mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
08c4f64c42e79df8a84b35cb3818f7f3835a66ea
37533
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
08c4f64c42 |
test(sql-editor): add mock-free hook tests (Step 4) (#48214)
## What Step 4 of the SQL editor testability plan: **mock-free hook tests** for the extracted SQL editor hooks, built on the Step 3 renderHook harness (`tests/lib/sql-editor-test-utils.tsx`) — in-memory editor port + real valtio stores + MSW. **Zero `vi.mock`.** | File | Tests | Covers | |------|-------|--------| | `useSqlEditorExecution.test.tsx` | 8 | destructive-query gating (`potentialIssues` vs. forced run), auto-limit suffixing, connection-string → `x-connection-encrypted` header, `onSuccess`/`onError` session-store writes, error-line highlight, diff-open short-circuit | | `useSqlEditorAi.test.tsx` | 7 | one-shot diff-request drain (empty vs. non-empty editor), drain-exactly-once across remounts, accept/discard diff, `onDebug` opening the assistant chat + debug prompt | | `usePrettifyQuery.test.tsx` | 2 | in-place format + write-back, diff-open no-op | | `useSnippetIdentity.test.tsx` | 2 | generated identity + store-driven loading state | | `useSnippetTitleGenerator.test.tsx` | 2 | untitled-snippet naming via the title endpoint | Every test exercises real dependencies at the seam where they're real: network via MSW, stores used real and reset per test, Monaco via the in-memory editor port. ## Test plan - [x] `pnpm test:studio -- SQLEditor` → **286/286 passing** (21 new tests included) - [x] `pnpm --filter studio typecheck` clean - [x] Confirmed zero `vi.mock` in the new files <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added comprehensive automated coverage for SQL query formatting, snippet identity, and AI-generated titles. * Added coverage for AI-assisted SQL editing, including diff acceptance, rejection, debugging, and request handling. * Added coverage for query execution, result persistence, safety checks, replica selection, error highlighting, and diff-state behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
359974d071 |
fix(docs) Fix local broken links (#48212)
Closes DOCS-1202 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem We have broken local links in docs. I ran locally tests that crawl through all of our docs and flags broken local links. ## Solution This PR fixes local links where they were errored. The report I generated had false-positives, so there are fewer fixes than initially thought. ## Preview checklist Docs preview: https://docs-git-docs-fix-broken-local-links-supabase.vercel.app WWW preview (redirects): https://zone-www-dot-com-git-docs-fix-broken-local-links-supabase.vercel.app | Page | Live (broken) | Preview (fixed) | Where to look | | --- | --- | --- | --- | | Amazon Bedrock | [Live](https://supabase.com/docs/guides/ai/integrations/amazon-bedrock) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/ai/integrations/amazon-bedrock) | **You'll also need** → `A Postgres database with the pgvector extension` | | Getting started | [Live](https://supabase.com/docs/guides/getting-started) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/getting-started) | Tutorial cards → **Expo React Native Social Auth** | | Product security | [Live](https://supabase.com/docs/guides/security/product-security) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/security/product-security) | **Database** list → `Superuser access and unsupported operations` | | OAuth flows | [Live](https://supabase.com/docs/guides/auth/oauth-server/oauth-flows) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/auth/oauth-server/oauth-flows) | End of page, before **Next steps** → `OAuth methods in supabase-js` | | ElevenLabs TTS | [Live](https://supabase.com/docs/guides/functions/examples/elevenlabs-generate-speech-stream) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/functions/examples/elevenlabs-generate-speech-stream) | **Dependencies** → ElevenLabs `JavaScript SDK` | | ElevenLabs STT | [Live](https://supabase.com/docs/guides/functions/examples/elevenlabs-transcribe-speech) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/functions/examples/elevenlabs-transcribe-speech) | **Dependencies** → ElevenLabs `JavaScript SDK` | | Realtime error codes | [Live](https://supabase.com/docs/guides/realtime/error_codes) | [Preview](https://docs-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/realtime/error_codes) | `RealtimeDisabledForTenant` → reference link | | Expo social auth redirect (legacy) | [Live](https://supabase.com/docs/guides/with-expo-social-auth) | [Preview](https://zone-www-dot-com-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/with-expo-social-auth) | Should land on the Expo social auth quickstart | | Expo social auth redirect (old tutorials path) | [Live](https://supabase.com/docs/guides/getting-started/tutorials/with-expo-social-auth) | [Preview](https://zone-www-dot-com-git-docs-fix-broken-local-links-supabase.vercel.app/docs/guides/getting-started/tutorials/with-expo-social-auth) | Should land on the Expo social auth quickstart | ### Manual testing 1. For each row, open the **Live** link and find the linked text in **Where to look**. 2. Click the link and confirm it 404s or lands on the wrong page. 3. Open the matching **Preview** link, find the same linked text, and click it. 4. Confirm the preview link resolves to the correct destination: - Amazon Bedrock → `/docs/guides/database/extensions/pgvector` - Getting started → `/docs/guides/auth/quickstarts/with-expo-react-native-social-auth` - Product security → `/docs/guides/database/postgres/roles-superuser` - OAuth flows → `/docs/reference/javascript/auth-admin-oauth-server` - ElevenLabs TTS / STT → `https://github.com/elevenlabs/elevenlabs-js` - Realtime error codes → `/docs/guides/troubleshooting/realtime-project-suspended-for-exceeding-quotas` - Redirect rows → `/docs/guides/auth/quickstarts/with-expo-react-native-social-auth` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated links for pgvector, OAuth, ElevenLabs SDK, and database security guidance. * Corrected the Expo React Native social authentication tutorial link. * Updated Realtime troubleshooting references to the current documentation path. * **Bug Fixes** * Fixed redirects for Expo social authentication guides so legacy URLs reach the correct quickstart. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
25658ab733 |
chore(lint): ignore dist build output in shared ESLint config (#48216)
Follow-up to #48202. The shared ESLint flat config only globally ignored `.next`, `public`, and `.contentlayer`, so with the TanStack Start migration, Studio's Vite build output in `dist/` was getting linted too — making `pnpm --filter studio run lint:ratchet` (and regular lint) far slower than it should be. ESLint flat config doesn't respect `.gitignore`, so being gitignored didn't help. **Changed:** - Added `dist` to the global `ignores` in `eslint-config-supabase/next` (applies to all apps extending the shared config) ## To test - In `apps/studio` (with a `dist/` folder present from a TanStack build), run `npx eslint dist/server/server.js` — it should report "File ignored because of a matching ignore pattern" - `pnpm --filter studio run lint:ratchet` no longer spends time linting `dist/**` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated linting exclusions to ignore generated build output and static asset directories. * Generalized related configuration documentation for clarity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
ca2a390a3d |
fix(docs): restore Supabase env vars to stop crash on every page load (#48213)
https://github.com/user-attachments/assets/0b9e4bd1-e2b6-4a58-b47e-803e2b34a32e ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Every page in `apps/docs` crashes at runtime with `Error: supabaseUrl is required.` Regression from #46757, which flipped `NEXT_PUBLIC_IS_PLATFORM` to `"true"` in `apps/docs/.env.development` and, in the same diff, duplicated a `NEXT_PUBLIC_MARKETPLACE_API_URL`/`NEXT_PUBLIC_MARKETPLACE_PUBLISHABLE_KEY` block where `NEXT_PUBLIC_SUPABASE_URL`/`NEXT_PUBLIC_SUPABASE_ANON_KEY` should have been. With `IS_PLATFORM` now `true`, `Feedback.tsx` (rendered on every docs page) unconditionally calls `createClient()` with an undefined URL/key, throwing synchronously on every page load. Closes DOCS-1208 / FE-3980. ## What is the new behavior? - `apps/docs/.env.development`: renamed the mislabeled duplicate block back to `NEXT_PUBLIC_SUPABASE_URL`/`NEXT_PUBLIC_SUPABASE_ANON_KEY`. - `apps/docs/components/Feedback/Feedback.tsx`: widened the guard to `IS_PLATFORM && supabaseUrl && supabaseAnonKey`, mirroring the existing pattern in `app/api/ai/docs/route.ts`, so a future env misconfiguration degrades gracefully (feedback votes silently skipped) instead of crashing every page. Verified locally by running `pnpm dev:docs` with no GitHub credentials set: - No more `"supabaseUrl is required."` anywhere; the Feedback widget renders and fires its vote request instead of throwing. - A normal guide page renders fine. - `/guides/database/database-advisors` still shows its existing graceful fallback admonition. - `/guides/graphql` (federated content, absent on a clean checkout) returns a clean 404 rather than crashing — confirming the related goal of running docs dev locally without federated content already works (via #48205 + existing `notFound()` handling), no extra changes needed there. ## Additional context A related but separate gap was found in `apps/docs/app/guides/database/extensions/wrappers/[[...slug]]/page.tsx`. A new Linear issue is created: https://linear.app/supabase/issue/DOCS-1209/wrappers-guide-page-crashes-on-unhandled-github-fetch-failure-without ## Manual testing 1. Checkout branch locally and run `pnpm run dev:docs` with no GitHub credentials set. Confirm it starts without errors. 2. Open any guide page on docs locally and confirm no `supabaseUrl is required` error, and the Feedback widget renders and responds to clicks. 3. Open `/docs/guides/database/database-advisors`. Confirm it renders and does not crash. 4. Open `/docs/guides/graphql`. Confirm a clean 404, not a server error. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved feedback functionality by safely handling missing configuration. * Feedback votes and comments are skipped when the required service configuration is unavailable, preventing errors. * **Chores** * Updated documentation-site configuration to use the appropriate content service settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
ac714e81ba |
docs(tanstack): add a proper SSR quick start with cookie-based auth (#48105)
## Summary TanStack Start's quickstart only ever wired up an anonymous `supabase-js` client — no cookies, no `@supabase/ssr`, no auth. This ports the real `@supabase/ssr` client/server split and password-based auth flow (already shipped in `apps/ui-library`) into the quickstart and adds a matching tab to the SSR guide. ## Where this changed - `apps/docs/content/guides/getting-started/quickstarts/tanstack.mdx` — quickstart now installs the cookie-based auth flow via the Supabase UI Library registry and queries data through the SSR-aware server client. - `apps/docs/content/guides/auth/server-side/creating-a-client.mdx` — new TanStack Start tab (client/server setup + protecting routes). - `examples/auth/tanstack/` (new) — source files backing the `$CodeSample` snippets above, ported from `apps/ui-library`'s registry. ## Test plan - [x] Scaffolded a real TanStack Start app and ran the quickstart commands end-to-end - [x] Confirmed SSR loader + protected-route redirect work as documented - [x] `pnpm lint:mdx` and `pnpm build:guides-markdown` pass <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added TanStack Start SSR setup examples for Supabase, including browser and server client helpers with cookie-based session support. * Included a protected route example that checks authentication on the server and redirects unauthenticated users to the login page. * Added a server-side claims fetch helper for authorization checks. * **Documentation** * Expanded the “creating a client” guide with TanStack Start-specific route protection and environment variable examples. * Updated the TanStack Start quickstart to use the official CLI and refined server-side authorization guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2d5ec97df8 |
chore: split CLAUDE.md into root and studio-specific files (#48202)
Splits agent guidance into a lean monorepo-wide root file and a studio-specific file that Claude Code lazy-loads when working under `apps/studio/`. This keeps every session's baseline context small while giving studio work much richer, enforceable guidance. **Changed:** - `.claude/CLAUDE.md` — now monorepo-wide only: corrected pnpm version (10 → 11), expanded workspace table (design-system, ui-library, lite-studio, ui-patterns, api-types, pg-meta, shared-data), commands (`format`, `generate:types`, `api:codegen`), CI gates + never-hand-edit generated files, monorepo-wide conventions (incl. the named-exports rule, which lives in the shared eslint preset and applies to all six apps), and monorepo-wide skill triggers. Studio detail is replaced by a pointer to the nested file. Also corrects a long-standing error inherited from the old file: the `_Shadcn_` convention was inverted — `Button_Shadcn_` is the only suffixed export left and is rarely the right choice; primitives are unsuffixed. - `.claude/skills/studio-ui-patterns/SKILL.md` — removed the same stale `_Shadcn_` claim from the forms section (this skill also feeds CodeRabbit reviews). - `apps/studio/components/README.md` — component template now uses a named export, matching the lint-enforced convention (was the one doc still showing `export default`). - `apps/studio/TANSTACK_MIGRATION.md` — cleanup checklist gains an item to remove the migration section from `apps/studio/CLAUDE.md` when the migration finishes. - `.gitignore` — removed the blanket `CLAUDE.md` ignore rule (added in #40231 for personal local files, no longer used that way). Nested `CLAUDE.md` files are now tracked by default, so shared guidance can't silently fail to land. For *personal* notes, use `CLAUDE.local.md` (Claude Code loads it automatically alongside `CLAUDE.md`, and it's now gitignored here) — or `.git/info/exclude` if you prefer a different filename. **Added:** - `apps/studio/CLAUDE.md` — studio guidance, loaded on demand: mandatory skill routing (always load `studio-best-practices`, plus a task → skill table), TanStack Start migration rules (pages/routes mirroring, when a manual mirror is needed, never delete `pages/**` files), data-layer/state orientation, a default-to-shipping-tests-with-changes policy, and a "defaults that differ here" list (ESLint warning ratchet + local `lint:ratchet` command, `copyToClipboard` await rule, `useParams` from `common`, dayjs/sonner, `ui` vs `ui-patterns` import split, `@tanstack/react-table` over `react-data-grid`, etc.). ## Accuracy Every factual claim in both files (62 total) was verified against the code by parallel review agents instructed to refute each one. Results: 54 correct as written, 2 wrong (the inherited `_Shadcn_` inversion, and a fabricated `useExecuteSqlQuery` hook name — the real export is `useExecuteSqlMutation`), 6 imprecise (e.g. dayjs plugins load in both runtime entries, the ratchet counts occurrences regardless of severity). All fixed in this PR. ## Context cost | File | Size | When it loads | % of a 200k window | |---|---|---|---| | `.claude/CLAUDE.md` | 70 lines, ~1.2k est. tokens | every session | ~0.6% | | `apps/studio/CLAUDE.md` | 53 lines, ~1.6k est. tokens | only when touching studio files | ~0.8% | The always-loaded footprint grew only ~0.2k est. tokens vs the old 45-line file — everything studio-heavy sits behind the lazy load, so docs/www sessions pay nothing for it. Both files are well under Claude Code's large-file warning threshold (~40k chars) and the <200-line adherence guidance, with room to roughly double before it's worth worrying about. ## To test - Open a fresh Claude Code session from the repo root and read any file under `apps/studio/` — `apps/studio/CLAUDE.md` should get pulled into context automatically. - `git check-ignore apps/studio/CLAUDE.md` exits 1 (not ignored); `git check-ignore CLAUDE.local.md` exits 0 (ignored). - Skim both files — every claim has been code-verified (see Accuracy above), but a human sanity pass on the *judgment* calls (what's included/omitted) is welcome. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Refreshed monorepo onboarding conventions with updated tooling requirements, expanded inventory, standardized common scripts, and clearer CI gating and checks. * Added/updated Studio contributor guidance, including the TanStack Start migration rules and Studio development/testing/UI conventions. * Updated Studio component documentation to use named exports. * Refreshed the “Forms” UI pattern guidance and adjusted the referenced UI primitives. * **Chores** * Updated ignore rules so the primary top-level onboarding document is tracked. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
6d7c3361dc |
fix(studio): hide support access toggle when no project is selected (#48206)
## Summary Support access is granted per-project, but the "Allow support access" toggle stayed visible and submittable even when "No specific project" was selected. This hides the toggle and forces `allowSupportAccess`/`allow_support_access` to `false` in that case, across the standalone support form, sidebar form, and link-ticket form. Addresses [FE-3979](https://linear.app/supabase/issue/FE-3979/support-form-allows-support-access-without-a-project-selected). ## Test plan - [x] Added/updated unit tests in `SupportFormPage.test.tsx` covering toggle visibility and submitted payload when no project is selected - [x] `pnpm vitest run components/interfaces/Support` passes (48 tests) - [x] Typecheck and lint pass on changed files <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Support access is now offered only when a valid project and eligible support category are selected. * Support access is automatically disabled when no specific project is selected. * Form submissions now prevent unsupported support-access requests from being enabled. * **Tests** * Added coverage for project clearing and scenarios without available projects or organizations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4d793a708e |
test(sql-editor): shared renderHook harness with in-memory editor port (#48209)
## Summary - Add `renderSqlEditorHook()` test harness that eliminates mocking Monaco by injecting a real, deterministic in-memory editor port (EditorController/DiffController backed by plain JS state) - Include `createInMemoryEditor()`, `resetSqlEditorStores()`, and `setupSqlEditorMocks()` utilities to provide isolation and mock-free network testing via MSW handlers - Export `CustomWrapper` from custom-render and add optional `editor`/`diff` injection points to SQLEditorProvider (production unaffected via null-coalesce fallback) This is **Step 3** of an in-progress SQL editor testability refactor (Step 2 finished EditorController/DiffController port; this harness has no consumers yet — hook tests land in a follow-up step). ## Test plan - [x] `pnpm --filter studio typecheck` passes (already verified) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added reusable SQL Editor test utilities for in-memory editing, selections, error highlighting, snippets, and diff content. * Added helpers for resetting editor state, configuring API mocks, and rendering SQL Editor hooks in a complete test environment. * Enabled SQL Editor providers to accept optional controller overrides for isolated testing. * Exported the shared test wrapper for reuse across test suites. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2c72847fa6 | docs: add new non-dictionary words to rule003 (#48207) | ||
|
|
90a53a5ee2 |
feat(studio): add shadcn tweet to sign-in testimonials (#48204)
## What kind of change does this PR introduce? Chore ## What is the current behavior? Sign-in testimonials are drawn from the weighted tweet pool in `packages/shared-data/tweets.ts`. shadcn's quote is not included. Resolves [FE-3978](https://linear.app/supabase/issue/FE-3978/add-shadcn-tweet-to-sign-in-page). ## What is the new behavior? Adds [@shadcn](https://x.com/shadcn/status/1672913636132790272)'s tweet ("Supabase is really good. ⚡") with weight `10`, plus the profile image under `twitter-profiles`. ## Additional context Weighted selection on the Studio sign-in page and `topTweets` on www both pick this up from the shared list. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated tweet module documentation to explain how tweet `weight` impacts Studio sign-in weighted random selection and the `topTweets` list (top 18 by weight). * **New Content** * Added a new tweet to the collection with an explicit `weight` of 10, making it eligible for weighted selection and top-ranked inclusion. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e19cd1863d |
feat(studio): connect logo contract for authorize (#48161)
## What kind of change does this PR introduce? Feature + docs. Closes [DEPR-604](https://linear.app/supabase/issue/DEPR-604/define-connect-logo-asset-and-variant-contract). ## What is the current behavior? `/authorize` logo resolution trusted self-asserted requester `name` (and similar) for curated MCP marks, fell back to a letter tile when there was no usable icon, and always used theme-reactive tile chrome. This includes the scenario when pairing against unclassified uploaded OAuth app bitmaps. ## What is the new behavior? - [Documents the Connect logo asset/variant contract](https://design-system-git-danny-depr-604-connect-logo-contract-supabase.vercel.app/design-system/docs/ui-patterns/connect-interstitials#logos) (default to light, keep pairs matched, no theme-recolour of vendor SVGs). - Resolves curated partner logos from allowlisted `redirect_uri` hosts only (`claude.ai` / `anthropic.com`, `cursor.com` / `cursor.sh`, `chatgpt.com` / `openai.com`, `perplexity.ai`). - Unknown / missing / failed requester icons show `SupabaseLogo` alone (no letter tile). - Uploaded organisation OAuth app icons (unclassified bitmaps) pair with fixed light tile chrome (`border-black/10 bg-white` / `SupabaseLogo forceLight`) on both sides across Studio themes. - Curated partners keep theme-reactive tiles and may use dark assets when available. ### To test Real MCP clients (Claude, Cursor, etc.) only send users to **production** `/authorize`, so you cannot drive a local or preview Studio build from those tools. Use a Network override instead: 1. Start Studio and sign in (`pnpm dev:studio`, or use the Vercel preview once available). 2. Open `/dashboard/authorize?auth_id=foo` (any `auth_id` is fine — the real response may 404). 3. DevTools → **Network** → find `GET …/platform/oauth/authorizations/foo` (or whatever id you used). 4. Right-click → **Override content** (enable Local Overrides / pick a folder if prompted). 5. Paste one of the payloads below (status **200**), save, then reload the authorize page. 6. Keep `expires_at` in the future so the request does not look expired. The fields that matter for this PR are `name`, `icon`, and `redirect_uri`. #### Curated pair (allowlisted redirect) Expect Cursor mark + Supabase pair. Toggle light/dark: curated dark assets may swap; tiles stay theme-reactive (`bg-surface-75`). ```json { "name": "Cursor", "website": "https://cursor.com", "icon": null, "domain": "cursor.com", "redirect_uri": "https://cursor.com/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "dynamic" } ``` #### Unknown → Supabase alone Expect Supabase bolt alone. No letter tile. No curated mark even if `name` says Claude. ```json { "name": "Acme", "website": "https://acme.example", "icon": null, "domain": "acme.example", "redirect_uri": "https://acme.example/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "dynamic" } ``` #### Spoofed trusted name, non-allowlisted redirect (logo only) Expect Supabase alone (no Claude mark). This PR does **not** show the impersonation caution (that is coming in #48162). ```json { "name": "Claude", "website": "https://claude.ai", "icon": null, "domain": "claude.ai", "redirect_uri": "https://evil.com/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "dynamic" } ``` #### Uploaded OAuth app icon → forced-light pair Expect remote icon + Supabase pair with forced-light tiles (`border-black/10 bg-white`) on both sides in light and dark Studio themes. The icon URL below is the checked-in solid-colour Acme bitmap on this branch. ```json { "name": "Acme", "website": "https://acme.example", "icon": "https://raw.githubusercontent.com/supabase/supabase/danny/depr-604-connect-logo-contract/apps/design-system/public/img/icons/acme-oauth-icon.png", "domain": "acme.example", "redirect_uri": "https://acme.example/callback", "expires_at": "2099-01-01T00:00:00.000Z", "scopes": ["organizations:read", "projects:read"], "approved_at": null, "registration_type": "static" } ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved authorization interstitial branding with trusted requester logos and safer fallback behavior. * Added support for consistent light-theme treatment of uploaded OAuth app icons. * Added examples and documentation for unknown requesters, uploaded logos, and wrong-account states. * **Bug Fixes** * Prevented unverified or unavailable requester icons from being presented as trusted. * Ensured logo pairing remains visually consistent across light and dark themes. * **Tests** * Added coverage for trusted-host validation, fallback branding, icon loading failures, and theme behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
c8aca8d3a0 |
chore(design-system): standardise keyboard focus rings (#41575)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? UI / design-system consistency (accessibility). ## What is the current behavior? Keyboard focus rings are inconsistent across Studio and `packages/ui`: - Custom Button uses thick `outline` with per-variant colours (brand / grey / destructive / warning) - Form controls use muted grey rings (`ring-background-control`) - Tabs / NavMenu / Radio use soft brand `ring-ring` - Studio `.inset-focus` uses dark green `outline-brand-600` Related: [DEPR-354](https://linear.app/supabase/issue/DEPR-354). ## What is the new behavior? One shared focus recipe, exposed as Tailwind `@utility` classes in `packages/config/css/utilities.css`: | Utility | Use when | | --- | --- | | `focus-ring` | Buttons, inputs, most controls (offset ring) | | `focus-inset` | Dense/flush surfaces such as interactive table rows (renamed from `inset-focus`) | ```txt # focus-ring outline-hidden focus-visible:ring-2 focus-visible:ring-ring focus-visible:ring-offset-2 focus-visible:ring-offset-background ``` Applied on Button, shadcn form controls, Menu/NavMenu, Command palette trigger, Studio table rows, and related call sites. Documented in the design-system accessibility docs. Variants do not change focus ring colour. When the ring must appear on a different element than the focused one (e.g. Menu + ProductMenu `Link` via `group-focus-visible`, or InputGroup via `:has()`), keep an explicit ring stack. The utilities bake in `:focus-visible` on the same element. ## Additional context **Out of scope** - Full `packages/ui` / Studio / www sweep - Legacy Studio form-group green box-shadow cleanup - ESLint rule for bare `outline-none` ## Test plan Prefer Safari (“hard mode” for `tabIndex`). Expect one soft brand ring everywhere: not grey, not solid green outline. ### Design system - [ ] [Accessibility](https://design-system-git-dnywh-choreimprove-tab-focus-styles-supabase.vercel.app/design-system/docs/accessibility): recipe docs match what you see - [ ] [Button](https://design-system-git-dnywh-choreimprove-tab-focus-styles-supabase.vercel.app/design-system/docs/components/button): Tab primary / default / danger; same ring colour - [ ] [Table → Row-level navigation](https://design-system-git-dnywh-choreimprove-tab-focus-styles-supabase.vercel.app/design-system/docs/components/table#row-level-navigation): Tab an interactive row; inset outline (`focus-inset`) sits inside the row ### Studio - [ ] **Org home → table view** (`/organizations/_` or org projects): switch to the table layout, Tab onto a project row; inset outline sits inside the row (list/card view uses CardButton, not `focus-inset`) - [ ] **Project sidebar** (Database, Auth, Storage, …): Tab the main product nav links; ring follows the focused item (not the nested section menus like Tables / Roles) - [ ] **Storage → Files**: Tab a bucket row; same inset outline as org table rows - [ ] **Project Settings → General** (or Compute and Disk): Tab through inputs, checkboxes, switches, selects; same offset ring, no ring on mouse click - [ ] **Header ⌘K** (desktop width): Tab to the search control after Feedback; same soft brand `focus-ring` (was a thicker `ring-border-strong` before) - [ ] **Table Editor or SQL Editor tabs**: focus a tab, Tab to × if active; close shows a ring - [ ] **Light + dark**: ring stays visible against both backgrounds |
||
|
|
71410b187a | build: do not run federated content and markdown pipeline on dev (#48205) | ||
|
|
0fe2366659 |
[FE-3790] fix(studio): hide Multigres from user-facing surfaces (#48191)
Hides the "Multigres" term from user-facing surfaces — it's the tech powering High Availability projects, but "High Availability" is the only term users should see for now (per Slack discussion with Saxon/Ivan). **Changed:** - High Availability badge hover card (project overview) no longer says "Driven by Multigres" - Project creation HA toggle description drops the Multigres name + multigres.com link, keeps the informational copy - All schema dropdowns now hide the `multigres` schema on HA projects, by wiring in the previously-unused `filterSchemasForHighAvailability` helper: - `SchemaSelector` (shared — Table Editor, Functions, Indexes, Triggers, Schema Visualizer, etc.) - `ExposedSchemaSelector` (API settings → exposed schemas) - `EnableExtensionModal`, `CreateIndexSidePanel`, `ForeignKeySelector`, `WrapperTableEditor`, Integrations install sheet `AdvancedSettings` - SQL editor schema autocomplete (`useAddDefinitions`) - Schema list computations in the touched components are now memoized (incl. stabilizing `SchemaSelector`'s `excludedSchemas` default so the memo actually holds) **Added:** - Unit tests for `filterSchemasForHighAvailability` / `resolveHighAvailability` - MSW component test for `SchemaSelector` asserting `multigres` is hidden on HA projects and still shown on non-HA projects The filter is HA-gated on purpose: a self-hosted/non-HA user with their own schema named `multigres` still sees it. The flag-gated Multigres option in Logs is intentionally untouched — that exposure is kept for the Multigres team's debugging (separate track). ## To test - On an HA project (`high_availability: true`): hover the High Availability badge on project overview — no "Multigres" mention; open schema dropdowns in Table Editor / Database pages / SQL editor autocomplete — no `multigres` schema - Project creation with HA entitlement: toggle description has no Multigres wording/link - On a non-HA project: schema dropdowns behave as before <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Made schema dropdowns and related selectors high-availability aware across extensions, indexes, integrations, SQL editing, API exposed schemas, and relationship editors. * Updated project high-availability UI text and badge hover description to remove outdated branding and clarify horizontally scalable Postgres architecture. * **Tests** * Added coverage to ensure the schema “multigres” option is hidden/shown correctly based on high availability, and validated high-availability value handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
9ea3919fb5 |
fix(studio): show column format in sort/filter type labels (#48201)
## What kind of change does this PR introduce? Bug fix ## What is the current behavior? Table editor sort (and filter) column pickers show `USER-DEFINED` for extension types such as PostGIS `geography`, because they use `dataType` from pg-meta. | Before | | --- | | <img width="549" height="196" alt="CleanShot 2026-07-22 at 11 32 44" src="https://github.com/user-attachments/assets/9ba2dec8-f5a3-479f-81c8-2dd133f6d419" /> | ## What is the new behavior? Those pickers use the same display helper as column headers (`getColumnFormat`), so labels match the header (e.g. `geography`, `int4[]`). ## Test plan In SQL Editor: ```sql create extension if not exists postgis with schema extensions; create table public.geography_sort_repro ( id bigint generated always as identity primary key, location extensions.geography(point, 4326), tags text[] ); ``` Then open `geography_sort_repro` in the Table Editor → Sort → pick `location` / `tags`. Confirm labels are `geography` and `text[]` (not `USER-DEFINED` / `_text`). Same check in the Filter column picker. Cleanup: `drop table public.geography_sort_repro;` ## Additional context `data_type` is intentionally coarse for non-`pg_catalog` types in pg-meta; `format` already carries the real type name. Arrays need `getColumnFormat` so `_int4` becomes `int4[]`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved column type labels in filter and sort menus by displaying the appropriate format instead of raw data types. * Preserved existing JSON-field restrictions and tooltips while improving the clarity of displayed column information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
badf16be07 |
[FE-3909] fix(studio): exclude generated columns from row insert form (#48195)
Inserting a row through the table editor failed on any table with a `GENERATED ALWAYS AS (...) STORED` column — the row editor sent an explicit value for the generated column (e.g. `false` for booleans, since the bool `Select` never hits the empty-string default heuristic from #46826), which Postgres rejects with `428C9: cannot insert a non-DEFAULT value into column`. **Changed:** - `RowField` now carries `isGenerated` (from pg-meta's `is_generated`, previously unused by Studio) - Generated columns are hidden from the row editor form (they're always computed by the database, so there's nothing to input) but stay in `rowFields` state so primary-key identifier logic is unaffected - `generateRowObjectFromFields` skips generated fields, so they're omitted from both insert and update payloads - `validateFields` skips generated fields — an error on a hidden field would be unfixable **Added:** - e2e test covering inserting a row into a table with a generated boolean column - unit tests for generated-column omission in insert/update payloads and validation ## To test 1. Create a table with a generated column: ```sql create table t ( id bigint generated by default as identity primary key, base_price int, discounted_price int, is_discounted boolean generated always as ( base_price is distinct from discounted_price ) stored ); ``` 2. Table Editor → `t` → Insert row — `is_discounted` should not appear in the form 3. Fill the other fields and save — the insert should succeed and the grid should show the computed value 4. Edit an existing row and save — should still work (generated column untouched) 5. Sanity-check a normal table with identity/default columns — clearing a default field on insert should still fall back to the default (#46826 behavior) Addresses [FE-3909](https://linear.app/supabase/issue/FE-3909/studio-insert-form-fails-on-generated-boolean-columns) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for generated columns in the table editor. * Generated columns are automatically computed and excluded from insert and update forms. * Generated values now appear correctly in the table after saving a row. * **Bug Fixes** * Prevented validation errors for non-editable generated fields. * Ensured generated columns are excluded from submitted row data. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
1144b83885 |
feat(studio): add loading and fallback states to SPA shell (#48185)
The prerendered TanStack SPA shell (`_shell.html`) had a visually empty body, so every cold load showed a blank page until the JS bundle downloaded and hydrated. This bakes proper fallback states into the shell as static HTML — none of them rely on JS executing. **Added:** - `ShellFallback` component, rendered as the `ClientOnly` fallback around the root `<Outlet />` — during the shell prerender it serializes into `_shell.html`, and on the client it unmounts the moment the app mounts (no hydration mismatch: `ClientOnly` renders the fallback on the server and first client render) - Animated `LogoLoader` (Supabase logo outline) centered on screen — the stroke-dash animation is pure CSS so it runs before any JS executes - Stuck-load help text that fades in after 7s via CSS `animation-delay` (clear cookies / reload, contact support@supabase.com — the support email is gated behind `IS_PLATFORM` so self-hosted builds don't get it) - `noscript` message for JS-disabled browsers, which also hides the loader so users don't see an infinite spinner (uses `dangerouslySetInnerHTML` so React hydration never diffs noscript children) - `data-nosnippet` on both text blocks so Google doesn't surface the boilerplate as the search snippet for dashboard URLs (the one shell serves every route) ## To test All on the Vercel preview: - Open the preview — on a cold load you should catch the animated logo loader before the app mounts (throttle to "Slow 4G" in devtools if it flashes by too fast), and it never reappears on client-side navigation - In devtools, block the JS bundle (Network tab → right-click the `/assets/index-*.js` request → Block request URL) and reload — the loader animates on its own, and the help text (clear cookies / contact support) fades in after ~7s - Disable JavaScript (devtools command palette → "Disable JavaScript") and reload — no spinner, just the "requires JavaScript" message - View page source (or `curl` any preview URL) — the body contains the logo SVG, the help text, and the noscript block, all with `data-nosnippet` on the text <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a client-aware loading shell for Studio during initialization. * Shows a branded loader with a help message that appears after a short delay. * Includes platform-specific support contact details when available. * **Bug Fixes** * Prevents partial or incomplete content from rendering before the app is ready. * Improves consistency for no-JavaScript fallback rendering to avoid hydration mismatches. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
50d7030f48 |
chore(studio): default opt-in to integrations layout (#48183)
Make the new "one-click" integrations feature preview opt-in by default so it appears for all users once we switch `marketplaceIntegrations` to _true_ and reframe the feature preview copywriting. <img width="1007" height="694" alt="Screenshot 2026-07-22 at 12 01 08" src="https://github.com/user-attachments/assets/4b35870c-dcf0-45cc-a1b5-69628e7e10b5" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a visual preview image to the integrations layout preview. * Renamed the preview to “One-Click Integrations.” * Made the preview enabled by default when the marketplace feature is enabled. * **Style** * Refreshed the preview text and updated the layout with improved spacing, border, and rounded corners. * **Documentation** * Updated the page header documentation link to the general integrations guide. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a10ebd9097 |
chore(studio): improve light mode images on featured integrations (#48179)
## What is the current behavior? featured integration image was looking muddy on light mode <img width="1479" height="792" alt="Screenshot 2026-07-16 at 16 20 29" src="https://github.com/user-attachments/assets/d51960f9-7c58-47d6-a751-e310f0edb32e" /> ## What is the new behavior? dedicated light-mode preview images <img width="1482" height="785" alt="Screenshot 2026-07-16 at 16 29 48" src="https://github.com/user-attachments/assets/5c1b9772-8ea2-4b94-aeba-cb095015df8e" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Stripe Sync Engine to the featured integrations list. * Added light-theme cover imagery for featured integrations. * Featured integration cards now display theme-aware images and improved visual overlays. * Updated the marketplace grid for improved responsive layouts across screen sizes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a132009a51 |
docs(dart): storage buckets, streaming/cache-purge, web3, OAuth grants, and July additions (#47971)
## What Updates the Dart/Flutter reference (`apps/docs/spec/supabase_dart_v2.yml`) for features shipped in [`supabase/supabase-flutter`](https://github.com/supabase/supabase-flutter) in July (through the July 17 storage CDN-cache additions). Built on the **new reference pipeline** (#47224 / #47994): each method's section is inherited from the nearest section-header entry in the YAML, and subcategory overviews are committed partials under `spec/reference/dart/v2/partials/`. `common-client-libs-sections.json` is **not** touched. Scoped to items **not** already covered by #47728 (OAuth server authorization details, custom providers admin, `explain` format, realtime `onHeartbeat` and filter examples). Rebased onto `master` now that #47994 and #47728 have landed. ## New reference entries **Storage** - Vector buckets (new **Vector Buckets** section): create/get/list/delete bucket, index create/get/list/delete/access, and vector put/get/list/query/delete (`supabase.storage.vectors`) - Analytics (Iceberg) buckets (new **Analytics Buckets** section): `createAnalyticsBucket`, `listAnalyticsBuckets`, `deleteAnalyticsBucket`, and the `analyticsCatalog()` accessor - `listPaginated` (list files v2), under File Buckets - `downloadStream()` (streaming file downloads), under File Buckets - `purgeCache()` (object CDN cache invalidation) and `purgeBucketCache()` (bucket CDN cache invalidation) **Auth** - `signInWithWeb3` - OAuth server `listGrants` and `revokeGrant` (in the **OAuth Server** section, `supabase.auth.oauth`) **Database** - `stripNulls()` modifier ## Enrichments to existing entries - Storage: `cacheNonce` on `getPublicUrl` / `createSignedUrl` / `download`; filter/sort/pagination options on `listBuckets` - Auth: `channel` on `mfa.challenge()`; `currentPassword` on `updateUser`; async `getSession()` note and example; `friendlyName` on `registerPasskey()` and `passkey.startRegistration()` - Functions: `abortSignal` on `invoke` ## Pipeline plumbing - New partials: `analytics-buckets.json`, `vector-buckets.json`, `oauth-server.json` - `generate-dart-reference.ts`: registers `analytics-buckets`, `vector-buckets`, and `oauth-server-api` group-header ids in `HEADER_IDS` so they render as section overviews rather than methods ## Source PRs supabase-flutter: #1547, #1554, #1557, #1559, #1561, #1563, #1578, #1579, #1580, #1585, #1588, #1590, #1591, #1593, #1603, #1607, #1608 ## Verification `pnpm codegen:references:dart` builds cleanly: the generator writes 141 method declarations (all ids resolve to a section, no invalid method names, no slug collisions), and the nav renders the Analytics Buckets, Vector Buckets, and OAuth Server sections with the expected methods. ## Notes - Skipped (no reference home / would need product decisions): Iceberg namespace/table management (the full `IcebergRestCatalog` API, which lives in a standalone `iceberg-js` package upstream), `dryRun`, functions exception subtypes, trace-context headers, `persistSession`, configurable postgrest timeout/retry. - `storageanalytics-from` maps to Dart's `analyticsCatalog(bucketId)` (the Iceberg catalog entry point), since Dart has no `analytics.from()` equivalent. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Expanded Dart docs with Web3 sign-in plus passkey, MFA channel, and OAuth grant listing/revocation. * Added storage APIs/examples for listing buckets with options, CDN cache bypass via `cacheNonce`, and cache/purge support. * Documented `stripNulls()` database modifier and cursor-based paginated storage listing. * **Documentation** * Updated auth references with optional `currentPassword`, `friendlyName`, and clarified `currentSession` vs `getSession()`. * Added `abortSignal` support and examples for `supabase.functions.invoke()`. * **Bug Fixes** * Improved Dart reference generation so analytics/vector bucket sections aren’t emitted as method declarations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2428bddcb5 |
chore: Bump vulnerable deps (#48178)
Fixes the following vulnerabilities: - https://github.com/supabase/supabase/security/dependabot/3963 - https://github.com/supabase/supabase/security/dependabot/3963 - https://github.com/supabase/supabase/security/dependabot/3964 - https://github.com/supabase/supabase/security/dependabot/3965 - https://github.com/supabase/supabase/security/dependabot/3966 - https://github.com/supabase/supabase/security/dependabot/3927 - https://github.com/supabase/supabase/security/dependabot/3955 - https://github.com/supabase/supabase/security/dependabot/3913 - https://github.com/supabase/supabase/security/dependabot/3972 - https://github.com/supabase/supabase/security/dependabot/3959 - https://github.com/supabase/supabase/security/dependabot/3960 - https://github.com/supabase/supabase/security/dependabot/3916 - https://github.com/supabase/supabase/security/dependabot/3918 - https://github.com/supabase/supabase/security/dependabot/3947 - https://github.com/supabase/supabase/security/dependabot/3948 - https://github.com/supabase/supabase/security/dependabot/3956 - https://github.com/supabase/supabase/security/dependabot/3957 - https://github.com/supabase/supabase/security/dependabot/3958 - https://github.com/supabase/supabase/security/dependabot/3917 - https://github.com/supabase/supabase/security/dependabot/3919 - https://github.com/supabase/supabase/security/dependabot/3970 - https://github.com/supabase/supabase/security/dependabot/3928 - https://github.com/supabase/supabase/security/dependabot/3949 - https://github.com/supabase/supabase/security/dependabot/3950 - https://github.com/supabase/supabase/security/dependabot/3973 - https://github.com/supabase/supabase/security/dependabot/3920 - https://github.com/supabase/supabase/security/dependabot/3951 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated the bundled `tar` dependency to a newer patch version for consistency and security across the workspace. * Added/adjusted overrides to pin a few transitive dependencies to specific versions. * Normalized workspace configuration formatting and made minor development configuration cleanup (no functional change). <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
31878cabf6 |
Stop re-rendering UI if live mode is off (#48188)
## Context For the Database Connections page, we run a `useEffect` every second to re-render the UI so that the timestamps of each process' duration reflects real time. However, duration should stop counting if live mode is paused as otherwise it becomes inaccurate then. Also forces an immediate refetch of the database activities when live mode is re-enabled <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved live activity updates on the Database Connections page. * Pausing live mode now stops activity timestamp updates and refreshes. * Resuming live mode immediately reloads the latest activity and updates the UI to reflect live state. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
efed6b5c6a |
chore: Server monaco editor from Cloudflare (#47973)
How to test: - Editor should load and work in the SQL Editor - Search for JS bundles `https://cdnjs.cloudflare.com/*` in the preview to verify that's it's loaded from a CDN - Check in the local build whether the Monaco editor is loaded from the base URL (have to do it locally, SQL Editor doesn't work on the self-hosted Vercel deployment) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Performance** * Improved delivery of Studio assets through CDN-based URLs in supported environments. * Updated the Monaco editor to load assets from the configured CDN when available, with a local fallback. * **Reliability** * Added support for explicitly enabling or disabling CDN asset delivery across environments. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d847c48464 |
feat: update @supabase/*-js libraries to v2.110.8 (#48156)
This PR updates @supabase/*-js libraries to version 2.110.8. **Source**: supabase-js-stable-release **Changes**: - Updated @supabase/supabase-js to 2.110.8 - Updated @supabase/auth-js to 2.110.8 - Updated @supabase/realtime-js to 2.110.8 - Updated @supabase/postgest-js to 2.110.8 - Refreshed pnpm-lock.yaml --- ## Release Notes ## v2.110.8 ## 2.110.8 (2026-07-21) ### 🩹 Fixes - **auth:** downgrade aborted/transient fetch failures from console.error to warn ([#2544](https://github.com/supabase/supabase-js/pull/2544)) - **functions:** clean up cross-signal abort listener on invoke() return ([#2487](https://github.com/supabase/supabase-js/pull/2487)) - **functions:** match response Content-Type case-insensitively ([#2515](https://github.com/supabase/supabase-js/pull/2515)) - **storage:** url-encode object key in CDN purge methods ([#2545](https://github.com/supabase/supabase-js/pull/2545)) - **supabase:** skip Node warning in Deno ([#2541](https://github.com/supabase/supabase-js/pull/2541)) ### ❤️ Thank You - Franco Kaddour @FrancoKaddour - Katerina Skroumpelou @mandarini - Pedro Henrique - Vaibhav @7ttp ## v2.110.7 ## 2.110.7 (2026-07-16) ### 🩹 Fixes - **postgrest:** correct self-reference inference ([#2525](https://github.com/supabase/supabase-js/pull/2525)) - **realtime:** trigger set auth on INITIAL_SESSION event ([#2531](https://github.com/supabase/supabase-js/pull/2531)) - **realtime:** update phoenix to fix presence issue ([#2532](https://github.com/supabase/supabase-js/pull/2532)) ### ❤️ Thank You - Eduardo Gurgel - Filipe Cabaço @filipecabaco - Vaibhav @7ttp This PR was created automatically. Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com> |
||
|
|
ffd5a93f37 |
feat(www): add hidden Legal Hub subprocessor list page (draft) (#48100)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1783431374242039?thread_ts=1783431374.242039&cid=C0161K73J1J)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature (`apps/www`). ## What is the current behavior? No public page for Supabase's subprocessor list, and no way for customers to be notified when it changes. ## What is the new behavior? A new hidden page at `/legal/customer-resources/subprocessor-list` shows the current dated subprocessor PDF and lets anyone subscribe with their name and email to receive an email whenever the list is updated. The page is `noindex` and not linked from any nav, so it's shareable by direct URL only for now. Mirrors Wiz's sub-processor-list page. **How:** - **Page** `apps/www/pages/legal/customer-resources/subprocessor-list.tsx` — pages-router, mirrors the existing Legal Hub pages (`DefaultLayout`, `NextSeo`, `PageHeader` + breadcrumb, `SectionContainer` prose). Embeds the PDF (inline preview + download link) and renders the subscribe form. Marked `NextSeo` noindex/nofollow and intentionally left unlinked. - A single `CURRENT_PDF` constant (filename + display date) is the only thing to change when Legal hands over a new dated PDF. - **Form** `apps/www/components/SubprocessorUpdatesForm.tsx` — mirrors `SecurityNewsletterForm` (First name, Last name, Email; `ui` primitives). Carries the framing copy verbatim, with **Subscribe to updates** bold and Privacy Policy linked to https://supabase.com/privacy. - **API route** `apps/www/app/api-v2/submit-form-subprocessor-updates/route.tsx` — exact mirror of `submit-form-security-newsletter`; subscribes the user to the Customer.io "Subprocessor Alerts" subscription (topic 4) via `cio_subscription_preferences.topics.topic_4: true`. - **PDF** `apps/www/public/legal/subprocessor-list/June-1-2026.pdf`. **Updating the list in future:** Drop the new dated PDF into `apps/www/public/legal/subprocessor-list/` and update the `CURRENT_PDF` constant. Nothing else changes. ## Additional context **Notes / to confirm:** - Customer.io topic id `4` → `topic_4` (per Prashant); not independently verified against Customer.io. - Draft: page is intentionally unlinked and noindex until Legal signs off. --- _Generated by [Claude Code](https://claude.ai/code/session_01D9WS2QWQ8Y3o7PqDZabS3F)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
bb811ef67e |
Joshen/fe 3972 add filter for application name (#48180)
## Context Adds supporting for filtering by application name for Database Connections <img width="592" height="325" alt="image" src="https://github.com/user-attachments/assets/e09b8d61-4215-4da4-b2aa-980cdc475738" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an **Application** filter to database activity views. * Expanded filtering to include session state, roles, and matching by activity application name. * Filter option counts are now more accurate based on the currently selected criteria. * **Bug Fixes** * Improved filter reset behavior to reliably clear application/state selections and restore role defaults. * Enhanced persistence of filter selections via URL query parameters. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d5a882c4fa |
Support click to copy PID from activity row (#48177)
## Context Very tiny one - just supports clicking to copy PID from the Activity Row in Database Connections Will be useful for diving into details of the query with the Assistant if needed <img width="323" height="120" alt="image" src="https://github.com/user-attachments/assets/b80a69eb-d1e8-49d3-93e3-08c111b3ea6e" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added the ability to click an activity process ID to copy it to the clipboard. * Added confirmation feedback after copying the process ID. * **UI Improvements** * Improved query tooltip behavior by providing a slightly longer hover delay. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cf7da58eb3 |
Add overview section for database connections (#48147)
## Context Building on top of "Database Connections" - this adds a top summary section, again from `pg_stat_activity` <img width="948" height="324" alt="image" src="https://github.com/user-attachments/assets/f4968193-0a5f-4754-a630-40685b747999" /> Each block comes with a tooltip in hopes to educate the significance of each metric - Connections: Spread of connections per database role <img width="313" height="164" alt="image" src="https://github.com/user-attachments/assets/8ceeab5d-b960-4be3-9a5b-8600bd5cf303" /> - Active queries: Rough representative of activity <img width="350" height="196" alt="image" src="https://github.com/user-attachments/assets/f9705ff1-a869-409a-86b6-50170a169674" /> - Idle in transaction: Important to identify as this indicates locks (Suggests root cause) <img width="350" height="196" alt="image" src="https://github.com/user-attachments/assets/f9705ff1-a869-409a-86b6-50170a169674" /> - Blocked queries: Also important to identify stuck queries <img width="335" height="183" alt="image" src="https://github.com/user-attachments/assets/57255fb8-24f6-4ddd-aa54-850a77173b5c" /> - Longest running query: Might be useful to identify unusually long queries - Will be `text-warning` if exceeds 30 seconds for active queries, `text-destructive` if exceeds 10 seconds for queries idle in transaction <img width="342" height="119" alt="image" src="https://github.com/user-attachments/assets/f6783b43-058a-4a32-a40c-0bc64f23d2ce" /> "Summarize activity" CTA leverages on the Assistant to give a quick overview - highlights any potential issues for quick reference <img width="1918" height="958" alt="image" src="https://github.com/user-attachments/assets/340121fe-3186-48a5-8023-fbac2a93397a" /> ## Other changes - Hides "View running queries" in SQL Editor if `topForPostgres` feature flag is enabled (since this UI is meant to replace that) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Database Connections observability overview with metric cards (connections, longest-running, active, blocked, idle-in-transaction) and an interactive “Longest running” PID selector. * Added a “Summarize activity” AI assistant dropdown that starts a timestamped, activity-aware summary chat. * **Improvements** * Enhanced live activity refresh (including window-focus updates) and standardized duration warning thresholds for active and idle-in-transaction sessions. * Improved hover details for query previews and allowed richer tooltip content for metric labels. * **Feature Changes** * Gated the “View running queries” bottom panel behind a feature flag. * **Bug Fixes** * Refined running-too-long badge and warning styling for idle-in-transaction cases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
751dcecf86 |
docs(log-drains): overhaul page style and add missing Last9 + Syslog … (#48140)
## Summary Brings the Log Drains docs up to the same standard as the Metrics API page. - Replaces the plain destination table with a visual `LogDrainDestinationCards` component — a 3-column card grid that mirrors the product UI destination picker. Cards link to anchors on the same page (no sub-pages needed since setup is simpler than Metrics). - Adds a "What you can do" intro section and a consistent "Required configuration + Steps" structure for every destination. - Adds two destinations that were missing from the docs entirely: **Last9** and **Syslog** (both are live in the product). Config fields sourced from `LogDrainDestinationSheetForm.tsx`. - Cleans up raw `<ul><li>` HTML to markdown lists. - Adds an "Additional resources" footer (pricing, Metrics API, JS SDK tracing). ## Files changed - `apps/docs/content/guides/telemetry/log-drains.mdx` — core of the changes - `apps/docs/components/LogDrainDestinationCards.tsx` — new card grid component - `apps/docs/components/LogDrainDestinationCards.data.ts` — destination data (9 entries) - `apps/docs/internals/markdown-schema/LogDrainDestinationCards.ts` — markdown fallback renderer - `apps/docs/features/docs/MdxBase.shared.tsx` — register new component - `apps/docs/internals/generate-guides-markdown.ts` — register new component ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update ## What is the current behavior? not supanice, also missing syslog and last9 <img width="619" height="687" alt="image" src="https://github.com/user-attachments/assets/58e8f07c-eb40-4d30-a5e2-3988d1af87c2" /> ## What is the new behavior? hopefully more supanice, also added syslog and last9 <img width="568" height="667" alt="image" src="https://github.com/user-attachments/assets/be61e67f-58aa-4e8c-be0d-44206f1b16de" /> ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized the Log Drains guide with destination-specific sections and a new destination chooser. * Added support and setup guidance for Last9 and Syslog destinations. * Clarified HTTP batching, JSON delivery, compression, authentication, and endpoint requirements. * Updated OpenTelemetry, Datadog, Loki, Amazon S3, Sentry, and Axiom instructions. * Added Edge Function examples covering compressed and uncompressed payloads. * Added links to pricing, Metrics API, and JavaScript tracing resources. * **UI Improvements** * Updated destination listings with clearer, consistent icons and presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
56a6ec2601 |
Add Wendie Cheung to humans.txt (#48119)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Bug fix, feature, docs update, ... ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Wendie Cheung to the team listing on the documentation site. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f55ff0e6dd |
Update copy for grace period (#48138)
## Context If an organization is exceeded usage and has the grace period banner - the current copy is really long which causes the text to truncate. <img width="1126" height="67" alt="image" src="https://github.com/user-attachments/assets/f8095dc6-540c-47e5-941a-31a4264a6017" /> Banners are meant to be short and to the point, so opting to revise the copy a little. <img width="1392" height="51" alt="image" src="https://github.com/user-attachments/assets/55596369-ee65-48cd-8616-66747e4d2590" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Copy Updates** - Clarified the grace-period message to explain that projects may be restricted from the displayed date if usage remains over quota. - Updated the available actions to include a billing link alongside “Review usage.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9199aad57e |
feat(docs) Add scaffolding and CI/CD step for Docs Playwright (#48120)
Closes DOCS-1197 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem We do not have any E2E testing established. ## Solution This PR creates an ultra-lean starting place for Docs Playwright: - A CI/CD step that skips on draft and relies on Preview for testing - One simple broken link check for one page The goal: - Playwright is implemented where we want it, with an architecture we want, with set-up steps we can build from The anti-goal of this PR: - We have meaningful tests running ## CI/CD steps <img width="1191" height="72" alt="Screenshot 2026-07-21 at 10 17 06 AM" src="https://github.com/user-attachments/assets/eeb2454c-d864-4574-a050-ce39bb3f083f" /> 1. Checkout a thin slice of the repo (`apps/docs`, `packages`, `patches`). 2. Wait for the Vercel **docs** preview for that commit SHA. 3. Use that preview URL as `PLAYWRIGHT_BASE_URL`. 4. Install Node deps and Chromium. 5. Run `pnpm run e2e:docs` (`--grep @quickstart`). 6. If anything fails, upload the HTML report + traces. Manual runs skip the Vercel wait and default to `https://supabase.com` (or whatever URL you enter), then run the full suite (`pnpm run e2e`). ## What the test checks Because this PR is scaffolding, it is doing something very basic: 1. Opens `/docs/guides/getting-started/quickstarts/nextjs` only if a connected file was edited in CI/CD step 2. Asserts the page loaded and the H1 is visible. 3. Collects docs-owned `/docs/**` links from `#sb-docs-guide-main-article`. 4. HTTP-checks each link (no full navigation) and soft-fails so every broken link is reported. Config keeps it cheap: Chromium only, 1 worker, 2 CI retries, failure screenshots/traces. ## Docs vs Studio/Dashboard The setup of Docs Playwright differs from Studio. | | Docs E2E | Studio E2E | |---|---|---| | Location |`e2e/docs/` | `e2e/studio/` | | What it tests | One published docs page + its links | Many Studio UI flows (tables, auth, storage, …) | | Where the app runs | Already-deployed **Vercel preview** | Built and started **on the runner** | | Backend needed | None | Local Supabase via Docker | | Path filtering | Native `on.pull_request.paths` (skip whole workflow) | `dorny/paths-filter` after checkout (workflow starts, heavy steps gated) | | Parallelism | 1 worker, no shards | Matrix of frameworks × 2 shards | | Retries | 2 in CI | 5 in CI | | Reports | HTML report on failure | Blob reports per shard → merge → PR comment | | Draft handling | Explicit draft skip | No draft skip today | | Manual broader run | Yes (`workflow_dispatch`) | No | The big conceptual difference: **Studio owns the environment** (build Studio, start Supabase, hit `localhost`). **Docs borrows Vercel’s preview** and only asks “does this page and its docs links work on the deployed site?” ## Docs architecture justification The docs architecture is deliberately lightweight because docs are **static, published content served by Vercel**, not an interactive app with a backend. That single fact justifies every difference: - **Borrow the Vercel preview instead of building on the runner.** The preview is already the exact artifact users will see, and Vercel builds it for free on every PR. Rebuilding docs on the runner would duplicate that work and risk testing something different from what ships. Studio, by contrast, needs a running app plus a local Supabase, so it *has* to own its environment. - **No backend.** Docs pages don't need a database or auth to render, so there's nothing to spin up. This is what keeps the job cheap enough to run per-PR. - **Native `paths` filtering.** Since the job is cheap and self-contained, an all-or-nothing skip at the workflow level is sufficient—no need for `dorny/paths-filter` to gate expensive setup steps mid-run like Studio does. - **Low parallelism and modest retries.** One page and its links is a tiny surface, so 1 worker is plenty and there's no sharding to coordinate. Retries exist only to absorb transient network flakiness against a live URL, hence 2 rather than Studio's 5 (which also cushions a heavier, stateful environment). - **Non-blocking + draft skip + manual dispatch.** As initial scaffolding checking link health on a deployed site, it should inform rather than gate merges, avoid burning minutes on drafts, and still be runnable on demand against production. In short: **Studio owns its environment because it must; docs borrows Vercel's preview because it can.** The scope is intentionally minimal today. ## Testing 1. Break a docs-owned link in the Next.js quickstart. 1. Follow README instructions to set up and run e2e docs test. 1. Confirm the suite fails. 1. Restore the broken link and re-run. 1. Confirm the suite **passes** (`1 passed`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary - **New Features** - Added a GitHub Actions workflow to run Playwright docs end-to-end tests on PRs and via manual dispatch (with optional base URL), including docs-preview waiting and concurrency cancellation. - **Documentation** - Added `e2e/docs` README with setup, how to run the suite (including UI/debug and single-spec), and how base URL selection works. - **Tests** - Added a quickstarts E2E spec that validates the page and soft-checks docs-owned links resolve. - **Chores** - Added shared Playwright configuration/package scripts and an `e2e/docs` `.gitignore` for test outputs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
b6ed55e272 |
fix(studio): restore project creation panel chrome on /new (#48171)
## What kind of change does this PR introduce? Bug fix ## What is the current behavior? Regression from #48113: the regular `/new` project creation form is missing its card border/shadow because Panel flatten classes were applied when `!isVercelIntegrationFlow`. ## What is the new behavior? Flattens Panel chrome only for the Vercel interstitial flow, restoring the card on `/new`. | Before | After | | --- | --- | | <img width="980" height="997" alt="New Project Supabase" src="https://github.com/user-attachments/assets/5af9bc8b-5abd-47ea-9821-207ea5c2c127" /> | <img width="980" height="997" alt="New Project Supabase" src="https://github.com/user-attachments/assets/28a32216-d250-497c-90df-94e2df19ce00" /> | ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated the project creation panel’s appearance during the Vercel integration flow, removing unnecessary borders, shadows, and background styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c7f9ce1a30 |
docs: add Anna Baker to humans.txt (#48169)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? I am not included 😢 ## What is the new behavior? I am included 😄 ## Additional context Onboarding task <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Anna Baker to the project contributors list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3d83e026f9 |
refactor(sql-editor): finish EditorController/DiffController port (Step 2) (#48166)
## Summary Step 2 of the SQL Editor testability plan. `SQLEditorContext` already wrapped the Monaco refs and exposed a few semantic imperative helpers (`getEditorSql`, `clearHighlights`, `applyErrorHighlight`, `refocusEditor`, …). This finishes that abstraction so no hook or controller touches `editorRef.current`/`diffEditorRef.current` directly anymore — they only call the port. The port is what will let Step 3's test harness inject a real in-memory editor adapter instead of mocking Monaco; production wires it to the real Monaco refs, unchanged. - Extends the context value with two semantic controllers, backed by the existing refs: - `editor: EditorController` — `isReady`, `getValue`, `getSelectionStartLine`, `getSql` (today's `getEditorSql`), `replaceAll` (wraps the repeated `executeEdits(...)` pattern), `focus`, `revealLineInCenter`, `highlightErrorLine` (today's `applyErrorHighlight`), `clearHighlights`. - `diff: DiffController` — `isMounted`, `getModifiedValue`, `setDiff` (the diff-sync effect body), `attach` (today's `handleDiffEditorMount`). - Migrates every touch point off raw refs onto the port: `useSqlEditorExecution`, `usePrettifyQuery`, `useSqlEditorShortcuts`, `SQLEditorControllers`' `readEditorSql`, and `useSqlEditorAi`'s `acceptAiHandler`/`drainDiffRequest`/`handleDiffEditorMount`/diff-sync effect. - `SQLEditorEditorPanel.tsx` is intentionally left untouched — it wires the raw refs into the real Monaco/DiffEditor React components for rendering, which isn't decision logic to abstract. Behavior-preserving. ## Test plan - [x] `pnpm --filter studio typecheck` - [x] `pnpm test:studio -- SQLEditor` (265 tests passing) - [x] `pnpm --filter studio run lint:ratchet` |
||
|
|
1952abb6d1 |
Fix featured blog post layout breaking on mobile with many authors (#48114)
AuthorAvatars now caps visible avatars at 4 (showing a "+N" badge for the rest) and collapses author names to "First Author, +N others" once there are more than two, instead of joining every name into one long string. A tooltip shows the full list. <img width="434" height="306" alt="Screenshot 2026-07-21 at 15 14 38" src="https://github.com/user-attachments/assets/507ce37e-b080-4dd6-bd49-ca694252cd72" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Enhancements** * Blog author displays now cap at three visible avatars and show a “+N” indicator for additional authors. * Author name labels are now summarized for multi-author posts (with full author names available via tooltip when applicable). * Featured post metadata (author, published date, reading time) has improved spacing, truncation behavior, and responsive visibility on smaller screens. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
0ba30d79e1 |
Revert "fix(docs): guard federated-content schema reads when artifact is absent" (#48159)
Reverts supabase/supabase#48144 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Documentation generation now surfaces missing or unreadable AI skills and Terraform schema data instead of silently producing empty sections. * This improves visibility into incomplete documentation builds and helps ensure generated reference content is available and accurate. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
5db1137c56 |
fix(sql-editor): guard removeFavorite against missing snippet like addFavorite (#48111)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Bug fix
## What is the current behavior?
Fixes #48110
In the SQL editor Valtio store, `removeFavorite` guards against a
missing snippet with `if (storeSnippet.snippet)`, which reads `.snippet`
off `undefined` and throws `TypeError: Cannot read properties of
undefined (reading 'snippet')` whenever the id is not loaded in
`sqlEditorState.snippets`. Its counterpart `addFavorite` guards
correctly with `if (storeSnippet)` and no-ops on the same input.
## What is the new behavior?
`removeFavorite` now uses the same `if (storeSnippet)` guard as
`addFavorite`, so un-favoriting an id that is not in the store is a safe
no-op instead of a crash. Behavior for loaded snippets is unchanged.
Since `StateSnippet.snippet` is a required field, the old check was
always true whenever `storeSnippet` existed, so the only real world
difference between the two guards was the crash on the missing case.
I also added a small vitest file covering both methods (favorite set
plus needsSaving queued for loaded snippets, no-op for missing ids). The
missing-id test for `removeFavorite` fails with the exact TypeError
above when run against the old guard, and passes with this fix.
## Additional context
Root cause: `apps/studio/state/sql-editor/sql-editor-state.ts` line 260
(compare `removeFavorite` at lines 258 to 264 with `addFavorite` at
lines 250 to 256).
Gates run locally on top of current master (
|
||
|
|
cdc843dadd |
refactor(sql-editor): extract deriveSnippetIdentity, debug/completion/diff-key helpers (#48014)
## Summary Pure-fn extraction pass across the SQL editor hooks. - Extracts `deriveSnippetIdentity` out of `useSnippetIdentity`'s inline id + `isLoading` derivation into `SQLEditor.utils.ts`. - Extracts `extractDebugContext` (shared snippet/result/error extraction) and `buildDebugChatArgs` (the `aiSnap.newChat(...)` payload builder) out of `useSqlEditorAi`'s `buildDebugPrompt`/`onDebug` into `SQLEditor.utils.ts`. - Extracts `buildCompletionRequestBody` (the AI completion endpoint's request body builder) and `planDiffRequestApplication` (the pending-diff-request application decision: replace vs. open a diff, depending on whether the editor is currently empty) out of `useSqlEditorAi` into `SQLEditor.utils.ts`. The `drainDiffRequest` effect now just applies the plan instead of branching inline. - Extracts `resolveDiffKeyAction` out of `useSqlEditorShortcuts`'s window-keydown Enter/Escape branch into `SQLEditor.utils.ts`. ## Test plan - [x] `pnpm --filter studio typecheck` - [x] `pnpm test:studio -- SQLEditor` (265 tests passing) - [x] `pnpm --filter studio run lint:ratchet` |
||
|
|
cd5935d3e2 |
docs(realtime): schema restriction (#48157)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Make it clear what users can and can't do on `realtime` schema. ## What is the current behavior? After https://github.com/supabase/realtime/pull/1993 creating or altering the realtime schema is no longer allowed, but some users are still trying to execute `ALTER TABLE realtime.messages ENABLE ROW LEVEL SECURITY` or trying to create objects on that schema. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified Realtime schema protections, including a caution about how the `realtime` schema is restricted and what permission errors to expect when creating objects there. * Confirmed that row level security is enabled by default on `realtime.messages`, and that managing its RLS policies is supported. * Documented the additional binary-capable function, `realtime.send_binary`, alongside the existing `realtime.send` behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3f81b52a21 |
adds shaun to humans.txt (#48150)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Updates humans.txt to include new Supabase team member, me. 😄 ## What is the current behavior? It's missing a new team member. ## What is the new behavior? Added me to the list! ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Shaun Newman to the team listings in the documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4158293d02 | fix: Fetch federated content on www build (#48145) | ||
|
|
94f2f5a4a3 | feat(pipelines): Adjust blog post naming (#48154) | ||
|
|
c13cb81e76 |
chore: remove noisy dashboard PR-reminder workflow (#48142)
<!-- ccr-slack-attribution --> _Requested by **Ivan Vasilov** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1784635673434979)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore / cleanup — removes a scheduled GitHub Actions workflow. ## What is the current behavior? The `Dashboard PR Reminder` workflow (`.github/workflows/dashboard-pr-reminder.yml`) runs on a schedule and posts a "Dashboard PRs Older Than 24 Hours" reminder to Slack. It has become too noisy — Jordi flagged that it fired 5 times in 3 days. The #team-frontend team agreed to remove it rather than reschedule it. ## What is the new behavior? The workflow and its exclusively-used supporting scripts are deleted, so the Slack reminder no longer runs. Files removed (each used exclusively by this workflow): - `.github/workflows/dashboard-pr-reminder.yml` — the reminder workflow itself. - `scripts/actions/find-stale-dashboard-prs.ts` — helper invoked only by this workflow's run step; not referenced anywhere else in the repo. - `scripts/actions/send-slack-pr-notification.ts` — helper invoked only by this workflow's run step; not referenced anywhere else in the repo. (This leaves `scripts/actions/` empty, so the directory is removed too.) No shared files were touched. The workflow's `sparse-checkout` of `scripts`/`patches`, `.nvmrc`, and `pnpm-lock.yaml` are repo-wide and remain in place. ## Additional context Verified via a full-repo grep that the two scripts and the workflow file are referenced nowhere outside this workflow before deleting them. --- _Generated by [Claude Code](https://claude.ai/code/session_01RynCtzP874KrpN8CPf7n7n)_ Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
2e12cdc2e1 |
fix: empty search_path (#48151)
## TL;DR Restores handling for functions with `search_path` set to `''` editing them in the UI was failing with a Postgres `zero-length delimited identifier` error since the SafeSql refactor dropped the empty-string sentinel conversion ## ref - closes #48149 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Preserved empty `search_path` configuration values when updating database functions. * Prevented empty configuration values from being altered or lost during function updates. * **Tests** * Added coverage verifying that function definitions can be updated without changing an existing empty `search_path` setting. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b883b102b4 | fix(studio): gate user logs tab behind feature flag (#48122) | ||
|
|
9f5e75183c |
chore(studio): add bullet-point to integration uninstall modal (#48139)
## What is the current behavior? <img width="533" height="394" alt="Screenshot 2026-07-21 at 11 55 05" src="https://github.com/user-attachments/assets/4e5e8fde-5823-4ad2-849e-abad90bfa72a" /> ## What is the new behavior? <img width="501" height="430" alt="Screenshot 2026-07-21 at 12 43 17" src="https://github.com/user-attachments/assets/2888d815-8c2c-47db-a058-dc60b208d6b1" /> ## Additional context Also fixed font-weight for strong text in studio to be `font-bold`. |
||
|
|
6928a0157b |
fix(www): correct Supabase Pipelines public alpha post date to July 21 (#48152)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Updates the publish date of the "Supabase Pipelines is now in Public Alpha" blog post from July 15 to July 21 - Renames the post file to match the new date - Updates the `date` frontmatter field ## What is the current behavior? The post is dated 2026-07-15. ## What is the new behavior? - The post is dated 2026-07-21 to match the public launch date - File renamed to `apps/www/_blog/2026-07-21-supabase-pipelines-public-alpha.mdx` - Frontmatter `date` set to `'2026-07-21'` ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the publication date for the Supabase Pipelines public alpha blog post to July 21, 2026. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Ana <ana1337x@users.noreply.github.com> |
||
|
|
d5c5a95cc8 |
feat(www): add "Supabase Pipelines is now in Public Alpha" blog post (#47864)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Add a new blog post: `apps/www/_blog/2026-07-15-supabase-pipelines-public-alpha.mdx`, announcing that Supabase Pipelines is moving from private to public alpha - Covers new schema change support (add/remove/rename columns, nullability/default changes), a faster parallelized initial copy, and new destination request forms for ClickHouse, Snowflake, and DuckLake - Authored by `riccardo_busetti` ## What is the current behavior? N/A — this is a new blog post page at `/blog/supabase-pipelines-public-alpha`. ## What is the new behavior? - New post published at `/blog/supabase-pipelines-public-alpha` ## Additional context n/a <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **Announcements** - Published a new blog post announcing **Supabase Pipelines** is now available in **Public Alpha**, with updates on improved performance and operability since private alpha. - **Documentation** - Documented **schema change support**, **faster initial copy** via parallelized table copying, and the pipeline lifecycle based on **Postgres logical replication**. - Added details for the first destination (**BigQuery**), destination request forms (ClickHouse/Snowflake/DuckDBLake), plus **roadmap**, **pricing**, **getting started**, and **public-alpha caveats**. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <ana1337x@users.noreply.github.com> Co-authored-by: Riccardo Busetti <riccardo.busetti@supabase.io> |
||
|
|
8a0b324dff |
docs(design-system): add connect interstitials pattern (#45356)
## Summary - Adds design-system guidance for the shared Connect interstitial layout used by authorisation, invite, marketplace, CLI, and credit flows - Includes a glanceable example showing the centred 400px card for partner authorise and wrong-account invite states - Documents Studio helpers (`InterstitialLayout`, logo helpers, account row, `OrganizationSelector`) so future surfaces reuse one pattern instead of bespoke shells ## Context Most of the Studio Connect UI work from this effort has already landed. This PR keeps the documentation and design-system example so the pattern stays discoverable. Related: [Shared Connect UI for Authorization and Partner Flows](https://linear.app/supabase/project/shared-connect-ui-for-authorization-and-partner-flows-94587ac29d38) ## Test plan - [ ] Open `/docs/ui-patterns/connect-interstitials` in the design system - [ ] Confirm the page appears under UI Patterns in the nav - [ ] Confirm the example renders the authorise and wrong-account cards side by side - [ ] Skim the guidance for accuracy against current Studio `InterstitialLayout` usage <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added new design-system “Connect Interstitials” example demos, including branding variations (single vs dual logos) and a complete connect-card flow with account row and sign-out action. * Registered the new Connect Interstitials examples in the design-system example registry. * **Documentation** * Added a “Connect Interstitials” UI Patterns page covering when to use the pattern, recommended card/layout structure, branding/logo guidance, and conventions for states, actions, and copy. * Updated the documentation sidebar to include the new page. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |