` copy is one revision behind the latest
draft (see #48771 for the prior round).

## What is the new behavior?

Updates the page copy to match the newest Notion draft.

## Additional context

- Verified locally in the browser against the Notion copy doc,
word-for-word.
- Verified the RSVP form's "Are you attending Select 2026?" select field
opens, selects, and submits correctly.
- `prettier --check` passes on the changed file.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Content Updates**
- Refined Partner Day event messaging and “What to expect” descriptions.
  - Simplified the hero description by removing timing-specific wording.
- Shortened inaugural-event messaging for clearer, more concise
communication.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 15:54:18 -07:00
shaziya 2736abf4c7 feat(www): update Partner Day at Select 2026 go page copy (#48771)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content update (marketing copy) for the `www` app.

## What is the current behavior?

`/go/select-2026/partner-day` has stale copy from an earlier draft of
the event: a time-boxed agenda table and a "What you'll gain" feature
grid that no longer match the approved messaging.

## What is the new behavior?

Updated copy! :)

## Additional context

- Verified the RSVP form's "Are you attending Select 2026?" select field
opens, selects, and submits correctly, with no React hydration warnings
on a clean `.next` build.
- `pnpm --filter=www exec tsc --noEmit` and `prettier --check` both pass
on the changed file.
- `pnpm build --filter=www` fails locally, but this is pre-existing and
unrelated to this change — it requires a `DOCS_GITHUB_APP_PRIVATE_KEY`
secret (for the `docs` app's federated-content prebuild step) that isn't
available in this local environment. Confirmed the identical failure
occurs on `master` with no changes applied.
2026-08-05 15:10:51 -07:00
claude[bot]andClaude b97ad08be5 docs: updating Edge Functions error codes (#48767)
<!-- ccr-slack-attribution -->
_Requested by **Kalleby Santos** · [Slack
thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785949561216739?thread_ts=1785949561.216739&cid=C02KMRX22NR)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update. Adds two missing entries to the Edge Functions **Error
codes** page (`apps/docs/content/guides/functions/error-codes.mdx`).

Refs https://github.com/supabase/supabase/issues/47739

## What is the current behavior?

Neither `NOT_FOUND_FUNCTION_BLOB` nor `LOAD_FUNCTION_UNBUNDLING_ERROR`
appears on the Error codes page. Someone who gets a 404 with
`sb-error-code: NOT_FOUND_FUNCTION_BLOB` and searches the page finds
nothing — and because the response body is the same `Requested function
was not found` string that generic `NOT_FOUND` returns, the existing
`NOT_FOUND` entry reads like it covers the case when it doesn't.

## What is the new behavior?

Both codes are documented under `## Server Errors` with a cause and a
remedy, in the page's existing `**Cause:**` / `**Solution:**` shape.

- `NOT_FOUND_FUNCTION_BLOB` goes directly after `### NOT_FOUND`, since
readers hitting it will scan for `NOT_FOUND` first. The cause explains
the metadata/bundle version mismatch (concurrent or batched deploys
double-incrementing the metadata version), notes that the message is
identical to `NOT_FOUND` so the `sb-error-code` header is the
distinguisher, and links the existing [Edge Function 404 error
response](https://supabase.com/docs/guides/troubleshooting/edge-function-404-error-response)
troubleshooting guide. Solution: redeploy with the latest CLI, avoid
concurrent deploys of the same function, contact support to re-sync
metadata if it persists.
- `LOAD_FUNCTION_UNBUNDLING_ERROR` goes at the end, keeping the
`LOAD_FUNCTION_*` cluster together. Cause: the bundle was fetched but
decompression/parsing failed, which points at a corrupt or
partially-written bundle. Solution: redeploy, contact support if it
persists.

## Additional context

Both codes are real and currently emitted by
`supabase/edge-functions-ingress` (`main`):

- `NOT_FOUND_FUNCTION_BLOB` — 404, declared at `src/main/errors.ts:29`,
emitted at `src/main/cache.ts:180`
- `LOAD_FUNCTION_UNBUNDLING_ERROR` — 503, declared at
`src/main/errors.ts:27`, emitted at `src/main/cache.ts:226`

Both were introduced by supabase/edge-functions-ingress#464.

### Notes for reviewer

- **Scope.** The comment on #47739 asked only for
`NOT_FOUND_FUNCTION_BLOB`. `LOAD_FUNCTION_UNBUNDLING_ERROR` is included
because it shipped in the same ingress PR and is equally undocumented —
happy to drop it if you'd rather keep this PR to exactly what was
requested.
- **No HTTP statuses in the copy.** The 404/503 above are deliberately
left out of the page text, because the Error codes page states no HTTP
status anywhere for any code. Adding them here would be a format
departure. Easy to add if you'd prefer to start including them.
- **Message mismatch, not fixed here.**
`apps/docs/content/troubleshooting/edge-function-404-error-response.mdx`
declares `message = "Function deployment bundle not found"` for
`NOT_FOUND_FUNCTION_BLOB`, but the runtime actually emits `"Requested
function was not found"` (`cache.ts:181`), which matches the response
pasted in #47739. Left untouched in this PR — flagging it for a
follow-up.

### Checks run

- `prettier --check` on the changed file: passes.
- `supa-mdx-lint` (v0.3.2) on the changed file: no new findings. The one
remaining warning (`error-codes.mdx:11` — "Use 'view and resolve errors'
instead of 'handle errors'") is pre-existing on `master` and untouched
here.
- The `{/* supa-mdx-lint-disable Rule001HeadingCase */}` pragma at line
8 sits above both new H3s, so the uppercase headings pass.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01Qw5D2wdScBN5TWuA2FgnDW)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-05 14:05:03 -06:00
Matt Rossman 5049f3eb81 docs: supabase evals note in AI tools page (#48663)
Following announcement
https://supabase.com/blog/introducing-supabase-evals

Adds an admonition to the [AI
Tools](https://supabase.com/docs/guides/ai-tools) overview calling out
the recently launched [Supabase
Evals](https://supabase.com/blog/introducing-supabase-evals) project to
demonstrate performance of (some of) the tools shown.

Preview:
https://docs-git-mattrossman-ai-969-link-to-evals-from-47d719-supabase.vercel.app/docs/guides/ai-tools

<img width="3600" height="1606" alt="CleanShot 2026-08-03 at 15 13
06@2x"
src="https://github.com/user-attachments/assets/8ea23f6c-fde0-4b04-bed1-035941570ac1"
/>

If preferred, we can move it below the fold, I just figure it's good for
visibility on the recent launch and it helps sell the "why" for using
these tools.

Closes AI-969


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Documentation**
* Added a link and note about Supabase Evals, an open-source benchmark
for AI coding agents.
* **Chores**
  * Updated spelling checks to recognize “eval” in any capitalization.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 14:47:46 -04:00
08867f94ff docs: lead self-hosting overview with what/why/CTA, restructure secondary content (#48415)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs restructure of the self-hosting overview: short fit intro, Get
started / community listings above the fold, parallel h2 sections for
how self-hosting differs (including local development),
responsibilities, and telemetry, plus a streamlined support listing with
better card content.

Closes DOCS-1251.

## What is the current behavior?

- Linear item: Explore two PR approaches for the self-hosting page
- The self-hosting overview page (`/guides/self-hosting`) is the top
search hit for "supabase self-hosting," but reads as a wall of text:
three full prose/bullet sections (differs / responsibilities /
telemetry) come before the getting-started CTA, which is buried as one
small card partway down the page.

## What is the new behavior?

- Short fit intro; `self-hosting-get-started` and
`self-hosting-community` listings sit directly under the intro.
- Top-level h2s for how self-hosting differs, responsibilities,
telemetry, and support (no "More about self-hosting" wrapper).
- Under differs: rewritten single-project + platform-gap copy, plus `###
Not the same as local development` (CLI stack is not a production
self-host; points to Docker / community options).
- Telemetry clarifies CLI local-dev telemetry vs Docker Compose (no
phone-home).
- Merged support into a single `self-hosting-support` listing;
Enterprise subsection unchanged.
- Minor a11y: `aria-hidden` on GlassPanel decorative icon background.

## Additional context

- Worktree:
`~/GitHub/supabase/supabase-worktrees/nikrichers/docs-1251-self-hosting-inform`
- Review: removed the "More about self-hosting" grouping after feedback
that it undersold differs / responsibilities.
- Companion prototype PR 48416 is closed; this branch is the direction
under review.
- Verification:

| Check | Result |
| ----------------------------------------------- |
------------------------------------------------------------------ |
| `pnpm lint:mdx content/guides/self-hosting.mdx` | Pass — no
errors/warnings on this file |
| Vercel docs preview | Pass — full-page after screenshot captured from
the preview deploy |

### Proof: intro and get-started above the fold; parallel h2s for
differs, responsibilities, and telemetry

**Verified:** `pnpm lint:mdx content/guides/self-hosting.mdx` (pass) ·
Vercel docs preview (pass)

### Before & After

| [Before (production)](https://supabase.com/docs/guides/self-hosting) |
[After (PR
preview)](https://docs-git-nikrichers-docs-1251-self-hosting-inform-supabase.vercel.app/docs/guides/self-hosting)
|
|
------------------------------------------------------------------------------------------------------------------------------------------------
|
----------------------------------------------------------------------------------------------------------------------------------------------
|
|
![Before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48415/self-hosting-before-23d8ce92.png)
|
![After](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48415/self-hosting-after-96d27909.png)
|

### Test plan

- [ ] Visit the preview link and confirm the page opens with intro above
the Get started listings
- [ ] Confirm parallel h2s for differs / responsibilities / telemetry /
support (no "More about self-hosting")
- [ ] Confirm "Not the same as local development" distinguishes the CLI
stack from self-hosting
- [ ] Confirm Support and community is one card grid
- [ ] Check mobile width — layout should still be usable
- [ ] Confirm `/guides/self-hosting/docker` link still works

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Reorganized the self-hosting guide with clearer getting-started
resources and community links.
- Added dedicated guidance for local development, managed Supabase,
telemetry, and self-hosting responsibilities.
- Consolidated support resources into one section covering discussions,
issues, chat, Reddit, and sharing experiences.
- **Accessibility**
- Marked decorative icon backgrounds as hidden from assistive
technologies.
  <!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
Co-authored-by: Claude <noreply@anthropic.com>
2026-08-05 10:57:09 -07:00
Aaron ByrneandClaude 47b8660d8d docs(troubleshooting): troubleshooting guide so users can amend their failed migrations (#48257)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Troubleshooting guide

## What is the current behavior?

NA
## What is the new behavior?

Troubleshooting guide
## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a new troubleshooting page: “Troubleshooting MIGRATIONS_FAILED:
missing tables or an incomplete schema on your branch” for Preview
Branch creation.
* Explained why replayed `main` migration history can fail when it no
longer matches the branch’s live schema.
* Included a step-by-step workflow to diagnose the failing migration via
logs, repair migration status, and then recreate or rebase the branch to
verify.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-05 18:12:20 +01:00
Jordi Enric a28214c236 feat(studio): add ClickHouse OTEL SQL for the Auth report's v2 metrics (#48750)
## Problem

Part of DEBUG-73 (migrate reports queries to the OTEL/ClickHouse
endpoint).

The Auth report's v2 metrics (ActiveUsers, SignInAttempts,
PasswordResetRequests, TotalSignUps, sign-in/sign-up processing time,
error breakdowns) currently only query the BigQuery-backed logs.all
endpoint.

## Fix

Adds `AUTH_REPORT_SQL_OTEL`, a ClickHouse-dialect mirror of the existing
`AUTH_REPORT_SQL`, covering all 10 metrics. Threads a `useOtel`
parameter through `fetchLogs` and the three report config creators
(`createUsageReportConfig`, `createErrorsReportConfig`,
`createLatencyReportConfig`), defaulting to `false` everywhere.

This PR is inert on its own: nothing yet passes `useOtel: true`, so it
changes no runtime behavior. The follow-up PR (stacked on this one)
wires the `otelReports` feature flag through the Auth report page to
actually select the OTEL SQL.

Also includes: one dataProvider now validates its raw rows with a Zod
schema instead of casting to `any`, and removal of a few functions in
this file that had zero callers (`AUTH_ERROR_CODE_VALUES`,
`createAuthReportConfig`, an exact duplicate of a status-code color map,
an unused hook).

## How to test

- Unit: `cd apps/studio && npx vitest run
data/reports/v2/auth.config.otel.test.ts`
- No manual testing needed for this PR alone since it changes no runtime
behavior (useOtel defaults to false, unwired). The follow-up PR covers
manual testing of the actual flag-gated behavior.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added OpenTelemetry-backed authentication reports.
* Authentication reports now include usage, errors, latency, sign-ins,
sign-ups, and edge-log metrics.
  * Added filtering by provider, status code, action, and time range.
  * Added selectable telemetry sources for retrieving report logs.
* **Bug Fixes**
  * Improved validation of authentication error codes.
* Improved handling of missing report data with consistent empty
results.
  * Improved report formatting for more consistent attribute display.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 18:25:41 +02:00
Abhishek Tripathi d101d6f3de docs: document NOT_FOUND_FUNCTION_BLOB Edge Function error (#48411)
This PR addresses the documentation portion of #47739.

## What the issue means

`NOT_FOUND_FUNCTION_BLOB` means the runtime cannot find the deployed
bundle for an Edge Function. This differs from the existing `NOT_FOUND`
error, which normally indicates that the function name in the request
URL is not recognized.

The dashboard status alone may not reveal this failure because the
function can still appear as `ACTIVE`.

## Changes

- Documented `NOT_FOUND_FUNCTION_BLOB` as an HTTP 404 error.
- Explained how it differs from `NOT_FOUND`.
- Added the command for redeploying one affected function.
- Added the command for redeploying all functions when several are
affected.
- Added guidance to retry the request and contact Support if
redeployment does not resolve the problem.

## Files changed

-
`apps/docs/content/troubleshooting/edge-function-404-error-response.mdx`

## Validation

- The change uses the troubleshooting page's existing TOML frontmatter
and MDX conventions.
- `git diff --check` passes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Expanded troubleshooting guidance for Edge Function 404 responses.
* Added coverage of the `NOT_FOUND_FUNCTION_BLOB` error, including
example responses and clarification of how it differs from `NOT_FOUND`.
* Updated redeployment instructions with options for deploying a single
function or all functions.
  * Refined retry and support guidance.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 17:11:00 +01:00
Charis 8831e15fc3 Revert "refactor(studio): static tab kind registry and tab id codec (PR 1/9)" (#48762)
Reverts supabase/supabase#48718
2026-08-05 16:03:16 +00:00
Miranda LimonczenkoandClaude Opus 5 d45e0cd3d5 fix(docs ci): stop Docs E2E blocking pull requests it shouldn't (#48726)
Supersedes #48725, which GitHub closed when its head branch was renamed.
Same commits, same diff.

Fixes
[DOCS-1270](https://linear.app/supabase/issue/DOCS-1270/fail-the-e2e-pipeline-if-the-docs-preview-never-loads).

`Docs E2E` is a required check on `master`, so anything that turns it
red blocks a merge. It had three ways of going red that had nothing to
do with whether the author's docs were correct.

## Problem

**1. Every troubleshooting page could fail, with nothing actionable.**
Troubleshooting entries were selected by `article.prose`. That class is
not unique — `apps/docs/app/not-found.tsx` renders `<article
className="prose …">` too — and nothing guaranteed it matched the
entry's article at all. When it missed, the link test failed with `Page
article should be present` and the a11y test failed inside axe with `No
elements found for include in page Context` plus a stack trace. Neither
tells the author what to do.

This is what DOCS-1270 actually was. The ticket describes tests running
"against a preview build that was never created", but the [failing
run](https://github.com/supabase/supabase/actions/runs/30949924515/job/92132543658)
for #48719 shows the preview resolved fine and `response.ok()` passed —
it broke at the article assertion. **Blocked:** anyone adding or editing
a troubleshooting entry.

**2. Fork pull requests failed for being forks.** Fork runs get no
`VERCEL_TOKEN`, so no preview URL resolves, and the base-URL step fell
back to `https://supabase.com`. The page paths under test can include
pages the pull request *adds*, which do not exist on production, so they
404. **Blocked:** every external contributor adding a docs page,
unconditionally, with no action available to them.

**3. A Vercel problem failed the docs check.**
`waitForVercelDocsPreview.js` throws when Vercel reports a failed
deployment, omits a `target_url`, or does not post a status within 900s.
The step had no `continue-on-error`, so any of those turned `Docs E2E`
red. **Blocked:** any author whose pull request coincided with a Vercel
incident. This is live right now — two Vercel checks on this very pull
request are failing with "unable to fetch required git information", a
git-integration auth error that happens before any build runs.

## Solution

**1. Select on a stable, purpose-named attribute.** Add
`id="sb-docs-troubleshooting-main-article"` on the troubleshooting
article, mirroring `#sb-docs-guide-main-article` on guides, and select
on that instead of the class. Per review feedback, a plain id doesn't
say it's a test hook, so both articles also get `data-testid` with the
same value — matching the convention `apps/studio` already uses with
Playwright's `getByTestId` — and the e2e selectors target that attribute
instead. Guides keep their `id` — `GuidesMdx.client.tsx` and
`GuidesSidebar.tsx` both query it directly for the table of contents and
the "copy article" fallback — and gain `data-testid` alongside it.

**2 and 3. Resolve a preview or skip — never substitute production,
never fail on Vercel.** The production fallback is gone.
`continue-on-error: true` on the preview wait means a Vercel failure
resolves no URL instead of failing the job, which lands in the same path
as a fork: `should_test=false`, so Playwright is skipped and the check
passes. Both cases emit a `::warning::` and a job summary with the exact
`gh workflow run` command to test the preview by hand, and manual runs
against a non-production base URL now send the protection bypass so that
command actually works.

Skipping does not let a broken preview through: `Vercel – docs` is
itself a required check on `master`, so a genuine preview failure still
blocks the merge — via the check that describes the real problem.


## Manual test

**1. The selector matches the markup, and it needs this pull request's
preview.** `data-testid` isn't deployed anywhere yet — not on
production, not on any other branch — so this is the one claim in this
PR that production cannot confirm. Verified directly against this
branch's own Vercel preview:

```bash
curl -s https://docs-git-docs-e2e-stop-false-blocks-supabase.vercel.app/docs/guides/database/overview \
  | grep -o 'data-testid="[^"]*"'
curl -s https://docs-git-docs-e2e-stop-false-blocks-supabase.vercel.app/docs/guides/troubleshooting/42501--permission-denied-for-table-httprequestqueue-KnozmQ \
  | grep -o 'data-testid="[^"]*"'
```

Expect `data-testid="sb-docs-guide-main-article"` and
`data-testid="sb-docs-troubleshooting-main-article"` respectively. Then
run the suite against that same preview — expect all page/link/a11y
checks to pass:

```bash
PLAYWRIGHT_BASE_URL=https://docs-git-docs-e2e-stop-false-blocks-supabase.vercel.app \
DOCS_E2E_PAGE_PATHS=/docs/guides/database/overview,/docs/guides/troubleshooting/42501--permission-denied-for-table-httprequestqueue-KnozmQ \
pnpm -C e2e/docs exec playwright test --reporter=list
```

Running the same command with `PLAYWRIGHT_BASE_URL=https://supabase.com`
fails both pages right now — expected until this merges, not a
regression. Once merged, exercise it through the real pipeline:

```bash
gh workflow run docs-e2e.yml --ref docs-e2e/stop-false-blocks \
  -f base_url=<preview-url> \
  -f page_paths=/docs/guides/troubleshooting/42501--permission-denied-for-table-httprequestqueue-KnozmQ
```

**2. No preview means skip, not a run against production.** Exercise the
base-URL step's three paths from the repository root:

```bash
export GITHUB_OUTPUT=$(mktemp) GITHUB_STEP_SUMMARY=$(mktemp) PAGE_PATHS=/docs/guides/a
script=$(python3 -c "import yaml;print([s for s in yaml.safe_load(open('.github/workflows/docs-e2e.yml'))['jobs']['e2e']['steps'] if s.get('name')=='Resolve base URL'][0]['run'])")
for c in "workflow_dispatch|https://supabase.com|" "pull_request||https://docs-abc.vercel.app" "pull_request||"; do
  IFS='|' read -r ev url dep <<< "$c"
  : > "$GITHUB_OUTPUT"
  EVENT_NAME="$ev" BASE_URL_INPUT="${url:-https://supabase.com}" DEPLOYMENT_URL="$dep" bash -c "$script" >/dev/null 2>&1
  echo "$ev deployment=[${dep:-none}] -> $(tr '\n' ' ' < "$GITHUB_OUTPUT")"
done
tail -4 "$GITHUB_STEP_SUMMARY"
```

Expected:

```
workflow_dispatch deployment=[none] -> url=https://supabase.com use_bypass=false should_test=true
pull_request deployment=[https://docs-abc.vercel.app] -> url=https://docs-abc.vercel.app use_bypass=true should_test=true
pull_request deployment=[none] -> url= use_bypass=false should_test=false
```

followed by a runnable `gh workflow run docs-e2e.yml` command in the job
summary. The third line covers both the fork case and the Vercel-failure
case: no base URL, no test, no block.

**3. A Vercel failure no longer fails the job.** `continue-on-error:
true` on the wait step is what routes a throw into that third line:

```bash
python3 -c "
import yaml
s=[x for x in yaml.safe_load(open('.github/workflows/docs-e2e.yml'))['jobs']['e2e']['steps'] if x.get('name')=='Wait for Vercel docs preview'][0]
print('continue-on-error:', s.get('continue-on-error'))
for n in ('Install dependencies','Install Playwright Chromium','Run docs E2E'):
    print(n, '->', [x for x in yaml.safe_load(open('.github/workflows/docs-e2e.yml'))['jobs']['e2e']['steps'] if x.get('name')==n][0]['if'])
"
```

Expect `continue-on-error: True` and all three run steps gated on
`steps.base-url.outputs.should_test == 'true'`.

**Note on this pull request's own check.** The scope resolver only maps
`apps/docs/content/**` to pages, and this pull request changes none, so
`Docs E2E` resolves zero pages and skips — which is correct, and why the
dispatch above is the real test.

🤖 Generated with [Claude Code](https://claude.com/claude-code)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved documentation preview checks so unavailable or delayed
previews no longer cause unnecessary workflow failures.
* Added clearer handling for manual documentation checks and missing
preview deployments.

* **Tests**
* Improved end-to-end documentation testing reliability across preview
and production environments.
* Added stable targeting for the troubleshooting article to reduce test
failures caused by page structure changes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-05 15:23:26 +00:00
Jordi Enric aed332b663 feat: migrate Edge Functions report to ClickHouse OTEL logs (#48756)
## Problem

The Edge Functions report (`observability/edge-functions`) only queries
BigQuery. As part of the broader Reports→ClickHouse OTEL migration
(DEBUG-73), we need each report migrated one at a time behind the
`otelReports` flag.

## Fix

Adds a ClickHouse OTEL SQL variant (`METRIC_SQL_OTEL`) for the 4 Edge
Functions metrics (TotalInvocations, ExecutionStatusCodes,
InvocationsByRegion, ExecutionTime), querying the unified `logs` table
filtered to `source = 'function_edge_logs'`, with fields read from
`log_attributes` (`function_id`, `response.status_code`,
`response.headers.x_sb_edge_region`, `execution_time_ms`) — the same
mapping already used by `edge-functions-last-hour-stats-query.ts`.

`edgeFunctionReports()` now takes a `useOtel` flag that picks between
the BQ and OTEL query sets and forwards it to `fetchLogs`. The page
wires this up via `useFlag('otelReports')`, matching the pattern used
for the Auth report. No behavior change while the flag is off — report
still fetches from BigQuery.

Also removed two pieces of dead code spotted in `report.utils.ts` while
touching it: the unused `useEdgeFnIdToName` hook and a
`STATUS_CODE_COLORS` map that was an exact duplicate of
`REPORT_STATUS_CODE_COLORS` (the one actually imported elsewhere).

This PR is standalone — no dependency on the in-flight Auth report OTEL
stack.

## How to test

- `pnpm vitest run data/reports/v2/edge-functions.config.otel.test.ts` —
9 new tests covering the OTEL SQL shape (single logs table,
unix-microsecond timestamp bucketing, field mapping, filters).
- `pnpm vitest run data/reports` and `pnpm vitest run
data/edge-functions components/interfaces/Reports` — existing suites (46
+ 54 tests) still pass, confirming no regression to the BQ path.
- Manually: with `otelReports` flag enabled, visit a project's Edge
Functions observability report and confirm charts render from the
ClickHouse endpoint.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added OpenTelemetry support for Edge Functions observability metrics,
including invocations, status codes, regional activity, and execution
time.
* Reports can now dynamically use either the standard or OpenTelemetry
logs source.

* **Bug Fixes**
* Improved filtering and timestamp handling for OpenTelemetry-based Edge
Functions metrics.
* Added coverage for status, execution time, function, and region
filters.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 17:13:34 +02:00
Etienne Stalmans 55095dcd00 chore: highlight totp app friendly name (#48755)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

UI update

## What is the current behavior?

We only show the alternative factor's name, if one exists.

## What is the new behavior?

When presenting user with the MFA screen, make the MFA factor's
friendly_name appear.

## Additional context

Before:

<img width="456" height="371" alt="Screenshot 2026-08-05 at 15 41 07"
src="https://github.com/user-attachments/assets/7d506641-6a9e-49fe-8c40-98c1eef4b384"
/>


After:
<img width="459" height="394" alt="Screenshot 2026-08-05 at 15 38 27"
src="https://github.com/user-attachments/assets/034312ba-691e-4f56-b4e3-a82df2a17273"
/>
<img width="468" height="434" alt="Screenshot 2026-08-05 at 15 37 43"
src="https://github.com/user-attachments/assets/4c585eae-b8e2-4f93-8210-2c8ac7c20278"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved multi-factor authentication prompts with clearer formatting
and more consistent factor labels.
* Ensured the primary code label appears whenever a verification factor
is selected.
* Added a fallback label for authentication factors without a display
name.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 22:07:22 +07:00
Charis ffd6d6636d refactor(studio): static tab kind registry and tab id codec (PR 1/9) (#48718)
## Summary

First PR in the tab/snippet decoupling stack. Purely additive: no
existing call sites change behavior except the `EntityTypeIcon` rewire,
which preserves its API exactly.

- **`state/tabs/kinds.ts`** — static `TAB_KINDS` descriptor table
(`TabKind`, `TabSurface`, `surfaceOf`, `kindsOnSurface`, `isTabKind`).
Leaf-safe: its only reference to the domain `Tab` type is a type-only
import, so it stays importable at module scope (needed later for the
valtio store and the persistence migration reader) without creating a
runtime cycle.
- **`state/tabs/kinds.icons.tsx`** — per-kind icon leaf module (`ui` +
`lucide-react` + `TabKind` type only), plus the preserved
`LogsSnippetIcon`.
- **`state/tabs/tab-id.ts`** — `createTabId` / `parseTabId` /
`toUrlSegment` / `parseUrlSegment(segment, surface)` codec.
`parseUrlSegment` is surface-scoped: a bare segment only resolves to a
kind when the surface has exactly one bare kind (true for `sql`). The
table surface has five bare kinds (`r`/`v`/`m`/`f`/`p`) with no URL
disambiguator between them, matching `/editor/[id]`, which learns kind
from the fetched entity rather than the URL — so a bare table segment
correctly resolves to nothing.
- **`components/ui/EntityTypeIcon.tsx`** — rewired to a thin wrapper
delegating to `kinds.icons.tsx`, preserving its exact prop API (`type`,
`size`, `strokeWidth`, `isActive`, `sqlSource`) for all existing
consumers.
- **`state/tabs/tab-id.test.ts`** — codec round-trips per kind,
bare-vs-prefixed URL segments, the `templates`/`examples`/`new`
sentinels, and surface scoping (including the table-surface ambiguity
above).

Full plan: `apps/studio/TABS_DECOUPLING_PLAN.md` (not included in this
PR).

## Test plan

- [x] `pnpm typecheck`
- [x] `pnpm lint --filter=studio` (0 errors)
- [x] `pnpm --filter studio run lint:ratchet` (warning counts did not
increase)
- [x] `pnpm test:studio` (full suite green, including 50 new/updated
tests in `state/tabs/`)
- [x] `pnpm format` (no-op)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added consistent icons and metadata for SQL, notebook, chat, table,
view, and related tab types.
* Added support for creating, parsing, and converting tab identifiers to
URL segments.
  * Improved handling of tab types across SQL and table surfaces.

* **Bug Fixes**
* Invalid, empty, or ambiguous tab identifiers and URL segments are now
rejected.

* **Tests**
* Added coverage for tab identifiers, URL conversion, supported tab
types, and edge cases.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 10:39:58 -04:00
AnaandAna 69b1f06152 docs(blog): add Enhancements for Postgres Changes launch post (#48711)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Adds the launch blog post for Enhancements for Postgres Changes, dated
2026-08-05
- Adds the social card and listing thumbnail for the post

## What is the current behavior?

N/A. New post.

## What is the new behavior?

- New post at `/blog/postgres-changes-filters-and-column-selection`
covering AND filter composition, the expanded filter operator set, and
column selection on Postgres Changes subscriptions
- Authored by Filipe Cabaço, using the existing `filipe` author id, so
no change to `apps/www/lib/authors.json`

## Additional context

**Please do not merge before 7:00 am PT on 2026-08-05.**

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation

* Added a product blog post covering enhanced Postgres Changes
filtering, including comma-separated AND filters across multiple
columns.
* Documented additional filter operators and the new filter builder.
* Explained optional column selection for event payloads, permissions
and row-level security behavior, DELETE limitations, unsupported
options, client-version requirements, usage examples, and upgrade
guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ana <ana1337x@users.noreply.github.com>
2026-08-05 10:24:44 -04:00
1f0fb64ce9 docs: CLI 'Transport error' caused by antivirus/proxy TLS interception (#48719)
## Summary
- Adds a troubleshooting entry for the Supabase CLI's generic
`HttpClientError: Transport error` when a Management API call (e.g.
`projects list`, `link`) fails.
- Root cause documented: antivirus software or corporate SSL-inspecting
proxies (e.g. Norton Safe Web/Web & Mail Shield, Zscaler, Netskope)
substituting their own TLS certificate, which the CLI's HTTP client
rejects and reports as a generic transport error rather than a
certificate error.
- Includes a vendor-agnostic diagnostic method (compare `curl`/browser
vs. CLI behavior, check the served certificate's Issuer field) plus the
specific Norton fix confirmed via a support ticket (disabling Smart
Firewall alone does not stop the interception; Safe Web/Web & Mail
Shield does).

## Test plan
- [ ] `pnpm --filter docs lint:mdx` passes in CI
- [ ] Frontmatter renders correctly on the troubleshooting page

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added troubleshooting guidance for Supabase CLI transport errors
caused by antivirus software or corporate TLS inspection.
* Included diagnostic steps, common error messages, and resolution
guidance for Norton 360 and SSL-inspecting proxies.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Rodrigo Mansueli <rodrigo@mansueli.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-05 09:09:13 -04:00
Andrey A. af384e136f chore(self-hosted): update tags in docker guide (#48739) 2026-08-05 14:19:11 +02:00
9952d6f10f [FE-4067] fix(studio): re-allow all regions in local project creation (#48704)
Local dev stacks can run in any of the three supported regions (e.g.
Bobbie's is in `ap-southeast-1`), but enabling High Availability on the
project creation form pinned local to Frankfurt only. This unrestricts
local so all three regions are selectable again.

**Changed:**
- `getHighAvailabilityRegionCode()` returns `undefined` for `local`
(same as prod), so `filterHighAvailabilityRegions()` no longer collapses
the list — staging stays pinned to `us-east-1`
- The three-region warning in `RegionSelector` now adds a local-only
recommendation: "Use Central EU (Frankfurt) unless you're on a personal
dev stack."
- Updated unit tests, including an `ap-southeast-1` fixture region to
prove pass-through

## To test

- On a local stack, open the new project form and enable High
Availability — the region selector should offer all three regions (East
US, Frankfurt, Southeast Asia) instead of locking to Frankfurt, and the
warning should recommend Frankfurt unless you're on a personal dev stack
- Confirm staging behavior is unchanged (HA still pins to East US)
- `pnpm --filter studio exec vitest run
components/interfaces/ProjectCreation`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Local development projects can now use high-availability regions
beyond Central EU.
* Region filtering and availability messaging now correctly reflect the
active environment, including staging restrictions.

* **User Experience**
* Added guidance recommending Central EU for local projects, unless
using a personal development stack.
* Region selection now provides clearer environment-specific information
when options are limited.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-05 14:51:57 +07:00
Danny White 3c811b9c29 fix(studio): extend SupportForm project waitFor timeout (#48211)
## What kind of change does this PR introduce?

Test flake fix.

## What is the current behavior?

`SupportFormPage` → “submits support request with attachments…” can fail
under CI load:

- expected project selector text `Project 1`
- received `No specific project`

Org is applied first; the project is filled asynchronously via
`onInitialLoad` after org projects fetch. That wait still used the
default ~1s `waitFor`, while every sibling Project 1 assertion already
uses `{ timeout: 5_000 }` (see #45852).

## What is the new behavior?

- Attachments test waits up to 5s for Organization 1 + Project 1
- Same timeout for the org-switch → Project 2 waiter (same pattern)

No production code changes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Improved support form test reliability by allowing additional time for
organization and project selectors to load during asynchronous
interactions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 07:15:20 +00:00
Danny White 9b3e0a9060 show Vercel connection errors inline (#48473)
## What kind of change does this PR introduce?

Bug fix.

## What is the current behavior?

Vercel install and project-link failures use transient toasts.

## What is the new behavior?

Failures remain visible below the relevant action and clear when the
user retries or changes a selection.

The Vercel mutation hooks expose errors without choosing their
presentation. Interstitial callers render them inline, while existing
non-interstitial callers explicitly retain their toasts.

| Before | After |
| --- | --- |
| <img width="1024" height="759" alt="Install Vercel Integration
Supabase"
src="https://github.com/user-attachments/assets/6348cdd2-220a-4ad8-89f9-7fc51de36a3c"
/> | <img width="1024" height="759" alt="Install Vercel Integration
Supabase"
src="https://github.com/user-attachments/assets/ecc50c4e-daab-4f6d-bf86-7282e2aff92c"
/> |

## To test

1. Switch to `dnywh/inline-vercel-errors` (this branch).
2. Open `apps/studio/pages/integrations/vercel/install.tsx`.
3. Find the `actionError` assignment immediately below
`useVercelIntegrationCreateMutation` and replace the whole assignment
with:
   ```tsx
   const actionError = 'Creating Vercel integration failed: Test error'
   ```
4. With local Studio running and while signed in, open
`http://localhost:8082/integrations/vercel/install?code=test&configurationId=test&source=marketplace`
5. Confirm the error remains visible below **Install integration**. No
Vercel installation or real authorisation code is required.
6. Revert the temporary edit.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Bug Fixes

* Improved error handling across Vercel project connection and
installation flows.
* Validation, duplicate-connection, and connection failures now appear
inline in the relevant setup steps.
* Errors clear automatically when the selected project or organization
changes.
* Notifications remain available in supported flows, including new
project creation and side-panel setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 16:06:58 +10:00
claude[bot]andClaude 89a5d03817 docs: add eu-central-2 to Edge Functions regional invocation page (#48721)
<!-- ccr-slack-attribution -->
_Requested by **Kalleby Santos** · [Slack
thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785871243937099?thread_ts=1785871243.937099&cid=C02KMRX22NR)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update — one-line content fix.

## What is the current behavior?

The [Regional
Invocations](https://supabase.com/docs/guides/functions/regional-invocation)
page's "Available regions" section lists every Edge Functions region
**except `eu-central-2`** (AWS Europe, Zurich). The region has been live
in production for a while, but it was never added to the docs. A user
reading this page to pick a region for `x-region` / `FunctionRegion` had
no way to know Zurich was an option — the page reads as an exhaustive
list, so the omission actively implies the region doesn't exist.

Reported by Kalleby Santos (Edge Functions team).

Linear: [FUNC-761 — Add eu-central-2 to regional invocation docs
page](https://linear.app/supabase/issue/FUNC-761/add-eu-central-2-to-regional-invocation-docs-page)

## What is the new behavior?

**Before:** the Europe group listed `eu-central-1`, `eu-west-1`,
`eu-west-2`, `eu-west-3`.

**After:** `eu-central-2` (Zurich) is listed alongside the others, so
the page reflects the regions Edge Functions actually serves.

### How

One line added to
`apps/docs/content/guides/functions/regional-invocation.mdx`, in the
**Europe** group directly after `eu-central-1`, following the list's
existing sort-by-region-code order and the surrounding `` `code` (Short
location) `` label style:

```diff
 **Europe:**

 - `eu-central-1` (Frankfurt)
+- `eu-central-2` (Zurich)
 - `eu-west-1` (Ireland)
 - `eu-west-2` (London)
 - `eu-west-3` (Paris)
```

No other files changed. This page's region list is hand-maintained in
the MDX and is deliberately narrower than the project-creation region
list in `packages/shared-data/regions.ts` (which also includes
`us-east-2` and `eu-north-1`), so no shared constant needed updating and
no other product's region list was touched.

## Additional context

**Verification that `eu-central-2` is a real Edge Functions invocation
region** — confirmed in three independent places:

1. `supabase/platform` → `pulumi/edge-runtime/Pulumi.prod.yaml:533` —
`region: eu-central-2`, with `enabled: true` at `:531`. A fully
provisioned prod region (360–540 always-on tasks), not a placeholder.
Branch `develop`, HEAD `1f44167768f951c0c794313006bc2c9f9758c344`.
2. `supabase/platform` →
`pulumi/edge-runtime-next/stack-config/Pulumi.prod.aws.euc2.yaml:6` —
`aws:region: eu-central-2` under the `Edge-Functions/K8s-Prod`
environment, tagged `product: functions`.
3. `supabase/api-gateway` → `customer-router/wrangler.toml` —
`eu-central-2` is present in the `EDGE_FUNCTIONS_REGIONAL_ORIGINS` map
(`eu-central-2 = "https://eu-central-2.edge-runtime.supabase.green"`).
This is the table that resolves the `x-region` header, so regional
invocation into Zurich is genuinely routable — not just deployed.

**For a reviewer to confirm separately (intentionally not in this
diff):** production infra has 16 enabled Edge Functions regions, so
`us-east-2` (Ohio, `pulumi/edge-runtime/Pulumi.prod.yaml:507`, `enabled:
true`) is *also* missing from this page. It's excluded here because we
don't yet know whether that omission is deliberate; it's being confirmed
with the team and can be a follow-up.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy

---
_Generated by [Claude
Code](https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-04 22:09:37 +01:00
Charis 2165746784 fix(studio): keep SQL editor source menu open when switching sources (#48715)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Selecting Database/Logs in the SQL Editor's query-source dropdown closes
the menu (Radix's default select behavior), so switching to Logs gives
no visible indication that a Time range control just became available
until the dropdown is reopened.

## What is the new behavior?

Selecting a source keeps the dropdown open, so the newly-available
source-specific controls (e.g. Time range for Logs) are immediately
visible.

## Additional context

Fixes FE-4036

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved source switching in the SQL editor so the selection menu
remains open while changing between database and logs sources.
  * Ensured source-specific controls update correctly after switching.

* **Tests**
* Added coverage for source selection, menu behavior, and
source-specific control updates.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-04 20:23:12 +00:00
Charis 5986fecc89 fix(studio): use table + card component in log retention upgrade prompt (#48713)
## Summary
- Refactor the SQL Editor / Logs "Log retention" upgrade-prompt dialog
to use the design system's `Card` + `Table` components instead of a
custom flexbox-div table, matching the pattern in
`apps/design-system/registry/default/example/table-demo.tsx`
- No behavior or data change

Fixes FE-4034

Non-blocking review nit from #48452 (comment:
https://github.com/supabase/supabase/pull/48452#issuecomment-5128918096)

## Test plan
- [x] `pnpm --filter studio typecheck` passes
- [x] `pnpm --filter studio run lint:ratchet` passes (no new warnings)
- [x] Prettier check passes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Updated the upgrade prompt with a more consistent card and table
layout.
  * Preserved existing plan names and log retention details.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-04 16:01:14 -04:00
Charis b9053794a0 fix(studio): add tooltip explaining why Prettify SQL is disabled (#48712)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

In the SQL Editor, the Prettify SQL action (both the "More actions"
dropdown menu item and the toolbar button) is disabled for logs
snippets, but gives no indication why.

## What is the new behavior?

The disabled Prettify menu item now uses `DropdownMenuItemTooltip` and
the disabled Prettify toolbar button uses `ButtonTooltip`, both showing
"Can only prettify SQL queries" while disabled. Addresses review
feedback from #48452 (Linear FE-4038).

## Additional context

Resolves FE-4038

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
  * Updated SQL editor tooltips with clearer, consistent messaging.
* Log-source users now see an explanation when SQL formatting is
unavailable.
  * Regular users continue to see the SQL prettify keyboard shortcut.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-04 18:07:08 +00:00
Guilherme SouzaandClaude Sonnet 5 0bf5ca584d docs: Update Swift/Kotlin postgrest specs and Swift Web3 sign-in (#48291)
## Summary

Cross-referenced recent commits across all 6 SDK repos (supabase-js,
supabase-flutter, supabase-py, supabase-swift, supabase-kt,
supabase-csharp) against `apps/docs/spec/` and
`apps/docs/content/guides/`. Most recent commits were
CI/chore/release/patch-fix noise; the following genuine feature gaps
were found and fixed.

## Changes analyzed

- **supabase-swift**: `dryRun()`, `notIn()`, `maybeSingle()` (PR
supabase/supabase-swift#1114) and `signInWithWeb3()` (PR
supabase/supabase-swift#1138)
- **supabase-kt**: `dryRun()`, `notIn()`, `maybeSingle()` (PR
supabase-community/supabase-kt#1365)

## Documentation updates

- `apps/docs/spec/supabase_swift_v2.yml` — added `notin`, `dry-run`,
`maybe-single` filter/modifier entries and a `sign-in-with-web3` auth
entry (Web3/Ethereum/Solana sign-in was already documented for JS and
Dart, missing for Swift)
- `apps/docs/spec/supabase_kt_v3.yml` — added `notin`, `maybe-single`,
`dry-run` entries
- `apps/docs/spec/common-client-libs-sections.json` — registered nav
entries for the two brand-new cross-SDK ids (`notin`, `dry-run`);
`sign-in-with-web3` was already registered

## Explicitly out of scope

- **Kotlin `custom_claims_allowlist`** (added to
`CustomOAuthProvider`/`CustomProviderBuilder` in supabase-kt) — skipped.
The Kotlin spec has no admin custom-OAuth-provider section documented at
all yet (create/list/get/update/delete), so adding just this one field
would require authoring a whole new, currently-undocumented admin API
section from scratch — too large/risky to guess correctly in this pass.
Flagging for a follow-up.
- Dart's recently-shipped storage features (vector buckets,
analytics/Iceberg buckets, `purgeCache`, `downloadStream`,
`listPaginated`) were checked and are already fully documented in
`supabase_dart_v2.yml`.
- Swift/Kotlin lacking Storage vector-bucket/analytics-bucket docs — out
of scope, those SDKs didn't ship that feature in this commit range
(Dart-only so far).

## Test plan

- [x] `python3 -c "import yaml; yaml.safe_load(open(...))"` — both
edited YAML specs parse cleanly
- [x] `python3 -c "import json; json.load(open(...))"` — nav JSON parses
cleanly
- [ ] Visual check of the rendered reference pages for
`notIn`/`dryRun`/`maybeSingle`/`signInWithWeb3` on Swift and Kotlin
reference docs

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added documentation for `notIn()` query filtering across supported
Kotlin and Swift query operations.
* Documented `maybeSingle()` for safely handling zero-or-one query
results without raising a single-row error.
* Added guidance for `dryRun()` mutations, including rollback behavior
and returned results.
* Added Swift authentication documentation for Web3 sign-in with
Ethereum and Solana credentials.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 14:37:14 -03:00
Charis 89010c1649 fix(studio): show selected custom time range in SQL editor time range menu (#48709)
## What

Display the actual selected custom date range in the Time Range
dropdown's secondary text, instead of the static "Custom range" label.
The range is formatted as `DD MMM, HH:mm - DD MMM, HH:mm` to match the
existing format in the Logs Explorer's date-picker trigger button,
ensuring visual consistency across the Logs UI.

Fixes FE-4035

## Test plan

- [x] Typecheck passes: `pnpm typecheck`
- [x] Manually verify: Open SQL Editor with `sqlEditorLogsSource` flag
enabled, open the Time Range dropdown menu, select a Custom range, and
confirm the dropdown's secondary text now displays the selected date
range instead of "Custom range"

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Custom time ranges now display formatted start and end timestamps for
clearer time selection.
  * Preset time ranges continue to show their existing helper text.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-04 13:26:02 -04:00
Filipe CabaçoandAli Waseem 4a9b5a538b chore: update pg changes to add python to the code blocks (#47793)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
## What kind of change does this PR introduce?

Adds code blocks for Python and new pg changes features

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated Python code examples for Realtime Postgres Changes to use
cleaner, working subscription syntax.
* Fixed a missing comma in a multi-change example so the sample code is
valid.
  * Added a missing Python example for selecting specific columns.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-04 10:26:26 -06:00
Charis 0791b04eb8 feat(sql-editor): roll out manual saving by default (#48706)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature — progresses the SQL Editor manual saving rollout, and removes a
fully rolled out feature flag.

## What is the current behavior?

Manual saving (snippets save only on an explicit Save / Cmd+S rather
than autosaving every edit) is opt-in. It requires both the
`sqlEditorManualSave` ConfigCat flag and the user turning on the
"Disable snippet auto-saving" feature preview themselves. That flag is
now fully rolled out.

## What is the new behavior?

- `sqlEditorManualSave` is removed, so the feature preview is listed for
everyone. (Delete the flag in ConfigCat after a few months.)
- New `sqlEditorManualSaveForced` flag progresses the rollout. It forces
manual saving on regardless of what the user stored previously,
including an explicit opt-out, via a new `isForced` field on
`FeaturePreview` that `initializeFlags` resolves ahead of the
localStorage lookup — so the feature preview modal reflects the forced
state too, not just the save behavior. Turning the flag off reverts
everyone who never opted in, so it remains a working kill switch.
- Users the rollout switches over get a one-time dialog on their first
SQL Editor route, explaining that snippets no longer autosave. Dismissal
persists in `sql-editor-manual-save-notice-dismissed` (allowlisted, so
it survives sign-out).
- Users who opted into the preview themselves never see the dialog — it
records their dismissal up front instead, since the notice needs to
outlive the feature preview and once the preview is retired there's no
stored opt-in left to recognize them by.
- The preview keeps its switch so users who lose their local storage can
opt in early, but once the rollout reaches them the "Disable feature"
button is disabled with a tooltip explaining why.

### To test

Turn on `sqlEditorManualSaveForced` on via the dev toolbar.

- No `supabase-ui-sql-editor-manual-save` and no dismissal key → dialog
appears on `/project/<ref>/sql`, toolbar shows the Save button. Dismiss,
reload → no dialog.
- `supabase-ui-sql-editor-manual-save` set to `false` (previously opted
out) → still forced onto manual saving, and still gets the dialog.
- `supabase-ui-sql-editor-manual-save` set to `true` → no dialog, and
the dismissal key is written automatically.
- Flag off, no opt-in → autosave, no dialog, and the "Disable autosave"
power-off button still opens the preview modal.
- Preview modal while forced → "Disable feature" is disabled with a
tooltip; another preview (e.g. Column-level privileges) still disables
normally.

## Additional context
2026-08-04 12:16:18 -04:00
Miranda LimonczenkoandClaude Sonnet 5 e7d9c88cbc fix(docs): resolve remaining heading-order issues found in Pass 2 diagnostic (#48664)
## Problem

After merging [#48456](https://github.com/supabase/supabase/pull/48456)
(shared components) and
[#48459](https://github.com/supabase/supabase/pull/48459) (per-page
content fixes), a follow-up diagnostic pass found 22 remaining
heading-order violations, logged as Pass 2 in the [triage
report](https://app.notion.com/p/supabase/Playwright-E2E-Triage-Reports-3ab5004b775f81e3bc60d058fa5a02c1).
None of them were caught by the earlier fixes because they came from
places that scan didn't check: shared partials, raw HTML heading tags
written directly in MDX, and a couple of shared/interactive components
rendering hardcoded heading levels.

## Solution

- `_partials/social_provider_setup.mdx`: `#### Local development` →
`###`, matching the `##` that always precedes it on all 14 social-login
pages.
- `guides/database/functions.mdx` and
`guides/integrations/vercel-marketplace.mdx`: replaced raw `<h4>`/`<h5>`
tags with correctly-nested real headings (`### Planets`/`### People`;
`#### Deploy a Next.js app...`) — no styling workarounds needed since
they nest naturally one level below their parent section.
- `auth/quickstarts/{nextjs,react-native,react,astrojs}.mdx`: these 4
pages had no heading at all before the embedded
`_partials/api_settings.mdx` partial's own `### Get API details`
heading, so added a `## Quickstart` heading above the walkthrough to
give it a valid parent.
- `packages/ui`'s `Accordion` component: Radix's
`AccordionPrimitive.Header` renders as an unconditional `<h3>`
regardless of where the accordion is used. That's shared across Studio,
www, and design-system, not just docs, and surfaced on docs'
vendor-agnostic telemetry page. Now rendered via `asChild` onto a plain
`div` instead, since a generic accordion has no way to know what heading
level (if any) is valid in a given page.
- SQL-to-REST translator tool (`/docs/guides/api/sql-to-rest`): its
`Assumptions`/`FAQs` section labels were hardcoded `<h3>` with no `h2`
anywhere on the page. Converted to styled spans rather than promoting to
a real `<h2>`, because real h1/h2/h3 tags in this codebase force a prose
font-size that utility classes can't override — promoting the tag would
have visibly changed its size.
- `RealtimeLimitsEstimator` (embedded on both `postgres-changes` and
`benchmarks`): its 3 section headings were hardcoded `<h4>`, but the two
embedding pages need different levels (h3 vs h4) for that spot to be
valid — no single correct heading level. Converted to styled spans, same
pattern used throughout this project for components embedded at varying
heading depths.

## Manual testing

1. Check out this branch and run `pnpm dev:docs`.
2. Visit `/docs/guides/auth/social-login/auth-github` (or any other
provider page) and confirm the "Local development" callout under "Find
your callback URL" still looks and reads the same.
3. Visit `/docs/guides/database/functions` → "Returning data sets" tab
and confirm the "Planets" / "People" table captions still look the same.
4. Visit `/docs/guides/integrations/vercel-marketplace` → "Quickstart" →
"Via template" and confirm the CTA card title still looks the same.
5. Visit `/docs/guides/auth/quickstarts/nextjs` (or
react-native/react/astrojs) and confirm a "Quickstart" heading now
appears above the walkthrough, and "Get API details" still renders
correctly further down.
6. Run `pnpm dev:design-system` and open
`/design-system/docs/components/accordion` — expand/collapse an item and
confirm it still animates and looks identical; inspect the DOM and
confirm the trigger's wrapper is a `div`, not an `h3`.
7. Visit `/docs/guides/api/sql-to-rest`, translate any query, and
confirm the "Assumptions"/"FAQs" section labels still look the same.
8. Visit `/docs/guides/realtime/postgres-changes` and
`/docs/guides/realtime/benchmarks`, scroll to the connection-limits
calculator, and confirm its section labels still look the same on both
pages.
9. (Optional, for a full re-check) Run `pnpm e2e:docs:a11y --all`
against a deployed preview of this branch — only `/docs/guides/cli`
(pre-existing 404, unrelated to headings) should fail; every other page
should pass.

Verified with a full Playwright run against a real preview deployment:
**756 passed, 1 failed** (`/docs/guides/cli`, the pre-existing unrelated
404). Zero heading-order violations remain.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added clearly labeled Quickstart sections to Astro, Next.js, React
Native, and React authentication guides.
- Improved heading hierarchy and formatting across social provider
setup, database functions, and deployment documentation.
- Updated estimator and SQL-to-REST section presentation for more
consistent content structure.

- **Bug Fixes**
- Improved accordion trigger layout while preserving existing behavior,
styling, accessibility, and icon display.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 09:00:29 -07:00
Alaister YoungandAlaister Young 0e71933ce3 [FE-4070] fix(studio): allow adding expressions to RLS policies (#48700)
A table RLS policy created via SQL without a `USING`/`WITH CHECK` clause
stores `null` for that field, and the policy editor's payload diff
skipped `null` fields entirely — so adding an expression later through
the dashboard closed the panel as if saved but persisted nothing. This
fixes the diff so those policies are editable, and cleans up adjacent
issues in the same code path.

**Changed:**
- Extracted the update-payload diff from `PolicyEditorPanel`'s submit
handler into a pure `generateUpdatePolicyPayload()` in
`PolicyEditorPanel.utils.ts`. A stored `null` definition/check now
counts as empty, so typing an expression into a previously empty editor
produces a payload field. The diff is branched by command so INSERT
policies only ever emit `WITH CHECK`, never an invalid `USING` clause.
- The required-expression validation ("Please provide a SQL
expression…") now applies only when creating a policy. When updating, a
`null` clause is valid, so rename-only and role-only saves on such
policies work; the update path instead rejects attempts to clear an
existing `USING`/`WITH CHECK` expression with an inline error (`ALTER
POLICY` can only replace an expression, not remove it).
- Saving with no changes now closes the panel without a round trip —
previously a null-vs-undefined comparison injected a
present-but-`undefined` payload key, which sent a literal `BEGIN;
COMMIT;` to the user's database.
- Fixed the unsaved-changes check comparing the form's lowercase command
against `'INSERT'` (never matched), which made closing an untouched
INSERT policy editor prompt about unsaved changes. It now compares
`selectedPolicy.command`.

**Added:**
- `PolicyEditorPanel.utils.test.ts` — 11 unit tests covering null→value
transitions for definition and check, INSERT command mapping,
value→value updates, no-op saves, and empty-value handling.

## To test

- Run in the SQL editor: `create policy "p1" on <table> for delete to
authenticated;` (no `USING` clause), then edit `p1` in Database →
Policies, add a `USING` expression, and save. Confirm via `select
pg_get_expr(polqual, polrelid) from pg_policy where polname = 'p1'` that
the expression persisted.
- Same for INSERT: `create policy "p2" on <table> for insert to
authenticated;`, then add a `WITH CHECK` expression via the editor and
confirm `polwithcheck` is set (and `polqual` stays null).
- On `p1` (still without a `USING` expression? recreate it if you added
one), rename the policy without touching the expression editors — the
rename should save successfully.
- Edit a policy that already has a `USING` expression, change it, and
confirm the new expression persists (regression).
- Open a policy and save without changing anything — the panel should
close with no `policy-update` network request.
- On a policy with an existing `USING` (or `WITH CHECK`) expression,
clear that editor and save — an inline error should appear and no
request should fire.
- Open an INSERT policy that has a `WITH CHECK` expression, change
nothing, and close the panel — it should close without an "Unsaved
changes" prompt.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Policy updates now submit only changed fields.
* Improved handling of policy expressions, including INSERT-specific
mappings.
* Prevented removal of existing `USING` or `WITH CHECK` expressions
where unsupported.
  * Empty expressions are omitted from update requests.
  * Updates are canceled when no changes are detected.

* **Tests**
* Added coverage for unchanged policies, expression updates, name and
role changes, and INSERT policy behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-04 23:16:49 +08:00
Hoon ceace2e90b fix(studio): account for SQL result column headers (#48676)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Fixes #48672.

The SQL Editor results grid calculates each column's initial width from
cell values only. When a long final column contains a short value such
as `NULL`, scrolling to the end of a wide result set reveals a truncated
header even though the full column name is needed to identify the
result.

### Before

<img width="760" height="370" alt="Before: final SQL result column
header is truncated"
src="https://github.com/user-attachments/assets/f73b7540-fc45-4ddf-91b6-996afe41807e"
/>

## What is the new behavior?

The initial width now accounts for both the column name and its cell
values while preserving the existing minimum and maximum width
constraints.

### After

<img width="760" height="370" alt="After: full SQL result column header
is visible"
src="https://github.com/user-attachments/assets/b289ab86-4277-46fc-ae9a-35c3eac5442f"
/>

## Additional context

The width calculation was extracted into a utility and covered for:

- short headers and values
- headers longer than their values
- values longer than their headers
- empty result sets
- maximum-width capping

Verification:

- `pnpm --filter studio exec vitest --run
components/interfaces/SQLEditor/UtilityPanel/Results.utils.test.ts
tests/components/SQLEditor/Results.test.tsx`
- `pnpm --filter studio run typecheck`
- `pnpm --filter studio run lint:ratchet`
- `pnpm run test:prettier`
- `SKIP_ASSET_UPLOAD=1 pnpm run build:studio`


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- SQL query results now automatically size columns based on their
headers and content.
- Column widths remain within practical minimum and maximum limits for
improved readability and usability.

- **Tests**
- Added coverage for minimum and maximum widths, content-based sizing,
and empty result sets.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-04 14:31:59 +00:00
Filipe Cabaço 469da990b6 chore: Add Filipe to humans (#48698) 2026-08-04 14:28:15 +01:00