mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
2c76bb371bc7ff3742aa59e35fd1a7b9ae790bd2
38198
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
2c76bb371b |
chore(studio): gate dead code with knip in CI (#49721)
Makes knip a CI gate for Studio so dead files and unused dependencies fail the PR instead of piling up. Third PR in the stack, on top of #49719 (dead code) and #49720 (unused deps), which get Studio to a clean run. **Changed:** - knip `pnpx knip@~5.50.0` → root devDependency `knip@6.32.3`, `pnpm knip` now runs it. The old `pnpx` form was actually broken: it resolved knip's `typescript` peer to TS 7 and crashed with `ts.getDefaultLibFilePath is not a function`. (6.33.0 is newer but blocked by `minimumReleaseAge`.) - `knip.jsonc` rewritten for v6 with a `workspaces["apps/studio"]` block. Framework-convention files (`router.tsx`, `start.ts`, `routes/**`, `compat/**`, `api/server.js`) are `entry` rather than `ignore` — an ignored file's imports aren't traced, which is how `ShellFallback.tsx` (only imported from `routes/__root.tsx`) was being reported as dead. knip 6's Next.js plugin already covers `instrumentation*.ts`, `proxy.ts`, `pages/**`; its tanstack-router plugin only looks under `src/`, hence the manual entries. Narrow `ignoreIssues` for graphql-codegen output and the `CONSTRAINT_TYPE` enum; `ignoreDependencies` for the five implicit deps from #49720, each with a comment; `ignoreBinaries: ["vercel"]`. - `apps/studio/CLAUDE.md`: one bullet on the gate and where framework files go. **Added:** - `.github/workflows/studio-knip.yml` — path-filtered to `apps/studio/**` + knip/pnpm config, mirrors `studio-lint-ratchet.yml`'s setup (no sparse checkout: knip needs every workspace's `package.json` to resolve the graph). Runs `pnpm knip --workspace apps/studio --reporter symbols --reporter github-actions` so findings show up as inline PR annotations. ~5s locally. Scope notes: the gate is Studio-only — the full-monorepo run still has ~400 dead files in `www`/`docs`/`blocks`, which is a separate effort. `exclude: ["types", "exports"]` is kept, so unused exports aren't gated yet, but `enumMembers`/`duplicates` are (they caught real things in #49719). ## To test - `pnpm knip --workspace apps/studio` exits 0 on this branch - The `Studio Dead Code (knip)` workflow runs on this PR and is green - Sanity-check the gate bites: add a throwaway `apps/studio/lib/unused.ts`, run `pnpm knip --workspace apps/studio` → reports it and exits 1 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **CI** * Added automated dead-code and unused-dependency checks for the Studio workspace on relevant pushes and pull requests. * Results appear in workflow summaries and as inline pull request annotations. * **Maintenance** * Improved analysis of framework-convention files and Studio code. * Standardized the local code-quality check and updated its configuration support. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
3260053e52 |
chore(studio): remove unused dependencies found by knip (#49720)
Removes the Studio dependencies knip reports as unused, and declares one it reports as unlisted. Second PR in the stack (on top of #49719, followed by #49721 which adds the CI gate). **Removed:** - `@ai-sdk/provider`, `@ai-sdk/provider-utils` — zero references - `eslint-plugin-jsx-a11y` — the `jsx-a11y/*` rules resolve through the plugin registered by `eslint-config-next` (via `eslint-config-supabase/next`); verified 259 a11y warnings still fire after removal - `common`, `config` from `devDependencies` — duplicates of the `dependencies` entries **Added:** - `@tailwindcss/postcss` as a Studio devDependency — `apps/studio/postcss.config.cjs` loads it (through `config/postcss.config`), but only `packages/config` declared it, so under pnpm's strict isolation it was never resolvable from Studio's own `node_modules` **Kept deliberately** (nothing imports them by a specifier knip can follow, but removing them breaks things — they get `ignoreDependencies` entries in #49721): `lodash-es` (string-resolved in `vite.config.ts`), `raw-loader` (loader string in `next.config.ts`), `import-in-the-middle` / `require-in-the-middle` (Sentry/OTel runtime hooks, #35030), `@babel/core` (resolution pin, #45876). Heads-up on the lockfile: ~500 of the lines are pnpm re-resolving `apps/www`'s stale auto-installed vitest peer from `vite@6.4.3` → `8.2.1` (www doesn't depend on vite directly; Studio already runs vitest on vite 8). Any dependency change triggers it — not specific to this PR. ## To test - `pnpm install --frozen-lockfile` succeeds - `pnpm dev:studio` — Tailwind styles still apply (the postcss plugin now resolves from Studio) - `pnpm lint --filter=studio` still reports `jsx-a11y/*` warnings, no "Definition for rule not found" - `pnpm --filter www test` (www's vitest now runs on vite 8) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated Studio’s development tooling configuration. * Removed unused package dependencies and development tools. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
0b27205ae4 |
fix(studio): clarify fast database reboot (#49741)
## What kind of change does this PR introduce? Bug fix. Resolves DEPR-657. ## What is the current behavior? The Fast database reboot description suggests the action may fail to recover from some failure modes, which can be read as a risk of the reboot itself. ## What is the new behavior? The description clearly explains that the faster option restarts only the database service, has less downtime than a full project restart, and leaves other project services running. | Before | After | | --- | --- | | <img width="1460" height="512" alt="CleanShot 2026-08-31 at 09 24 49@2x" src="https://github.com/user-attachments/assets/2d4a940c-4d66-4753-99d8-9d0d2b4951af" /> | <img width="1458" height="500" alt="CleanShot 2026-08-31 at 09 31 18@2x" src="https://github.com/user-attachments/assets/f58aa351-5c8c-4a9a-b31d-b771659defd3" /> | ## To test 1. Open a project's **Settings > General** page. 2. Under **Project availability**, tab to **Restart project**, then tab again to the adjacent chevron button. 3. Press Enter and confirm focus moves to **Fast database reboot**. 4. Confirm its description reads: “Restarts only the database service, with less downtime than a full project restart. Other project services remain running.” 5. Confirm the project availability descriptions appear as secondary text beneath their action labels. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility Improvements** * Improved keyboard navigation with separate tab stops for restart actions and restart-type selection. * Added clearer labeling and focus behavior when choosing a restart type. * **UI Improvements** * Clarified that fast database restarts affect only PostgreSQL while other services continue running. * Improved text contrast on the project settings page. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b0e31be89a |
chore(studio): remove dead code found by knip (#49719)
Removes Studio code that nothing imports, as reported by knip. First PR in a stack of three: this one is pure deletions, #49720 removes the unused dependencies, #49721 upgrades knip and adds the CI gate so this doesn't accumulate again. Every file was verified with a repo-wide grep for its basename, exported symbols, and string/dynamic imports before deletion — none are reachable via `next/dynamic`, a barrel file, or a config. **Removed:** - `Billing/Usage/UsageWarningAlerts/{CPU,RAM,DiskIOBandwidth}Warnings.tsx` (whole directory) - `DataWarehouse/FormFooterChangeBadge.tsx` (whole directory) - `Database/Replication/ReplicationDiagram/EmptyReplicationDiagram.tsx` - `Integrations/Vercel/OrganizationPicker.tsx` - `QueryInsights/QueryInsightsTable/QueryInsightsTableRow.tsx` - `hooks/misc/useTrackExperimentExposure.ts` - `data/ai/{parse-client-code,sql-policy}-mutation.ts`, `data/misc/parse-query-mutation.ts`, `data/database/table-check-rls-mutation.ts` - `data/notifications/notifications-v2-{archive-all-mutation,summary-query}.ts` + their two now-unused keys in `notifications/keys.ts` (`listV2` kept) - `data/platform-apps/platform-app-{update,signing-key-delete}-mutation.ts` - `DateTimeFormats.DATE_ONLY` and the unused `Notebooks.{MarkdownCell,LogCell,ChartConfig}` types **Changed:** - `ReportPadding` no longer has a duplicate default export; its 9 default importers (observability pages) now use the named export Not removed: `CONSTRAINT_TYPE`'s unused members mirror the closed set of `pg_constraint.contype` values, so they're documentation rather than dead code — suppressed narrowly in #49721's knip config instead. ## To test - `pnpm --filter studio run typecheck` and `lint:ratchet` pass - Observability pages (`/project/[ref]/observability/*`) still render with padding — they're the only code touched, via the `ReportPadding` import change - Notifications popover still loads and marks-as-read (the removed keys weren't used for invalidation) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Removed Features** - Removed CPU, memory, and disk usage warning alerts. - Removed the Vercel organization picker and empty replication diagram. - Removed query insights row actions and several SQL assistance tools. - Removed notification summary and archive-all capabilities. - Removed platform app update and signing-key deletion actions. - Removed the form change-count badge and experiment exposure tracking. - **Refactor** - Updated observability reports to use the revised report layout export. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
8439b0c77e |
fix(www): prevent Safari publicity logo clipping (#49742)
## What kind of change does this PR introduce? Bug fix for [DEPR-658](https://linear.app/supabase/issue/DEPR-658/fix-clipped-v0-and-langchain-logos-in-safari). ## What is the current behavior? Inline publicity logos reuse the same SVG clip-path ID. Safari can resolve v0 and LangChain against another logo's clipping rectangle, causing the artwork to appear cropped or letterboxed. ## What is the new behavior? Each publicity logo uses a namespaced clip-path ID. A focused regression test verifies that SVG IDs are unique and every `url(#...)` reference has a matching definition. | Figure | | --- | | Before | | <img width="2200" height="388" alt="CleanShot 2026-08-31 at 09 58 44@2x" src="https://github.com/user-attachments/assets/99ef02e4-e436-4155-880a-6291364ea4cd" /> | | After | | <img width="2196" height="370" alt="CleanShot 2026-08-31 at 09 58 00@2x" src="https://github.com/user-attachments/assets/d36a9b83-737b-47f1-9f12-a110b3c82f23" /> | ## To test 1. Open the deploy preview homepage in Safari. 2. Scroll to “Trusted by fast-growing companies worldwide”. 3. Confirm the v0 and LangChain logos are fully visible and the other publicity logos are unchanged. |
||
|
|
86c813ec03 |
fix(notebooks): reset insert offset when anchor cell moves (#49694)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? When a cell gets moved via `move_cell` operation in `deriveNotebookDiff`, the `insertedAfter` offset map is not cleared for that anchor cell. This causes later `insert_cell` operations anchored on the same (now-moved) cell to apply the stale offset on top of the correct current-position lookup, resulting in the new cell landing after the wrong position. ## What is the new behavior? The offset for an anchor cell is now cleared from `insertedAfter` when it gets moved, since cells previously inserted after it stay behind at its old location and should not affect subsequent inserts at its new position. A regression test has been added that reproduces the exact ticket scenario (insert after cell-1, move cell-1 after cell-3, insert after cell-1 again) and verifies the correct final cell order. ## Additional context Fixes: https://linear.app/supabase/issue/FE-4308/insert-anchored-to-a-previously-moved-cell-lands-after-the-wrong-cell <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed notebook cell insertions after moving an anchor cell, ensuring new inserts appear relative to the anchor’s updated position. * Preserved the placement of inserts made before the anchor cell was moved. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8790e657e9 |
feat(ai): include org slug in Assistant Braintrust span metadata (#49692)
<!-- ccr-slack-attribution --> _Requested by **Matt Rossman** · [Slack thread](https://supabase.slack.com/archives/D0A79RYJKRB/p1787926891744399)_ # Problem Assistant spans in Braintrust record only the numeric `orgId`, whereas support tickets show org slug. This incurs an extra manual step to resolve the ID through admin studio before the trace can be found. # Fix Adds `orgSlug` to spans, sourced from the same verified org lookup that produces `orgId`. Renamed the request body's `orgSlug` to `rawOrgSlug` to distinguish the verified slug from getAIDetails, following the existing rawRequestedModel / requestedModel pattern. ## How to review See sample trace [94863b6d-aaa9-449a-a9c9-981ad40e614a](https://www.braintrust.dev/app/supabase.io/p/Assistant/trace?object_type=project_logs&object_id=5a8d02e5-b3b6-40cc-ba76-ecee286478f4&r=223112cd-33f4-45c4-a273-8d3781689448&s=223112cd-33f4-45c4-a273-8d3781689448) produced from sending a chat from the [Preview](https://studio-staging-git-mattrossman-ai-1149-include-698a5f-supabase.vercel.app/dashboard/org) on this PR. Note it now includes the org slug in span metadata: <img width="873" height="548" alt="CleanShot 2026-08-28 at 10 59 49@2x" src="https://github.com/user-attachments/assets/bcf47a94-6782-434a-9006-c7b9c95f1c37" /> If desired you can test yourself too by chatting with Assistant in the preview and looking up the corresponding Chat ID from Braintrust [logs](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs). Closes AI-1149 --- _Generated by [Claude Code](https://claude.ai/code/session_01N2ziJech9dV19pJ9MisYdX)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
95954ab81b |
fix: attempt project wake only if its in ACTIVE_HEALTHY state (#49693)
There is no point in trying to wake up a project that is not `ACTIVE_HEALTHY` as it will always fail. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved project wake-up behavior by limiting automatic wake-ups to hibernating projects with a healthy active status. * Prevented unnecessary wake-up attempts for projects in other states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f1e0808223 |
Disable analyze button for notebooks if notebook is empty (#49674)
## Context As per PR title - just disables the analyze button if the notebook is empty <img width="1077" height="323" alt="image" src="https://github.com/user-attachments/assets/f8da8bd4-eb0c-43ae-85c7-b60c1c7dcfed" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Disabled the Analyze action for empty notebooks. * Added guidance prompting users to add a cell before starting analysis. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c4fe153fd8 |
Joshenlim/fe 4290 add save to notebook button in query tabs (#49667)
## Context Adds a "Save" action for query tabs in the explorer, which opts for 2 options to either add to an existing notebook, or create a new notebook. Both of these actions just opens the notebook in a new tab with unsaved changes - the changes will only be persisted in the DB when the user hits "Save" on the notebook. For adding to an existing notebook, the snippet will be appended to the bottom of the notebook - UI will scroll to the bottom after navigating to the notebook. <img width="469" height="368" alt="image" src="https://github.com/user-attachments/assets/19d16940-89e2-4d10-b71e-8d501f749668" /> |
||
|
|
f5f897a29b |
feat(functions): inject env var function slug (#49617)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature (self-hosted Edge Functions) ## What is the current behavior? The self-hosted Edge Functions router (`docker/volumes/functions/main/index.ts`) doesn't tell a function which slug a request resolved to. As a result, `@supabase/server`'s `withOAuthProtectedResource` can't derive its canonical resource URL and falls back to reconstructing it from the request path against the internal `api-gw` origin, so the advertised OAuth Protected Resource is /wrong for self-hosted deployments. ## What is the new behavior? `main/index.ts` now injects `SUPABASE_FUNCTION_SLUG: service_name` per request (after the `Deno.env.toObject()` snapshot, so nothing in the container env can shadow it). Combined with the operator's `SUPABASE_PUBLIC_URL`, the advertised resource is the correct external `{SUPABASE_PUBLIC_URL}/functions/v1/{slug}`, not the internal `http://api-gw:8000`. Verified on the docker stack: the slug is injected per-function, the resource origin resolves to `SUPABASE_PUBLIC_URL`, and the `401` `www-authenticate` carries the right `resource_metadata`. ## Additional context Fixes AI-1128 Companion to `@supabase/server` [PR #117](https://github.com/supabase/server/pull/117) and the [CLI slug injection](https://github.com/supabase/cli/pull/6345) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Edge workers now receive the correct function slug in their runtime environment, improving per-function request handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
29493e02d0 |
[FE-4010] feat(studio): add read-only replica connection option for HA projects (#49485)
For Multigres (HA) projects you can't connect to read replicas directly — reads go through a read-only load balancer on the primary's host at port 5433. Since #44695 stripped the pooler UI, HA projects showed no source option at all in the Connect dialog and still prompted for the IPv4 add-on. This surfaces it as a first-class, clearly-labeled read-only source. In the UI it's labeled `Replica (read-only)` rather than "load balancer" — the primary goes through the same gateway, so "load balancer" would be confusing from a product perspective (internally the `load-balancer` source identifier and `HIGH_AVAILABILITY_LOAD_BALANCER_PORT` constant keep their names). <img width="883" height="342" alt="Screenshot 2026-08-24 at 11 32 26 PM" src="https://github.com/user-attachments/assets/3716f6dd-0325-4b9d-adbc-9ece9244de62" /> **Added:** - Source select for HA projects in the Direct tab: `Primary database` + `Replica (read-only)` (individual replica rows are filtered out — they're only reachable via the load balancer) - Replica (load balancer) connection strings on all 9 connection types: primary host, port `5433`, with the Multigres-required `sslmode=require&sslnegotiation=direct` params (JDBC gets the `sslNegotiation` spelling, .NET gets `SSL Negotiation=Direct`) - `Read-only` badge on the connection code block + note pointing writes at the primary - Programmatic labels for the ConnectSheet select/switch/multi-select fields (the Source combobox previously had no accessible name) **Changed:** - The generated-file step (Node.js/Golang/.NET/Python/SQLAlchemy) is now source-aware — it previously ignored the Source selection entirely (also affected read replicas on normal projects) and silently rendered the primary's connection info - .NET template now emits `Port=` (Npgsql defaults to 5432 when omitted) and the install step actually installs Npgsql (pinned 9.0.5 — `SSL Negotiation` requires 9+) - SQLAlchemy `DATABASE_URL` merges `sslmode=require` into the string's existing query params instead of a hardcoded suffix that could drop TLS - Source option labels normalized to sentence case (`Primary database`, `Read replica (…)`) - `MultipleCodeBlock` (ui-patterns) accepts an optional `className` - HA coercion in `useConnectState` extended: a stale replica `connectionSource` restored from URL/localStorage falls back to the primary **Removed:** - IPv4 add-on admonition for HA projects (the forced-direct method was tripping it; the add-on doesn't apply to Multigres) Out of scope (needs platform work): SQL editor / Data API / other `DatabaseSelector` surfaces — executing against the load balancer requires a platform-issued connection string, and the load-balancers API only returns a REST endpoint today. The `5433` port is a client-side constant (`HIGH_AVAILABILITY_LOAD_BALANCER_PORT`) until the API exposes it. ## To test On an HA (Multigres) project: - Open Connect → Direct: Source shows exactly `Primary database` and `Replica (read-only)`; selecting the replica shows `…@<primary-host>:5433/postgres?sslmode=require&sslnegotiation=direct`, a `Read-only` badge, and the read-only note - Cycle all 9 connection types with the replica selected — every snippet carries port 5433 (`.NET` includes `Port=5433;…;SSL Negotiation=Direct`), badge/note persist - No "Enable IPv4 add-on" admonition anywhere in the Direct tab - Switch tabs / hard-reload: source resets to primary with no stale badge/string combos On a normal project: - Direct tab unchanged: no `Replica (read-only)` option, pooler badges and IPv4 admonitions behave as before, `.NET` now shows `Port=5432` and no `SSL Negotiation` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added read-only load-balancer connection options for high-availability projects. - Added .NET and SQLAlchemy connection examples with required SSL settings. - Added clear read-only labels and notices explaining write restrictions. - **Bug Fixes** - Suppressed IPv4 add-on notices for high-availability connections. - Improved connection-source selection and restored-setting handling. - Improved connection form identification and accessibility. - **Style** - Added customizable styling support for multi-code-block displays. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
59c8ea3ddc |
docs(BRA-282): clarify that branches are created as clones of the base project (#49594)
## What kind of change does this PR introduce? Docs update. ## What is the new behavior? The branching docs now state consistently that every branch, preview or persistent, is created as a clone of the base project, starting with that project's schema, Edge Functions, and configuration. Data and storage objects are not cloned by default. ## Additional context This documents new branch-creation behavior. Two automated reviewers flagged the clone wording and argued for a migration-replay description; that reflects the previous implementation, so their findings don't apply here and the clone framing stands. --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
5fd2023708 |
feat(studio): worker detail page (FE-4189, FE-4197) (#49195)
## What
The worker detail page at `/project/[ref]/workers/[name]`, reading `GET
/v2/projects/{ref}/workers/{name}`. Base: #49194.
## How to test
Only on the **Mockamaster** project in staging — it is the one project
in the alpha allow-list.
1. Staging dashboard → Mockamaster → **Workers** → click
`dashboard-test`
2. Overview: instances read 1 declared / 1 live / 1 ready / 0 stale, no
error alerts
3. Settings: Deno 2, `denoland/deno:latest`, 2 GB · 1 vCPU, private, US
West (locked)
4. **How to call** in the header → the snippets name the real worker URL
No write actions. Delete (FE-4190) is deliberately out.
Closes FE-4189
Closes FE-4197
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added worker detail pages with overview, requests, logs, builds, and
settings tabs.
* Added worker metadata, runtime details, invocation examples, and local
development commands.
* Added worker log streams with refresh, row selection, loading, empty,
and error states.
* Added worker-specific log formatting and clearer instance status
information.
* **Documentation**
* Updated migration tracking to mark the worker route as complete.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
35531ea2f4 |
feat(www): serve openapi spec at /openapi.json (#49587)
Agent-readiness scanners and agent fetchers look for an OpenAPI spec at conventional same-origin paths, but the Management API spec is only served on api.supabase.com and linked from the /.well-known/api-catalog linkset, which scanners do not read. I added a rewrite so supabase.com/openapi.json proxies the spec from its source of truth at api.supabase.com/api/v1-json, using the same fall-through proxy mechanism as /humans.txt and /evals. **Note:** no cache or CORS headers on purpose: no consumer needs them today, and the upstream response's set-cookie header defeats edge caching regardless. I rejected a checked-in copy of the spec in favor of proxying live (staleness). The /.well-known/api-catalog linkset already points at the spec (PR #44880) and is untouched here; this PR only adds the conventional same-origin path. **Merge order:** merge only after supabase/platform#37571 deploys. The spec currently ships `servers: []`, so OpenAPI consumers resolve relative paths against the fetch origin; without the platform fix this proxy would point spec-compliant clients at supabase.com/v1/*. ## To test Tested on Vercel preview: - [x] `curl -s https://<preview-url>/openapi.json | head -c 40` returns `{"openapi":"3.0.0"` - [x] `curl -sI https://<preview-url>/openapi.json` returns 200 with `content-type: application/json` - [x] `curl -sI https://<preview-url>/humans.txt` returns 200 (control: rewrite fall-through chain intact) ## Linear - fixes GROWTH-1138 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added access to the OpenAPI specification at `/openapi.json`. * Requests are automatically routed to the API specification endpoint. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Aleksi Immonen <aleksi@supabase.io> |
||
|
|
27dba8d02d |
fix(studio): group pipeline destinations by release stage (#49669)
## What kind of change does this PR introduce? UI clarity improvement for the current pipeline creation sheet. ## What is the current behavior? All destination types appear under a generic Pipelines heading, with release-stage badges repeated beside each option. ## What is the new behavior? Destination types are grouped under Public Alpha, Early Access, and Deprecated headings. The selected value stays compact, while its release-stage guidance remains below the field. | Before | After | | --- | --- | | <img width="1280" height="750" alt="CleanShot 2026-08-28 at 15 45 29@2x" src="https://github.com/user-attachments/assets/5be32928-21fa-4911-bc68-3376c068703f" /> | <img width="1280" height="888" alt="CleanShot 2026-08-28 at 15 44 49@2x" src="https://github.com/user-attachments/assets/2046d174-dd4f-41f1-98da-3d8d48af8a1c" /> | ## To test 1. Open a project, then go to Database → Replication and select Add destination. 2. Open the Type selector. 3. Confirm available destinations are grouped by Public Alpha, Early Access, and Deprecated. 4. Select BigQuery and confirm the field still explains that it is in public alpha. 5. Edit an existing destination and confirm the Type selector remains disabled. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Destination options are now organized into clear release-stage groups: Public Alpha, Early Access, and Deprecated. * Added group headings and separators to make destination selection easier to scan. * Removed individual stage badges from destination labels for a cleaner, more consistent layout. * **Tests** * Updated coverage to verify grouping and visibility across supported destination types. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
19e3844a0e |
feat(studio): upload BigQuery pipeline credentials (#49668)
## What kind of change does this PR introduce? Feature improvement for BigQuery pipeline creation and editing. ## What is the current behavior? Users must paste the complete service-account JSON into a text area. ## What is the new behavior? Users can paste, upload, or drag and drop a service-account JSON file. Imported credentials remain editable, and unreadable or oversized files show an inline form error. ## To test 1. Open a project, then go to Database → Replication and select Add destination. 2. Select BigQuery. 3. Under Service account key, select Upload JSON file and choose a service-account `.json` file. 4. Confirm its contents appear in the editable text area. 5. Drag and drop a JSON file onto the same field and confirm it replaces the contents. 6. Confirm pasting credentials manually still works. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for uploading BigQuery service account key JSON files. * Added drag-and-drop support for service account key files. * Updated guidance to clarify that keys can be pasted or uploaded. * Constrained the service account key field to 5,000 characters. * **Bug Fixes** * Added clear validation when keys exceed the character limit. * Improved handling of unreadable files while preserving the existing key. * Improved editing of imported service account key content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
02bb456647 |
fix(studio): clarify pipeline form guidance (#49666)
## What kind of change does this PR introduce? UI copy improvement for the current pipeline creation sheet. ## What is the current behavior? Several pipeline fields use ambiguous labels or omit useful guidance. Validation messages also use inconsistent punctuation. ## What is the new behavior? - Explains how the pipeline name is used - Clarifies invalidated replication slot behaviour - Explains that BigQuery maximum staleness is optional - Makes pipeline validation messages consistent ## To test 1. Open a project, then go to Database → Replication and select Add destination. 2. Confirm Name explains that it identifies the pipeline in Supabase. 3. Expand Advanced settings and confirm Invalidated slot behaviour uses Block startup and Recreate slot. 4. Select BigQuery and confirm Maximum staleness explains that leaving it blank gives the freshest results. 5. Submit incomplete destination settings and confirm validation messages end with full stops. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Replication slot behavior options now use clearer labels: “Block startup” and “Recreate slot.” * Added guidance explaining that the pipeline name identifies the pipeline in Supabase. * Improved the BigQuery maximum-staleness description and display. * **Bug Fixes** * Standardized replication destination validation messages with consistent punctuation. * Clarified the ClickHouse HTTPS validation message. * Updated validation tests to reflect the improved error messages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8d59e69da4 |
Add support for running only selected query in QueryEditor (#49651)
## Context As per PR title - this behaviour currently exists in the SQL Editor so just bringing it over to the Explorer, applies to both QueryTab and QueryCell since they use the same QueryEditor component "Run" button also updates to "Run selected" for clarity when a specific portion of the code editor is selected <img width="1387" height="958" alt="image" src="https://github.com/user-attachments/assets/7e652951-3c07-4f8d-851b-bb9219d0c1f2" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Run only the selected SQL when text is highlighted in the query editor. * Run the full query when no text is selected. * Updated the run button label and tooltip to reflect the action. * **Bug Fixes** * Improved query execution for empty or collapsed selections. * Corrected selection state when reopening the query editor. * **Tests** * Added coverage for selected-text, full-query, and editor reopening scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
53df997425 |
feat(studio): add SteppedFlow component (#49583)
## What kind of change does this PR introduce? Feature (shared UI primitive). ## What is the current behavior? No shared stepped wizard shell in Studio. Upcoming create-pipeline work needs a reusable step container with header, progress, and primary/secondary actions. ## What is the new behavior? Adds `SteppedFlow` and `SteppedFlowHeader` with unit tests: step list, current step content, next/back, optional first-step cancel, and header actions slot. No product callsite yet. Safe to merge on its own; the create-pipeline wizard PR will consume it. ## To test Code review + vitest: ```sh cd apps/studio && pnpm exec vitest run components/ui/SteppedFlow/SteppedFlow.test.tsx ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a reusable stepped-flow interface with progress indicators and step-specific content. * Supports optional headers, actions, loading and disabled states, forms, and configurable button types. * Added navigation controls for moving forward, going back, cancelling, and completing the flow. * Supports customizable final actions. * **Tests** * Added coverage for navigation, cancellation, headers, optional actions, final actions, and disabled states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c984771ed8 |
Update pricing page: BYO Cloud → AWS PrivateLink (#49624)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update to /pricing. ## What is the current behavior? - The Enterprise plan card lists "BYO Cloud supported" as a feature. - The Platform Security and Compliance comparison table has a separate "BYO cloud" row (Enterprise-only), alongside an existing "AWS PrivateLink" row. ## What is the new behavior? - Enterprise plan card bullet changed to "Supports AWS PrivateLink". - Removed the "BYO cloud" row entirely from the Platform Security and Compliance comparison table (the AWS PrivateLink row already covers this). ## Additional context Data-only change in `packages/shared-data/plans.ts` and `packages/shared-data/pricing.ts`. No component logic changed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Enterprise plan details now highlight AWS PrivateLink support. * Removed the BYO Cloud feature from the security feature listings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
658a5c7fee |
Update Lingo.dev customer story slug to lingodotdev (#49623)
## What kind of change does this PR introduce? Content: slug update for an already-live customer story. ## What is the current behavior? The Lingo.dev customer story (originally added in #49595) lives at `/customers/lingo-dev`. ## What is the new behavior? - Renames `apps/www/_customers/lingo-dev.mdx` to `apps/www/_customers/lingodotdev.mdx`. - Updates the `url` in `apps/www/data/CustomerStories.ts` to `/customers/lingodotdev`. - Adds a permanent redirect from `/customers/lingo-dev` to `/customers/lingodotdev` in `apps/www/lib/redirects.js`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a customer story highlighting Lingo.dev’s localization workflow, platform usage, security practices, results, and future plans. * **Bug Fixes** * Updated the customer story link to its new URL. * Added a permanent redirect so existing links to the previous URL continue to work. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> |
||
|
|
172a14fe34 |
chore(studio): update edge functions detail page to use PageBreadcrumbs ui pattern (#49649)
| Before | After | |--|--| | <img width="1227" height="656" alt="Screenshot 2026-08-27 at 17 30 58" src="https://github.com/user-attachments/assets/2c523708-d816-41c0-a401-a9502bb2d8e2" /> | <img width="1227" height="654" alt="Screenshot 2026-08-27 at 17 29 45" src="https://github.com/user-attachments/assets/0169faa3-5bf9-43c3-ad71-1b2343e95053" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Restructured the edge function details header for a cleaner layout. * Improved placement and behavior of breadcrumbs and actions, including Docs, Download, and Test. * Preserved existing navigation, download, testing, URL copying, and timestamp functionality. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
aeb9511967 |
docs: retarget upgrade caveats to 15.19/17.11 + add btree_gist reindex note (#49621)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update — Postgres upgrade guide for the 15.19 / 17.11 minor release. ## What is the current behavior? The upgrade guide's caveats are tagged for 15.18 / 17.10. ## What is the new behavior? - Retarget the ltree-reindex and custom-operator caveats: `15.18 or 17.10` → `15.19 or 17.11`. - Replace the ltree detection query with an operator-class-based one that also catches expression indexes and excludes `INCLUDE`d columns. - Add a `btree_gist` caveat: `float4`/`float8` gist indexes that may contain `NaN` need a `REINDEX` (upstream fixed NaN handling in 15.19/17.11). - Note the separate ltree >~14,653-label overflow case (encoding-independent). - Use schema-qualified names in `REINDEX INDEX CONCURRENTLY` and note it cannot run inside a transaction block. Detection queries validated on real 15.19 and 17.11. ## Additional context Refs: PSQL-1245. A pgcrypto (CVE-2026-14663) caveat is intentionally not included here. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated upgrade guidance for PostgreSQL 15.19 and 17.11. * Documented schema-qualified ltree index names and transaction-block restrictions for reindexing. * Improved the ltree overflow query to account for partial-index predicates when identifying values exceeding approximately 14,653 labels. * Added guidance for identifying and concurrently rebuilding affected `btree_gist` floating-point indexes containing `NaN` values. * Updated supported-version guidance for custom operator selectivity estimators. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
45d8f30ba8 |
chore(icons): add workers icon (#49645)
- added workers to icons package - used workers as product icon in studio sidebar <img width="200" height="79" alt="Screenshot 2026-08-27 at 16 36 19" src="https://github.com/user-attachments/assets/0e2e7ce6-dde2-439a-93e8-e795aa5efded" /> |
||
|
|
26e89b36c3 |
chore: Regenerate API types and fix all issues (#49646)
A bunch of small issues have showed up where the API types are breaking the FE repo: - Regenerate the API types. - For the removed Response types, use the return types from the operations instead. - Fix some types which now have a suffix `_Output`. - Add `requires_indirect_tax_declaration` property to Organization instances in mocks. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Updated Studio and shared type references to use generated API definitions consistently. * Improved typing for SSO configuration creation and updates. * Aligned telemetry lint categories with API-provided values. * Marked the legacy API type re-export as deprecated. * **Tests** * Updated test fixtures and response types to reflect current API contracts. * Added indirect tax declaration data to organization test scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5802f4f83e |
fix(www): career page apply button sizing (#49647)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Noticed this by accident, simplified the apply button area sizing on large screens. | Before | After | |--------|--------| | <img width="390" height="228" alt="Screenshot 2026-08-27 at 15 25 36" src="https://github.com/user-attachments/assets/7f49021c-1332-4a00-b19c-5544537c1cb4" /> | <img width="491" height="274" alt="Screenshot 2026-08-27 at 15 45 11" src="https://github.com/user-attachments/assets/846faff8-bd72-4141-b8d4-01d7ddd97b6d" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved job listing badge layout and responsiveness. * Long location names now truncate cleanly instead of overflowing. * Reduced location icon size for a more balanced presentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
102d3d1df5 |
Disable disk management for HA projects (#49633)
## Context As per PR title, disables disk management for HA projects, which involves - Disabling "Increase disk size" CTAs in reports/database and the old disk config settings in database/settings - Disabling all input fields related to disk management in settings/infrastructure <img width="1076" height="857" alt="image" src="https://github.com/user-attachments/assets/bfbdfc36-8ae3-41ce-af12-c05b46e620f4" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added High Availability notices and restrictions throughout disk management settings. * Disabled disk size, IOPS, throughput, and autoscaling controls where High Availability limits changes. * Added explanatory tooltips for restricted disk-size actions. * Updated database observability controls to reflect High Availability restrictions. * **Accessibility** * Added an accessible label to the database observability refresh button. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
df002b4018 |
fix: Fix a type error in List JIT access API (#49612)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved database access rule handling by excluding records without an associated user. * Preserved valid user-rule mappings while preventing incomplete entries from being included. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0b5be1fada |
Disable read replica creation CTAs for HA projects (#49629)
## Context As per PR title - disables creation of read replicas for HA projects. This involves: - Hiding new replica CTA in `DatabaseSelector` - Used in pages like reports - Hiding new replica CTA in `DatabaseParametersSubMenu` - Used in SQL Editor + Explorer - Disabling new replica CTA in settings/infrastructure under Read Replicas <img width="1065" height="401" alt="image" src="https://github.com/user-attachments/assets/18c59cee-2f47-4874-9861-8211684282ab" /> <img width="418" height="366" alt="image" src="https://github.com/user-attachments/assets/553cf75b-ff95-41c0-beca-357430a7e888" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Bug Fixes - Updated read replica controls to accurately reflect project availability. - Hid read replica creation options for high-availability projects. - Prevented read replica deployment for high-availability projects. - Added an explanatory notice and guidance when read replicas are unavailable due to high-availability settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
292c08b7b7 |
Added new /regions page (#49306)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature ## What is the current behavior? Region and data residency information is split across docs, `/security`, and legal pages. [MARKET-1866](https://linear.app/supabase/issue/MARKET-1866/package-and-display-available-regions-better-on-website) ## What is the new behavior? Adds `/regions`: a catalog of all 17 regions generated from `regions.ts`, plus what stays in-region, the Europe vs EU caveat, and links to the DPA, GDPR guide, sub-processor list, and security page. Regions is in the footer under Security & Compliance. The security page residency card now links here. ## Test plan - [ ] Open `/regions` in light and dark mode - [ ] Confirm the region count and list match `packages/shared-data/regions.ts` - [ ] Confirm footer Regions link and `/security` residency link go to `/regions` Made with [Cursor](https://cursor.com) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a Regions page showcasing available AWS regions by geography. - Added an interactive map and region list with selection, hover states, keyboard accessibility, and residency badges. - Included data residency guidance, legal resources, and a call-to-action for next steps. - Added Regions links in the site footer and security documentation. - **Documentation** - Updated agent skill resources with expanded troubleshooting and operational guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Francesco Sansalvadore <f.sansalvadore@gmail.com> |
||
|
|
b66258c0b8 |
feat(studio): improve feature preview sidebar legibility (#49616)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Based off user feedback, improvement for general legibility of items and light mode. | Before | After | |--------|--------| | <img width="1950" height="1416" alt="CleanShot 2026-08-26 at 17 56 33@2x" src="https://github.com/user-attachments/assets/29bc6d28-9600-4fea-af28-11097450c1e5" /> | <img width="2008" height="1446" alt="CleanShot 2026-08-26 at 17 55 47@2x" src="https://github.com/user-attachments/assets/da002085-cc8f-4baf-8bc3-ca7a605ae04b" /> | | <img width="2028" height="1472" alt="CleanShot 2026-08-26 at 17 56 46@2x" src="https://github.com/user-attachments/assets/54c810fa-c455-449d-b9c9-2c1022d12b59" /> | <img width="2034" height="1464" alt="CleanShot 2026-08-26 at 17 59 50@2x" src="https://github.com/user-attachments/assets/19094e8e-4ab5-4faf-bac7-5d8aefc70f6c" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated feature preview navigation with clearer selected and unselected item styling. * Applied tertiary backgrounds to accordion items. * Removed unnecessary open-state and individual item border styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
10950d286b |
chore(studio): address review comments on Multigres topology diagram (#49592)
<!-- ccr-slack-attribution --> _Requested by **Alaister Young** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1787738517181409?thread_ts=1787635785.354489&cid=C0161K73J1J)_ Follow-up to #49298, which was squash-merged before @joshenlim's last review round was addressed. Picking up the review comments here. ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore — dead code removal and comment corrections. No behavior change. ## What is the current behavior? Three of @joshenlim's review comments on #49298 are still open on master: - [Dead code in `ha-cluster-cells-query.ts`](https://github.com/supabase/supabase/pull/49298#discussion_r3861029414) — "seems to be dead code? no one's consuming this file" - [Dead code in `ha-cluster-databases-query.ts`](https://github.com/supabase/supabase/pull/49298#discussion_r3861031230) — "likewise - seems to be dead code" - [`STATUS_BADGE_VARIANTS` statuses](https://github.com/supabase/supabase/pull/49298#discussion_r3861095281) — "just to sanity check these are the only statuses? are there any failure states? e.g 'Failed'" Concretely, on master today: - `apps/studio/data/ha-admin/ha-cluster-cells-query.ts` and `apps/studio/data/ha-admin/ha-cluster-databases-query.ts` ship query options that nothing imports. The diagram only reads `/poolers` and `/gateways`. - `multipoolerSchema.lifecycleStatus` is an undocumented `z.string()`, while its neighbours `type` and `servingStatus` both list their expected proto values in a comment. - The comment above `HA_POOLER_STATUS_LABELS` claims the labels "Matches the status vocabulary of the read replica surfaces (getStatusLabel)". They don't — `getStatusLabel` in `ReadReplicas/ReadReplicas.utils.ts` also returns `Failed`, `Restarting`, `Resizing` and `Restoring`, none of which the HA labels have. ## What is the new behavior? - Deleted both dead query modules and pruned the orphaned `cells` and `databases` factories from `haAdminKeys`, keeping `poolers` and `gateways`. Verified by grep that neither file name nor any of their exported symbols (`haClusterCellsQueryOptions`, `HaClusterCellsData`, `haClusterDatabasesQueryOptions`, `HaClusterDatabasesData`, the `*Variables`/`*Error` types) nor `haAdminKeys.cells` / `haAdminKeys.databases` has a single reference left anywhere outside the deleted files. No re-export shims left behind. `get-ha-admin.ts` stays — `poolers` and `gateways` still use it. - Documented `lifecycleStatus` against the actual enum, `PoolerLifecycleStatus` in [multigres `proto/clustermetadata.proto`](https://github.com/multigres/multigres/blob/main/proto/clustermetadata.proto): `LIFECYCLE_UNKNOWN` (zero value, omitted from JSON) | `STARTING` | `ACTIVE` | `STOPPING` | `SHUTDOWN` | `QUARANTINED`. `getPoolerStatus` already maps every member. - Reworded the `HA_POOLER_STATUS_LABELS` comment to say the labels are a subset drawn from the read replica vocabulary rather than a match for it, and noted where the read replica `Failed` lands on the HA side. **On the `Failed` question:** the answer from the proto is that there is no dedicated failure member. The terminal states are `QUARANTINED` — the pooler "has given up trying to become a healthy replica: it cannot automatically recover to a functioning state (e.g. it could not complete a pg_rewind, could not restore from backup to start postgres, or fell irrecoverably behind on replication)", kept alive for forensics — and `SHUTDOWN`, "durably down". Both already map to `unhealthy` / the `Unhealthy` warning badge, so the four statuses on `STATUS_BADGE_VARIANTS` are complete for the enum as it stands. If we'd rather show `QUARANTINED` as its own `Failed` status with a destructive badge (matching the read replica surface), that's a small follow-up — a product/copy call rather than a gap, so not folded in here. **Not included: [the replication page UX comment](https://github.com/supabase/supabase/pull/49298#discussion_r3861055216)** ("is there any other content we plan to add here? it feels empty atm... it's just a repeat of the home page + settings/infrastructure"). @joshenlim flagged that one himself as "UX feedback which can be addressed separately". It's a product and IA question about what that page is for, not something to answer with a code change here — leaving it for @alaister and design. ## Additional context - Verified locally: `tsc --noEmit` (0 errors), ESLint on the touched files (clean), Prettier check (clean), and `HaTopology.utils.test.ts` + `HaInstanceConfiguration.utils.test.ts` (26/26 passing). CI is green as well. - Exhaustive grep across the repo (excluding `node_modules`/`.git`/build output, covering `apps/**` incl. `lite-studio`, `packages/**` and `e2e/**`) confirmed zero remaining references to the deleted files, their exported symbols, and the removed key factories. - No test changes: the diff deletes unreferenced code and edits comments only, so there's no new behavior to cover. `HaTopology.utils.test.ts` already pins every `lifecycleStatus` value listed in the new comment. --- _Generated by [Claude Code](https://claude.ai/code/session_012StGVQSmPzpGTXrduo9Xyi)_ --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
57a6f74407 |
Revert "fix: FormItemLayout does not apply item id correctly" (#49635)
Reverts supabase/supabase#49593 because we currently provide `id` manually in some places and that breaks many tests. We didn't see the failures because the PR only modified `ui-patterns` which isn't in the paths checked to actually run the tests (this must be fixed too). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved form accessibility by correctly associating labels with their corresponding fields in React form layouts. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a8240e3da8 | feat(studio): deploy worker form (#49613) | ||
|
|
777cf83ec4 |
feat(studio): add leave feedback on replication list (#49582)
## What kind of change does this PR introduce? Feature. ## What is the current behavior? Replication destinations list has docs and add-destination actions, but no clear path to leave pipelines feedback. ## What is the new behavior? Adds a **Leave feedback** button that opens the pipelines GitHub discussion. Create destination still opens the existing sheet (no wizard redirect in this PR). | Before | After | | --- | --- | | <img width="1024" height="759" alt="Replication Database ETL BigTable ETL Team Supabase" src="https://github.com/user-attachments/assets/9a18a90b-3041-49f6-a65c-adb5c07ef0fe" /> | <img width="1024" height="759" alt="47954" src="https://github.com/user-attachments/assets/675d0137-9acb-436a-a3aa-741efeaf74bb" /> | | <img width="1024" height="759" alt="49523" src="https://github.com/user-attachments/assets/1f8f5cd6-315f-45b1-a1e0-0b02a83d9780" /> | <img width="1024" height="759" alt="Replication Database ETL BigTable ETL Team Supabase" src="https://github.com/user-attachments/assets/d61e0db9-e28f-4384-8206-4dedbf7ecc74" /> | ## To test 1. Open a project → Database → Replication 2. Click **Leave feedback** in the list toolbar 3. Confirm it opens the pipelines discussion in a new tab 4. Confirm **Add destination** still opens the sheet as today <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features - Added a feedback button to the replication destinations toolbar. - Feedback opens the relevant discussion forum in a new browser tab. ## Improvements - Simplified destination status descriptions for clearer presentation. - Removed inline discussion links from individual destination descriptions. - Centralized feedback access in the replication destinations interface for easier discovery. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
df48528443 |
fix: FormItemLayout does not apply item id correctly (#49593)
## Problem `<FormItemLayout>` does not apply item id correctly. This can be seen on https://supabase.com/design-system/docs/ui-patterns/forms: open the devtool and check the form items labels. They have no `for` attribute. This makes it harder to correctly test and is an accessibility issue. Axe devtool actually report it ## Solution When inside React Hook Form, `<FormItemLayout>` actually generate an `id` (via `<FormItem>`). However, this `id` is overridden in `<FormLayout>` and read from context by `<FormLabel>`. Simply removing this line fixes it and correctly binds the label to its input |
||
|
|
961fc749d4 |
Add feature preview banner toast for explorerd (#49606)
## Context Adds a feature preview banner toast for the explorer - flagged behind the configcat flag <img width="315" height="342" alt="image" src="https://github.com/user-attachments/assets/9dbd7ffd-02c6-4083-9ca0-266b862e1b5d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added an Explorer preview banner to project layouts when the feature is enabled. - Added an “Enable Explorer” call-to-action that opens the feature preview. - Banner dismissal is remembered and persists across sessions. - Added telemetry tracking for banner dismissal and CTA interactions. - **Bug Fixes** - Improved banner behavior and stability when displaying database connection notifications. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1cb119b63d |
Set default opt in for explorer to be false (#49611)
## Context As per PR title - default opt in for explorer preview should be false |
||
|
|
164de2c347 |
feat(www): markdown 404 for markdown-negotiated paths (#49596)
Nonexistent paths return a real 404 everywhere, but always with an HTML body, even when the client asked for markdown via `Accept: text/markdown` or a `.md` suffix. Middleware can't fix this: it gates on a static slug allowlist and can't know a path will 404. I added two `fallback` rewrites (`.md` suffix; Accept header containing `text/markdown` or `text/*`) that run only after every route has failed to match and route the request to a small `md-404` handler returning a short markdown 404 pointing at /docs, /sitemap.xml, and /llms.txt. Real pages are structurally unaffected. **Note:** `lib/rewrites.js` is untouched (the plain rewrites array became the `afterFiles` phase), so #49587 merges independently. I updated next.config.test.ts's rewrites assertion for the phased shape; it now also pins the two fallback rules. ## To test I verified on the Vercel preview: - [x] `curl -s -D - -H "Accept: text/markdown" <preview>/definitely-not-a-page` (404, `Content-Type: text/markdown`, body with the three pointers) - [x] Same URL with a browser Accept header (existing HTML 404, unchanged) - [x] `curl -s -D - <preview>/definitely-not-a-page.md` (markdown 404) - [x] `curl -s -D - -H "Accept: text/markdown" <preview>/auth` (200 markdown, unchanged) and `<preview>/support` (200 HTML, unchanged) - [x] `/homepage.md` still 308s to `/index.md` (redirects phase wins); `Accept: text/*` gets the markdown 404, matching real-page negotiation Known boundary: `/changelog/<unknown>` keeps the HTML 404 body (pages-router `fallback: 'blocking'` routes take priority over fallback rewrites per Next docs); the status is still 404, verified on the preview. ## Linear - fixes GROWTH-1142 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added Markdown-formatted 404 responses for unmatched documentation and `.md` page requests. - Included helpful documentation links in not-found responses. - Requests that explicitly accept Markdown now receive a consistent Markdown response. - Added appropriate response headers for security, caching, and content variation. - **Bug Fixes** - Improved routing for unmatched Markdown paths, ensuring they are handled by the appropriate not-found response instead of returning an unexpected format. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3945234b9e |
feat(studio): polish replication destination sheet form (#49581)
## What kind of change does this PR introduce? Feature (sheet polish, no wizard). ## What is the current behavior? Edit destination sheet uses a disabled region Select, weaker BigQuery JSON validation messaging, and a name field that password managers may fill. ## What is the new behavior? - Read-only pipeline region field with flag, display name, region code, and destination-specific hint - Clearer BigQuery service-account JSON validation - Destination name ignores password managers (`data-1p-ignore` and related attrs) - Advanced settings can optionally group fields (defaults keep full accordion for the sheet) Independent of the [create-pipeline wizard](https://github.com/supabase/supabase/pull/49243). Safe to merge on its own. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Replication Database Chisel Toolshed Supabase" src="https://github.com/user-attachments/assets/98360d10-3efd-4f77-9645-2f054bb8caab" /> | <img width="1024" height="759" alt="Replication Database Chisel Toolshed Supabase" src="https://github.com/user-attachments/assets/fdb55904-44f5-4fdf-a750-d4b7f1602b4e" /> | | <img width="1024" height="759" alt="Replication Database Chisel Toolshed Supabase" src="https://github.com/user-attachments/assets/cd40e4c3-5653-467b-a3b6-c0c497f9c500" /> | <img width="1024" height="759" alt="Replication Database Chisel Toolshed Supabase" src="https://github.com/user-attachments/assets/d4115dab-fd94-411c-bbc4-ee69e22436d6" /> | ## To test 1. Open a project → Database → Replication 2. Edit an existing destination 3. Confirm **Pipeline region** is read-only (not a combobox) and shows flag + region name/code 4. Open Advanced settings and confirm fields still appear 5. For BigQuery: paste invalid service-account JSON and confirm a clear validation message <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added grouped advanced settings for connection and data configuration. - Added a read-only pipeline region display with destination-specific guidance. - Destination names now receive focus automatically when forms open. - **Bug Fixes** - Improved BigQuery credential validation, including malformed or missing service-account keys. - Password-manager autofill is now suppressed for destination name fields. - **Tests** - Added coverage for BigQuery validation and pipeline-region display behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
272a288c9b |
chore(docs): add Simon Tomlinson to humans.txt (#49547)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Add my name to humans.txt ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Simon Tomlinson to the team information listed in the project documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f09d35cfd5 |
fix(docs): make code blocks reachable and readable by keyboard and screen reader (#49562)
Closes DOCS-1283 https://github.com/user-attachments/assets/6e55a27f-6f73-453b-b98f-e91d3c14a9e4 ## Problem Three defects in the docs code block: - The scroll container has no `tabindex`. On `/guides/database/tables`, 18 blocks, none focusable, 2 overflowing at 1280px. Tab skips the scroll region, so a keyboard-only user cannot scroll code that runs off the edge. - The container has `role="group"` with no accessible name, so it announces as bare "group". - The line-number gutter has no `aria-hidden`, so digits are read inline with the code. A block linearizes as `1import { createClient } from '@supabase/supabase-js'23const supabase = ...`, with lines 2 and 3 collapsing into "23". Four more surfaced while testing the fix: - The wrap and copy buttons were absolutely positioned inside the element that scrolls, so `right-2` measured against the scrollable content box. Scrolling dragged them out of the corner into the middle of the code. This one predates the PR. - The buttons preceded the code in the DOM, so a screen reader read two actions before naming what they act on. - `focus-within` only fired for the buttons, so focusing the block left the controls invisible. - Both buttons set an `aria-label` identical to their tooltip text, and Radix points `aria-describedby` at the tooltip on focus, producing "Copy code, button, Copy code". ## Solution Keyboard: - Split the scroll region out of the positioning container, so the controls stay pinned. - Give the scroll region a `tabIndex` and a focus ring. - Reveal the controls on `group-focus-within`. Screen reader: - Name the region `<language>, <n> lines`. Code content stays readable; the summary goes in the name so the group can be skipped or stepped into. - Map fence aliases to spoken names, so `ts` announces as TypeScript. Only the ambiguous ones; `bash`, `python`, `kotlin`, `dart`, `swift` already read fine. - `aria-hidden` the gutter. The numbers are already `select-none`, and copy takes its content from the source string rather than the DOM, so copy behavior is unchanged. - Order the controls after the code. - Announce the word wrap toggle through a live region, matching the copy button. - Opt both buttons out of Radix's generated description. Also moved the `data-wrapped` side effect out of the `setIsWrapped` updater, since React calls updaters twice under StrictMode. ## Manual testing 1. Open `/docs/guides/database/tables`. 2. Run `document.querySelectorAll('.code-scroll[tabindex="0"]').length` in the console. Expect `18`. 3. Run `[...document.querySelectorAll('.code-scroll')].map(b => b.getAttribute('aria-label'))`. Expect entries like `SQL, 11 lines` and `bash, 2 lines`, plus one bare `2 lines` for the fence with no language. 4. Tab to a code block. Expect a visible focus ring, and the wrap and copy buttons to appear. 5. Press ArrowRight on the block under "Basic data loading", which overflows. Expect it to scroll, and the buttons to stay in the top-right corner. 6. Press Enter on the wrap button. Expect the code to wrap and a screen reader to announce "Word wrap enabled". 7. With VoiceOver on, focus a code block. Expect "SQL, 11 lines, code block", then the code read without line numbers interleaved. Focus each button and expect its name once, not twice. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Accessibility** - Improved code block labels for screen readers, including programming language and line count. - Added announcements when word wrap is enabled or disabled. - Enhanced keyboard focus behavior for code block controls. - **Usability** - Kept code block controls visible while scrolling through code. - Improved wrapped-code overflow handling. - Removed redundant tooltip descriptions for copy and word-wrap controls. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b9a4b3fa53 |
feat: update mgmt api docs (#49128)
This PR updates mgmt api docs automatically. Co-authored-by: samirketema <6003000+samirketema@users.noreply.github.com> |
||
|
|
478d95b35c |
fix: display request body Array<object> schema/fields in Management API Reference (#49575)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Fix/Docs Update - Fixes the Management API Reference ## What is the current behavior? Management API Reference cannot properly render request body fields of type `Array<object>`. [Example here](https://supabase.com/docs/reference/api/v2-create-organization-invitations) <img width="586" height="511" alt="CleanShot 2026-08-25 at 20 26 35" src="https://github.com/user-attachments/assets/b8358477-d9f3-4621-8b08-104a6589e7c9" /> ## What is the new behavior? Properly expands the request body fields & schema: <img width="606" height="885" alt="CleanShot 2026-08-25 at 20 27 09" src="https://github.com/user-attachments/assets/94305ece-8a5c-4f06-b584-6bca528aa5ea" /> ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Object and array-of-object API schemas now display summaries alongside expanded properties in clearly separated sections. * Improved handling of array item details and schema composition values for more reliable rendering. * Other schema types continue to use the existing detail-list presentation. * **Bug Fixes** * Prevented errors when displaying API specifications with incomplete array-item details or single-value schema combinations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2d1a2ff9a2 |
Set up feature preview for explorer (#49602)
## Context Sets up the Explorer behind the feature preview modal + removes the temporary entry point from the SQL Editor Changes are still not live on production, so will only affect local + staging. Enabling the feature preview will replace the sidebar nav for SQL Editor to new Explorer (Icon remains unchanged, just the label) <img width="918" height="647" alt="image" src="https://github.com/user-attachments/assets/b088eb47-1176-4618-b345-d1ec0521b092" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added an “Explorer & Notebooks” feature preview with an overview image and direct access to Explorer or SQL Editor. - Added Explorer navigation when the preview is enabled. - **Improvements** - Updated desktop and mobile navigation to consistently display the available editor destination. - Improved the Explorer shortcut tooltip to clearly say “Go to Explorer.” - Organized SQL Editor previews under the Editors category. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
73e36ec516 |
docs(troubleshooting): add postgres_changes not delivering guide (#48997)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? ## What is the new behavior? Realtime postgres changes troubleshooting. ## Additional context Just a guide for customer to check why they wont see events with postgres changes. Couple of steps to check etc. Would appreciate Realtime team's feedback. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a comprehensive troubleshooting guide for Realtime Postgres change events. * Covers publication settings, row-level security, replica identity, subscription status, timing gaps, project and table configuration, logs, delivery guarantees, and network issues. * Includes practical SQL, JavaScript, and React examples, diagnostic steps, fixes, and links to related documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4c37eb4ac0 |
chore: Update API types (#49598)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Updated configuration drift test data to include the database major version, improving coverage for current project configuration responses. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
334b112e7a |
refactor(studio): fetch MCP tool→FGA map from mgmt-api endpoint (#49225)
Paired with [supabase/platform#37175](https://github.com/supabase/platform/pull/37175). Deletes the hand-maintained `MCPToolScopeMappings.ts` (the map is currently 'manually extracted from the mcp controller' and drifts) and fetches the `tool → FGA permission` map from the new mgmt-api `GET /mcp-tools-permissions` endpoint, the same way it already fetches the v1/v2 OpenAPI specs. Closes AI-1016 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * MCP tool permissions are now fetched dynamically from the management API and included in API permission mappings. * Permission data is validated before being applied. * **Bug Fixes** * Improved handling of invalid responses and request failures from the MCP permissions service. * Removed outdated bundled permission mappings, keeping access controls aligned with current configuration. * Updated permission mapping coverage to include both current API specifications and MCP tools. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
ff5376c9f0 |
Add go page: Postgres Summit US 2026 contest (#49597)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — new marketing landing page (`/go` page). ## What is the current behavior? No landing page exists yet for Supabase's presence at Postgres Summit US 2026 (Sept 30 - Oct 2, 2026, NYC). ## What is the new behavior? Adds a contest landing page and thank-you page, modeled on the existing `pgconf-dev-2026/contest` go page pattern: - `supabase.com/go/postgres-summit-2026/contest` — MacBook Neo giveaway entry page, featuring the "Everything to know about Postgres Locks" talk by Brian Brennglass (Supabase), Wed Sept 30, 4:00–4:50 PM EDT, Rossi Intermediate room - `supabase.com/go/postgres-summit-2026/contest/thank-you` — confirmation page after entry - Registered both in `apps/www/_go/index.tsx` with a `// remove after October 31, 2026` cleanup marker, since this is a temporary event page - HubSpot form wired to a real form GUID, with field mapping verified against the form's actual internal property names (note: `company_name` maps to `name` on the HubSpot **Company** object, not the usual `company` Contact property — verified directly in the HubSpot form editor rather than assumed) Verified locally: both pages render correctly (hero, speaker section with headshot, how-to-enter steps, form) via `pnpm --filter www dev`. ## Additional context - Contest entry deadline is currently set to Monday, October 12, 2026, 12:00 PM PDT — a placeholder estimate (~12 days post-event, matching the pattern used on other event contest pages), not sourced from an official deadline. Flagging for review before this goes live. - No talk-slides link exists yet for this session, so the "View session details" CTA links to the official postgresql.us session page instead. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Postgres Summit US 2026 contest landing page featuring prize information, event content, entry instructions, and a contest entry form. * Added a thank-you page with submission confirmation, contest details, onboarding guidance, and links to the dashboard and website. * Added registration for both pages with availability through October 31, 2026. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> |