mirror of
https://github.com/supabase/supabase.git
synced 2026-10-07 18:35:07 +03:00
studio-remote-dev
6501
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
29c0aa507d |
Remove dev-tools-extension; keep minimal remote-dev plumbing
Extension moved to github.com/supabase/supabase-chrome-tools. Keeps only the remote-dev proxy, launcher (production + staging targets), and npm scripts. Comments repointed to the extension repo. |
||
|
|
daabb83ccd |
Potential fix for pull request finding 'CodeQL / Clear-text logging of sensitive information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> |
||
|
|
633842a8c6 | Merge branch 'master' into studio-remote-dev | ||
|
|
84b1327de0 |
Potential fix for pull request finding 'CodeQL / Clear-text logging of sensitive information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> |
||
|
|
aef1599d3e |
Add keyboard shortcut for saving notebook (#50707)
### Context Adds a keyboard shortcut for saving a notebook in the explorer <img width="269" height="112" alt="image" src="https://github.com/user-attachments/assets/c9ab1c4b-fbb3-40ed-8f10-47301e16e6b3" /> Also shifts the keyboard shortcuts for queue operations into the table editor registry - more contextual to there since queue operations is specifically for the table editor only <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a keyboard shortcut (`Mod+S`) for saving notebooks in Explorer. - The save toolbar action now displays its keyboard shortcut. - Restored table editing shortcuts for saving pending edits, toggling the operation queue, and undoing changes (`Mod+S`, `Mod+.`, and `Mod+Z`). <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c7880e328f |
Add a live preview markdown editor for explorer (#50717)
## Context We've gotten some requests for a better markdown editing experience in the Explorer so this PR adds a proper live preview markdown editor, similar UX to how you'd edit notion or obsidian documents. Opting to use `lexical` as the main library to support this UI for its size and composability without going too low level like prose mirror <img width="933" height="452" alt="image" src="https://github.com/user-attachments/assets/7161ae6c-3dff-4b36-818f-01b5e573f121" /> Actual file changes are just this size excluding the package-lock <img width="150" height="39" alt="image" src="https://github.com/user-attachments/assets/bb01f2cf-8ef7-4daf-975b-614b2d817b54" /> ## Changes involved This adjusts the UX for markdown cells a little - Clicking on a markdown cell immediately allows you to edit - Instead of the existing behaviour which requires a double click to enter "Edit" state - Editing doesn't eject you into a monaco editor, but rather inline editor - Nicer transition - Clicking out of the cell persists the cell's content - No more "Cancel" or "Save" buttons ## To test - [ ] Verify that editing markdown cells are still working - [ ] Verify that tabs do get marked with unsaved changes if you edit a markdown cell <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Replaced the previous Markdown editing workflow with an always-visible inline editor. - Added rich Markdown editing for headings, lists, links, blockquotes, code blocks, inline code, and text formatting. - Changes are saved automatically when leaving the editor. - Markdown formatting shortcuts take precedence within the editor. - **Bug Fixes** - Avoids unnecessary saves when content has not changed. - **Tests** - Added coverage verifying Markdown formatting conversions remain consistent and repeatable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ef7b2a5211 |
fix: ESLint errors relating to accessibility in integration section (#50224)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Improving accessibility by adding aria-label. Adding Tooltip for icon only buttons. ## What is the current behavior? Some `aria-label` and `Tooltip` are missing. ## What is the new behavior? Icon-only buttons have now Tooltip and aria-label have been added. ## Additional context No visual changes have been made. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility Improvements** * Added descriptive tooltips and screen-reader labels to search-clear and close-panel controls. * Added accessible labels and tooltips for managing secrets, showing or hiding secret values, and editing or removing foreign tables. * Improved the lint details panel close control with a descriptive label. * Prevented duplicate tooltip announcements for assistive technologies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
14bda8a5cf |
Joshenlim/fe 4438 explorer allow deleting notebookchat without first having to (#50701)
### Context Adds context menu to the explorer nav to allow users to delete notebooks or chats from there (instead of having to open the notebook / chat first, then select delete from the header) <img width="304" height="339" alt="image" src="https://github.com/user-attachments/assets/2ad0f21c-0d49-407c-97a2-ef11ae59e280" /> ### Changes involved: - Consolidates the rendering of explorer nav items into a single component that both `ExplorerNavNotebook`, `ExplorerNavHome` and `ExplorerNavChats` use. - We were previously rendering a link for notebook, and a button for chats. But chats' button was just calling `router.push` under the hood. - Opting to use a Context to handle the delete functionality such that we can render the confirmation modal just once at the layout level since there's multiple places that have this delete functionality - notebook tab, chat tab, context menu in each of the explorer navs ### To test - [ ] Verify that navigating around the explorer is status quo - [ ] Verify that you can delete a notebook/chat from within the notebook/chat tab - [ ] Verify that you can delete a notebook/chat from the explorer nav - [ ] Verify that after deleting a notebook/chat from either locations, the tabs should clear <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Unified chat and notebook navigation with direct links and active-item highlighting. - Added context-menu options to delete chats and notebooks with confirmation and status notifications. - Added double-click support for keeping recently viewed chats and notebooks open as tabs. - Deleted items and their related tabs are removed automatically. - **Tests** - Updated Explorer navigation tests for the unified link-based item behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ec53175b8a |
refactor(ui): rename text-brand to text-primary (#50564)
## What kind of change does this PR introduce? Refactor. Follow-up to #49871. ## What is the current behavior? Branded (green) text still uses the `text-brand` classname while the colour comes from `--primary`. ## What is the new behavior? **Rename-only:** `text-brand` → `text-primary` across callsites and docs. Leftover `bg-brand` / `border-brand` alias to `brand-default`. No intentional colour changes in this PR. This better matches how we treat our green in other components and props, like `variant="primary"` for green buttons. ## To test On light mode: smoke-test that branded text still looks like #49871 (readable green, not the bright fill). - [Homepage](https://zone-www-dot-com-git-dnywh-depr-316-text-brand-de2380-supabase.vercel.app/): “Scale to millions” uses `text-primary` - [Docs homepage](https://docs-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/docs): branded links like “More on self-hosting” are still readable - [Typography docs](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/typography): documents `text-primary` - [Colour usage](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/color-usage): `text-primary` is visibly darker than `bg-brand-default` _on light mode_ - [Studio auth providers](https://studio-staging-git-dnywh-depr-316-text-brand-to-60fa6c-supabase.vercel.app/dashboard/project/_/auth/providers): enabled provider badge text readable; status dot stays bright green <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated branded text, link hover states, icons, badges, indicators, and highlighted content across the Design System, Docs, Studio, Learn, UI Library, and marketing experiences to use the primary theme color. * Updated syntax highlighting and table-of-contents styling for consistent primary-color presentation. * Refined brand color fallback behavior for bright fills and borders. * **Documentation** * Updated color-usage and typography guidance to recommend the primary text utility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c837116598 |
fix(studio): sort replicated tables by name by default (#50696)
## Problem Replicated tables on the pipeline detail page reshuffle after a reset. API order is unstable, and the default client sort was by status, so status changes moved rows around. Fixes PIPE-1137. ## Solution Default the replicated tables table to sort by `schema` + `name` ascending. Status sorting remains available via the Status column header. ## To test 1. Open a project with a pipeline that has several replicated tables: `/project/<ref>/database/replication/<pipelineId>`. 2. Confirm the Replicated tables list is alphabetical by `schema.name`, with the Table column showing ascending sort. 3. Reset one table and confirm its row stays in place while its status updates. 4. Click the Status column header and confirm status sorting still works. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Replicated tables are now sorted alphabetically by schema and table name by default. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
47592ace0f |
Set last visited page when going to preferences from explorer (#50691)
### Context Resolves FE-4442 Tiny one to follow up from https://github.com/supabase/supabase/pull/50670 - just sets the last route before visiting account page from the explorer. Otherwise hitting "back to dashboard" from account preferences brings you back to the /projects page, rather than back to where you left off from the explorer Also added a fix for scrolling to the corresponding section on the preferences page when landing with a `#` in the URL - was bugging out as there's some sections that render skeletons first (`ProfileInformation` and `AccountIdentities`) which changes the height of the content, so the native `#` behaviour doesn't land correctly. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Updated the Preferences link to navigate directly to the account page. - Preserved the current route when navigating to Preferences, improving return navigation behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a4be167491 |
fix(studio): clarify Warehouse status and navigation (#50554)
## What kind of change does this PR introduce? Bug fix and UI polish. ## What is the current behavior? The Warehouse Connect option repeats its own name, and a configured Warehouse has no direct route back to its management page. Warehouse table states also use badges instead of the status-dot pattern used by Replication, and a backfilling table can misleadingly appear as “Caught up”. ## What is the new behavior? - Describes Warehouse as an analytical endpoint and adds a low-emphasis “Manage Warehouse” link from the Connect sheet. - Shares Replication’s status-dot presentation with Warehouse while keeping feature-specific state mapping separate. - Shows replication lag only for live tables, so backfilling and “Caught up” are never presented together. | Before | After | | --- | --- | | <img width="1244" height="1156" alt="CleanShot 2026-09-18 at 14 03 49@2x" src="https://github.com/user-attachments/assets/60aa3496-6930-491a-af9e-9ffcfb035a0f" /> | <img width="1216" height="1214" alt="CleanShot 2026-09-18 at 14 04 33@2x" src="https://github.com/user-attachments/assets/84a8c80e-d8d1-4ee5-9cce-352d1f6477c2" /> | | <img width="1314" height="1414" alt="CleanShot 2026-09-18 at 14 02 50@2x" src="https://github.com/user-attachments/assets/8871a4a5-0543-4290-91a7-9da949ec4c49" /> | <img width="1308" height="1498" alt="CleanShot 2026-09-18 at 14 02 43@2x" src="https://github.com/user-attachments/assets/ac3fc6d1-5b4d-4a3a-8ab7-bb54025e2145" /> | ## To test 1. Open `/project/<ref>?showConnect=true&connectTab=warehouse` for a project with Warehouse configured. Confirm the mode subtitle says “Analytical endpoint”. Confirm the new “Manage Warehouse” button opens `/project/<ref>/integrations/warehouse/overview`. 2. Open `/project/<ref>/integrations/warehouse/overview` while a table is backfilling. Confirm it has a pulsing amber status dot and does not show “Caught up”. 3. Once the table is live, confirm it has a green “Live” status dot and its lag appears normally. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added clearer Warehouse setup progress messaging with a “View progress” action while setup is running. - Connection details are shown once the Warehouse is provisioned or has live tables. - Added a Cancel action when editing changed Warehouse table selections. - Updated table statuses with live, syncing, and warning indicators, including animated syncing states. - Lag details are displayed for live tables when available. - Renamed the Warehouse connection option to “Analytical endpoint.” - **Style** - Improved Warehouse management controls and table name readability. - Removed the table Size column from the Warehouse overview. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
509c797be1 |
fix(studio): keep Explorer Home tab selected (#50684)
## Problem Selecting Explorer's Home tab immediately redirects back to the last visited tab. ## Solution Clear the saved Explorer destination before navigating Home. Explorer owns this behavior through a generic `onTabChange` callback on the shared tabs component. ## Review instructions 1. Open Explorer with the Home tab visible, then open a query, notebook, or chat. 2. Click Home. Confirm it stays selected and the previous tab remains open. 3. Switch back to the previous tab, then use Tab and arrow keys to select Home. Confirm it stays selected. 4. Select a content tab, leave Explorer, and return. Confirm the last visited tab still restores. ## Validation Mouse and keyboard regression tests and existing restoration tests pass (12 tests). Typecheck, targeted lint, and formatting checks pass. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md). - Docs authoring checks: not applicable; no docs changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Explorer navigation now clears the previously saved Explorer destination when returning to the home tab. * Returning to Explorer home works consistently through both mouse and keyboard navigation. * **Tests** * Added coverage for Explorer tab navigation, history cleanup, and selected-tab state. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a31ca2bad0 |
fix(ui): make brand text readable across themes (#49871)
## What kind of change does this PR introduce? Bug fix and design-system update. Resolves DEPR-316. Follow-up rename (`text-brand` → `text-primary`) is in a dedicated PR (https://github.com/supabase/supabase/pull/50564) stacked on this one. ## What is the current behavior? `text-brand` resolves to the canonical bright brand green in places that need readable text, which fails WCAG AA on light surfaces. A separate `text-brand-display` token adds another green for large type. ## What is the new behavior? - `text-brand` maps to accessible `--primary` (light mode darkened to meet ~4.5:1 AA) - `--hue` / `--primary-hue` aligned to 157.5 - `text-brand-display` removed; former display callsites use `text-brand` - Bright fills/borders stay on `brand-default` - Design-system colour and typography docs updated | Before | After | | --- | --- | | <img width="514" height="112" alt="CleanShot 2026-09-02 at 11 13 09@2x" src="https://github.com/user-attachments/assets/4e0138a9-a32d-4e4c-a426-90736706e1e7" /> | <img width="512" height="138" alt="CleanShot 2026-09-21 at 11 42 05@2x" src="https://github.com/user-attachments/assets/164cc5b1-a0c5-4e93-95f1-80016641a114" /> | | <img width="864" height="266" alt="CleanShot 2026-09-02 at 11 13 53@2x" src="https://github.com/user-attachments/assets/3c1ca53f-bf9e-431e-bc15-816b4a275b8e" /> | <img width="882" height="248" alt="CleanShot 2026-09-21 at 11 41 37@2x" src="https://github.com/user-attachments/assets/24828e7b-ed6b-44cb-b9dc-becc3398bdfc" /> | | <img width="782" height="692" alt="CleanShot 2026-09-02 at 11 16 30@2x" src="https://github.com/user-attachments/assets/fc871977-77bc-47fb-9e0e-9284e0ecd5cc" /> | <img width="730" height="690" alt="CleanShot 2026-09-21 at 11 42 52@2x" src="https://github.com/user-attachments/assets/bf479515-d5f9-471e-b82d-f097c0f4b56c" /> | | <img width="480" height="306" alt="CleanShot 2026-09-02 at 11 18 53@2x" src="https://github.com/user-attachments/assets/03f341f4-f02e-44f8-a2b2-8c31670d0427" /> | <img width="470" height="300" alt="CleanShot 2026-09-21 at 11 43 19@2x" src="https://github.com/user-attachments/assets/9df18217-d5e6-48b8-ba0b-579d2664b94b" /> | | <img width="960" height="300" alt="CleanShot 2026-09-02 at 11 32 04@2x" src="https://github.com/user-attachments/assets/6b1d9373-7a71-4247-81ff-26441604b09d" /> | <img width="980" height="306" alt="CleanShot 2026-09-21 at 11 44 13@2x" src="https://github.com/user-attachments/assets/41ad4784-02ec-4b29-b860-32af9fa79aa8" /> | | <img width="924" height="214" alt="CleanShot 2026-09-02 at 11 34 44@2x" src="https://github.com/user-attachments/assets/1de661fe-c7b6-499b-a94f-e4737436ec79" /> | <img width="752" height="162" alt="CleanShot 2026-09-21 at 11 44 56@2x" src="https://github.com/user-attachments/assets/1811890f-0660-4445-84e9-447720954fa1" /> | ## To test Test each callsite **in light mode** (dark mode is largely unchanged). ### WWW - [Homepage](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/): “Scale to millions” uses readable brand text (display token is gone) - [Careers](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/careers): small “Careers” eyebrow readable; green dividers stay bright `brand-default` - [Contact](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/contact-us): email / policy links use readable brand text - [Regions](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/regions): “Ask about early access to BYOC” readable ### Docs - [Docs homepage](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs): “DOCS” wordmark and resource links readable - [Database overview](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/guides/database/overview): nav / footer brand links readable - [JavaScript reference](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/reference/javascript/introduction): active sidebar treatment readable ### Design system - [Typography](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/typography): documents `text-brand` only (no display) - [Colour usage](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/color-usage): `text-brand` vs `bg-brand-default` - [Design-system homepage](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/): brand text examples across themes ### Studio - [Auth providers](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/auth/providers): enabled provider badge text readable; status dot stays bright - [Database policies](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/database/policies?new=true): template hover text more legible - [Database connections](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/observability/connections): “Live” status readable; animated dot stays bright green --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
5b50701c11 |
fix(studio): surface link to Explorer start-page preference (#50670)
## Summary * Added a persistent "Preferences" link (with Settings icon) pinned to the bottom of the Explorer sidebar's root navigation * Links to `/account/me#dashboard`, the existing Account settings anchor that contains the Explorer startup preference dropdown * Restructured sidebar layout to keep the footer link pinned while content scrolls, addressing [FE-4437](https://linear.app/supabase/issue/FE-4437/give-higher-visibility-to-changing-explorer-start-page-preference) * The Home tab disappears when "SQL query" is selected as the start page, so this visible link ensures users can always find and change their preference ## Test plan - [X] Typecheck passes on `apps/studio/components/layouts/ExplorerLayout/ExplorerNavHome.tsx` - [X] ESLint passes on the changed file - [X] Manual verification of sidebar behavior and link functionality Fixes [FE-4437](https://linear.app/supabase/issue/FE-4437/give-higher-visibility-to-changing-explorer-start-page-preference): "Give higher visibility to changing Explorer start page preference" <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a fixed **Preferences** link to the Explorer navigation footer. - **UI Improvements** - Updated Explorer navigation layout so resource links and recently updated items scroll independently from the footer. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6bec90a744 |
docs: unpublish Multigres Public Alpha docs (#50662)
## I have read the CONTRIBUTING.md file. YES ## What kind of change does this PR introduce? Revert. Removes the Multigres Public Alpha docs section that was published in #49020. Linear: MUL-1621 (follow-up to MUL-452). ## What is the current behavior? - Overview guide live at `/docs/guides/database/multigres` - Compatibility stub live at `/docs/guides/database/multigres/compatibility` - Database sidebar has a Multigres section - Features table lists Database / Multigres / `public alpha` - Database "What you get" cards render for Multigres ## What is the new behavior? Clean revert of #49020: overview and compatibility pages removed, sidebar entry removed, features table row removed, "What you get" cards removed. The unrelated `ContentListings` optional-`href` support this PR introduced is also reverted since nothing else uses it yet. Docs go back up once Sugu gives the go-ahead to re-publish (tracked in MUL-1621). ## Additional context - `pnpm --filter docs exec vitest run lib/content-listings.test.ts` — 20 passed <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Removed Multigres documentation, navigation links, feature listings, and related references. - Updated the JavaScript client library link in the getting-started guide. - Corrected the High Availability badge’s “Read more” link. - **Content Listings** - Content listing entries now require links and consistently render as linked items. - Non-linked listing items are no longer displayed as static content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
6fab3bd789 |
fix(studio): keep sharp out of the self-hosted standalone build (#50658)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (self-hosted Studio image packaging). ## What is the current behavior? Since the Next 16.3.5 bump, the self-hosted `next build` (`output: 'standalone'`) traces Next's optional `sharp` dependency into `.next/standalone`. Next 16.3.5 upgraded `@vercel/nft` (vercel/next.js#93979), so tracing now follows `module-sync` export conditions, and Next only excludes sharp from the trace when it detects Vercel. Effects: - The self-hosted standalone output carries the `sharp` and `@img/*` native binaries, roughly 10 to 20 percent of the image. - The slim-services Studio image fails: it loads every `.node` file eagerly, and sharp's binary segfaults on linux/amd64 without the matching libvips shared library. `apps/studio` does not depend on `sharp` directly. The last Studio image without sharp in the trace was `2026.09.14`. ## What is the new behavior? Single-file change to `apps/studio/next.config.ts`. When `NEXT_PUBLIC_IS_PLATFORM` is not `'true'`: - `images.unoptimized: true`, so `next/image` renders plain `<img>` and the server 404s `/_next/image` before sharp is ever loaded. This matches what the TanStack build already does via `compat/next/image.tsx`. - `outputFileTracingExcludes` drops `**/node_modules/sharp/**` and `**/node_modules/@img/**` from the standalone trace. Hosted Studio is unchanged: `unoptimized` stays `false`, the exclude key is omitted, and image optimization keeps running on Vercel. Self-hosted CSP is `frame-ancestors 'none'` only, so loading remote avatars directly instead of through `/_next/image` does not hit a CSP rule. Also hoists the existing `isPlatform` const from `redirects()` to module scope. **Why the globs start with `../../`.** Studio builds with Turbopack, which resolves `outputFileTracingExcludes` relative to the app directory. A plain `**/node_modules/sharp/**` becomes `apps/studio/**/node_modules/sharp/**` and never matches the pnpm store hoisted to the monorepo root. Each leading `../` moves the glob root up one level (`relativize_glob` in Next's `crates/next-core/src/util.rs`), so `../../` anchors the pattern at the repo root. The webpack path applies the same globs unprefixed for the server trace, so this is Turbopack-specific. ## Additional context Considered and rejected: a Next.js issue. Next intentionally ships sharp for self-hosted `next start` image optimization and intentionally excludes it only on Vercel. Opting out per app is the supported path. Test plan: - CI: typecheck, lint, Prettier, Studio unit tests, Studio Docker Build. - Verified on this PR with a temporary step in the Studio Docker Build workflow that ran `find` inside the production image for `node_modules/sharp*` and `node_modules/@img*` files. It failed on the first commit (globs rooted at `apps/studio`, image still contained `@img/colour`) and passed once the globs were anchored at the repo root. The step was removed before merge. - Hosted preview should still serve optimized images from `/_next/image`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01SZHcgqB2qNqCvWsFJ9Qvo8 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved configuration handling for platform and self-hosted deployments. * Self-hosted builds now avoid bundling unnecessary image-processing binaries, while platform deployments retain image optimization support. * Clarified configuration comments. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> |
||
|
|
d6ca0e5900 |
feat(studio): migrate API reports to OTEL (#50638)
## Problem The API Gateway and Data API observability reports still send legacy BigQuery SQL to the logs.all endpoint. The Data API shared-report hook also hardcodes logs.all, so the otelReports flag cannot move that report to ClickHouse. ## Fix - Add the ClickHouse requests-by-country query needed by API Gateway. - Select API Gateway SQL and endpoint atomically from otelReports. - Route the Data API PostgREST report through the existing tested OTEL API query builders and logs.all.otel. - Wait for ConfigCat before the Data API sends a request, avoiding an initial legacy request while the flag loads. - Keep logs.all behavior when the flag is disabled and leave other shared reports unchanged. ## How to test 1. Enable otelReports and open API Gateway, then confirm its report requests use logs.all.otel. 2. Open Data API and confirm all report requests use logs.all.otel with a request.path filter for /rest. 3. Change the date range, add a filter, and refresh each report. 4. Disable otelReports and confirm both reports use logs.all. All OTEL query shapes were tested individually against logs.all.otel. The focused query suite and lint pass locally. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - API reports can use OpenTelemetry data when enabled. - Added country-level request reporting, excluding requests without country information. - Added OpenTelemetry-backed PostgREST reports and Storage cache hit/miss metrics. - **Improvements** - Reports wait for required configuration before loading data. - Refreshing reports consistently refetches active metrics. - Improved error handling for analytics query failures. - Improved report accuracy with numeric time buckets and more precise attribute filtering. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6965ce133c |
Ensure horizontal scrollbar is visible for unified logs raw json panel (#50661)
### Context Just adds a `overflow-x` to ensure that the horizontal scrollbar is visible for the unified logs raw json panel when viewing a single log as per demo: (Can verify on staging/prod that it doesn't show up unless you scroll all the way to the bottom for a very long raw json) https://github.com/user-attachments/assets/e580fe2e-e7d9-4928-9335-fe957da0405a <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Style** - Improved horizontal visibility for content in the Raw JSON display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cb21b89899 |
feat: make feature previews easier to discover (#50086)
## What kind of change does this PR introduce? Feature previews are only discoverable if you already know to look for the "Feature previews" item under the account profile dropdown. There's no way to find or toggle them from Cmd+K. Fixes: [FE-4305](https://linear.app/supabase/issue/FE-4305/make-feature-previews-easier-to-discover). ## What is the new behavior? - Adds a "Feature previews..." command to Cmd+K that opens a drill-down page listing all available previews, grouped by category (mirroring the existing settings modal's grouping via a new shared useVisibleFeaturePreviewsByCategory hook, so the two can't drift apart). - Each preview can be toggled on/off directly from the list, with a "New" badge for new previews and a "Default" badge + hint for previews that can no longer be turned off. - Each preview also has a hidden "View details" command (surfaces via search) that opens the full settings modal to that preview's description/discussion link. ## Heads up for reviewers/testing Enabling a feature preview only navigates to its page when you're already within a project route in the URL (`/project/<ref>/...`). In the preview environment, there’s no project in scope, so enabling the feature still works and updates the flag, but it won't navigate to the feature's project-specific page. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added feature preview pages and actions to the command menu. - Feature previews are organized by category for easier browsing. - Enabling a preview with a dedicated page takes you directly to that page. - Preview activation and deactivation now provide status notifications. - **Bug Fixes** - Preview toggles and project navigation no longer unexpectedly return users to the root command menu. - Only relevant, available previews are shown based on the current environment. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7d3e8fa5a3 |
feat(studio): migrate Storage report to OTEL (#50519)
## Problem
The Storage observability report still sends legacy BigQuery SQL to the
`logs.all` analytics endpoint, so it cannot use the ClickHouse-backed
OTEL logs path.
## Fix
Add ClickHouse query variants for the API and cache metrics used by the
Storage report, and switch SQL plus endpoint together behind
`otelReports`. Keep legacy behavior when the flag is disabled and
prevent requests until feature flags have resolved on platform.
Tested by checking the preview AND running all queries in log explorer
one by one ✅
## How to test
- Run `CI=1 pnpm --filter studio exec vitest run
components/interfaces/Reports/Reports.constants.otel.test.ts
data/reports/storage-report-query.test.tsx`
- Enable `otelReports`, open Project > Observability > Storage, and
verify all charts load.
- Expected result: Storage analytics requests use `logs.all.otel` with
ClickHouse SQL; no legacy request is sent during flag hydration.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Reports now support OpenTelemetry-based querying for API and storage
metrics.
* Report filters provide safer numeric comparisons and improved route,
status, timing, traffic, and cache metrics.
* **Bug Fixes**
* Reports now wait for reporting configuration and the project reference
to be ready before querying.
* Invalid numeric filters are safely ignored, and cache-status
calculations are more reliable.
* **Tests**
* Added coverage for OpenTelemetry report queries, filtering,
aggregations, caching, and project readiness.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
8422045b86 |
chore: Use @supabase/config for the code configuration page (#50398)
How to test: 1. Connect a project to GH repo 2. Deploy the `config.toml` once 3. Change some setting in Auth 4. You should see a change in `/dashboard/project/_/settings/code-configuration` <img width="1271" height="1186" alt="Screenshot 2026-09-16 at 16 26 39" src="https://github.com/user-attachments/assets/dfc135a4-e495-489e-88fd-b760383793b4" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Configuration drift comparisons now use a consistent project configuration schema. - Drift details display complete current-environment and `config.toml` values, grouped by section. - Matching and unmanaged settings are organized into dedicated sections. - Configuration fields link directly to relevant Studio settings. - Added a warning that GitHub deployments overwrite local changes. - **Bug Fixes** - Configuration updates now refresh project configuration data automatically. - Improved labels and formatting for boolean and redirect URL values. - Drift errors identify invalid configuration paths and provide corrective guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
be9c67a761 |
fix: warn that resetting the DB password affects pooler and read replicas (#50649)
## What kind of change does this PR introduce? Fixes: [FE-3607](https://linear.app/supabase/issue/FE-3607/re-proper-ui-warning-when-changing-db-password). ## What is the current behavior? `ResetDbPasswordDialog` (the "Reset database password" dialog, reachable from Database Settings and the Connect sheet) only validates password strength. It has no warning about what actually happens when the password changes: the same password is shared across the direct connection, the pooler, read replicas, and third-party integrations (Warehouse, ORMs, backend services) that have it configured. Resetting it silently breaks any of those still using the old value. ## What is the new behavior? Adds an `Admonition` warning inside the shared `ResetDbPasswordDialog` component explaining that the pooler, read replicas, and any app/ORM/tool using the old password will be disconnected. Added to the shared dialog itself (not the Database Settings page wrapper) so both places it's embedded, the Database Settings page and the Connect sheet's direct-connection step, get the warning automatically. ## Additional context No behavior change to the reset flow itself, copy-only addition. No new tests added since this doesn't introduce new logic/branches. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Added a warning to the database password reset dialog explaining that the password is shared across all connection methods. - Clarified that resetting the password disconnects the pooler, read replicas, and applications, ORMs, or tools using the previous password. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ce683aa0e3 |
Recovery Codes: improve code format (#50646)
## Problem 1. Recovery are displayed as returned by the backend <img width="516" height="347" alt="image" src="https://github.com/user-attachments/assets/c2599858-a65d-42d4-af3f-6bc738a810e1" /> 2. Recovery codes are not displayed even if present when more than 1 MFA is set up ## Solution 1. Format them as uppercased groups of 4 characters <img width="541" height="394" alt="image" src="https://github.com/user-attachments/assets/74c6b4eb-03c1-4de2-a772-b30ec4d7bb52" /> 3. Fix the condition check to display recovery codes ## How to test - Generate or regenerate your recovery codes: check the format is correct - If you haven't already, add a 2nd MFA: check recovery codes are still displayed <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Recovery codes are now displayed in uppercase with clear hyphen-separated groups. - Copied recovery codes use the same formatted presentation for easier sharing and entry. - The recovery codes section is available whenever recovery codes are enabled, regardless of the number of authenticator apps configured. - Codes that do not match the expected format remain unchanged. - **Tests** - Added coverage to verify consistent recovery code formatting and clipboard behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3669fef749 |
Fix tooltip a11y comment (#50640)
## Problem The tooltip comment we have about removing the `aria-describedby` attribute to avoid screen readers reading the same text twice is wrong. ## Solution Make it clear why we do that so that future devs don't remove it. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility** * Clarified accessibility guidance for tooltips and screen-reader labels across code blocks, database controls, function editors, hooks, and table actions. * **Documentation** * Updated internal comments to more clearly explain why duplicate tooltip text is avoided for screen readers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5bdfb8743c |
fix(telemetry): give warehouse_disabled the same schema and table counts as warehouse_enabled (#50643)
<!-- ccr-slack-attribution --> _Requested by **Pam Chia** · [Slack thread](https://supabase.slack.com/archives/C076KTY11DF/p1789979663384919?thread_ts=1789953229.116889&cid=C076KTY11DF)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (telemetry). ## What is the current behavior? **Before:** Disabling Warehouse fires `warehouse_disabled` with no properties at all, while enabling it fires `warehouse_enabled` with `schemaTargetCount` and `tableTargetCount`. Disables can be counted, but nothing says how much was being replicated when the user turned it off, so churn cannot be segmented by the size or shape of the setup being torn down. ## What is the new behavior? **After:** `warehouse_disabled` carries `schemaTargetCount` and `tableTargetCount` with exactly the same meaning they have on `warehouse_enabled`: schemas replicated in full, and tables replicated individually on top of those. A disable of a project replicating one whole schema plus two loose tables now reports one schema target and two table targets, so enable and disable volume line up on the same two properties. ## Additional context **How:** The counts are read once, when the user confirms the dialog, and held in a ref until the mutation succeeds. The setup mutation's own `onSuccess` invalidates the setup-status and replication-sources queries and awaits those refetches before the caller's callback runs, so anything read inside `onSuccess` already reflects the post-disable state and would report nothing replicated. The event is tracked from that hook-level `onSuccess` rather than a `mutateAsync` callback: the status refetch swaps the Disable card out of the panel, and mutate-level callbacks are skipped once the component has unmounted. The shape is reproduced from the `supabase_warehouse` publication through the same helpers the table picker uses — the publication's tables become a selection, and that selection is mapped back to targets against the project's selectable schemas. Counting distinct schemas and tables off the replicated-table list instead would put a different meaning behind the same property names: a fully covered schema would be counted as its individual tables rather than as one schema target, and the two events would no longer be comparable. Both properties are optional. The replicated-table list is assembled from four queries, and when they have not resolved the properties are omitted rather than sent as `0`, so "unknown" is never recorded as "nothing was replicated". Tests: unit tests for the extracted `buildSchemasWithTables` helper, and a component test that drives the disable dialog against a publication covering one schema in full plus one table from another. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_0197pGnhiAkhiiYiRxY3qVFY --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com> |
||
|
|
aaa1b8c0df |
fix(ui): fail copyToClipboard when the Clipboard API is unavailable (#50641)
<!-- ccr-slack-attribution --> _Requested by **Pam Chia** · [Slack thread](https://supabase.slack.com/archives/C076KTY11DF/p1789979683276099?thread_ts=1789953317.522459&cid=C076KTY11DF)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? **Before:** `copyToClipboard` writes text with `navigator.clipboard?.writeText(text)`. When `navigator.clipboard` is undefined — an insecure context, such as self-hosted Studio served over plain http or Studio reached over a LAN IP, where `ClipboardItem` is also undefined so the Safari branch above is skipped — the optional chaining makes the whole expression resolve to `undefined`. Nothing throws, so the `catch` never runs and the success callback on the next line runs anyway. The caller is told the copy succeeded: the UI shows its "Copied!" confirmation state and the copy-tracking telemetry event fires as a successful copy, even though nothing reached the clipboard. That contradicts the documented contract of those events, which are defined as firing only when the clipboard write succeeded. ## What is the new behavior? **After:** the missing-clipboard case fails instead of silently succeeding. The callback does not run, no copy event fires, and the error toast that the function already shows on failure (`Unable to copy to clipboard`) is what the user sees. Every working path behaves exactly as before, including the Safari `ClipboardItem` branch, which is untouched. ## Additional context How: throw when `navigator.clipboard` is missing, inside the `try` block that already exists, so the case lands in the existing `catch` and its error toast rather than falling through to the success path. The now-redundant optional chaining on the write is dropped. One case was added to the existing shared clipboard util tests asserting that the callback does not fire and the error toast shows when the Clipboard API is unavailable; it fails on `master` and passes with this change. Linear: [GROWTH-1261](https://linear.app/supabase/issue/GROWTH-1261/clipboard-copy-helper-reports-success-when-the-clipboard-api-is) --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01QdJB22CngN3tpc7Kfdpram Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
ad30c04e0e |
Persist last visited explorer tab (#50557)
## Context Saves the last visited explorer tab via `useDashboardHistory`, such that landing back on `/explorer` will open the last visited page. Similar behaviour to Table Editor and SQL Editor Would also be useful when going between the SQL Editor and Explorer to bring snippets over <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Explorer now remembers and restores the last visited query, chat, or notebook tab. * Automatically returns to the Explorer home screen when a saved tab is unavailable. * Displays a loading state while the last visited tab is being restored. * **Bug Fixes** * Closing deleted chat tabs now clears their saved history. * **Tests** * Added coverage for Explorer tab restoration, loading states, and stale history cleanup. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f8257f2146 |
Decouple DataTableInfinite from unified logs (#50498)
## Context
No visual changes - just refactoring to decouple DataTableInfinite from
unified logs so that we can reuse the DataTableInfinite component in
other places. Note that we're only decoupling the table - not the side
menu stuffs
- Removes depedency on `QuerySearchParamsType` from unified logs in
`DataTableProvider.tsx`
- Remove unnecessary `searchParamsParser`
- Was feeding a dead `useQueryState('live')` in `DataTableRow` that
never used its return value
Am planning to revisit the audit logs UI subsequently as i realised its
current state makes it hard to find things for debugging
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Bug Fixes**
- Improved error messaging in data tables, including a clearer “Failed
to retrieve logs” message when log retrieval fails.
- Standardized default error messaging for other data-loading failures.
- **Improvements**
- Enhanced compatibility for asynchronous table filters and search
parameters without changing existing user workflows.
- Preserved existing filtering and live data behavior while improving
table reliability.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
d276f75c89 |
Recovery codes: allow users to use recovery codes to access their account (#50569)
## What kind of change does this PR introduce? Allow users to sign in using a recovery code after being redirected to the MFA verification page. ## Additional context <img width="435" height="373" alt="image" src="https://github.com/user-attachments/assets/968fd15e-3081-4aa2-b645-4e0d2ec2637c" /> <img width="494" height="404" alt="image" src="https://github.com/user-attachments/assets/fd7cee49-dca7-4f1a-873a-293e21c68faa" /> ## How to test - Enable MFA on your account if needed - Generate recovery codes if needed (make sure you actually saved the recovery codes somewhere) - Sign out - Sign in and when redirected to the MFA verification page, click the _Authenticate using a recovery code_ link - Enter one recovery code Check that: - you're signed in - when on [your account security page](https://studio-staging-git-gildasgarcia-auth-1624-dashb-177251-supabase.vercel.app/dashboard/account/security), you have one less code available Then: - Disable the `enableAuthRecoveryCodes` config cat flag - Sign out - Sign in and wait on the MFA verification page Check that: - the _Authenticate using a recovery code_ link is not displayed - Accessing [the recovery code sign in page](https://studio-staging-git-gildasgarcia-auth-1624-dashb-177251-supabase.vercel.app/dashboard/sign-in-recovery-code) redirects you to the MFA page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added recovery-code authentication as an alternative MFA sign-in method. * Added a dedicated recovery-code sign-in page with validation, visibility controls, cancellation, and sign-out options. * Added a link from the MFA sign-in screen when recovery codes are available. * Added loading and error states while checking recovery-code availability. * **Bug Fixes** * Prevented valid recovery-code sign-ins from being redirected back to the MFA prompt. * Limited recovery-code settings to accounts with exactly one enrolled authenticator. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
ced974e073 | docs(pipelines): Align and streamline replication guides (#49252) | ||
|
|
512201dcd0 |
chore(ui): remove the Classic Dark theme (#50387)
## What kind of change does this PR introduce? Chore. ## What is the current behaviour? Classic Dark remains available across the shared theme library and several apps. Studio now supports System, Dark, and Light as its theme modes, but still carries compatibility paths for Classic Dark. ## What is the new behaviour? - Removes Classic Dark from shared theme options, application commands, stylesheets, previews, examples, and replay handling. - Deletes the Classic Dark and faux Classic Dark stylesheets. - Removes the now-unused Classic Dark branches from Studio theme colour controls. - Migrates `classic-dark` to `dark` so first rendered frame renders Dark (not Light) | After | | --- | | <img width="1458" height="1778" alt="CleanShot 2026-09-18 at 11 07 40@2x" src="https://github.com/user-attachments/assets/679bf87f-a3c1-4599-ad2f-292d98d0b856" /> | ## To test 1. In Studio, open Account Preferences → Appearance. Confirm the available themes are System, Dark, and Light, and that theme colour controls still work in each resolved mode. 2. Set the `theme` local storage value to `classic-dark`, then reload Studio. Confirm it renders as Dark immediately and the stored value becomes `dark`. 3. Open the theme switcher in Design System, Learn, and UI Library. Confirm Classic Dark is no longer available and Light, Dark, and System still apply correctly. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Changes** * Removed the Classic Dark theme option from theme menus and settings across the application. * Classic Dark selections are automatically migrated to the standard Dark theme. * Updated theme documentation and demonstrations to list only System, Light, and Dark. * Removed Classic Dark styling and preview support; existing Dark, Light, and System themes remain available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8511f92314 |
feat(studio): show table WAL retention headroom (#50499)
## What kind of change does this PR introduce? Feature ## What is the current behavior? Replicated table rows show their temporary sync slot's pending bytes, WAL risk, and last check-in, but omit the amount of WAL retention remaining. ## What is the new behavior? Replicated table rows include the temporary slot's WAL retention headroom alongside the existing sync details. Finite values use a compact byte value, an explicit unlimited value is labelled `Unlimited WAL retention`, and absent values remain omitted. | After | | --- | | <img width="1862" height="966" alt="CleanShot 2026-09-17 at 15 11 26@2x" src="https://github.com/user-attachments/assets/8475bc8a-792c-46fc-b776-1ea20b7dfb89" /> | ## To test 1. Open `/project/<ref>/database/replication/<pipeline-id>` for a BigQuery pipeline while at least one table is completing its initial sync (or was just restarted). 2. Find that table under **Replicated tables**. 3. Confirm its **Details** cell reads in this order when all values are available: `720 MB waiting to sync · 1.3 GB WAL retention remaining · Last check-in 2 min`. 4. Confirm a temporary slot with unlimited retention shows `Unlimited WAL retention`, and a missing retention value adds no placeholder. 5. Confirm WAL warnings such as `Some changes at risk` or `Some changes lost` still appear alongside the retention value. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Replication status now displays remaining WAL retention. - Shows unlimited retention when applicable or presents finite capacity in a readable format. - Reports when retention is exhausted and changes may be at risk. - **Bug Fixes** - Invalid retention values no longer produce misleading WAL retention messages. - Replication pipeline status more clearly identifies conditions where changes may be at risk due to limited or exhausted retention. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
62c5a224d0 |
productize and cleanup
- clean up a lot of slop comments - condense files for the actual studio - make the extension feel like a product - log and fixings to be able to make it a real extension |
||
|
|
2a75ff7ae6 |
chore: Disable turbopack cache for builds (#50616)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved build reliability by disabling Turbopack’s on-disk build cache. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
02231d52ab |
Connect local dev work to production
I was surprised that we had no way have connecting local studio work to a product org and projects. So people are working with a lot of faked data, and wasting cycles. Sentry has modes for running only the frontend so this work was inspired by that, and theor chrome extension to support developers working locally. https://github.com/getsentry/sentry/blob/master/AGENTS.md?utm_source=chatgpt.com#frontend-development-commands https://github.com/getsentry/cookie-sync/blob/main/README.md This was some opinionated vibe coding to be clear. But I think it could help save a lot of Supabase developers a lot of time, and develop against real data. THis could be pointed at staging or any hosted supabase as well. |
||
|
|
3a11d78c6f |
Revert source-map disable from #50579 (re-enable Sentry source maps for studio) (#50581)
<!-- ccr-slack-attribution --> _Requested by **Ali Waseem** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1789738618897549?thread_ts=1789738618.897549&cid=C0161K73J1J)_ **Before:** #50579 disabled Sentry source-map generation and upload for `apps/studio` (`sourcemaps: { disable: true }` in `apps/studio/next.config.ts`), as a same-day attempt to fix Vercel Preview builds OOMing during compilation. **After:** Sentry source maps are re-enabled for `apps/studio` by removing that option, restoring the file to its exact pre-#50579 state for this line. Disabling source maps turned out not to fix the OOM issue after all — builds still hung. The actual fix was switching Vercel to Elastic Build Machines (an infrastructure setting, not a code change), which brought build times down to ~4 minutes. Since source maps are valuable for Sentry crash visibility and are no longer needed to work around the OOM, this PR re-enables them. Note on scope: `output: 'standalone'` in `apps/studio/next.config.ts` is left untouched by this PR. It was removed and then re-added within #50579 itself (net no change on merge), and it remains present (`output: 'standalone'`) on the current default branch HEAD. Any further discussion about removing `output: 'standalone'` (raised separately in the Slack thread) is intentionally out of scope here. This is a minimal, surgical revert of only the sourcemaps-disable line from #50579 — it does not touch #50578 (an unrelated Next.js/dependency version bump) or any other change. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01UqvBiopu7KUqAkQNvEnkoJ --- _Generated by [Claude Code](https://claude.ai/code/session_01UqvBiopu7KUqAkQNvEnkoJ)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
823d4d0991 |
build: disable sentry source maps for deployment test (#50579)
## Problem Next.js deployments can stall after compilation while Sentry performs post-compile source-map processing. We need a controlled deployment test to isolate that phase. ## Fix Disable Sentry source-map generation and upload for Studio, Docs, and WWW without changing Sentry logging, dependencies, or other build configuration. ## How to test - Deploy Preview builds for Studio, Docs, and WWW. - Confirm each build passes the post-compile phase. - Expected result: the builds complete without running Sentry source-map processing. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated production build configuration to use the default output mode. * Continued disabling source map handling in production. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
45a80b5685 |
fix(studio): price nano compute at the micro rate in restore to new project (#50546)
Restore to new project showed $0 Additional Monthly Compute for nano projects on paid plans, because the cost estimate hardcoded nano and pico to $0 regardless of plan. It now prices them at the micro rate on paid plans, matching how they're billed (and how Disk Management already displays them). Fixes FE-4427 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Corrected monthly pricing estimates when restoring a project with pico or nano compute sizes on paid plans. - Free plans continue to show no compute charge. - Pricing for micro and small compute sizes remains calculated using their expected rates. - **Tests** - Added coverage for compute pricing across free and paid plans and multiple instance sizes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d72a29852c |
fix(studio): reject custom log time ranges outside the Date range (#50539)
Typing a 9-digit amount into the logs date picker's custom field built a "Last N days" helper that subtracted past the representable `Date` range, so `toISOString()` threw `RangeError: Invalid time value` while rendering the helper list — crashing both Unified Logs and Logs Explorer. `parseCustomInput` now rejects those amounts, so oversized input behaves like any other invalid input (empty helper list) instead of producing a helper that throws. Fixes FE-4426 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Logs date filters now reject excessively large day values outside the supported date range. - Invalid date inputs no longer generate unusable date filter options. - The date picker now displays guidance when an invalid custom format produces no matching options. - **Tests** - Added coverage for out-of-range values and confirmed valid large date ranges continue to work correctly. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
4bb36b944f |
feat(studio): let High Compliance projects opt-in to Assistant data access (#50548)
Orgs with the HIPAA add-on had the Assistant's opt-in level forced to `disabled` on any project marked High Compliance, regardless of what the org picked in its AI settings. The restriction predated our AI provider BAAs. The consequence is those users see the Assistant failing to answer questions about their data w/ no clear path how to fix it, even though the LLM provider supports this use case. This PR removes these Assistant restrictions on the server and client so those projects honor the org's chosen level. Braintrust conversation tracing is unchanged and still blocked for these projects, see [this test case](https://github.com/supabase/supabase/blob/b9800ccf16/apps/studio/lib/ai/braintrust-logger.test.ts#L16-L20). See [comments](https://linear.app/supabase/issue/AI-1153/allow-hipaa-orgs-to-opt-in-to-assistant-data-access-for-high#comment-485a0d46) for legal approval and conditions. The client-side changes enable features like "Debug with AI" on SQL query failures, “Generate/Rename with AI” for snippet titles, and generated Assistant chat titles for these customers. The AI opt-in copy now adds a reminder to obtain consent from data subjects, linking the [shared responsibility model](https://supabase.com/docs/guides/deployment/shared-responsibility-model) based also on [this comment](https://linear.app/supabase/issue/AI-1153/allow-hipaa-orgs-to-opt-in-to-assistant-data-access-for-high#comment-f81ee610). <img width="400" alt="CleanShot 2026-09-17 at 5 01 02 PM@2x" src="https://github.com/user-attachments/assets/d02123f2-3e32-4d83-9f98-7d15e59222ef" /> To test with a HIPAA-enabled project in staging, you can use this [Plan Change [Staging]](https://app.hex.tech/supabase/app/Plan-Change-Staging-032BD32jo1EaisCS85qunf/latest) Hex to add the HIPAA add-on. Once the add-on is present, you can turn on High Compliance from a project's settings. Also in org settings, crank up the Assistant data opt-in level and verify the Assistant is able to answer questions about the project's data. My results testing with opt-in level "Schema, Logs & Database Data": | High compliance setting | Data opt-in working | |--------|--------| | <img width="1302" height="422" alt="CleanShot 2026-09-17 at 5 03 36 PM@2x" src="https://github.com/user-attachments/assets/c416371b-2eb8-49df-9c07-6d8eababb443" /> | <img width="1566" height="1516" alt="CleanShot 2026-09-17 at 5 05 14 PM@2x" src="https://github.com/user-attachments/assets/39624355-7f8f-46ce-9f08-a8acfb9da830" /> | Closes AI-1153 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features - AI-assisted query renaming, snippet title generation, debugging, and tools now follow organization AI opt-in settings rather than project HIPAA status. - Debugging assistance and AI actions remain available for eligible users without additional HIPAA-based blocking. - AI metadata warnings consistently show standard opt-in messaging and permission settings. - AI settings remind users to obtain consent before entering personal data and link to shared responsibility guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
ef527f447a |
chore(studio): enable Sentry build diagnostics (#50474)
## Problem Studio Vercel builds can stall after compilation inside the Sentry production compile hook. Sentry currently suppresses its build output, so the deployment log does not show which operation stalls. ## Change Enable Sentry build diagnostics for Studio platform builds on Vercel by setting silent to false and debug to true. Source-map generation, upload behavior, and runtime reporting remain unchanged. ## How to test - Deploy this branch to the Studio Vercel project. - Inspect the log after Next.js compilation completes. - Confirm that Sentry reports its post-compile progress and exposes the operation that stalls or fails. The diagnostic build may still time out; this change is intended to reveal the cause before applying a workaround. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Chores** - Enabled additional diagnostic logging for platform builds to improve visibility into build-time error monitoring configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
47a532eef7 |
feat(studio): add copy path and copy link row actions (#50480)
| | PR | Base | Branch | | --- | --- | --- | --- | | 1 | #50476 | `master` | pre-existing correctness fixes | | 2 | #50413 | `fix/storage-explorer-listing-and-scroll` | `?path`/`?preview` deep-linking | | 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link test | | 4 | **this PR** | `test/storage-deep-link-e2e` | copy path / copy link row actions | To read the whole change in one view: ```bash git diff master...feat/storage-copy-row-actions -- apps/studio e2e ``` ## What is the new behavior? Both row menus now offer two actions: - **Copy relative path** — the bucket-relative object key, i.e. what `storage.from(bucket)` takes - **Copy link** — the dashboard URL that reopens the item in the explorer **Copy path to folder** is replaced by **Copy relative path**. It produces the same value for a folder and now works for files too, so nothing is lost. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Storage Explorer now provides separate actions to copy a relative path or a direct link for files and folders. * Copied links open the relevant storage location, including folder navigation and file preview details. * Success notifications appear after clipboard copying completes. * **Tests** * Added coverage for file and folder copy actions, generated paths and links, URL encoding, and clipboard behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
cdbe2963fa |
Add DownloadResultsButton to explorer query editor (#50563)
## Context Adds the `DownloadResultsButton` component to the footer of the explorer's query editor - will show up in notebook + query tab <img width="1147" height="907" alt="image" src="https://github.com/user-attachments/assets/141278a8-1e00-424e-84ec-8ddb7cf0a96b" /> <img width="1152" height="913" alt="image" src="https://github.com/user-attachments/assets/0e4a48b0-ebc3-473e-8bc0-19ab633e1904" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a results footer displaying row counts and optional row limits. - Added download and export actions when query results are available. - Standardized the results footer across query and notebook previews. - Added keyboard shortcut hints to export options when shortcuts are enabled. - **Improvements** - Export actions now support read-only result sets without changing displayed output. - Export menu sizing and shortcut labels adapt to the enabled shortcut configuration. - Improved accessibility with a label for refreshing logs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d9cfdcd741 |
feat(studio): deep-link folders and files in the storage explorer (#50413)
| | PR | Base | Branch | | --- | --- | --- | --- | | 1 | #50476 | `master` | pre-existing correctness fixes | | 2 | **this PR** | `fix/storage-explorer-listing-and-scroll` | `?path`/`?preview` deep-linking | | 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link test | | 4 | #50480 | `test/storage-deep-link-e2e` | copy path / copy link row actions | ## What is the current behavior? The file explorer doesn't keep track of folder navigation. Files and folders paths aren't shareable ## What is the new behavior? With this PR: - nav state is stored via params - "path" to store folder path (if nested folder paths) - "preview" to store the selected filename - back/forward nav history - file url opens correct folder/file [https://github.com/user-attachments/assets/](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[0cfb7fcc-2c6e](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[528d5c1d-a1b9](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[-](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[4f5a-950d](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[4061-9b67](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[-](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[060c8eb2027b](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[a41dd98716e0](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0) ## Steps to review - Open bucket in Storage File Explorer - navigate between files and folders and notice url params change - reload page, it should reopen where you left off - hitting back/forward on the browser history should follow file/folder navigation history --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
45381bf857 |
Double clicking items in explorer nav should persist their tabs (#50558)
## Context As per PR title - this behaviour exists in the Table Editor and SQL Editor but was just missing in the Explorer <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Double-click chats or notebooks in the Explorer to pin their tabs as permanent. * Pin recent chats and notebooks directly from the Home view. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
252f69e451 |
chore(studio): refine Explorer sidebar, onboarding, and notebooks (#50555)
## Summary A round of small Explorer refinements. **Sidebar** - Adds a **Run SQL** row (with a `+` icon) above Notebooks in the Explorer sidebar; opens a new query tab. **Assistant** - Assistant query cells now have the same **Save** dropdown as query tabs (add to an existing notebook or create a new one). It shows only when Explorer is enabled, and not while the query is still streaming. - `SaveQueryDropdown` takes an optional `source`, so logs queries are saved as log cells (keeping their time range) instead of database cells. This also fixes saving logs queries from query tabs. - The "Drafting notebook..." notice (and the notebook loading/status rows) now span the full message width; `delete_notebook` parts use the wide layout like create/update. **Onboarding** - Replaces the single page with a four-step walkthrough: Welcome to Explorer (with a **Preview** badge), Run SQL, Notebooks, and Chat with your project. Each step has an icon, heading, and short description, with step dots and **Skip** / **Back** / **Next** buttons; the last step ends with **Continue to Explorer**. - Removes the "Choose how Explorer opens" choice (still available in Account preferences) and the collapsible "Learn more" section. Skipping or finishing still respects the saved startup preference. - Deletes `ExplorerOnboardingLearnMore`, `ExplorerHomePreference`, and `ExplorerHomePreview`, which were only used by onboarding. **Notebooks** - Query cells use the same max width as markdown cells (`48rem`, was `72rem`). - "Add query cell" / "Add markdown cell" are now **Add query** / **Add markdown** everywhere; the buttons at the bottom of a notebook are larger (34px, 18px icons). ## Test plan - [ ] Explorer sidebar: **Run SQL** opens a new query tab - [ ] Assistant: generate SQL, use **Save** to add it to a new and an existing notebook; repeat with a logs query and confirm a log cell is created - [ ] Assistant: ask for a notebook and confirm the drafting notice is full width - [ ] Clear `hasCompletedOnboarding` in Explorer preferences and step through onboarding (Next / Back / Skip); finishing or skipping respects the startup preference set in Account preferences - [ ] Notebook: query cells line up with markdown cell width; bottom add buttons are larger <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a **Run SQL** shortcut to Explorer navigation. - Assistant query results can now be saved to notebooks, including log queries. - **Improvements** - Updated Explorer onboarding with guided steps, progress navigation, and visual previews. - Shortened Explorer action labels and refined control sizing. - Reduced notebook query layout width and adjusted assistant notebook displays. - **Changes** - Removed the Explorer startup preference selector and onboarding “Learn more” section. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
501666e504 |
Explorer home chat to present a Run SQL secondary action if value is detected to be a SQL query (#50560)
## Context We previously introduced a behaviour for the explorer home tab's chat form to run a SQL Query if the input is detected to be a SQL query. Adjusting it to shift that behaviour into a secondary action instead <img width="740" height="210" alt="image" src="https://github.com/user-attachments/assets/d4b1fec1-f38c-426f-8108-b50ead1a61ca" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * SQL statements entered in Explorer can be run directly with a dedicated “Run SQL” action. * Assistant forms support context-specific submit icons, labels, tooltips, and accessibility text. * **Bug Fixes** * Improved SQL detection for multi-statement queries. * Prevented mixed SQL and conversational text from being treated as executable SQL. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
edec85d1ca |
fix(pipelines): Make pipeline actions and status updates reliable (#50085)
## Summary Make pipeline actions and status feedback reliable while requests are running or fail. Let the backend coordinate table resets and restarts, keep stopped pipelines stopped after resets or settings changes, and refresh the UI from confirmed backend state. ## Pipeline actions and recovery - Reset one table, all errored tables, or all tables through the rollback endpoint without separate frontend stop/start requests. Explain which destination data is deleted, which rows are copied again, initial sync charges, and the skip-initial-sync setting. - Keep pending feedback until the action and a fresh status read finish, including across navigation and polling errors. Prevent overlapping actions and disable start/stop controls when status is unavailable or transitioning. - Close the creation form once the pipeline is created. If its initial start fails, users can retry Start on the existing pipeline without creating a duplicate. - Wait for confirmed shutdown before deletion; a shutdown error or timeout leaves deletion retryable. Keep failed version updates open and avoid reporting success. - Clarify recovery guidance and pending labels, suppress duplicate error toasts, and hide stale table errors during transitions. ## Status updates and shared UI - Poll pipeline status and table metrics one second after each response, share in-flight reads, pause dashboard polling in background tabs, and respect rate-limit backoff. The shutdown waiter continues in the background. - Refresh metadata after mutations even when an older read is in flight, while preserving shared polling requests. Refresh affected data after failures that may follow a committed reset or settings change. - Move pending request state into the shared, project-keyed `DatabaseLayout` so the list, detail page, and diagram stay consistent. The surrounding database-page changes update named imports in both Next.js and TanStack routes. - Simplify action, status, and form rendering; announce status changes to assistive technology; and sort table statuses without mutating cached data. --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
64ab76262e | feat(studio): exhaustion banner links to metrics (#50276) |