- PromptPanel: new `adaptiveHeight?: boolean` prop. When true, only the active
TabsContent renders and the panel resizes to fit that tab. Default false
keeps the existing stacked-in-one-grid-cell behavior so the docs homepage
still gets a stable frame across tabs
- WorkerPromptPanel passes adaptiveHeight so the tabbed snippets in the
Deploy-a-worker dialog size to whichever tab is active (AI Prompt is short,
config.toml/cURL are taller)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
Follow the design-system dialog form pattern: one padded DialogSection with
space-y-4 between fields (instead of per-field p-5), and move the "Deploys a
Deno starter worker" admonition to the bottom of the form, flush with the
dialog borders. Its own border-top divides it from the fields; border-b-0 lets
the DialogSectionSeparator below draw the single line before the snippets.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
- Sidebar: add an `isNew?: boolean` field to the Route type and render a small
"New" success badge next to the label in SideBarNavLink; flag the Workers
entry with isNew: true. The badge is clipped by the button's overflow-hidden
when the sidebar collapses to icon width, so no extra hide class is needed
- Workers index: show the shared AlphaNotice banner at the top ("Introducing
workers", plus a share-feedback link), matching AnalyticsBuckets and
VectorBuckets
- CreateWorkerDialog: adopt the CreateAnalyticsBucketForm layout — dialog
header followed by a DialogSectionSeparator (bottom border), the intro
Admonition flush with the borders (rounded-none border-x-0 border-t-0),
each FormItemLayout carrying its own p-5 inside a p-0! DialogSection, then
a separator before the live snippets section and the footer
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
- Workers empty state is back to the plain presentational container with just
the Deploy worker CTA
- The tabbed copyable snippets now live at the bottom of the Deploy a worker
dialog and track the form live: a CreateWorkerSnippets child subscribes via
useWatch on name/size/access/instances so a keystroke re-renders only the
snippets, not the whole dialog
- Drop the editor/fillHeight/wrap props from WorkerSnippetTabs, which existed
only for the old side-by-side empty state and now have no callers
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
Rework the empty state into a single card with a horizontal split: the
EmptyStatePresentational icon/title/description/CTA stays on the left (its own
border/background stripped so the outer wrapper is the only visible card
chrome), and the quickstart PromptPanel sits fixed-width on the right. Stacks
vertically below lg.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
Move the tabbed PromptPanel from a side-by-side column into the presentational
empty state, directly under the Deploy worker button — centered, capped at
600px wide even as the container grows, with a short "Or quickstart a worker
with a snippet" intro.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
- PromptPanel: pin the stacked-pane grid track to minmax(0,1fr) and give each
pane min-w-0 so the AI prompt wraps and the CLI/config/cURL code blocks scroll
instead of pushing the panel past its column
- Workers Secrets: reuse the Edge Functions AddNewSecretForm for adding project
secrets (drop the bespoke add dialog/button) and remove the "restrict per
worker from its Settings tab" pointer copy
- Rewrite the Workers index subdescription to "Fully managed compute that runs
any runtime next to your database"
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
- Lift PromptPanel from apps/docs into packages/ui-patterns so Studio and Docs
share one component; update both docs importers and drop the old file (no shim)
- Rebuild the Workers empty state as a 3/5 hero + 2/5 PromptPanel grid; render
CLI / config.toml / cURL tabs through CodeBlock for language-correct highlighting
- Rename the product back to "Workers" (PRODUCT_NAME / CLI_NAME) and fix the
hardcoded "Compute" copy on the index page; correct the skill region to us-west-2
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
Rework the empty state into a two-column layout:
- Left (2/3): a clean EmptyStatePresentational — BoxPlus icon, "Deploy your
first worker", short description, and a single "+ Deploy worker" button.
Dropped the redundant "Deploy with CLI" button and the ", in US West
(Oregon)" clause.
- Right (1/3): a code-editor-style panel (recessed bg-surface-75, filling the
row height) with tabs AI Prompt (sparkle) · CLI · config.toml · cURL. Content
wraps and scrolls vertically when it overflows.
Extend WorkerSnippetTabs with editor / fillHeight / wrap props to support the
panel, rename the AI tab label to "AI Prompt" and give it a sparkle icon
(only surfaced in the empty state today).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
The previous empty state used a bespoke two-column Card with steps and a
right-rail — inconsistent with the design system and carrying wrong info
(listed Bun/Python as supported runtimes, referenced US West without noting
the alpha lock).
Rewrite on ui-patterns/EmptyStatePresentational: BoxPlus icon, active-language
title ("Deploy your first worker"), a short description aligned with the
Private Alpha requirements (Dockerfile/Node.js/Deno supported, US West
(Oregon), Bun and Python coming soon), and the primary Deploy worker /
Deploy with CLI actions from the previous version.
Below the actions, a tabbed snippet block using WorkerSnippetTabs seeded with
EXAMPLE_WORKER exposes AI prompt, CLI, and cURL variants — copy-ready, so a
user landing here can go straight to a template without leaving the page.
Also fix a drive-by: the config.toml snippet's region comment said us-west-1
while WORKERS_REGION is us-west-2. Corrected to match.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
Mirror Edge Functions: below the custom project-level secrets table, render a
"Default secrets" section (SUPABASE_URL, SUPABASE_DB_URL, SUPABASE_PUBLISHABLE_KEYS,
etc.) with a link to the docs. Reuses DefaultEdgeFunctionSecrets and
getVisibleDefaultEdgeFunctionSecrets directly since these defaults are
project-level env vars and are identical for every Supabase compute product —
extracting to a shared module can wait for a third consumer.
Also switch the custom-secrets filter from a hand-rolled SUPABASE_* prefix
check to the shared isInternalEdgeFunctionSecret helper, so any additional
default names stay out of the custom table automatically.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
Mirror Edge Functions' Secrets pattern, adapted for the future Workers Secrets
API's fine-grained model.
Project pool (real API):
- New sidebar item "Secrets" under Workers, next to the main list.
- New page /project/[ref]/workers/secrets backed by useSecretsQuery /
useSecretsCreateMutation / useSecretsDeleteMutation — the same v1 project
secrets endpoint Edge Functions already reads. Filters out SUPABASE_*.
Per-worker overrides (prototype):
- New state/worker-secret-overrides.ts valtio store keyed by
${projectRef}:${workerName}. Two axes: `overrides` (name → value) and
`denied` (project secret names hidden from this worker).
- Worker Settings gains a "Secrets" section with a resolved table:
From project / Override / This worker / Denied — with per-row actions
(override value, deny/allow, revert to project, delete worker-only).
- Admonition on the section makes it clear the fine-grained control is
prototype state until the real Workers Secrets API ships.
Reusable AddSecretDialog handles both the project add flow and per-worker
add/override with a SCREAMING_SNAKE zod schema, SUPABASE_ reserved-prefix
guard, and dup detection.
Note: TanStack route mirror for the new page is deferred — routeTree.gen.ts
is a Vite-plugin generated file and can't be hand-edited. Next pages router
serves the page today; whoever runs pnpm dev:studio next can regenerate the
tree and add the route wrapper.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XQ5b58nwfCGsifA7PCheQb
Follows the API team's flow: mint an upload slot, PUT a gzipped tar of the
starter source to the presigned URL, then deploy with the context upload id.
Overview now shows the instance tally, build failure reason and instance errors
the endpoint returns, replacing the seeded request and resource charts.
The tab queried the functions log source with a worker_name filter that source
does not have. It now points at the CLI until the workers logs endpoint ships.
Replaces the seeded store with GET /v2/projects/{ref}/workers, and reshapes the
view model, state pill and resource formatting to what the endpoint returns.
Moves the seed data behind data/workers query options so swapping in the v2
endpoint is a change to one function, and drops the constants the removed
create dialog left behind.
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs update
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Clarified that OAuth authorization requests support both `S256` and
`plain` code challenge methods.
* Recommends `S256` for improved security.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Breaking down #49007 into smaller PR's. Part 1 merged in.
More to follow...
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Redesigned token capability details with expandable cards and dense
views for larger permission sets.
* Added filtering by all, read, and read-write capabilities.
* Improved endpoint and MCP tool attribution, display, and endpoint
copying.
* Added risk banners with permission and access warnings.
* Enhanced resource badges, responsive layouts, relative timestamps, and
dismissible creation guidance.
* **Bug Fixes**
* Corrected MCP tool attribution across alternative permission scopes.
* Improved handling and display of inaccessible resources.
* **Tests**
* Expanded coverage for capability views, filtering, risk messaging, and
permission evaluation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Chore / dependency upgrade.
## What is the current behavior?
Studio is on AI SDK 6 (`ai` ^6.0.174, `@ai-sdk/react` ^3). Tool
approvals still use the v6 `needsApproval` flag on individual tools.
## What is the new behavior?
Upgrades Studio to AI SDK 7 (`ai` 7.0.59) and the matching `@ai-sdk/*`
packages. Aligns call sites with v7 names (`instructions`,
`isStepCount`, `onEnd`, `ToolExecutionOptions`).
This is the bottom of stack #49171. Later layers add a shared Confirm
card and AssistantQueryCell.
## Additional context
- Stack: #49167 → #49168 → #49169 → #49170
- `needsApproval` on tools is left as-is in this PR so the upgrade can
land independently. A follow-up can move those gates to `streamText({
toolApproval })` and `experimental_toolApprovalSecret`.
- Independent of the notebook preview stack
([#49112](https://github.com/supabase/supabase/pull/49112),
[#49159](https://github.com/supabase/supabase/pull/49159)), which should
merge first before we wrap notebook proposals in Confirm.
## Test plan
- [ ] `pnpm --filter studio test` for `lib/ai/tools/*` and assistant
generate path
- [ ] Assistant chat still streams and tool-approval SQL / Edge Function
still pause for confirm
- [ ] Evals still run with mock tools (`needsApproval: false` overrides)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Improvements**
* Updated AI-powered chat, onboarding, SQL, code completion, and recipe
generation workflows for more reliable responses.
* Streaming responses now better preserve reasoning and source
information where available.
* Improved tool privacy notices while preserving dynamically generated
tool descriptions.
* Refined AI response handling, including step limits and structured
policy results.
* **Bug Fixes**
* Improved compatibility across AI-powered tool interactions and
execution scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->