Commit Graph
38007 Commits
Author SHA1 Message Date
Claude 0b4eec5066 feat(ui-patterns): add adaptiveHeight to PromptPanel; use it in Workers dialog
- PromptPanel: new `adaptiveHeight?: boolean` prop. When true, only the active
  TabsContent renders and the panel resizes to fit that tab. Default false
  keeps the existing stacked-in-one-grid-cell behavior so the docs homepage
  still gets a stable frame across tabs
- WorkerPromptPanel passes adaptiveHeight so the tabbed snippets in the
  Deploy-a-worker dialog size to whichever tab is active (AI Prompt is short,
  config.toml/cURL are taller)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 15:31:29 +00:00
Claude 0a8d2601c6 fix(studio): tighten Create worker dialog spacing, move admonition below fields
Follow the design-system dialog form pattern: one padded DialogSection with
space-y-4 between fields (instead of per-field p-5), and move the "Deploys a
Deno starter worker" admonition to the bottom of the form, flush with the
dialog borders. Its own border-top divides it from the fields; border-b-0 lets
the DialogSectionSeparator below draw the single line before the snippets.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 15:02:37 +00:00
Claude f620cb5c3b feat(studio): Workers New badge in sidebar, AlphaNotice on index, dialog cleanup
- Sidebar: add an `isNew?: boolean` field to the Route type and render a small
  "New" success badge next to the label in SideBarNavLink; flag the Workers
  entry with isNew: true. The badge is clipped by the button's overflow-hidden
  when the sidebar collapses to icon width, so no extra hide class is needed
- Workers index: show the shared AlphaNotice banner at the top ("Introducing
  workers", plus a share-feedback link), matching AnalyticsBuckets and
  VectorBuckets
- CreateWorkerDialog: adopt the CreateAnalyticsBucketForm layout — dialog
  header followed by a DialogSectionSeparator (bottom border), the intro
  Admonition flush with the borders (rounded-none border-x-0 border-t-0),
  each FormItemLayout carrying its own p-5 inside a p-0! DialogSection, then
  a separator before the live snippets section and the footer

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 14:48:22 +00:00
Claude f4c4357360 feat(studio): move Workers quickstart snippets into the create dialog
- Workers empty state is back to the plain presentational container with just
  the Deploy worker CTA
- The tabbed copyable snippets now live at the bottom of the Deploy a worker
  dialog and track the form live: a CreateWorkerSnippets child subscribes via
  useWatch on name/size/access/instances so a keystroke re-renders only the
  snippets, not the whole dialog
- Drop the editor/fillHeight/wrap props from WorkerSnippetTabs, which existed
  only for the old side-by-side empty state and now have no callers

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 13:38:48 +00:00
Claude de0438fed6 feat(studio): horizontal split for the Workers empty state
Rework the empty state into a single card with a horizontal split: the
EmptyStatePresentational icon/title/description/CTA stays on the left (its own
border/background stripped so the outer wrapper is the only visible card
chrome), and the quickstart PromptPanel sits fixed-width on the right. Stacks
vertically below lg.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 12:18:59 +00:00
Claude a9d91a7ecb feat(studio): nest Workers quickstart panel inside the empty-state container
Move the tabbed PromptPanel from a side-by-side column into the presentational
empty state, directly under the Deploy worker button — centered, capped at
600px wide even as the container grows, with a short "Or quickstart a worker
with a snippet" intro.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 11:22:20 +00:00
Claude 8df6b9ebdd fix(studio): Workers empty-state overflow, secrets reuse EF add form, copy
- PromptPanel: pin the stacked-pane grid track to minmax(0,1fr) and give each
  pane min-w-0 so the AI prompt wraps and the CLI/config/cURL code blocks scroll
  instead of pushing the panel past its column
- Workers Secrets: reuse the Edge Functions AddNewSecretForm for adding project
  secrets (drop the bespoke add dialog/button) and remove the "restrict per
  worker from its Settings tab" pointer copy
- Rewrite the Workers index subdescription to "Fully managed compute that runs
  any runtime next to your database"

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 10:57:09 +00:00
Claude 5474577292 feat(studio): reuse docs PromptPanel in Workers empty state; rename Compute → Workers
- Lift PromptPanel from apps/docs into packages/ui-patterns so Studio and Docs
  share one component; update both docs importers and drop the old file (no shim)
- Rebuild the Workers empty state as a 3/5 hero + 2/5 PromptPanel grid; render
  CLI / config.toml / cURL tabs through CodeBlock for language-correct highlighting
- Rename the product back to "Workers" (PRODUCT_NAME / CLI_NAME) and fix the
  hardcoded "Compute" copy on the index page; correct the skill region to us-west-2

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 10:33:45 +00:00
Claude dd65a8de51 feat(studio): split Workers empty state into hero + code panel
Rework the empty state into a two-column layout:
- Left (2/3): a clean EmptyStatePresentational — BoxPlus icon, "Deploy your
  first worker", short description, and a single "+ Deploy worker" button.
  Dropped the redundant "Deploy with CLI" button and the ", in US West
  (Oregon)" clause.
- Right (1/3): a code-editor-style panel (recessed bg-surface-75, filling the
  row height) with tabs AI Prompt (sparkle) · CLI · config.toml · cURL. Content
  wraps and scrolls vertically when it overflows.

Extend WorkerSnippetTabs with editor / fillHeight / wrap props to support the
panel, rename the AI tab label to "AI Prompt" and give it a sparkle icon
(only surfaced in the empty state today).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 09:55:21 +00:00
Claude dd491f78b2 feat(studio): rebuild Workers empty state on EmptyStatePresentational
The previous empty state used a bespoke two-column Card with steps and a
right-rail — inconsistent with the design system and carrying wrong info
(listed Bun/Python as supported runtimes, referenced US West without noting
the alpha lock).

Rewrite on ui-patterns/EmptyStatePresentational: BoxPlus icon, active-language
title ("Deploy your first worker"), a short description aligned with the
Private Alpha requirements (Dockerfile/Node.js/Deno supported, US West
(Oregon), Bun and Python coming soon), and the primary Deploy worker /
Deploy with CLI actions from the previous version.

Below the actions, a tabbed snippet block using WorkerSnippetTabs seeded with
EXAMPLE_WORKER exposes AI prompt, CLI, and cURL variants — copy-ready, so a
user landing here can go straight to a template without leaving the page.

Also fix a drive-by: the config.toml snippet's region comment said us-west-1
while WORKERS_REGION is us-west-2. Corrected to match.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-20 09:30:21 +00:00
Claude 0ae221455d feat(studio): show Default secrets on the Workers Secrets page
Mirror Edge Functions: below the custom project-level secrets table, render a
"Default secrets" section (SUPABASE_URL, SUPABASE_DB_URL, SUPABASE_PUBLISHABLE_KEYS,
etc.) with a link to the docs. Reuses DefaultEdgeFunctionSecrets and
getVisibleDefaultEdgeFunctionSecrets directly since these defaults are
project-level env vars and are identical for every Supabase compute product —
extracting to a shared module can wait for a third consumer.

Also switch the custom-secrets filter from a hand-rolled SUPABASE_* prefix
check to the shared isInternalEdgeFunctionSecret helper, so any additional
default names stay out of the custom table automatically.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-19 13:49:29 +00:00
Claude 04aec655ae feat(studio): add Secrets to Workers — project pool + per-worker overrides
Mirror Edge Functions' Secrets pattern, adapted for the future Workers Secrets
API's fine-grained model.

Project pool (real API):
- New sidebar item "Secrets" under Workers, next to the main list.
- New page /project/[ref]/workers/secrets backed by useSecretsQuery /
  useSecretsCreateMutation / useSecretsDeleteMutation — the same v1 project
  secrets endpoint Edge Functions already reads. Filters out SUPABASE_*.

Per-worker overrides (prototype):
- New state/worker-secret-overrides.ts valtio store keyed by
  ${projectRef}:${workerName}. Two axes: `overrides` (name → value) and
  `denied` (project secret names hidden from this worker).
- Worker Settings gains a "Secrets" section with a resolved table:
  From project / Override / This worker / Denied — with per-row actions
  (override value, deny/allow, revert to project, delete worker-only).
- Admonition on the section makes it clear the fine-grained control is
  prototype state until the real Workers Secrets API ships.

Reusable AddSecretDialog handles both the project add flow and per-worker
add/override with a SCREAMING_SNAKE zod schema, SUPABASE_ reserved-prefix
guard, and dup detection.

Note: TanStack route mirror for the new page is deferred — routeTree.gen.ts
is a Vite-plugin generated file and can't be hand-edited. Next pages router
serves the page today; whoever runs pnpm dev:studio next can regenerate the
tree and add the route wrapper.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
2026-08-19 12:56:58 +00:00
Jordi Enric eeda0573bb feat(studio): gate worker deploys on the Edge Functions write permission 2026-08-19 11:45:49 +02:00
Jordi Enric 5399b6d1f5 fix(studio): type the tar buffer so it is a valid BlobPart 2026-08-19 11:45:49 +02:00
Jordi Enric 63db18a04c feat(studio): deploy a starter worker through the upload and deploy endpoints
Follows the API team's flow: mint an upload slot, PUT a gzipped tar of the
starter source to the presigned URL, then deploy with the context upload id.
2026-08-19 11:45:49 +02:00
Jordi Enric 48a8e6d30c feat(studio): deploy a worker from the dashboard
The v2 deploy endpoint accepts a spec without a build context when runtime is
set, so the dashboard can create a worker without uploading a tarball.
2026-08-19 11:45:49 +02:00
Jordi Enric 74d8640b52 fix(studio): pass dehydratedState to the worker detail page from its route 2026-08-19 11:45:49 +02:00
Jordi Enric 389c7936f4 fix(studio): add the worker detail route to the generated route tree 2026-08-19 11:45:49 +02:00
Jordi Enric fc3cd55440 feat(studio): add the TanStack worker detail route 2026-08-19 11:45:49 +02:00
Jordi Enric ace5136a60 feat(studio): read the worker detail from the v2 Management API
Overview now shows the instance tally, build failure reason and instance errors
the endpoint returns, replacing the seeded request and resource charts.
2026-08-19 11:45:49 +02:00
Jordi Enric 00d1a4a147 refactor(studio): read the worker detail through React Query and drop section-marker comments 2026-08-19 11:45:49 +02:00
Jordi Enric 8c8c249a1e fix(studio): import WorkersLayout by name on the worker detail page 2026-08-19 11:45:49 +02:00
Jordi Enric 89e8c0580c fix(studio): remove the docs link from the worker settings tab 2026-08-19 11:45:49 +02:00
Jordi Enric dcbe0ddaa1 fix(studio): stop rendering Edge Function logs on the worker Logs tab
The tab queried the functions log source with a worker_name filter that source
does not have. It now points at the CLI until the workers logs endpoint ships.
2026-08-19 11:45:49 +02:00
Jordi Enric e4140b7814 feat(studio): add the worker detail page with overview, logs and settings (FE-4189, FE-4197) 2026-08-19 11:45:49 +02:00
Jordi Enric da754ea48f fix(studio): resolve worker snippet URLs from the project endpoint 2026-08-19 11:45:39 +02:00
Jordi Enric 23064ba0c1 refactor(studio): build worker snippets from the API's runtime and size values 2026-08-19 11:45:39 +02:00
Jordi Enric 02886ba6eb fix(studio): restore the Button import on the workers list 2026-08-19 11:45:39 +02:00
Jordi Enric 37538d3d0d refactor(studio): drop section-marker comments from the workers empty state 2026-08-19 11:45:39 +02:00
Jordi Enric e5c894779c fix(studio): remove the docs links from the workers deploy surfaces 2026-08-19 11:45:39 +02:00
Jordi Enric 1d93b24c1a refactor(studio): drop restating comments from the worker snippet helpers 2026-08-19 11:45:39 +02:00
Jordi Enric 928c11c08d feat(studio): show CLI deploy instructions for workers (FE-4191) 2026-08-19 11:45:39 +02:00
Jordi Enric f392da1c04 fix(studio): tell a missing workers permission apart from a project outside the alpha
A 404 means the project is not allow-listed; a 403 means the caller lacks the
workers_read permission. They had been reported with the same message.
2026-08-19 11:45:22 +02:00
Jordi Enric 9fd08667df fix(studio): build worker URLs on the project domain and correct the region
Workers answer at <project>/workers/v1/<name>, not a shared workers.supabase.co
host, and the alpha region is us-west-2.
2026-08-19 11:10:45 +02:00
Jordi Enric 537ca65e59 feat(studio): gate the workers pages on the Edge Functions read permission 2026-08-19 11:02:56 +02:00
Jordi Enric 7277e1b012 fix(studio): pass dehydratedState to the workers page from its route 2026-08-18 23:05:49 +02:00
Jordi Enric a078e50708 fix(studio): regenerate the route tree and type the workers access check 2026-08-18 22:43:13 +02:00
Jordi Enric 2c6a9a923b feat(studio): add the TanStack workers route and handle non-allowlisted projects 2026-08-18 22:34:12 +02:00
Jordi Enric 7df9cefb57 fix(studio): narrow the workers response so data is defined after the error guard 2026-08-18 14:58:44 +02:00
Jordi Enric fa58d0753e feat(studio): read the workers list from the v2 Management API
Replaces the seeded store with GET /v2/projects/{ref}/workers, and reshapes the
view model, state pill and resource formatting to what the endpoint returns.
2026-08-18 14:45:52 +02:00
Jordi Enric c3df56c22f refactor(studio): read workers through React Query instead of a valtio store
Moves the seed data behind data/workers query options so swapping in the v2
endpoint is a change to one function, and drops the constants the removed
create dialog left behind.
2026-08-18 14:16:25 +02:00
Jordi Enric 736567fc81 fix(studio): drop the workers docs link until the page exists
supabase.com/docs/guides/workers returns 404.
2026-08-18 13:42:26 +02:00
Jordi Enric 469ae20445 fix(studio): address review on the workers list
Exports WorkersLayout by name and explains the disabled pagination buttons.
2026-08-18 13:41:51 +02:00
Jordi Enric 8b94a57555 refactor(studio): extract workers list filtering and pagination
Adds unit tests, removes the filter-value casts, and gives the worker name a
real link so the row is reachable by keyboard.
2026-08-18 13:36:07 +02:00
Jordi Enric 4f5b66b22b feat(studio): add the workers list behind the workers flag (FE-4188) 2026-08-18 13:29:46 +02:00
Cemal KılıçandJeremias Menichelli 2440b06cb7 fix(docs/oauth-server): add plain for code_challenge_method (#49180)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?
docs update

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified that OAuth authorization requests support both `S256` and
`plain` code challenge methods.
  * Recommends `S256` for improved security.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
2026-08-18 12:13:07 +02:00
dbb153042e feat(studio): cleaned up view permissions sheet (#49144)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Breaking down #49007 into smaller PR's. Part 1 merged in.

More to follow...


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Redesigned token capability details with expandable cards and dense
views for larger permission sets.
  * Added filtering by all, read, and read-write capabilities.
* Improved endpoint and MCP tool attribution, display, and endpoint
copying.
  * Added risk banners with permission and access warnings.
* Enhanced resource badges, responsive layouts, relative timestamps, and
dismissible creation guidance.

* **Bug Fixes**
  * Corrected MCP tool attribution across alternative permission scopes.
  * Improved handling and display of inaccessible resources.

* **Tests**
* Expanded coverage for capability views, filtering, risk messaging, and
permission evaluation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-08-18 10:58:56 +01:00
Ayaan Gazali e0ee774c74 fix(docs): point the Management API nav entry at the Management API reference (#49165) 2026-08-18 11:20:44 +02:00
Saxon Fletcher c80f8ad78d chore(studio): upgrade AI SDK to v7 (#49167)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore / dependency upgrade.

## What is the current behavior?

Studio is on AI SDK 6 (`ai` ^6.0.174, `@ai-sdk/react` ^3). Tool
approvals still use the v6 `needsApproval` flag on individual tools.

## What is the new behavior?

Upgrades Studio to AI SDK 7 (`ai` 7.0.59) and the matching `@ai-sdk/*`
packages. Aligns call sites with v7 names (`instructions`,
`isStepCount`, `onEnd`, `ToolExecutionOptions`).

This is the bottom of stack #49171. Later layers add a shared Confirm
card and AssistantQueryCell.

## Additional context

- Stack: #49167 → #49168 → #49169 → #49170
- `needsApproval` on tools is left as-is in this PR so the upgrade can
land independently. A follow-up can move those gates to `streamText({
toolApproval })` and `experimental_toolApprovalSecret`.
- Independent of the notebook preview stack
([#49112](https://github.com/supabase/supabase/pull/49112),
[#49159](https://github.com/supabase/supabase/pull/49159)), which should
merge first before we wrap notebook proposals in Confirm.

## Test plan

- [ ] `pnpm --filter studio test` for `lib/ai/tools/*` and assistant
generate path
- [ ] Assistant chat still streams and tool-approval SQL / Edge Function
still pause for confirm
- [ ] Evals still run with mock tools (`needsApproval: false` overrides)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Updated AI-powered chat, onboarding, SQL, code completion, and recipe
generation workflows for more reliable responses.
* Streaming responses now better preserve reasoning and source
information where available.
* Improved tool privacy notices while preserving dynamically generated
tool descriptions.
* Refined AI response handling, including step limits and structured
policy results.
* **Bug Fixes**
* Improved compatibility across AI-powered tool interactions and
execution scenarios.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-18 17:04:36 +08:00
Jeremias Menichelli 81507e37bb fix(Search): Add server sources for search (#49148) 2026-08-18 10:32:01 +02:00