6632 Commits
Author SHA1 Message Date
Jordi Enric d2ffd76395 perf(logs): load pathname facet counts on demand DEBUG-230 (#51112)
## Problem

Unified Logs included a pathname aggregation in every initial sidebar
count query, even when the pathname filter was closed. This issue is
tracked in
[DEBUG-230](https://linear.app/supabase/issue/DEBUG-230/fetch-sidebar-counts-only-when-needed).

## Fix

Remove pathname aggregation from the initial ClickHouse and BigQuery
count queries while keeping the existing shared count scans. Fetch
scoped pathname options through the existing facet query when the filter
opens or its search changes. Order limited pathname results by count,
validate response rows with Zod, and retain selected paths during
loading and validation errors. Use live sidebar filters while their URL
update is pending and URL filters after navigation. Cache results by
project and filter scope, and wait for feature flags before requesting
options.

## How to test

- Open Unified Logs, then open Pathname and search. Confirm options load
on demand.
- Change the time range, another filter, or navigate through browser
history. Confirm the options reflect the current scope.
- Close and reopen Pathname without changing the scope. Confirm cached
options return.
- Run the pathname filter component tests and Studio typecheck.
2026-10-06 16:38:30 +02:00
Joshen Lim eb20a4674d getTableDefinitionSql to escape SQL identifiers (#51258)
## Context

Similar to domain to https://github.com/supabase/supabase/pull/51256 -
`getTableDefinitionSql` doesn't escape SQL identifiers, which generates
invalid SQL on the dashboard's table editor for the "Copy table schema"
CTA, or the table definition tab.

Also fixes the "Copy table schema" CTA which was missing the `scoped`
parameter when calling `getTableDefinition`

Changes here addresses this issue, can test with a table named like
`test"table`
2026-10-06 21:34:36 +08:00
K-Dog (Kevin) 1da25a7e72 chore(hipaa): self-serve PITR (#51342)
There is no reason why HIPAA customers cannot self-serve PITR add-on.
Instead of telling customers to reach out to support, let them
self-serve it.

- Docs also wrongfully stated the need for Small compute add-on.
- Ability to self-serve PITR
- Only 28-day PITR available
- Price is now also correct and displays $0 (pending backend change)

When enabled (marked as HIPAA compliant):
<img width="1128" height="216" alt="Screenshot 2026-10-06 at 1 53 01 PM"
src="https://github.com/user-attachments/assets/d83982e7-c71b-4236-ab29-67f85fc40f39"
/>

When not enabled (marked as HIPAA compliant):
<img width="1132" height="255" alt="Screenshot 2026-10-06 at 1 53 55 PM"
src="https://github.com/user-attachments/assets/f182813b-2163-4905-8cdf-9c69983ec1b9"
/>

<img width="772" height="542" alt="Screenshot 2026-10-06 at 1 56 08 PM"
src="https://github.com/user-attachments/assets/2cd59439-74b9-49d6-90d1-47c8d1722c9f"
/>
2026-10-06 15:11:55 +02:00
Joshen Lim 23e7bbcdc6 Joshenlim/fe 3359 fix user permission UI for orgs with thousands of projects (#51329)
## Context

Adds virtualization to the organization team members page - browser
performance was facing issues for organizations with a large amount of
members (e.g 1000+), primarily due to some computation within
`MemberActions.tsx`, so virtualization addresses this by controlling the
number of member rows being rendered in the DOM at any one time.

<img width="1182" height="435" alt="image"
src="https://github.com/user-attachments/assets/e3da7036-c1c8-4d73-a363-85ecbdb79179"
/>


## Unrelated changes
- Updated `TeamSettings` to use the `PageContainer` components for UI
consistency
- Updated user `ProfileImage` to render the first alphabet of the email,
rather than a generic user icon
<img width="275" height="126" alt="image"
src="https://github.com/user-attachments/assets/17eae3b1-c527-4b8f-afcd-c5151bdaf869"
/>
- Updated row heights of member rows to be more smaller
- Updated MFA column to use tooltips with a clearer CTA for members that
don't have MFA enabled
<img width="332" height="144" alt="image"
src="https://github.com/user-attachments/assets/a479af31-7fec-454d-b64e-e6314fd6d55e"
/>
- Added a filter for MFA status  
<img width="375" height="177" alt="image"
src="https://github.com/user-attachments/assets/fd87105e-524d-4ded-b471-769592be96c7"
/>


## To test
- Can override the content for the `members` network request with the
following sample JSON, main thing is just to test that initial load +
searching should not run into any significant browser performance
issues.

[members-response-1000.json](https://github.com/user-attachments/files/33100317/members-response-1000.json)
- Can also test on production that this mock response does indeed cause
browser performance issues as well
2026-10-06 06:41:39 -06:00
089133cc2c feat(storage): add bucket object versioning form fields (FE-4161) (#49203)
| # | Branch | Base |
| - | ------ | ---- |
| 1 | `feat/storage-versioning-private-alpha` — merged | `master` |
| 2 | `feat/storage-versioning/002-bucket-form-fields` ◀ | `master` |
| 3 | `feat/storage-versioning/003-bucket-modals` | 2 |
| 4 | `feat/storage-versioning/004-object-versions-data` | 3 |
| 5 | `feat/storage-versioning/005-file-preview-versions` | 4 |
| 6 | `feat/storage-versioning/006-billing-storage-retention` | 5 |
| 7 | `feat/storage-versioning/007-archived-objects-data` | 6 |
| 8 | `feat/storage-versioning/008-archived-rows` | 7 |
| 9 | `feat/storage-versioning/009-archived-preview-pane` | 8 |
| 10 | `feat/storage-versioning/010-replace-file` | 9 |

## [2/10] Storage object versioning: bucket form fields

The object versioning + lifecycle policy form section for the create and
edit bucket modals.
Mounted onto the ui in PR 3 #49205 

- `BucketVersioningFields` — the versioning switch and the suspension /
public-bucket / retention-tightening warnings
- `LifecyclePolicySection` — the retention window and version cap inputs
- `ExpirationModeToggle` — how the two conditions combine (and / or)
- `BucketVersioningFields.schema.ts` — zod fields the parent modals
spread into their own schema, plus `superRefineBucketVersioning`
- `BucketVersioningFields.utils.ts` — retention-tightening detection
- `StorageVersioning.constants.ts` — versioning state and expiration
mode types, the prefill defaults, and `getBucketVersioningState`

Note: a single s3 lifecycle policy expects both `version_expiry_days`
and `max_noncurrent_versions` and always evaluate the two fields within
the same policy with an AND logic. To enable both AND and OR/EITHER
logic, we save two distinct s3 policies so we can enforce the OR logic.

See demos and how to reproduce in #49205 

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **New Features**
* Eligible projects with the preview enabled can configure object
versioning for storage buckets, including version expiration,
retained-version limits, and “and/or” lifecycle conditions.
* Settings default to 30 days and 10 retained versions, with validation
for retention values and requirements for setting a version limit.
* Notices highlight public buckets, missing lifecycle conditions,
suspending existing versioning, and changes that tighten retention
limits.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-06 14:24:50 +02:00
Beng Eu 53a637a359 fix(studio): don't watch Next's .next build output in TanStack dev (#51308)
## Problem

Switching a local checkout from `STUDIO_FRAMEWORK=next` to `tanstack`
leaves `apps/studio/.next` behind, including a full `node_modules` copy
under `.next/standalone`. Vite's dev server watches all of it, logging
hundreds of `page reload .next/server/pages/...` lines and wasting file
handles.

## Change

Add `**/.next/**` to `server.watch.ignored` in
`apps/studio/vite.config.ts`. Vite's default ignores (`.git`,
`node_modules`) still apply.

## Verification

With a stale `.next` present, ran `STUDIO_FRAMEWORK=tanstack pnpm run
dev`, touched `.next/server/pages/account/me.html`: no reload logged
(previously ~220 `.next` reloads on startup).
2026-10-06 14:38:04 +08:00
Joshen LimandGildas Garcia dc95335a8d Joshenlim/fe 4068 warn users ai assistant history can be wiped (#51260)
## Context

Chats with the AI Assistant is currently stored locally on the browser
and not synced across devices which caused a bit of confusion for some
users when they realised they couldn't access their chat histories on
different devices. (Ideal state tbh is to persist the chat
conversations, but that'll need support on the BE)

PR here just adds a foot note to both the chat history dropdown in the
side panel + chat nav for the explorer regarding this - opting for
something with a small footprint
<img width="293" height="322" alt="image"
src="https://github.com/user-attachments/assets/284ee0c1-16bf-432b-b473-29ee048ed4cc"
/>
<img width="392" height="956" alt="image"
src="https://github.com/user-attachments/assets/e5eb1409-fa63-4dae-9439-86facbe41277"
/>

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-10-06 11:37:26 +08:00
Joshen Lim 2538f7eb29 Fix unescaped SQL identifiers in row export (#51256)
## Context

Resolves https://github.com/supabase/supabase/issues/49977

Addresses an issue in `formatTableRowsToSQL` to use `ident` for schema,
table, and column name which will handle escaping of SQL identifiers.

Can verify fix by creating a table like `test"table`, then adding some
rows, and selecting either Copy as SQL or Export as SQL
2026-10-06 11:35:01 +08:00
Joshen Lim be1ba651ed Add branching nav items to cmd k (#51255)
## Context

Adds a couple of branching nav items to Command K
- Create new branch
- Branch management
- Merge requests
- Github Connection (For branching)
- Branching feedback

Switch branch is still available, and only visible after a branch has
been created (status quo)

<img width="610" height="531" alt="image"
src="https://github.com/user-attachments/assets/3068184e-889d-44ed-8cf6-2afd59ffb109"
/>
2026-10-06 11:12:53 +08:00
Joshen Lim 642a02db49 Prevent enabling spend cap if org has projects with RRs (#51253)
## Context

Prevents organizations from enabling spend cap if the org has projects
with read replicas - We currently gate creation of read replicas to
ensure that orgs have spend caps disabled, but were missing the guard
for the other way around
<img width="662" height="378" alt="image"
src="https://github.com/user-attachments/assets/44ad036c-4c1b-48e8-beb7-f16f6170c9fb"
/>

## Other changes involved
- Refactored to use new `Sheet` and `Table` components in
`SpendCapSidePanel`
2026-10-06 11:12:35 +08:00
Pamela Chia 20d6f2197f chore(studio): remove privacy policy notice (#51299)
I removed the Studio Privacy Policy update notice that #50397 added on
2026-09-16, when Privacy Policy v4 took effect. It has been up for
almost three weeks, and the ToS v4 banner (#51109) goes out next. I did
the same in #44380, removing the March 2026 privacy notice after 15
days.

This is the exact inverse of #50397: the banner component and its test,
the banner ID, the dismissal local storage key, and the org-landing path
helper that only this notice used.

## To test

Tested on Vercel preview:
- [ ] In a fresh browser profile (no
`privacy-policy-update-2026-09-16-dismissed` key), open
`/organizations`: expect no Privacy Policy notice
- [ ] Open `/org/<slug>`: expect no Privacy Policy notice and the
project list renders normally
- [ ] Open a project's Logs page: expect the logs deprecation banner
behavior unchanged (only shows before its expiry)

## Linear
- fixes GROWTH-1322
2026-10-05 19:24:14 -07:00
Danny White 0cb8bd95dd feat(studio): add spot colour control to Appearance (#50782)
## Problem

The theme's primary hue can change in CSS, but Appearance had no way to
try other spot colours. That makes it hard to find controls whose colour
still depends on the fixed Supabase brand palette.

## Solution

Add a **Spot color** control under Appearance → Theme colors
(employee-only via ConfigCat `appearanceSpotColor`, targeted to Supabase
Team Email).

### Spot color UX
- Rainbow spectrum track with a thin outline so pale tracks stay visible
- Live trifecta swatches for `--primary-solid`, `--primary`, and
`--primary-bright` (darkest → lightest) next to the degree readout
- Drag updates are rAF-batched so React paint and CSS preview stay to
one frame

### Canvas tint coupling
- `--surface-hue` is derived in CSS as `calc(var(--primary-hue) +
var(--surface-hue-offset))`
- Dark: offset `0` (same hue as spot)
- Light: offset `180` (complementary canvas tint; brand green ≈157.5° →
rose ≈337.5°)
- No JS override of `--surface-hue`. Changing Spot color moves primary
controls and the low-chroma canvas tint together

### Other theme sliders
- Renamed **Color intensity** → **Surface tint** (it only drives the
neutral ramp via `--chroma`, not spot chroma)
- Meaning-shaped tracks for every knob (spectrum, grey→tint, soft→hard,
dark→light, flat→lift)
- Same outline treatment on those tracks

| Before | After |
| --- | --- |
| <img width="1476" height="2174" alt="CleanShot 2026-10-05 at 15 02
21@2x"
src="https://github.com/user-attachments/assets/d08b0fa8-32af-450e-adce-861f59c9d6ca"
/> | <img width="1474" height="2354" alt="CleanShot 2026-10-05 at 14 56
35@2x"
src="https://github.com/user-attachments/assets/9a1e6183-a4ba-4c8e-a458-bb0eea946db8"
/> |
| _Anyone else_ | _With staff flag, custom settings_ |

## Review instructions

1. Confirm ConfigCat flag `appearanceSpotColor` is on for your staff
account (or flip it in the Dev Toolbar).
2. Open `/account/me` → **Appearance → Theme colors**.
3. Without the flag: Spot color is hidden; other theme sliders still
work.
4. With the flag: drag Spot color in light and dark. Primary controls
and canvas tint should move together; Supabase brand assets should stay
fixed.
5. Raise Surface tint and confirm the canvas hue follows the
complementary (light) or same-hue (dark) offset.
6. Refresh, switch modes, and use **Reset** to check persistence and
defaults.
2026-10-06 10:11:26 +11:00
09a245d72d [FE-4520] fix(studio): hide Realtime setup for published tables (#51152)
The Realtime Inspector now checks the Realtime publication before
showing setup guidance. Projects with published tables get the
join-channel view even before this Inspector session receives any
messages; unconfigured projects keep the setup guide.

Setup guidance also stays hidden while publications are loading or
unavailable. Joining a channel and displaying received messages retain
their existing behavior.

Addresses
[FE-4520](https://linear.app/supabase/issue/FE-4520/realtime-inspector-ui-implies-i-am-not-using-realtime-despite-already).

## To test

- With no tables in `supabase_realtime`, open Realtime → Inspector and
confirm the setup guide appears.
- Enable Realtime on a table and confirm a client receives a database
change. Open the Inspector without joining a channel: it should show
“Join a channel to start listening to messages” and no setup guide.
- Join a channel, trigger a table change, and check the event and
payload appear. Stop listening and confirm messages remain visible.
- Open Policies, then return to the Inspector and confirm the setup
guide stays hidden for the configured project.
- Join a broadcast-only channel with no incoming messages and confirm
the messages view appears immediately.

## Validation

Reproduced the original prompt locally with a working Realtime table,
then verified the fix in the browser, including an independent client
subscription, a live INSERT in the Inspector, navigation, stopping, and
the unconfigured state. Temporary test data and services were cleaned
up.

All nine new regression tests pass; four fail against the original code.
Typecheck, formatting, lint ratchet, Knip, and the case-sensitivity
check pass. The full Studio suite passed 7,799 tests with one unrelated
Explorer test failure; that test passed on a focused rerun alongside the
Inspector tests.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* The Realtime inspector keeps the messages view visible while
publication status is loading or unavailable, and when a channel is
joined or messages are present.
* Setup guidance appears only after publications load successfully and
confirm that Realtime is unavailable, with no channel or messages to
show. This includes cases where there are no publications, the Realtime
publication has no tables, or only a differently named publication
exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-05 12:05:21 -07:00
Jordi Enric 7d04c43082 fix(logs): default unified logs to otel DEBUG-228 (#51089)
## Problem

Unified Logs could start legacy BigQuery requests while ConfigCat
loaded, then switch to OTEL when the flag resolved.

## Fix

Default Unified Logs to OTEL unless otelUnifiedLogs is explicitly false.
Use that selection for list, count, chart, facet, detail, download, and
manual refresh requests. Keep BigQuery as an explicit opt-out until the
legacy backend is removed.

## Validation

- Studio typecheck passed locally.
- Existing Unified Logs utility tests passed (21 tests).
- The focused Unified Logs query test file was removed as requested;
backend-selection and manual-refresh regressions are no longer covered
by that suite.
- CI checks are running on the current head.

Tracks
[DEBUG-228](https://linear.app/supabase/issue/DEBUG-228/prevent-bq-queries-before-the-feature-flag-loads).
2026-10-05 17:43:15 +02:00
kemal.earthandAli Waseem b028908136 feat(studio): add never option to scoped pat expiry (#51273)
## Problem

When building scoped pat's we had omitted the option to have them never
expire.

## Solution

This re-adds the option to select "never" and it comes with the caveat
of an admonition to warn the user that they would need to manually
delete or revoke this token.

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. Open /account/tokens
2. Click Generate new token.
3. Open Expires in. Confirm "Never" is the last option, after "Custom",
and has no Recommended badge.
4. Select Never. A warning admonition appears directly below the expiry
row: "This token never expires — Anyone with the token keeps access
until you delete it."
5. Pick an org and project, grant one permission, click Review access.
Summary shows Expires: Never.
6. Create the token. The POST body has no expires_at, and the new row's
Expires column reads Never.

Fixes FE-4527.

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-10-05 16:42:17 +01:00
Matt Rossman 87681812a0 fix(studio): assistant get_active_incidents url in prod (#51047)
The Assistant's `get_active_incidents` tool has [failed in prod 99.8% of
the time over the past 60
days](https://supabase.slack.com/archives/C051L8U2EJF/p1790712805774689),
so users reporting outages get told it couldn't check incident status.
The failures never showed up as errors, which is why nobody noticed.

The Assistant now includes the `/dashboard` base path when it calls its
own API routes, so the tool stops hitting a 404 in prod
([`/api/incident-status`](https://supabase.com/api/incident-status) is a
404,
[`/dashboard/api/incident-status`](https://supabase.com/dashboard/api/incident-status)
is a 200). The tool also throws on a failed fetch now instead of
returning an `{ error }` result. That way failures show up as span
errors in Braintrust and as a failed tool call in the UI. The model
still gets the error message and tells the user it couldn't check.

When the fetch fails (in dashboard):

| Before (prod) | After (local, path temporarily broken) |
| --- | --- |
| <img width="1036" height="784" alt="CleanShot 2026-09-29 at 5 08 49
PM@2x"
src="https://github.com/user-attachments/assets/4539f968-4aa6-49a5-8c7f-7911b6b497a0"
/> | <img width="1026" height="716" alt="CleanShot 2026-09-29 at 5 08 06
PM@2x"
src="https://github.com/user-attachments/assets/7c9a565c-efe1-4d1a-901b-e440bbb5a739"
/> |

When the fetch fails (in Braintrust):

| Before (prod) | After (local, path temporarily broken) |
| --- | --- |
| <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 07
PM@2x"
src="https://github.com/user-attachments/assets/87860568-b50f-49ee-98fd-4c82f14d1913"
/> | <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 10
PM@2x"
src="https://github.com/user-attachments/assets/64f58d47-e083-464e-b8d0-8b9c57710a05"
/> |

When the fetch works (local):

| Dashboard | Braintrust |
| --- | --- |
| <img width="1054" height="808" alt="CleanShot 2026-09-29 at 5 20 58
PM@2x"
src="https://github.com/user-attachments/assets/1c9e4cf8-79f0-48e6-b95a-1694fc00a9f9"
/> | <img width="2918" height="1144" alt="CleanShot 2026-09-30 at 9 07
03 AM@2x"
src="https://github.com/user-attachments/assets/0d2b9685-57a9-4028-a451-272b3de8e23a"
/> |

Ran it locally with tracing on. Here's a [successful
call](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=251bcd44-c55b-44bb-9ce2-b034b26f8832),
and one with the path temporarily broken, which now [logs a span
error](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=637f2dc8-f65b-4d65-9d86-0511b36e8685).
Local dev has no base path, so the prod URL is covered by the new
`getBasePathURL` tests.

Closes AI-1272




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Incident lookups now report fetch, HTTP, parsing, and validation
errors rather than returning an empty incident result.
* AI SQL generation now accounts for the configured site base path when
building its service URL.
* **Improvements**
* Site URLs now handle trailing slashes and existing base paths
consistently, avoiding duplicate path segments.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 09:37:51 -04:00
0c2257fb3d feat(studio): scoped oauth data layer (#49476)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

~~This is the first part (and ultimately the final part of the stacked
PR). PR 1 introduces mock data for us while we build the requirements of
the scoped oauth interstitial, all following PR's will be stacked on top
of this one.~~

This is the first part, the data layer side. We began with mock data,
but as backend support arrived we've used this PR to help us shape the
UI as well as the frontend data layer. This now acts as the frontend
data layer.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added OAuth app authorization request handling.
* Added visibility into application details, requested scopes, and
existing authorizations.
  * Added organization and project selection during authorization.
  * Added organization roles and project access details.
  * Added approval and denial options with secure redirect handling.
* Added validation for required authorization details and project
selections.
  * Added support for role validation feedback during approval.
* Added representative authorization scenarios for approved, denied, and
re-consent flows.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Co-authored-by: Samir Ketema <6003000+samirketema@users.noreply.github.com>
2026-10-05 15:20:21 +02:00
Charis de41b029ef always use canonical link for new status page (#51264) 2026-10-05 09:18:24 -04:00
0d8b1417bc [bot] Decrease ESLint ratchet baselines (#51225)
Automated weekly decrease of ESLint ratchet baselines.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
2026-10-05 13:16:39 +00:00
Tanun Turbo Chalermsinsuwan 77e3b4382f feat(role): Allow eligible organizations to invite users as 'No-access' base role (#50922)
## Problem

As the API has allow inviting users into `None / No-access` role for
team, enterprise, and platform tier organization, we need to update the
documentation and descriptions for this new role on the invitation form.

## Solution

1. Updated `apps/docs/content/guides/platform/access-control.mdx` to
include the role
2. Added the role description on
`apps/studio/components/interfaces/Organization/TeamSettings/Roles.constants.tsx`
3. Add the roles into the proper sorting order at
`apps/studio/data/organization-members/organization-roles-query.ts`
4. Add logic to invitation components to disable the role when inviting
user into project(s), as the backend does not allow it.

## Testing and verification steps
The UI:
https://studio-staging-aa8is1m07-supabase.vercel.app/dashboard/org
Documentation:
https://docs-kht98bi78-supabase.vercel.app/docs/guides/platform/access-control

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **Updates**
* The **None** role is labeled **No-access** and describes the lack of
organization and project resource access.
* **None** is included after **Read-only** in the role list. When
inviting a member with project-only access, **None** is disabled with an
explanation.
* **Documentation**
* Clarified plan coverage for **Read-Only** and **No access**, and added
guidance on assigning **No access** at the organization level before
granting project-specific roles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 19:54:55 +07:00
Charis 01bfab39d6 studio: improve warning for replicas on spend cap (#51179)
## Summary

The "> 8 GB warning" when spend cap enabled used to be conflated with
the "has replicas with spend cap" warning, which causes a confusing
error message.

Opting to split them out into 2 separate warnings to give the user a
better description of the problem.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Read replicas alone no longer trigger the disk-size threshold warning.
* **New Features**
* When usage billing is disabled, a warning appears if read replicas are
present and no project exceeds 8 GB, with guidance on next steps.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 11:46:32 +00:00
kemal.earth cb52c0f425 chore(studio): update segment control in view permissions to ds one (#51125)
## Problem

We were using a custom segment control. Recently we introduced segmented
toggle groups in our design system. The old one is inconsistent and
doesn't match anything else.

## Solution

Replace segmented control with [this
one](https://supabase.com/design-system/docs/components/toggle-group#segmented).

| Before | After |
|--------|--------|
| <img width="777" height="85" alt="Screenshot 2026-10-01 at 11 36 47"
src="https://github.com/user-attachments/assets/84e28075-248d-42d4-a537-f18cd2fe86db"
/> | <img width="783" height="95" alt="Screenshot 2026-10-01 at 11 37
00"
src="https://github.com/user-attachments/assets/1071f031-8e96-4db1-8ea1-36cb34e9923a"
/> |

## Test plan
- [ ] Go to Account Settings → Access Tokens, create a new scoped token,
and on the capability review step confirm the All/Read/Read-write
segmented control renders correctly and filters the capability list as
expected
- [ ] Open an existing scoped token's "View" sheet and confirm the same
segmented control filters correctly there too
- [ ] Verify keyboard navigation (arrow keys) and that exactly one
option is always selected (no deselect state)
- [ ] Visual check against the design system's segmented `ToggleGroup`
styling (no leftover custom border/divider artifacts from the old
implementation)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated the capability-level selector to use a segmented control.
Selection behavior remains unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 10:11:13 +01:00
Joshen Lim 838fcaaa89 Joshenlim/fe 4509 fdw general UI consolidation and refactor (#51079)
## Context

Stacks on top of https://github.com/supabase/supabase/pull/51074

PR's just mainly refactoring, no visual differences:
- `CreateWrapperSheet` + `EditWrapperSheet` use the same UI components
for the foreign tables section
  - Can be consolidated into one reusable component
- `WrapperTableEditor` is still using `SidePanel` component
  - Can be swapped to use new `Sheet` component
- Refactor `WrapperTableEditor`'s layout a little - added separators for
clarity between sections
<img width="400" alt="image"
src="https://github.com/user-attachments/assets/b1983bf2-cff5-43eb-8b31-40a7abb65038"
/>
- Update `getCreateFDWSql` to just use the Foreign Data Wrapper's name
from `wrapperMeta` since its now standardized

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a shared foreign-table selector for wrapper setup and editing,
with options to view columns, add or edit table definitions, and remove
tables.
  * Updated the table editor to use a sheet layout with a fixed footer.
* **Bug Fixes**
* Wrapper creation now uses the wrapper’s configured name when creating
the server.
* Foreign-table targets display the table name when other target details
are unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 16:20:50 +08:00
Joshen Lim 521881a899 Joshenlim/fe 4480 fdw create wrapper to only init fdw once users to name the (#51074)
## Context

PR here refactors the way we manage Foreign Data Wrappers in the
dashboard (Under Project -> Integrations), as there's some DX problems
with the current behaviour.

Currently whenever a user creates a new wrapper, the dashboard is
creating both the Foreign Data Wrapper (`create foreign data
wrapper...`) + server (`create server ...`). The former is
**_redundant_** to create multiples of given that it just handles the
`handler` and `validator`, whereas what matters more is the server which
holds the connection credentials. Hence standard practice is usually one
Foreign Data Wrapper with multiple servers. (The former just needs to be
created once if not done yet)

This also led to some problems as well when users created their own
wrappers via SQL and tried to manage them through the dashboard GUI,
leading to us having to add some guard rails to prevent managing
wrappers sharing the same Foreign Data Wrapper
([ref](https://github.com/supabase/supabase/pull/50785))

## Changes involved
- When creating a wrapper, if the Foreign Data Wrapper has yet to be set
up for the wrapper type, the dashboard will initialize one and
subsequently use that same Foreign Data Wrapper for any new wrappers
- When creating / editing a wrapper, users will name the **server**
instead of the **wrapper**
<img width="500" alt="image"
src="https://github.com/user-attachments/assets/b3e61204-0e16-4599-84ac-af2aab5b93c2"
/>
- When deleting a wrapper, the clean up for vault secrets are now
deterministic by referencing the wrapper's server options
- RE backwards compatibility: Existing wrappers will _not_ be affected
by the changes here - they can be edited / deleted as per normal

## Unrelated fixes + UI refactors added
- Fix Iceberg Wrapper not showing the right form when adding new wrapper
- Adjust form layouts in side panel to be horizontal instead of vertical
(Follows Database -> Pipelines)
- Clean up to use newer UI components like `ButtonTooltip`
- Opt to hide Docs + Create CTA under `WrappersTab` if marketplace
feature preview is enabled (Since these actions are already in the
header, will be duplicates)
- Consolidate foreign tables configuration for create + edit wrapper
sheet into one component `ForeignTablesSelector`

## To test
- [ ] Verify that existing wrappers with their own Foreign Data Wrapper
can be edited correctly
- [ ] Verify that existing wrappers with their own Foreign Data Wrapper
can be deleted
- [ ] Verify that existing wrappers with shared Foreign Data Wrapper can
be edited correctly
- [ ] Verify that existing wrappers with shared Foreign Data Wrapper can
be deleted
- [ ] Verify that new wrappers can be created
- [ ] Verify that newly created wrappers can be edited correctly
- [ ] Verify that newly created wrappers can be deleted
2026-10-05 16:00:37 +08:00
Gildas Garcia 5de3666930 Fix: storage explorer ignore current filter after mutations (#51174)
## Problem

When users trigger actions such as deleting an item, the storage
explorer reloads the opened folders but ignore the currently applied
filter.

## Solution

Move the filter state in Valtio so that its other functions are aware of
it.

## Review instructions

1. Create a Supabase project and upload objects in Storage with date
prefixes (e.g., 202608XX)
2. Navigate to Storage, select a bucket with multi-dated/prefixed
objects
3. Enter a filter in the search box (e.g., 20260820) to show only
matching objects
4. Select one or more filtered objects and delete them

Observe the file list after deletion - it should show filtered contents
according to the search box value


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Storage search now stays in sync as you open folders and refresh their
contents.
* When restoring open folders, search results are filtered in the
deepest open folder rather than hiding ancestor folders.
* Deleting a file from filtered results keeps the search applied and
displays the remaining matches correctly.
* Search results remain consistent across folder navigation, refreshes,
and file deletion.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 09:52:32 +02:00
Danny White ba82106697 chore(www + studio): remove expired Select 2026 promo banners (#51245)
## Problem

Supabase Select 2026 has finished. The promo banners already hide via
the scheduled expiry from #51006, but the campaign code, assets, and
wiring are still in the tree.

## Solution

Remove the Select 2026 sitewide promotion across www and Studio:

- Delete shared `Select26*` banner code, font, and tests from
`ui-patterns`
- Delete Studio `BannerSelect2026*` and its Banner Stack registration
- Unmount the www announcement banner and revert the State of Startups
spacing that only existed for it
- Drop the Select-only session-replay `data-band` allowlist entry and
lint ratchet baseline

Event go pages, blog posts, and other Select content are left alone. The
`Announcement` shell stays for the next campaign.

## Review instructions

1. Open the www homepage on the deploy preview. Confirm there is no
Select announcement bar above the nav.
2. Open `/state-of-startups` on the deploy preview. Confirm the hero
still looks correct with no extra top gap from the removed banner.
3. Open a hosted Studio dashboard page on the deploy preview. Confirm
the Banner Stack no longer shows a Select card.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)
2026-10-05 18:36:13 +11:00
Joshen LimandGildas Garcia acaf640d1c Joshenlim/fe 4522 polish recovery codes UI (#51124)
## Context

Just a couple of UI polishes for the recovery codes UI under Account
settings -> Security - all visual, no functional changes

## Changes involved

- Shift position of Recovery codes section below MFA
- Better hierarchy since recovery codes only matter after adding an MFA
app
  - Prevents layout shift with the feature flag as well

| Before | After |
|------|------|
| <img width="400" alt="image"
src="https://github.com/user-attachments/assets/3f24e30b-14b1-49cc-8942-0bd139af031b"
/> | <img width="400" alt="image"
src="https://github.com/user-attachments/assets/9a020b9b-4644-4e39-ba75-082e7f3a08db"
/> |

- Update how recovery codes are displayed

| Before | After |
|------|------|
| <img width="400" alt="image"
src="https://github.com/user-attachments/assets/9ce00013-9b7f-4ab9-9a10-0eec536022f5"
/> | <img width="400" alt="image"
src="https://github.com/user-attachments/assets/6bdc8c18-cfd2-46ea-a851-5a9fe03a5211"
/> |

- Update recovery codes modal, aligns "confirmation" UX to be more
consistent with scoped PAT
- Footer CTA is just "Done" that's disabled until either Copy or
Download is clicked
  - Copy CTA shifted below codes for contextual grouping
  - Also added download CTA, which just downloads codes in TXT

| Before | After |
|------|------|
| <img width="534" height="389" alt="image"
src="https://github.com/user-attachments/assets/55cdbe9f-f37c-4284-b2ac-46834fd14437"
/> | <img width="533" height="548" alt="image"
src="https://github.com/user-attachments/assets/ab091822-e5fc-464c-94e6-f1d6b6792c59"
/> |

- Show success toast after codes are successfully deleted
- Use warning variant for regenerate confirmation dialog





<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Recovery codes are displayed as a numbered list, with separate options
to copy or download them.
* You must confirm that you’ve saved the codes before closing the
success dialog.
* **Improvements**
  * Generation buttons show when codes are being created.
* Recovery-code actions have updated layouts, icons, and confirmation
styling. Available codes are identified as single-use, and loading
errors are displayed in an alert.
* Removing codes displays a success message before the confirmation
dialog closes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-10-05 14:15:17 +08:00
Danny White 52f34c3097 fix(studio): drop brand override on last-used sign-in badge (#51248)
## Problem

The Sign in **Last used** badge overrode `Badge variant="success"` with
`bg-brand-400`, which reads as lime in light mode instead of the normal
success green.

## Solution

Remove the colour override so Last used uses the standard soft success
badge. No new Badge variant; no other callsite churn.

| Before | After |
| --- | --- |
| <img width="908" height="1292" alt="CleanShot 2026-10-05 at 14 19
27@2x"
src="https://github.com/user-attachments/assets/6890bf3d-90ce-423e-832a-0bbb0ecdf7cf"
/> | <img width="902" height="1280" alt="CleanShot 2026-10-05 at 14 31
15@2x"
src="https://github.com/user-attachments/assets/18b193a5-8015-4303-ac9a-a8d5981dd471"
/> |

## Review instructions

1. Open the Studio preview
[/sign-in](https://studio-staging-git-dnywh-1ce8f481-supabase.vercel.app/dashboard/sign-in)
(or the Vercel bot URL if it differs).
2. In DevTools: `localStorage.setItem('supabase-last-sign-in-method',
'email')`, then refresh.
3. Spot-check light and dark.
2026-10-05 16:16:03 +11:00
Joshen Lim 94b8b06eb2 Clean up auto region selection experiment (#51121)
## Context

Just cleans up the experiment that was introduced
[here](https://github.com/supabase/supabase/issues/50851) - can clean up
feature flag in ConfigCat thereafter too

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Project Creation**
* Removed the “Best available” region option. Choose a specific region
or smart group when creating a project; the selected region name appears
in the selector.
  * Recommended badges remain visible on recommended regions.
* **Telemetry**
* Project creation events no longer include details about the removed
region option or the initial region recommendation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 12:13:11 +08:00
Joshen Lim 39e13d3181 Fix dependency array in RouteValidationWrapper causing loop (#51170)
## Context

For staging and local only, if you opened the a table in the table
editor, then navigate out, and back into the table editor - the browser
freezes
- The TableEditor itself has a `useEffect` that reads that and redirects
to the last visited table when landing on `/editor`
- `router` is in the dependency array which for the TanStack build is
not a stable singleton, resulting in a redirect loop - so the main fix
was to remove `router` from the dependency array
- (Unrelated) Also cleaned up some logic in the redirect regarding
reading the tab ID

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved table editor redirects so they select the matching open table
tab from history or fall back to the first open table tab when
available.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 12:04:52 +08:00
Ali Waseem 7353782724 fix(studio): show compute waitlist notice when project is not enrolled (#51224)
Resolves FUNC-941

## What

When a project isn't enrolled in Compute, show a short notice with a
link to the waitlist (https://supabase.com/compute) instead of a generic
error.

## Why

The compute API returns its 404 as `{ "error": { "code", "message" } }`.
`handleError` only reads a top-level `message`, so it dropped the status
code, `isComputeUnavailable` never matched, and users saw "API error
happened while trying to communicate with the server." The query now
checks `response.status === 404` directly.

## Testing

- [ ] Project not enrolled in Compute: the waitlist notice shows
- [ ] Enrolled project: the instance list loads as before
2026-10-03 20:34:14 +00:00
Riccardo Busetti 4ab54b9359 ref(docs): Make ClickHouse, Snowflake and DuckLake in public alpha (#51195) 2026-10-02 18:40:44 +00:00
Nik RichersandNik Richers 0405b31b26 docs: re-publish Multigres Private Alpha docs — merge on October 2, 2026 (#50664)
## I have read the CONTRIBUTING.md file.

YES

## What kind of change does this PR introduce?

Re-add. Reapplies the Multigres Private Alpha docs section removed in
#50662, ready to merge once Sugu gives the go-ahead. Do not merge until
then.

Linear: MUL-1621 (follow-up to MUL-452).

## What is the current behavior?

Multigres docs section is down (per #50662): no overview/compatibility
pages, no sidebar entry, no features-table row, no "What you get" cards.

## What is the new behavior?

Exact reapply of #49020 (with Multigres marked Private Alpha): overview
guide at `/docs/guides/database/multigres`, compatibility stub, Database
sidebar entry, features-table row, "What you get" cards, and the
`ContentListings` optional-`href` support they rely on.

Base branch is the revert PR (#50662) so the diff here is legible now;
retarget to `master` once #50662 merges.

## Additional context

- `pnpm --filter docs exec vitest run lib/content-listings.test.ts` — 22
passed
- Blocked on Sugu's go-ahead — `do-not-merge` label applied

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
2026-10-02 09:18:25 -07:00
Artur ZakirovandCharis 4b2d163a1d fix(orioledb): use alpha and beta conditionally based on AMI version (#51162)
## Problem

- Older orioledb projects show "Public Beta" instead of "Public Alpha"
in UI.
- List of backups in the "Scheduled backups" tab hangs.

## Solution

- show in the UI "Public Alpha" for projects older than
17.11.0.001-orioledb
- show in the UI "Public Beta" for new projects
- enable scheduled-backup query for "Public Beta"


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Backup availability messages now reflect OrioleDB’s current release
stage rather than always describing it as public beta.
* AWS backup queries are no longer disabled for every OrioleDB project;
they remain disabled during the alpha stage.
* **New Features**
* Added an informational notice and documentation link for scheduled
backups on AWS OrioleDB projects in alpha.
  * Added release-stage details to the PITR availability notice.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
2026-10-02 09:43:32 -04:00
Anthony Lio b13d6c2878 feat(chore): add a lint ratchet for shadcn rules (#51014)
## Problem

shadcn lint rules has been soft landed in #50676 and are now on as
warnings in every app, but nothing stops a PR from adding new violations

linear: FE-4473

## Solution

- moved the ratchet script and its tests from `apps/studio/scripts` to
`packages/eslint-config-supabase` so every app runs one copy
- added a shared rule list,
`packages/eslint-config-supabase/ratchet-rules.json` with the shadcn
rules
- www, docs, design-system, ui-library and learn get `lint-ratchet.yml`
with one job per changed app (triggered by the app, `packages/**` or the
lockfile) + a weekly `lint-ratchet-decrease.yml` (as for studio ratchet)
- package tests run in `eslint-config-supabase-tests.yml`

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. run `pnpm --filter ./apps/www run lint:ratchet`
2. add `p-[13px]` to a `className` in any www component and run it
again. it fails with `shadcn/no-arbitrary-values` and the file name with
`(+1)`
3. revert change
4. run `pnpm --filter eslint-config-supabase test` and see 6 tests pass
5. in ci, check `Ratchet studio lint checks` and the `ratchet (<app>)`
jobs for the apps this pr touches

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Developer Improvements**
* Expanded automated lint checks to cover additional apps and shared
package changes.
* Added checks for arbitrary Tailwind values, unknown classes, and raw
colors across supported apps.
* Added automated baseline updates that can open or update a pull
request when lint counts change.
* Added tests for the lint configuration and support for combining
multiple rule files.
* Updated Studio lint notifications to exclude Shadcn rules with
zero-baseline counts.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-02 14:13:59 +03:00
Danny White 6143441493 fix(pipelines): clarify DuckLake destination setup (#51013)
## Problem

The DuckLake setup form makes it hard to choose between Supabase
projects and external connection details. Bucket creation, catalog
settings, and the guide do not clearly follow the setup flow.

## Solution

- Show **Configuration method** as two clear choices: **Select Supabase
projects** and **Enter connection details**.
- Group catalog and storage fields, move **Pool size** to **Advanced
settings**, and add **New bucket** to the bucket selector.
- Clarify the custom Postgres and S3 fields, including the metadata
schema, connection URL, and storage options.
- Update the [DuckLake destination
guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake)
to follow the form and explain resource preparation and validation.

| Before | After |
| --- | --- |
| <img width="1280" height="1323" alt="50587"
src="https://github.com/user-attachments/assets/bf5997cf-9fc4-48a8-ad4f-13fa991d56f9"
/> | <img width="1280" height="1323" alt="61914"
src="https://github.com/user-attachments/assets/2c1dd7ef-797f-4302-9e2e-93a5f1e6e515"
/> |

## Review instructions

1. Open **Database > Pipelines > Add pipeline** and select **DuckLake**.
2. Select **Select Supabase projects**. Check the catalog and storage
fields, create a bucket from the bucket selector, and find **Pool size**
under **Advanced settings**.
3. Select **Enter connection details**. Check the Catalog URL, S3 URL
style, and Use SSL guidance.
4. Compare both routes with the [DuckLake destination
guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake).

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] I used the `/edit-the-docs` skill and the docs [style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* DuckLake destinations support Supabase-managed projects or an existing
Postgres catalog with S3-compatible storage.
* Select a storage bucket using search, configure a metadata schema, and
access clearer guidance for catalog and storage settings.
* Advanced settings provide a connection pool size from 1 to 6, with a
default of 4. Credential fields include show and hide controls.
* **Documentation**
* Updated setup steps, configuration guidance, query credential details,
and troubleshooting instructions for both configuration modes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-02 10:34:49 +10:00
Kody JacksonandIvan Vasilov 6572fad288 fix(studio / ui) - update xss vuln version of tanstack (#51141)
## Problem

When I bumped the pnpm-lock file in an unrelated KB fix (#51132), I
believe that refreshed the build cache (either that, or Vercel started
flagging this issue very recently).

At any rate, builds are now failing b/c of a [vulnerable
Tanstack/react-start
package](https://github.com/TanStack/router/security/advisories/GHSA-qx66-fv34-fjm8),
which this PR attempts to fix.

```
The build blocks vulnerable @tanstack/react-start@1.168.18 due to an XSS security check.
```

<img width="1355" height="397" alt="image"
src="https://github.com/user-attachments/assets/7d0d90fb-009c-4a0b-aadc-b526e0fcce0a"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated project maintenance settings and supporting TanStack package
versions.
* Improved error reporting so standard errors include their stack trace,
while other error values are logged directly.
  * No app features were added or removed.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-02 00:42:12 +02:00
Monica Khoury 123c768de1 Warn when authenticator role overrides exposed schemas (FE-4472) (#50982)
## What

Adds a warning in Project Settings > API when the `authenticator` role's
`pgrst.db_schemas` setting overrides the Dashboard's "Exposed schemas"
configuration, plus an inline "Reset override" button to fix it in one
click.

## Why

`ALTER ROLE authenticator SET pgrst.db_schemas = ...` silently overrides
what PostgREST actually exposes, regardless of what's selected in the
Dashboard. Users hit a confusing PGRST106 error with no indication that
a role-level override is the cause.

## How

- New query (`authenticatorRoleConfigQueryOptions`) reads
`pg_roles.rolconfig`
for the `authenticator` role and parses out any `pgrst.db_schemas`
value.
Configured to always refetch on mount and window focus, since the fix is
often applied outside the Dashboard (SQL editor, another client) with no
  cache-invalidation event for the app to react to.
- `PostgrestConfig.tsx` compares that value against the currently
selected
  schemas and shows an `Admonition` warning naming the actual overriding
  schemas, with a link to the PGRST106 troubleshooting guide, when they
  differ.
- The warning includes a "Reset override" button that runs
  `alter role authenticator reset pgrst.db_schemas` after a confirmation
  step (showing the exact SQL that will run, with a copy button), then
  refetches so the warning clears immediately without a page reload.

## Testing

1. In the SQL Editor of a test project, run:
   ```sql
   alter role authenticator set pgrst.db_schemas = 'public';
   ```
2. Go to Project Settings > API, and select a schema other than (or in
   addition to) `public` in "Exposed schemas" (e.g. add `api`).
3. The new warning should appear, naming `public` as the schema actually
   in effect, with a link to the PGRST106 troubleshooting guide.
4. Click "Reset override" in the warning, confirm in the modal, and
check
   that the warning clears immediately without a page reload.
5. Alternatively, clear the override manually from the SQL editor:
   ```sql
   alter role authenticator reset pgrst.db_schemas;
   ```
then navigate away from the API settings page and back (or refocus the
   browser tab) — the warning should clear without a hard refresh.

Fixes
[FE-4472](https://linear.app/supabase/issue/FE-4472/warn-when-authenticator-role-overrides-exposed-schemas)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* The API settings page now warns when the authenticator role’s exposed
schemas differ from the saved Dashboard configuration.
* You can reset the override to restore the saved schema configuration.
The reset requires permission and provides success or error feedback.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 16:02:00 +03:00
Danny White 4f0be099e7 fix(studio): restore the Snowflake destination mark (#51075)
## Problem

The Snowflake destination still uses a neutral text monogram even though
its Studio asset is available. Supporting that monogram also leaves a
separate rendering path used by no other destination.

## Solution

Restore Snowflake through the shared brand-icon registry introduced by
#51073. Simplify `DestinationLogo` back to a map of destination marks,
removing the monogram type, configuration, and rendering branch.

| After |
| --- |
| <img width="924" height="730" alt="CleanShot 2026-09-30 at 15 14
59@2x"
src="https://github.com/user-attachments/assets/7409d483-3371-45ec-bf54-0ddc6ad22857"
/> |

## Review instructions

1. Open `/project/<ref>/database/replication` with a Snowflake pipeline.
2. Confirm the Snowflake mark appears in the pipeline list and diagram.
3. Open the pipeline child route and confirm the same mark appears in
its header.
4. Confirm the other destination marks remain unchanged in light and
dark themes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Visual Updates**
* Snowflake replication destinations now display a themed brand icon
instead of the “SF” monogram. Other destinations retain their existing
icons.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 18:00:55 +10:00
Joshen Lim d6c81b66c9 Apply scrollBeyondLastLine for CodeEditor in QueryEditor and Logs Explorer (#51082)
## Context

As per PR title - this was the behaviour for the SQL Editor and figured
it makes sense to also have this behaviour in the Explorer QueryEditor +
Logs Explorer where the main UX is writing queries, and lets the user
bring the active section of the code closer to the middle of the
viewport (rather than right at the bottom)
<img width="790" height="305" alt="image"
src="https://github.com/user-attachments/assets/07eb63fa-1bb9-4abe-859e-2968a73e7ca5"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Editor Improvements**
* Query editors now allow scrolling beyond the final line, providing
more room to position the last lines on screen.
* The SQL editor no longer forces the decoration area to zero width; it
now uses Monaco’s default width behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 11:20:41 +08:00
Danny White 5fbf1ac4ff feat(studio): support themed pipeline destination logos (#51073)
## Problem

Some destination marks need different assets to maintain contrast across
light and dark surfaces. Their paths are also duplicated between
Pipelines and Wrappers.

## Solution

Add a shared brand-icon registry that supports either one asset or light
and dark variants. Pipeline destination logos resolve against the active
theme, while Wrappers continue using the light variant for their white
logo tiles.

This keeps single-asset destinations unchanged and preserves the
existing monogram treatment where applicable.

| Light | Dark |
| --- | --- |
| <img width="926" height="742" alt="CleanShot 2026-09-30 at 15 03
31@2x"
src="https://github.com/user-attachments/assets/d76e5995-1bb8-4cb7-b991-c5dc1a5d8cb0"
/> | <img width="926" height="732" alt="CleanShot 2026-09-30 at 15 03
03@2x"
src="https://github.com/user-attachments/assets/83d45f30-3bf6-4ddc-8607-e27628cb4966"
/> |

## Review instructions

1. Open `/project/<ref>/database/replication` with pipelines using the
themed destination marks.
2. Switch between light and dark themes from the account menu.
3. Confirm each themed mark swaps assets and remains legible in the
pipeline list, diagram, and child-route header.
4. Open Database Integrations and confirm the corresponding Wrapper
tiles continue using their light-surface assets.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated the BigQuery, ClickHouse, DuckLake, and Snowflake icons in
integration and replication views to use branded marks. Icons now use
theme-appropriate variants where available, helping them display
consistently across light and dark themes. ClickHouse’s previous “CH”
monogram is replaced with its branded mark.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 12:04:07 +10:00
Artur Zakirov bd9a0ff4e6 feat(orioledb): rename orioledb from Public Alpha to Public Beta in dashboard (#50975)
## Problem

We need to rename orioledb in Dashboard.

## Solution

- Update Studio copy/badges referencing OrioleDB from "Public Alpha" to
"Public Beta" (project creation advanced config, restore-to-new-project,
PITR empty state)
- Remove the scheduled-backups block that hid backups for OrioleDB
projects — OrioleDB now has WAL-G scheduled backups in beta, so that
page should behave normally. PITR keeps its existing guard since PITR is
not yet supported for OrioleDB.
- Update the `useOrioleDb` telemetry property doc-comment to reflect the
beta status
- Update project-creation wizard test expectations/fixtures accordingly
(`release_channel: 'beta'`)

Marketing (`apps/www`) and docs (`apps/docs`) references to OrioleDB
alpha status are being updated separately.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* OrioleDB is now labeled as being in public beta rather than public
alpha, and project creation selects the beta release channel.
* Restore-to-new-project and Point-in-Time Recovery notices clarify that
these features are unavailable for OrioleDB projects.
* OrioleDB projects now follow the standard eligibility checks and page
flow for scheduled backups.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:39:41 +02:00
Tanun Turbo Chalermsinsuwan cd305313e4 fix(roles): Show only document-defined roles (#51087)
## Problem

As part of having `None / No Access` available to customers, we need to
start providing this role entry in `/platform/organization/:ref/roles`
endpoint. However, when making it available, the role will show up
prematurely on all the components that relies on
`useOrganizationRolesV2Query` function.

## Solution

This change is to allow us to test the behavior of the new role without
having to turn the API on/off. The UI will show only the "predefined"
entries and ignore the "extras" sent by API.

After this is merged, we will do the following

1. Unhide the None role from the API
https://github.com/supabase/platform/pull/39137 -- this will not have
any effect on the frontend as we already ignore it in this PR
2. Work and continue testing on
https://github.com/supabase/supabase/pull/50922 -- which will be easier
to verify as we no longer need to change the API side

## Review instructions

1. Modify the items in the `FIXED_ROLE_ORDER` list, remove some roles
from there
2. You will see that the role will disappear from the components like
the invitation form or managed access form.



## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Bug Fixes**
* Organization role lists now show only supported roles, in the expected
order. Roles outside the supported set are no longer displayed. This
keeps the list consistent and focused on recognized roles, making
available organization roles easier to review.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 20:40:42 +07:00
Ivan Vasilov ec6be68356 chore: Bump vulnerable deps (#50901)
This PR bumps the vulnerable dependencies `devalue`, `mermaid`,
`@faker-js/faker`, `brace-expansion`, `undici`, `fast-uri` and
`markdown-it`.

It also dedupes `rolldown`, `vite` and various `react-router` deps.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated development and build tooling for Lite Studio, Studio, and the
Vue block, along with tooling used in automated Studio checks. These
changes do not alter app features or workflows, and no new user-facing
capabilities or behavior changes are included. They are limited to the
project’s underlying development setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 14:53:28 +02:00
Kamil Ogórek c5b4fbfa11 fix: Handle NO_PROJECT_MARKER for projectRef (#51083)
Skip `NO_PROJECT_MARKER` values for projectRef in API validation.
2026-09-30 10:34:26 +00:00
Danny White 92952bf903 fix(studio): clarify S3 access key dialogs (#51070)
## Problem

The S3 access key creation dialogs are wider than their contents, use
plural titles for one key pair, and call the name field “Description”
even though the table calls it “Name”. The save state also implies both
values disappear, although only the secret does.

## Solution

Use the small dialog size for both states. Use singular titles, label
the field “Name”, shorten the create button to “Create”, and clarify
when the secret must be copied. The API field remains `description`.

## Review instructions

1. Open a project’s **Storage > S3** page and select **New access key**.
Check the dialog width, title, Name field, and Create button.
2. Create a key and check the save dialog width, singular title, and
secret visibility guidance.

| Before | After |
| --- | --- |
| <img width="1084" height="572" alt="CleanShot 2026-09-30 at 14 37
20@2x"
src="https://github.com/user-attachments/assets/781706ee-0ecc-4535-abb5-f6ac65f02c71"
/> | <img width="844" height="584" alt="CleanShot 2026-09-30 at 14 36
56@2x"
src="https://github.com/user-attachments/assets/119df19f-2f39-4e23-94b4-26665583765c"
/> |
| <img width="1096" height="730" alt="CleanShot 2026-09-30 at 14 37
57@2x"
src="https://github.com/user-attachments/assets/00481ed7-dc05-48b9-8cbc-e76d608aa4b1"
/> | <img width="842" height="780" alt="CleanShot 2026-09-30 at 14 37
39@2x"
src="https://github.com/user-attachments/assets/8c837101-250a-474f-a0fc-cf46ce491f83"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* The credential form now labels the field “Name” and uses “Create” for
the submit button.
* Confirmation text now clarifies that the access key is bucket-wide,
bypasses RLS, and its secret is shown only once. It also refers to a
single access key instead of using S3-specific wording.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 15:21:47 +10:00
Pamela Chia 38b74af3f1 fix(studio): fall back for framework icons without an asset (#51065)
I made the connected-project framework icons fall back when no shipped
SVG exists for a framework. The three icon sites built
`/img/icons/frameworks/<framework>.svg` straight from the integration's
framework preset, which is an open-ended string. They only fell back
when the value was empty, so any preset without an asset (`express`,
`hono`, `fastapi`, `tanstack-start` and others) showed a broken image
and logged a 404.

**Changed:**
- **Broken framework icons**: `getFrameworkIconUrl` returns the asset
URL only for slugs in a set that mirrors `public/img/icons/frameworks/`.
The integration connection row, the org project linker and the
marketplace project picker now show their existing fallback icon for any
other slug. A test keeps the set equal to the directory listing.
- **Framework type**: I deleted the hand-kept `VercelFramework` union.
It listed exactly the shipped icon slugs, while the API types the field
as `string | null`, and that mismatch is what made the old empty-only
check look safe.

**Note:** I rejected an `onError` fallback because the browser still
sends the 404 request. Adding logos for common presets is left for
design.

## To test

Tested on Vercel preview (staging): no real connection there uses these
presets, so I rewrote the org integrations response in the browser to
give one integration four connections.
- [x] Open an org's Integrations page with connections whose framework
has no shipped icon (`express`, `eve`, `tanstack-start-lovable`). Expect
the fallback badge and no request under
`/dashboard/img/icons/frameworks/` for those slugs. Observed: all three
rows showed the badge and the network log had no request for their SVGs.
- [x] Same page with a `nextjs` connection. Expect its framework logo.
Observed: `nextjs.svg` loaded with a 200.
- [x] Same page with the real, unmodified response (one connection with
`framework: null`). Expect the badge, no frameworks requests, and no new
console errors. Observed: as expected.

## Linear
- fixes GROWTH-1309


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Vercel integration and project views now display framework icons when
available and fall back to the Vercel icon when no matching icon exists.
* Framework metadata now supports values beyond a fixed list, while
unsupported frameworks continue to use the fallback icon.

* **Tests**
* Added coverage for supported and unsupported framework icons,
including base-path handling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 12:59:36 +08:00
Pamela Chia 9690efeb42 fix(vault): link to current dashboard route (#51058)
I updated first-party Vault links to open the current secrets route
directly. Wrapper credentials, extension metadata, and blog posts still
linked to the retired path and relied on a redirect.

## To test

On the preview:
- [x] Inspect a Wrapper credential's Vault link. Expect
`/integrations/vault/secrets` with a `search` query for that credential.
- [x] Open the inspected target URL. Expect Vault to show the matching
secret.
- [ ] Click a Wrapper credential's Vault link. Expect the filtered Vault
view.
- [ ] Open the pgsodium extension's Vault link and a Vault blog link.
Expect `/integrations/vault/secrets` without the retired route in the
address bar.

## Linear
- fixes GROWTH-1312


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Vault secrets links now direct you to the project’s Integrations page,
including links from wrapper metadata, blog articles, and the `pgsodium`
extension listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 12:54:28 +08:00
Pamela Chia e0e58f8814 fix(studio): redirect moved dashboard routes (#51056)
I added permanent redirects for the moved Dashboard routes that still
send visitors to 404s. Project and organization identifiers carry
through, while the old project billing path opens the organization
picker for billing.

**Note:** The bare `/dashboard/project` path redirects straight to
Organizations instead of the `/dashboard/projects` hop named in
GROWTH-1295, since `/projects` already redirects there.

## To test

Tested on the Studio preview:
- [x] Requested the eight old Dashboard paths in GROWTH-1295 while
signed out. Each returned 308 with the specified destination.
- [ ] Request bare `/dashboard/project` while signed out on the latest
preview. Expect a single 308 to `/dashboard/organizations`.
- [x] Requested a project backup path with a query string. The
destination kept the project ref and query string.
- [x] Requested `/dashboard/project/_`. The project picker remained
reachable.

## Linear
- fixes GROWTH-1295


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Added permanent redirects for legacy Studio routes covering account
and project pages, backups, email templates, edge-function logs,
secrets, and billing settings.
* Redirects preserve incoming query parameters and URL fragments; the
project selector remains unaffected.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 23:59:31 +00:00
Danny White 68d5011514 fix(studio): hide secret visibility controls in pipeline edit forms (#51010)
## Problem

Pipeline edit forms hide stored credentials but still show visibility
controls beside their placeholders. The controls suggest that the stored
secret can be revealed.

## Solution

- Hide visibility controls in edit mode for ClickHouse, Snowflake,
DuckLake, and Analytics Bucket secret fields.
- Keep the controls available when creating a destination, with
accessible labels for the DuckLake and Analytics Bucket controls.

| Before | After |
| --- | --- |
| <img width="1024" height="196" alt="CleanShot 2026-09-29 at 16 48
56@2x"
src="https://github.com/user-attachments/assets/a9da9a32-ab17-4c07-abf3-dfa88b8c6475"
/> | <img width="1024" height="168" alt="CleanShot 2026-09-29 at 16 47
23@2x"
src="https://github.com/user-attachments/assets/fddeb880-cd23-4752-ae73-8f27348c647f"
/> |

## To test

1. Open **Database → Pipelines** and edit a destination of each type:
ClickHouse, Snowflake, DuckLake with custom parameters, and Analytics
Bucket. Check that the hidden secret fields have no eye button.
2. Start creating each destination and check that its secret fields
still offer a working visibility control.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **Improvements**
* Secret fields in replication destination forms remain masked when
editing an existing destination, and their visibility controls are
hidden. When creating a destination, supported secret fields can be
revealed.
* **Accessibility**
* Catalog-token visibility controls now use dynamic, descriptive labels.
DuckLake catalog URL and S3 secret-key reveal controls also have
descriptive labels.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:55:45 +10:00