mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 11:25:06 +03:00
4e686dfe5629fc58d2db7a413e5fa64034f254a1
38953
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
4e686dfe56 | keep the terms notice test aligned with its dismissal action | ||
|
|
9223489ad3 | format | ||
|
|
933fb3554c | tweaks | ||
|
|
bd408597e1 | notify dashboard users about the Terms of Service update | ||
|
|
be1ba651ed |
Add branching nav items to cmd k (#51255)
## Context Adds a couple of branching nav items to Command K - Create new branch - Branch management - Merge requests - Github Connection (For branching) - Branching feedback Switch branch is still available, and only visible after a branch has been created (status quo) <img width="610" height="531" alt="image" src="https://github.com/user-attachments/assets/3068184e-889d-44ed-8cf6-2afd59ffb109" /> |
||
|
|
642a02db49 |
Prevent enabling spend cap if org has projects with RRs (#51253)
## Context Prevents organizations from enabling spend cap if the org has projects with read replicas - We currently gate creation of read replicas to ensure that orgs have spend caps disabled, but were missing the guard for the other way around <img width="662" height="378" alt="image" src="https://github.com/user-attachments/assets/44ad036c-4c1b-48e8-beb7-f16f6170c9fb" /> ## Other changes involved - Refactored to use new `Sheet` and `Table` components in `SpendCapSidePanel` |
||
|
|
20d6f2197f |
chore(studio): remove privacy policy notice (#51299)
I removed the Studio Privacy Policy update notice that #50397 added on 2026-09-16, when Privacy Policy v4 took effect. It has been up for almost three weeks, and the ToS v4 banner (#51109) goes out next. I did the same in #44380, removing the March 2026 privacy notice after 15 days. This is the exact inverse of #50397: the banner component and its test, the banner ID, the dismissal local storage key, and the org-landing path helper that only this notice used. ## To test Tested on Vercel preview: - [ ] In a fresh browser profile (no `privacy-policy-update-2026-09-16-dismissed` key), open `/organizations`: expect no Privacy Policy notice - [ ] Open `/org/<slug>`: expect no Privacy Policy notice and the project list renders normally - [ ] Open a project's Logs page: expect the logs deprecation banner behavior unchanged (only shows before its expiry) ## Linear - fixes GROWTH-1322 |
||
|
|
a629c9c1ac |
Add hidden Supplemental Terms legal page (#51100)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_ ## Problem No page existed yet for the upcoming "Supplemental Terms" document. Nicole Kramer (Commercial & Product Counsel) needs a stable, linkable URL to reference from future Terms of Service / Enterprise SaaS Subscription Agreement updates, before the legal content itself is ready. The page needs to be reachable by direct URL but not surfaced in the visible Legal Hub nav yet, matching the existing "hidden" precedent used for `/enterprise-terms`. ## Solution Added a new page at `/legal/customer-resources/supplemental-terms`: - `apps/www/pages/legal/customer-resources/supplemental-terms.tsx` — a page component mirroring the existing Data Processing Addendum page (`apps/www/pages/legal/customer-resources/data-processing-addendum.tsx`): `DefaultLayout` + `PageHeader` (h1 "Supplemental Terms") + `LegalDocVersions` rendering a single MDX version. - `apps/www/data/legal/customer-resources/supplemental-terms/v1.mdx` — placeholder body content (`_Content coming soon._`), no frontmatter/h1, following this repo's existing legal MDX convention (the h1 is rendered by `PageHeader`, not the MDX itself). Nicole will fill in the actual legal content later. **On "hidden":** I investigated the actual codebase state before implementing, since the two precedents named didn't turn out to work the same way: - `/enterprise-terms` is genuinely hidden — it is not linked anywhere in `apps/www/pages/legal/index.tsx`'s Legal Hub listing, and its `NextSeo` meta sets `noindex: true, nofollow: true`. - The Data Processing Addendum and Subprocessor List pages, by contrast, **are** linked in the visible Legal Hub listing (`apps/www/pages/legal/index.tsx`, "Customer Legal Resources" section) — they are not hidden today. Given that, this PR mirrors the DPA/Subprocessor List *structural* pattern (route under `/legal/customer-resources/`, page-component + versioned-MDX content) since that's what "under Customer Legal Resources" means structurally in this codebase, but mirrors `enterprise-terms`' *hidden* mechanism: the new page's `NextSeo` meta sets `noindex: true, nofollow: true`, and — importantly — **no entry was added** to the `sections` array in `apps/www/pages/legal/index.tsx`, so it does not appear in the visible Legal Hub or any nav. The page is reachable only via its direct URL. Terms of Service and the Enterprise SaaS Subscription Agreement pages were not touched. ## Review instructions 1. Confirm `/legal/customer-resources/supplemental-terms` renders with h1 "Supplemental Terms" and placeholder body text. 2. Confirm the page does **not** appear anywhere on `/legal` (the Legal Hub listing). 3. Confirm `apps/www/pages/terms.tsx` / `apps/www/pages/enterprise-terms.tsx` (and their MDX content) are unchanged. ## Checklist - [x] I have read CONTRIBUTING.md - [ ] N/A — no docs topic edited (legal page content is a placeholder, not docs content) --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC --- _Generated by [Claude Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
81da60392e |
feat(www): add multigres alpha form to /database (#51298)
The Multigres private alpha request form only lives at /go/multigres-early-access (#51053), and nothing on the product site links to it. I added the same form to /database, the way /compute embeds its waitlist form. The new section sits at the bottom of the page, directly above the closing "Start your project" CTA: the go page's hero copy, the alpha caveats, and a "Learn about Multigres" link to multigres.com on the left, the form on the right. Fields, disclaimer, and redirect are read from the go page definition. The form posts `{ slug: 'multigres-early-access', formId: 'form' }`, so the server resolves the existing CRM config and submissions land in the same database as the go page. **Note:** the section throws at build time if the go page or its form section is removed, so retiring the go page means removing this section in the same change. ## To test Tested on Vercel preview: - [ ] Open /database and scroll to the bottom: expect a "Private alpha / Multigres on Supabase" section directly above "Build in a weekend, scale to millions", with the email and organization slug form, the alpha caveats, and the Privacy Policy disclaimer - [ ] Click "Learn about Multigres": expect multigres.com to open in a new tab - [ ] Resize to a phone width: expect the text stacked above the form card with no horizontal scroll - [ ] Open /go/multigres-early-access: expect its page and form unchanged - [ ] After merge, submit a test request from supabase.com/database: expect a redirect to /go/multigres-early-access/thank-you and a new row in the Multigres requests database ## Linear - fixes GROWTH-1321 |
||
|
|
22cdd05492 | fix: update disk maxSize in pricing page (#51295) | ||
|
|
d21c20eae6 |
docs: add Multigres early access request link to the Multigres docume… (#51297)
…ntation ## Problem Currently there's no way for users to request access to private alpha for Multigres. ## Solution Add a link to the form to fillout for customers to get access. ## Checklist Check all before review: - [X] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [X] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) Co-authored-by: Aditya Maruvada <aditya@Adityas-MacBook-Pro.local> |
||
|
|
5cc0450950 |
fix(www): plate State of Startups Sign in over the aurora (#51163)
## Problem On `/state-of-startups`, the nav starts transparent over the aurora. Default buttons use a translucent fill in dark mode, so Sign in (and Dashboard) look see-through. ## Solution Wrap those default nav buttons in `FloatingPlate`. Primary “Start your project” is already opaque and unchanged. | Before | After | | --- | --- | | <img width="1024" height="759" alt="23474_296a1f8f952ae7f73ae9205e5db6bb9cda4cf0a904bc2d440d6395b5f12346ab" src="https://github.com/user-attachments/assets/c247cdaa-06b0-46ad-b1f8-cee3e06fde8e" /> | <img width="1024" height="759" alt="State of Startups 2026 Supabase" src="https://github.com/user-attachments/assets/e9a1a0e0-9f2f-427f-a7d3-75e4e1cbba63" /> | ## Review instructions In dark mode: 1. [Live /state-of-startups](https://supabase.com/state-of-startups) · [Preview /state-of-startups](https://zone-www-dot-com-git-dnywh-fixsos-sign-in-float-91d2b1-supabase.vercel.app/state-of-startups) 2. At the top of the page (transparent nav, before scrolling), check Sign in: opaque plate, aurora does not show through the fill. 3. Scroll until the nav gains a solid background: Sign in should still look normal. Ideally you could sign in and confirm the now ‘Dashboard’ button gets the same plate treatment. But that’s not possible until merge. |
||
|
|
36364e7df3 |
fix(www): stop wrapping oklch semantic tokens in hsl() (#51161)
## Problem Semantic colour tokens (`--border-*`, `--foreground-*`, `--background-*`) now resolve to full `oklch(...)` values. Call sites that still wrapped them in `hsl(var(--…))` are invalid CSS and drop the colour (Partners ambient grid was the clearest case). Brand / destructive / warning channel tokens still correctly use `hsl(var(--…))` and were left alone. Presence avatar stack polish is in https://github.com/supabase/supabase/pull/51164. ## Solution - Use bare `var(--…)`, `currentColor`, or Tailwind utilities for semantic tokens. Opacity cases use `oklch(from var(--…) l c h / …)`. - Partners grid: fix, and then use `text-foreground/20` in light, `text-foreground/30` in dark for optical correction. | Before | After | | --- | --- | | <img width="1860" height="1106" alt="CleanShot 2026-10-02 at 16 29 08@2x" src="https://github.com/user-attachments/assets/4554b0c9-22cf-4b06-bbe3-798e8b15304e" /> | <img width="1852" height="1112" alt="CleanShot 2026-10-02 at 16 28 44@2x" src="https://github.com/user-attachments/assets/20ccbc80-5eaa-49e6-8f94-48b99dc01474" /> | | <img width="1024" height="759" alt="20701" src="https://github.com/user-attachments/assets/a4e578cf-5adb-4f7a-a53b-870a51f5f948" /> | <img width="1024" height="759" alt="59176" src="https://github.com/user-attachments/assets/dda3fc2d-d86b-45a5-adca-403223cc5f33" /> | ## Review instructions 1. [Live /partners](https://supabase.com/partners) · [Preview /partners](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/partners). Ambient dashed grid under the hero (light and dark). 2. [Live /database](https://supabase.com/database) · [Preview /database](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/database). Postgres elephant idle outline should be muted grey, not black. Hover still brand green. 3. [Live /state-of-startups](https://supabase.com/state-of-startups) · [Preview /state-of-startups](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/state-of-startups). Chart **More AI-generated code, less likely to be monetizing yet**: horizontal gridlines at 0/25/50/75/100% should render. 4. Storage / Edge Functions changes are correctness-only (shadows, idle borders, a top fade). Near-invisible to the naked eye; skip unless debugging. |
||
|
|
0cb8bd95dd |
feat(studio): add spot colour control to Appearance (#50782)
## Problem The theme's primary hue can change in CSS, but Appearance had no way to try other spot colours. That makes it hard to find controls whose colour still depends on the fixed Supabase brand palette. ## Solution Add a **Spot color** control under Appearance → Theme colors (employee-only via ConfigCat `appearanceSpotColor`, targeted to Supabase Team Email). ### Spot color UX - Rainbow spectrum track with a thin outline so pale tracks stay visible - Live trifecta swatches for `--primary-solid`, `--primary`, and `--primary-bright` (darkest → lightest) next to the degree readout - Drag updates are rAF-batched so React paint and CSS preview stay to one frame ### Canvas tint coupling - `--surface-hue` is derived in CSS as `calc(var(--primary-hue) + var(--surface-hue-offset))` - Dark: offset `0` (same hue as spot) - Light: offset `180` (complementary canvas tint; brand green ≈157.5° → rose ≈337.5°) - No JS override of `--surface-hue`. Changing Spot color moves primary controls and the low-chroma canvas tint together ### Other theme sliders - Renamed **Color intensity** → **Surface tint** (it only drives the neutral ramp via `--chroma`, not spot chroma) - Meaning-shaped tracks for every knob (spectrum, grey→tint, soft→hard, dark→light, flat→lift) - Same outline treatment on those tracks | Before | After | | --- | --- | | <img width="1476" height="2174" alt="CleanShot 2026-10-05 at 15 02 21@2x" src="https://github.com/user-attachments/assets/d08b0fa8-32af-450e-adce-861f59c9d6ca" /> | <img width="1474" height="2354" alt="CleanShot 2026-10-05 at 14 56 35@2x" src="https://github.com/user-attachments/assets/9a1e6183-a4ba-4c8e-a458-bb0eea946db8" /> | | _Anyone else_ | _With staff flag, custom settings_ | ## Review instructions 1. Confirm ConfigCat flag `appearanceSpotColor` is on for your staff account (or flip it in the Dev Toolbar). 2. Open `/account/me` → **Appearance → Theme colors**. 3. Without the flag: Spot color is hidden; other theme sliders still work. 4. With the flag: drag Spot color in light and dark. Primary controls and canvas tint should move together; Supabase brand assets should stay fixed. 5. Raise Surface tint and confirm the canvas hue follows the complementary (light) or same-hue (dark) offset. 6. Refresh, switch modes, and use **Reset** to check persistence and defaults. |
||
|
|
17512de71d |
docs(database): connect security definer to the default execute grant (#50817)
Closes DOCS-1319 Part 4 of 4 in stack #50823. This PR carries **additions**: content the page never had. Style, structure, and snippet fixes land below it in #50820, #50821, and #50822. ## Problem Developers and AI agents read the Database functions guide. The guide shows how to write a function inside the database. A function runs in one of two modes. In `invoker` mode it runs as the caller. In `definer` mode it runs as the creator. The guide gives one rule for `definer` mode. The rule is to set the `search_path`. A reader who obeys that rule still gets an unsafe function. I wrote a function that obeys the rule. I pinned the search path to the empty string. Then I called it three times. | Caller | Result | | --- | --- | | The order's owner | 4330 cents, correct | | A different signed-in customer | 8660 cents, another customer's order | | Nobody, no session at all | 8660 cents | Every role can call a new function in `public`. The guide states that fact under Function privileges. It never connects the fact to the `definer` rule. A reader has no reason to look. Customers report the same failure. AI tools choose `definer` mode. The function then answers the front end with no session. The hole is hard to find, because no policy is involved in it. ## Solution - **Joins the two halves in the Security definer subsection.** A `danger` admonition states three facts: - The function runs with its creator's privileges. - A function created in the Dashboard or by a migration is owned by `postgres`, which bypasses Row Level Security. - Every role can call the function by default. The admonition then gives the fix. Check ownership inside the function body, and narrow the execute privilege as well. - **Applies the regrant to both ways of restricting execute.** The `grant execute` block sat inside the second way. A reader who took the first way saw no way to restore their own app's access. **Not changed:** the existing definer paragraph, the page structure, and the Function privileges statements. The lower PRs in the stack own those. **No eval re-run.** The guide scored 6 of 6 on three baseline runs, so the score has no room to move. All three runs chose `invoker` mode. The eval never enters the branch this PR fixes. Measuring it needs a new check, not a re-run. **Diff size:** one file, 15 lines added and 4 removed. ## Manual testing 1. Open the [Security definer vs invoker section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker) on the deploy preview. The admonition renders as a red `danger` panel below the definer paragraph. The two fixes appear as bullets. 2. Click the `Function privileges` link inside the admonition. It jumps to the [Function privileges section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#function-privileges) on the same page. 3. Read that section. The `grant execute` block sits after the numbered list. It applies to both ways of restricting execute. 4. Run `pnpm build:guides-markdown` from `apps/docs`. Read `apps/docs/public/markdown/guides/database/functions.md`. The admonition appears as a `Danger:` paragraph. Discard the `manifest.json` change. 5. Run `npx prettier --check apps/docs/content/guides/database/functions.mdx`. Clean. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded guidance on the security risks of `security definer` functions, including their privileges, interaction with Row Level Security, and default execution access. * Added recommendations for checking data ownership and restricting execution to intended roles. * Clarified that pinning `search_path` does not limit execution privileges. * Presented the function-privileges example separately from the default-privileges instructions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Preview links | Site | Live | Preview | Search for | | --- | --- | --- | --- | | Docs | [/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions) | [/docs/guides/database/functions](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions) | `every signed-in caller` | ## Review instructions This PR adds one admonition and moves one code block. The question is whether the admonition is correct and whether an agent reading the page would act on it. 1. Open the preview at [Security definer vs invoker](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker). A red `danger` panel sits below the definer paragraph. 2. **Read the first paragraph for accuracy.** It claims the function runs with its creator's privileges, that a function created in the Dashboard or by a migration is owned by `postgres`, and that `postgres` bypasses Row Level Security. This matches [Use security definer functions](https://supabase.com/docs/guides/database/postgres/row-level-security#use-security-definer-functions) in the RLS guide. Flag any drift. 3. **Read the two bullets for sufficiency.** The ownership check is the primary fix. The execute grant is listed as a complement, not an alternative, because granting to `authenticated` still returns any user's row to every signed-in caller. Confirm the wording can't be read as "either one is enough." 4. Click the `Function privileges` link inside the admonition. It jumps down the same page. 5. In the Function privileges section, confirm the `grant execute` block sits after the numbered list rather than inside item 2, so it applies to both ways of restricting execute. 6. **Check the agent-facing copy.** Open [the markdown export](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions.md) and find `Danger:`. This is what an agent reads, and it is the audience this PR exists for. **If you only have two minutes:** do steps 3 and 6. Step 3 is the correctness of the advice. Step 6 is whether the audience that prompted the ticket actually receives it. **A note on running SQL from this page.** Don't hand-paste from the rendered page. Blocks are split across tabs, and the Data tab in Returning data sets holds markdown tables that look pasteable but are not SQL. Use the `.md` export of the page, which flattens every tab in page order. #50822 has a copy-paste command for this. |
||
|
|
d8b0a3e87f |
docs(database): make the guide's snippets run in document order (#50822)
Part 3 of 4 in stack #50823. This PR carries **technical revision only**: claims that produce a wrong outcome for a reader. ## Problem This PR came from running a technical assessment using `/test-the-docs`. A reader pastes the guide top to bottom. Two snippets fail. The `planets` table uses a `serial` primary key, then the seed sets ids explicitly. Explicit ids don't advance the sequence, so it stays at 0. The `add_planet('Jakku')` example then draws id 1, which the seed already used: ``` ERROR: duplicate key value violates unique constraint "planets_pkey" DETAIL: Key (id)=(1) already exists. ``` The `security definer` example re-creates `hello_world` with `create` rather than `create or replace`, so it collides with the function from Basic functions: ``` ERROR: function "hello_world" already exists with same argument types ``` The Data tab spells the planet Tatooine. The SQL tab spells it Tattoine. Two debugging snippets read `attendance_table` and `some_table`. No fence creates either, and neither is marked as omitted. ## Solution - **Seeds `planets` and `people` without explicit ids.** The sequence advances, so `add_planet` succeeds. This also settles Tattoine against Tatooine. - **Uses `create or replace` in the definer example**, so it no longer collides. - **Marks the two assumed tables** in the debugging snippets with a comment. - **Points the CREATE FUNCTION link at the current Postgres docs.** It pointed at 9.1, while the intro already links the current version of the same page. **Verification.** I ran every `sql` fence from the guide in document order against Postgres 15 in a throwaway container, with `anon` and `authenticated` created first. Before these changes, two fences errored. After them, the sequence runs clean. ## Manual testing 1. Start a throwaway Postgres: `docker run --rm -d --name pgcheck -e POSTGRES_PASSWORD=pw postgres:15`. 2. Create the Supabase roles the guide references: `docker exec -i pgcheck psql -U postgres -c "create role anon; create role authenticated;"`. 3. Paste every `sql` block from the guide, in page order, into `docker exec -i pgcheck psql -U postgres`. No statement errors. 4. Run `select * from planets;`. Tatooine, Alderaan, Kashyyyk, and Jakku, with sequential ids. 5. Remove it: `docker rm -f pgcheck`. ## Preview links | Site | Live | Preview | Search for | | --- | --- | --- | --- | | Docs | [/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions) | [/docs/guides/database/functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/functions) | `('Tatooine')` | | Docs | New page, 404 in production | [/docs/guides/database/debugging-functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/debugging-functions) | `assumes an attendance_table` | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Clarified the required column types in database function examples. - Expanded guidance on function return values, including `INSERT`, `UPDATE`, and `DELETE` statements with `RETURNING` clauses. - Updated SQL examples to show table creation and automatically generated IDs, corrected the spelling of “Tatooine,” and refreshed the PostgreSQL reference link. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8b148f93c1 |
docs(database): regroup the database functions guide and split out debugging (#50821)
Part 2 of 4 in stack #50823. This PR carries **structure only**: moves, regrouping, and the connective text the new shape needs. Reworded prose already landed in #50820. ## Problem This PR is running a structure edit. A reader arrives from search and has to find one thing. The guide gave them eight top-level headings, no grouping, and no opening outline. The style guide caps a group at 5 ± 1. Four of those headings are the action path: Getting started, Basic functions, Returning data sets, and Passing parameters. Nothing marked them as one sequence. `Suggestions` held four unrelated things: an Edge Functions comparison, two security topics, and a three-part debugging reference. The heading names nothing the reader is doing. Debugging was the largest thing on the page. It sat at H3 with three H4 children, and it shared only the word "function" with the rest of the guide. ## Solution - **Groups the four procedures** under `Create a database function`, so the action path is one unbroken sequence. - **Moves the Edge Functions comparison ahead of the procedures.** A reader choosing between the two needs it before the steps, not after them. - **Groups the two security sections** under `Secure a database function`. - **Splits debugging onto its own page**, `guides/database/debugging-functions`. It is registered in the Database sidebar and cross-referenced from the guide. - **Folds `Deep dive` into `Resources`.** Two trailing headings did one job. - **Adds an opening outline** linking each group and saying when to use it. - **Renames the frontmatter title** to sentence case, `Database functions`. ## Manual testing 1. Open the [guide on the deploy preview](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions). Five top-level headings, with the opening outline linking each group. 2. Open the [new debugging page](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions). It appears in the Database sidebar under Managing database functions. 3. Follow a repointed link. Open [Postgres log config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config) and click Database Function Logging. It lands on the new page at General logging. 4. Run `pnpm build:guides-markdown` from `apps/docs`. Both pages appear under `public/markdown/guides/database/`. Discard the `manifest.json` change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a guide to debugging Postgres database functions, with examples for logging, error handling, and inspecting query results. * Added the guide to Database navigation and updated related resources to link to it. * Reorganized the database functions guide to clarify function creation, security, and privileges. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Preview links | Site | Live | Preview | Search for | | --- | --- | --- | --- | | Docs | [/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions) | [/docs/guides/database/functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions) | `Secure a database function` | | Docs | New page, 404 in production | [/docs/guides/database/debugging-functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions) | `Debugging database functions` | | Docs | [/docs/guides/database/postgres/postgres-log-config](https://supabase.com/docs/guides/database/postgres/postgres-log-config) | [/docs/guides/database/postgres/postgres-log-config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config) | `Database Function Logging` | ## Review instructions This PR moves content. The risk is a broken link, not bad prose. 1. Open the preview of the guide. Count the top-level headings in the right-hand outline. There are five, down from eight. 2. Read the four bullets at the top of the page. Each links to a group, and each says when to use it. Click all four and confirm each lands on its section. 3. Open the new debugging page from the second row. Confirm it appears in the left sidebar under **Managing database functions**. 4. **Check the three locked anchors.** Append each to the preview guide URL and confirm the page jumps: `#quick-demo`, `#security-definer-vs-invoker`. Then append `#general-logging` to the **debugging page** URL. Four other pages link to these. 5. Open the Postgres log config preview from the third row. Find **Database Function Logging** in the Resources list and click it. It lands on the new debugging page, not on a dead anchor. 6. Compare the prose against the live page. **No sentence should have changed** beyond the new opening outline and the cross-reference to the debugging page. **If you only have two minutes:** do steps 4 and 5. A moved section that leaves a dead anchor is the failure this PR could cause. **A note on running SQL from this page.** Don't hand-paste from the rendered page. Blocks are split across tabs, and the Data tab in Returning data sets holds markdown tables that look pasteable but are not SQL. Use the `.md` export of the page, which flattens every tab in page order. #50822 has a copy-paste command for this. |
||
|
|
a9078612f2 |
fix(www): stop cross-zone link prefetch (#51066)
About 95% of the 404s served on supabase.com are App Router RSC prefetches (`?_rsc=`) that www `<Link>`s fire at paths another zone serves: `/docs`, `/dashboard`, `/library`, and the footer's `humans.txt`, `lawyers.txt` and `security.txt`. Next.js can't prefetch or client-navigate across multi-zone boundaries, so each prefetch 404s even though the link itself works. I turned every www link into another zone into a plain `<a>` and added a lint rule so new ones stay that way. **Changed:** - **Cross-zone links are plain anchors**: links that always leave www (literal `/docs`, `/dashboard` and `.txt` hrefs, absolute `https://supabase.com/dashboard` URLs, the `getDashboardCtaHref` CTAs) render `<a>`. Renderers whose href comes from data (nav, footer, plan and add-on CTAs, product cards) branch on `isCrossZoneHref`, which reads the zone list from `lib/rewrites.js`. In-zone links stay `<Link>` and keep prefetching. - **New literal links can't regress**: `www/no-cross-zone-link` errors on a `next/link` `<Link>` whose literal or template href points at another zone. It evaluates `lib/rewrites.js` as production, so `/docs` counts in every environment. - **Click tracking survives the full navigation**: `sign_in_button_clicked`, `start_project_button_clicked` and `www_pricing_plan_cta_clicked` now send with `keepalive`, like `sign_in_submitted` already did, so an immediate page load can't cancel them. The mobile nav Sign in and Start your project buttons used `legacyBehavior`, which never called their `onClick`: PostHog has no `Mobile Nav` location for either event in the last 30 days. Those clicks report from this PR on. - **Typecheck no longer crashes**: the functions page's default export inferred a type through `RealtimeLogs`'s unexported `Props`, which makes the native TypeScript compiler panic during `tsc --noEmit`. I exported `Props`. **Note:** the lint rule only sees literal hrefs. A new renderer whose href comes from data needs its own `isCrossZoneHref` branch, and review is the only check on that. ## To test `/docs` is only rewritten on production and absolute `https://supabase.com/...` links are cross-origin on a preview, so the preview proves the relative non-docs cases (`/dashboard*`, `/library`, the footer .txt files). `/docs/...` prefetches still appear on the preview because it has no docs rewrite. Tested on Vercel preview: - [x] Open `/` with the network tab filtered to `_rsc` and scroll to the footer: no requests for `/dashboard*`, `/library`, `/design-system`, `/kb`, `/evals`, `/humans.txt`, `/lawyers.txt` or `/.well-known/security.txt`, while in-zone ones such as `/pricing`, `/features` and `/blog` still appear - [x] Same check on `/pricing`, `/auth`, `/database`, `/storage`, `/realtime`, `/edge-functions`, `/blog` and a blog post: no `_rsc` requests to `/dashboard*`, `/library` or the footer .txt files - [x] Open the Developers dropdown on desktop and the mobile menu at 390px: no new `_rsc` requests to `/dashboard*` or `/library` - [x] Click header Docs, footer Humans.txt, the hero Start your project button and the pricing Free plan button: each lands where it did before (`/docs`, `/humans.txt` text, `https://supabase.com/dashboard/sign-up`, `https://supabase.com/dashboard/new?plan=free`). Signed out, the Free plan button lands on the dashboard sign-in with `plan=free&returnTo=%2Fnew` - [x] Click the hero Start your project button: the `/platform/telemetry/event` POST with `start_project_button_clicked` completes with a 2xx after the page starts navigating. 201 with the navigation held; on the real navigation the event still reached staging PostHog - [x] At 390px, open the mobile menu and click Sign in: a `/platform/telemetry/event` POST with `sign_in_button_clicked` and `buttonLocation: "Mobile Nav"` fires. Start your project in the same menu also sends `start_project_button_clicked` with `buttonLocation: "Mobile Nav"` - [ ] Signed in, load `/`: no `/dashboard/projects?_rsc=` request (not run: the preview origin has no signed-in session) - [x] Open the desktop Product dropdown and the Product section of the 390px mobile menu: Compute shows its Private Alpha badge and the other products show none (checks the master merge into `MenuItem`) After deploy, `/` and `/pricing` on supabase.com show no `_rsc` requests to `/docs*`, `/dashboard*` or `/library`. After a full day, the share of supabase.com 404s carrying `_rsc=` should drop from about 95% to under 10%, and `sign_in_button_clicked` and `start_project_button_clicked` should start showing a `Mobile Nav` location in PostHog. ## Linear - fixes GROWTH-1294 |
||
|
|
63c165311e |
docs(functions): act on the Edge Function auth eval findings (#50886)
Closes DOCS-1318 ## Problem An agent was asked to build an Edge Function returning the order history for whoever is signed in and calling it. Three runs, all correct: each one used the page's `auth: 'user'` pattern and read through the caller-scoped client. The eval scores 7 of 7, including the guide-read check. These are the gaps that showed up around it. | Finding | What the page does now | Why it matters | | --- | --- | --- | | Two clients, no guidance | The first example destructures `supabase` and `supabaseAdmin` together and labels the second "bypasses RLS (service role)" | A reader skimming for the client to use sees two, and one of them is wrong for that section | | No consequence named | "Bypasses RLS" is the strongest phrasing anywhere | A handler querying a shared table through the privileged client without a filter returns every user's rows. The page never said so | | `verify_jwt` as a value to set | Appears six times, five of them as something to change | Switching it off to clear a 401 in development is a reported failure. The page never said the default is the safe one | ## Solution - **Say which client to reach for**, in the section where both are handed over. - **Name the outcome** in a `danger` admonition: a handler that queries a shared table through `ctx.supabaseAdmin` without filtering by the caller's ID returns every user's rows. - **Frame `verify_jwt = true` as the default to leave alone** on user-facing functions, and say what turning it off costs. - **Say every project starts with a secret key named `default`.** **Not asserted here:** the eval is not re-run. It was already at 7 of 7, so there is no headroom to measure an improvement. A candidate new check is proposed on DOCS-1318. ## Preview links | Site | Live | Preview | Search for | | ---- | ---- | ------- | ---------- | | Docs | [/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth) | [/docs/guides/functions/auth](https://docs-git-docs-functions-auth-eval-findings-supabase.vercel.app/docs/guides/functions/auth) | returns every user's rows | ## Review instructions 1. Open the live and preview links side-by-side. 2. Read Authenticated user calls on the preview. See a paragraph on choosing between `ctx.supabase` and `ctx.supabaseAdmin`, then a `danger` admonition naming the every-user's-rows outcome. 3. See the same section say to leave `verify_jwt = true` on for user-facing functions. 4. Read the note under Service-to-service calls. See it mention the `default` secret key. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that `secret` and `publishable` authentication modes accept the `default` key, and documented how default, wildcard, and additional keys are handled. * Explained that JWT verification is enabled by default and that disabling it leaves `withSupabase` as the only caller-verification step. * Added guidance that admin queries bypass row-level security and should be scoped to the caller when accessing shared tables. * Clarified that service-to-service authentication with `secret` validates only the `default` key. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
259dbe11f1 |
docs/functions auth structure (#50885)
## Problem Restructure the topic based off of the PRed Style Guide. ## Solution - **Group the seven sections into three.** A concept opener, `Choose an auth mode`, holds the mode table. `Secure your function` holds the six patterns. `Environment variables` stays last as the fact group. - **Add an intro outline** linking the three groups, and a group introduction for the patterns. - **Move the Authorization headers link below the mode table**, so the sentence that introduces the table sits next to it. - **Correct the content listing entry** to match the page's own title. **Anchors:** every heading text is unchanged. Five headings move from `##` to `###`, which preserves the slug. The in-page link to `#external-webhooks` and the two existing redirects in `apps/www/lib/redirects.js` all still resolve. Verified by grepping the repo for `functions/auth#` before and after. ## Preview links | Site | Live | Preview | Search for | | ---- | ---- | ------- | ---------- | | Docs | [/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth) | [/docs/guides/functions/auth](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions/auth) | Choose an auth mode | | Docs | [/docs/guides/functions](https://supabase.com/docs/guides/functions) | [/docs/guides/functions](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions) | Securing Edge Functions | ## Review instructions 1. Open the live and preview links side-by-side. 2. See three top-level entries in the preview's table of contents, with six nested under `Secure your function`. 3. Load `/docs/guides/functions/auth#external-webhooks` on the preview. See the page jump to that section. 4. Open the second preview link. See the listing card read "Securing Edge Functions" rather than "With supabase-js". ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized the authentication guide with a table of contents and clearer sections on choosing an auth mode and securing a function. * Clarified that the guide covers all supported auth modes, combining modes, and custom error responses. * Renamed the guide listing to “Securing Edge Functions” and updated its description to mention declaring accepted credentials. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dcf266c360 | feat(docs): update search v2 ui (#51175) | ||
|
|
47fd296fc1 |
Add Flick Games case study (#51285)
## Problem New customer case study for the Case Studies content track: Flick Games, an indie UK games studio running Art of Solitaire and Goalman on Supabase. ## Solution Adds `apps/www/_customers/flick-games.mdx` plus the logo (on-light/on-dark) and quote-avatar assets. Content is ready for design/eng review. Tracked in [MARKET-2252](https://linear.app/supabase/issue/MARKET-2252/case-study-flick-games-sept-23). ## Review instructions 1. Open the preview link for `/customers/flick-games`. 2. Check the logo renders correctly in both light and dark mode, and that both quote avatars load. 3. Read through for tone and flow. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
09a245d72d |
[FE-4520] fix(studio): hide Realtime setup for published tables (#51152)
The Realtime Inspector now checks the Realtime publication before showing setup guidance. Projects with published tables get the join-channel view even before this Inspector session receives any messages; unconfigured projects keep the setup guide. Setup guidance also stays hidden while publications are loading or unavailable. Joining a channel and displaying received messages retain their existing behavior. Addresses [FE-4520](https://linear.app/supabase/issue/FE-4520/realtime-inspector-ui-implies-i-am-not-using-realtime-despite-already). ## To test - With no tables in `supabase_realtime`, open Realtime → Inspector and confirm the setup guide appears. - Enable Realtime on a table and confirm a client receives a database change. Open the Inspector without joining a channel: it should show “Join a channel to start listening to messages” and no setup guide. - Join a channel, trigger a table change, and check the event and payload appear. Stop listening and confirm messages remain visible. - Open Policies, then return to the Inspector and confirm the setup guide stays hidden for the configured project. - Join a broadcast-only channel with no incoming messages and confirm the messages view appears immediately. ## Validation Reproduced the original prompt locally with a working Realtime table, then verified the fix in the browser, including an independent client subscription, a live INSERT in the Inspector, navigation, stopping, and the unconfigured state. Temporary test data and services were cleaned up. All nine new regression tests pass; four fail against the original code. Typecheck, formatting, lint ratchet, Knip, and the case-sensitivity check pass. The full Studio suite passed 7,799 tests with one unrelated Explorer test failure; that test passed on a focused rerun alongside the Inspector tests. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * The Realtime inspector keeps the messages view visible while publication status is loading or unavailable, and when a channel is joined or messages are present. * Setup guidance appears only after publications load successfully and confirm that Realtime is unavailable, with no channel or messages to show. This includes cases where there are no publications, the Realtime publication has no tables, or only a differently named publication exists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
a5688423d0 |
docs(cli): restructure and tighten the CLI getting started guide (#50736)
Closes DOCS-1320 Was the bottom of a two-PR stack. The commit from #50680 moved here, so that PR is closed and this one carries both changes. ## Problem The CLI getting started guide had accumulated structural and prose problems, none of which change what the page claims: - **Nine flat H2 headings**, with Beta channel and Updating the Supabase CLI sitting between installing and running. A first-time reader crossed about 150 lines of beta and upgrade tabs before reaching `supabase init`. - **The introduction opened with a two-step procedure under no heading**, listing `init` and `start` before the CLI is installed. Its first sentence named the tool and where it runs rather than what the reader gets. - **Running a local Supabase project ran concept, fact, procedure, and process together** as one stretch of prose, so the two commands the reader has to run sat in paragraphs between the Docker background and the first-run note. - **Task headings mixed gerunds with imperatives:** Installing, Running, Stopping, and Updating next to Access and Manage. - **No navigation.** A long guide that mixes information types opened straight into commands, with no outline of its major groups. The sidebar contents is not a substitute: it isn't part of the document, and the generated markdown an agent reads has no sidebar at all. - **Four more sequences were prose.** Installing via npm, installing a Linux package, the pre-upgrade backup, and opting out of telemetry each had to be followed in order with nothing marking the order. - **Smaller things:** the Studio screenshot's alt text named the topic its heading already states, two links used "note above" and "here" as their text, and an admonition restated where `sb_publishable_...` comes from. ## Solution Twelve commits, one change type each, plus a master merge and its fixup. - **Style.** The install-method callout drops from four blocks to two paragraphs and uses the documented `title` prop. Active voice on the Postgres, analytics, and telemetry instructions. Descriptive link text. Alt text that describes the Studio screenshot rather than naming it. Cut the admonition restating `sb_publishable_...`. - **Structure.** Beta channel and Updating the Supabase CLI move out of the getting started path. - **Grouping.** Local setup goes under Set up a local project, updating and beta builds under Change your CLI version. The intro's `init` and `start` list gets a Quickstart heading. - **Value statement.** The opening sentence now says what the reader gets. - **Procedure format.** Running a local Supabase project leads with the container runtime prerequisite, then four numbered actions, then the first-run download as an outcome. Starting the container runtime is its own step, since the old prose only assumed it with "with a container runtime running". - **Imperative headings.** Install, Run, Access, Stop, Update, Use the beta channel. - **Four more procedures.** npm install, Linux packages, the pre-upgrade backup, and telemetry opt-out. The three pre-upgrade commands were one unexplained block inside an admonition, so each step now says what its command does. Re-enabling telemetry moves to a sentence, since it's the reverse action rather than a step. - **Intro navigation** listing the major groups, each line saying what the reader gets from it. - **Connect to a hosted project** (from #50680). A new section between Stop local services and Change your CLI version, saying the stack runs only on the reader's machine and nothing reaches a hosted project until they sign in and link one, then pointing at the page that owns the procedure. No commands. The `init` step gains a sentence saying it creates local files only, and the value statement and intro navigation cover the added goal. - **Style guide and word list fixes** from an audit of the page against `CONTRIBUTING.md` and `WORD_LIST.md`. `directory` over `folder` in command-line contexts, `might` over `may`, present tense over `will`, a noun after `this`, no `above` as a pointer, concrete verbs over `manage`, no time-relative `latest`, no parentheses for supplementary information, and an impact-first `caution` on the pre-upgrade callout. The container runtime list becomes a table of tool and platforms, and the group heading becomes Change your CLI version. ## Preview links | Site | Live | Preview | Search for | | ---- | ---- | ------- | ---------- | | Docs | [/docs/guides/local-development/cli/getting-started](https://supabase.com/docs/guides/local-development/cli/getting-started) | [/docs/guides/local-development/cli/getting-started](https://docs-git-docs-cli-getting-started-edits-supabase.vercel.app/docs/guides/local-development/cli/getting-started) | Change your CLI version, Connect to a hosted project | ## Manual testing 1. Open the docs preview link above. 2. Read the introduction. It opens with a value statement, then links the four major groups. Under Quickstart, the install-method callout explains how the install method changes the command you run. 3. Read the On this page list. It nests: Quickstart, Set up a local project with four sections under it, Change your CLI version with two sections under it, Telemetry, Learn more. 4. Check Run a local Supabase project renders four numbered steps, with code blocks inside steps 3 and 4. Check the npm tab of Install the Supabase CLI renders three, and How to opt out renders two. 5. Load the page at `#installing-the-supabase-cli`, `#beta-channel`, and `#updating-the-supabase-cli`. All three land on their sections despite the renamed headings. 6. Load the legacy path `/docs/guides/cli/getting-started#updating-the-supabase-cli`. It redirects to the current path and keeps the fragment. 7. Check the introduction's group list includes Connect to a hosted project, and that the section appears in the On this page list between Stop local services and Change your CLI version. 8. Check that section is two sentences and a pointer, with no commands. 9. In Run a local Supabase project, select the "Connect to a hosted project" link in step 3. The page scrolls to that section. 10. Follow both outbound links from the new section and confirm they resolve, including the `#configure-github-actions` fragment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized the local development guide with a clearer quickstart, setup steps, service access instructions, and CLI version guidance. * Expanded installation examples to include bun and clarified package-runner commands. * Clarified upgrade, backup, container cleanup, and telemetry instructions. * Added a reference to the Microsoft Writing Style Guide. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
53ecbf9f2a |
chore: Add telemetry to search v2 user actions (#51146)
## Problem We need to collect data from search v2 experiment usage. ## Solution Add telemetry to search v2 modal being opened, closing, sending a query and clicking a search v2 result. <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions 1. Open the preview link and add the search v2 flag query: `?docs-search-v2=search-v2-active` 2. Trigger all actions mentioned above 3. Telemetry data should be sent on the network tab ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Documentation search activity is now recorded when the dialog opens from the keyboard shortcut or search input, and when it closes. Search submissions include the query and whether results were found; selected results include their destination and the highlighted query. This adds visibility into key search interactions without changing how search results or highlighting work. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
42dc4dbe90 |
chore: Add observability to search_v2 route (#51149)
## Problem Our new Search V2 edge function can fail, we want to know when that happens. ## Solution Added the common Sentry wrapping plus try/catch strategy to the edge function so we can add alerts to our Sentry dashboards and report channels. <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions There's no way to reproduce this for the moment. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Search requests that encounter unexpected server-side errors now receive a handled 500 response instead of an unhandled failure. Errors returned by the search service also produce a 500 response, making failure behavior more consistent for clients. The search query and result-limit behavior remain unchanged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d7cac841c4 |
docs: state the adapter removal date in the server frameworks guide (#51276)
The server frameworks guide still said the adapters "will be deprecated soon" and would be "removed in a future major". They have been deprecated since `@supabase/server` 1.9.0, with `@deprecated` tags shipping in 1.9.1, and the removal date is December 1, 2026. This PR updates the two sentences to state that date and drops the wording about the release shape, which is not decided. |
||
|
|
7d04c43082 |
fix(logs): default unified logs to otel DEBUG-228 (#51089)
## Problem Unified Logs could start legacy BigQuery requests while ConfigCat loaded, then switch to OTEL when the flag resolved. ## Fix Default Unified Logs to OTEL unless otelUnifiedLogs is explicitly false. Use that selection for list, count, chart, facet, detail, download, and manual refresh requests. Keep BigQuery as an explicit opt-out until the legacy backend is removed. ## Validation - Studio typecheck passed locally. - Existing Unified Logs utility tests passed (21 tests). - The focused Unified Logs query test file was removed as requested; backend-selection and manual-refresh regressions are no longer covered by that suite. - CI checks are running on the current head. Tracks [DEBUG-228](https://linear.app/supabase/issue/DEBUG-228/prevent-bq-queries-before-the-feature-flag-loads). |
||
|
|
b028908136 |
feat(studio): add never option to scoped pat expiry (#51273)
## Problem When building scoped pat's we had omitted the option to have them never expire. ## Solution This re-adds the option to select "never" and it comes with the caveat of an admonition to warn the user that they would need to manually delete or revoke this token. ## Review instructions Provide a clear numbered procedure that the PR reviewer can walk through. 1. Open /account/tokens 2. Click Generate new token. 3. Open Expires in. Confirm "Never" is the last option, after "Custom", and has no Recommended badge. 4. Select Never. A warning admonition appears directly below the expiry row: "This token never expires — Anyone with the token keeps access until you delete it." 5. Pick an org and project, grant one permission, click Review access. Summary shows Expires: Never. 6. Create the token. The POST body has no expires_at, and the new row's Expires column reads Never. Fixes FE-4527. Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
c4221ef689 |
fix(www) - redirects are never evaluated for anchor fragments (#51198)
## Problem Fragments are never evaluated by the server, only paths. ## Solution Removes non-functioning redirects to reduce clutter + potential routes to evaluate. ## Preview links N/A, since these redirects are within the docs project but the redirect logic is attached to the www project (this setup makes redirects difficult to test and preview). ## Steps to test Try out any of the removed redirects in the live site today, they won't work. |
||
|
|
d7f422eb7e |
fix(www) - remove unnecessary docs redirect for serverless drivers page (#51197)
## Problem The [content](https://github.com/supabase/supabase/blob/master/apps/docs/content/guides/database/connecting-to-postgres/serverless-drivers.mdx) about serverless drivers can't be accessed b/c it's covered by a historical redirect (but still exists in the navigation menu). ## Solution Remove the redirect (tagging @czenko b/c I see you're closer to here contextually and you'd be able to confirm this is correct after your work in #49869). |
||
|
|
b14a577f9d |
fix(docs) - remove temp redirect that should've been removed previously (#51200)
## Problem The `pg_partman` extension was temporarily redirected in #30149, but then never un-redirected. This guide became live again in https://github.com/supabase/supabase/pull/40037/changes#diff-4db130f9070f72e3e0a3f5794a6088230e28977fe743d79af767adb18327c8ab. (#40037) |
||
|
|
0f453c89fa |
docs: add @supabase/middleware install step to server frameworks guide (#51266)
The framework bridges in the `@supabase/server` reference import `@supabase/middleware` directly, but the guide never said to install it. `@supabase/server` depends on it, so npm and yarn users get it through hoisting, while pnpm users hit "Cannot find module '@supabase/middleware'" the moment they copy a bridge. This PR adds the direct-dependency note to the Versions admonition, an `npm install @supabase/middleware` line to the copy-the-bridge step, and the same instruction to the agent migration prompt. |
||
|
|
87681812a0 |
fix(studio): assistant get_active_incidents url in prod (#51047)
The Assistant's `get_active_incidents` tool has [failed in prod 99.8% of the time over the past 60 days](https://supabase.slack.com/archives/C051L8U2EJF/p1790712805774689), so users reporting outages get told it couldn't check incident status. The failures never showed up as errors, which is why nobody noticed. The Assistant now includes the `/dashboard` base path when it calls its own API routes, so the tool stops hitting a 404 in prod ([`/api/incident-status`](https://supabase.com/api/incident-status) is a 404, [`/dashboard/api/incident-status`](https://supabase.com/dashboard/api/incident-status) is a 200). The tool also throws on a failed fetch now instead of returning an `{ error }` result. That way failures show up as span errors in Braintrust and as a failed tool call in the UI. The model still gets the error message and tells the user it couldn't check. When the fetch fails (in dashboard): | Before (prod) | After (local, path temporarily broken) | | --- | --- | | <img width="1036" height="784" alt="CleanShot 2026-09-29 at 5 08 49 PM@2x" src="https://github.com/user-attachments/assets/4539f968-4aa6-49a5-8c7f-7911b6b497a0" /> | <img width="1026" height="716" alt="CleanShot 2026-09-29 at 5 08 06 PM@2x" src="https://github.com/user-attachments/assets/7c9a565c-efe1-4d1a-901b-e440bbb5a739" /> | When the fetch fails (in Braintrust): | Before (prod) | After (local, path temporarily broken) | | --- | --- | | <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 07 PM@2x" src="https://github.com/user-attachments/assets/87860568-b50f-49ee-98fd-4c82f14d1913" /> | <img width="2218" height="920" alt="CleanShot 2026-09-29 at 5 19 10 PM@2x" src="https://github.com/user-attachments/assets/64f58d47-e083-464e-b8d0-8b9c57710a05" /> | When the fetch works (local): | Dashboard | Braintrust | | --- | --- | | <img width="1054" height="808" alt="CleanShot 2026-09-29 at 5 20 58 PM@2x" src="https://github.com/user-attachments/assets/1c9e4cf8-79f0-48e6-b95a-1694fc00a9f9" /> | <img width="2918" height="1144" alt="CleanShot 2026-09-30 at 9 07 03 AM@2x" src="https://github.com/user-attachments/assets/0d2b9685-57a9-4028-a451-272b3de8e23a" /> | Ran it locally with tracing on. Here's a [successful call](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=251bcd44-c55b-44bb-9ce2-b034b26f8832), and one with the path temporarily broken, which now [logs a span error](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?r=637f2dc8-f65b-4d65-9d86-0511b36e8685). Local dev has no base path, so the prod URL is covered by the new `getBasePathURL` tests. Closes AI-1272 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Incident lookups now report fetch, HTTP, parsing, and validation errors rather than returning an empty incident result. * AI SQL generation now accounts for the configured site base path when building its service URL. * **Improvements** * Site URLs now handle trailing slashes and existing base paths consistently, avoiding duplicate path segments. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f414a68e1b |
docs(cli): address final review feedback on supabase stack guides (#51217)
- Add stack = true under the existing [experimental] table instead of pasting a duplicate table, which leaves the setting off. - Note that db dump targets the linked project unless --local is passed, and that --db-url reaches a named local project through DB_URL. - Qualify offline destroy on the host data being deletable, and scope the shared Docker volume cleanup note to volume-backed projects. - Say Docker database storage is chosen when the local project is created. - Allow GitHub's release download host alongside github.com, or the S3 host alone, in allowlisted sandboxes. - www: most services stop when idle (not Functions), and state the [experimental] stack prerequisite in the native runtime entry. |
||
|
|
0c2257fb3d |
feat(studio): scoped oauth data layer (#49476)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? ~~This is the first part (and ultimately the final part of the stacked PR). PR 1 introduces mock data for us while we build the requirements of the scoped oauth interstitial, all following PR's will be stacked on top of this one.~~ This is the first part, the data layer side. We began with mock data, but as backend support arrived we've used this PR to help us shape the UI as well as the frontend data layer. This now acts as the frontend data layer. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added OAuth app authorization request handling. * Added visibility into application details, requested scopes, and existing authorizations. * Added organization and project selection during authorization. * Added organization roles and project access details. * Added approval and denial options with secure redirect handling. * Added validation for required authorization details and project selections. * Added support for role validation feedback during approval. * Added representative authorization scenarios for approved, denied, and re-consent flows. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> Co-authored-by: Samir Ketema <6003000+samirketema@users.noreply.github.com> |
||
|
|
de41b029ef | always use canonical link for new status page (#51264) | ||
|
|
0d8b1417bc |
[bot] Decrease ESLint ratchet baselines (#51225)
Automated weekly decrease of ESLint ratchet baselines. Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Charis <26616127+charislam@users.noreply.github.com> |
||
|
|
77e3b4382f |
feat(role): Allow eligible organizations to invite users as 'No-access' base role (#50922)
## Problem As the API has allow inviting users into `None / No-access` role for team, enterprise, and platform tier organization, we need to update the documentation and descriptions for this new role on the invitation form. ## Solution 1. Updated `apps/docs/content/guides/platform/access-control.mdx` to include the role 2. Added the role description on `apps/studio/components/interfaces/Organization/TeamSettings/Roles.constants.tsx` 3. Add the roles into the proper sorting order at `apps/studio/data/organization-members/organization-roles-query.ts` 4. Add logic to invitation components to disable the role when inviting user into project(s), as the backend does not allow it. ## Testing and verification steps The UI: https://studio-staging-aa8is1m07-supabase.vercel.app/dashboard/org Documentation: https://docs-kht98bi78-supabase.vercel.app/docs/guides/platform/access-control <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary * **Updates** * The **None** role is labeled **No-access** and describes the lack of organization and project resource access. * **None** is included after **Read-only** in the role list. When inviting a member with project-only access, **None** is disabled with an explanation. * **Documentation** * Clarified plan coverage for **Read-Only** and **No access**, and added guidance on assigning **No access** at the organization level before granting project-specific roles. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
04a6baf869 |
fix(kb) - add topic name (#51186)
## Problem Adds a new topic b/c `Comparisons` is reserved for other types of content. ## Preview links TBD <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Made the Comparison topic visible and added a hidden Rundowns topic covering comparisons across technologies and facets. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
901d1915b6 |
add Ben Fritsch to humans.txt (#51265)
Adding myself to humans.txt |
||
|
|
01bfab39d6 |
studio: improve warning for replicas on spend cap (#51179)
## Summary The "> 8 GB warning" when spend cap enabled used to be conflated with the "has replicas with spend cap" warning, which causes a confusing error message. Opting to split them out into 2 separate warnings to give the user a better description of the problem. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Read replicas alone no longer trigger the disk-size threshold warning. * **New Features** * When usage billing is disabled, a warning appears if read replicas are present and no project exceeds 8 GB, with guidance on next steps. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cb52c0f425 |
chore(studio): update segment control in view permissions to ds one (#51125)
## Problem We were using a custom segment control. Recently we introduced segmented toggle groups in our design system. The old one is inconsistent and doesn't match anything else. ## Solution Replace segmented control with [this one](https://supabase.com/design-system/docs/components/toggle-group#segmented). | Before | After | |--------|--------| | <img width="777" height="85" alt="Screenshot 2026-10-01 at 11 36 47" src="https://github.com/user-attachments/assets/84e28075-248d-42d4-a537-f18cd2fe86db" /> | <img width="783" height="95" alt="Screenshot 2026-10-01 at 11 37 00" src="https://github.com/user-attachments/assets/1071f031-8e96-4db1-8ea1-36cb34e9923a" /> | ## Test plan - [ ] Go to Account Settings → Access Tokens, create a new scoped token, and on the capability review step confirm the All/Read/Read-write segmented control renders correctly and filters the capability list as expected - [ ] Open an existing scoped token's "View" sheet and confirm the same segmented control filters correctly there too - [ ] Verify keyboard navigation (arrow keys) and that exactly one option is always selected (no deselect state) - [ ] Visual check against the design system's segmented `ToggleGroup` styling (no leftover custom border/divider artifacts from the old implementation) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the capability-level selector to use a segmented control. Selection behavior remains unchanged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
838fcaaa89 |
Joshenlim/fe 4509 fdw general UI consolidation and refactor (#51079)
## Context Stacks on top of https://github.com/supabase/supabase/pull/51074 PR's just mainly refactoring, no visual differences: - `CreateWrapperSheet` + `EditWrapperSheet` use the same UI components for the foreign tables section - Can be consolidated into one reusable component - `WrapperTableEditor` is still using `SidePanel` component - Can be swapped to use new `Sheet` component - Refactor `WrapperTableEditor`'s layout a little - added separators for clarity between sections <img width="400" alt="image" src="https://github.com/user-attachments/assets/b1983bf2-cff5-43eb-8b31-40a7abb65038" /> - Update `getCreateFDWSql` to just use the Foreign Data Wrapper's name from `wrapperMeta` since its now standardized <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a shared foreign-table selector for wrapper setup and editing, with options to view columns, add or edit table definitions, and remove tables. * Updated the table editor to use a sheet layout with a fixed footer. * **Bug Fixes** * Wrapper creation now uses the wrapper’s configured name when creating the server. * Foreign-table targets display the table name when other target details are unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4311c2c31c |
chore(deps): bump axios from 1.18.1 to 1.20.0 in the npm_and_yarn group across 1 directory (#51114)
Bumps the npm_and_yarn group with 1 update in the / directory: [axios](https://github.com/axios/axios). Updates `axios` from 1.18.1 to 1.20.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/axios/axios/releases">axios's releases</a>.</em></p> <blockquote> <h2>v1.20.0 — August 19, 2026</h2> <p>This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.</p> <h2>⚠️ Breaking Changes & Deprecations</h2> <ul> <li>HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (<a href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li> </ul> <h2>🔒 Security Fixes</h2> <ul> <li>Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (<a href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li>Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (<a href="https://redirect.github.com/axios/axios/issues/11087">#11087</a>, <a href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li> <li>Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (<a href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li> <li>XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (<a href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>, <a href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li> <li>Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (<a href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li> <li>Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (<a href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li> </ul> <h2>🔧 Maintenance & Chores</h2> <ul> <li>Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (<a href="https://redirect.github.com/axios/axios/issues/11092">#11092</a>, <a href="https://redirect.github.com/axios/axios/issues/11098">#11098</a>, <a href="https://redirect.github.com/axios/axios/issues/11099">#11099</a>, <a href="https://redirect.github.com/axios/axios/issues/11106">#11106</a>, <a href="https://redirect.github.com/axios/axios/issues/11107">#11107</a>, <a href="https://redirect.github.com/axios/axios/issues/11122">#11122</a>, <a href="https://redirect.github.com/axios/axios/issues/11123">#11123</a>, <a href="https://redirect.github.com/axios/axios/issues/11126">#11126</a>, <a href="https://redirect.github.com/axios/axios/issues/11127">#11127</a>, <a href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>, <a href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>, <a href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>, <a href="https://redirect.github.com/axios/axios/issues/11144">#11144</a>)</li> <li>Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (<a href="https://redirect.github.com/axios/axios/issues/11101">#11101</a>, <a href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>, <a href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>, <a href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li> <li>Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (<a href="https://redirect.github.com/axios/axios/issues/11124">#11124</a>, <a href="https://redirect.github.com/axios/axios/issues/11136">#11136</a>, <a href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li> <li>CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (<a href="https://redirect.github.com/axios/axios/issues/11128">#11128</a>, <a href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li> </ul> <h2>🌟 New Contributors</h2> <p>We are thrilled to welcome our new contributors. Thank you for helping improve axios:</p> <ul> <li><a href="https://github.com/yens1"><code>@yens1</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11109">#11109</a>)</li> <li><a href="https://github.com/Sasireddy001"><code>@Sasireddy001</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11113">#11113</a>)</li> <li><a href="https://github.com/ari-token-security"><code>@ari-token-security</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11094">#11094</a>)</li> <li><a href="https://github.com/timothyokooboh"><code>@timothyokooboh</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11097">#11097</a>)</li> <li><a href="https://github.com/gi9439041-png"><code>@gi9439041-png</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11119">#11119</a>)</li> <li><a href="https://github.com/Hashim1999164"><code>@Hashim1999164</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11082">#11082</a>)</li> <li><a href="https://github.com/v-dev-cl"><code>@v-dev-cl</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11091">#11091</a>)</li> <li><a href="https://github.com/r0h1tb"><code>@r0h1tb</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li> <li><a href="https://github.com/ostapondo"><code>@ostapondo</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li> </ul> <p>Full Changelog (<a href="https://github.com/axios/axios/compare/v1.19.0...v1.20.0">https://github.com/axios/axios/compare/v1.19.0...v1.20.0</a>)</p> <h2>v1.19.0 - July 22, 2026</h2> <p>This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.</p> <h2>🔒 Security Fixes</h2> <ul> <li>Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>). (<a href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <h2>v1.19.0 — July 22, 2026</h2> <p>This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.</p> <h2>🔒 Security Fixes</h2> <ul> <li>Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>). (<a href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li> </ul> <h2>🚀 New Features</h2> <ul> <li>Configuration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors, adapters, and serializers. (<a href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>, <a href="https://redirect.github.com/axios/axios/issues/11081">#11081</a>)</li> <li>Header Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (<a href="https://redirect.github.com/axios/axios/issues/11051">#11051</a>)</li> <li>HTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (<a href="https://redirect.github.com/axios/axios/issues/11067">#11067</a>)</li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li> <p>Form Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (<a href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>, <a href="https://redirect.github.com/axios/axios/issues/11018">#11018</a>)</p> </li> <li> <p>Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (<a href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>, <a href="https://redirect.github.com/axios/axios/issues/11053">#11053</a>)</p> </li> <li> <p>Cancellation: Propagated already-aborted input signals immediately when composing abort signals. (<a href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</p> </li> <li> <p>Header Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (<a href="https://redirect.github.com/axios/axios/issues/11036">#11036</a>, <a href="https://redirect.github.com/axios/axios/issues/11037">#11037</a>)</p> </li> <li> <p>URL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (<a href="https://redirect.github.com/axios/axios/issues/11008">#11008</a>, <a href="https://redirect.github.com/axios/axios/issues/11038">#11038</a>)</p> </li> <li> <p>Progress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (<a href="https://redirect.github.com/axios/axios/issues/11039">#11039</a>, <a href="https://redirect.github.com/axios/axios/issues/11040">#11040</a>)</p> </li> <li> <p>Error and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (<a href="https://redirect.github.com/axios/axios/issues/11044">#11044</a>, <a href="https://redirect.github.com/axios/axios/issues/11059">#11059</a>)</p> </li> <li> <p>Content-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (<a href="https://redirect.github.com/axios/axios/issues/11061">#11061</a>)</p> </li> <li> <p>Synchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (<a href="https://redirect.github.com/axios/axios/issues/11071">#11071</a>)</p> </li> </ul> <h2>🔧 Maintenance & Chores</h2> <ul> <li>Dependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (<a href="https://redirect.github.com/axios/axios/issues/11031">#11031</a>, <a href="https://redirect.github.com/axios/axios/issues/11055">#11055</a>, <a href="https://redirect.github.com/axios/axios/issues/11056">#11056</a>, <a href="https://redirect.github.com/axios/axios/issues/11058">#11058</a>, <a href="https://redirect.github.com/axios/axios/issues/11079">#11079</a>, <a href="https://redirect.github.com/axios/axios/issues/11080">#11080</a>, <a href="https://redirect.github.com/axios/axios/issues/11088">#11088</a>, <a href="https://redirect.github.com/axios/axios/issues/11089">#11089</a>, <a href="https://redirect.github.com/axios/axios/issues/11090">#11090</a>)</li> <li>Build Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (<a href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li> <li>Form Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (<a href="https://redirect.github.com/axios/axios/issues/11062">#11062</a>)</li> <li>Developer Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (<a href="https://redirect.github.com/axios/axios/issues/11032">#11032</a>, <a href="https://redirect.github.com/axios/axios/issues/11073">#11073</a>)</li> <li>Documentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (<a href="https://redirect.github.com/axios/axios/issues/11041">#11041</a>, <a href="https://redirect.github.com/axios/axios/issues/11068">#11068</a>, <a href="https://redirect.github.com/axios/axios/issues/11076">#11076</a>, <a href="https://redirect.github.com/axios/axios/issues/11078">#11078</a>)</li> <li>Publishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (<a href="https://redirect.github.com/axios/axios/issues/11083">#11083</a>, <a href="https://redirect.github.com/axios/axios/issues/11095">#11095</a>)</li> </ul> <h2>🌟 New Contributors</h2> <p>We are thrilled to welcome our new contributors. Thank you for helping improve Axios:</p> <ul> <li><a href="https://github.com/afonsojramos"><code>@afonsojramos</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li> <li><a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>)</li> <li><a href="https://github.com/yassertawfik4"><code>@yassertawfik4</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11024">#11024</a>)</li> <li><a href="https://github.com/AnandSundar"><code>@AnandSundar</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>)</li> <li><a href="https://github.com/lin-hongkuan"><code>@lin-hongkuan</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</li> <li><a href="https://github.com/Wali007-lab"><code>@Wali007-lab</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li> <li><a href="https://github.com/magicdawn"><code>@magicdawn</code></a> (<a href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/axios/axios/commit/84a9f3b9a4f3244b8c8e818f557d64c7b964fb25"><code>84a9f3b</code></a> chore(release): prepare release 1.20.0 (<a href="https://redirect.github.com/axios/axios/issues/11152">#11152</a>)</li> <li><a href="https://github.com/axios/axios/commit/e6824eec5fcf9da467a9792724396badc490c469"><code>e6824ee</code></a> fix: core methodList, HTTP adapter errors, and add tests (<a href="https://redirect.github.com/axios/axios/issues/11096">#11096</a>)</li> <li><a href="https://github.com/axios/axios/commit/d8a919fd81403d59058c0e9dbefc540407dee83f"><code>d8a919f</code></a> fix(xhr): flush final progress during the live loadend dispatch (<a href="https://redirect.github.com/axios/axios/issues/11121">#11121</a>)</li> <li><a href="https://github.com/axios/axios/commit/2d2a21af8a433089474a2149781799c93acbcf3c"><code>2d2a21a</code></a> fix(interceptors): tolerate nullish handlers in syncHandlerEntries (<a href="https://redirect.github.com/axios/axios/issues/11118">#11118</a>)</li> <li><a href="https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"><code>d19040b</code></a> fix: harden runtime option handling (<a href="https://redirect.github.com/axios/axios/issues/11141">#11141</a>)</li> <li><a href="https://github.com/axios/axios/commit/e0a02dd16671deabe2b809334d4c2ebede29a233"><code>e0a02dd</code></a> chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...</li> <li><a href="https://github.com/axios/axios/commit/d10cb3aa3cda1d78721ddf96be590478df26cd81"><code>d10cb3a</code></a> chore(deps-dev): bump the development_dependencies group with 4 updates (<a href="https://redirect.github.com/axios/axios/issues/11143">#11143</a>)</li> <li><a href="https://github.com/axios/axios/commit/2c94646eb7cb7ab9dcb2aefdb04ab1b040c28e16"><code>2c94646</code></a> chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (<a href="https://redirect.github.com/axios/axios/issues/11133">#11133</a>)</li> <li><a href="https://github.com/axios/axios/commit/76c12bce5a4fe9a45bef9a5bf2baaf599d7d382e"><code>76c12bc</code></a> chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (<a href="https://redirect.github.com/axios/axios/issues/11140">#11140</a>)</li> <li><a href="https://github.com/axios/axios/commit/ba98559a7f5a18e531b5762387e5957bd281af3d"><code>ba98559</code></a> docs: add ScrapingBee sponsor (<a href="https://redirect.github.com/axios/axios/issues/11137">#11137</a>)</li> <li>Additional commits viewable in <a href="https://github.com/axios/axios/compare/v1.18.1...v1.20.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
521881a899 |
Joshenlim/fe 4480 fdw create wrapper to only init fdw once users to name the (#51074)
## Context PR here refactors the way we manage Foreign Data Wrappers in the dashboard (Under Project -> Integrations), as there's some DX problems with the current behaviour. Currently whenever a user creates a new wrapper, the dashboard is creating both the Foreign Data Wrapper (`create foreign data wrapper...`) + server (`create server ...`). The former is **_redundant_** to create multiples of given that it just handles the `handler` and `validator`, whereas what matters more is the server which holds the connection credentials. Hence standard practice is usually one Foreign Data Wrapper with multiple servers. (The former just needs to be created once if not done yet) This also led to some problems as well when users created their own wrappers via SQL and tried to manage them through the dashboard GUI, leading to us having to add some guard rails to prevent managing wrappers sharing the same Foreign Data Wrapper ([ref](https://github.com/supabase/supabase/pull/50785)) ## Changes involved - When creating a wrapper, if the Foreign Data Wrapper has yet to be set up for the wrapper type, the dashboard will initialize one and subsequently use that same Foreign Data Wrapper for any new wrappers - When creating / editing a wrapper, users will name the **server** instead of the **wrapper** <img width="500" alt="image" src="https://github.com/user-attachments/assets/b3e61204-0e16-4599-84ac-af2aab5b93c2" /> - When deleting a wrapper, the clean up for vault secrets are now deterministic by referencing the wrapper's server options - RE backwards compatibility: Existing wrappers will _not_ be affected by the changes here - they can be edited / deleted as per normal ## Unrelated fixes + UI refactors added - Fix Iceberg Wrapper not showing the right form when adding new wrapper - Adjust form layouts in side panel to be horizontal instead of vertical (Follows Database -> Pipelines) - Clean up to use newer UI components like `ButtonTooltip` - Opt to hide Docs + Create CTA under `WrappersTab` if marketplace feature preview is enabled (Since these actions are already in the header, will be duplicates) - Consolidate foreign tables configuration for create + edit wrapper sheet into one component `ForeignTablesSelector` ## To test - [ ] Verify that existing wrappers with their own Foreign Data Wrapper can be edited correctly - [ ] Verify that existing wrappers with their own Foreign Data Wrapper can be deleted - [ ] Verify that existing wrappers with shared Foreign Data Wrapper can be edited correctly - [ ] Verify that existing wrappers with shared Foreign Data Wrapper can be deleted - [ ] Verify that new wrappers can be created - [ ] Verify that newly created wrappers can be edited correctly - [ ] Verify that newly created wrappers can be deleted |
||
|
|
5de3666930 |
Fix: storage explorer ignore current filter after mutations (#51174)
## Problem When users trigger actions such as deleting an item, the storage explorer reloads the opened folders but ignore the currently applied filter. ## Solution Move the filter state in Valtio so that its other functions are aware of it. ## Review instructions 1. Create a Supabase project and upload objects in Storage with date prefixes (e.g., 202608XX) 2. Navigate to Storage, select a bucket with multi-dated/prefixed objects 3. Enter a filter in the search box (e.g., 20260820) to show only matching objects 4. Select one or more filtered objects and delete them Observe the file list after deletion - it should show filtered contents according to the search box value <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Storage search now stays in sync as you open folders and refresh their contents. * When restoring open folders, search results are filtered in the deepest open folder rather than hiding ancestor folders. * Deleting a file from filtered results keeps the search applied and displays the remaining matches correctly. * Search results remain consistent across folder navigation, refreshes, and file deletion. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ba82106697 |
chore(www + studio): remove expired Select 2026 promo banners (#51245)
## Problem Supabase Select 2026 has finished. The promo banners already hide via the scheduled expiry from #51006, but the campaign code, assets, and wiring are still in the tree. ## Solution Remove the Select 2026 sitewide promotion across www and Studio: - Delete shared `Select26*` banner code, font, and tests from `ui-patterns` - Delete Studio `BannerSelect2026*` and its Banner Stack registration - Unmount the www announcement banner and revert the State of Startups spacing that only existed for it - Drop the Select-only session-replay `data-band` allowlist entry and lint ratchet baseline Event go pages, blog posts, and other Select content are left alone. The `Announcement` shell stays for the next campaign. ## Review instructions 1. Open the www homepage on the deploy preview. Confirm there is no Select announcement bar above the nav. 2. Open `/state-of-startups` on the deploy preview. Confirm the hero still looks correct with no extra top gap from the removed banner. 3. Open a hosted Studio dashboard page on the deploy preview. Confirm the Banner Stack no longer shows a Select card. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) |
||
|
|
63718b4b84 |
feat(docs): render experimental badge for Management API endpoints
Management API endpoints now supports expressing an "experimental" stage where we previously only marked it as deprecated. We now render the badge as experimental instead and avoid the strikethrough. This clearly shows that the endpoint is not to be removed, but rather being tested for inclusion. PR: https://github.com/supabase/supabase/pull/51045 |
||
|
|
acaf640d1c |
Joshenlim/fe 4522 polish recovery codes UI (#51124)
## Context Just a couple of UI polishes for the recovery codes UI under Account settings -> Security - all visual, no functional changes ## Changes involved - Shift position of Recovery codes section below MFA - Better hierarchy since recovery codes only matter after adding an MFA app - Prevents layout shift with the feature flag as well | Before | After | |------|------| | <img width="400" alt="image" src="https://github.com/user-attachments/assets/3f24e30b-14b1-49cc-8942-0bd139af031b" /> | <img width="400" alt="image" src="https://github.com/user-attachments/assets/9a020b9b-4644-4e39-ba75-082e7f3a08db" /> | - Update how recovery codes are displayed | Before | After | |------|------| | <img width="400" alt="image" src="https://github.com/user-attachments/assets/9ce00013-9b7f-4ab9-9a10-0eec536022f5" /> | <img width="400" alt="image" src="https://github.com/user-attachments/assets/6bdc8c18-cfd2-46ea-a851-5a9fe03a5211" /> | - Update recovery codes modal, aligns "confirmation" UX to be more consistent with scoped PAT - Footer CTA is just "Done" that's disabled until either Copy or Download is clicked - Copy CTA shifted below codes for contextual grouping - Also added download CTA, which just downloads codes in TXT | Before | After | |------|------| | <img width="534" height="389" alt="image" src="https://github.com/user-attachments/assets/55cdbe9f-f37c-4284-b2ac-46834fd14437" /> | <img width="533" height="548" alt="image" src="https://github.com/user-attachments/assets/ab091822-e5fc-464c-94e6-f1d6b6792c59" /> | - Show success toast after codes are successfully deleted - Use warning variant for regenerate confirmation dialog <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Recovery codes are displayed as a numbered list, with separate options to copy or download them. * You must confirm that you’ve saved the codes before closing the success dialog. * **Improvements** * Generation buttons show when codes are being created. * Recovery-code actions have updated layouts, icons, and confirmation styling. Available codes are identified as single-use, and loading errors are displayed in an alert. * Removing codes displays a success message before the confirmation dialog closes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |