Commit Graph
36846 Commits
Author SHA1 Message Date
Miranda Limonczenko 6762c6d215 chore(docs) Resolve all mdx lint errors 2026-06-15 18:07:17 -07:00
Ivan Vasilov f9b4ee871a fix: Disable generate snippet title feature when the org has disabled AI features (#46959)
This PR disabled generating snippet titles when running and disables the
"generate titles" buttons in Rename Snippet and Save Snippet dialogs
(which is accessed through the side SQL Editor).

How to test:
1. Disable AI for an org.
2. Try to run a new snippet, it shouldn't be renamed automatically.
3. Right click it, click Rename. The "generate title" in the dialog
should be disabled with a reason in a tooltip.
4. Open the side SQL Editor, write "select 1", click Save snippet. The
"generate title" in the dialog should be disabled.

Testing the same flows for HIPAA projects should say `This feature is
not available for HIPAA projects.`

<img width="715" height="833" alt="Screenshot 2026-06-15 at 23 02 15"
src="https://github.com/user-attachments/assets/f9b68f2f-5a5a-4a66-bd0d-9245f4e2f78e"
/>
<img width="948" height="845" alt="Screenshot 2026-06-15 at 23 02 01"
src="https://github.com/user-attachments/assets/b0c9a90e-6cc1-4262-a246-88617cec41dc"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* AI feature availability is now gated by organization-level AI opt-in
settings instead of subscription-based HIPAA add-ons.

* **Bug Fixes**
* Updated "Generate with AI" buttons to display disabled state with
contextual messaging (missing API key, organization AI opt-out, HIPAA
project restriction, or generation in progress).

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-16 00:21:40 +02:00
Danny WhiteandCursor 1a93714232 fix(studio): polish interstitial logo contrast and redirect text (#46958)
## What kind of change does this PR introduce?

Bug fix / UI polish. Resolves DEPR-597.

## What is the current behavior?

In shared Connect / interstitial surfaces, partner logos in `LogoPair`
often have baked-in backgrounds (e.g. Figma white, Cursor black, CLI
`bg-black`), while `SupabaseLogo` uses the default `LogoBox` `bg-muted`
and can look washed out in dark mode.

The OAuth redirect footnote on `/authorize` also lacked `text-balance`,
unlike other interstitial footnotes.

## What is the new behavior?

- `SupabaseLogo` now uses `bg-surface-75` on its `LogoBox` for better
contrast alongside partner logos in light and dark mode, without the
harsh fixed-white pairing on flows like CLI login.
- The `/authorize` redirect footnote uses `text-balance` for cleaner
wrapping of long redirect URLs.

| Before | After |
| --- | --- |
| <img width="524" height="455" alt="Authorize CLI
Supabase-206F0310-3508-41F6-8255-6840FD1DFB21"
src="https://github.com/user-attachments/assets/86a41a79-4074-4263-abba-e9db97dd1f9d"
/> | <img width="524" height="455" alt="Authorize CLI
Supabase-25A580E2-5353-4CA4-BDA7-C6953154A5FE"
src="https://github.com/user-attachments/assets/83046770-f9fc-4648-b7c4-428423510f53"
/> |

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-16 06:52:48 +10:00
Kalleby Santos 67cfab1047 fix(docs): functions error codes into Debugging section and link references (#46957)
## What kind of change does this PR introduce?

docs update

## What is the new behavior?

Moving the new `error-codes` page to "Debugging" section.
Adding link reference to it under `status-codes` page.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Documentation**
* Reorganized Error Codes guide navigation to the Debugging section for
improved discoverability
* Enhanced status codes guide with details on HTTP status codes and
error response headers in Edge Functions

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 21:45:39 +01:00
Danny White 7e25c27e02 fix(studio): map email template anchors to docs (#46952)
## What kind of change does this PR introduce?

Bug fix. Resolves FE-3469.

## What is the current behavior?

On auth email template pages, the Docs button builds anchor hashes from
the Studio URL slug (derived from user-facing titles), not from
canonical template IDs.

E.g. **Reset password** links to `#authemailtemplateresetpassword`, but
the docs section is `#authemailtemplaterecovery`.

12 of 13 templates had broken Docs links.

## What is the new behavior?

Docs links use an explicit `EMAIL_TEMPLATE_DOCS_ANCHORS` map keyed by
`template.id`, matching the anchors in
[customizing-email-templates.mdx](https://supabase.com/docs/guides/local-development/customizing-email-templates).

Examples:
- Reset password → `#authemailtemplaterecovery`
- Magic link or OTP → `#authemailtemplatemagic_link`
- Password changed → `#authemailnotificationpassword_changed`

Dashboard URL slugs (`reset-password`, etc.) are unchanged.

## Additional context

- Added `EMAIL_TEMPLATE_DOCS_ANCHORS` in `EmailTemplates.constants.ts`
with `satisfies Record<AuthTemplateType, string>` for exhaustiveness
- Added `EmailTemplates.constants.test.ts` to verify all template types
are covered and anchors match docs heading paths

**Test plan**
- [x] `pnpm --filter studio test EmailTemplates.constants`
- [ ] Spot-check Docs button on Reset password, Magic link or OTP, and
Password changed templates

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Tests**
* Added automated checks to ensure every authentication email template
has the correct documentation anchor mapping.

* **Chores**
* Updated the documentation link behavior for email templates to use a
consistent, predefined anchor mapping—improving reliability and
maintainability of the docs button.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 13:39:53 -06:00
Johan Bergström fcf81c7d42 ci: restore contents write for mgmt api docs token
The implicit `contents: write` it previously inherited from the App installation.
This led to the weekly mgmt api docs job failing with a 403 once the upstream spec changed.

Add `permission-contents: write` so the token can push the branch again.

PR: https://github.com/supabase/supabase/pull/46954
Closes: https://linear.app/supabase/review/ci-restore-contents-write-for-mgmt-api-docs-token-bb8134ed1ecf
Refs: https://github.com/supabase/supabase/pull/46454
Refs: https://github.com/supabase/supabase/actions/workflows/docs-mgmt-api-update.yml
2026-06-15 19:19:41 +01:00
Miranda LimonczenkoandMiranda Limonczenko dcf02db5c7 chore(docs) Prescribe more detailed docs style lints (#46895)
Closes
[DOCS-1036](https://linear.app/supabase/issue/DOCS-1036/add-docs-lint-rule-for-copywriting-style-gaps)

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This change expands upon the "us this, not that" style rules and applies
them to our linting.

## What is the current behavior?

Our current behavior does far fewer checks.

## What is the new behavior?

The new behavior spots the following:

- Suggesting swapping Latin phrases for common English
- Remove formal words for simpler words
- Removes marketing language
- And more (see code diff)

## Additional context

For more information about general style rules, see the style guide:
https://supabase.com/design-system/docs/copywriting


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Refined contribution guidelines with clearer style guidance for filler
words, terminology (including “Backend” hyphenation), abbreviation
usage, and updated wording examples.
* Updated the foundations quickstart wording to “Utilize shadcn/ui”
under setup guidance.

* **Chores**
* Expanded MDX linting guidance to flag filler/marketing language, vague
verbs, formal corporate phrasing, apologies, human-language punctuation
variants, and certain Latin phrases.
* Adjusted related lint preferences and downgraded several checks to
**WARNING** for a less disruptive experience.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Miranda Limonczenko <miranda@supabase.io>
2026-06-15 09:55:48 -07:00
supabase-supabase-autofixer[bot]andgithub-actions[bot] 02e50aa86e [bot] Decrease ESLint ratchet baselines (#46913)
Automated weekly decrease of ESLint ratchet baselines.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-06-15 10:09:23 -06:00
Joshen Lim 1baaded0bb Consolidate execute-sql-query into execute-sql-mutation (#46944)
## Context

Just some clean up as I was going through stuff
- `useExecuteSqlQuery` is deprecated and not used at all
- As such `execute-sql-query` is technically irrelevant, the more
relevant file is `execute-sql-mutation`
- Hence opting to consolidate `execute-sql-query` into
`execute-sql-mutation`
- Also removing `ExecuteSqlError` since its just re-exporting the
`ResponseError` type

There's a lot of file changes but its essentially just updating the
importing statements across the files
2026-06-16 00:07:16 +08:00
Pamela Chia 91982e6a2d feat(studio): track unified logs cta variant and auto-dismiss on explore (#46940)
## Summary
The Unified Logs promo banner (shipped in #46847) had two telemetry/UX
gaps I found while auditing the weekly PostHog event review. Its CTA
fired one event for two different user paths with no way to tell them
apart, and clicking "Explore" left the banner in place. This adds an
`is_enabled` property to the CTA event and auto-dismisses the banner on
the Explore path.

## Changes
- Add `is_enabled: boolean` to `unified_logs_banner_cta_button_clicked`.
It is `true` when the user is already enabled and the button navigates
to the logs page ("Explore"), and `false` when not enabled and the
button opens the feature-preview modal ("Enable"). The two cohorts are
now queryable independently, which is what makes the CTA data usable for
measuring adoption.
- Auto-dismiss the banner when an already-enabled user clicks "Explore".
Previously only the X button dismissed it, so an Explore click left the
banner showing on the next project page load. Scoped to the Explore path
on purpose: the not-enabled path only opens a preview modal (it does not
enable), so dismissing there would hide the banner from users who never
enabled.

## Testing
Behavior to verify on the Vercel preview:
- [x] Enabled user clicks "Explore Unified Logs": navigates to the logs
page, banner does not reappear on the next project page load, CTA event
fires with `is_enabled` true.
- [x] Non-enabled user clicks "Enable Unified Logs": preview modal
opens, banner is still present after closing the modal, CTA event fires
with `is_enabled` false.
- [x] X button: banner dismissed as before, dismiss event fires.

Out of scope on purpose: no impression event (it would fire on every
banner render, low-millions of events per month for one banner), so true
click-through rate stays unmeasurable for now.

## Linear
- fixes GROWTH-925


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Unified Logs banner now intelligently updates behavior based on
feature state.
* When enabled, exploring the feature automatically dismisses the
banner.
  * When disabled, the enable action opens the feature preview flow.
  * Enhanced tracking for banner interactions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 15:07:03 +00:00
Jordi EnricandClaude Sonnet 4.6 0920e48d12 feat(timezone-picker): pin UTC as second option FE-3570 (#46934)
## Problem

UTC was buried in the middle of the timezone list. Users managing
servers (which run in UTC) had to scroll or search to find it.

## Fix

Hardcode a UTC entry immediately after "Auto detect" so the two most
common choices are always at the top. The entry uses the standard `UTC`
IANA name and shows the checkmark when selected, consistent with all
other entries.

## How to test

- Open any page in Studio and click your user avatar.
- Open the Timezone submenu.
- Confirm the order is: Auto detect, (UTC) Coordinated Universal Time,
then the rest of the list.
- Select UTC and confirm the checkmark appears and the trigger label
updates.
- Search "UTC" in the search box and confirm it still matches.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added explicit "UTC (Coordinated Universal Time)" option at the top of
the timezone selector dropdown for easier access.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 16:26:25 +02:00
Joshen LimandAli Waseem 4691372093 Joshen/fe 3610 projectneedssecuring to avoid fetching all table privileges (#46929)
## Context

The dashboard has an RQ hook that fetches all table privileges in the
database `useTablePrivilegesQuery`
[here](https://github.com/supabase/supabase/blob/master/apps/studio/data/privileges/table-privileges-query.ts#L21)
which can potentially be a resource heavy query on the database,
especially if the database has a large number of relations.

A recent UI that was added `ProjectNeedsSecuring` uses that query, and
has become a common entry point for all projects as it's rendered when
the user lands on the project's home page, and the project has tables
with RLS issues, in which case if the project has a large number of
tables, the database will face run into resource issues, resulting in
statement timeouts.

## Changes involved

Opting to pass in `includedSchemas` parameter wherever we're calling
`useTablePrivilegesQuery`, which includes:
- `ProjectNeedsSecuring`
- `QueueSettings`
- `column-privileges`
In which we'll hence only fetch the table privileges for the provided
schemas only (rather than the whole DB)

Also did a similar fix for `useColumnPrivilegesQuery` as well as it
likely runs into the same problem

## To test
- [ ] Verify that those 3 UIs are still working as expected (should not
have any visual changes)
- [ ] Verify in the network tab that table / column privileges are now
filtered to the schema provided, rather than fetching for all schemas in
the DB

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved permission-save failure messaging by generating clearer toast
errors from unexpected failures.
* Prevented privilege-related UI from loading until required
configuration is successfully retrieved.
* **Performance**
* Faster, more targeted privilege loading by scoping both table and
column privilege queries to the selected/relevant schema(s), reducing
unnecessary client-side filtering.
* Switched privilege retrieval to schema-aware database metadata queries
for more efficient results.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-06-15 08:10:34 -06:00
Joshen Lim 84772721f3 Ensure that fetching policies is filtered by schema in table editor and auth policies page (#46930)
## Context

We're currently fetching _all_ database policies when landing on the
Table Editor which is unnecessarily since only the table in view matters
in that moment.

## Changes involved

- Ensure that fetching policies is filtered by the current schema in the
table editor to avoid fetching all policies in the DB
- ^ Applied the same fix on the Auth Policies page as well since it
faces the same issue

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved database policy fetching so it respects the currently
selected schema and won’t run when the table context is missing.
* Enhanced project status updates by aligning cached updates with the
infinite-list query structure.
* **Refactor**
* Streamlined auth policy schema handling by deriving exposed schemas
via shared utilities and requesting only the needed configuration field
for subsequent policy queries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 07:22:22 -06:00
Blut-agentandKalleby Santos 15214d02de fix(docs): use proper apikey instead of Authorization header for Functions examples (#46013)
## Problem

The Supabase Functions documentation shows examples that send a
publishable key in the `Authorization: Bearer` header. This causes
`UNAUTHORIZED_INVALID_JWT_FORMAT` errors because publishable keys are
not JWTs.

Per the [Understanding authorization
headers](/docs/guides/functions/auth#understanding-authorization-headers)
guide:
> A common mistake is sending a publishable or secret key as a bearer
token: `Authorization: Bearer sb_pub.....`. The new API keys are not
JWTs. The platform check can't validate them, and your handler can't
verify them as JWTs either. Instead, put API keys in the `apikey`
header.

## Fix

Updated three documentation files to use the `apikey` header instead of
`Authorization: Bearer` when calling Edge Functions with a publishable
key:

- **quickstart-dashboard.mdx**: Changed fetch example from
`Authorization: 'Bearer YOUR_PUBLISHABLE_KEY'` to `apikey:
'<SUPABASE_PUBLISHABLE_KEY>'`
- **recursive-functions.mdx**: Changed fetch example from
`Authorization: \`Bearer ${SUPABASE_DEFAULT_PUBLISHABLE_KEY}\`` to
`apikey: SUPABASE_DEFAULT_PUBLISHABLE_KEY`
- **schedule-functions.mdx**: Changed SQL cron example from
`'Authorization', 'Bearer ' || ...` to `'apikey', ...`

## Related

-
[supabase/supabase#45993](https://github.com/supabase/supabase/issues/45993)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated Function guide examples for invoking Edge Functions to send
the publishable key in an `apikey` request header instead of using an
`Authorization: Bearer ...` header.
* Aligned both `fetch` and scheduled-invocation examples with the
updated authentication snippet.
* Refreshed an example output comment to match the updated response
text.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Kalleby Santos <105971119+kallebysantos@users.noreply.github.com>
2026-06-15 12:41:19 +00:00
Ivan VasilovandGildas Garcia e1ccc31fcc chore: Disable some of the Studio features on Multigres projects (#46775)
This PR disables the following features on Multigres projects

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Enhanced replication interface with improved visual states.

* **Bug Fixes**
* Added validation to prevent incompatible database configuration
combinations.

* **Changes**
* High Availability projects now display informational notices
indicating unavailable features: Realtime, Replication, and PITR
backups.

* **Removed**
  * Removed redundant UI component from the application.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-06-15 14:09:41 +02:00
Francesco Sansalvadore dfc2dede05 chore(www): integration partner addendum - v1.1 (#46931)
Update integration partner addenda.
2026-06-15 10:31:31 +00:00
Riccardo Busetti f14d49dd2d Standardize external replication (ETL) docs (#46875) 2026-06-15 12:22:46 +02:00
Kalleby SantosandChris Chinchilla e5832d210c docs(functions): add error codes page (#46833)
Towards FUNC-308

## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

Missing error codes definitions for Edge Functions

## What is the new behavior?

This PR adds maps the possible error codes that Edge Functions can
return

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a new “Error Codes” guide for Edge Functions, explaining how to
use the `sb-error-code` response header and covering error categories
(bad implementation, authentication, request, server) with causes and
solutions.
* **New Features**
* Updated site navigation to include a direct “Error Codes” link under
the functions menu for quicker access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2026-06-15 11:03:22 +01:00
Chris Chinchilla 954c861b11 docs: Set path on 404 errors (#46848)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* 404 handling now returns path-aware not-found pages for missing docs
and guides, improving accurate user-facing 404 responses.
* Improved file-missing errors for guides so missing content cases
surface clearer diagnostic info.

* **Chores**
* Enhanced 404 telemetry so missing-path information is recorded for
better monitoring and quicker troubleshooting.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 11:33:11 +02:00
SOUFIAN3HM ebcd052018 docs: fix stale links to the Metrics guide after move to /telemetry (#46816)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update (stale internal links / dead anchors).

## What is the current behavior?

The Metrics guide moved from `/docs/guides/platform/metrics` to
`/docs/guides/telemetry/metrics` and was split into sub-pages, but 15
internal links across the docs still use the old path:

1. **Redirect chain** — non-anchored links to
`/docs/guides/platform/metrics` only resolve via a two-hop permanent
redirect (`platform/metrics` → `monitoring-troubleshooting/metrics` →
`telemetry/metrics`, in `apps/www/lib/redirects.js`).
2. **Dead anchors** — `#accessing-the-metrics-endpoint` and
`#deploying-supabase-grafana` no longer exist on the restructured page,
so those links currently land at the top of the page instead of the
intended section.

## What is the new behavior?

- Non-anchored links now point directly at the canonical
`/docs/guides/telemetry/metrics` (relative links use
`../telemetry/metrics`), avoiding the redirect chain.
- `#accessing-the-metrics-endpoint` links →
`/docs/guides/telemetry/metrics` (the Metrics API endpoint access
content lives on that page).
- `#deploying-supabase-grafana` links →
`/docs/guides/telemetry/metrics/grafana-self-hosted`, the page that now
holds the Prometheus/Grafana installation instructions those links
referenced.

15 files changed, links only — no content changes.

## Additional context

Pure documentation link cleanup. Affected files include several guides
(`database/connection-management`, `database/inspect`,
`platform/performance`, `platform/read-replicas`) and troubleshooting
entries that reference the Metrics/Grafana setup guide.
2026-06-15 09:10:33 +00:00
SOUFIAN3HM bb80fa49d5 docs: fix stale links to the Logs guide after move to /telemetry (#46817)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update (stale internal links).

## What is the current behavior?

The Logs guide moved from `/docs/guides/platform/logs` to
`/docs/guides/telemetry/logs`, but five internal links still use the old
path. They only resolve through a two-hop permanent redirect
(`platform/logs` → `monitoring-troubleshooting/logs` → `telemetry/logs`,
in `apps/www/lib/redirects.js`).

Affected:
- `guides/database/extensions/pgaudit.mdx`
- `guides/platform/read-replicas.mdx`
- `guides/storage/cdn/metrics.mdx` (`#logs-explorer`)
-
`troubleshooting/how-to-interpret-and-explore-the-postgres-logs-OuCIOj.mdx`
- `troubleshooting/http-status-codes.mdx` (`#logs-explorer`)

## What is the new behavior?

Links now point directly at `/docs/guides/telemetry/logs` (relative
links use `../telemetry/logs`), avoiding the redirect chain. The
`#logs-explorer` anchor is preserved and still resolves (`## Logs
Explorer` in `guides/telemetry/logs.mdx`).

5 files changed, links only — no content changes.

## Additional context

Pure documentation link cleanup, analogous to the Metrics-guide link
fixes.
2026-06-15 09:08:16 +00:00
Ivan Vasilov 4cdbe67980 chore: Bump vulnerable dependencies (#46840)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated React Router packages to v7.17.0 for improved routing
stability.
* Adjusted workspace dependency governance and overrides for more
consistent installs.
  * Removed an obsolete PostCSS re-export.

* **New Features**
* Integrated Tailwind into the build pipeline to enable utility-first
styling.

* **Style**
* Added global base styles to standardize border color across UI
elements.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 10:12:06 +02:00
Jordi EnricandClaude Opus 4.8 f5358fda86 docs: document swap as a series in the memory usage chart DEBUG-127 (#46874)
## Problem

The Memory usage chart now includes a Swap series, but the telemetry
reports docs do not mention it. Swap is shown alongside Used, Cache +
buffers, and Free in the same chart, not as a standalone chart.

## Fix

- Add **Swap** to the Memory usage component table
- Add a short note that the Swap series only appears when the system is
swapping, with a brief explanation of what swap means for performance
- Add a swap-activity row to the Memory usage "How it helps debug
issues" table

No standalone Swap section and no separate entry in the charts summary
table, since swap is part of the Memory usage chart.

## How to test

- Run the docs site and open the Reports guide
(`/docs/guides/telemetry/reports`)
- Confirm the Memory usage section lists Swap as a component and the
tables render correctly

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated Advanced Telemetry (Database) to include "Swap" in the
memory-usage breakdown, explain what swap is, and note its impact when
RAM is exhausted.
* Added "Swap activity monitoring" to troubleshooting guidance as a
signal of sustained paging to disk and its effect on database
performance, plus recommended mitigation actions.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 09:57:31 +02:00
Jordi EnricandClaude Sonnet 4.6 4c011cf9c0 feat(reports): add optimistic delete for custom reports (#46803)
## Problem

Deleting a custom report waited for the API round trip before updating
the UI. The confirmation modal showed a loading spinner, the report
stayed visible in the sidebar until the request resolved, and the
interaction felt sluggish.

## Fix

The delete now applies optimistically. On confirm, the report is removed
from the sidebar immediately and the user is navigated away. The actual
delete runs in the background. If it fails, the cached list is rolled
back to its previous state and an error toast is shown.

The optimistic behavior lives inside `useContentDeleteMutation` (via
`onMutate` snapshot + `onError` rollback), so any current or future
caller of that hook gets it for free, no per-call wiring required.

## How to test

- Open a project with at least one custom report
- Click the kebab menu on a report and choose Delete report, then
confirm
- Expected result: the report disappears from the sidebar instantly and
a success toast appears
- To test rollback: throttle/offline the network or force the delete
endpoint to fail, then delete again
- Expected result: the report reappears in the sidebar and an error
toast is shown

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Deletion flows now provide explicit loading, success and error
feedback; UI updates immediately on delete and will restore if the
action fails.

* **Removals**
* Removed the reports menu and individual report menu item UI components
(affects report-level rename/delete dropdowns and related menu
navigation).

* **Tests**
* Added tests covering content deletion behavior, multiple-deletion
cases, and data integrity after removals.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 09:57:19 +02:00
Jordi EnricandClaude Sonnet 4.6 b8c8b00b40 fix(reports): improve disk size section UI/UX DEBUG-91 (#46771)
## Problem

The Disk Size section in the database report used raw HTML headings and
unstyled spans without semantic Tailwind tokens, resulting in
inconsistent typography and spacing compared to the rest of the report.

## Fix

- Replace bare `<h5>` labels with `<p className="text-sm
text-foreground-light">` for consistent muted label styling
- Add `font-semibold text-foreground` to stat values so they stand out
clearly
- Simplify the stat row layout from a brittle `inline-grid grid-cols-12
gap-12` to `flex flex-wrap items-center gap-8` with `ml-auto` on the
action button
- Replace `<h3 className="mt-8 text-sm">` with a properly styled `<p>`
label for the Large Objects sub-section
- Style the empty-state "No large objects found" message with `text-sm
text-foreground-light`

## How to test

- Go to `/project/<ref>/observability/database`
- Scroll to the Database Size section
- Confirm the Space used and Provisioned disk size labels are muted and
values are bold/prominent
- Confirm the layout is clean and the Increase disk size button sits to
the right
- Confirm the Large Objects sub-section label and empty state are
consistently styled

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Updated the visual layout and styling of the Database Size widget's
summary area, improving the presentation of disk space metrics.
* Enhanced the styling of the Large Objects section header and
empty-state messaging for better visual consistency.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 09:56:58 +02:00
K-Dog (Kevin) a412298fb0 feat(hibernation): automated wake (#46845)
As part of hibernation (suspend and wake), wakes via PostgREST happen
automatically. However, if a user goes straight to the dashboard, we
want to ensure the project wakes up from it's slumber. I've decided to
add this logic at a very central point that will prevent most
project-ref related pages to load (purposely).

The project ref details endpoint returns whether the project is
hibernating or not - so for any regularly running project, none of the
added logic will be invoked and there is no extra network calls, so no
negative perf impact for these checks.

Eventually with v3 architecture none of this is needed as wakes are done
at the proxy/network layer, but this is a necessary change for v2 for
more graceful wakes.

Adjusted network restrictions as it would query before the project loads
and potentially time out while still loading


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **New Features**
* Automatic wake-up for hibernating projects restores functionality
without manual intervention.

* **Platform API Enhancements**
* New conversation management endpoints for escalation, synchronization,
and resolution.
  * New project wake endpoint for managing dormant project states.
* Updated read-replica operation response codes for improved API
consistency.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 13:44:35 +08:00
Inder Singh 5d8d1f359f chore(self-hosted): use /bin/sh shebang in kong-entrypoint.sh (#46897) 2026-06-13 10:30:39 +00:00
Prashant Sridharanandshaziya 68a7e45aca Added go pages for several ancillary events at Supabase Select (#46879)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added landing pages for some events

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Launched three Supabase Select 2026 event pages (Partner Day, VIP
Dinner, VIP Experience) with RSVP flows, agendas, host details, and
thank-you confirmations.

* **Updates**
* RSVP forms now support per-form CRM mapping and explicit field
exclusions for HubSpot.
  * Site index updated to include the new event pages.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: shaziya <99940835+shaziyabandukia@users.noreply.github.com>
2026-06-12 21:18:10 +01:00
Mrinal Paliwal e26dc700e4 feat(www): use 'Publish to Web Title' for Notion event names (#46888)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature

## What is the current behavior?

Event names use 'Event Name' property from Notion database

## What is the new behavior?

Prefer the 'Publish to Web Title' property for displaying event names,
falling back to the 'Event Name'

## Additional context

N/A

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Event titles now prioritize the "Publish to Web Title" field when
available, falling back to the generic title only if that
publish-specific value is empty—improves accuracy of displayed event
titles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 23:00:56 +05:30
Ali Waseem ee3bec08af fix: intercept responses missing content lenght and re-add (#46885)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Cases with cloudflares http/3 the content-length header is optional, so
in many cases we need to make sure in this case `openapi-fetch` can
safely parse this (i.e ignore when the body is empty and no header is
present)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Bug Fixes**
* Fixed JSON parsing failures when successful API responses contain
empty bodies without `Content-Length` headers. Improves compatibility
with HTTP/3 and similar response types.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 11:16:12 -06:00
Ali Waseem 359c933e77 fix: warn against dangerous queries in dynamic SQL execution (#46882)
Extends the SQL editor's destructive query detection to catch dangerous
operations (DROP, DELETE, TRUNCATE) hidden within dynamic SQL execution
patterns like `EXECUTE`, `EXECUTE format()`, `OPEN cursor FOR EXECUTE`,
and `RETURN QUERY EXECUTE`.

Previously, only direct statements like `DROP TABLE users` triggered
warnings. Dynamic SQL inside PL/pgSQL blocks bypassed detection
entirely.

Closes FE-3603 and https://github.com/supabase/supabase/issues/46876

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved detection of potentially destructive SQL across many
execution styles, including DROP/DELETE/TRUNCATE, ALTER ... DROP COLUMN,
and dynamic/executed or string-constructed queries to reduce missed
destructive cases.

* **Tests**
* Expanded test coverage for SQL validation with extensive positive and
negative scenarios covering dynamic execution patterns (EXECUTE
variants, concatenation, dollar-quoted and escaped strings) to reduce
false positives and negatives.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 10:59:56 -06:00
Mrinal Paliwal ba947adf0a fix(www): z-index clash between event filter and event label (#46884)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

UI bug fix in `/events` page. The z index of event filters clashes with
event labels

## What is the current behavior?


https://github.com/user-attachments/assets/fda9947b-5a2b-4f0a-9964-6e00184ecb8c

## What is the new behavior?


https://github.com/user-attachments/assets/97c962da-734f-4fd7-87d7-9a0e51bc301a

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Adjusted the event gallery's sticky container layering so it reliably
appears above overlapping page elements, preventing visual obstruction
and improving scrolling behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 21:47:45 +05:30
Kimaswa Emmanuel YusufuandChris Chinchilla 64085b2d0c docs: fix broken code examples and wrong identifiers in guides (#46755)
A handful of code samples in the guides either don't run or contradict
the surrounding text. I found these reading through the docs.

- `database/debugging-performance`: `insert into books` targets a table
that's never created. The table made just above is `instruments`.
- `database/drizzle`: the `db.ts` snippet references an undefined
`host`. The variable in scope is `connectionString`.
- `database/postgres/column-level-security`: the `create table` is
missing a comma after `created_at ... now()`, so it won't parse.
- `database/postgres/first-row-in-group`: `distinct on (team)` with
`order by id, ...` is rejected by Postgres (the DISTINCT ON column has
to lead the ORDER BY). Ordered by `team, points desc` so it returns one
row per team.
- `database/postgres/data-deletion`: reversed markdown link
`(text)[url]`, plus "parititioning" misspelled.
- `database/extensions/pg_plan_filter`: prose says
`statement_cost_filter`, but the real parameter (used everywhere else in
the file) is `statement_cost_limit`.
- `auth/auth-hooks/mfa-verification-hook`: the insert and on-conflict
update use `last_refreshed_at`, but the table column is
`last_failed_at`.
- `telemetry/advanced-log-filtering`: the "ends with" example writes
`'$port=12345'`. The `$` anchor needs to come after the literal:
`'port=12345$'`.
- `ai/examples/headless-vector-search`: uses `${projectURL}` but the
const is `projectUrl`.
- `getting-started/quickstarts/redwoodjs`: prose says
`scripts/seeds.ts`, but the code block and Redwood use
`scripts/seed.ts`.
- `getting-started/tutorials/with-flutter`: two code-fence headers have
a stray trailing `"`.
- `local-development/cli/testing-and-linting`: stray backtick in "Edge`
Functions".


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Corrected code examples across multiple guides including vector
search, authentication hooks, database guides, and quickstarts
* Fixed SQL syntax errors, variable names, and table references in
example snippets
* Resolved typos, broken links, and formatting inconsistencies in guide
text
  * Clarified parameter names and script references in documentation
  * Updated code fence syntax in tutorials for proper rendering

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-06-12 16:08:41 +00:00
kemal.earth 5662a72ef5 fix(studio): save button alignment on logs (#46881)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Simple one.

| Before | After |
|--------|--------|
| <img width="186" height="114" alt="Screenshot 2026-06-12 at 15 29 18"
src="https://github.com/user-attachments/assets/6e83af04-f97a-4cc9-b82b-b5eb86959e0d"
/> | <img width="243" height="119" alt="Screenshot 2026-06-12 at 15 29
26"
src="https://github.com/user-attachments/assets/2bfb522f-dec2-4205-967f-89223978bcd4"
/> |


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Improved spacing and alignment of action buttons in the logs table
header for better visual consistency.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 15:55:22 +01:00
Ali Waseemandkemal 47dbbddc91 chore: fix secrets editor for functions to be text area/ support newlines (#46754)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Update to support text area for functions

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Secret inputs now accept and preserve multi-line values and
auto-resize to fit content.
* Secret values can be masked/unmasked via a show/hide toggle with
tooltip; masking uses styled concealment.
* Per-secret controls refined: clearer row layout, dedicated remove
icon, and add/save controls moved to the card footer.

* **Tests**
* Added tests validating multi-line secret entry and that submitted
payloads include embedded newlines.
* Updated tests to assert masking/unmasking behavior via visual security
styling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: kemal <hello@kemal.earth>
2026-06-12 08:11:36 -06:00
Saxon Fletcher e92f13f11a adjust project settings integrations layout (#46868)
<img width="1521" height="967" alt="image"
src="https://github.com/user-attachments/assets/8d7bed1f-3ed8-4311-bd4b-92345ae02a52"
/>

Updates project settings integration page to more aligned with our
updated layout guidance (as defined in layout.mdx in design system).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Refined the integrations settings page layout and visual design across
AWS PrivateLink, GitHub, and Vercel integration sections for improved
consistency.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 07:42:11 -06:00
Saxon Fletcher d8fadcc1c8 makes it possible to reset password from connect dialog (#46866)
Makes it possible to reset password from the connect sheet. Once reset
the password is shown temporarily in the connection string for copy. The
copy prompt action does not copy the password.

<img width="1043" height="953" alt="image"
src="https://github.com/user-attachments/assets/fe1a33bb-839f-47e3-b07f-7a5fa1df2b8d"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Session Pooler notice for direct connections on IPv4 networks
* Option to show a temporary database password during direct-connection
setup

* **Improvements**
  * New password reset dialog with strength checks and generation
* Connection-copy behavior now redacts temporary passwords and produces
cleaner copy prompts

* **Tests**
* Added tests covering connection-string password insertion/replacement
and copy-prompt behavior
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 07:38:18 -06:00
Etienne Stalmans a59b797216 fix: improve redirect validation (#46794)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

returnTo is not correctly validated

## What is the new behavior?

returnTo is validated


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved validation of redirect URLs used after organization creation;
when a return URL is provided it is now validated before redirecting,
while auth-related query parameters are still preserved.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 12:34:24 +02:00
Andrey A. 098157eb90 fix(self-hosted): block access to tenants and openapi realtime api (#46856) self-hosted/v0.5.1 2026-06-12 11:48:58 +02:00
K-Dog (Kevin) 9bf5bbcc75 chore(etl): add pricing (#46872)
<img width="1196" height="58" alt="Screenshot 2026-06-12 at 4 21 02 PM"
src="https://github.com/user-attachments/assets/132742b4-652c-4aeb-9296-b830578f153b"
/>

<img width="314" height="209" alt="Screenshot 2026-06-12 at 4 21 07 PM"
src="https://github.com/user-attachments/assets/69bf5e04-3c84-4464-90a6-3297626bfd65"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Introduced a database Replication (ETL) offering now available in Pro,
Team, and Enterprise plans with usage-based billing options.
* Updated the pricing table with explanatory tooltip text to clarify
replication billing and features.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 17:43:37 +08:00
Carlos Vera 712387bbac fix(self-hosted): add healthcheck to rest (PostgREST) service (#46658) 2026-06-12 11:09:55 +02:00
Andrey A. aeca45d4de fix(self-hosted): use explicit /bin/sh for kong entrypoint (#46873) 2026-06-12 10:58:06 +02:00
1e2c616db6 docs: update storage analytics guide example for pyiceberg (#46762)
## Summary

Updates the PyIceberg installation instruction to use the
`supabase[iceberg]` extras instead of listing dependencies separately.

## Change

**`apps/docs/content/guides/storage/analytics/examples/pyiceberg.mdx`**
— Replace `pip install pyiceberg pyarrow` with `pip install
"supabase[iceberg]"`. The `pyiceberg` dependency is optional in
`supabase-py` v2.31.0 and is now declared under
`[project.optional-dependencies]` in the package — users should use the
extras syntax rather than installing dependencies outside of the
`supabase` package.

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated installation instructions for the Iceberg storage analytics
integration guide to reflect the recommended package installation
method.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-12 05:27:28 -03:00
bf633521b4 fix: add vector bucket local CLI section (#46646)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## What is the nee current behavior?

Added new section to explain how  vector buckets works locally

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a "Local Development" guide for Vector Buckets covering
alpha-status cautions, local vs hosted behavior, steps to enable local
vector storage, declarative bucket configuration, and how to create
buckets for local testing.
* Updated site navigation to include the new Local Development guide in
the Storage → Vector docs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2026-06-12 08:09:31 +00:00
K-Dog (Kevin) b347c8341d chore(etl): etl add-on forward compat (#46869)
Prep work for new ETL pipeline add-on, forward compatible
2026-06-12 16:06:55 +08:00
Erfi Anugrah e757ce9c87 added myself to humans.txt (#46734)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added myself to humans.txt

## What is the current behavior?

The same as the commit I pulled it on

## What is the new behavior?

No new behaviour.

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated team member listings in project credits.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 10:00:39 +02:00
Andrey A. ff23552aae chore(docs): add openapi to lint rule003 (#46859) 2026-06-12 08:55:51 +02:00
Ali Waseem 7414802e57 test(studio): unflake schema visualizer Copy as SQL assertion (#46863) 2026-06-11 16:09:16 -06:00
Alex Hall 5ce086b06d feat(studio): Marketplace integration partner links (#46827)
Adds partner-provided links for installed marketplace integrations (if
provided) to the marketplace detail breadcrumbs
2026-06-11 15:30:56 -04:00
Terry SuttonandClaude Sonnet 4.6 82ddc6f783 feat(studio): add 'Reset database password' cmd+k shortcut (#46861)
sad:

<img width="1334" height="444" alt="CleanShot 2026-06-11 at 15 27 51"
src="https://github.com/user-attachments/assets/48b77cf2-3034-48ed-8915-f57f2e9a003f"
/>

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-11 18:04:47 +00:00