mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
2d4e87f579c27d4b1fc86106fd33eed22f805ec8
36309
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
2d4e87f579 |
studio: SafeSql for reports, query performance, privileges (4/7) (#45998)
## Summary Part 4 of the SafeSql migration stack ([#45897](https://github.com/supabase/supabase/pull/45897), [#45903](https://github.com/supabase/supabase/pull/45903), [#45990](https://github.com/supabase/supabase/pull/45990), this PR, …). Converts the remaining reports, query performance, observability, index advisor, and privileges call sites of `executeSql` to produce `SafeSqlFragment` values. The `ReportQuery.sql` field flips from `string` to `SafeSqlFragment`, which cascades into every consumer — landed here atomically so each branch typechecks cleanly. Touched areas: - `interfaces/Reports/*` — `ReportQuery.sql: SafeSqlFragment`, plus all report definitions/utilities updated - `interfaces/QueryPerformance/useQueryPerformanceQuery.ts` - `interfaces/Database/IndexAdvisor/*` and `data/database/{table-index-advisor,retrieve-index-advisor-result}-query.ts` - `data/privileges/{table-api-access,update-exposed-entities}-mutation.ts` - `interfaces/Storage/StoragePolicies/StoragePolicies.tsx` - `hooks/analytics/useDbQuery.tsx` - `Observability/useSlowQueriesCount.ts` + `useQueryInsightsIssues.utils.test.ts` ## Test plan - [x] `pnpm typecheck` passes - [x] `useQueryInsightsIssues.utils.test.ts` passes - [x] Dev-server smoke test: reports pages, query performance, index advisor, storage policies <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Reworked SQL construction and typings across reporting, query performance, index advisor, and privilege features to use safer SQL fragments, improving reliability and preventing query composition issues. * **Types** * Reporting query types were split to distinguish database vs. logs queries, enabling correct handling and validation. * **Docs/Utils** * Added a helper to consistently generate logs SQL for report hooks. * **Tests** * Updated tests to exercise the new SQL-building API. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45998) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e925385415 |
studio,pg-meta: SafeSql for functions/policies/triggers (3/7) (#45990)
## Summary
Third PR in the SafeSql migration stack. Flips the input/output types on
`pgMeta.functions/policies/triggers`'s `.create/.update/.remove` to use
`SafeSqlFragment`, and updates every Studio consumer atomically.
### pg-meta
- `pgMeta.functions/policies/triggers` `.create/.update/.remove` now
return `{ sql: SafeSqlFragment }` and accept branded input parameters
(`PGFunctionCreate`, `PGSavedFunction`, `PolicyCreate/UpdateParams`,
`PGTriggerCreate` with branded condition).
- `QueryModifier.toSql()` returns `SafeSqlFragment`.
### Studio consumers updated to the new branded API
- `data/database-functions/*` (query, create/update/delete mutations)
- `data/database-policies/*` (create, update mutations)
- `data/database-triggers/database-trigger-update-transaction-mutation`
- `components/Database/Triggers/TriggerSheet`
- `components/Database/Functions/CreateFunction`
- `components/Auth/Policies/PolicyEditorPanel`
These consumers land atomically with the pg-meta API change because the
input-type strictness flip (string → `SafeSqlFragment` for SQL fields)
forces every call site to update together.
## Stack
- 1/7: #45897 (merged)
- 2/7: #45903 (merged)
- 3/7: this PR
- 4/7–7/7: upcoming
## Test plan
- [x] `pnpm typecheck` passes
- [x] `pnpm --filter @supabase/pg-meta test` passes
- [x] Dev-server smoke test: function editor, policy editor, trigger
sheet
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Strengthened SQL safety across policy, function, and trigger workflows
by converting raw SQL strings to typed SQL fragments and safer
composition
* Updated editor behavior to handle policy conditions/checks as typed
SQL fragments with improved initialization and template handling
* Aligned query and modifier interfaces to return typed SQL fragments
for safer composition
* **Tests**
* Updated tests to use typed SQL fragments and synchronous builders
where applicable
<!-- review_stack_entry_start -->
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45990)
<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
4d9879d62d |
chore: remove slider shadcn suffix (#45992)
## Problem The `_Shadcn_` suffix isn't needed anymore on slider components ## Solution - Remove the `_Shadcn_` suffix - Simplify UI package exports <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved internal component export structure and import organization for better code maintainability. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45992) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
aedd91a9bb |
chore: remove <HoverCard> _Shadcn_ suffix (#45987)
## Problem The `_Shadcn_` suffix isn't needed anymore on `HoverCard` components ## Solution Remove it. No other changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized hover-card component usage across the apps and design system for consistent behavior and markup. * No user-facing changes — hover previews, tooltips, snippet/template previews, and code hover panels retain the same appearance and interactions. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45987) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
426f150e02 |
chore: remove <Breadcrumb> _Shadcn_ suffix (#45984)
## Problem The `_Shadcn_` suffix isn't needed anymore on breadcrumb components ## Solution Remove it. No other changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized breadcrumb component exports across the codebase by removing internal aliasing and using direct component exports. No UI, behavior, or public API changes; end-user experience unchanged. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45984) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5d97339d41 |
chore: remove <Select> _Shadcn_ suffix (#45988)
## Problem The `_Shadcn_` suffix isn't needed anymore on `Select` components ## Solution Remove it. No other changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Updated internal component architecture to standardize and simplify the codebase. These changes improve code maintainability and consistency across the application without affecting existing functionality or user experience. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45988) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8d647f3d05 |
fix: incorrect react 19 type change (#45991)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Enhanced type safety in internal function handling to improve code stability and maintainability. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45991) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b9fe7eabe5 |
fix(www): fix contributors section overflow on mobile in careers page (#45923)
## Problem The contributors section on /careers has a fixed `w-[1080px]` container with no max-width constraint. On mobile viewports this causes horizontal overflow and breaks the page layout. ## Fix Added `max-w-full overflow-hidden` to the contributors wrapper so it caps at 1080px on large screens and fits within the viewport on smaller ones. ## File changed `apps/www/pages/careers.tsx` ## Screenshots | Before | After | |--------|-------| | <img src="https://github.com/user-attachments/assets/71c2ac3b-e4b8-49cf-801b-90ecb8b41811" width="300" /> | <img src="https://github.com/user-attachments/assets/594465f4-2ca7-4858-89ef-dee71eb37415" width="300" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Bug Fixes * Fixed overflow in the contributors section to prevent content spilling and ensure background clipping. * Improved layout stability so contributor avatars and content render consistently across screen sizes. * Resolved visual glitch that could cause unintended scroll or layout shifts within the contributors area. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45923) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
86a3f8b03d |
chore: upgrade to react-19 (#45886)
- Most changes are related to either types or `useRef` usages (it now requires an initial value). - also updated `vaul` to its latest version and haven't noticed any change ([design-system demo](https://design-system-git-react-19-supabase.vercel.app/design-system/docs/components/drawer)) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Upgraded workspace to React 19. * **Bug Fixes** * Improved null-safety and ref handling across editors, UI components, shortcuts, and markdown/image rendering to reduce runtime errors. * Safer event/timeout/interval cleanup and more robust command/context handling. * **Chores** * Bumped vaul dependency versions. * **Documentation** * Type and TypeScript accuracy improvements for clearer developer feedback. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45886) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bffe49bb1d |
feat(edge-functions): keyboard shortcuts on overview, detail, and test sheet (#45947)
Closes [FE-3245](https://linear.app/supabase/issue/FE-3245/add-keyboard-shortcuts-to-edge-functions-pages). Adds keyboard shortcuts across the Edge Functions surface, mirroring the patterns already in place for Database / Auth / Storage. ## Summary Three layers of new shortcuts, plus one quality-of-life fix on the existing search input: ### 1. Edge Functions list page (`/project/:ref/functions`) | Key | Action | |---|---| | `Shift+F` | Focus the search input | | `Shift+N` | Route to `/functions/new` (deploy a new function) | | `F` then `C` | Clear search filter | | `Shift+R` | Refresh the functions list (new toolbar button) | | `S` then `C` | Reset sort to `name:asc` | | `Esc` (in search) | Clears value, then blurs on a second press (`onSearchInputEscape`) | ### 2. Edge Functions section nav (active anywhere under `/functions/*`) | Key | Action | |---|---| | `F` then `O` | Functions overview | | `F` then `K` | Secrets | Wired through `EdgeFunctionsProductMenu` items via `shortcutId`, registered by `<ProductMenuShortcuts />` mounted in `EdgeFunctionsLayout`. ### 3. Per-function detail (active anywhere under `/functions/:slug/*`) | Key | Action | |---|---| | `1` | Overview | | `2` | Invocations | | `3` | Logs | | `4` | Code | | `5` | Settings | | `Shift+T` | Open the Test sheet | | `Shift+D` | Toggle the Download popover | | `Shift+C` | Copy the function URL (with toast) | ### 4. Test sheet (active when `EdgeFunctionTesterSheet` is open) | Key | Action | |---|---| | `Mod+Enter` | Send Request — first binding for this; mirrors `SQL_EDITOR_RUN` semantics | ### 5. New per-function Overview (`edgeFunctionsOverview` flag) | Key | Action | |---|---| | `I` then `M` | 15 min | | `I` then `H` | 1 hour | | `I` then `T` | 3 hours | | `I` then `D` | 1 day | | `Shift+R` | Refresh combined stats query | | `O` then `L` | Open Logs (or Invocations if unified-logs preview is off) | `ShortcutTooltip` added to the most prominent buttons (search, refresh, copy URL, download, test, send request). Interval/refresh/open-logs on the overview are registered without inline tooltips but remain discoverable via `Cmd+K` and the shortcut reference sheet (`Mod+/`). ## Implementation notes - New reference group `NAVIGATION_FUNCTION_DETAIL` ("Function Page Navigation") added to keep the reference sheet grouped sensibly. - Three new registry files: `functions-list.ts`, `functions-nav.ts`, `functions-detail.ts`, `functions-detail-nav.ts`, `functions-overview.ts`. - Three new hooks: `useFunctionsListShortcuts`, `useFunctionsDetailShortcuts`, `useEdgeFunctionOverviewShortcuts`. - `EdgeFunctionsLayout` refactored to share a single `useGenerateEdgeFunctionsMenu` hook between `<ProductMenu>` and `<ProductMenuShortcuts>` (matches the AuthLayout / DatabaseLayout pattern). - Download popover hoisted to controlled state so `Shift+D` can toggle it. ## Test plan ### Functions list page - [x] On `/project/:ref/functions`, press `Shift+F` — search input gains focus and value is selected - [x] Type in the search → press `Esc` → value clears (focus retained). Press `Esc` again → blurs - [x] Press `Shift+N` → routes to `/functions/new` - [x] With a non-default sort, press `S` then `C` → sort resets to `name:asc`. Confirm shortcut is disabled when already at default - [x] Press `Shift+R` → list refetches; loading indicator appears on the new Refresh button - [x] Press `F` then `C` → search clears ### Section nav (anywhere under `/functions/*`) - [x] From any page under `/functions/*`, press `F` then `O` → navigates to Functions list - [x] Press `F` then `K` → navigates to Secrets - [x] Verify the chord doesn't fire while typing in an input ### Per-function detail (any sub-page) - [x] On any function detail tab, press `1`/`2`/`3`/`4`/`5` → navigates to Overview / Invocations / Logs / Code / Settings respectively (digits 2 and 3 only on platform builds) - [x] Press `Shift+T` → Test sheet opens. Press escape to close - [x] Press `Shift+D` → Download popover opens; press escape to close - [x] Press `Shift+C` → URL copied + toast appears - [x] Hover the URL copy button, Download button, Test button — `ShortcutTooltip` shows the chord ### Test sheet - [x] Open the Test sheet (button or `Shift+T`) - [x] Without focusing anything, press `Mod+Enter` → request fires - [x] With focus inside the body editor / a header input, press `Mod+Enter` → request still fires (`Mod+`-keys bypass input guard) - [x] While `isPending`, `Mod+Enter` is a no-op (shortcut disabled) - [x] Hover Send Request → tooltip shows `Mod+Enter` ### New overview (with `edgeFunctionsOverview` flag enabled) - [x] Press `I` then `M` / `H` / `T` / `D` → interval segmented buttons highlight accordingly and chart re-fetches - [x] Press `Shift+R` → stats refetch - [x] Press `O` then `L` → routes to logs (or invocations when unified-logs preview is off) ### Regression checks - [x] `Cmd+/` opens the reference sheet and the new "Edge Functions Navigation" and "Function Page Navigation" groups render - [x] `Cmd+K` command palette includes the new shortcut entries under "Shortcuts" - [x] On the list page, the existing X button on the search still clears value - [x] Esc handler does not interfere with closing modals/popovers elsewhere on the page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added comprehensive keyboard shortcuts for Edge Functions (navigation, tab switching, chart intervals, create/refresh, test/send request, download, copy URL) with visible shortcut hints on relevant buttons and inputs. * **Refactor** * Layouts and product menu updated to surface and wire these shortcuts across the UI. * **Tests** * Shortcut reference tests updated to include Edge Functions groups and entries. * **Documentation** * Shortcut reference sheet labels updated to include Edge Functions sections. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45947) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
8c6d5036ea |
chore: remove <Label> _Shadcn_ suffix (#45986)
## Problem The `_Shadcn_` suffix isn't needed anymore on label component ## Solution Remove it. No other changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized Label usage across the codebase by removing the legacy alias and using the direct Label export from the UI package consistently. * **Documentation** * Updated component examples and docs to use the standardized Label component in usage snippets and demos. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45986) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
590ec2bbd4 |
fix: improve accessibility for icon buttons (#45981)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Improving accessibility for icon-only buttons ## What is the current behavior? Icon-only buttons do not have explicit accessible names for screen readers. ## What is the new behavior? All icon-only buttons now have explicit accessible names using visually hidden text (sr-only), ensuring proper screen reader support. ## Additional context Tooltip text is preserved for visual users. No visual changes were introduced. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Added/updated aria-labels across refresh buttons, sidebar controls, dropdown triggers, and navigation links for better accessibility. * Added conditional aria-labels for the “Create with Assistant” control to reflect permission states. * Improved screen-reader descriptions for sidebar toggle and other stateful controls to better convey status changes. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45981) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1591e41351 |
fix: storage shortcuts (#45978)
## TL;DR fixes a few storage shortcut edge cases ## ref: - closes https://github.com/supabase/supabase/issues/45977 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * The storage bucket creation shortcut now respects user permissions and will only be available when allowed. * Storage file deletion shortcut now requires appropriate write permission before it can be used on selections. * Refresh shortcut in the storage explorer is always available regardless of selection state. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45978) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d0fd4478c0 |
chore: migrate Popover usages to Shadcn components (#45980)
## Problem We have multiple Popover components ## Solution - [x] migrate Popover usages to Shadcn components - Migrated JSON and text editor in the `TableEditor` (inline row edition) - Migrated the template popover in the logs explorer templates page - [x] remove `_Shadcn_` suffix from Popover components (renaming + prettier) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Unified popover implementation across the app and design system; dropdowns, calendars, menus and tooltips now use a consistent popover API with no visual or interaction changes. * **Chores** * Minor prop typing update for the logs date-picker to align with the consolidated popover content type. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45980) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4e86c39ea1 |
chore: remove <ContextMenu> _Shadcn_ suffix (#45971)
## Problem The `_Shadcn_` suffix isn't needed anymore on `<ContextMenu_Shadcn_>` and related components ## Solution Remove it. No other changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Replaced legacy context-menu component variants with the unified UI context-menu components across the app for consistent rendering and imports; behavior and menu content remain unchanged. * **Tests** * Updated a test mock to track the unified context-menu component mount count. * **Chores** * Simplified UI package re-exports to expose the canonical context-menu symbols. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45971) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
69acd647e1 |
chore: remove fields _Shadcn_ suffix (#45972)
## Problem The `_Shadcn_` suffix isn't needed anymore on fields components ## Solution Remove it. No other changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Refactor** * Streamlined internal component export patterns and standardized import references to improve code organization and maintainability. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45972) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0713a1efc1 |
chore: remove shadcn suffix for Input, Textarea, Alert and Collapsible (#45867)
## Problem Now that we migrated old components to their new shadcn alternatives, we don't need the `_Shadcn_` suffix anymore. ## Solution Remove it <img width="659" height="609" alt="image" src="https://github.com/user-attachments/assets/2d7271a9-066a-4dcc-92fe-729b106d2c2f" /> |
||
|
|
5bf9948bb0 |
docs: fix embeddings (#45968)
- closes https://github.com/supabase/supabase/issues/45954 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated guidance on embedding job batching to reflect improved handling of edge cases. * **Bug Fixes** * Fixed handling of scenarios where no embedding job batches exist, ensuring consistent behavior in queue processing. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45968) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
95a4243f0e | chore(self-hosted): update nginx image in the override (#45979) | ||
|
|
4195b9af27 |
chore: update leaked password button in attack protection (#45975)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Frontend improvement ## What is the current behavior? "Configure email provider" button in the Authentication > Attack Protection: the title doesn't change, only the label on the left depending on whether it's enabled or disabled. <img width="1512" height="148" alt="CleanShot 2026-05-15 at 12 15 57@2x" src="https://github.com/user-attachments/assets/b2069333-6f1a-4503-9b3b-d75c005e4522" /> ## What is the new behavior? "Configure in email provider" - to clarify that this feature is managed in the email provider settings, and not refer to the whole email provider setup. <img width="1668" height="172" alt="CleanShot 2026-05-15 at 12 19 10@2x" src="https://github.com/user-attachments/assets/35fd5b35-8b31-4912-875d-cc9fc7b1968e" /> ## Additional context Relevant ticket where the button title was confusing for the customer: https://supabase.frontapp.com/open/cnv_1mtka5ni?key=-r6o8zPz-3XzuiQ7eh5FfCZBjTuKg78n |
||
|
|
640869da47 |
chore: Clean up remaining Tailwind code (#45925)
This PR finishes the Tailwind migration by doing some minor fixes: - Remove `@radix-ui/colors` and inline the color values into the color definitions. The default Tailwind colors are unset and replaced by our own color set (both in light and dark variants). - Remove the `colorA` colors because they were used with alpha values. They were unused and Tailwind v4 supports alpha values natively. - Replace the `hit-area` JS config with the original CSS config from https://bazza.dev/craft/2026/hit-area. The original config was migrated to JS config to work with Tailwind v3. Now that we're on v4, we can just use the source format. - Remove the `motion-safe-transition` plugin since it's now [supported natively by Tailwind](https://tailwindcss.com/docs/transition-duration#supporting-reduced-motion) - Replace `tailwindcss-animate` with `tw-animate-css`. The old plugin was unmaintained and using JS config. The new one should be a drop-in replacement. - Remove all scripts for generating colors, they're not needed anymore, all values are hardcoded. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added hit-area debugging and sizing utilities for enhanced layout control. * **Refactor** * Restructured color system to use hand-edited CSS variables with inlined values for improved performance and maintainability. * Migrated animation utilities to a new framework. * **Style** * Enhanced motion-reduced animations with improved transition behavior. * Adjusted sidebar layout styling for better visual presentation. * **Chores** * Updated animation dependencies. * Removed legacy color generation scripts. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45925) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|
|
5845ef13f0 |
chore: remove <Toggle> _Shadcn_ suffix (#45970)
## Problem The `_Shadcn_` suffix isn't needed anymore on `<Toggle__Shadcn_>` ## Solution Remove it. No other changes <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Refactor** * Updated Toggle component examples and standardized exports * Simplified export structure for improved consistency * All existing Toggle component functionality maintained <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45970) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
802be950ba |
fix(studio): fix grammar typo and add aria-labels for icon-only buttons (#45762)
## Summary - Fix a grammar error in `GridError.tsx`: the `title` prop used `"is not supporting on"` (wrong verb form) while the body text immediately below in the same component already correctly reads `"is not supported on"`. - Add `aria-label` to two icon-only `<Button>` elements in the table grid editor — `RefreshButton` and the TextEditor expand button — which had no accessible name for screen readers. Tooltip content alone is not announced by assistive technology (WCAG 2.1 §4.1.2). ## Changes - `apps/studio/components/grid/components/grid/GridError.tsx` — grammar fix (`supporting` → `supported`) - `apps/studio/components/grid/components/header/RefreshButton.tsx` — add `aria-label="Refresh table data"` - `apps/studio/components/grid/components/editor/TextEditor.tsx` — add `aria-label="Expand editor"` ## Test plan - [ ] No logic changed; UI text and accessibility attributes only - [ ] Visually identical for sighted users - [ ] Screen reader users can now identify both icon-only buttons by their accessible name <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Bug Fixes** * Corrected error message text for invalid sorting operations. * **Accessibility** * Added descriptive labels for screen readers to the "Expand editor" and "Refresh table data" buttons. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45762) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
207f812878 |
fix: SQL Editor private queries empty state CSS bug (#45963)
## Screenshots Before: <img width="258" height="312" alt="image" src="https://github.com/user-attachments/assets/998609fa-bf39-4ff9-a9c5-9b7018d6a5a3" /> After: <img width="258" height="381" alt="image" src="https://github.com/user-attachments/assets/23d7d8f7-e3ab-4737-8c3f-25f5995c1880" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved the layout and spacing of the empty private queries sidebar placeholder in the SQL editor. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45963) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fdeaaec098 |
Add non prod env favicons to improve visual indicator difference (#45871)
## Context Use a different favicon (black logo on white bg) for dashboard staging or local CLI to improve visual differentiation against hosted dashboard (green logo on black bg) <img width="357" height="52" alt="image" src="https://github.com/user-attachments/assets/b5c88a6e-0ab3-40ce-9c85-fddd8d6ce92b" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Favicon routing now switches automatically to staging icons when running in non-production or CLI-release contexts so the UI reflects the environment. * **Chores** * Added staging favicon assets, a browserconfig, and a staging web app manifest to support environment-specific branding. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45871) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
88c43b31b9 |
Support optionally remove custom domain addon when deleting custom domain after activated (#45880)
## Context Related BE PR: https://github.com/supabase/platform/pull/32693 Add support to remove the custom domain add-on when deleting a custom domain after the custom domain is activated. <img width="411" height="310" alt="image" src="https://github.com/user-attachments/assets/23d57fc0-f760-42d4-8383-480ff2b2ec5a" /> We previously had this behaviour by default to address some customer feedback RE confusion that they were still being charged for custom domain add-on despite deleting the custom domain, but not removing the add-on. However this was a bit of confusing UX (RE deleting the add-on implicitly), so this makes the deleting of the custom domain add-on an explicit action instead. ## To test - [ ] Set up custom domain on a project - [ ] Trying deleting the custom domain after activating _without_ removing the add-on - [ ] Trying deleting the custom domain after activating _with_ removing the add-on |
||
|
|
dd512e912a |
fix(self-hosted): prevent Kong startup failures from CRLF line endings (#44422)
## What changed - added `docker/volumes/.gitattributes` with `* text=auto eol=lf` to enforce LF line endings for Docker-mounted volume files - added a Windows troubleshooting warning to the self-hosting Docker guide for Kong startup failures caused by CRLF line endings ## Why Issue #44052 reports `supabase-kong` failing with `exec /home/kong/kong-entrypoint.sh: no such file or directory`. A common cause is CRLF conversion on Windows for mounted shell scripts. Enforcing LF in `docker/volumes` prevents this class of failure for fresh checkouts/copies. ## Validation - `git check-attr text eol -- docker/volumes/api/kong-entrypoint.sh docker/volumes/db/roles.sql docker/volumes/logs/vector.yml` - `pnpm exec prettier --check apps/docs/content/guides/self-hosting/docker.mdx` - attempted `pnpm --prefix apps/docs run lint:mdx` (failed locally due missing `node-pty` native module in this environment) Closes #44052 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added warning about Windows CRLF line ending issues with Docker mounted scripts and resolution steps. * **Chores** * Added line ending configuration to enforce LF format in Docker volumes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> |
||
|
|
d18043327f |
Update humans.txt - Add Keith Resar as contributor (#45344)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Updates humans.txt to include my name. ## What is the current behavior? n/a ## What is the new behavior? n/a ## Additional context n/a <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated team contributor information in public documentation <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Your Name <you@example.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
748aa4fd2a |
Add Alex Hsu to humans.txt (#45830)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Adds "Alex Hsu" to `humans.txt` ## What is the current behavior? -- ## What is the new behavior? -- ## Additional context Adding name to `humans.txt` as part of employee onboarding <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated team information in public documentation. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45830) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
005fa6eea2 |
Add Jesse White to humans.txt (#45899)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Bug fix, feature, docs update, ... ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated team member information in public documentation. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45899) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2f64b5401e |
Shift internal only fields on new project form into a collapsible (#45873)
## Context Changes here aren't public facing - we're just shifting some internal only fields on the new project page to consolidate them into the "internal-only" collapsible Mainly to improve clarity from our POV RE what fields do users see and the general look of the new project form <img width="727" height="558" alt="image" src="https://github.com/user-attachments/assets/7d8f2915-3a81-4d9d-a067-cd45c1725726" /> So everything that's not within the collapsible are essentially fields that users will see on prod. The changes here also subsequently deprecates the use of 2 feature flags on the new project page: - `showPostgresVersionSelector` -> replaced by new flag `newProjectInternalOnlyConfiguration` - `enableFlyCloudProvider` -> was used to control the visibility of the cloud provider field, now replaced by `newProjectInternalOnlyConfiguration` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Reorganized project creation form layout and field ordering for improved structure. * Updated project resume flow with refined confirmation modal UI. * Simplified cloud provider selection interface. * Streamlined high-availability configuration presentation. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45873) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
980c1bc3cb | chore(self-hosted): update prerequisites and example in docs (#45948) | ||
|
|
8e901c980a | feat: Update replication docs (#45825) | ||
|
|
09fa2b8fc1 |
Clarify alert and collapsible design-system patterns (#45863)
## What kind of change does this PR introduce? Docs update and design-system component taxonomy cleanup ## What is the current behavior? The design-system docs conflate low-level shadcn primitives with product-level alert patterns. Collapsible documentation previews the alert-specific wrapper, and the alert/collapsible relationship is unclear ## What is the new behavior? - Documents Alert and Collapsible as low-level atom components - Moves the alert-styled expandable wrapper into `ui-patterns/expandable-alert` as `ExpandableAlert` - Documents Expandable Alert as a Fragment Component next to Admonition - Updates the Session Timeout modal to import `ExpandableAlert` from `ui-patterns/expandable-alert` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * `CollapsibleAlert` component is now available for alert-styled expandable content. * **Documentation** * Updated component documentation to clarify when to use `Alert`, `Collapsible`, `Admonition`, and `CollapsibleAlert`. * Added comprehensive documentation for `CollapsibleAlert` with usage examples and variant options. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45863) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
bcffb9d245 |
fix: ai sidebar closing (#45932)
## TL:DR fixes ai assistant panel closing after running queries in logs and analytics ## b4: (thanks to OP) <img width="2102" height="854" alt="Image" src="https://github.com/user-attachments/assets/6a1416d8-67bf-4166-999a-d8743746efda" /> ## after: https://github.com/user-attachments/assets/bec3366b-b4d6-41c8-a287-f8c37a818f71 ## ref: - closes https://github.com/supabase/supabase/issues/45930 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved synchronization between the Logs Explorer editor and the URL/search state: running a query now updates the shared search state (and recent snippets) rather than performing a full route push, and the editor now prioritizes the URL/state value when present to prevent mismatches during navigation or query execution. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45932) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8935043a1b |
simplify sql editor warning dialog (#45912)
## What kind of change does this PR introduce? Studio UI cleanup. ## What is the current behaviour? The SQL editor query warning modal repeats itself with an admonition, a nested warning panel, and extra confirmation copy. Single-warning cases are harder to scan than they need to be. ## What is the new behaviour? The warning now uses `AlertDialog` and resolves each detected issue into concise title/body copy. Single-warning cases show one short description, while multi-warning cases show a compact list. The existing RLS actions are preserved. ## Testing instructions Manual SQL editor checks: Open the Studio SQL editor, paste each snippet, click **Run**, verify the warning copy, then click **Cancel**. These snippets are only intended to trigger the warning UI, so do not confirm the dangerous ones. Destructive operation warning: ```sql drop table if exists public.codex_warning_destructive; ``` UPDATE without WHERE warning: ```sql update public.codex_warning_table set id = id; ``` Prevent database connections warning: ```sql alter database postgres connection limit 0; ``` Missing RLS warning: ```sql create schema if not exists codex_warning; create table codex_warning.missing_rls (id bigint); ``` Multiple issues warning: ```sql drop table if exists public.codex_warning_destructive; update public.codex_warning_table set id = id; create schema if not exists codex_warning; create table codex_warning.missing_rls_multi (id bigint); ``` ## Additional context | Before | After | | --- | --- | | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-BDBD32C7-FCE8-4623-ACF2-D2554233EBB4" src="https://github.com/user-attachments/assets/aaed16c2-9910-424a-8a3c-f9815139b1bf" /> | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-C8964C98-1CF9-4992-89D6-86C081C884E8" src="https://github.com/user-attachments/assets/d291c559-1e64-4c63-b918-b20b58d9a2a5" /> | | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-C341A032-B5B0-49A2-8EA2-E3E6EEC54E4F" src="https://github.com/user-attachments/assets/667d9d1a-e34b-4411-9f91-4972ee8d1a23" /> | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-FC66ADE9-6AF1-44D2-A6B6-F7B2FC935C0E" src="https://github.com/user-attachments/assets/1348377e-6606-47c0-aa95-128d7f86ed56" /> | | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-43AAD9FA-7FAC-4DCE-A713-00E8FC76B343" src="https://github.com/user-attachments/assets/bdadedc2-f17d-4011-ae67-5248097b3e92" /> | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-279EC81D-31C7-49C7-B4A8-EEEF1738740A" src="https://github.com/user-attachments/assets/0c178fff-ff49-4522-870d-7a3401c6af30" /> | | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-D405AED5-613F-4C78-909E-F718C67CF17E" src="https://github.com/user-attachments/assets/a4399935-3596-471b-854a-c689e2e0df07" /> | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-725FBCE6-5606-4BC3-B13F-6210DBADF6F2" src="https://github.com/user-attachments/assets/0dcd08fc-cfb4-4d67-b167-eb6eaa768764" /> | | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-EA6563AF-DE7E-4AB8-9164-AC66164CA581" src="https://github.com/user-attachments/assets/ef56fe0f-0243-4ff3-a2b2-ee8b3fe2330a" /> | <img width="1024" height="759" alt="Codex Warning Table Maintenance SQL Editor Hammer Toolshed Supabas-EC85EFB1-715E-4841-BBCA-51F88B539595" src="https://github.com/user-attachments/assets/5be05527-920d-4f23-92eb-c7cd0bbff13e" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Prevented unintended modal dismissal and duplicate handling when confirming. * **Refactor** * Redesigned SQL editor warning modal with structured, consolidated warnings, adaptive title/confirmation copy, and centralized handling of missing-RLS table names. * Added conditional "Run and enable RLS" confirmation when available. * **Tests** * Updated end-to-end tests to match the new modal headings and body text. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45912) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3e50212ad7 |
fix storage policy warning spacing (#45910)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? The Storage public bucket warning confirmation modal can render `SELECTpolicy` without a space. The source relied on implicit JSX whitespace after an inline `<code>` element, and that whitespace can be normalised away when React renders the sentence. ## What is the new behavior? The modal now renders an explicit JSX space after the `SELECT` code element, so the sentence reads `SELECT policy`. | Before | After | | --- | --- | | <img width="860" height="666" alt="CleanShot 2026-05-14 at 14 31 36@2x-2B492E39-5CB4-4D4D-A409-0F0AF268E108" src="https://github.com/user-attachments/assets/683cc8c7-c112-411e-9569-de3be2a1d906" /> | <img width="858" height="668" alt="CleanShot 2026-05-14 at 15 08 08@2x" src="https://github.com/user-attachments/assets/e9a28bb0-9977-4da9-aecb-d4fa56dff368" /> | ## Additional context Testing instructions: 1. Open the staging link. 2. Open the SQL Editor and run: ```sql insert into storage.buckets (id, name, public) values ('public-warning-repro', 'public-warning-repro', true) on conflict (id) do update set public = true; drop policy if exists "public warning broad select repro" on storage.objects; create policy "public warning broad select repro" on storage.objects for select to anon, authenticated using (bucket_id = 'public-warning-repro'); ``` 3. Navigate to Storage > `public-warning-repro`. 4. Click `Remove policy` on the warning banner. 5. Confirm the modal says `This will drop the SELECT policy...`, not `SELECTpolicy`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved wording and inline code styling in the public bucket destructive confirmation modal for clearer, more readable messaging; visual presentation updated without changing behavior or confirmation logic. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45910) <!-- review_stack_entry_end --> <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45910) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1f28a37569 | fix(self-hosted): allow configuring supavisor tenant db_host via env var (#41273) | ||
|
|
856b2badf7 |
feat(telemetry): mirror signup_timestamp to PostHog person property (#45951)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — tiny telemetry addition. +7/-1 in one file. ## What is the current behavior? [PR #45946](https://github.com/supabase/supabase/pull/45946) added `org_count` as a PostHog person property to unblock targeting on org membership. But `org_count` is set on every authenticated session (the `Telemetry` component fires identify whenever `user.id` + `organizations` resolve), not just at signup completion. That means flag filters like `person.org_count == 1` match two populations: - Brand-new dashboard signups currently in their first org (intended) - Returning users who happen to have one org and just signed in (not intended) For the upcoming `dataApiRevokeOnCreateDefault` experiment, this contaminates the activation comparison because the "returning single-org" group can't activate (they already did, months ago), diluting the measured effect. ## What is the new behavior? Adds `signup_timestamp: user.created_at` to the existing `posthogClient.identify` call in `useTelemetryIdentify`. Since gotrue's `user.created_at` is immutable, the value stays constant across sign-ins — no need for `$set_once` semantics, no race with anonymous activity, no cohort refresh lag. Flag targeting can now combine `person.org_count == 1 AND person.signup_timestamp >= <experiment_start_date>` to cleanly scope to brand-new signups. ## Testing No new unit tests added — the existing `useTelemetryIdentify` function has no test file, the change is one additional field on an existing call, and the property's correctness is verifiable end-to-end (sign up → check PostHog person record). Adding to the test ticket [GROWTH-854](https://linear.app/supabase/issue/GROWTH-854) for coverage along with the broader posthog-client wrapper tests. ## Additional context Ref: [GROWTH-853](https://linear.app/supabase/issue/GROWTH-853) This is the follow-up gate before the 5% rollout of `dataApiRevokeOnCreateDefault` — without this, the experiment would mix brand-new signups with legacy single-org users on sign-in. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Enhanced telemetry and analytics data collection for signed-in users by improving user identification tracking and adding signup timestamp information for better analytics insights. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45951) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4c77ab5fef |
feat(telemetry): mirror org_count to PostHog person property (#45946)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature + two follow-on fixes — small, scoped to telemetry / experiment plumbing. ## What is the current behavior? PostHog feature flags evaluated in Studio only have access to the `gotrue_id` person property (set in `useTelemetryIdentify`) and the `organization`/`project` group associations from pageviews. Flags can't target users by org membership without a behavioral cohort, which refreshes on a ~hourly schedule and lags behind real-time signup state. This is blocking the rollout of the `dataApiRevokeOnCreateDefault` experiment ahead of the May 30 default-privileges breaking change — we need to target brand-new dashboard signups with no prior org membership, and there's no person property to filter on. ## What is the new behavior? Three changes, scoped tightly to make experiment targeting reliable for brand-new signups: ### 1. Mirror `org_count` to a PostHog person property (`apps/studio/lib/telemetry.tsx`) The Studio `Telemetry` component now mirrors the user's current org-list length to a PostHog person property `org_count` via `posthog.identify(user.id, { org_count })`. The effect: - Subscribes to `useOrganizationsQuery` (shares the same React Query cache as `useSelectedOrganizationQuery`, so no extra network requests). - Dedupes via a ref keyed on `{ userId, orgCount }` so we only call identify when the value actually changes — handles user-switch (logout/login as different user with same count) correctly. - Generic enough to be useful beyond this experiment — analytics segmentation by org membership, future flags that depend on multi-org behavior, etc. ### 2. Merge pre-init identify properties (`packages/common/posthog-client.ts`) The previous `pendingIdentification` slot was a single-write buffer — calling `posthogClient.identify()` before the PostHog SDK initialized would overwrite any prior queued identify. Latent until this PR added a second identify caller (`org_count`), which exposed the last-write-wins behavior on first-visitor-before-consent flows. Now merges properties across pre-init calls for the same user so both `{ gotrue_id }` and `{ org_count }` land on the person record when the SDK flushes. Caught during Codex review. ### 3. Gate the exposure event on `org_count` being present (`apps/studio/hooks/misc/useDataApiRevokeOnCreateDefault.ts`) `useTrackDefaultPrivilegesExposure` previously fired on the first non-undefined value of the `dataApiRevokeOnCreateDefault` flag. For brand-new signups, this races the `org_count` identify: the initial `/flags/` response (before targeting can match) returns the untargeted variant, the exposure locks it in via `hasTracked`, then our identify fires and a subsequent `/flags/` refresh updates the flag — but the exposure has already recorded the wrong variant. Fix: gate the exposure on `org_count` being present on the SDK person, subscribing via `onFeatureFlags` so we pick up the post-identify `/flags/` response. Adds `posthogClient.getPersonProperty` as the local-state reader. Without this, the experiment would have a ~5-15% noise floor on cohort assignment for new signups. ## Verification End-to-end verified locally against the staging PostHog project (34343): - Local Studio's PostHog SDK has `$stored_person_properties: { gotrue_id: <uuid>, org_count: 1 }` after sign-in. - Both `$set` events landed server-side within ~300ms of each other, and the staging person record now shows `org_count = 1.0` with `gotrue_id` preserved. - Targeting query `person.properties.org_count == 1` works end-to-end against staging. ## Additional context Ref: [GROWTH-853](https://linear.app/supabase/issue/GROWTH-853) Targeting plan for the flag once shipped: `person.org_count == 1` plus a behavioral filter on recent `sign_up` event, at 5% rollout. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Telemetry now records and syncs the user's organization count as an analytics person property and avoids redundant identifications when unchanged. * Analytics client now merges queued identification properties made before initialization and exposes a method to read stored person properties. * **Bug Fixes** * Tracking now waits for organization-count readiness before firing certain exposure events to prevent missing data. * **Tests** * Added/updated tests to cover person-property behavior and gating logic. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45946) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d79a276824 |
studio: ColumnTypeRef cascade + FK type comparison fixes (2/7) (#45903)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor + bug fixes (part of the SafeSql migration stack — PR 2 of 7, stacks on top of #45897). ## What is the current behavior? - `pgMeta.columns.create` and the table-editor SQL builder take column type as a string with array suffix and schema baked in (e.g. `'private.test_enum'`, `'int4[]'`). - The studio table-editor SQL emits the legacy schema-embedded `format` string for enums in non-public schemas, while the pg-meta columns SQL already returns the new shape (bare `format` + separate `format_schema`). The two queries disagree on how to represent the same column, surfacing as a false-positive type mismatch in the FK selector when both ends are an enum from a non-public schema. - The FK selector compares column types by `format` alone — same-named enums in different schemas appear equal, and arrays vs. scalars of the same base type pass the family check. - `displayColumnType` renders arrays as the raw `_typname` pg-meta emits (e.g. `_int4` instead of `int4[]`). ## What is the new behavior? **pg-meta** - Introduce `ColumnTypeRef` (`{ schema?, name, isArray? }`) for column type input, replacing the legacy string-with-array-suffix format. `pgMeta.columns.create` and the table-editor SQL builder consume the new shape. - Add `format_schema` to the column zod schema; pg-meta SQL emits the type's schema for the table editor's ColumnType dropdown. - `pgMeta.columns.create` returns a `SafeSqlFragment`. - Studio table-editor SQL now emits bare `format` + `format_schema`, matching pg-meta's columns SQL. **Studio** - `SafePostgresColumn`/`SafePostgresTable` extend the new `PG*` types (master dropped postgres-meta). - Pipe `ColumnTypeRef` through `SidePanelEditor` → `ColumnEditor` → `TableEditor`, along with the column-create mutation, table retrieve/list queries, and the `TableList`/`ColumnList` surfaces. - `displayColumnType` helper renders arrays as `type[]` (or `schema.type[]`) and handles non-implicit schemas. - FK selector now carries `sourceIsArray`/`targetIsArray` and compares the full `(format, format_schema, isArray)` triple. Family checks for numeric/text/uuid skip when either side is an array (FKs across array boundaries are never compatible). - Type-mismatch and type-notice alerts pass `isArray` to the display helper. - Bundle `Policies.utils` + `Policies.types` + `sql-policy-mutation`, `PolicyEditorModal`, and `SchemaGraph` here because `SidePanelEditor` consumes `acceptGeneratedPolicy`/`AcceptedGeneratedPolicy` — splitting requires temporary overloads with no architectural payoff. ## Additional context Part of the SafeSql migration stack. Stacks on top of #45897. ### Manual test checklist Surfaces touched by this PR — please exercise each: **Table editor** - [x] Create a new table with a mix of column types (scalar, array, enum, foreign key) - [x] Add a column to an existing table; verify the type dropdown lists scalars + arrays separately and shows schema-qualified names for non-public enums - [x] Edit an existing column's type (scalar ↔ array, switch between enums in different schemas) and save - [x] Verify enum types from a non-public schema (e.g. `private.my_enum`) display as `private.my_enum` in the column list **Foreign key selector** - [x] Open the FK selector for a column and pick a target column with a matching type — no mismatch warning - [x] Pick a target column whose type differs only by schema (two same-named enums in different schemas) — should show a type-mismatch alert - [x] Pick a target column where one side is an array and the other is a scalar of the same base type — should show a type-mismatch alert (no auto-cast across array boundary) - [x] When FK target sets the column type, verify `format_schema` and `isArray` are preserved on the source column - [x] Type-mismatch and type-notice alert messages render array types as `type[]` (not `_type`) **Column list / table list** - [x] Schema-qualified type names display correctly for columns whose type lives in a non-public schema - [x] Array columns display as `type[]` (or `schema.type[]`) **Policies (bundled due to import dependency)** - [x] Open the Policies page; create/edit/delete a row-level policy via the modal - [x] Generate a policy via the AI assistant and accept it through `SidePanelEditor` — verify the accepted policy lands in the editor correctly **Schema visualizer** - [x] Open the Schemas → Schema Visualizer page; verify it renders without type errors and shows tables/relationships <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Support for column types in non-public schemas and richer column type presentation (includes schema and array info). * Stronger SQL safety around policies and constraints; draft policy SQL is now promoted explicitly on save. * Improved foreign-key type validation and compatibility checks using enhanced type metadata. * **Tests** * Updated snapshots and tests to reflect new column metadata and SQL fragment handling. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45903) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
29bfa7b75b |
fix(studio): encode special characters in project securing policies links (#45849)
Closes #45847. ## Summary `ProjectNeedsSecuringView.tsx` built the `View policies` href on the first-time security gate by interpolating `table.schema` and `table.name` directly into the URL. A table or schema containing `&`, `=`, `+`, or `#` corrupted the destination and routed the user to the wrong policies filter on what is meant to be a guided onboarding flow. Extracts the URL into `getTablePoliciesHref` in `ProjectNeedsSecuring.utils.ts` with `encodeURIComponent` wraps, and replaces the inline interpolation. Same pattern as #45385. ## Test plan Added `ProjectNeedsSecuring.utils.test.ts` covering `getTablePoliciesHref` (plain values, special chars in name, special chars in schema, both, undefined inputs) and pulling in the previously-untested `getTableKey`, `formatRlsDescription`, `sortTables`, and `buildSecurityPromptMarkdown` utilities. Ten tests total. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added comprehensive test coverage for security utilities, including URL construction, formatting, sorting, and markdown report generation. * **Refactor** * Extracted URL building logic into a centralized utility function for improved consistency and maintainability. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45849) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
461c1c1783 |
fix(studio): encode special characters in trigger/function cross-link search params (#45851)
Closes #45850. ## Summary `TriggerList`, `EventTriggerList`, and `FunctionList` built cross-links between the database triggers and functions pages by interpolating user-controlled identifiers directly into the URL query string. A function or schema name containing `&`, `=`, `+`, or `#` corrupted the destination filter and routed users to the wrong row. Adds `getDatabaseFunctionsHref` to `TriggerList.utils` (used by both `TriggerList` and `EventTriggerList`) and a new `getDatabaseTriggersHref` in `FunctionList.utils`, both with `encodeURIComponent` wraps. Replaces the three inline interpolations. `FunctionList` only has a single search param (no schema) because the link filters by function name only, so its helper takes one less argument. Same pattern as #45385. ## Test plan Added `TriggerList.utils.test.ts` covering `getDatabaseFunctionsHref` (plain, special chars in name, special chars in schema, both, undefined inputs) and `FunctionList.utils.test.ts` covering `getDatabaseTriggersHref` (plain, special chars in name, plus signs and spaces, undefined inputs). Nine tests total. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved database navigation links for functions and triggers by standardizing link generation through centralized utility functions. This ensures consistent URL encoding and parameter handling across the application. * **Tests** * Added comprehensive test coverage for database navigation link utilities, including edge cases with special characters and empty parameters. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45851) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
39f1358f08 |
fix(studio): encode special characters in table editor policy links (#45846)
Closes #45845. ## Summary `GridHeaderActions.tsx` interpolated `table.name` and `table.schema` directly into the policies URL at two `<Link href>` builders. A table or schema containing `&`, `=`, `+`, or `#` corrupted the destination and routed users to the wrong policies filter. Extracts the URL into `getTablePoliciesUrl` in `TableEntity.utils.ts` with `encodeURIComponent` wraps, and replaces both inline interpolations. Same pattern as #45385 (Linter shortcut links). ## Test plan Added four `getTablePoliciesUrl` cases in `TableEntity.utils.test.ts`: plain values, special chars in name, special chars in schema, special chars in both. Existing seven tests in the same file still pass. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved Row-Level Security (RLS) policy URL handling in the table editor using a shared utility function for consistent URL building and proper parameter encoding. * **Tests** * Added test coverage for RLS policy URL generation with various parameter combinations and special character handling. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45846) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2035b2fb7b |
feat(logs): gate CH/otel toggle in log explorer behind feature flag (#45944)
## Problem
The CH/otel queries toggle in log explorer was only shown on staging and
local environments, controlled by the hardcoded `IS_STAGING_OR_LOCAL`
check. This made it impossible to enable for specific users or teams in
production via a feature flag.
## Fix
Replaced the `IS_STAGING_OR_LOCAL` check with
`useFlag('showChToggleInLogExplorer')` from `common`, so the toggle
visibility is controlled by the PostHog feature flag instead of the
environment.
## How to test
1. Open log explorer on a project.
2. Without the `showChToggleInLogExplorer` flag enabled, confirm the
CH/otel toggle is not visible.
3. Enable the `showChToggleInLogExplorer` flag in PostHog for your user.
4. Reload log explorer and confirm the CH/otel toggle appears.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated internal feature gating mechanism for the OTEL toggle in Logs
settings from environment-based to flag-based configuration.
<!-- review_stack_entry_start -->
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45944)
<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
|
||
|
|
453c31da16 |
refactor(common): drop ConfigCat proxy probe in favor of waitForReady (#45939)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor / performance. ## What is the current behavior? `packages/common/configcat.ts` does a two-step setup: a probe `fetch` to the ConfigCat proxy URL, followed by SDK client initialization with the proxy as `baseUrl` (or against the direct ConfigCat CDN if the probe fails). On the happy path this fires **two** network requests for the same JSON config on cold start — the probe, then the SDK's own initial AutoPoll fetch. ## What is the new behavior? The probe is removed. We initialize the proxy client directly and inspect the `ClientCacheState` returned by `waitForReady()`. On `NoFlagData` (proxy unreachable, no cache) we `dispose()` the proxy client and fall back to the direct SDK key client. Cold-start fetches drop from 2 to 1 when the proxy is healthy. Worst-case fallback delay is bounded by `maxInitWaitTimeSeconds` (5s default), comparable to today's probe timeout on a broken proxy. The unused exported \`fetchHandler\` is removed (no external importers — verified via grep). Tests in \`configcat.test.ts\` are updated to mock \`waitForReady\`/\`dispose\` and a new test covers the proxy-failure fallback path. ## Additional context Resolves FE-3174 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved ConfigCat client initialization with robust fallback handling when proxy is unavailable. * **Chores** * Removed `fetchHandler` export from ConfigCat module. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45939) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5a067d0937 |
feat(unified-logs): show feature preview for flag or team/enterprise plan (#45937)
## Problem The unified logs feature preview was only shown to users with the \`unifiedLogs\` LaunchDarkly flag enabled AND who were either on an enterprise plan or on staging/local. Team plan users were excluded, and the staging escape hatch added noise. ## Fix Updated the eligibility check to use an OR condition: show the feature preview if the \`unifiedLogs\` flag is on OR the org is on a team or enterprise plan. Also added \`team\` to the \`useIsEnterpriseOrSupabaseOrg\` hook and removed the \`IS_STAGING_OR_LOCAL\` bypass. ## How to test - Log in as a user on a team plan and verify the "New Logs interface" option appears in the Feature Previews modal - Log in as a user on an enterprise plan and verify the same - Log in as a user on a free or pro plan without the \`unifiedLogs\` flag enabled and verify the option does not appear - Enable the \`unifiedLogs\` LaunchDarkly flag for a free/pro user and verify the option appears <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Unified logs preview is now more accessible for enterprise and Supabase organizations without requiring additional staging conditions. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45937) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
36d1f2c0ec | feat(self-hosted): do not require openssl or node for new auth (#45941) | ||
|
|
8b01d388b9 |
docs: Remove leftover auth-ui components (#45931)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated authentication guide for Kotlin Compose Multiplatform with revised dependency configuration. * Enhanced user-management example README with improved project structure, deployment steps, and resources. * **Chores** * Refactored example applications to use custom authentication forms instead of pre-built Auth UI components. * Removed unused authentication UI dependencies from multiple example projects. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45931) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cemal Kılıç <cemalkilic@users.noreply.github.com> |
||
|
|
5f32b3ec6b |
Added PGConf Vancouver back into the go pages (#45943)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Accidentally deleted a couple of go pages. Adding them back. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Introduced contest registration and confirmation pages for PGConf Dev 2026, designed as time-limited features with automatic removal scheduled for May 31, 2026. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45943) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |