mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
45bb7c30ceaa2cd5c8627ea18fb5d2dd689a625c
2128
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
45bb7c30ce |
docs(database): fix RLS guide copy and two SQL examples (#49015)
Stacked on #49011. Base is `docs/rls-revision`, so review that one first. ## Problem An audit of the Row Level Security guide against `apps/docs/CONTRIBUTING.md` and `WORD_LIST.md` turned up 4 lint warnings and 3 things that are wrong rather than just untidy. - Two SQL examples contradict the guide's own advice. The own-profile `SELECT` policy has no `TO` clause. The `security definer` example has no `set search_path`. - `## Bypassing Row Level Security` says Service Keys bypass RLS, then a note says Supabase adheres to the signed-in user's policy anyway. The condition that separates the two is never stated. - `#using-functions` is linked twice from the RBAC guide and has never existed on the RLS page. ## Solution Copy and correctness only. No section moves, no heading renames. - Replace the italic emphasis on `never` with bold. CONTRIBUTING permits **bold** for a term the reader must not miss, not italics for general emphasis. The matching fix for `must` lives in #49011, which rewrites that line anyway. - Drop marketing language from the opener, the Supabase intro, and the policies and performance leads. Removes the idiom "get the hang of them" and the filler `just`. - Replace `we` with second person in two places. - Scope the own-profile `SELECT` example with `to authenticated`. - Pin `search_path = ''` on the `security definer` example, schema-qualify its body to match, and state the requirement in prose. - State when a Service Key actually bypasses RLS. - Repoint the two RBAC links to `#use-security-definer-functions` and `#helper-functions`. `supa-mdx-lint` on the RLS guide goes from 4 warnings to 0. ## Manual testing 1. Open the [Row Level Security guide](https://docs-git-docs-rls-copy-fixes-supabase.vercel.app/docs/guides/database/postgres/row-level-security) on the preview. The own-profile SELECT example shows `to authenticated`, and the security definer example shows `set search_path = ''`. 2. Open the [RBAC guide](https://docs-git-docs-rls-copy-fixes-supabase.vercel.app/docs/guides/api/custom-claims-and-role-based-access-control-rbac) and select the "RLS helper functions" link near the end. It lands on the Helper functions section instead of the top of the page. 3. From `apps/docs`, run `pnpm lint:mdx`. The RLS guide reports no warnings. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated access-control guidance with clearer links for security-definer functions and RLS helper functions. - Clarified that exposed tables require Row Level Security (RLS), while table grants and row policies provide separate controls. - Added least-privilege and grant-revocation examples, plus explanations for authorization errors. - Expanded testing guidance for CRUD policies, identity switching, and denied operations. - Improved recommendations for service keys, policy performance, indexing, and secure function configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
d2ccbe5d46 |
docs(database): close the RLS guide gaps the eval flagged (#49011)
Closes DOCS-1274 ## Problem The `build-docs-002-rls-guide` eval points an agent at the Row Level Security guide with a vibe-coder prompt that never says RLS, policy, role, or test. It failed 6 of 35 checks. Each failure traces to something the guide doesn't say. - **Grants.** `anon` kept insert, update, and delete on all four to-do tables. Both client roles kept writes on the weather feed. 24 privileges untouched. - **Indexes.** Missing on `list_members.user_id`. The agent indexed the other three, so it missed the composite-primary-key case specifically. - **Tests.** No pgTAP files. `Result: NOTESTS`, so the coverage judge never ran. ## Solution - **Add a `Grants and policies` section.** - **Rewrite the opening danger admonition around revoke-then-grant.** It previously showed `grant` only, which reads as though privileges start from nothing. - **Drop the `(or primary keys)` carve-out from `Add indexes`.** A column counts as indexed only when it leads a `btree` index, shown with a composite-primary-key example. - **Add a `Test your policies` section.** Covers file location under `supabase/tests/`, `supabase test db`, role and identity switching, which assertion matches which denial, and an 11-assertion example spanning allow and deny for all four operations across `anon` and `authenticated`. Used the supacademy RLS course as a second reference. Its framing of grants running before RLS shaped the new section. ## Manual testing 1. Open the [Row Level Security guide](https://docs-git-docs-rls-revision-supabase.vercel.app/docs/guides/database/postgres/row-level-security) on the preview. `Grants and policies` and `Test your policies` appear in the table of contents. 2. Select the `Grants and policies` link at the end of the first admonition. It jumps to the new section. 3. Open the [markdown version](https://docs-git-docs-rls-revision-supabase.vercel.app/docs/guides/database/postgres/row-level-security.md), which is what agents fetch. Both new sections and the revised `Add indexes` text are present. 4. From `apps/docs`, run `pnpm lint:mdx`. The 4 warnings on this file match `master`, with no new ones. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Clarified that exposed tables must enable row-level security. * Explained the distinction between database grants and row-level security policies. * Added least-privilege examples for client roles, including read-only access. * Added pgTAP testing guidance with a complete `profiles` example. * Clarified that composite indexes support policy filters only on their leading columns. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
ff6c8d4b30 |
fix(log-drains): add UK1 and US2-FED Datadog regions (#49156)
## Summary - Add `UK1` and `US2-FED` to the Datadog region dropdown in the log drains studio UI - Add the same two regions to the Datadog region list in the log-drains docs page The Logflare backend added support for these two Datadog regions in [Logflare/logflare#3790](https://github.com/Logflare/logflare/pull/3790) (shipped in v1.50.1), but the studio dropdown and docs were never updated, so customers on UK1 or US2-FED couldn't actually select their region when setting up a Datadog log drain. ## Test plan - [ ] Open Project Settings → Log Drains → add a Datadog destination and confirm UK1 and US2-FED appear in the Region dropdown - [ ] Confirm a log drain configured with `UK1`/`US2-FED` saves and sends events successfully <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for configuring Datadog log drains in the UK1 and US2-FED regions. * **Documentation** * Updated the monitoring and debugging guide with the UK1 Datadog region. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
04ddc6bef8 |
chore: update cors for pg routes (#49136)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix - config hardening ## What is the current behavior? CORS is applied at the global level in a permissive mode ## What is the new behavior? Self-hosted envoy config should apply CORS to the `/pg` routes. These should only be called from the studio dashboard (when called via a browser). uses `SUPABASE_PUBLIC_URL`, which should mean this isn't a breaking change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Security & Access** * Added stricter CORS controls for the `/pg/` route. * Requests are limited to the configured public URL and localhost origins. * Standard HTTP methods and headers are supported, with preflight responses cached for one hour. * **Documentation** * Updated self-hosting guidance to describe the `/pg/` route’s CORS policy. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7c46793a3f |
docs: mention MCP debugging tools and Supabase agent skill in debugging docs (#48978)
## What - Adds a **Debug with AI tools** section to the debugging guide, covering the MCP debugging tools (`get_logs`, `query_logs`, `get_advisors`, `execute_sql`), the Supabase agent skill, and the combined plugin install, with a pointer to the MCP security best practices. - Adds a one-line pointer to it from the Monitoring and Debugging overview. - Adds the missing `query_logs` entry to the MCP server's Debugging tool group. Note: `pnpm lint:mdx` couldn't run locally (Node version), Prettier passes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added guidance for debugging with AI tools, including MCP tools and the Supabase agent skill for reading logs and advisors. * Documented plugin installation and security considerations when connecting AI agents through MCP. * Added links from monitoring and debugging guidance to the new AI tools documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
4433d9ddaf |
feat(studio): mark PrivateLink waiting as a warning (#49086)
## What kind of change does this PR introduce? UI ## What is the current behavior? Waiting (still labelled Ready in #49085) is green. Creating is orange. Deleting is red. ## What is the new behavior? Waiting is orange. Creating is grey. Deleting is orange. Connected stays the only green state. | Before | After | | --- | --- | | <img width="1448" height="492" alt="CleanShot 2026-08-14 at 12 43 59@2x" src="https://github.com/user-attachments/assets/c0d95b51-7841-4714-a01b-47e5587c3efb" /> | <img width="1434" height="470" alt="CleanShot 2026-08-14 at 12 44 59@2x" src="https://github.com/user-attachments/assets/3ba10dc5-5fdd-464a-a748-5085d2d65df3" /> | | <img width="842" height="440" alt="CleanShot 2026-08-14 at 12 44 21@2x" src="https://github.com/user-attachments/assets/757db647-4b7c-4f77-8dcf-1eb289c40cc1" /> | <img width="842" height="432" alt="CleanShot 2026-08-14 at 12 44 49@2x" src="https://github.com/user-attachments/assets/1311a6d2-4712-4cb9-a6f2-f39387f0a953" /> | ## Additional context Stacked on #49085. See #49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink.** A connection that AWS has not accepted yet should show an orange **Waiting** badge, not green Ready. - Creating should be grey. Deleting orange. Expired and Failed stay red. - **Docs preview → Platform → PrivateLink.** Should say Waiting, not Ready. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated AWS PrivateLink connection statuses to accurately show “Waiting” while the AWS Resource Share is pending acceptance. * Refined status badge styling for creating, waiting, and deleting connections. * Clarified that Resource Shares must be accepted within 12 hours. * **Documentation** * Updated PrivateLink setup instructions to reflect the revised connection status flow. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0c1da8fd09 |
feat(studio): tighten PrivateLink sheet fields (#49085)
## What kind of change does this PR introduce? Feature ## What is the current behavior? Add connection field order and nickname handling are harder to scan. Empty description can still show up as a blank name. ## What is the new behavior? Add connection is AWS account ID, then database, then optional description. An empty description is omitted from the list title. | Before | After | | --- | --- | | <img width="846" height="874" alt="CleanShot 2026-08-14 at 12 42 33@2x" src="https://github.com/user-attachments/assets/abfc4f37-a401-4bba-9408-c2530b0ac09b" /> | <img width="844" height="794" alt="CleanShot 2026-08-14 at 12 43 01@2x" src="https://github.com/user-attachments/assets/0cadeaea-583d-4c2b-9336-3d0fe6a1415b" /> | ## Additional context Stacked on #49084. See #49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink → Add connection.** Confirm field order: account ID, database, description. - Save once with a description and once without. Without one, the row title should fall back to the account ID. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added AWS account ID and database target fields to the PrivateLink setup form. - Added validation and improved preservation of entered values while editing. - Made the connection description optional. - Updated connection status labels and badges for clearer status visibility. - **Documentation** - Updated PrivateLink setup instructions to reflect the revised field order and optional description. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3d966e3709 |
feat(studio): show PrivateLink resource IDs and use connection copy (#48967)
## What kind of change does this PR introduce? Feature and docs ## What is the current behavior? PrivateLink is labelled as an AWS account, and there is no way to tell which resource configuration belongs to the primary vs a read replica. Put simply: you’re not adding an AWS account. You’re adding a connection. One AWS account can have multiple PrivateLink connections, just to different databases, with more fields also coming soon. Part of PRODSEC-238 and fixes SEC-939. ## What is the new behavior? Each connection shows resource configuration IDs so primary and replica are distinguishable. Customer-facing copy says **connection**. API paths and AWS console labels still say association. | Before | After | | --- | --- | | <img width="1452" height="496" alt="CleanShot 2026-08-14 at 12 33 49@2x" src="https://github.com/user-attachments/assets/3b295136-0325-4587-9291-b5f01fc07806" /> | <img width="1440" height="434" alt="CleanShot 2026-08-14 at 12 34 30@2x" src="https://github.com/user-attachments/assets/dd6ba064-18e4-4969-9c76-e3b79ac9d288" /> | | <img width="846" height="912" alt="CleanShot 2026-08-14 at 12 33 28@2x" src="https://github.com/user-attachments/assets/c4c6caca-a2f6-4516-99c7-ad7cf865f8ac" /> | <img width="844" height="880" alt="CleanShot 2026-08-14 at 12 34 39@2x" src="https://github.com/user-attachments/assets/f3874c6b-abdc-4ef8-84fa-141cd9150871" /> | | <img width="1448" height="560" alt="CleanShot 2026-08-14 at 12 33 10@2x" src="https://github.com/user-attachments/assets/8ae734cb-ec1f-4e4e-acf7-f4de459296d1" /> | <img width="1460" height="496" alt="CleanShot 2026-08-14 at 12 32 15@2x" src="https://github.com/user-attachments/assets/883050d5-a6f1-44bd-8ebd-1513a2c41e9f" /> | ## Additional context First PR in a stacked PrivateLink series (#49084 onwards). See https://github.com/supabase/supabase/pull/49030 for the end state, as it may already include fixes you might propose. ## To test - **Project Settings → Integrations → AWS PrivateLink.** Open **Add connection**, or **View** an existing one. Confirm the UI says connection, and that resource config IDs are copyable. - **Docs preview → Platform → PrivateLink.** Procedure steps should say Add connection / View connection. --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
ee1eb5dbca |
docs: standardize quickstart guides (#48950)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the new behavior? - All 19 guides follow one step order: create project → set up database → create app → AI tooling → add keys → create client → query data → run it → go to production. Added _template.mdx with structure requirements; it is not enforced with a lint check for now - this will be a separate PR before adding new guides. - 4 new partials replace copy-pasted blocks (AI tooling, connection strings, mobile env vars, going to production). - Error handling: return a message instead of a blank page when a query fails. - All guides verified and tested separately - all work as described. What was fixed: wrong env var names in the Hono sample, a Next.js page that redirected to login, missing database permissions in Refine and Hono, and stale file paths and APIs in SvelteKit, Refine, and TanStack. - Astro, Expo, Python, Laravel, and Rails were live but missing from the quickstart grid or listing page. Added, with two new icons. ## Quick links for review Base preview: https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs **Quickstart discovery**: new Astro/Expo/Python/Laravel/Rails entries and icons - [Docs homepage grid](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs) <img width="1998" height="882" alt="CleanShot 2026-08-12 at 12 06 31@2x" src="https://github.com/user-attachments/assets/942eb7e2-1e85-4b20-a6a7-c2b127d31b2b" /> - [Getting started overview](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started) <img width="856" height="878" alt="CleanShot 2026-08-12 at 12 13 30@2x" src="https://github.com/user-attachments/assets/d48091a9-7daf-4796-a521-14116b7479c9" /> ### New shared files: **[apps/docs/content/guides/getting-started/quickstarts/_template.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/guides/getting-started/quickstarts/_template.mdx?plain=1)** A reference contract the other 19 quickstart guides are checked against. Documents the required frontmatter, the canonical 10-step section order, every guide's deviation from that order (and why), the direct-Postgres exception (Laravel/Rails/RedwoodJS/Spring Boot), and the discovery-surface/icon requirements for adding a new guide. No lint rule enforces it yet; that's a follow-up PR. **[apps/docs/content/_partials/quickstart_ai_tooling.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_ai_tooling.mdx?plain=1)** Example: [Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#4-set-up-ai-tooling-optional) → "Set up AI tooling" section Shared by all 19 guides: astrojs, expo-react-native, flask, flutter, hono, ios-swiftui, kotlin, laravel, nextjs, nuxtjs, reactjs, redwoodjs, refine, ruby-on-rails, solidjs, spring-boot, sveltekit, tanstack, vue **[apps/docs/content/_partials/quickstart_going_to_production.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_going_to_production.mdx?plain=1)** Example: [Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#going-to-production) → "Going to production" section Shared by all 19 guides: same full list as above **[apps/docs/content/_partials/quickstart_connection_string.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_connection_string.mdx?plain=1)** Example: [Laravel](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#5-set-up-the-postgres-connection-details) → connection string setup step Shared by 3 guides: laravel, ruby-on-rails, spring-boot – the ORM/backend frameworks that connect directly to Postgres rather than through the Data API **[apps/docs/content/_partials/quickstart_mobile_env_note.mdx](https://github.com/supabase/supabase/blob/e311542913cf8da07f322a7586339d6f5de30c61/apps/docs/content/_partials/quickstart_mobile_env_note.mdx?plain=1)** Example: [iOS SwiftUI](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ios-swiftui#get-api-details:~:text=This%20guide%20substitutes%20your%20project%20URL%20and%20key%20directly) → environment variables step Shared by 3 guides: ios-swiftui, flutter, kotlin – note Expo React Native is mobile too but doesn't use this partial, since it has its own `EXPO_PUBLIC_` prefix convention inline instead. ## Per guide changes **[Astro](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/astrojs#9-query-supabase-data-from-astro)** Typed query error in the server client sample. **[Expo React Native](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/expo-react-native#8-query-data-from-the-app)** Added an `error` state alongside instruments. Also removed the broken [`--web` verification path](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/expo-react-native#9-start-the-app): expo-sqlite needs Metro wasm + COEP/COOP config the guide never had (CodeRabbit finding). **[Flask](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flask#7-create-the-supabase-client)** Split "Create the Supabase client" and ["Query data"](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flask#8-query-data-from-the-app) into their own steps. **[Flutter](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flutter#9-setup-deep-links-optional)** Reworded the deep-links section; keeps the framework-specific [Android `INTERNET` permission subsection](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/flutter#android) under "Going to production." **[Hono](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/hono#6-declare-supabase-environment-variables)** Split into "Install dependencies," "Declare environment variables," "Set up anonymous sign-ins," and "Query data" as separate steps. Fixes wrong env var names from the previous sample. **[iOS SwiftUI](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ios-swiftui#8-query-data-from-the-app)** Added an `isLoading` state so the loading overlay doesn't hang forever on a successful empty result (CodeRabbit fix). **[Kotlin](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/kotlin#5-install-dependencies)** Fixed the Compose compiler plugin declaration: `apply false` was missing from the app module (CodeRabbit finding). **[Laravel](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#5-set-up-the-postgres-connection-details)** Now uses the shared `quickstart_connection_string.mdx` partial for the session-pooler/SSL guidance instead of inline copy. **[Next.js](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#6-allow-public-access-to-the-instruments-page)** New step fixing the page that previously redirected to login. Its middleware path check is also now segment-aware so it doesn't over-match paths like `/instruments-private` (CodeRabbit finding). **[Nuxt](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nuxtjs#7-create-the-supabase-client)** "Create the Supabase client" and ["Query data"](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/nuxtjs#8-query-data-from-the-app) split out as their own steps. **[React](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/reactjs#7-create-the-supabase-client)** Same client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/reactjs#8-query-data-from-the-app) split as the other Vite-based guides. **[RedwoodJS](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/redwoodjs#2-gather-database-connection-strings)** Expanded into explicit transaction-mode/session-mode connection strings, Prisma schema, migration, seed, and scaffold steps; fixes stale file paths and APIs from the previous version. **[Refine](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/refine#8-allow-writes-to-the-instruments-table)** New step fixing the missing RLS grants that made the scaffolded create/edit pages fail. **[Ruby on Rails](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#4-set-up-the-postgres-connection-details)** Now uses `quickstart_connection_string.mdx`; added a [reminder to save the database password](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#1-create-a-supabase-project) before it's needed for the connection string. **[SolidJS](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/solidjs#7-create-the-supabase-client)** Same client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/solidjs#8-query-data-from-the-app) split, adapted to Solid's `resource.error`. **[Spring Boot](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/spring-boot#4-set-up-the-postgres-connection-details)** Connection-string section now uses the shared partial instead of a duplicated inline caution. **[SvelteKit](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/sveltekit#8-query-data-from-the-app)** Updated `load` functions (both `+page.js` and `+page.server.ts` variants) with explicit query-error typing; fixes stale file paths and APIs from the previous version. **[TanStack](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/tanstack#8-query-supabase-data-from-tanstack-start)** `fetchInstruments` now returns and renders the query error instead of silently returning an empty list (CodeRabbit finding); fixes stale file paths and APIs from the previous version. **[Vue](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/vue#7-create-the-supabase-client)** Same client-creation/[query-data](https://docs-git-docs-standardize-framework-quickstarts-supabase.vercel.app/docs/guides/getting-started/quickstarts/vue#8-query-data-from-the-app) split as the other Vite-based guides. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added SolidJS, RedwoodJS, Refine, Laravel, and Ruby on Rails quickstarts. * Added framework discovery entries for Astro, Expo React Native, Python, Laravel, and Rails. * Added optional AI tooling, MCP setup, connection-string, mobile configuration, and production-readiness guidance. * Added a Hono authentication example with anonymous sign-in, user details, and instrument data. * **Documentation** * Expanded setup, environment, authentication, RLS, migration, SSL, and deployment guidance. * **Bug Fixes** * Improved sample error handling for failed data requests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
a5afb3dd22 |
feat(docs): add enterprise managed MCP auth (#47691)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Added docs for enterprise managed MCP auth <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added guidance for Enterprise-Managed Authentication for MCP. * Documented setup requirements, authorization flow, configuration steps, and security considerations. * Expanded the SSO guide and navigation with links to the new MCP authentication documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
773b388f25 |
chore(docs): correct api for temporary access (#48741)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated temporary access guidance to require SSL-enforced incoming connections. * Updated Management API examples to use the `/jit-access` endpoint for checking, enabling, and disabling temporary access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9ef9f1b8c1 |
feat(self-host): use @supabase/server in functions template and docs (#48996)
Updates the self-host Edge Functions template to use `@supabase/server`, matching the CLI's `supabase functions new` templates (part of SDK-1150, follows up on #45635 which exposed `SUPABASE_JWKS` to the functions container). The `hello` example function now wraps its handler in `withSupabase({ auth: 'none' })` and resolves the package through a per-function `deno.json` import map, which the runtime auto-discovers, so no dispatcher changes are needed. The self-hosted functions guide is updated to match: the create-a-function snippet, a `ctx.supabaseAdmin` example replacing the manual esm.sh `createClient` wiring, and a note that `auth: 'user'` requires `SUPABASE_JWKS`. Verified on `supabase/edge-runtime:v1.74.0` with the compose environment variables: `curl /functions/v1/hello` returns the same response body as before, so existing docs and troubleshooting pages stay accurate. The `docker/.gitignore` change: `volumes/functions/**` ignores self-hosters' own functions, but it also hid the new `deno.json`, which must ship with the repo for the `hello` import to resolve. The allowlist entries follow the existing `main/index.ts` pattern. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Edge Functions now support authenticated invocation with publishable or secret API keys. * Function handlers can access authenticated and administrative Supabase clients through the request context. * Added automatic environment configuration and JWT verification support. * **Documentation** * Updated the self-hosting guide with the new function setup and authentication workflow. * Improved local function examples for supported access patterns and privileged operations. * **Tests** * Updated self-hosted smoke tests to validate publishable-key function access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Kalleby Santos <kalleby_santos@hotmail.com> Co-authored-by: Kalleby Santos <105971119+kallebysantos@users.noreply.github.com> |
||
|
|
7bfc45cc7b |
Update pg_net schema (#48694)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the current behavior? The create extension snippet defaults to public which trips the Security Advisor check "0014_extension_in_public". The extension either way creates its own "net" schema. ## What is the new behavior? Register pg_net in the extensions schema. This is also the default when installing the extension from the dashboard. <img width="425" height="224" alt="image" src="https://github.com/user-attachments/assets/160309c0-9d35-4de7-b583-32f5db310a96" /> ## Additional context When no schema is specified, defaults to public which trips the Security Advisor check: <img width="1084" height="250" alt="image" src="https://github.com/user-attachments/assets/ac5f2859-17bf-4763-9880-453b0f414b4f" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the pg_net installation example to place the extension in the `extensions` schema. * Clarified that this configuration keeps pg_net out of `public` and satisfies the Security Advisor check. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5627d01183 |
docs: Update tab reference in project setup documentation (#48451)
Tab naming has changed ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. * YES/NO ## What kind of change does this PR introduce? * docs update ## What is the current behavior? * Tab section referred do NOT exist anymore ## What is the new behavior? <img width="1823" height="823" alt="image" src="https://github.com/user-attachments/assets/7f2253ba-a251-434d-a005-10a598ae83b9" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the User Management Starter quickstart navigation instructions to use **Reference > Examples** in the Dashboard. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com> |
||
|
|
514f53a944 |
docs: point explain and rpc reference links at their current pages (#48655)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs fix (broken links). ## What is the current behavior? Three links in two troubleshooting entries point at `/docs/reference/javascript/explain`, which returns 404. That slug is not in the docs sitemap any more. Two of the three are not explain links at all. In `fixing-520-errors-in-the-database-rest-api-Ur5-B2.mdx` the link text is "RPCs" and "RPC" and the query string asks for `example=call-a-postgres-function-with-arguments`, so both were meant to point at the `rpc` reference. The third, in `understanding-postgresql-explain-output-Un9dqX.mdx`, really is about explain: the text is "EXPLAIN" and it asks for `example=get-execution-plan-with-analyze-and-verbose`. ## What is the new behavior? - the two "RPC" links now point at `/docs/reference/javascript/rpc` - the "EXPLAIN" link now points at `/docs/reference/javascript/using-modifiers-explain` Both destinations return 200. The `queryGroups` and `example` query strings are carried over unchanged, I only changed the slug. ## Additional context Files: - `apps/docs/content/troubleshooting/fixing-520-errors-in-the-database-rest-api-Ur5-B2.mdx` (2 links, to `rpc`) - `apps/docs/content/troubleshooting/understanding-postgresql-explain-output-Un9dqX.mdx` (1 link, to `using-modifiers-explain`) What I verified: `/docs/reference/javascript/explain` returns 404, and both `/docs/reference/javascript/rpc` and `/docs/reference/javascript/using-modifiers-explain` return 200 and appear in the sitemap. After the change there are no `javascript/explain?` references left in `apps/docs/content`. What I could not verify, so I am flagging it rather than claiming it: I could not confirm server side that the `example=` ids still exist on the destination pages, because the reference pages appear to build their example selectors client side and the ids are not in the fetched HTML. I kept each existing `example=` value as it was, on the basis that an unmatched example parameter just leaves the default selection rather than breaking the page, which is still better than the current 404. If you know those example ids have been renamed too, tell me and I will update them in the same PR. This was the one case I deliberately left out of #48568, where I said the intended target looked ambiguous. Looking at it again, the link text and the example parameter agree with each other in all three cases, so the mapping is clearer than I first thought. Gates run locally: `test:prettier` passes repo wide and the docs vitest suite passes (22 files, 169 tests, 1 file and 2 tests skipped). I did not run a build: `pnpm build` needs `DOCS_GITHUB_APP_PRIVATE_KEY` for the docs `build:federated-content` step, which I do not have, and it fails before Next compiles. Freshman contributor here, working through these with Claude Code's help and checking each URL myself. Happy to change any of the targets if you would rather they went elsewhere. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated database REST API troubleshooting links for RPC guidance. * Corrected the Supabase JavaScript EXPLAIN documentation link. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com> |
||
|
|
ececf6c003 |
docs: Update Devin Desktop Supabase plugin guides (#49048)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Windsurf has been renamed to Devin Desktop. This PR updates public-facing mentions of Windsurf to Devin Desktop - Update MCP installation instruction to match the current behavior. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated supported environment guidance to reference Devin Desktop instead of Windsurf. * Updated the MCP configuration path for Devin Desktop. * Removed outdated Windsurf-specific setup instructions and transport limitations. * Refreshed related MCP client labeling and setup guidance for clarity and consistency across the documentation and configuration experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
4d492db5eb |
docs: update settings links after upgrade UI move to General (#49053)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update - Upgrade project button and Postgres/PostgREST version checks moved from Infrastructure to General settings - Updated links across 13 docs pages to match <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated dashboard links throughout the documentation to direct users to **General Settings** instead of **Infrastructure Settings**. - Corrected guidance for Postgres, pgvector, pg_net, and PostgREST upgrades, configuration, and version checks. - Updated monitoring, Grafana, and Log Drains links to current documentation paths. - Fixed troubleshooting links, CLI project path examples, pg_cron terminology, and Markdown formatting. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0c2b8d77b2 |
fix: Update supabase test docs to use _test.sql (#48993)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? The database testing docs currently show test files using the `.test.sql` suffix, but `supabase test new` generates `_test.sql` files. Both formats work, but the generator behavior matches the previous Go CLI implementation and existing test fixtures. Update the docs for consistency with the actual generated file naming. Relevant context: [database testing docs](<https://supabase.com/docs/guides/database/testing>) and [CLI-1318](<https://linear.app/supabase/issue/CLI-1318/port-supabase-test-db-supabase-test-new>). We might want to add `supabase test new` to the docs, but that's a separate change. ## What is the current behavior? It reports `.test.sql` ## What is the new behavior? it reports `_test.sql` inline with the generator ## Additional context [slack thread](https://supabase.slack.com/archives/C07E5GFAHTM/p1786373594478619) - we can also add the test generator to the docs but I think that's a separate issue. |
||
|
|
25e77c4720 |
(fix): clarify re-enabling data api section of no exposed schemas troubleshooting guide (#48998)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update ## What is the current behavior? ## What is the new behavior? ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded troubleshooting guidance for re-enabling the Data API after applying the schema exposure workaround. * Clarified the steps and context for reversing the workaround. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ba5f0f57fd |
docs: add update step to agent skills docs page (#48982)
The agent skills docs page covered installing skills but not upgrading them, and skill fixes/features (like the debugging skill, only available from v0.1.8) can go unnoticed if users never re-run the CLI. Adds an **Upgrading skills** section with the `npx skills update` command and a link to the [`skills update` docs](https://github.com/vercel-labs/skills#skills-update). ### Preview <img width="813" height="611" alt="image" src="https://github.com/user-attachments/assets/c4b96316-f2d1-4b8a-b7bd-a868156447d5" /> [source](https://docs-git-docs-add-update-agent-skills-step-to-docs-supabase.vercel.app/docs/guides/ai-tools/ai-skills) Closes [AI-1066](https://linear.app/supabase/issue/AI-1066/add-agent-skills-upgrade-step-to-docs-page). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added an “Upgrading skills” guide explaining how to update all or selected installed skills. * Included links to additional documentation for more details. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0c27456c86 |
docs: Update documentation from JS, Dart, and Swift SDK changes (#48723)
## Summary Updates docs based on recent SDK changes across three of the six tracked SDKs. `supabase-py`, `supabase-kt`, and `supabase-csharp` were also analyzed this cycle but had no doc-worthy changes (internal bug fixes / dependency bumps only, or no new commits). ## Changes analyzed | SDK | Repo | Commits | Latest tag | |---|---|---|---| | js | https://github.com/supabase/supabase-js | `485695ff7...21e410f56` | v3.0.0-next.29 | | dart | https://github.com/supabase/supabase-flutter | `6979093...5447063` | yet_another_json_isolate-v2.1.1 | | py | https://github.com/supabase/supabase-py | `3c98900...0490201` | v3.0.0a1 | | swift | https://github.com/supabase/supabase-swift | `c24795d...51a083a` | v2.54.1 | | kt | https://github.com/supabase-community/supabase-kt | (no new commits) | 3.7.0 | | csharp | https://github.com/supabase-community/supabase-csharp | `572624e...ac057a2` | v1.5.0 | ## Documentation updates - **`apps/docs/content/guides/auth/sessions/pkce-flow.mdx`** — new "Overlapping flows" section documenting the experimental `appendPkceFlowIdToRedirects` option and `flowId`-aware `exchangeCodeForSession()`, added in supabase-js #2569, which fixes concurrent PKCE flows (e.g. multiple tabs) clobbering each other's stored code verifier. - **`apps/docs/spec/supabase_dart_v2.yml`** — `stream()` entry: documented the new filter methods (`like`, `ilike`, `match`, `imatch`, `isFilter`, `isDistinct`) and multi-filter chaining added in supabase-flutter #1610, plus two behavioral caveats (filter re-evaluation on UPDATE, primary-key-only DELETE payloads) and a new example. - **`apps/docs/spec/supabase_swift_v2.yml`**: - `invoke()` entry: documented the new `timeoutInterval` override on `FunctionInvokeOptions` (supabase-swift #1144), with a new example. - Added missing `generate-link` and `signOut()` (admin) spec entries — supabase-swift #1152 added these methods but Swift had no reference entries for them, even though the shared nav ids already existed in `common-client-libs-sections.json` for other SDKs. ## Test plan - [x] `python3 -c "import yaml; yaml.safe_load(...)"` on both edited YAML spec files — parses cleanly - [x] `npx prettier --check` on all three changed files — passes - [ ] Visual check of rendered reference pages for the new Swift `generate-link` / `signOut` / timeout examples and the Dart `stream()` multi-filter example (docs dev server) --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added guidance for experimental overlapping PKCE authentication flows, including separating concurrent flows and exchanging their flow IDs. - Expanded Dart streaming documentation with filter operators, multiple-filter behavior, update semantics, delete payloads, and chained-filter examples. - Added Swift documentation for admin link generation, user sign-out, and configurable Edge Function timeouts. - Documented the default 150-second Edge Function idle timeout and per-invocation timeout overrides. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
1440cb81ab |
docs: update database inspect page title DOCS-1300 (#48972)
## Problem The database debugging and monitoring guide had the generic title "Debugging and monitoring", which lacked product context and made it unclear in search results or breadcrumbs which area it covered. ## Fix Changed the page title to "Database debugging and monitoring". The sidebar entry keeps its shorter "Debugging and monitoring" label since it already has database section context. ## How to test - Navigate to the database debugging and monitoring guide in the docs - Confirm the page H1 reads "Database debugging and monitoring" - Confirm the sidebar entry still reads "Debugging and monitoring" <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the guide title to “Database debugging and monitoring” for clearer navigation and context. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
47595f8ac7 |
feat(self-hosted): implement queryLogs for the MCP debugging tools (#48900)
> [!IMPORTANT] > > Only merge this when (https://github.com/supabase/platform/pull/36804) is merged, as the AI assistant will not have access to the `query_logs` tool for the remote MCP server ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature (self-hosted / CLI Studio MCP server). ## What is the current behavior? Self-hosted `getDebuggingOperations` (`apps/studio/lib/api/self-hosted/mcp.ts`) implements only `getLogs`, so the MCP `debugging` group exposes `get_logs` — a fixed per-service log dump built by `getLogQuery`. Logs are served by Logflare, which speaks BigQuery SQL. ## What is the new behavior? Bumps `@supabase/mcp-server-supabase` to `^0.10.0` (adds `query_logs` + `logsDialect`, and hides `get_logs` wherever a platform declares `queryLogs`) and moves logs over to it. - **Self-hosted `query_logs`:** declares `logsDialect: 'bigquery'` and implements `queryLogs`, passing the model's SQL straight through to the same Logflare `logs.all` endpoint (arbitrary `sql` param) — no new endpoint, no dialect translation. - **Drops `get_logs` from self-hosted:** `getLogs` throws (the server hides it once `queryLogs` exists) and the per-service `getLogQuery` builder is deleted; the model now writes its own BigQuery SQL, guided by the dialect schema hint. - **Honors no-logs mode:** `query_logs` throws when `logs:all` is disabled — the self-hosted default, enabled via the `docker-compose.logs.yml` override. - **Assistant:** switches the dashboard assistant from `get_logs` to `query_logs` (allowlist, drift guard, prompt, mocks, evals). Refs AI-1046 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * AI debugging can query recent project logs using read-only SQL. * Log queries support optional time-range filters, filtering, aggregation, and joins. * Self-hosted debugging checks whether logging is enabled before running queries. * **Bug Fixes** * Updated debugging workflows and validation to consistently use the new log-query capability. * Removed reliance on legacy service-specific log filtering and query behavior. * **Documentation** * Updated MCP debugging tool guidance to describe SQL-based log queries. * **Tests** * Expanded coverage for enabled, disabled, and unsupported logging scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
34c29f0b98 |
docs(python): add python docs for otel instrumention (#48898)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Adds a new tab section for the `client-side-tracing.mdx` document file, explaining how to setup OTel context propagation in the `supabase-py` library. ## What is the current behavior? No documentation. ## What is the new behavior? Documentation. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the client-side tracing guide to document W3C trace-context propagation support in the Python SDK. * Added Python setup instructions for OpenTelemetry HTTPX instrumentation, tracer configuration, and tracing Supabase queries. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Katerina Skroumpelou <sk.katherine@gmail.com> |
||
|
|
433175e79a |
Clarify behavior of preview branches in documentation (#48744)
Update the description of preview branches to clarify that they are automatically deleted when a PR is merged or closed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Clarified that preview branches are temporary and automatically deleted when a pull request is merged or closed. - Removed outdated guidance stating that preview branches pause after inactivity. - Clarified that persistent branches remain available long-term and are not automatically paused or deleted due to inactivity or pull request closure. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fc5db9bb03 |
docs: update client-side tracing and Edge Function CORS guides (#48924)
Updates the client-side tracing and Edge Function CORS docs for changes shipping in `@supabase/supabase-js` v2.112.3 (supabase/supabase-js#2603, supabase/supabase-js#2604). The tracing guide gains a vendor compatibility table (plain OpenTelemetry works as is, Sentry needs `propagateTraceparent: true`, Datadog RUM needs `allowedTracingUrls`), the new `respectSamplingDecision` semantics (non-sampled requests now carry `traceparent` only, so logs stay correlatable), a troubleshooting entry for the SDK's new propagator warning, and a note that browser calls to Edge Functions need the trace headers in the function's CORS allow-list. The CORS guide now states explicitly that trace headers are sent only when trace propagation is opted in (never by default), adds a table of when each SDK header is actually sent, and the hardcoded `corsHeaders` examples are updated to the full header list. Should merge after the v2.112.3 release is published, since it documents that version's behavior. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded CORS guidance with trace-propagation requirements and SDK version considerations. * Added browser and Edge Function setup guidance for client-side tracing. * Documented updated sampling behavior, advanced configuration, vendor setup examples, and troubleshooting. * **Bug Fixes** * Updated CORS configurations to allow retry and tracing headers required for supported requests. * Improved compatibility for browser requests that transmit distributed tracing context. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
5b301e1ffa |
Add docs for diagnosing stuck and blocked queries (#48920)
## Context Related to the dashboard work for [Database Connections](https://github.com/orgs/supabase/discussions/48639) - updates the "Connection Management" docs page to include a section about "Diagnosing stuck and blocked queries". Content is intentionally agnostic to the UI, but more focused on Postgres. Preview: https://docs-cdukolvgy-supabase.vercel.app/docs/guides/database/connection-management Covers the following sub-topics: - Reading a session's state - Finding out what's blocking a query - How to stop the session responsible - Small footer to link to the dashboard's Database Connections page Also adding a cross-reference in 2 areas - Troubleshooting: How to check if my queries are being blocked by other queries - Monitoring and Debugging MDX -> Related to observability skills <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded connection-management guidance with clearer explanations of session states. * Added instructions for diagnosing stuck or blocked queries, identifying blocking sessions and chains, and choosing when to cancel or terminate them. * Documented required permissions and available dashboard tools for managing sessions. * Added cross-references and telemetry updates to make troubleshooting guidance easier to discover. * Clarified how to use PostgreSQL activity information when investigating blocked queries. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5a8eecf509 | feat(self-hosted): envoy is the default api gateway (#48153) | ||
|
|
9596b5f3ed | docs(self-hosted): add a separate architecture diagram (#48763) | ||
|
|
cb35e1f98e |
chore(library): update routes, redirects, and naming (#48668)
Our UI Library registry is expanding to include blocks that go beyond UI and in some cases focus purely on back-end. This PR is a precursor to adding more back-end related blocks. This PR includes the `ui-library -> library` rename plus redirects and small UI copy updates. Since this is a rename we'll need to update Vercel configuration. ## Vercel rollout Keep the Library project Root Directory as `apps/ui-library` 1. In the **Library** Vercel project, set: `NEXT_PUBLIC_BASE_PATH=/library` Apply it to Preview and Production, then redeploy the Library project. 2. In the **www** Vercel project, add: `NEXT_PUBLIC_LIBRARY_URL=<current value of NEXT_PUBLIC_UI_LIBRARY_URL>` Apply it to Preview and Production. Keep `NEXT_PUBLIC_UI_LIBRARY_URL` during the migration, then redeploy the www project. 3. Deploy in this order: 1. Library project 2. www project 4. Validate: - `/library` - `/library/docs/nextjs/password-based-auth` - `/ui` redirects to `/library` - `/ui/docs/nextjs/password-based-auth` redirects to `/library/docs/nextjs/password-based-auth` - `/ui/docs/ai-editors-rules/*` still uses its existing Docs redirects No Vercel dashboard redirect rules are needed. Environment-variable changes require a new deployment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Supabase UI Library has been renamed to **Supabase Library** across navigation, pages, documentation, and resource links. * The Library is now available at `/library`, with updated descriptions covering components, blocks, and developer tools. * **Bug Fixes** * Added permanent redirects from legacy `/ui` URLs to corresponding `/library` paths. * Updated links throughout the site and documentation to prevent broken navigation and references. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ae9042ceb4 |
feat(docs): scoped pat update (#48802)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Updates docs around scoped PAT's. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that temporary database access uses a Personal Access Token as the Postgres role password. * Updated API documentation to explain that Personal Access Tokens support custom expiration rather than being described as long-lived. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
18c26bf933 |
docs(auth): clarify audit logs storage options and configuration (#48852)
## Summary - Clarify that external log storage is the default - Explain that Postgres database storage is optional - Fix grammar and typos - Improve admonition messaging to be more actionable - Simplify toggle step wording for clarity Slack thread with team-auth: https://supabase.slack.com/archives/C022071RB2L/p1785945149999009 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that audit logs are stored in external log storage by default. * Documented optional database storage in `auth.audit_log_entries`. * Added instructions for enabling or disabling database storage with the “Write audit logs to the database” toggle. * Noted that enabling database storage incurs additional database storage costs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
66a4a0b32d | fix(docs): realtime deletes can be surfaced and filtered (#48785) | ||
|
|
1ff84a239c |
docs(auth): note that resetPasswordForEmail doesn't send email for un… (#48800)
add note on `resetPasswordForEmail` doesn't send email for unregistered emails <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that password reset requests do not reveal whether an email address is associated with an account. * Documented that requests for unrecognized email addresses complete without an error. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
a18ee934cd |
docs(auth): handle incoming deep link URLs on Swift (#48774)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? The Swift tab in the [Native Mobile Deep Linking guide](https://supabase.com/docs/guides/auth/native-mobile-deep-linking?platform=swift) only covers registering a custom URL scheme (Info.plist config). Unlike the React Native, Flutter, and Kotlin tabs, it never shows the runtime code that actually consumes the incoming URL and completes the sign-in, so a Swift developer following the guide is left without a working implementation. Linear: [SDK-83](https://linear.app/supabase/issue/SDK-83/swift-improve-docs-on-how-to-handle-deep-link-url) ## What is the new behavior? Added a "Handling the incoming URL" section to the Swift tab with: - SwiftUI: `onOpenURL` calling `supabase.auth.handle(url)` - UIKit app delegate lifecycle: `application(_:didFinishLaunchingWithOptions:)` and `application(_:open:options:)` - UIKit scene delegate lifecycle: `scene(_:openURLContexts:)` - A note pointing to `session(from:)` for callers that need the returned `Session` or custom error handling `handle(url)` and its usage patterns match the current `supabase-swift` reference spec (`supabase_swift_v2.yml`) and source. Also added `UIKit` to the docs spelling allowlist (`supa-mdx-lint/Rule003Spelling.toml`) since it isn't in the dictionary. ## Additional context `pnpm lint:mdx` passes on the changed file. `pnpm build:guides-markdown` fails, but on a pre-existing unrelated issue (missing generated `database-advisors.json`), not on this change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Swift guidance for handling authentication deep links in SwiftUI and UIKit apps. * Documented deep-link behavior during cold launches and scene-based URL delivery. * Clarified when to use `handle(_:)` and `session(from:)`, including error-handling considerations. * Updated the SwiftUI tutorial to pass authentication URLs directly to the recommended handler. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d61d3533f2 |
docs: fix broken Swift example in joins-and-nesting guide (#48775)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs fix. ## What is the current behavior? Fixes [SDK-958](https://linear.app/supabase/issue/SDK-958/docs-incomplete-documentation), reported via the docs feedback widget on [joins-and-nesting](https://supabase.com/docs/guides/database/joins-and-nesting). In the "Specifying the `ON` clause for joins with multiple foreign keys" section, the Swift example was broken relative to the other language tabs (JS, Dart, Kotlin, Python, C#): - The query string aliased the second embed as `scans: scan_id_end`, which isn't valid PostgREST embed syntax (should be `end_scan:scans!scan_id_end`). - The `Shift` struct only declared a single `scans: [Scan]` property with no `CodingKeys` entry for `start_scan` or `end_scan` — so it never actually decoded either aliased relation, which is why the reporter couldn't tell where `start_scan` was supposed to come from. ## What is the new behavior? - Query now aliases both relations consistently: `start_scan:scans!scan_id_start (...)` and `end_scan:scans!scan_id_end (...)`, matching the other language examples. - `Shift` struct now declares `startScan: Scan` and `endScan: Scan`, mapped via `CodingKeys` to `start_scan` and `end_scan`. ## Additional context Docs-only change to a code sample inside `apps/docs/content/guides/database/joins-and-nesting.mdx`. Verified with `prettier --check` (mdx lint tool failed locally due to an unrelated missing native module, `node-pty`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the Swift join example to represent separate start and end scan relationships. * Revised response field selections and coding keys to match the updated relationship names. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b97ad08be5 |
docs: updating Edge Functions error codes (#48767)
<!-- ccr-slack-attribution --> _Requested by **Kalleby Santos** · [Slack thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785949561216739?thread_ts=1785949561.216739&cid=C02KMRX22NR)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. Adds two missing entries to the Edge Functions **Error codes** page (`apps/docs/content/guides/functions/error-codes.mdx`). Refs https://github.com/supabase/supabase/issues/47739 ## What is the current behavior? Neither `NOT_FOUND_FUNCTION_BLOB` nor `LOAD_FUNCTION_UNBUNDLING_ERROR` appears on the Error codes page. Someone who gets a 404 with `sb-error-code: NOT_FOUND_FUNCTION_BLOB` and searches the page finds nothing — and because the response body is the same `Requested function was not found` string that generic `NOT_FOUND` returns, the existing `NOT_FOUND` entry reads like it covers the case when it doesn't. ## What is the new behavior? Both codes are documented under `## Server Errors` with a cause and a remedy, in the page's existing `**Cause:**` / `**Solution:**` shape. - `NOT_FOUND_FUNCTION_BLOB` goes directly after `### NOT_FOUND`, since readers hitting it will scan for `NOT_FOUND` first. The cause explains the metadata/bundle version mismatch (concurrent or batched deploys double-incrementing the metadata version), notes that the message is identical to `NOT_FOUND` so the `sb-error-code` header is the distinguisher, and links the existing [Edge Function 404 error response](https://supabase.com/docs/guides/troubleshooting/edge-function-404-error-response) troubleshooting guide. Solution: redeploy with the latest CLI, avoid concurrent deploys of the same function, contact support to re-sync metadata if it persists. - `LOAD_FUNCTION_UNBUNDLING_ERROR` goes at the end, keeping the `LOAD_FUNCTION_*` cluster together. Cause: the bundle was fetched but decompression/parsing failed, which points at a corrupt or partially-written bundle. Solution: redeploy, contact support if it persists. ## Additional context Both codes are real and currently emitted by `supabase/edge-functions-ingress` (`main`): - `NOT_FOUND_FUNCTION_BLOB` — 404, declared at `src/main/errors.ts:29`, emitted at `src/main/cache.ts:180` - `LOAD_FUNCTION_UNBUNDLING_ERROR` — 503, declared at `src/main/errors.ts:27`, emitted at `src/main/cache.ts:226` Both were introduced by supabase/edge-functions-ingress#464. ### Notes for reviewer - **Scope.** The comment on #47739 asked only for `NOT_FOUND_FUNCTION_BLOB`. `LOAD_FUNCTION_UNBUNDLING_ERROR` is included because it shipped in the same ingress PR and is equally undocumented — happy to drop it if you'd rather keep this PR to exactly what was requested. - **No HTTP statuses in the copy.** The 404/503 above are deliberately left out of the page text, because the Error codes page states no HTTP status anywhere for any code. Adding them here would be a format departure. Easy to add if you'd prefer to start including them. - **Message mismatch, not fixed here.** `apps/docs/content/troubleshooting/edge-function-404-error-response.mdx` declares `message = "Function deployment bundle not found"` for `NOT_FOUND_FUNCTION_BLOB`, but the runtime actually emits `"Requested function was not found"` (`cache.ts:181`), which matches the response pasted in #47739. Left untouched in this PR — flagging it for a follow-up. ### Checks run - `prettier --check` on the changed file: passes. - `supa-mdx-lint` (v0.3.2) on the changed file: no new findings. The one remaining warning (`error-codes.mdx:11` — "Use 'view and resolve errors' instead of 'handle errors'") is pre-existing on `master` and untouched here. - The `{/* supa-mdx-lint-disable Rule001HeadingCase */}` pragma at line 8 sits above both new H3s, so the uppercase headings pass. --- _Generated by [Claude Code](https://claude.ai/code/session_01Qw5D2wdScBN5TWuA2FgnDW)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
5049f3eb81 |
docs: supabase evals note in AI tools page (#48663)
Following announcement https://supabase.com/blog/introducing-supabase-evals Adds an admonition to the [AI Tools](https://supabase.com/docs/guides/ai-tools) overview calling out the recently launched [Supabase Evals](https://supabase.com/blog/introducing-supabase-evals) project to demonstrate performance of (some of) the tools shown. Preview: https://docs-git-mattrossman-ai-969-link-to-evals-from-47d719-supabase.vercel.app/docs/guides/ai-tools <img width="3600" height="1606" alt="CleanShot 2026-08-03 at 15 13 06@2x" src="https://github.com/user-attachments/assets/8ea23f6c-fde0-4b04-bed1-035941570ac1" /> If preferred, we can move it below the fold, I just figure it's good for visibility on the recent launch and it helps sell the "why" for using these tools. Closes AI-969 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Documentation** * Added a link and note about Supabase Evals, an open-source benchmark for AI coding agents. * **Chores** * Updated spelling checks to recognize “eval” in any capitalization. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
08867f94ff |
docs: lead self-hosting overview with what/why/CTA, restructure secondary content (#48415)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs restructure of the self-hosting overview: short fit intro, Get started / community listings above the fold, parallel h2 sections for how self-hosting differs (including local development), responsibilities, and telemetry, plus a streamlined support listing with better card content. Closes DOCS-1251. ## What is the current behavior? - Linear item: Explore two PR approaches for the self-hosting page - The self-hosting overview page (`/guides/self-hosting`) is the top search hit for "supabase self-hosting," but reads as a wall of text: three full prose/bullet sections (differs / responsibilities / telemetry) come before the getting-started CTA, which is buried as one small card partway down the page. ## What is the new behavior? - Short fit intro; `self-hosting-get-started` and `self-hosting-community` listings sit directly under the intro. - Top-level h2s for how self-hosting differs, responsibilities, telemetry, and support (no "More about self-hosting" wrapper). - Under differs: rewritten single-project + platform-gap copy, plus `### Not the same as local development` (CLI stack is not a production self-host; points to Docker / community options). - Telemetry clarifies CLI local-dev telemetry vs Docker Compose (no phone-home). - Merged support into a single `self-hosting-support` listing; Enterprise subsection unchanged. - Minor a11y: `aria-hidden` on GlassPanel decorative icon background. ## Additional context - Worktree: `~/GitHub/supabase/supabase-worktrees/nikrichers/docs-1251-self-hosting-inform` - Review: removed the "More about self-hosting" grouping after feedback that it undersold differs / responsibilities. - Companion prototype PR 48416 is closed; this branch is the direction under review. - Verification: | Check | Result | | ----------------------------------------------- | ------------------------------------------------------------------ | | `pnpm lint:mdx content/guides/self-hosting.mdx` | Pass — no errors/warnings on this file | | Vercel docs preview | Pass — full-page after screenshot captured from the preview deploy | ### Proof: intro and get-started above the fold; parallel h2s for differs, responsibilities, and telemetry **Verified:** `pnpm lint:mdx content/guides/self-hosting.mdx` (pass) · Vercel docs preview (pass) ### Before & After | [Before (production)](https://supabase.com/docs/guides/self-hosting) | [After (PR preview)](https://docs-git-nikrichers-docs-1251-self-hosting-inform-supabase.vercel.app/docs/guides/self-hosting) | | ------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- | |  |  | ### Test plan - [ ] Visit the preview link and confirm the page opens with intro above the Get started listings - [ ] Confirm parallel h2s for differs / responsibilities / telemetry / support (no "More about self-hosting") - [ ] Confirm "Not the same as local development" distinguishes the CLI stack from self-hosting - [ ] Confirm Support and community is one card grid - [ ] Check mobile width — layout should still be usable - [ ] Confirm `/guides/self-hosting/docker` link still works <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Reorganized the self-hosting guide with clearer getting-started resources and community links. - Added dedicated guidance for local development, managed Supabase, telemetry, and self-hosting responsibilities. - Consolidated support resources into one section covering discussions, issues, chat, Reddit, and sharing experiences. - **Accessibility** - Marked decorative icon backgrounds as hidden from assistive technologies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
47b8660d8d |
docs(troubleshooting): troubleshooting guide so users can amend their failed migrations (#48257)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Troubleshooting guide ## What is the current behavior? NA ## What is the new behavior? Troubleshooting guide ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new troubleshooting page: “Troubleshooting MIGRATIONS_FAILED: missing tables or an incomplete schema on your branch” for Preview Branch creation. * Explained why replayed `main` migration history can fail when it no longer matches the branch’s live schema. * Included a step-by-step workflow to diagnose the failing migration via logs, repair migration status, and then recreate or rebase the branch to verify. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
d101d6f3de |
docs: document NOT_FOUND_FUNCTION_BLOB Edge Function error (#48411)
This PR addresses the documentation portion of #47739. ## What the issue means `NOT_FOUND_FUNCTION_BLOB` means the runtime cannot find the deployed bundle for an Edge Function. This differs from the existing `NOT_FOUND` error, which normally indicates that the function name in the request URL is not recognized. The dashboard status alone may not reveal this failure because the function can still appear as `ACTIVE`. ## Changes - Documented `NOT_FOUND_FUNCTION_BLOB` as an HTTP 404 error. - Explained how it differs from `NOT_FOUND`. - Added the command for redeploying one affected function. - Added the command for redeploying all functions when several are affected. - Added guidance to retry the request and contact Support if redeployment does not resolve the problem. ## Files changed - `apps/docs/content/troubleshooting/edge-function-404-error-response.mdx` ## Validation - The change uses the troubleshooting page's existing TOML frontmatter and MDX conventions. - `git diff --check` passes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded troubleshooting guidance for Edge Function 404 responses. * Added coverage of the `NOT_FOUND_FUNCTION_BLOB` error, including example responses and clarification of how it differs from `NOT_FOUND`. * Updated redeployment instructions with options for deploying a single function or all functions. * Refined retry and support guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1f0fb64ce9 |
docs: CLI 'Transport error' caused by antivirus/proxy TLS interception (#48719)
## Summary - Adds a troubleshooting entry for the Supabase CLI's generic `HttpClientError: Transport error` when a Management API call (e.g. `projects list`, `link`) fails. - Root cause documented: antivirus software or corporate SSL-inspecting proxies (e.g. Norton Safe Web/Web & Mail Shield, Zscaler, Netskope) substituting their own TLS certificate, which the CLI's HTTP client rejects and reports as a generic transport error rather than a certificate error. - Includes a vendor-agnostic diagnostic method (compare `curl`/browser vs. CLI behavior, check the served certificate's Issuer field) plus the specific Norton fix confirmed via a support ticket (disabling Smart Firewall alone does not stop the interception; Safe Web/Web & Mail Shield does). ## Test plan - [ ] `pnpm --filter docs lint:mdx` passes in CI - [ ] Frontmatter renders correctly on the troubleshooting page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added troubleshooting guidance for Supabase CLI transport errors caused by antivirus software or corporate TLS inspection. * Included diagnostic steps, common error messages, and resolution guidance for Norton 360 and SSL-inspecting proxies. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Rodrigo Mansueli <rodrigo@mansueli.com> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
af384e136f | chore(self-hosted): update tags in docker guide (#48739) | ||
|
|
89a5d03817 |
docs: add eu-central-2 to Edge Functions regional invocation page (#48721)
<!-- ccr-slack-attribution --> _Requested by **Kalleby Santos** · [Slack thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785871243937099?thread_ts=1785871243.937099&cid=C02KMRX22NR)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update — one-line content fix. ## What is the current behavior? The [Regional Invocations](https://supabase.com/docs/guides/functions/regional-invocation) page's "Available regions" section lists every Edge Functions region **except `eu-central-2`** (AWS Europe, Zurich). The region has been live in production for a while, but it was never added to the docs. A user reading this page to pick a region for `x-region` / `FunctionRegion` had no way to know Zurich was an option — the page reads as an exhaustive list, so the omission actively implies the region doesn't exist. Reported by Kalleby Santos (Edge Functions team). Linear: [FUNC-761 — Add eu-central-2 to regional invocation docs page](https://linear.app/supabase/issue/FUNC-761/add-eu-central-2-to-regional-invocation-docs-page) ## What is the new behavior? **Before:** the Europe group listed `eu-central-1`, `eu-west-1`, `eu-west-2`, `eu-west-3`. **After:** `eu-central-2` (Zurich) is listed alongside the others, so the page reflects the regions Edge Functions actually serves. ### How One line added to `apps/docs/content/guides/functions/regional-invocation.mdx`, in the **Europe** group directly after `eu-central-1`, following the list's existing sort-by-region-code order and the surrounding `` `code` (Short location) `` label style: ```diff **Europe:** - `eu-central-1` (Frankfurt) +- `eu-central-2` (Zurich) - `eu-west-1` (Ireland) - `eu-west-2` (London) - `eu-west-3` (Paris) ``` No other files changed. This page's region list is hand-maintained in the MDX and is deliberately narrower than the project-creation region list in `packages/shared-data/regions.ts` (which also includes `us-east-2` and `eu-north-1`), so no shared constant needed updating and no other product's region list was touched. ## Additional context **Verification that `eu-central-2` is a real Edge Functions invocation region** — confirmed in three independent places: 1. `supabase/platform` → `pulumi/edge-runtime/Pulumi.prod.yaml:533` — `region: eu-central-2`, with `enabled: true` at `:531`. A fully provisioned prod region (360–540 always-on tasks), not a placeholder. Branch `develop`, HEAD `1f44167768f951c0c794313006bc2c9f9758c344`. 2. `supabase/platform` → `pulumi/edge-runtime-next/stack-config/Pulumi.prod.aws.euc2.yaml:6` — `aws:region: eu-central-2` under the `Edge-Functions/K8s-Prod` environment, tagged `product: functions`. 3. `supabase/api-gateway` → `customer-router/wrangler.toml` — `eu-central-2` is present in the `EDGE_FUNCTIONS_REGIONAL_ORIGINS` map (`eu-central-2 = "https://eu-central-2.edge-runtime.supabase.green"`). This is the table that resolves the `x-region` header, so regional invocation into Zurich is genuinely routable — not just deployed. **For a reviewer to confirm separately (intentionally not in this diff):** production infra has 16 enabled Edge Functions regions, so `us-east-2` (Ohio, `pulumi/edge-runtime/Pulumi.prod.yaml:507`, `enabled: true`) is *also* missing from this page. It's excluded here because we don't yet know whether that omission is deliberate; it's being confirmed with the team and can be a follow-up. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy --- _Generated by [Claude Code](https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
4a9b5a538b |
chore: update pg changes to add python to the code blocks (#47793)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Adds code blocks for Python and new pg changes features <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated Python code examples for Realtime Postgres Changes to use cleaner, working subscription syntax. * Fixed a missing comma in a multi-change example so the sample code is valid. * Added a missing Python example for selecting specific columns. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
e7d9c88cbc |
fix(docs): resolve remaining heading-order issues found in Pass 2 diagnostic (#48664)
## Problem After merging [#48456](https://github.com/supabase/supabase/pull/48456) (shared components) and [#48459](https://github.com/supabase/supabase/pull/48459) (per-page content fixes), a follow-up diagnostic pass found 22 remaining heading-order violations, logged as Pass 2 in the [triage report](https://app.notion.com/p/supabase/Playwright-E2E-Triage-Reports-3ab5004b775f81e3bc60d058fa5a02c1). None of them were caught by the earlier fixes because they came from places that scan didn't check: shared partials, raw HTML heading tags written directly in MDX, and a couple of shared/interactive components rendering hardcoded heading levels. ## Solution - `_partials/social_provider_setup.mdx`: `#### Local development` → `###`, matching the `##` that always precedes it on all 14 social-login pages. - `guides/database/functions.mdx` and `guides/integrations/vercel-marketplace.mdx`: replaced raw `<h4>`/`<h5>` tags with correctly-nested real headings (`### Planets`/`### People`; `#### Deploy a Next.js app...`) — no styling workarounds needed since they nest naturally one level below their parent section. - `auth/quickstarts/{nextjs,react-native,react,astrojs}.mdx`: these 4 pages had no heading at all before the embedded `_partials/api_settings.mdx` partial's own `### Get API details` heading, so added a `## Quickstart` heading above the walkthrough to give it a valid parent. - `packages/ui`'s `Accordion` component: Radix's `AccordionPrimitive.Header` renders as an unconditional `<h3>` regardless of where the accordion is used. That's shared across Studio, www, and design-system, not just docs, and surfaced on docs' vendor-agnostic telemetry page. Now rendered via `asChild` onto a plain `div` instead, since a generic accordion has no way to know what heading level (if any) is valid in a given page. - SQL-to-REST translator tool (`/docs/guides/api/sql-to-rest`): its `Assumptions`/`FAQs` section labels were hardcoded `<h3>` with no `h2` anywhere on the page. Converted to styled spans rather than promoting to a real `<h2>`, because real h1/h2/h3 tags in this codebase force a prose font-size that utility classes can't override — promoting the tag would have visibly changed its size. - `RealtimeLimitsEstimator` (embedded on both `postgres-changes` and `benchmarks`): its 3 section headings were hardcoded `<h4>`, but the two embedding pages need different levels (h3 vs h4) for that spot to be valid — no single correct heading level. Converted to styled spans, same pattern used throughout this project for components embedded at varying heading depths. ## Manual testing 1. Check out this branch and run `pnpm dev:docs`. 2. Visit `/docs/guides/auth/social-login/auth-github` (or any other provider page) and confirm the "Local development" callout under "Find your callback URL" still looks and reads the same. 3. Visit `/docs/guides/database/functions` → "Returning data sets" tab and confirm the "Planets" / "People" table captions still look the same. 4. Visit `/docs/guides/integrations/vercel-marketplace` → "Quickstart" → "Via template" and confirm the CTA card title still looks the same. 5. Visit `/docs/guides/auth/quickstarts/nextjs` (or react-native/react/astrojs) and confirm a "Quickstart" heading now appears above the walkthrough, and "Get API details" still renders correctly further down. 6. Run `pnpm dev:design-system` and open `/design-system/docs/components/accordion` — expand/collapse an item and confirm it still animates and looks identical; inspect the DOM and confirm the trigger's wrapper is a `div`, not an `h3`. 7. Visit `/docs/guides/api/sql-to-rest`, translate any query, and confirm the "Assumptions"/"FAQs" section labels still look the same. 8. Visit `/docs/guides/realtime/postgres-changes` and `/docs/guides/realtime/benchmarks`, scroll to the connection-limits calculator, and confirm its section labels still look the same on both pages. 9. (Optional, for a full re-check) Run `pnpm e2e:docs:a11y --all` against a deployed preview of this branch — only `/docs/guides/cli` (pre-existing 404, unrelated to headings) should fail; every other page should pass. Verified with a full Playwright run against a real preview deployment: **756 passed, 1 failed** (`/docs/guides/cli`, the pre-existing unrelated 404). Zero heading-order violations remain. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added clearly labeled Quickstart sections to Astro, Next.js, React Native, and React authentication guides. - Improved heading hierarchy and formatting across social provider setup, database functions, and deployment documentation. - Updated estimator and SQL-to-REST section presentation for more consistent content structure. - **Bug Fixes** - Improved accordion trigger layout while preserving existing behavior, styling, accessibility, and icon display. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
de5d3cd115 | docs(self-hosted): update manual setup instructions (#48692) | ||
|
|
31d1a639c0 |
docs: Update SDK references from recent releases (#47830)
## Summary Updates SDK reference docs and the client-side tracing guide based on recent releases across all six Supabase SDKs. ## SDKs analyzed | SDK | Repo | Latest commit | Latest tag | |-----|------|--------------|------------| | js | supabase/supabase-js | `e4e8864` | v3.0.0-next.29 | | dart | supabase/supabase-flutter | `c3e3602` | yet_another_json_isolate-v2.1.1 | | py | supabase/supabase-py | `6570638` | v3.0.0a1 | | swift | supabase/supabase-swift | `ebef170` | v2.51.0 | | kt | supabase-community/supabase-kt | `e23df20` | 3.7.0-beta-1 | | csharp | supabase-community/supabase-csharp | `3fad62f` | v1.1.2 | ## Documentation changes ### `apps/docs/spec/supabase_dart_v2.yml` - **OAuth Server API** ([supabase-flutter#1561](https://github.com/supabase/supabase-flutter/pull/1561)): Added `oauth-server-api` group stub and `listGrants()` / `revokeGrant()` method entries, matching the existing `common-client-libs-sections.json` nav IDs. - **`listBuckets()` options** ([supabase-flutter#1557](https://github.com/supabase/supabase-flutter/pull/1557)): Added example showing `ListBucketsOptions` with `search`, `limit`, `offset`, `sortColumn`, and `sortOrder`. ### `apps/docs/spec/supabase_py_v2.yml` - **`on_postgres_changes` `select` param** ([supabase-py#1524](https://github.com/supabase/supabase-py/pull/1524)): Added `listening-to-selected-columns` example for the new `select=["id", "name"]` parameter. - **Expanded filter operators** ([supabase-py#1524](https://github.com/supabase/supabase-py/pull/1524)): Updated `listening-to-row-level-changes` note to list all supported operators (`eq`, `neq`, `lt`, `lte`, `gt`, `gte`, `in`, `like`, `ilike`, `is`, `match`, `imatch`, `isdistinct`) plus `not.` prefix and comma-AND. ### `apps/docs/spec/supabase_swift_v2.yml` - **OpenTelemetry tracing setup** ([supabase-swift#1101](https://github.com/supabase/supabase-swift/pull/1101)): Added `initialize-client-with-opentelemetry` example under the `initializing` section documenting the `OpenTelemetry` SwiftPM package trait, provider wiring, and known `_invokeWithStreamedResponse` limitation. ### `apps/docs/content/guides/telemetry/client-side-tracing.mdx` - **Merged Swift and Dart tracing docs** into the existing JS guide ([supabase-swift#1101](https://github.com/supabase/supabase-swift/pull/1101), [supabase-flutter#1564](https://github.com/supabase/supabase-flutter/pull/1564)). - **Converted to tabbed layout** (`<Tabs queryGroup="language">`) with JavaScript / Swift / Dart tabs, matching the pattern used across other multi-SDK guides. - Updated title to "Client-side tracing" and nav label accordingly. ## SDKs with no doc-worthy changes - **js**: Bug fixes only (auth session clearing, realtime heartbeat suppression) — no new API surface. - **kt**: PKCE for `resend()` — behavioral enhancement, no new spec entry needed. - **csharp**: Chore/compliance/maintenance only. --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Dart “OAuth Server” API docs for listing OAuth grants and revoking grants (including signed-in context and the `clientId` parameter), with examples. * Extended Dart Storage docs with a new `listBuckets` example using `ListBucketsOptions` for filtering, pagination, and sorting. * Updated Python Realtime docs with generalized PostgREST-style row filter operators and added examples for listening to selected columns. * Reworked the “Client-side tracing” guide across JS, Swift, and Dart, including expanded configuration and troubleshooting (trace propagation and `traceparent` details). * Renamed the telemetry navigation label to “Client-side tracing.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
b17a33fb26 |
fix: cleanup privatelink documentation (#48466)
Some light copy cleanup for privatelink documentation based on feedback. Fixes PRODSEC-232 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated PrivateLink guidance with revised architecture, supported ports, routing, and security group instructions. * Added labeled connectivity tests for direct PostgreSQL and PgBouncer connections. * Added connection-string examples for both connection methods. * Replaced public-connectivity instructions with optional network restriction steps and reorganized limitations guidance. * Refined PrivateLink availability wording across platform security documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3c903b7dfa |
Add Elastic Tile to Supabase Metrics API page (#48564)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature ## What is the current behavior? Elastic is not added as a tile in metrics API page. ## What is the new behavior? Now Elastic is supporting Supabase metrcis ingestion, hence it should be listed in the Metrics page. ![Uploading Screenshot 2026-08-03 at 4.31.46 PM.png…]() <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added Elastic as a supported metrics integration in the documentation. - Added an Elastic integration card with community labeling and a link to Elastic’s documentation. - Added Elastic to the monitoring metrics navigation and Metrics API guide resources. - Added Elastic branding and iconography to the metrics integration listings for easier recognition. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |