Commit Graph
34678 Commits
Author SHA1 Message Date
Jonathan Fulton 25f9f7c5e3 docs(realtime): add note about sync event behavior in Presence (#42338)
## What kind of change does this PR introduce?

Documentation improvement for Realtime Presence.

## What is the current behavior?

The Presence documentation doesn't explain that during a `sync` event,
clients may receive `join` and `leave` events simultaneously even when
no users are actually joining or leaving. This can be confusing for
developers new to Presence.

## What is the new behavior?

Added an explanatory note clarifying that:
- During `sync`, you may receive `join` and `leave` events at the same
time
- This is normal and expected
- It reflects state reconciliation with the server, not real user
movement

This helps developers understand this behavior upfront rather than
having to discover it through debugging.

## Additional context

As mentioned in the issue, this behavior is discussed in [this community
discussion](https://github.com/orgs/supabase/discussions/26748) where
the solution had to be discovered by users.

Fixes #41175

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified behavior during sync events in the Realtime Presence guide.
Added explanation that simultaneous join and leave events may occur due
to state reconciliation rather than actual user movement changes.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-19 08:08:08 +00:00
Joshen Lim 3f05963630 Joshen/fe 2573 table editor user still wants to run the query if it causing (#43004)
## Context

Related to this previous PR
[here](https://github.com/supabase/supabase/pull/42321)

Table Editor: Adding a CTA to the `HighQueryCost` UI to allow users to
proceed with fetching data despite the high query cost warning, to
prevent completely blocking the users from their workflows (realised
that certain heavy queries are required and this safeguard shouldn't be
creating dead-ends for users)

<img width="1159" height="264" alt="image"
src="https://github.com/user-attachments/assets/5fa01f7f-4442-4349-91f2-f4275e177f89"
/>

Clicking "Load more" will open a confirmation dialog, in which
proceeding to load the data will thereafter suppress this preflight
check for the table, for the rest of the browser session

<img width="450" height="305" alt="image"
src="https://github.com/user-attachments/assets/d3197a5d-a861-47a8-95da-e157972ce092"
/>

## Other changes

- Also bumped the query cost threshold from 100,000 to 200,000 - the
former might have been too aggressive 😓
- (Unrelated) Added query cost tooltip for cron jobs high query cost
warning
<img width="450" height="230" alt="image"
src="https://github.com/user-attachments/assets/d2c66972-7c4c-4f99-818c-e90a0991c2f5"
/>
2026-02-19 16:02:59 +08:00
Yogeshwaran C faba829684 docs: fix broken "Control your costs" link in billing overview (#42906)
## What kind of change does this PR introduce?

Documentation fix

## What is the current behavior?

In `apps/docs/content/guides/platform/billing-on-supabase.mdx`, the
"Control your costs" link has an empty URL (`[Control your costs]()`),
making it non-functional. Users clicking this link are not taken to the
cost control documentation.

## What is the new behavior?

The link now correctly points to `/docs/guides/platform/cost-control`,
which is the existing page that covers Spend Cap, Billing Alerts, and
other cost control features.

## Additional context

The other two links in the same list (`Your monthly invoice` and `Manage
your usage`) already have correct URLs. This appears to be an oversight
where the cost-control page was created but the link in the billing
overview was not updated.
2026-02-19 07:58:46 +00:00
Joshen Lim 31a85bcb97 Final clean up for useQueryStateWithSelect (#43008)
## Context

Final clean up of `useQueryStateWithSelect` - removes the hook
2026-02-19 15:22:07 +08:00
Joshen Lim b77de2dfbc Hide actions in schema visualizer if schema has no tables (#42849)
## Context

In database/tables (Schema visualizer), if the schema has no tables,
clicking on "Auto layout" causes a client error as we're trying to run
the `dagre.layout` on a graph with 0 nodes and edges

Opting to hide all actions on the Schema Visualizer if there's no tables
(understandably we've been leaning towards disabled states rather than
hiding, but in this case i was thinking hiding is better since that's an
empty state - unless some actions were applicable in the empty state,
but in this case none of the actions are)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Bug Fixes**
* Improved reliability of the database schema interface by strengthening
empty state handling
* Ensured database actions are properly hidden when no tables exist in
the schema

* **Refactor**
* Consolidated schema state validation logic for better code
maintainability

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-19 14:32:35 +08:00
Joshen LimandAli Waseem e125ad7ff6 Chore/deprecate use query state with select part 03 (#42734)
## Context

Related to FE-2461

More refactoring to clean up usage of `useQueryStateWithSelect`, mainly
in the database pages
- Roles
- Triggers
- Functions
- Enumerated Types

## To test

In each of those pages, verify that
- [ ] Clicking the "new" cta updates the URL params, and refreshing
should re-open the sheet
- [ ] Editing an existing item should update URL params, and refreshing
should re-open the sheet with the right item
- Verify that if the URL param has the wrong id, page should not open
the sheet, show a toast, and reset the URL param
- [ ] Deleting an existing item should update URL params, and refreshing
should re-open the sheet with the right item
- Verify that if the URL param has the wrong id, page should not open
the sheet, show a toast, and reset the URL param

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-02-19 13:46:25 +08:00
Jordi Enric 5a3d12edec docs: update axiom docs (#42983) 2026-02-19 12:42:25 +08:00
Jordi Enric b1dfb7e474 sentry: 0.1 sampling (#43003) 2026-02-18 15:39:57 -07:00
Charis ccf8ce2aee db: add incident_status_cache table (#43002)
Database migration — adds a new table.

## What is the current behavior?

There is no table to cache AI-derived incident metadata.

## What is the new behavior?

Adds an `incident_status_cache` table for caching AI-derived incident
metadata.
2026-02-18 16:13:04 -05:00
Vaibhav f56361511e fix: use generic avatars for team mems (#42995)
closes https://github.com/supabase/supabase/issues/42989
2026-02-18 21:07:20 +00:00
Prashant Sridharan 52e2bf6325 Added a new agency webinar (#43000)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added a new webinar event
Speakers are both already in the system
2026-02-18 19:58:20 +00:00
Ali Waseem 649fd08dc9 chore: E2E tests for Realtime (#42518)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Minor amount of tests for Realtime because we have zero E2E coverage
here

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Tests**
* Added comprehensive end-to-end test coverage for the Realtime
Inspector: channel join/leave, start/stop listening, broadcast
workflows, message display, JSON validation, and cleanup to improve
reliability.
* Added supporting test helpers/utilities to enable deterministic
navigation, channel operations, message waiting, and modal interactions
for stable test execution.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-18 12:27:09 -07:00
6d1a064a39 feat(studio): enable functions counter on Home for self-hosted environments (#42992)
Feature

## What is the current behavior?

The Functions counter on the Home page is only displayed in platform
environments.
In self-hosted setups, the counter is hidden due to a platform guard,
even though Functions may be available.

## What is the new behavior?

The Functions counter is now also displayed in self-hosted environments.

This is now possible thanks to the following PRs:

- #40690  
- #42322  
- #42349  
- #42350  

These PRs introduce and enable the API required for listing Functions in
Studio, making it feasible to show the Functions count outside of the
platform environment.

## Additional context

Related issues: #36285

This change removes the platform-only restriction around the Functions
card in the Home interface, allowing feature parity between platform and
self-hosted deployments where the Functions API is available.

---------

Co-authored-by: Andrey A. <56412611+aantti@users.noreply.github.com>
Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com>
2026-02-18 18:40:15 +00:00
Andrey A. b9ec8927c4 use chainguard images for minio and tidy up configs 2026-02-18 18:46:36 +01:00
Inder Singh 97d9865ed4 feat(docker): add deno-cache volume and use Deno.serve 2026-02-18 18:34:34 +01:00
Ali Waseem 9d1aef9d6b chore: update image alt (#42958)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

React Doctor fix: image alt addition
2026-02-18 17:20:57 +00:00
Ali Waseem c57c341244 chore: add ratchet rules to stop nesting components (#42962)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

The changes required for this React Doctor need more thought that I can
hammer with AI. Just need to stop this from happening in the future with
Ratchet rules
2026-02-18 10:09:08 -07:00
Ali Waseem 2dd75cbfdd chore: Update aria-controls and aria-expanded for components (#42961)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- React Doctor fixes for aria controls and aria expanded
- Updated eslint to include the role
2026-02-18 16:41:10 +00:00
Michal KleczekandChris Chinchilla 3ae6cd7b1f docs: expand joins-and-nesting with join modifiers and multi-language examples (#42973)
This PR:
- Adds a new Join types and join modifiers section to the
joins-and-nesting guide.
- Documents default left join semantics for embedded relations.
- Explains !inner for inner-join behavior.
- Explains : aliasing and ! join modifiers (!inner, !foreign_key).
- Adds join/filter examples with expected JSON results.
- Includes query examples across JavaScript, Dart, Swift, Kotlin,
Python, and URL.

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-18 16:17:12 +00:00
Ali Waseem 1890624a1a fix: add missing keys to studio (#42957)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Cleanup from React Doctor! Components missing keys
2026-02-18 09:05:22 -07:00
4370c2e83c docs: Read replicas page general overhaul (#42368)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Tom Gallacher <tgallacher@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-02-18 15:56:43 +00:00
Zachary Stallings 192cbfe999 One liner: Adding more specific css to target open and closing animations without affecting the resize animation (#42069)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix. One liner.

## What is the current behavior?

The resizable product menu to the left on drag responds with a slow drag
animation.
This is inconsistent with other resizable drag animations.


![supabase-resizable-before](https://github.com/user-attachments/assets/d8807aa9-2d9a-4371-a4a3-13f0983a1866)

## What is the new behavior?

the drag animation is consistent and snappy!


![supabase-resizable-after](https://github.com/user-attachments/assets/716c28af-3cba-4d97-8ee5-8d1331dd6bd5)


## Additional context

As far as I can tell the transition animation on the `ResizablePanel` is
for the open and closing of the menu and not for resizing. It looks like
a just overly broad transition target (`transition-all`).

The react-resizable-panels seems to use flex grow to do the animation.
The `transition-all` which is currently on the `ResizablePanel`
component is causing the flex grow to animate and this in turn is
causing some minor layout thrashing.
<img width="406" height="579" alt="Screenshot 2026-01-21 at 8 40 24 PM"
src="https://github.com/user-attachments/assets/9282731a-f1d6-411d-9092-25f0bddff29f"
/>

After this update the layout thrashing from flex-grow is fixed.
<img width="539" height="520" alt="Screenshot 2026-01-21 at 6 38 00 PM"
src="https://github.com/user-attachments/assets/dc2b2e28-8298-400e-8f19-77edaf6b9884"
/>

Related to [this](https://github.com/supabase/supabase/issues/27801)
issue.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Refined sidebar animation to animate width-related properties only,
delivering smoother and more responsive open/close transitions without
changing timing.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-18 08:52:48 -07:00
Katerina Skroumpelou 9065909e3e fix(docs): use pnpm exec for redocly instead of npx (#42987)
## Problem
The [spec generation Makefile started
failing](https://github.com/supabase/supabase/actions/runs/22142393017)
with:

```text
  ReferenceError: React is not defined                                                                     
      at Object. (/Users/.../_npx/.../node_modules/styled-components/dist/styled-components.cjs.js:1:860)  
```

This occurred when `@redocly/cli@2.18.2` was released on Feb 16, 2026.
The error happens because `npx @redocly/cli` installs the package in an
isolated temporary cache without properly resolving peer dependencies
(React is a peer dependency of styled-components).

## Solution
Replace `npx @redocly/cli` with `pnpm exec redocly` to use the installed
version from `packages/generator/package.json`.

This ensures:                                                         

1. **Proper dependency resolution** - pnpm installs the full dependency
tree including peer dependencies
2. **Version control** - locked to the version in package.json instead
of always fetching latest
3. **Reproducible builds** - won't break when new versions are released
## Changes
- Replace `npx @redocly/cli` → `cd $(GENERATOR_DIR) && pnpm exec
redocly` (5 places)
- Replace `npm run` → `pnpm run` for consistency with project's package
manager (6 places)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated build configuration to execute documentation generation tasks
from a centralized generator directory with unified package management,
ensuring consistent handling of OpenAPI bundling, TypeScript
documentation, and validation workflows.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-18 15:28:01 +00:00
supabase-supabase-autofixer[bot]andsupabase-releaser[bot] 36592e0a2e feat: update @supabase/*-js libraries to v2.97.0 (#42982)
This PR updates @supabase/*-js libraries to version 2.97.0.

**Source**: supabase-js-stable-release

**Changes**:
- Updated @supabase/supabase-js to 2.97.0
- Updated @supabase/auth-js to 2.97.0
- Updated @supabase/realtime-js to 2.97.0
- Updated @supabase/postgest-js to 2.97.0
- Refreshed pnpm-lock.yaml

This PR was created automatically.

Co-authored-by: supabase-releaser[bot] <223506987+supabase-releaser[bot]@users.noreply.github.com>
2026-02-18 17:14:13 +02:00
Coenen Benjamin a15ef2b084 Add Benjamin Coenen to humans.txt (#42865)
Add myself into `humans.txt`


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated team information in public metadata.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-18 22:18:18 +08:00
Yogeshwaran C f829c31990 fix: correct article usage for acronyms (an MFA, an SMS, an OTP) (#42915)
## What kind of change does this PR introduce?

Documentation / text fix (grammar)

## What is the current behavior?

Several places in the codebase use "a" before acronyms that start with
vowel sounds, which is grammatically incorrect:

- "enter a MFA code" (MFA is pronounced "em-eff-ay", starting with a
vowel sound)
- "a SMS with a OTP" (SMS = "ess-em-ess", OTP = "oh-tee-pee")

## What is the new behavior?

Corrected to use "an" before acronyms with vowel sounds:

- "enter an MFA code"
- "an SMS with an OTP"

## Files changed

- `apps/studio/data/profile/mfa-challenge-and-verify-mutation.ts` -
comment fix
- `apps/docs/content/guides/platform/multi-factor-authentication.mdx` -
user-facing docs
- `apps/docs/docs/ref/javascript/v1/upgrade-guide.mdx` - code comment in
example
- `apps/docs/docs/ref/dart/v0/upgrade-guide.mdx` - code comment in
example

## Additional context

The rule: use "an" before acronyms pronounced with an initial vowel
sound, regardless of the first letter. "MFA" starts with "em" (vowel
sound), "SMS" starts with "ess" (vowel sound), "OTP" starts with "oh"
(vowel sound).
2026-02-18 15:10:38 +01:00
Ivan Vasilov 554a91e1b2 fix: update storage to use the new URL endpoint (#42974)
This pull request introduces improvements to the handling of storage
endpoints in the Studio app, ensuring that storage operations utilize
the correct endpoint and enhancing maintainability through import path
updates and code clarity. The most significant changes are grouped
below:

**Storage Endpoint Handling:**

* The `useProjectEndpointQuery` hook now returns both `clientEndpoint`
and `storageEndpoint`, allowing storage operations to use a dedicated
endpoint when available.
* In the `StorageExplorerStateContextProvider`, the logic for
constructing the resumable upload URL now prefers `storageEndpoint` if
present, falling back to `clientEndpoint` otherwise. This ensures
uploads use the most appropriate endpoint.
* The context provider now sets `clientEndpoint` to `storageEndpoint`
when available, further aligning storage requests with the correct
endpoint.
* The dependency array for the provider effect now includes
`storageEndpoint`, ensuring state updates when the storage endpoint
changes.

**Code Quality and Maintainability:**

* Import paths in `storage-explorer.tsx` have been updated to use alias
(`@/`) references, improving clarity and maintainability. Type-only
imports are also used where appropriate, reducing bundle size and
potential circular dependencies.

**Code Clarity:**

* Added comments to chunk size calculations in the upload logic,
clarifying the rationale behind chunk sizing for different file sizes.
2026-02-18 14:53:17 +01:00
Yogeshwaran C 418f68b3c1 docs: fix doubled words in IPv4 FAQ and email templates docs (#42907)
## What kind of change does this PR introduce?

Documentation fix

## What is the current behavior?

1. In `apps/docs/content/troubleshooting/enabling-ipv4-addon.mdx`, the
heading reads "Will the project instance **will** be restarted?" with a
doubled "will"
2. In `apps/docs/content/guides/auth/auth-email-templates.mdx`, the `{{
.Email }}` description reads "Empty **when when** trying to link an
email address..." with a doubled "when"

## What is the new behavior?

1. Heading now reads "Will the project instance be restarted?"
2. Description now reads "Empty when trying to link an email address..."

## Additional context

Minor grammar fixes for documentation clarity.
2026-02-18 13:47:19 +00:00
Jordi Enricandgithub-actions[bot] a806f7dc44 feat: add OTLP log drain (#42869)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added OpenTelemetry Protocol (OTLP) as a log drain destination with
configurable endpoint, protocol (HTTP/Protobuf), gzip compression, and
custom headers.
* OTLP appears as a selectable destination in the Log Drains UI with its
own icon and form fields.

* **Documentation**
* Added a full OTLP guide including HTTP/Protobuf details, Collector
example, and authentication examples.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-02-18 14:44:07 +01:00
Jordi Enric d56517fb7a sentry: lower sampling (#42981)
lowers to 3%
2026-02-18 13:27:47 +00:00
Andrey A. e43e7fff4e add s3 configuration how-to for self-hosted 2026-02-18 14:15:42 +01:00
Katerina SkroumpelouandChris Chinchilla 0419494c6d docs: add troubleshooting article for UNUSED_EXTERNAL_IMPORT build warning (#42977)
## Description

Adds a troubleshooting article for the `UNUSED_EXTERNAL_IMPORT` build
warnings
that Vite/Rollup/Nuxt users see when bundling apps that use
`@supabase/supabase-js`.

**File:**
`apps/docs/content/troubleshooting/unused-external-import-warning-vite-rollup.mdx`

## What the article covers

- What the warning looks like
- Why it's a false positive (re-exported external imports not recognised
as "used"
  by Rollup's code-body check)
- `onwarn` suppression snippet for Vite/Rollup
- `onwarn` suppression snippet for Nuxt

## Related

- https://github.com/supabase/supabase-js/issues/2010
- https://github.com/supabase/supabase-js/pull/2122

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-18 15:04:31 +02:00
Ali Waseem a8b953bf63 chore: added E2E tests for webhooks (#42951)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

E2E suite for webhook integrations since we've broken it before, ideally
stop this from happening again
2026-02-18 21:01:47 +08:00
kemal.earth 48e4140202 chore(studio): remove [edge] label from logs search suggestions (#42944)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This removes the label `[edge]` from the suggested list of log types in
the new logging interface. 🤞 this doesn't break anywhere else.

| Before | After |
|--------|--------|
| <img width="966" height="260" alt="image (1)"
src="https://github.com/user-attachments/assets/24fb996e-8bed-4d48-81f2-a3942c58ba1f"
/> | <img width="380" height="39" alt="Screenshot 2026-02-17 at 12 55
58"
src="https://github.com/user-attachments/assets/595a28be-bb27-4797-b82d-b3c4e32adb3d"
/> |
2026-02-18 10:35:14 +00:00
Ivan Vasilov 3d4459ef98 chore: Add more ratchets for deprecated packages and default exports (#42948)
This PR adds a new rule `no-restricted-imports` for deprecating old
packages. For now, only `react-data-grid` and `react-contexify` have
been added.

The ratchet baselines has been rerun with the new rules.
2026-02-18 09:11:54 +01:00
Etienne Stalmans a5f92e797d chore: pg-meta quotes (#42941)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Manual replacement of quotes

## What is the new behavior?

Uses defined SQL literal function

## Additional context

No security risk, but builds better sql strings following best practice
and avoids potential issues with frontend mis-escaping something
2026-02-18 15:28:21 +08:00
Daniel Velázquez 1fd07fbfab docs: Add Daniel Velázquez Lara to humans.txt (#42960)
Add `Daniel Velázquez Lara` to humans.txt
2026-02-17 15:13:04 -08:00
Matt Rossman 2fc062a725 feat(assistant): detect HIPAA customers in assistant logic (#42787)
Detects HIPAA customers server-side in the assistant code path. Threads
`isHipaaEnabled` boolean through `getOrgAIDetails` → `generate-v4` →
`generateAssistantResponse`. The motivation is to support online evals
down the road, where we'll want to exclude HIPAA projects from Assistant
tracing.

This PR follows existing patterns for checking if HIPAA is enabled for a
project (org has HIPAA addon + project is sensitive). Example
[[1]](https://github.com/supabase/supabase/blob/a5dd0a96716561443778f38a518b61d6cac95c19/apps/studio/components/interfaces/Settings/Addons/Addons.tsx#L75),
[[2]](https://github.com/supabase/supabase/blob/6858d4e18d9359d573fe3dff73bc4e5fa1cfe219/apps/studio/hooks/misc/useOrgOptedIntoAi.ts#L69).

```ts
const hasHipaaAddon = subscriptionHasHipaaAddon(subscription) && settings?.is_sensitive
```

(I call it `isHipaaEnabled` in this PR to avoid it being misunderstood
as just the org-level addon, rather it's a combo of that addon being
present AND high compliance being enabled on the project).

### Verification steps

<details><summary>Click to view the steps I followed to sanity check it
works with the local stack</summary>

Tested locally with `mise fullstack`:

1. Found my org's subscription ID:

   ```sh
docker exec platform-db-1 psql -U postgres -c "SELECT id, customer_id,
status FROM orb.subscriptions;"
   ```

2. Added HIPAA addon to it:

   ```sh
   docker exec platform-db-1 psql -U postgres -c "
     UPDATE orb.subscriptions
SET price_intervals = price_intervals || '[{\"price\": {\"unit_config\":
{\"unit_amount\": \"350.00\"}, \"external_price_id\":
\"addon_security_hipaa\", \"item\": {\"name\": \"HIPAA\"}}}]'::jsonb
     WHERE id = '<subscription_id>';"
   ```

2. Toggled on High Compliance (Project Settings → General)

3. Added a temporary log after `getOrgAIDetails` in `generate-v4.ts`:

   ```ts
   console.log('[HIPAA]', { isHipaaEnabled })
   ```

4. Sent a message in the AI Assistant → `isHipaaEnabled: true`

5. Toggled off High Compliance → resent → `isHipaaEnabled: false`

6. Removed addon from subscription, left project toggle on →
`isHipaaEnabled: false`

   ```sql
   -- Find addon index:
   SELECT ordinality - 1 as idx FROM orb.subscriptions,
jsonb_array_elements(price_intervals) WITH ORDINALITY AS elem(val,
ordinality)
     WHERE id = '<subscription_id>'
     AND val->'price'->>'external_price_id' = 'addon_security_hipaa';

   -- Remove by index:
UPDATE orb.subscriptions SET price_intervals = price_intervals - <idx>
     WHERE id = '<subscription_id>';
   ```

All three cases confirm `isHipaaEnabled` requires both the org addon and
the project-level toggle.


</details> 

Closes AI-434

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added HIPAA mode detection and exposed it in AI workflows.
* API request functions now accept optional custom authorization headers
for downstream calls.

* **Tests**
* Added tests covering HIPAA scenarios and verifying authorization
header propagation in related flows.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-17 15:59:26 -05:00
hallidayo 4dff317c06 docs: org oauth redirect (#42940)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Redirect for docs button in [oauth
panel](https://supabase.com/dashboard/org/_/apps)
2026-02-17 12:47:29 -07:00
Ignacio Dobronich 22ef5a306c chore: pitr entitlement check in db backups (#42901)
Adds the PITR entitlement check to the `Database Backup` -> `PITR` page.
2026-02-17 15:24:46 -03:00
Ali Waseem c558c5d22e fix: updated tab bar behavior (#42875)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Fix: remove tab auto completion in favor of tab handlers
2026-02-17 17:05:35 +00:00
Jeremias Menichelli e97b067a94 chore(humans): Add Jeremias Menichelli to humans.txt (#42950) 2026-02-17 17:31:41 +01:00
supabase-supabase-autofixer[bot]andsupabase-releaser[bot] 3a5fd59a12 docs: update js sdk docs (2.96.0) (#42946)
Updates JS sdk documentation following stable release. 
Ran `make` in apps/docs/spec to regenerate tsdoc files.

**Details:**
- **Version:** `2.96.0`
- **Source:** `supabase-js-stable-release`
- **Changes:** Regenerated tsdoc files from latest spec files

🤖 Auto-generated from @supabase/supabase-js stable release.

Co-authored-by: supabase-releaser[bot] <223506987+supabase-releaser[bot]@users.noreply.github.com>
2026-02-17 17:12:18 +01:00
Ali Waseem 28977561f2 fix: update header title to wrap in span instead of fragments (#42885)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Fix missing space in Table Editor row panel header ("Add new row totest"
→ "Add new row to test") by wrapping the HeaderTitle content in a span
to prevent flexbox whitespace collapsing between sibling elements. Its
only used in a single place

<img width="670" height="50" alt="Screenshot 2026-02-16 at 2 11 03 PM"
src="https://github.com/user-attachments/assets/29ab98b3-bb3e-488d-ac05-c934f7e028a0"
/>
2026-02-17 07:22:54 -07:00
Ivan Vasilov a41d7138a5 feat: add vitest configuration and tests for X-Robots-Tag headers (#42873)
This pull request introduces a testing setup for the Next.js app using
Vitest. The main changes include the addition of a test configuration,
test scripts, and a sample test for the Next.js config. It also adds
relevant dependencies to support Vitest and path resolution, and updates
the lock file accordingly.

Testing infrastructure:

* Added a sample test file `next.config.test.ts` using Vitest to verify
that specific headers are present in the Next.js configuration.
* Created a Vitest configuration file `vitest.config.ts` with TypeScript
path resolution support via the `vite-tsconfig-paths` plugin.

Scripts and dependencies:

* Added `test` and `test:watch` scripts to `package.json` for running
and watching tests, and included `vitest` and `vite-tsconfig-paths` as
dev dependencies.
2026-02-17 07:15:55 -07:00
Mats Kindahl c29a2ba1e8 Add Mats Kindahl to humans.txt (#42938)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adding me to humans.txt

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.
2026-02-17 21:32:03 +08:00
d1ac14c788 fixing doc inconsistencies: privatelink is in beta not alpha, and rea… (#42601)
fixing doc inconsistencies: privatelink is in beta not alpha, and read
replicas can be requested by contacting account rep.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs Update.

## What is the current behavior?

Inconsistent docs.

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-17 14:19:28 +01:00
Francesco Sansalvadore 0b2edc77fd chore(studio): refine "Create..." commands (#42772)
- Move the "Create..." command menu item at the top of the Actions group
based on feedback.
- Remove "Pro" badge and replace with "New" on Analytics and Vector
buckets
- Hide "Create Data API" and "Create GraphQL" as "create" doesn't apply
2026-02-17 14:08:47 +01:00
Francesco Sansalvadore 6a2dabc058 fix: card paddings (#42775)
Uniform card paddings to use the `--card-padding-x` css var and `px-card` tw utility class.
2026-02-17 13:59:29 +01:00
Bobbie Soedirgo df464bb823 docs: update configurable superuser settings (#42850)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

Superuser settings list is out of date

## What is the new behavior?

Update superuser settings with [new
configs](https://github.com/supabase/postgres/blob/21338c84583acc6f0d65fc99f014c83206aaa32d/ansible/files/postgresql_config/supautils.conf.j2#L13)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated PostgreSQL custom configuration guide with new superuser-level
settings options including deadlock timeout, parameter logging, network
connectivity, safe update enforcement, and function tracking
capabilities.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-17 13:53:48 +01:00