Commit Graph
20566 Commits
Author SHA1 Message Date
Pamela Chia 1716d87f59 fix(studio): cap project name at 256 chars (#50804) 2026-09-24 02:34:53 +08:00
Ali Waseem ce0b778fec fix(studio): remove duplicate O T shortcut registration in schema visualizer (#50803)
The schema visualizer bound `schema-visualizer.find-table` (`O` then
`T`) twice — once via `useShortcut` and again through the `<Shortcut>`
wrapper around `FindTableSelector`, which registers the hotkey itself —
so every mount logged a conflict warning and fired both handlers.

Removed the redundant standalone hook; the wrapper renders under the
same `shortcutsEnabled` gate, so behavior is unchanged.

Fixes FE-4454

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Behavior Changes**
* The schema visualizer no longer registers the standalone keyboard
shortcut handler for Find Table. Find Table remains available from the
toolbar.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 11:30:31 -06:00
Joshen Lim 5b18f1d084 Allow setting null for connection pool size (#50726)
## Context

Allows users to "reset" the value for connection pool size in pooler
configuration under [database
settings](http://supabase.com/dashboard/project/_/database/settings)
<img width="500" alt="image"
src="https://github.com/user-attachments/assets/4eb98088-1898-423c-8ef6-655fd0573601"
/>

Refer to the [Linear
ticket](https://linear.app/supabase/issue/FE-4425/support-setting-null-for-pool-size-in-pooler-config)
for more details about why this change is needed - its a bit of an
explanation 😅 🙏

## To test
- [ ] Verify that you can save a pool size, and that the GET
`/config/pgbouncer` network request returns `default_pool_size` property
in its response
- [ ] Verify that you can save while leaving the pool size input field
empty, and that the GET `/config/pgbouncer` network request thereafter
doesn't return `default_pool_size` in its response

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Preserved the intended database connection pool setting when no
default pool size is specified, rather than automatically applying a
compute-size-based value.
  * Explicitly entered pool sizes continue to be saved unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-24 01:12:19 +08:00
Lukas Bernert f1b7c0aa4d docs: update compute size selection screenshots (#50798)
## Problem

The Compute & Disk sizes screenshot is outdated after the changes from .
https://supabase.com/docs/guides/platform/compute-and-disk#compute

The screenshot still shows architecture, core-counts, and CPU labels.

Fixes PROD-656

## Solution

A new screenshot has been provided to reflect the latest state of
Studio.

## Review instructions

Review the screenshot under:
/docs/guides/platform/compute-and-disk#compute

It should depict what the Studio shows under
/dashboard/project/_/settings/infrastructure .
Test dark & light mode.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| Docs |
[/docs/guides/platform/compute-and-disk#compute](https://supabase.com/docs/guides/platform/compute-and-disk#compute)
|
[/docs/guides/platform/compute-and-disk#compute](https://docs-git-docs-update-compute-size-screenshot-supabase.vercel.app/docs/guides/platform/compute-and-disk#compute)
| N/A (screenshot) |

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the /write-the-docs or /edit-the-docs skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide
2026-09-23 16:53:34 +02:00
Mert YEREKAPAN 1f3f050573 feat(www): clarify database-only positioning on the database page (#50667)
## Summary

Clarifies on the database product page that a Supabase project can be
used as a standalone Postgres database, and mirrors the change in the
page's markdown version (`/database.md`).

Ref: GROWTH-1191

## Changes

- **Hero and page metadata**: adds "Use it on its own, or with the rest
of the Supabase platform."
- **Features section**: intro reframed around the database. The "Just
Postgres" card heading adds "standalone".
- **`content/md/database.md`**: same sentence in the tagline. New short
"Use it as a standalone database" section covering connecting, pooling,
pricing, and Free plan pausing. Client libraries marked optional. Pooler
naming updated to Supavisor. Links added for the connection guide and
`pricing.md`.

## Notes

- Pricing figures in the markdown mirror `packages/shared-data/plans.ts`
and are static here.
- The pausing statement matches
`docs/guides/platform/free-project-pausing`.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Clarified that Supabase projects include dedicated, standalone
Postgres databases.
- Explained that databases can be used independently or alongside the
Supabase platform.
- Added guidance on connections, pooling, pricing, pausing, and optional
client libraries.
- Identified Supavisor as the pooling service and added relevant
connection and pricing links.
- **Content**
- Updated database page messaging to highlight built-in security,
realtime subscriptions, auto-generated APIs, portability, and no vendor
lock-in.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 14:28:58 +00:00
f508eae926 Add Polymet case study (#50793)
## Summary
- Adds the Polymet case study (`apps/www/_customers/polymet.mdx`): how
Polymet, an AI product designer, runs a real backend for tens of
thousands of user projects a month on Supabase with a three-person team
and no dedicated backend hire.
- Adds light/dark logo assets provided by Polymet.
- Content is the final draft reconciled with the customer's (Yus Hilmi,
Founder/CEO) approved review edits.

Ready for design/eng review. Tracked on
[MARKET-2264](https://linear.app/supabase/issue/MARKET-2264/case-study-polymet).

## Test plan
- [ ] Case study renders correctly at `/customers/polymet`
- [ ] Logo displays correctly in both light and dark mode
- [ ] Frontmatter fields (industry, region, company_size,
supabase_products) render correctly in any related listing/filter UI

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a customer story about how Polymet uses Supabase for its users’
projects, including its experience and future plans.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 23:56:08 +10:00
Monica Khoury e143c94e5f fix(studio): clarify SMTP password field UX when a password is already saved (#50794)
## What
The custom SMTP password field showed a "Reveal" and "Copy" button next
to text saying "this password cannot be viewed once saved" —
contradictory, since those buttons implied there was something to reveal
or copy. In reality the backend never returns the saved password, so the
field was always blank and those buttons acted on an empty string.

## Why
Reported in FE-3765: users found it confusing whether saving other
fields would blank out their password, and the Reveal/Copy buttons
appeared broken.

## Fix
- Removed the non-functional Reveal/Copy buttons from the password
input.
- When a password is already saved, the field now shows a
`••••••••••••••••` placeholder and copy reading "Stored password is
hidden. Enter a new password to replace it." — matching the existing
`STORED_SECRET_PLACEHOLDER` pattern already used in the Replication
destination forms (BigQuery, ClickHouse, Snowflake, etc).
- No behavior change: leaving the field blank on save still preserves
the existing password (unchanged logic).

## Testing
- Manually verified in the running app.
- Added a component test (`SmtpForm.test.tsx`) covering both the
"password already saved" and "fresh setup" states.
- `tsc --noEmit`, `eslint`, and `prettier --check` all pass with no new
errors/warnings.

Fixes
[FE-3765](https://linear.app/supabase/issue/FE-3765/custom-smtp-password-field-ux-issues)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* Configured SMTP passwords are masked, with a notice that entering a
new password will replace the stored one.
* For new SMTP setups, the password field prompts for the SMTP server
password and does not show the stored-password notice.
* The SMTP password field no longer provides controls to reveal or copy
the password.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 16:40:53 +03:00
Ali Waseem f3094a29ce Remove cloud provider text from project cards (#50754)
Project cards and the project table showed the raw cloud provider
(`AWS`, `AWS_K8S`) alongside the region, which is an internal
implementation detail. Both now show the region only — matching the
table's existing "Region" column header.

Fixes FE-4441

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
  * Project cards now display the project’s region directly.
* Project tables show only the region in the region column, with “N/A”
when unavailable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 07:40:48 -06:00
Matt Rossman fd5ef806d6 feat(studio): enable Assistant tracing for High Compliance projects (#50759)
Assistant chats from High Compliance projects now flow to Braintrust
like any other project. The constraint that required suppressing them no
longer applies, see AI-1241 for the details.

`isTracingAllowed` now takes only the project region to maintain EU
exclusion. Traces also carry an `isHighComplianceProject` metadata
field, so the project's status at the time of the trace is recorded
rather than looked up later against a setting customers can toggle.

To verify, see [this sample
trace](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=afabbdcc-aa89-446e-aa52-78aaa90d44a4&v=Production&s=afabbdcc-aa89-446e-aa52-78aaa90d44a4&tvt=trace)
from a High Compliance project on staging which indicates that tracing
is now enabled for these projects and that it carries metadata showing
the high compliance status.

| High Compliance project setting | `isHighComplianceProject` metadata |
|--------|--------|
| <img width="1554" height="454" alt="CleanShot 2026-09-22 at 5 14 58
PM@2x"
src="https://github.com/user-attachments/assets/23901c6e-0d79-44e8-a6dd-43cdedba1799"
/> | <img width="1674" height="990" alt="CleanShot 2026-09-22 at 5 17 40
PM@2x"
src="https://github.com/user-attachments/assets/fb2fba55-bcc1-4136-a432-b33a5c7f9ca2"
/> |

Closes AI-1241


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Changes**
* AI project compliance information is now represented by a unified
high-compliance project status.
* AI response tracing is now determined by project region: tracing
remains disabled for EU and unknown regions, while known non-EU regions
are eligible.
* AI feedback and SQL generation now use the updated compliance and
regional handling.
* **Tests**
* Updated coverage to reflect the revised compliance and tracing
behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 09:39:01 -04:00
Steven EubankandClaude Sonnet 4.6 4730e3a640 docs: remove Generalist monitoring agent (#50784)
The Generalist is too broad and doesn't do any one thing well. Removing
it to focus on dogfooding the four targeted agents (Health, Security,
Performance, Capacity) before revisiting a combined agent.

https://github.com/supabase/supabase/pull/50396 new PR since this one
became messy with many upstream changes

## Problem

I don't like the generalist

## Solution

I am removing the generalist

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

Simply removing generalist:

https://supabase.com/docs/guides/observability/automate-with-agents

<img width="305" height="339" alt="image"
src="https://github.com/user-attachments/assets/bb537038-799f-4ec6-a357-c4cb3c552cba"
/>

So generalist will be no mas

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Removed the combined Generalist monitoring guide and its navigation
entry. Separate guides for health, security, performance, and usage
monitoring remain.
* The Generalist agent card and combined monitoring prompt are no longer
available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-09-23 15:31:35 +02:00
Gildas Garcia 1235245e6e Recovery codes: delete recovery codes when deleting the last MFA (#50731)
## Problem

The API prevents users from deleting their last MFA when they also have
recovery codes. However the UI doesn't and they may see an error instead
of being guided.

## Solution

Delete the recovery codes first.
<img width="1080" height="850" alt="image"
src="https://github.com/user-attachments/assets/67d999e7-06ff-4c0a-a2cc-11b864cb32f4"
/>

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. With an account that have only one MFA and recovery codes generated
2. Delete the MFA => You should see the dialog as in above screenshot.
Check the presence of _Your recovery codes will be deleted too_

After deletion, you shouldn't see the Recovery codes section anymore.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved multi-factor authentication management when recovery codes
are available.
- Users are warned that recovery codes will be deleted before removing
their last authentication factor.
- Removing the final authentication factor handles recovery-code
deletion first.
  - Cancelling deletion leaves the factor and recovery codes unchanged.
- Recovery-code handling applies only when enabled and relevant to
last-factor removal.
  - Recovery-code management is available in all environments.
- Delete actions are disabled while recovery-code status is loading, and
an error message appears if recovery codes fail to load.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 15:28:50 +02:00
Andrey A. 564eab8ad7 chore(self-hosted): update 2026-09-23 - 0.8.2 (#50790) 2026-09-23 15:16:17 +02:00
Jordi EnricandJoshen Lim 3063679f1b feat(auth): restore key last-used timestamps FE-2462 FE-4315 (#50732)
## Problem

Studio expected aliased fields from the last-used API-key endpoint, but
the live endpoint returns OTEL attribute names. This kept legacy API-key
activity unavailable and prevented Studio from showing activity for new
JWT signing keys. Tracks FE-2462 and FE-4315.

## Fix

Normalize the endpoint response at the data boundary, keep the
`showApiKeysLastUsed` feature flag, and show activity from the past 24
hours for new JWT signing keys. Legacy HS256 signing keys remain blank
because the analytics response does not provide a stable signing-key
record ID for them. The request remains hosted-only, permission-gated,
and non-blocking, and the existing last-rotated column remains intact.

## How to test

- Make a request with a legacy anon or service-role API key, then open
Project Settings > API Keys and verify its last request appears.
- Make an Auth request signed by a new JWT signing key, then open JWT
Keys and verify the matching key shows a Last used timestamp.
- Verify a new key without activity shows No requests in the past 24
hours.
- Verify the legacy HS256 signing-key row leaves Last used blank.
- Expected result: legacy API keys and new JWT signing keys display
activity from the shared endpoint without changing self-hosted Studio.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a **Last used** column for JWT signing keys on supported
platforms.
* Displays usage timestamps, loading and error states, or when a key has
had no requests in the past 24 hours.
  * Usage tracking now includes both API keys and JWT signing keys.
* **Bug Fixes**
  * Improved handling of usage records for legacy and current keys.
* Usage details appear only on supported platforms and for users with
the required permissions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 13:46:00 +02:00
K-Dog (Kevin) cee7461a9a chore: allow PITR without small compute addon (#50699)
We no longer require Small Compute add-on to configure PITR.
2026-09-23 19:31:12 +08:00
Monica KhouryandJoshen Lim 4b365eb4ee fix: pass projectRef/orgSlug to support link in table grid error (#50724)
## Summary

Fixes
[FE-3987](https://linear.app/supabase/issue/FE-3987/contact-support-pre-fills-the-wrong-supabase-project-id):
the "Contact support" button shown in the Table Editor's inline error
banner (e.g. "Failed to retrieve rows from table") didn't pass the
current project or organization to the support form. This caused the
support form to fall back to the user's first organization/project
instead of the one actually affected — especially noticeable when the
Management API request used to resolve the org also fails.

## Test plan

  - [ ] Open a project in Studio, go to **Table Editor**, open a table.
- [ ] Trigger a failing table query — either block the `rest/v1/<table>`
request in DevTools, or apply a filter with a mismatched type (e.g. `id
= 'abc'` on an int column).
- [ ] On the inline red "Failed to retrieve rows from table" banner,
click **Contact support**.
- [ ] Confirm the support form pre-fills the **correct organization and
project** — the one the failing table actually belongs to.
- [ ] Repeat with a project belonging to an organization that is *not*
first in your org list, to confirm it's not coincidentally correct.
- [ ] Repeat while simulating a Management API failure (e.g. block
`api.supabase.com`/`*.supabase.co/platform/*`) to confirm the org still
resolves correctly via the `orgSlug` fallback instead of silently
defaulting to your first org.
- [ ] Sanity check other "Contact support" entry points (header Feedback
dropdown, Help sidebar) are unaffected — they use a separate,
already-correct code path.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved error handling when project details cannot be loaded,
preserving relevant project and organization context.
* Improved fallback behavior for identifying the correct organization
when project information is unavailable or unresolved.
* Support requests opened from error messages now include applicable
project and organization information.
* Error messages now consistently display available additional actions
alongside contact support options.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 10:02:32 +00:00
Jordi Enric d1d9620cdf feat(studio): migrate Auth and Realtime reports to OTEL (#50663)
## Problem

PR #50638 migrates API Gateway and Data API reports to OTEL, but the
shared Auth and Realtime metrics still select legacy BigQuery SQL and
the `logs.all` endpoint.

## Fix

Route all active hosted shared API reports through the existing OTEL
builders after feature flags load. Remove unused report variants and
their source-selection abstraction while preserving the legacy BigQuery
path for self-hosted Studio.

This PR is stacked on #50638.

## How to test

- Open the Auth observability report and confirm its seven shared metric
requests use `logs.all.otel` with a `/auth` request-path filter.
- Open the Realtime observability report and confirm its seven shared
metric requests use `logs.all.otel` with a `/realtime` request-path
filter.
- Open the Data API report and confirm its existing OTEL behavior
remains unchanged with a `/rest` request-path filter.
- Expected result: hosted reports wait for ConfigCat before querying,
while self-hosted Studio continues using the legacy BigQuery path.
- Run `./apps/studio/node_modules/.bin/vitest --run
apps/studio/components/interfaces/Reports/Reports.constants.otel.test.ts
--config apps/studio/vitest.config.ts`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Changes**
- Shared API reports now support filtering by Auth, Realtime, and
PostgREST traffic.
- Filters for Storage, GraphQL, Functions, and other previously
supported traffic types are no longer available.
- Report queries now consistently use edge log data, improving
consistency across request totals, routes, errors, response times, and
network traffic metrics.
- OpenTelemetry-backed reporting is now enabled consistently across
supported report types where available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 09:44:45 +02:00
Julian Domke 3ec2dfca44 fix(stripe-atlas): guard stripe-atlas page in self-hosted mode (#50780) 2026-09-23 09:44:04 +02:00
Julien GouxandIvan Vasilov ab7783f2ca docs: add Mike Podobnik to humans.txt (#50779)
## Problem

Mike Podobnik is missing from the team list in
`apps/docs/public/humans.txt`.

## Solution

Add Mike Podobnik between Michelle Jubrey and Miranda Limonczenko,
preserving alphabetical placement and the existing plain-text format.

## Review instructions

1. Confirm the diff adds only `Mike Podobnik`.
2. Verify the name appears between Michelle Jubrey and Miranda
Limonczenko.

## Validation

- `git diff --check` passes.
- Verified a single insertion, no deletions, and correct alphabetical
placement between the adjacent entries.
- Build and application tests skipped for this static text-only
addition. The repository's Prettier check does not include `.txt` files.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md).
- Docs topic authoring checklist is not applicable: this change only
adds a name to a plain-text team list.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Mike Podobnik to the team listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-09-23 07:20:59 +00:00
Saxon FletcherandClaude Opus 5.5 cf5f1545bd feat(studio): add notebook permissions to scoped access tokens (#50764)
## Problem

The Management API now has `/v2/projects/{ref}/notebooks`, gated by the
new `project_notebooks_read` / `project_notebooks_write` FGA
permissions. Studio pins `@supabase/shared-types` 0.1.95, which predates
them, so the scoped access token form can't grant them. Tokens created
with every permission selected still get `403 forbidden` on the notebook
endpoints.

## Solution

- Bump `@supabase/shared-types` to 0.1.96 (Studio and shared-data),
which publishes the notebook permissions.
- Add a **Notebooks** entry to the permission catalog (Project category,
next to SQL Snippets).
- Add minimum roles to `FGA_SCOPE_MINIMUM_ROLE`: read is `readonly`,
write is `developer`, matching the OpenFGA model.

The docs permission tables don't change yet. They're built from the
docs' checked-in v2 spec, which doesn't include the notebook endpoints,
so the row appears on the next spec sync.

## Review instructions

1. In the preview, go to **Account → Access Tokens** and create a scoped
token for a project. Check that **Notebooks** is listed under Project,
and set it to Read-write.
2. List notebooks with the new token:
   ```bash
curl -s -H "Authorization: Bearer $TOKEN"
"https://api.supabase.com/v2/projects/$REF/notebooks"
   ```
It should return `200` with `{ "links": ..., "data": [...] }`, not
`403`.
3. Optional: create a token with Notebooks set to None, repeat step 2,
and check it returns `403`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
  - Added project-level notebook permissions to access tokens.
- Access tokens can now grant read-only or developer-level access for
managing shared project notebooks.
- Project notebook permissions are displayed in the token creation
interface and supporting documentation.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 15:18:28 +08:00
Gregor c8521c7ed4 Add Carson Adam to humans.txt (#50650)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Update humans text - new joiner

Bug fix, feature, docs update, ...

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
  - Added Carson Adam to the team member listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 09:14:47 +02:00
ec574f3a51 fix(studio): pass Authorization header to assistant list_policies tool (#50756)
<!-- ccr-slack-attribution -->
_Requested by **Saxon Fletcher** · [Slack
thread](https://supabase.slack.com/archives/C051L8U2EJF/p1789995309253479?thread_ts=1789995309.253479&cid=C051L8U2EJF)_

Resolves AI-1246

## Problem

**Before:** The Assistant's `list_policies` tool fails in about 70% of
traces. It only "succeeds" when the org has AI opt-in disabled, because
then it returns the privacy stub and never makes a request. When opt-in
is enabled, it runs the pg-meta query server-side with no
`Authorization` header, so the request is unauthenticated and fails. The
Assistant then falls back to `execute_sql`.

**After:** `list_policies` sends the caller's `Authorization` header,
the same way `execute_sql` in `studio-tools.ts` already does, so it
returns the project's RLS policies.

## Solution

`getTools` already receives `authorization` but didn't pass it to
`getSchemaTools`. This PR passes it through. `list_policies` builds `{
Authorization }` from it, and `getDatabasePolicies` gets an optional
`headersInit` argument that it forwards to `executeSql`, the same
pattern `getDatabaseFunctions` uses. Existing client-side callers of
`getDatabasePolicies` don't change.

Files: `lib/ai/tools/index.ts`, `lib/ai/tools/schema-tools.ts`,
`data/database-policies/database-policies-query.ts`, plus tests in
`lib/ai/tools/schema-tools.test.ts` (new) and
`lib/ai/tools/index.test.ts`.

## Review instructions

1. Read `schema-tools.ts` and compare it with the `authHeaders` handling
in `studio-tools.ts` (`execute_sql`).
2. On the preview, use an org with AI opt-in set to at least "schema"
and ask the Assistant to list the RLS policies on `public`.
`list_policies` should return the policies without falling back to
`execute_sql`.

Local gates (all passed):
- `pnpm typecheck` in `apps/studio` (next typegen + `tsc --noEmit`)
- `npx eslint` on touched files: 0 errors. The 2 warnings are on lines
this PR doesn't change.
- `npx vitest run lib/ai/tools/schema-tools.test.ts
lib/ai/tools/index.test.ts lib/ai/tool-filter.test.ts`: 24/24 passed. I
also ran the new header test against the old `schema-tools.ts` and it
failed, as expected.
- `SORT_IMPORTS=false npx prettier --config prettier.config.mjs --check`
on touched files

Follow-up, not in this PR: `getRlsKnowledge` in `fallback-tools.ts`
(self-hosted path) also calls `getDatabasePolicies` without headers,
even though a `headers` object is already in scope there.

## AI disclosure

Claude Code (agent) wrote this PR from the Slack request. @SaxonF (Saxon
Fletcher) is the accountable human owner. A human needs to review it
before merge.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill (N/A, no docs changes)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK

---
_Generated by [Claude
Code](https://claude.ai/code/session_0171Mk7SiKYLDDoAQvbDYfeK)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 14:38:40 +08:00
Stephen Morgan e7e76ca0da fix: misleading privatelink dns copy (#50771)
Somewhat urgent update to documentation based on new AWS behavior.
Will include additional details when we properly support custom DNS for
privatelink

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the PrivateLink endpoint creation guide’s Option A steps and
numbering. The DNS record note now stands on its own, without
referencing a removed step.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 21:55:26 -07:00
Saxon FletcherandDanny White cd77bebafd chore(ui): refresh shared button styles (#50197)
## What kind of change does this PR introduce?

UI polish / design system: refreshed button styles, related token
tweaks, and a shared floating-button plate.

Resolves DEPR-652.

## What is the current behavior?

Default, primary, and secondary buttons use older fills, borders, and
hover treatments. Primary still leans on brand scale utilities. Default
fills don’t always read as raised chrome across surfaces, and floating
copy / expand / scroll controls can let busy content show through
translucent fills. Call sites hand-roll `rounded-* bg-background`
wrappers for that.

## What is the new behavior?

Refreshes primary, default, and secondary buttons with medium-weight
labels, subtle shadows and inset edges, and smoother transitions.
Light-mode default buttons use a raised fill with an accent hover state,
primary text is brighter, and inline keyboard shortcuts inherit the
button’s colour.

Adds `FloatingPlate`: an opaque `bg-popover` shell for floating default
buttons (and small clusters). Migrates Studio, Docs-related patterns,
www, and `ui-patterns` floaters onto it so busy content no longer shows
through translucent fills. Positioning, z-index, and hover/focus reveal
stay on the plate’s `className`. Use `rounded="full"` for pills.

Also:

- Moves primary onto semantic `--primary` / `--primary-hover` (with a
light-theme override) instead of brand utility fills
- Tokenises button shadows as `--button-shadow-drop` /
`--button-shadow-raised` / `--button-shadow-default` on the Button base
- Aligns hover direction: darken on light mode, lighten on dark mode for
both default and primary
- Default fill stays opaque `bg-card` in light (occlusion) and
translucent `bg-muted` in dark (adapts to the local surface)
- Documents fills and `FloatingPlate` on the design-system Button page
(with a live example)
- Scales shared radius tokens in Studio and www; medium+ Button sizes
use a proportionally softer radius
- Fixes www nav CTA centering (`lg:inline-flex` instead of `lg:block`)
- Query detail Expand/Collapse wires `aria-expanded` / `aria-controls`

| Before | After |
| --- | --- |
| <img width="1074" height="438" alt="CleanShot 2026-09-18 at 15 52
51@2x"
src="https://github.com/user-attachments/assets/ef43da21-b053-4b7e-9ac4-ab8b428228ab"
/> | <img width="1090" height="464" alt="CleanShot 2026-09-18 at 15 50
59@2x"
src="https://github.com/user-attachments/assets/2ddc55fc-4c8d-499c-a280-f3db3d99023c"
/> |
| <img width="1082" height="446" alt="CleanShot 2026-09-18 at 15 52
35@2x"
src="https://github.com/user-attachments/assets/3dd5452d-325a-4e4a-a79d-26c6c6950a31"
/> | <img width="1078" height="446" alt="CleanShot 2026-09-18 at 15 51
13@2x"
src="https://github.com/user-attachments/assets/93666385-3e6e-42e0-9891-9cd6bb935b67"
/> |

## To test

### Design system

- [Button
page](https://design-system-git-chore-button-styles-supabase.vercel.app/design-system/docs/components/button):
default / primary in light and dark; hover should darken on light,
lighten on dark
- Same page: [Floating over
content](https://design-system-git-chore-button-styles-supabase.vercel.app/design-system/docs/components/button#floating-over-content)
/ [Floating
plate](https://design-system-git-chore-button-styles-supabase.vercel.app/design-system/docs/components/button#floating-plate)
example; Copy over SQL should stay opaque
- Spot-check hover on a code preview Copy control

### Docs

[Docs deploy
preview](https://docs-git-chore-button-styles-supabase.vercel.app/docs):

- [Docs
homepage](https://docs-git-chore-button-styles-supabase.vercel.app/docs):
top-right **Sign up** / **Dashboard** primary; menu icon beside it
(default icon button)
- Shrink below `lg` and open the hamburger drawer: bottom **Sign in**
(default) + **Start your project** (primary) medium block buttons
- Tab once for **Skip to content** (FloatingPlate)
- [MCP
guide](https://docs-git-chore-button-styles-supabase.vercel.app/docs/guides/ai-tools/mcp):
project picker
- [Apple
login](https://docs-git-chore-button-styles-supabase.vercel.app/docs/guides/auth/social-login/auth-apple):
**Generate Secret Key** button in the Apple Secret Generator
- Optional opacity check: any guide code block Copy control (e.g. at the
bottom of [Import data into
Supabase](https://docs-git-chore-button-styles-supabase.vercel.app/docs/guides/database/import-data))

### Studio

[Studio deploy
preview](https://studio-staging-git-chore-button-styles-supabase.vercel.app/):

- **Observability → Query Performance**: open a query detail →
Expand/Collapse pill + SQL Copy chip (dark: no bleed-through)
- **Observability → Query Insights**: select a query → Clear query pill
- **Table Editor → any table → Definition** → floating **Open in SQL
Editor**
- **Connect → Framework → Add files**: Copy on the code tabs
(FloatingPlate; light hover follow-up is DEPR-694)
- Tab once for **Skip to content**

### WWW

- [www deploy
preview](https://zone-www-dot-com-git-chore-button-styles-supabase.vercel.app/):
nav Sign in / Start your project vertical centering; hero medium CTAs
radius

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-23 03:43:00 +00:00
Danny White 59e2122833 docs(pipelines): nest destination guides (#50708)
## Problem

Pipeline destination guides live beside the Pipelines overview, so their
sidebar hierarchy and URLs do not reflect that they belong to Pipelines.

## Solution

Moves the BigQuery, ClickHouse, DuckLake, and Snowflake guides under
`/database/replication/pipelines/`, redirects the old URLs in both docs
preview (`apps/docs/next.config.mjs`) and production
(`apps/www/lib/redirects.js`), and updates internal documentation links.

The matching Studio changes, including destination-aware links from the
creation sheet, will follow in a separate PR.

## To test

- [Pipelines
overview](https://docs-git-dnywh-docsnest-pipeline-destinations-supabase.vercel.app/docs/guides/database/replication/pipelines)
- Destination guides:
[BigQuery](https://docs-git-dnywh-docsnest-pipeline-destinations-supabase.vercel.app/docs/guides/database/replication/pipelines/bigquery),
[ClickHouse](https://docs-git-dnywh-docsnest-pipeline-destinations-supabase.vercel.app/docs/guides/database/replication/pipelines/clickhouse),
[DuckLake](https://docs-git-dnywh-docsnest-pipeline-destinations-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake),
[Snowflake](https://docs-git-dnywh-docsnest-pipeline-destinations-supabase.vercel.app/docs/guides/database/replication/pipelines/snowflake)
- [Old Snowflake
URL](https://docs-git-dnywh-docsnest-pipeline-destinations-supabase.vercel.app/docs/guides/database/replication/snowflake)

## Review instructions

1. Open the Pipelines overview and confirm the four destination guides
appear beneath Pipelines in the sidebar.
2. Open each destination guide and confirm its nested URL and content
load correctly.
3. Open the old Snowflake URL and confirm it redirects to its new
location.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Moved BigQuery, ClickHouse, DuckLake, and Snowflake replication guides
to a dedicated pipelines section and updated related navigation and
links.
* **Bug Fixes**
* Added permanent redirects so existing links to the four destination
guides continue to work.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-23 10:53:50 +10:00
claude[bot]andClaude ea3a7743b1 feat(studio): default AI Assistant to GPT-6 Luna (AI-1245) (#50757)
<!-- ccr-slack-attribution -->
_Requested by **Saxon Fletcher** · [Slack
thread](https://supabase.slack.com/archives/C051L8U2EJF/p1790104861710199?thread_ts=1790104861.710199&cid=C051L8U2EJF)_

## Problem

**Before:** The Assistant's base model is `gpt-5.6-luna` at medium
reasoning effort.

**After:** The base model is `gpt-6-luna`, its direct successor, still
at medium effort. It costs half as much: $0.10/$0.50 per MTok against
$0.20/$1.20.

Resolves
[AI-1245](https://linear.app/supabase/issue/AI-1245/move-the-assistants-base-model-to-gpt-6-luna).

## Solution

This swaps `gpt-5.6-luna` for `gpt-6-luna` in
`apps/studio/lib/ai/model.utils.ts`: the model ID union, the
reasoning-support map, `ASSISTANT_MODELS`,
`DEFAULT_ASSISTANT_BASE_MODEL_ID`, and the OpenAI provider registry. The
old ID is removed, not kept next to the new one. A stored selection of
`gpt-5.6-luna` is no longer a known ID, so the client and `generate-v4`
both fall back to the new default. The eval cost table (AI-1242) and
eval experiments (AI-1243) are out of scope.

Source for the model ID and supported efforts (none/low/medium
default/high/xhigh/max): [OpenAI model docs: GPT-6
Luna](https://developers.openai.com/api/docs/models/gpt-6-luna).
`@ai-sdk/openai@4.0.41` types model IDs as a union plus `string & {}`,
so no SDK bump is needed.

## Review instructions

1. Check the diff in `model.utils.ts`. Say so if you'd rather keep
`gpt-5.6-luna` selectable as a fallback.
2. AI-1245 asks for the Assistant evals before shipping. Add the
`run-evals` label to run `braintrust-evals.yml` on this PR, or run `pnpm
--filter studio evals:run` locally. They have not been run yet because
they need OpenAI/Braintrust credentials.
3. Already run: studio `typecheck`, eslint + prettier on the changed
files, vitest for `lib/ai`, `pages/api/ai` and `state/ai-assistant` (264
passed), and `evals:preflight`.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] No docs topics changed

**AI disclosure:** Claude Code wrote this PR from start to finish. Saxon
Fletcher (@SaxonF) is the accountable human and must review it before
merge.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01W21zLTfzde6FFPyYGbGC6K


---
_Generated by [Claude
Code](https://claude.ai/code/session_01W21zLTfzde6FFPyYGbGC6K)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-23 10:03:27 +10:00
Danny WhiteandJoshen Lim 05a45dd1ed feat(studio): rename Replication to Pipelines (#50637)
## What kind of change does this PR introduce?

Feature and docs update.

## What is the current behavior?

The Dashboard lists Pipelines destinations under Database > Replication.
Read replicas have moved to Infrastructure, but the temporary notices
remain on the destinations page and new destination sheet.

Closes PIPE-1021.

## What is the new behavior?

The canonical Dashboard routes are Database > Pipelines, while legacy
Replication list and detail URLs permanently redirect to the equivalent
Pipelines routes. Navigation, command palette, shortcuts, pipeline
links, docs, and current marketing copy use Pipelines. Read-replica
notices and their obsolete dismissal state are removed.

| Before | After |
| --- | --- |
| <img width="1024" height="759" alt="Replication Database Agua Basket
Supabase"
src="https://github.com/user-attachments/assets/53f9f565-1ed1-43e9-a7d9-b66b2a47e948"
/> | <img width="1024" height="759" alt="2540"
src="https://github.com/user-attachments/assets/14ab2d61-d01c-483f-9d4f-0ac286dae159"
/> |

The Management API, pipeline behaviour, replication logs, and Postgres
replication terminology remain unchanged.

## To test

- Open `/project/<ref>/database/pipelines` and confirm the Database
navigation, page header, and pipeline breadcrumb say Pipelines.
- Open
`/project/<ref>/database/replication?source=bookmark#destinations` and a
legacy pipeline detail URL. Confirm each redirects to the matching
Pipelines URL while preserving parameters and fragments.
- From the Pipelines page, open Add destination. Confirm no read-replica
migration notice appears.
- Open the Pipelines guide and confirm its Dashboard steps lead to
Database > Pipelines.

## Before merge

- [ ] Get changelog entry reviewed
https://github.com/supabase/changelog/pull/262 and prepare to merge
simultaneously

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added dedicated **Database > Pipelines** pages for pipeline lists and
details.
- Added permanent redirects from legacy Replication URLs to their
corresponding Pipelines pages.
- Read replica management links now open **Settings > Infrastructure**.

- **Documentation**
- Updated Pipelines setup, monitoring, troubleshooting, and usage
guidance to reference the current dashboard locations.
  - Updated Realtime guidance to use **Database > Publications**.

- **Updates**
- Renamed dashboard navigation, breadcrumbs, commands, and keyboard
shortcuts from **Replication** to **Pipelines**.
  - Removed the “Read replicas have moved” notification.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-23 08:52:07 +10:00
Anthony Lio ef0f7f2b3d feat(docs): updates codetabs ui (#50734)
## Problem

codetab feels inconsistent vs its codeblock (radii + border_

## Solution

this pr is a proposal to update the codetab ui to convey proximity from
file name and its code

| state | preview |
| -------|------|
| before | <img width="822" height="482" alt="image"
src="https://github.com/user-attachments/assets/03addd77-37a3-4887-b7ba-9482bb5920e9"
/> |
| after | <img width="822" height="482" alt="image"
src="https://github.com/user-attachments/assets/670e92be-d90c-45db-965c-7c80e77cdd9e"
/> |

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. visit
`/docs/guides/getting-started/quickstarts/nextjs#6-allow-public-access-to-the-instruments-page`

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
  * Refined named code block styling in the documentation.
* Updated label spacing, borders, colors, and corner rounding for
improved visual alignment with code examples.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 21:45:35 +03:00
Miranda Limonczenko 7ce4ee53ae chore(docs) Retire supa-mdx-lint (#50602)
Closes
[DOCS-1289](https://linear.app/supabase/issue/DOCS-1289/get-the-linter-to-fix-what-it-flags-or-retirereplace-the-linter)

Stacked on #50600, which points contributors at the authoring skills.
Merge that one first.

## Problem

Contributors experienced friction with the linter. They felt nickle and
dimed for tiny nits and felt detracted from the work itself. PRs would
become noisy with tiny one-word suggestions.

Additionally, our homegrown linter is not very intelligent, causing
frequent overrides.

## Solution

This removes the linter entirely in favor of directing contributors to
use SKILLS instead.

The removal entails...

- **CI.** Delete the three `docs_lint` workflows: the PR check, the
external-PR comment companion, and the nightly `--fix` bot. Drop the
stale `zizmor.yml` ignore entry for the deleted workflow.
- **Tooling.** Delete `supa-mdx-lint.config.toml` and the 14 rule files.
Drop the `lint:mdx` script and the `@supabase/supa-mdx-lint` dependency
from docs, learn, and ui-library, and regenerate the lockfile.
- **Content.** Remove the 181 directives. A separate commit carries
Prettier's reformatting of the tables and blank lines those comments had
suppressed, so the deletion commit stays readable. No prose changes.
- **Style guide.** The word list states each rule directly instead of
describing what the linter flagged. Every term survives, including the
phrase groups that mirrored `Rule004ExcludeWords`.
- **Skills.** `write-the-docs`, `edit-the-docs`, and `review-the-docs`
drop `pnpm lint:mdx` from their self-review commands and check the word
list directly. `ask-the-docs`'s CI reference drops both workflows.

## Manual testing

1. Run `git grep -i supa-mdx-lint -- . ':!pnpm-lock.yaml'`. No matches.
2. Run `pnpm install --frozen-lockfile --lockfile-only`. It passes, so
the lockfile matches the three trimmed manifests.
3. Run `git diff master...HEAD --name-only --diff-filter=ACMR | grep -E
'\.(md|mdx)$' | xargs npx prettier --config prettier.config.mjs
--check`. All changed markdown passes.
4. Open the [reformatted filter
table](https://docs-git-docs-retire-mdx-linter-supabase.vercel.app/docs/guides/observability/logs#filter-events)
on the preview and compare it with
[production](https://supabase.com/docs/guides/observability/logs#filter-events).
The table renders the same.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Documentation guidance now uses manual prose and terminology review
with the shared word list.
* Clarified storage configuration and common Realtime channel mistakes.
* Improved table formatting, text wrapping, and selected reference
links.
  * Updated documentation authoring and review guidance.

* **Chores**
* Retired automated MDX linting from workflows and local validation
commands.
* Removed lint-suppression markers throughout documentation without
changing instructions.
  * Added targeted documentation review guidance for pull requests.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 10:00:41 -07:00
Julian Domke f65ee588c1 feat(stripe-atlas): wire up redemption flow (#50575) 2026-09-22 17:57:40 +02:00
Gildas Garcia 314856558b Recovery codes: fix condition to display them (#50716)
## Problem

1. Recovery codes section is displayed even when users don't have any
MFA set up
2. Codes modals are janky while the operation (generate or regenerate)
is pending

## Solution

1. Fix the condition checked to display the section (at least one MFA
set up)
2. Fix loading states handling

## Review instructions

On an account without any MFA set up:
1. Check that the recovery codes section is not displayed on 
2. Add a new MFA and check the modal for recovery codes appearance is
not janky
3. Delete the recovery codes (this button only exists on local and
staging envs)
4. Check that the warning for missing recovery codes is displayed
5. Generate the codes and check the modal appearance is not janky
6. Regenerate the codes and check the modal appearance is not janky

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Recovery-code dialogs now open only after code generation or
regeneration finishes.
* Generation and regeneration actions display a loading state while
processing.
  * Screen readers are notified when recovery codes are being generated.
* Confirmation actions are disabled while recovery codes are being
generated.
* Recovery-code status and related controls are shown only when a TOTP
factor is configured.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 17:10:24 +02:00
Alice Crosbie 01ba39163f Add Alice Crosbie to humans.txt (#50728)
Adding Alice Crosbie to humans.txt

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added Alice Crosbie to the team members list in the public team
information.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 16:22:06 +02:00
Andrey A. d7ff2c29e7 fix(self-hosted): make setup.sh work for non-root sudo users (#50653) 2026-09-22 16:08:49 +02:00
Andrey A. 8ed27fdb50 docs(auth): forward Set-Cookie headers on server-side OAuth redirect (PKCE) (#50722) 2026-09-22 16:01:37 +02:00
Jordi Enric 01321d9222 feat(studio): migrate auth log links to OTEL (#50718) 2026-09-22 16:00:21 +02:00
3253595fe4 feat(library): move Open in v0 into the page header (#50371)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature, bug fix.

Part 4 of 6 in a stack that splits the library redesign into reviewable
pieces.

## What is the current behavior?

`BlockItem` renders the Open in v0 button, and `BlockItem` sits inside
the Installation section — so the button appears partway down the page.
On guides that install a client first it appears twice, once for the
client and once for the block, and the MDX opts the extra one out with
`showOpenInV0={false}`.

So the page's markup already knows which registry item v0 should open.
Only the component using it is in the wrong place.

## What is the new behavior?

Velite reads that same signal at build time and records the item on the
document, so the page header renders one icon button beside the
framework selector, above the fold. `BlockItem` is left rendering only
the install command.

Guides with no installable item — the getting-started pages, the
TanStack DB generator, and the starters — get no button. Guides that
install a client first resolve to the block, not the client.

## Additional context

63 of 73 documents resolve to a registry item; the 10 that don't are
exactly the ones that should have no button.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Documentation pages now display an “Open in v0” button when supported.
* The button uses a compact, icon-only design alongside the framework
selector.

* **Improvements**
* The applicable v0 destination is determined automatically from
documentation content.
* The page-level action replaces individual block-level v0 buttons,
providing a more consistent experience.
* The button includes an accessible label and appears only for
documentation with a supported v0 destination.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-09-22 14:43:51 +02:00
3e79df3ece feat(library): serve the block catalog as Markdown and harden the exporter (#50370)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature, bug fix.

Part 3 of 6 in a stack that splits the library redesign into reviewable
pieces.

## What is the current behavior?

An agent can already fetch any guide as Markdown, but has no way to find
out what guides exist: the entry point is a rendered React page.

The exporter also fails quietly in ways that ship wrong output rather
than failing the build:

- An unknown component silently unwraps to its children, so a component
rename drops its rendered content.
- A registry item that cannot be read produces a page with no file
listing.
- A link to a missing page produces a 404 URL.
- An unrecognized install framework produces a plausible command for the
wrong CLI.
- Only absolute `/library/docs` links are rewritten, so in-page anchors
and sibling links break in the export.

## What is the new behavior?

`/library` negotiates Markdown the same way the guides do — `Accept:
text/markdown`, or an explicit `/library/index.md` — and returns a
categorized catalog with every block, its description, its framework
variants, and a link to each guide's Markdown.

`config/library.ts` is the single catalog description the generator
reads, and a test ties it to the content directory in both directions: a
guide cannot be added without a catalog entry, or listed without a
guide.

Each quiet failure above now throws, and links resolve against the page
they appear on and are checked against the set of published documents.

```bash
curl -H 'Accept: text/markdown' https://supabase.com/library
```

## Additional context

`config/library.ts` also carries the category and preview metadata the
redesigned homepage consumes in the last PR of the stack; here it is
exercised by the Markdown index and its test.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a browsable library catalog covering categories, blocks, starter
apps, and supported frameworks.
- Added Markdown versions of the library homepage and documentation for
compatible tools and workflows.
- Added framework-aware links and expanded registry information,
including dependencies and source details.
- Markdown requests now work for the homepage and documentation, while
browser requests continue receiving HTML.

- **Bug Fixes**
- Improved document link handling, metadata validation, slug
consistency, and detection of duplicate or missing documentation
entries.

- **Tests**
- Added coverage for catalog routes, Markdown generation, homepage
negotiation, document parsing, and framework-specific links.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-09-22 14:14:04 +02:00
Joshen Lim aef1599d3e Add keyboard shortcut for saving notebook (#50707)
### Context

Adds a keyboard shortcut for saving a notebook in the explorer 
<img width="269" height="112" alt="image"
src="https://github.com/user-attachments/assets/c9ab1c4b-fbb3-40ed-8f10-47301e16e6b3"
/>

Also shifts the keyboard shortcuts for queue operations into the table
editor registry - more contextual to there since queue operations is
specifically for the table editor only

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added a keyboard shortcut (`Mod+S`) for saving notebooks in Explorer.
  - The save toolbar action now displays its keyboard shortcut.
- Restored table editing shortcuts for saving pending edits, toggling
the operation queue, and undoing changes (`Mod+S`, `Mod+.`, and
`Mod+Z`).

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 19:29:40 +08:00
Joshen Lim c7880e328f Add a live preview markdown editor for explorer (#50717)
## Context

We've gotten some requests for a better markdown editing experience in
the Explorer so this PR adds a proper live preview markdown editor,
similar UX to how you'd edit notion or obsidian documents. Opting to use
`lexical` as the main library to support this UI for its size and
composability without going too low level like prose mirror

<img width="933" height="452" alt="image"
src="https://github.com/user-attachments/assets/7161ae6c-3dff-4b36-818f-01b5e573f121"
/>

Actual file changes are just this size excluding the package-lock
<img width="150" height="39" alt="image"
src="https://github.com/user-attachments/assets/bb01f2cf-8ef7-4daf-975b-614b2d817b54"
/>

## Changes involved

This adjusts the UX for markdown cells a little
- Clicking on a markdown cell immediately allows you to edit
- Instead of the existing behaviour which requires a double click to
enter "Edit" state
- Editing doesn't eject you into a monaco editor, but rather inline
editor
  - Nicer transition
- Clicking out of the cell persists the cell's content
  - No more "Cancel" or "Save" buttons

## To test
- [ ] Verify that editing markdown cells are still working
- [ ] Verify that tabs do get marked with unsaved changes if you edit a
markdown cell


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Replaced the previous Markdown editing workflow with an always-visible
inline editor.
- Added rich Markdown editing for headings, lists, links, blockquotes,
code blocks, inline code, and text formatting.
  - Changes are saved automatically when leaving the editor.
  - Markdown formatting shortcuts take precedence within the editor.

- **Bug Fixes**
  - Avoids unnecessary saves when content has not changed.

- **Tests**
- Added coverage verifying Markdown formatting conversions remain
consistent and repeatable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 19:09:25 +08:00
ChloeGarciaMillerandandGildas Garcia ef7b2a5211 fix: ESLint errors relating to accessibility in integration section (#50224)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Improving accessibility by adding aria-label.
Adding Tooltip for icon only buttons.

## What is the current behavior?

Some `aria-label` and `Tooltip` are missing.

## What is the new behavior?

Icon-only buttons have now Tooltip and aria-label have been added.

## Additional context

No visual changes have been made.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Accessibility Improvements**
* Added descriptive tooltips and screen-reader labels to search-clear
and close-panel controls.
* Added accessible labels and tooltips for managing secrets, showing or
hiding secret values, and editing or removing foreign tables.
* Improved the lint details panel close control with a descriptive
label.
* Prevented duplicate tooltip announcements for assistive technologies.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-09-22 11:31:30 +02:00
Joshen Lim 14bda8a5cf Joshenlim/fe 4438 explorer allow deleting notebookchat without first having to (#50701)
### Context

Adds context menu to the explorer nav to allow users to delete notebooks
or chats from there (instead of having to open the notebook / chat
first, then select delete from the header)
<img width="304" height="339" alt="image"
src="https://github.com/user-attachments/assets/2ad0f21c-0d49-407c-97a2-ef11ae59e280"
/>

### Changes involved:
- Consolidates the rendering of explorer nav items into a single
component that both `ExplorerNavNotebook`, `ExplorerNavHome` and
`ExplorerNavChats` use.
- We were previously rendering a link for notebook, and a button for
chats. But chats' button was just calling `router.push` under the hood.
- Opting to use a Context to handle the delete functionality such that
we can render the confirmation modal just once at the layout level since
there's multiple places that have this delete functionality - notebook
tab, chat tab, context menu in each of the explorer navs

### To test
- [ ] Verify that navigating around the explorer is status quo
- [ ] Verify that you can delete a notebook/chat from within the
notebook/chat tab
- [ ] Verify that you can delete a notebook/chat from the explorer nav
- [ ] Verify that after deleting a notebook/chat from either locations,
the tabs should clear

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Unified chat and notebook navigation with direct links and active-item
highlighting.
- Added context-menu options to delete chats and notebooks with
confirmation and status notifications.
- Added double-click support for keeping recently viewed chats and
notebooks open as tabs.
  - Deleted items and their related tabs are removed automatically.

- **Tests**
- Updated Explorer navigation tests for the unified link-based item
behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 16:21:55 +08:00
Alaister YoungandAlaister Young 2f1ad03640 fix(www): prevent GitHub stars from falling back to zero (#50704)
The www build saves failed GitHub star requests as zero, which the
navigation displays as `0K`. This passes `GITHUB_TOKEN` through Turbo's
build environment and preserves a valid previously generated count when
a request fails.

If there is no valid previous count, the navigation displays “GitHub”
and the homepage contribution graphic omits the number. Cached fallback
is available only when the previous generated content exists; rate
limiting is a possible cause of the original failure, but has not been
confirmed from deployment logs.

## To test

- Run `pnpm --filter www exec vitest run
scripts/lib/githubStars.test.ts` — all 16 tests pass, covering
authenticated and anonymous requests, rate limiting, malformed
responses, and missing or invalid cached content.
- Build with a valid `GITHUB_TOKEN` and check that the navigation and
homepage graphic show the star count.
- Simulate a failed GitHub request with and without existing generated
content. Confirm that a valid previous count is retained, or that no
zero count appears when none is available.

Verified locally: live GitHub fetch through the new loader, Turbo dry
run with strict environment filtering and `GITHUB_TOKEN` allowed,
Prettier, and ESLint (one existing default-export warning). Full build
and browser checks have not been run.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- GitHub star counts are now displayed only when valid; otherwise, the
interface shows a clear fallback label.
- Star counts can fall back to cached data when GitHub is unavailable or
returns invalid results.
- Builds without GitHub data now complete gracefully instead of failing.

- **Tests**
- Added coverage for authenticated and unauthenticated requests, cached
fallbacks, invalid responses, and clean builds.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-22 18:04:14 +10:00
Juan Manuel Valenzuela 845e1fb5df Add Juan Manuel Valenzuela to humans.txt (#50700)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Add Juan Manuel Valenzuela to humans.txt

## What is the current behavior?

Juan Manuel Valenzuela is not in humans.txt

## What is the new behavior?

Juan Manuel Valenzuela has joined Supabase

## Additional context

Done as part of the onboarding tasks.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added Juan Manuel Valenzuela to the team member list in the public
contributor
information.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->


Provide a clear numbered procedure that the PR reviewer can walk
through.

1. For example, `Open the live and preview links side-by-side.`
2. For example, `See the issue is fixed.`


## Checklist

Check all before review:

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Juan Manuel Valenzuela to the team member list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 07:53:10 +00:00
Kostas Botsasandcoderabbitai[bot] e1e16d4a18 docs(troubleshooting): document custom roles in troubleshooting guide (#50510)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs

## Additional context

Explicitly mention custom roles in the troubleshooting guide for
password authentication failure

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added troubleshooting guidance for using custom PostgreSQL roles with
direct connections, dedicated pooling, and shared pooling.
- Documented temporary authentication failures that may occur after
resetting a custom role’s password when using shared pooling.
- Added guidance to verify the password directly and retry shared-pooler
connections with bounded retries.
  - Added a link to password-rotation documentation for further details.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-09-22 09:19:47 +02:00
Danny White ec53175b8a refactor(ui): rename text-brand to text-primary (#50564)
## What kind of change does this PR introduce?

Refactor. Follow-up to #49871.

## What is the current behavior?

Branded (green) text still uses the `text-brand` classname while the
colour comes from `--primary`.

## What is the new behavior?

**Rename-only:** `text-brand` → `text-primary` across callsites and
docs. Leftover `bg-brand` / `border-brand` alias to `brand-default`. No
intentional colour changes in this PR.

This better matches how we treat our green in other components and
props, like `variant="primary"` for green buttons.

## To test

On light mode: smoke-test that branded text still looks like #49871
(readable green, not the bright fill).

-
[Homepage](https://zone-www-dot-com-git-dnywh-depr-316-text-brand-de2380-supabase.vercel.app/):
“Scale to millions” uses `text-primary`
- [Docs
homepage](https://docs-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/docs):
branded links like “More on self-hosting” are still readable
- [Typography
docs](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/typography):
documents `text-primary`
- [Colour
usage](https://design-system-git-dnywh-depr-316-text-brand-to-primary-supabase.vercel.app/design-system/docs/color-usage):
`text-primary` is visibly darker than `bg-brand-default` _on light mode_
- [Studio auth
providers](https://studio-staging-git-dnywh-depr-316-text-brand-to-60fa6c-supabase.vercel.app/dashboard/project/_/auth/providers):
enabled provider badge text readable; status dot stays bright green

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated branded text, link hover states, icons, badges, indicators,
and highlighted content across the Design System, Docs, Studio, Learn,
UI Library, and marketing experiences to use the primary theme color.
* Updated syntax highlighting and table-of-contents styling for
consistent primary-color presentation.
  * Refined brand color fallback behavior for bright fills and borders.

* **Documentation**
* Updated color-usage and typography guidance to recommend the primary
text utility.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 16:19:03 +10:00
Danny White c837116598 fix(studio): sort replicated tables by name by default (#50696)
## Problem

Replicated tables on the pipeline detail page reshuffle after a reset.
API order is unstable, and the default client sort was by status, so
status changes moved rows around.

Fixes PIPE-1137.

## Solution

Default the replicated tables table to sort by `schema` + `name`
ascending. Status sorting remains available via the Status column
header.

## To test

1. Open a project with a pipeline that has several replicated tables:
`/project/<ref>/database/replication/<pipelineId>`.
2. Confirm the Replicated tables list is alphabetical by `schema.name`,
with the Table column showing ascending sort.
3. Reset one table and confirm its row stays in place while its status
updates.
4. Click the Status column header and confirm status sorting still
works.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Replicated tables are now sorted alphabetically by schema and table
name by default.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 16:15:18 +10:00
Joshen Lim 47592ace0f Set last visited page when going to preferences from explorer (#50691)
### Context

Resolves FE-4442

Tiny one to follow up from
https://github.com/supabase/supabase/pull/50670 - just sets the last
route before visiting account page from the explorer. Otherwise hitting
"back to dashboard" from account preferences brings you back to the
/projects page, rather than back to where you left off from the explorer

Also added a fix for scrolling to the corresponding section on the
preferences page when landing with a `#` in the URL - was bugging out as
there's some sections that render skeletons first (`ProfileInformation`
and `AccountIdentities`) which changes the height of the content, so the
native `#` behaviour doesn't land correctly.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Updated the Preferences link to navigate directly to the account page.
- Preserved the current route when navigating to Preferences, improving
return navigation behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 12:39:19 +08:00
Danny White a4be167491 fix(studio): clarify Warehouse status and navigation (#50554)
## What kind of change does this PR introduce?

Bug fix and UI polish.

## What is the current behavior?

The Warehouse Connect option repeats its own name, and a configured
Warehouse has no direct route back to its management page. Warehouse
table states also use badges instead of the status-dot pattern used by
Replication, and a backfilling table can misleadingly appear as “Caught
up”.

## What is the new behavior?

- Describes Warehouse as an analytical endpoint and adds a low-emphasis
“Manage Warehouse” link from the Connect sheet.
- Shares Replication’s status-dot presentation with Warehouse while
keeping feature-specific state mapping separate.
- Shows replication lag only for live tables, so backfilling and “Caught
up” are never presented together.

| Before | After |
| --- | --- |
| <img width="1244" height="1156" alt="CleanShot 2026-09-18 at 14 03
49@2x"
src="https://github.com/user-attachments/assets/60aa3496-6930-491a-af9e-9ffcfb035a0f"
/> | <img width="1216" height="1214" alt="CleanShot 2026-09-18 at 14 04
33@2x"
src="https://github.com/user-attachments/assets/84a8c80e-d8d1-4ee5-9cce-352d1f6477c2"
/> |
| <img width="1314" height="1414" alt="CleanShot 2026-09-18 at 14 02
50@2x"
src="https://github.com/user-attachments/assets/8871a4a5-0543-4290-91a7-9da949ec4c49"
/> | <img width="1308" height="1498" alt="CleanShot 2026-09-18 at 14 02
43@2x"
src="https://github.com/user-attachments/assets/ac3fc6d1-5b4d-4a3a-8ab7-bb54025e2145"
/> |

## To test

1. Open `/project/<ref>?showConnect=true&connectTab=warehouse` for a
project with Warehouse configured. Confirm the mode subtitle says
“Analytical endpoint”. Confirm the new “Manage Warehouse” button opens
`/project/<ref>/integrations/warehouse/overview`.
2. Open `/project/<ref>/integrations/warehouse/overview` while a table
is backfilling. Confirm it has a pulsing amber status dot and does not
show “Caught up”.
3. Once the table is live, confirm it has a green “Live” status dot and
its lag appears normally.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added clearer Warehouse setup progress messaging with a “View
progress” action while setup is running.
- Connection details are shown once the Warehouse is provisioned or has
live tables.
- Added a Cancel action when editing changed Warehouse table selections.
- Updated table statuses with live, syncing, and warning indicators,
including animated syncing states.
  - Lag details are displayed for live tables when available.
  - Renamed the Warehouse connection option to “Analytical endpoint.”

- **Style**
  - Improved Warehouse management controls and table name readability.
  - Removed the table Size column from the Warehouse overview.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 12:21:40 +10:00
Saxon Fletcher 509c797be1 fix(studio): keep Explorer Home tab selected (#50684)
## Problem

Selecting Explorer's Home tab immediately redirects back to the last
visited tab.

## Solution

Clear the saved Explorer destination before navigating Home. Explorer
owns this behavior through a generic `onTabChange` callback on the
shared tabs component.

## Review instructions

1. Open Explorer with the Home tab visible, then open a query, notebook,
or chat.
2. Click Home. Confirm it stays selected and the previous tab remains
open.
3. Switch back to the previous tab, then use Tab and arrow keys to
select Home. Confirm it stays selected.
4. Select a content tab, leave Explorer, and return. Confirm the last
visited tab still restores.

## Validation

Mouse and keyboard regression tests and existing restoration tests pass
(12 tests). Typecheck, targeted lint, and formatting checks pass.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md).
- Docs authoring checks: not applicable; no docs changes.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Explorer navigation now clears the previously saved Explorer
destination when returning to the home tab.
* Returning to Explorer home works consistently through both mouse and
keyboard navigation.
* **Tests**
* Added coverage for Explorer tab navigation, history cleanup, and
selected-tab state.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 11:34:31 +10:00
Danny WhiteandJoshen Lim a31ca2bad0 fix(ui): make brand text readable across themes (#49871)
## What kind of change does this PR introduce?

Bug fix and design-system update. Resolves DEPR-316.

Follow-up rename (`text-brand` → `text-primary`) is in a dedicated PR
(https://github.com/supabase/supabase/pull/50564) stacked on this one.

## What is the current behavior?

`text-brand` resolves to the canonical bright brand green in places that
need readable text, which fails WCAG AA on light surfaces. A separate
`text-brand-display` token adds another green for large type.

## What is the new behavior?

- `text-brand` maps to accessible `--primary` (light mode darkened to
meet ~4.5:1 AA)
- `--hue` / `--primary-hue` aligned to 157.5
- `text-brand-display` removed; former display callsites use
`text-brand`
- Bright fills/borders stay on `brand-default`
- Design-system colour and typography docs updated

| Before | After |
| --- | --- |
| <img width="514" height="112" alt="CleanShot 2026-09-02 at 11 13
09@2x"
src="https://github.com/user-attachments/assets/4e0138a9-a32d-4e4c-a426-90736706e1e7"
/> | <img width="512" height="138" alt="CleanShot 2026-09-21 at 11 42
05@2x"
src="https://github.com/user-attachments/assets/164cc5b1-a0c5-4e93-95f1-80016641a114"
/> |
| <img width="864" height="266" alt="CleanShot 2026-09-02 at 11 13
53@2x"
src="https://github.com/user-attachments/assets/3c1ca53f-bf9e-431e-bc15-816b4a275b8e"
/> | <img width="882" height="248" alt="CleanShot 2026-09-21 at 11 41
37@2x"
src="https://github.com/user-attachments/assets/24828e7b-ed6b-44cb-b9dc-becc3398bdfc"
/> |
| <img width="782" height="692" alt="CleanShot 2026-09-02 at 11 16
30@2x"
src="https://github.com/user-attachments/assets/fc871977-77bc-47fb-9e0e-9284e0ecd5cc"
/> | <img width="730" height="690" alt="CleanShot 2026-09-21 at 11 42
52@2x"
src="https://github.com/user-attachments/assets/bf479515-d5f9-471e-b82d-f097c0f4b56c"
/> |
| <img width="480" height="306" alt="CleanShot 2026-09-02 at 11 18
53@2x"
src="https://github.com/user-attachments/assets/03f341f4-f02e-44f8-a2b2-8c31670d0427"
/> | <img width="470" height="300" alt="CleanShot 2026-09-21 at 11 43
19@2x"
src="https://github.com/user-attachments/assets/9df18217-d5e6-48b8-ba0b-579d2664b94b"
/> |
| <img width="960" height="300" alt="CleanShot 2026-09-02 at 11 32
04@2x"
src="https://github.com/user-attachments/assets/6b1d9373-7a71-4247-81ff-26441604b09d"
/> | <img width="980" height="306" alt="CleanShot 2026-09-21 at 11 44
13@2x"
src="https://github.com/user-attachments/assets/41ad4784-02ec-4b29-b860-32af9fa79aa8"
/> |
| <img width="924" height="214" alt="CleanShot 2026-09-02 at 11 34
44@2x"
src="https://github.com/user-attachments/assets/1de661fe-c7b6-499b-a94f-e4737436ec79"
/> | <img width="752" height="162" alt="CleanShot 2026-09-21 at 11 44
56@2x"
src="https://github.com/user-attachments/assets/1811890f-0660-4445-84e9-447720954fa1"
/> |

## To test

Test each callsite **in light mode** (dark mode is largely unchanged).

### WWW

-
[Homepage](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/):
“Scale to millions” uses readable brand text (display token is gone)
-
[Careers](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/careers):
small “Careers” eyebrow readable; green dividers stay bright
`brand-default`
-
[Contact](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/contact-us):
email / policy links use readable brand text
-
[Regions](https://zone-www-dot-com-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/regions):
“Ask about early access to BYOC” readable

### Docs

- [Docs
homepage](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs):
“DOCS” wordmark and resource links readable
- [Database
overview](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/guides/database/overview):
nav / footer brand links readable
- [JavaScript
reference](https://docs-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/reference/javascript/introduction):
active sidebar treatment readable

### Design system

-
[Typography](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/typography):
documents `text-brand` only (no display)
- [Colour
usage](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/docs/color-usage):
`text-brand` vs `bg-brand-default`
- [Design-system
homepage](https://design-system-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/):
brand text examples across themes

### Studio

- [Auth
providers](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/auth/providers):
enabled provider badge text readable; status dot stays bright
- [Database
policies](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/database/policies?new=true):
template hover text more legible
- [Database
connections](https://studio-staging-git-dnywh-depr-316-brand-text-tokens-supabase.vercel.app/dashboard/project/_/observability/connections):
“Live” status readable; animated dot stays bright green

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-22 10:07:28 +10:00
Zoë Braddock e1bdcc99db chore: add Zoe Braddock to humans.txt (#50679)
## Problem

Zoe Braddock works at Supabase now, but she is not yet in humans.txt!

## Solution

Add Zoe to humans.txt

 ## Additional context

Part of onboarding -
https://app.notion.com/p/supabase/Add-yourself-to-humans-txt-bbf5004b775f828d8132815552553f32?source=copy_link

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. For example, `Open the live and preview links side-by-side.`
2. For example, `See the issue is fixed.`


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
  - Added Zoë Braddock to the publicly available team member list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-22 10:11:19 +12:00