mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 18:05:11 +03:00
master
6632
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
d2ffd76395 |
perf(logs): load pathname facet counts on demand DEBUG-230 (#51112)
## Problem Unified Logs included a pathname aggregation in every initial sidebar count query, even when the pathname filter was closed. This issue is tracked in [DEBUG-230](https://linear.app/supabase/issue/DEBUG-230/fetch-sidebar-counts-only-when-needed). ## Fix Remove pathname aggregation from the initial ClickHouse and BigQuery count queries while keeping the existing shared count scans. Fetch scoped pathname options through the existing facet query when the filter opens or its search changes. Order limited pathname results by count, validate response rows with Zod, and retain selected paths during loading and validation errors. Use live sidebar filters while their URL update is pending and URL filters after navigation. Cache results by project and filter scope, and wait for feature flags before requesting options. ## How to test - Open Unified Logs, then open Pathname and search. Confirm options load on demand. - Change the time range, another filter, or navigate through browser history. Confirm the options reflect the current scope. - Close and reopen Pathname without changing the scope. Confirm cached options return. - Run the pathname filter component tests and Studio typecheck. |
||
|
|
eb20a4674d |
getTableDefinitionSql to escape SQL identifiers (#51258)
## Context Similar to domain to https://github.com/supabase/supabase/pull/51256 - `getTableDefinitionSql` doesn't escape SQL identifiers, which generates invalid SQL on the dashboard's table editor for the "Copy table schema" CTA, or the table definition tab. Also fixes the "Copy table schema" CTA which was missing the `scoped` parameter when calling `getTableDefinition` Changes here addresses this issue, can test with a table named like `test"table` |
||
|
|
1da25a7e72 |
chore(hipaa): self-serve PITR (#51342)
There is no reason why HIPAA customers cannot self-serve PITR add-on. Instead of telling customers to reach out to support, let them self-serve it. - Docs also wrongfully stated the need for Small compute add-on. - Ability to self-serve PITR - Only 28-day PITR available - Price is now also correct and displays $0 (pending backend change) When enabled (marked as HIPAA compliant): <img width="1128" height="216" alt="Screenshot 2026-10-06 at 1 53 01 PM" src="https://github.com/user-attachments/assets/d83982e7-c71b-4236-ab29-67f85fc40f39" /> When not enabled (marked as HIPAA compliant): <img width="1132" height="255" alt="Screenshot 2026-10-06 at 1 53 55 PM" src="https://github.com/user-attachments/assets/f182813b-2163-4905-8cdf-9c69983ec1b9" /> <img width="772" height="542" alt="Screenshot 2026-10-06 at 1 56 08 PM" src="https://github.com/user-attachments/assets/2cd59439-74b9-49d6-90d1-47c8d1722c9f" /> |
||
|
|
23e7bbcdc6 |
Joshenlim/fe 3359 fix user permission UI for orgs with thousands of projects (#51329)
## Context Adds virtualization to the organization team members page - browser performance was facing issues for organizations with a large amount of members (e.g 1000+), primarily due to some computation within `MemberActions.tsx`, so virtualization addresses this by controlling the number of member rows being rendered in the DOM at any one time. <img width="1182" height="435" alt="image" src="https://github.com/user-attachments/assets/e3da7036-c1c8-4d73-a363-85ecbdb79179" /> ## Unrelated changes - Updated `TeamSettings` to use the `PageContainer` components for UI consistency - Updated user `ProfileImage` to render the first alphabet of the email, rather than a generic user icon <img width="275" height="126" alt="image" src="https://github.com/user-attachments/assets/17eae3b1-c527-4b8f-afcd-c5151bdaf869" /> - Updated row heights of member rows to be more smaller - Updated MFA column to use tooltips with a clearer CTA for members that don't have MFA enabled <img width="332" height="144" alt="image" src="https://github.com/user-attachments/assets/a479af31-7fec-454d-b64e-e6314fd6d55e" /> - Added a filter for MFA status <img width="375" height="177" alt="image" src="https://github.com/user-attachments/assets/fd87105e-524d-4ded-b471-769592be96c7" /> ## To test - Can override the content for the `members` network request with the following sample JSON, main thing is just to test that initial load + searching should not run into any significant browser performance issues. [members-response-1000.json](https://github.com/user-attachments/files/33100317/members-response-1000.json) - Can also test on production that this mock response does indeed cause browser performance issues as well |
||
|
|
089133cc2c |
feat(storage): add bucket object versioning form fields (FE-4161) (#49203)
| # | Branch | Base | | - | ------ | ---- | | 1 | `feat/storage-versioning-private-alpha` — merged | `master` | | 2 | `feat/storage-versioning/002-bucket-form-fields` ◀ | `master` | | 3 | `feat/storage-versioning/003-bucket-modals` | 2 | | 4 | `feat/storage-versioning/004-object-versions-data` | 3 | | 5 | `feat/storage-versioning/005-file-preview-versions` | 4 | | 6 | `feat/storage-versioning/006-billing-storage-retention` | 5 | | 7 | `feat/storage-versioning/007-archived-objects-data` | 6 | | 8 | `feat/storage-versioning/008-archived-rows` | 7 | | 9 | `feat/storage-versioning/009-archived-preview-pane` | 8 | | 10 | `feat/storage-versioning/010-replace-file` | 9 | ## [2/10] Storage object versioning: bucket form fields The object versioning + lifecycle policy form section for the create and edit bucket modals. Mounted onto the ui in PR 3 #49205 - `BucketVersioningFields` — the versioning switch and the suspension / public-bucket / retention-tightening warnings - `LifecyclePolicySection` — the retention window and version cap inputs - `ExpirationModeToggle` — how the two conditions combine (and / or) - `BucketVersioningFields.schema.ts` — zod fields the parent modals spread into their own schema, plus `superRefineBucketVersioning` - `BucketVersioningFields.utils.ts` — retention-tightening detection - `StorageVersioning.constants.ts` — versioning state and expiration mode types, the prefill defaults, and `getBucketVersioningState` Note: a single s3 lifecycle policy expects both `version_expiry_days` and `max_noncurrent_versions` and always evaluate the two fields within the same policy with an AND logic. To enable both AND and OR/EITHER logic, we save two distinct s3 policies so we can enforce the OR logic. See demos and how to reproduce in #49205 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary * **New Features** * Eligible projects with the preview enabled can configure object versioning for storage buckets, including version expiration, retained-version limits, and “and/or” lifecycle conditions. * Settings default to 30 days and 10 retained versions, with validation for retention values and requirements for setting a version limit. * Notices highlight public buckets, missing lifecycle conditions, suspending existing versioning, and changes that tighten retention limits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
53a637a359 |
fix(studio): don't watch Next's .next build output in TanStack dev (#51308)
## Problem Switching a local checkout from `STUDIO_FRAMEWORK=next` to `tanstack` leaves `apps/studio/.next` behind, including a full `node_modules` copy under `.next/standalone`. Vite's dev server watches all of it, logging hundreds of `page reload .next/server/pages/...` lines and wasting file handles. ## Change Add `**/.next/**` to `server.watch.ignored` in `apps/studio/vite.config.ts`. Vite's default ignores (`.git`, `node_modules`) still apply. ## Verification With a stale `.next` present, ran `STUDIO_FRAMEWORK=tanstack pnpm run dev`, touched `.next/server/pages/account/me.html`: no reload logged (previously ~220 `.next` reloads on startup). |
||
|
|
dc95335a8d |
Joshenlim/fe 4068 warn users ai assistant history can be wiped (#51260)
## Context Chats with the AI Assistant is currently stored locally on the browser and not synced across devices which caused a bit of confusion for some users when they realised they couldn't access their chat histories on different devices. (Ideal state tbh is to persist the chat conversations, but that'll need support on the BE) PR here just adds a foot note to both the chat history dropdown in the side panel + chat nav for the explorer regarding this - opting for something with a small footprint <img width="293" height="322" alt="image" src="https://github.com/user-attachments/assets/284ee0c1-16bf-432b-b473-29ee048ed4cc" /> <img width="392" height="956" alt="image" src="https://github.com/user-attachments/assets/e5eb1409-fa63-4dae-9439-86facbe41277" /> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
2538f7eb29 |
Fix unescaped SQL identifiers in row export (#51256)
## Context Resolves https://github.com/supabase/supabase/issues/49977 Addresses an issue in `formatTableRowsToSQL` to use `ident` for schema, table, and column name which will handle escaping of SQL identifiers. Can verify fix by creating a table like `test"table`, then adding some rows, and selecting either Copy as SQL or Export as SQL |
||
|
|
be1ba651ed |
Add branching nav items to cmd k (#51255)
## Context Adds a couple of branching nav items to Command K - Create new branch - Branch management - Merge requests - Github Connection (For branching) - Branching feedback Switch branch is still available, and only visible after a branch has been created (status quo) <img width="610" height="531" alt="image" src="https://github.com/user-attachments/assets/3068184e-889d-44ed-8cf6-2afd59ffb109" /> |
||
|
|
642a02db49 |
Prevent enabling spend cap if org has projects with RRs (#51253)
## Context Prevents organizations from enabling spend cap if the org has projects with read replicas - We currently gate creation of read replicas to ensure that orgs have spend caps disabled, but were missing the guard for the other way around <img width="662" height="378" alt="image" src="https://github.com/user-attachments/assets/44ad036c-4c1b-48e8-beb7-f16f6170c9fb" /> ## Other changes involved - Refactored to use new `Sheet` and `Table` components in `SpendCapSidePanel` |
||
|
|
20d6f2197f |
chore(studio): remove privacy policy notice (#51299)
I removed the Studio Privacy Policy update notice that #50397 added on 2026-09-16, when Privacy Policy v4 took effect. It has been up for almost three weeks, and the ToS v4 banner (#51109) goes out next. I did the same in #44380, removing the March 2026 privacy notice after 15 days. This is the exact inverse of #50397: the banner component and its test, the banner ID, the dismissal local storage key, and the org-landing path helper that only this notice used. ## To test Tested on Vercel preview: - [ ] In a fresh browser profile (no `privacy-policy-update-2026-09-16-dismissed` key), open `/organizations`: expect no Privacy Policy notice - [ ] Open `/org/<slug>`: expect no Privacy Policy notice and the project list renders normally - [ ] Open a project's Logs page: expect the logs deprecation banner behavior unchanged (only shows before its expiry) ## Linear - fixes GROWTH-1322 |
||
|
|
0cb8bd95dd |
feat(studio): add spot colour control to Appearance (#50782)
## Problem The theme's primary hue can change in CSS, but Appearance had no way to try other spot colours. That makes it hard to find controls whose colour still depends on the fixed Supabase brand palette. ## Solution Add a **Spot color** control under Appearance → Theme colors (employee-only via ConfigCat `appearanceSpotColor`, targeted to Supabase Team Email). ### Spot color UX - Rainbow spectrum track with a thin outline so pale tracks stay visible - Live trifecta swatches for `--primary-solid`, `--primary`, and `--primary-bright` (darkest → lightest) next to the degree readout - Drag updates are rAF-batched so React paint and CSS preview stay to one frame ### Canvas tint coupling - `--surface-hue` is derived in CSS as `calc(var(--primary-hue) + var(--surface-hue-offset))` - Dark: offset `0` (same hue as spot) - Light: offset `180` (complementary canvas tint; brand green ≈157.5° → rose ≈337.5°) - No JS override of `--surface-hue`. Changing Spot color moves primary controls and the low-chroma canvas tint together ### Other theme sliders - Renamed **Color intensity** → **Surface tint** (it only drives the neutral ramp via `--chroma`, not spot chroma) - Meaning-shaped tracks for every knob (spectrum, grey→tint, soft→hard, dark→light, flat→lift) - Same outline treatment on those tracks | Before | After | | --- | --- | | <img width="1476" height="2174" alt="CleanShot 2026-10-05 at 15 02 21@2x" src="https://github.com/user-attachments/assets/d08b0fa8-32af-450e-adce-861f59c9d6ca" /> | <img width="1474" height="2354" alt="CleanShot 2026-10-05 at 14 56 35@2x" src="https://github.com/user-attachments/assets/9a1e6183-a4ba-4c8e-a458-bb0eea946db8" /> | | _Anyone else_ | _With staff flag, custom settings_ | ## Review instructions 1. Confirm ConfigCat flag `appearanceSpotColor` is on for your staff account (or flip it in the Dev Toolbar). 2. Open `/account/me` → **Appearance → Theme colors**. 3. Without the flag: Spot color is hidden; other theme sliders still work. 4. With the flag: drag Spot color in light and dark. Primary controls and canvas tint should move together; Supabase brand assets should stay fixed. 5. Raise Surface tint and confirm the canvas hue follows the complementary (light) or same-hue (dark) offset. 6. Refresh, switch modes, and use **Reset** to check persistence and defaults. |
||
|
|
09a245d72d |
[FE-4520] fix(studio): hide Realtime setup for published tables (#51152)
The Realtime Inspector now checks the Realtime publication before showing setup guidance. Projects with published tables get the join-channel view even before this Inspector session receives any messages; unconfigured projects keep the setup guide. Setup guidance also stays hidden while publications are loading or unavailable. Joining a channel and displaying received messages retain their existing behavior. Addresses [FE-4520](https://linear.app/supabase/issue/FE-4520/realtime-inspector-ui-implies-i-am-not-using-realtime-despite-already). ## To test - With no tables in `supabase_realtime`, open Realtime → Inspector and confirm the setup guide appears. - Enable Realtime on a table and confirm a client receives a database change. Open the Inspector without joining a channel: it should show “Join a channel to start listening to messages” and no setup guide. - Join a channel, trigger a table change, and check the event and payload appear. Stop listening and confirm messages remain visible. - Open Policies, then return to the Inspector and confirm the setup guide stays hidden for the configured project. - Join a broadcast-only channel with no incoming messages and confirm the messages view appears immediately. ## Validation Reproduced the original prompt locally with a working Realtime table, then verified the fix in the browser, including an independent client subscription, a live INSERT in the Inspector, navigation, stopping, and the unconfigured state. Temporary test data and services were cleaned up. All nine new regression tests pass; four fail against the original code. Typecheck, formatting, lint ratchet, Knip, and the case-sensitivity check pass. The full Studio suite passed 7,799 tests with one unrelated Explorer test failure; that test passed on a focused rerun alongside the Inspector tests. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * The Realtime inspector keeps the messages view visible while publication status is loading or unavailable, and when a channel is joined or messages are present. * Setup guidance appears only after publications load successfully and confirm that Realtime is unavailable, with no channel or messages to show. This includes cases where there are no publications, the Realtime publication has no tables, or only a differently named publication exists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
7d04c43082 |
fix(logs): default unified logs to otel DEBUG-228 (#51089)
## Problem Unified Logs could start legacy BigQuery requests while ConfigCat loaded, then switch to OTEL when the flag resolved. ## Fix Default Unified Logs to OTEL unless otelUnifiedLogs is explicitly false. Use that selection for list, count, chart, facet, detail, download, and manual refresh requests. Keep BigQuery as an explicit opt-out until the legacy backend is removed. ## Validation - Studio typecheck passed locally. - Existing Unified Logs utility tests passed (21 tests). - The focused Unified Logs query test file was removed as requested; backend-selection and manual-refresh regressions are no longer covered by that suite. - CI checks are running on the current head. Tracks [DEBUG-228](https://linear.app/supabase/issue/DEBUG-228/prevent-bq-queries-before-the-feature-flag-loads). |
||
|
|
b028908136 |
feat(studio): add never option to scoped pat expiry (#51273)
## Problem When building scoped pat's we had omitted the option to have them never expire. ## Solution This re-adds the option to select "never" and it comes with the caveat of an admonition to warn the user that they would need to manually delete or revoke this token. ## Review instructions Provide a clear numbered procedure that the PR reviewer can walk through. 1. Open /account/tokens 2. Click Generate new token. 3. Open Expires in. Confirm "Never" is the last option, after "Custom", and has no Recommended badge. 4. Select Never. A warning admonition appears directly below the expiry row: "This token never expires — Anyone with the token keeps access until you delete it." 5. Pick an org and project, grant one permission, click Review access. Summary shows Expires: Never. 6. Create the token. The POST body has no expires_at, and the new row's Expires column reads Never. Fixes FE-4527. Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
87681812a0 |
fix(studio): assistant get_active_incidents url in prod (#51047)
The Assistant's `get_active_incidents` tool has [failed in prod 99.8% of the time over the past 60 days](https://supabase.slack.com/archives/C051L8U2EJF/p1790712805774689), so users reporting outages get told it couldn't check incident status. The failures never showed up as errors, which is why nobody noticed. The Assistant now includes the `/dashboard` base path when it calls its own API routes, so the tool stops hitting a 404 in prod ([`/api/incident-status`](https://supabase.com/api/incident-status) is a 404, [`/dashboard/api/incident-status`](https://supabase.com/dashboard/api/incident-status) is a 200). The tool also throws on a failed fetch now instead of returning an `{ error }` result. That way failures show up as span errors in Braintrust and as a failed tool call in the UI. The model still gets the error message and tells the user it couldn't check. When the fetch fails (in dashboard): | Before (prod) | After (local, path temporarily broken) | | --- | --- | | <img width="1036" height="784" alt="CleanShot 2026-09-29 at 5 08 49 PM@2x" src="https://github.com/user-attachments/assets/4539f968-4aa6-49a5-8c7f-7911b6b497a0" /> | <img width="1026" height="716" alt="CleanShot 2026-09-29 at 5 08 06 PM@2x" src="https://github.com/user-attachments/assets/7c9a565c-efe1-4d1a-901b-e440bbb5a739" /> | When the fetch fails (in Braintrust): | Before (prod) | After (local, path temporarily broken) | | --- | --- | | <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 07 PM@2x" src="https://github.com/user-attachments/assets/87860568-b50f-49ee-98fd-4c82f14d1913" /> | <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 10 PM@2x" src="https://github.com/user-attachments/assets/64f58d47-e083-464e-b8d0-8b9c57710a05" /> | When the fetch works (local): | Dashboard | Braintrust | | --- | --- | | <img width="1054" height="808" alt="CleanShot 2026-09-29 at 5 20 58 PM@2x" src="https://github.com/user-attachments/assets/1c9e4cf8-79f0-48e6-b95a-1694fc00a9f9" /> | <img width="2918" height="1144" alt="CleanShot 2026-09-30 at 9 07 03 AM@2x" src="https://github.com/user-attachments/assets/0d2b9685-57a9-4028-a451-272b3de8e23a" /> | Ran it locally with tracing on. Here's a [successful call](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=251bcd44-c55b-44bb-9ce2-b034b26f8832), and one with the path temporarily broken, which now [logs a span error](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=637f2dc8-f65b-4d65-9d86-0511b36e8685). Local dev has no base path, so the prod URL is covered by the new `getBasePathURL` tests. Closes AI-1272 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Incident lookups now report fetch, HTTP, parsing, and validation errors rather than returning an empty incident result. * AI SQL generation now accounts for the configured site base path when building its service URL. * **Improvements** * Site URLs now handle trailing slashes and existing base paths consistently, avoiding duplicate path segments. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0c2257fb3d |
feat(studio): scoped oauth data layer (#49476)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? ~~This is the first part (and ultimately the final part of the stacked PR). PR 1 introduces mock data for us while we build the requirements of the scoped oauth interstitial, all following PR's will be stacked on top of this one.~~ This is the first part, the data layer side. We began with mock data, but as backend support arrived we've used this PR to help us shape the UI as well as the frontend data layer. This now acts as the frontend data layer. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added OAuth app authorization request handling. * Added visibility into application details, requested scopes, and existing authorizations. * Added organization and project selection during authorization. * Added organization roles and project access details. * Added approval and denial options with secure redirect handling. * Added validation for required authorization details and project selections. * Added support for role validation feedback during approval. * Added representative authorization scenarios for approved, denied, and re-consent flows. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> Co-authored-by: Samir Ketema <6003000+samirketema@users.noreply.github.com> |
||
|
|
de41b029ef | always use canonical link for new status page (#51264) | ||
|
|
0d8b1417bc |
[bot] Decrease ESLint ratchet baselines (#51225)
Automated weekly decrease of ESLint ratchet baselines. Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> |
||
|
|
77e3b4382f |
feat(role): Allow eligible organizations to invite users as 'No-access' base role (#50922)
## Problem As the API has allow inviting users into `None / No-access` role for team, enterprise, and platform tier organization, we need to update the documentation and descriptions for this new role on the invitation form. ## Solution 1. Updated `apps/docs/content/guides/platform/access-control.mdx` to include the role 2. Added the role description on `apps/studio/components/interfaces/Organization/TeamSettings/Roles.constants.tsx` 3. Add the roles into the proper sorting order at `apps/studio/data/organization-members/organization-roles-query.ts` 4. Add logic to invitation components to disable the role when inviting user into project(s), as the backend does not allow it. ## Testing and verification steps The UI: https://studio-staging-aa8is1m07-supabase.vercel.app/dashboard/org Documentation: https://docs-kht98bi78-supabase.vercel.app/docs/guides/platform/access-control <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary * **Updates** * The **None** role is labeled **No-access** and describes the lack of organization and project resource access. * **None** is included after **Read-only** in the role list. When inviting a member with project-only access, **None** is disabled with an explanation. * **Documentation** * Clarified plan coverage for **Read-Only** and **No access**, and added guidance on assigning **No access** at the organization level before granting project-specific roles. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
01bfab39d6 |
studio: improve warning for replicas on spend cap (#51179)
## Summary The "> 8 GB warning" when spend cap enabled used to be conflated with the "has replicas with spend cap" warning, which causes a confusing error message. Opting to split them out into 2 separate warnings to give the user a better description of the problem. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Read replicas alone no longer trigger the disk-size threshold warning. * **New Features** * When usage billing is disabled, a warning appears if read replicas are present and no project exceeds 8 GB, with guidance on next steps. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cb52c0f425 |
chore(studio): update segment control in view permissions to ds one (#51125)
## Problem We were using a custom segment control. Recently we introduced segmented toggle groups in our design system. The old one is inconsistent and doesn't match anything else. ## Solution Replace segmented control with [this one](https://supabase.com/design-system/docs/components/toggle-group#segmented). | Before | After | |--------|--------| | <img width="777" height="85" alt="Screenshot 2026-10-01 at 11 36 47" src="https://github.com/user-attachments/assets/84e28075-248d-42d4-a537-f18cd2fe86db" /> | <img width="783" height="95" alt="Screenshot 2026-10-01 at 11 37 00" src="https://github.com/user-attachments/assets/1071f031-8e96-4db1-8ea1-36cb34e9923a" /> | ## Test plan - [ ] Go to Account Settings → Access Tokens, create a new scoped token, and on the capability review step confirm the All/Read/Read-write segmented control renders correctly and filters the capability list as expected - [ ] Open an existing scoped token's "View" sheet and confirm the same segmented control filters correctly there too - [ ] Verify keyboard navigation (arrow keys) and that exactly one option is always selected (no deselect state) - [ ] Visual check against the design system's segmented `ToggleGroup` styling (no leftover custom border/divider artifacts from the old implementation) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the capability-level selector to use a segmented control. Selection behavior remains unchanged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
838fcaaa89 |
Joshenlim/fe 4509 fdw general UI consolidation and refactor (#51079)
## Context Stacks on top of https://github.com/supabase/supabase/pull/51074 PR's just mainly refactoring, no visual differences: - `CreateWrapperSheet` + `EditWrapperSheet` use the same UI components for the foreign tables section - Can be consolidated into one reusable component - `WrapperTableEditor` is still using `SidePanel` component - Can be swapped to use new `Sheet` component - Refactor `WrapperTableEditor`'s layout a little - added separators for clarity between sections <img width="400" alt="image" src="https://github.com/user-attachments/assets/b1983bf2-cff5-43eb-8b31-40a7abb65038" /> - Update `getCreateFDWSql` to just use the Foreign Data Wrapper's name from `wrapperMeta` since its now standardized <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a shared foreign-table selector for wrapper setup and editing, with options to view columns, add or edit table definitions, and remove tables. * Updated the table editor to use a sheet layout with a fixed footer. * **Bug Fixes** * Wrapper creation now uses the wrapper’s configured name when creating the server. * Foreign-table targets display the table name when other target details are unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
521881a899 |
Joshenlim/fe 4480 fdw create wrapper to only init fdw once users to name the (#51074)
## Context PR here refactors the way we manage Foreign Data Wrappers in the dashboard (Under Project -> Integrations), as there's some DX problems with the current behaviour. Currently whenever a user creates a new wrapper, the dashboard is creating both the Foreign Data Wrapper (`create foreign data wrapper...`) + server (`create server ...`). The former is **_redundant_** to create multiples of given that it just handles the `handler` and `validator`, whereas what matters more is the server which holds the connection credentials. Hence standard practice is usually one Foreign Data Wrapper with multiple servers. (The former just needs to be created once if not done yet) This also led to some problems as well when users created their own wrappers via SQL and tried to manage them through the dashboard GUI, leading to us having to add some guard rails to prevent managing wrappers sharing the same Foreign Data Wrapper ([ref](https://github.com/supabase/supabase/pull/50785)) ## Changes involved - When creating a wrapper, if the Foreign Data Wrapper has yet to be set up for the wrapper type, the dashboard will initialize one and subsequently use that same Foreign Data Wrapper for any new wrappers - When creating / editing a wrapper, users will name the **server** instead of the **wrapper** <img width="500" alt="image" src="https://github.com/user-attachments/assets/b3e61204-0e16-4599-84ac-af2aab5b93c2" /> - When deleting a wrapper, the clean up for vault secrets are now deterministic by referencing the wrapper's server options - RE backwards compatibility: Existing wrappers will _not_ be affected by the changes here - they can be edited / deleted as per normal ## Unrelated fixes + UI refactors added - Fix Iceberg Wrapper not showing the right form when adding new wrapper - Adjust form layouts in side panel to be horizontal instead of vertical (Follows Database -> Pipelines) - Clean up to use newer UI components like `ButtonTooltip` - Opt to hide Docs + Create CTA under `WrappersTab` if marketplace feature preview is enabled (Since these actions are already in the header, will be duplicates) - Consolidate foreign tables configuration for create + edit wrapper sheet into one component `ForeignTablesSelector` ## To test - [ ] Verify that existing wrappers with their own Foreign Data Wrapper can be edited correctly - [ ] Verify that existing wrappers with their own Foreign Data Wrapper can be deleted - [ ] Verify that existing wrappers with shared Foreign Data Wrapper can be edited correctly - [ ] Verify that existing wrappers with shared Foreign Data Wrapper can be deleted - [ ] Verify that new wrappers can be created - [ ] Verify that newly created wrappers can be edited correctly - [ ] Verify that newly created wrappers can be deleted |
||
|
|
5de3666930 |
Fix: storage explorer ignore current filter after mutations (#51174)
## Problem When users trigger actions such as deleting an item, the storage explorer reloads the opened folders but ignore the currently applied filter. ## Solution Move the filter state in Valtio so that its other functions are aware of it. ## Review instructions 1. Create a Supabase project and upload objects in Storage with date prefixes (e.g., 202608XX) 2. Navigate to Storage, select a bucket with multi-dated/prefixed objects 3. Enter a filter in the search box (e.g., 20260820) to show only matching objects 4. Select one or more filtered objects and delete them Observe the file list after deletion - it should show filtered contents according to the search box value <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Storage search now stays in sync as you open folders and refresh their contents. * When restoring open folders, search results are filtered in the deepest open folder rather than hiding ancestor folders. * Deleting a file from filtered results keeps the search applied and displays the remaining matches correctly. * Search results remain consistent across folder navigation, refreshes, and file deletion. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ba82106697 |
chore(www + studio): remove expired Select 2026 promo banners (#51245)
## Problem Supabase Select 2026 has finished. The promo banners already hide via the scheduled expiry from #51006, but the campaign code, assets, and wiring are still in the tree. ## Solution Remove the Select 2026 sitewide promotion across www and Studio: - Delete shared `Select26*` banner code, font, and tests from `ui-patterns` - Delete Studio `BannerSelect2026*` and its Banner Stack registration - Unmount the www announcement banner and revert the State of Startups spacing that only existed for it - Drop the Select-only session-replay `data-band` allowlist entry and lint ratchet baseline Event go pages, blog posts, and other Select content are left alone. The `Announcement` shell stays for the next campaign. ## Review instructions 1. Open the www homepage on the deploy preview. Confirm there is no Select announcement bar above the nav. 2. Open `/state-of-startups` on the deploy preview. Confirm the hero still looks correct with no extra top gap from the removed banner. 3. Open a hosted Studio dashboard page on the deploy preview. Confirm the Banner Stack no longer shows a Select card. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) |
||
|
|
acaf640d1c |
Joshenlim/fe 4522 polish recovery codes UI (#51124)
## Context Just a couple of UI polishes for the recovery codes UI under Account settings -> Security - all visual, no functional changes ## Changes involved - Shift position of Recovery codes section below MFA - Better hierarchy since recovery codes only matter after adding an MFA app - Prevents layout shift with the feature flag as well | Before | After | |------|------| | <img width="400" alt="image" src="https://github.com/user-attachments/assets/3f24e30b-14b1-49cc-8942-0bd139af031b" /> | <img width="400" alt="image" src="https://github.com/user-attachments/assets/9a020b9b-4644-4e39-ba75-082e7f3a08db" /> | - Update how recovery codes are displayed | Before | After | |------|------| | <img width="400" alt="image" src="https://github.com/user-attachments/assets/9ce00013-9b7f-4ab9-9a10-0eec536022f5" /> | <img width="400" alt="image" src="https://github.com/user-attachments/assets/6bdc8c18-cfd2-46ea-a851-5a9fe03a5211" /> | - Update recovery codes modal, aligns "confirmation" UX to be more consistent with scoped PAT - Footer CTA is just "Done" that's disabled until either Copy or Download is clicked - Copy CTA shifted below codes for contextual grouping - Also added download CTA, which just downloads codes in TXT | Before | After | |------|------| | <img width="534" height="389" alt="image" src="https://github.com/user-attachments/assets/55cdbe9f-f37c-4284-b2ac-46834fd14437" /> | <img width="533" height="548" alt="image" src="https://github.com/user-attachments/assets/ab091822-e5fc-464c-94e6-f1d6b6792c59" /> | - Show success toast after codes are successfully deleted - Use warning variant for regenerate confirmation dialog <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Recovery codes are displayed as a numbered list, with separate options to copy or download them. * You must confirm that you’ve saved the codes before closing the success dialog. * **Improvements** * Generation buttons show when codes are being created. * Recovery-code actions have updated layouts, icons, and confirmation styling. Available codes are identified as single-use, and loading errors are displayed in an alert. * Removing codes displays a success message before the confirmation dialog closes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
52f34c3097 |
fix(studio): drop brand override on last-used sign-in badge (#51248)
## Problem The Sign in **Last used** badge overrode `Badge variant="success"` with `bg-brand-400`, which reads as lime in light mode instead of the normal success green. ## Solution Remove the colour override so Last used uses the standard soft success badge. No new Badge variant; no other callsite churn. | Before | After | | --- | --- | | <img width="908" height="1292" alt="CleanShot 2026-10-05 at 14 19 27@2x" src="https://github.com/user-attachments/assets/6890bf3d-90ce-423e-832a-0bbb0ecdf7cf" /> | <img width="902" height="1280" alt="CleanShot 2026-10-05 at 14 31 15@2x" src="https://github.com/user-attachments/assets/18b193a5-8015-4303-ac9a-a8d5981dd471" /> | ## Review instructions 1. Open the Studio preview [/sign-in](https://studio-staging-git-dnywh-1ce8f481-supabase.vercel.app/dashboard/sign-in) (or the Vercel bot URL if it differs). 2. In DevTools: `localStorage.setItem('supabase-last-sign-in-method', 'email')`, then refresh. 3. Spot-check light and dark. |
||
|
|
94b8b06eb2 |
Clean up auto region selection experiment (#51121)
## Context Just cleans up the experiment that was introduced [here](https://github.com/supabase/supabase/issues/50851) - can clean up feature flag in ConfigCat thereafter too <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Project Creation** * Removed the “Best available” region option. Choose a specific region or smart group when creating a project; the selected region name appears in the selector. * Recommended badges remain visible on recommended regions. * **Telemetry** * Project creation events no longer include details about the removed region option or the initial region recommendation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
39e13d3181 |
Fix dependency array in RouteValidationWrapper causing loop (#51170)
## Context For staging and local only, if you opened the a table in the table editor, then navigate out, and back into the table editor - the browser freezes - The TableEditor itself has a `useEffect` that reads that and redirects to the last visited table when landing on `/editor` - `router` is in the dependency array which for the TanStack build is not a stable singleton, resulting in a redirect loop - so the main fix was to remove `router` from the dependency array - (Unrelated) Also cleaned up some logic in the redirect regarding reading the tab ID <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved table editor redirects so they select the matching open table tab from history or fall back to the first open table tab when available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7353782724 |
fix(studio): show compute waitlist notice when project is not enrolled (#51224)
Resolves FUNC-941 ## What When a project isn't enrolled in Compute, show a short notice with a link to the waitlist (https://supabase.com/compute) instead of a generic error. ## Why The compute API returns its 404 as `{ "error": { "code", "message" } }`. `handleError` only reads a top-level `message`, so it dropped the status code, `isComputeUnavailable` never matched, and users saw "API error happened while trying to communicate with the server." The query now checks `response.status === 404` directly. ## Testing - [ ] Project not enrolled in Compute: the waitlist notice shows - [ ] Enrolled project: the instance list loads as before |
||
|
|
4ab54b9359 | ref(docs): Make ClickHouse, Snowflake and DuckLake in public alpha (#51195) | ||
|
|
0405b31b26 |
docs: re-publish Multigres Private Alpha docs — merge on October 2, 2026 (#50664)
## I have read the CONTRIBUTING.md file. YES ## What kind of change does this PR introduce? Re-add. Reapplies the Multigres Private Alpha docs section removed in #50662, ready to merge once Sugu gives the go-ahead. Do not merge until then. Linear: MUL-1621 (follow-up to MUL-452). ## What is the current behavior? Multigres docs section is down (per #50662): no overview/compatibility pages, no sidebar entry, no features-table row, no "What you get" cards. ## What is the new behavior? Exact reapply of #49020 (with Multigres marked Private Alpha): overview guide at `/docs/guides/database/multigres`, compatibility stub, Database sidebar entry, features-table row, "What you get" cards, and the `ContentListings` optional-`href` support they rely on. Base branch is the revert PR (#50662) so the diff here is legible now; retarget to `master` once #50662 merges. ## Additional context - `pnpm --filter docs exec vitest run lib/content-listings.test.ts` — 22 passed - Blocked on Sugu's go-ahead — `do-not-merge` label applied --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
4b2d163a1d |
fix(orioledb): use alpha and beta conditionally based on AMI version (#51162)
## Problem - Older orioledb projects show "Public Beta" instead of "Public Alpha" in UI. - List of backups in the "Scheduled backups" tab hangs. ## Solution - show in the UI "Public Alpha" for projects older than 17.11.0.001-orioledb - show in the UI "Public Beta" for new projects - enable scheduled-backup query for "Public Beta" <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Backup availability messages now reflect OrioleDB’s current release stage rather than always describing it as public beta. * AWS backup queries are no longer disabled for every OrioleDB project; they remain disabled during the alpha stage. * **New Features** * Added an informational notice and documentation link for scheduled backups on AWS OrioleDB projects in alpha. * Added release-stage details to the PITR availability notice. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> |
||
|
|
b13d6c2878 |
feat(chore): add a lint ratchet for shadcn rules (#51014)
## Problem shadcn lint rules has been soft landed in #50676 and are now on as warnings in every app, but nothing stops a PR from adding new violations linear: FE-4473 ## Solution - moved the ratchet script and its tests from `apps/studio/scripts` to `packages/eslint-config-supabase` so every app runs one copy - added a shared rule list, `packages/eslint-config-supabase/ratchet-rules.json` with the shadcn rules - www, docs, design-system, ui-library and learn get `lint-ratchet.yml` with one job per changed app (triggered by the app, `packages/**` or the lockfile) + a weekly `lint-ratchet-decrease.yml` (as for studio ratchet) - package tests run in `eslint-config-supabase-tests.yml` <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions 1. run `pnpm --filter ./apps/www run lint:ratchet` 2. add `p-[13px]` to a `className` in any www component and run it again. it fails with `shadcn/no-arbitrary-values` and the file name with `(+1)` 3. revert change 4. run `pnpm --filter eslint-config-supabase test` and see 6 tests pass 5. in ci, check `Ratchet studio lint checks` and the `ratchet (<app>)` jobs for the apps this pr touches ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Developer Improvements** * Expanded automated lint checks to cover additional apps and shared package changes. * Added checks for arbitrary Tailwind values, unknown classes, and raw colors across supported apps. * Added automated baseline updates that can open or update a pull request when lint counts change. * Added tests for the lint configuration and support for combining multiple rule files. * Updated Studio lint notifications to exclude Shadcn rules with zero-baseline counts. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6143441493 |
fix(pipelines): clarify DuckLake destination setup (#51013)
## Problem The DuckLake setup form makes it hard to choose between Supabase projects and external connection details. Bucket creation, catalog settings, and the guide do not clearly follow the setup flow. ## Solution - Show **Configuration method** as two clear choices: **Select Supabase projects** and **Enter connection details**. - Group catalog and storage fields, move **Pool size** to **Advanced settings**, and add **New bucket** to the bucket selector. - Clarify the custom Postgres and S3 fields, including the metadata schema, connection URL, and storage options. - Update the [DuckLake destination guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake) to follow the form and explain resource preparation and validation. | Before | After | | --- | --- | | <img width="1280" height="1323" alt="50587" src="https://github.com/user-attachments/assets/bf5997cf-9fc4-48a8-ad4f-13fa991d56f9" /> | <img width="1280" height="1323" alt="61914" src="https://github.com/user-attachments/assets/2c1dd7ef-797f-4302-9e2e-93a5f1e6e515" /> | ## Review instructions 1. Open **Database > Pipelines > Add pipeline** and select **DuckLake**. 2. Select **Select Supabase projects**. Check the catalog and storage fields, create a bucket from the bucket selector, and find **Pool size** under **Advanced settings**. 3. Select **Enter connection details**. Check the Catalog URL, S3 URL style, and Use SSL guidance. 4. Compare both routes with the [DuckLake destination guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake). ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] I used the `/edit-the-docs` skill and the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * DuckLake destinations support Supabase-managed projects or an existing Postgres catalog with S3-compatible storage. * Select a storage bucket using search, configure a metadata schema, and access clearer guidance for catalog and storage settings. * Advanced settings provide a connection pool size from 1 to 6, with a default of 4. Credential fields include show and hide controls. * **Documentation** * Updated setup steps, configuration guidance, query credential details, and troubleshooting instructions for both configuration modes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6572fad288 |
fix(studio / ui) - update xss vuln version of tanstack (#51141)
## Problem When I bumped the pnpm-lock file in an unrelated KB fix (#51132), I believe that refreshed the build cache (either that, or Vercel started flagging this issue very recently). At any rate, builds are now failing b/c of a [vulnerable Tanstack/react-start package](https://github.com/TanStack/router/security/advisories/GHSA-qx66-fv34-fjm8), which this PR attempts to fix. ``` The build blocks vulnerable @tanstack/react-start@1.168.18 due to an XSS security check. ``` <img width="1355" height="397" alt="image" src="https://github.com/user-attachments/assets/7d0d90fb-009c-4a0b-aadc-b526e0fcce0a" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated project maintenance settings and supporting TanStack package versions. * Improved error reporting so standard errors include their stack trace, while other error values are logged directly. * No app features were added or removed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
123c768de1 |
Warn when authenticator role overrides exposed schemas (FE-4472) (#50982)
## What Adds a warning in Project Settings > API when the `authenticator` role's `pgrst.db_schemas` setting overrides the Dashboard's "Exposed schemas" configuration, plus an inline "Reset override" button to fix it in one click. ## Why `ALTER ROLE authenticator SET pgrst.db_schemas = ...` silently overrides what PostgREST actually exposes, regardless of what's selected in the Dashboard. Users hit a confusing PGRST106 error with no indication that a role-level override is the cause. ## How - New query (`authenticatorRoleConfigQueryOptions`) reads `pg_roles.rolconfig` for the `authenticator` role and parses out any `pgrst.db_schemas` value. Configured to always refetch on mount and window focus, since the fix is often applied outside the Dashboard (SQL editor, another client) with no cache-invalidation event for the app to react to. - `PostgrestConfig.tsx` compares that value against the currently selected schemas and shows an `Admonition` warning naming the actual overriding schemas, with a link to the PGRST106 troubleshooting guide, when they differ. - The warning includes a "Reset override" button that runs `alter role authenticator reset pgrst.db_schemas` after a confirmation step (showing the exact SQL that will run, with a copy button), then refetches so the warning clears immediately without a page reload. ## Testing 1. In the SQL Editor of a test project, run: ```sql alter role authenticator set pgrst.db_schemas = 'public'; ``` 2. Go to Project Settings > API, and select a schema other than (or in addition to) `public` in "Exposed schemas" (e.g. add `api`). 3. The new warning should appear, naming `public` as the schema actually in effect, with a link to the PGRST106 troubleshooting guide. 4. Click "Reset override" in the warning, confirm in the modal, and check that the warning clears immediately without a page reload. 5. Alternatively, clear the override manually from the SQL editor: ```sql alter role authenticator reset pgrst.db_schemas; ``` then navigate away from the API settings page and back (or refocus the browser tab) — the warning should clear without a hard refresh. Fixes [FE-4472](https://linear.app/supabase/issue/FE-4472/warn-when-authenticator-role-overrides-exposed-schemas) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * The API settings page now warns when the authenticator role’s exposed schemas differ from the saved Dashboard configuration. * You can reset the override to restore the saved schema configuration. The reset requires permission and provides success or error feedback. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4f0be099e7 |
fix(studio): restore the Snowflake destination mark (#51075)
## Problem The Snowflake destination still uses a neutral text monogram even though its Studio asset is available. Supporting that monogram also leaves a separate rendering path used by no other destination. ## Solution Restore Snowflake through the shared brand-icon registry introduced by #51073. Simplify `DestinationLogo` back to a map of destination marks, removing the monogram type, configuration, and rendering branch. | After | | --- | | <img width="924" height="730" alt="CleanShot 2026-09-30 at 15 14 59@2x" src="https://github.com/user-attachments/assets/7409d483-3371-45ec-bf54-0ddc6ad22857" /> | ## Review instructions 1. Open `/project/<ref>/database/replication` with a Snowflake pipeline. 2. Confirm the Snowflake mark appears in the pipeline list and diagram. 3. Open the pipeline child route and confirm the same mark appears in its header. 4. Confirm the other destination marks remain unchanged in light and dark themes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Visual Updates** * Snowflake replication destinations now display a themed brand icon instead of the “SF” monogram. Other destinations retain their existing icons. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d6c81b66c9 |
Apply scrollBeyondLastLine for CodeEditor in QueryEditor and Logs Explorer (#51082)
## Context As per PR title - this was the behaviour for the SQL Editor and figured it makes sense to also have this behaviour in the Explorer QueryEditor + Logs Explorer where the main UX is writing queries, and lets the user bring the active section of the code closer to the middle of the viewport (rather than right at the bottom) <img width="790" height="305" alt="image" src="https://github.com/user-attachments/assets/07eb63fa-1bb9-4abe-859e-2968a73e7ca5" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Editor Improvements** * Query editors now allow scrolling beyond the final line, providing more room to position the last lines on screen. * The SQL editor no longer forces the decoration area to zero width; it now uses Monaco’s default width behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5fbf1ac4ff |
feat(studio): support themed pipeline destination logos (#51073)
## Problem Some destination marks need different assets to maintain contrast across light and dark surfaces. Their paths are also duplicated between Pipelines and Wrappers. ## Solution Add a shared brand-icon registry that supports either one asset or light and dark variants. Pipeline destination logos resolve against the active theme, while Wrappers continue using the light variant for their white logo tiles. This keeps single-asset destinations unchanged and preserves the existing monogram treatment where applicable. | Light | Dark | | --- | --- | | <img width="926" height="742" alt="CleanShot 2026-09-30 at 15 03 31@2x" src="https://github.com/user-attachments/assets/d76e5995-1bb8-4cb7-b991-c5dc1a5d8cb0" /> | <img width="926" height="732" alt="CleanShot 2026-09-30 at 15 03 03@2x" src="https://github.com/user-attachments/assets/83d45f30-3bf6-4ddc-8607-e27628cb4966" /> | ## Review instructions 1. Open `/project/<ref>/database/replication` with pipelines using the themed destination marks. 2. Switch between light and dark themes from the account menu. 3. Confirm each themed mark swaps assets and remains legible in the pipeline list, diagram, and child-route header. 4. Open Database Integrations and confirm the corresponding Wrapper tiles continue using their light-surface assets. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the BigQuery, ClickHouse, DuckLake, and Snowflake icons in integration and replication views to use branded marks. Icons now use theme-appropriate variants where available, helping them display consistently across light and dark themes. ClickHouse’s previous “CH” monogram is replaced with its branded mark. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bd9a0ff4e6 |
feat(orioledb): rename orioledb from Public Alpha to Public Beta in dashboard (#50975)
## Problem We need to rename orioledb in Dashboard. ## Solution - Update Studio copy/badges referencing OrioleDB from "Public Alpha" to "Public Beta" (project creation advanced config, restore-to-new-project, PITR empty state) - Remove the scheduled-backups block that hid backups for OrioleDB projects — OrioleDB now has WAL-G scheduled backups in beta, so that page should behave normally. PITR keeps its existing guard since PITR is not yet supported for OrioleDB. - Update the `useOrioleDb` telemetry property doc-comment to reflect the beta status - Update project-creation wizard test expectations/fixtures accordingly (`release_channel: 'beta'`) Marketing (`apps/www`) and docs (`apps/docs`) references to OrioleDB alpha status are being updated separately. <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * OrioleDB is now labeled as being in public beta rather than public alpha, and project creation selects the beta release channel. * Restore-to-new-project and Point-in-Time Recovery notices clarify that these features are unavailable for OrioleDB projects. * OrioleDB projects now follow the standard eligibility checks and page flow for scheduled backups. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cd305313e4 |
fix(roles): Show only document-defined roles (#51087)
## Problem As part of having `None / No Access` available to customers, we need to start providing this role entry in `/platform/organization/:ref/roles` endpoint. However, when making it available, the role will show up prematurely on all the components that relies on `useOrganizationRolesV2Query` function. ## Solution This change is to allow us to test the behavior of the new role without having to turn the API on/off. The UI will show only the "predefined" entries and ignore the "extras" sent by API. After this is merged, we will do the following 1. Unhide the None role from the API https://github.com/supabase/platform/pull/39137 -- this will not have any effect on the frontend as we already ignore it in this PR 2. Work and continue testing on https://github.com/supabase/supabase/pull/50922 -- which will be easier to verify as we no longer need to change the API side ## Review instructions 1. Modify the items in the `FIXED_ROLE_ORDER` list, remove some roles from there 2. You will see that the role will disappear from the components like the invitation form or managed access form. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Bug Fixes** * Organization role lists now show only supported roles, in the expected order. Roles outside the supported set are no longer displayed. This keeps the list consistent and focused on recognized roles, making available organization roles easier to review. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ec6be68356 |
chore: Bump vulnerable deps (#50901)
This PR bumps the vulnerable dependencies `devalue`, `mermaid`, `@faker-js/faker`, `brace-expansion`, `undici`, `fast-uri` and `markdown-it`. It also dedupes `rolldown`, `vite` and various `react-router` deps. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated development and build tooling for Lite Studio, Studio, and the Vue block, along with tooling used in automated Studio checks. These changes do not alter app features or workflows, and no new user-facing capabilities or behavior changes are included. They are limited to the project’s underlying development setup. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c5b4fbfa11 |
fix: Handle NO_PROJECT_MARKER for projectRef (#51083)
Skip `NO_PROJECT_MARKER` values for projectRef in API validation. |
||
|
|
92952bf903 |
fix(studio): clarify S3 access key dialogs (#51070)
## Problem The S3 access key creation dialogs are wider than their contents, use plural titles for one key pair, and call the name field “Description” even though the table calls it “Name”. The save state also implies both values disappear, although only the secret does. ## Solution Use the small dialog size for both states. Use singular titles, label the field “Name”, shorten the create button to “Create”, and clarify when the secret must be copied. The API field remains `description`. ## Review instructions 1. Open a project’s **Storage > S3** page and select **New access key**. Check the dialog width, title, Name field, and Create button. 2. Create a key and check the save dialog width, singular title, and secret visibility guidance. | Before | After | | --- | --- | | <img width="1084" height="572" alt="CleanShot 2026-09-30 at 14 37 20@2x" src="https://github.com/user-attachments/assets/781706ee-0ecc-4535-abb5-f6ac65f02c71" /> | <img width="844" height="584" alt="CleanShot 2026-09-30 at 14 36 56@2x" src="https://github.com/user-attachments/assets/119df19f-2f39-4e23-94b4-26665583765c" /> | | <img width="1096" height="730" alt="CleanShot 2026-09-30 at 14 37 57@2x" src="https://github.com/user-attachments/assets/00481ed7-dc05-48b9-8cbc-e76d608aa4b1" /> | <img width="842" height="780" alt="CleanShot 2026-09-30 at 14 37 39@2x" src="https://github.com/user-attachments/assets/8c837101-250a-474f-a0fc-cf46ce491f83" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * The credential form now labels the field “Name” and uses “Create” for the submit button. * Confirmation text now clarifies that the access key is bucket-wide, bypasses RLS, and its secret is shown only once. It also refers to a single access key instead of using S3-specific wording. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
38b74af3f1 |
fix(studio): fall back for framework icons without an asset (#51065)
I made the connected-project framework icons fall back when no shipped SVG exists for a framework. The three icon sites built `/img/icons/frameworks/<framework>.svg` straight from the integration's framework preset, which is an open-ended string. They only fell back when the value was empty, so any preset without an asset (`express`, `hono`, `fastapi`, `tanstack-start` and others) showed a broken image and logged a 404. **Changed:** - **Broken framework icons**: `getFrameworkIconUrl` returns the asset URL only for slugs in a set that mirrors `public/img/icons/frameworks/`. The integration connection row, the org project linker and the marketplace project picker now show their existing fallback icon for any other slug. A test keeps the set equal to the directory listing. - **Framework type**: I deleted the hand-kept `VercelFramework` union. It listed exactly the shipped icon slugs, while the API types the field as `string | null`, and that mismatch is what made the old empty-only check look safe. **Note:** I rejected an `onError` fallback because the browser still sends the 404 request. Adding logos for common presets is left for design. ## To test Tested on Vercel preview (staging): no real connection there uses these presets, so I rewrote the org integrations response in the browser to give one integration four connections. - [x] Open an org's Integrations page with connections whose framework has no shipped icon (`express`, `eve`, `tanstack-start-lovable`). Expect the fallback badge and no request under `/dashboard/img/icons/frameworks/` for those slugs. Observed: all three rows showed the badge and the network log had no request for their SVGs. - [x] Same page with a `nextjs` connection. Expect its framework logo. Observed: `nextjs.svg` loaded with a 200. - [x] Same page with the real, unmodified response (one connection with `framework: null`). Expect the badge, no frameworks requests, and no new console errors. Observed: as expected. ## Linear - fixes GROWTH-1309 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Vercel integration and project views now display framework icons when available and fall back to the Vercel icon when no matching icon exists. * Framework metadata now supports values beyond a fixed list, while unsupported frameworks continue to use the fallback icon. * **Tests** * Added coverage for supported and unsupported framework icons, including base-path handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9690efeb42 |
fix(vault): link to current dashboard route (#51058)
I updated first-party Vault links to open the current secrets route directly. Wrapper credentials, extension metadata, and blog posts still linked to the retired path and relied on a redirect. ## To test On the preview: - [x] Inspect a Wrapper credential's Vault link. Expect `/integrations/vault/secrets` with a `search` query for that credential. - [x] Open the inspected target URL. Expect Vault to show the matching secret. - [ ] Click a Wrapper credential's Vault link. Expect the filtered Vault view. - [ ] Open the pgsodium extension's Vault link and a Vault blog link. Expect `/integrations/vault/secrets` without the retired route in the address bar. ## Linear - fixes GROWTH-1312 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Vault secrets links now direct you to the project’s Integrations page, including links from wrapper metadata, blog articles, and the `pgsodium` extension listing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e0e58f8814 |
fix(studio): redirect moved dashboard routes (#51056)
I added permanent redirects for the moved Dashboard routes that still send visitors to 404s. Project and organization identifiers carry through, while the old project billing path opens the organization picker for billing. **Note:** The bare `/dashboard/project` path redirects straight to Organizations instead of the `/dashboard/projects` hop named in GROWTH-1295, since `/projects` already redirects there. ## To test Tested on the Studio preview: - [x] Requested the eight old Dashboard paths in GROWTH-1295 while signed out. Each returned 308 with the specified destination. - [ ] Request bare `/dashboard/project` while signed out on the latest preview. Expect a single 308 to `/dashboard/organizations`. - [x] Requested a project backup path with a query string. The destination kept the project ref and query string. - [x] Requested `/dashboard/project/_`. The project picker remained reachable. ## Linear - fixes GROWTH-1295 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Added permanent redirects for legacy Studio routes covering account and project pages, backups, email templates, edge-function logs, secrets, and billing settings. * Redirects preserve incoming query parameters and URL fragments; the project selector remains unaffected. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
68d5011514 |
fix(studio): hide secret visibility controls in pipeline edit forms (#51010)
## Problem Pipeline edit forms hide stored credentials but still show visibility controls beside their placeholders. The controls suggest that the stored secret can be revealed. ## Solution - Hide visibility controls in edit mode for ClickHouse, Snowflake, DuckLake, and Analytics Bucket secret fields. - Keep the controls available when creating a destination, with accessible labels for the DuckLake and Analytics Bucket controls. | Before | After | | --- | --- | | <img width="1024" height="196" alt="CleanShot 2026-09-29 at 16 48 56@2x" src="https://github.com/user-attachments/assets/a9da9a32-ab17-4c07-abf3-dfa88b8c6475" /> | <img width="1024" height="168" alt="CleanShot 2026-09-29 at 16 47 23@2x" src="https://github.com/user-attachments/assets/fddeb880-cd23-4752-ae73-8f27348c647f" /> | ## To test 1. Open **Database → Pipelines** and edit a destination of each type: ClickHouse, Snowflake, DuckLake with custom parameters, and Analytics Bucket. Check that the hidden secret fields have no eye button. 2. Start creating each destination and check that its secret fields still offer a working visibility control. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary * **Improvements** * Secret fields in replication destination forms remain masked when editing an existing destination, and their visibility controls are hidden. When creating a destination, supported secret fields can be revealed. * **Accessibility** * Catalog-token visibility controls now use dynamic, descriptive labels. DuckLake catalog URL and S3 secret-key reveal controls also have descriptive labels. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |