Commit Graph
34977 Commits
Author SHA1 Message Date
Saxon Fletcher ad5e2f605d ordering env 2026-03-16 11:48:41 +10:00
Saxon Fletcher b085c6350f checks 2026-03-16 11:43:29 +10:00
Saxon Fletcher 594882d89c remove old pages 2026-03-16 11:38:12 +10:00
Saxon Fletcher 7c243afd17 self hosted fixes 2026-03-16 11:10:13 +10:00
Saxon Fletcher cab2639a54 all the things 2026-03-13 20:56:40 +10:00
Saxon Fletcher 72644c7ebd switch to project meta 2026-03-13 13:26:36 +10:00
Saxon Fletcher 59b6551e10 project meta 2026-03-12 20:16:38 +10:00
Sean Oliver 3570abad4d chore: update posthog-js to 1.357.0 (#43574)
PostHog flagged our SDK as outdated — we were on 1.257.2, latest is
1.357.0.

**Changes**
- Bumped `posthog-js` in `packages/common/package.json` from `^1.257.2`
to `^1.333.0` (resolved to 1.357.0)
- Updated lockfile

**Why is the lockfile diff so large?**
posthog-js added several new dependencies between 1.257.2 and 1.357.0: a
full `@opentelemetry/*` stack (for opt-in log exporting),
`@posthog/core` and `@posthog/types` (internal monorepo split),
`dompurify`, and `query-selector-shadow-dom`. None of these affect our
bundle unless explicitly enabled — they're opt-in features. The lockfile
entries are large because pnpm records each package with its full
resolution tree and checksums.

**Testing**
Spun up the full local stack and verified all three PostHog endpoints
return 200 with the new SDK version:
- `/e/` (event capture) — pageviews firing correctly
- `/flags/` (feature flag evaluation) — flags loading correctly
- `/i/v0/e/` (identify) — user identification working

No breaking changes in any of the 16 releases between our old and new
version (all Minor/Patch Changes). TypeScript compilation clean across
all apps.

GROWTH-589
2026-03-09 15:14:36 -07:00
Charis 8732fc3bd9 fix: add multi-object download signing for storage (#43576)
Bug fix

## What is the current behavior?

Read-only users cannot download files because the download feature
requires minting a temporary API key, which is properly blocked for
read-only users.

## What is the new behavior?

Instead of using temporary API keys, we now create signed URLs for the
files to be downloaded. We batch-create signed URLs for an entire
folder's worth of files, requiring only a single management API call,
then use those signed URLs to download the files. This allows read-only
users to download files without needing elevated permissions.

## Additional context

Resolves FE-2737
2026-03-09 16:49:59 -04:00
Ali Waseem f7d3d2d3c3 feat: filter by value for simple types on new filter experience (#43579)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Added filter by value for the new feature bar experience
- Will follow up with an E2E test later
2026-03-09 14:48:59 -06:00
Sean Oliver 8ebbad3a5b feat(growth): expand www middleware to /dashboard and /docs (Phase 1 - instrumentation only) (#43413)
## Problem

The `_sb_first_referrer` cookie isn't working. The www middleware
matcher explicitly excludes `/dashboard` and `/docs`, so the cookie
never gets stamped for Studio or Docs traffic. PostHog confirmed: only 1
event with `first_referrer_cookie_present=true` out of ~46.5M Studio
pageviews in the last 7 days.

## Background: what the matcher does

In Next.js, the `matcher` config controls which incoming requests the
middleware function even runs on. If a path doesn't match, the
middleware is skipped entirely — the request passes through untouched.
If it matches, the middleware runs and can mutate the response (set
cookies, headers, etc.).

This matters because Studio's SPA navigation works via silent
`/_next/data/` JSON fetches. If middleware runs on those requests and
returns `NextResponse.next()` with any mutations, it breaks those
fetches and causes full page reloads instead of client-side transitions.

## What we tried before

| PR | www runs on `/dashboard`? | Studio `proxy.ts` runs on all routes?
| Result |
|---|---|---|---|
| **#42768** (Attempt 1) | ✅ Yes — and also intercepts `_next/data` | ✅
Yes — `matcher` config removed, stamps cookie everywhere | Full page
reloads in Studio |
| **#43129** (Full revert) | ❌ No — www middleware deleted entirely | ❌
No — restored to `matcher: '/api/*'` only | Back to baseline, no cookie
stamping anywhere |
| **#43153** (Attempt 2) | ❌ No — `/dashboard` explicitly excluded | ✅
Yes — `matcher` config removed again, stamps cookie everywhere | Full
page reloads in Studio again |
| **#43189** (Attempt 3) | ❌ No — same as #43153 | ✅ Yes — `matcher`
config still removed, cookie stamping made conditional | Still broken |
| **#43190** (Ivan's fix) | ❌ No — `/dashboard` still excluded | ❌ No —
restored to `matcher: '/api/*'` only | Works — but cookie never stamps
for `/dashboard` traffic |
| **#43413** (this PR) | ✅ Yes — sets diagnostic cookie only, no
attribution stamping yet | ❌ No — unchanged, still `matcher: '/api/*'`
only | ❓ Untested in prod |

The common factor in every failure: Studio's `proxy.ts` ran on all
routes (including `_next/data` requests), which broke SPA navigation.
This PR is the first one that runs www middleware on `/dashboard` while
Studio's `proxy.ts` stays in its original narrow `/api/*` scope.

## What changed

This is Phase 1 of a two-phase rollout. We remove `dashboard|docs` from
the matcher's negative lookahead so www middleware runs on those paths —
but instead of stamping cookies, we set a short-lived (60s) diagnostic
cookie `_sb_mw_diag` on `/dashboard` and `/docs` requests.

The diagnostic cookie encodes
`hit=1&would_stamp={0|1}&has_cookie={0|1}`, which Studio telemetry reads
on the initial pageview and reports to PostHog as `mw_diag_hit`,
`mw_diag_would_stamp`, and `mw_diag_has_existing_cookie` properties.

A cookie rather than a header because response headers aren't readable
by JS. It also tests the actual Set-Cookie mutation path that Phase 2
will use (which is what Next.js issue #41885 is specifically about).

Phase 1 answers two key questions before we commit to Phase 2:
1. Does expanding the matcher break Studio SPA navigation?
2. What % of /dashboard arrivals would get a first-referrer cookie
stamped in Phase 2?

## Phase 2 readiness criteria

**Important caveat**: `mw_diag_*` data reflects consented users only and
may under-represent first-visit anonymous traffic. The Phase 2 decision
should account for this — the actual middleware execution rate is likely
higher than what PostHog reports.

### PostHog query spec

**Middleware execution rate**: Of all Studio initial pageviews on
`/dashboard` or `/docs` paths, what percentage have `mw_diag_hit =
true`? Expected: >= 90%. Below 70% warrants investigation (could
indicate edge caching bypassing middleware, or a matcher configuration
issue).

```
Filter: event = "$pageview" AND (current_url contains "/dashboard" OR current_url contains "/docs")
Breakdown: mw_diag_hit (true vs null/missing)
Metric:    count(mw_diag_hit = true) / count(all) * 100
```

**Would-stamp rate**: Of events with `mw_diag_hit = true`, what
percentage have `mw_diag_would_stamp = true`? This tells us what
percentage of Phase 2 traffic would actually get a cookie stamped. No
hard threshold — unexpected values (< 5% or > 95%) suggest a logic bug
worth investigating before Phase 2.

```
Filter: event = "$pageview" AND mw_diag_hit = true
Breakdown: mw_diag_would_stamp (true vs false)
Metric:    count(mw_diag_would_stamp = true) / count(all) * 100
```

**Existing cookie rate**: Of events with `mw_diag_hit = true`, what
percentage have `mw_diag_has_existing_cookie = true`? This tells us how
many users already have the cookie from a prior www visit.

```
Filter: event = "$pageview" AND mw_diag_hit = true
Breakdown: mw_diag_has_existing_cookie (true vs false)
Metric:    count(mw_diag_has_existing_cookie = true) / count(all) * 100
```

### Go / no-go threshold table

| Signal | Go | Investigate | No-Go |
|---|---|---|---|
| `mw_diag_hit` rate (% of /dashboard+/docs pageviews) | >= 90% | 70-90%
| < 70% |
| SPA navigation errors (Sentry / Vercel logs) | No increase | < 0.1%
increase | > 0.5% increase |
| Middleware p99 latency (Vercel function logs) | < 50ms added |
50-100ms | > 100ms |
| Sample volume in first 24h | > 1,000 events | 100-1,000 (extend
window) | < 100 (insufficient data) |

## Changes

- `apps/www/middleware.ts`: Removed `dashboard|docs` from matcher; added
`isDashboardOrDocs` guard that sets `_sb_mw_diag` diagnostic cookie
instead of stamping attribution
- `apps/www/middleware.test.ts`: 12 tests covering cookie stamping on
www paths, diagnostic cookie encoding for all scenarios (external
referrer, direct nav, internal referrer, existing cookie)
- `packages/common/first-referrer-cookie.ts`: Exported
`MW_DIAG_COOKIE_NAME`, `MwDiagData` type, and `parseMwDiagCookie()`
helper
- `packages/common/telemetry.tsx`: Reads `_sb_mw_diag` on initial Studio
pageview; reports `mw_diag_*` properties to PostHog

## Testing

Unit tests pass (13/13 www, 31/31 first-referrer-cookie). Production
validation needed:

- [ ] Studio SPA navigation works (tab changes, SQL editor, no full page
reloads)
- [ ] PostHog shows `mw_diag_hit = true` on Studio initial pageviews
- [ ] `mw_diag_would_stamp` distribution looks reasonable before
enabling Phase 2
- [ ] Monitor 24h before Phase 2

Ref: GROWTH-625 / GROWTH-668
2026-03-09 11:47:20 -07:00
Jordi Enric e854f3e9e7 FE-2736 chore: optimize world map json (#43550)
- reduce file size to 709K from 4.9MB 
- add antartica back
- everything else stays the same
2026-03-09 19:32:42 +01:00
kemal.earth 6695a9eeb0 feat(shared-data): add error codes to shared data (#43458)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This is something we've discussed for a while. A shared place for error
codes and their mappings, descriptors etc. Available for all projects in
the monorepo.
2026-03-09 17:42:38 +00:00
kemal.earthandClaude Sonnet 4.6 9b028f6fd5 feat(studio): map error codes to docs (#43140)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This introduces a small snippet preview of the error code coming via our
content API for the docs. This appears in a couple of places right now.

- **Auth Overview** - This page isn't fully released yet, but it appears
on the error codes table (as depicted below).
- **Logs** - When you delve into the logs panel, if there's an error
code available, they're also wrapped in this popover.

We are also working on a shared-data package (#43458) to potentially
replace this endpoint internally. Also introduces a multifaceted button
to debug/fix with either Assistant or LLM of choice.

| Auth Overview | Logs Panel |
|--------|--------|
| <img width="407" height="287" alt="Screenshot 2026-03-09 at 14 14 09"
src="https://github.com/user-attachments/assets/7450dddb-6828-4cd3-802d-37d47ba1b440"
/> | <img width="394" height="216" alt="Screenshot 2026-03-09 at 14 13
56"
src="https://github.com/user-attachments/assets/80c2a46e-dbe4-4e88-a0a7-68b977a71d6b"
/> |

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-09 17:33:14 +00:00
Matt Rossman 517171b246 feat(assistant): online evals support and CI workflows (#43194)
Lays groundwork for online evals on Assistant chat logs.

https://www.braintrust.dev/docs/observe/score-online

### Changes

- New workflows:
- `braintrust-scorers-deploy.yml` keeps prod scorers in sync on push to
`master`
- `braintrust-preview-scorers-deploy.yml` deploys preview scorers to the
staging project for PRs labeled `preview-scorers`, posting a comment
with scorer links
([example](https://github.com/supabase/supabase/pull/43194#issuecomment-4000097222))
- `braintrust-preview-scorers-cleanup.yml` deletes preview scorers when
the PR is closed
([example](https://github.com/supabase/supabase/pull/43194#issuecomment-4000749847))
- Adds `evals/scorer-online.ts` entry point invoked with `pnpm
scorers:deploy`, registering scorers for online evals in the Braintrust
"Assistant" project
- Refactors scorer code to separate online-compatible scorers
(`scorer-online.ts`) from WASM-dependent ones (`scorer-wasm.ts`)
- "URL Validity" scorer now only checks Supabase domains to prevent
requests to untrusted origins
- Span `input` is now shaped `{ prompt: string }` instead of plain
`string` for compatibility with offline eval scorers
- Env vars `BRAINTRUST_STAGING_PROJECT_ID` and `BRAINTRUST_PROJECT_ID`
configured in GitHub repo settings
- `generateAssistantResponse` now uses `startSpan` + `withCurrent`
instead of `traced()` to manually manage the root span lifecycle — this
ensures `onFinish` logs output to the span _before_ `span.end()` is
called, which is when Braintrust triggers scoring automations

### Online Scorers

We share scoring logic across offline and online evals, but some of our
scorers aren't transferrable to an "online" setting due to runtime
challenges or ground truth requirements.

**Supported**
- Goal Completion
- Conciseness
- Completeness
- Docs Faithfulness
- URL Validity

**Unsupported**
- Correctness (requires ground truth output)
- Tool Usage (requires ground truth requiredTools)
- SQL Syntax (uses libpg-query WASM)
- SQL Identifier Quoting (uses libpg-query WASM)
 
### How to use these scorers

Going forward if you want to add/edit online eval scorers, add the
`preview-scorers` label to a PR. This deploys scorers to the [Assistant
(Staging
Scorers)](https://www.braintrust.dev/app/supabase.io/p/Assistant%20(Staging%20Scorers)?v=Overview)
project in Braintrust with branch-specific slugs, and comments on the PR
([example](https://github.com/supabase/supabase/pull/43194#issuecomment-4000097222)).
From the Braintrust dashboard you can "Test" the scorer with traces from
any project.

<img width="1866" height="528" alt="CleanShot 2026-03-05 at 15 15 00@2x"
src="https://github.com/user-attachments/assets/4f15cebc-3f2d-4e8a-9ee2-fe8ef7bf4199"
/>

Once merged, scorers are deployed to the primary
[Assistant](https://www.braintrust.dev/app/supabase.io/p/Assistant)
project, and preview scorers are deleted from the staging project. Down
the road, scorers on the Assistant project will run automatically on a
sample of production traces.

Closes AI-437
2026-03-09 13:05:26 -04:00
Gildas Garcia 950c26dcb0 chore - make database e2e tests run in parallel and more stable (#43569)
## Problem

- database e2e tests run in serial mode, which is slower
- they also are a bit flaky

## Solution

- Ensure they can run in parallel
- Make them more stable by using UI checks when waiting
- Use assertions that automatically wait/retry in playwright
2026-03-09 16:45:16 +00:00
Gildas Garcia bab4e8db65 chore - allow cron jobs e2e tests to run in parallel and make them stable (#43566)
Follow up of #43547 and #43560

## Problem

The cron job tests run in serial mode and can be flaky.

## Solution

- Use simple query to install the `pg_cron` extension (way faster than
using UI)
- Make sure all tests can run in parallel
2026-03-09 17:29:24 +01:00
Sean Oliver 0aa23980bb remove tableCreateGeneratePolicies experiment (failed variant) (#43498)
## Problem

The `tableCreateGeneratePolicies` A/B experiment tested an AI-assisted
policy generator (`RLSManagement`) as a variation in the table creation
side panel. The variation didn't pass — control wins, so the standard
RLS checkbox should be the permanent behavior.

## Changes

- Deleted `useTableCreateGeneratePolicies` hook (PostHog flag + exposure
tracking)
- Deleted the entire `RLSManagement/` component directory (variation UI
— `RLSManagement`, `PolicyList`, `PolicyListEmptyState`,
`ToggleRLSButton`)
- Removed experiment flag checks from `TableEditor.tsx` — RLS checkbox
is now always rendered (was already the control)
- Removed experiment conversion tracking from `SidePanelEditor.tsx`

## Testing

Verified `pnpm typecheck` passes clean. Table creation side panel
renders the RLS checkbox unconditionally as it did in the control.

GROWTH-653
2026-03-09 09:23:50 -07:00
Sean Oliver 96f776fc63 graduate auto-RLS project creation experiment (test variant wins) (#43499)
## Problem

The `projectCreationEnableRlsEventTrigger` A/B experiment tested showing
an opt-in "Enable automatic RLS" checkbox in the project creation flow,
which sets up a Postgres event trigger to auto-enable RLS on every new
table in the public schema. The test variant passed with a +3.3pp lift.

## Changes

- `SecurityOptions.tsx` — removed PostHog flag check, checkbox is now
always rendered
- `pages/new/[slug].tsx` — removed experiment flag reads, exposure
tracking (`useTrackExperimentExposure`), and the conditional
`rlsOptionVariant` telemetry property

The underlying feature logic (`enableRlsEventTrigger` form field,
`AUTO_ENABLE_RLS_EVENT_TRIGGER_SQL`, submission handling) is unchanged —
we're just removing the scaffolding that was gating it.

## Testing

Verified `pnpm typecheck` passes clean. The "Enable automatic RLS"
checkbox now shows unconditionally in the Security Options section of
project creation.

GROWTH-653
2026-03-09 09:22:23 -07:00
Danny White 18bee64d98 www(chore): remove State of Startups flag (#43423)
## What kind of change does this PR introduce?

Remove feature flag.

## What is the current behavior?

The [State of Startups](https://supabase.com/state-of-startups) page
instantly redirects to the homepage rather than staying put.

## What is the new behavior?

The [State of Startups](https://supabase.com/state-of-startups) page
rightfully loads.

## Additional context

Some sort of race condition with the `useFlag`. Simpler to just remove
the flag logic entirely and keep the page permanently on.
2026-03-09 12:13:11 -04:00
Gildas Garcia d004d13e3f chore - stabilize and make e2e tests faster - part 2 (#43560)
## Problem

- Some tests don't always cleanup after themselves or don't do it
consistently which make it hard to work on them locally
- Some test suites don't allow parallel execution of their tests
- Some tests are flaky

This a follow up of #43547
2026-03-09 16:10:28 +01:00
Monica Khoury 7b8bec544e Fix spacing and schema prefix inconsistency in Table Editor (#43524)
Fixes this [Linear
issue](https://linear.app/supabase/issue/FE-2732/table-editor-header-spacing-and-schema-prefix-inconsistency.).

# Before

<img width="320" height="200" alt="image"
src="https://github.com/user-attachments/assets/45dc3a08-50df-4a03-b7ee-1b107c60059e"
/>
<img width="320" height="150" alt="image"
src="https://github.com/user-attachments/assets/c5cca6d5-a294-4137-8cf6-20e56678ebe6"
/>
<img width="320" height="150" alt="image"
src="https://github.com/user-attachments/assets/be54093b-8ff0-4c71-9934-574baac13039"
/>


# After

<img width="320" height="150" alt="CleanShot 2026-03-08 at 13 05 48@2x"
src="https://github.com/user-attachments/assets/4ed9817d-5ae7-45c2-9da7-6d1aec023975"
/>
<img width="320" height="150" alt="CleanShot 2026-03-08 at 13 06 06@2x"
src="https://github.com/user-attachments/assets/7ae0920e-0b5b-4eb3-993c-180d51ffd942"
/>
2026-03-09 08:40:55 -06:00
supabase-supabase-autofixer[bot]andgithub-actions[bot] 4d37a5f44d [bot] Decrease ESLint ratchet baselines (#43521)
Automated weekly decrease of ESLint ratchet baselines.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-03-09 08:40:22 -06:00
Gildas Garcia 13bfc4502a chore: e2e general improvements (#43547)
## Problem

e2e tests are still flaky and not as fast as they could be

## Solution

- [x] Reset supabase instance: this makes the database visualiser tests
faster as there are less tables to screenshot
- [x] Improve the single file setup utilities so that they never block
local tests by cleaning them up before starting
- [x] Disable animations while running the tests (less time waiting for
animations to complete
- [x] Add utility functions that help reproducing flaky tests locally
2026-03-09 15:38:06 +01:00
Ivan Vasilov b4b4532065 fix: Update dev script port to 3004 for ui-library (#43555)
Revert the port for the `dev` command in `ui-library`.
2026-03-09 14:20:37 +00:00
supabase-supabase-autofixer[bot]andsupabase-releaser[bot] 5e3e6f3f47 feat: update @supabase/*-js libraries to v2.99.0 (#43552)
This PR updates @supabase/*-js libraries to version 2.99.0.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.99.0
- Updated @supabase/auth-js to 2.99.0
- Updated @supabase/realtime-js to 2.99.0
- Updated @supabase/postgest-js to 2.99.0
- Refreshed pnpm-lock.yaml

This PR was created automatically.

Co-authored-by: supabase-releaser[bot] <223506987+supabase-releaser[bot]@users.noreply.github.com>
2026-03-09 16:01:09 +02:00
supabase-supabase-autofixer[bot]andsupabase-releaser[bot] 2a30411dc2 docs: update js sdk docs (2.99.0) (#43553)
Updates JS sdk documentation following stable release. 
Ran `make` in apps/docs/spec to regenerate tsdoc files.

**Details:**
- **Version:** `2.99.0`
- **Source:** `supabase-js-stable-release`
- **Changes:** Regenerated tsdoc files from latest spec files

🤖 Auto-generated from @supabase/supabase-js stable release.

Co-authored-by: supabase-releaser[bot] <223506987+supabase-releaser[bot]@users.noreply.github.com>
2026-03-09 16:01:02 +02:00
Ivan Vasilov 98c0cea1c3 feat: Add TDB block (#43490) 2026-03-09 14:32:44 +01:00
Jeremias Menichelli ac41f6bd6f chore: Remove unused ShowUntil (#43546) 2026-03-09 13:30:19 +01:00
TheOtherBrian1 3885265c0c docs: Update realtimeErrorCodes.toml | fixed typo (#43493)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

doc update

## What is the current behavior?

Error description states that realtime breaks when a message is JSON
parsable. Should state when it is "not" JSON parsable

## What is the new behavior?

Added not key word to description:

```
Payload sent in NOTIFY operation was "NOT" JSON parsable.
```
2026-03-09 10:30:49 +01:00
Raminder Singh 5aafe30cd1 docs: fix a typo (#43509) 2026-03-09 10:29:52 +01:00
Kamil Ogórek 10b4fb2a3d fix(api): Use correct explainer for x-ratelimit-reset header (#43527)
ref: https://github.com/supabase/platform/pull/30380
2026-03-09 10:29:17 +01:00
Chris Chinchilla c20cfe832a docs: Update getSession usage in Angluar ionic tutorial (#43489)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
2026-03-09 10:26:54 +01:00
Chris Chinchilla 579357089b docs: Update auth-helpers usage from examples (#43345)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
2026-03-09 10:26:16 +01:00
Danny White 96ac1c2652 feat(studio): page titles (core) (#43538)
## What kind of change does this PR introduce?

- Resolves FE-1960
- Resolves FE-1983
- Resolves DEPR-207

## What is the current behavior?

Page titles between surfaces are inconsistent and vague. Sometimes they
say the product name:

```
My Project | My Org | Supabase
```

...even when on a specific surface like Database > Tables.

Other times they show the entity name but skip over the project or org
name :

```
Edge Functions | Supabase
```

## What is the new behavior?

Page titles *mostly* (see below) follow the same format:
```
users | Table Editor | My Project | My Org | Supabase
hello-world | Logs | Edge Functions | My Project | My Org | Supabase
Backups | Database | My Project | My Org | Supabase
Authentication | My Project | My Org | Supabase
```

That format is:

entity, section, surface, project, org, brand

## Additional context

This is stacked PR 1/5 for page title improvements. Includes the core
title utility and ProjectLayout integration/tests. Follow-up stacked PRs
are based on this branch:

- https://github.com/supabase/supabase/pull/43534
- https://github.com/supabase/supabase/pull/43535
- https://github.com/supabase/supabase/pull/43536
- https://github.com/supabase/supabase/pull/43537

This one should be merged first. The others (listed right above) can
_then_ be merged in any order.
2026-03-09 15:25:05 +07:00
Akash MandJoshen Lim 8a4d2e17fc fix: trim leading/trailing whitespaces from SMTP settings input fields (#43530)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Currently, the SMTP Host input field in the Project Dashboard
(Authentication > Email > SMTP Settings) does not sanitize whitespace.
If a user accidentally pastes a hostname with leading or trailing spaces
(e.g., " smtp.resend.com "), the DNS lookup fails during the OTP
delivery process.

This results in the following error in the Auth logs:

```"dial tcp: lookup smtp.resend.com on 127.0.0.53:53: server misbehaving"```

Noticed, the other input fields of Sender details and Host, Username and Password under SMTP Provider settings take leading and trailing whitespaces as well.

## What is the new behavior?

Input sanitization has been applied across the SMTP configuration schema. The following fields now utilize .trim() to ensure data integrity:

- SMTP_HOST
- SMTP_ADMIN_EMAIL & SMTP_SENDER_NAME
- SMTP_USER
- SMTP_PASS

## Screenshots:

Before Fix:

<img width="604" height="198" alt="Screenshot 2026-03-09 at 2 04 49 AM" src="https://github.com/user-attachments/assets/76ae23a6-3ad8-4f82-8f0f-ab12f4168e81" />

After Fix:

<img width="594" height="194" alt="Screenshot 2026-03-09 at 1 58 48 AM" src="https://github.com/user-attachments/assets/03f64294-0bfe-4fca-a82b-12ee07a6d218" />



This fixes the issue #43529

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-03-09 15:24:49 +07:00
Danny White ff8fb72ce6 fix(studio): wrap project actions (#43532)
## What kind of change does this PR introduce?

- UI fix

## What is the current behavior?

- The _New project_ button overflows to the right on smaller
(phone-sized) breakpoints
- Due to addition of _Sort by_ dropdown last week

## What is the new behavior?

- All actions now wrap on smaller breakpoint

| Before | After |
| --- | --- |
| <img width="393" height="852"
alt="Supabase-383C523F-0BF1-48CD-8052-F6D68301DA4E"
src="https://github.com/user-attachments/assets/3983a815-16ff-48cd-857f-b84b82bfc923"
/> | <img width="393" height="852"
alt="Supabase-ED7AD923-E837-4D48-B7D1-6DA3C6E45BFA"
src="https://github.com/user-attachments/assets/fe19f9cc-f832-4c5d-b412-0aa1a0c16d5b"
/> |
2026-03-09 15:02:44 +07:00
Joshen Lim 9b0dc8d9b9 Chore/fix storage explorer when switching buckets (#43541)
## Context

Taking a slightly different approach to [this
PR](https://github.com/supabase/supabase/pull/43370)

Original problem was that if you opened some folders while in a bucket
and then switched to a different bucket, the folder UI will persists
(folders from Bucket A will render when landing on Bucket B)

## Changes involved
- Shift `StorageExplorerStateContextProvider` into `[bucketId].tsx]`
instead of `ProjectContext`
- The valtio store here only applies for the storage explorer so having
it so high in the project's context was unnecessary
- This also just implies that the valtio store will automatically reset
whenever the bucket changes
- Simplify storage explorer valtio store by initializing the store with
the bucket
- We'll initialize the selected bucket with the store now (Same as
previous PR)
- Removes unnecessary `setSelectedBucket` method which required a
separate `useEffect` in `StorageExplorer.tsx`

## To test
- [ ] Verify that the original is resolved
- [ ] General smoke test of the storage explorer - i've also re-added
the e2e test that Gildas wrote up in his PR
2026-03-09 14:32:34 +07:00
Joshen Lim 4a173eea60 Revert "fix: storage view is not reset when switching buckets" (#43539)
Reverts supabase/supabase#43370
2026-03-09 11:17:43 +07:00
Danny White ed46a5ab3f chore(studio): refocus editor after Run button tap (#43476)
## What kind of change does this PR introduce?

Resolves FDBK-40065

## What is the current behavior?

Using the _Run_ button on either inline or “full” SQL Editor removes
focus from the Monaco editor.

## What is the new behavior?

The text caret remains in the Monaco editor even after button press.

## To test

Try running a few queries both with keyboard (⌘ enter) and mouse click
on the _Run_ button:

```sql
-- 1) Create a mock table + seed data
drop table if exists public.test;

create table public.test (
  id bigserial primary key,
  name text not null,
  created_at timestamptz not null default now()
);

insert into public.test (name)
values
  ('alpha'),
  ('beta'),
  ('gamma'),
  ('delta');

select * from public.test order by id;
```

```sql
-- 2) Deletion query that should trigger the warning modal (destructive op)
delete from public.test where id <= 2;

-- Verify remaining rows
select * from public.test order by id;
```

## Additional context

- [ ] This was FDBK-40065 that we should reply to
2026-03-09 10:27:31 +11:00
Danny White ed8ac5bb90 chore(design-system): preserve icon fill or stroke (#43417)
## What kind of change does this PR introduce?

Bug fix: custom icons now respect their source SVG’s stroke/fill and
stroke-width instead of always getting a global stroke.

## What is the current behavior?

Every custom icon gets `stroke="currentColor"` and `strokeWidth={2}`
from `createSupabaseIcon`, so fill-only logos get an extra stroke and
icons designed at `stroke-width="1"` (e.g. postgres, auth) render too
thick. Call sites and the design-system grid needed workarounds
(`strokeWidth={0}`, `FILL_ONLY_ICONS`, `STROKE_WIDTH_FROM_SOURCE`).

## What is the new behavior?

The icon build reads root SVG attributes (`fill`, `stroke`,
`stroke-width`, etc.) and passes them as per-icon defaults. Fill-only
icons (chatgpt, claude, axiom, last9) have `stroke="none"` in source and
render with no stroke; stroke icons keep their source stroke-width (e.g.
postgres at 1). No `strokeWidth={0}` or allowlists needed at call sites
or in the icon grid.

| Before | After |
| --- | --- |
| <img width="1826" height="552" alt="CleanShot 2026-03-05 at 10 53
31@2x-3D63CEF0-1132-44F5-A382-730346432F1E"
src="https://github.com/user-attachments/assets/9caf73fa-351b-4ea2-a420-b3339f934742"
/> | <img width="1814" height="552" alt="CleanShot 2026-03-05 at 10 53
40@2x-514FC8BD-D30F-4D23-B209-0ECD6D13A184"
src="https://github.com/user-attachments/assets/936ea5a5-dae0-413f-8545-b90a502cea69"
/> |

## Additional context

- Added `stroke="none"` to the four fill-only source SVGs;
sentry/grafana/otlp/datadog already had `stroke-width="0"`.
- `createSupabaseIcon` only applies `color`/`strokeWidth` when the
consumer passes them, so `svgDefaults` from the build are used
otherwise.
- Removed workarounds from `icons.tsx` and GuidesSidebar; updated
icons.mdx (defaults + fill-only guidance).
2026-03-09 10:26:59 +11:00
Ali Waseem 819a9c0fc8 fix: added not found as errors when filter is active (#43497)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

fix: small issue when a filter was active and does not found error
popped up, we didn't allow users to reset the value. This handles the
edge cases where a filter is applied and the column is deleted
2026-03-08 13:43:28 -04:00
Charis 14b2af415f fix: accept inconsistent casing in incident regions (#43492)
Bug fix

## What is the current behavior?

The `affected_regions` generated by the AI sometimes have inconsistent
casing, causing validation to fail.

## What is the new behavior?

The system now accepts `affected_regions` that match case-insensitively,
allowing for variations in casing.
2026-03-06 19:02:06 +00:00
Marouane SoudaandAli Waseem efa40ea0e4 fix(studio): contrast ratio of JSON cell viewer colors in light mode (#40691)
JSON column viewer looks fine on dark mode, but barely visible on light
mode, especially when the value is of string type.

There are no colors that can satisfy the 4.5:1 contrast ratio (minimum
requirement for web and digital accessibility) on both white and black
background, so I had to pick different classes for ight mode (dark mode
is fine, I checked the colors against the dark background and the
contrast is good).

Even though the new colors may not look that contrasting to each other,
I prioritized accessibility, and made sure they all complied with the
4.5:1 contrast ratio.

Before:
<img width="499" height="179" alt="112"
src="https://github.com/user-attachments/assets/7f0821cf-6127-4246-a2c2-a78a5d31083a"
/>

After:
<img width="499" height="211" alt="222"
src="https://github.com/user-attachments/assets/0b5b2c35-9211-4a25-a9f5-eef4e5c8c8f3"
/>

Fixes #40633

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-03-06 08:38:49 -07:00
Joshen LimandAli Waseem f0b44ae087 Adjust header + project list for wildcard routes (#43387)
## Context

Small adjustments to wildcard routes

- Header logo to be consistent with other layouts
  - Before:
<img width="463" height="172" alt="image"
src="https://github.com/user-attachments/assets/217bb9d8-d4f9-4482-8c40-5f0c49afeee6"
/>
  - After:
<img width="523" height="229" alt="image"
src="https://github.com/user-attachments/assets/707dd541-f0ab-4023-ba25-e244eb7c3e7a"
/>
- Project wildcard route list view to be consistent with org/[slug] page
- project list shouldn't take full height if there's no need to, scroll
behaviour should be on the page
  - Before:
<img width="1224" height="868" alt="image"
src="https://github.com/user-attachments/assets/6ff9f8a3-9f68-40a0-9a0b-e60fbef603cd"
/>
  - After:
<img width="1230" height="477" alt="image"
src="https://github.com/user-attachments/assets/91d65969-9457-49f9-9ce2-d3befc4576ad"
/>

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-03-06 22:39:04 +08:00
Ignacio Dobronich ebec20f542 chore: prevention of used leaked passwords entitlement (#43410)
### Changes
- Replaces the isPaid plan-based check on the "Prevent use of leaked
passwords" (PASSWORD_HIBP_ENABLED) setting with a proper entitlement
check using the `password_hibp` entitlement key
- Adds a new `useHasEntitlementAccess` hook that returns a reusable
checker function for any entitlement key, backed by the same cached
entitlements query


### Testing
- Head to `/project/_/auth/providers?provider=Email` with an Org on the
Free Plan
- Assert that the "Prevent use of leaked passwords" toggle is disabled.
- Head to `/project/_/auth/providers?provider=Email` with an Org on the
Pro Plan
- Assert that the "Prevent use of leaked passwords" toggle is enabled
and can be toggled and saved.

<img width="612" height="496" alt="image"
src="https://github.com/user-attachments/assets/fc1ccc79-016c-4265-96ac-bdb458d2a8de"
/>
2026-03-06 11:17:57 -03:00
hallidayo 98c34582b8 feat: add description to schema visualizer (#43406)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Studio > Database > Schema Visualizer

## What is the current behavior?

If a table has a description value then the value does not show on the
visualizer

## What is the new behavior?

<img width="393" height="243" alt="Screenshot 2026-03-04 at 19 09 47"
src="https://github.com/user-attachments/assets/fcd61ecb-c1b8-4408-b753-62cc1d136c69"
/>


## Additional context

Closes #36072
2026-03-06 06:59:07 -07:00
Jeremias Menichelli a25e116c50 chore(Docs): Run format on docs folder to update files (#43463) 2026-03-06 14:25:55 +01:00
Kanishk Dudeja 95283fafb5 fix(billing): remove duplicate tax ID entry for New Zealand (#43482)
This PR removes a duplicate `nz_gst` entry from the tax ID types list.

**Testing**

<img width="1217" height="614" alt="Screenshot 2026-03-06 at 5 25 38 PM"
src="https://github.com/user-attachments/assets/2895ddbd-d124-4ee3-9135-2c08d6f1b0b3"
/>
2026-03-06 18:54:47 +05:30
Alaister YoungandNick Babadzhanian 5894e37b40 [FE-2158] – feat(studio): Add exposed tables config to Postgrest settings (#43280)
Adds a feature flagged exposed tables config to postgrest settings:
<img width="1158" height="589" alt="Screenshot 2026-03-02 at 17 04 13"
src="https://github.com/user-attachments/assets/8fa8ab81-0bfa-4781-83bc-80ac52e180f8"
/>

To test:
- make sure the existing (feature flag off) settings work as expected
- make sure exposing and removing schemas works in the new mode
- make sure exposing and removing tables works in the new mode
- ideally try with a lot of tables to check search and infinite scroll
work as expected
- try exposing a schema without any tables (like `graphql_public`) and
make sure it doesn't get removed randomly when editing tables
- try with a table with custom permissions (for example `REVOKE SELECT
ON public.posts FROM anon;`) and make sure the user is informed with the
tooltip

---------

Co-authored-by: Nick Babadzhanian <33933459+pgnickb@users.noreply.github.com>
2026-03-06 20:51:37 +08:00