mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 01:15:03 +03:00
master
38898
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
9aae037dff |
Joshenlim/fe 4475 fdw update sql to run proper alter statements instead of (#50988)
## Context Currently for FDWs under integrations, editing an FDW involves tearing it down then re-creating it - which while conveniently works has a lot of problems like: - Blast radius is way bigger than the edit - Everything is recreated, including vault secrets - Silent drops grants/comments/ownership - Cascades on dependent objects - Views or functions built on top of foreign tables would get dropped along with it Changes in this PR hence updates `getUpdateFDWSql` to diff the current wrapper state against the form state and generate targeted `ALTER` statements for only what actually changed ## To test - [ ] Verify that updating an existing wrapper still works as expected <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Wrapper changes can be saved in place, including server options, encrypted values, foreign tables, and column definitions. * Input fields can display placeholder text, and missing server-option values display their defaults. * **Improvements** * Saving is unavailable until encrypted values are ready; a waiting message appears while they load. * The edit panel closes after a successful save. Confirmation text explains that table or column changes may affect dependent functionality. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b91870b012 |
Add Kacper Mentel to humans.txt (#51017)
Add Kacper Mentel to `humans.txt`. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Kacper Mentel to the team list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e3fec137fe |
Joshenlim/fe 4466 audit logs update organization logs as well (#50935)
## Context Follows up from [this PR](https://github.com/supabase/supabase/pull/50799) - updates the Audit Logs UI for organization audit logs. Just differs from Account audit logs slightly with added "Actor" + "Target" column Reuses the same UI components from account audit logs so quite a bit of code clean up 🙂 <img width="1451" height="955" alt="image" src="https://github.com/user-attachments/assets/a1002cee-917f-4d9a-b977-3fab8ecd2d13" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Organization audit logs now use a sortable table with row selection and a resizable details panel. * Actor details show a member’s username when available, otherwise the actor’s email; a dash appears when neither is available. * Logs can be filtered by users and projects, with separate messages for no logs and no matching results. * A refresh control and loading indicators help show audit-log updates. * **Bug Fixes** * Organization project lists stop loading when pagination totals are unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
864cca6cda |
fix(design-system): update border radius for menu items (#50973)
## Problem Border radiuses for inner items of dropdowns, menus etc. didn't keep up with recent changes. ## Solution Adds a token/variable to help keep this consistent across our apps and components. One caveat is this modifies shadcn components, so I'm open to alternative ways of doing this. | Before | After | |--------|--------| | <img width="293" height="206" alt="Screenshot 2026-09-28 at 12 00 27" src="https://github.com/user-attachments/assets/cd5e0708-0223-43ac-9893-a33ce5acd1ca" /> | <img width="335" height="231" alt="Screenshot 2026-09-28 at 12 00 41" src="https://github.com/user-attachments/assets/dc993b09-1410-4596-ae8f-4e78e6739fa6" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Standardized corner rounding across command items, context menus, dropdown menus, menubars, select options, and multi-select options. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c3bb547e24 |
Add Kevin Shaffer-Morrison to humans.txt (#51015)
Adding Kevin Shaffer-Morrison to humans.txt as he just joined the team! ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Kevin Shaffer-Morrison to the public team listing. No other documentation or public-facing declarations changed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
93a262d185 |
Check region selection for project creation (#51012)
## Context Previously added telemetry for `selectedRegionOption` and `selectedRegionOptionType` [here](https://github.com/supabase/supabase/issues/50851) if the best available region option is available for users Opting to extend this telemetry (still just for Free plan orgs) irregardless if best available region was selected and include `initialRecommendedRegion` Main thing to understand is what regions users are spinning projects up in outside of the recommended option ## To test - [ ] Verify the telemetry network request after creating projects - [ ] Non-free plan: Telemetry request doesn't have `initialRecommendedRegion` in the payload - [ ] Free plan: Telemetry request has `initialRecommendedRegion` in the payload - Sends correctly if best available region option is available (default behaviour for staging) - Sends correctly if best available region option is NOT available (override with dev tools the configcat flag) |
||
|
|
8f6a6f7032 |
fix(studio): wait for organization before loading regions (#50572)
## Problem The new-project page can request available regions with a paid compute size before the selected organization plan resolves. For free organizations, this produces a failed request followed by a successful request without the size. ## Fix Delay both available-regions query observers until the selected organization resolves, while preserving size-dependent refetches. Add request-level coverage for the initial free- and paid-plan behavior. ## How to test - Run `pnpm --filter studio exec vitest --run 'tests/pages/new/[slug].test.tsx'`. - Open the new-project page for a free organization and inspect the available-regions request. - Expected result: one initial request is sent without `desired_instance_size`; paid organizations send one initial request with `desired_instance_size=micro`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved project creation so available regions are loaded only after an organization is selected. - Ensured region availability requests use the appropriate instance size for the organization’s plan: no size parameter for free plans and `micro` for paid plans. - Prevented unnecessary region-availability requests when no organization has been selected. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
177ef0cdd6 |
fix(www): repair broken docs links and redirect /blog/rss.xml (#51002)
## Problem Four www pages link to docs URLs that return 404: - `/storage`: the "Learn more" links for analytics and vector buckets (`storage/analytics-buckets`, `storage/vector-buckets`) - `/` (frameworks grid): the Vue quickstart (`quickstarts/vuejs`) - `/edge-functions`: the CI/CD link (`functions/cicd-workflow`; that page was merged into the deploy guide) - `/partners`: the Enterprise SSO link (`auth/sso`) Feed readers also request `/blog/rss.xml`, which renders the blog 404, while the feed lives at `/rss.xml`. Apart from prefetch requests, it is the most-requested 404 on www. ## Solution - Point each link at the live page: `storage/analytics/introduction`, `storage/vector/introduction`, `quickstarts/vue`, `functions/deploy#cicd-deployment`, `auth/enterprise-sso`. - Redirect `/docs/guides/functions/cicd-workflow` to the deploy guide. This also fixes the older blog post and changelog links to it. The redirect destination has no anchor because the `.md` redirect generator in `next.config.mjs` appends `.md` to the destination. - Redirect `/blog/rss.xml` to `/rss.xml`. ## To test On the www Vercel preview: - [x] On `/storage`, click "Learn more" under analytics buckets and vector buckets: expect the analytics and vector introduction pages. They navigate to `/docs/guides/storage/analytics/introduction` and `/docs/guides/storage/vector/introduction`. The www preview doesn't serve `/docs`, so I confirmed every new docs target returns 200 on production. - [x] On `/`, click Vue in the frameworks grid: expect the Vue quickstart. The Vue tab's "Read docs for Vue" link navigates to `/docs/guides/getting-started/quickstarts/vue`. - [x] On `/edge-functions`, click the CI/CD link: expect the deploy guide scrolled to CI/CD deployment. Opens "Deploy to Production" in a new tab with `#cicd-deployment` in view. - [x] On `/partners`, click the Enterprise SSO link: expect the enterprise SSO guide. Opens "Enterprise Single Sign-On" in a new tab. - [x] Request `/blog/rss.xml` and `/docs/guides/functions/cicd-workflow`: expect 308s to `/rss.xml` and `/docs/guides/functions/deploy`. Both return 308, and `/rss.xml` serves the feed as XML. - [x] `/docs/guides/functions/cicd-workflow.md` returns 308 to `/docs/guides/functions/deploy.md`. - [x] None of the four pages still links to an old path (`analytics-buckets`, `vector-buckets`, `quickstarts/vuejs`, `functions/cicd-workflow`, `auth/sso`). ## Linear - fixes GROWTH-1297 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated quickstart and integration links for Vue, Edge Functions CI/CD, analytics and vector storage buckets, and Enterprise SSO. * Added permanent redirects from the old RSS feed and Functions CI/CD guide URLs to their current locations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
138b654994 |
fix(studio): point Usage log ingest and query links at logs-* docs (#51001)
## Problem The org Usage page links added in #50570 point to `/docs/guides/platform/manage-your-usage/log-ingest` and `/log-query`. Neither page exists. The docs live at `logs-ingest` and `logs-query`, so every click from the Usage page lands on a 404. Within a day of #50570 shipping, these two paths were the top docs 404s by unique visitors. ## Solution - Point both Usage page links at the `logs-*` pages. - Add permanent redirects from the singular paths, because they're already being shared: search engines and AI assistants now send people to them. The existing generator in `apps/www/next.config.mjs` adds the `.md` variants. ## To test On the Vercel previews: - [x] Open an org's Usage page on the Studio preview and click the Log Ingestion docs link: expect the `logs-ingest` docs page, not a 404. Opens `supabase.com/docs/guides/platform/manage-your-usage/logs-ingest` in a new tab ("Manage Logs Ingest usage"). - [x] Click the Log Query docs link: expect the `logs-query` docs page. Opens `.../logs-query` in a new tab ("Manage Logs Query usage"). - [x] No docs link on the Usage page still points at the singular `log-ingest` or `log-query` paths. - [x] On the www preview, request `/docs/guides/platform/manage-your-usage/log-ingest` and `/log-query`: expect a 308 to the `logs-*` pages. Both return 308 to the matching `logs-*` path. The www preview doesn't serve `/docs`, so I confirmed both targets return 200 on production. - [x] `log-ingest.md` and `log-query.md` also return 308 to the matching `logs-*.md` paths. ## Linear - fixes GROWTH-1296 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated the Log Ingestion and Log Query documentation links to their current pages. * Added permanent redirects from the previous documentation paths to the corresponding pages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5951fb6c47 |
fix(studio): polish Pipelines loading and update cues (#50963)
## Problem Pipelines loading causes layout shifts, and the update cue is hard to connect to its menu action. - Resolves [PIPE-1078](https://linear.app/supabase/issue/PIPE-1078/show-destination-rows-while-details-are-loading) - Resolves [DEPR-688](https://linear.app/supabase/issue/DEPR-688/widen-the-update-available-modal) - Resolves [DEPR-691](https://linear.app/supabase/issue/DEPR-691/clarify-the-update-available-indicator-in-pipeline-actions) ## Solution Reserve space for the graph and list while loading, show destination rows before their details arrive, align the detail header, and stack version values in the update dialog. Match the primary-colour dot on the options button and its Update available menu item. Give the status tooltip more room. | Before | After | | --- | --- | | <img width="408" height="346" alt="8294" src="https://github.com/user-attachments/assets/9a44dfe0-5473-4809-b705-fd6077efe44b" /> | <img width="844" height="738" alt="CleanShot 2026-09-28 at 17 10 34@2x" src="https://github.com/user-attachments/assets/4eba3f16-6dc4-4c02-83b4-9689203859bd" /> | | After | | --- | | <img width="426" height="472" alt="CleanShot 2026-09-28 at 17 11 27@2x" src="https://github.com/user-attachments/assets/8b3c181c-b48e-4803-a24a-fb7dce3957d4" /> | | _Links ambiguous dot to dropdown menu item_ | | <img width="1942" height="262" alt="CleanShot 2026-09-28 at 17 29 18@2x" src="https://github.com/user-attachments/assets/efc047bb-a8ea-4041-bd0d-fa2cb15f4414" /> | | _Better alignment with nav bar above it_ | ## Review instructions 1. Reload Database > Pipelines and check the loading layout and destination rows. 2. Open a pipeline detail page and check its header, update dialog, and matching update dots. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Destination rows now appear while pipeline details are loading, with controls becoming available when the details finish loading. * **Style** * Loading states on the replication page now use diagram and table-shaped placeholders. * Updated replication page spacing, version-status tooltips, update indicators, and the version comparison layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c415f502ed |
feat(studio): show publication partition handling (#50773)
## Problem During pipeline creation, Studio did not show how an existing Postgres publication handles partitioned tables. The checkbox in the new-publication sheet also made the two possible modes harder to compare. Resolves [DEPR-675](https://linear.app/supabase/issue/DEPR-675/show-and-edit-postgres-partition-handling-for-publications). ## Solution Replace the checkbox in the new-publication sheet with a two-option dropdown. The default remains “Use parent table identity”. For an existing publication, append its partition-handling mode to the Publication field description in the pipeline creation sheet. This shows the current setting without presenting it as an editable pipeline option. Changing an existing publication’s setting is outside this PR. | Existing Publication Selection | | --- | | <img width="1260" height="224" alt="CleanShot 2026-09-28 at 12 52 10@2x" src="https://github.com/user-attachments/assets/240d7c23-d226-40b9-8d27-a359c8ae4b75" /> | | _Loading_ | | <img width="1238" height="198" alt="CleanShot 2026-09-28 at 12 52 00@2x" src="https://github.com/user-attachments/assets/36c8b1de-eb47-4f76-890d-19d0f33a75a1" /> | | _One of two values_ | | New Publication Creation | | --- | | <img width="832" height="660" alt="CleanShot 2026-09-28 at 12 52 33@2x" src="https://github.com/user-attachments/assets/c1108c3a-d65b-4d20-b1a8-7e0b68fe5e87" /> | | _One of two values_ | | <img width="840" height="650" alt="CleanShot 2026-09-28 at 12 52 40@2x" src="https://github.com/user-attachments/assets/6a2c23d9-12d5-4949-91b1-3867b60ccdd5" /> | | _Second of two values_ | ## Review instructions 1. Open the pipeline creation sheet and choose to create a new publication. Confirm that Postgres partition handling offers “Use parent table identity” and “Replicate each partition separately”, with the former selected by default. 2. Select each option in turn and confirm that the new publication is created with the selected mode. 3. Select an existing publication and confirm that its partition-handling mode appears in the description beneath Publication. Switch publications and confirm that the description updates. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * The replication destination form explains whether the selected publication uses the parent table’s identity or replicates partitions separately. It also shows when publication details are loading or unavailable. * When creating a publication, choose how partitioned tables are handled: use the parent table’s identity or replicate each partition separately. * **Tests** * Added coverage for publication guidance, loading and unavailable states, and partition-handling choices. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2c5b0a5ca0 |
fix(ui): fall back to writeText when clipboard.write fails (#50777)
## Problem Safari can expose `navigator.clipboard.write()` while rejecting it with `NotAllowedError`. Studio's shared clipboard helper treated that rejection as a terminal failure, so Copy buttons showed "Unable to copy to clipboard" even though `writeText()` worked. Fixes #50769 ## Solution - Fall back to `navigator.clipboard.writeText()` when the rich clipboard write fails. - Preserve the existing success callback and error behavior. - Add regression coverage for fallback success, total failure, and callback exceptions. ## Verification - `pnpm exec vitest run lib/helpers.test.ts --pool=threads` - `pnpm test:prettier` - `pnpm --filter ui run typecheck` - `pnpm --filter studio run typecheck` - `pnpm --filter studio run lint` - `npm run build -- --filter=studio` - Rendered browser verification with `clipboard.write()` forced to reject; `writeText()` received the expected payload and the Copy button showed success. ## Review instructions 1. Review the fallback logic in `packages/ui/src/lib/utils/clipboard.ts`. 2. Review the regression tests in `apps/studio/lib/helpers.test.ts`. 3. Confirm no generated or vendored files are changed. - [x] I have read CONTRIBUTING.md - [x] This PR does not change documentation content. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Copying now falls back to standard clipboard copying when rich clipboard access is unavailable or denied. * An error message is shown only when both clipboard methods fail. Successful rich clipboard writes do not trigger a fallback if a follow-up action fails. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3f205627e0 |
feat(library): redesign the site around the block catalog (#50372)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — the visual redesign itself. Part 5 of 6 in a stack that splits the library redesign into reviewable pieces. The four PRs beneath it carry the build, content and Markdown work; what's left here is layout, navigation and styling. ## What is the current behavior? The library is laid out like a documentation site: a sidebar tree of framework folders, a homepage that lists links, and a guide page that opens with prose. That shape suits reference material, but the library's job is to help someone find a block and install it — and the sidebar is the only way to discover one. ## What is the new behavior? The homepage is the catalog itself — blocks grouped by what they do (authentication, database, storage, realtime, messaging, AI, foundations) rather than by framework, each with a preview of what it renders, filterable by category. Navigation moves into a site header whose Explore menu opens the same categories, so the catalog is reachable from any page and the per-page sidebar tree is gone. A guide opens with what the reader came for: the block's name, the install command, and a preview pane with tabs — the running component and its files — before any prose. The file tree that used to sit mid-page under "Folder structure" is one of those tabs. Every guide also offers a copy of the agent prompt that points at its Markdown. Getting-started pages get the same treatment: the quickstart is now a framework-tabbed walkthrough rather than a wall of setup links. ## Additional context `BlockOverviewTabs` renders Preview and Files here. #50369, stacked on top of this one, adds the third "What's added" tab — it is the only part of the redesign that depends on the new resource analyzer, which is why it sits above this PR rather than below it. Also removes what the redesign orphaned: the table-of-contents component and its `remark` / `mdast-util-toc` dependencies, and the sidebar nav and command-item configuration the new header replaced. The block source changes are typography only — auth card titles move from `text-2xl` to `font-medium text-lg tracking-normal` — which is what regenerates the auth registry artifacts. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a redesigned Supabase Library catalog with categorized blocks, framework-aware navigation, previews, file views, and installation actions. * Added framework-specific quickstart guides for Next.js, React, Vue, Nuxt, React Router, and TanStack Start. * Added copy-to-clipboard prompts, “Open in v0” actions, starter templates, and richer visual previews. * **Improvements** * Updated documentation layouts, FAQ content, typography, navigation, accessibility, and responsive behavior. * Improved mobile navigation, framework selection, and standardized block installation guidance. * Refined authentication and social-login block presentation with more consistent heading styles. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
80761d2521 |
docs(troubleshooting): Add guide for NXDOMAIN errors (#50969)
## Problem We get several tickets related to NXDOMAIN errors ## Solution Add guide to troubleshoot the issue, providing typical scenarios and workarounds ## Checklist Check all before review: - [X] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [X] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) Used `/write-the-docs` and then manually modified several things <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added troubleshooting guidance for `NXDOMAIN` errors when connecting to a project, covering possible causes, checks, and next steps. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
7f1df457f8 |
feat: Create action to upsert table for new search (#50683)
## Problem For the new search, we will scan all files present within the public/markdown directory, extract text nodes and upsert a new Supabase table in a new project to do FTS type search. ## Solution In this PR: - A new script directory is created with files to solve all the steps described above. - Unit tests added for the fundamental bits of the script. - A new workflow file is added so the action runs after push every time content is altered, added or removed. <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions Sadly, testing this work is quite complex, but in case someone wants to: 1. Create a new Supabase project ton your personal space 1. Copy the id of the project and a secret key and add it to the new Search V2 environment variables as shown in the example file 1. Copy the content of the newly added `setup.sql` and run it on the SQL editor of your project. 1. Fetch this branch and on the search directory, run `search-v2:ingest` 1. Your project's table should have rows corresponding to the content from docs ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Documentation pages are now indexed for full-text search at the page and section level. - Search results can show the most relevant section from each page, with its title, heading, excerpt, and relevance score. - Search content is automatically refreshed when published Markdown documentation changes. - **Tests** - Added coverage for Markdown parsing, page structure, routing, and search-content generation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2532fab239 |
feat(www): note that paid projects aren't paused for inactivity on pricing (#50986)
## Summary Adds "Projects on paid plans aren't paused for inactivity" to the pricing page's meta and Open Graph descriptions and to the generated `pricing.md` intro. The existing copy is unchanged. Ref: GROWTH-1191 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated pricing descriptions to clarify that projects on paid plans are not paused for inactivity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
49da804baa |
feat(www): add database-only and agent guidance to homepage and pricing markdown (#50992)
## Problem The markdown versions of the homepage (`/index.md`) and pricing page (`/pricing.md`) don't say that a Supabase project can be used as a standalone Postgres database, what that costs, or how an agent should get set up. `llms.txt` also doesn't link to the product markdown pages. Ref: GROWTH-1191 ## Solution Markdown only. No changes to the rendered HTML pages. All changes are additive. - **`/pricing.md`** (`apps/www/lib/llms.ts`): new "Database-only projects" section covering Free and Pro costs for a single database project and that paid-plan projects are not paused. Plan prices, the Free database size, the Pro disk size, and the Free plan pausing note are read from `packages/shared-data/plans.ts`, so they stay in sync. - **`/index.md`**: short note for agents, a "Use it as just a Postgres database" section, agent setup commands (agent skills, CLI), a goal-to-docs table, and machine interfaces (MCP, OpenAPI, agent skills index, llms.txt, markdown negotiation). One bullet added to Key Differentiators. - **`/llms.txt`**: new "Product overviews" section linking the product markdown pages. ## Review instructions 1. Open `/index.md`, `/pricing.md`, and `/llms.txt` on the preview deployment. 2. Check the new sections read correctly and the figures in "Database-only projects" match the pricing page. 3. Every added link returns 200 as markdown, except `https://mcp.supabase.com/mcp`, which requires OAuth. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added product overview links for Database, Auth, Storage, Realtime, Edge Functions, Cron, Queues, and Vector, including a note about Database’s Postgres compatibility. * Expanded guidance on using Supabase as a standalone Postgres database, optional product costs, Free-plan pausing, and database-only pricing. * Added agent setup instructions, task-specific documentation links, machine-readable endpoints, and a Markdown pricing link. * Added database-only project details to generated pricing content, including plan features, compute credits, pausing, and connection guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
27af9ca162 |
chore(www): run production builds through Turbo (#50713)
www builds currently bypass Turbo. This caches Next.js compilation and sitemap generation while keeping content refreshes and asset uploads on every build, including cache hits. **Changed:** - Refresh content before Turbo hashes its inputs, and upload assets after Turbo saves or restores the build output. - Include generated content, shared code, environment settings, sitemaps, and the customer RSS feed in the cache configuration. - Remove the redundant `vercel.json` build override and consolidate public environment settings into `NEXT_PUBLIC_*`. Cache reuse requires the same commit and build inputs because production CDN URLs include the commit SHA. **Added:** - Build lifecycle tests covering cache restoration, input invalidation, root/app commands, and upload ordering and failure handling. ## To test - From `apps/www`, run `pnpm exec vitest run turbo-build.test.ts generate-sitemap.test.ts scripts/lib/githubStars.test.ts`. - Check the Vercel preview build runs content preparation before `build:next`, and verify the homepage, `/sitemap.xml`, and `/customers-rss.xml` load. - Rebuild with identical prepared content and environment settings to check compilation is cached. Asset uploads should still run when enabled. Validation: 63 tests passed, along with typecheck, ESLint for the new test, formatting, and a full local build. The local build used public example settings and placeholder survey configuration, with asset uploads disabled; Vercel deployment validation is still pending. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Build & Deployment** - Production builds now reuse cached outputs and restore generated assets when a cache is available. - Static assets upload after a successful build, and changes to content, documentation, configuration, or shared components trigger a fresh build. - **Documentation** - Added production build guidance covering caching, CDN uploads, overrides, and direct-build limitations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
dd02e96a17 |
Use common shift click helper for audit logs (#50894)
## Context This [PR](https://github.com/supabase/supabase/pull/50462) introduced a shared helper to handle shift click selections for tables. Changes here just updates the account audit logs to use that shared helper <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Audit log row selection now toggles individual rows on click and uses the last-clicked row as the anchor for Shift-click range selection. When no rows remain selected, the range anchor is cleared. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
54c2a2788f |
Joshenlim/fe 4474 add command to generate types off api production (#50960)
## Context Adds a pnpm command `api:codegen:prod` to generate API types off prod to work with the `verify-production-types` GHA. Just uses the existing logic in `verify-production-types.mjs` to fetch the OpenAPI specs, and writes it into the local API types files <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * API types can now be generated from the production API specifications when a local API environment is unavailable. * **Bug Fixes** * Resending invitations and updating project-scoped roles now handle roles without a base role ID more reliably. * **Documentation** * Updated guidance clarifies that API or schema changes must be deployed before relying on updated types. * Production is the source of truth for merge checks. Type verification should pass after deployment, and production-generated types are expected to pass verification. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ae7b9ee245 |
fix(www): inner border radii for homepage cards (#50987)
## Problem Looks like they broke when something else got updated. ## Solution Fixes width some CSS var magic that should inherit whatever the outer radii is. | Before | After | |--------|--------| | <img width="1186" height="170" alt="Screenshot 2026-09-28 at 17 36 18" src="https://github.com/user-attachments/assets/69ba7e37-d57e-4c86-a668-fa707cf80ccb" /> | <img width="1182" height="180" alt="Screenshot 2026-09-28 at 17 36 26" src="https://github.com/user-attachments/assets/de23b3fe-2b92-440d-b01f-57cd71e95971" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated panel corner radii to scale at medium screen sizes, with the inner corners kept slightly smaller than the outer corners. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e3a937edb0 |
chore(studio): pin online scorer threads to the built-in preprocessor (#50981)
Pins the online scorers' `trace.getThread()` to the built-in `thread` preprocessor, so we can set the Assistant project's default preprocessor to a [custom one for Topics](https://linear.app/supabase/issue/AI-1258/add-a-topics-preprocessor-that-caps-tool-results-in-assistant-traces) without changing scorer input. `getThread()` otherwise [uses the project default](https://github.com/braintrustdata/braintrust-sdk-javascript/blob/cc165a4843805b531645ddb1d27969204aab9ade/js/src/trace.ts#L807). Ref AI-1258 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Corrected thread retrieval to use Braintrust’s thread preprocessor, ensuring evaluation traces are processed consistently. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b2cf3693dd |
feat(studio): /api/status-page endpoint backed by incident.io Widget API (#50931)
## Summary * Adds `/api/status-page` (Next route + TanStack wrapper), backed by the [incident.io](<http://incident.io>) Widget API, annotating each item with `visible`, `show_banner`, and (for scheduled maintenances) `banner_lead_days`. * Deployment-mode visibility is driven by a new `status_page:visibility_field_ids` custom-content key. * Widget array parsing is fault-tolerant: a malformed item in one array is dropped and logged rather than failing the whole response, so one bad item can't hide a real ongoing incident. * 429s from [incident.io](<http://incident.io>) are retried with equal-jitter exponential backoff, respecting `Retry-After`, up to 2 retries. * Nothing consumes this endpoint yet — it replaces no existing behavior and changes nothing user-visible. Later PRs (this is PR 1 of a stack) wire up consumers behind the `incidentIoStatusPage` ConfigCat flag. Part of [FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured) — see Linear for full design context. ## Test plan - [X] `pnpm --filter studio run typecheck` - [X] `pnpm --filter studio run lint:ratchet` - [X] `pnpm knip --workspace apps/studio` - [X] `pnpm test:prettier` - [X] `pnpm --filter studio exec vitest run status-page` — 44 tests passing, including a regression test built from a real production [incident.io](<http://incident.io>) payload that initially failed to parse, and a compile-time type-safety regression test for the array-parsing helper Co-authored-by: Claude Code [charis@supabase.io](<mailto:charis@supabase.io>) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a status page that displays ongoing incidents and maintenance, with visibility and banner settings based on linked incident details. * Status page data is available through a new API endpoint, with caching for successful responses and degraded results. * **Bug Fixes** * Status page data can still display when some linked incident details are unavailable; affected results are marked as degraded. * Improved handling of invalid widget entries so they don’t prevent valid items from being processed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Code <charis@supabase.io> |
||
|
|
1b5a806963 |
fix: show support contact message if Studio fails to load (FE-4460) (#50872)
## Summary
- Adds a fallback message ("Taking longer than expected?... contact
support@supabase.io") shown after 7s if Studio fails to fully load, for
the Next.js runtime — mirrors the existing TanStack-only
`ShellFallback`, which had no Next.js equivalent
- Fixes the support email in the existing TanStack `ShellFallback` (was
`support@supabase.com`, should be `support@supabase.io`)
- Extracts the shared copy (message, email, delay) into one file so both
fallbacks stay in sync
## Why
Linear FE-4460: users reported the Dashboard going completely blank with
no way to reach support when a JS chunk failed to load. The Next.js
runtime (the current default) had no fallback at all for this case.
## Test plan
- [ ] Normal page load: fallback never appears
- [ ] Simulated stuck boot (mount signal disabled): fallback appears
after 7s with correct copy/email, no layout bugs
- [ ] Same two checks on the TanStack runtime
(`STUDIO_FRAMEWORK=tanstack`)
- [ ] `pnpm --filter studio run typecheck` / `lint:ratchet` pass
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added a loading fallback that appears if the app takes too long to
load, with guidance to clear browser cookies and reload.
* On self-hosted platforms, the fallback includes a support contact
link.
* The fallback is automatically hidden once the app loads.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
0003958f70 |
chore(ci): notify #team-frontend when ratchet baseline hits zero (#50978)
<!-- ccr-slack-attribution --> _Requested by **Charis Lam** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1790599888647059?thread_ts=1790599888.647059&cid=C0161K73J1J)_ ## Problem The weekly "Decrease studio lint ratchet baselines" workflow (`.github/workflows/studio-lint-ratchet-decrease.yml`) mechanically decreases each tracked ESLint rule's baseline count in `apps/studio/.github/eslint-rule-baselines.json` and opens/updates a PR. When a rule's count reaches exactly 0, there's nothing left to ratchet — a human (or agent) needs to remove it from ratchet tracking (`apps/studio/scripts/ratchet-rules.json` and the baseline file) and bump its ESLint severity to `error`, as was just done manually in #50977. Nobody is currently notified when this threshold is crossed, so it can sit unnoticed. ## Solution **Before:** the job silently commits the decreased baselines and opens/updates its PR with no signal that any rule just hit 0. **After:** a new step runs after the baseline commit/PR step, only when that step found changes (via a new `id: decrease-baselines` and a `changed` step output, added without touching the existing decrease logic itself — just capturing its existing control flow into an output). It parses the final `apps/studio/.github/eslint-rule-baselines.json` on disk for any rule whose count is exactly `0`. If any are found, it posts a Slack message via `curl` to a webhook, tagging `@Claude` in `#team-frontend` with the rule names and a link to the PR the job just created/updated, asking it to do the same triage as #50977 (remove from ratchet tracking, bump severity to `error`). If no rule is at 0, it skips silently. The webhook URL comes from a new repo secret, `secrets.SLACK_TEAM_FRONTEND_WEBHOOK_URL`, which **does not exist yet**. **A human needs to create a Slack incoming webhook for #team-frontend and add its URL as the `SLACK_TEAM_FRONTEND_WEBHOOK_URL` repository secret before this step will actually post anything.** Until then, the step detects the missing/empty secret and only logs a `::warning::`, exiting 0 — it will never fail the job. ## Review instructions 1. Read `.github/workflows/studio-lint-ratchet-decrease.yml`: confirm the existing decrease/commit/PR step is unchanged except for the added `id: decrease-baselines` and the two `echo ... >> "$GITHUB_OUTPUT"` lines that record whether anything changed and the PR URL. 2. Confirm the new final step only runs `if: steps.decrease-baselines.outputs.changed == 'true'`. 3. Confirm the new step parses `apps/studio/.github/eslint-rule-baselines.json`'s `rules` map for entries equal to `0`, and skips (exit 0, no curl) when none are found. 4. Confirm the `curl` call is gated on `SLACK_WEBHOOK_URL` being non-empty, and that a failed `curl` only emits `::warning::` rather than failing the step (`set -euo pipefail` is still safe because the failure is inside an `if !`). 5. Note that this PR alone does not make the notification fire: `SLACK_TEAM_FRONTEND_WEBHOOK_URL` must be provisioned as a repo secret (Settings → Secrets and variables → Actions) from a Slack incoming webhook for #team-frontend first. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com> |
||
|
|
4a9b4b0a9e |
feat(docs): o11y agent setup stepper (#50962)
## Problem on monitoring agent pages the prompt lives in a "prompt" tab next to agent ones, while each agent tab ended with "paste the prompt" users have to work out that the prompt is sitting in that previous tab ## Solution this pr is a proposal to set agent setup as a two stepper `1` for the prompt panel `2` holds the agent tabs: - extracts prompt into a first step - moves agent tabs within their own step - polishes agent docs to match recent ui updates - sets `prompt` as an anchor link within agent tabs | state | preview | | -------|------| | before | <img width="823" height="452" alt="image" src="https://github.com/user-attachments/assets/a6a01832-ea73-48c1-b31d-25a0ef970e4e" /> | | after | <img width="823" height="716" alt="image" src="https://github.com/user-attachments/assets/f5014ad0-1555-4578-b4b1-5bf2733b4d37" /> | <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions Provide a clear numbered procedure that the PR reviewer can walk through. 1. visit [/automate-with-agents/health](https://docs-git-docs-agent-setup-stepper-supabase.vercel.app/docs/guides/observability/automate-with-agents/health#set-up-the-agent) ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Agent setup instructions are organized into prompt-copying and scheduling steps, with links to harness documentation. * Code tabs support icons and controlled selection. * Source code samples support adjustable footer notches. * **Bug Fixes** * Step numbers now display the correct shadow. * Links to page anchors now scroll to, focus, and highlight their targets, while respecting reduced-motion preferences. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f0e0865acc |
chore(studio): promote zero-baseline eslint ratchet rules to error (#50977)
<!-- ccr-slack-attribution --> _Requested by **Charis Lam** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1790599888647059?thread_ts=1790599888.647059&cid=C0161K73J1J)_ ## Problem The Studio ESLint "ratchet" (`apps/studio/scripts/ratchet-eslint-rules.ts`, baseline in `apps/studio/.github/eslint-rule-baselines.json`, tracked rules in `apps/studio/scripts/ratchet-rules.json`) lets certain rules stay at `warn` severity while CI blocks the *count* of violations from increasing. Several of those tracked rules had already reached a baseline of 0 allowed violations, meaning there's nothing left to ratchet — they should be enforced directly instead of tracked indirectly. ## Solution **Before:** `no-restricted-imports`, `jsx-a11y/aria-props`, `jsx-a11y/aria-proptypes`, `jsx-a11y/role-supports-aria-props`, `jsx-a11y/anchor-has-content`, `jsx-a11y/aria-role`, `jsx-a11y/no-aria-hidden-on-focusable`, `jsx-a11y/tabindex-no-positive`, `jsx-a11y/no-distracting-elements`, and `react-hook-form/no-use-watch` were all tracked in the ratchet baseline with a count of 0, and (apart from `no-restricted-imports`, see below) configured as ESLint `warn` in `apps/studio/eslint.config.cjs`. **After:** each of those rules is removed from `apps/studio/.github/eslint-rule-baselines.json` (both the `rules` count and the now-empty `ruleFiles` entry) and from `apps/studio/scripts/ratchet-rules.json`. Their severity in `apps/studio/eslint.config.cjs` is bumped from `warn` to `error` so they're enforced directly by lint going forward instead of being tracked via the ratchet. `no-restricted-imports` was a special case: a later config block in `apps/studio/eslint.config.cjs` already overrides the shared `warn` default with `error` (confirmed via `eslint --print-config`), so only the ratchet bookkeeping needed removing for that rule — no severity change was needed. Promoting `jsx-a11y/role-supports-aria-props` to `error` surfaced one real violation that the ratchet's non-test-file filter had been hiding: a mock `<button>` in `LocalDropdown.test.tsx` set `aria-checked`, which that role doesn't support. Removed the unused `aria-checked` attribute from the mock (it wasn't asserted on by any test). Every other rule still tracked by the ratchet (e.g. `@typescript-eslint/no-explicit-any`, `react-hooks/exhaustive-deps`, `no-restricted-exports`, …) has a baseline above 0 and was left untouched. ### How verified - `pnpm --filter studio run lint:ratchet` → `Stable: No regressions for selected rules.` - `pnpm --filter studio run lint` → `0 errors, 2430 warnings` (no new errors from the severity bumps) - `npx vitest run components/interfaces/LocalDropdown.test.tsx` → 3/3 passing after the mock fix - `npx prettier --check` on all touched files → clean - `npx tsc --noEmit` shows one pre-existing, unrelated error in `packages/ui-patterns` (reproduced identically on `master` before this change) ## Review instructions 1. Confirm `apps/studio/.github/eslint-rule-baselines.json` and `apps/studio/scripts/ratchet-rules.json` no longer list the 10 rules named above. 2. Confirm those same rules (except `no-restricted-imports`, already `error`) are now `'error'` in `apps/studio/eslint.config.cjs`. 3. Run `pnpm --filter studio run lint:ratchet` and `pnpm --filter studio run lint` locally to confirm both pass. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP --- _Generated by [Claude Code](https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
8e20712475 |
chore(design system): clean up compute icon (#50971)
Cleaned up the `compute` icon which wasn't aligned and perfectly isometric. | Before | After | | -------------- | ------ | | <img width="240" height="209" alt="Screenshot 2026-09-28 at 12 56 10" src="https://github.com/user-attachments/assets/ffe0232f-5933-4310-886f-2de8caa53712" /> | <img width="269" height="208" alt="Screenshot 2026-09-28 at 12 56 13" src="https://github.com/user-attachments/assets/0e4ab8ab-6818-473b-a786-42ca3aae32e4" /> | |
||
|
|
db63b4d6a2 |
docs: add usage examples partial to the server reference (#50858)
## Problem The `@supabase/server` reference goes straight from Installing to the generated API reference. It has no worked example. The middleware reference has a "Usage examples" page in that spot (#50461). ## Solution A new "Usage examples" partial sits between Installing and the generated reference. It has three examples, taken from the server repo's `docs/getting-started.md`: - **Protect an endpoint with a user JWT:** `withSupabase({ auth: 'user' })`, its CORS handling, and `ctx.supabase` vs `ctx.supabaseAdmin`. - **Serve a public endpoint:** `auth: 'none'`, plus the `verify_jwt = false` setting Edge Functions need. - **Build the context yourself:** `createSupabaseContext` returning `{ data, error }`. Files: - `spec/reference/server/v1/partials/usage-examples.mdx` and its `docs/ref/server/` mirror - `usage-examples` added to `partialsOrder` in `spec/reference/server/v1/config.json` Every claim is checked against the source code in `supabase/server`, `supabase/middleware`, and `supabase/cli`. ## Preview links | Site | Preview | | ---- | ------- | | Docs | [/docs/reference/server/usage-examples](https://docs-git-docs-server-usage-examples-supabase.vercel.app/docs/reference/server/usage-examples) | ## Review instructions 1. Open the preview link. 2. Check that "Usage examples" appears in the sidebar between Installing and the generated reference. 3. Check that the three examples render with the code on the right. ## Checklist - [ ] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added server usage examples for protecting endpoints, serving public endpoints, and creating Supabase context manually. * Documented runtime requirements, JWT verification settings, CORS behavior, and the differences between caller-scoped and admin access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3d8da2d827 |
[bot] Decrease ESLint ratchet baselines (#48332)
Automated weekly decrease of ESLint ratchet baselines. Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> |
||
|
|
99cfaf1f01 |
chore(design system): uniform elastic icon style (#50974)
The `elastic` icon wasn't following the same styling of other icons in our design system. This PR uniforms it. | Before | After | | -------------- | ------ | | <img width="121" height="81" alt="Screenshot 2026-09-28 at 13 46 47" src="https://github.com/user-attachments/assets/f22f53b0-4b13-4d7a-b6f3-ce92664782de" /> | <img width="104" height="90" alt="Screenshot 2026-09-28 at 13 47 18" src="https://github.com/user-attachments/assets/39edc6f3-614a-4c12-8dd6-31ba953507be" /> | Link to preview icon: https://design-system-git-chore-elastic-icon-supabase.vercel.app/design-system/docs/icons |
||
|
|
7994191e49 |
feat(studio): group consecutive assistant tool calls (#50893)
<img width="913" height="572" alt="image" src="https://github.com/user-attachments/assets/e8112085-508a-49e4-abb1-7550248e611e" /> ## Problem A single Assistant response often produces 10+ reasoning and lookup rows ("Reasoned", "Ran search_docs", …). They push the answer down the chat, use raw tool names, and a fast tool call flashes past before the row goes back to "Thinking...". ## Solution Consecutive reasoning and lookup rows fold into one collapsible group. - **Running:** the header shows a tool only while it executes ("Checking policies in public..."). Between calls it reads "Thinking...", however long that lasts. Each header label stays up for at least 1 second, so quick calls no longer flash. - **Finished:** the header lists what the tools did, e.g. "Searched docs and checked policies", or "…, and 2 more". - **Expanded (any time):** every call is listed under a vertical rule. Rows still in progress shimmer, including several at once for parallel calls. ## How to test 1. Run `pnpm dev:studio` and open the Assistant on a project with a few tables. 2. Ask something that needs several lookups, e.g. "What RLS policies do I have and what do the docs recommend for them?" 3. While it streams, check the collapsed header: - It shows each tool while it runs, then goes back to "Thinking..." between calls. - Labels don't flash. Each stays up for about a second. - Only the shimmer marks progress, with no blinking cursor underneath. 4. Expand the group mid-stream. Rows read like "Checking policies in public..." rather than tool names, and only rows still in progress shimmer. 5. When it finishes, the header lists the actions ("Searched docs and checked policies") and stops shimmering. 6. Press Stop while a group is running. The unfinished row reads "Response interrupted" and stops spinning. 7. Reload the chat. Older groups show their collapsed summaries. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * AI assistant tool activity is grouped into collapsible sections with progress labels while work is underway and summaries when complete. * Expand grouped activity to review reasoning and tool details. Active tools and reasoning are highlighted, while completed reasoning without text is hidden. * Progress labels remain visible briefly during transitions, and active responses display a shimmer effect. * **Bug Fixes** * The loading indicator no longer appears while the assistant is processing a tool group. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
93a032c90d |
Design System: Improve icon button example accessibility (#50783)
## Problem The Icon only button example lacks some accessibility features: - no `aria-label` for screen readers - no tooltip for sighted users ## Solution Add both with comments explaining the reasons ## Review instructions See https://design-system-imfc534k0-supabase.vercel.app/design-system/docs/components/button#only-an-icon <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified icon-only button guidance: use a tooltip for sighted users and an accessible label for screen readers. When the tooltip repeats the button’s label, prevent it from being announced twice. * Added guidance to use a square button container and increase the tap target by 8px. Updated the icon-button example to demonstrate a “View logs” tooltip and accessible labeling. * **New Features** * Icon-only buttons now use a compact square layout with an expanded tap target. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
c856de8fda |
fix(studio): polish pipeline creation copy and actions (#50956)
## Problem The current pipeline creation sheet describes destination type with two disconnected sentences. The enablement callout repeats itself, while three Pipelines action menus have undersized triggers. ## Solution Use a complete destination-specific description for each release stage. Present the Enable Pipelines callout as a note with an action title, a short explanation, and one button. Clarify the enablement dialog copy and align the three action-menu triggers with a consistent button width and hit area. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Pipelines Database Sandals Field Lab Supabase" src="https://github.com/user-attachments/assets/fac744dd-2701-40ae-a65d-0801a1a86e6f" /> | <img width="1024" height="759" alt="Pipelines Database Sandals Field Lab Supabase" src="https://github.com/user-attachments/assets/075bf609-5b65-40ca-8aaf-d27335d48838" /> | | <img width="1024" height="759" alt="18436" src="https://github.com/user-attachments/assets/92f8c63b-f9b9-4dd6-b9b6-26ede932c172" /> | <img width="1076" height="759" alt="93893" src="https://github.com/user-attachments/assets/3c6f26b0-130c-4508-bf6b-d2c641805426" /> | | <img width="1024" height="759" alt="16935" src="https://github.com/user-attachments/assets/63e75045-412a-4bcc-9cf9-20245ac60871" /> | <img width="1024" height="759" alt="75021" src="https://github.com/user-attachments/assets/09771e1e-2e89-466d-8f60-22c5bacc9956" /> | ## Review instructions 1. Open [Database > Pipelines in the Studio preview](https://studio-staging-git-dnywh-fixpipelines-creation-polish-supabase.vercel.app/dashboard/project/_/database/pipelines), click **Add pipeline**, and select BigQuery or Snowflake. Confirm the Type description reads as a complete sentence. 2. On a project where Pipelines is not enabled, open the creation sheet. Confirm the note has no extra padding or Docs link, then click **Enable** and check the dialog copy. The list menu's **Enable Pipelines** action opens the same dialog. 3. Check the action-menu triggers on the Pipelines list, pipeline detail page, and table row for consistent sizing and click targets. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **User Experience** * Replication setup now displays a loading state while access and organization details are checked, then shows the appropriate access request, enablement notice, or destination form. * Access notices use clearer, responsive messaging with a primary “Request access” link. * Enablement messaging now reflects whether your plan includes access, and the success notification is shorter. * Destination-type notices now identify the selected type and clarify that it cannot be changed after creation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f2ff4ec0e9 |
fix(realtime): display banner when realtime has been suspended by admin (#50497)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? If Realtime's admin_suspended_at is set we display a banner. ## What is the current behavior? REAL-1095 ## What is the new behavior? <img width="1160" height="442" alt="Screenshot 2026-09-17 at 12 06 30 pm" src="https://github.com/user-attachments/assets/f5abe900-a163-48c9-ab55-945fc62df0d1" /> ## Additional context Depends on https://github.com/supabase/platform/pull/38476 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - Added a notice to Realtime settings when the service is suspended, with instructions to contact support. - **Bug Fixes** - Improved invitation resending and role updates for roles without a linked base role. - **Tests** - Added coverage to verify the suspension notice appears only when applicable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
c75d87d5ef |
Add /go/ask-supabase-select Select 2026 recap page (#50889)
## Problem Attendees at Supabase Select 2026 need a quick, linkable page that recaps what shipped and points them to the right next step, whether that's a theme blog post, a solution page, or the full features directory. ## Solution Added `/go/ask-supabase-select` using the go-page system (`GoPageInput` config, no bespoke React): - **Hero**: "Build in an instant. Scale to infinity." with a "Read the Recap" CTA - **Our announcements**: three theme cards (Build anything, Scale without limits, Operate with confidence), each with a blurb sourced from the drafted Select 2026 theme blog posts and a CTA to that post - **Explore Supabase for your team**: a 2x2 grid of solution cards (AI Builders, Startups, Developers, Enterprise), each fully clickable to its solutions page - **Supabase features**: closing CTA out to `/features` Also adds `whitespace-pre-line` support to the shared go-page `HeroSection` component so a hero description can wrap onto a second line when the config string includes `\n`. This is additive and doesn't change rendering for existing `/go` pages that don't use a line break. Note: the "Read the Build/Scale/Operate Blog" and "Read the Recap" CTAs currently point to `/docs` as a placeholder — the real blog posts are still in progress and will be swapped in once published. ## Review instructions 1. Run `pnpm --filter www dev` and visit `http://localhost:3000/go/ask-supabase-select`. 2. Confirm the three announcement cards, the four solution cards (hover/click highlight, no button chrome), and the closing features CTA all render and link correctly. ## Checklist - [x] I have read CONTRIBUTING.md 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added the “Ask Supabase” landing page, with product resources, documentation links, team-solution cards, and a blog post marked as coming soon. * **Improvements** * Hero descriptions now preserve line breaks for clearer text presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
b10511052d |
fix(ui): share raised styling across dropdown triggers (#50830)
## Problem Select, combobox and empty multi-select triggers use a flat border treatment, while the default Button has a raised surface and shadow. This makes dropdown controls look inconsistent when closed. ## Solution Share the existing Button shadow variables and raised surface classes with the select trigger CVA. SelectTrigger and ComboboxTrigger keep their own layout, focus, and disabled behaviour. The multi-select shares the raised surface when empty and keeps a sunk field surface for selected chips. Static size classes keep its empty and single-row selected states at the same height; wrapped badges can still grow. The caret stays aligned as values are selected. Select, Combobox and Multi-select share Button's size-specific corner radii. Button's existing styling is preserved. | Before | After | | --- | --- | | <img width="518" height="180" alt="CleanShot 2026-09-24 at 13 36 32@2x" src="https://github.com/user-attachments/assets/3822e51f-b1c5-46a2-b268-0bf08a03ae06" /> | <img width="534" height="224" alt="CleanShot 2026-09-24 at 13 36 41@2x" src="https://github.com/user-attachments/assets/e553c973-3d21-4228-ae6f-d3c098d051d3" /> | | <img width="638" height="148" alt="CleanShot 2026-09-24 at 15 08 01@2x" src="https://github.com/user-attachments/assets/6d0c3dfe-3392-4b76-ae61-b6aa7a09583d" /> | <img width="658" height="148" alt="CleanShot 2026-09-24 at 15 08 17@2x" src="https://github.com/user-attachments/assets/184c50c3-b951-410e-89d5-3b1c2ee8f3b8" /> | | <img width="482" height="162" alt="CleanShot 2026-09-24 at 15 07 22@2x" src="https://github.com/user-attachments/assets/a088d832-d0a9-45c5-a272-9c84cc601d1d" /> | <img width="490" height="168" alt="CleanShot 2026-09-24 at 14 59 52@2x" src="https://github.com/user-attachments/assets/4df0ca29-53d8-4926-80db-1cafb705faad" /> | ## Review instructions 1. Open the design system [Select](https://design-system-git-dnywh-dropdown-trigger-surface-supabase.vercel.app/design-system/docs/components/select), [Combobox](https://design-system-git-dnywh-dropdown-trigger-surface-supabase.vercel.app/design-system/docs/components/combobox) and [Multi-select](https://design-system-git-dnywh-dropdown-trigger-surface-supabase.vercel.app/design-system/docs/fragments/multi-select) examples. 2. Compare the closed surfaces and corner radii with a default Button, then check hover, focus and open states. 3. Select one or two multi-select items. Check that a single row remains the same height as the empty control, the caret stays aligned and the chip field remains distinct. Add enough items to check wrapping. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary * **Style** * Default buttons display a raised surface with a subtle shadow and size-appropriate rounded corners. * Select and combobox triggers share a raised, card-like appearance, with consistent shadows and rounded corners at small sizes. Invalid select triggers display a border. * Empty multi-select controls use a raised surface, while controls with selected values use a field-style surface. * Small and tiny multi-select controls have updated spacing and sizing in empty and selected states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5e59b6047e |
chore(studio): extend Assistant response time and handle timeouts (#50892)
## Problem
- Assistant responses were capped at 120 seconds and 10 steps, which is
too short for longer reasoning or multi-step tool work.
- When the hosting platform ended a request at that limit, the
connection just dropped. The user got no explanation, and "Thinking…"
and tool rows kept spinning.
- Studio's own tools ignored the request's abort signal, so a stop,
disconnect or deadline couldn't cancel their in-flight requests.
- Aborted responses never closed their Braintrust span. Under TanStack
Start, the remote MCP client was only released on `res.on('close')`,
which the adapter never emits.
## Solution
Uses AI SDK options instead of custom stream handling:
- `maxDuration` goes to 300s and the step limit to 20. `streamText({
timeout: { totalMs } })` stops the response at 270s, leaving time to
finish the stream before the platform cutoff.
- `toUIMessageStream({ messageMetadata })` marks an aborted response
`timedOut: true`. `Chat` ignores `abort` chunks, so the client reads
this flag instead and shows a timeout alert with Retry. The flag is
saved with the message, so the alert survives a reload.
- `toUIMessageStream({ onEnd })` aborts the request whenever the stream
ends, releasing the MCP client on both runtimes. `streamText({ onAbort
})` ends the Braintrust span.
- Studio tools pass the SDK's `abortSignal` to their fetches. MCP tools
already did.
- Reasoning and server-tool rows that never finished show "Response
interrupted" instead of a spinner or "Ran X ✓".
There's no per-tool timeout. Approved SQL and migrations can
legitimately run longer, and aborting the HTTP request doesn't stop the
query in Postgres.
## Review instructions
1. Run the unit tests: `cd apps/studio && pnpm vitest run
lib/api/generate-v4.test.ts lib/ai components/ui/AIAssistantPanel`
2. To see a timeout without waiting 4.5 minutes, temporarily set
`ASSISTANT_TIMEOUT_MS` in `apps/studio/lib/ai/assistant-timeout.ts` to
`15_000` and run `pnpm dev:studio`.
3. Ask the Assistant something that needs several tool calls or long
reasoning, for example "Audit my schema for missing indexes and RLS
gaps, then write the fixes."
4. After 15 seconds, check that:
- the response stops and a "Assistant response timed out" alert appears
with Retry
- any in-progress reasoning or tool row shows "Response interrupted"
instead of spinning
- Retry starts a new response
- reloading the page still shows the alert on that chat
5. Stop a response with the Stop button before the deadline. It should
stop without the timeout alert.
6. With the default 270s, confirm that a normal response completes as
before.
## Checklist
Check all before review:
- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Improvements**
* AI assistant responses can now run for up to five minutes, supporting
longer requests.
* When a response times out, the assistant displays a message suggesting
you retry or ask for a smaller change.
* Incomplete responses now show a “Response interrupted” notice, and
loading indicators stop when generation ends.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
|
||
|
|
0eb08cb9f0 |
docs: prepare scoped personal access tokens docs for GA (#50839)
Scoped personal access tokens are leaving alpha. Remove the pre-GA framing and update pages that assumed every token carries full account access. - Personal Access Tokens guide: remove the public alpha / early access admonition. Add a section on using a scoped token with the Supabase CLI: the browser flow of `supabase login` creates a classic token, while SUPABASE_ACCESS_TOKEN or `supabase login --token` uses a scoped one, and commands that connect with the database password aren't limited by the token's permissions. - Management API introduction: replace "PATs carry the same privileges as your user account" with the scoped vs. classic distinction and link to the guide's permission tables. - MCP guide: the CI setup now asks for a scoped token limited to the connected project and links to the MCP tool permissions table. - API keys guide: replace the internal "fine-grained token" permission ID with the names shown in the dashboard (API Keys, Read), and note that `reveal=true` in the example also needs API Key Secrets (Read). - Managing environments: recommend a scoped token for the GitHub Actions deploy workflow. |
||
|
|
b03448ec59 |
docs(pipelines): improve Snowflake setup guidance (#50715)
## Problem The Snowflake guide leaves several setup details open to interpretation, particularly how roles are used and which RSA key content belongs in Snowflake versus the Dashboard. This PR is stacked on #50751 so the documented role location, private-key upload, and **Start pipeline** action match the updated creation sheet. The full stack starts with #50708, which moves the guide to its nested Pipelines path. ## Solution Clarifies the setup sequence, explains the default and optional role behaviour, distinguishes `rsa_key.pub` from `rsa_key.p8`, and makes the destination field guidance more direct. ## To test - [Snowflake guide](https://docs-git-dnywh-docsimprove-snowflake-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/snowflake) ## Review instructions 1. Read the setup path from **Prepare Snowflake resources** through **Configure Snowflake as a destination**. 2. Confirm the role guidance explains what happens when the Dashboard field is empty. 3. Confirm it is clear which key file is registered in Snowflake and which file is pasted or uploaded in the Dashboard. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the Snowflake guide with clearer setup steps and requirements for roles, ownership, key handling, account IDs, and Dashboard settings. * Expanded guidance on append-only history, current-state queries, dynamic-table freshness and costs, stream and task recovery, type serialization, and the effects of schema changes on historical data. * Renamed the pipeline setup button to **Start pipeline**. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fd0918833f |
feat(studio): refine pipeline creation copy (#50751)
## Problem The pipeline creation sheet uses generic examples, inconsistent destination terminology, and Advanced settings copy that does not explain what is being overridden. Its Docs button also sends most destinations to the general Pipelines guide. This PR is stacked on #50719 so the shared copy builds on the focused Snowflake field improvements. ## Solution Adds destination-specific pipeline-name examples and field descriptions, clarifies destination summaries and Advanced settings, uses human-readable ClickHouse engine names, shortens the primary action to **Start pipeline**, and links the Docs button to the selected destination guide. ## Review instructions 1. Open **[Database Replication](https://studio-staging-git-dnywh-studiorefine-pipeline-1eaf59-supabase.vercel.app/dashboard/project/_/database/replication)** and click **Add pipeline**. 2. Switch between destination types and confirm the pipeline-name example, destination summary, and field descriptions update appropriately. 3. Open **Advanced settings** and confirm the batch wait-time default is shown in the description while the input placeholder is `10000`. 4. Select each supported destination and confirm **Docs** opens its matching destination guide. 5. Select ClickHouse and confirm the engine choices read **ReplacingMergeTree** and **MergeTree**. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Clarified replication settings, destination field descriptions, and batch wait-time guidance. * Added destination-specific pipeline name placeholders and updated the labels for ClickHouse engine options. * Clarified ClickHouse password guidance for new destinations. * Updated new-pipeline buttons to say “Start pipeline” or “Start pipeline anyway.” * Added destination-specific documentation links for BigQuery, ClickHouse, DuckLake, and Snowflake. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9fb173e827 |
feat(studio): improve Snowflake destination setup (#50719)
## Problem Snowflake setup makes the public and private key files easy to confuse, treats the optional SQL role like a primary connection field, and requires users to paste private-key contents manually. Password managers can also mistake the Snowflake user field for a sign-in field. This PR is based on #50708 so its later Docs-button follow-up can use the nested destination-guide URLs. ## Solution Clarifies the Snowflake field copy and example values, moves **Role** into Advanced settings, opts the service-user field out of password-manager overlays, and adds drag-and-drop or button upload for P8 and PEM private-key files. Public key files are rejected without replacing the current field value. | Before | After | | --- | --- | | <img width="1280" height="1323" alt="Pipelines Database Agua Basket Supabase" src="https://github.com/user-attachments/assets/83d91b03-34f0-479f-ba65-ad9275b28431" /> | <img width="1280" height="1323" alt="Replication Database Agua Basket Supabase" src="https://github.com/user-attachments/assets/a722722c-d518-4c60-94b8-e79bab6de2ca" /> | ## Review instructions 1. Open **[Database > Replication](https://studio-staging-git-dnywh-studioimprove-snowflake-form-supabase.vercel.app/project/_/database/replication)**, click **Add pipeline**, and select **Snowflake**. 2. Confirm **Role** appears under **Advanced settings** and explains the default-role behaviour. 3. Upload or drop a valid P8 or PEM private key and confirm its contents appear in **Private key**. 4. Select a public key file and confirm the form rejects it without replacing the existing value. 5. Confirm 1Password (or Bitwarden etc) does _not_ add its widget to **User**. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added Snowflake private key upload via file picker or drag-and-drop. - Supports P8 and PEM private key files, with validation and clear error messages. - Added an optional Snowflake role field in Advanced Settings. - **Usability Improvements** - Preserves manual edits made while a private key file is processing. - Improved drag-and-drop feedback and updated field guidance and placeholders. - Prevents password managers from automatically filling Snowflake credentials. - Validates private keys when submitting the Snowflake destination form. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
9a03f3cd9c |
fix(studio): show keyboard focus on filter bar (#50827)
## Problem - Filter fields could not be re-entered with Tab, and remove buttons were previously skipped. - Earlier focus rings flashed or crowded controls. Segmented filters and design system examples also had uneven layout. ## Solution - Tab now reaches each filter’s property, operator, value and remove button. Editable fields use the caret; read-only values and remove buttons keep a visible focus cue. - Refined spacing and sizing. The segmented highlight is inset and clears when focus enters a control. Both variants and the focus guidance are documented on the [design system page](https://design-system-git-dnywh-fix-filter-bar-focus-supabase.vercel.app/design-system/docs/fragments/filter-bar). |After | | --- | | <img width="462" height="126" alt="CleanShot 2026-09-24 at 15 04 23@2x" src="https://github.com/user-attachments/assets/2ee8bee2-f4fa-40f4-ada5-67bfe32384e7" /> | | <img width="362" height="96" alt="CleanShot 2026-09-24 at 15 04 47@2x" src="https://github.com/user-attachments/assets/9f42054a-f432-493d-b417-f10892676c96" /> | ## Review instructions The easiest way to test this is to open Table Editor on both production/staging and on this PR’s [deploy preview](https://studio-staging-git-dnywh-fix-filter-bar-focus-supabase.vercel.app/). Try navigating by keyboard (tab, left/right arrow) within the Filter Bar. Compare the two. - In Studio’s Table Editor or the [design system example](https://design-system-git-dnywh-fix-filter-bar-focus-supabase.vercel.app/design-system/docs/fragments/filter-bar), add a filter. Tab through its property, operator, value and remove button, then Shift+Tab back into editing. - Check that the segmented and pill examples fill their preview width and that focus cues do not collide with neighbouring controls. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary * **New Features** * Added a pill appearance for the Filter Bar, with usage guidance and interactive examples for pill and segmented presentations. * **Accessibility** * Improved keyboard navigation through filter controls, including removing a filter with the keyboard. * Clarified that an editable text field’s insertion caret can serve as its visible focus indicator; read-only fields and controls without a caret still need another visible indicator. * **Style** * Refined Filter Bar spacing and focus styling across appearances. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
36371de151 |
docs: trim CONTRIBUTING to repo mechanics and point at the style guide (#50743)
Part 3 of 3. Stack: #50742 → #50744 → #50743. Review #50742 and #50744 first. Closes DOCS-1177 ## Problem `CONTRIBUTING.md` mixed how to write a page with how the repo is laid out. That's why it reached 568 lines, and why a contributor looking for either half reads past the other. #50742 gives the writing half its own home. ## Solution Trim `CONTRIBUTING.md` to repo mechanics, 568 lines down to 163. **Removed**, now in the style guide: general principles, information types, document types, components and elements, styling and grammar, word usage. **Kept**: the skills table, repo organization, guide and reference structure, content reuse, search. Content listings keeps its data file, ID rules, and test command here; the when-to-use-one part is in the style guide. **Added**: a table linking each style guide file. Wire the contributor-facing entry points at the guide: - `apps/docs/AGENTS.md` — gains a style guide section listing each file separately, so an agent can load one file without the others. This auto-loads for anything under `apps/docs`, making it the highest-leverage pointer in the repo. - Root `AGENTS.md` — claimed the skills are "the source of truth for conventions." For docs content style that's now the guide, with the skills as the process that applies it. - `.github/pull_request_template.md`, `.coderabbit.yaml`, `apps/docs/README.md`, `apps/docs/DEVELOPERS.md` — updated paths. Drop the `.prettierignore` exemption for `apps/docs/CONTRIBUTING.md`. It's short enough to format now, and a repo that publishes a style guide shouldn't exempt its own contributing doc. ## Notes for review Discoverability in a markdown-only guide is entirely these pointers, so they're the load-bearing part of this PR rather than cleanup. Both surviving anchor links into `CONTRIBUTING.md` target `#ai-agent-skills-for-docs-authoring`, which is kept. No dangling anchors. This PR sits last in the stack on purpose. It deletes the style sections that seven skill instructions referenced, so it has to land after #50744 rewires them. ## Manual testing 1. Open `apps/docs/CONTRIBUTING.md` and confirm every remaining section is repo mechanics, and the style guide table links resolve. 2. Confirm `apps/docs/AGENTS.md` names each style guide file, in size order: `WORD_LIST`, `01-voice-and-tone`, `02-elements`, `03-page-structure`. 3. Run `grep -rn "apps/docs/WORD_LIST" --include="*.md" --include="*.yaml" . | grep -v node_modules` and confirm only the intentional stub matches. 4. Run `npx prettier --config prettier.config.mjs --check apps/docs/CONTRIBUTING.md`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated contributor guidance to distinguish writing conventions from repository mechanics, with the style guide as the reference for documentation style. * Added style guide links and clarified when to use the writing and editing skills. * Revised the docs contribution guide with a style guide file list and steps for adding content listings. * Updated the pull request checklist to direct contributors to the documentation skills for style guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f5fcecf3d7 |
docs: point the authoring skills at the style guide (#50744)
Part 2 of 3. Stack: #50742 → #50744 → #50743. Review #50742 first. ## Problem Six skills restated style rules inline, so a rule could be corrected in the guide and stay wrong in a skill. `edit-the-docs` alone carried a second copy of the procedure format, the information-type classification rules, and the tables outline example. Two reference files said in their own text that they should be retired once a style guide existed. ## Solution Replace the restatements with pointers to the file that owns each rule. **Retired, as each file asked:** - `style-fallback.md` is deleted. It ended by telling an agent to follow the nearest comparable page, which launders whatever that page happens to do into a rule. The guide's References section replaces it. - `common-pitfalls.md` becomes a pointer, per the note at its own line 94. **Rewired**: `write-the-docs`, `edit-the-docs`, `review-the-docs`, `pm-the-docs`'s checklist, and `drafting-mechanics.md`. Skills cite a specific file rather than the directory, so one file can be loaded instead of the whole guide. `review-the-docs` gains a docs-tooling check for the inverse case: a style rule added to a skill belongs in the guide, with the skill pointing at it. ## Notes for review **`edit-the-docs`' PR 1 / PR 2 boundary is unchanged on purpose.** That split is by kind of diff — PR 1 is inline changes only, nothing moves a line — which is what makes each PR reviewable. The guide's files split by the size of the thing they govern, and the two cut across each other: choosing an admonition is an element decision but an inline diff, and chunking is a page-structure decision but currently applied in PR 1. Forcing them to match would stop PR 1 being a pure inline pass. Dropping the dash-aside rule from `write-the-docs` here lost it entirely, since it had no home in the guide. #50742 restores it in `01-voice-and-tone.md`. I audited the other four rules this PR removes from that checklist; only that one was lost. The skill's document-type list keeps `troubleshooting`, which CodeRabbit flagged as a fifth type not in the guide. The repo has 219 troubleshooting pages and a content-type gate that treats them as authorable, so the gap was in the guide. #50742 now lists five document types. ## Manual testing 1. Run `grep -rn "style-fallback\|apps/docs/WORD_LIST" .agents/skills/` and confirm no matches. 2. Open each rewired skill and confirm every style guide link resolves, including anchors such as `03-page-structure.md#chunking`. 3. Invoke `/edit-the-docs` and confirm it reads the guide rather than restating rules. 4. Run `npx prettier --config prettier.config.mjs --check ".agents/skills/*-the-docs/**/*.md"`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated documentation writing, editing, and review guidance to reference the dedicated style guide for voice, terminology, page structure, and content elements. * Clarified how to classify and organize sections, and expanded style-consistency checks. * Updated related checklists and references to distinguish style guidance from repository contribution instructions. * Consolidated common drafting advice into the style guide and updated the page-type table layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Stack order This PR moved above the `CONTRIBUTING.md` trim after review. The trim deletes the style sections that seven skill instructions still referenced, so trimming first left those references dangling until this PR landed. Rewiring the skills first removes that intermediate state: the skills point at the guide while `CONTRIBUTING.md` is still whole, and the trim then breaks nothing. --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
8fa75be01b |
docs: add a standalone style guide (#50742)
Part 1 of 3. Stack: #50742 → #50744 → #50743. ## Problem We have several problems: - Style guidance lives in lots of places and need consolidation - Our CONTRIBUTING guide has turned into one massive style document that needs to be broken up ## Solution Add `apps/docs/style-guide/` as plain markdown. | File | Covers | | --- | --- | | `README.md` | What the guide covers, who it's for, how to contribute, and the references it defers to | | `WORD_LIST.md` | Terminology, spelling, capitalization, and the `agent` / `LLM` / `AI` distinction. Moved from `apps/docs/` with history intact | | `01-voice-and-tone.md` | Audience, brevity, sentence construction | | `02-elements.md` | Which component renders each piece, and linking conventions | | `03-page-structure.md` | Document types, information types, grouping, chunking, timeless documentation | ### New content This guide is mostly rearrangement and glue, but it includes some new content: - Links and cross-reference formatting - WORD_LIST entries for LLM and AI agent - Timeless documentation guidance - Accessibility guidance - Sharper guidance on brevity and chunking ## Manual testing 1. Open `apps/docs/style-guide/` on this branch and confirm `README.md` renders below the file list. 2. Follow every link in `README.md` and read the document through. 3. You can test by locally pointing an agent at the style-guide and seeing that it makes great choices when revising a document. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a documentation style guide covering voice and tone, page structure, and guidance for writing procedures, code, tables, diagrams, media, and links. * Added a word list with preferred spelling, capitalization, and usage, including guidance on inclusive and concise language. * Added recommendations for reviewing documentation drafts and runnable examples. * Replaced the existing word list page’s content with a link to its new location in the style guide. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
db2242e223 | fix(o11y): add connections to footer (#50928) | ||
|
|
d5cda0c6ef |
chore(www): update quote attribution in Gemini Enterprise blog post (#50929)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update (blog post) ## What is the current behavior? The Google Cloud quote in the "Supabase is now available in Gemini Enterprise" blog post is attributed to Rayn Veerubhotla. ## What is the new behavior? The quote is now attributed to Ritika Suri, Managing Director, AI and Data Partnerships at Google Cloud. The quote text itself is unchanged. ## Additional context Attribution updated per the latest version of the internal launch doc. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the Google Cloud partnership quote attribution. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c6b92060d2 |
docs(realtime): realtime permissions (#50735)
All changes are related to Realtime permissions that I observed on support tickets recently: - Migrations can't have `ALTER TABLE realtime.messages`. That's is not allowed and breaks migrations. - Missing realtime.messages partitions are usually due to lack of connections - Errors like "must be owner of table messages" are misleading Closes REAL-1125 ## Additional context https://supabase.slack.com/archives/C01G8CC0X9D/p1789981286693829 and SU-479680 ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified Realtime authorization restrictions, supported RLS policy management, and the existing RLS configuration for `realtime.messages`. * Documented broadcast partition creation, connection requirements, and warning behavior when partitions are unavailable. * Added troubleshooting guidance for ownership errors, including migration rollback implications and supported remedies. * Added instructions for inspecting message partitions and diagnosing missing, expired, or unavailable partition configurations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a21111b7e0 |
docs: Clarify private flag for broadcast from database (#50192)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Doc update ## What is the current behavior? The description of the private flag for broadcast from database functions is inconsistent and a bit confusing. ## What is the new behavior? Use the same language on both examples and clarify the default, and what true and false map to. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Clarified the meaning of boolean privacy flags in realtime SQL examples: `true` indicates Private (the default), while `false` indicates Public. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |