mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
master
1254
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
51a167d910 |
feat(www): partners landing page (#47874)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a redesigned Partners page with partnership options, benefits, application steps, FAQs, integration resources, and featured partners. - Added an on-page partner application form with questions tailored to the selected partnership type. - Added a confirmation message with next steps and a link to the OAuth integration guide. - **Bug Fixes** - Updated partner application links to open the form on the Partners page. - Added support for checkbox-group fields in forms. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alan Daniel <stylesshjs@gmail.com> Co-authored-by: Alex Hall <alex.hall@supabase.io> Co-authored-by: Dion Zeneli <101271736+Dionysos288@users.noreply.github.com> |
||
|
|
ec53175b8a |
refactor(ui): rename text-brand to text-primary (#50564)
## What kind of change does this PR introduce? Refactor. Follow-up to #49871. ## What is the current behavior? Branded (green) text still uses the `text-brand` classname while the colour comes from `--primary`. ## What is the new behavior? **Rename-only:** `text-brand` → `text-primary` across callsites and docs. Leftover `bg-brand` / `border-brand` alias to `brand-default`. No intentional colour changes in this PR. This better matches how we treat our green in other components and props, like `variant="primary"` for green buttons. ## To test On light mode: smoke-test that branded text still looks like #49871 (readable green, not the bright fill). - [Homepage](https://zone-www-dot-com-git-dnywh-depr-316-text-brand-de2380-supabase.vercel.app/): “Scale to millions” uses `text-primary` - [Docs homepage](https://docs-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/docs): branded links like “More on self-hosting” are still readable - [Typography docs](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/typography): documents `text-primary` - [Colour usage](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/color-usage): `text-primary` is visibly darker than `bg-brand-default` _on light mode_ - [Studio auth providers](https://studio-staging-git-dnywh-depr-316-text-brand-to-60fa6c-supabase.vercel.app/dashboard/project/_/auth/providers): enabled provider badge text readable; status dot stays bright green <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated branded text, link hover states, icons, badges, indicators, and highlighted content across the Design System, Docs, Studio, Learn, UI Library, and marketing experiences to use the primary theme color. * Updated syntax highlighting and table-of-contents styling for consistent primary-color presentation. * Refined brand color fallback behavior for bright fills and borders. * **Documentation** * Updated color-usage and typography guidance to recommend the primary text utility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a31ca2bad0 |
fix(ui): make brand text readable across themes (#49871)
## What kind of change does this PR introduce? Bug fix and design-system update. Resolves DEPR-316. Follow-up rename (`text-brand` → `text-primary`) is in a dedicated PR (https://github.com/supabase/supabase/pull/50564) stacked on this one. ## What is the current behavior? `text-brand` resolves to the canonical bright brand green in places that need readable text, which fails WCAG AA on light surfaces. A separate `text-brand-display` token adds another green for large type. ## What is the new behavior? - `text-brand` maps to accessible `--primary` (light mode darkened to meet ~4.5:1 AA) - `--hue` / `--primary-hue` aligned to 157.5 - `text-brand-display` removed; former display callsites use `text-brand` - Bright fills/borders stay on `brand-default` - Design-system colour and typography docs updated | Before | After | | --- | --- | | <img width="514" height="112" alt="CleanShot 2026-09-02 at 11 13 09@2x" src="https://github.com/user-attachments/assets/4e0138a9-a32d-4e4c-a426-90736706e1e7" /> | <img width="512" height="138" alt="CleanShot 2026-09-21 at 11 42 05@2x" src="https://github.com/user-attachments/assets/164cc5b1-a0c5-4e93-95f1-80016641a114" /> | | <img width="864" height="266" alt="CleanShot 2026-09-02 at 11 13 53@2x" src="https://github.com/user-attachments/assets/3c1ca53f-bf9e-431e-bc15-816b4a275b8e" /> | <img width="882" height="248" alt="CleanShot 2026-09-21 at 11 41 37@2x" src="https://github.com/user-attachments/assets/24828e7b-ed6b-44cb-b9dc-becc3398bdfc" /> | | <img width="782" height="692" alt="CleanShot 2026-09-02 at 11 16 30@2x" src="https://github.com/user-attachments/assets/fc871977-77bc-47fb-9e0e-9284e0ecd5cc" /> | <img width="730" height="690" alt="CleanShot 2026-09-21 at 11 42 52@2x" src="https://github.com/user-attachments/assets/bf479515-d5f9-471e-b82d-f097c0f4b56c" /> | | <img width="480" height="306" alt="CleanShot 2026-09-02 at 11 18 53@2x" src="https://github.com/user-attachments/assets/03f341f4-f02e-44f8-a2b2-8c31670d0427" /> | <img width="470" height="300" alt="CleanShot 2026-09-21 at 11 43 19@2x" src="https://github.com/user-attachments/assets/9df18217-d5e6-48b8-ba0b-579d2664b94b" /> | | <img width="960" height="300" alt="CleanShot 2026-09-02 at 11 32 04@2x" src="https://github.com/user-attachments/assets/6b1d9373-7a71-4247-81ff-26441604b09d" /> | <img width="980" height="306" alt="CleanShot 2026-09-21 at 11 44 13@2x" src="https://github.com/user-attachments/assets/41ad4784-02ec-4b29-b860-32af9fa79aa8" /> | | <img width="924" height="214" alt="CleanShot 2026-09-02 at 11 34 44@2x" src="https://github.com/user-attachments/assets/1de661fe-c7b6-499b-a94f-e4737436ec79" /> | <img width="752" height="162" alt="CleanShot 2026-09-21 at 11 44 56@2x" src="https://github.com/user-attachments/assets/1811890f-0660-4445-84e9-447720954fa1" /> | ## To test Test each callsite **in light mode** (dark mode is largely unchanged). ### WWW - [Homepage](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/): “Scale to millions” uses readable brand text (display token is gone) - [Careers](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/careers): small “Careers” eyebrow readable; green dividers stay bright `brand-default` - [Contact](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/contact-us): email / policy links use readable brand text - [Regions](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/regions): “Ask about early access to BYOC” readable ### Docs - [Docs homepage](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs): “DOCS” wordmark and resource links readable - [Database overview](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/guides/database/overview): nav / footer brand links readable - [JavaScript reference](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/reference/javascript/introduction): active sidebar treatment readable ### Design system - [Typography](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/typography): documents `text-brand` only (no display) - [Colour usage](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/color-usage): `text-brand` vs `bg-brand-default` - [Design-system homepage](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/): brand text examples across themes ### Studio - [Auth providers](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/auth/providers): enabled provider badge text readable; status dot stays bright - [Database policies](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/database/policies?new=true): template hover text more legible - [Database connections](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/observability/connections): “Live” status readable; animated dot stays bright green --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
adca15deab |
chore(www): add Privacy Policy v4 (data controller entity, Freebuff cookie) (#50392)
<!-- ccr-slack-attribution --> _Requested by **Sofia Calado** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1789462983606899)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — a new version (v4) of the Privacy Policy legal page, added following the existing versioned-legal-page pattern (v1-v3 already present, selectable via a version dropdown). ## What is the current behavior? Before: On `/privacy`, the latest selectable version is "Version 3 — May 13, 2026". That text names "Supabase, Inc" as the entity you're dealing with — both in the opening paragraph ("Thank you for your interest in Supabase, Inc., ...") and again as the named data controller in the EEA/UK/Switzerland disclosures section ("Supabase, Inc is the data controller..."). The Section 8 cookie table (EEA cookies) lists nine cookies/rows (Stripe x3, Cloudflare x2, Youtube, hCaptcha, Posthog, Google Analytics 4, Google Ads, `_sb_first_referrer`) and does not mention Freebuff anywhere. ## What is the new behavior? After: `/privacy` gains a new "Version 4" entry in the dropdown, at the top of the list (selected by default). Reading Version 4, the same two passages instead name "Supabase Pte. Ltd." as the entity/data controller. The Section 8 cookie table gains one additional row for "Freebuff" (Type: Advertising; dropped when you visit the Site after interacting with a Freebuff ad; 30-day duration; purpose: measuring ad campaign performance and attributing conversions to ad clicks upon consent; linking to the Freebuff Privacy Policy), formatted identically to the existing rows. Versions 1-3 are unchanged and remain selectable. ## Additional context Two changes, scoped exactly as requested: 1. **Data controller entity**: every "Supabase, Inc" / "Supabase Inc." reference that names the data controller is replaced with "Supabase Pte. Ltd." — at the top of the policy and in the EEA disclosures section. No other "Supabase" references (e.g. plain brand mentions) were touched. 2. **Freebuff cookie row**: added to the Section 8 (EEA cookies) table, matching the existing table's markdown formatting exactly. **Open question — effective date needs Sofia/Nicole's input before merge.** No effective date was given for v4. The version-selector component (`LegalDocVersions`) requires a non-empty `effectiveDate` string per version to render (used both in the dropdown label and, for a single-version page, an on-page line) — there's no way to add the version without wiring some string. Following the pattern's convention of never inventing a plausible-looking date, `effectiveDate` is set to the literal placeholder `'TBD'` for v4 in `apps/www/pages/privacy.tsx`. **This must be replaced with a real effective date before this PR merges** — flagging for Sofia Calado / Nicole Kramer to confirm. **Validation**: `pnpm --filter=www build` fails in this sandbox due to an unrelated prebuild step (`docs` app's `build:federated-content` script needs live GitHub API credentials to fetch tags — 401 Bad credentials — not related to this change). `tsc --noEmit` on `apps/www` ran clean of any error touching `privacy.tsx` or the privacy `.mdx` files (all reported errors are pre-existing, about unrelated missing generated assets/images). As a direct substitute, all four `apps/www/data/legal/privacy/*.mdx` files (v1-v4) were compiled through the app's actual MDX pipeline (`@mdx-js/mdx` with the same `remark-code-hike` + `remark-gfm` + `rehype-slug` config as `next.config.mjs`) and all compiled successfully, confirming the new table syntax and content are valid MDX/GFM. Files touched: - `apps/www/data/legal/privacy/v4.mdx` (new) - `apps/www/pages/privacy.tsx` (added v4 to the `versions` array) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01BzHiVEUzjvrwxgnxCrrER1 --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
fb22534439 |
fix: share sentry crash policy and enable www reporting (#50232)
## Problem The website initializes Sentry only on the server and edge runtimes, leaving browser crashes unreported. Its crash-reporting setup also needs the same consent and third-party filtering policy that docs and Studio otherwise maintain separately. ## Fix Add www browser initialization and tagged crash capture for both Next.js routers, with accessible fallback focus. Move the shared consent/platform and third-party filtering into common/sentry, reuse it from all three apps, and remove the duplicated docs/www helpers and tests. Preserve each app's initialization and Studio's additional noise filtering, sampling, and sanitization. Include the source-map upload token in www's build cache inputs, and trigger the shared/www and Studio test workflows when the shared policy changes. ## How to test - Run `pnpm --filter www test ../../packages/common/sentry.test.ts lib/sentry-capture.test.tsx`: all 22 shared-policy and real-SDK capture tests passed locally. - Run `pnpm --filter studio exec vitest run lib/sentry-client-options.test.ts`: all 42 Studio options and policy-parity tests passed locally. - The www capture tests exercise the actual initializer and both router handlers with an in-memory transport, verify crash tags and fallback focus, and enforce consent. Removing initialization, capture calls, boundary tags, or consent gating was verified to fail these tests. - On a www preview with its DSN configured, accept telemetry consent and trigger temporary render errors in both routers. Verify they reach the www Sentry project with the boundary tag and readable stack traces. Formatting passes. Full local app typechecks encounter existing dependency/generated-file drift, with no diagnostics in changed files. Three unchanged TanStack mock call-count tests fail locally and reproduce against the pre-refactor implementation. Live Sentry ingestion and source-map uploads remain deployment checks. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Accessibility** - Error pages now automatically move focus to a clearly labeled error message, helping screen-reader and keyboard users understand when a page fails. - **Reliability** - Browser error reporting now captures application crashes more consistently across supported page types and navigation transitions. - Reporting respects consent and platform availability while filtering unrelated third-party failures. - **Testing** - Expanded automated coverage for error capture, reporting rules, consent handling, and accessible error-page behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
476d4a5851 |
refactor(ui): drop redundant Button variant="default" props (#50161)
## What kind of change does this PR introduce? Mechanical cleanup on top of the Button default-variant change (#50160). ## What is the current behavior? Many callsites still pass `variant="default"` even though that is now the component default. ## What is the new behavior? Removes redundant static `variant="default"` from legacy `Button` and `ButtonTooltip` callsites. Keeps explicit defaults where they document the API: - `button-default.tsx` and `button-sizes.tsx` demos - `DocsButton`, which pins neutral styling at the wrapper boundary ## To test Studio: - [Auth → Rate Limits](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/auth/rate-limits): dirty the form so Cancel appears; Cancel stays neutral, Save stays green - [Project Settings → API Keys](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/settings/api-keys): `DocsButton` in the header actions stays neutral Design system: - [Design system → Button](https://design-system-git-dnywh-dc924ac1-supabase.vercel.app/design-system/docs/components/button): `button-default` / `button-sizes` still show explicit default styling; Primary (green) is restricted to the Primary section (and `asChild`) WWW: - [www → Brand assets](https://zone-www-dot-com-git-dnywh-dc924ac1-supabase.vercel.app/brand-assets): Download logo kit / Download button kit stay neutral |
||
|
|
b8b92fe566 |
fix(www): careers page error (#50185)
## What kind of change does this PR introduce?
bug fix careers page on anchor link click
## What is the current behavior?
on `/careers`, clicking "open positions", scrolling down and back up,
then clicking it again crashes the page
## What is the new behavior?
destructuring defaults on the page props, so an empty-props render is
harmless instead of fatal _ prefetch still returns `{}`, but the
sequence now renders normally instead of throwin
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved the careers page so it renders correctly when job listings,
placeholder job details, or contributor information are unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
1131e3e2ce |
fix(ui): default Button variant to default instead of primary (#50160)
## What kind of change does this PR introduce? Bug fix / design-system alignment for the legacy `Button` from `ui`. ## What is the current behavior? Omitting `variant` on the legacy `Button` falls back to brand-green `primary`. That makes accidental greens easy, and it is hard to spot the real main action on busy pages. ## What is the new behavior? - Legacy `Button` now defaults to neutral `default` - Intentional primary CTAs (create, save, submit, marketing CTAs, and matching `ButtonTooltip` usages) now set `variant="primary"` so their appearance is unchanged - Neutral actions that previously relied on the old fallback (cancel, close, back, dashboard nav, and similar) become grey/white - Design-system docs updated; regression tests cover the new default `Button_Shadcn_` is unchanged. It already uses its own CVA default. This is PR 1 of 2 in a stack. PR 2 drops now-redundant `variant="default"` props. ## To test Studio (http://localhost:8082): - `/sign-in`: Sign in stays green - Open a project → Database → Tables: New table stays green - Auth → Users → Invite: Invite user stays green; Cancel / dismiss controls stay neutral - Project Settings → General: edit a field so Cancel and Save appear. Cancel is neutral, Save is green Design system (http://localhost:3003): - Components → Button: default demo is neutral; primary demo is green; featured preview is the default variant Marketing (optional): - www header: Start your project stays green; logged-in Dashboard is neutral <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Style** - Buttons now default to a neutral style, while primary actions across Studio, documentation, marketing pages, forms, dialogs, and error states use prominent primary styling. - Updated button examples and previews clarify the distinction between default and primary variants. - Event registration now includes a directional arrow icon. - **Tests** - Added coverage confirming default button styling and explicit primary styling behave as expected. - Updated related test fixtures to use primary styling where appropriate. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
58e77483b4 |
chore(www): add open position to careers btn (#50139)
Add number of open position on the main cta button in the careers page. ## Before <img width="1328" height="614" alt="Screenshot 2026-09-08 at 16 57 24" src="https://github.com/user-attachments/assets/7c640e52-afdf-4e77-9705-fe539ed045a7" /> ## After <img width="1352" height="639" alt="Screenshot 2026-09-08 at 16 57 05" src="https://github.com/user-attachments/assets/40c265dd-b28e-44e7-9170-f45a330edfbb" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * The careers page now displays the current number of open positions. * The “Open positions” call-to-action includes the position count and uses a medium-sized button style. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
eba2aeb517 |
chore: remove stale references to the removed build:llms pipeline (#49848)
## What The `build:llms` script no longer exists in apps/docs (its output, `apps/docs/public/llms/*.txt`, is superseded by `apps/www/app/llms/[slug]/route.ts` serving the generated reference markdown directly). Four stale references remained: - `apps/docs/.gitignore`: removed the `public/llms/` entry and its comment referencing the dead script. Nothing writes to that directory anymore; if you have leftover local files there, delete them. - `apps/docs/spec/reference/README.md`: the react-server `tsx` warning cited `pnpm build:llms` as the consumer. Replaced with `pnpm embeddings`, a live script that runs under `tsx --conditions=react-server`. I verified the constraint still holds: importing `Reference.utils.ts` crashes under `--conditions=react-server` (in `next/navigation`) and loads fine under plain `tsx`. - `apps/www/pages/modules/vector.tsx`: the maintenance comment pointed at `public/llms/vector.txt`, which doesn't exist in www. The hand-maintained markdown sibling lives at `content/md/modules/vector.md`. - `.agents/skills/ask-the-docs/reference/llm-agent-parity.md`: the "In-flux / stale wiring" bullet asserted the exact `.gitignore` line this PR deletes (and its "generation path is unclear" caveat no longer holds; per-source links resolve live via `apps/www/app/llms/[slug]/route.ts`). Removed the bullet so the ask-the-docs skill doesn't report a gitignore entry that no longer exists. No behavior change; docs and comments only (plus a gitignore entry). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated the embeddings documentation to use the current `pnpm embeddings` command. - Clarified where vector module content should be maintained alongside the corresponding page. - Removed outdated references to generated per-source LLM files and retired documentation describing stale generation paths. - Improved consistency between reference documentation and the current content-generation workflow. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8aade77966 |
fix(www): gate changelog md alternate on slug set (#49754)
Changelog entry pages advertised a `.md` alternate tag unconditionally while the page is ISR, so an entry published in the changelog repo between www deploys pointed agents at a `.md` sibling that 404s until the next build (the static file and `CHANGELOG_PAGES` are both build-time artifacts). PR #49357 made bare-URL negotiation fail closed for those entries; I gate the advertising side here the same way. **Changed:** - **No more dead `.md` links on freshly published entries**: `getStaticProps` passes a `hasMarkdownVariant` flag computed from `CHANGELOG_PAGES` membership and the page renders the alternate tag only when true. An entry published between deploys carries no tag until the build that ships its `.md` file; the set reference stays inside `getStaticProps`, so the generated module stays out of the client bundle. - **Drift coverage**: `md-alternates.test.ts` gains the changelog direction, source-level like the existing `_app.tsx` drift test; the assertion pins the full `CHANGELOG_PAGES.has(` + backtick-`changelog/${entry.slug}`-backtick + `)` expression so a dropped key prefix fails the suite, and removing the gate fails it too. **Note:** without changelog sync secrets `CHANGELOG_PAGES` is empty, so the tag never renders in local dev. Preview and prod are the verification surface. ## To test Tested on Vercel preview: - [x] Open a published changelog entry page and view source: expect `<link rel="alternate" type="text/markdown" href="/changelog/<slug>.md">` in the head — observed exact href `/changelog/19669-supavisor-1-0.md` - [x] Fetch that href: expect 200 with `content-type: text/markdown` — observed 200, `text/markdown; charset=utf-8` - [x] (added) Client-side nav from `/changelog` into an entry: alternate tag appears with that entry's slug; hopping to a second entry updates the href (no stale tag) - [x] (added) Navigating back to `/changelog`: entry tag gone; the index shows its own pre-existing `/changelog.md` alternate (hardcoded in `pages/changelog.tsx`, outside this diff), and `/changelog.md` returns 200 `text/markdown` - [x] (added) Console: zero new errors across all scenarios vs page-load baseline ## Linear - fixes GROWTH-1120 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Changelog pages now advertise a Markdown alternate link only when a Markdown version is available. * Prevented links to unavailable Markdown content from appearing on changelog entries. * **Tests** * Added coverage to verify correct Markdown alternate detection and rendering. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5802f4f83e |
fix(www): career page apply button sizing (#49647)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Noticed this by accident, simplified the apply button area sizing on large screens. | Before | After | |--------|--------| | <img width="390" height="228" alt="Screenshot 2026-08-27 at 15 25 36" src="https://github.com/user-attachments/assets/7f49021c-1332-4a00-b19c-5544537c1cb4" /> | <img width="491" height="274" alt="Screenshot 2026-08-27 at 15 45 11" src="https://github.com/user-attachments/assets/846faff8-bd72-4141-b8d4-01d7ddd97b6d" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved job listing badge layout and responsiveness. * Long location names now truncate cleanly instead of overflowing. * Reduced location icon size for a more balanced presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
292c08b7b7 |
Added new /regions page (#49306)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature ## What is the current behavior? Region and data residency information is split across docs, `/security`, and legal pages. [MARKET-1866](https://linear.app/supabase/issue/MARKET-1866/package-and-display-available-regions-better-on-website) ## What is the new behavior? Adds `/regions`: a catalog of all 17 regions generated from `regions.ts`, plus what stays in-region, the Europe vs EU caveat, and links to the DPA, GDPR guide, sub-processor list, and security page. Regions is in the footer under Security & Compliance. The security page residency card now links here. ## Test plan - [ ] Open `/regions` in light and dark mode - [ ] Confirm the region count and list match `packages/shared-data/regions.ts` - [ ] Confirm footer Regions link and `/security` residency link go to `/regions` Made with [Cursor](https://cursor.com) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a Regions page showcasing available AWS regions by geography. - Added an interactive map and region list with selection, hover states, keyboard accessibility, and residency badges. - Included data residency guidance, legal resources, and a call-to-action for next steps. - Added Regions links in the site footer and security documentation. - **Documentation** - Updated agent skill resources with expanded troubleshooting and operational guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Francesco Sansalvadore <f.sansalvadore@gmail.com> |
||
|
|
60f7903b52 |
fix(www): group the filter controls and announce the result count (#49410)
Closes FE-4251 ## Problem The filter sidebars are unstructured `div` nesting. Measured on a preview: * 9 checkboxes on `/features` and 13 on `/partners/catalog`, none inside a `fieldset`, a `role="group"`, or any region. * The `/features` "Filter by tags:" `h2` has no `id`, so nothing can reference it as a group name. * The only landmarks on `/features` are two `nav` elements, so the filter panel is unreachable by landmark navigation. A screen reader user meets a checkbox announced as "authentication, checkbox" with nothing conveying that it filters features by tag. Separately, both result counts update on every filter change with no live region, so the outcome of toggling a filter is never announced. ## Solution * Wrap each checkbox set in a labelled `role="group"`. * Wrap each filter panel in an `aside` labelled "Filters". * Add `aria-live="polite"` to both result counts. The two pages name their group differently on purpose. `/features` uses `aria-labelledby` pointing at the existing `h2`, so the visible heading is the accessible name. `/partners/catalog` uses `aria-label`, because `filtersPanel` renders into both the desktop sidebar and the mobile sheet, so an `id` would appear twice in the DOM. That file already calls out the duplicate-id hazard at line 152 as its reason for using wrapping labels. Chose `role="group"` over `fieldset` and `legend` to avoid resetting UA styling in a styled sidebar. The single self-hosted checkbox keeps its own label and needs no group. ## Manual testing **/features** 1. Open [/features](https://zone-www-dot-com-git-www-filter-groups-and-live-count-supabase.vercel.app/features) with Screenreader. 2. Confirm the tag checkboxes report as a group named "Filter by tags:". 3. Confirm a "Filters" landmark appears in landmark navigation. 4. Tick a tag filter. The result count changes and is announced. **/partners/catalog** 5. Open [/partners/catalog](https://zone-www-dot-com-git-www-filter-groups-and-live-count-supabase.vercel.app/partners/catalog) at a desktop width. The filter panel is `hidden md:block`, so the landmark only exists at md and above. 6. Confirm the category checkboxes report as a group named "Categories". 7. Open the mobile filter sheet at a narrow width and confirm the group is still named, with no duplicate ids. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility Improvements** * Improved screen reader navigation for partner catalog and feature filters. * Added accessible labels and landmarks for filter sections. * Updated result counts to be announced when selections change. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
78d6d57faa |
fix(www): stop rendering the invisible Clear all filters button (#49409)
Closes FE-4250 <img width="661" height="294" alt="Screenshot 2026-08-21 at 10 44 38 AM" src="https://github.com/user-attachments/assets/db7e09db-845c-43a8-a6ca-5d0c67436355" /> ## Problem With no filters active, `/features` still rendered the "Clear all filters" button and hid it with `opacity-0`. Found with VoiceOver, which announced "You are currently on a button" on an apparently empty control. Measured on a preview with no filters active: | Property | Value | | -- | -- | | `opacity` | `0` | | `visibility` | `visible` | | `display` | `block` | | `tabIndex` | `-1` | | `aria-hidden`, `inert`, `disabled` | none | | `pointer-events` | `auto` | | Layout | 256 x 26px | Two assumptions were wrong. `opacity: 0` does not remove an element from the accessibility tree, and `tabIndex="-1"` only removes it from tab order, not the tree. Screen readers walk the tree. It was also a live 256 x 26 mouse target, so a sighted user could click an invisible button. ## Solution Render it conditionally, matching `IntegrationsContent.tsx` which already does this and was unaffected. No layout shift. The button is the last child of the sidebar column, so nothing above it moves when it appears. ## Manual testing 1. Open [/features](https://zone-www-dot-com-git-www-features-clear-filters-button-supabase.vercel.app/features) with no filters applied. Confirm no "Clear all filters" button exists anywhere in the DOM. 2. Tick a tag filter in the left sidebar. The button appears. 3. Click it. Every filter clears, the count returns to 79 features, and the button disappears again. For the before state, open [/features on production](https://supabase.com/features) with no filters, then run this in the console. It reveals the button that is present but invisible: ```js const b = [...document.querySelectorAll('button')].find(x => /Clear all filters/.test(x.textContent)) Object.assign(b.style, { opacity: '1', outline: '3px solid red' }) ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * The “Clear all filters” button now appears only when filters are active. * Improved keyboard navigation by removing inactive filter controls from the tab order. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
0243ad7cf1 |
fix(www): make the view toggles a radio group and fix the filter rows (#49346)
Closes FE-4227 > [!NOTE] > Bottom of a stack. #49409 and #49410 sit on top of this one, so merge this first. ## Problem Five defects in the view toggles on `/features` and `/partners/catalog`, plus one in the `/features` filter rows. All measured on a preview. **Toggles** | Defect | Evidence | | -- | -- | | No pointer cursor | Tailwind 4 Preflight no longer sets `cursor: pointer` on buttons. 14 of 19 buttons on `/features` computed to `default`. Anchors were unaffected, which is why it looked inconsistent rather than total. | | The selected toggle offered a pointer | It is a no-op, so the cursor promised an action that does nothing. | | The selected state was invisible in light mode | `bg-surface-300` and `bg-surface-75` both resolve to pure white. Contrast ratio exactly 1.000. The light theme base lightness is `.995` and each surface step adds `.024`, so every lighter step clamps at white. The only cue left was icon colour. | | Hover inverted the selection | Unselected hover is `bg-surface-200`, a 2.7% black overlay, while the selected state was white. Hovering the wrong button made it look selected. | | No grouping | Two unrelated buttons. Nothing conveyed one choice with two options, and the selected view was not programmatically determinable at all. | **Filter rows on /features** A pointer appeared only on the narrow gap between each checkbox and its label: | Element | Computed cursor | | -- | -- | | wrapper `div` | `pointer` | | `label` | `default` | | checkbox | `default` | `cursor-pointer!` sat on the wrapper. A declaration targeting an element always beats an inherited value, so `!important` on the parent changed nothing and both children overrode it. ## Solution **Toggles become a `ToggleGroup`** on both pages, replacing the raw button pairs. * `type="single"` renders `role="group"` with `role="radio"` and `aria-checked` per item. That describes one choice with two options rather than two independent toggles, so a screen reader announces the selection and its position in the set. * Each group gets an `aria-label`, which the existing `ToggleGroup` usage on `/pricing` lacks. * Selected item gets `cursor-default`, unselected gets `cursor-pointer`. * Selected background becomes `bg-surface-400`, a 5.4% overlay that clears the 2.7% unselected hover and removes the inversion. **Filter rows** become wrapping `label` elements with `cursor-pointer` directly on the label, matching `IntegrationsContent.tsx`. The whole row becomes a click target, and `id` values derived from raw product names go away. `toggleVariants` sets the selected background to `bg-surface-300` under both `data-[state=on]:` and `aria-checked:`, and twMerge only dedupes matching prefixes. Both are overridden here so adopting the primitive does not reintroduce the invisible state this PR fixes. The primitive defect is FE-4245. ### Behaviour change The toggle pair is now a single tab stop navigated with arrow keys, rather than two separate tab stops. That is correct for a mutually exclusive group, but it is a change from current behaviour. ### Related, deliberately not here | Work | Where | | -- | -- | | Checkbox primitive pointer cursor | #49408, so the shared-package change is reviewed separately. The checkbox itself still shows an arrow on this branch. | | Naming these toggles, which rely on `title` | FE-4229 | | Base-layer cursor fix across www, Docs and Studio | FE-4228 | | Sharing one component between the two pages | FE-4244 | ## Manual testing 1. Open [/features](https://zone-www-dot-com-git-www-view-toggle-pointer-cursor-supabase.vercel.app/features) in light mode. The selected toggle is visibly darker than the unselected one. 2. Hover the selected toggle. The cursor is an arrow. Hover the unselected one. It is a pointer, and it does not become darker than the selected one. 3. Tab to the toggle pair. It takes one tab stop. Move between options with the arrow keys. 4. Inspect either toggle. It has `role="radio"` with `aria-checked` tracking the selection, and the wrapping group has an `aria-label`. 5. Hover a tag filter row over the label text and over the gap between the checkbox and the text. Both show a pointer. The checkbox itself still shows an arrow here; that is #49408. 6. Click a filter row well away from the checkbox. The filter toggles. 7. Repeat steps 1 to 4 on [/partners/catalog](https://zone-www-dot-com-git-www-view-toggle-pointer-cursor-supabase.vercel.app/partners/catalog). --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
c79d7be7d9 |
fix(www): give the feature and partner card grids list semantics (#49411)
Closes FE-4252 ## Problem `/features` renders 79 feature cards as bare `Link` elements in a grid `div`. Measured on a preview, `main` contains zero `ul`, `ol`, `li`, and zero `role="list"`. `/partners/catalog` is the same. A screen reader user gets a run of loose links with no "list, 79 items", no set size, and no way to navigate by list. Sighted users see an obvious grid of cards, and the structure conveying that is purely visual. Same defect class as FE-4101 and DOCS-1279, both already in this milestone. ## Solution Make each card container a `ul` with one `li` per card. Four containers: | File | Container | | -- | -- | | `apps/www/pages/features.tsx` | feature card grid | | `apps/www/app/partners/catalog/IntegrationsContent.tsx` | featured partners grid | | same | grid view | | same | list view | This change makes a Screenreader announce the number of items and track them. Most of this diff is re-indentation from the added wrapper. ## Manual testing **/features** 1. Open [/features](https://zone-www-dot-com-git-www-card-grid-list-semantics-supabase.vercel.app/features) with Screenreader. Confirm the cards report as a list of 79 items, and that the count tracks the filters. 2. Check the grid at mobile, tablet and desktop widths. Cards stay equal height within a row and the column counts are unchanged. **/partners/catalog** 3. Open [/partners/catalog](https://zone-www-dot-com-git-www-card-grid-list-semantics-supabase.vercel.app/partners/catalog) in grid view with Screenreader. Confirm both the featured section and the main grid are lists. 4. Switch to [list view](https://zone-www-dot-com-git-www-card-grid-list-semantics-supabase.vercel.app/partners/catalog?view=list). Confirm it is a list and the dividing lines between rows are unchanged. Compare any of these against [production](https://supabase.com/features). The rendering should be identical; only the markup changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility** * Improved semantic structure for partner catalog and feature cards using properly organized lists. * Expanded card links to make larger portions of featured and grid cards clickable. * Preserved existing layouts, content, and filtering behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
21a27eeb4f |
feat(www): canonicalize homepage markdown at /index.md (#49384)
The www root markdown lived at an accidental URL: `/.md` served the
homepage markdown only because middleware strips the `.md` suffix and
the empty slug fell through to the homepage allowlist entry, while the
canonical-looking `/index.md` 404'd. The served markdown also opened
with stale legacy positioning copy that no longer matches the site. I
renamed the homepage content slug to `index` end-to-end so `/index.md`
is the one canonical markdown URL.
**Changed:**
- **`/index.md` serves the homepage markdown (200 `text/markdown`)**:
`content/md/homepage.md` renamed to `index.md`; the middleware bare-root
slug mapping, the generator's sort special-case, and the homepage
alternate tag follow, so the tag now advertises `/index.md`.
- **Legacy aliases 308 to the canonical URL**: `/.md`, `/homepage.md`,
and bare `/index` redirect via `lib/redirects.js`; `/llms/homepage.txt`
retargeted straight to `/index.md` to avoid a redirect chain. New
`next.config.test.ts` assertions pin all four.
- **Positioning refreshed**: the markdown now opens with "Supabase is
the Postgres development platform" (matching the site title), replacing
the outdated tagline.
- **Generator safety**: the redirect-exclusion filter in
`generateMdContent.mjs` now exempts the `index` slug (its HTML page is
`/`, not `/index`, so a `/index` redirect never refers to it), and the
build fails if `content/md/index.md` ever goes missing while middleware
still maps `/` to the `index` slug.
- **CI actually runs the new assertions**: I widened the `www-tests.yml`
paths filter to include `apps/www/lib/**/*.js`,
`apps/www/content/md/**`, and `apps/www/scripts/**/*.mjs`. It previously
only matched `.ts*` and the next.config files, so a PR touching only
`lib/redirects.js`, the markdown content, or the generator would skip
the tests that pin these redirects.
**Note:** the existing homepage alternate tag still exists, re-pointed
to the canonical URL. Whether the homepage should advertise a markdown
sibling at all is a separate decision; leaving it aimed at a 308 would
break tag consumers. Positioning wording is editorial, happy to tweak.
## To test
Tested on Vercel preview:
- [x] `curl -si <preview>/index.md`: expect 200 `content-type:
text/markdown`, body opens with the Postgres development platform
positioning and no longer contains the old tagline
- [x] `curl -sI <preview>/.md`: expect 308 with `location: /index.md`
- [x] `curl -sI <preview>/homepage.md` and `curl -sI
<preview>/llms/homepage.txt`: expect 308 with `location: /index.md`
- [x] `curl -sI <preview>/index`: expect 308 with `location: /`
- [x] `curl -s -H "Accept: text/markdown" -o /dev/null -w "%{http_code}
%{content_type}" <preview>/`: expect `200 text/markdown` (bare-URL
negotiation unchanged)
- [x] `curl -s <preview>/ | grep -o 'type="text/markdown"
href="[^"]*"'`: expect href ending `/index.md`
## Linear
- fixes GROWTH-1117
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Added support for `/index.md` as the canonical Markdown representation
of the homepage.
- Added permanent redirects for legacy homepage Markdown and text URLs.
- Added `/index` to `/` redirect handling.
- **Bug Fixes**
- Updated homepage metadata, alternate links, Markdown negotiation, and
content generation to consistently use the new canonical path.
- Improved homepage content description.
- **Tests**
- Expanded coverage for homepage Markdown routes, redirects, and URL
matching.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
21fccb0ecd |
fix(www): name the /features page button controls (#49343)
Closes FE-4097 https://github.com/user-attachments/assets/bc7cad1a-763e-469f-8a3b-e4d23bed94d9 _See bottom left of screen for screen reader captions._ ## Problem Two controls in the shared `/features/[slug]` template have no accessible name. Both live in the template, so both fire on all 79 feature pages. * The feature list dropdown trigger contains only a `List` icon. `button-name`, critical. * The breadcrumb back chevron wraps only a `ChevronLeft`. `link-name`, serious. ## Solution * Name both with `sr-only` text, matching the sibling prev and next controls in the same component and the theme switcher in the site header. * Label the product pill with its destination. It announced only "vector", with no indication it filters the catalog. Not an axe finding, since the product name already supplies a name. The label keeps the visible word so it satisfies WCAG 2.5.3 Label in Name. * Fix a stray `className="` inside the `iconClassName` string literal, which dropped the icons' width class. * Add `cursor-pointer` to `buttonClassName`. Tailwind 4 no longer sets a pointer cursor on buttons, so the middle control behaved differently from its two anchor siblings. This line belongs to FE-4227 and sits here only to keep two open PRs off adjacent lines of the same file. ## Manual testing 1. Open [/features/ai-integrations](https://zone-www-dot-com-git-www-features-chrome-access-1aef01-supabase.vercel.app/features/ai-integrations) using a Screenreader. 2. Tab through the three round controls at top right. They announce "Previous feature", "Browse all features", "Next feature". **Note:** The order of the elements is strange; captured in a separate ticket. 3. Tab to the round back control at top left. It announces "Back to all features". 4. Tab to the product pill beside it. It announces "All vector features", and the visible word "vector" is unchanged. 5. Hover each of the three round controls. All show a pointer cursor. 6. Run axe on the page. `button-name` and `link-name` report zero elements. Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
10c425ad0b | feat(www): markdown copy/ask affordances (#48475) | ||
|
|
70715790b8 |
chore(www): unpublish and redirect the legacy launch week pages (#49335)
Closes [FE-4226](https://linear.app/supabase/issue/FE-4226/unpublish-and-redirect-legacy-launch-week-pages) ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content removal. ## What is the current behavior? `/launch-week/x`, `/launch-week/12`, `/launch-week/13`, and `/launch-week/14` are still published. Each one carries its own page component and a ticket flow for a launch week that ended. The accessibility scan flags them, and they hold no SEO value. This follows #49281, which took down `/launch-week/6` on the same pattern. ## What is the new behavior? - Delete the `/launch-week/x`, `/12`, `/13`, and `/14` page routes. - Redirect each path to its recap blog post, matching the destinations agreed in `#team-marketing`. - Point the Launch Week 12, 13, and 14 blog summary components at `/launch-week` instead of their deleted pages. `LWXSummary` already does this. - Drop the `disableStickyNav` and `showLaunchWeekNavMode` checks in `Nav` that only matched the deleted routes. - Drop the Launch Week X branches in `useDarkLaunchWeeks` and `_app`. | Source | Destination | | --- | --- | | `/launch-week/x` | `/blog/launch-week-x-best-launches` | | `/launch-week/12` | `/blog/launch-week-12-top-10` | | `/launch-week/13` | `/blog/launch-week-13-top-10` | | `/launch-week/14` | `/blog/launch-week-14-top-10` | ## Additional context `/launch-week/7` and `/launch-week/8` stay published. Neither has a recap post to redirect to, so they need a destination decision before they come down. The `components/LaunchWeek/{X,12,13,14}` trees stay. `BlogPostRenderer` imports the summary component from each one, and those summaries read the same `Releases/data` modules the deleted pages used. The stage and nav components under those directories are now unreachable, so they need their own dead-code audit. Assets under `public/images/launchweek/` are untouched, same as #49281. ## Manual testing Preview: https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app 1. Open [/launch-week/x](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/x). It returns a 308 and lands on `/blog/launch-week-x-best-launches`. 2. Open [/launch-week/12](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/12). It returns a 308 and lands on `/blog/launch-week-12-top-10`. 3. Open [/launch-week/13](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/13). It returns a 308 and lands on `/blog/launch-week-13-top-10`. 4. Open [/launch-week/14](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/14). It returns a 308 and lands on `/blog/launch-week-14-top-10`. 5. On each of those blog posts, the launch week summary card header links to `/launch-week`. 6. Open [/launch-week](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week), [/launch-week/7](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/7), and [/launch-week/8](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/8). All still load. Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
6edef9f067 |
chore(www): unpublish the Launch Week 6 page (#49281)
Closes [FE-4100](https://linear.app/supabase/issue/FE-4100/www-remove-httpssupabasecomlaunch-week6) ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content removal. ## What is the current behavior? `/launch-week/6` is still published. Launch Week 6 ran in December 2022. The page carries its own 1,085-line component, two CSS modules, and a Supabase client that reads the `lw6_creators` and `lw6_tickets` tables. ## What is the new behavior? - Delete the `/launch-week/6` page, its CSS modules, its day data, and its types. - Redirect `/launch-week/6` to `/blog/launch-week-6-wrap-up`, which holds the same content. - Drop the Launch Week 6 card from the archive section on `/launch-week/8`, leaving Launch Week 7. ## Additional context Scope is Launch Week 6 only. Whether the other launch week pages come down is still open with marketing. Assets under `public/images/launchweek/` are untouched. Several are shared across launch weeks, so they need their own audit. ## Manual testing 1. Open [https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/6](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/6) on the deploy preview. It returns a 308 and lands on `/blog/launch-week-6-wrap-up`. 2. Open [the Launch Week 7 page](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/7). It still loads. 3. Open [the Launch Week 8 page](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/8) and scroll to "Previous Launch Weeks". Only the Launch Week 7 card shows. Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
18dc7e971d | chore: update vendor DepthFirst (#49093) | ||
|
|
2e7a8a3362 |
chore(www): rename customer logo folders to on-dark and on-light (#48962)
## What kind of change does this PR introduce?
Chore: rename customer logo folders and document the theme contract. No
intended visual change, aside from Phoenix Energy whose two marks were
in the wrong folders.
## What is the current behavior?
Customer logos live at:
- `/images/customers/logos/{slug}.png` (`logo`, light mode)
- `/images/customers/logos/light/{slug}.png` (`logo_inverse`, dark mode)
`light/` actually means “use me on a dark background”.
## What is the new behavior?
Same assets, clearer paths:
- `/images/customers/logos/on-light/{slug}.png` → dark/black mark →
`logo` → light mode
- `/images/customers/logos/on-dark/{slug}.png` → light/white mark →
`logo_inverse` → dark mode
Icon chips stay at `/images/customers/logos/{slug}-icon.svg`. Old
`/images/customers/logos/light/*` URLs redirect to `on-dark`. www README
now has the contract.
# To test
Use the [www
preview](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app).
Toggle light/dark from the site header on each page. Logos should stay
readable (no white-on-white or black-on-black).
1. [Customers
grid](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/customers)
— main `logo` / `logo_inverse` surface. Spot-check Juniver, Phoenix
Energy, and one other card.
2. [Phoenix Energy
story](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/customers/phoenix-energy)
— story header uses `logo` only (on-light, plus a dark-mode brightness
filter). We swapped this pair.
3.
[Homepage](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/)
— “How industry leaders…” section. Icon chips only (`*-icon.svg`); the
wordmark `logo` field is unused here.
4. [Solutions /
Agents](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/agents)
— Chatbase quote near the top shows both theme variants. Same pattern on
[/healthcare](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/healthcare),
[/finserv](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/finserv),
and
[/b2b-saas](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/b2b-saas).
5. [Contact
sales](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/contact/sales)
— Good Tape / Xendit / Chatbase wordmarks (`on-light`). Same logos on
the demo form at
[/solutions/enterprise](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/enterprise).
6.
[Enterprise](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/solutions/enterprise)
— Mozilla / Epsilon3 / Pebblely icons in the use-cases section
(`on-dark`).
7.
[Vector](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/modules/vector)
— customer quotes. This is the only page that builds `on-light` /
`on-dark` paths at runtime from the customer slug.
8. [Mobbin
event](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/events/migrating-from-firebase-mobbin)
— company logo uses event `logo` / `logo_light` (dark vs light).
Optional second:
[/events/scale-to-millions-goodtape-auth](https://zone-www-dot-com-git-dnywh-chorecustomer-logo-o-0d7bc1-supabase.vercel.app/events/scale-to-millions-goodtape-auth).
Quick extra: hover **Product** in the site nav. The customer story
thumbnail uses `imgUrl` (`on-light`).
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Documentation
- Clarified customer logo requirements, including separate light and
dark asset locations, monochrome formats, and dark PNG assets for image
generation.
## Updates
- Standardized customer logos across stories, events, sales pages,
solution pages, testimonials, and generated images.
- Improved logo rendering across light and dark themes with dedicated
variants.
- Added permanent redirects for legacy logo URLs while preserving
filename suffixes.
## Tests
- Added coverage verifying legacy logo redirects resolve correctly,
including supported exceptions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
86854671e9 |
feat(www): add Open Authorization Integration Addendum (#48804)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1786027145751449)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — a new legal page on the marketing site (`apps/www`). ## What is the current behavior? **Before:** the Program Addenda page at `/legal/partner-resources/program-addenda` lists exactly one addendum, the Integration Partner Addendum. There is no published Open Authorization (OAuth) addendum anywhere on the site. ## What is the new behavior? **After:** the Program Addenda page also lists the **Open Authorization Integration Addendum**, linking to a new page at `/legal/partner-resources/program-addenda/oauth-partner-addendum`. Formatting, breadcrumbs, version selector, and listing badge all match the existing Integration Partner Addendum. **How:** three files. - `apps/www/data/legal/partner-resources/oauth-partner-addendum/20260806-v1.mdx` — the addendum text, formatted to match `integration-partner-addendum/20260615-v1.1.mdx` (escaped section-number periods, `####` run-in headings for the lettered subsections, italic `_Label_` run-in labels for the enumerated data-protection clauses, explicit `[url](url)` links). - `apps/www/pages/legal/partner-resources/program-addenda/oauth-partner-addendum.tsx` — the page, mirroring `integration-partner-addendum.tsx` with a single-version `versions` array. - `apps/www/lib/addenda.ts` — adds a small `TITLE_OVERRIDES` map. The listing derives titles by capitalizing slug words, which turns `oauth-partner-addendum` into "Oauth Partner Addendum"; the override makes the listing link read the same as the page's `h1`. No other wiring was needed: the addenda listing is generated from the directory, so there is no hub entry, redirect, rewrite, sitemap entry, or `noindex` rule to add. ## Additional context Two things for the requester to confirm: - **The effective date is an assumption.** The addendum document itself contains no date. The listing and version label derive the effective date from the `YYYYMMDD` filename prefix, so this file is dated **August 6, 2026**, taken from the source document's own filename (`2026.08.06 - Supabase-OAuthAddendum-ONLINE.docx`). To change it, rename the file — no code change required. - **The legal text is a verbatim transcription.** Source wording, capitalization, and punctuation are preserved exactly as drafted, including anything that reads like a typo. Only markup was added; the plain text was diffed against the transcription and is character-identical. Please review the wording itself rather than assuming it was copy-edited. One wording choice that was not in the source document: the page subheader, "An addendum to the Master Partner Program Agreement governing OAuth integrations." It mirrors the one-line subheader style of the existing addendum page and is easy to reword. ## Also fixed here: a literal `(c)` rendered as `©` in legal headings While formatting the new addendum we hit a rendering bug that turned out to be **already live on supabase.com**, not new to this branch. The heading font, **Manrope**, ships a default-on standard `liga` feature that maps the glyph sequence `parenleft c parenright` to the copyright glyph. So a literal `(c)` anywhere inside an `h2`–`h6` on the marketing site paints as `©`. Body copy is unaffected because it uses Inter, whose subset has no such ligature — which is why this only ever shows up in headings. This branch adds a `legal-prose` utility (`font-variant-ligatures: no-common-ligatures`) in `apps/www/styles/globals.css` and applies it to two pages: - the new **Open Authorization Integration Addendum** page (heading `#### (c) Security.`), and - the **Master Partner Program Agreement** page, where the `#### (b) Such indemnity …` heading in section 17.1 contains `… ; or (c) replace the Covered Materials …` about 600 characters into the line. That page was **already published**, and rendered "or © replace the Covered Materials" in production. The MPPA change is one word — `className="prose"` → `className="prose legal-prose"`. **No legal text was modified**: no HTML entities, no zero-width characters, no rewording, no re-hyphenation. The DOM still holds `U+0028 U+0063 U+0029`; only the font's shaping is suppressed. Verified in Chromium against the real heading text and the same two font subsets `next/font` serves: the `(c)` run measures **15.36px** before the fix (a single `©` glyph) and **22.05px** after (three literal glyphs), against a 23.30px control for the `(b)` in the same heading. All 17 `.mdx` files under `apps/www/data/legal/` were swept for `(c)` and the other Manrope `liga` input sequences (`--`, `->`, `<-`, `(>)`, `<3`) on heading lines. The only two hits are the two pages fixed above; nothing else needs the utility today. (Headings do contain `ff`/`fi`/`fl`/`tt` — those ligatures are ordinary typography and are intentionally left alone.) **For future legal pages:** because the cause is the heading font's default ligature rather than anything about these documents, any new legal page whose source has `(c)` in a heading will need `legal-prose` on its prose container too. **One side effect worth flagging:** `no-common-ligatures` is blunt, so on those two pages it also suppresses the ordinary `fi`, `ff` and `tt` ligatures — a sweep of the legal `.mdx` files counts 107 such occurrences in headings (`fi` 83, `ff` 21, `tt` 3, `fl` 0), so the note above about leaving them alone holds for the rest of the site rather than for these two pages. That is a deliberate trade-off: correctness of the legal text beats typographic polish on two addendum pages. A narrower alternative exists — `font-feature-settings: "liga" 0` scoped to just the offending ligature, or overriding only the `parenleft_c_parenright` substitution — but it is more fragile and more subset-specific, so push back here if you would rather have that instead. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01VtcJJGqw5jL1ESwhs8DGCu --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
ca94d842a7 |
design demo: security page content additions (content-only) (#48403)
## Summary - Adds four missing content cards to the existing `security.mdx` using the same `Section` component and grid already on the page — no new UI components or features - Cards added: **GDPR & European Compliance**, **Data Residency**, **Data Processing Agreement**, **Shared Responsibility** - Also fixes the HIPAA shared responsibility link path (`/deployment/` not `/platform/`) Worth validating still. ## What this is A content-only drop-in that addresses some gaps ## What's out of scope here - No sticky nav, tables, plan comparison grids, or new components - No DPA request automation — just a plain link to `/legal/dpa` - No plan-gating claims (removed — accuracy unconfirmed) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized the security page into clearer, grouped sections (Compliance, Data, Configuration, and Misc) for easier navigation. * Expanded compliance coverage with HIPAA, ISO 27001, GDPR & European compliance, and updated shared responsibility details. * Added new content for data residency and a Data Processing Agreement section. * Reordered configuration items (multi-factor authentication, role-based access, vulnerability management, DDoS) and moved payment processing into the Misc section. * Updated icons and card layout visuals throughout the page. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Nik Richers <nrichers@gmail.com> |
||
|
|
c4c58ef3e3 |
feat: remove pandadoc dpa request flow (#48525)
Terms of Service v3 (effective August 1, 2026, #48482) incorporates the Data Processing Addendum by reference, so customers no longer sign a separate DPA. Legal confirmed the PandaDoc signing flow can go; previously signed DPAs remain binding. This removes the frontend flow only. I'll remove the platform endpoint (`POST /platform/organizations/{slug}/documents/dpa`) separately once the PandaDoc contract conversation wraps. **Changed:** - **Dashboard DPA card no longer requests PandaDoc documents**: the Request DPA button and confirm modal are replaced with a View DPA link to the canonical legal page, with evergreen copy explaining the DPA is part of the Terms. Tracked via the same `document_view_button_clicked` event the other document cards use. - **Legacy `/legal/dpa` page retired**: the page told users to request a signed DPA from the dashboard, which no longer exists. It now permanently redirects to `/legal/customer-resources/data-processing-addendum` (the follow-up already flagged in #48483), and the footer link is removed. The `dpa_pdf_opened` and `dpa_request_button_clicked` events are removed with their last call sites. The latest privacy version links the canonical page directly; archived v1/v2 keep their original `/legal/dpa` link, served by the redirect. - **Orphaned DPA PDFs removed**: the four dated `Supabase+DPA+*.pdf` files under `/downloads/docs` had zero remaining references once the signing flow is gone. No redirect: nothing links these URLs, so they 404. - **Subscription tracking**: the subprocessor updates form now fires `www_subprocessor_updates_subscribed` on successful submit, so we can measure uptake of the notification list that replaces per-customer DPA emails. ## To test Verified on the Vercel previews (Playwright): - [x] Studio: `/org/_/documents` shows the DPA card with the incorporation copy and a working View DPA link (href = canonical page); no Request DPA button, no PandaDoc mention; TIA/SOC2/ISO27001/HIPAA cards unaffected - [x] www: `/legal/dpa` permanently redirects to `/legal/customer-resources/data-processing-addendum`; footer no longer shows DPA; zero console errors - [x] www: subscribing on the subprocessor page succeeds (200 from the form route, profile created with topic_4) and fires `www_subprocessor_updates_subscribed` (201 from the telemetry endpoint); test profile unsubscribed afterwards - [x] www: `/downloads/docs/Supabase+DPA+260601.pdf` returns 404 with no redirect; DPA card copy verified without the effective date ## Linear - fixes GROWTH-1068 |
||
|
|
4ae0c08967 |
feat: tos v3 update banner + publish subprocessor list (#48524)
Terms of Service v3 (effective August 1, 2026, #48482) incorporates the Data Processing Addendum by reference, and Legal asked for an in-app notice announcing the change. The subprocessor list page that the new Terms, DPA, and notice all point at was merged as an intentionally hidden draft (#48100) and never un-hidden. **Changed:** - **Dashboard ToS-update banner**: re-enables `BannerTOSUpdate` with the v3 copy provided by Legal (DPA incorporation, subprocessor list location, fees provisions). New expiry (August 29) and a new localStorage key, since anyone who dismissed the May v2 banner would otherwise never see this one. - **Subprocessor list page published**: removes `noindex,nofollow` and links the page from the Legal Hub index, so the page customers are told to subscribe on is actually discoverable. - **Studio e2e fixture updated**: the global Playwright fixture suppressed the banner via the old localStorage key; with the gate live again it would have rendered the banner into every e2e run. It now sets the new key. ## To test Verified on the Vercel previews : - [x] Studio: banner renders on dashboard load with the Notice badge and new copy; Learn more dialog shows the three changes with correct hrefs (DPA page, subprocessor list, /terms); Understood dismisses and persists across reload via `terms-of-service-update-2026-08-01` - [x] www: `/legal` lists Subprocessor List under Customer Legal Resources; `/legal/customer-resources/subprocessor-list` serves `robots` meta `index,follow` and renders the download button + subscribe form; zero console errors on all tested pages ## Linear - fixes GROWTH-1067 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a publicly accessible Subprocessor List to the legal resources. * Updated the Terms of Service notice to reflect the August 1, 2026 update, including data processing, subprocessors, fraud prevention, and consumer provisions. * **Documentation** * Made the Subprocessor List discoverable through standard search indexing and the legal resources page. * Extended the Terms of Service banner availability through August 29, 2026. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3b06c6c7cc |
fix(docs): unify docs card hover and retire IconPanel (#48379)
## What kind of change does this PR introduce?
Bug fix / docs UI polish.
## What is the current behavior?
- Many docs `GlassPanel`s use `background={false}`, so hover only tweaks
the border and reads as having no hover state
- Compact icon+label grids still use `IconPanel`, which has a broken
`-z-10` hover fill and overlaps with the newer `IconLink` pattern
- Description card grids jump to 3-up too early on medium widths
## What is the new behavior?
**GlassPanel**
- Removes the `background` prop; cards always use the filled surface
with stronger border hover
- Tightens icon→description gap (`gap-6` → `gap-3`)
- Decorative icons/logos use empty `alt` so screen readers don’t hear
the title twice
**Icon tiles**
- Retires `IconPanel` from docs and deletes it from `ui-patterns`
- Uses `IconLink` / `IconLinkList` for compact navigation tiles (auth
providers, social login, etc.)
- Adds `IconLinkButton` for SMS provider pickers (same chrome, opens a
dialog)
- Adds focus styles, list labelling, and dialog-trigger ARIA where
needed
**Layout / content**
- Migrate-to-Supabase description cards on resources use `GlassPanel`
(not slim icon tiles)
- Grid spans use `md:… xl:…` so cards stay 2-up until ~1280px
- Fixes migrate links to `/guides/platform/migrating-to-supabase/…` and
SSR quickstarts to `creating-a-client` with framework query params
- Moves the Extensions list `key` onto the outer `Link`
| Before | After |
| --- | --- |
| <img width="1185" height="1323" alt="Resources Supabase Docs"
src="https://github.com/user-attachments/assets/1677bf65-d3a3-4202-8c70-e758f7c3bcce"
/> | <img width="1185" height="1323" alt="Resources Supabase Docs"
src="https://github.com/user-attachments/assets/51760f0f-62b6-4010-9841-de26039f37b4"
/> |
## Additional context
Homepage compact sections already use `IconLinkList` from #48317; this
PR finishes that pattern for remaining docs `IconPanel` callsites and
cleans up GlassPanel hover.
`www/customers` only drops the removed `background` prop; those cards
already use the filled surface via `logo`.
## Test plan
- [ ] `/guides/getting-started`: GlassPanels show filled surface and
clearer border hover
- [ ] `/guides/resources`: migrate cards are GlassPanels with working
`/platform/…` links; 2-up until xl
- [ ] `/guides/auth/social-login` and auth providers partial: IconLink
tiles hover/focus correctly
- [ ] `/guides/auth/phone-login`: SMS provider buttons open dialogs;
keyboard focus works
- [ ] Docs homepage: migrate / self-host IconLinkLists unchanged in
behaviour
- [ ] `/guides/auth/server-side`: Next.js / SvelteKit cards resolve on
docs preview
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Improved Layouts**
* Made “GlassPanel” card grids more responsive and consistent; refined
card and success badge spacing for a cleaner presentation.
* **Updated Documentation**
* Refreshed multiple guide and resource pages (including quickstarts and
migration content) with standardized card layouts and updated link
destinations.
* **Component Updates**
* Standardized “GlassPanel” styling (background toggle removed) and
simplified icon-based panels; added an `IconLinkButton` for action
tiles; updated authentication provider grids to use the shared tile UI.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
76a9ba968c |
refactor(www): unify legal page shells and versioning (#48483)
<!-- ccr-slack-attribution --> _Requested by **Francesco Sansalvadore, Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399057853249?thread_ts=1785399057.853249&cid=C0161K73J1J)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor of the marketing site's legal pages, plus two small content fixes (removal of duplicated dates, two heading corrections) and two permanent redirects. ## What is the current behavior? The documents linked from the Legal Hub are built three different ways: - `/terms` and `/enterprise-terms` render a plain inline heading with no breadcrumbs. - `/sla`, `/support-policy`, `/aup` and `/privacy` are standalone MDX pages carrying their own layout. - `/legal/dpa` has a one-off centered heading and grid of its own. On top of that, the documents that already have a version selector *also* print a "Last Modified" line inside the document body, so the same fact is stated twice on the page. On `/terms` and `/enterprise-terms` the two statements disagree: the selector says "Version 2 — May 6, 2026" while the body says "Last Modified: 1 May 2026". `/privacy` handles its history differently again — earlier versions live at their own archived URLs (`/privacy-260316` and `/privacy-250528`), strung together by "Previous Version" links at the bottom of each page. ## What is the new behavior? Every legal page now renders through one shell: `PageHeader` with a `PageBreadcrumb`, so the Legal Hub is one click away from any document. - The duplicate "Last Modified" rows are removed from the five versioned documents. The version selector is now the single place a date appears. - `/aup` and `/privacy` gain the version selector. - `/privacy`'s three historical versions are now selectable from the one page, and the two old archived URLs permanently redirect to it. - `/sla` and `/support-policy` pick up the shell and breadcrumbs but intentionally show neither a date nor a selector — neither document has ever carried one, and Legal asked that the SLA stay that way for now. Implementation-wise the canonical pattern is the one the Data Processing Addendum page was already using: `DefaultLayout` > `NextSeo` > `PageHeader` (with a `breadcrumb` slot) > `MDXProvider` > `SectionContainer className="prose"` > `LegalDocVersions`. The standalone MDX pages were moved to `apps/www/data/legal/<slug>/vN.mdx` as bare content partials, with a new TSX shell taking over the original route. No route changed except the two archived privacy pages, which redirect. Dates were carried across from the "Last Modified" lines being deleted rather than invented: `/aup` becomes Version 1 — June 1, 2026, and privacy v1/v2/v3 become May 28 2025, March 16 2026 and May 13 2026. ## Additional context **This is a stacked PR.** It is sequenced behind three PRs that touch the same files and should land first: the Terms of Service v3 bump, the Enterprise SaaS Subscription Agreement v3 bump, and #48481 (DPA effective date → August 1, 2026). #48481 edits the very "Last Modified" line this PR removes from the DPA content file, so a trivial conflict there is expected. This branch will be rebased onto master before it leaves draft. **Two contracts now contain a clause that no longer describes the page.** `apps/www/data/legal/terms/v1.mdx` and `v2.mdx` — and the same sentence in the MPPA and both integration-partner addenda — still read "The date on which the Agreement was last modified will be updated at the top of this Agreement". There is no longer a date in the document body; it sits in the version selector above it. Left untouched here because it is contract text, but Legal should re-word it. **The date mismatch is resolved in favour of the selector.** On `/terms` and `/enterprise-terms`, deleting the body line leaves May 6, 2026 as the only date on the page. Nicole Kramer confirmed in Slack that May 6 is the correct date. **Two headings change visibly**, to line up with the labels used on the Legal Hub: "Terms of service" → "Terms of Service", and "Service Level Agreements" → "Service Level Agreement". **`/legal/dpa` now looks almost identical to `/legal/customer-resources/data-processing-addendum`** — same heading, same breadcrumb, different content. The legacy page is a PDF download plus a signing flow and was deliberately left live, but the overlap is more obvious than it was. Redirecting it to the versioned page is the natural follow-up; it is not done here. **Build verification was incomplete in this environment.** `pnpm install` could not finish because `npm.jsr.io` is blocked by network policy (403), so `next build` never gave a real signal. What did run and pass: - `tsc --noEmit` on `apps/www`, with output byte-identical to clean master - ESLint on every changed file — 0 errors - Prettier using the repo's actual config - a direct MDX compile of all 14 `data/legal/**/*.mdx` files using the app's own MDX options The one thing left unverified is webpack resolving `ui-patterns/PrivacySettings` from the privacy content's new directory. CI will confirm that. Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
8a607a6108 |
feat(www): add Enterprise SaaS Subscription Agreement v3 (#48484)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399555203219)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — a new version of a published legal agreement. ## What is the current behavior? The version selector on `/enterprise-terms` offers two versions of the Enterprise SaaS Subscription Agreement: Version 2 (May 6, 2026) and Version 1 (April 17, 2026). Version 2 is what the page shows by default. ## What is the new behavior? **Before:** opening `/enterprise-terms` showed Version 2 — May 6, 2026. **After:** it shows **Version 3 — August 1, 2026**. Versions 2 and 1 are unchanged and still reachable from the dropdown (`?version=v2`, `?version=v1`). Two files change: - **New** `apps/www/data/legal/enterprise-terms/v3.mdx` — the Version 3 text, transcribed from the source Word document supplied in the Slack thread (`2026.07.29 - Supabase - Enterprise Terms.docx`). - `apps/www/pages/enterprise-terms.tsx` — imports the new MDX and prepends `{ id: 'v3', label: 'Version 3', effectiveDate: 'August 1, 2026', Component: V3 }` to the `versions` array. Since the array is newest-first, v3 becomes the default. ## Additional context ### Transcription fidelity The legal text was not edited, reworded, reordered, or corrected — only re-rendered in the MDX conventions already used by `v1.mdx` and `v2.mdx`. This was verified mechanically rather than by eye: markdown markup was stripped from `v3.mdx` and the result diffed paragraph-by-paragraph against text extracted directly from the source document's OOXML. - **137 paragraphs in the source, 137 in `v3.mdx`, 0 differing.** - 14 top-level sections and 48 subsections, matching the source's heading counts exactly. - All 3 distinct URLs preserved, written as bare URLs per the existing convention in this file family (remark-gfm autolinks them). - Pure ASCII apart from 5 `§` characters in the 48 C.F.R. citations, matching `v1.mdx`/`v2.mdx`. - Prettier clean; no British spellings that would trip the US-locale misspell check. Formatting decisions worth knowing: the source document contains no bold or italic runs at all, but `v1.mdx` and `v2.mdx` both bold defined terms and section numbers, so v3 follows that house style for consistent rendering across the three versions. The source also carries no date or version line of its own; the `_Last Modified: 1 August 2026_` first line is repo convention, matching how every other legal MDX in `apps/www/data/legal/` is written. ### What changed from v2, in the legal text Structure is identical — same 14 sections, same 48 subsection titles. Five substantive prose changes: 1. **Preamble** — the effective date is now "the date of last signature of an Order referencing these terms", replacing v2's unfilled `[Deal.CloseDate]` merge-field placeholder. "Signature block below" becomes "signature block in an Order". 2. **New § 1.4 "Data Processing Addendum"** — defined by reference to `https://supabase.com/legal/customer-resources/data-processing-addendum`, with a carve-out for a separately executed agreement covering the same subject matter. Former § 1.4–1.12 shift to § 1.5–1.13; nothing was removed or reordered. 3. **§ 7.2 Data Processing** replaced — v2's GDPR / UK GDPR / Swiss clause is gone, replaced by a general compliance paragraph that incorporates the Data Processing Addendum into the Agreement. 4. **§ 13.3** cross-reference corrected from Section 10.1 (Mutual) to Section 10.3 (Limited Warranty), which is the clause the refund remedy actually depends on. 5. **§ 14.4 Amendment and Modification** rewritten — v2 required a writing executed by both Parties; v3 gives Supabase a unilateral right to modify by posting a revised version at `https://supabase.com/enterprise-terms`, effective the first day of the following calendar month, or at the start of the next Renewal Subscription Period for Orders with a fixed Subscription Period of 12 months or longer, with non-renewal under § 13.1 as Customer's sole and exclusive remedy. Two things carried over verbatim from the source rather than fixed, since the text must not be edited: § 7.2 is now near-duplicative of § 7.1 (three of its four sentences repeat § 7.1 almost word for word), and "HIPAA" is used in both § 7.1 and § 7.2 without being defined. One pre-existing inconsistency, unrelated to this change: `v2.mdx`'s own first line reads `_Last Modified: 1 May 2026_` while the page lists Version 2's effective date as `May 6, 2026`. Left alone here. ### Overlap with concurrent work Two sibling changes are in flight for the same requester today — one adjusting the new Data Processing Addendum page's dates, one publishing Terms of Service v3. Neither touches these two files, but all three touch the `apps/www/data/legal/` tree, and note that § 1.4 above now links to the DPA page. [#48483](https://github.com/supabase/supabase/pull/48483) removes the `_Last Modified:` first line from every versioned legal MDX, on the principle that the version selector should be the only place a date appears. It is sequenced to land after this PR, and its file list predates `v3.mdx`. A three-way merge of the two branches is clean, but whoever rebases #48483 should add `apps/www/data/legal/enterprise-terms/v3.mdx` to that removal — otherwise v3 keeps a body date after v1 and v2 lose theirs. The `_Last Modified: 1 May 2026` / `May 6, 2026` mismatch on v2 is also handled in #48483 and is deliberately left alone here, so the same line isn't touched by two PRs. Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
44bc7b5a57 |
feat(www): add Terms of Service v3 (effective August 1, 2026) (#48482)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399344523739)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — adds a new version of the Terms of Service to the marketing site (`apps/www`). ## What is the current behavior? `/terms` offers two versions in the version dropdown: **Version 2 (May 6, 2026)**, shown by default, and **Version 1 (July 11, 2025)**. ## What is the new behavior? `/terms` shows **Version 3 (August 1, 2026)** by default. Version 2 and Version 1 are still selectable from the version dropdown (`/terms?version=v2`, `/terms?version=v1`) and are completely unchanged. Two files: - **New:** `apps/www/data/legal/terms/v3.mdx` — the full v3 Terms of Service. - **Changed:** `apps/www/pages/terms.tsx` — imports `V3` and prepends it to the `versions` array. Newest-first ordering is required, because `LegalDocVersions` treats `versions[0]` as the latest. ## Additional context ### The legal text is a verbatim transcription — please review it as such It comes from a Word document supplied by Legal, converted with pandoc and then verified character-exact against the source: **8055 words, 136 blocks, 0 word-level diffs**. Prettier was run over the file and changed nothing. **Known typos in the source document were deliberately preserved. Please do not correct them in review:** - §1 Definitions contains a **duplicate `d.`** — one `d.` introduces the Data Processing Addendum definition and the very next item is also lettered `d.` for the Documentation definition. The list therefore runs a, b, c, d, d, e … Re-lettering would shift internal cross-references, so it is left exactly as drafted. - §12(d) Survival contains a **doubled “and”** — *and Sections 1, 5, 6, 8, 9, 10, 11, and 13, and 14 survive*. Also preserved verbatim from the source: curly quotes on the Data Processing Addendum definition only (every other defined term uses straight quotes), and non-breaking spaces around the hyperlinks. ### Date The source document carries **no date line of its own**, even though its §14(d) states that the last-modified date *will be updated at the top of this Agreement*. August 1, 2026 was specified by the requester, and is placed in the `_Last Modified: 1 August 2026_` line at the top of the MDX, following the v1/v2 convention. As with v1 and v2, the `.mdx` uses `D Month YYYY` while `effectiveDate` in `terms.tsx` uses US long form (`August 1, 2026`). That split is pre-existing and intentional. ### New DPA link §1 of v3 links the Data Processing Addendum page at `/legal/customer-resources/data-processing-addendum`. This link is new relative to v2, and the DPA is also incorporated by reference in §7(b). ### No overlap with the concurrent DPA branch This PR touches only `apps/www/data/legal/terms/v3.mdx` and `apps/www/pages/terms.tsx` — **zero file overlap** with the branch updating the DPA page dates. ### Reviewer checklist - 14 numbered sections (1 Definitions → 14 Miscellaneous), 44 lettered subsections, 6 roman sub-subsections. - ALL-CAPS acceptance block at the top; ALL-CAPS AI disclaimer at the end of §9(b); ALL-CAPS §11 Limitations of Liability. - Three link targets intact: the DPA page, `https://supabase.com/privacy`, and `mailto:legal@supabase.io` (×3). Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
4db78dfe5f |
chore(www): update DPA effective date to August 1, 2026 (#48481)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785399057853249?thread_ts=1785399057.853249&cid=C0161K73J1J)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — moves the Data Processing Addendum's effective date out by two months. ## What is the current behavior? The DPA page at `/legal/customer-resources/data-processing-addendum` shows "Version 1 — June 1, 2026" in the version selector, and the document body opens with "Last Modified: 1 June 2026". ## What is the new behavior? Both now read August 1, 2026: the version selector shows "Version 1 — August 1, 2026" and the document opens with "Last Modified: 1 August 2026". ## Additional context The page renders a hardcoded `versions` array through the shared `LegalDocVersions` component, so the effective date lives in the TSX file; the "Last Modified" line is simply the first line of the MDX content file. Both were updated, each keeping its file's existing date format (`M D, YYYY` in the TSX, `D Month YYYY` in the MDX). No other content changed. ### Not changed — flagging for confirmation The same June 1, 2026 date appears on a few other surfaces. I left them alone because they are either different documents or point at a dated PDF asset that would need to be re-generated and re-uploaded. Let me know if any of these should move too: - `apps/www/pages/legal/dpa.tsx` — the legacy `/legal/dpa` page, which links `Supabase+DPA+260601.pdf` - `apps/studio/components/interfaces/Organization/Documents/DPA.tsx` — Studio links that same PDF - `apps/www/pages/legal/customer-resources/subprocessor-list.tsx` — the subprocessor list (`June-1-2026.pdf` and a "June 1, 2026" label); a separate document - `apps/www/pages/aup.mdx` — the Acceptable Use Policy, "Last Modified: 1 June 2026"; a separate document Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
ca2b50a0a7 |
chore(ui-patterns): collapse the admonition shim into ui-patterns/Admonition (#48377)
Follow-up to #48344: collapses the two resolution paths for the Admonition module into one. `src/admonition.tsx` was a back-compat shim re-exporting `src/Admonition/`. Two ways to resolve one module is exactly what produced the macOS self-import bug fixed in #48344, and the local typecheck errors that #48374 worked around. This removes the shim and standardizes on the PascalCase subpath, matching every other export in the package. **Changed:** - Codemodded all 246 `ui-patterns/admonition` imports to `ui-patterns/Admonition` (240 `.tsx`, 5 `.mdx`, 1 `.ts` across studio, docs, www, design-system, and lite-studio) - Pointed the 5 internal `'../admonition'` imports back at the `'../Admonition'` directory **Removed:** - `packages/ui-patterns/src/admonition.tsx`, and its `./admonition` entry in the exports map (regenerated with `pnpm gen:exports`) ## To test - `grep -r "ui-patterns/admonition" --include='*.ts*'` → no hits - `pnpm test:case-hazards` → passes - `pnpm typecheck` → all 15 tasks green - `pnpm --filter studio run lint:ratchet` → passes - `pnpm --filter ui-patterns vitest run src/Admonition` → 11 tests pass <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Standardized Admonition component imports across the application and documentation. * Improved compatibility with case-sensitive environments by using the canonical component path. * Removed the legacy Admonition import entry point. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
35b2e82852 |
feat(www): add Data Processing Addendum legal page (#48269)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1784836047880599?thread_ts=1784836047.880599&cid=C0161K73J1J)_ ## What kind of change does this PR introduce? Feature — a new marketing-site legal page. ## What is the current behavior? There is no Data Processing Addendum page under Customer Legal Resources. The only DPA content is a legacy `/legal/dpa` page that links out to a static PDF. ## What is the new behavior? **Before:** no DPA page under Customer Legal Resources; DPA content lived only on the legacy `/legal/dpa` page (static PDF link). **After:** a new DPA page at `/legal/customer-resources/data-processing-addendum`, styled like the Terms of Service page — a version dropdown ready for future versions, a "Last Modified: 1 June 2026" line, and the full DPA text (14 clauses + 3 schedules). A "Data Processing Addendum" link is added to the Legal Hub under Customer Legal Resources, using the same FileText icon as Terms of Service. **How:** - New versioned MDX at `apps/www/data/legal/customer-resources/data-processing-addendum/v1.mdx`. - New page `apps/www/pages/legal/customer-resources/data-processing-addendum.tsx`, modeled on the ToS / integration-partner-addendum pattern and rendering via the shared `LegalDocVersions` component (`versions` entry: `{ id: 'v1', label: 'Version 1', effectiveDate: 'June 1, 2026' }`). - Legal Hub link added in `apps/www/pages/legal/index.tsx` with `type: 'document'`. ## Preview Please review on the Vercel preview deploy. Two URLs to check: - `/legal/customer-resources/data-processing-addendum` - `/legal` ## Notes for reviewers - Content was converted faithfully from the provided .docx (normalized word-content diff: 5678/5678 words, zero missing/extra). The source has no tables. - The legacy `/legal/dpa` page (static PDF link) is left untouched — flag if it should be redirected to the new route or retired. - Typecheck/lint could not be run in the build sandbox due to an unrelated JSR-registry 403 during `pnpm install`; Prettier was run and passes. Please confirm CI (typecheck + lint) is green. ## Additional context Version dropdown is single-version for now and is set up to accept future DPA versions. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --- _Generated by [Claude Code](https://claude.ai/code/session_01JA6SATQGc9J8kApnH2NvCz)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
a72259b3f0 |
feat(www): group careers page jobs by department (#48358)
<!-- ccr-slack-attribution --> _Requested by **Dasha Nikolov, Ivan Vasilov** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1785158372513869?thread_ts=1785158372.513869&cid=C0161K73J1J)_ **Before:** the careers page lists open roles under one heading per individual team (Auth, Data API, Functions, Realtime, Storage, ...). **After:** roles are grouped under their top-level department heading (Engineering, Design, ...), collapsing the per-team split. ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature / enhancement to the marketing site (`apps/www`) careers page. ## What is the current behavior? Open positions on the careers page are grouped by individual team, producing one `<h3>` heading per team (Auth, Data API, Functions, Realtime, Storage, ...). This fragments the list into many small groups. ## What is the new behavior? Roles are grouped under their top-level department heading (Engineering, Design, ...), so related teams are collapsed under a single department section. **How:** added a `department: string` field to `JobItemProps` and group on `job.department` (from the Ashby public job-board API, which returns both `department` and `team` as top-level strings per posting) instead of `job.team`. `groupJobsByTeam` is replaced by `groupJobsByDepartment` (it had no other callers), `getServerSideProps` now calls it, and the render loop was updated to key on and display the department heading. All styling, keys, and job rendering are unchanged. ## Additional context A Vercel preview deploy will show the result on the careers page. --- _Generated by [Claude Code](https://claude.ai/code/session_01GEvKydFSLsHhpBbNJ2PEzg)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
8252b69b6a |
feat(www): convert TRAE webinar page to on-demand (#48225)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — converts the TRAE webinar event page to its on-demand version and adds a small template enhancement to support a custom type label. ## What is the current behavior? The [TRAE webinar page](https://supabase.com/events/supabase-trae-high-quality-apps) is set up as a live, upcoming event: `onDemand: false`, a registration CTA linking out to GoToWebinar, and copy written in the future tense ("What we'll cover"). The shared event page template (`pages/events/[slug].tsx`) always renders the raw `type` frontmatter value (e.g. "WEBINAR") as the label at the top of the page, with no way to override it. ## What is the new behavior? - Flips `onDemand` to `true` and swaps the `main_cta` from the GoToWebinar registration link to a `#recording` anchor labeled "Watch the recording", matching the pattern used for the Bolt and Perplexity webinars once they went on-demand. - Adds a `video-container` iframe placeholder (`id="recording"`) below the intro copy. The `src` is intentionally left empty with a `TODO` comment — neither the Bolt nor Perplexity on-demand pages expose the recording URL in frontmatter, it's a hardcoded YouTube embed URL in the MDX body, so this needs the real embed URL dropped in before merging. - Replaces the "What we'll cover" section with updated "Key Takeaways" copy and a closing line ("We hope you enjoy the recording!"). - Adds an optional `type_label` frontmatter field to the event page template. When set, it renders in place of the raw `type` value at the top of the page; when unset, behavior is unchanged for every other event page. Used here to show "Supabase Live" instead of "WEBINAR". ## Additional context Verified locally in preview: - TRAE event page renders correctly with the new CTA, video placeholder, updated copy, and "SUPABASE LIVE" label. - Other event pages (e.g. `enterprise-innovation-with-bolt`) are unaffected and still show their original type label, confirming the `type_label` change is backward compatible. Still needed before merging: the actual recording embed URL in the iframe `src`. |
||
|
|
312d05af4b |
fix(www): changelog frontmatter (#48249)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Security/bug fix ## What is the current behavior? The changelog entry parser exposes all YAML frontmatter fields parsed by `matter()` directly to the client via Next.js props. This includes private fields like `internal:` (escalation teams, notes) and `reviewers:`, which get serialized into the page's `__NEXT_DATA__` and are visible in View Source even if never rendered. ## What is the new behavior? - Added `PUBLIC_FRONTMATTER_KEYS` constant that explicitly allowlists only the fields safe to expose to the browser - Added `toPublicFrontmatter()` function that filters frontmatter down to the allowlist, dropping `internal:`, `reviewers:`, and any other private keys - Updated `parseChangelogEntryFile()` to apply the allowlist before returning frontmatter to callers - Added comprehensive unit tests covering both the filtering logic and the integration with the parser This uses an allowlist approach rather than a denylist, so new private fields added upstream won't silently leak to clients. ## Additional context The allowlist is kept in sync with `ChangelogEntryFrontmatter` in `changelog-repo.ts` per the code comment. Tests verify that: - Only allowlisted keys are present in the returned frontmatter - Private fields like `internal` and `reviewers` are never exposed - Public fields flow through untouched - Undefined values are omitted from the result https://claude.ai/code/session_017uSmnCLsskFYR7YH8DKGkr <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a shared changelog title renderer that safely displays titles as inline Markdown. * Added plain-text title extraction for consistent headings and SEO metadata. * **Bug Fixes** * Prevented private/internal changelog frontmatter (including reviewer metadata) from being exposed to browser-rendered pages. * Ensured featured and non-featured changelog timelines stay consistent even when some entries fail to serialize. * Improved the changelog detail not-found behavior to revalidate instead of caching 404s indefinitely. * **Tests** * Added coverage for public frontmatter allowlisting, date normalization (`publish_date`/sorting), and `sortDate` consistency across YAML variations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Lukas Bernert <lukas@bernert.at> |
||
|
|
7c20cc574c |
feat(www): new changelog sync (#47880)
## What kind of change does this PR introduce? Sync changelog from private supabase/changelog. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Changelog entries now come from the structured changelog repository. * Added filters for change type, product stage, and self-hosted impact. * Updated badge UI for affected products and change types with filter links. * Changelog detail sidebar now shows lifecycle stage, sunset dates, and self-hosted impact (when available). * **Improvements** * Product category discovery and filtering now use affected products. * Discussion links show only when legacy discussion data is present. * RSS feeds and generated changelog markdown now use the updated metadata. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3bca21b3f8 |
chore(a11y): convert leftover focus recipes to focus-ring (#48219)
## What kind of change does this PR introduce? Accessibility cleanup (DEPR-628). ## What is the current behavior? Leftover call sites still use ad-hoc focus recipes (`ring-foreground-muted`, `outline-brand`, Dialog/Sheet `focus:` rings, etc.) instead of the shared utilities from #41575. ## What is the new behavior? Converts those leftovers across `packages/ui`, Studio, www, docs, and design-system to `focus-ring`, preferring `focus-visible`. Keeps documented exceptions (`group-focus-visible`, InputGroup `:has()`). ## To test Tab through controls (keyboard only). Expect a consistent offset ring on `:focus-visible`, not a green/brand/custom stack, and no ring animation. ### www (marketing) Preview: https://zone-www-dot-com-git-danny-depr-628-focus-ring-fbccf9-supabase.vercel.app - Global nav on `/`: Product, Developers, Solutions dropdowns; logo; hamburger + mobile menu - `/features`: view toggles and feature cards - `/company`: card links - `/changelog`: timeline / entry links - `/partners/catalog`: grid/list toggle and partner cards - `/pricing`: compute section expand control - Product / Modules / Solutions sticky navs on product pages (e.g. `/database`, `/storage`) - `/state-of-startups`: TwoOptionToggle if present ### docs Preview: https://docs-git-danny-depr-628-focus-ring-long-tail-supabase.vercel.app - Any guide page: top nav dropdowns and items - Narrow viewport: hamburger, then mobile menu links + close - Guide with PromptPanel / tabs: tab to prompt actions and tab list ### studio (dashboard) Preview: https://studio-staging-git-danny-depr-628-focus-ring-long-tail-supabase.vercel.app - Project home: Connect section tiles; drag-handle focus on sortable sections - Integrations marketplace (`/project/<ref>/integrations`): featured cards, list/grid toggle, list rows - Auth (`/project/<ref>/auth/oauth-apps`, `/project/<ref>/auth/providers`): open create/edit sheet, tab to close (X) - Database policies (`/project/<ref>/database/policies`): open policy editor sheet, tab to close - Storage policies (`/project/<ref>/storage/files/policies`): bucket section links; policy modal close - Query performance (`/project/<ref>/observability/query-performance`): info icon buttons on metrics - Replication pipeline detail (if available): slot lag / status info icons - Support (`/support/new`): attachment add/remove controls - Table editor: spreadsheet import preview checkboxes; row text/JSON editor TwoOptionToggle - Any Dialog/Sheet/toast close (X): ring on keyboard focus only, not mouse click ### design-system Preview: https://design-system-git-danny-depr-628-focus-ring-long-tail-supabase.vercel.app - Colour palette swatches (keyboard focus) - Form patterns sidepanel example: avatar / focusable control in the example ## Additional context - Linear: [DEPR-628](https://linear.app/supabase/issue/DEPR-628) - Follow-ups: form-group CSS (DEPR-629), Storage columns selection (DEPR-630), ESLint rule (DEPR-632) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility & Usability** * Standardized keyboard focus indicators across navigation, dialogs, forms, buttons, toggles, links, and tooltips using a consolidated focus style. * Improved toggle controls to use proper button semantics (instead of clickable text), including `aria-pressed`/disabled handling and better keyboard navigation. * **Visual Updates** * Harmonized hover/focus ring visuals across the design system, Studio, documentation, and marketing pages while preserving existing layout and interaction behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6f6badae51 |
fix(eslint): promote require-explicit-tabindex to error (#48170)
## What kind of change does this PR introduce? Accessibility / lint hardening (Safari keyboard focus). ## What is the current behavior? `supabase/require-explicit-tabindex` is `'warn'`. Studio’s ratchet was at 0 but the rule was still ratcheted; www / docs / design-system still had raw `<button>` / `role="button"` call sites without an explicit `tabIndex`. [DEPR-627](https://linear.app/supabase/issue/DEPR-627) · follow-up to #47984 / #48040 ## What is the new behavior? - Shared config: `'supabase/require-explicit-tabindex': 'error'` - Swept www / docs / design-system (+ Studio test fixtures the ratchet skipped) - Removed the rule from the Studio ratchet + baselines ## To test Prefer **Safari**. This PR only adds explicit `tabIndex` to raw `<button>` / `role="button"` call sites — not links, and not controls that already go through `Button` from `ui`. ### Marketing (`www`) ([staging link](https://zone-www-dot-com-git-danny-depr-627-promote-req-7ae43c-supabase.vercel.app/)) - [x] Homepage frameworks / dashboard feature tabs — Tab through each tab button - [x] Product pages (e.g. `/auth`, `/database`) — section tab switchers - [x] Narrow viewport — open the hamburger; Tab through menu buttons - [x] `/partners/catalog` — filter / view controls - [x] Blog view toggle (list ↔ grid) ### Docs ([staging link](https://docs-git-danny-depr-627-promote-require-explici-25e46d-supabase.vercel.app/)) - [x] **Desktop (≥ lg):** top-right **⋯ menu** (hamburger icon) — opens a dropdown that includes Theme. Not a separate theme button. - [x] **Mobile (< lg):** top-right **hamburger** opens the sheet; close (X) is the raw button we tagged. Theme inside the sheet uses `ThemeToggle` / `DropdownMenuTrigger` from `ui` (already supposed to set `tabIndex`). - [x] **Code blocks** — copy / language controls - [x] **Is this helpful?** — X / check are `Button` from `ui` (should already Tab). After voting **while signed in**, the follow-up “What went well?” / “How can we improve?” text button is the raw one we tagged. - [x] **AI Tools → Copy as Markdown** (right rail on a guide) — this is the only GuidesSidebar control this PR changed. “On this page” TOC items are **links**, not covered by this lint. - [x] **Reference docs** (e.g. JS client reference) — section headers that expand/collapse in the left nav (`Collapsible.Trigger`) - [x] **Troubleshooting index** — type in the search field, then Tab to the **clear (X)** control ### Dashboard (`studio`) No production UI changes in this PR (tests + lint config only). Quick Safari smoke that prior tabindex work still holds: - [x] Project sidebar — Tab through primary nav links - [x] Settings → General — Tab through inputs / buttons - [x] Storage → Files — Tab a bucket row / file actions |
||
|
|
ffd5a93f37 |
feat(www): add hidden Legal Hub subprocessor list page (draft) (#48100)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1783431374242039?thread_ts=1783431374.242039&cid=C0161K73J1J)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature (`apps/www`). ## What is the current behavior? No public page for Supabase's subprocessor list, and no way for customers to be notified when it changes. ## What is the new behavior? A new hidden page at `/legal/customer-resources/subprocessor-list` shows the current dated subprocessor PDF and lets anyone subscribe with their name and email to receive an email whenever the list is updated. The page is `noindex` and not linked from any nav, so it's shareable by direct URL only for now. Mirrors Wiz's sub-processor-list page. **How:** - **Page** `apps/www/pages/legal/customer-resources/subprocessor-list.tsx` — pages-router, mirrors the existing Legal Hub pages (`DefaultLayout`, `NextSeo`, `PageHeader` + breadcrumb, `SectionContainer` prose). Embeds the PDF (inline preview + download link) and renders the subscribe form. Marked `NextSeo` noindex/nofollow and intentionally left unlinked. - A single `CURRENT_PDF` constant (filename + display date) is the only thing to change when Legal hands over a new dated PDF. - **Form** `apps/www/components/SubprocessorUpdatesForm.tsx` — mirrors `SecurityNewsletterForm` (First name, Last name, Email; `ui` primitives). Carries the framing copy verbatim, with **Subscribe to updates** bold and Privacy Policy linked to https://supabase.com/privacy. - **API route** `apps/www/app/api-v2/submit-form-subprocessor-updates/route.tsx` — exact mirror of `submit-form-security-newsletter`; subscribes the user to the Customer.io "Subprocessor Alerts" subscription (topic 4) via `cio_subscription_preferences.topics.topic_4: true`. - **PDF** `apps/www/public/legal/subprocessor-list/June-1-2026.pdf`. **Updating the list in future:** Drop the new dated PDF into `apps/www/public/legal/subprocessor-list/` and update the `CURRENT_PDF` constant. Nothing else changes. ## Additional context **Notes / to confirm:** - Customer.io topic id `4` → `topic_4` (per Prashant); not independently verified against Customer.io. - Draft: page is intentionally unlinked and noindex until Legal signs off. --- _Generated by [Claude Code](https://claude.ai/code/session_01D9WS2QWQ8Y3o7PqDZabS3F)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
c914163a06 |
Improve features search with relevance-based ranking (#48039)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature enhancement ## What is the current behavior? The features page filters search results by simple substring matching, treating all matches equally. Features are then sorted alphabetically regardless of search relevance. ## What is the new behavior? Search results are now ranked by relevance using a weighted scoring system: - Title matches starting with the search term score highest (5 points) - Title substring matches score 4 points - Subtitle matches score 2 points - Description matches score 1 point Results are sorted by relevance score (highest first), with alphabetical ordering as a tiebreaker. This ensures users see the most relevant features first when searching. ## Additional context The implementation adds: - `SEARCH_WEIGHT` constant defining the relevance weights for different match types - `getSearchScore()` function that calculates a feature's relevance to a search term - Updated filtering and sorting logic that uses relevance scoring The weights are carefully chosen so that any title match always ranks above features that only match in subtitle/description, improving search quality without requiring complex algorithms. https://claude.ai/code/session_01573vYv6WZhrboV14NQSuc4 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved feature search with relevance-based matching. * Search results now prioritize matches in feature titles, especially title prefixes, followed by subtitles and descriptions. * Results are displayed in relevance order for faster discovery. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
805aee289e |
fix(studio): color regressions after theme update (#47794)
## What kind of change does this PR introduce? Bug fix + small shared component ## What is the current behavior? After the recent colour system changes, several UI elements lost contrast in light mode: - `InfoIcon` with a background appeared as a flat grey circle (glyph fill matched the background) - Several buttons forced `text-white`, which no longer contrasts correctly against the updated brand fills - Selected / completed check badges were inconsistent between call sites ## What is the new behavior? - `InfoIcon` uses `text-background` for the glyph fill so the "i" is visible against the grey circle - www primary buttons drop hardcoded `text-white` and use standard `Button` colours - New shared `SuccessCheck` in `ui` for selected state and completion progress (green circle; white check in light mode, black check in dark mode) - Documented in the design system with selected + progress examples Note on `InfoIcon`: [#47933](https://github.com/supabase/supabase/pull/47933) landed a related fix using `text-background-200` (`--card`). This PR keeps `text-background` instead, to match `CheckIcon` / `EyeOffIcon` in the same file and avoid the legacy alias. | Before | After | | --- | --- | | <img width="688" height="268" alt="CleanShot 2026-07-10 at 11 30 25@2x" src="https://github.com/user-attachments/assets/c0276b0c-1023-46c8-805c-35a22def1353" /> | <img width="664" height="278" alt="CleanShot 2026-07-10 at 11 29 43@2x" src="https://github.com/user-attachments/assets/3508cf37-1b48-4fb7-a939-83522feb44f1" /> | | <img width="468" height="550" alt="CleanShot 2026-07-10 at 11 31 04@2x" src="https://github.com/user-attachments/assets/acd42273-15ce-4fb2-9d0c-5a43ac23073c" /> | <img width="460" height="540" alt="CleanShot 2026-07-10 at 11 32 50@2x" src="https://github.com/user-attachments/assets/f66fb4bc-81f7-4df1-95f5-63980c4e8537" /> | ## To test Use the staging preview link from this PR and check the following in **light mode** (and spot-check dark mode): **www** - Visit `/404` — "Head back" button should have readable text (not white-on-green) - Visit `/company` — "Join the team" button in the Team section - Visit a product page with a hero CTA (e.g. `/database`, `/realtime`) — primary "Start for free" button **studio** - Database → Replication → deploy a read replica — footer `InfoIcon` next to the pricing line should show a visible "i" inside the grey circle - `/redeem` — select an org; green `SuccessCheck` should match light/dark contrast (white check / black check) - Settings → API → service role key row — red "secret" tag text should be readable **design system** - `/docs/components/success-check` — demo, selected-state, and progress examples |
||
|
|
d23f86021a |
feat(www): Partner Catalog update (#46757)
## Info architecture change around "Partners" The www "integrations" now become more partner-driven. `/partners/integrations` -> now Partner Catalog under `/partners/catalog` (old links redirect to new paths) Moved them close together in the nav dropdown and in the footer <img width="494" height="336" alt="Screenshot 2026-07-09 at 11 06 41" src="https://github.com/user-attachments/assets/a875fef0-0ab8-47ca-8756-d658b27c4892" /> <img width="1149" height="665" alt="Screenshot 2026-07-09 at 11 09 48" src="https://github.com/user-attachments/assets/9631bb72-fe25-4fb4-b1af-9f14a37d02e7" /> ## /partners This page remains untouched in this PR, updates to layout, content and intake form are delegated to #47874 ## /partners/catalog Listed in the [catalog](https://zone-www-dot-com-git-feat-www-partners-pages-supabase.vercel.app/partners/catalog) are now partners. Some partners match with a listing. <img width="1207" height="866" alt="Screenshot 2026-07-09 at 11 14 17" src="https://github.com/user-attachments/assets/b65216be-976f-4ef5-91f8-1ad49da87b45" /> ## /partners/catalog/[partner] Each partner can have one or more "listings" which are either - simple guides - foreign data wrappers - dashboard integrations Integrations available in the dashboard now all have a prominent "Install integration" cta to open it in the dashboard [integrations page](https://supabase.com/dashboard/project/_/integrations). <img width="1269" height="776" alt="Screenshot 2026-07-09 at 11 16 51" src="https://github.com/user-attachments/assets/3c7bb715-ffce-4d0a-905f-9a660c3b1f5a" /> ## Docs Update docs → [Preview](https://docs-git-feat-www-partners-pages-supabase.vercel.app/docs/guides/integrations) - remove "Supabase marketplace" - use "Dashboard Integrations and Partner Catalog - update integrations in sidenav to link to updated /partners/catalog/** listings <img width="1520" height="696" alt="Screenshot 2026-07-15 at 12 54 47" src="https://github.com/user-attachments/assets/9f5a2794-4536-4299-97df-9732d3d75b4c" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Partner Catalog experience with search, category filters, official-partner toggle, responsive filtering (sidebar + bottom sheet), grid/list views, and featured partners. * Added Partner Catalog detail pages with tabbed listings, MDX-rendered content, image gallery with zoom overlay, and “add/install” actions. * **Improvements** * Updated “Become a Partner” layout and form support for prefilled values and checkbox-group fields (including validation). * Updated navigation/footer/docs and partner tile links to use Partner Catalog routes; expanded redirects from legacy integrations paths. * Added public agent-skills discovery manifest. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alan Daniel <stylesshjs@gmail.com> Co-authored-by: Alex Hall <alex.hall@supabase.io> Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
949a57d285 |
content(www): update investor logo wall on company page (#47753)
## Summary - Adds 8 new investor logos: Accel, Craft, Figma, Georgian, GIC, Peak XV, Salesforce Ventures, Stripe - Reorders lead investor grid to match design mockup (3 rows of 4) - Adds per-logo `scale` field to control logo size within each cell - Adds `grayscaleOnly` field for Salesforce Ventures to preserve tonal contrast (prevents wordmark from being hidden by `contrast-0` filter) ## Test plan - [ ] Visit /company and verify all 12 investor logos render correctly across 3 rows - [ ] Check logo sizing and order matches the mockup - [ ] Verify Salesforce Ventures wordmark is visible inside the cloud shape - [ ] Check dark mode 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Expanded and reordered the “Our investors” lead cards with additional entries (including Stripe, Salesforce Ventures, and others). * Enhanced logo presentation options for lead cards with per-investor sizing/positioning controls. * **Bug Fixes** * Improved lead investor card image rendering by removing internal scrolling and using an overflow-hidden container with scale-based sizing. * Preserved the existing logo filter behavior (opacity-only when configured, grayscale-only when selected, otherwise the default contrast treatment). <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
586ed82270 |
content(www): update company page metrics, investors, and press (#47700)
## Summary - Updated community stats: 10M+ developers, 100K+ GitHub stars, 200K+ followers, 50K+ SupaTroopers - Updated funding copy from \"over \$116 million\" to \"\$1 Billion\" - Added Supabase Series F blog post to Press section - Changed press articles grid from 3-column to 4-column to match podcasts layout - Reduced community stats font size (text-4xl → text-3xl) and added right padding to prevent overlap with dividers <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Bug Fixes** * Improved spacing and borders in the community stats grid for cleaner end-of-list alignment. * **Style** * Reduced the community stat number size for better readability. * Updated the Press articles layout on large screens to show more items per row. * **Content Updates** * Refreshed community stat counts for Developers, GitHub, Twitter, and Discord. * Updated “Our investors” copy to **$1 billion**. * Added **“Supabase Series F”** as the first Press article. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
31509521b6 |
feat(www): add Customer Legal Resources to legal hub and declutter footer (#47655)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature / content update to the Legal Hub (`apps/www`). ## What is the current behavior? The `/legal` hub page (`apps/www/pages/legal/index.tsx`) has a single section, "Partner Legal Resources." The customer-facing legal documents (Terms of Service, Support Policy, Service Level Agreement) are only reachable from the footer "Company" column, which is cluttered. ## What is the new behavior? - Adds a new **"Customer Legal Resources"** section to the `/legal` hub, placed **above** "Partner Legal Resources," with links to: - Terms of Service → `/terms` - Support Policy → `/support-policy` - Service Level Agreement → `/sla` These use the same formatting (document icon + link) as the existing "Master Partner Program Agreement" entry. - Removes those same three links (Terms of Service, Support Policy, Service Level Agreement) from the footer **"Company"** column (`apps/www/data/Footer.ts`) to declutter it. The "Legal" hub link, Privacy Policy, Privacy Settings, and Acceptable Use Policy all remain. The `/terms`, `/support-policy`, and `/sla` URLs are unchanged and continue to operate exactly as they do today — this only changes where they're surfaced in navigation. Note: per discussion, the hidden `/enterprise-terms` page was intentionally **not** linked from the public hub; it remains `noindex/nofollow` and reachable only by direct URL. ## Additional context Visual result (Customer section above Partner section, three matching links) and footer cleanup match the requested design. No routing, redirect, or page-content changes. --- _Generated by [Claude Code](https://claude.ai/code/session_015kQyGkM9s9XEbA3HSLpeku)_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a **“Customer Legal Resources”** section to the legal resources page with links to **Terms of Service**, **Support Policy**, and **Service Level Agreement**. * **UI Updates** * Updated the legal page branding from **“Legal”** to **“Legal Hub”** and adjusted the layout to a more spacious two-column presentation. * Updated the footer **Company** links by replacing **“Legal”** with **“Legal Hub”** and removing the Terms/Support/Service Level links from that set. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
fb02182e86 |
Color system (#47288)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Bug fix, feature, docs update, ... ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Refreshed theming across the UI to use modern color expressions and shared theme variables (including OKLCH-based gradients), improving consistency for charts, code blocks, overlays, icons, and decorative backgrounds. * **Bug Fixes** * Improved light/dark color and gradient consistency across axis/grid styling, reference lines, buttons/badges, sidebar accents, loaders, and other visual components. * **Documentation** * Updated styling/theming guidance to align with the revised semantic token system and the updated theme variable usage patterns. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
aa764e4013 |
chore(www): refine www styling (#47499)
### Logo positioning bug on Safari #### Before <img width="1538" height="1404" alt="CleanShot 2026-07-01 at 07 11 55@2x_b0d735b7df6470afb861f4e82cfeed554743cec621475197e07ff39a98c5c506" src="https://github.com/user-attachments/assets/dc8483bd-5a2a-4d89-9b90-d0ab3529b4b5" /> #### After <img width="1177" height="526" alt="Screenshot 2026-07-01 at 15 25 59" src="https://github.com/user-attachments/assets/e5ab66eb-56eb-4f1b-8a66-783aafad069d" /> ### Uniform h1 styling #### Before Font-weight too heavy <img width="721" height="504" alt="Screenshot 2026-07-01 at 15 55 53" src="https://github.com/user-attachments/assets/4dc4e157-f746-4626-9ec7-5e893d7155ba" /> #### After <img width="693" height="410" alt="Screenshot 2026-07-01 at 15 56 04" src="https://github.com/user-attachments/assets/c012d6e5-0889-4466-b2b2-56d1c9516e27" /> ### AI Builders platform card ### Before <img width="675" height="573" alt="Screenshot 2026-07-01 at 16 18 31" src="https://github.com/user-attachments/assets/a34e2fde-115b-45e8-8d44-9fc32c22c0a1" /> ### After <img width="640" height="576" alt="Screenshot 2026-07-01 at 16 18 23" src="https://github.com/user-attachments/assets/45ebf1c7-6508-40de-a755-dda17824979a" /> ### Logo theme-awareness on 404 page #### Before <img width="1053" height="670" alt="Screenshot 2026-07-02 at 11 22 45" src="https://github.com/user-attachments/assets/d1f45cc8-00ad-48ad-a21a-3b92bf6097f0" /> #### After <img width="1053" height="666" alt="Screenshot 2026-07-02 at 11 22 28" src="https://github.com/user-attachments/assets/8b6435aa-da87-46f3-9d5c-750f8222edb1" /> --- Plus other minor padding/spacing issues: - remove customer stories in homepage - use correct container width and align "Use Supabase with [framework]" section - restore default `--font-sm` sizing as it resulted too small for www <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes / UI Improvements** * Refined spacing, layout, and responsive styling across multiple homepage sections. * Improved featured logo positioning and adjusted community/hero copy sizing. * Updated site typography for better readability and wrapping. * Refreshed the 404 experience with a smoother reveal animation and consistent layout. * Updated deep dark-mode behavior to apply only during launch weeks. * **Performance** * Lazy-loaded multiple homepage sections to improve initial load and perceived speed. * **SEO / New Features** * Added a dedicated 404 page that disables indexing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |