Commit Graph
38874 Commits
Author SHA1 Message Date
531431cd77 docs: document MCP cost confirmation via elicitations (#50017)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update for the MCP cost confirmation launch
([AI-1161](https://linear.app/supabase/issue/AI-1161/write-the-docs)).

## What is the current behavior?

The MCP server guide lists `get_cost` / `confirm_cost` but doesn't
describe the elicitation-based cost confirmation flow that
`@supabase/mcp-server-supabase` 0.12.0 introduces for `create_project`
and `create_branch` on form-capable clients.

## What is the new behavior?

- New **Cost confirmation** section in the MCP server guide: how the
elicitation flow works (accept / decline / expiry / rate-change
outcomes, all side-effect-free except accept), the zero-cost skip,
client support, and how to tell which cost flow a connection uses.
- New troubleshooting entry: "Cost confirmations do not appear in your
MCP client".
- Three `supa-mdx-lint` dictionary additions the new prose needs
(`elicitation(s)`, `dialogs`, `pauses`).

## Additional context

**Draft — hold until launch.** Merge gates before publishing:

1. The feature is enabled for hosted connections.
2. The client support table is re-verified against launch verification
results (there's a matching `{/* ... */}` reviewer note above the
table). Client support moves quickly; the table reflects verification as
of 2026-09-04.

Needs review:

- **Rate-change behavior follows the shipped code, not the spec docs**:
on any change to the computed cost between confirmation and creation
(including a decrease), the server reissues a fresh confirmation rather
than proceeding (`account-tools.ts` redemption path in supabase/mcp).
Flagging in case the intent was lower-or-equal proceeds.
- No exact confirmation expiry is stated because the TTL is
deployment-configured (`ttlSeconds`).
- Wording deliberately says "client-mediated" style confirmation and
avoids claiming a person approved each action, since clients can answer
elicitations via hooks.

Test plan: `supa-mdx-lint` clean on both files; Prettier (repo config)
clean. No runnable snippets, so no sandbox verification needed. Vercel
preview link will appear below.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added advanced options to hosted MCP connections for skipping selected
cost or destructive-SQL confirmations when supported. Available options
depend on connection scope, enabled features, and read-only settings.
* The configuration panel explains when skip selections are unavailable
or ignored by certain client configurations.

* **Documentation**
* Added guidance on cost and SQL confirmation prompts, Edge Function
secret entry, and troubleshooting missing prompts or unavailable secret
collection. This includes client requirements, fallback behavior, and
relevant security considerations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Barry Roodt <barry.roodt@supabase.io>
2026-10-02 08:58:34 +02:00
Wen Bo Xie ffd2754c7a docs(cli): document experimental supabase stack commands and native runtime (#50391)
Add two guides under Local Development for the experimental `supabase
stack` commands, wire them into the docs nav, the CLI reference, the
marketing features list, and the pages that readers reach with a port
conflict.

New pages:
- guides/local-development/parallel-projects: run one local project per
app, git worktree, branch, or named environment on a single machine.
Covers identity, automatic port assignment, removing fixed ports from
config.toml, named projects, finding endpoints, stop and destroy, the
`[experimental] stack` setting, and current limitations.
- guides/local-development/runtimes: the Docker and native runtimes, how
the CLI picks one, native platform requirements, artifact download and
cache locations, and runtime limitations.

Cross-links and context:
- Local development index, CLI getting started, CLI workflows, managing
environments, AI tools, MCP, and the edge functions port troubleshooting
entry now point readers to the new guides where a second `supabase
start` fails on a port conflict.
- CLI reference: `supabase stack`, `stack start`, `stack stop`, `stack
destroy`, the `experimental.stack` config key, and a note on `supabase
start` and `[experimental] stack`.
- www: two feature entries and copy tweaks on the hosted Postgres and
innovation teams solution pages.
- supa-mdx-lint: allow worktree, glibc, musl, and checksum.
2026-10-02 08:39:18 +02:00
Danny White 6143441493 fix(pipelines): clarify DuckLake destination setup (#51013)
## Problem

The DuckLake setup form makes it hard to choose between Supabase
projects and external connection details. Bucket creation, catalog
settings, and the guide do not clearly follow the setup flow.

## Solution

- Show **Configuration method** as two clear choices: **Select Supabase
projects** and **Enter connection details**.
- Group catalog and storage fields, move **Pool size** to **Advanced
settings**, and add **New bucket** to the bucket selector.
- Clarify the custom Postgres and S3 fields, including the metadata
schema, connection URL, and storage options.
- Update the [DuckLake destination
guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake)
to follow the form and explain resource preparation and validation.

| Before | After |
| --- | --- |
| <img width="1280" height="1323" alt="50587"
src="https://github.com/user-attachments/assets/bf5997cf-9fc4-48a8-ad4f-13fa991d56f9"
/> | <img width="1280" height="1323" alt="61914"
src="https://github.com/user-attachments/assets/2c1dd7ef-797f-4302-9e2e-93a5f1e6e515"
/> |

## Review instructions

1. Open **Database > Pipelines > Add pipeline** and select **DuckLake**.
2. Select **Select Supabase projects**. Check the catalog and storage
fields, create a bucket from the bucket selector, and find **Pool size**
under **Advanced settings**.
3. Select **Enter connection details**. Check the Catalog URL, S3 URL
style, and Use SSL guidance.
4. Compare both routes with the [DuckLake destination
guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake).

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] I used the `/edit-the-docs` skill and the docs [style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* DuckLake destinations support Supabase-managed projects or an existing
Postgres catalog with S3-compatible storage.
* Select a storage bucket using search, configure a metadata schema, and
access clearer guidance for catalog and storage settings.
* Advanced settings provide a connection pool size from 1 to 6, with a
default of 4. Credential fields include show and hide controls.
* **Documentation**
* Updated setup steps, configuration guidance, query credential details,
and troubleshooting instructions for both configuration modes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-02 10:34:49 +10:00
Steven EubankandClaude Opus 4.8 26010d80ce docs(observability): rename "Hire an agent" to "Agent prompts" (#51148)
The "Hire an agent" and "monitor" wording oversold the feature: it is
just a prompt you give an agent to check health, security, performance,
or resources, optionally on a schedule. Rename the group to "Agent
prompts", drop "monitor" from the four child pages (Health, Security,
Performance, Resources), and use plainer framing across the landing page
and observability hub. URL slugs are unchanged.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Renamed the Observability section to “Agent prompts” and updated its
page titles and descriptions to describe project checks.
* Clarified that prompts read project data without changing it, and that
findings can be sent through existing harness connections.
* Updated setup guidance to refer to running prompts and using “checks”
in task names.
* Renamed the Health, Security, Performance, and Resources entries. The
related links, schedules, and reporting details remain unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-10-01 23:20:06 +00:00
Andrey A. da2d0c46d7 docs(self-hosting): refresh the overview page (#51127) 2026-10-01 15:45:43 -07:00
Kody JacksonandIvan Vasilov 6572fad288 fix(studio / ui) - update xss vuln version of tanstack (#51141)
## Problem

When I bumped the pnpm-lock file in an unrelated KB fix (#51132), I
believe that refreshed the build cache (either that, or Vercel started
flagging this issue very recently).

At any rate, builds are now failing b/c of a [vulnerable
Tanstack/react-start
package](https://github.com/TanStack/router/security/advisories/GHSA-qx66-fv34-fjm8),
which this PR attempts to fix.

```
The build blocks vulnerable @tanstack/react-start@1.168.18 due to an XSS security check.
```

<img width="1355" height="397" alt="image"
src="https://github.com/user-attachments/assets/7d0d90fb-009c-4a0b-aadc-b526e0fcce0a"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated project maintenance settings and supporting TanStack package
versions.
* Improved error reporting so standard errors include their stack trace,
while other error values are logged directly.
  * No app features were added or removed.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-02 00:42:12 +02:00
Jeremias Menichelli be976bec49 fix: Add federeated content pre-step for search v2 ingestion (#51116) 2026-10-01 13:29:08 +00:00
Jonathan Smock 0fbd5f3037 chore: Add Jonathan Smock to humans.txt (#51115)
## Problem

I have an onboarding task to add myself to humans.txt

## Solution

I have added the characters "Jonathan Smock\n" to humans.txt

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

Please verify that I've inserted my name alphabetically and correctly
spelled.

## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added a team member to the team listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 13:22:40 +00:00
Monica Khoury 123c768de1 Warn when authenticator role overrides exposed schemas (FE-4472) (#50982)
## What

Adds a warning in Project Settings > API when the `authenticator` role's
`pgrst.db_schemas` setting overrides the Dashboard's "Exposed schemas"
configuration, plus an inline "Reset override" button to fix it in one
click.

## Why

`ALTER ROLE authenticator SET pgrst.db_schemas = ...` silently overrides
what PostgREST actually exposes, regardless of what's selected in the
Dashboard. Users hit a confusing PGRST106 error with no indication that
a role-level override is the cause.

## How

- New query (`authenticatorRoleConfigQueryOptions`) reads
`pg_roles.rolconfig`
for the `authenticator` role and parses out any `pgrst.db_schemas`
value.
Configured to always refetch on mount and window focus, since the fix is
often applied outside the Dashboard (SQL editor, another client) with no
  cache-invalidation event for the app to react to.
- `PostgrestConfig.tsx` compares that value against the currently
selected
  schemas and shows an `Admonition` warning naming the actual overriding
  schemas, with a link to the PGRST106 troubleshooting guide, when they
  differ.
- The warning includes a "Reset override" button that runs
  `alter role authenticator reset pgrst.db_schemas` after a confirmation
  step (showing the exact SQL that will run, with a copy button), then
  refetches so the warning clears immediately without a page reload.

## Testing

1. In the SQL Editor of a test project, run:
   ```sql
   alter role authenticator set pgrst.db_schemas = 'public';
   ```
2. Go to Project Settings > API, and select a schema other than (or in
   addition to) `public` in "Exposed schemas" (e.g. add `api`).
3. The new warning should appear, naming `public` as the schema actually
   in effect, with a link to the PGRST106 troubleshooting guide.
4. Click "Reset override" in the warning, confirm in the modal, and
check
   that the warning clears immediately without a page reload.
5. Alternatively, clear the override manually from the SQL editor:
   ```sql
   alter role authenticator reset pgrst.db_schemas;
   ```
then navigate away from the API settings page and back (or refocus the
   browser tab) — the warning should clear without a hard refresh.

Fixes
[FE-4472](https://linear.app/supabase/issue/FE-4472/warn-when-authenticator-role-overrides-exposed-schemas)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* The API settings page now warns when the authenticator role’s exposed
schemas differ from the saved Dashboard configuration.
* You can reset the override to restore the saved schema configuration.
The reset requires permission and provides success or error feedback.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 16:02:00 +03:00
Julien GouxandIvan Vasilov 7b08726d3a docs(cli): document OrioleDB initialization and db.orioledb_version (#50908)
Document `supabase init --use-orioledb` in the CLI reference. Add
`db.orioledb_version` to the CLI config reference, and mark
`experimental.orioledb_version` as deprecated.

This complements the general OrioleDB beta guide update in #50813.

Companion CLI PR: https://github.com/supabase/cli/pull/6828, released in
[v2.119.0](https://github.com/supabase/cli/releases/tag/v2.119.0).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Documented the `supabase init --use-orioledb` option, which sets the
OrioleDB image version in `supabase/config.toml`.
* Added configuration guidance for `db.orioledb_version`, including its
PostgreSQL version requirements.
* Marked `experimental.orioledb_version` as deprecated and directed
users to `db.orioledb_version`. The CLI continues to read the
experimental setting and warns when it is set.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-01 13:13:19 +02:00
Danny White 4f0be099e7 fix(studio): restore the Snowflake destination mark (#51075)
## Problem

The Snowflake destination still uses a neutral text monogram even though
its Studio asset is available. Supporting that monogram also leaves a
separate rendering path used by no other destination.

## Solution

Restore Snowflake through the shared brand-icon registry introduced by
#51073. Simplify `DestinationLogo` back to a map of destination marks,
removing the monogram type, configuration, and rendering branch.

| After |
| --- |
| <img width="924" height="730" alt="CleanShot 2026-09-30 at 15 14
59@2x"
src="https://github.com/user-attachments/assets/7409d483-3371-45ec-bf54-0ddc6ad22857"
/> |

## Review instructions

1. Open `/project/<ref>/database/replication` with a Snowflake pipeline.
2. Confirm the Snowflake mark appears in the pipeline list and diagram.
3. Open the pipeline child route and confirm the same mark appears in
its header.
4. Confirm the other destination marks remain unchanged in light and
dark themes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Visual Updates**
* Snowflake replication destinations now display a themed brand icon
instead of the “SF” monogram. Other destinations retain their existing
icons.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 18:00:55 +10:00
Joshen Lim d6c81b66c9 Apply scrollBeyondLastLine for CodeEditor in QueryEditor and Logs Explorer (#51082)
## Context

As per PR title - this was the behaviour for the SQL Editor and figured
it makes sense to also have this behaviour in the Explorer QueryEditor +
Logs Explorer where the main UX is writing queries, and lets the user
bring the active section of the code closer to the middle of the
viewport (rather than right at the bottom)
<img width="790" height="305" alt="image"
src="https://github.com/user-attachments/assets/07eb63fa-1bb9-4abe-859e-2968a73e7ca5"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Editor Improvements**
* Query editors now allow scrolling beyond the final line, providing
more room to position the last lines on screen.
* The SQL editor no longer forces the decoration area to zero width; it
now uses Monaco’s default width behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 11:20:41 +08:00
Danny White 5fbf1ac4ff feat(studio): support themed pipeline destination logos (#51073)
## Problem

Some destination marks need different assets to maintain contrast across
light and dark surfaces. Their paths are also duplicated between
Pipelines and Wrappers.

## Solution

Add a shared brand-icon registry that supports either one asset or light
and dark variants. Pipeline destination logos resolve against the active
theme, while Wrappers continue using the light variant for their white
logo tiles.

This keeps single-asset destinations unchanged and preserves the
existing monogram treatment where applicable.

| Light | Dark |
| --- | --- |
| <img width="926" height="742" alt="CleanShot 2026-09-30 at 15 03
31@2x"
src="https://github.com/user-attachments/assets/d76e5995-1bb8-4cb7-b991-c5dc1a5d8cb0"
/> | <img width="926" height="732" alt="CleanShot 2026-09-30 at 15 03
03@2x"
src="https://github.com/user-attachments/assets/83d45f30-3bf6-4ddc-8607-e27628cb4966"
/> |

## Review instructions

1. Open `/project/<ref>/database/replication` with pipelines using the
themed destination marks.
2. Switch between light and dark themes from the account menu.
3. Confirm each themed mark swaps assets and remains legible in the
pipeline list, diagram, and child-route header.
4. Open Database Integrations and confirm the corresponding Wrapper
tiles continue using their light-surface assets.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Updated the BigQuery, ClickHouse, DuckLake, and Snowflake icons in
integration and replication views to use branded marks. Icons now use
theme-appropriate variants where available, helping them display
consistently across light and dark themes. ClickHouse’s previous “CH”
monogram is replaced with its branded mark.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 12:04:07 +10:00
Luiz Felipe Machado cf063c4ae8 docs: clarify self-hosted function timeout limits (#50807) 2026-09-30 18:07:29 -07:00
Pamela Chia 232eb921ed fix(docs): omit category sections from reference sitemap (#51069)
The Docs sitemap lists a `/reference/<sdk>/undefined` URL for every
reference category header, on both latest and versioned paths (for
example `/reference/kotlin/v1/undefined`). `generateReferencePages`
turns every flattened section into a link, and category headers never
carry a slug. Search engines get a 404 for the `api/undefined` entries
and a soft 404 for the SDK ones.

I filtered the sections with the same predicate the reference static
params already use (`type !== 'category' && !!slug` in
`Reference.utils.ts`). I ran the generator locally before and after the
change: the only entries it removes are the `/undefined` ones (about 4%
of the sitemap), and it adds none.

**Note:** `getFlattenedSections` stays unchanged because the crawler
route and the reference pages share it.

## To test

Tested on Vercel preview:
- [x] Fetch `/docs/sitemap.xml` on the Docs preview and search for
`/undefined</loc>`: expect no matches
- [x] In the same file, search for `/docs/reference/javascript/select`
and `/docs/reference/kotlin/v1/select`: expect both still listed

## Linear
- fixes GROWTH-1310


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reference pages no longer generate links for category sections or
sections without a slug. Existing link paths and priorities remain
unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:13:52 -07:00
Pamela Chia 5a7c0d6d84 fix(docs): resolve legacy sdk reference urls (#51064)
I made the crawler renderer resolve legacy JavaScript and Dart reference
slugs to their current sections, and updated authored guide and SDK spec
links to use them. Exact slugs still win, ambiguous bare slugs still
return 404, and `file-buckets-listv2` remains a section slug in
canonical links. I kept the www redirect work in a separate draft PR
because the apps deploy independently.

## To test

- [x] On the Docs preview, request `reference/javascript/order` and
`reference/dart/get-user` with a bot user agent. Expect the intended
heading and canonical URL.
- [x] Request `reference/javascript/file-buckets-listv2` with bot and
browser user agents. Expect it to open the list v2 section.
- [x] Request `reference/swift/get-user` and the Kotlin reference root
with a bot user agent. Expect the intended heading.
- [x] Open the Storage quickstart guide and follow its upload reference
link. Expect the current JavaScript upload section.

## Linear

refs GROWTH-1293


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Reference pages now resolve legacy aliases and ambiguous slugs more
accurately, with canonical links that preserve explicit SDK versions.
* SDK version paths are recognized only when the full path segment
matches the version format, improving reference-page routing.

* **Documentation**
* Updated API reference links across authentication, storage, security,
and SDK guides to point to current pages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:11:53 -07:00
Pedro RodriguesandOpenAI Codex 2303de33f5 fix(www): avoid fetching agent skills during development (#51111)
## Problem

`pnpm dev:www` ran `content:build`, whose final `fetchAgentSkills` step
rewrote the committed skills index.

## Change

Local development now runs the existing `content:build:core` generators
and serves the committed index. Every WWW build still runs
`content:build`, which runs the core generators followed by
`fetchAgentSkills`.

```mermaid
flowchart LR
  L[Local dev] --> C[content:build:core]
  C --> N[Next dev]
  I[Committed index] --> N
  B[Preview / production build] --> F[content:build]
  F --> C
  F --> A[fetchAgentSkills]
  R[Latest GitHub release] --> A
  A --> D[Next build]
```

Preview builds fall back to the committed index if fetching fails.
Production builds fail rather than publish a stale index. The committed
fallback is updated to v0.1.9.

## Test plan

- `pnpm dev:www` leaves the index unchanged and serves it byte-for-byte
- stale v0.1.8 fixture refreshes to v0.1.9 through the real fetch script
- `pnpm --filter www test turbo-build.test.ts`
- `pnpm --filter www typecheck`
- `pnpm exec prettier --check apps/www/package.json
apps/www/public/.well-known/agent-skills/index.json`

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

Closes
[AI-1275](https://linear.app/supabase/issue/AI-1275/running-pnpm-devwww-modifies-the-generated-agent-skills-index)

Co-authored-by: OpenAI Codex <noreply@openai.com>
2026-09-30 14:39:36 -07:00
Miranda Limonczenko 9a60894bfa docs(functions): edit the secrets guide against the new style guide (#50763)
Production secrets sat after two non-procedure sections, so the reader
setting up a key crossed reference material to get from the local steps
to the production ones. Move it up to follow Local secrets, which runs
all four procedure sections unbroken before the reference sections.

Group "Where local values come from" and "Default secrets" under a
Reference heading. Both answer "what are its parts?", so both are
Structure under the style guide's information types, and Reference is
the group the worked outline ends with. They demote from H2 to H3,
which keeps them in the page TOC, since it is built from h2 and h3.

No heading is renamed, so the anchors Studio deep-links into
(#default-secrets, #using-the-cli) and the one the secrets-limit
troubleshooting page uses (#accessing-environment-variables) are
intact. Changing a heading's level preserves its slug.

Glue the new shape needs: an outline of the three section groups at the
top, a transition out of the troubleshooting section, and an opening
line under Reference.
2026-09-30 14:36:29 -07:00
Miranda Limonczenko e29f4e0736 docs(database): style pass on the database functions guide (#50820)
Inline rewording only. Nothing moves and no claim changes.

Addresses reader-facing "we", UI labels in quotes rather than bold, "allows
you to", "e.g.", future tense, and title-case common nouns in body prose.
2026-09-30 14:36:17 -07:00
Miranda Limonczenko 19188ece58 docs(functions): style pass on the Edge Function auth guide (#50884)
Apply the docs style guide to Securing Edge Functions. Inline changes only.

- Open the page with a value statement
- Split the sentences that ran past the 26-word aim, and keep one
  relationship per sentence
- Replace dash-bounded asides with separate sentences
- Lift `(the default)` out of parentheses so it reads as a claim
- Name the section instead of "above" and "the sections below"
- Introduce the mode table in the sentence before it
- Raise the `auth: 'none'` admonition to `danger`, and state it in the
  positive form
- Stop restating that admonition in the Public functions section
- Spell out Row Level Security, and name `@supabase/server` rather than
  "the SDK"
- Use Supabase Dashboard and Supabase Platform consistently
- Use "function" rather than "endpoint", and spell out "db"
- Link `@supabase/server` once, and name it as a GitHub destination
- Rewrite the Secret keys alt text to describe both rows, the column
  headers, and the masked key format
2026-09-30 14:36:05 -07:00
Jeremias Menichelli 99103b3571 feat: Add edge function and hooks for search V2 (#51103) 2026-09-30 18:12:07 -03:00
salmanrf 8696762b4b fix(www): keep committed agent-skills index when fetch fails outside production (#50556)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix (build resilience)

## What is the current behavior?

`apps/www/scripts/fetchAgentSkills.mjs` runs as part of `content:build`
and fails the whole `www` build (and `pnpm dev:www`) whenever the GitHub
API call fails. #50106 added `AGENT_SKILLS_GITHUB_TOKEN` to mitigate
rate limits on Vercel, but that does not cover local runs or builds
where the env var is not available (e.g. fork PRs).

Example from a local `pnpm dev:www` hitting the unauthenticated rate
limit:

```
www:dev: Error: GET https://api.github.com/repos/supabase/agent-skills/releases/latest → 403
www:dev: at fetchJson (file:///.../apps/www/scripts/fetchAgentSkills.mjs:38:22)
www:dev: at process.processTicksAndRejections (node:internal/process/task_queues:105:5)
www:dev: at async main (file:///.../apps/www/scripts/fetchAgentSkills.mjs:53:19)
```

## What is the new behavior?

`public/.well-known/agent-skills/index.json` is already committed to the
repo, so when the fetch fails and `VERCEL_ENV` is not `production`, the
script logs the error, keeps the committed file, and exits 0:

```
www:dev: Error: GET https://api.github.com/repos/supabase/agent-skills/releases/latest → 403
www:dev: ...
www:dev: Fetch failed — keeping committed public/.well-known/agent-skills/index.json
```

Production builds still fail loudly so a stale skills list is never
silently shipped.

Verified locally by forcing a 401 with a bad token:

- `VERCEL_ENV=preview` exits 0 and keeps the committed `index.json`
- `VERCEL_ENV=production` exits 1

## Additional context

Follow-up to #50106.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
  * Improved handling of skill data fetch failures outside production.
* Preserves previously available skill data when a fetch fails and a
committed fallback is available.
  * Continues to report failures when no fallback data exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 11:11:39 -07:00
Andrew ValleteauandClaude 2cb70302b0 docs(cli): recommend OrbStack as primary Docker alternative on macOS (#51101)
## Problem

The documentation currently lists Docker Desktop as the preferred option
for all platforms, but OrbStack is a superior alternative on macOS that
offers better performance (faster startup, lower CPU/memory/disk usage).
Users on macOS should be guided toward OrbStack first.

## Solution

Reordered and updated the container runtime recommendations to:
1. Highlight OrbStack as the recommended option specifically for macOS
2. Position Docker Desktop as the recommended option for Windows and
Linux
3. Moved OrbStack higher in the list to reflect its priority on macOS
4. Added a dedicated paragraph in the CLI getting started guide
explaining OrbStack's benefits and why it's recommended over Docker
Desktop on macOS

The changes improve the developer experience by directing macOS users
toward the more performant option while maintaining clear guidance for
other platforms.

## Review instructions

1. Open the preview links for the modified documentation pages
2. Verify that OrbStack is now listed first and marked as "recommended
on macOS"
3. Verify that Docker Desktop is now marked as "recommended on Windows
and Linux"
4. Check the CLI getting started guide to confirm the new paragraph
about OrbStack's benefits is clear and helpful
5. Ensure the information is consistent across both modified files

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] Documentation changes follow the docs style guide

https://claude.ai/code/session_01Nbp9LwhMkqxEvQJzEVUbwt

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated local development guidance to recommend OrbStack for macOS and
Docker Desktop for Windows and Linux.
* Clarified that OrbStack supports extended file attributes on mounted
volumes and container networking, and added startup and resource-use
comparisons with Docker Desktop.
* Listed Rancher Desktop and Podman as alternatives; the CLI guide also
lists Colima.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-30 17:04:49 +00:00
supabase-supabase-autofixer[bot]andzamotany e54394cfd8 feat: update mgmt api docs (#49743)
This PR updates Management API docs automatically.

This regenerates:

- Management API specs and sections
- Personal Access Tokens permission-to-endpoint table
- Personal Access Tokens MCP tool permissions table

Sources include the live Management API specs, MCP permission map,
and Studio's shared permission catalog.

Co-authored-by: zamotany <17573635+zamotany@users.noreply.github.com>
2026-09-30 18:34:09 +02:00
Kody Jackson c44d053aec [KB] fix: update header positioning values for KB (#51096)
## Problem

z-index issue for the KB `Topics` dropdown on the main page, where it
would get hidden behind other elements on the screen.

## Solution

Update z-index values

## Preview links


[Preview](https://kb-git-fix-kb-header-positioning-supabase.vercel.app/kb)
[Prod](https://supabase.com/kb/)

## Additional context

**Before**


https://github.com/user-attachments/assets/61216776-166a-41f9-b1b0-7b2e734ff229

**After**


https://github.com/user-attachments/assets/0c15855d-fac5-4d55-b403-b091fb48e178

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. Open the live and preview links side-by-side.
2. Expand the `Topics` dropdown and see whether or not it's covered.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated header and navigation menu layering to improve visibility when
elements overlap.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 11:20:53 -05:00
samroseandArtur Zakirov 9946747579 docs(orioledb): update OrioleDB docs for public beta (#50813)
> [!IMPORTANT]
> Don't merge until the OrioleDB public beta launches. Docs deploy on
merge.

## What

Updates the OrioleDB guide (`guides/database/orioledb`) for the public
beta:

- States that OrioleDB is in public beta and that OrioleDB projects have
access to the same paid features as other Supabase projects.
- Replaces the outdated "choose `OrioleDB Public Alpha` Postgres
version" instruction and its screenshot with text steps that match the
current project creation form (**Advanced Configuration** → **Postgres
Type** → **Postgres with OrioleDB**). It also notes that OrioleDB can't
be added to or removed from an existing project. A new screenshot will
follow once the dashboard shows the beta labels.
- Corrects the `orioledb.default_compress` range to `-1` to `22`. Values
outside that range are rejected.
- Updates the `EXPLAIN` output for the primary key lookup to match what
OrioleDB returns (`Custom Scan (o_scan)`).
- Replaces the benchmark chart's alt text with a description of the
chart.

Headings, frontmatter, and navigation are unchanged, so existing links
to this page and its sections still work.

## Checked against upstream OrioleDB

Checked the page's claims against the [OrioleDB
docs](https://github.com/orioledb/orioledb/tree/main/doc/usage) and
codebase on `main`:

- The concepts section, the `orioledb.serializable` values, and the
compression settings match.
- The limitations link still resolves (`#current-limitations`).
- Doc changes on `main` since beta17 (collations, sparse files,
concurrent unique bridged indexes) don't affect claims on this page.

## Verification (`/test-the-docs`)

| Snippet / step | Class | Sandbox | Result | Notes |
| --- | --- | --- | --- | --- |
| `create table blog_post …` | runnable-local | DinD + runner,
`supabase/postgres:17.9.0.028-orioledb` | pass | Table created with the
`orioledb` access method (default) |
| `create index …` (2 indexes) | runnable-with-setup | same | pass | |
| `insert …` + `select …` | runnable-with-setup | same | pass |
Timestamp differs, as expected |
| `explain` (3 statements) | runnable-with-setup | same | pass | Primary
key lookup output updated in this PR to match |
| `select … from pg_settings where name like 'orioledb.%'` |
runnable-local | same | pass | All 10 automatically tuned settings
present |
| `alter database … default_compress to 1` | runnable-local | same |
pass | |
| Compression range `-1`–`22` | claim check | same | pass | `23`
rejected: "outside the valid range (-1 .. 22)" |
| User-configurable settings have `user` context | claim check | same |
pass | `serializable` values match the page |
| Hidden `ctid` key when no primary key is defined | claim check | same
| pass | |
| HNSW index via index bridging | claim check | same | fail (product
bug) | Index misses rows inserted after it's created. Known upstream as
orioledb/orioledb#1118, fixed after beta17. The tested image bundles an
earlier OrioleDB release. Re-test on an image with beta18 before
merging. |
| Dashboard project creation steps | deferred | — | deferred | Needs a
hosted project; labels checked against Studio source |

**Tier A path:** every SQL block on the page, run in page order against
the Supabase OrioleDB image.

**Environment:** Docker 29.4.0 (linux/aarch64); compose sandbox from
`test-the-docs`; all SQL run inside the runner container.

**Build:** `pnpm build:guides-markdown` passes; the generated markdown
for this page includes all changes.

## Self-review

**Blockers:** none.

**Before merging:**

- [ ] Re-run the HNSW check on an image with OrioleDB beta18.
- [ ] Re-check the page against the `beta18` tag once it's published.

**Nits left for a follow-up (existing text, outside this PR's scope):**

- The page spells `pg_vector`; the extension is `pgvector`.
- Index support is described twice, in the top note and again under
"Creating indexes".
- The markdown export (`internals/markdown-schema/Admonition.ts`) drops
admonition titles on every page. This PR avoids relying on a title for
the beta status.

Linear: DOCS-1399

🤖 Generated with [Claude Code](https://claude.com/claude-code)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the OrioleDB guide with benchmark results for an 8xlarge
instance, including a 1.8x speedup and throughput data across 32–256
connections.
* Clarified that OrioleDB projects have access to the same paid features
as other Supabase projects, and added guidance to review its
limitations.
* Updated project setup instructions, noting that OrioleDB must be
selected when creating a project and cannot be added later or removed.
* Revised the query plan example and documented compression levels from
`0` through `22`.
* **Product Updates**
  * Updated OrioleDB’s availability stage to public beta.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Artur Zakirov <zaartur@gmail.com>
2026-09-30 11:42:21 -04:00
Artur Zakirov bd9a0ff4e6 feat(orioledb): rename orioledb from Public Alpha to Public Beta in dashboard (#50975)
## Problem

We need to rename orioledb in Dashboard.

## Solution

- Update Studio copy/badges referencing OrioleDB from "Public Alpha" to
"Public Beta" (project creation advanced config, restore-to-new-project,
PITR empty state)
- Remove the scheduled-backups block that hid backups for OrioleDB
projects — OrioleDB now has WAL-G scheduled backups in beta, so that
page should behave normally. PITR keeps its existing guard since PITR is
not yet supported for OrioleDB.
- Update the `useOrioleDb` telemetry property doc-comment to reflect the
beta status
- Update project-creation wizard test expectations/fixtures accordingly
(`release_channel: 'beta'`)

Marketing (`apps/www`) and docs (`apps/docs`) references to OrioleDB
alpha status are being updated separately.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* OrioleDB is now labeled as being in public beta rather than public
alpha, and project creation selects the beta release channel.
* Restore-to-new-project and Point-in-Time Recovery notices clarify that
these features are unavailable for OrioleDB projects.
* OrioleDB projects now follow the standard eligibility checks and page
flow for scheduled backups.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:39:41 +02:00
Paweł Gulbinowiczandcoderabbitai[bot] 032c71c5bf fix(docs): use summary instead of slug for webhooks api spec (#51088)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Operations names for webhooks in Organizations webhooks and Project
webhooks use titles derived from slug, which produces wrong/incoherent
titles, for example: `Organizations slug webhooks deliveries id get`.

## What is the new behavior?

For Organizations webhooks and Project webhooks use `summary` from the
OpenAPI spec as the title instead of deriving it from the operation id.

## Additional context

Once this PR is merged, an _Update Mgmt Api Docs_ workflow needs to be
run to regenerate the sections and the spec.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Management API documentation section titles for organization and
project operations now use the OpenAPI summary when one is available. If
no summary is provided, the title falls back to the existing name-based
format. Titles for other operations continue to use the existing format,
so their presentation is unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-09-30 17:25:17 +02:00
Kevin Webb 525c1de326 chore: Add Kevin Webb to humans.txt (#51093)
## Problem

Kevin Webb joined team and needs to add name to humans.txt as part of
onboarding

## Solution

Edited humans.txt and added Kevin Webb 

## Review instructions

Confirm name is correctly alphabetized.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the team listing to include Kevin Webb, keeping the published
team information current. This change is visible in the project’s public
documentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 14:39:01 +00:00
Katerina Skroumpelou 2013ebf417 docs: drop alpha labels and pin server and middleware imports to a major (#51031)
## Problem

`@supabase/middleware` ships as 1.0.0. The docs still label the
`pipeline` entry form of `withSupabase` alpha, and several snippets
import `npm:@supabase/server` and `npm:@supabase/middleware` with no
version or with a `^0.5.0` pin. A snippet without a version leaves
readers and tools to guess one, and a guessed version fails on deploy.

## Solution

- Removes the alpha wording from the middleware reference intro and
usage examples, the server frameworks partial, and the Bring your own
MCP guide. The `@supabase/server` 1.6.0 floor stays.
- Pins every `npm:@supabase/server` and `npm:@supabase/middleware`
import in the guides to a major range, `@1`, following the
`npm:@supabase/supabase-js@2` convention in Managing dependencies.
- Bumps the authenticated-mcp-server example to middleware `^1.0.0` and
server `^1.9.0`.

~~Blocked by supabase/middleware#49. The `@1` range resolves once 1.0.0
is on npm.~~




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated authentication, API key, and MCP examples to use versioned
Supabase server and middleware packages.
* Clarified that pipeline and nested composition behave the same, and
that both require `@supabase/server` 1.6.0 or later.
* Removed alpha-status labels from `withSupabase` guidance while
retaining the 1.6.0 minimum-version requirement.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:27:44 +03:00
mkaruzaandmkaruza b59447d310 chore: Add Mario Karuza to humans.txt (#50710)
## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

humans.txt doesn't list my name.

## What is the new behavior?

Add to humans.txt

## Additional context

Done as part of the onboarding tasks.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the public team information to include Mario Karuza. The
listed team members now reflect this addition.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: mkaruza <mkaruza@users.noreply.github.com>
2026-09-30 16:02:12 +02:00
Andrey A. e811d984ad docs(auth): inline the Remix code in the OAuth troubleshooting (#50854) 2026-09-30 07:44:50 -06:00
Tanun Turbo Chalermsinsuwan cd305313e4 fix(roles): Show only document-defined roles (#51087)
## Problem

As part of having `None / No Access` available to customers, we need to
start providing this role entry in `/platform/organization/:ref/roles`
endpoint. However, when making it available, the role will show up
prematurely on all the components that relies on
`useOrganizationRolesV2Query` function.

## Solution

This change is to allow us to test the behavior of the new role without
having to turn the API on/off. The UI will show only the "predefined"
entries and ignore the "extras" sent by API.

After this is merged, we will do the following

1. Unhide the None role from the API
https://github.com/supabase/platform/pull/39137 -- this will not have
any effect on the frontend as we already ignore it in this PR
2. Work and continue testing on
https://github.com/supabase/supabase/pull/50922 -- which will be easier
to verify as we no longer need to change the API side

## Review instructions

1. Modify the items in the `FIXED_ROLE_ORDER` list, remove some roles
from there
2. You will see that the role will disappear from the components like
the invitation form or managed access form.



## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Bug Fixes**
* Organization role lists now show only supported roles, in the expected
order. Roles outside the supported set are no longer displayed. This
keeps the list consistent and focused on recognized roles, making
available organization roles easier to review.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 20:40:42 +07:00
Ivan Vasilov ec6be68356 chore: Bump vulnerable deps (#50901)
This PR bumps the vulnerable dependencies `devalue`, `mermaid`,
`@faker-js/faker`, `brace-expansion`, `undici`, `fast-uri` and
`markdown-it`.

It also dedupes `rolldown`, `vite` and various `react-router` deps.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated development and build tooling for Lite Studio, Studio, and the
Vue block, along with tooling used in automated Studio checks. These
changes do not alter app features or workflows, and no new user-facing
capabilities or behavior changes are included. They are limited to the
project’s underlying development setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 14:53:28 +02:00
Luiz Felipe Machado ff80bb1499 feat(self-hosted): function worker retries (#50618) 2026-09-30 13:15:41 +02:00
Luiz Felipe Machado 3fc8af387e feat(self-hosted): add function runtime errors (#50589) 2026-09-30 12:57:27 +02:00
Kamil Ogórek c5b4fbfa11 fix: Handle NO_PROJECT_MARKER for projectRef (#51083)
Skip `NO_PROJECT_MARKER` values for projectRef in API validation.
2026-09-30 10:34:26 +00:00
Andrey A. c8b665caf2 feat(self-hosted): add api gateway logic for functions (#46810) 2026-09-30 11:14:47 +02:00
Saxon FletcherandClaude Opus 5.5 904e3c4aa0 chore(library): remove the Supabase files caption from block previews (#51077)
## Problem

The Files tab on block previews showed a "Supabase files." caption row
between the tabs and the file viewer. It doesn't add anything useful and
takes space from the code.

## Solution

Remove the caption row and render the file viewer directly in the tab
panel. The registry lookup that fed the caption is dropped from
`BlockOverview`; the markdown and agent-prompt export still lists
dependencies as before.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Interface Changes**
* Block overviews now show the generated file tree directly when file
display is enabled.
* The “Supabase files” banner and dependency details are no longer
shown, and the surrounding file layout has been removed.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 05:50:57 +00:00
Danny White 8204854986 docs(design-system): document create actions in comboboxes (#51061)
## Problem

Studio lets people create an item while selecting one, but the design
system does not document this pattern.

## Solution

Document the create action in the Combobox guide with a focused example.
The action sits below the options and leaves the current selection
unchanged. Products can connect it to their own creation flow.

| After |
| --- |
| <img width="552" height="352" alt="CleanShot 2026-09-30 at 10 57
46@2x"
src="https://github.com/user-attachments/assets/69c8069c-d4f9-45e2-b3a1-6e5431e2aff9"
/> |

## Review instructions

1. Open the design system Combobox page and find “[Create from
list](https://design-system-git-dnywh-document-select-create-action-supabase.vercel.app/design-system/docs/components/combobox#create-from-list)”.
2. Select a bucket, then choose “New bucket”. Because it’s just an
example, the selector closes without replacing the selected bucket.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a combobox example with a separate “New bucket” action. Choosing
it closes the menu without changing the current selection; choosing an
existing bucket updates the selection.
* Added documentation showing how to use this create-action pattern,
including guidance on labeling and positioning the action.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 15:40:50 +10:00
Danny White 92952bf903 fix(studio): clarify S3 access key dialogs (#51070)
## Problem

The S3 access key creation dialogs are wider than their contents, use
plural titles for one key pair, and call the name field “Description”
even though the table calls it “Name”. The save state also implies both
values disappear, although only the secret does.

## Solution

Use the small dialog size for both states. Use singular titles, label
the field “Name”, shorten the create button to “Create”, and clarify
when the secret must be copied. The API field remains `description`.

## Review instructions

1. Open a project’s **Storage > S3** page and select **New access key**.
Check the dialog width, title, Name field, and Create button.
2. Create a key and check the save dialog width, singular title, and
secret visibility guidance.

| Before | After |
| --- | --- |
| <img width="1084" height="572" alt="CleanShot 2026-09-30 at 14 37
20@2x"
src="https://github.com/user-attachments/assets/781706ee-0ecc-4535-abb5-f6ac65f02c71"
/> | <img width="844" height="584" alt="CleanShot 2026-09-30 at 14 36
56@2x"
src="https://github.com/user-attachments/assets/119df19f-2f39-4e23-94b4-26665583765c"
/> |
| <img width="1096" height="730" alt="CleanShot 2026-09-30 at 14 37
57@2x"
src="https://github.com/user-attachments/assets/00481ed7-dc05-48b9-8cbc-e76d608aa4b1"
/> | <img width="842" height="780" alt="CleanShot 2026-09-30 at 14 37
39@2x"
src="https://github.com/user-attachments/assets/8c837101-250a-474f-a0fc-cf46ce491f83"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* The credential form now labels the field “Name” and uses “Create” for
the submit button.
* Confirmation text now clarifies that the access key is bucket-wide,
bypasses RLS, and its secret is shown only once. It also refers to a
single access key instead of using S3-specific wording.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 15:21:47 +10:00
Pamela Chia 38b74af3f1 fix(studio): fall back for framework icons without an asset (#51065)
I made the connected-project framework icons fall back when no shipped
SVG exists for a framework. The three icon sites built
`/img/icons/frameworks/<framework>.svg` straight from the integration's
framework preset, which is an open-ended string. They only fell back
when the value was empty, so any preset without an asset (`express`,
`hono`, `fastapi`, `tanstack-start` and others) showed a broken image
and logged a 404.

**Changed:**
- **Broken framework icons**: `getFrameworkIconUrl` returns the asset
URL only for slugs in a set that mirrors `public/img/icons/frameworks/`.
The integration connection row, the org project linker and the
marketplace project picker now show their existing fallback icon for any
other slug. A test keeps the set equal to the directory listing.
- **Framework type**: I deleted the hand-kept `VercelFramework` union.
It listed exactly the shipped icon slugs, while the API types the field
as `string | null`, and that mismatch is what made the old empty-only
check look safe.

**Note:** I rejected an `onError` fallback because the browser still
sends the 404 request. Adding logos for common presets is left for
design.

## To test

Tested on Vercel preview (staging): no real connection there uses these
presets, so I rewrote the org integrations response in the browser to
give one integration four connections.
- [x] Open an org's Integrations page with connections whose framework
has no shipped icon (`express`, `eve`, `tanstack-start-lovable`). Expect
the fallback badge and no request under
`/dashboard/img/icons/frameworks/` for those slugs. Observed: all three
rows showed the badge and the network log had no request for their SVGs.
- [x] Same page with a `nextjs` connection. Expect its framework logo.
Observed: `nextjs.svg` loaded with a 200.
- [x] Same page with the real, unmodified response (one connection with
`framework: null`). Expect the badge, no frameworks requests, and no new
console errors. Observed: as expected.

## Linear
- fixes GROWTH-1309


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Vercel integration and project views now display framework icons when
available and fall back to the Vercel icon when no matching icon exists.
* Framework metadata now supports values beyond a fixed list, while
unsupported frameworks continue to use the fallback icon.

* **Tests**
* Added coverage for supported and unsupported framework icons,
including base-path handling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 12:59:36 +08:00
Pamela Chia 9690efeb42 fix(vault): link to current dashboard route (#51058)
I updated first-party Vault links to open the current secrets route
directly. Wrapper credentials, extension metadata, and blog posts still
linked to the retired path and relied on a redirect.

## To test

On the preview:
- [x] Inspect a Wrapper credential's Vault link. Expect
`/integrations/vault/secrets` with a `search` query for that credential.
- [x] Open the inspected target URL. Expect Vault to show the matching
secret.
- [ ] Click a Wrapper credential's Vault link. Expect the filtered Vault
view.
- [ ] Open the pgsodium extension's Vault link and a Vault blog link.
Expect `/integrations/vault/secrets` without the retired route in the
address bar.

## Linear
- fixes GROWTH-1312


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Vault secrets links now direct you to the project’s Integrations page,
including links from wrapper metadata, blog articles, and the `pgsodium`
extension listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 12:54:28 +08:00
Pamela Chia 99c6e306c7 fix(www): repair legacy reference redirects (#51059)
I repointed legacy reference redirects and first-party links to the
sections the Docs app currently serves. Old client and common-filter
URLs still targeted bare slugs, while SDK landing URLs targeted
`/start`. I preserved v1 auth destinations and linked the retired Dart
v0 migration guide to its original source.

## To test

On the www preview:
- [x] Request `/docs/client/order` with a crawler user agent. Expect a
redirect to `/docs/reference/javascript/using-modifiers-order`.
- [x] Request `/docs/common/filters/_sl` with a crawler user agent.
Expect a redirect to `/docs/reference/javascript/using-filters-rangelt`.
- [x] Request `/docs/reference/kotlin` with a crawler user agent. Expect
a redirect to `/docs/reference/kotlin/introduction`.
- [x] Open the Storage permissions section. Expect its bucket reference
link to target `/docs/reference/javascript/file-buckets-createbucket`.

## Linear
- fixes GROWTH-1293


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated links across blog posts, product pages, and feature listings
to point to current JavaScript, Flutter, and Dart documentation.
* Updated legacy documentation redirects to current reference pages,
including filter, modifier, client, and authentication guides.
* Changed reference-root redirects to lead to each language’s
introduction page.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 20:48:03 -07:00
Steven Eubank ad0ed2cdbc Update docs based on SRE Agent findings (#50910)
## Problem

SRE Agent running against a project which is read-only due to disk being
full.

## Solution

The SRE agent struggled to find the information which is now included in
this PR.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

- https://supabase.com/docs/guides/api/rest/postgrest-error-codes
- https://supabase.com/docs/guides/observability/advanced-log-filtering
- https://supabase.com/docs/guides/platform/database-size

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added guidance for recognizing platform-related PostgreSQL errors,
including read-only mode, disk exhaustion, connection-pool limits, and
database restarts or failovers.
* Added SQL queries for grouping PostgreSQL errors and reviewing recent
error events while filtering out selected platform-level codes.
* Clarified that read-write transaction settings apply only to the
current session, and that background writes resume automatically after
read-only mode ends.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 20:55:02 -05:00
Saxon FletcherandClaude Opus 5.5 a9c594a820 chore(library): rename mcp-server block to mcp (#50999)
Renames the `mcp-server` Library block to `mcp`. Installing it now
creates `supabase/functions/mcp`, so the server is served at
`/functions/v1/mcp`.

- Block, Edge Function folder, and docs page renamed
(`/docs/headless/mcp`)
- Headless App block now installs its tools into
`supabase/functions/mcp` and configures `[functions.mcp]`
- Links in the BYO MCP and MCP authentication guides updated
- Permanent redirects keep `/r/mcp-server.json` and
`/docs/headless/mcp-server` working
- `public/r` rebuilt


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* The MCP Server block is now named `mcp` across its documentation,
installation links, and setup instructions.
  * Updated function endpoints and deployment commands to use `/mcp`.
* Added permanent redirects from the previous `mcp-server` documentation
and install URLs to their new locations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 11:46:35 +10:00
Pamela Chia e0e58f8814 fix(studio): redirect moved dashboard routes (#51056)
I added permanent redirects for the moved Dashboard routes that still
send visitors to 404s. Project and organization identifiers carry
through, while the old project billing path opens the organization
picker for billing.

**Note:** The bare `/dashboard/project` path redirects straight to
Organizations instead of the `/dashboard/projects` hop named in
GROWTH-1295, since `/projects` already redirects there.

## To test

Tested on the Studio preview:
- [x] Requested the eight old Dashboard paths in GROWTH-1295 while
signed out. Each returned 308 with the specified destination.
- [ ] Request bare `/dashboard/project` while signed out on the latest
preview. Expect a single 308 to `/dashboard/organizations`.
- [x] Requested a project backup path with a query string. The
destination kept the project ref and query string.
- [x] Requested `/dashboard/project/_`. The project picker remained
reachable.

## Linear
- fixes GROWTH-1295


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Added permanent redirects for legacy Studio routes covering account
and project pages, backups, email templates, edge-function logs,
secrets, and billing settings.
* Redirects preserve incoming query parameters and URL fragments; the
project selector remains unaffected.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 23:59:31 +00:00
Danny White 68d5011514 fix(studio): hide secret visibility controls in pipeline edit forms (#51010)
## Problem

Pipeline edit forms hide stored credentials but still show visibility
controls beside their placeholders. The controls suggest that the stored
secret can be revealed.

## Solution

- Hide visibility controls in edit mode for ClickHouse, Snowflake,
DuckLake, and Analytics Bucket secret fields.
- Keep the controls available when creating a destination, with
accessible labels for the DuckLake and Analytics Bucket controls.

| Before | After |
| --- | --- |
| <img width="1024" height="196" alt="CleanShot 2026-09-29 at 16 48
56@2x"
src="https://github.com/user-attachments/assets/a9da9a32-ab17-4c07-abf3-dfa88b8c6475"
/> | <img width="1024" height="168" alt="CleanShot 2026-09-29 at 16 47
23@2x"
src="https://github.com/user-attachments/assets/fddeb880-cd23-4752-ae73-8f27348c647f"
/> |

## To test

1. Open **Database → Pipelines** and edit a destination of each type:
ClickHouse, Snowflake, DuckLake with custom parameters, and Analytics
Bucket. Check that the hidden secret fields have no eye button.
2. Start creating each destination and check that its secret fields
still offer a working visibility control.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **Improvements**
* Secret fields in replication destination forms remain masked when
editing an existing destination, and their visibility controls are
hidden. When creating a destination, supported secret fields can be
revealed.
* **Accessibility**
* Catalog-token visibility controls now use dynamic, descriptive labels.
DuckLake catalog URL and S3 secret-key reveal controls also have
descriptive labels.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:55:45 +10:00
Danny White 6b7c91a773 docs(pipelines): clarify ClickHouse setup and form copy (#51009)
## Problem

The ClickHouse destination guide leaves parts of resource setup unclear.
The pipeline form suggests the `default` ClickHouse user and database
even when a dedicated user and database are prepared.

## Solution

- Clarify the ClickHouse setup path, connection details, engine choice,
and query example in the guide.
- Align the pipeline form's labels, examples, and help text with that
setup path.
- Include **Start pipeline** in the BigQuery guide before the cost
confirmation and **Create and start pipeline**.

## Review instructions

1. Open **Database → Pipelines**, add a pipeline, and choose
**ClickHouse**. Check the endpoint label, user and database examples,
and table engine help.
2. Read the [ClickHouse destination
guide](https://supabase.com/docs/guides/database/replication/pipelines/clickhouse),
especially **Prepare ClickHouse resources** and **Configure ClickHouse
as a destination**.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the BigQuery guide to explain the pipeline validation, cost
review, and start steps.
* Expanded the ClickHouse guide with destination setup requirements,
engine behavior, and querying guidance for current-state views and
append-only history.
* **User Experience**
* Clarified ClickHouse connection field labels and descriptions,
password visibility controls, and table-engine options in the setup
form.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:44:06 +10:00
Danny White 3b1867f314 fix(studio): use neutral fallbacks for pending destination marks (#51003)
## Problem

Some Pipelines destinations should not display third-party brand marks
until their use is confirmed.

## Solution

Render neutral text monograms for destinations with pending brand marks.
Keep approved destination marks unchanged and preserve the existing
assets so they can be restored with a small configuration change.

| After |
| --- |
| <img width="1022" height="936" alt="CleanShot 2026-09-29 at 11 44
37@2x"
src="https://github.com/user-attachments/assets/d94fca61-aa02-4efb-aa78-47ada5d149d3"
/> |

## Review instructions

1. Open `/project/<ref>/database/replication`.
2. Open the destination picker and confirm destinations with pending
marks use neutral two-letter monograms.
3. Confirm the other destination marks are unchanged.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* ClickHouse and Snowflake destinations now display “CH” and “SF”
monograms instead of image marks. BigQuery and DuckLake continue to
display their image marks, while destinations without configured
branding continue to show their destination icons. These logo treatments
make the configured destination branding visible in the replication
destination interface.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:13:06 +10:00