Commit Graph
38083 Commits
Author SHA1 Message Date
Victor Farazdagi 3bc52101ee (docs/pipelines): early access destinations (#49304)
## What kind of change does this PR introduce?

Docs update


## Summary

- Add Early Access setup and reference guides for ClickHouse, DuckLake,
and Snowflake.
- Update Pipelines navigation and shared documentation with
destination-specific data models, source requirements, schema-change
support, and recovery behavior.
- Keep all three destinations organization-gated. DuckLake is documented
only as a Pipelines replication destination i.e. query compute remains
external and this is not a Warehouse launch.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added ClickHouse, DuckLake, and Snowflake as Early Access Pipelines
destinations.
  * Added BigQuery as a managed destination.
* Added destination navigation and setup guides covering configuration,
replication behavior, schema changes, type mappings, troubleshooting,
and monitoring.

* **Documentation**
* Clarified destination availability, regional guidance, requirements,
limitations, and processing behavior.
* Documented destination-specific schema-change support, table identity
requirements, reset behavior, and CDC replication modes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 14:44:54 +03:00
Katerina Skroumpelou 30835c6f5a docs: remove deprecated processLock from react-native auth quickstart (#49471)
Removes `lock: processLock` from the React Native auth quickstart. Since
supabase-js 2.107.0 the client coordinates session refreshes without a
lock (single-flight dedupe within the client, with concurrent refresh
races resolved server-side), so the option is no longer needed; it is
deprecated and will be removed in v3, and upcoming 2.x releases log a
one-time deprecation warning when it is passed. The quickstart installs
`@supabase/supabase-js@^2`, so anyone following it gets the lockless
behavior out of the box.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated the React Native authentication quickstart to initialize the
client without the removed locking configuration, improving
compatibility with current authentication setup.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 13:36:05 +03:00
claude[bot] c32db2b80b fix(studio): track resourceAccess='account' for legacy access tokens (#49448) 2026-08-24 16:44:23 +08:00
Ayaan Gazali 18896e33de fix(studio): give two DropdownMenuTriggers asChild so they stop nesting buttons (#49264)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix. Two `DropdownMenuTrigger`s wrap a `Button` without `asChild`,
so each renders a `<button>` inside a `<button>`. One of them also loses
its `aria-label`, leaving an icon-only menu trigger with no accessible
name.

## What is the current behavior?

`DropdownMenuTrigger` forwards to `DropdownMenuPrimitive.Trigger`, which
renders its own `<button>` unless `asChild` is set. So this:

```tsx
<DropdownMenuTrigger>
  <Button variant="default" className="px-1" icon={<MoreVertical />}
          aria-label={`Open actions for ${hook.title}`} />
</DropdownMenuTrigger>
```

produces `<button><button/></button>`, which is invalid HTML, and puts
the props on the inner element rather than on the thing that actually
opens the menu.

Measured by rendering `HookCard` before and after, rather than reasoning
about it:

| | before | after |
| --- | --- | --- |
| `container.querySelectorAll('button button').length` | 1 | 0 |
| `aria-label` on `[aria-haspopup="menu"]` | `null` | `Open actions for
Send Email` |

That second row is the part worth caring about. The `aria-label` was
written deliberately for a button whose only content is a `MoreVertical`
icon, and it lands on the nested inner button instead of the trigger, so
a screen reader gets no name for the control it actually operates.

Two sites:

- `components/interfaces/Auth/Hooks/HookCard.tsx`, the per-hook actions
menu. This is the one with the orphaned `aria-label`.
- `components/layouts/ProjectLayout/PauseFailedState.tsx`, the overflow
menu next to "Download backup".

## What is the new behavior?

Both get `asChild`, so the `Button` becomes the trigger. No nesting, and
the props land where they were meant to.

## Additional context

#48948 fixed exactly this in `RestoreFailedState.tsx`, which sits in the
same directory as `PauseFailedState.tsx` and has the same overflow-menu
shape. This is that fix applied to the two places it was not.

I swept all 4398 `.tsx` files across studio, www, docs, design-system,
ui-library, `packages/ui` and `packages/ui-patterns` for any Radix-style
trigger (`DropdownMenu`, `Tooltip`, `Popover`, `Dialog`, `Sheet`,
`AlertDialog`, `HoverCard`, `Collapsible`, `ContextMenu`, `Menubar`,
`Select`, `Tabs`, `Accordion`) that wraps a button-like element without
`asChild`. After discarding one false positive in
`EdgeFunctionDetails.tsx`, where the `Button` is a sibling of
`TabsTrigger` inside `TabsList` rather than its child, these two are the
only ones left. So this should be the end of the pattern rather than the
start of a series.

No test added, matching what #48948 did for the same change. The
`asChild` behaviour belongs to Radix, and a test asserting DOM nesting
around two JSX attributes would be testing the library. I did verify it
the other way round while developing: a throwaway render assertion
failed on unmodified master with a nested-button count of 1 and a null
trigger `aria-label`, and passed after the change. Happy to commit that
assertion if you would rather have it in the suite.

Gates: `test:prettier` passes repo wide, `typecheck --filter=studio
--force` passes 9/9, `--filter studio run lint:ratchet` reports rules
improved, and the tests covering both touched directories pass (18
files, 143 tests, including the `RestoringState` suite that came in with
#48948).

Freshman contributor. Found this with Claude Code's help by checking
whether the `asChild` fix in #48948 had siblings, and I confirmed the
nesting and the missing accessible name myself before touching anything.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved dropdown menu trigger behavior in the authentication hooks
and project layout interfaces.
* Existing buttons now correctly serve as menu triggers without changing
available actions or menu behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 10:43:56 +02:00
Cemal Kılıç f857be2063 feat: enable idjag for all (#49462)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

remove feature flag gate for enterprise mcp auth



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Advanced SSO settings are now available for all SSO configurations.
* **Changes**
* Removed organization-specific eligibility restrictions for advanced
SSO settings.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 10:35:39 +02:00
Saxon FletcherandJoshen Lim de2a7d8d9e Add view options to Query (#49447)
Currently Query tabs in explorer do not support view options e.g. table
vs chart. This adds display state to query tabs to match the behaviour
of Notebooks

## To test
- create a query in explorer
- Run a query
- Set the display options via toolbar

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Query results can now be displayed as either a table or chart.
* Chart settings are saved with each query draft and restored when
reopened.
* Display preferences are maintained independently across query drafts.
  * Editing a preview query now converts it into a permanent tab.
* **Bug Fixes**
* Invalid or legacy display settings safely fall back to the table view
without removing saved drafts.
* Charts and empty states now use the available editor space more
effectively.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-24 16:19:17 +08:00
Alaister YoungandAlaister Young caceeb429f [MUL-1336] fix(studio): show HA project costs as free during Alpha (#49383)
HA (Multigres) projects are free during Alpha, but the project creation
form still presented the forced large compute as a real charge. The
footer now shows **$0/m** for HA projects, with the usual compute price
struck through + a "Free during Alpha" note in the cost-breakdown
tooltip and the compute size dropdown. Follows the pattern from #49249.

Addresses
[MUL-1336](https://linear.app/supabase/issue/MUL-1336/bug-when-creating-new-projects).

<img width="688" height="167" alt="Screenshot 2026-08-21 at 5 27 39 PM"
src="https://github.com/user-attachments/assets/804b9243-77ae-4961-9083-5e1290734d3a"
/>
<img width="503" height="202" alt="Screenshot 2026-08-21 at 5 27 32 PM"
src="https://github.com/user-attachments/assets/f217edd4-2204-4e5e-87f8-f54974e3c6fa"
/>

**Changed:**
- `ProjectCreationFooter`: "Additional costs" shows `$0/m` when HA is
on; the tooltip gains a "High availability projects are free during
Alpha for up to 2 projects." sentence; the New-project row's price
renders struck through with a "Free during Alpha" sub-line; the HA
project's compute is excluded from "Total Monthly Compute Costs"
(clamped at 0 so credits can't produce a negative total — a no-op for
non-HA since spend already floors above zero)
- `ComputeSizeSelector`: the per-option `$X/hour (~$Y/month)` line
renders struck through with "Free during Alpha" beneath it when HA is on
(both tagged `data-field="instance-details"` so the collapsed trigger
keeps hiding them)
- `ProjectCreationForm`: threads the watched `highAvailability` value
into the footer

The "Confirm compute costs" modal was already suppressed for HA by the
existing `!values.highAvailability` guard — no change needed there.

## To test

- On a paid org, open New Project and toggle High Availability on: the
footer should read `$0/m` (brand green, no strikethrough), its ⓘ tooltip
should show the HA sentence and the New row's `$110` struck through with
"Free during Alpha", and the Total should exclude the $110; the compute
dropdown's Large option should show its price struck through with "Free
during Alpha"
- Toggle HA off (and on/off a few times): all cost displays should
revert exactly to normal — green real price, no strikethrough, no "Free
during Alpha" anywhere outside the HA toggle's own description
- With HA off and compute size Medium, submit: the "Confirm compute
costs" modal should still appear as before (Cancel works)
- Collapsed compute-size trigger should never show a price line or "Free
during Alpha" in either state

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## New Features

- High-availability project options now show compute pricing as free
during Alpha.
- Standard compute prices are displayed with a strikethrough alongside
the Alpha-free notice.
- Project cost summaries accurately show no additional compute charge
for high-availability selections.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-24 16:10:14 +08:00
Alaister YoungandAlaister Young b9df7aaf9e [FE-3711] feat(studio): make compute config read-only for HA projects (#49359)
Makes the compute-size configuration on Settings → Infrastructure
read-only for High Availability (Multigres) projects during Alpha — HA
projects run on a single fixed compute size and resizing isn't supported
yet (previously attempting one could leave a project stuck Resizing).

Gated on `project.high_availability` via the existing
`useHighAvailability()` hook — the same signal every other HA gate in
Studio uses.

**Changed:**
- Compute size options other than the project's current size render with
the existing locked treatment (greyed out, lock icon, tooltip) for HA
projects, and the whole radio group is disabled
- A `HighAvailabilityDisabledSectionNotice` in the Compute section
explains that HA projects run on a fixed compute size during Alpha
- The compute branch of `onSubmit` and the read-replica
compute-recommendation handoff are skipped for HA projects, so a compute
change can never reach `POST /billing/addons`
- The "Contact Us" larger-sizes card is hidden for HA projects
- Form initialization now also fires once the project loads for HA
projects (disk-attribute queries never run on their cloud provider, so
the existing reset effect never fired and the picker showed the
`ci_micro` fallback as selected)

**Added:**
- Two MSW page tests in the Infrastructure suite covering the HA
read-only state and the unchanged editable state for non-HA projects

## To test

- On an HA (Multigres) project: Settings → Infrastructure should show a
notice under Compute size, the project's current size selected, every
other size locked with a tooltip, no "Contact Us" card, and clicking any
option should never surface the "Review changes" bar
- On a regular project: compute selection, "Review changes" → "Confirm
changes", and the Contact Us card all behave as before
- `pnpm vitest run
"tests/pages/project/[ref]/settings/infrastructure.test.tsx"`

Addresses
[FE-3711](https://linear.app/supabase/issue/FE-3711/make-compute-configuration-read-only-for-mvp)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added High Availability notices and guidance to the Compute settings.
* High Availability projects now show compute sizes as read-only, with
explanations for unavailable options.
* Hid the larger-instance contact option for High Availability projects.

* **Bug Fixes**
* Prevented unsupported compute resizing and add-on changes for High
Availability projects.
  * Preserved compute resizing and review actions for standard projects.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-24 16:09:43 +08:00
CharisandJoshen Lim 48cc37f0d2 refactor(studio): extract notebook cache eviction helper (#49414)
## Summary

Part 1 of the FE-4247 stack
([FE-4247](https://linear.app/supabase/issue/FE-4247/assistant-invalidate-cache-after-notebook-editdeletion)).
Pure refactor, no behavior change — extracts the notebook cache eviction
logic that `ExplorerNotebookTabCoordinator` had open-coded into a shared
helper, so the upcoming assistant create/update/delete cache
invalidation (PR 2/3 in the stack) can reuse it instead of duplicating
the two-cache-layer eviction dance.

- New `evictNotebookFromCaches({ queryClient, projectRef, id, mode })`
in `apps/studio/data/content/notebooks/notebook-cache.ts`. `mode:
'refresh' | 'remove'` selects `invalidateQueries` vs `removeQueries` on
`contentKeys.resource`. Drops the notebook from `notebooksState` only
when its status is `'saved'`, matching the original open-coded guard
exactly. Returns whether it evicted, so callers can branch.
- `ExplorerNotebookTabCoordinator` now calls the helper with `mode:
'remove'` instead of inlining the logic.

## Test plan

- [x] `pnpm test:studio -- notebook-cache
ExplorerNotebookTabCoordinator` — new helper tests
(refresh/remove/dirty-guard/unknown-id) and existing coordinator tests
all pass
- [x] `pnpm typecheck --filter=studio`
- [x] `pnpm lint --filter=studio` — 0 errors, no new warnings

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved detection of unsaved notebook changes for tab indicators and
close confirmations.
- Empty, never-saved notebooks are no longer included in discard
prompts.
- Improved cache cleanup when closing saved notebooks while preserving
unsaved work.
  - Added safeguards for missing notebook records.
- **Tests**
- Added coverage for notebook cache refresh, removal, preservation, and
no-op scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-24 15:59:41 +08:00
Danny White fdf33e72c4 fix(studio): clean up onboarding returnTo paths (#49283)
## What kind of change does this PR introduce?

Bug fix. Follow-up to #41041 and DEPR-318.

## What is the current behavior?

Marketing "Start your project" links go to `/dashboard`, which redirects
unauthenticated users to `/org` and sets `returnTo=/org`. That value
survives when they switch from sign-in to sign-up, so email verification
still lands on the org list instead of org creation.

## What is the new behavior?

- Sign-in's **Sign up** link rewrites `returnTo=/org` (and
`/organizations`) to `/new`
- Docs mobile menu, www homepage/product CTAs, and solution page CTAs
link to `/dashboard/sign-up` for guests
- Signed-in visitors get the dashboard URL instead, so they never hit
the sign-up form
- Shared `DASHBOARD_SIGN_UP_URL` / `getDashboardCtaHref` helpers for www

Stacked on #41041.

## To test

Stacked on #41041. The studio preview below includes both PRs. www and
docs have their own previews.

### Studio: sign-in → sign-up rewrite

Using the [studio-staging
preview](https://studio-staging-git-dnywh-fixonboarding-return-to-supabase.vercel.app/)
from Vercel checks:

1. Open the preview while logged out. It should land on
`/dashboard/sign-in?returnTo=%2Forg`
2. Click **Sign up**. Expect the URL to include `returnTo=%2Fnew`

### Optional: www CTAs

Using the [www
preview](https://zone-www-dot-com-git-dnywh-fixonboarding-return-to-supabase.vercel.app/):

3. Logged out: homepage, product, or solutions **Start your project**
should go to `/dashboard/sign-up`
4. Logged in: the same CTAs should go to `/dashboard` (not sign-up)
(thought this will be hard if not impossible to test on staging)

### Optional: docs CTAs

Using the [docs
preview](https://docs-git-dnywh-fixonboarding-return-to-supabase.vercel.app/):

5. On mobile nav while logged out, click **Start your project**. Expect
`/dashboard/sign-up`

### Compare on supabase.green

Optional. Just to show what happens currently on `master`:

6. Open **supabase.green** while logged out, then click **Sign up** from
`/dashboard/sign-in?returnTo=%2Forg`. `returnTo` should stay as `/org`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Start-project and sign-up links now direct visitors to registration
while signed-in users continue to reach the dashboard.
* Homepage, product, solution, and mobile navigation CTAs now provide
consistent authentication-aware destinations.
* Sign-up links preserve return destinations and existing navigation
parameters.

* **Bug Fixes**
* Corrected mobile navigation and marketing CTA links that previously
sent visitors to the dashboard root instead of the appropriate sign-up
flow.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 17:32:56 +10:00
Danny White ee931e49a1 fix(studio): send new signups to org creation directly (#41041)
## What kind of change does this PR introduce?

Bug fix. Resolves DEPR-318.

## What is the current behavior?

New users who confirm their email land on `/sign-in`, then
`/organizations`, then get bounced to `/new` via a `useEffect`.
Cancelling org creation with zero orgs sends them back to
`/organizations`, which immediately redirects into `/new` again.

## What is the new behavior?

- Signup email verification redirects to `/new` directly
- `/organizations` with zero orgs shows the existing empty state instead
of force-redirecting

## To test

### One-time setup

Assuming you don’t already have a staging account with **zero** orgs:

1. On **supabase.green**, sign up with a fresh email and confirm it
2. Stop at org creation. Do **not** create an org

### On this PR

Using the [studio-staging
preview](https://studio-staging-git-dnywh-fixremove-org-redirect-supabase.vercel.app/)
from Vercel checks:

4. Sign in on the preview with that account
5. Open `/dashboard/organizations`. Expect the **Create an
organization** empty state, with no redirect to `/new`
6. Open `/dashboard/new`, click **Cancel**. Expect to land on
`/organizations` and stay there

### Compare on supabase.green

Optional. Just to show what happens currently on `master`:

7. Repeat steps 3–5 on **supabase.green**. `/organizations` should
bounce to `/new`, and **Cancel** should send you back into org creation

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved signup redirects by preserving valid destinations and
relevant query parameters.
* Added safer fallback behavior for missing, invalid, or unsupported
destinations.
  * Improved handling of signup redirects provided in multiple formats.
* Prevented automatic redirection from the organizations page when no
organizations exist.

* **Style**
  * Updated the organizations page title capitalization for consistency.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 17:23:25 +10:00
Pamela Chia 21a27eeb4f feat(www): canonicalize homepage markdown at /index.md (#49384)
The www root markdown lived at an accidental URL: `/.md` served the
homepage markdown only because middleware strips the `.md` suffix and
the empty slug fell through to the homepage allowlist entry, while the
canonical-looking `/index.md` 404'd. The served markdown also opened
with stale legacy positioning copy that no longer matches the site. I
renamed the homepage content slug to `index` end-to-end so `/index.md`
is the one canonical markdown URL.

**Changed:**
- **`/index.md` serves the homepage markdown (200 `text/markdown`)**:
`content/md/homepage.md` renamed to `index.md`; the middleware bare-root
slug mapping, the generator's sort special-case, and the homepage
alternate tag follow, so the tag now advertises `/index.md`.
- **Legacy aliases 308 to the canonical URL**: `/.md`, `/homepage.md`,
and bare `/index` redirect via `lib/redirects.js`; `/llms/homepage.txt`
retargeted straight to `/index.md` to avoid a redirect chain. New
`next.config.test.ts` assertions pin all four.
- **Positioning refreshed**: the markdown now opens with "Supabase is
the Postgres development platform" (matching the site title), replacing
the outdated tagline.
- **Generator safety**: the redirect-exclusion filter in
`generateMdContent.mjs` now exempts the `index` slug (its HTML page is
`/`, not `/index`, so a `/index` redirect never refers to it), and the
build fails if `content/md/index.md` ever goes missing while middleware
still maps `/` to the `index` slug.
- **CI actually runs the new assertions**: I widened the `www-tests.yml`
paths filter to include `apps/www/lib/**/*.js`,
`apps/www/content/md/**`, and `apps/www/scripts/**/*.mjs`. It previously
only matched `.ts*` and the next.config files, so a PR touching only
`lib/redirects.js`, the markdown content, or the generator would skip
the tests that pin these redirects.

**Note:** the existing homepage alternate tag still exists, re-pointed
to the canonical URL. Whether the homepage should advertise a markdown
sibling at all is a separate decision; leaving it aimed at a 308 would
break tag consumers. Positioning wording is editorial, happy to tweak.

## To test
Tested on Vercel preview:
- [x] `curl -si <preview>/index.md`: expect 200 `content-type:
text/markdown`, body opens with the Postgres development platform
positioning and no longer contains the old tagline
- [x] `curl -sI <preview>/.md`: expect 308 with `location: /index.md`
- [x] `curl -sI <preview>/homepage.md` and `curl -sI
<preview>/llms/homepage.txt`: expect 308 with `location: /index.md`
- [x] `curl -sI <preview>/index`: expect 308 with `location: /`
- [x] `curl -s -H "Accept: text/markdown" -o /dev/null -w "%{http_code}
%{content_type}" <preview>/`: expect `200 text/markdown` (bare-URL
negotiation unchanged)
- [x] `curl -s <preview>/ | grep -o 'type="text/markdown"
href="[^"]*"'`: expect href ending `/index.md`

## Linear
- fixes GROWTH-1117



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Added support for `/index.md` as the canonical Markdown representation
of the homepage.
- Added permanent redirects for legacy homepage Markdown and text URLs.
  - Added `/index` to `/` redirect handling.

- **Bug Fixes**
- Updated homepage metadata, alternate links, Markdown negotiation, and
content generation to consistently use the new canonical path.
  - Improved homepage content description.

- **Tests**
- Expanded coverage for homepage Markdown routes, redirects, and URL
matching.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 15:19:56 +08:00
Joshen Lim 5c6ef8ae3d Joshenlim/fe 4221 explorer tab behaviours to mimic sql editor (#49386)
## Context

Improves the tab behaviour for explorer to follow the SQL Editor
- Tabs now start as preview tabs and become permanent once you start
interacting with them
 - Query Tabs become permanent as soon as you start typing in the editor
- Chat tabs become permanent as soon as you start typing in the chat
input
- Notebook tabs become permanenet as soon as you make any changes to the
notebook
- Notebooks with unsaved changes will show the orange dot indicator
<img width="197" height="67" alt="image"
src="https://github.com/user-attachments/assets/3005c379-a49a-4cd8-8d90-65406b186141"
/>
- Closing a notebook tab with unsaved changes will show a confirmation
dialog
  - Except if the new notebook has no content (no changes)
<img width="375" height="218" alt="image"
src="https://github.com/user-attachments/assets/6ad10779-6415-4c55-bb4f-61d938e744c9"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Explorer chat, query, and notebook tabs now begin as previews and
become permanent when edited or saved.
* Added unsaved-change indicators and close confirmation for edited
notebook tabs.
  * Confirmed closure of edited notebooks now discards unsaved changes.
* **Bug Fixes**
  * Improved restoration and persistence of Explorer drafts.
  * Notebook saves now reflect the latest edits and tab state.
* Prevented stale save responses from incorrectly marking newer edits as
saved.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 14:35:22 +08:00
Joshen Lim 4dc973048d Add confirmation modal when running notebook if notebook contains query cells that aren't read only (#49376)
## Context

Adds a confirmation modal when hitting "run notebook" if the notebook
contains any query cells that involve any sort of mutation (insert,
update, alter, etc, etc). Also gives users the option to run the
notebook's read only cells as an alternative.

<img width="432" height="355" alt="image"
src="https://github.com/user-attachments/assets/0413a3ad-5419-4c83-8bf3-976bfa683b9a"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added confirmation prompts before running queries that may modify data
or database structure.
* Prompts identify potentially mutating notebook queries and allow
running read-only cells instead.
* Query execution now includes checks for destructive operations and
missing row-level security, with optional automatic setup.
* Notebook runs use the latest saved and unsaved SQL and reliably reset
execution status.

* **Bug Fixes**
* Improved notebook layout behavior so content shrinks correctly within
flexible sections.

* **Tests**
* Expanded coverage for mutation detection, comments, multiple
statements, live SQL, and cell filtering.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 14:15:56 +08:00
claude[bot] 8ec45b23dc chore(studio): remove dead unified logs banner telemetry and storage key (#49454) 2026-08-24 03:57:42 +00:00
Danny White 34454037d3 clean up docs admonition structure (#48669)
## What kind of change does this PR introduce?

Docs update. Resolves DEPR-634.

Stacked on #48664. The linter package and CI revision pins will be
updated after
[supa-mdx-lint#121](https://github.com/supabase-community/supa-mdx-lint/pull/121)
merges and is released.

## What is the current behavior?

Admonition body content can contain structural headings, which inherit
prose spacing and produce awkward callout layouts. Standalone Docs
actions are also rendered as ordinary body content in two places.

| Before |
| --- |
| <img width="1264" height="840" alt="70168"
src="https://github.com/user-attachments/assets/00aa7620-a6b4-452c-971f-b3ce2eda0e8c"
/> |
| _Recent violation with Markdown header in `children`. Notice the big
gap up top._ |

## What is the new behavior?

- Documents that admonition titles belong in the `title` prop,
standalone calls to action belong in `actions`, and document sections
belong outside admonitions.
- Configures heading-inside-admonition violations as errors for the
forthcoming linter release.
- Moves the UI-library and wrapper dashboard buttons into the existing
`actions` slot without changing the shared component.

Validated with the forthcoming linter across all 810 Docs sources, Docs
type-checking, targeted ESLint and Prettier checks, and desktop/mobile
rendering.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified admonition guidelines for optional titles, headings, rich
content, and standalone calls to action.
* Improved guidance on when contextual links and interactive examples
belong in admonition content.

* **Style**
* Updated documentation call-to-action buttons to use the designated
actions area.

* **Quality Improvements**
* Added validation to prevent headings inside admonitions and maintain
consistent formatting.
  * Updated documentation linting to apply the latest validation rules.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-24 00:26:03 +00:00
Joshen Lim a18253f7c7 QueryEditor to have the same validations as per SQL editor (#49380)
## Context

Adds the same validations such as UPDATE without where clause, or
destructive query into the QueryEditor of explorer / notebooks. Kicks in
for both notebook cells and query tab

<img width="887" height="718" alt="image"
src="https://github.com/user-attachments/assets/27757d41-e5df-4473-9278-ec30ff2306ca"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added safety checks for potentially destructive database queries.
  - Queries may pause for confirmation before execution.
  - Added optional RLS statement handling during query execution.
  - Added warnings and cancellation support for pending query runs.
  - Added read-only mode to prevent SQL edits and proposal acceptance.

- **Bug Fixes**
  - SQL commits now use the current editor content.
  - Discarding a proposed query is handled directly and reliably.

- **Tests**
- Added coverage for query approval, cancellation, and RLS-enabled table
creation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-22 15:49:12 +08:00
Charis 233cbdc8e5 Restore notebook diff preview for completed updates (#49402)
## Summary

This is **PR 3 of 3** in the FE-4243 stack fixing "Notebook update
proposal shows 'unapplyable' error for already-completed updates."

- Consumes the `previous_content` field added by PR 2 (#49401) to
reconstruct diffs for already-applied notebook updates
- Restores the diff preview that PR 1 initially dropped — completed
updates now show the full before/after instead of a generic "Notebook
updated" message
- Uses the same diff derivation function called pre-approval,
guaranteeing the rendered diff matches what was shown during
confirmation
- Includes defensive fallback handling for older persisted chats (before
`previous_content` existed) and edge cases

**Depends on**: PR 2 (#49401) merging first — this PR consumes the
`previous_content` field from that server change.

Resolves FE-4243 

## Test plan

- ✅ 19/19 tests pass in NotebookProposalRenderer.test.tsx (2 confirmed
as real regressions)
- ✅ 118/118 tests pass in full AIAssistantPanel suite
- ✅ Typecheck: clean on modified files
- ✅ ESLint: zero errors/warnings on changed files  
- ✅ Lint ratchet: passes (some rules improved)
- ✅ New regression tests cover: delete_cell, insert_cell, missing
previous_content, and operations that no longer reconcile
- ✅ No notebook fetch in completed update tests (proves no redundant
re-fetching)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added visual previews showing notebook changes, including inserted and
deleted cells, when prior content is available.
  * Prevented duplicate cells from appearing in update previews.
* Retained a compact completion message when change details are
unavailable or inconsistent.
  * Ensured previews are shown only for the relevant notebook.

* **Tests**
* Added coverage for notebook update previews, deletion and insertion
diffs, duplicate prevention, notebook matching, and fallback behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 15:09:44 -04:00
Charis 8920439569 Expose previous notebook content in update_notebook (#49401)
## Summary
- Plumb pre-update notebook snapshot through `update_notebook` tool
response as `previous_content`
- Add sanitizers in `tool-sanitizer.ts` to strip snapshot before model
sees it
- Add client-side stripping in `prepareMessagesForAPI` to avoid
re-uploading snapshot on subsequent turns
- This is PR 2 of 3 fixing Linear issue FE-4243 (notebook update
proposal shows 'unapplyable' error for already-completed updates)
- Ships no visible behavior change on its own; enables PR 3 to restore
diff preview for completed updates

## Test plan
- [x] Unit tests: 80/80 passing across notebook-tools.test.ts,
tool-sanitizer.test.ts, generate-assistant-response.utils.test.ts,
message-utils.test.ts, and mock-tools.test.ts
- [x] Typecheck: clean for all changed files
- [x] ESLint: zero errors, lint:ratchet passes (exit 0)
- [x] Integration: previous_content is correctly populated with
pre-update notebook, stripped before model context, and stripped on
client-side re-upload

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Notebook updates now retain previous content for recovery and history.
- AI responses expose only the notebook’s ID and name, keeping previous
content out of model-visible data.

- **Tests**
- Added coverage for notebook update results, content sanitization, and
message preparation, including cases where previous content is absent or
preserved.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 14:58:32 -04:00
Daniel Guerra b2a216b617 feat(billing): Use the customer data endpoint to update billing emails (#49160)
## What kind of change does this PR introduce?

Change the update billing email component so it uses the update customer
endpoint instead of the update org endpoint. This allows users that have
the BILLING_WRITE permission to use the endpoint to update relevant
organization data, while keeping the restrictions of the update
organization endpoint that allow updating other values (e.g. the org
name).

This change requires an update in the Update Customer endpoint to
support billing email updates. Do not merge until that is deployed.

## What is the current behavior?

- Admins are not allowed to update the billing emails of an
organization.
- The update organization endpoint (`PATCH
/platform/organizations/{slug}/`) is used to update the billing email
details.

## What is the new behavior?

- Both admin and owners are allowed to update the billing email details.
- The update customer endpoint (`PUT
/platform/organizations/{slug}/customer`) is used to update the billing
email details.

### Additional Context

[Platform PR](https://github.com/supabase/platform/pull/37145), needs to
be deployed first.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Billing email settings now use customer profile information.
* Added support for updating primary and additional billing email
addresses.
* Billing customer details now display address and billing name
information.

* **Bug Fixes**
* Prevented unrelated billing profile fields from being overwritten
during updates.
* Billing forms now synchronize correctly when customer profile data
changes.
* Removed unnecessary organization name requirements from billing
profile updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 10:56:20 -06:00
kemal.earth 0218de559b fix(studio): validation scroll area bug in scoped pat (#49395)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

When trying to submit the scoped pat creation form a second time, after
expanding accordion in the `<ScrollArea />` the `scrollTo` was breaking
the height of the container. This PR fixes that.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Bug Fixes**
- Improved the missing-permissions warning when creating scoped access
tokens.
- The warning now scrolls into view after each invalid submission
attempt, using smooth scrolling when supported.
- Prevented repeated scrolling during unrelated form updates or
motion-preference changes.
- Selecting a permission or applying a non-empty preset clears the
warning state.
  - Improved accessibility by respecting reduced-motion preferences.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 17:32:59 +01:00
Charis c172195269 test(studio): add eval cases for list_databases-driven notebook creation (#49398)
## Summary
- Adds three eval cases exercising the behavior this stack wires up: a
happy path where the model calls `list_databases` before targeting a
named read replica, a guard against fabricating an identifier when the
user names a region/replica `list_databases` doesn't actually return,
and a guard against targeting a non-primary database when the user never
asked for one.

Part 6/6 (final) of the stack for FE-4225 (expose valid database
identifiers to the notebook AI agent). Stacked on #49334.

## Test plan
- [x] Ran all three cases against the real model; inspected transcripts
directly
- [x] Re-verified reworded `correctAnswer` text against real outputs via
the correctness evaluator
- [x] `pnpm --filter studio exec tsc --noEmit` passes
- [x] `prettier --check` passes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Added evaluation coverage for selecting the correct database replica
when creating notebooks.
  * Verified primary-database defaults when no database is specified.
* Added checks to prevent fabricated database identifiers when a
requested replica is unavailable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 12:12:55 -04:00
Charis 27ff49c145 Stop re-deriving notebook update diffs after completion (#49399)
## Summary

- Fixes false-negative "This update can't be applied" warning for
completed notebook updates (FE-4243)
- When `state='output-available'` (tool completed), skips notebook fetch
and diff derivation
- Renders compact "Notebook updated: {name}" instead of a phantom/failed
diff
- `UnapplyableNotebookUpdateNotice` now accepts and forwards
`footerAction` prop, preserving "Open notebook" link
- Different warning copy for terminal confirm states
(success/error/denied): "Preview unavailable / notebook has changed"
instead of "can't be applied"
- Preserves diff derivation for non-completed states
(output-denied/error)

This is PR 1 of a 3-PR stack; PRs 2-3 restore the full diff preview for
completed updates (requires server snapshot).

Towards FE-4243

## Test plan

- [x] All 15 tests in NotebookProposalRenderer.test.tsx pass
- [x] Typecheck clean
- [x] ESLint clean
- [x] Regression tests added: completed updates with missing target
cells (auto & manual approval)
- [x] Confirms denied/error states still derive against live content

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
  - Added clearer status handling for AI-generated notebook updates.
- Completed updates now show a confirmation with the notebook name when
available.
- Update actions and footer controls now adapt to the proposal’s current
state.

- **Bug Fixes**
- Improved messaging when notebook changes prevent an update preview
from being reconstructed.
- Preserved accurate previews for denied or failed updates using the
notebook’s latest content.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 12:05:52 -04:00
Gildas Garcia c7e8373bce Scoped PAT: Fix projects handling when user has more than 100 projects (#49393)
## Problem

Some users have more than 100 projects and our current UI has the
following issues:

1. The project selector only loads the first 100 making it impossible to
see more
2. The review step and the token permissions view only loads the first
100 so we may display invalid warnings about missing projects

However, we currently don't have an API route to fetch many projects by
their refs in a single call.

## Solution

1. Make sure we load more projects when scrolling down in the project
selector
2. When below 100 project, show the admonition for missing resources.
Anyone above for the time being won't see these message and we display
the project refs instead of their names

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Improved scoped access-token setup with paginated project loading and
an easier scrolling project selector.
- Organization and project access are now displayed as separate, clearer
access indicators.
- Access details show project information when available, with a
fallback reference when details cannot be loaded.

- **Bug Fixes**
- Updated resource warnings to better reflect deleted resources and
large project lists.
  - Improved multi-select list handling for more reliable interactions.
- Preserved the name of inaccessible organizations when displaying lost
access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 18:01:28 +02:00
Charis dd534d229b docs(studio): instruct the notebook agent to use list_databases (#49334)
## Summary
- Adds a bullet to `NOTEBOOKS_PROMPT` instructing the assistant to call
`list_databases` before setting a `database_cell`'s
`database_identifier`, mirroring the existing `list_tables`
schema-validation instruction immediately above it.

Part 5/6 of the stack for FE-4225 (expose valid database identifiers to
the notebook AI agent). Stacked on #49333. This is the last piece that
makes the assistant actually *use* the tool and schema field wired up
earlier in the stack, rather than just having them available.

## Test plan
- [x] `pnpm --filter studio exec tsc --noEmit` passes
- [x] `prettier --check` passes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved notebook database configuration by ensuring database
identifiers are selected from available databases.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 11:57:13 -04:00
Miranda LimonczenkoandClaude Opus 5 21fccb0ecd fix(www): name the /features page button controls (#49343)
Closes FE-4097


https://github.com/user-attachments/assets/bc7cad1a-763e-469f-8a3b-e4d23bed94d9

_See bottom left of screen for screen reader captions._

## Problem

Two controls in the shared `/features/[slug]` template have no
accessible name. Both live in the template, so both fire on all 79
feature pages.

* The feature list dropdown trigger contains only a `List` icon.
`button-name`, critical.
* The breadcrumb back chevron wraps only a `ChevronLeft`. `link-name`,
serious.

## Solution

* Name both with `sr-only` text, matching the sibling prev and next
controls in the same component and the theme switcher in the site
header.
* Label the product pill with its destination. It announced only
"vector", with no indication it filters the catalog. Not an axe finding,
since the product name already supplies a name. The label keeps the
visible word so it satisfies WCAG 2.5.3 Label in Name.
* Fix a stray `className="` inside the `iconClassName` string literal,
which dropped the icons' width class.
* Add `cursor-pointer` to `buttonClassName`. Tailwind 4 no longer sets a
pointer cursor on buttons, so the middle control behaved differently
from its two anchor siblings. This line belongs to FE-4227 and sits here
only to keep two open PRs off adjacent lines of the same file.

## Manual testing

1. Open
[/features/ai-integrations](https://zone-www-dot-com-git-www-features-chrome-access-1aef01-supabase.vercel.app/features/ai-integrations)
using a Screenreader.
2. Tab through the three round controls at top right. They announce
"Previous feature", "Browse all features", "Next feature". **Note:** The
order of the elements is strange; captured in a separate ticket.
3. Tab to the round back control at top left. It announces "Back to all
features".
4. Tab to the product pill beside it. It announces "All vector
features", and the visible word "vector" is unchanged.
5. Hover each of the three round controls. All show a pointer cursor.
6. Run axe on the page. `button-name` and `link-name` report zero
elements.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:48:04 -07:00
Miranda LimonczenkoandClaude Opus 5 61b2a18724 fix(docs): stop rendering empty troubleshooting error-code pills (#49344)
Closes DOCS-1281

## Problem

Two defects in the "Related error codes" list, both from the page
diverging from what `Troubleshooting.utils.ts` already does.

* **Empty pills.** `formatError` returns an empty string when an error
has neither an HTTP status code nor a code. The page renders the pill
anyway, giving a link with no text whose `href` ends in `errorCodes=`
with no value. So it is both an unnamed link and a pill filtering on
nothing.
* **Duplicate pills.** The same formatted code renders once per
underlying error object, so one entry shows seven identical "500
unexpected_failure" pills.

Measured on production, across the 59 entries that render the section:

| | Count |
| -- | -- |
| Entries with an empty pill | 23 |
| Empty pills | 33 |
| Entries with duplicate pills | 4 |
| Redundant pills | 9 |

The guard also evaluated to `0` rather than `false` for an empty array,
which React renders as a literal "0".

## Solution

* Derive the formatted codes once, drop the empties, and dedupe. An
entry whose every code formats empty no longer renders a heading and
rule with nothing under them.
* Call `formatError` once per code instead of twice per pill, and key on
the code now that codes are unique.
* Fix the same `0`-rendering guard on the keywords section.

`Troubleshooting.utils.ts` already filters on `error?.http_status_code
|| error?.code` at lines 69 and 150, and already dedupes by formatted
code at lines 72 to 79. This brings the page in line with the sidebar
and filter list rather than introducing a new pattern.

`formatError` itself is unchanged. It also produces grouping and sort
keys in `Troubleshooting.utils.ts` and `Troubleshooting.ui.tsx`, so
changing its return contract would reach well beyond this fix.

## Manual testing

Compare each page against production, which still shows both defects.

1. Open [dashboard-errors-when-managing-users on
production](https://supabase.com/docs/guides/troubleshooting/dashboard-errors-when-managing-users-N1ls4A).
It shows 8 pills: seven identical "500 unexpected_failure" and one
empty.
2. Open [the same page on the
preview](https://docs-git-docs-troubleshooting-empty-error-pills-supabase.vercel.app/docs/guides/troubleshooting/dashboard-errors-when-managing-users-N1ls4A).
One "500 unexpected_failure" pill remains.
3. Open [prisma-error-management on
production](https://supabase.com/docs/guides/troubleshooting/prisma-error-management-Cm5P_o).
It shows 6 empty pills.
4. Open [the same page on the
preview](https://docs-git-docs-troubleshooting-empty-error-pills-supabase.vercel.app/docs/guides/troubleshooting/prisma-error-management-Cm5P_o).
The section is gone, because every code on that entry formats empty.
5. Run axe on either preview page. `link-name` reports zero elements.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved troubleshooting displays by formatting and deduplicating
error values.
  * Removed empty or invalid error entries from the rendered results.
* Related error-code links now appear only when valid error codes are
available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:44:28 -07:00
Charis ee59d28240 fix(studio): reject unknown database_identifier before writing a notebook (#49333)
## Summary
- `create_notebook`/`update_notebook` now validate every
`database_cell`'s `database_identifier` against the project's real
database list (`getReadReplicas`) before writing, throwing an
assistant-actionable `NotebookToolError` (same pattern as the existing
`expected_updated_at` mismatch check) when it doesn't match.
- Only fetches the database list when a cell actually sets
`database_identifier` — no added cost for the common case.
- `update_notebook` validates only the cells its own operations
introduce (`insert_cell`/`replace_cell`), not the whole resulting
notebook — otherwise an unrelated, untouched pre-existing cell whose
replica was removed after the fact would block updates that never touch
it.

Part 4/6 of the stack for FE-4225 (expose valid database identifiers to
the notebook AI agent). Stacked on #49332. This closes the gap that PR 3
reopened: a model can no longer invent an identifier that silently
breaks a cell — it now gets a retryable error naming `list_databases`
(added in #49328) as the way to find a real one.

## Test plan
- [x] `create_notebook`/`update_notebook` reject an unknown
`database_identifier` with `NotebookToolError` + `exposeToAssistant:
true`
- [x] Both succeed when the identifier matches a real database
- [x] `create_notebook` never calls the databases endpoint when no cell
sets `database_identifier`
- [x] `update_notebook` succeeds without validating or fetching
databases when no operation introduces a database_cell, even if an
untouched existing cell carries a now-invalid identifier
- [x] `pnpm --filter studio exec tsc --noEmit` passes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a database-listing tool that provides database identifiers and
metadata, including primary-database status.
  * Database results now return only the relevant fields.

* **Bug Fixes**
* Added validation to prevent notebooks from referencing unknown
databases.
* Create and update actions now provide clear errors for invalid
database identifiers.
* Updates validate newly added or replaced cells while preserving
existing, untouched cells.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 11:05:31 -04:00
Charis 7b04fc7d09 revert(studio): reinstate database_identifier on the agent notebook schema (#49332)
## Summary
- Reverts #49326's temporary mitigation, which stripped
`database_identifier` from the agent-facing notebook cell schema
(`agentCellSchema`) because the assistant had no legitimate source of
truth for valid read-replica identifiers.
- The previous PR in this stack (#49328) added the `list_databases`
tool, so that source of truth now exists — `database_cell`s can carry
`database_identifier` again.

Part 3/6 of the stack for FE-4225 (expose valid database identifiers to
the notebook AI agent). Stacked on #49328.

## Test plan
- [x] Existing schema/preview tests (reverted alongside the mitigation)
pass
- [x] `pnpm --filter studio exec tsc --noEmit` passes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* AI-generated notebook database cells now support database identifiers.
* Notebook previews display the associated database source, including
transitions between primary and replica databases.

* **Bug Fixes**
* Improved database metadata handling to preserve identifiers when
updating notebook cells.
* Database information is now shown only when available, preventing
inaccurate or missing metadata displays.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 10:36:20 -04:00
Charis 144c2eadb6 fix(studio): expose notebook diff validation errors for auto-retry (#49331)
## Summary

- Automatically deny notebook tool proposals with specific error reasons
when client-side diff validation fails (e.g., unknown cell ID)
- Enables the AI Assistant to see the actual failure reason and retry
automatically instead of requiring manual user intervention
- Exposes the same `describeNotebookOperationError` helper used
server-side for consistent error messaging
- Adds `denyWithReason()` to manual tool approval handlers for flexible
denial messaging

## Test plan

- Run `pnpm --filter studio exec vitest run
apps/studio/components/ui/AIAssistantPanel/Confirm.utils.test.ts` to
verify denyWithReason tests
- Run `pnpm --filter studio exec vitest run
apps/studio/components/ui/AIAssistantPanel/NotebookProposalRenderer.test.tsx`
to verify auto-deny behavior, Skip fallback, and no re-fire after
approval is already handled
- Confirm no regressions in existing notebook tool approval flows

## Manual testing

- Get assistant to create a notebook.
- Open the notebook and manually delete a cell yourself.
- Ask the assistant to delete the cell you just deleted.
- Assistant should automatically recover from the error.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **New Features**
* Notebook proposals now display clear success, error, and denial
outcomes.
* Tool errors for SQL, Edge Functions, and notebooks now appear in their
respective result views.
  * Output links are supported in notebook proposal results.
* Approval panels remain visible after completed actions with
standardized status messages.

* **Bug Fixes**
* Specific denial reasons are preserved instead of showing a generic
skipped message.
* Unapplyable notebook updates are automatically denied with an
explanation.
  * Prevented duplicate denial responses after approval decisions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 10:35:56 -04:00
Ali Waseem d8563cfc6a fix(studio): require full authentication for the support form (#49318)
The support form was exempted from the highest AAL check (since the
original MFA rollout in #16813) so that users stuck on the MFA challenge
could still file a ticket. The platform API now rejects AAL1 sessions
with `403 Insufficient AAL: MFA required`, so for those users the form
is simply broken — it renders an error toast and the submit would fail
too.

This requires AAL2 on `/support/new`, so an AAL1 session gets redirected
to the MFA challenge and returns to the form afterwards, and removes the
links to the support form from the MFA screen. A dedicated flow for
users who can't get past MFA to reach us is being worked on separately
and should be out soon!

Fixes FE-4218

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added an “Email support” action for multi-factor authentication
issues, with a prefilled subject line.
- Provided clearer guidance when authentication factors cannot be
retrieved.

- **Bug Fixes**
- Improved authentication error handling based on the session’s
assurance level.
- Reduced confusing permission and error messages for lower-assurance
sessions.
- Updated support page access to use standard authentication behavior
for a more consistent sign-in experience.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 08:27:37 -06:00
Tanya Bouman eabe06be5b typo fix: placehoder -> placeholder (#43451) 2026-08-21 13:38:24 +00:00
Charis 0f730de9e0 feat(studio): add list_databases tool for the AI assistant (#49328)
## Summary
- Adds a `list_databases` tool to the notebook AI tools
(`getNotebookTools`), returning `{ identifier, is_primary, region,
status }` for the project's primary and any read replicas, via
`getReadReplicas`.
- Registers `list_databases` in `tool-filter.ts` (opt-in validation
schema + SCHEMA category), and adds a mock fixture in `mock-tools.ts`
for evals.

Part 2/6 of the stack for FE-4225 (expose valid database identifiers to
the notebook AI agent). Stacked on #49327. A later PR in the stack
reinstates `database_identifier` on the agent-facing notebook schema and
requires the agent to call this tool first.

## Test plan
- [x] New test coverage in `notebook-tools.test.ts` for
`list_databases`, including `is_primary` computation
- [x] Existing exact-tool-set assertion updated
- [x] `pnpm --filter studio exec tsc --noEmit` passes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
  * Added an AI notebook tool for listing a project’s databases.
* Results include each database’s identifier, region, status, and
whether it is the primary database.
  * Supports projects with read replicas.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 09:28:56 -04:00
Andrey A. 22e2370b35 docs(self-hosted): add poolers how-to guide (#49303) 2026-08-21 07:10:18 -06:00
Charis 7a2e237892 Add update_notebook evals; fix prompt gaps they surfaced (#49324)
## Summary
- Add `update_notebook` eval cases (insert/replace/delete/move, a
combined delete+insert, and guard/safety cases) mirroring the existing
`create_notebook` cases, targeting the notebooks already seeded in the
mock tool harness.
- Fix two behavior gaps in `NOTEBOOKS_PROMPT`/`LIMITATIONS_PROMPT` that
these cases surfaced when run live: the assistant asking the user for a
notebook id instead of resolving it via `list_notebooks`, and the
destructive-operations warning rule not being connected to SQL written
into notebook cells.
- Soften the destructive-SQL case's `correctAnswer` to match
`update_notebook`'s real approval-gated behavior — a warning
accompanying the reported change is acceptable, not only one strictly
preceding the tool call.

## Test plan
- [x] `pnpm run typecheck` (apps/studio) — clean
- [x] `pnpm exec prettier --check` on both changed files — clean
- [x] `evals/scorer.test.ts`, `evals/transcript.test.ts`,
`evals/trace-utils.test.ts` — 21/21 pass
- [x] Ran the new eval cases live against OpenAI (bypassing the
Braintrust proxy) via Braintrust MCP; confirmed via trace inspection
that the prompt fix resolved the id-resolution gap (Tool Usage 0% → 100%
across 3 trials) and that the assistant now includes an explicit
irreversibility warning when destructive SQL is written into a notebook
cell

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Improved notebook creation and editing support across SQL, query,
chart, and time-range cells.
- Added clearer handling for saved notebooks, recurring requests, and
one-time SQL execution.
  - Enhanced validation for database cells and notebook configuration.

- **Bug Fixes**
- Improved safeguards and warnings for destructive queries, including
saved notebook queries.
  - Better handling of missing tables and notebooks.
  - More precise notebook cell updates and tool usage validation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 08:39:46 -04:00
Barry Roodt 75a722c4e4 chore(studio): update self-hosted MCP server to 0.11.0 (#49379)
## Summary

- Update `apps/studio` to `@supabase/mcp-server-supabase` `^0.11.0` and
add its required `@modelcontextprotocol/server` `^2.0.0` peer.
- Keep `@modelcontextprotocol/sdk` `^1.29.0` for Studio's existing
transports. `@supabase/mcp-utils` resolves transitively to `0.7.0`, so
it remains indirect.


[AI-1107](https://linear.app/supabase/issue/AI-1107/2b-update-self-hosted-remote-mcp-server)

## Testing

- Five focused MCP test files passed, 47 tests total.
- Studio production build passed with `SKIP_ASSET_UPLOAD=1`.
- A real `POST` initialize request to the built self-hosted `/api/mcp`
endpoint returned HTTP 200 with `serverInfo.version` `0.11.0`.
- Studio typecheck still reports one pre-existing error in unchanged
`packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx:20`:
`string` is not assignable to `StaticImageData`.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
  - Improved compatibility with the latest MCP server capabilities.
- Refreshed the Supabase MCP integration for a more up-to-date
experience.
- Verified that the available MCP tools remain consistent after the
update.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 14:22:55 +02:00
kemal.earth 31497ba127 feat(studio): add permission presets to scoped pat creation form (#49381)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This adds a quick presets selector to scoped pat permissions. No access,
read-only and full access.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added permission presets for scoped access tokens: No access,
Read-only, and Full access.
  * Added a selector to quickly configure permissions across resources.
  * Displays “Custom” when individual permissions differ from a preset.
  * Shows warnings and guidance for high-risk full-access permissions.
* Automatically uses read-only access for resources that do not support
write permissions.

* **Tests**
* Added coverage for preset selection, application, warnings, ordering,
and custom configurations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 11:12:37 +01:00
Saxon Fletcher f0cb024139 feat(studio): preserve assistant tool previews after completion (#49352)
<img width="2337" height="1005" alt="image"
src="https://github.com/user-attachments/assets/08298850-715e-4b31-866d-186d73266305"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Assistant execution feedback improvement.

## Stack context

Builds on #49351.

## What is the current behavior?

When an Assistant query, notebook, Edge Function deployment, or log
query completes or fails, the preview can be replaced by a terse text
result.

## What is the new behavior?

- Retains the original query, log-query, notebook, and Edge Function
preview after the tool resolves.
- Replaces confirmation actions with a success, error, or skipped footer
state.
- Keeps the Open notebook action available after a successful notebook
creation or update.

## To test

1. Ask the Assistant to run a valid SQL query, approve it, and confirm
the query cell remains visible with a Query executed footer.
2. Trigger a failed SQL or log query and confirm the original preview
remains visible with an error footer and error result.
3. Ask the Assistant to create or update a notebook, approve it, and
confirm the preview remains visible with a completed footer and Open
notebook action.
4. Skip any approval and confirm the preview remains visible with a
skipped footer instead of being replaced by plain text.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Assistant actions now show clear success, error, or denied-status
messages.
* Completed actions retain relevant previews and provide follow-up
actions, such as opening a created notebook.
* SQL, log-query, Edge Function, and notebook errors appear within their
respective result views.
* Status updates are announced more clearly as actions progress and
complete.

* **Bug Fixes**
* Preserved submitted tool details when execution fails or original
input is unavailable.
* Improved handling of failed and denied operations across assistant
workflows.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 10:12:00 +00:00
Joshen Lim 502e0f9b09 Add isReadOnly flag into QueryEditor component (#49378)
## Context

`QueryEditor` component is being used in the Assistant Chat currently
and needs to be read only in this context specifically
<img width="1251" height="564" alt="image"
src="https://github.com/user-attachments/assets/97d7ce9c-59bc-4acb-a105-e70361b6729e"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Enhancements**
* Added read-only support for query editors, allowing query content to
be viewed without making changes.
* Assistant-generated queries are now displayed in a non-editable mode
to prevent accidental modifications.
* Read-only editors also prevent applying suggested SQL changes, helping
preserve the original query while it is being reviewed.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 17:47:57 +08:00
claude[bot]andClaude 12a8e31fa6 chore(studio): render Sign in with ChatGPT unconditionally (#49375)
<!-- ccr-slack-attribution -->
_Requested by **Ivan Vasilov** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1787296019236949?thread_ts=1787296019.236949&cid=C0161K73J1J)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore / feature-flag cleanup.

## What is the current behavior?

The "Sign in with ChatGPT" button on `/sign-in` and `/sign-up` sits
behind three gates in `useEnabledIdentityProviders`:

1. the static `dashboard_auth:sign_in_with_chatgpt` feature flag, AND
2. either the `ShowSignInWithChatGptButton` ConfigCat flag, OR
3. the `SIGN_IN_CHATGPT_ENABLED` (`siwc-enabled`) localStorage opt-in,
flipped by a shareable `?siwc-enabled=1` link via
`useSiwcQueryParamOptIn`.

The ConfigCat flag resolves client-side, so on a fresh load the button
is absent for the first render and appears once the flag comes back.
That pushes the rest of the sign-in options down and produces a visible
layout shift on the sign-in page.

## What is the new behavior?

ChatGPT is gated only by its static
`dashboard_auth:sign_in_with_chatgpt` feature flag, which is resolved
synchronously from `enabled-features.json`. The button renders on the
first paint, with no async re-layout.

Removed:

- the `useFlag('ShowSignInWithChatGptButton')` call and the
`chatgptLocalStorageEnabled || chatGptConfigCatFlagEnabled` branch in
`apps/studio/hooks/misc/useEnabledIdentityProviders.ts`
- `LOCAL_STORAGE_KEYS.SIGN_IN_CHATGPT_ENABLED` and its
`LOCAL_STORAGE_KEYS_ALLOWLIST` entry in
`packages/common/constants/local-storage.ts`
- `apps/studio/hooks/misc/useSiwcQueryParamOptIn.ts` and its callers in
`pages/sign-in.tsx` / `pages/sign-up.tsx` — its only job was writing
that localStorage flag
- the tests that covered the two removed rollout gates

The static `dashboard_auth:sign_in_with_chatgpt` kill switch is
untouched.

## Additional context

The `ShowSignInWithChatGptButton` ConfigCat flag is reported as 100%
enabled (per Joshen Lim in the linked thread). The repo contains no
default value, allowlist, or env gate for it — the live value lives only
in ConfigCat, so that number is not verifiable from here. Once this
merges the flag is unreferenced and should be **archived in ConfigCat by
a human**; nothing in ConfigCat was changed as part of this PR.

Verification notes: `packages/common` typechecks clean (`tsc --noEmit`)
and all touched files pass the repo's Prettier config. Studio's
`typecheck`, `lint`, and `vitest` could not be run here — `pnpm install`
fails in this environment because `npm.jsr.io` (needed for studio's
`@std/path` dependency) is not reachable through the network allowlist,
so `apps/studio/node_modules` was never installed. CI should be treated
as the first real run of those checks.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01M21SPvwf6FSthomX4Lj3ZC)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-21 11:32:22 +02:00
Filipe CabaçoandIvan Vasilov 29e47821f5 fix(realtime): add pg changes pool to realtime settings (#49256)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature — adds a new Realtime setting to configure the Postgres Changes
connection pool size.

## What is the current behavior?

The Realtime settings page only exposes the connection pool used for
Realtime Authorization (`connection_pool`). The pool that Realtime uses
for Postgres Changes is not surfaced anywhere in the dashboard, so
projects that need to tune it have no self-serve way to do so — the only
option is to contact support.

## What is the new behavior?

The Realtime settings page now includes a **Postgres Changes connection
pool size** field:

- Reads `postgres_changes_pool` from the project's Realtime config,
falling back to a default of `2` when no override is stored.
- Validates input from `1` through `20` (`MAX_POSTGRES_CHANGES_POOL`),
and submits the value as a number in the config `PATCH` payload.
- Docs (`apps/docs/content/guides/realtime/settings.mdx`) are expanded
with sizing guidance for both connection pools, plus limits,
resource-usage notes, and the operational error codes to look for.

<img width="1160" height="166" alt="Screenshot 2026-08-19 at 13 59 04"
src="https://github.com/user-attachments/assets/fd3ee29e-e9bf-438b-970f-8008ec57020f"
/>

## Additional context

The named `RealtimeConfigResponse` / `UpdateRealtimeConfigBody` schemas
in the generated `api-types` package do not carry
`postgres_changes_pool` yet, so both the query and mutation types extend
the generated schema locally — the same pattern already used elsewhere
in `apps/studio/data/`. Once the platform OpenAPI spec ships the field
and `api-types` is regenerated, those two local intersections can be
dropped.

Covered by component tests in `RealtimeSettings.test.tsx` for both the
fetch and save paths.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a Realtime setting to configure the Postgres Changes connection
pool size.
  * Connection pools support 1–20 connections, with a default of 2.
  * Saving the setting now applies the configured value correctly.

* **Documentation**
* Expanded Realtime Settings guidance with configuration limits,
resource usage, channel access, payload and presence limits, plan
ceilings, spend-cap restrictions, and operational error codes.
* Added guidance for sizing authorization and Postgres Changes
connection pools.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-08-21 09:08:28 +01:00
Alaister YoungandAlaister Young aa3643f39d fix(studio): restrict geolocated default region to provider regions (#49141)
Follow-up to #49131. For `AWS_NIMBUS` orgs, the new-project form's
Region trigger could show a region that wasn't in the dropdown at all
(e.g. "Southeast Asia (Singapore)" while the list only offered "East US
(North Virginia)"). The geolocation-based default region
(`useDefaultRegionQuery`) picked the nearest region from **all** AWS
regions and seeded it into `dbRegion` unvalidated, ignoring the
provider's restricted region list.

**Changed:**

- `getDefaultRegionOption` now computes the nearest region only over the
provider's available regions (new `getDefaultRegionCandidateKeys`
helper). The flag-based restricted pool (`defaultRegionRestrictedPool`)
narrows within that set and is ignored if the intersection would be
empty.
- The form's default-region selection is extracted into
`resolveDefaultDbRegion` (`ProjectCreation.utils.ts`): High Availability
region first, then the recommended smart region, then the geolocated
default — used only when the provider actually offers that region —
falling back to the provider's static default.
- `getAvailableRegions` takes an injectable `environment` param (same
pattern as `getHighAvailabilityRegionCode`) so the prod-only Nimbus
region list is unit-testable.

**Added:**

- Unit tests for `getDefaultRegionCandidateKeys` (provider clamping
incl. Nimbus on prod, restricted-pool intersection, empty-intersection
fallback), `getAvailableRegions` across environments, and
`resolveDefaultDbRegion` (branch priority plus the fallback when the
geolocated region isn't offered).

## To test

- Emulate a Nimbus org locally by setting `"infra:cloud_providers":
["AWS_NIMBUS"]` in
`apps/studio/hooks/custom-content/custom-content.json`, then open the
new-project form: the Region trigger must show the same region the
dropdown offers (locally that's only Southeast Asia (Singapore)). To
reproduce the original mismatch path, stub
`https://www.cloudflare.com/cdn-cgi/trace` to return `loc=US` — the
trigger should still be clamped to the provider's region rather than
showing a US region
- Block or fail the Cloudflare trace request: the trigger should fall
back to the provider's static default region, not sit blank or loading
- Restore the normal provider list: the smart-region flow ("General
regions" + "Specific regions" with Recommended badges) is unaffected —
the geolocation request doesn't even fire on that path — and toggling
High Availability still transitions the region list cleanly

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Summary by CodeRabbit

- **Bug Fixes**
- Region suggestions now respect the selected cloud provider and
deployment environment.
- Project creation avoids unavailable geolocated regions and falls back
to a supported provider default.
- Restricted region pools now fall back reliably to available provider
regions.
- AWS Nimbus selection reflects the active environment while preserving
high-availability and smart-region behavior.

- **Tests**
- Added coverage for provider-specific, environment-specific,
restricted, and fallback region selection scenarios.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-08-21 15:51:03 +08:00
Joshen Lim 4778ae66e0 Flush notebook cache in valtio and react query whenever closing notebook tab (#49369)
## Context

Opting to flush the notebook cache within the Valtio store
(nootebook-store) and react query whenever we close the notebook tab in
the explorer.

Mainly to ensure that whenever we re-open the notebook again, the
notebook content isn't stale and we refetch the notebook content from
the API

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Closing a saved notebook tab now removes it from the session and
clears its cached content.
  - Notebooks with unsaved changes are preserved when their tabs close.

- **Tests**
  - Added coverage for saved and unsaved notebook tab cleanup behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 15:27:53 +08:00
86105ca5ec feat(studio): align assistant message parts (#49351)
<img width="2252" height="1228" alt="image"
src="https://github.com/user-attachments/assets/5c1165ae-cb65-4495-97dd-427b30ceaefc"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Studio UI improvement.

## Stack context

Builds on #49350.

## What is the current behavior?

The Assistant conversation uses one outer width constraint. This leaves
query and notebook previews too narrow, separates consecutive generic
tool rows, and leaves message actions aligned to the far left.

## What is the new behavior?

- Gives Assistant query cells and notebook previews a `max-w-6xl`
container.
- Keeps text and other regular message parts at their existing
`max-w-3xl` width.
- Keeps consecutive generic tool rows such as Reasoned and Ran
load_knowledge compact.
- Aligns message action rows with regular message content.

## To test

1. In the Assistant, produce a response containing text plus a SQL query
or notebook preview. Confirm the preview is wide while regular text
remains at the normal width.
2. Produce a response that reasons and runs consecutive non-preview
tools. Confirm those rows remain close together with their separators.
3. Hover an Assistant response and confirm copy, rating, and branch
actions align with the regular message content.
4. Hover a user message and confirm edit and delete actions use the same
alignment.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Style**
- Improved AI Assistant message layout with centered, consistent content
widths.
- Expanded notebooks, SQL results, and query-related content where
additional space is helpful.
- Improved alignment and spacing for actions, tool outputs, loading
states, errors, and disclaimers.
  - Improved query editor visibility when switching between cells.
  - Loading indicators now respect reduced-motion preferences.

- **Tests**
- Added coverage for message layouts, tool grouping, and notebook
preview sizing.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Saxon Fletcher <SaxonF@users.noreply.github.com>
2026-08-21 15:09:05 +08:00
Pamela Chia f208743432 fix(www): changelog md negotiation slug-set gate (#49357)
Bare-URL `Accept: text/markdown` negotiation never fires on changelog
entries authored after the GitHub-discussions backfill: the middleware
gate `/^changelog\/\d+/` only matches legacy numeric slugs (from
`legacy_gh_discussion` frontmatter), so agents that signal markdown via
Accept get HTML on every new entry. I found this in the independent
review round on #48475; pre-existing, not introduced there.

**Changed:**
- **Non-legacy entries negotiate markdown**: `generateMdContent.mjs` now
lists `public/changelog/*.md` (written moments earlier by
`generateStaticContent.mjs` in the same `content:build:core` chain) and
emits a `CHANGELOG_PAGES` set into the generated module; the middleware
regex becomes a set lookup, so negotiation coverage derives from the
exact static files served and can't drift from what's published.
- **Unknown and deep changelog paths stop negotiating**: the old regex
prefix-matched paths like `changelog/100/bar` and nonexistent numeric
slugs, rewriting them to missing `.md` files (404 under a markdown
Accept); they now pass through to the dynamic route's canonicalizing
308/404.
- **Build guard**: zero collected changelog slugs on Vercel fails the
build (today a zero-entry changelog fetch ships empty output with a
green build), and a shape assertion fails the build if collected slugs
ever lose the `changelog/` prefix the middleware matches on. Locally
without `CHANGELOG_SYNC_APP_*` secrets it warns and changelog
negotiation is off, matching the absent content.
- **`/changelog` index gated the same way**: the index slug is emitted
into the set only when `public/changelog.md` was generated, replacing
the hardcoded `slug === 'changelog'` branch; locally without secrets the
index no longer rewrites to a nonexistent file.

**Note:** script order in `content:build:core` is load-bearing (static
content generation must precede md content generation); the Vercel guard
turns a reorder into a loud build failure instead of a silent empty
gate.

## To test
Tested on the Vercel preview (`zone-www-dot-com` deployment of head
`f451da3`):
- [x] `curl -sI -H "Accept: text/markdown" <preview>/changelog` and
`curl -sI <preview>/changelog.md`: got 200 `text/markdown` (index via
the generated gate)
- [x] `curl -sI -H "Accept: text/markdown"
<preview>/changelog/pipelines`: got 200 `text/markdown` (prod today
returns `text/html`)
- [x] Same curl against the legacy numeric slug
`48235-migration-of-...`: got 200 `text/markdown` (no regression)
- [x] `curl -sI -H "Accept: application/json"
<preview>/changelog/pipelines`: got 406 (prod today returns 200 HTML)
- [x] Explicit `.md` fetches for both slug shapes
(`/changelog/pipelines.md`, `/changelog/48235-....md`): got 200
`text/markdown`
- [x] `curl -sI -H "Accept: text/markdown"
<preview>/changelog/does-not-exist-xyz`: got a 404 HTML passthrough from
the dynamic route, not a 406
- [x] `pnpm test middleware.test.ts` in `apps/www` at head: 41/41 pass
(36 pre-existing + 5 new). No CI job runs the www vitest suite, so this
local run is the only oracle for the new tests.

## Linear
- fixes GROWTH-1062


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Improved changelog page handling, including markdown versions of
published entries.
- Added content negotiation for supported changelog formats, with clear
responses for unsupported requests.
- **Bug Fixes**
- Prevented unpublished numeric-prefix pages from being treated as
published.
  - Fixed deep links under published changelog entries.
- **Reliability**
- Changelog availability is now detected automatically, with improved
validation during content generation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 15:01:50 +08:00
Joshen Lim 1d47a3190b Debounce notebook search (#49368)
## Context

Sets up debouncing for notebooks search in the explorer so that we're
not hammering the API when searching
<img width="281" height="178" alt="image"
src="https://github.com/user-attachments/assets/1fa2d633-7f7f-4891-87cc-aa90a5062bb7"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved notebook search responsiveness by delaying searches until 500
ms after typing stops.
  * Empty searches now update immediately.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 14:57:07 +08:00
Saxon Fletcher d93defe1e0 feat(studio): refine notebook query cell layout (#49350)
<img width="2326" height="1257" alt="image"
src="https://github.com/user-attachments/assets/d0f63793-ff58-4f48-971f-0622d375b3c7"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Studio UI improvement.

## What is the current behavior?

Explorer notebook query cells can extend beyond the intended reading
width, and saved notebooks open with SQL code expanded.

## What is the new behavior?

- Caps Explorer notebook query cells at `max-w-6xl`.
- Hides SQL code by default in saved notebooks.
- Keeps SQL visible by default for new notebooks.

## To test

1. Open a saved Explorer notebook with query cells. Confirm each cell is
capped at the wider notebook width and its SQL editor is initially
collapsed.
2. Expand a saved query cell and confirm the existing SQL and result
remain available.
3. Create a new notebook, add a query cell, and confirm its SQL editor
is initially visible.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added controls to show or hide SQL for individual query cells.
* Query visibility is preserved when switching notebook tabs or
reopening them.
* New notebooks display SQL by default, while saved notebooks can hide
SQL editors.
  * Expanded the query editor width for improved readability.

* **Bug Fixes**
* Prevented visibility settings from affecting notebook save status or
unrelated cells.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 14:27:51 +08:00
Charis da1a3ae948 fix(studio): thread auth headers through getReadReplicas (#49327)
## Summary
- `getReadReplicas` now accepts an optional `headers?: HeadersInit`
param, forwarded to the underlying `get()` call — mirrors
`getContentById`/`getNotebook`.
- Pure plumbing: no behavior change for existing (browser/cookie-auth)
callers.

Part 1/6 of the stack for FE-4225 (expose valid database identifiers to
the notebook AI agent). This PR lets a server-side AI tool call
`getReadReplicas` with the request's bearer token in a later PR in the
stack.

## Test plan
- [x] `getReadReplicas` unit test verifying the header is forwarded on
the outgoing request
- [x] `pnpm --filter studio exec tsc --noEmit` passes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved read-replica data requests by forwarding authorization
headers correctly.
* Maintained existing request cancellation and error-handling behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 11:24:03 +08:00
Joshen LimandCharis 9a3500aad2 Set up infinite loading for notebooks (#49321)
## Context

Sets up infinite loading for notebooks with the `InfiniteListDefault`
component

Also adds the notebook and chats count on the explorer home nav
<img width="275" height="137" alt="image"
src="https://github.com/user-attachments/assets/c3f16e8f-f520-4107-a188-43b1abcca043"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Explorer navigation now displays accurate notebook and chat counts.
* Notebook lists support infinite scrolling, loading indicators, and
improved active-state styling.
  * Notebook navigation remains available as additional items load.

* **Bug Fixes**
* Corrected default markdown cell formatting by removing unintended
leading spaces from headings and notes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
2026-08-21 11:15:26 +08:00
Joshen Lim 6779bf52e1 Joshenlim/fe 4208 explorer templates need to be properly set up (#49322)
## Context

Set up Explorer templates properly for notebooks and chat. Tried (with
the help of Claude) to come up with templates that are generic enough
for most projects to sort of pick up and use, or even pick up to study
how notebooks are meant to be used.

Feel free to play around on the preview to check out the content of each
template! 🙂

<img width="768" height="232" alt="image"
src="https://github.com/user-attachments/assets/590893c4-9772-437d-980f-05ea62ffef81"
/>

<img width="1918" height="955" alt="image"
src="https://github.com/user-attachments/assets/2114e73e-dc44-403d-a998-e87c8d328516"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added ready-to-use chat templates for sample data, security policies,
and notebook creation.
* Added notebook templates for database health, user growth, and error
investigation workflows.
* Explorer cards now dynamically create chats and notebooks from
selected templates.
* Templates include guided prompts, queries, logs, charts, and relevant
notebook content.
* **Bug Fixes**
* Improved generated log cell identifiers for more reliable notebook
creation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 11:06:20 +08:00