80 Commits
Author SHA1 Message Date
kemal.earthandAli Waseem b028908136 feat(studio): add never option to scoped pat expiry (#51273)
## Problem

When building scoped pat's we had omitted the option to have them never
expire.

## Solution

This re-adds the option to select "never" and it comes with the caveat
of an admonition to warn the user that they would need to manually
delete or revoke this token.

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. Open /account/tokens
2. Click Generate new token.
3. Open Expires in. Confirm "Never" is the last option, after "Custom",
and has no Recommended badge.
4. Select Never. A warning admonition appears directly below the expiry
row: "This token never expires — Anyone with the token keeps access
until you delete it."
5. Pick an org and project, grant one permission, click Review access.
Summary shows Expires: Never.
6. Create the token. The POST body has no expires_at, and the new row's
Expires column reads Never.

Fixes FE-4527.

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-10-05 16:42:17 +01:00
kemal.earth cb52c0f425 chore(studio): update segment control in view permissions to ds one (#51125)
## Problem

We were using a custom segment control. Recently we introduced segmented
toggle groups in our design system. The old one is inconsistent and
doesn't match anything else.

## Solution

Replace segmented control with [this
one](https://supabase.com/design-system/docs/components/toggle-group#segmented).

| Before | After |
|--------|--------|
| <img width="777" height="85" alt="Screenshot 2026-10-01 at 11 36 47"
src="https://github.com/user-attachments/assets/84e28075-248d-42d4-a537-f18cd2fe86db"
/> | <img width="783" height="95" alt="Screenshot 2026-10-01 at 11 37
00"
src="https://github.com/user-attachments/assets/1071f031-8e96-4db1-8ea1-36cb34e9923a"
/> |

## Test plan
- [ ] Go to Account Settings → Access Tokens, create a new scoped token,
and on the capability review step confirm the All/Read/Read-write
segmented control renders correctly and filters the capability list as
expected
- [ ] Open an existing scoped token's "View" sheet and confirm the same
segmented control filters correctly there too
- [ ] Verify keyboard navigation (arrow keys) and that exactly one
option is always selected (no deselect state)
- [ ] Visual check against the design system's segmented `ToggleGroup`
styling (no leftover custom border/divider artifacts from the old
implementation)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated the capability-level selector to use a segmented control.
Selection behavior remains unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 10:11:13 +01:00
Wen Bo Xie 0eb08cb9f0 docs: prepare scoped personal access tokens docs for GA (#50839)
Scoped personal access tokens are leaving alpha. Remove the pre-GA
framing
and update pages that assumed every token carries full account access.

- Personal Access Tokens guide: remove the public alpha / early access
admonition. Add a section on using a scoped token with the Supabase CLI:
  the browser flow of `supabase login` creates a classic token, while
SUPABASE_ACCESS_TOKEN or `supabase login --token` uses a scoped one, and
  commands that connect with the database password aren't limited by the
  token's permissions.
- Management API introduction: replace "PATs carry the same privileges
as
your user account" with the scoped vs. classic distinction and link to
the
  guide's permission tables.
- MCP guide: the CI setup now asks for a scoped token limited to the
  connected project and links to the MCP tool permissions table.
- API keys guide: replace the internal "fine-grained token" permission
ID
  with the names shown in the dashboard (API Keys, Read), and note that
  `reveal=true` in the example also needs API Key Secrets (Read).
- Managing environments: recommend a scoped token for the GitHub Actions
  deploy workflow.
2026-09-28 10:43:18 +09:00
Gildas Garcia 0381c5bc23 Fix unstable test by increasing its timeout (#50860)
## Problem

We have an unstable test that fails the CI too often.

## Solution

Increase its timeout.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Updated the automated test timing allowance for an
organization-switching scenario, helping the test complete reliably when
mocked project-list requests take longer. This is a test-only change and
does not alter the app’s behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 17:22:45 +02:00
Saxon FletcherandClaude Opus 5.5 cf5f1545bd feat(studio): add notebook permissions to scoped access tokens (#50764)
## Problem

The Management API now has `/v2/projects/{ref}/notebooks`, gated by the
new `project_notebooks_read` / `project_notebooks_write` FGA
permissions. Studio pins `@supabase/shared-types` 0.1.95, which predates
them, so the scoped access token form can't grant them. Tokens created
with every permission selected still get `403 forbidden` on the notebook
endpoints.

## Solution

- Bump `@supabase/shared-types` to 0.1.96 (Studio and shared-data),
which publishes the notebook permissions.
- Add a **Notebooks** entry to the permission catalog (Project category,
next to SQL Snippets).
- Add minimum roles to `FGA_SCOPE_MINIMUM_ROLE`: read is `readonly`,
write is `developer`, matching the OpenFGA model.

The docs permission tables don't change yet. They're built from the
docs' checked-in v2 spec, which doesn't include the notebook endpoints,
so the row appears on the next spec sync.

## Review instructions

1. In the preview, go to **Account → Access Tokens** and create a scoped
token for a project. Check that **Notebooks** is listed under Project,
and set it to Read-write.
2. List notebooks with the new token:
   ```bash
curl -s -H "Authorization: Bearer $TOKEN"
"https://api.supabase.com/v2/projects/$REF/notebooks"
   ```
It should return `200` with `{ "links": ..., "data": [...] }`, not
`403`.
3. Optional: create a token with Notebooks set to None, repeat step 2,
and check it returns `403`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
  - Added project-level notebook permissions to access tokens.
- Access tokens can now grant read-only or developer-level access for
managing shared project notebooks.
- Project notebook permissions are displayed in the token creation
interface and supporting documentation.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 15:18:28 +08:00
Danny White ec53175b8a refactor(ui): rename text-brand to text-primary (#50564)
## What kind of change does this PR introduce?

Refactor. Follow-up to #49871.

## What is the current behavior?

Branded (green) text still uses the `text-brand` classname while the
colour comes from `--primary`.

## What is the new behavior?

**Rename-only:** `text-brand` → `text-primary` across callsites and
docs. Leftover `bg-brand` / `border-brand` alias to `brand-default`. No
intentional colour changes in this PR.

This better matches how we treat our green in other components and
props, like `variant="primary"` for green buttons.

## To test

On light mode: smoke-test that branded text still looks like #49871
(readable green, not the bright fill).

-
[Homepage](https://zone-www-dot-com-git-dnywh-depr-316-text-brand-de2380-supabase.vercel.app/):
“Scale to millions” uses `text-primary`
- [Docs
homepage](https://docs-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/docs):
branded links like “More on self-hosting” are still readable
- [Typography
docs](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/typography):
documents `text-primary`
- [Colour
usage](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/color-usage):
`text-primary` is visibly darker than `bg-brand-default` _on light mode_
- [Studio auth
providers](https://studio-staging-git-dnywh-depr-316-text-brand-to-60fa6c-supabase.vercel.app/dashboard/project/_/auth/providers):
enabled provider badge text readable; status dot stays bright green

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated branded text, link hover states, icons, badges, indicators,
and highlighted content across the Design System, Docs, Studio, Learn,
UI Library, and marketing experiences to use the primary theme color.
* Updated syntax highlighting and table-of-contents styling for
consistent primary-color presentation.
  * Refined brand color fallback behavior for bright fills and borders.

* **Documentation**
* Updated color-usage and typography guidance to recommend the primary
text utility.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 16:19:03 +10:00
Jordi Enric fa7c223209 fix(studio): use Compute management endpoints FUNC-896 (#50393)
## Problem

Studio still called the legacy `/workers` Management API routes and used
the old `project_worker` response contract, so Compute instances could
not be listed or retrieved after the API rename. The production API type
check also detected drift in the v1 and platform declarations.

## Fix

- Regenerate the v1, v2, and platform API declarations from the deployed
schemas.
- Update Studio list and detail queries to `/compute`.
- Align typed fixtures with the Compute response schemas and
`project_compute_instance` resource type.
- Update platform response type references to the generated `_Output`
schema names.

## How to test

- Run `pnpm api:verify-types`.
- Run `pnpm --filter api-types test`.
- Run `pnpm --filter studio test data/compute/compute.utils.test.ts
"tests/pages/project/[ref]/compute/index.test.tsx"`.
- Run `pnpm --filter studio typecheck`.
- Run `pnpm --filter common typecheck`.
- Run `pnpm --filter studio lint:ratchet`.

Expected result: production API declarations are synchronized, and
Studio requests the `/compute` list and detail endpoints and renders
`project_compute_instance` responses successfully.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Updated API response handling across profiles, backups, notifications,
integrations, warehouses, access tokens, payments, and other Studio
workflows for more accurate serialized data.
* Compute instance pages and queries now use the compute-specific API
endpoints and response data.
* Improved feature-flag type handling when disabled feature data is
unavailable.

* **Tests**
* Updated automated coverage and fixtures to reflect current compute and
API response formats.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-15 12:50:56 +02:00
Gildas Garcia 6f15081892 Scoped PAT: show dependencies between permissions (#50271)
## Problem

Some permissions require others to actually have an effect, for
instance:

- `api_gateway_keys_secret_read` requires `api_gateway_keys_read` or
`api_gateway_keys_write`
- `data_api_config_secret_read` requires `data_api_config_read` or
`data_api_config_write`

This is not obvious from a user perspective.

## Solution

We decided to make these requirements explicit by:
- Adding a line in the permission item stating the dependency
- Disabling the permission if its dependency isn't met
- Resetting the permission if it was selected but the dependencies
aren't met anymore

## How to test

- On
[staging](https://studio-staging-git-gildasgarcia-fe-4380-dashboa-b2a227-supabase.vercel.app/dashboard/account/tokens)
- Create a new token
- Check that _API Key Secrets_ is greyed out and disabled
- Select _API Key_ read or read-write
-  _API Key Secrets_ shouldn't be greyed out and disabled
- Select a value for _API Key Secrets_
- Set _API Key_ to none
- Check that _API Key Secrets_ is greyed out, disabled and reset to none
too
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added dependency-aware permissions for scoped access tokens.
- Permission descriptions now show required dependencies and permission
levels.
- Dependent permissions automatically reset to “None” when requirements
are not met.
- Permission controls and unavailable selections reflect dependency
requirements.
- **Accessibility**
- Screen readers now receive an announcement when a permission is reset
to “None” due to unmet dependencies.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 11:09:46 +02:00
Danny White 476d4a5851 refactor(ui): drop redundant Button variant="default" props (#50161)
## What kind of change does this PR introduce?

Mechanical cleanup on top of the Button default-variant change (#50160).

## What is the current behavior?

Many callsites still pass `variant="default"` even though that is now
the component default.

## What is the new behavior?

Removes redundant static `variant="default"` from legacy `Button` and
`ButtonTooltip` callsites. Keeps explicit defaults where they document
the API:

- `button-default.tsx` and `button-sizes.tsx` demos
- `DocsButton`, which pins neutral styling at the wrapper boundary

## To test

Studio:

- [Auth → Rate
Limits](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/auth/rate-limits):
dirty the form so Cancel appears; Cancel stays neutral, Save stays green
- [Project Settings → API
Keys](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/settings/api-keys):
`DocsButton` in the header actions stays neutral

Design system:

- [Design system →
Button](https://design-system-git-dnywh-dc924ac1-supabase.vercel.app/design-system/docs/components/button):
`button-default` / `button-sizes` still show explicit default styling;
Primary (green) is restricted to the Primary section (and `asChild`)

WWW:

- [www → Brand
assets](https://zone-www-dot-com-git-dnywh-dc924ac1-supabase.vercel.app/brand-assets):
Download logo kit / Download button kit stay neutral
2026-09-11 17:05:26 +10:00
Gildas GarciaandAlaister Young 9b1dddde11 Scoped PAT: add api_gateway_keys_secret_read and data_api_config_secret_read permissions (#50134)
## What kind of change does this PR introduce?

Surface the new scoped personal access token permissions published in
`@supabase/shared-types` 0.1.95 (added by
https://github.com/supabase/platform/pull/38060, now deployed).

**Stacked on #50234**, which regenerates the Management API types so
Studio's scope type includes the new ids. This PR targets that branch
and will retarget to `master` when it merges.

## What's in here

- Bump `@supabase/shared-types` to 0.1.95 (Studio and shared-data).
- Catalog entries in
`packages/shared-data/scoped-access-token-permissions.ts`:
- **API Key Secrets** (`api_gateway_keys_secret_read`): gates
`?reveal=true` on the API keys endpoints. Renamed from "JWT secret",
which described the wrong thing.
- **Data API JWT Secret** (`data_api_config_secret_read`): gates the
`jwt_secret` field on the PostgREST config endpoint.
- **Compute** (`workers_read` / `workers_write`): shared-types 0.1.95
also publishes the workers scopes, so they surface in the catalog now.
Named to match Studio's product naming (#50208).
- Minimum roles for the four new ids in `FGA_SCOPE_MINIMUM_ROLE`,
transcribed from the OpenFGA model (secret reads: developer; workers
read: readonly; workers write: developer).
- Docs generator (`generateAccessControlPartials.mts`):
  - Drop the workers exclusion now that the scopes are live.
- When an endpoint lists alternative permission sets (for example API
keys read alone, or read plus secret read for reveal), a row's footnote
now only considers the alternatives that include that row's own scope.
Previously the API Key Secrets row would have said "Requires API Keys
(Read), or API Keys (Read) and API Key Secrets (Read)".
- Regenerated PAT guide tables. The committed Management API specs
predate the secret scopes, so this also includes the same spec refresh
the weekly docs bot performs (`chore(docs): refresh the Management API
specs`, kept as its own commit). Besides the new rows it picks up two
new upstream endpoints under Advisors and the branch rows.

## Verified

- `pnpm --filter studio typecheck` clean on top of #50234.
- Access token test suite passes, including the guard that the role
table covers exactly the ids shared-types publishes.
- Partial regeneration is idempotent, so the Docs Tests stale-table gate
passes.

## Follow-ups (not in this PR)

- `apps/docs/content/guides/getting-started/api-keys.mdx` says a
fine-grained token needs `api_gateway_keys_read` for the `?reveal=true`
example. It now also needs `api_gateway_keys_secret_read`.
- `project:api_gateway_keys` still says "Read exposes API keys" in its
risk reason, which overstates it now that secret values sit behind a
separate scope. Rewording may mean revisiting its risk level.
- The comment in `ComputeLayout.tsx` about shared-types not exposing
`workers_read` is stale.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added permission support for API key secrets, Data API JWT secrets,
and compute workers.
  * Added API endpoints to run project advisors and create branches.
* Added support for additional log-drain destinations, including S3,
Last9, and OTLP.
* Added storage object versioning information to project configuration
responses.
* **Documentation**
* Updated access-control documentation for new permissions, worker
operations, advisor runs, and branch creation.
  * Clarified Data API configuration and secret descriptions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-11 13:31:21 +08:00
Gildas GarciaandAlaister Young 737b8595f2 Update API types (#50234)
## Problem

platform, v1 and v2 have been already completely migrated and introduced
some changes.

Some types have been renamed, some outputs and inputs updated.

## Solution

- Update the API types
- Fix the TS errors

## Update

Taking this over to unblock #50134, which needs the new scoped token
permission ids from the regenerated types.

- Merged `master`.
- Regenerated `api-v2.d.ts` from the production spec. The previous files
came from a local API that exposed a webhook events endpoint production
doesn't have yet. Production has since added standardized 400 error
responses on the v2 organization endpoints. `api-v1.d.ts` and
`platform.d.ts` already matched production.
- Fixed `verify-production-types`. It formatted the regenerated files in
a temp directory outside the repository, so Prettier fell back to its
defaults and the comparison could never match the committed files. It
now passes the repository config explicitly. `pnpm api:verify-types`
passes on this branch.
- Verified locally: `pnpm typecheck`, `pnpm api:verify-types`, Studio
unit tests.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Preserved descriptions when saving, sharing, moving, or unsharing
notebooks, reports, SQL snippets, and saved queries.
* Improved handling of empty or null values across notebook
descriptions, billing usage, pooler settings, and infrastructure fields.
* Improved read-replica connection handling, including read-only
connection strings.
* Updated storage configuration and capability handling to match current
settings.

* **API and Compatibility**
* Updated organization, project, storage, OAuth, billing, and
infrastructure data handling to match current API responses.
  * OAuth app creation and updates now require scopes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-11 12:17:49 +08:00
Danny White 1131e3e2ce fix(ui): default Button variant to default instead of primary (#50160)
## What kind of change does this PR introduce?

Bug fix / design-system alignment for the legacy `Button` from `ui`.

## What is the current behavior?

Omitting `variant` on the legacy `Button` falls back to brand-green
`primary`. That makes accidental greens easy, and it is hard to spot the
real main action on busy pages.

## What is the new behavior?

- Legacy `Button` now defaults to neutral `default`
- Intentional primary CTAs (create, save, submit, marketing CTAs, and
matching `ButtonTooltip` usages) now set `variant="primary"` so their
appearance is unchanged
- Neutral actions that previously relied on the old fallback (cancel,
close, back, dashboard nav, and similar) become grey/white
- Design-system docs updated; regression tests cover the new default

`Button_Shadcn_` is unchanged. It already uses its own CVA default.

This is PR 1 of 2 in a stack. PR 2 drops now-redundant
`variant="default"` props.

## To test

Studio (http://localhost:8082):

- `/sign-in`: Sign in stays green
- Open a project → Database → Tables: New table stays green
- Auth → Users → Invite: Invite user stays green; Cancel / dismiss
controls stay neutral
- Project Settings → General: edit a field so Cancel and Save appear.
Cancel is neutral, Save is green

Design system (http://localhost:3003):

- Components → Button: default demo is neutral; primary demo is green;
featured preview is the default variant

Marketing (optional):

- www header: Start your project stays green; logged-in Dashboard is
neutral

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Style**
- Buttons now default to a neutral style, while primary actions across
Studio, documentation, marketing pages, forms, dialogs, and error states
use prominent primary styling.
- Updated button examples and previews clarify the distinction between
default and primary variants.
  - Event registration now includes a directional arrow icon.

- **Tests**
- Added coverage confirming default button styling and explicit primary
styling behave as expected.
- Updated related test fixtures to use primary styling where
appropriate.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-10 11:23:17 +10:00
Gildas Garcia bfb0737d14 Fix to ensure labels, descriptions and validation errors are correctly linked to their inputs (#50080)
## Problem

`FormItemLayout` does not correctly binds inputs descriptions and
validation messages to their inputs. This is because the input ids are
generated and not correctly propagated to the `FormMessage` and
`FormDescription` components. Besides, we still pass `name` or `id`
directly to the inputs or `FormItemLayout` in some places.

## Solution

- Fix `FormItemLayout` to correctly binds inputs descriptions and
validation messages to their inputs
- Fix incorrect usages
- Fix Design System documentation

## How to test

The issue is visible in production:
- Open https://supabase.com/design-system/docs/ui-patterns/forms
- Open the devtool and check the labels `for`, the description `id` and
the input `id` or `aria-describedby` attributes. You'll see they often
don't match

Do the same on staging:
- Open
https://design-system-git-fix-a11y-form-input-descriptions-supabase.vercel.app/design-system/docs/ui-patterns/forms
- Open the devtool and check the labels `for`, the description `id` and
the input `id` or `aria-describedby` attributes. They now match

Dashboard fixes:
-
https://studio-staging-git-fix-a11y-form-input-descriptions-supabase.vercel.app/dashboard/account/tokens:
_Expires in_ select button is now correctly linked to its label
-
https://studio-staging-git-fix-a11y-form-input-descriptions-supabase.vercel.app/dashboard/account/me:
the switches are now correctly linked to their label
- In Database/Indexes: the select buttons when creating an index are now
correctly linked to their label
- All other changes are the same things
2026-09-08 09:47:32 +02:00
c086fe0d3f fix(studio): stop duplicating access_token_creation_sheet_dismissed on Done (#50077)
<!-- ccr-slack-attribution -->
_Requested by **Pam Chia** · [Slack
thread](https://supabase.slack.com/archives/C076KTY11DF/p1788743741768969?thread_ts=1788743741.768969&cid=C076KTY11DF)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (telemetry).

## What is the current behavior?

`access_token_creation_sheet_dismissed` (added in #49965) fires on every
close of the "Generate token" sheet in `/account/tokens`, including a
successful completion. The "Token created" step closes the sheet through
a "safe" path (clicking **Done**), but `handleOpenChange` tracked the
dismissed event on that path too: a 1:1 duplicate of the already-tracked
`access_token_done_button_clicked` event, with `step: 'success'`.

The event's `tokenType` property was also never meaningful: it is
derived from a variable that is only set after a token is actually
created and never reset, so on a first-attempt abandonment it is always
`'none'` by construction, and on a later abandonment in the same session
it carries the *previous* token's type.

The sheet also force-closes when the permissions map fails to load. That
close was indistinguishable from a user abandonment.

Linear:
[GROWTH-1196](https://linear.app/supabase/issue/GROWTH-1196/fix-access-token-creation-sheet-dismissed-duplicate-on-done)

## What is the new behavior?

- The event no longer fires on **Done**. The token-created step already
blocks Escape, outside click, and Cancel, so the event now only reflects
the sheet closing before a token exists.
- Dropped `tokenType` (never described the abandoned attempt, see above)
and `step` (a constant `'form'` once Done stops firing it; it was also
typed Numeric project-wide in PostHog, so its string values read as NULL
in HogQL).
- New properties, read from the live form at close time through a small
`useImperativeHandle` ref on `NewScopedTokenForm` (`useForm` ownership
stays inside the form component):
- `resourceAccess` (`project` | `organization` | `account`): the
in-flight scope selection. `account` is the classic-token path, so this
carries what `tokenType` was meant to. It is the default `project` when
the form is untouched, so filter on `isFormTouched` before reading it as
intent.
- `formStep` (`form` | `review`): which screen the user was on. The
sheet-level `step` never captured this.
  - `isFormTouched`: whether any field was changed from its default.
- `trigger` (`user` | `permissions_load_error`): the forced close on a
failed permissions load now fires with its own trigger, so an endpoint
regression shows up in the funnel instead of silently lowering
`access_token_created`.
- Fixed a double-fire on the load-error path: the form's error effect
depended on the `onCancel` callback identity and re-ran on the sheet's
close re-render (double toast, and a double event). It now reads the
callback through a ref and depends only on `isError`, matching the
existing `isReducedMotionPreferredRef` pattern in the same file.

## Additional context

`NewScopedTokenSheet.test.tsx` asserts: Done does not emit the dismissed
event; Cancel and Escape emit it with `trigger: 'user'` and the
in-progress `resourceAccess` and `isFormTouched`; dismissing from the
review screen reports `formStep: 'review'`; a 500 from the permissions
endpoint emits exactly one event with `trigger:
'permissions_load_error'` and closes the sheet.

`step` being typed Numeric in PostHog affects every event that sends a
string `step`. That is a PostHog data-management fix handled separately,
not in this PR.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01XW73umv73LrrKxFwwymSaH

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-09-07 16:53:56 +08:00
Gildas Garcia 50a6ebbe6d Scoped PAT: improve error handling when showing a token details (#49997)
We already have proper error handling on:

- the token list query
- token creation/deletion with toasts

We had custom error handling on the token permissions sheet. Replaced it
with an `AlertError`:

<img width="798" height="371" alt="image"
src="https://github.com/user-attachments/assets/24145308-b1cd-491f-8f54-0c628dd185ce"
/>

Question: should we do something about the sheet header when the token
couldn't be loaded?

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved the access token loading error state with a clearer,
consistent error display and “Please try again” guidance.
* Added a fallback label of “Unknown” when an access token name is
unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-04 17:18:40 +02:00
kemal.earthandGildas Garcia 8654991847 feat(studio): additional events for scoped pat telemetry (#49965)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds PostHog tracking to the final step of the scoped PAT creation flow,
after `access_token_created` fires. The token value is only ever shown
once, so this measures whether users actually leave with a usable token.

Three new events on the "Token created" step:

| Event | Properties |
| --- | --- |
| `access_token_copied` | `tokenType` |
| `access_token_stored_checkbox_clicked` | `tokenType`, `isChecked` |
| `access_token_done_button_clicked` | `tokenType`, `hasCopiedToken` |

- `isChecked` is the resulting state, so unticking the acknowledgement
is captured too.
- `hasCopiedToken` records whether the Copy button was used before
finishing. Done is gated on the checkbox, not on copying, so this
separates "copied it" from "ticked the box and left."
- `tokenType` is threaded through from the sheet, which creates a
classic token when resource access is `account` and a scoped one
otherwise. It matches the existing `access_token_created` /
`access_token_removed` property.

## Changes

- `packages/common/telemetry-constants.ts` — three event interfaces,
added to the
`TelemetryEvent` union
- `NewScopedTokenSuccess.tsx` — `useTrack()` plus a new `tokenType`
prop;
copy/acknowledge/done routed
- `NewScopedTokenSheet.tsx` — `createdToken` state now holds `{ token,
tokenType }` so
the success step knows which
- `NewScopedTokenSheet.test.tsx` — extended the two tests that already
walk the full
success flow with assertions  and classic paths)

## Testing

`pnpm test:studio` on `NewSco16 passing. Typecheck clean.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Analytics**
* Added tracking for key access-token creation interactions, including
copying tokens, selecting storage options, and completing the flow.
* Tracking distinguishes between classic and scoped access tokens and
records whether a token was copied before completion.
* Added tracking when the access-token creation sheet is dismissed,
including the current step.

* **Behavior**
* Existing copy, storage-selection, notification, and completion actions
continue to work as expected.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-09-04 11:15:18 +02:00
Gildas Garcia 6181e27b93 Scoped PAT: ensure innaccessible resources are distinguishable (#49948)
## Problem

When users don't have access to some resources targeted by a token, we
show those resources slugs or refs. However, they are not
distinguishable enough.

## Solution

- Make them distinguishable by applying the _destructive_ color
- Cleaned up unused code (`isInaccessible` prop wasn't used anymore
after last refactoring but we forgot to remove it)

## How to test

1. Invite another user to one of your projects
2. As this other user, create a scoped pat targeting the project
3. As the initial user, remove the invited user from the project
4. As the invited user, check the token permissions: you should see an
admonition at the top and the project should be displayed in red with
only its ref (not its name)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Access token resource indicators now accurately show when an
organization or project is inaccessible.
- Inaccessible resources are clearly labeled as “revoked,” reducing
ambiguity about their access status.

- **Style**
- Organization and project access indicators now use consistent badge
styling, spacing, and icon treatments.

- **Accessibility**
- Revoked status messages are now announced more clearly to assistive
technologies.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-03 14:48:05 +02:00
kemal.earth d088ec6259 fix(studio): project selector fetch on scoped pat (#49865)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

The scoped-access-token project selector fetched a single page of the
user's projects across all orgs and filtered client-side, so switching
to an org whose projects weren't in that page left the list empty with
no way to load more. Use the org-scoped projects query instead, keyed on
the selected org, and fix project search to match by name.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Project selection now displays projects belonging to the currently
selected organization.
* Switching organizations refreshes the available project list,
preventing projects from another organization from appearing.

* **Tests**
* Added coverage for organization-specific project loading, organization
switching, pagination, and empty project lists.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-02 09:29:58 +01:00
Gildas Garcia 3146650a5a Fix FormItemLayout usages for a11y (#49761)
Follow up of #49637. Usages that impacted tests were fixed in the
previous PR. This PR fixes the other usages so that label are correctly
linked to their inputs.

No visual changes

## How to test

1. Design system: [Form
examples](https://design-system-git-fix-form-item-layout-usages-supabase.vercel.app/design-system/docs/ui-patterns/forms):
moved `FormControl` around the `SelectTrigger` so that the label is
linked to the button (It's actually done like this in the [Select Form
example](https://design-system-git-fix-form-item-layout-usages-supabase.vercel.app/design-system/docs/components/select#form)
and Radix recommend targeting the button too in their
[documentation](https://www.radix-ui.com/primitives/docs/components/select#labelling))
2. [Access
tokens](https://studio-staging-463111oii-supabase.vercel.app/dashboard/account/tokens):
updated usage to fallback on generated ids and fixed the select just
like _1_
3. [New TOTP
factor](https://studio-staging-463111oii-supabase.vercel.app/dashboard/account/security):
updated usage to fallback on generated ids
4. _Studio/Database/Extensions_
(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/database/extensions`):
updated the extension enabling modal to fallback on generated ids
5. _Studio/Integrations/Vault
(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/integrations/vault/secrets`):
updated the secret edition modal to fallback on generated ids
6.
_Studio/Observability(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/observability`):
updated the report creation and edition modals to fallback on generated
ids
7. _Studio/SQL
Editor(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/sql/new`):
updated the query renaming modal to fallback on generated ids
8.
_Studio/Storage/Analytics(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/storage/analytics`):
updated the table creation sheet to fallback on generated ids (you must
have a bucket first)
9.
_Studio/Workers(`https://studio-staging-463111oii-supabase.vercel.app/dashboard/project/[PROJECT]/workers`):
updated the worker creation modal to fallback on generated ids (you must
have a bucket first)
10. Updated
[Signup](https://studio-staging-463111oii-supabase.vercel.app/dashboard/sign-up?returnTo=%2Fnew),
[Signin](https://studio-staging-463111oii-supabase.vercel.app/dashboard/sign-in)
and [SSO
Signin](https://studio-staging-463111oii-supabase.vercel.app/dashboard/sign-in-sso)
forms to fallback on generated ids

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- Standardized form field presentation across access tokens,
authentication, reports, integrations, database extensions, SQL editor,
storage, and worker deployment workflows.
- Updated password fields and visibility toggles for more consistent
input behavior.
- Refined token expiration selection, verification code entry, and
dropdown layouts.
- Preserved existing labels, validation, options, and form functionality
while simplifying the interface structure.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 15:22:55 +02:00
Wen Bo Xie 2681a21f5c docs: add Personal Access Tokens guide with generated permission tables (#49732)
Add a guide that compares classic and scoped personal access tokens,
explains how account roles constrain token permissions, and walks
through creating and testing a project-scoped token. Include generated
tables mapping permissions to Management API endpoints and MCP tools,
and link the guide from docs navigation and Studio token sheets.

Move the scoped-token permission catalog from Studio into shared-data.
Studio and docs generation now share permission names, categories,
descriptions, risk metadata, modes, scopes, and display order.

Generate the tables from the shared catalog, OpenAPI
x-fga-permissions, and the downloaded MCP permission map. Exclude
Workers permissions until the feature is live.

Run regeneration through the docs Makefile, verify checked-in output in
CI, and refresh it in the weekly Management API workflow. Add Dashboard
and Docs ownership plus contributor guidance so permission changes stay
synchronized.
2026-09-01 12:30:56 +00:00
Ivan Vasilov 02cf09212e chore: Remove tsconfig paths (#49770)
This PR removes all `paths` in `tsconfig.json` for all apps and
packages. They were added previosly because some of the components had a
`_Shadcn` suffix because of an ongoing migration. How that the migration
is done, the paths can be removed.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Refactor**
* Standardized shared UI component, utility, and icon imports across
design-system examples and application screens.
  * Simplified shared component access and project configuration.
  * Added shared access to anchor-link helpers and animation styles.

* **Compatibility**
* Updated component exports and imports without changing existing
behavior.
  * No changes to user-facing workflows, screens, or functionality.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-01 13:13:30 +02:00
Gildas Garcia 4f92790587 fix: FormItemLayout does not apply item id correctly (#49637)
## Problem

`<FormItemLayout>` does not apply item id correctly. This can be seen on
https://supabase.com/design-system/docs/ui-patterns/forms: open the
devtool and check the form items labels. They have no `for` attribute.
This makes it harder to correctly test and is an accessibility issue.

Axe devtool actually report it

## Solution

When inside React Hook Form, `<FormItemLayout>` actually generate an
`id` (via `<FormItem>`). However, this `id` is overridden in
`<FormLayout>` and read from context by `<FormLabel>`. Ensure we use the
generated id unless one was provided.

Also updated the paths filters for the CI check so that any changes in
either `ui` or `ui-patterns` triggers the studio unit and e2e tests.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved form accessibility by ensuring labels consistently connect to
their corresponding input fields.
- React-based forms now correctly preserve field-specific identifiers
when associating labels with inputs.
- Added support for explicitly specifying a label’s input target,
improving compatibility with customized form layouts.
- Updated Studio forms to use consistent control identifiers and
labeling behavior.

- **Quality Improvements**
- Automated validation now also runs when shared UI components and
patterns are updated.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-31 10:32:45 +02:00
claude[bot] c32db2b80b fix(studio): track resourceAccess='account' for legacy access tokens (#49448) 2026-08-24 16:44:23 +08:00
kemal.earth 0218de559b fix(studio): validation scroll area bug in scoped pat (#49395)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

When trying to submit the scoped pat creation form a second time, after
expanding accordion in the `<ScrollArea />` the `scrollTo` was breaking
the height of the container. This PR fixes that.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved the missing-permissions warning when creating scoped access
tokens.
- The warning now scrolls into view after each invalid submission
attempt, using smooth scrolling when supported.
- Prevented repeated scrolling during unrelated form updates or
motion-preference changes.
- Selecting a permission or applying a non-empty preset clears the
warning state.
  - Improved accessibility by respecting reduced-motion preferences.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 17:32:59 +01:00
Gildas Garcia c7e8373bce Scoped PAT: Fix projects handling when user has more than 100 projects (#49393)
## Problem

Some users have more than 100 projects and our current UI has the
following issues:

1. The project selector only loads the first 100 making it impossible to
see more
2. The review step and the token permissions view only loads the first
100 so we may display invalid warnings about missing projects

However, we currently don't have an API route to fetch many projects by
their refs in a single call.

## Solution

1. Make sure we load more projects when scrolling down in the project
selector
2. When below 100 project, show the admonition for missing resources.
Anyone above for the time being won't see these message and we display
the project refs instead of their names

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Improved scoped access-token setup with paginated project loading and
an easier scrolling project selector.
- Organization and project access are now displayed as separate, clearer
access indicators.
- Access details show project information when available, with a
fallback reference when details cannot be loaded.

- **Bug Fixes**
- Updated resource warnings to better reflect deleted resources and
large project lists.
  - Improved multi-select list handling for more reliable interactions.
- Preserved the name of inaccessible organizations when displaying lost
access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 18:01:28 +02:00
kemal.earth 31497ba127 feat(studio): add permission presets to scoped pat creation form (#49381)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This adds a quick presets selector to scoped pat permissions. No access,
read-only and full access.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added permission presets for scoped access tokens: No access,
Read-only, and Full access.
  * Added a selector to quickly configure permissions across resources.
  * Displays “Custom” when individual permissions differ from a preset.
  * Shows warnings and guidance for high-risk full-access permissions.
* Automatically uses read-only access for resources that do not support
write permissions.

* **Tests**
* Added coverage for preset selection, application, warnings, ordering,
and custom configurations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 11:12:37 +01:00
Gildas Garcia 54f56a1baa Scoped PAT: use CSS for the long text reveal animation (#49245)
Simplify the code for the long text reveal animation on hover using only
CSS. This also improves performances on some devices

## How to test

- Open
https://studio-staging-git-gildas-scoped-pat-css-only-a-1d2de2-supabase.vercel.app/dashboard/account/tokens
- Create a token with project settings read/write permissions
- In the review step, ensure you can hover long URL to trigger a
scrolling animation showing its end
- In the review step, ensure short URL don't have this animation on
hover
- Create the token
- Open its permissions and check the hover effects again

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Style**
- Improved endpoint path reveal animations with smoother transitions and
masking.
  - Added responsive behavior based on available container space.
  - Increased transition duration for easier reading.
  - Added support for reduced-motion preferences.
- **Bug Fixes**
- Improved endpoint path visibility and hover behavior while preserving
the existing copy interaction.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-19 12:12:55 +02:00
kemal.earth ce27b4ee5b chore(studio): scoped pat mcp tool ui improvement (#49188)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Follow on from view permissions sheet and review step tidy up to show a
clear list of available mcp tools.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added an “Available MCP tools” section to scoped token reviews and
token details.
* Displays enabled tools as badges, with a clear empty state when none
are available.
* **Improvements**
  * Simplified capability cards to focus on enabled API endpoints.
* Removed per-permission MCP tool details and ungranted capability
listings.
* Updated endpoint count formatting for clearer singular and plural
labels.
* **Tests**
* Updated capability and token detail tests to reflect the new MCP tool
summary presentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 12:29:12 +01:00
dbb153042e feat(studio): cleaned up view permissions sheet (#49144)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Breaking down #49007 into smaller PR's. Part 1 merged in.

More to follow...


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Redesigned token capability details with expandable cards and dense
views for larger permission sets.
  * Added filtering by all, read, and read-write capabilities.
* Improved endpoint and MCP tool attribution, display, and endpoint
copying.
  * Added risk banners with permission and access warnings.
* Enhanced resource badges, responsive layouts, relative timestamps, and
dismissible creation guidance.

* **Bug Fixes**
  * Corrected MCP tool attribution across alternative permission scopes.
  * Improved handling and display of inaccessible resources.

* **Tests**
* Expanded coverage for capability views, filtering, risk messaging, and
permission evaluation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-08-18 10:58:56 +01:00
Danny White fba3733148 test(studio): allow scoped token creation in CI (#49163)
## What kind of change does this PR introduce?

Test reliability fix.

## What is the current behavior?

The two longest scoped access token creation tests can exceed Vitest's
default five-second timeout when they run under the full Studio CI
shard, despite passing locally.

## What is the new behavior?

The project-scoped and organisation-scoped token creation tests each use
a targeted ten-second timeout. The global timeout and production code
remain unchanged.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Increased test timeouts for project- and organization-scoped token
creation scenarios to improve test reliability.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 11:40:40 +10:00
Danny White 14fe0c0cc8 fix(studio): slightly round split-button corners on focus (#49129)
## What kind of change does this PR introduce?

UI polish for split buttons (primary action + dropdown chevron).
Follow-up to #49055.

## What is the current behavior?

The focus ring sits above the neighbouring half, but the inner edge
stays square, so the ring has two sharp corners at the join.

## What is the new behavior?

On keyboard focus, the squared-off edge uses a slight radius so the ring
matches the outer corners more closely. Resting state is unchanged.
Split-button callsites now share the same join classes as the
design-system example.

| Before | After |
| --- | --- |
| <img width="1030" height="296" alt="43471"
src="https://github.com/user-attachments/assets/9df3bd72-c7ac-4419-ae18-a7e649dc2d66"
/> | <img width="1056" height="276" alt="CleanShot 2026-08-17 at 10 45
09@2x"
src="https://github.com/user-attachments/assets/52e8a4dc-9c52-45ce-b4d0-f0e7b1b75935"
/> |

## To test

Tab to each half (labelled button, then chevron). Inner corners of the
focus ring should be slightly rounded, not square.

1. [Split with
dropdown](https://design-system-git-fix-split-button-focus-radius-supabase.vercel.app/design-system/docs/components/button#split-with-dropdown)
(no login)
2. [Access
Tokens](https://studio-staging-git-fix-split-button-focus-radius-supabase.vercel.app/dashboard/account/tokens)
→ Generate new token
3. Any project on [studio
staging](https://studio-staging-git-fix-split-button-focus-radius-supabase.vercel.app/dashboard/_/settings/general)
→ Settings → General → Restart project

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Accessibility**
  - Added accessible labels to dropdown and export controls.
- Improved keyboard-focus visibility, layering, and rounded edge
treatment across joined buttons and menus.
  - Removed misleading or redundant screen-reader text and titles.

- **Bug Fixes**
- Prevented split-button controls from shrinking or displaying awkward
borders and corners.
- Refined hover and focus behavior for action buttons throughout
settings, database, storage, account, and documentation interfaces.

- **Documentation**
- Clarified guidance for using overflow menus and responsive
split-button actions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 17:28:22 +10:00
kemal.earth 88e916a4c0 fix(studio): focus state for buttons with dropdown (#49055)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

We've quite a few instances where some buttons have a dropdown
appendage. The focus state for these were broken as well as visually
regarding the separator. This first pass fixes the instances we have in
studio, I've left potentially adding this to our design system fragment
components as another PR.

| Before | After |
|--------|--------|
| <img width="531" height="133" alt="Screenshot 2026-08-13 at 11 29 36"
src="https://github.com/user-attachments/assets/70747fd0-11d4-4670-85fa-d76f3564837b"
/> | <img width="519" height="130" alt="Screenshot 2026-08-13 at 11 40
15"
src="https://github.com/user-attachments/assets/5920bebb-81ce-4962-908b-5f61526ca7ca"
/> |
| <img width="538" height="146" alt="Screenshot 2026-08-13 at 11 29 48"
src="https://github.com/user-attachments/assets/f1c7018f-cd43-47fa-b4c0-045af350f80b"
/> | <img width="515" height="148" alt="Screenshot 2026-08-13 at 11 39
56"
src="https://github.com/user-attachments/assets/fee09113-433a-4b5d-ac68-3ab3f2565d34"
/> |
| <img width="538" height="143" alt="Screenshot 2026-08-13 at 11 29 52"
src="https://github.com/user-attachments/assets/3063d391-99b2-4599-9cdf-edd0b2cdfdf0"
/> | <img width="529" height="159" alt="Screenshot 2026-08-13 at 11 40
05"
src="https://github.com/user-attachments/assets/4bdeb9e0-8324-45df-a211-8c7fd0ee11a6"
/> |




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved keyboard focus visibility across Studio controls, including
token management, email settings, replication, log drains, query
insights, infrastructure, storage, and assistant actions.
* Focused buttons in adjacent or split-button groups now appear above
neighboring controls, preventing borders and overlays from obscuring the
active selection.
* Preserved existing button behavior, layout, and appearance while
improving focus-state clarity.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-13 12:45:06 +01:00
kemal.earth 99545dc03a chore(studio): remove mcp mention in legacy token creation (#48945)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Small bit of lingering text that was leftover.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the legacy access token description to remove an outdated
reference.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 17:13:18 +01:00
kemal.earth 1cc0682c47 chore(studio): remove admonition now that mcp supports scoped pat (#48931)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This removes the pre-cautionary admonition we had before the MCP support
for scoped access tokens landed. We can now remove this admonition (and
anything related) as it's been merged.

| Before | After |
|--------|--------|
| <img width="790" height="202" alt="Screenshot 2026-08-11 at 09 11 08"
src="https://github.com/user-attachments/assets/8b99d93f-c398-4b86-84fe-e63a2ba40e26"
/> | <img width="781" height="104" alt="Screenshot 2026-08-11 at 09 17
18"
src="https://github.com/user-attachments/assets/b28b8262-ec01-4686-ace8-50065eb22822"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Changes**
* Removed the MCP unsupported warning from scoped access-token creation
and viewing screens.
* Removed the option to switch from scoped-token creation to the legacy
account-wide token flow.
  * MCP tools now display directly when available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 09:48:02 +01:00
kemal.earth 5b68af1720 feat(studio): role-aware access feedback in scoped token creation (#48858)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Remaining bits of #48714


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added role-aware access checks throughout scoped token creation.
* Organization selectors now disable project-only organizations and
recommend project-scoped tokens when appropriate.
* Review screens highlight missing capabilities and permissions
exceeding your current role.
  * Permission rows display indicators when access exceeds your role.
* Added resource keys, labels, and summaries to improve token review
clarity.

* **Documentation**
* Updated permission guidance with links to access-control
documentation.

* **Bug Fixes**
* Corrected project selector behavior when no organization is selected.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-08 08:19:35 +01:00
kemal.earthandClaude Sonnet 5 124ff77ad0 feat(studio): warn that scoped tokens don't support the MCP server (#48849)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Scoped PATs are blocked from the Supabase MCP server until AI-1025 ships
FGA guard support, so surface that on the scoped review step (with a
link back into legacy mode) and on the view-token sheet, sharing one
warning module for easy removal.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a clear notice explaining that scoped access tokens aren’t
supported by the Supabase MCP server.
  * Added an option to create a legacy token when applicable.
* Displayed the MCP compatibility notice in token review and access
views.
* **UI Improvements**
  * Organization selectors now display their associated icons.
* Standardized MCP guidance across token-related screens for a more
consistent experience.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-07 17:41:45 +01:00
kemal.earthandClaude Sonnet 5 33482bdc88 feat(studio): lifecycle and role-aware scoped token view sheet (#48848)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Extracts the token view sheet slice of #48742
(w3b6x9/scoped-pat-access-feedback, commit 56ef87a). The role-evaluation
logic (estimateRoleLevel, computeTokenRoleContext,
applySelectionToRoleContext, groupFailingResources) already landed on
master via #48805 and #48809 — this PR only wires the view sheet up to
it:

- Bindings whose project/org was deleted (FGA bindings erased) render a
"resources no longer exist" state; bindings the user can no longer reach
render an anonymous count with a "No longer accessible" badge and a
"removed from" admonition.
- Accessible resources list their name plus ref/slug; capabilities show
"Exceeds your role" pills and the risk badge reflects what the owner's
current role actually allows.
- Header split into separate "Access control" and "API docs" buttons.
- Everything recomputes from live org/project/permission queries (no
stored state) and degrades to no warnings while loading or on
self-hosted.

Also gives DocsButton an optional `label` prop (defaults preserve
existing behavior for every other consumer) so the two header buttons
can carry distinct text.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Enhanced access-token details with permission categories, risk
summaries, endpoint, and MCP information.
  * Added warnings for permissions exceeding the token’s role.
* Clearly identifies inaccessible, deleted, or unavailable organizations
and projects.
  * Added resource details and remediation guidance for unusable tokens.
  * Documentation links can now display custom labels.

* **Bug Fixes**
* Improved access evaluation when organization or project data is
incomplete or access has changed.
  * Deferred resource loading until token details are opened.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-07 17:19:30 +01:00
kemal.earthandClaude Sonnet 5 3a98b0c818 feat(studio): add legacy token mode to scoped pat creation flow (#48844)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Replaces the scoped form's inline account-level access mode with a
proper legacy-token escape hatch: "Create legacy token" switches the
sheet to the classic form (name + expiry only) and creates through the
legacy endpoint, skipping the two-step review. Mirrors the mode-switch
links in both directions and restores the "Generate token for
experimental API" split-button dropdown, extracted into a shared
ExperimentalTokenDropdown.

Ported from origin/w3b6x9/scoped-pat-ui-rework, excluding its expiry
handling (shipped in #48811) and MCP-unsupported warnings (follow-up
PR).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added support for creating classic account-wide access tokens
alongside scoped tokens.
  * Added an experimental token dropdown for quick token creation.
* Added links to switch between scoped and legacy token creation flows.
* Classic token creation now provides dedicated warnings and simplified
access settings.

* **Improvements**
* Updated token access messaging, descriptions, and labels for clarity.

* **Tests**
* Expanded coverage for token creation, navigation, validation, and
clipboard behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-07 13:05:56 +01:00
e8f5120dc5 feat(studio): enforce expiry scoped pat (#48811)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

Waiting on #48809


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added custom access-token expiration date limits, allowing dates from
today through one year ahead.
* Date pickers now enforce configured minimum and maximum date
boundaries.

* **Updates**
  * Removed the option to create non-expiring access tokens.
  * Expiration is now required when creating classic access tokens.
  * Improved form reset behavior and expiry tracking.

* **Tests**
* Added validation coverage for required, valid, and out-of-range custom
expiration dates.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Wen Bo Xie <wenbox323@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 10:09:21 +01:00
f8206a5f81 fix(studio): model scoped pat permissions as OR-of-AND alternatives - smaller version (#48809)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Breaking down #48635


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Scoped access tokens now support alternative permission requirements,
enabling more precise access for APIs and tools.
- Added clearer role and resource access evaluation, including
project-specific permissions and partial read access.
- Access reviews now identify unavailable or excessive permissions and
group inaccessible resources for easier resolution.
- **Bug Fixes**
- Improved handling of legacy, incomplete, or invalid permission data
with safer fallback behavior.
  - Corrected access filtering for MCP tools and API capabilities.
- **Documentation**
- Updated access-review wording to clarify the relationship between
scopes and related MCP tools.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Wen Bo Xie <wenbox323@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 09:51:36 +01:00
2a3025df25 feat(studio): role inference core for scoped pat (#48805)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Logic-only extraction from #48742. Scoped PATs are enforced server-side
as the intersection of the token's granted scopes and the owner's live
role, re-checked on every request. This lands the pure inference layer
that will power advisory (never blocking) UI feedback; no UI consumes it
yet.

- FGA_SCOPE_MINIMUM_ROLE: all 83 permission scopes transcribed from the
OpenFGA model's role unions, mapped to the lowest base role that holds
them. A drift-guard test pins the key set to the scope ids published in
@supabase/shared-types, so upstream additions fail CI here with
re-transcription instructions.
- estimateRoleLevel: derives the user's base role per org (or per
project for project-invited members) from the ungated /platform/profile/
permissions rows via four discriminating ABAC probes. Works for every
member type with no permission-gated endpoint.
- computeTokenRoleContext + applySelectionToRoleContext: role resolution
(expensive, memoized) is split from selection evaluation (cheap, re-run
per permission toggle).

AccessToken.permissions.ts gains only what the roles module needs: the
PermissionLevel type and the catalog's `level` field (decides whether an
org or project role governs a resource), plus getEntryScopes, which
selectionToScopes now reuses. The UI-only additions from #48742 (risk
badge/dot variants, mode labels, the OverallRisk.text -> description
rename) are deliberately left out so this PR touches no .tsx.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added role-aware evaluation for scoped access-token permissions.
* Added support for organization- and project-level permission scoping.
* Added guidance when selected permissions exceed the current role,
including read-only downgrades and inaccessible resources.
  * Added clearer grouping of permission access issues by resource.

* **Tests**
* Added comprehensive coverage for role mapping, permission evaluation,
scoping, and failure scenarios.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Wen Bo Xie <wenbox323@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 17:31:41 +01:00
33008a39e5 chore(studio): remove scoped pat orphaned form (#48803)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

First step in breaking down #48635


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Removed the scoped access-token form, including token details,
expiration settings, resource access, and permission configuration.
* Removed resource and permission selection controls from the
access-token workflow.

* **Tests**
* Removed automated coverage for access-token validation, permission
handling, expiration logic, and resource selection.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Wen Bo Xie <wenbox323@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 17:20:55 +01:00
cddb430310 feat(studio): scoped pat root branch (#48384)
## Description

This is the Scoped PAT stacked PRs root branch

## How to test

### With the `scopedPAT` enabled (default on staging)

Go to
https://studio-staging-git-scopedpat-merge-token-lists-supabase.vercel.app/dashboard/account/tokens.
- You shouldn't see two tabs anymore
- If you had classic tokens, they should have the _Legacy_ badge
- You can create scoped tokens
- You have a way to copy newly created tokens before closing the form
side panel

### With the `scopedPAT` disabled (use the devtool to override)
- You shouldn't see two tabs anymore
- If you had classic tokens, they should **not** have the _Legacy_ badge
- You can create classic tokens
- You have a way to copy newly created tokens above the list upon form
submission

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Show classic and scoped access tokens together in one list, with
classic tokens labeled “Legacy” when the scoped experience is enabled.
* Add scoped access token creation with a two-step configure → review →
success flow (when enabled).
* Add a dismissible migration notice about scoped tokens with a link to
API docs.
  * Show “View permissions” only for scoped tokens.
* **Bug Fixes**
* Token deletion now supports both classic and scoped tokens with the
correct confirmation and success handling.
* The scoped tokens page now redirects to the unified access tokens
page.
* **Accessibility**
* Improved accessibility by adding a label to the token “more options”
action.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
Co-authored-by: kemal.earth <606977+kemaldotearth@users.noreply.github.com>
2026-08-06 07:40:56 -06:00
ChloeGarciaMillerand e241a21a9a fix: ESLint errors relating to accessibility in table editor, API Key and Access Token (#48479)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added aria-label attributes and Tooltip to buttons

## What is the current behavior?

alt attributes and Tooltip were missing

## What is the new behavior?

Buttons have now aria-label attributes and Tooltip.

## Additional context

No visual changes have been made.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Accessibility Improvements**
* Added tooltips and improved accessible labeling for filter removal,
sort controls, and action menu triggers.
* Enhanced “More actions”/“More options” tooltips and aria-labels for
API keys and access tokens.
* Updated token scope selection and token banner close actions to use
clearer tooltip messaging.
* Wrapped panel close control with a tooltip and added an aria-label for
clearer screen reader support.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-31 18:05:41 +02:00
Joshen Lim fcfb0f0222 Refactor all usage of form.watch to either useWatch or subscribe (#48436)
## Context

Replaces all usage of `form.watch()` to use `useWatch` instead + follows
the "name what you watch" convention as specified in the react-hook-form
skills.

There's also a small refactor in `SmtpForm.tsx` which removes the
unnecessary use of a `useState` to track if SMTP is enabled or not

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Updated many Studio forms to watch specific fields more precisely,
improving live UI updates for previews, warnings, conditional sections,
and validation messages.
* Enhanced responsiveness across settings, authentication, billing,
storage, integrations, and support flows while keeping save/update
behavior the same.
* **Refined Experiences**
* Improved the analytics table creation flow with tighter, enum-based
column type validation and structured, type-specific column options.
* **Preserved Behavior**
* Maintained existing permission checks, submission flows, and
account-management workflows.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-30 11:45:40 +08:00
Miranda Limonczenko 0d465e7b5f chore(ui): Remove 'tip' from Admonition (#48419)
Closes FE-3966

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## Problem

- The admonition uses both 'tip' and 'note', but the visual distinction
has long-ago collapsed.
- 'Note' is used far more frequently than 'tip'
- The two are very similar and it is confusing to know which one to use
when they are visually identical

## Solution

Collapse 'tip' and 'note' into one by removing all places where there is
'tip' and updating all references to 'tip' into 'note'.

**Note:** This PR also resolves new broken links flagged by the E2E docs
checker. It may move to another PR since E2Es keep erroring.

### Specific changes

See below for an AI-generated list of changes:

- **Type system** — removed `'tip'` from `AdmonitionType`, its
`TYPE_TO_VARIANT`/`TYPE_LABEL` entries, and the test case in
[`packages/ui-patterns/src/Admonition/](packages/ui-patterns/src/Admonition/)
- **Remark plugin** —
[remarkAdmonition.ts](apps/docs/lib/mdx/plugins/remarkAdmonition.ts) now
maps mkdocs `tip` → `note`
- **Lint allowlist** — `tip` dropped from `supa-mdx-lint.config.toml`
- **Content migration** — all 109 files with `type="tip"` (across
`apps/docs`, `apps/www`, `apps/studio`) converted to `type="note"`; zero
remaining hits confirmed by repo-wide grep
- **Style guide** — `CONTRIBUTING.md` and `contributing/content.mdx`
updated to describe 4 admonition types instead of 5

### Usage before implementation

See the usage table that points toward 'note' as being dominant across
all apps:

Here's the usage table:

| Location | `note` | `tip` |
|---|---|---|
| apps/docs | ~480 | ~143 |
| apps/studio | 34 | 6 |
| apps/www (blog) | 19 | 3 |
| packages/ui-patterns (tests) | 3 | 1 (parametrized) |
| design-system / ui-library / packages/ui / packages/common | 0–1 (test
fixture only) | 0 |

## Preview links


| App | Page | Search text (Ctrl+F) | Verify |
|---|---|---|---|
| docs |
[/docs/guides/ai-tools/byo-mcp](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/ai-tools/byo-mcp)
| official MCP TypeScript SDK | callout's aria-label="Note" |
| docs |
[/docs/guides/ai-tools/mcp](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/ai-tools/mcp)
| MCP server is available at | callout's aria-label="Note" |
| docs |
[/docs/guides/ai/python-clients](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/ai/python-clients)
| Click Connect at the top of any project page | callout's
aria-label="Note" |
| docs |
[/docs/guides/auth/audit-logs](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/auth/audit-logs)
| Disabling Postgres storage reduces your database storage costs |
callout's aria-label="Note" |
| docs |
[/docs/guides/database/tables](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/database/tables)
| access a custom schema through the Supabase Data API | callout's
aria-label="Note" |
| docs |
[/docs/guides/troubleshooting/edge-function-404-error-response](https://docs-git-admonition-collapse-note-tip-supabase.vercel.app/docs/guides/troubleshooting/edge-function-404-error-response)
| Always configure an appropriate time frame | callout's
aria-label="Note" (was single-quoted type='tip') |
| www | [blog:
cli-v2-config-as-code](https://zone-www-dot-com-git-admonition-collapse-note-tip-supabase.vercel.app/blog/cli-v2-config-as-code)
| Detecting config drift | callout's aria-label="Note" |
| www | [blog:
cli-v2-config-as-code](https://zone-www-dot-com-git-admonition-collapse-note-tip-supabase.vercel.app/blog/cli-v2-config-as-code)
| Setting Edge Function secrets | callout's aria-label="Note" |
| www | [blog:
nosql-mongodb-compatibility-with-ferretdb-and-flydotio](https://zone-www-dot-com-git-admonition-collapse-note-tip-supabase.vercel.app/blog/nosql-mongodb-compatibility-with-ferretdb-and-flydotio)
| If your network supports IPv6 connections | callout's
aria-label="Note" |

Note: the `www` rows use the `zone-www-dot-com` preview host, not the
`docs` one you gave — since blog pages are served from the www app, not
docs.


## Manual testing

1. Open preview links for affected pages.
2. Inspect. Open console.
3. Paste the following in and see there is no 'Tip' on the page:
```
document.querySelectorAll('[role="alert"]').forEach(el => console.log(el.getAttribute('aria-label'), el.textContent.slice(0,60)))
```



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Standardized informational callouts across docs and tutorials from
**“Tip”** to **“Note”**, updating multiple examples and guidance blocks.
* Updated a few related doc references/links and conditional “Next
steps” content.
* **UI Updates**
* Switched various in-app banners and notices to the **“Note”** style
variant.
* **Bug Fixes / Improvements**
* Removed support for the retired **“Tip”** callout type and aligned
docs linting, component behavior, and aria labeling to the remaining
admonition types.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-29 09:26:50 -07:00
Alaister YoungandAlaister Young ca2b50a0a7 chore(ui-patterns): collapse the admonition shim into ui-patterns/Admonition (#48377)
Follow-up to #48344: collapses the two resolution paths for the
Admonition module into one.

`src/admonition.tsx` was a back-compat shim re-exporting
`src/Admonition/`. Two ways to resolve one module is exactly what
produced the macOS self-import bug fixed in #48344, and the local
typecheck errors that #48374 worked around. This removes the shim and
standardizes on the PascalCase subpath, matching every other export in
the package.

**Changed:**

- Codemodded all 246 `ui-patterns/admonition` imports to
`ui-patterns/Admonition` (240 `.tsx`, 5 `.mdx`, 1 `.ts` across studio,
docs, www, design-system, and lite-studio)
- Pointed the 5 internal `'../admonition'` imports back at the
`'../Admonition'` directory

**Removed:**

- `packages/ui-patterns/src/admonition.tsx`, and its `./admonition`
entry in the exports map (regenerated with `pnpm gen:exports`)

## To test

- `grep -r "ui-patterns/admonition" --include='*.ts*'` → no hits
- `pnpm test:case-hazards` → passes
- `pnpm typecheck` → all 15 tasks green
- `pnpm --filter studio run lint:ratchet` → passes
- `pnpm --filter ui-patterns vitest run src/Admonition` → 11 tests pass

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Standardized Admonition component imports across the application and
documentation.
* Improved compatibility with case-sensitive environments by using the
canonical component path.
  * Removed the legacy Admonition import entry point.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-07-29 00:48:56 +08:00
Gildas Garcia dba31df91d fix: scoped PAT creation form error messages are hidden (#48011)
## Problem

When creating a new scoped PAT, if users didn't add at least one
permission or have a misconfigured permission (no access selected), the
form does not submit but no error message is shown. The UI looks broken.

## Solution

This is because there's a zod validation happening but its messages are
not displayed for permissions.
The proper fix is to use react-hook-form field array.

<img width="541" height="633" alt="image"
src="https://github.com/user-attachments/assets/89cab58d-761e-4131-9bce-460625067f8a"
/>

<img width="540" height="594" alt="image"
src="https://github.com/user-attachments/assets/ed95cee0-06b5-4233-9a23-6819fb0e1a17"
/>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved permission selection and toggling behavior in the scoped
access token flow.
* Enhanced validation feedback for permission rows and action
selections, keeping error states in sync after changes.
* Updated error handling to surface permission-related messages more
reliably.
* **Refactor**
* Reworked the permissions UI to use a more reliable control-based
rendering approach for rows, selection changes, and error presentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-17 16:08:13 +02:00
Joshen Lim 22b3419a28 Extract project creation form into its own component (#47957)
## Context

This is just a pre-requisite to consolidating the project creation UI as
there's another page that has the project creation flow too
[here](https://github.com/supabase/supabase/blob/master/apps/studio/pages/integrations/vercel/%5Bslug%5D/deploy-button/new-project.tsx).
So the next step will just be to use the same `ProjectCreationForm`
there

No functional changes here - just moving things around

## To test
- [ ] Verify that project creation still works



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a full “create project” experience with eligibility-aware
defaults, advanced configuration sections, optional GitHub integration,
and compute-cost confirmation when applicable.
* **Improvements**
  * Enhanced project-creation success/error handling and navigation.
* Refined CLI backup/restore dialogs (better layout/wording,
accessibility updates, and improved section separation).
* **Documentation**
* Standardized all relevant documentation links across the app using a
shared `DOCS_URL` source.
* **Refactor**
* Refactored the “New Project” page to delegate the wizard UI and flow
to a reusable creation component.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-16 14:00:55 +08:00
Gildas Garcia b30db91d71 chore: cleanup UI patterns exports (#47406)
## Problem

We now export components under a subpath in ui-patterns to avoid barrel
files as they slow down every tools (from IDE to linters, etc.) and may
also affect bundles our users have to download.

## Solution

- Remove the UI patterns index file
- Fix invalid impors
2026-06-30 09:23:17 +02:00