Commit Graph
38953 Commits
Author SHA1 Message Date
Danny White 4e686dfe56 keep the terms notice test aligned with its dismissal action 2026-10-06 15:49:28 +11:00
Danny White 9223489ad3 format 2026-10-06 15:39:20 +11:00
Danny White 933fb3554c tweaks 2026-10-06 15:04:20 +11:00
Danny White bd408597e1 notify dashboard users about the Terms of Service update 2026-10-06 14:22:10 +11:00
Joshen Lim be1ba651ed Add branching nav items to cmd k (#51255)
## Context

Adds a couple of branching nav items to Command K
- Create new branch
- Branch management
- Merge requests
- Github Connection (For branching)
- Branching feedback

Switch branch is still available, and only visible after a branch has
been created (status quo)

<img width="610" height="531" alt="image"
src="https://github.com/user-attachments/assets/3068184e-889d-44ed-8cf6-2afd59ffb109"
/>
2026-10-06 11:12:53 +08:00
Joshen Lim 642a02db49 Prevent enabling spend cap if org has projects with RRs (#51253)
## Context

Prevents organizations from enabling spend cap if the org has projects
with read replicas - We currently gate creation of read replicas to
ensure that orgs have spend caps disabled, but were missing the guard
for the other way around
<img width="662" height="378" alt="image"
src="https://github.com/user-attachments/assets/44ad036c-4c1b-48e8-beb7-f16f6170c9fb"
/>

## Other changes involved
- Refactored to use new `Sheet` and `Table` components in
`SpendCapSidePanel`
2026-10-06 11:12:35 +08:00
Pamela Chia 20d6f2197f chore(studio): remove privacy policy notice (#51299)
I removed the Studio Privacy Policy update notice that #50397 added on
2026-09-16, when Privacy Policy v4 took effect. It has been up for
almost three weeks, and the ToS v4 banner (#51109) goes out next. I did
the same in #44380, removing the March 2026 privacy notice after 15
days.

This is the exact inverse of #50397: the banner component and its test,
the banner ID, the dismissal local storage key, and the org-landing path
helper that only this notice used.

## To test

Tested on Vercel preview:
- [ ] In a fresh browser profile (no
`privacy-policy-update-2026-09-16-dismissed` key), open
`/organizations`: expect no Privacy Policy notice
- [ ] Open `/org/<slug>`: expect no Privacy Policy notice and the
project list renders normally
- [ ] Open a project's Logs page: expect the logs deprecation banner
behavior unchanged (only shows before its expiry)

## Linear
- fixes GROWTH-1322
2026-10-05 19:24:14 -07:00
claude[bot]andClaude a629c9c1ac Add hidden Supplemental Terms legal page (#51100)
<!-- ccr-slack-attribution -->
_Requested by **Nicole Kramer** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_

## Problem

No page existed yet for the upcoming "Supplemental Terms" document.
Nicole Kramer (Commercial & Product Counsel) needs a stable, linkable
URL to reference from future Terms of Service / Enterprise SaaS
Subscription Agreement updates, before the legal content itself is
ready. The page needs to be reachable by direct URL but not surfaced in
the visible Legal Hub nav yet, matching the existing "hidden" precedent
used for `/enterprise-terms`.

## Solution

Added a new page at `/legal/customer-resources/supplemental-terms`:

- `apps/www/pages/legal/customer-resources/supplemental-terms.tsx` — a
page component mirroring the existing Data Processing Addendum page
(`apps/www/pages/legal/customer-resources/data-processing-addendum.tsx`):
`DefaultLayout` + `PageHeader` (h1 "Supplemental Terms") +
`LegalDocVersions` rendering a single MDX version.
- `apps/www/data/legal/customer-resources/supplemental-terms/v1.mdx` —
placeholder body content (`_Content coming soon._`), no frontmatter/h1,
following this repo's existing legal MDX convention (the h1 is rendered
by `PageHeader`, not the MDX itself). Nicole will fill in the actual
legal content later.

**On "hidden":** I investigated the actual codebase state before
implementing, since the two precedents named didn't turn out to work the
same way:
- `/enterprise-terms` is genuinely hidden — it is not linked anywhere in
`apps/www/pages/legal/index.tsx`'s Legal Hub listing, and its `NextSeo`
meta sets `noindex: true, nofollow: true`.
- The Data Processing Addendum and Subprocessor List pages, by contrast,
**are** linked in the visible Legal Hub listing
(`apps/www/pages/legal/index.tsx`, "Customer Legal Resources" section) —
they are not hidden today.

Given that, this PR mirrors the DPA/Subprocessor List *structural*
pattern (route under `/legal/customer-resources/`, page-component +
versioned-MDX content) since that's what "under Customer Legal
Resources" means structurally in this codebase, but mirrors
`enterprise-terms`' *hidden* mechanism: the new page's `NextSeo` meta
sets `noindex: true, nofollow: true`, and — importantly — **no entry was
added** to the `sections` array in `apps/www/pages/legal/index.tsx`, so
it does not appear in the visible Legal Hub or any nav. The page is
reachable only via its direct URL.

Terms of Service and the Enterprise SaaS Subscription Agreement pages
were not touched.

## Review instructions

1. Confirm `/legal/customer-resources/supplemental-terms` renders with
h1 "Supplemental Terms" and placeholder body text.
2. Confirm the page does **not** appear anywhere on `/legal` (the Legal
Hub listing).
3. Confirm `apps/www/pages/terms.tsx` /
`apps/www/pages/enterprise-terms.tsx` (and their MDX content) are
unchanged.

## Checklist

- [x] I have read CONTRIBUTING.md
- [ ] N/A — no docs topic edited (legal page content is a placeholder,
not docs content)

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC

---
_Generated by [Claude
Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-06 13:09:25 +11:00
Pamela Chia 81da60392e feat(www): add multigres alpha form to /database (#51298)
The Multigres private alpha request form only lives at
/go/multigres-early-access (#51053), and nothing on the product site
links to it. I added the same form to /database, the way /compute embeds
its waitlist form.

The new section sits at the bottom of the page, directly above the
closing "Start your project" CTA: the go page's hero copy, the alpha
caveats, and a "Learn about Multigres" link to multigres.com on the
left, the form on the right. Fields, disclaimer, and redirect are read
from the go page definition. The form posts `{ slug:
'multigres-early-access', formId: 'form' }`, so the server resolves the
existing CRM config and submissions land in the same database as the go
page.

**Note:** the section throws at build time if the go page or its form
section is removed, so retiring the go page means removing this section
in the same change.

## To test
Tested on Vercel preview:
- [ ] Open /database and scroll to the bottom: expect a "Private alpha /
Multigres on Supabase" section directly above "Build in a weekend, scale
to millions", with the email and organization slug form, the alpha
caveats, and the Privacy Policy disclaimer
- [ ] Click "Learn about Multigres": expect multigres.com to open in a
new tab
- [ ] Resize to a phone width: expect the text stacked above the form
card with no horizontal scroll
- [ ] Open /go/multigres-early-access: expect its page and form
unchanged
- [ ] After merge, submit a test request from supabase.com/database:
expect a redirect to /go/multigres-early-access/thank-you and a new row
in the Multigres requests database

## Linear
- fixes GROWTH-1321
2026-10-05 18:50:48 -07:00
Ignacio Dobronich 22cdd05492 fix: update disk maxSize in pricing page (#51295) 2026-10-05 22:46:23 -03:00
Aditya MaruvadaandAditya Maruvada d21c20eae6 docs: add Multigres early access request link to the Multigres docume… (#51297)
…ntation

## Problem

Currently there's no way for users to request access to private alpha
for Multigres.

## Solution

Add a link to the form to fillout for customers to get access.


## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [X] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

Co-authored-by: Aditya Maruvada <aditya@Adityas-MacBook-Pro.local>
2026-10-05 17:16:16 -07:00
Danny White 5cc0450950 fix(www): plate State of Startups Sign in over the aurora (#51163)
## Problem

On `/state-of-startups`, the nav starts transparent over the aurora.
Default buttons use a translucent fill in dark mode, so Sign in (and
Dashboard) look see-through.

## Solution

Wrap those default nav buttons in `FloatingPlate`. Primary “Start your
project” is already opaque and unchanged.

| Before | After |
| --- | --- |
| <img width="1024" height="759"
alt="23474_296a1f8f952ae7f73ae9205e5db6bb9cda4cf0a904bc2d440d6395b5f12346ab"
src="https://github.com/user-attachments/assets/c247cdaa-06b0-46ad-b1f8-cee3e06fde8e"
/> | <img width="1024" height="759" alt="State of Startups 2026
Supabase"
src="https://github.com/user-attachments/assets/e9a1a0e0-9f2f-427f-a7d3-75e4e1cbba63"
/> |

## Review instructions

In dark mode:

1. [Live /state-of-startups](https://supabase.com/state-of-startups) ·
[Preview
/state-of-startups](https://zone-www-dot-com-git-dnywh-fixsos-sign-in-float-91d2b1-supabase.vercel.app/state-of-startups)
2. At the top of the page (transparent nav, before scrolling), check
Sign in: opaque plate, aurora does not show through the fill.
3. Scroll until the nav gains a solid background: Sign in should still
look normal.

Ideally you could sign in and confirm the now ‘Dashboard’ button gets
the same plate treatment. But that’s not possible until merge.
2026-10-06 10:46:59 +11:00
Danny White 36364e7df3 fix(www): stop wrapping oklch semantic tokens in hsl() (#51161)
## Problem

Semantic colour tokens (`--border-*`, `--foreground-*`,
`--background-*`) now resolve to full `oklch(...)` values. Call sites
that still wrapped them in `hsl(var(--…))` are invalid CSS and drop the
colour (Partners ambient grid was the clearest case).

Brand / destructive / warning channel tokens still correctly use
`hsl(var(--…))` and were left alone.

Presence avatar stack polish is in
https://github.com/supabase/supabase/pull/51164.

## Solution

- Use bare `var(--…)`, `currentColor`, or Tailwind utilities for
semantic tokens. Opacity cases use `oklch(from var(--…) l c h / …)`.
- Partners grid: fix, and then use `text-foreground/20` in light,
`text-foreground/30` in dark for optical correction.

| Before | After |
| --- | --- |
| <img width="1860" height="1106" alt="CleanShot 2026-10-02 at 16 29
08@2x"
src="https://github.com/user-attachments/assets/4554b0c9-22cf-4b06-bbe3-798e8b15304e"
/> | <img width="1852" height="1112" alt="CleanShot 2026-10-02 at 16 28
44@2x"
src="https://github.com/user-attachments/assets/20ccbc80-5eaa-49e6-8f94-48b99dc01474"
/> |
| <img width="1024" height="759" alt="20701"
src="https://github.com/user-attachments/assets/a4e578cf-5adb-4f7a-a53b-870a51f5f948"
/> | <img width="1024" height="759" alt="59176"
src="https://github.com/user-attachments/assets/dda3fc2d-d86b-45a5-adca-403223cc5f33"
/> |

## Review instructions

1. [Live /partners](https://supabase.com/partners) · [Preview
/partners](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/partners).
Ambient dashed grid under the hero (light and dark).
2. [Live /database](https://supabase.com/database) · [Preview
/database](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/database).
Postgres elephant idle outline should be muted grey, not black. Hover
still brand green.
3. [Live /state-of-startups](https://supabase.com/state-of-startups) ·
[Preview
/state-of-startups](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/state-of-startups).
Chart **More AI-generated code, less likely to be monetizing yet**:
horizontal gridlines at 0/25/50/75/100% should render.
4. Storage / Edge Functions changes are correctness-only (shadows, idle
borders, a top fade). Near-invisible to the naked eye; skip unless
debugging.
2026-10-06 10:28:36 +11:00
Danny White 0cb8bd95dd feat(studio): add spot colour control to Appearance (#50782)
## Problem

The theme's primary hue can change in CSS, but Appearance had no way to
try other spot colours. That makes it hard to find controls whose colour
still depends on the fixed Supabase brand palette.

## Solution

Add a **Spot color** control under Appearance → Theme colors
(employee-only via ConfigCat `appearanceSpotColor`, targeted to Supabase
Team Email).

### Spot color UX
- Rainbow spectrum track with a thin outline so pale tracks stay visible
- Live trifecta swatches for `--primary-solid`, `--primary`, and
`--primary-bright` (darkest → lightest) next to the degree readout
- Drag updates are rAF-batched so React paint and CSS preview stay to
one frame

### Canvas tint coupling
- `--surface-hue` is derived in CSS as `calc(var(--primary-hue) +
var(--surface-hue-offset))`
- Dark: offset `0` (same hue as spot)
- Light: offset `180` (complementary canvas tint; brand green ≈157.5° →
rose ≈337.5°)
- No JS override of `--surface-hue`. Changing Spot color moves primary
controls and the low-chroma canvas tint together

### Other theme sliders
- Renamed **Color intensity** → **Surface tint** (it only drives the
neutral ramp via `--chroma`, not spot chroma)
- Meaning-shaped tracks for every knob (spectrum, grey→tint, soft→hard,
dark→light, flat→lift)
- Same outline treatment on those tracks

| Before | After |
| --- | --- |
| <img width="1476" height="2174" alt="CleanShot 2026-10-05 at 15 02
21@2x"
src="https://github.com/user-attachments/assets/d08b0fa8-32af-450e-adce-861f59c9d6ca"
/> | <img width="1474" height="2354" alt="CleanShot 2026-10-05 at 14 56
35@2x"
src="https://github.com/user-attachments/assets/9a1e6183-a4ba-4c8e-a458-bb0eea946db8"
/> |
| _Anyone else_ | _With staff flag, custom settings_ |

## Review instructions

1. Confirm ConfigCat flag `appearanceSpotColor` is on for your staff
account (or flip it in the Dev Toolbar).
2. Open `/account/me` → **Appearance → Theme colors**.
3. Without the flag: Spot color is hidden; other theme sliders still
work.
4. With the flag: drag Spot color in light and dark. Primary controls
and canvas tint should move together; Supabase brand assets should stay
fixed.
5. Raise Surface tint and confirm the canvas hue follows the
complementary (light) or same-hue (dark) offset.
6. Refresh, switch modes, and use **Reset** to check persistence and
defaults.
2026-10-06 10:11:26 +11:00
Miranda Limonczenko 17512de71d docs(database): connect security definer to the default execute grant (#50817)
Closes DOCS-1319

Part 4 of 4 in stack #50823. This PR carries **additions**: content the
page never had.
Style, structure, and snippet fixes land below it in #50820, #50821, and
#50822.

## Problem

Developers and AI agents read the Database functions guide. The guide
shows how to write a function inside the database.

A function runs in one of two modes. In `invoker` mode it runs as the
caller. In `definer` mode it runs as the creator.

The guide gives one rule for `definer` mode. The rule is to set the
`search_path`. A reader who obeys that rule still gets an unsafe
function.

I wrote a function that obeys the rule. I pinned the search path to the
empty string. Then I called it three times.

| Caller | Result |
| --- | --- |
| The order's owner | 4330 cents, correct |
| A different signed-in customer | 8660 cents, another customer's order
|
| Nobody, no session at all | 8660 cents |

Every role can call a new function in `public`. The guide states that
fact under Function privileges. It never connects the fact to the
`definer` rule. A reader has no reason to look.

Customers report the same failure. AI tools choose `definer` mode. The
function then answers the front end with no session. The hole is hard to
find, because no policy is involved in it.

## Solution

- **Joins the two halves in the Security definer subsection.** A
`danger` admonition states three facts:
  - The function runs with its creator's privileges.
- A function created in the Dashboard or by a migration is owned by
`postgres`, which bypasses Row Level Security.
  - Every role can call the function by default.

The admonition then gives the fix. Check ownership inside the function
body, and narrow the execute privilege as well.

- **Applies the regrant to both ways of restricting execute.** The
`grant execute` block sat inside the second way. A reader who took the
first way saw no way to restore their own app's access.

**Not changed:** the existing definer paragraph, the page structure, and
the Function privileges statements. The lower PRs in the stack own
those.

**No eval re-run.** The guide scored 6 of 6 on three baseline runs, so
the score has no room to move. All three runs chose `invoker` mode. The
eval never enters the branch this PR fixes. Measuring it needs a new
check, not a re-run.

**Diff size:** one file, 15 lines added and 4 removed.

## Manual testing

1. Open the [Security definer vs invoker
section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker)
on the deploy preview. The admonition renders as a red `danger` panel
below the definer paragraph. The two fixes appear as bullets.
2. Click the `Function privileges` link inside the admonition. It jumps
to the [Function privileges
section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#function-privileges)
on the same page.
3. Read that section. The `grant execute` block sits after the numbered
list. It applies to both ways of restricting execute.
4. Run `pnpm build:guides-markdown` from `apps/docs`. Read
`apps/docs/public/markdown/guides/database/functions.md`. The admonition
appears as a `Danger:` paragraph. Discard the `manifest.json` change.
5. Run `npx prettier --check
apps/docs/content/guides/database/functions.mdx`. Clean.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded guidance on the security risks of `security definer`
functions, including their privileges, interaction with Row Level
Security, and default execution access.
* Added recommendations for checking data ownership and restricting
execution to intended roles.
* Clarified that pinning `search_path` does not limit execution
privileges.
* Presented the function-privileges example separately from the
default-privileges instructions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions)
| `every signed-in caller` |

## Review instructions

This PR adds one admonition and moves one code block. The question is
whether the admonition is correct and whether an agent reading the page
would act on it.

1. Open the preview at [Security definer vs
invoker](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker).
A red `danger` panel sits below the definer paragraph.
2. **Read the first paragraph for accuracy.** It claims the function
runs with its creator's privileges, that a function created in the
Dashboard or by a migration is owned by `postgres`, and that `postgres`
bypasses Row Level Security. This matches [Use security definer
functions](https://supabase.com/docs/guides/database/postgres/row-level-security#use-security-definer-functions)
in the RLS guide. Flag any drift.
3. **Read the two bullets for sufficiency.** The ownership check is the
primary fix. The execute grant is listed as a complement, not an
alternative, because granting to `authenticated` still returns any
user's row to every signed-in caller. Confirm the wording can't be read
as "either one is enough."
4. Click the `Function privileges` link inside the admonition. It jumps
down the same page.
5. In the Function privileges section, confirm the `grant execute` block
sits after the numbered list rather than inside item 2, so it applies to
both ways of restricting execute.
6. **Check the agent-facing copy.** Open [the markdown
export](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions.md)
and find `Danger:`. This is what an agent reads, and it is the audience
this PR exists for.

**If you only have two minutes:** do steps 3 and 6. Step 3 is the
correctness of the advice. Step 6 is whether the audience that prompted
the ticket actually receives it.

**A note on running SQL from this page.** Don't hand-paste from the
rendered page. Blocks are split across tabs, and the Data tab in
Returning data sets holds markdown tables that look pasteable but are
not SQL. Use the `.md` export of the page, which flattens every tab in
page order. #50822 has a copy-paste command for this.
2026-10-05 15:18:01 -07:00
Miranda Limonczenko d8b0a3e87f docs(database): make the guide's snippets run in document order (#50822)
Part 3 of 4 in stack #50823. This PR carries **technical revision
only**: claims that produce a wrong outcome for a reader.

## Problem

This PR came from running a technical assessment using `/test-the-docs`.

A reader pastes the guide top to bottom. Two snippets fail.

The `planets` table uses a `serial` primary key, then the seed sets ids
explicitly. Explicit ids don't advance the sequence, so it stays at 0.
The `add_planet('Jakku')` example then draws id 1, which the seed
already used:

```
ERROR:  duplicate key value violates unique constraint "planets_pkey"
DETAIL:  Key (id)=(1) already exists.
```

The `security definer` example re-creates `hello_world` with `create`
rather than `create or replace`, so it collides with the function from
Basic functions:

```
ERROR:  function "hello_world" already exists with same argument types
```

The Data tab spells the planet Tatooine. The SQL tab spells it Tattoine.

Two debugging snippets read `attendance_table` and `some_table`. No
fence creates either, and neither is marked as omitted.

## Solution

- **Seeds `planets` and `people` without explicit ids.** The sequence
advances, so `add_planet` succeeds. This also settles Tattoine against
Tatooine.
- **Uses `create or replace` in the definer example**, so it no longer
collides.
- **Marks the two assumed tables** in the debugging snippets with a
comment.
- **Points the CREATE FUNCTION link at the current Postgres docs.** It
pointed at 9.1, while the intro already links the current version of the
same page.

**Verification.** I ran every `sql` fence from the guide in document
order against Postgres 15 in a throwaway container, with `anon` and
`authenticated` created first. Before these changes, two fences errored.
After them, the sequence runs clean.

## Manual testing

1. Start a throwaway Postgres: `docker run --rm -d --name pgcheck -e
POSTGRES_PASSWORD=pw postgres:15`.
2. Create the Supabase roles the guide references: `docker exec -i
pgcheck psql -U postgres -c "create role anon; create role
authenticated;"`.
3. Paste every `sql` block from the guide, in page order, into `docker
exec -i pgcheck psql -U postgres`. No statement errors.
4. Run `select * from planets;`. Tatooine, Alderaan, Kashyyyk, and
Jakku, with sequential ids.
5. Remove it: `docker rm -f pgcheck`.

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/functions)
| `('Tatooine')` |
| Docs | New page, 404 in production |
[/docs/guides/database/debugging-functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/debugging-functions)
| `assumes an attendance_table` |




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
  - Clarified the required column types in database function examples.
- Expanded guidance on function return values, including `INSERT`,
`UPDATE`, and `DELETE` statements with `RETURNING` clauses.
- Updated SQL examples to show table creation and automatically
generated IDs, corrected the spelling of “Tatooine,” and refreshed the
PostgreSQL reference link.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:18:00 -07:00
Miranda Limonczenko 8b148f93c1 docs(database): regroup the database functions guide and split out debugging (#50821)
Part 2 of 4 in stack #50823. This PR carries **structure only**: moves,
regrouping, and the connective text the new shape needs. Reworded prose
already landed in #50820.

## Problem

This PR is running a structure edit.

A reader arrives from search and has to find one thing. The guide gave
them eight top-level headings, no grouping, and no opening outline. The
style guide caps a group at 5 ± 1.

Four of those headings are the action path: Getting started, Basic
functions, Returning data sets, and Passing parameters. Nothing marked
them as one sequence.

`Suggestions` held four unrelated things: an Edge Functions comparison,
two security topics, and a three-part debugging reference. The heading
names nothing the reader is doing.

Debugging was the largest thing on the page. It sat at H3 with three H4
children, and it shared only the word "function" with the rest of the
guide.

## Solution

- **Groups the four procedures** under `Create a database function`, so
the action path is one unbroken sequence.
- **Moves the Edge Functions comparison ahead of the procedures.** A
reader choosing between the two needs it before the steps, not after
them.
- **Groups the two security sections** under `Secure a database
function`.
- **Splits debugging onto its own page**,
`guides/database/debugging-functions`. It is registered in the Database
sidebar and cross-referenced from the guide.
- **Folds `Deep dive` into `Resources`.** Two trailing headings did one
job.
- **Adds an opening outline** linking each group and saying when to use
it.
- **Renames the frontmatter title** to sentence case, `Database
functions`.

## Manual testing

1. Open the [guide on the deploy
preview](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions).
Five top-level headings, with the opening outline linking each group.
2. Open the [new debugging
page](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions).
It appears in the Database sidebar under Managing database functions.
3. Follow a repointed link. Open [Postgres log
config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config)
and click Database Function Logging. It lands on the new page at General
logging.
4. Run `pnpm build:guides-markdown` from `apps/docs`. Both pages appear
under `public/markdown/guides/database/`. Discard the `manifest.json`
change.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a guide to debugging Postgres database functions, with examples
for logging, error handling, and inspecting query results.
* Added the guide to Database navigation and updated related resources
to link to it.
* Reorganized the database functions guide to clarify function creation,
security, and privileges.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions)
| `Secure a database function` |
| Docs | New page, 404 in production |
[/docs/guides/database/debugging-functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions)
| `Debugging database functions` |
| Docs |
[/docs/guides/database/postgres/postgres-log-config](https://supabase.com/docs/guides/database/postgres/postgres-log-config)
|
[/docs/guides/database/postgres/postgres-log-config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config)
| `Database Function Logging` |

## Review instructions

This PR moves content. The risk is a broken link, not bad prose.

1. Open the preview of the guide. Count the top-level headings in the
right-hand outline. There are five, down from eight.
2. Read the four bullets at the top of the page. Each links to a group,
and each says when to use it. Click all four and confirm each lands on
its section.
3. Open the new debugging page from the second row. Confirm it appears
in the left sidebar under **Managing database functions**.
4. **Check the three locked anchors.** Append each to the preview guide
URL and confirm the page jumps: `#quick-demo`,
`#security-definer-vs-invoker`. Then append `#general-logging` to the
**debugging page** URL. Four other pages link to these.
5. Open the Postgres log config preview from the third row. Find
**Database Function Logging** in the Resources list and click it. It
lands on the new debugging page, not on a dead anchor.
6. Compare the prose against the live page. **No sentence should have
changed** beyond the new opening outline and the cross-reference to the
debugging page.

**If you only have two minutes:** do steps 4 and 5. A moved section that
leaves a dead anchor is the failure this PR could cause.

**A note on running SQL from this page.** Don't hand-paste from the
rendered page. Blocks are split across tabs, and the Data tab in
Returning data sets holds markdown tables that look pasteable but are
not SQL. Use the `.md` export of the page, which flattens every tab in
page order. #50822 has a copy-paste command for this.
2026-10-05 15:18:00 -07:00
Pamela Chia a9078612f2 fix(www): stop cross-zone link prefetch (#51066)
About 95% of the 404s served on supabase.com are App Router RSC
prefetches (`?_rsc=`) that www `<Link>`s fire at paths another zone
serves: `/docs`, `/dashboard`, `/library`, and the footer's
`humans.txt`, `lawyers.txt` and `security.txt`. Next.js can't prefetch
or client-navigate across multi-zone boundaries, so each prefetch 404s
even though the link itself works. I turned every www link into another
zone into a plain `<a>` and added a lint rule so new ones stay that way.

**Changed:**
- **Cross-zone links are plain anchors**: links that always leave www
(literal `/docs`, `/dashboard` and `.txt` hrefs, absolute
`https://supabase.com/dashboard` URLs, the `getDashboardCtaHref` CTAs)
render `<a>`. Renderers whose href comes from data (nav, footer, plan
and add-on CTAs, product cards) branch on `isCrossZoneHref`, which reads
the zone list from `lib/rewrites.js`. In-zone links stay `<Link>` and
keep prefetching.
- **New literal links can't regress**: `www/no-cross-zone-link` errors
on a `next/link` `<Link>` whose literal or template href points at
another zone. It evaluates `lib/rewrites.js` as production, so `/docs`
counts in every environment.
- **Click tracking survives the full navigation**:
`sign_in_button_clicked`, `start_project_button_clicked` and
`www_pricing_plan_cta_clicked` now send with `keepalive`, like
`sign_in_submitted` already did, so an immediate page load can't cancel
them. The mobile nav Sign in and Start your project buttons used
`legacyBehavior`, which never called their `onClick`: PostHog has no
`Mobile Nav` location for either event in the last 30 days. Those clicks
report from this PR on.
- **Typecheck no longer crashes**: the functions page's default export
inferred a type through `RealtimeLogs`'s unexported `Props`, which makes
the native TypeScript compiler panic during `tsc --noEmit`. I exported
`Props`.

**Note:** the lint rule only sees literal hrefs. A new renderer whose
href comes from data needs its own `isCrossZoneHref` branch, and review
is the only check on that.

## To test
`/docs` is only rewritten on production and absolute
`https://supabase.com/...` links are cross-origin on a preview, so the
preview proves the relative non-docs cases (`/dashboard*`, `/library`,
the footer .txt files). `/docs/...` prefetches still appear on the
preview because it has no docs rewrite.

Tested on Vercel preview:
- [x] Open `/` with the network tab filtered to `_rsc` and scroll to the
footer: no requests for `/dashboard*`, `/library`, `/design-system`,
`/kb`, `/evals`, `/humans.txt`, `/lawyers.txt` or
`/.well-known/security.txt`, while in-zone ones such as `/pricing`,
`/features` and `/blog` still appear
- [x] Same check on `/pricing`, `/auth`, `/database`, `/storage`,
`/realtime`, `/edge-functions`, `/blog` and a blog post: no `_rsc`
requests to `/dashboard*`, `/library` or the footer .txt files
- [x] Open the Developers dropdown on desktop and the mobile menu at
390px: no new `_rsc` requests to `/dashboard*` or `/library`
- [x] Click header Docs, footer Humans.txt, the hero Start your project
button and the pricing Free plan button: each lands where it did before
(`/docs`, `/humans.txt` text, `https://supabase.com/dashboard/sign-up`,
`https://supabase.com/dashboard/new?plan=free`). Signed out, the Free
plan button lands on the dashboard sign-in with
`plan=free&returnTo=%2Fnew`
- [x] Click the hero Start your project button: the
`/platform/telemetry/event` POST with `start_project_button_clicked`
completes with a 2xx after the page starts navigating. 201 with the
navigation held; on the real navigation the event still reached staging
PostHog
- [x] At 390px, open the mobile menu and click Sign in: a
`/platform/telemetry/event` POST with `sign_in_button_clicked` and
`buttonLocation: "Mobile Nav"` fires. Start your project in the same
menu also sends `start_project_button_clicked` with `buttonLocation:
"Mobile Nav"`
- [ ] Signed in, load `/`: no `/dashboard/projects?_rsc=` request (not
run: the preview origin has no signed-in session)
- [x] Open the desktop Product dropdown and the Product section of the
390px mobile menu: Compute shows its Private Alpha badge and the other
products show none (checks the master merge into `MenuItem`)

After deploy, `/` and `/pricing` on supabase.com show no `_rsc` requests
to `/docs*`, `/dashboard*` or `/library`. After a full day, the share of
supabase.com 404s carrying `_rsc=` should drop from about 95% to under
10%, and `sign_in_button_clicked` and `start_project_button_clicked`
should start showing a `Mobile Nav` location in PostHog.

## Linear
- fixes GROWTH-1294
2026-10-05 15:17:04 -07:00
Miranda Limonczenko 63c165311e docs(functions): act on the Edge Function auth eval findings (#50886)
Closes DOCS-1318

## Problem

An agent was asked to build an Edge Function returning the order history
for whoever is signed in and calling it. Three runs, all correct: each
one used the page's `auth: 'user'` pattern and read through the
caller-scoped client. The eval scores 7 of 7, including the guide-read
check.

These are the gaps that showed up around it.

| Finding | What the page does now | Why it matters |
| --- | --- | --- |
| Two clients, no guidance | The first example destructures `supabase`
and `supabaseAdmin` together and labels the second "bypasses RLS
(service role)" | A reader skimming for the client to use sees two, and
one of them is wrong for that section |
| No consequence named | "Bypasses RLS" is the strongest phrasing
anywhere | A handler querying a shared table through the privileged
client without a filter returns every user's rows. The page never said
so |
| `verify_jwt` as a value to set | Appears six times, five of them as
something to change | Switching it off to clear a 401 in development is
a reported failure. The page never said the default is the safe one |


## Solution

- **Say which client to reach for**, in the section where both are
handed over.
- **Name the outcome** in a `danger` admonition: a handler that queries
a shared table through `ctx.supabaseAdmin` without filtering by the
caller's ID returns every user's rows.
- **Frame `verify_jwt = true` as the default to leave alone** on
user-facing functions, and say what turning it off costs.
- **Say every project starts with a secret key named `default`.**

**Not asserted here:** the eval is not re-run. It was already at 7 of 7,
so there is no headroom to measure an improvement. A candidate new check
is proposed on DOCS-1318.

## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth)
|
[/docs/guides/functions/auth](https://docs-git-docs-functions-auth-eval-findings-supabase.vercel.app/docs/guides/functions/auth)
| returns every user's rows |

## Review instructions

1. Open the live and preview links side-by-side.
2. Read Authenticated user calls on the preview. See a paragraph on
choosing between `ctx.supabase` and `ctx.supabaseAdmin`, then a `danger`
admonition naming the every-user's-rows outcome.
3. See the same section say to leave `verify_jwt = true` on for
user-facing functions.
4. Read the note under Service-to-service calls. See it mention the
`default` secret key.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified that `secret` and `publishable` authentication modes accept
the `default` key, and documented how default, wildcard, and additional
keys are handled.
* Explained that JWT verification is enabled by default and that
disabling it leaves `withSupabase` as the only caller-verification step.
* Added guidance that admin queries bypass row-level security and should
be scoped to the caller when accessing shared tables.
* Clarified that service-to-service authentication with `secret`
validates only the `default` key.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:14:27 -07:00
Miranda Limonczenko 259dbe11f1 docs/functions auth structure (#50885)
## Problem

Restructure the topic based off of the PRed Style Guide.

## Solution

- **Group the seven sections into three.** A concept opener, `Choose an
auth mode`, holds the mode table. `Secure your function` holds the six
patterns. `Environment variables` stays last as the fact group.
- **Add an intro outline** linking the three groups, and a group
introduction for the patterns.
- **Move the Authorization headers link below the mode table**, so the
sentence that introduces the table sits next to it.
- **Correct the content listing entry** to match the page's own title.

**Anchors:** every heading text is unchanged. Five headings move from
`##` to `###`, which preserves the slug. The in-page link to
`#external-webhooks` and the two existing redirects in
`apps/www/lib/redirects.js` all still resolve. Verified by grepping the
repo for `functions/auth#` before and after.


## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth)
|
[/docs/guides/functions/auth](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions/auth)
| Choose an auth mode |
| Docs |
[/docs/guides/functions](https://supabase.com/docs/guides/functions) |
[/docs/guides/functions](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions)
| Securing Edge Functions |

## Review instructions

1. Open the live and preview links side-by-side.
2. See three top-level entries in the preview's table of contents, with
six nested under `Secure your function`.
3. Load `/docs/guides/functions/auth#external-webhooks` on the preview.
See the page jump to that section.
4. Open the second preview link. See the listing card read "Securing
Edge Functions" rather than "With supabase-js".

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reorganized the authentication guide with a table of contents and
clearer sections on choosing an auth mode and securing a function.
* Clarified that the guide covers all supported auth modes, combining
modes, and custom error responses.
* Renamed the guide listing to “Securing Edge Functions” and updated its
description to mention declaring accepted credentials.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:14:27 -07:00
Anthony Lio dcf266c360 feat(docs): update search v2 ui (#51175) 2026-10-05 20:33:19 +00:00
47fd296fc1 Add Flick Games case study (#51285)
## Problem

New customer case study for the Case Studies content track: Flick Games,
an indie UK games studio running Art of Solitaire and Goalman on
Supabase.

## Solution

Adds `apps/www/_customers/flick-games.mdx` plus the logo
(on-light/on-dark) and quote-avatar assets. Content is ready for
design/eng review. Tracked in
[MARKET-2252](https://linear.app/supabase/issue/MARKET-2252/case-study-flick-games-sept-23).

## Review instructions

1. Open the preview link for `/customers/flick-games`.
2. Check the logo renders correctly in both light and dark mode, and
that both quote avatars load.
3. Read through for tone and flow.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-05 12:23:52 -07:00
09a245d72d [FE-4520] fix(studio): hide Realtime setup for published tables (#51152)
The Realtime Inspector now checks the Realtime publication before
showing setup guidance. Projects with published tables get the
join-channel view even before this Inspector session receives any
messages; unconfigured projects keep the setup guide.

Setup guidance also stays hidden while publications are loading or
unavailable. Joining a channel and displaying received messages retain
their existing behavior.

Addresses
[FE-4520](https://linear.app/supabase/issue/FE-4520/realtime-inspector-ui-implies-i-am-not-using-realtime-despite-already).

## To test

- With no tables in `supabase_realtime`, open Realtime → Inspector and
confirm the setup guide appears.
- Enable Realtime on a table and confirm a client receives a database
change. Open the Inspector without joining a channel: it should show
“Join a channel to start listening to messages” and no setup guide.
- Join a channel, trigger a table change, and check the event and
payload appear. Stop listening and confirm messages remain visible.
- Open Policies, then return to the Inspector and confirm the setup
guide stays hidden for the configured project.
- Join a broadcast-only channel with no incoming messages and confirm
the messages view appears immediately.

## Validation

Reproduced the original prompt locally with a working Realtime table,
then verified the fix in the browser, including an independent client
subscription, a live INSERT in the Inspector, navigation, stopping, and
the unconfigured state. Temporary test data and services were cleaned
up.

All nine new regression tests pass; four fail against the original code.
Typecheck, formatting, lint ratchet, Knip, and the case-sensitivity
check pass. The full Studio suite passed 7,799 tests with one unrelated
Explorer test failure; that test passed on a focused rerun alongside the
Inspector tests.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* The Realtime inspector keeps the messages view visible while
publication status is loading or unavailable, and when a channel is
joined or messages are present.
* Setup guidance appears only after publications load successfully and
confirm that Realtime is unavailable, with no channel or messages to
show. This includes cases where there are no publications, the Realtime
publication has no tables, or only a differently named publication
exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-05 12:05:21 -07:00
Miranda Limonczenko a5688423d0 docs(cli): restructure and tighten the CLI getting started guide (#50736)
Closes DOCS-1320

Was the bottom of a two-PR stack. The commit from #50680 moved here, so
that PR is closed and this one carries both changes.

## Problem

The CLI getting started guide had accumulated structural and prose
problems, none of which change what the page claims:

- **Nine flat H2 headings**, with Beta channel and Updating the Supabase
CLI sitting between installing and running. A first-time reader crossed
about 150 lines of beta and upgrade tabs before reaching `supabase
init`.
- **The introduction opened with a two-step procedure under no
heading**, listing `init` and `start` before the CLI is installed. Its
first sentence named the tool and where it runs rather than what the
reader gets.
- **Running a local Supabase project ran concept, fact, procedure, and
process together** as one stretch of prose, so the two commands the
reader has to run sat in paragraphs between the Docker background and
the first-run note.
- **Task headings mixed gerunds with imperatives:** Installing, Running,
Stopping, and Updating next to Access and Manage.
- **No navigation.** A long guide that mixes information types opened
straight into commands, with no outline of its major groups. The sidebar
contents is not a substitute: it isn't part of the document, and the
generated markdown an agent reads has no sidebar at all.
- **Four more sequences were prose.** Installing via npm, installing a
Linux package, the pre-upgrade backup, and opting out of telemetry each
had to be followed in order with nothing marking the order.
- **Smaller things:** the Studio screenshot's alt text named the topic
its heading already states, two links used "note above" and "here" as
their text, and an admonition restated where `sb_publishable_...` comes
from.

## Solution

Twelve commits, one change type each, plus a master merge and its fixup.

- **Style.** The install-method callout drops from four blocks to two
paragraphs and uses the documented `title` prop. Active voice on the
Postgres, analytics, and telemetry instructions. Descriptive link text.
Alt text that describes the Studio screenshot rather than naming it. Cut
the admonition restating `sb_publishable_...`.
- **Structure.** Beta channel and Updating the Supabase CLI move out of
the getting started path.
- **Grouping.** Local setup goes under Set up a local project, updating
and beta builds under Change your CLI version. The intro's `init` and
`start` list gets a Quickstart heading.
- **Value statement.** The opening sentence now says what the reader
gets.
- **Procedure format.** Running a local Supabase project leads with the
container runtime prerequisite, then four numbered actions, then the
first-run download as an outcome. Starting the container runtime is its
own step, since the old prose only assumed it with "with a container
runtime running".
- **Imperative headings.** Install, Run, Access, Stop, Update, Use the
beta channel.
- **Four more procedures.** npm install, Linux packages, the pre-upgrade
backup, and telemetry opt-out. The three pre-upgrade commands were one
unexplained block inside an admonition, so each step now says what its
command does. Re-enabling telemetry moves to a sentence, since it's the
reverse action rather than a step.
- **Intro navigation** listing the major groups, each line saying what
the reader gets from it.
- **Connect to a hosted project** (from #50680). A new section between
Stop local services and Change your CLI version, saying the stack runs
only on the reader's machine and nothing reaches a hosted project until
they sign in and link one, then pointing at the page that owns the
procedure. No commands. The `init` step gains a sentence saying it
creates local files only, and the value statement and intro navigation
cover the added goal.
- **Style guide and word list fixes** from an audit of the page against
`CONTRIBUTING.md` and `WORD_LIST.md`. `directory` over `folder` in
command-line contexts, `might` over `may`, present tense over `will`, a
noun after `this`, no `above` as a pointer, concrete verbs over
`manage`, no time-relative `latest`, no parentheses for supplementary
information, and an impact-first `caution` on the pre-upgrade callout.
The container runtime list becomes a table of tool and platforms, and
the group heading becomes Change your CLI version.


## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/local-development/cli/getting-started](https://supabase.com/docs/guides/local-development/cli/getting-started)
|
[/docs/guides/local-development/cli/getting-started](https://docs-git-docs-cli-getting-started-edits-supabase.vercel.app/docs/guides/local-development/cli/getting-started)
| Change your CLI version, Connect to a hosted project |

## Manual testing

1. Open the docs preview link above.
2. Read the introduction. It opens with a value statement, then links
the four major groups. Under Quickstart, the install-method callout
explains how the install method changes the command you run.
3. Read the On this page list. It nests: Quickstart, Set up a local
project with four sections under it, Change your CLI version with two
sections under it, Telemetry, Learn more.
4. Check Run a local Supabase project renders four numbered steps, with
code blocks inside steps 3 and 4. Check the npm tab of Install the
Supabase CLI renders three, and How to opt out renders two.
5. Load the page at `#installing-the-supabase-cli`, `#beta-channel`, and
`#updating-the-supabase-cli`. All three land on their sections despite
the renamed headings.
6. Load the legacy path
`/docs/guides/cli/getting-started#updating-the-supabase-cli`. It
redirects to the current path and keeps the fragment.
7. Check the introduction's group list includes Connect to a hosted
project, and that the section appears in the On this page list between
Stop local services and Change your CLI version.
8. Check that section is two sentences and a pointer, with no commands.
9. In Run a local Supabase project, select the "Connect to a hosted
project" link in step 3. The page scrolls to that section.
10. Follow both outbound links from the new section and confirm they
resolve, including the `#configure-github-actions` fragment.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Reorganized the local development guide with a clearer quickstart,
setup steps, service access instructions, and CLI version guidance.
* Expanded installation examples to include bun and clarified
package-runner commands.
* Clarified upgrade, backup, container cleanup, and telemetry
instructions.
  * Added a reference to the Microsoft Writing Style Guide.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 11:22:13 -07:00
Jeremias Menichelli 53ecbf9f2a chore: Add telemetry to search v2 user actions (#51146)
## Problem

We need to collect data from search v2 experiment usage.

## Solution

Add telemetry to search v2 modal being opened, closing, sending a query
and clicking a search v2 result.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. Open the preview link and add the search v2 flag query:
`?docs-search-v2=search-v2-active`
2. Trigger all actions mentioned above
3. Telemetry data should be sent on the network tab


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Documentation search activity is now recorded when the dialog opens
from the keyboard shortcut or search input, and when it closes. Search
submissions include the query and whether results were found; selected
results include their destination and the highlighted query. This adds
visibility into key search interactions without changing how search
results or highlighting work.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 13:22:22 -03:00
Jeremias Menichelli 42dc4dbe90 chore: Add observability to search_v2 route (#51149)
## Problem

Our new Search V2 edge function can fail, we want to know when that
happens.

## Solution

Added the common Sentry wrapping plus try/catch strategy to the edge
function so we can add alerts to our Sentry dashboards and report
channels.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

There's no way to reproduce this for the moment.


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Search requests that encounter unexpected server-side errors now
receive a handled 500 response instead of an unhandled failure. Errors
returned by the search service also produce a 500 response, making
failure behavior more consistent for clients. The search query and
result-limit behavior remain unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 13:22:12 -03:00
Katerina Skroumpelou d7cac841c4 docs: state the adapter removal date in the server frameworks guide (#51276)
The server frameworks guide still said the adapters "will be deprecated
soon" and would be "removed in a future major". They have been
deprecated since `@supabase/server` 1.9.0, with `@deprecated` tags
shipping in 1.9.1, and the removal date is December 1, 2026. This PR
updates the two sentences to state that date and drops the wording about
the release shape, which is not decided.
2026-10-05 16:08:24 +00:00
Jordi Enric 7d04c43082 fix(logs): default unified logs to otel DEBUG-228 (#51089)
## Problem

Unified Logs could start legacy BigQuery requests while ConfigCat
loaded, then switch to OTEL when the flag resolved.

## Fix

Default Unified Logs to OTEL unless otelUnifiedLogs is explicitly false.
Use that selection for list, count, chart, facet, detail, download, and
manual refresh requests. Keep BigQuery as an explicit opt-out until the
legacy backend is removed.

## Validation

- Studio typecheck passed locally.
- Existing Unified Logs utility tests passed (21 tests).
- The focused Unified Logs query test file was removed as requested;
backend-selection and manual-refresh regressions are no longer covered
by that suite.
- CI checks are running on the current head.

Tracks
[DEBUG-228](https://linear.app/supabase/issue/DEBUG-228/prevent-bq-queries-before-the-feature-flag-loads).
2026-10-05 17:43:15 +02:00
kemal.earthandAli Waseem b028908136 feat(studio): add never option to scoped pat expiry (#51273)
## Problem

When building scoped pat's we had omitted the option to have them never
expire.

## Solution

This re-adds the option to select "never" and it comes with the caveat
of an admonition to warn the user that they would need to manually
delete or revoke this token.

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. Open /account/tokens
2. Click Generate new token.
3. Open Expires in. Confirm "Never" is the last option, after "Custom",
and has no Recommended badge.
4. Select Never. A warning admonition appears directly below the expiry
row: "This token never expires — Anyone with the token keeps access
until you delete it."
5. Pick an org and project, grant one permission, click Review access.
Summary shows Expires: Never.
6. Create the token. The POST body has no expires_at, and the new row's
Expires column reads Never.

Fixes FE-4527.

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-10-05 16:42:17 +01:00
Kody Jackson c4221ef689 fix(www) - redirects are never evaluated for anchor fragments (#51198)
## Problem

Fragments are never evaluated by the server, only paths.

## Solution

Removes non-functioning redirects to reduce clutter + potential routes
to evaluate.

## Preview links

N/A, since these redirects are within the docs project but the redirect
logic is attached to the www project (this setup makes redirects
difficult to test and preview).

## Steps to test

Try out any of the removed redirects in the live site today, they won't
work.
2026-10-05 09:45:26 -05:00
Kody Jackson d7f422eb7e fix(www) - remove unnecessary docs redirect for serverless drivers page (#51197)
## Problem

The
[content](https://github.com/supabase/supabase/blob/master/apps/docs/content/guides/database/connecting-to-postgres/serverless-drivers.mdx)
about serverless drivers can't be accessed b/c it's covered by a
historical redirect (but still exists in the navigation menu).

## Solution

Remove the redirect (tagging @czenko b/c I see you're closer to here
contextually and you'd be able to confirm this is correct after your
work in #49869).
2026-10-05 09:42:41 -05:00
Kody Jackson b14a577f9d fix(docs) - remove temp redirect that should've been removed previously (#51200)
## Problem

The `pg_partman` extension was temporarily redirected in #30149, but
then never un-redirected.

This guide became live again in
https://github.com/supabase/supabase/pull/40037/changes#diff-4db130f9070f72e3e0a3f5794a6088230e28977fe743d79af767adb18327c8ab.
(#40037)
2026-10-05 09:42:07 -05:00
Katerina Skroumpelou 0f453c89fa docs: add @supabase/middleware install step to server frameworks guide (#51266)
The framework bridges in the `@supabase/server` reference import
`@supabase/middleware` directly, but the guide never said to install it.
`@supabase/server` depends on it, so npm and yarn users get it through
hoisting, while pnpm users hit "Cannot find module
'@supabase/middleware'" the moment they copy a bridge. This PR adds the
direct-dependency note to the Versions admonition, an `npm install
@supabase/middleware` line to the copy-the-bridge step, and the same
instruction to the agent migration prompt.
2026-10-05 16:56:05 +03:00
Matt Rossman 87681812a0 fix(studio): assistant get_active_incidents url in prod (#51047)
The Assistant's `get_active_incidents` tool has [failed in prod 99.8% of
the time over the past 60
days](https://supabase.slack.com/archives/C051L8U2EJF/p1790712805774689),
so users reporting outages get told it couldn't check incident status.
The failures never showed up as errors, which is why nobody noticed.

The Assistant now includes the `/dashboard` base path when it calls its
own API routes, so the tool stops hitting a 404 in prod
([`/api/incident-status`](https://supabase.com/api/incident-status) is a
404,
[`/dashboard/api/incident-status`](https://supabase.com/dashboard/api/incident-status)
is a 200). The tool also throws on a failed fetch now instead of
returning an `{ error }` result. That way failures show up as span
errors in Braintrust and as a failed tool call in the UI. The model
still gets the error message and tells the user it couldn't check.

When the fetch fails (in dashboard):

| Before (prod) | After (local, path temporarily broken) |
| --- | --- |
| <img width="1036" height="784" alt="CleanShot 2026-09-29 at 5 08 49
PM@2x"
src="https://github.com/user-attachments/assets/4539f968-4aa6-49a5-8c7f-7911b6b497a0"
/> | <img width="1026" height="716" alt="CleanShot 2026-09-29 at 5 08 06
PM@2x"
src="https://github.com/user-attachments/assets/7c9a565c-efe1-4d1a-901b-e440bbb5a739"
/> |

When the fetch fails (in Braintrust):

| Before (prod) | After (local, path temporarily broken) |
| --- | --- |
| <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 07
PM@2x"
src="https://github.com/user-attachments/assets/87860568-b50f-49ee-98fd-4c82f14d1913"
/> | <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 10
PM@2x"
src="https://github.com/user-attachments/assets/64f58d47-e083-464e-b8d0-8b9c57710a05"
/> |

When the fetch works (local):

| Dashboard | Braintrust |
| --- | --- |
| <img width="1054" height="808" alt="CleanShot 2026-09-29 at 5 20 58
PM@2x"
src="https://github.com/user-attachments/assets/1c9e4cf8-79f0-48e6-b95a-1694fc00a9f9"
/> | <img width="2918" height="1144" alt="CleanShot 2026-09-30 at 9 07
03 AM@2x"
src="https://github.com/user-attachments/assets/0d2b9685-57a9-4028-a451-272b3de8e23a"
/> |

Ran it locally with tracing on. Here's a [successful
call](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=251bcd44-c55b-44bb-9ce2-b034b26f8832),
and one with the path temporarily broken, which now [logs a span
error](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=637f2dc8-f65b-4d65-9d86-0511b36e8685).
Local dev has no base path, so the prod URL is covered by the new
`getBasePathURL` tests.

Closes AI-1272




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Incident lookups now report fetch, HTTP, parsing, and validation
errors rather than returning an empty incident result.
* AI SQL generation now accounts for the configured site base path when
building its service URL.
* **Improvements**
* Site URLs now handle trailing slashes and existing base paths
consistently, avoiding duplicate path segments.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 09:37:51 -04:00
Wen Bo Xie f414a68e1b docs(cli): address final review feedback on supabase stack guides (#51217)
- Add stack = true under the existing [experimental] table instead of
pasting a duplicate table, which leaves the setting off.
- Note that db dump targets the linked project unless --local is passed,
and that --db-url reaches a named local project through DB_URL.
- Qualify offline destroy on the host data being deletable, and scope
the shared Docker volume cleanup note to volume-backed projects.
- Say Docker database storage is chosen when the local project is
created.
- Allow GitHub's release download host alongside github.com, or the S3
host alone, in allowlisted sandboxes.
- www: most services stop when idle (not Functions), and state the
[experimental] stack prerequisite in the native runtime entry.
2026-10-05 09:26:52 -04:00
0c2257fb3d feat(studio): scoped oauth data layer (#49476)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

~~This is the first part (and ultimately the final part of the stacked
PR). PR 1 introduces mock data for us while we build the requirements of
the scoped oauth interstitial, all following PR's will be stacked on top
of this one.~~

This is the first part, the data layer side. We began with mock data,
but as backend support arrived we've used this PR to help us shape the
UI as well as the frontend data layer. This now acts as the frontend
data layer.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added OAuth app authorization request handling.
* Added visibility into application details, requested scopes, and
existing authorizations.
  * Added organization and project selection during authorization.
  * Added organization roles and project access details.
  * Added approval and denial options with secure redirect handling.
* Added validation for required authorization details and project
selections.
  * Added support for role validation feedback during approval.
* Added representative authorization scenarios for approved, denied, and
re-consent flows.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Co-authored-by: Samir Ketema <6003000+samirketema@users.noreply.github.com>
2026-10-05 15:20:21 +02:00
Charis de41b029ef always use canonical link for new status page (#51264) 2026-10-05 09:18:24 -04:00
0d8b1417bc [bot] Decrease ESLint ratchet baselines (#51225)
Automated weekly decrease of ESLint ratchet baselines.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
2026-10-05 13:16:39 +00:00
Tanun Turbo Chalermsinsuwan 77e3b4382f feat(role): Allow eligible organizations to invite users as 'No-access' base role (#50922)
## Problem

As the API has allow inviting users into `None / No-access` role for
team, enterprise, and platform tier organization, we need to update the
documentation and descriptions for this new role on the invitation form.

## Solution

1. Updated `apps/docs/content/guides/platform/access-control.mdx` to
include the role
2. Added the role description on
`apps/studio/components/interfaces/Organization/TeamSettings/Roles.constants.tsx`
3. Add the roles into the proper sorting order at
`apps/studio/data/organization-members/organization-roles-query.ts`
4. Add logic to invitation components to disable the role when inviting
user into project(s), as the backend does not allow it.

## Testing and verification steps
The UI:
https://studio-staging-aa8is1m07-supabase.vercel.app/dashboard/org
Documentation:
https://docs-kht98bi78-supabase.vercel.app/docs/guides/platform/access-control

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **Updates**
* The **None** role is labeled **No-access** and describes the lack of
organization and project resource access.
* **None** is included after **Read-only** in the role list. When
inviting a member with project-only access, **None** is disabled with an
explanation.
* **Documentation**
* Clarified plan coverage for **Read-Only** and **No access**, and added
guidance on assigning **No access** at the organization level before
granting project-specific roles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 19:54:55 +07:00
Kody Jackson 04a6baf869 fix(kb) - add topic name (#51186)
## Problem

Adds a new topic b/c `Comparisons` is reserved for other types of
content.

## Preview links

TBD

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Made the Comparison topic visible and added a hidden Rundowns topic
covering comparisons across technologies and facets.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 07:43:35 -05:00
Ben Fritsch 901d1915b6 add Ben Fritsch to humans.txt (#51265)
Adding myself to humans.txt
2026-10-05 14:32:29 +02:00
Charis 01bfab39d6 studio: improve warning for replicas on spend cap (#51179)
## Summary

The "> 8 GB warning" when spend cap enabled used to be conflated with
the "has replicas with spend cap" warning, which causes a confusing
error message.

Opting to split them out into 2 separate warnings to give the user a
better description of the problem.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Read replicas alone no longer trigger the disk-size threshold warning.
* **New Features**
* When usage billing is disabled, a warning appears if read replicas are
present and no project exceeds 8 GB, with guidance on next steps.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 11:46:32 +00:00
kemal.earth cb52c0f425 chore(studio): update segment control in view permissions to ds one (#51125)
## Problem

We were using a custom segment control. Recently we introduced segmented
toggle groups in our design system. The old one is inconsistent and
doesn't match anything else.

## Solution

Replace segmented control with [this
one](https://supabase.com/design-system/docs/components/toggle-group#segmented).

| Before | After |
|--------|--------|
| <img width="777" height="85" alt="Screenshot 2026-10-01 at 11 36 47"
src="https://github.com/user-attachments/assets/84e28075-248d-42d4-a537-f18cd2fe86db"
/> | <img width="783" height="95" alt="Screenshot 2026-10-01 at 11 37
00"
src="https://github.com/user-attachments/assets/1071f031-8e96-4db1-8ea1-36cb34e9923a"
/> |

## Test plan
- [ ] Go to Account Settings → Access Tokens, create a new scoped token,
and on the capability review step confirm the All/Read/Read-write
segmented control renders correctly and filters the capability list as
expected
- [ ] Open an existing scoped token's "View" sheet and confirm the same
segmented control filters correctly there too
- [ ] Verify keyboard navigation (arrow keys) and that exactly one
option is always selected (no deselect state)
- [ ] Visual check against the design system's segmented `ToggleGroup`
styling (no leftover custom border/divider artifacts from the old
implementation)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated the capability-level selector to use a segmented control.
Selection behavior remains unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 10:11:13 +01:00
Joshen Lim 838fcaaa89 Joshenlim/fe 4509 fdw general UI consolidation and refactor (#51079)
## Context

Stacks on top of https://github.com/supabase/supabase/pull/51074

PR's just mainly refactoring, no visual differences:
- `CreateWrapperSheet` + `EditWrapperSheet` use the same UI components
for the foreign tables section
  - Can be consolidated into one reusable component
- `WrapperTableEditor` is still using `SidePanel` component
  - Can be swapped to use new `Sheet` component
- Refactor `WrapperTableEditor`'s layout a little - added separators for
clarity between sections
<img width="400" alt="image"
src="https://github.com/user-attachments/assets/b1983bf2-cff5-43eb-8b31-40a7abb65038"
/>
- Update `getCreateFDWSql` to just use the Foreign Data Wrapper's name
from `wrapperMeta` since its now standardized

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a shared foreign-table selector for wrapper setup and editing,
with options to view columns, add or edit table definitions, and remove
tables.
  * Updated the table editor to use a sheet layout with a fixed footer.
* **Bug Fixes**
* Wrapper creation now uses the wrapper’s configured name when creating
the server.
* Foreign-table targets display the table name when other target details
are unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 16:20:50 +08:00
dependabot[bot]andIvan Vasilov 4311c2c31c chore(deps): bump axios from 1.18.1 to 1.20.0 in the npm_and_yarn group across 1 directory (#51114)
Bumps the npm_and_yarn group with 1 update in the / directory:
[axios](https://github.com/axios/axios).

Updates `axios` from 1.18.1 to 1.20.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/releases">axios's
releases</a>.</em></p>
<blockquote>
<h2>v1.20.0 — August 19, 2026</h2>
<p>This release hardens runtime option handling, adds RFC 9110
status-code aliases, fixes Node.js and XHR reliability issues, and
refreshes project tooling and documentation.</p>
<h2>⚠️ Breaking Changes &amp; Deprecations</h2>
<ul>
<li>HTTP Status Naming: Added ContentTooLarge (413) and
UnprocessableContent (422), while retaining PayloadTooLarge and
UnprocessableEntity as backward-compatible deprecated aliases. (<a
href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li>
</ul>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Runtime Option Handling: Hardened behavioral configuration reads
against shared and foreign prototype pollution and normalized unsafe
interceptor replacement objects. This also clarifies Fetch redirect and
custom implementation behavior, HTTP/2 DNS and proxy handling,
CIDR-based NO_PROXY matching, and malformed data URI rejection; see the
PR for documented compatibility effects. (<a
href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>Interceptor Lifecycle: Prevented unbounded handler-array growth by
trimming trailing ejected interceptors without changing iteration
semantics, and kept interceptor operations safe when the public handlers
field is nullish. (<a
href="https://redirect.github.com/axios/axios/issues/11087">#11087</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li>
<li>Request Error Preservation: Prevented custom Error.prepareStackTrace
implementations that return non-string values from replacing the
original request failure with an unrelated TypeError. (<a
href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li>
<li>XHR Reliability: Navigation-canceled requests now reject with
ECONNABORTED instead of resolving with status 0, while successful
downloads flush their final progress callback during the live loadend
dispatch. (<a
href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li>
<li>Node.js Socket Memory: Removed request-context retention from
per-socket error listeners, preventing completed response data from
being pinned for the lifetime of pooled keep-alive sockets. (<a
href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li>
<li>Core Methods and HTTP Errors: Prevented structural method-header
buckets from leaking into outgoing headers, standardized invalid DNS
lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and
corrected the timeoutErrorMessage merge strategy. (<a
href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>Dependencies: Updated fast-uri, postcss, js-yaml, mocha,
development-tooling groups, and GitHub Actions dependencies. (<a
href="https://redirect.github.com/axios/axios/issues/11092">#11092</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11098">#11098</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11099">#11099</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11106">#11106</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11107">#11107</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11122">#11122</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11123">#11123</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11126">#11126</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11127">#11127</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11144">#11144</a>)</li>
<li>Documentation: Applied the v1.19.0 documentation updates, added the
missing fs import to the README stream example, introduced localized
global search, and repaired the interceptor test link. (<a
href="https://redirect.github.com/axios/axios/issues/11101">#11101</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li>
<li>Sponsorship: Updated sponsorship links and data and added
ScrapingBee as a sponsor. (<a
href="https://redirect.github.com/axios/axios/issues/11124">#11124</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11136">#11136</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li>
<li>CI and Release: Switched ESM smoke tests to locked dependencies and
synchronized package and runtime version metadata for v1.20.0. (<a
href="https://redirect.github.com/axios/axios/issues/11128">#11128</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve axios:</p>
<ul>
<li><a href="https://github.com/yens1"><code>@​yens1</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li>
<li><a
href="https://github.com/Sasireddy001"><code>@​Sasireddy001</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>)</li>
<li><a
href="https://github.com/ari-token-security"><code>@​ari-token-security</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>)</li>
<li><a
href="https://github.com/timothyokooboh"><code>@​timothyokooboh</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>)</li>
<li><a
href="https://github.com/gi9439041-png"><code>@​gi9439041-png</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li>
<li><a
href="https://github.com/Hashim1999164"><code>@​Hashim1999164</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li>
<li><a href="https://github.com/v-dev-cl"><code>@​v-dev-cl</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li>
<li><a href="https://github.com/r0h1tb"><code>@​r0h1tb</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li>
<li><a href="https://github.com/ostapondo"><code>@​ostapondo</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li>
</ul>
<p>Full Changelog (<a
href="https://github.com/axios/axios/compare/v1.19.0...v1.20.0">https://github.com/axios/axios/compare/v1.19.0...v1.20.0</a>)</p>
<h2>v1.19.0 - July 22, 2026</h2>
<p>This release raises the form-data security floor, adds configuration
and type-system capabilities, and fixes NO_PROXY matching, interceptor
errors, progress reporting, and serialization edge cases.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Multipart Form Data: Raised the form-data dependency floor to
^4.0.6, preventing fresh installations from resolving versions affected
by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a
href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>).
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v1.19.0 — July 22, 2026</h2>
<p>This release raises the form-data security floor, adds configuration
and type-system capabilities, and fixes NO_PROXY matching, interceptor
errors, progress reporting, and serialization edge cases.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Multipart Form Data: Raised the form-data dependency floor to
^4.0.6, preventing fresh installations from resolving versions affected
by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a
href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>).
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
</ul>
<h2>🚀 New Features</h2>
<ul>
<li>Configuration Extensibility: Preserved own-enumerable symbol-keyed
fields through mergeConfig and added a generic params type across public
TypeScript declarations, responses, errors,
adapters, and serializers. (<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11081">#11081</a>)</li>
<li>Header Parameter Parsing: Added the opt-in
AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP
parameter parsing while preserving legacy parsing behavior. (<a
href="https://redirect.github.com/axios/axios/issues/11051">#11051</a>)</li>
<li>HTTP Status Codes: Added the missing Cloudflare 520
WebServerReturnsAnUnknownError status and matching ESM/CJS declarations.
(<a
href="https://redirect.github.com/axios/axios/issues/11067">#11067</a>)</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>
<p>Form Data Conversion: Limited formDataToJSON path splitting to dot
and bracket notation, preserving literal punctuation in keys, and
removed browser-facing Buffer.from usage from toFormData to avoid
unnecessary polyfills. (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11018">#11018</a>)</p>
</li>
<li>
<p>Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal
forms during NO_PROXY matching and honored * entries within comma- or
space-separated bypass lists. (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11053">#11053</a>)</p>
</li>
<li>
<p>Cancellation: Propagated already-aborted input signals immediately
when composing abort signals. (<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</p>
</li>
<li>
<p>Header Handling: Preserved empty first values for duplicate singleton
headers and made AxiosHeaders#getSetCookie() consistently return arrays
for present values. (<a
href="https://redirect.github.com/axios/axios/issues/11036">#11036</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11037">#11037</a>)</p>
</li>
<li>
<p>URL Handling: Included normalized, safely redacted offending URLs in
malformed-protocol errors and removed repeated trailing slashes when
combining base URLs. (<a
href="https://redirect.github.com/axios/axios/issues/11008">#11008</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11038">#11038</a>)</p>
</li>
<li>
<p>Progress Events: Clamped malformed negative progress values to zero
and ensured final Node.js download progress events are delivered before
streamed responses close. (<a
href="https://redirect.github.com/axios/axios/issues/11039">#11039</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11040">#11040</a>)</p>
</li>
<li>
<p>Error and JSON Serialization: Serialized Set values as arrays in
JSON-compatible snapshots and synthesized useful AxiosError messages
from otherwise-empty AggregateError instances. (<a
href="https://redirect.github.com/axios/axios/issues/11044">#11044</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11059">#11059</a>)</p>
</li>
<li>
<p>Content-Length Enforcement: Corrected base64 data: URL size
estimation so maxContentLength is enforced consistently by the HTTP and
Fetch adapters. (<a
href="https://redirect.github.com/axios/axios/issues/11061">#11061</a>)</p>
</li>
<li>
<p>Synchronous Interceptors: Prevented requests from being dispatched
after synchronous request interceptors fail unless their paired
rejection handler resolves successfully. (<a
href="https://redirect.github.com/axios/axios/issues/11071">#11071</a>)</p>
</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>Dependencies: Updated development and test tooling, the docs
fixture's Axios version, and GitHub Actions integrations including
Checkout, Setup Node, Setup Deno, and Zizmor. (<a
href="https://redirect.github.com/axios/axios/issues/11031">#11031</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11055">#11055</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11056">#11056</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11058">#11058</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11079">#11079</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11080">#11080</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11088">#11088</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11089">#11089</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11090">#11090</a>)</li>
<li>Build Outputs: Limited sourcemap generation to published minified
bundles, removing broken map references from non-minified builds. (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li>Form Data Internals: Centralized FormData header handling and made
the Node.js adapter tolerate getHeaders() returning undefined under the
content-only policy. (<a
href="https://redirect.github.com/axios/axios/issues/11062">#11062</a>)</li>
<li>Developer Experience: Ignored common local AI-tooling directories
and fixed a constant-reassignment crash when the development sandbox
serves its root path. (<a
href="https://redirect.github.com/axios/axios/issues/11032">#11032</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11073">#11073</a>)</li>
<li>Documentation: Updated sponsor information, clarified that baseURL
is not a path-security boundary, scoped provenance claims to attested
releases, and corrected the configuration-defaults documentation. (<a
href="https://redirect.github.com/axios/axios/issues/11041">#11041</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11068">#11068</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11076">#11076</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11078">#11078</a>)</li>
<li>Publishing: Simplified v1 publishing to use the npm version bundled
with Node.js 26 and updated package metadata for the 1.19.0 release. (<a
href="https://redirect.github.com/axios/axios/issues/11083">#11083</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11095">#11095</a>)</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve Axios:</p>
<ul>
<li><a
href="https://github.com/afonsojramos"><code>@​afonsojramos</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
<li><a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>)</li>
<li><a
href="https://github.com/yassertawfik4"><code>@​yassertawfik4</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11024">#11024</a>)</li>
<li><a
href="https://github.com/AnandSundar"><code>@​AnandSundar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>)</li>
<li><a
href="https://github.com/lin-hongkuan"><code>@​lin-hongkuan</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</li>
<li><a
href="https://github.com/Wali007-lab"><code>@​Wali007-lab</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li><a href="https://github.com/magicdawn"><code>@​magicdawn</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/axios/axios/commit/84a9f3b9a4f3244b8c8e818f557d64c7b964fb25"><code>84a9f3b</code></a>
chore(release): prepare release 1.20.0 (<a
href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/e6824eec5fcf9da467a9792724396badc490c469"><code>e6824ee</code></a>
fix: core methodList, HTTP adapter errors, and add tests (<a
href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/d8a919fd81403d59058c0e9dbefc540407dee83f"><code>d8a919f</code></a>
fix(xhr): flush final progress during the live loadend dispatch (<a
href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/2d2a21af8a433089474a2149781799c93acbcf3c"><code>2d2a21a</code></a>
fix(interceptors): tolerate nullish handlers in syncHandlerEntries (<a
href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"><code>d19040b</code></a>
fix: harden runtime option handling (<a
href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/e0a02dd16671deabe2b809334d4c2ebede29a233"><code>e0a02dd</code></a>
chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the
github-...</li>
<li><a
href="https://github.com/axios/axios/commit/d10cb3aa3cda1d78721ddf96be590478df26cd81"><code>d10cb3a</code></a>
chore(deps-dev): bump the development_dependencies group with 4 updates
(<a
href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/2c94646eb7cb7ab9dcb2aefdb04ab1b040c28e16"><code>2c94646</code></a>
chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (<a
href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/76c12bce5a4fe9a45bef9a5bf2baaf599d7d382e"><code>76c12bc</code></a>
chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (<a
href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/ba98559a7f5a18e531b5762387e5957bd281af3d"><code>ba98559</code></a>
docs: add ScrapingBee sponsor (<a
href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/axios/axios/compare/v1.18.1...v1.20.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-05 10:19:22 +02:00
Joshen Lim 521881a899 Joshenlim/fe 4480 fdw create wrapper to only init fdw once users to name the (#51074)
## Context

PR here refactors the way we manage Foreign Data Wrappers in the
dashboard (Under Project -> Integrations), as there's some DX problems
with the current behaviour.

Currently whenever a user creates a new wrapper, the dashboard is
creating both the Foreign Data Wrapper (`create foreign data
wrapper...`) + server (`create server ...`). The former is
**_redundant_** to create multiples of given that it just handles the
`handler` and `validator`, whereas what matters more is the server which
holds the connection credentials. Hence standard practice is usually one
Foreign Data Wrapper with multiple servers. (The former just needs to be
created once if not done yet)

This also led to some problems as well when users created their own
wrappers via SQL and tried to manage them through the dashboard GUI,
leading to us having to add some guard rails to prevent managing
wrappers sharing the same Foreign Data Wrapper
([ref](https://github.com/supabase/supabase/pull/50785))

## Changes involved
- When creating a wrapper, if the Foreign Data Wrapper has yet to be set
up for the wrapper type, the dashboard will initialize one and
subsequently use that same Foreign Data Wrapper for any new wrappers
- When creating / editing a wrapper, users will name the **server**
instead of the **wrapper**
<img width="500" alt="image"
src="https://github.com/user-attachments/assets/b3e61204-0e16-4599-84ac-af2aab5b93c2"
/>
- When deleting a wrapper, the clean up for vault secrets are now
deterministic by referencing the wrapper's server options
- RE backwards compatibility: Existing wrappers will _not_ be affected
by the changes here - they can be edited / deleted as per normal

## Unrelated fixes + UI refactors added
- Fix Iceberg Wrapper not showing the right form when adding new wrapper
- Adjust form layouts in side panel to be horizontal instead of vertical
(Follows Database -> Pipelines)
- Clean up to use newer UI components like `ButtonTooltip`
- Opt to hide Docs + Create CTA under `WrappersTab` if marketplace
feature preview is enabled (Since these actions are already in the
header, will be duplicates)
- Consolidate foreign tables configuration for create + edit wrapper
sheet into one component `ForeignTablesSelector`

## To test
- [ ] Verify that existing wrappers with their own Foreign Data Wrapper
can be edited correctly
- [ ] Verify that existing wrappers with their own Foreign Data Wrapper
can be deleted
- [ ] Verify that existing wrappers with shared Foreign Data Wrapper can
be edited correctly
- [ ] Verify that existing wrappers with shared Foreign Data Wrapper can
be deleted
- [ ] Verify that new wrappers can be created
- [ ] Verify that newly created wrappers can be edited correctly
- [ ] Verify that newly created wrappers can be deleted
2026-10-05 16:00:37 +08:00
Gildas Garcia 5de3666930 Fix: storage explorer ignore current filter after mutations (#51174)
## Problem

When users trigger actions such as deleting an item, the storage
explorer reloads the opened folders but ignore the currently applied
filter.

## Solution

Move the filter state in Valtio so that its other functions are aware of
it.

## Review instructions

1. Create a Supabase project and upload objects in Storage with date
prefixes (e.g., 202608XX)
2. Navigate to Storage, select a bucket with multi-dated/prefixed
objects
3. Enter a filter in the search box (e.g., 20260820) to show only
matching objects
4. Select one or more filtered objects and delete them

Observe the file list after deletion - it should show filtered contents
according to the search box value


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Storage search now stays in sync as you open folders and refresh their
contents.
* When restoring open folders, search results are filtered in the
deepest open folder rather than hiding ancestor folders.
* Deleting a file from filtered results keeps the search applied and
displays the remaining matches correctly.
* Search results remain consistent across folder navigation, refreshes,
and file deletion.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 09:52:32 +02:00
Danny White ba82106697 chore(www + studio): remove expired Select 2026 promo banners (#51245)
## Problem

Supabase Select 2026 has finished. The promo banners already hide via
the scheduled expiry from #51006, but the campaign code, assets, and
wiring are still in the tree.

## Solution

Remove the Select 2026 sitewide promotion across www and Studio:

- Delete shared `Select26*` banner code, font, and tests from
`ui-patterns`
- Delete Studio `BannerSelect2026*` and its Banner Stack registration
- Unmount the www announcement banner and revert the State of Startups
spacing that only existed for it
- Drop the Select-only session-replay `data-band` allowlist entry and
lint ratchet baseline

Event go pages, blog posts, and other Select content are left alone. The
`Announcement` shell stays for the next campaign.

## Review instructions

1. Open the www homepage on the deploy preview. Confirm there is no
Select announcement bar above the nav.
2. Open `/state-of-startups` on the deploy preview. Confirm the hero
still looks correct with no extra top gap from the removed banner.
3. Open a hosted Studio dashboard page on the deploy preview. Confirm
the Banner Stack no longer shows a Select card.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)
2026-10-05 18:36:13 +11:00
Johan Bergström 63718b4b84 feat(docs): render experimental badge for Management API endpoints
Management API endpoints now supports expressing an "experimental" stage
where we previously only marked it as deprecated.

We now render the badge as experimental instead and avoid the strikethrough.

This clearly shows that the endpoint is not to be removed, but rather being
tested for inclusion.

PR: https://github.com/supabase/supabase/pull/51045
2026-10-05 07:35:51 +01:00
Joshen LimandGildas Garcia acaf640d1c Joshenlim/fe 4522 polish recovery codes UI (#51124)
## Context

Just a couple of UI polishes for the recovery codes UI under Account
settings -> Security - all visual, no functional changes

## Changes involved

- Shift position of Recovery codes section below MFA
- Better hierarchy since recovery codes only matter after adding an MFA
app
  - Prevents layout shift with the feature flag as well

| Before | After |
|------|------|
| <img width="400" alt="image"
src="https://github.com/user-attachments/assets/3f24e30b-14b1-49cc-8942-0bd139af031b"
/> | <img width="400" alt="image"
src="https://github.com/user-attachments/assets/9a020b9b-4644-4e39-ba75-082e7f3a08db"
/> |

- Update how recovery codes are displayed

| Before | After |
|------|------|
| <img width="400" alt="image"
src="https://github.com/user-attachments/assets/9ce00013-9b7f-4ab9-9a10-0eec536022f5"
/> | <img width="400" alt="image"
src="https://github.com/user-attachments/assets/6bdc8c18-cfd2-46ea-a851-5a9fe03a5211"
/> |

- Update recovery codes modal, aligns "confirmation" UX to be more
consistent with scoped PAT
- Footer CTA is just "Done" that's disabled until either Copy or
Download is clicked
  - Copy CTA shifted below codes for contextual grouping
  - Also added download CTA, which just downloads codes in TXT

| Before | After |
|------|------|
| <img width="534" height="389" alt="image"
src="https://github.com/user-attachments/assets/55cdbe9f-f37c-4284-b2ac-46834fd14437"
/> | <img width="533" height="548" alt="image"
src="https://github.com/user-attachments/assets/ab091822-e5fc-464c-94e6-f1d6b6792c59"
/> |

- Show success toast after codes are successfully deleted
- Use warning variant for regenerate confirmation dialog





<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Recovery codes are displayed as a numbered list, with separate options
to copy or download them.
* You must confirm that you’ve saved the codes before closing the
success dialog.
* **Improvements**
  * Generation buttons show when codes are being created.
* Recovery-code actions have updated layouts, icons, and confirmation
styling. Available codes are identified as single-use, and loading
errors are displayed in an alert.
* Removing codes displays a success message before the confirmation
dialog closes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-10-05 14:15:17 +08:00