Commit Graph
20360 Commits
Author SHA1 Message Date
Ali Waseem 2cd9b42e80 fix(studio): add a keyboard shortcut for the Compute sidebar item (#50361)
The Compute entry in the project sidebar was the only product route
without a `shortcutId`, so it had neither a `G`-chord nor the hover
keybind tooltip every sibling gets. Bound it to `G` then `C` (previously
unused) and added a test asserting every product route carries a
shortcut.

Fixes FE-4389

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added a keyboard shortcut for quick navigation to Compute: press
**G**, then **C**.
- Compute navigation now includes a discoverable shortcut for consistent
access from the navigation interface.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 19:44:40 +00:00
8bbd1d3048 fix(studio): fall back to unified preset for an unrecognized query-performance preset (#50348)
## Summary
- `useIndexInvalidation()` resolves the `preset` URL param through
`QUERY_PERFORMANCE_PRESET_MAP` with no fallback.
- A value that isn't one of the four known
`QUERY_PERFORMANCE_REPORT_TYPES` (stale bookmark, hand-edited URL, a
renamed/removed preset) resolves to `undefined`.
- That `undefined` preset flows into `generateQueryPerformanceSql()`,
which indexes `queryPerfQueries.queries[preset]` with it, producing
`undefined` for `baseSQL` — and the very next line reads
`baseSQL.queryType`, crashing the whole page via `globalErrorBoundary`.
- Fix: fall back to the `unified` preset when the URL value doesn't map
to a known preset, mirroring the `parseAsString.withDefault('unified')`
intent already expressed a few lines above for the case where the param
is entirely absent.

## Evidence (Sentry, past week)
- [SUPABASE-APP-K9Z](https://supabase.sentry.io/issues/7721026586/) —
`TypeError: Cannot read properties of undefined (reading 'queryType')`
on `/dashboard/project/[ref]/observability/query-performance`.

## Test plan
- [ ] Existing `useQueryPerformanceQuery.test.ts` suite still passes
- [ ] Manually confirmed
`QUERY_PERFORMANCE_PRESET_MAP[QUERY_PERFORMANCE_REPORT_TYPES.UNIFIED]`
resolves to `'unified'`, a valid key in
`PRESET_CONFIG[Presets.QUERY_PERFORMANCE].queries`

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM

---
_Generated by [Claude
Code](https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-14 13:28:24 -06:00
Miranda Limonczenko bc917370d1 docs: recommend a local CLI install on the front page (#50356)
Closes DOCS-1391

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update.

## What is the current behavior?

The docs front page is the only place that still recommends a global CLI
install. It shows `npm install -g supabase` in both the CLI tab and the
AI prompt, and tells the agent to run `supabase init`.

Everywhere else in the docs installs the CLI as a project dev
dependency, so the version is pinned in `package.json` and everyone on a
team runs the same one.

## What is the new behavior?

- `installCli` becomes `npm install supabase --save-dev`, matching
[Install and run the
CLI](https://supabase.com/docs/guides/local-development/cli/getting-started).
- `initialize` becomes `npx supabase init`. A dev-dependency install
leaves no global `supabase` command.
- The AI prompt says "as a project dev dependency" and states the
reason, so an agent doesn't fall back to a global install.
- Updates the same wording in the monitoring and debugging prompt, which
shares the constants.
- Updates the `AiPrompt` markdown schema test assertion.

## Manual testing

1. Open the [docs front page
preview](https://docs-git-docs-cli-local-install-supabase.vercel.app/docs).
The AI Prompt tab reads "Install the Supabase CLI as a project dev
dependency with `npm install supabase --save-dev`, so the version is
pinned per project" and ends with `npx supabase init`.
2. Select the **CLI** tab. It shows `npm install supabase --save-dev` on
the first line and `npx plugins add supabase-community/supabase-plugin`
on the second.
3. Run `pnpm run -F docs test:local:unwatch
internals/markdown-schema/AiPrompt.test.ts`. All tests pass.
2026-09-14 12:21:59 -07:00
Prashant Sridharan c38117b613 Added new go page for CISO dinner at Select (#50360)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added a CISO dinner landing page and integration with Notion.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added an RSVP page for the Supabase Select 2026 CISO Dinner in San
Francisco.
* Included event details, host information, attendee fields, and RSVP
submission with confirmation redirect.
* Added a thank-you page confirming successful registration and sharing
event timing and security resources.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 20:20:43 +01:00
c3ccf9179f fix(www): skip the careers-page globe when WebGL is unavailable (#50350)
## Summary
- `cobe`'s `createGlobe()` resolves the canvas context internally as
`getContext('webgl2') || getContext('webgl') || 'experimental-webgl'` (a
context-name *string*, not an actual context). When both `webgl2` and
`webgl` are unavailable, it falls through to that string, but modern
browsers no longer support the `experimental-webgl` context name, so the
resulting context is `null` and cobe crashes internally reading
`.enable(...)` on it.
- `apps/www/components/Globe.tsx` (used only on `/careers`) had no guard
for this, so a browser/device with WebGL disabled or unavailable (GPU
blocklist, corporate policy, privacy setting) crashes the entire careers
page via `globalErrorBoundary`.
- Fix: detect WebGL support ourselves (`getContext('webgl2') ||
getContext('webgl')`) before mounting the globe, and skip rendering it
(no globe, rest of the page renders fine) when unsupported.

## Evidence (Sentry, past week)
- [WWW-41](https://supabase.sentry.io/issues/7731263201/) — `TypeError:
Cannot read properties of null (reading 'enable')` on `/careers`, leaf
frame inside `cobe`/`phenomenon`.

## Test plan
- [ ] Manually confirmed `Globe.tsx` is only imported by
`apps/www/pages/careers.tsx`
- [ ] No automated test added (this is a purely decorative,
non-interactive canvas element with no existing test coverage); happy to
add one if reviewers want it

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM

---
_Generated by [Claude
Code](https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-14 13:20:02 -06:00
62fe0fca4a fix(studio): guard branches and read-replicas queries against non-array 200 bodies (#50347)
## Summary
- `getBranches()` (`apps/studio/data/branches/branches-query.ts`) and
`getReadReplicas()` (`apps/studio/data/read-replicas/replicas-query.ts`)
cast the raw API response body to an array with no runtime check.
- When the endpoint returns a defined-but-non-array 200 body, the `??
[]` fallback in each consumer doesn't catch it (the value isn't
nullish), and the first `.find`/`.filter` call throws, crashing the
whole page via `globalErrorBoundary`.
- This is the same known class of bug already fixed elsewhere in the
codebase (e.g. `apps/studio/data/lint/lint-query.ts`, and the
`api-keys`/`oauthApps`/`secrets` fetchers) — applies the same
`Array.isArray(data) ? data : EMPTY_ARR` guard.

## Evidence (Sentry, past week)
- [SUPABASE-APP-KA2](https://supabase.sentry.io/issues/7722780387/) —
`(m??[]).find is not a function` in `ActivityStats.tsx`
(`branchesData.find`), full-page crash on `/dashboard/project/[ref]`.
- [SUPABASE-APP-KAE](https://supabase.sentry.io/issues/7729679561/) —
`u.filter is not a function` in `AWSPrivateLinkForm.tsx`
(`databases.filter`), full-page crash on
`/project/[ref]/settings/integrations`.

## Test plan
- [ ] Existing query hook tests still pass
- [ ] Manually verified `Array.isArray` guard mirrors the established
`lint-query.ts` pattern

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM

---
_Generated by [Claude
Code](https://claude.ai/code/session_01RUrmUfMBpPqkgerh9onNTM)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-14 19:16:41 +00:00
Sean Oliver d439ba57f4 feat(studio): mask HTML attributes in session replay (#48818)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Hardening ahead of any decision to enable session replay, plus a
dependency bump. Follow-up to #48515.

### What's inside

- ~50 lines of logic: the callback, the `url()` pattern, and the theme
and SVG-reference gates
([session-replay.ts](https://github.com/supabase/supabase/pull/48818/changes#diff-b7e4f10387ee7a116dd1673f70a55c0ba066687ff2d228bc2320eba75a349fac))
- ~170 lines of allowlist, one attribute name per line, skimmable ([same
file](https://github.com/supabase/supabase/pull/48818/changes#diff-b7e4f10387ee7a116dd1673f70a55c0ba066687ff2d228bc2320eba75a349fac))
- ~150 lines of comments saying why each group is allowlisted, since a
wrong entry is a privacy or a fidelity bug ([same
file](https://github.com/supabase/supabase/pull/48818/changes#diff-b7e4f10387ee7a116dd1673f70a55c0ba066687ff2d228bc2320eba75a349fac))
- ~430 lines of tests, one case per policy decision
([session-replay.test.ts](https://github.com/supabase/supabase/pull/48818/changes#diff-f9feb872ad0136cf87c7e9fb2af72eb3f4019464c06f0b7dd050ffb85373ccb8))
- 1 line of dependency bump, plus its lockfile
([package.json](https://github.com/supabase/supabase/pull/48818/changes#diff-50d7c39a9430d37971aa76858165ab4f7921c4cc4340b28e9b673ce6982e63cf))

## What is the current behavior?

Session replay is disabled in every environment, and no recordings
exist. This is about what a recording *would* contain if it were ever
switched on.

Attributes are the one channel replay masking cannot reach. `maskTextFn`
only sees DOM text nodes, so a component interpolating customer data
into a `placeholder`, `title` or `aria-label` would be captured
verbatim. Before `posthog-js` 1.413.0 there was no hook for it at all,
and the only mitigation was blocking the element, which drops it from
the capture entirely.

Two places in Studio where that would apply:

- `CreateOrUpdateCustomProviderSheet.tsx:506-507` interpolates the
project's API host into both `value` and `placeholder`. The `value` is
masked. The `placeholder` is not.
- `FileExplorerHeader.tsx:185` renders `Search in
${currentFolderName}...`, a customer storage folder name.

The list is not complete. Any component echoing context into a tooltip
reproduces it, and the author has no reason to be thinking about replay.

Linear [GROWTH-1094](https://linear.app/supabase/issue/GROWTH-1094).
Blocks [GROWTH-1073](https://linear.app/supabase/issue/GROWTH-1073).

## What is the new behavior?

`maskAttributeFn` with a default-deny policy: an allowlist of the
attributes replay needs to render, everything else masked.

### Policy edge cases

- **rrweb's `rr_*` layout attributes have to be allowlisted
explicitly.** posthog-js only applies its own exemption for those when
`maskAllElementAttributes` does the masking. A callback does not get the
exemption.
- **HTML `id` is masked. SVG `id` passes.** `AreaChart.tsx:119` emits
`<linearGradient id="colorUv">` and references it as
`fill="url(#colorUv)"`, so masking it breaks the gradient. But Studio
also binds customer-named values to `id` (`bucket.id` is a storage
bucket name). Split on `element.namespaceURI`.
- **SVG reference attributes pass only fragment-only targets.** recharts
clips every series with `clip-path="url(#clipPath-<id>)"`, so
`clip-path`, `mask`, `filter`, `marker-*`, `fill` and `stroke` have to
survive. They accept external URLs too, so the policy checks the target
rather than allowlisting the attribute name.
- **The `url()` pattern consumes escaped delimiters and ignores case.**
A target containing a quote serializes as `\"` and one containing a
bracket as `\)`, so a naive `[^")]*` stops at the backslash and leaves
the tail of the URL recorded. `URL(...)` is the same function as
`url(...)`. A token the pattern cannot parse falls through to a masking
fallback rather than passing.
- **`url()` targets inside `style` are masked, keeping the
declarations.** The feedback widget puts `toPng(document.body)`, a
base64 PNG of the whole dashboard, into a `background-image`, and the
storage preview panes put signed object URLs there. No other masking
path covers those, because they are not text nodes, a canvas, a network
request or an `img src`.

The config also pins `maskAllElementAttributes: false`. Left unset it
resolves from the PostHog UI, and `true` discards `maskAttributeFn`
entirely.

The `posthog-js` floor rises to `^1.416.1`, the first version carrying
both attribute masking and the "coarse option wins" precedence.

This does not enable recording anywhere.

## Additional context

### Verification

Ran on the studio-staging preview against a live session: 817 seconds,
190 clicks, 82 keypresses. Staging has no server-side masking config, so
everything masked came from this code.

| Check | Result |
|---|---|
| Storage folder search placeholder | Asterisked. Pre-fix it read
`Search in <folder>...` |
| Custom auth provider sheet | Fully masked, including the callback URL
field |
| Canary folder name in event properties | 0 hits, with 51 events in the
session as the control |
| Console capture | `console_log_count: 0` despite the project having
`capture_console_log_opt_in: true` |
| Telemetry regression | None: `$pageview` x34, `$pageleave` x5,
`$groupidentify` x4, `$identify` x1 |

Recording was scoped to that one preview by an origin restriction plus a
URL trigger. Both were reverted afterwards along with the project
toggle.

The policy has 175 unit tests. Separately, the config was bundled with
esbuild and applied to a DOM reproducing Studio's serialized output (the
AreaChart gradient, a recharts `clip-path`, a lucide icon, an inline
`background-image`), and the chart, gradient fill and icon come out
pixel-identical.

### Known fidelity costs

- `img src` is masked, so images don't render in replay. Storage object
URLs are signed customer content.
- `ProviderIcon` renders its mark as `maskImage: url(<src>)` and
`normalizeIconPath` accepts absolute URLs, so provider icons don't
render either.

### Out of scope

rrweb records `<style>` element text without calling either masking
function, because its text-node serializer skips masking when the parent
is `STYLE`. This PR does not reach that channel. Fixed separately in
#50270 / [GROWTH-1229](https://linear.app/supabase/issue/GROWTH-1229).

`captureJsonLd` also defaults on as of PostHog's 2026-08-30 defaults,
which is a capture channel masking doesn't reach. Studio renders no
`ld+json`, so it's inert there, and pinning it off was left out to keep
this PR to its scope.

### The allowlist is the weak part

The policy is default-deny over attribute *names*, so its surface is
every attribute any shipped library emits, and that set grows with each
dependency. A miss is also invisible to these tests, which assert what
the function returns rather than whether some selector elsewhere still
matches. Both failure directions are reachable that way: an attribute
carrying customer data, and an attribute a stylesheet needs.

[GROWTH-1232](https://linear.app/supabase/issue/GROWTH-1232) tracks the
mechanism change: scope by namespace instead of by name, since 50 of the
159 entries exist only to serve SVG rendering, plus a conformance test
that derives the expected set from the codebase so a new dependency
fails CI rather than degrading a replay. Deliberately not done here,
since rewriting the mechanism of a privacy control buys maintainability
rather than correctness.
2026-09-14 09:48:58 -07:00
Sean Oliver 32f17f994d fix(studio): key query chart series by position, not column name (#50270)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix. Hardening ahead of any decision to enable session replay.

### What's inside

- ~47 lines of logic: positional series keys, the X-key collision guard,
and the rewiring of rows, cumulative results and axis width
([QueryResultChart.tsx](https://github.com/supabase/supabase/pull/50270/changes#diff-dae994728613498678bcc06a3ea5176b36708e06b531cfc7eddae3e588fff528))
- ~123 lines of tests, one case per chart type, cumulative setting and
edge case
([QueryResultChart.test.tsx](https://github.com/supabase/supabase/pull/50270/changes#diff-6e1c92ad725bac0324db4d079f3d0cd061b8f6e2aecdc21bcdc5969c90dc3c59))

## What is the current behavior?

Session replay is disabled in every environment, and no recordings
exist. This is about what a recording *would* contain if it were ever
switched on: charting a query result would put the customer's own column
names into it.

`ChartContainer` writes every chart config key into a `<style>` element
as `--color-<key>`. rrweb records `<style>` text verbatim:

```js
u = "STYLE" === parentTagName || void 0
h = "SCRIPT" === parentTagName || void 0
!u && !h && o && r && (o = maskTextFn ? maskTextFn(o, parent) : o.replace(/\S/g, "*"))
```

The `!u` guard means `maskTextFn` never sees stylesheet text. It is a
text node, so `maskAttributeFn` does not see it either. CSS written into
the DOM is a channel no masking hook reaches.

`QueryResultChart` keyed its config by the column names picked for the Y
axis, which come from the customer's own SQL results. With recording
enabled, a query charting a column named `customer_email` would produce
`--color-customer_email` in the captured DOM.

Linear [GROWTH-1229](https://linear.app/supabase/issue/GROWTH-1229).
#48818 masks the attribute channel. This channel is text, so that PR
does not reach it.

## What is the new behavior?

Y series are keyed by position (`series_0`, `series_1`), so no customer
string reaches the config keys.

The column name still goes through as `config[key].label`, which
`chart.tsx` renders into the tooltip and legend as text. Text nodes
outside `<style>` are masked by `maskReplayText`, so the name is safe
there and the chart stays readable.

The X column keeps its own name. Only config keys reach the `<style>`
and the X column is never one, so renaming it would buy nothing, and it
would cost the `timestamp` handling: `ChartBar` and `ChartLine` branch
on `xKey === 'timestamp'` to format tooltip dates and render the
date-range footer. Keeping the original name needs one guard, since an X
column literally named `series_0` would share a row key with the first Y
series. `xKeyFor` appends underscores until the two are distinct.

## Additional context

### Testing

Eleven tests. They assert the rendered `<style>` contains
`--color-series_0` and does not contain the column name, across both
chart types and both cumulative settings, plus the two-series case, the
`timestamp` column and the collision guard.

Three are verified to catch the defect they cover: the style-key
assertion fails against the unfixed component, the `timestamp` assertion
fails when the X key is pinned to a constant, and the `xKeyFor` cases
fail when the guard's body is removed.

`vitest run components/interfaces/Explorer` passes: 170 tests across 16
files.

The tooltip and legend path isn't asserted, because recharts doesn't
render either one at the 0x0 size jsdom gives the container. That the
label is what renders there comes from reading `chart.tsx`. It is
unverified at runtime.

### Remaining exposure

Every other `ChartContainer` caller passes literal keys
(`--color-error`, `--color-ok_count`), and `UnifiedLogs` filters a
static config by a fixed level set, so this was the only caller feeding
it customer strings.

`chart-bar.tsx:119-124` and `chart-line.tsx` still fall back to building
a config from whatever `dataKeys` they're given, so a future caller can
reintroduce this without touching `QueryResultChart`. A general guard
would have to live in `ChartContainer` or in the replay config.

CSSOM writes (`insertRule`, `replace`, `replaceSync`, adopted
stylesheets) also emit CSS outside both masking hooks. This PR does not
close that path.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved query result charts to preserve the source column name used
for the X-axis.
- Prevented X-axis names from conflicting with generated series
identifiers.
- Ensured bar and line charts consistently bind data to the correct
X-axis and series.
- Preserved timestamp-based chart behavior, including the date-range
footer.
- Chart series styling now uses stable positional identifiers, ensuring
colors remain correctly assigned across configured series.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 09:48:47 -07:00
kemal.earthandAli Waseem 4aa34f556a feat(studio): mcp secrets interstitial polish (#50351)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- We made the Next step copy a bit more generic so it doesn't read like
it's pointing you back to Inspector UI.
- Added CTA on key stored screen to send you to Edge Function Secrets
directly.
- Tidies up footer area to always be centrally aligned across all
states.

### 1. Enable the feature flag

### 2. Preview states via URL

Mock mode is enabled automatically in local/staging. Navigate to
`/mcp/secrets` with a `state` query param:

http://localhost:8082/mcp/secrets?state=<state>

States that need no other params:

| `state` value    | What it shows                          |
| ----------------- | --------------------------------------- |
| `loading`          | Loading skeleton                        |
| `expired`          | Link expired                            |
| `cancelled`        | Request cancelled                       |
| `paused`           | Storing keys paused                     |
| `wrong-account`    | Signed in as the wrong account          |
| `error`            | Generic failure                         |

States that need a real project —ame=<KEY_NAME>`:

| `state` value      | What it sh           |
| -------------------- | ---------------------- |
| `form`                | The "st              |
| `stored`              | Success              |
| `stored-timeout`      | Successopped waiting |
| `already-stored` | Key was already stored, nothing to do |

Example:

http://localhost:8082/mcp/secretsJECT_REF&name=OPENAI_API_KEY

### 3. What to check

- [ ] `stored` / `already-stored`tions secrets"** button linking to
`/project/<ref>/functions/secrets
- [ ] States without a project re `paused`, `error`) don't show that
button
- [ ] Footer text is centered on
- [ ] `wrong-account` → **Switch its footer is centered
- [ ] The provider-dashboard link` state, use a `name`
like`OPENAI_API_KEY` or `RESEND_API_Khint) is centered too


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a project-specific link to Edge Functions secrets from the MCP
setup screen when a project is available.
* Added a separator to distinguish the secrets link from the remaining
setup guidance.

* **Improvements**
* Updated completion guidance to tell users to return to their agent and
confirm the setup is finished.
* Standardized interstitial footer content with centered guidance and
consistent provider dashboard instructions.

* **Tests**
* Added coverage for displaying the project-specific secrets link and
hiding it when no project is associated.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-14 17:44:42 +01:00
b0de9dd7a6 Create log docs (#47047)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

No docs on how to interpret and configure PG logs

## What is the new behavior?

Adds docs on how to interpret and manage PG logs

## Additional context

Related Linear issue:
-
https://linear.app/supabase/issue/DEBUG-131/create-docs-outlining-all-log-settings


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
  * Added a new guide for customizing Supabase-hosted Postgres logging.
* Documented available log settings with default values, plus SQL
examples to inspect effective settings and role-specific overrides.
* Covered configuration options (CLI, Management API, SQL), including
precedence rules, role-level override/reset examples, and restart
guidance for scheduled logging.
* Updated the docs navigation with a new “Postgres log configuration”
entry.
* **Chores**
  * Updated the MDX spelling allow list to include “subfield”.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-14 12:15:15 -04:00
Nik RichersandNik Richers ea79df46bc docs: explain purpose of /edit-the-docs in CONTRIBUTING.md rather than the "Write the docs" checklist (#50313)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs authoring guidance: keep `/edit-the-docs` out of the Write the docs
checklist and document when to use what skill in `CONTRIBUTING.md`.

## What is the current behavior?

The Write the docs checklist mentions `/edit-the-docs` mid-flow and
lists it among checklist skills. That skill is a different workflow and
audience, so it risks steering people off the six-stage process.

## What is the new behavior?

- Checklist lists only Write the docs skills; no `/edit-the-docs`
mid-stage note.
- `CONTRIBUTING.md` splits **Write the docs skills** from **Edit
existing pages**.
- Write the docs applies when product intent and code drive the change,
including revising or restructuring existing pages. `edit-the-docs` is
for style, structure, or brevity when the product story is unchanged.

## Additional context

Also drops a redundant `/test-the-docs` note from "What good looks like"
(Self-review still covers it).

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
2026-09-14 09:02:17 -07:00
Ivan VasilovandAli Waseem c60bb37a74 chore: Bump nextjs to non-vulnerable version (#50341)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated the Next.js version used by the application and documentation
sites.
* Aligned workspace tooling with the latest supported Next.js 16.3.5
release and refreshed related platform builds.
  * Updated application and documentation sites to Next.js 15.5.24.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-14 17:55:02 +02:00
Joshen Lim c9e035910d Add HA toggle to enabled features (#50344)
## Context

As per PR title - flags the HA toggle in project creation form behind a
flag in enabled-features
Behaviour should be status quo for both staging and prod

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a high-availability option to the project creation flow for
eligible accounts when the feature is enabled.
  * The option is available through controlled feature configuration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 23:14:10 +08:00
Joshen Lim 5104754018 Fix types master (#50345)
## Context

Just needed to adjust the API types import - the name likely changed
somewhere
`AnalyticsResponse` -> `AnalyticsResponse_Output`

Verified the typecheck locally

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Updated analytics test typing to align with the current analytics
response schema.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 23:02:16 +08:00
Jordi Enric 35f2eeefcf fix(observability): replace egress chart with usage link FE-4310 (#49850)
## Problem

The Network Traffic egress chart is derived from request logs and can
substantially undercount billed traffic. Showing it beside diagnostic
ingress data left customers with an untrustworthy egress number.

## Fix

Remove the log-derived egress chart, retain ingress, and add a Billable
egress callout that links to the selected organization’s Usage page. The
callout is shown only on hosted Studio, where organization billing data
is available.

## How to test

- Open API, Storage, Auth, or PostgREST observability.
- Confirm Network Traffic shows only the ingress chart.
- Confirm the Billable egress callout links to the organization Usage
page’s egress section.
- Expected result: diagnostic traffic and billable usage are no longer
presented as competing egress totals.
- Automated checks: git diff --check and final code review passed.
Focused lint could not run because missing dependencies require registry
access, and DNS for registry.npmjs.org is unavailable.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* Clarified Network Traffic report tooltips to explain that ingress is
measured from request logs.
* Platform deployment reports now display ingress data only; egress
charts are no longer shown.
* Added a notice linking to the Usage page for billable egress details.
* Applied the updated Network Traffic explanation consistently across
API overview, storage, and shared report views.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 15:43:55 +02:00
Jordi Enric d2ed60da27 fix(auth): migrate overview errors to clickhouse (#50174)
## Problem

Auth overview error tables call the legacy logs endpoint through
fetchLogs defaults, even with the ClickHouse migration enabled.
Success-rate cards also show zero when there are no requests and
misleading relative changes between small rates.

## Fix

Select matching BigQuery or ClickHouse queries with otelLegacyLogs,
separate caches by engine, and normalize numeric results.

Show No data for success rates without requests and omit comparisons
when either period has no requests. Show success-rate changes in
percentage points: 0% to 0.2% displays +0.2 pp. Omit undefined relative
changes from a zero baseline for activity and sign-up counts. Show
explicit errors for failed log requests, including error payloads
returned with HTTP 200, instead of empty tables.

## Validation

- Auth overview error tables compared against staging with matching
data.
- 84 focused tests passed across four suites, including 25 direct
formatter tests.
- 12 MSW integration tests exercise both endpoint/SQL pairs, HTTP and
embedded API failures, and rendered No data, genuine 0%, and +0.2 pp
states.
- Unit tests cover missing periods, zero requests, percentage-point and
relative changes, SQL structure, and numeric result parsing.
- Formatting and diff checks passed; code review found no actionable
issues.
- Full local lint/typecheck are limited by shared checkout dependencies.
Browser comparison confirmed the deployed rate display uses percentage
points and shows No data without a comparison for absent server
requests; populated error rows match staging. The final formatter
extraction (9886b78682) was also deployed and verified in the browser;
CI completion remains outstanding.

Split from #50173.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added OpenTelemetry support for authentication error and metrics
reporting.
- Added clearer handling of missing metric data, including “No data”
states.
- Improved success-rate change calculations using percentage-point
differences.
  - Added user-visible error states when analytics requests fail.

- **Bug Fixes**
- Improved validation and handling of authentication metrics and error
data.
  - Corrected formatting and rounding for metric values and changes.

- **Tests**
- Expanded coverage for legacy and OpenTelemetry analytics, error
handling, empty data, formatting, and edge cases.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 15:35:03 +02:00
Jordi Enric 38e8f12b1b fix(studio): gate homepage health advisor (#50328)
## Problem

Health Advisor results appear on the project homepage whenever the main
`healthAdvisor` flag is enabled, so the homepage cannot be rolled out
separately. The existing gates also contain redundant boolean and
platform checks.

## Fix

Require both `healthAdvisor` and `healthAdvisorInHomepage` before
fetching or displaying health advisories on the homepage. Simplify all
Health Advisor gates to use the boolean ConfigCat flag directly,
including the cleanup requested in the review of #50326.

## How to test

- Enable only `healthAdvisor` and verify Health Advisor remains
available outside the homepage while health results do not appear or
load on the homepage.
- Enable both flags and verify health results appear on the homepage.
- Disable `healthAdvisor` and verify Health Advisor remains unavailable
everywhere.
- Existing targeted tests pass: 5 tests across Advisor menu and panel
integration suites.
- Prettier and whitespace checks pass.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Health Advisor is now available in non-platform environments when
enabled.
* Navigation, filtering, lint checks, and project pages consistently
follow the Health Advisor feature setting.
  * Self-hosted environments can use the Health Advisor category.
* **Bug Fixes**
* Homepage Health Advisor visibility now follows both the Health Advisor
and homepage-specific settings.
* Updated empty states and health lint results to match the configured
availability.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 13:34:24 +00:00
Anthony Lio 819df2ae4d feat(www): menu nav enhancements (#50282)
## What kind of change does this PR introduce?

feature reworks the www header dropdowns

## What is the current behavior?

menu dropdown navigation animation between items feels scattered

## What is the new behavior?

- adds dropdown card resize with a transition and the content crossfades
when switching
- removes dead zone between or under nav items
- sets card is centered on the screen + enhance tablet bp
- adds slight ui refresh spacing, colors, sizes

| state | preview |
| -------|------|
| before | <video
src="https://github.com/user-attachments/assets/acd8e161-a697-4070-b751-4f4e9f1eab19"
/> |
| after | <video
src="https://github.com/user-attachments/assets/fe403afd-0074-4cb5-9223-fd6cdd2f7d5a"
/> |



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Navigation dropdowns now provide smoother directional transitions,
keyboard-focus states, and reduced-motion support.
* Product navigation is organized into clearer Products and Modules
sections.
* Navigation layouts adapt earlier across screen sizes with responsive
two-column arrangements.

* **Style**
* Updated dropdown spacing, colors, borders, menu item styling, and
customer imagery sizing.
  * Refined blog loading placeholders with slightly tighter spacing.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 15:51:39 +03:00
Pedro RodriguesandClaude Sonnet 5 22d7bc0cfd feat(studio-evals): custom search_docs tool for the eval harness (no token / no PAT) (#50092)
- Eval harness's only live tool, `search_docs`, no longer needs the
in-process MCP client or its dummy token — it now calls the public docs
GraphQL API (`https://supabase.com/docs/api/graphql`) directly. Low risk
as this is an eval-harness change only. Production assistant path
(`mcp-tools.ts`) untouched.

**Update:** per [@mattrossman's
review](https://github.com/supabase/supabase/pull/50092#discussion_r3980396341),
the eval tool's description embeds the Content API's own GraphQL schema
(fetched via a `{ schema }` query and minified with `gqlmin`), mirroring
how `@supabase/mcp-server-supabase`'s `docs-tools.ts`/`loadSchema`
populates production's `search_docs` description. Without it, the model
had no schema to work from and issued malformed queries, which caused
the 218 `search_docs` errors and the -25pp Docs Faithfulness regression
in the first eval run on this PR. Schema loading is required:
`createSearchDocsTool()` rejects if the schema fetch fails, so preflight
and the gated eval job fail loudly instead of producing untrustworthy
fallback results. `createSearchDocsTool` is async because the `ai`
package's `tool()` only accepts a plain string `description`, unlike the
MCP SDK's async description support; both callers (`getMockTools`,
`evals/preflight.ts`) await it. `gqlmin` is a direct `apps/studio`
dependency and was already transitive via
`@supabase/mcp-server-supabase`.

### Verification
- `pnpm -C apps/studio exec -- tsc --noEmit` reaches the compiler; it
reports only the pre-existing unrelated
`packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx`
`StaticImageData` error.
- `pnpm -C apps/studio exec -- vitest run
lib/ai/tools/mock-tools.test.ts lib/ai/tools/mcp-tools.test.ts` — 21/21
passed.
- `pnpm exec tsx evals/preflight.ts` — live docs API schema fetch and
search_docs call passed.
- `NEXT_PUBLIC_CONTENT_API_URL=http://127.0.0.1:1/graphql pnpm -C
apps/studio exec -- tsx evals/preflight.ts` — failed fast as expected,
proving schema/API failures gate evals.
- Fresh `run-evals` pass: Docs Faithfulness 55.7% (0pp), with no
systemic `search_docs` regression.

Risk: eval-harness-only; schema/API outage now fails the eval job before
scoring rather than allowing fallback descriptions.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added documentation search powered by the public Supabase
documentation GraphQL API.
* Documentation search results now include live schema information and
clearer error handling for failed or invalid requests.

* **Bug Fixes**
* Improved evaluation tooling reliability by removing unnecessary
connection-abort behavior.
* Updated validation to detect missing search tools and malformed
documentation responses.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-14 12:51:14 +02:00
Gildas Garcia 6f15081892 Scoped PAT: show dependencies between permissions (#50271)
## Problem

Some permissions require others to actually have an effect, for
instance:

- `api_gateway_keys_secret_read` requires `api_gateway_keys_read` or
`api_gateway_keys_write`
- `data_api_config_secret_read` requires `data_api_config_read` or
`data_api_config_write`

This is not obvious from a user perspective.

## Solution

We decided to make these requirements explicit by:
- Adding a line in the permission item stating the dependency
- Disabling the permission if its dependency isn't met
- Resetting the permission if it was selected but the dependencies
aren't met anymore

## How to test

- On
[staging](https://studio-staging-git-gildasgarcia-fe-4380-dashboa-b2a227-supabase.vercel.app/dashboard/account/tokens)
- Create a new token
- Check that _API Key Secrets_ is greyed out and disabled
- Select _API Key_ read or read-write
-  _API Key Secrets_ shouldn't be greyed out and disabled
- Select a value for _API Key Secrets_
- Set _API Key_ to none
- Check that _API Key Secrets_ is greyed out, disabled and reset to none
too
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added dependency-aware permissions for scoped access tokens.
- Permission descriptions now show required dependencies and permission
levels.
- Dependent permissions automatically reset to “None” when requirements
are not met.
- Permission controls and unavailable selections reflect dependency
requirements.
- **Accessibility**
- Screen readers now receive an announcement when a permission is reset
to “None” due to unmet dependencies.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 11:09:46 +02:00
Jordi Enric 519a3a5644 fix(studio): gate health advisor behind feature flag (#50326)
## Problem

Health Advisor runs checks and displays health alerts without a
dedicated rollout flag.

## Fix

Gate Health Advisor behind the ConfigCat `healthAdvisor` flag,
defaulting to off when missing or loading. This covers the navigation
and shortcut, command menu, direct page access, homepage alerts, Advisor
panel filters and details, and health-check requests. Cached health
results and saved Health filters no longer surface health content when
disabled. Existing platform-only restrictions remain.

The `healthAdvisor` flag will be created separately in ConfigCat.

## How to test

- With `healthAdvisor` off, verify Health Advisor is absent from
navigation, command search, homepage alerts, and Advisor panel
categories. Opening `/project/<ref>/advisors/health` shows an
unavailable message. No health-check POST requests should run.
- With the flag on for an active platform project, verify these surfaces
return and health checks load.
- Disable the flag after loading health results and selecting the Health
filter or an alert. Verify cached health alerts disappear and the panel
remains usable.
- Existing menu tests pass. No new feature flag tests are included.
Formatting and whitespace checks passed.
- Local lint could not start because the available dependency
installation is missing `@eslint/compat`. Full TypeScript validation
failed with missing dependencies and incompatible workspace types in the
reused local dependency installation; it did not provide a clean
validation result.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Health Advisor availability is now controlled by a feature flag on the
platform.
* When enabled, health advisories appear in advisor menus, filters,
project checks, and empty-state messaging.
* When unavailable, the Health Advisor page clearly indicates that it
isn’t available for the project.

* **Bug Fixes**
* Health advisory data is no longer requested when the feature is
disabled, preventing unavailable health results and errors from
appearing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 11:00:02 +02:00
Guillaume Faas 1531eb427d docs(csharp): add new C# Reference for v8.0.0 (#50116)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Documentation update: add a new page for the C# SDK reference v8.0.0


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added C# client reference documentation for version 8.1.0.
  * Added navigation for the C# Reference v8 documentation.
* Documented authentication, database, Realtime, Storage, filtering, and
query APIs with C# examples.

* **Documentation**
* Added C# SDK 8.0.0 and 8.1.0 release notes, including breaking
changes, new capabilities, and bug fixes.
* Updated documentation version listings and search coverage for C# v8.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 10:07:26 +02:00
Guillaume Faas ae7167fe58 docs: update SignUp documentation in C# reference (#48733)
Addresses https://github.com/supabase-community/gotrue-csharp/issues/85

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Clarified sign-up behavior, including returned sessions, email
confirmation, automatic session adoption, and sign-in events.
- Documented existing-user obfuscation and the error raised when
registration is rejected.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 10:07:10 +02:00
Coenen Benjamin 9f7944a853 fix(warehouse): add support for both db host and db host addr in catalog (#50261) 2026-09-14 16:01:46 +08:00
Jordi Enric fb22534439 fix: share sentry crash policy and enable www reporting (#50232)
## Problem

The website initializes Sentry only on the server and edge runtimes,
leaving browser crashes unreported. Its crash-reporting setup also needs
the same consent and third-party filtering policy that docs and Studio
otherwise maintain separately.

## Fix

Add www browser initialization and tagged crash capture for both Next.js
routers, with accessible fallback focus. Move the shared
consent/platform and third-party filtering into common/sentry, reuse it
from all three apps, and remove the duplicated docs/www helpers and
tests. Preserve each app's initialization and Studio's additional noise
filtering, sampling, and sanitization.

Include the source-map upload token in www's build cache inputs, and
trigger the shared/www and Studio test workflows when the shared policy
changes.

## How to test

- Run `pnpm --filter www test ../../packages/common/sentry.test.ts
lib/sentry-capture.test.tsx`: all 22 shared-policy and real-SDK capture
tests passed locally.
- Run `pnpm --filter studio exec vitest run
lib/sentry-client-options.test.ts`: all 42 Studio options and
policy-parity tests passed locally.
- The www capture tests exercise the actual initializer and both router
handlers with an in-memory transport, verify crash tags and fallback
focus, and enforce consent. Removing initialization, capture calls,
boundary tags, or consent gating was verified to fail these tests.
- On a www preview with its DSN configured, accept telemetry consent and
trigger temporary render errors in both routers. Verify they reach the
www Sentry project with the boundary tag and readable stack traces.

Formatting passes. Full local app typechecks encounter existing
dependency/generated-file drift, with no diagnostics in changed files.
Three unchanged TanStack mock call-count tests fail locally and
reproduce against the pre-refactor implementation. Live Sentry ingestion
and source-map uploads remain deployment checks.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Accessibility**
- Error pages now automatically move focus to a clearly labeled error
message, helping screen-reader and keyboard users understand when a page
fails.

- **Reliability**
- Browser error reporting now captures application crashes more
consistently across supported page types and navigation transitions.
- Reporting respects consent and platform availability while filtering
unrelated third-party failures.

- **Testing**
- Expanded automated coverage for error capture, reporting rules,
consent handling, and accessible error-page behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 09:28:08 +02:00
Danny WhiteandJoshen Lim 4dd8a95f0b feat(studio): polish Warehouse connection methods (#50246)
## What kind of change does this PR introduce?

Feature polish and a connection behaviour change.

## What is the current behaviour?

The Warehouse Connect sheet presents FlightSQL and DuckDB configuration
together. Enabling Warehouse also enables DuckDB catalogue access
automatically, even when the user only needs FlightSQL.

## What is the new behaviour?

The Connect sheet now starts with a query engine selector:

- FlightSQL shows the endpoint, connection string, user, password
action, and command-line example.
- DuckDB shows a persistent catalogue access switch. When enabled,
credentials and the attach script appear as the same numbered "Follow
these steps" flow used by other connection methods.
- Switching back to FlightSQL removes the DuckDB instructions.

> [!NOTE]
> This is an incremental change towards [this
UI](https://linear.app/supabase/project/warehouse-core-mvp-b85711dc2eff/activity#project-update-4e3183e1),
where the Integrations page is the control plane and Connect sheet is
simply for read-only connect values.

https://github.com/supabase/supabase/pull/50247 and
https://github.com/supabase/supabase/pull/50195 are subsequent PRs that
get us there.

> [!IMPORTANT]
> Enabling Warehouse no longer enables DuckDB catalogue access
automatically. DuckDB users must enable it explicitly from the
connection details. FlightSQL is unaffected.

This keeps global Warehouse provisioning separate from optional
credentials for one query engine. It also prevents successful Warehouse
setup from being followed by a secondary catalogue mutation that can
fail independently.

| Before | After |
| --- | --- |
| <img width="1280" height="1323" alt="10752"
src="https://github.com/user-attachments/assets/83b1069b-a262-4068-a5e3-b7f49860fdb2"
/> | <img width="1280" height="1323" alt="Regular AWS Teamer Supabase"
src="https://github.com/user-attachments/assets/86ff1fe4-6513-44a8-88e1-1c7985f4910e"
/> |
| <img width="1280" height="1323" alt="10752"
src="https://github.com/user-attachments/assets/83b1069b-a262-4068-a5e3-b7f49860fdb2"
/> | <img width="1280" height="1323" alt="31254"
src="https://github.com/user-attachments/assets/733f074d-a52a-44a6-8898-a8f3c2b68294"
/> |
| _Unable to replicate._ | <img width="1280" height="1323" alt="Regular
AWS Teamer Supabase"
src="https://github.com/user-attachments/assets/c7d4ee59-b3f0-48b0-a6d7-2202ef5c2609"
/> |

## To test

1. Open `/project/{ref}?showConnect=true&connectTab=warehouse` on a
project. Enable Warehouse on 1+ table.
2. Confirm FlightSQL is selected initially and its connection fields are
visible.
3. Select DuckDB and confirm the catalogue switch is always visible.
4. Enable catalogue access and confirm the environment variables and SQL
appear below in two numbered steps.
5. Switch back to FlightSQL and confirm the DuckDB steps disappear.
6. Set up Warehouse on a project where it is not yet enabled and confirm
DuckDB catalogue access is not enabled automatically.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a query-engine selector for FlightSQL and DuckDB connection
setups.
* Added guided DuckDB setup steps, copy-to-clipboard support, and
reveal/hide controls for secrets.
  * Added a catalog access toggle with confirmation feedback.
  * Catalog details load only when DuckDB is selected.

* **Updates**
  * Streamlined warehouse connection layouts with consistent spacing.
* Catalog access is now controlled separately from the initial warehouse
setup.
* Excluded sensitive setup details from copied prompts and added
copy-status announcements.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-14 10:49:45 +10:00
19d7233580 feat(ui-library): add headless app block for TanStack Start (#49579)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature — a new UI Library block. Stacked on #49573 (already in main)

Fixes AI-1064

## What is the new behavior?

Adds `headless-app-tanstack`: customers sign in, authorize an MCP
client, and use the product through agent tool calls. It composes the
existing Password-Based Auth, OAuth Consent, and MCP Server blocks.

- `/agents` provides a copyable connection prompt, lists OAuth
authorizations, and lets customers revoke access.
- The shared MCP runtime exposes `whoami` plus example task CRUD tools.
Tools use the caller's Supabase client, with database grants and RLS
enforcing ownership.
- A root-level `supabase/` directory supplies local Auth/OAuth
configuration, a declarative tasks schema, and Edge Function files,
including `.env.example`.
- Docs cover local setup, signing keys, migrations, environment
configuration, deployment, and extending the tools.
`/example/headless-app` previews the sign-in, consent, connect, and
connected states.

Shared block fixes make a fresh install work:

- Explicit public URL resolution fixes OAuth discovery in local Edge
Runtime when middleware runtime detection fails. Both external OAuth
access tokens and ordinary authenticated app session tokens remain
supported; embedded agents do not need an additional consent flow.
- Registry targets keep backend files outside `src/`, and generated
consumer routes omit source-only TypeScript suppressions.
- Signup respects `auth.email.enable_confirmations`; sign-in/signup
preserve the return destination. Missing consent IDs retain the existing
error state without serializing `null` into the URL.

## How to test

Use the UI Library on **staging** and follow the block pages'
instructions.

1. Open the **Headless App** block page for TanStack Start. Install it
into a fresh app and follow the setup instructions through connecting an
MCP client.
2. Sign up, open `/agents`, and use the connection prompt to authorize a
client. Call `whoami`, then create, list, update, and delete a task.
3. Confirm the client appears on `/agents`. Revoke access and verify it
disappears and token refresh fails. An existing access token can
continue working until it expires.
4. Follow the **MCP Server** block page's embedded-agent instructions
using an authenticated app session. Confirm tools work without another
OAuth consent flow and `whoami` returns `client_id: null`.
5. With a second user, confirm each user can only access their own
tasks. Check that signup behaves correctly for the configured
email-confirmation setting.
6. Check the Headless App preview states and run the installed app's
typecheck and production build.

## Validation performed

Fresh local installation and browser/SDK verification passed: 26 live
MCP/Data API checks, 10 Deno tests, and 7 connection-page component
tests. Also passed UI Library typecheck, targeted lint,
registry/Markdown builds, and fresh consumer typecheck/production build.
Both OAuth and ordinary app session authentication were exercised.

Hosted deployment and consuming the confirmation-email link were not
tested.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a TanStack Headless App example with sign-in, OAuth consent, MCP
connection, and connected-agent screens.
- Added task management tools for listing, creating, updating, and
deleting tasks through MCP.
- Added connected-agent management, including server URL and prompt
copying, refresh, and access revocation.
  - Added a new Headless App registry block and documentation.

- **Bug Fixes**
- Preserved intended destinations through sign-up, email confirmation,
and protected-route login redirects.
- Improved OAuth discovery URL handling across forwarded-host
deployments.

- **Documentation**
- Updated setup, environment, deployment, and Supabase CLI guidance for
headless apps and MCP servers.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Saxon Fletcher <SaxonF@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: repro <repro@local>
Co-authored-by: Raúl Barroso <code@raulb.dev>
2026-09-14 10:30:26 +10:00
Danny White 31046e7a7f perf(design-system): improve local dev content reload (#50069)
## What kind of change does this PR introduce?

Performance improvement for design-system doc page reload in local dev.

## What is the current behavior?

Doc pages import all compiled MDX from a single `.velite/allDocs.json`
bundle (~27MB for 105 docs). Velite rebuilds are fast, but every MDX
save forces Next to re-parse that entire file.

## What is the new behavior?

- Writes each doc's compiled MDX to `.velite/codes/{codeId}.json`;
`allDocs.json` keeps metadata only (~367KB)
- Loads doc code on demand in `lib/docs.ts` via `readFile`, with
`connection()` + dynamic `import('@/.velite')` in dev so pages re-read
fresh output after Velite rebuilds
- Skips `generateStaticParams` in dev
- Velite `output.clean` only in production
- README notes the per-doc output and adds commented getting-started
commands

Dev workflow is unchanged: `pnpm dev` still runs `velite dev` alongside
Next.js.

## To test

Local-only:

1. `cd apps/design-system && pnpm dev`
2. Open http://localhost:3003/design-system/docs/components/button
3. Edit `content/docs/components/button.mdx`, wait for `[VELITE] rebuild
finished`, refresh: change should land in ~200ms, not multi-second

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Updated design-system setup instructions for environment
configuration, installation, development, and the local browser URL.
- Added guidance for building documentation content and regenerating
components.
  - Updated alternative command examples.
  - Removed the previous “Hot reload” section.

- **Improvements**
- Improved documentation page loading during development and production
builds.
- Documentation pages now reliably display their associated code
examples.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 09:40:17 +10:00
Danny White ffc76c1e36 feat(studio): give replication destinations a brand mark (#50251)
## What kind of change does this PR introduce?

Studio UI polish. This is the first PR in the Pipelines review stack and
targets `master`. Resolves DEPR-674.

## What is the current behaviour?

Replication destinations use generic line icons across the destination
picker, pipelines list, and replication diagram. The existing shared
ClickHouse and Snowflake assets also use older artwork.

## What is the new behaviour?

Adds a reusable `DestinationLogo` treatment and uses it consistently
across Replication surfaces. BigQuery, ClickHouse, DuckLake, and
Snowflake now use their colour brand marks, while destinations without a
dedicated asset retain their existing line icon in the same frame.

The refreshed ClickHouse and Snowflake artwork replaces the canonical
shared assets, so existing consumers such as the Wrappers catalogue
receive the updated marks too.

| Light | Dark |
| --- | --- |
| <img width="572" height="804" alt="CleanShot 2026-09-11 at 16 48
42@2x"
src="https://github.com/user-attachments/assets/5c2eaef3-8714-4c0a-8bcc-7c8618abd677"
/> | <img width="552" height="788" alt="CleanShot 2026-09-11 at 16 47
30@2x"
src="https://github.com/user-attachments/assets/2aff8775-cdc1-4d6b-9f78-7b40d42e102a"
/> |

| Add Pipeline form |
| --- |
| <img width="1252" height="730" alt="CleanShot 2026-09-11 at 16 48
57@2x"
src="https://github.com/user-attachments/assets/025a158c-57ee-495e-8356-00ed1717d09d"
/> |

## To test

1. Open `/project/<ref>/database/replication` and start adding a
pipeline.
2. Confirm the BigQuery, ClickHouse, DuckLake, and Snowflake marks
appear consistently in the destination picker, pipelines list, and
replication diagram.
3. Open the ClickHouse and Snowflake entries in the Wrappers catalogue
and confirm they use the refreshed artwork.
4. Confirm Analytics Bucket retains its existing fallback icon within
the same frame.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Visual Updates**
* Destination logos now display dedicated brand marks for ClickHouse,
DuckLake, Snowflake, and BigQuery.
* Updated replication destination selectors, rows, and diagrams to use
consistent destination logos.
  * Adjusted the destination type column width for improved layout.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-14 09:31:27 +10:00
26585dd4a4 [bot] Sync from supabase/troubleshooting (#50284)
This PR syncs the latest troubleshooting guides from the
supabase/troubleshooting repository.

---------

Co-authored-by: github-docs-bot <github-docs-bot@supabase.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Miranda Limonczenko <czenko@users.noreply.github.com>
2026-09-11 15:24:43 -07:00
Miranda LimonczenkoandClaude Opus 5 c7534b9e29 docs: document the stacked PRs workflow in edit-the-docs (#50018)
Closes DOCS-1381

## Problem

The `edit-the-docs` skill describes a page edit as one continuous pass
and has no notion of output. No commits, no branches, no PRs. It ends at
edited files in the working tree.

That leaves a reviewer one diff that mixes reworded prose, moved
sections, and corrected claims, where a move can't be told from a
rewrite.

## Solution

- **Split the edit by change type:** style, structure, technical
revision, and additions. Style runs before structure, so the structure
diff reads as pure moves against already-clean prose.
- **Ship one PR, one change type per commit.** A stack of PRs is an ask,
not a default. When the edit both rewrites prose and moves sections and
runs over roughly 150 changed lines, the skill says how large the diff
is and offers the split. The requester decides, and no answer means one
PR. A stack buys clean per-type diffs, and it costs a reviewer the
whole-edit view, since no PR page shows it.
- **State the scope boundary once.** The edit is exactly the buckets
that have content. A dropped bucket is beyond the edit, and a later
request for that change type is a new request. Additions stay
author-driven, which keeps a mid-edit request from reopening an earlier
commit.
- **Scope the technical pass with a wrong-outcome test.** A claim
changes only when leaving it would hand the reader an error, a different
result than the page promises, or a fact that isn't true. An external
best-practices rule doesn't clear that gate on its own, and a missing
safeguard is an absence, so it goes to additions. Without the test, a
verification pass becomes a rewrite.
- **Add `reference/stacked-prs.md`** for the `gh stack` commands, branch
naming, restack auditing, and the one command that diffs a whole stack
at once.

### What driving the skill on a real page changed

Running it end to end on a 684-line guide, then shipping the result,
corrected five things a read-through didn't:

- **The anchor gate grepped the wrong scope.** It said
`apps/docs/content`. Five of the seven inbound anchors to that page
lived outside it, in Studio components and `apps/www`, and those are the
matches that break a Docs button in the product. The gate is now
repo-wide and is step 1 of the structure pass, because moving a section
preserves its slug and only renaming breaks it. That's what makes an
aggressive regroup safe.
- **Grouping sections by subject doesn't work.** On a page about tables
every section is about tables, so subject grouping produces one
task-named bucket that collects the background too. Classification is
now by what the reader is doing, and the skill carries the outline that
page settled on.
- **Snippet testing finds claims, it doesn't just confirm them.** One
example re-created a table an earlier example had made, which stopped
that block and left a third example referencing a table nothing ever
created. Every fence was individually correct; the sequence was not. So
the rule is to run every fence in document order, because that order is
what the reader pastes.
- **Restacking silently drops upper-branch edits.** The conflict
presents as new structure versus old content being re-added, and
resolving toward the structure takes the edit with it. `stacked-prs.md`
says to audit each branch with a grep per expected change rather than
reading the diff.
- **`build:guides-markdown` dirties a tracked file.** It writes
`apps/docs/public/markdown/manifest.json`, which the repo commits as
`[]`. Without a note the artifact lands in the next commit.

## Manual testing

1. Open `.agents/skills/edit-the-docs/SKILL.md` and read Phase 0. You
can tell whether to ship one PR or offer a stack, and what to say when
offering it, without opening the reference file.
2. Read the PR 3 section. The wrong-outcome test, the external-rule
tiebreaker, and the absences line together tell you where a
best-practices violation goes.
3. Run `npx prettier --check .agents/skills/edit-the-docs
apps/docs/CONTRIBUTING.md`. Reports all matched files use Prettier code
style.
4. Run `cat .claude/skills/edit-the-docs/reference/stacked-prs.md`. The
branch table resolves through the `.claude/skills` symlink and shows
`4+` as a pattern.
5. Run `git diff master -- .agents/skills/write-the-docs/SKILL.md`.
Reports no changes, so nothing in `write-the-docs` routes a drafter into
this workflow.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Updated guidance for editing existing documentation through distinct
style, structure, technical, and additions phases.
- Added work-sizing, scope, validation, confirmation, and handoff rules
for stacked pull requests.
- Documented support for multiple topic-based additions branches and
their merge order.
- Clarified when to use drafting versus editing workflows, including
when a draft becomes a restructure.
- Improved guidance for validating code examples, checking
repository-wide references, handling generated artifacts, and updating
pull request titles.
  - Updated contributor guidance and related documentation references.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 14:26:34 -07:00
Miranda Limonczenko 86f3a98399 fix(docs): stop reporting guide 404s to Sentry, redirect missing paths (#50279)
Closes DOCS-1388

## Problem

Expected guide-path 404s were reported to Sentry as errors. They made up
roughly 246k events and nearly all Docs volume, with 0 users impacted.

The cause is a type check that never matched.
`getGuidesMarkdownInternal` tested `error.cause instanceof
FileNotFoundError`, but `GuideModelLoader.fromFs` rethrows
`FileNotFoundError` directly and sets `cause` to the underlying `ENOENT`
error. Every missing guide path fell through to the `else` branch and
hit `Sentry.captureException`.

Nine storage section paths and `database/postgrest` also 404 in
production. They are section `url` values in the nav config with no
landing page and no redirect. They are not reachable from the sidebar,
because a nav item with children renders as an accordion button, so the
traffic is inbound links and crawlers.

## Solution

- Check the error itself as well as its cause, so expected 404s take the
quiet branch.
- Add `ignoreErrors` for `FileNotFound` to `sentry.server.config.ts`,
matching the filtering the client config already does.
- Redirect nine storage section paths to their first child page,
following the existing `storage/cdn` and `storage/uploads` pattern.
- Redirect `database/postgrest` to the Data API guide. The path has no
git history, so its 27k hits are external inbound links.
- Add the missing leading slash to the `storage/access-control`
destination. It resolves correctly today, so this is a cleanup, not a
fix.

## Redirect previews

Redirects are served by the `www` config, so the **Redirect** column
uses the www preview. The www preview cannot render `/docs/**` pages, so
each link lands on a 404 after the hop. That is expected. Check the
`Location` header, or use the **Destination** column to confirm the page
itself.

| Source | Redirect | Destination |
| :--- | :--- | :--- |
| `/docs/guides/storage/production` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/production)
|
[storage/production/scaling](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/production/scaling)
|
| `/docs/guides/storage/security` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/security)
|
[storage/security/ownership](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/security/ownership)
|
| `/docs/guides/storage/serving` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/serving)
|
[storage/serving/downloads](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/serving/downloads)
|
| `/docs/guides/storage/management` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/management)
|
[storage/management/copy-move-objects](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/management/copy-move-objects)
|
| `/docs/guides/storage/s3` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/s3)
|
[storage/s3/authentication](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/s3/authentication)
|
| `/docs/guides/storage/debugging` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/debugging)
|
[storage/debugging/logs](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/debugging/logs)
|
| `/docs/guides/storage/schema` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/schema)
|
[storage/schema/design](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/schema/design)
|
| `/docs/guides/storage/vector` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/vector)
|
[storage/vector/introduction](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/vector/introduction)
|
| `/docs/guides/storage/analytics/examples` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/analytics/examples)
|
[storage/analytics/examples/duckdb](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/analytics/examples/duckdb)
|
| `/docs/guides/database/postgrest` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/database/postgrest)
|
[api](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/api)
|
| `/docs/guides/storage/access-control` |
[test](https://zone-www-dot-com-git-docs-sentry-404s-and-guide-fa783f-supabase.vercel.app/docs/guides/storage/access-control)
|
[storage/security/access-control](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/security/access-control)
|

All eleven return `308` on the www preview with the `Location` shown in
the Destination column. Every destination returns `200`.

## Manual testing

1. Open any **Redirect** link above. The URL changes to the Destination
path, confirming the redirect fires.
2. Open any **Destination** link. The page renders.
3. Confirm the sources 404 on production today, for example
`https://supabase.com/docs/guides/storage/production`.
4. On the [docs
preview](https://docs-git-docs-sentry-404s-and-guide-redirects-supabase.vercel.app/docs/guides/storage/schema),
request a missing guide path and check the deployment logs. The line
reads `Could not read Markdown at path`, not `Error processing Markdown
file at path`. The second form is the branch that calls
`Sentry.captureException`.
2026-09-11 14:05:24 -07:00
Anthony Lio 42f1401769 fix(ui-patterns): a11y accessible names for ExpandableVideo (#50226)
## What kind of change does this PR introduce?

bug fix a11y `ExapndableVideo` 

## What is the current behavior?

`ExpandableVideo` blurred thumbnail has `alt="Video guide preview"`
sitting behind an overlay that already reads "Watch video guide" making
screen readers announcing the same thing twice

## What is the new behavior?

- adds an optional `videoTitle` prop that names the video once and feeds
both the button's `aria-label` and the player's `title`.

## Test
1. visit `/docs/guides/functions`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Enhancements**
  - Video previews in guides now display the relevant guide title.
  - Partner introduction videos now include a descriptive title.
- Video controls and embedded players provide more specific
accessibility labels when titles are available.
- Preview images without meaningful alternative text are treated as
decorative to reduce redundant screen-reader output.
- **Bug Fixes**
- Guide titles with Markdown formatting now appear as clean, readable
text in video labels.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 23:37:52 +03:00
Anthony Lio 71d652483e fix(docs): youtube iframe lack titles (#50225)
## What kind of change does this PR introduce?

a11y bug fix on youtube embed

## What is the current behavior?

YouTube iframes across guide pages have no `title` attribute, so screen
readers announce them as an unnamed frame

## What is the new behavior?

- extracts a `YouTube.tsx` ui component
- adds `<YouTube id title />` + `title` as a required prop

## Test
1. visit `/docs/guides/ai/examples/openai`


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Standardized embedded YouTube videos across guides with a consistent
video player.
  - Added descriptive titles to improve accessibility and clarity.
  - Preserved existing video content and playback behavior.
- Updated video embeds across AI, authentication, database, functions,
realtime, self-hosting, storage, and migration documentation.
- **New Features**
- Added privacy-enhanced YouTube playback for embedded documentation
videos.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 23:37:52 +03:00
Miranda Limonczenko 15a7b0ab18 docs(database): correct the dashboard_user and storage admin role descriptions (#50274)
Closes DOCS-1387

## Problem

The Postgres roles guide describes `dashboard_user` as "For running
commands via the Supabase UI." That was the original intent, not current
behavior. Dashboard queries run as `postgres` and carry a `-- source:
dashboard` comment, which the [Postgres logs troubleshooting
guide](https://supabase.com/docs/guides/troubleshooting/how-to-interpret-and-explore-the-postgres-logs-OuCIOj)
already documents. The two pages contradict each other.

Two smaller problems in the same list:

- `supabase_storage_admin` is described as an Auth middleware role,
copied from the `supabase_auth_admin` entry above it.
- Studio ships both stale strings in its own role tooltips. The docs
list and `QUERY_PERFORMANCE_ROLE_DESCRIPTION` are near-verbatim copies
of each other.

## Solution

- Replace the `dashboard_user` description with what the Dashboard
connects as instead, and point readers to the `-- source: dashboard`
comment for finding Dashboard queries in the logs.
- Attribute `supabase_storage_admin` to the Storage middleware.
- Apply both corrections to the Query Performance and Query Insights
role tooltips.

## Manual testing

1. Open the [roles guide on the deploy
preview](https://docs-git-docs-dashboard-user-role-supabase.vercel.app/docs/guides/database/postgres/roles).
2. Scroll to `dashboard_user`. It states that the Dashboard doesn't
connect as the role, and that Dashboard queries execute as `postgres`
with a `-- source: dashboard` comment.
3. Select **find them in the Postgres logs**. The Postgres logs
troubleshooting guide loads.
4. Scroll to `supabase_storage_admin`. It reads "Used by the Storage
middleware," not "Auth middleware."
5. In Studio, open **Observability > Query Performance** and hover a
`dashboard_user` or `supabase_storage_admin` value in the **Role**
column. The tooltip shows the same two corrected descriptions.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Corrected the description of the `supabase_storage_admin` role to
reference Storage middleware.
- Clarified that the Dashboard does not connect using the
`dashboard_user` role.
- Documented that Dashboard queries run as `postgres` and can be
identified in Postgres logs with a `source: dashboard` comment.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 11:57:25 -07:00
Jason Voegele 6cc6e36d58 chore(docs): add Jason Voegele to humans.txt (#50272)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds new entry into `humans.txt`.

## What is the current behavior?

Jason Voegele is not in `humans.txt`.

## What is the new behavior?

Jason Voegele _is_ in `humans.txt` :)

## Additional context

This completes the onboarding task "Add yourself to humans.txt"


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Added Jason Voegele to the team member list in the site’s public
credits file.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 14:23:18 -04:00
Pamela Chia f012dfa850 fix(www): sitemap lists all changelog slugs (#50275)
The www sitemap generator reads changelog URLs from the build-generated
RSS feed but only accepted links whose slug starts with a number, the
shape `computeChangelogEntrySlug` produces solely for entries carrying
`legacy_gh_discussion`. Every changelog entry authored since that
migration has a plain text slug and was silently missing from
`sitemap_www.xml`. I widened the link match to any non-empty slug; the
RSS builder is the only producer of that file and emits exactly one link
per item, so no other filter is needed.

I added a text-slug RSS item to the fixture-driven sitemap test and
asserted that the changelog URL list equals the RSS item list, so a
future filter that drops entries fails the suite.

**Note:** text-slug entries now pass through the same fail-the-build
pubDate check that numeric-prefixed entries already did after #50198. A
changelog entry with no `publish_date` and no date-prefixed filename
would produce an unparseable pubDate and stop the www build. The
alternative, shipping the URL without lastmod, is a one-line change. I
kept the gate because every current changelog entry carries a
date-prefixed filename, the changelog repo documents that convention,
and the build error names the entry URL.

## To test

Tested on Vercel preview:
- [x] Count `<item>` blocks in `<preview>/changelog-rss.xml`, then count
`/changelog/` locs in `<preview>/sitemap_www.xml`, expect the two counts
to match
- [x] Search the preview sitemap for `/changelog/pipelines`, expect one
`<loc>` entry with a `<lastmod>` date
- [x] Search the preview sitemap for a numeric-prefixed entry such as
`/changelog/47796-developer-update-july-2026`, expect it still present

## Linear
- fixes GROWTH-1212


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Changelog pages with text-based slugs are now correctly recognized in
the sitemap.
- Sitemap entries for these changelog pages now use their RSS
publication dates.
- RSS links are matched more reliably, ensuring all valid changelog URLs
are included.
- Invalid publication dates are rejected instead of producing incorrect
sitemap metadata.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-12 02:11:25 +08:00
Charis ea203f70df fix(studio): use configured gp3 max-IOPS ceiling (#50269)
## Summary

* GP3 IOPS calculation was hardcoded to 16,000 instead of reading from
DISK_LIMITS config
* AWS updated the real ceiling to 80,000, making the hardcoded constant
stale
* Users with large multi-TB GP3 disks were incorrectly blocked from
provisioning above 16,000 IOPS

## Test plan

- [X] Updated unit tests for `calculateMaxIopsAllowedForDiskSizeWithGp3`
now assert correct behavior: scaling linearly (100 GB → 50,000 IOPS) and
capping at new 80,000 ceiling (1000 GB → 80,000 IOPS)
- [X] All 26 tests in DiskManagement.test.ts pass locally
- [X] Manually verify Infrastructure Settings > Disk IOPS field no
longer blocks GP3 disks above 16,000 IOPS up to 80,000

Closes
[FE-4379](https://linear.app/supabase/issue/FE-4379/update-iops-limits-for-new-aws-disk-capacity)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Updated GP3 disk performance calculations to support up to 80,000
IOPS.
- Disk sizes below the minimum threshold continue to receive the correct
3,000 IOPS floor.
- Larger disks now scale linearly until reaching the updated maximum
IOPS limit.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 10:57:29 -04:00
AnaandAna ed4162e055 feat(www): add Select Hackathon day-of go page (#50243)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Adds a new `/go` page for the Select Hackathon (Oct 3, 2026, YC) at
`supabase.com/go/select-2026/hackathon`
- New page definition `apps/www/_go/events/select-2026/hackathon.tsx`
(`lead-gen` template)
- Registers it in the go page registry `apps/www/_go/index.tsx`

## What is the current behavior?

There is no day-of one-pager for the Select Hackathon on the site.

## What is the new behavior?

- A day-of one-pager rendered as a `selecthackathon2026.sql` code-block
section (run of show, wifi, how to submit, prizes)
- `noIndex` by default (day-of page, not for search)
- Removable after Select 2026 (tagged in the registry alongside the
other `select-2026` go pages)

## Additional context

`hackathon.supabase.com` is handled at DNS/Vercel and can point at this
path. wifi network/password and help-desk location are still
placeholders pending final details.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added a dedicated Supabase Select Hackathon 2026 schedule page.
* Includes event timing, Wi‑Fi details, submission instructions, prize
information, and mentor support guidance.
* Updated the run of show to list sponsor arrival at 9:00 AM and doors
opening/check-in at 9:15 AM.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ana <ana1337x@users.noreply.github.com>
2026-09-11 10:45:56 -04:00
Anthony Lio 3de0e3a614 fix(docs): a11y alt text on Colab badge (#50222)
## What kind of change does this PR introduce?

a11y fix

## What is the current behavior?

Colab badge image is missing alt attribute leaving both image and the
link unnamed _ screen reader users have no way to tell what the link
does

## What is the new behavior?

- adds `alt="Open in Colab"`, matching the text rendered inside the SVG
so voice control users can activate it by its visible label

## Test
1. visit
[/docs/guides/ai/google-colab](https://supabase.com/docs/guides/ai/google-colab)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Improved accessibility across AI guides and quickstarts by adding
descriptive alternative text to “Open in Colab” badge images.
- Updated Google Colab, LlamaIndex, face similarity, hello world, and
text deduplication documentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 17:42:27 +03:00
Anthony Lio 2e861b5415 fix(docs): guides table overflow (#50221)
## What kind of change does this PR introduce?

bug fix of table usage within guides

## What is the current behavior?

table markup is used within the observability guide causing overflow of
the content

## What is the new behavior?

favors table component usage within mdx guide to fix the overflow and
enable scroll

| state | preview |
| -------|------|
| before | <img width="1171" height="668" alt="image"
src="https://github.com/user-attachments/assets/bdbb905e-0ea9-4cde-b20b-84b4ef9a4137"
/> |
| after | <img width="1171" height="668" alt="image"
src="https://github.com/user-attachments/assets/9e062222-1dad-49da-bdbe-616d89703301"
/> |

## Test
1. visit
[/docs/guides/observability/log-field-reference](https://supabase.com/docs/guides/observability/log-field-reference?queryGroups=source&source=edge_logs)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
  - Improved table rendering in the log field reference documentation.
- Updated documentation tables to use the shared table presentation for
a more consistent layout.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 17:40:53 +03:00
Jordi Enric 15f80e5f9d fix(docs): restore browser crash reporting to sentry (#50231)
## Problem

Docs discarded every browser exception because its third-party
stack-frame filter never returned a value from its predicate. Errors
captured by the page error boundaries were discarded too.

## Fix

Use Studio's Sentry SDK tagging approach with a matching webpack
application key, retaining page-crashing exceptions even when their
frames are classified as third-party. Preserve consent and platform
checks, and pass the source-map upload token through Turbo.

## How to test

- Run `pnpm --filter docs run test:local:unwatch
lib/sentry-client.test.ts` with the documented local Supabase
prerequisites satisfied. Eleven filter regression checks passed locally
using an isolated Vitest configuration.
- On a production-mode preview with the docs DSN configured, accept
telemetry consent and trigger a temporary client render error. Verify
that the docs Sentry project receives it with `globalErrorBoundary:
true` and readable stack traces.
- Verify that third-party-only errors are filtered and declining consent
suppresses browser reports.

Prettier, focused filter/test TypeScript checks, and an in-memory
transport check using the real Sentry SDK passed. Full app typecheck and
lint are blocked locally by existing dependency/generated-file drift;
the standard docs suite requires unavailable Docker access. Live Sentry
ingestion and source-map uploads still need deployment verification.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved error monitoring to distinguish documentation app boundary
crashes from other exceptions.
- Reduced noise in error reports by filtering third-party-only errors
and respecting platform and consent settings.
- Preserved reporting for first-party failures and critical application
crashes.

- **Chores**
- Improved Sentry build and deployment configuration for more consistent
error tracking.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 12:48:33 +02:00
Aditya Maruvada 74daa990bc Update humans.txt with new employee (Aditya) (#50212)
Add Aditya Maruvada to humans.txt

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?
Add new employee (Aditya) to the list.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Aditya Maruvada to the team member list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 03:07:17 -07:00
Pamela Chia e315fbcb53 feat(www): emit sitemap lastmod from content dates (#50198)
I added content dates to `sitemap_www.xml` and `dateModified` to blog
JSON-LD so crawlers can compare freshness with page metadata. Both use
`updated` when present, otherwise the publication date.

**Changed:**
- **Consistent dates:** I use the same frontmatter parser for the blog
page and sitemap. It preserves authored dates across quoting and
timezones and rejects JavaScript frontmatter.
- **Invalid dates stop the build:** I reject impossible calendar days,
out-of-range times and offsets, malformed dates, and `updated` before
publication. Content changes run the generator in CI.
- **Authoring:** I documented optional `updated` for substantive
revisions. Events, static pages, and `/evals` omit `<lastmod>`.

**Note:** Changelog dates come from RSS. Existing sitemap omissions for
nonnumeric changelog slugs (GROWTH-1212) and app-router pages
(GROWTH-1214) remain separate.

## To test

On the preview:
- [x] Open `/sitemap_www.xml`: blog, alternatives, customer stories, and
included changelog entries should carry `YYYY-MM-DD` lastmod values.
Verified on the 2092513 preview: all 425 blog, 3 alternatives, 43
customer story, and 207 changelog entries carry a `YYYY-MM-DD` lastmod,
zero malformed values. Production currently emits no lastmod at all.
- [x] Inspect `/blog/supabase-is-now-available-in-gemini-enterprise`:
BlogPosting `dateModified` should be `2026-09-09`, matching its sitemap
entry. Verified: one BlogPosting block, `datePublished` and
`dateModified` both `2026-09-09`, sitemap lastmod `2026-09-09`.
- [x] Find the `/company` and event entries in the sitemap: neither
should carry lastmod. Verified: `/company` and all 13 `/events/` entries
have no lastmod.
- [x] Added: `/evals` and the `/changelog` index carry no lastmod
either.
- [x] Added: the blog page renders with no new console errors. The only
console error is a `/docs?_rsc=` prefetch 404: the preview host serves
404 for `/docs` itself, unrelated to this change.

## Linear
- fixes GROWTH-1206


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Blog posts now support optional updated dates for substantive
revisions.
- Sitemap entries include accurate modification dates for blog,
alternatives, customers, and changelog content.
  - Blog structured data now includes the post’s modification date.

- **Bug Fixes**
- Improved validation prevents invalid or inconsistent content dates
from generating incorrect sitemap data.
- Changelog sitemap links are deduplicated and assigned their published
dates.

- **Documentation**
- Added guidance for specifying publication and update dates in blog
post metadata.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 17:20:53 +08:00
Saxon Fletcher 66c6da82fe fix(studio): refine Explorer query surfaces and tab styling (#50249)
Explorer query surfaces now use `bg-card` in light mode and `bg-muted`
in dark mode, including embedded notebook/chat queries and query tab
toolbars. Notebook Run buttons match query tabs, with `ml-1` spacing on
both. Fix doubled tab separators by applying the leading border only to
the first tab.

### How to test

1. Open Explorer with multiple query, notebook, and chat tabs. Switch,
reorder, and close tabs; confirm each separator stays one pixel wide.
2. In light and dark mode, inspect query tabs and embedded notebook/chat
queries: backgrounds should be card in light mode and muted in dark
mode, including their toolbars.
3. Compare notebook and query Run buttons: matching default styling and
spacing. Run a read-only query such as `select 1` in both and check
loading and results.
4. Check SQL Editor and Table Editor tab separators, since the tab
component is shared.

Validation: Prettier passed for all four changed files. Manual checks
above have not been run.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Style**
- Refined notebook and query run button styling, including spacing and
tooltip placement.
- Improved query editor panel backgrounds across light and dark themes.
  - Updated tab border rendering for more consistent visual alignment.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 16:53:04 +08:00
Han QiaoandClaude 85573164f4 docs: document that branches are secure by default (#50193)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

The branching docs don't mention that new branches are created without
default privileges on the `public` schema.

Linear: BRA-189

## What is the new behavior?

- Working with branches: new "Default privileges on branches" section
covering the keep-enabled path (initial migration grants) and the revoke
path (new migration).
- Troubleshooting: new entry for `42501` permission denied errors on a
new branch.

## Additional context

None.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added troubleshooting guidance for permission-denied errors affecting
tables or functions on new branches.
- Explained how migrations can restore intended default privileges on
the `public` schema.
- Added workflows for retaining or revoking default privileges,
including dashboard configuration, migration-history repair, and
access-management steps.
- Added examples for granting or revoking access to sequences,
functions, and tables.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-11 16:27:37 +08:00
Pamela Chia c6a1c2052c feat(www): cross-list openapi and mcp endpoint (#50180)
`/.well-known/ard.json` advertises the Management API OpenAPI spec and
the MCP server, but `/llms.txt` listed neither and
`/.well-known/api-catalog` listed only the Management API. I added both
resources to the two surfaces that were missing them, so an agent finds
the same spec and endpoint whichever discovery file it reads first.

**Changed:**
- **llms.txt gains an `## API and agent resources` section**: two
described links, the same-origin `/openapi.json` spec and
`https://mcp.supabase.com/mcp`, from a small list in
`lib/agent-resources.ts`. A named heading rather than `## Optional`,
since llmstxt.org defines Optional as links an agent may skip. The
descriptions restate ard.json's on purpose; ard.json is curated to the
ARD schema and stays untouched.
- **api-catalog lists the MCP endpoint**: added as a catalog `item` plus
its own linkset member carrying `service-doc` (the MCP guide) and
`service-meta` (the OAuth protected-resource metadata the endpoint's 401
response already points at).
- **Tests cover what the two files advertise**: `ard-catalog.test.ts`
now parses api-catalog, checks that its `item` list and its anchored
members agree, and runs every same-origin URL from api-catalog and the
llms.txt resource list through the existing dead-URL resolver (public
file, app route, rewrite, or docs guide). The www tests workflow now
checks out `apps/docs/content/guides` (the directory the llms.txt route
already reads at runtime) and runs on changes to it, so moving a guide
that a catalog links to fails that PR rather than the next www one.

**Note:** `/openapi.json` is an external rewrite served uncached on
every request (338 KB). I tried `Cache-Control` and then the documented
`x-vercel-enable-rewrite-caching` + `CDN-Cache-Control` pair on that
path; the preview kept returning `x-vercel-cache: MISS`, so both are
reverted. Caching the alias is a separate change.

## To test

Tested on Vercel preview:
- [x] `curl -s <preview>/llms.txt | tail -5`: expect an `## API and
agent resources` heading followed by the OpenAPI spec link and the MCP
server link; the diff against production `llms.txt` is those appended
lines only
- [x] `curl -s <preview>/.well-known/api-catalog | jq '.linkset[2]'`:
expect a member anchored at `https://mcp.supabase.com/mcp` with
`service-doc` and `service-meta`, served as `application/linkset+json`

## Linear
- fixes GROWTH-1207


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added API and agent resource links to `llms.txt`, including the
Management API specification and MCP server.
- Added the Supabase MCP server to the API catalog with service
documentation and metadata links.

- **Tests**
- Expanded catalog validation to cover API catalog entries, agent
resources, and documentation guide links.
  - Updated pull request checks to run when guide content changes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 16:12:44 +08:00
4f10a55983 docs: add troubleshooting guide for password auth failures after rotation (#50122)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update (new troubleshooting entry + cross-links).

## What is the current behavior?

There's no public troubleshooting entry for a transient `password
authentication failed` (`28P01`) error through the Shared Pooler
(Supavisor) right after a database password rotation. The closest
existing entry only covers the IP-lockout circuit-breaker case (`FATAL:
Circuit breaker open`), and the generic FAQ answer for "FATAL: Password
authentication failed" in `connecting-to-postgres.mdx` reads as "your
credentials are simply wrong," with no mention that this is expected
right after a legitimate rotation.

## What is the new behavior?

- New entry:
`supavisor-error-password-authentication-failed-after-password-rotation.mdx`
— explains this is expected, by-design pooler-cache behavior (not a
bug), scopes it to SCRAM/password auth (not JIT), and walks through
confirming the new password via a direct connection before contacting
support.
- Cross-links added from the existing circuit-breaker entry, the "How do
I reset my Supabase database password?" entry, and the FAQ in
`connecting-to-postgres.mdx`.

## Additional context

Prettier check passes on all 4 touched files. `lint:mdx`
(`supa-mdx-lint`) could not be run locally due to a pre-existing,
unrelated native-module issue (`node-pty` missing its compiled binary
for this platform) — expected to run in CI.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation

* Added troubleshooting guidance for `28P01` password authentication
failures after database password rotation.
* Clarified Shared Pooler credential-refresh behavior, affected
connection patterns, the built-in `postgres` role, and unaffected JIT
access-token connections.
* Added steps to verify credentials, retry connections, handle rate
limits, and avoid repeated rotations.
* Added guidance for updating credentials across live application
instances and cross-references between related troubleshooting guides.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Changed docs
* the new guide:
[docs-git-docs-supavisor-password-rotation-troub-026280-supab/…/supavisor-error-password-authentication-failed-after-password-rotation](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/supavisor-error-password-authentication-failed-after-password-rotation)
* mention the new guide + info on auth_error Circuit Breaker
[docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/…/fatal-password-authentication-failed](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/fatal-password-authentication-failed)
* mention the new guide:
[docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/…/how-do-i-reset-my-supabase-database-password…](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/how-do-i-reset-my-supabase-database-password-oTs5sB)
* mention of the new guide:
[docs-git-docs-supavisor-password-rotation-troub-026280-supabase.ver/…/supavisor-error-circuit-breaker-open-after-password-rotation…](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/supavisor-error-circuit-breaker-open-after-password-rotation-0fdb72)

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Nik Richers <nrichers@gmail.com>
Co-authored-by: felipe stival <14948182+v0idpwn@users.noreply.github.com>
Co-authored-by: Codesmith <codesmith-bot@users.noreply.github.com>
2026-09-11 10:03:14 +02:00
Joshen Lim 2bd67ef91b Chore/team members rendering optimizations (#50255)
## Context

Follow up to https://github.com/supabase/supabase/pull/50238 which
addressed some rendering issues for organization team settings. The
changes in 50238 improved the performance of searching members, but
there's still a bit of client side latency. There shouldn't be any
functional changes from the changes here, just refactoring

- `MemberRow` wrapped in `memo` so unaffected rows skip re-rendering
- Memoized a number of variables in `MembersView` so they only recompute
when filtered members/user/role actually change, not on every render
- In `MemberRow`, replaced per-role `.find()` chains with Map-based
lookups and memoized the whole per-role derivation
- Fixed a mutating in-place `.sort()` in `organization-roles-query.ts`'s
select that was silently rewriting the shared RQ cache entry
- Added `TeamSettingsDataContext` + reduce prop drilling for `MemberRow`
+ `MemberActions`
- Removed an any cast on member.metadata?.origin in MemberRow, replaced
with explicit Boolean(...) coercion

Organization team settings page should work as per status quo including
searching. The searching was the main issue so these are hoping to
alleviate the performance issues. It's quite hard to test unless you've
got an organization with a 150 + members though (< 100 you don't really
see any issues).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- Improved the Team Settings member list for more consistent role and
project information.
- Member role links now provide more direct navigation to associated
projects.
  - Improved performance when displaying and sorting team members.
  - Added an accessible label to the member actions menu.
- **Bug Fixes**
- Prevented organization role data from being unexpectedly changed while
it is sorted.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-11 15:11:07 +08:00
Danny White 476d4a5851 refactor(ui): drop redundant Button variant="default" props (#50161)
## What kind of change does this PR introduce?

Mechanical cleanup on top of the Button default-variant change (#50160).

## What is the current behavior?

Many callsites still pass `variant="default"` even though that is now
the component default.

## What is the new behavior?

Removes redundant static `variant="default"` from legacy `Button` and
`ButtonTooltip` callsites. Keeps explicit defaults where they document
the API:

- `button-default.tsx` and `button-sizes.tsx` demos
- `DocsButton`, which pins neutral styling at the wrapper boundary

## To test

Studio:

- [Auth → Rate
Limits](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/auth/rate-limits):
dirty the form so Cancel appears; Cancel stays neutral, Save stays green
- [Project Settings → API
Keys](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/settings/api-keys):
`DocsButton` in the header actions stays neutral

Design system:

- [Design system →
Button](https://design-system-git-dnywh-dc924ac1-supabase.vercel.app/design-system/docs/components/button):
`button-default` / `button-sizes` still show explicit default styling;
Primary (green) is restricted to the Primary section (and `asChild`)

WWW:

- [www → Brand
assets](https://zone-www-dot-com-git-dnywh-dc924ac1-supabase.vercel.app/brand-assets):
Download logo kit / Download button kit stay neutral
2026-09-11 17:05:26 +10:00