Commit Graph
3053 Commits
Author SHA1 Message Date
Sean OliverandJoshen Lim a7cf044118 feat(telemetry): capture ChatGPT Ads oppref click id (GROWTH-1278) (#51397)
## Problem

ChatGPT Ads appends an `oppref` click id to landing URLs. We don't read
it, so ChatGPT ad signups show up in PostHog with no click id and the
first-referrer cookie doesn't treat the visit as paid.

GROWTH-1278

## Solution

- Add `oppref` to the first-touch click ids sent with PostHog events
(`telemetry.tsx`)
- Add `oppref` to `CLICK_ID_KEYS` in `first-referrer-cookie.ts`, so it
is stored in `_sb_first_referrer` and counts as a paid signal

Conversion reporting to OpenAI itself goes through GTM, so it isn't part
of this PR.

## Review instructions

1. Run `pnpm exec vitest run first-referrer-cookie` in
`packages/common`. The `hasPaidSignals` test now covers `oppref`.
2. On the preview, load any page with `?oppref=test` and check the
first-touch event in PostHog carries `oppref`.

## Checklist

Check all before review:

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-10-08 08:26:17 -07:00
6ef729cb5c feat(storage): versioning bucket modals (FE-4161) (#49205)
| # | Branch | Base |
| - | ------ | ---- |
| 1 | `feat/storage-versioning-private-alpha` — merged | `master` |
| 2 | `feat/storage-versioning/002-bucket-form-fields` | `master` |
| 3 | `feat/storage-versioning/003-bucket-modals` ◀ | 2 |
| 4 | `feat/storage-versioning/004-object-versions-data` | 3 |
| 5 | `feat/storage-versioning/005-file-preview-versions` | 4 |
| 6 | `feat/storage-versioning/006-billing-storage-retention` | 5 |
| 7 | `feat/storage-versioning/007-archived-objects-data` | 6 |
| 8 | `feat/storage-versioning/008-archived-rows` | 7 |
| 9 | `feat/storage-versioning/009-archived-preview-pane` | 8 |
| 10 | `feat/storage-versioning/010-replace-file` | 9 |

## [3/10] Storage object versioning: wire into the bucket modals

**Base:** `feat/storage-versioning/002-bucket-form-fields` (PR 2)

### This PR

Mounts the object-versioning form section in the create and edit bucket
modals behind the feature preview, and saves it.

- create and edit bucket modals spread `bucketVersioningFormFields` into
their existing form schema
- lifecycle defaults  to 30 days / 10 versions
- edit adds a confirmation before suspending an actively versioned
bucket

## Enabling object versioning on a new bucket and setting lifecycle
policies


https://github.com/user-attachments/assets/194f8319-4929-432e-8a50-206f180a77a8

## Edit and suspend object-versioning


https://github.com/user-attachments/assets/f31e1d34-9840-4f5a-a269-6a911214742d

## To reproduce

1. Make sure storage versioning is enabled under feature previews >
Storage Versioning
2. Open Storage Bucket File explorer
3. create new bucket and enable Object Versioning
4. set lifecycle policy
- Noncurrent version expiration: can be either empty or >1
- Retained noncurrent versions: can be either empty or between 1 and 100
and can't exist without "Noncurrent version expiration"
5. Open new bucket with object versioning and test changing lifecycle
policies
6. Disabling object-versioning shows proper warning and updates
`versioning_status` to SUSPENDED (it can never go back to DISABLED once
it has been enabled on a bucket)

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-07 16:38:35 +02:00
Ivan VasilovandClaude Sonnet 5.5 075c611463 chore: bump vulnerable dependencies (#51381)
## Summary

- Bumps vulnerable transitive dependencies flagged by `pnpm audit`, one
commit per dependency (lockfile only, no permanent overrides):
proxy-addr, shell-quote, @fastify/busboy,
@graphql-tools/executor-legacy-ws, @modelcontextprotocol/sdk,
compression, http-cache-semantics, source-map-js, smol-toml, dompurify.
- Updates `scripts/fix-audit-vulnerability.ts` to be agent-friendly:
accepts a dependency name argument, adds `--json` (single JSON object on
stdout, logs on stderr, never prompts) and `--help`.

## Not fixed

The remaining audit findings could not be resolved by this script. Some
are blocked by `minimumReleaseAge` (braces, node-forge, sprintf-js);
others stay vulnerable even with an override and need a parent
dependency update or scoped override.

## Test plan

- [ ] CI passes (typecheck, lint, prettier)
- [ ] `pnpm audit` shows fewer findings than on master

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-07 16:23:43 +02:00
claude[bot]andClaude 6c6b19c6c6 chore(studio): report empty-body GET 200s to Sentry with a no-store probe (#51123)
<!-- ccr-slack-attribution -->
_Requested by **Ivan Vasilov** · [Slack
thread](https://supabase.slack.com/archives/C063LNYJJKS/p1790710416069689?thread_ts=1790710416.069689&cid=C063LNYJJKS)_

**Before:** When a Studio API GET comes back as a 200 with an empty
body, openapi-fetch hands the caller `{}` and we only see the downstream
crash, with no record of the response that caused it.

**After:** The first time this happens for an endpoint in a page
session, Studio sends one Sentry warning, `Empty response body on
successful API request`. It carries the response metadata, browser
state, resource timing, and the result of a single `cache: 'no-store'`
refetch. What the caller receives is unchanged.

## Problem

Studio crashes trace back to GET requests that return 200 with an empty
body, which openapi-fetch turns into `{}`. They are heavily skewed to
Firefox and Safari. The leading hypothesis is browser cache revalidation
(Express weak ETags, no `Cache-Control` on api.supabase.com), but
nothing confirms it yet. The `no-store` probe tells the two cases apart:
if the refetch has a body, the browser cache is the likely culprit; if
it is also empty, the server or the edge is sending empty bodies. This
data should show whether the fix belongs on the API side or the
Cloudflare side.

Context: #51041 (closed) tried to guard the crashing call sites instead.

## Needs API-side change to be fully useful

Cross-origin, Studio can only read CORS-safelisted response headers, and
resource timing sizes read as zero. If api.supabase.com sends
`Access-Control-Expose-Headers: ETag, cf-ray, cf-cache-status,
x-request-id` and `Timing-Allow-Origin: <studio origin>`, this event
will also carry the ETag, cf-ray, and cache status, plus the real
transfer and body sizes and the negotiated protocol. Until then, those
fields read as `null` or `0`.

## Solution

- `data/empty-body-diagnostics.ts` (new): `reportEmptyBodyResponse({
request, response, schemaPath })`.
- Runs only for `GET` and only when `IS_PLATFORM`. Empty POST/201 bodies
are legitimate.
- Reports at most once per templated endpoint per page session
(module-level `Set`).
- Endpoint: openapi-fetch's `schemaPath` (e.g.
`/platform/projects/{ref}/settings`), passed through
`templateEndpointPath`. That function drops the query string and hash,
replaces the segment after `projects`/`organizations`/`branches` with
`{ref}`/`{slug}`/`{branch}`, and replaces UUIDs, numeric IDs, and 20+
character alphanumeric IDs with `{id}`. I used `schemaPath` rather than
the request URL so user-chosen names (bucket names, function slugs)
never end up in tags or fingerprints.
- Probe: one plain `fetch(new Request(request, { cache: 'no-store', ...
}))` with a fresh `X-Request-Id` and a 10s `AbortController` timeout.
`AbortSignal.timeout` isn't available in older Safari. The probe
bypasses the openapi-fetch middleware, so it can't recurse. Only the
body's byte length is recorded, never its contents.
- Event: `level: 'warning'`, `fingerprint: ['empty-body-response',
endpoint]`, `tags: { endpoint, probe_has_body, empty_body_diagnostic:
'true' }`, where `probe_has_body` is `true` / `false` / `error`. `extra`
holds:
- the request: method, status, `response.type`, `redirected`, and the
original `X-Request-Id` (for API log lookup)
- response headers: `content-type`, `cache-control`, `last-modified`,
`expires`, `content-length`, `etag`, `cf-ray`, `cf-cache-status`,
`x-request-id`
- browser state: `visibilityState`, `navigator.onLine`, the navigation
type, ms since navigation start, and whether the page was restored from
bfcache
- the latest `PerformanceResourceTiming` for the URL (transfer, encoded,
and decoded size, `nextHopProtocol`, `responseStatus`)
- the probe: status, request ID, body length, `content-length`,
`content-type`, or the error name
- Fire-and-forget: everything is wrapped in a `try`/`catch`, and the
caller does not await it.
- `data/fetchers.ts`: the `onResponse` middleware passes `{ request,
schemaPath }` to `normalizeEmptyBodyResponse`, which calls the reporter
in its empty-body branch and also for a 200 that carries
`Content-Length: 0`. openapi-fetch short-circuits that case to `{}` the
same way, so it is the same symptom. The return value is unchanged in
every branch.
- `packages/common/sentry.ts`: `filterSentryEvent` normally keeps only
1% of events that aren't page crashes. It now sends events tagged
`empty_body_diagnostic` unsampled, with `codeSampleRate: '1'`. A
once-per-session warning would barely show up at 1%. Consent and
platform gating and the third-party filter still apply. www and docs
also use `filterSentryEvent`, but only Studio's reporter sets this tag,
so sampling for them and for every other Studio event is unchanged.

Sentry config: Studio's `beforeSend` doesn't otherwise drop this
message. It has no exception values, so the no-stack-trace filter
doesn't apply, and it matches no `ignoreErrors` entry.

## Review instructions

1. Check `normalizeEmptyBodyResponse` in `data/fetchers.ts`: the
reporter is `void`-called and its return value is untouched.
2. Check `probe()` in `data/empty-body-diagnostics.ts`: only
`byteLength` is read from the body. The probe reuses the original
request's headers and credentials (same auth as the original GET).
3. Check `filterSentryEvent` in `packages/common/sentry.ts`: only the
`empty_body_diagnostic` tag skips sampling.
4. Tests: `data/empty-body-diagnostics.test.ts` and
`packages/common/sentry.test.ts`.

## Verification

- Unit tests (`data/empty-body-diagnostics.test.ts`, new):
  - path templating cases
  - `probe_has_body` `true` / `false` / `error`
  - the secret body content never appears in the Sentry call
  - one report per endpoint
  - non-GET and non-platform requests are skipped
  - no throw when `fetch` or Sentry throws
- end-to-end through `client.GET`: still resolves `{}` and reports the
`schemaPath`, for both a missing `Content-Length` and `Content-Length:
0`
- `packages/common/sentry.test.ts`: tagged diagnostics are sent
unsampled, untagged or false-tagged ones are still sampled, and they're
still dropped without consent.

These tests, plus the existing `normalizeEmptyBodyResponse.test.ts`,
`handleError.test.ts`, and the rest of `sentry.test.ts`, pass (67 tests)
under vitest 5 + jsdom. I ran them in a minimal harness, not the full
`pnpm install` workspace, because the local checkout is sparse.
- I ran TypeScript 7.0.2 (`--strict`) on the five touched files against
the real `api-types`, with stubbed `common`/Sentry types. No errors in
the touched files.
- Prettier `--check` with the repo config passes, with and without
`SORT_IMPORTS=false`.
- Not run locally: the full studio typecheck, `lint:ratchet`, and knip.
CI covers them. The change adds no `any`, no default exports, and no
deps.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01UefDak8XYLMi9aiEjDPXc5

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-07 16:15:57 +02:00
Charis 22886fd304 feat(studio): add flag-gated general region selection (#51274)
## Problem

We want to be able to show free-plan organizations a simplified region
selector that only lists general regions (Americas, Europe,
Asia-Pacific), controlled per organization through ConfigCat.

## Solution

- ConfigCat flags are now evaluated with `organization_slug` and
`organization_created_at` (Unix seconds) custom attributes, so flags can
target and bucket by organization.
- `organization_created_at` is read from `GET
/platform/organizations/{slug}`, fetched only for free-plan
organizations, since the organization list response doesn't include it.
- Two flags:
- `freeTierGeneralRegionEnrollment`: the organization is enrolled
(control or test).
- `freeTierGeneralRegionSelection`: the organization sees only general
regions.
- For enrolled free organizations, the region selector stays in its
loading state until flags have been evaluated with the organization's
creation time, so specific regions aren't shown and then removed.
- In the test variant, the selector hides specific regions and shows a
footer linking to the plan upgrade panel. High Availability keeps its
own region list.
- Telemetry: new `free_tier_general_region_experiment_exposed` and
`free_tier_general_region_upgrade_clicked` events, and
`freeTierGeneralRegionExperiment` / `regionSelectionType` properties on
`project_creation_simple_version_submitted`.
- `created_at` is added to `OrganizationSlugResponse` in the generated
platform types, matching the API.

## Review instructions

1. With both flags off, open `/new/[slug]` for a free organization and
confirm the region selector is unchanged.
2. Using the dev toolbar, set `freeTierGeneralRegionEnrollment` and
`freeTierGeneralRegionSelection` to `true`. Confirm only general regions
are listed and the footer links to the billing plan panel.
3. Set `freeTierGeneralRegionSelection` to `false` and confirm the full
selector is shown.
4. Repeat with a paid organization and confirm the full selector is
always shown.
2026-10-07 09:43:28 -04:00
Danny White d95ff5bda9 docs(design-system): rewrite sidebar page for monorepo tokens (#51165)
## Problem

The design-system Sidebar page was mostly an upstream shadcn paste:
first-person voice, a broken `/blocks` link, missing structure images,
CLI install steps that do not match this monorepo, and a long changelog
/ data-fetching tutorial that do not apply here.

Separately, it still taught classic shadcn **HSL channel** variables
plus `hsl(var(--sidebar-*))`. In this monorepo those tokens are **full
colours**. Mixing the two patterns produces invalid CSS.

Related call-site cleanup:
https://github.com/supabase/supabase/pull/51161

## Solution

- Rewrite the Sidebar docs as a shorter monorepo guide: import from
`'ui'`, structure, theming, provider / sidebar props, menu building
blocks, controlled mode, state styling.
- Move Studio’s `--sidebar-*` aliases into shared `packages/ui` compat
CSS so every app on the shared theme gets working `bg-sidebar`
utilities.
- Drop the duplicate definitions from Studio `globals.css`.

Left alone on purpose: brand / destructive channel tokens and docs that
correctly use `hsl(var(--brand-…))`.

## Review instructions

Design-system preview:
[design-system](https://design-system-git-dnywh-docssidebar-full-colour-tokens-supabase.vercel.app/)

1. [Live Sidebar
docs](https://supabase.com/design-system/docs/components/sidebar) ·
[Preview Sidebar
docs](https://design-system-git-dnywh-docssidebar-full-colour-tokens-supabase.vercel.app/design-system/docs/components/sidebar).
Confirm the page is no longer the upstream essay: no broken images, no
`/blocks` link, imports from `'ui'`, theming shows full-colour aliases.
2. Smoke Studio: left nav should look unchanged (same aliases, now from
compat.css).
3. Optional: in DevTools, confirm `--sidebar-background` resolves to a
full `oklch(...)` colour.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)
2026-10-07 10:36:41 +11:00
Danny White b5c865521f feat(studio): notify users about the Terms of Service update (#51302)
## Problem

Dashboard users need a notice about the Terms of Service update
alongside #51106 and #51107.

## Solution

Reuse the organisation landing-page notice pattern from #50397. A
compact “We've updated our Terms of Service.” notice opens the
explanation and agreement link through **Learn more**. Closing the
notice or choosing **Got it** remembers dismissal in the browser with a
new version-specific key.

```text
Organisation landing page
  Notice → Learn more → Explanation and Terms of Service link
  Close / Got it → Remember dismissal
```

| After |
| --- |
| <img width="628" height="444" alt="CleanShot 2026-10-06 at 14 47
46@2x"
src="https://github.com/user-attachments/assets/72922712-321f-4972-b20c-1a075e0745d0"
/> |
| _Banner_ |
| <img width="1078" height="718" alt="CleanShot 2026-10-06 at 16 58
18@2x"
src="https://github.com/user-attachments/assets/2109c2ab-e9b7-4855-8acb-42d5232cd002"
/> |
| _Dialog_ |

## Review instructions

1. Open `/organizations` or an organisation's `/org/<slug>` landing page
in the hosted Studio preview. Expect the compact notice.
2. Click **Learn more**. Expect the explanation and a link to the Terms
of Service. Escape closes the dialog without dismissing the notice.
3. Choose **Got it**, then reload. The notice stays dismissed. Repeat in
a fresh browser profile using **Close banner**.
4. Open a project or an organisation settings page. The notice should
not appear.
2026-10-07 09:09:01 +11:00
Joshen Lim eb20a4674d getTableDefinitionSql to escape SQL identifiers (#51258)
## Context

Similar to domain to https://github.com/supabase/supabase/pull/51256 -
`getTableDefinitionSql` doesn't escape SQL identifiers, which generates
invalid SQL on the dashboard's table editor for the "Copy table schema"
CTA, or the table definition tab.

Also fixes the "Copy table schema" CTA which was missing the `scoped`
parameter when calling `getTableDefinition`

Changes here addresses this issue, can test with a table named like
`test"table`
2026-10-06 21:34:36 +08:00
Pamela Chia 20d6f2197f chore(studio): remove privacy policy notice (#51299)
I removed the Studio Privacy Policy update notice that #50397 added on
2026-09-16, when Privacy Policy v4 took effect. It has been up for
almost three weeks, and the ToS v4 banner (#51109) goes out next. I did
the same in #44380, removing the March 2026 privacy notice after 15
days.

This is the exact inverse of #50397: the banner component and its test,
the banner ID, the dismissal local storage key, and the org-landing path
helper that only this notice used.

## To test

Tested on Vercel preview:
- [ ] In a fresh browser profile (no
`privacy-policy-update-2026-09-16-dismissed` key), open
`/organizations`: expect no Privacy Policy notice
- [ ] Open `/org/<slug>`: expect no Privacy Policy notice and the
project list renders normally
- [ ] Open a project's Logs page: expect the logs deprecation banner
behavior unchanged (only shows before its expiry)

## Linear
- fixes GROWTH-1322
2026-10-05 19:24:14 -07:00
Danny White 0cb8bd95dd feat(studio): add spot colour control to Appearance (#50782)
## Problem

The theme's primary hue can change in CSS, but Appearance had no way to
try other spot colours. That makes it hard to find controls whose colour
still depends on the fixed Supabase brand palette.

## Solution

Add a **Spot color** control under Appearance → Theme colors
(employee-only via ConfigCat `appearanceSpotColor`, targeted to Supabase
Team Email).

### Spot color UX
- Rainbow spectrum track with a thin outline so pale tracks stay visible
- Live trifecta swatches for `--primary-solid`, `--primary`, and
`--primary-bright` (darkest → lightest) next to the degree readout
- Drag updates are rAF-batched so React paint and CSS preview stay to
one frame

### Canvas tint coupling
- `--surface-hue` is derived in CSS as `calc(var(--primary-hue) +
var(--surface-hue-offset))`
- Dark: offset `0` (same hue as spot)
- Light: offset `180` (complementary canvas tint; brand green ≈157.5° →
rose ≈337.5°)
- No JS override of `--surface-hue`. Changing Spot color moves primary
controls and the low-chroma canvas tint together

### Other theme sliders
- Renamed **Color intensity** → **Surface tint** (it only drives the
neutral ramp via `--chroma`, not spot chroma)
- Meaning-shaped tracks for every knob (spectrum, grey→tint, soft→hard,
dark→light, flat→lift)
- Same outline treatment on those tracks

| Before | After |
| --- | --- |
| <img width="1476" height="2174" alt="CleanShot 2026-10-05 at 15 02
21@2x"
src="https://github.com/user-attachments/assets/d08b0fa8-32af-450e-adce-861f59c9d6ca"
/> | <img width="1474" height="2354" alt="CleanShot 2026-10-05 at 14 56
35@2x"
src="https://github.com/user-attachments/assets/9a1e6183-a4ba-4c8e-a458-bb0eea946db8"
/> |
| _Anyone else_ | _With staff flag, custom settings_ |

## Review instructions

1. Confirm ConfigCat flag `appearanceSpotColor` is on for your staff
account (or flip it in the Dev Toolbar).
2. Open `/account/me` → **Appearance → Theme colors**.
3. Without the flag: Spot color is hidden; other theme sliders still
work.
4. With the flag: drag Spot color in light and dark. Primary controls
and canvas tint should move together; Supabase brand assets should stay
fixed.
5. Raise Surface tint and confirm the canvas hue follows the
complementary (light) or same-hue (dark) offset.
6. Refresh, switch modes, and use **Reset** to check persistence and
defaults.
2026-10-06 10:11:26 +11:00
Pamela Chia a9078612f2 fix(www): stop cross-zone link prefetch (#51066)
About 95% of the 404s served on supabase.com are App Router RSC
prefetches (`?_rsc=`) that www `<Link>`s fire at paths another zone
serves: `/docs`, `/dashboard`, `/library`, and the footer's
`humans.txt`, `lawyers.txt` and `security.txt`. Next.js can't prefetch
or client-navigate across multi-zone boundaries, so each prefetch 404s
even though the link itself works. I turned every www link into another
zone into a plain `<a>` and added a lint rule so new ones stay that way.

**Changed:**
- **Cross-zone links are plain anchors**: links that always leave www
(literal `/docs`, `/dashboard` and `.txt` hrefs, absolute
`https://supabase.com/dashboard` URLs, the `getDashboardCtaHref` CTAs)
render `<a>`. Renderers whose href comes from data (nav, footer, plan
and add-on CTAs, product cards) branch on `isCrossZoneHref`, which reads
the zone list from `lib/rewrites.js`. In-zone links stay `<Link>` and
keep prefetching.
- **New literal links can't regress**: `www/no-cross-zone-link` errors
on a `next/link` `<Link>` whose literal or template href points at
another zone. It evaluates `lib/rewrites.js` as production, so `/docs`
counts in every environment.
- **Click tracking survives the full navigation**:
`sign_in_button_clicked`, `start_project_button_clicked` and
`www_pricing_plan_cta_clicked` now send with `keepalive`, like
`sign_in_submitted` already did, so an immediate page load can't cancel
them. The mobile nav Sign in and Start your project buttons used
`legacyBehavior`, which never called their `onClick`: PostHog has no
`Mobile Nav` location for either event in the last 30 days. Those clicks
report from this PR on.
- **Typecheck no longer crashes**: the functions page's default export
inferred a type through `RealtimeLogs`'s unexported `Props`, which makes
the native TypeScript compiler panic during `tsc --noEmit`. I exported
`Props`.

**Note:** the lint rule only sees literal hrefs. A new renderer whose
href comes from data needs its own `isCrossZoneHref` branch, and review
is the only check on that.

## To test
`/docs` is only rewritten on production and absolute
`https://supabase.com/...` links are cross-origin on a preview, so the
preview proves the relative non-docs cases (`/dashboard*`, `/library`,
the footer .txt files). `/docs/...` prefetches still appear on the
preview because it has no docs rewrite.

Tested on Vercel preview:
- [x] Open `/` with the network tab filtered to `_rsc` and scroll to the
footer: no requests for `/dashboard*`, `/library`, `/design-system`,
`/kb`, `/evals`, `/humans.txt`, `/lawyers.txt` or
`/.well-known/security.txt`, while in-zone ones such as `/pricing`,
`/features` and `/blog` still appear
- [x] Same check on `/pricing`, `/auth`, `/database`, `/storage`,
`/realtime`, `/edge-functions`, `/blog` and a blog post: no `_rsc`
requests to `/dashboard*`, `/library` or the footer .txt files
- [x] Open the Developers dropdown on desktop and the mobile menu at
390px: no new `_rsc` requests to `/dashboard*` or `/library`
- [x] Click header Docs, footer Humans.txt, the hero Start your project
button and the pricing Free plan button: each lands where it did before
(`/docs`, `/humans.txt` text, `https://supabase.com/dashboard/sign-up`,
`https://supabase.com/dashboard/new?plan=free`). Signed out, the Free
plan button lands on the dashboard sign-in with
`plan=free&returnTo=%2Fnew`
- [x] Click the hero Start your project button: the
`/platform/telemetry/event` POST with `start_project_button_clicked`
completes with a 2xx after the page starts navigating. 201 with the
navigation held; on the real navigation the event still reached staging
PostHog
- [x] At 390px, open the mobile menu and click Sign in: a
`/platform/telemetry/event` POST with `sign_in_button_clicked` and
`buttonLocation: "Mobile Nav"` fires. Start your project in the same
menu also sends `start_project_button_clicked` with `buttonLocation:
"Mobile Nav"`
- [ ] Signed in, load `/`: no `/dashboard/projects?_rsc=` request (not
run: the preview origin has no signed-in session)
- [x] Open the desktop Product dropdown and the Product section of the
390px mobile menu: Compute shows its Private Alpha badge and the other
products show none (checks the master merge into `MenuItem`)

After deploy, `/` and `/pricing` on supabase.com show no `_rsc` requests
to `/docs*`, `/dashboard*` or `/library`. After a full day, the share of
supabase.com 404s carrying `_rsc=` should drop from about 95% to under
10%, and `sign_in_button_clicked` and `start_project_button_clicked`
should start showing a `Mobile Nav` location in PostHog.

## Linear
- fixes GROWTH-1294
2026-10-05 15:17:04 -07:00
Anthony Lio dcf266c360 feat(docs): update search v2 ui (#51175) 2026-10-05 20:33:19 +00:00
Jeremias Menichelli 53ecbf9f2a chore: Add telemetry to search v2 user actions (#51146)
## Problem

We need to collect data from search v2 experiment usage.

## Solution

Add telemetry to search v2 modal being opened, closing, sending a query
and clicking a search v2 result.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. Open the preview link and add the search v2 flag query:
`?docs-search-v2=search-v2-active`
2. Trigger all actions mentioned above
3. Telemetry data should be sent on the network tab


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Documentation search activity is now recorded when the dialog opens
from the keyboard shortcut or search input, and when it closes. Search
submissions include the query and whether results were found; selected
results include their destination and the highlighted query. This adds
visibility into key search interactions without changing how search
results or highlighting work.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 13:22:22 -03:00
Joshen Lim 838fcaaa89 Joshenlim/fe 4509 fdw general UI consolidation and refactor (#51079)
## Context

Stacks on top of https://github.com/supabase/supabase/pull/51074

PR's just mainly refactoring, no visual differences:
- `CreateWrapperSheet` + `EditWrapperSheet` use the same UI components
for the foreign tables section
  - Can be consolidated into one reusable component
- `WrapperTableEditor` is still using `SidePanel` component
  - Can be swapped to use new `Sheet` component
- Refactor `WrapperTableEditor`'s layout a little - added separators for
clarity between sections
<img width="400" alt="image"
src="https://github.com/user-attachments/assets/b1983bf2-cff5-43eb-8b31-40a7abb65038"
/>
- Update `getCreateFDWSql` to just use the Foreign Data Wrapper's name
from `wrapperMeta` since its now standardized

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a shared foreign-table selector for wrapper setup and editing,
with options to view columns, add or edit table definitions, and remove
tables.
  * Updated the table editor to use a sheet layout with a fixed footer.
* **Bug Fixes**
* Wrapper creation now uses the wrapper’s configured name when creating
the server.
* Foreign-table targets display the table name when other target details
are unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 16:20:50 +08:00
Joshen Lim 521881a899 Joshenlim/fe 4480 fdw create wrapper to only init fdw once users to name the (#51074)
## Context

PR here refactors the way we manage Foreign Data Wrappers in the
dashboard (Under Project -> Integrations), as there's some DX problems
with the current behaviour.

Currently whenever a user creates a new wrapper, the dashboard is
creating both the Foreign Data Wrapper (`create foreign data
wrapper...`) + server (`create server ...`). The former is
**_redundant_** to create multiples of given that it just handles the
`handler` and `validator`, whereas what matters more is the server which
holds the connection credentials. Hence standard practice is usually one
Foreign Data Wrapper with multiple servers. (The former just needs to be
created once if not done yet)

This also led to some problems as well when users created their own
wrappers via SQL and tried to manage them through the dashboard GUI,
leading to us having to add some guard rails to prevent managing
wrappers sharing the same Foreign Data Wrapper
([ref](https://github.com/supabase/supabase/pull/50785))

## Changes involved
- When creating a wrapper, if the Foreign Data Wrapper has yet to be set
up for the wrapper type, the dashboard will initialize one and
subsequently use that same Foreign Data Wrapper for any new wrappers
- When creating / editing a wrapper, users will name the **server**
instead of the **wrapper**
<img width="500" alt="image"
src="https://github.com/user-attachments/assets/b3e61204-0e16-4599-84ac-af2aab5b93c2"
/>
- When deleting a wrapper, the clean up for vault secrets are now
deterministic by referencing the wrapper's server options
- RE backwards compatibility: Existing wrappers will _not_ be affected
by the changes here - they can be edited / deleted as per normal

## Unrelated fixes + UI refactors added
- Fix Iceberg Wrapper not showing the right form when adding new wrapper
- Adjust form layouts in side panel to be horizontal instead of vertical
(Follows Database -> Pipelines)
- Clean up to use newer UI components like `ButtonTooltip`
- Opt to hide Docs + Create CTA under `WrappersTab` if marketplace
feature preview is enabled (Since these actions are already in the
header, will be duplicates)
- Consolidate foreign tables configuration for create + edit wrapper
sheet into one component `ForeignTablesSelector`

## To test
- [ ] Verify that existing wrappers with their own Foreign Data Wrapper
can be edited correctly
- [ ] Verify that existing wrappers with their own Foreign Data Wrapper
can be deleted
- [ ] Verify that existing wrappers with shared Foreign Data Wrapper can
be edited correctly
- [ ] Verify that existing wrappers with shared Foreign Data Wrapper can
be deleted
- [ ] Verify that new wrappers can be created
- [ ] Verify that newly created wrappers can be edited correctly
- [ ] Verify that newly created wrappers can be deleted
2026-10-05 16:00:37 +08:00
Danny White ba82106697 chore(www + studio): remove expired Select 2026 promo banners (#51245)
## Problem

Supabase Select 2026 has finished. The promo banners already hide via
the scheduled expiry from #51006, but the campaign code, assets, and
wiring are still in the tree.

## Solution

Remove the Select 2026 sitewide promotion across www and Studio:

- Delete shared `Select26*` banner code, font, and tests from
`ui-patterns`
- Delete Studio `BannerSelect2026*` and its Banner Stack registration
- Unmount the www announcement banner and revert the State of Startups
spacing that only existed for it
- Drop the Select-only session-replay `data-band` allowlist entry and
lint ratchet baseline

Event go pages, blog posts, and other Select content are left alone. The
`Announcement` shell stays for the next campaign.

## Review instructions

1. Open the www homepage on the deploy preview. Confirm there is no
Select announcement bar above the nav.
2. Open `/state-of-startups` on the deploy preview. Confirm the hero
still looks correct with no extra top gap from the removed banner.
3. Open a hosted Studio dashboard page on the deploy preview. Confirm
the Banner Stack no longer shows a Select card.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)
2026-10-05 18:36:13 +11:00
Joshen Lim 94b8b06eb2 Clean up auto region selection experiment (#51121)
## Context

Just cleans up the experiment that was introduced
[here](https://github.com/supabase/supabase/issues/50851) - can clean up
feature flag in ConfigCat thereafter too

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Project Creation**
* Removed the “Best available” region option. Choose a specific region
or smart group when creating a project; the selected region name appears
in the selector.
  * Recommended badges remain visible on recommended regions.
* **Telemetry**
* Project creation events no longer include details about the removed
region option or the initial region recommendation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 12:13:11 +08:00
Francesco Sansalvadore edb8a2dc31 fix(www): hover bug on www menu (#51194)
## Problem

The website "freezes" after hovering the menu.

## Solution

No more freeze.
2026-10-02 18:14:16 +00:00
Francesco Sansalvadore 4617b6f4cb feat: compute landing page (#50899)
Compute landing page.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a Compute product page introducing ephemeral sandboxes and
always-on HTTP services, with information on workloads, security,
deployment, and common questions.
* Added a private-alpha waitlist form with submission confirmation and
error feedback.
* Added Compute links and a “Private Alpha” badge in product navigation
and the footer.
* Added an animated diagram illustrating Compute workloads and their
lifecycle.
* **Documentation**
* Added a Compute overview covering runtimes, scaling, security,
deployment, and availability.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-02 16:14:13 +02:00
Anthony Lio b13d6c2878 feat(chore): add a lint ratchet for shadcn rules (#51014)
## Problem

shadcn lint rules has been soft landed in #50676 and are now on as
warnings in every app, but nothing stops a PR from adding new violations

linear: FE-4473

## Solution

- moved the ratchet script and its tests from `apps/studio/scripts` to
`packages/eslint-config-supabase` so every app runs one copy
- added a shared rule list,
`packages/eslint-config-supabase/ratchet-rules.json` with the shadcn
rules
- www, docs, design-system, ui-library and learn get `lint-ratchet.yml`
with one job per changed app (triggered by the app, `packages/**` or the
lockfile) + a weekly `lint-ratchet-decrease.yml` (as for studio ratchet)
- package tests run in `eslint-config-supabase-tests.yml`

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. run `pnpm --filter ./apps/www run lint:ratchet`
2. add `p-[13px]` to a `className` in any www component and run it
again. it fails with `shadcn/no-arbitrary-values` and the file name with
`(+1)`
3. revert change
4. run `pnpm --filter eslint-config-supabase test` and see 6 tests pass
5. in ci, check `Ratchet studio lint checks` and the `ratchet (<app>)`
jobs for the apps this pr touches

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Developer Improvements**
* Expanded automated lint checks to cover additional apps and shared
package changes.
* Added checks for arbitrary Tailwind values, unknown classes, and raw
colors across supported apps.
* Added automated baseline updates that can open or update a pull
request when lint counts change.
* Added tests for the lint configuration and support for combining
multiple rule files.
* Updated Studio lint notifications to exclude Shadcn rules with
zero-baseline counts.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-02 14:13:59 +03:00
531431cd77 docs: document MCP cost confirmation via elicitations (#50017)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update for the MCP cost confirmation launch
([AI-1161](https://linear.app/supabase/issue/AI-1161/write-the-docs)).

## What is the current behavior?

The MCP server guide lists `get_cost` / `confirm_cost` but doesn't
describe the elicitation-based cost confirmation flow that
`@supabase/mcp-server-supabase` 0.12.0 introduces for `create_project`
and `create_branch` on form-capable clients.

## What is the new behavior?

- New **Cost confirmation** section in the MCP server guide: how the
elicitation flow works (accept / decline / expiry / rate-change
outcomes, all side-effect-free except accept), the zero-cost skip,
client support, and how to tell which cost flow a connection uses.
- New troubleshooting entry: "Cost confirmations do not appear in your
MCP client".
- Three `supa-mdx-lint` dictionary additions the new prose needs
(`elicitation(s)`, `dialogs`, `pauses`).

## Additional context

**Draft — hold until launch.** Merge gates before publishing:

1. The feature is enabled for hosted connections.
2. The client support table is re-verified against launch verification
results (there's a matching `{/* ... */}` reviewer note above the
table). Client support moves quickly; the table reflects verification as
of 2026-09-04.

Needs review:

- **Rate-change behavior follows the shipped code, not the spec docs**:
on any change to the computed cost between confirmation and creation
(including a decrease), the server reissues a fresh confirmation rather
than proceeding (`account-tools.ts` redemption path in supabase/mcp).
Flagging in case the intent was lower-or-equal proceeds.
- No exact confirmation expiry is stated because the TTL is
deployment-configured (`ttlSeconds`).
- Wording deliberately says "client-mediated" style confirmation and
avoids claiming a person approved each action, since clients can answer
elicitations via hooks.

Test plan: `supa-mdx-lint` clean on both files; Prettier (repo config)
clean. No runnable snippets, so no sandbox verification needed. Vercel
preview link will appear below.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added advanced options to hosted MCP connections for skipping selected
cost or destructive-SQL confirmations when supported. Available options
depend on connection scope, enabled features, and read-only settings.
* The configuration panel explains when skip selections are unavailable
or ignored by certain client configurations.

* **Documentation**
* Added guidance on cost and SQL confirmation prompts, Edge Function
secret entry, and troubleshooting missing prompts or unavailable secret
collection. This includes client requirements, fallback behavior, and
relevant security considerations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Barry Roodt <barry.roodt@supabase.io>
2026-10-02 08:58:34 +02:00
Jeremias Menichelli 99103b3571 feat: Add edge function and hooks for search V2 (#51103) 2026-09-30 18:12:07 -03:00
Artur Zakirov bd9a0ff4e6 feat(orioledb): rename orioledb from Public Alpha to Public Beta in dashboard (#50975)
## Problem

We need to rename orioledb in Dashboard.

## Solution

- Update Studio copy/badges referencing OrioleDB from "Public Alpha" to
"Public Beta" (project creation advanced config, restore-to-new-project,
PITR empty state)
- Remove the scheduled-backups block that hid backups for OrioleDB
projects — OrioleDB now has WAL-G scheduled backups in beta, so that
page should behave normally. PITR keeps its existing guard since PITR is
not yet supported for OrioleDB.
- Update the `useOrioleDb` telemetry property doc-comment to reflect the
beta status
- Update project-creation wizard test expectations/fixtures accordingly
(`release_channel: 'beta'`)

Marketing (`apps/www`) and docs (`apps/docs`) references to OrioleDB
alpha status are being updated separately.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Updates**
* OrioleDB is now labeled as being in public beta rather than public
alpha, and project creation selects the beta release channel.
* Restore-to-new-project and Point-in-Time Recovery notices clarify that
these features are unavailable for OrioleDB projects.
* OrioleDB projects now follow the standard eligibility checks and page
flow for scheduled backups.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:39:41 +02:00
Pamela Chia 9690efeb42 fix(vault): link to current dashboard route (#51058)
I updated first-party Vault links to open the current secrets route
directly. Wrapper credentials, extension metadata, and blog posts still
linked to the retired path and relied on a redirect.

## To test

On the preview:
- [x] Inspect a Wrapper credential's Vault link. Expect
`/integrations/vault/secrets` with a `search` query for that credential.
- [x] Open the inspected target URL. Expect Vault to show the matching
secret.
- [ ] Click a Wrapper credential's Vault link. Expect the filtered Vault
view.
- [ ] Open the pgsodium extension's Vault link and a Vault blog link.
Expect `/integrations/vault/secrets` without the retired route in the
address bar.

## Linear
- fixes GROWTH-1312


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Vault secrets links now direct you to the project’s Integrations page,
including links from wrapper metadata, blog articles, and the `pgsodium`
extension listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 12:54:28 +08:00
Danny White ed692f6905 feat(select): schedule livestream banners (#51006)
## Problem

The Select banners on www and Studio still promote attendance. They need
to keep serving the waitlist until the event, promote the livestream
during the requested window, and disappear after the event.

## Solution

Use a shared three-phase clock: existing promotion before 8:00am PT on 2
October, livestream promotion from 8:00am to 5:30pm PT, and no banner
afterwards. Both livestream CTAs lead to `select.supabase.com`, where
viewers can choose a stage. Separate dismissal keys let someone who
dismissed the earlier promotion see the livestream. Open pages set a
timer for the next boundary and recheck on visibility, focus, or page
restore.

| `www` |
| --- |
| <img width="736" height="136" alt="CleanShot 2026-09-29 at 16 27
38@2x"
src="https://github.com/user-attachments/assets/1281bcf0-ece4-41fc-99d2-1f9ab6e1b3f5"
/> |
| _Until Friday 8am PT_ |
| <img width="734" height="138" alt="CleanShot 2026-09-29 at 16 28
06@2x"
src="https://github.com/user-attachments/assets/05b8779a-9961-4886-ad7d-96ba31c8b4f7"
/> |
| _Friday 8am to 5:30pm PT_ |

| `studio` |
| --- |
| <img width="612" height="454" alt="CleanShot 2026-09-29 at 16 26
51@2x"
src="https://github.com/user-attachments/assets/0d9a8bbb-c636-41dc-aa76-381196c149c2"
/> |
| _Until Friday 8am PT_ |
| <img width="616" height="440" alt="CleanShot 2026-09-29 at 16 27
09@2x"
src="https://github.com/user-attachments/assets/458afdb9-6576-4699-9419-947ca5312bcd"
/> |
| _Friday 8am to 5:30pm PT_ |

## Review instructions

1. Open the [www
homepage](https://zone-www-dot-com-git-dnywh-select-2026-livestre-93dab1-supabase.vercel.app/)
and a [hosted Studio
dashboard](https://studio-staging-git-dnywh-select-2026-livestream-05b822-supabase.vercel.app/)
in separate tabs. If the Privacy Policy update card is in front in
Studio, close it (only) to reveal the Select banner.
2. In each tab's DevTools console, paste this helper:
   ```js
   window.selectRealNow = Date.now
   window.showSelectAt = (iso) => {
     Date.now = () => new Date(iso).getTime()
     window.dispatchEvent(new Event('focus'))
   }
   ```
3. Run `showSelectAt('2026-10-02T07:59:00-07:00')`: both banners keep
the existing “Apply to attend” CTA.
4. Run `showSelectAt('2026-10-02T08:00:00-07:00')`: www shows “Supabase
Select 2026” and “Watch the livestream”; Studio shows the same title,
the description “Keynote, main stage, and build stage, streamed all
day.” and “Watch livestream”. Both CTAs link to
`https://select.supabase.com/`.
5. Run `showSelectAt('2026-10-02T17:30:00-07:00')`: neither banner is
visible. Restore the clock with `Date.now = window.selectRealNow;
window.dispatchEvent(new Event('focus'))`.

The console clock override affects only the current tab and is lost on
reload.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- The Select 2026 banner switches from waitlist messaging to livestream
details and a “Watch livestream” link during the livestream period.
- Livestream banner dismissals are tracked separately from waitlist
banner dismissals.
- Promotion banners end at 5:30 p.m. Pacific on October 2, 2026, and
update when the promotion changes phase, including after returning to an
open tab.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:09:12 +10:00
Charis 0daafca2ca feat(studio): status page banner (incident / maintenance / upcoming) (#51044)
## Summary

* Adds a new global status banner (`StatusBanner`) driven by the
[incident.io](<http://incident.io>) status page data, showing at most
one of: an active incident, in-progress maintenance, or upcoming
maintenance, in that priority order.
* All three types are independently dismissible (persisted to a new
localStorage key, `status-banner-dismissed-keys`); dismissal hides the
banner for items still active, and a new incident reappears even if a
related item was previously dismissed.
* Only shows to users who are actually affected (based on their
projects' regions) or when region data is incomplete (fails open), and
is bypassed entirely by the existing emergency incident override.
* Behind the existing `incidentIoStatusPage` ConfigCat flag —
`AppBannerWrapper` renders this new banner instead of the legacy
`StatusPageBanner` only when the flag is on; default behavior is
unchanged.
* This is PR 5b in a stacked series for Linear
[FE-4057](https://linear.app/supabase/issue/FE-4057) — see that issue
for full design context.

## Test plan

* New unit tests (`StatusBanner.utils.test.ts`) covering
banner-selection priority, dismissal-key handling, and copy generation
* New MSW component test (`StatusBanner.test.tsx`) covering loading
state, dismiss-and-persist, and the emergency-override path
* `pnpm --filter studio run typecheck`, `lint:ratchet`, `pnpm knip
--workspace apps/studio`, `pnpm test:prettier`, and relevant vitest
suites all pass

🤖 Generated with [Claude Code](<https://claude.com/claude-code>)

Co-Authored-By: Claude
[noreply@anthropic.com](<mailto:noreply@anthropic.com>)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added status banners for relevant incidents and scheduled maintenance,
including incident details, maintenance timing, and links to the status
page.
* Banners can be dismissed, and dismissed items stay hidden while new
incidents or maintenance updates can still appear.
* Upcoming maintenance banners appear within the relevant lead time, and
maintenance timing is shown when available.
* Emergency overrides display a warning banner without a dismiss option.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 18:09:47 -04:00
Pamela ChiaandJoshen Lim 4a941518e3 feat(studio): track Explorer runs and saves (#51004)
I added outcome events for Explorer query runs and successful manual
notebook saves. Existing page visits and preview toggles do not show
whether users complete queries or persist notebooks.

**Changed:**
- **Query usage:** Accepted runs from query tabs and notebook cells emit
submitted and terminal outcome events with a shared run ID. Canceled
confirmations emit no run events.
- **Notebook adoption:** Successful manual saves emit created or updated
events. Recreated notebooks count as creations. Unsaved drafts and
failed saves emit neither.
- **Event metadata:** Explorer action events use `Explorer` as their
page title.

**Note:** Assistant-generated saves are outside this PR. Custom
properties omit SQL and notebook content. Page visits still carry the
browser title, which can include a notebook name.

## To test

Tested on the staging preview:
- [x] Run valid and invalid SQL from an Explorer query tab. Each run
emits one submitted event and one matching completed or failed event
with the same run ID.
- [x] Run database and Logs notebook query cells, then add a markdown
cell. The query cells emit matching event pairs; the markdown cell emits
no query event.
- [x] Save a new notebook, then edit and save it again. The successful
saves emit created and updated events.
- [x] Cancel a guarded query. It emits no query run event.
- [ ] Recreate a notebook deleted on the server after local edits. A
successful save emits created, not updated.
- [x] Inspect an Explorer action event request. Its page title is
`Explorer`; page visits still use the browser title.
- [ ] Force a notebook save failure. It should emit no save event. This
case was not tested manually.

## Linear
- fixes GROWTH-1298


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Analytics**
* Explorer query runs are tracked for database and log queries,
including whether they complete or fail.
* Query activity is associated with its location in Explorer, such as a
query tab or notebook cell.
  * Successful notebook saves are tracked as creations or updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-29 13:54:13 -07:00
Anthony Lio 8ebbfe3272 feat(chore): bump cn (#51016)
## Problem

currently using `cn` 0.2.5 makes `@shadcn/lint` lint run printed a
notice as it needs 0.3.2 or later

## Solution

- added `cn: ^0.4.0` to the pnpm catalog. `packages/ui` and `blocks/vue`
now use `catalog:` so they stay on the same version
- added `cn` to the root `devDependencies`
- runtime changes from 0.2.5 to 0.4.0

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. run `pnpm install`
2. run `pnpm --filter ui exec vitest run` and `pnpm --filter ui-patterns
exec vitest run` and see them pass
3. run `pnpm --filter @supabase/vue-blocks run typecheck` and see it
pass

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated package version management across the project to keep related
packages aligned. This maintenance change does not alter the app’s
features or behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 18:32:27 +03:00
Anthony Lio e7f0d3c04f fix(ui): popover component (#50657)
## What kind of change does this PR introduce?

fixture on the popover + command components

## What is the current behavior?

currently there is a misalignment in the command component <> searchbar
icon and items + the popover menu animation in is slightly scattered

## What is the new behavior?

- fixes icon alignment in command component
- updates popover animation in 

`command`
| state | preview |
| -------|------|
| before | <img width="881" height="542" alt="image"
src="https://github.com/user-attachments/assets/e38aa22f-5eea-4b08-8a24-254e26bf90fe"
/> |
| after | <img width="881" height="542" alt="image"
src="https://github.com/user-attachments/assets/85608e11-8415-4d47-945f-cc13772e4ad1"
/> |

`popover`
| state | preview |
| -------|------|
| before | <video
src="https://github.com/user-attachments/assets/cbb2da1a-6f73-4a8d-87d6-21e8b636c110"
/> |
| after | <video
src="https://github.com/user-attachments/assets/1b0832f5-e6ac-4e93-ae78-9e0aee31205c"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Style**
  - Adjusted command input spacing for improved visual alignment.
- Updated popover transitions with state-based fade and zoom animations,
and refined their visual origin.
  - Set a consistent size for the AI docs command icon.
- **New Features**
- Added an option to customize the command menu input wrapper’s styling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 18:17:45 +03:00
Manan Gupta 951a22183a feat: regenerate api types from production (#51019)
## Summary

- Regenerates `packages/api-types/types/{api-v2,platform}.d.ts` from the
live production OpenAPI specs (via the new `pnpm --filter=api-types run
codegen:prod`), picking up everything that's shipped to production since
the committed types were last regenerated.
- Notably includes `high_availability` on the `available-regions` and
`available-versions` project-creation pre-flight endpoints, which
unblocks the Studio-side wiring in #50902.
- Fixes one collateral typecheck break the regen surfaces: the invoice
schema's `prepaid_credits_applied_cents` field became required, and
`InvoicesSettings.test.tsx`'s mock invoice builder didn't set it.

## Description

`api-v1.d.ts` needed no changes — it was already in sync with
production. `api-v2.d.ts` and `platform.d.ts` pick up unrelated drift
that has landed on production independently of this change (a few new
fields/endpoints), verified against `pnpm api:verify-types` passing
clean and `pnpm typecheck` passing across the whole monorepo.

This PR is intentionally separate from #50902 (the Studio-side High
Availability pre-flight fix) so that PR's diff stays focused on the
actual feature work. #50902 will be rebased once this merges.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Updated the invoice test fixture to default prepaid credits applied to
zero.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: GuptaManan100 <guptamanan100@gmail.com>
2026-09-29 17:24:16 +05:30
Joshen Lim 9aae037dff Joshenlim/fe 4475 fdw update sql to run proper alter statements instead of (#50988)
## Context

Currently for FDWs under integrations, editing an FDW involves tearing
it down then re-creating it - which while conveniently works has a lot
of problems like:
- Blast radius is way bigger than the edit
  - Everything is recreated, including vault secrets
- Silent drops grants/comments/ownership
- Cascades on dependent objects
- Views or functions built on top of foreign tables would get dropped
along with it

Changes in this PR hence updates `getUpdateFDWSql` to diff the current
wrapper state against the form state and generate targeted `ALTER`
statements for only what actually changed

## To test
- [ ] Verify that updating an existing wrapper still works as expected

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Wrapper changes can be saved in place, including server options,
encrypted values, foreign tables, and column definitions.
* Input fields can display placeholder text, and missing server-option
values display their defaults.

* **Improvements**
* Saving is unavailable until encrypted values are ready; a waiting
message appears while they load.
* The edit panel closes after a successful save. Confirmation text
explains that table or column changes may affect dependent
functionality.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 19:47:57 +08:00
kemal.earth 864cca6cda fix(design-system): update border radius for menu items (#50973)
## Problem

Border radiuses for inner items of dropdowns, menus etc. didn't keep up
with recent changes.

## Solution

Adds a token/variable to help keep this consistent across our apps and
components. One caveat is this modifies shadcn components, so I'm open
to alternative ways of doing this.

| Before | After |
|--------|--------|
| <img width="293" height="206" alt="Screenshot 2026-09-28 at 12 00 27"
src="https://github.com/user-attachments/assets/cd5e0708-0223-43ac-9893-a33ce5acd1ca"
/> | <img width="335" height="231" alt="Screenshot 2026-09-28 at 12 00
41"
src="https://github.com/user-attachments/assets/dc993b09-1410-4596-ae8f-4e78e6739fa6"
/> |



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Standardized corner rounding across command items, context menus,
dropdown menus, menubars, select options, and multi-select options.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 09:50:15 +01:00
Joshen Lim 93a262d185 Check region selection for project creation (#51012)
## Context

Previously added telemetry for `selectedRegionOption` and
`selectedRegionOptionType`
[here](https://github.com/supabase/supabase/issues/50851) if the best
available region option is available for users

Opting to extend this telemetry (still just for Free plan orgs)
irregardless if best available region was selected and include
`initialRecommendedRegion`

Main thing to understand is what regions users are spinning projects up
in outside of the recommended option

## To test
- [ ] Verify the telemetry network request after creating projects
- [ ] Non-free plan: Telemetry request doesn't have
`initialRecommendedRegion` in the payload
- [ ] Free plan: Telemetry request has `initialRecommendedRegion` in the
payload
- Sends correctly if best available region option is available (default
behaviour for staging)
- Sends correctly if best available region option is NOT available
(override with dev tools the configcat flag)
2026-09-29 16:34:03 +08:00
Dongha 2c5b0a5ca0 fix(ui): fall back to writeText when clipboard.write fails (#50777)
## Problem

Safari can expose `navigator.clipboard.write()` while rejecting it with
`NotAllowedError`.
Studio's shared clipboard helper treated that rejection as a terminal
failure, so Copy buttons showed "Unable to copy to clipboard" even
though `writeText()` worked.

Fixes #50769

## Solution

- Fall back to `navigator.clipboard.writeText()` when the rich clipboard
write fails.
- Preserve the existing success callback and error behavior.
- Add regression coverage for fallback success, total failure, and
callback exceptions.

## Verification

- `pnpm exec vitest run lib/helpers.test.ts --pool=threads`
- `pnpm test:prettier`
- `pnpm --filter ui run typecheck`
- `pnpm --filter studio run typecheck`
- `pnpm --filter studio run lint`
- `npm run build -- --filter=studio`
- Rendered browser verification with `clipboard.write()` forced to
reject; `writeText()` received the expected payload and the Copy button
showed success.

## Review instructions

1. Review the fallback logic in
`packages/ui/src/lib/utils/clipboard.ts`.
2. Review the regression tests in `apps/studio/lib/helpers.test.ts`.
3. Confirm no generated or vendored files are changed.

- [x] I have read CONTRIBUTING.md
- [x] This PR does not change documentation content.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Copying now falls back to standard clipboard copying when rich
clipboard access is unavailable or denied.
* An error message is shown only when both clipboard methods fail.
Successful rich clipboard writes do not trigger a fallback if a
follow-up action fails.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 11:13:40 +10:00
3f205627e0 feat(library): redesign the site around the block catalog (#50372)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature — the visual redesign itself.

Part 5 of 6 in a stack that splits the library redesign into reviewable
pieces. The four PRs beneath it carry the build, content and Markdown
work; what's left here is layout, navigation and styling.

## What is the current behavior?

The library is laid out like a documentation site: a sidebar tree of
framework folders, a homepage that lists links, and a guide page that
opens with prose. That shape suits reference material, but the library's
job is to help someone find a block and install it — and the sidebar is
the only way to discover one.

## What is the new behavior?

The homepage is the catalog itself — blocks grouped by what they do
(authentication, database, storage, realtime, messaging, AI,
foundations) rather than by framework, each with a preview of what it
renders, filterable by category.

Navigation moves into a site header whose Explore menu opens the same
categories, so the catalog is reachable from any page and the per-page
sidebar tree is gone.

A guide opens with what the reader came for: the block's name, the
install command, and a preview pane with tabs — the running component
and its files — before any prose. The file tree that used to sit
mid-page under "Folder structure" is one of those tabs. Every guide also
offers a copy of the agent prompt that points at its Markdown.

Getting-started pages get the same treatment: the quickstart is now a
framework-tabbed walkthrough rather than a wall of setup links.

## Additional context

`BlockOverviewTabs` renders Preview and Files here. #50369, stacked on
top of this one, adds the third "What's added" tab — it is the only part
of the redesign that depends on the new resource analyzer, which is why
it sits above this PR rather than below it.

Also removes what the redesign orphaned: the table-of-contents component
and its `remark` / `mdast-util-toc` dependencies, and the sidebar nav
and command-item configuration the new header replaced.

The block source changes are typography only — auth card titles move
from `text-2xl` to `font-medium text-lg tracking-normal` — which is what
regenerates the auth registry artifacts.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a redesigned Supabase Library catalog with categorized blocks,
framework-aware navigation, previews, file views, and installation
actions.
* Added framework-specific quickstart guides for Next.js, React, Vue,
Nuxt, React Router, and TanStack Start.
* Added copy-to-clipboard prompts, “Open in v0” actions, starter
templates, and richer visual previews.

* **Improvements**
* Updated documentation layouts, FAQ content, typography, navigation,
accessibility, and responsive behavior.
* Improved mobile navigation, framework selection, and standardized
block installation guidance.
* Refined authentication and social-login block presentation with more
consistent heading styles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-29 10:45:23 +10:00
Joshen Lim 54c2a2788f Joshenlim/fe 4474 add command to generate types off api production (#50960)
## Context
Adds a pnpm command `api:codegen:prod` to generate API types off prod to
work with the `verify-production-types` GHA. Just uses the existing
logic in `verify-production-types.mjs` to fetch the OpenAPI specs, and
writes it into the local API types files

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* API types can now be generated from the production API specifications
when a local API environment is unavailable.
* **Bug Fixes**
* Resending invitations and updating project-scoped roles now handle
roles without a base role ID more reliably.
* **Documentation**
* Updated guidance clarifies that API or schema changes must be deployed
before relying on updated types.
* Production is the source of truth for merge checks. Type verification
should pass after deployment, and production-generated types are
expected to pass verification.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 01:34:34 +08:00
Francesco Sansalvadore 8e20712475 chore(design system): clean up compute icon (#50971)
Cleaned up the `compute` icon which wasn't aligned and perfectly
isometric.

| Before           | After              |
| -------------- | ------ |
| <img width="240" height="209" alt="Screenshot 2026-09-28 at 12 56 10"
src="https://github.com/user-attachments/assets/ffe0232f-5933-4310-886f-2de8caa53712"
/> | <img width="269" height="208" alt="Screenshot 2026-09-28 at 12 56
13"
src="https://github.com/user-attachments/assets/0e4ab8ab-6818-473b-a786-42ca3aae32e4"
/> |
2026-09-28 15:32:37 +02:00
Francesco Sansalvadore 99cfaf1f01 chore(design system): uniform elastic icon style (#50974)
The `elastic` icon wasn't following the same styling of other icons in
our design system.
This PR uniforms it.

| Before           | After              |
| -------------- | ------ |
| <img width="121" height="81" alt="Screenshot 2026-09-28 at 13 46 47"
src="https://github.com/user-attachments/assets/f22f53b0-4b13-4d7a-b6f3-ce92664782de"
/> | <img width="104" height="90" alt="Screenshot 2026-09-28 at 13 47
18"
src="https://github.com/user-attachments/assets/39edc6f3-614a-4c12-8dd6-31ba953507be"
/> |

Link to preview icon:
https://design-system-git-chore-elastic-icon-supabase.vercel.app/design-system/docs/icons
2026-09-28 13:56:51 +02:00
Gildas GarciaandDanny White 93a032c90d Design System: Improve icon button example accessibility (#50783)
## Problem

The Icon only button example lacks some accessibility features:
- no `aria-label` for screen readers
- no tooltip for sighted users

## Solution

Add both with comments explaining the reasons

## Review instructions

See
https://design-system-imfc534k0-supabase.vercel.app/design-system/docs/components/button#only-an-icon

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified icon-only button guidance: use a tooltip for sighted users
and an accessible label for screen readers. When the tooltip repeats the
button’s label, prevent it from being announced twice.
* Added guidance to use a square button container and increase the tap
target by 8px. Updated the icon-button example to demonstrate a “View
logs” tooltip and accessible labeling.
* **New Features**
* Icon-only buttons now use a compact square layout with an expanded tap
target.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-28 09:56:54 +02:00
Sean GeogheganandJoshen Lim f2ff4ec0e9 fix(realtime): display banner when realtime has been suspended by admin (#50497)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

If Realtime's admin_suspended_at is set we display a banner.

## What is the current behavior?

REAL-1095

## What is the new behavior?

<img width="1160" height="442" alt="Screenshot 2026-09-17 at 12 06
30 pm"
src="https://github.com/user-attachments/assets/f5abe900-a163-48c9-ab55-945fc62df0d1"
/>


## Additional context

Depends on https://github.com/supabase/platform/pull/38476


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

- **New Features**
- Added a notice to Realtime settings when the service is suspended,
with instructions to contact support.
- **Bug Fixes**
- Improved invitation resending and role updates for roles without a
linked base role.
- **Tests**
- Added coverage to verify the suspension notice appears only when
applicable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-28 15:17:24 +08:00
c75d87d5ef Add /go/ask-supabase-select Select 2026 recap page (#50889)
## Problem

Attendees at Supabase Select 2026 need a quick, linkable page that
recaps what shipped and points them to the right next step, whether
that's a theme blog post, a solution page, or the full features
directory.

## Solution

Added `/go/ask-supabase-select` using the go-page system (`GoPageInput`
config, no bespoke React):

- **Hero**: "Build in an instant. Scale to infinity." with a "Read the
Recap" CTA
- **Our announcements**: three theme cards (Build anything, Scale
without limits, Operate with confidence), each with a blurb sourced from
the drafted Select 2026 theme blog posts and a CTA to that post
- **Explore Supabase for your team**: a 2x2 grid of solution cards (AI
Builders, Startups, Developers, Enterprise), each fully clickable to its
solutions page
- **Supabase features**: closing CTA out to `/features`

Also adds `whitespace-pre-line` support to the shared go-page
`HeroSection` component so a hero description can wrap onto a second
line when the config string includes `\n`. This is additive and doesn't
change rendering for existing `/go` pages that don't use a line break.

Note: the "Read the Build/Scale/Operate Blog" and "Read the Recap" CTAs
currently point to `/docs` as a placeholder — the real blog posts are
still in progress and will be swapped in once published.

## Review instructions

1. Run `pnpm --filter www dev` and visit
`http://localhost:3000/go/ask-supabase-select`.
2. Confirm the three announcement cards, the four solution cards
(hover/click highlight, no button chrome), and the closing features CTA
all render and link correctly.

## Checklist

- [x] I have read CONTRIBUTING.md

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added the “Ask Supabase” landing page, with product resources,
documentation links, team-solution cards, and a blog post marked as
coming soon.
* **Improvements**
* Hero descriptions now preserve line breaks for clearer text
presentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 16:53:30 +10:00
Danny White b10511052d fix(ui): share raised styling across dropdown triggers (#50830)
## Problem

Select, combobox and empty multi-select triggers use a flat border
treatment, while the default Button has a raised surface and shadow.
This makes dropdown controls look inconsistent when closed.

## Solution

Share the existing Button shadow variables and raised surface classes
with the select trigger CVA. SelectTrigger and ComboboxTrigger keep
their own layout, focus, and disabled behaviour.

The multi-select shares the raised surface when empty and keeps a sunk
field surface for selected chips. Static size classes keep its empty and
single-row selected states at the same height; wrapped badges can still
grow. The caret stays aligned as values are selected. Select, Combobox
and Multi-select share Button's size-specific corner radii. Button's
existing styling is preserved.

| Before | After |
| --- | --- |
| <img width="518" height="180" alt="CleanShot 2026-09-24 at 13 36
32@2x"
src="https://github.com/user-attachments/assets/3822e51f-b1c5-46a2-b268-0bf08a03ae06"
/> | <img width="534" height="224" alt="CleanShot 2026-09-24 at 13 36
41@2x"
src="https://github.com/user-attachments/assets/e553c973-3d21-4228-ae6f-d3c098d051d3"
/> |
| <img width="638" height="148" alt="CleanShot 2026-09-24 at 15 08
01@2x"
src="https://github.com/user-attachments/assets/6d0c3dfe-3392-4b76-ae61-b6aa7a09583d"
/> | <img width="658" height="148" alt="CleanShot 2026-09-24 at 15 08
17@2x"
src="https://github.com/user-attachments/assets/184c50c3-b951-410e-89d5-3b1c2ee8f3b8"
/> |
| <img width="482" height="162" alt="CleanShot 2026-09-24 at 15 07
22@2x"
src="https://github.com/user-attachments/assets/a088d832-d0a9-45c5-a272-9c84cc601d1d"
/> | <img width="490" height="168" alt="CleanShot 2026-09-24 at 14 59
52@2x"
src="https://github.com/user-attachments/assets/4df0ca29-53d8-4926-80db-1cafb705faad"
/> |

## Review instructions

1. Open the design system
[Select](https://design-system-git-dnywh-dropdown-trigger-surface-supabase.vercel.app/design-system/docs/components/select),
[Combobox](https://design-system-git-dnywh-dropdown-trigger-surface-supabase.vercel.app/design-system/docs/components/combobox)
and
[Multi-select](https://design-system-git-dnywh-dropdown-trigger-surface-supabase.vercel.app/design-system/docs/fragments/multi-select)
examples.
2. Compare the closed surfaces and corner radii with a default Button,
then check hover, focus and open states.
3. Select one or two multi-select items. Check that a single row remains
the same height as the empty control, the caret stays aligned and the
chip field remains distinct. Add enough items to check wrapping.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **Style**
* Default buttons display a raised surface with a subtle shadow and
size-appropriate rounded corners.
* Select and combobox triggers share a raised, card-like appearance,
with consistent shadows and rounded corners at small sizes. Invalid
select triggers display a border.
* Empty multi-select controls use a raised surface, while controls with
selected values use a field-style surface.
* Small and tiny multi-select controls have updated spacing and sizing
in empty and selected states.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 14:26:47 +10:00
Danny White 9a03f3cd9c fix(studio): show keyboard focus on filter bar (#50827)
## Problem

- Filter fields could not be re-entered with Tab, and remove buttons
were previously skipped.
- Earlier focus rings flashed or crowded controls. Segmented filters and
design system examples also had uneven layout.

## Solution

- Tab now reaches each filter’s property, operator, value and remove
button. Editable fields use the caret; read-only values and remove
buttons keep a visible focus cue.
- Refined spacing and sizing. The segmented highlight is inset and
clears when focus enters a control. Both variants and the focus guidance
are documented on the [design system
page](https://design-system-git-dnywh-fix-filter-bar-focus-supabase.vercel.app/design-system/docs/fragments/filter-bar).

|After |
| --- |
| <img width="462" height="126" alt="CleanShot 2026-09-24 at 15 04
23@2x"
src="https://github.com/user-attachments/assets/2ee8bee2-f4fa-40f4-ada5-67bfe32384e7"
/> |
| <img width="362" height="96" alt="CleanShot 2026-09-24 at 15 04 47@2x"
src="https://github.com/user-attachments/assets/9f42054a-f432-493d-b417-f10892676c96"
/> |

## Review instructions

The easiest way to test this is to open Table Editor on both
production/staging and on this PR’s [deploy
preview](https://studio-staging-git-dnywh-fix-filter-bar-focus-supabase.vercel.app/).
Try navigating by keyboard (tab, left/right arrow) within the Filter
Bar. Compare the two.

- In Studio’s Table Editor or the [design system
example](https://design-system-git-dnywh-fix-filter-bar-focus-supabase.vercel.app/design-system/docs/fragments/filter-bar),
add a filter. Tab through its property, operator, value and remove
button, then Shift+Tab back into editing.
- Check that the segmented and pill examples fill their preview width
and that focus cues do not collide with neighbouring controls.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **New Features**
* Added a pill appearance for the Filter Bar, with usage guidance and
interactive examples for pill and segmented presentations.
* **Accessibility**
* Improved keyboard navigation through filter controls, including
removing a filter with the keyboard.
* Clarified that an editable text field’s insertion caret can serve as
its visible focus indicator; read-only fields and controls without a
caret still need another visible indicator.
* **Style**
  * Refined Filter Bar spacing and focus styling across appearances.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-28 10:13:53 +10:00
Anthony Lio e3febf3b63 feat(lint): add shadcn lint warnings (#50676)
## Problem

six apps had no shared lint checks for invalid tailwind classes,
off-scale values, and raw colors.

## Solution

add @shadcn/lint warnings with narrow exceptions for existing theme
colors and artwork. fix several invalid classes. the existing lint
command reports findings without blocking prs on the current warning
count.

## Review instructions

1. check the shared rules and app-specific exceptions.
2. run `pnpm --filter design-system lint` and confirm it reports shadcn
warnings without errors.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved vertical alignment of checkbox labels and supporting text in
dialogs, settings, and examples.
* Corrected alignment of organization member details and the color
styling of deprecated chart text.
* Standardized spacing in the date and time editor without changing its
appearance or behavior.

* **Developer Experience**
* Updated linting and UI configuration across several apps to support
consistent style checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-25 17:50:50 +03:00
Jordi Enric f0952fdef8 fix(studio): delete only the selected foreign server FE-4462 (#50785)
## Problem

The dashboard lists one row per foreign server, but deleting a row
dropped its foreign data wrapper with CASCADE. When multiple servers
shared a wrapper, deleting one removed all of them.

## Fix

Drop the selected server and its foreign tables. Remove the underlying
wrapper and Vault secret only when no servers still use it. Edits to a
shared wrapper now stop before making changes because the existing edit
flow recreates the underlying wrapper.

## How to test

1. Configure two BigQuery foreign servers that use the same foreign data
wrapper. Delete one from the dashboard.
2. Confirm the other server and its foreign tables still exist and work.
3. Delete the remaining server. Confirm the foreign data wrapper and its
Vault secret are removed.
4. Attempt to edit one of two servers sharing a wrapper. Confirm the
edit fails without removing either server.

Focused pg-meta tests and typecheck pass.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Shared connections are identified in the integrations list, with
guidance for editing them in the SQL Editor. Editing is disabled when a
wrapper is shared, with an explanation shown.
* Deleting a connection removes its foreign tables and removes the
wrapper and Vault secret only when no other connection uses them.
* **Bug Fixes**
* Connection deletion verifies that the selected server still belongs to
the wrapper and reports failures using connection-focused wording.
* Attempts to edit a wrapper used by another connection are blocked with
a clear explanation.
* Connection deletion and confirmation messages now consistently refer
to deleting a connection.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-25 16:49:01 +02:00
51a167d910 feat(www): partners landing page (#47874)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a redesigned Partners page with partnership options, benefits,
application steps, FAQs, integration resources, and featured partners.
- Added an on-page partner application form with questions tailored to
the selected partnership type.
- Added a confirmation message with next steps and a link to the OAuth
integration guide.
- **Bug Fixes**
- Updated partner application links to open the form on the Partners
page.
  - Added support for checkbox-group fields in forms.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
Co-authored-by: Alex Hall <alex.hall@supabase.io>
Co-authored-by: Dion Zeneli <101271736+Dionysos288@users.noreply.github.com>
2026-09-25 15:53:32 +02:00
kemal.earthandGildas Garcia 0e6fff6760 feat(design-system): segmented controls (#50738)
## Problem

We don't have any one defined way of displaying segmented controls. This
PR looks at unifying and using underlying primtives to put something
together. Open to comment.

## Solution

Improves upon the shadcn toggle group, which has a specific use case.

## Review instructions

Run the design system and find "Segmented Controls" in the Fragment
Components. Test
[here](https://design-system-git-feat-button-group-component-draft-supabase.vercel.app/design-system/docs/components/toggle-group#segmented).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **New Features**
* Added segmented toggle groups with default, text, outline, and primary
tones.
* Single-select groups display a sliding selection indicator;
multi-select groups highlight selected items individually.
* Groups can keep the selected option active; deselection is enabled by
default.
  * Added examples for tone variations and a status filter.
* **Documentation**
* Updated segmented-control guidance and props tables, including usage
recommendations, accessibility labeling, and filter options.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-09-25 11:26:46 +01:00
Saxon Fletcher d0135231fb chore(studio): improve assistant feed performance (#50888)
## Problem

Assistant conversations with multiple query and Edge Function blocks
repeatedly render expensive content while streaming. Scrolling past the
feed boundary can also move the surrounding layout.

## Solution

Memoize unchanged messages, blocks, and code highlighting; batch
streaming UI updates; and skip off-screen query layout while keeping
block state mounted. Preserve streamed status updates and contain
scrolling in the message viewport. The changes are shared by Next and
TanStack.

## Review instructions

1. Compare the base branch and this branch using the same saved
conversation containing 10–20 query, result/chart, and Edge Function
blocks. Keep the browser, viewport, and conversation identical.
2. In Chrome DevTools, record Performance with 4× CPU throttling while
streaming a follow-up, typing in the composer, and scrolling through the
feed. Compare scripting/layout time and long tasks. React DevTools
Profiler should show unchanged completed blocks avoiding renders during
subsequent text updates.
3. Scroll away from query blocks and return. Confirm results, display
settings, selections, and controls retain their state. Run a read-only
query such as `select 1` and check its results still update.
4. Confirm “Thinking…” finishes, Stop retains the latest streamed text,
and approval/skip, copy, edit, and branch actions still work. Repeated
scrolling at the feed boundary must leave the outer layout/composer
stationary; jump-to-latest and following new messages should still work.
5. Repeat in both runtimes: `STUDIO_FRAMEWORK=next pnpm dev:studio` and
`STUDIO_FRAMEWORK=tanstack pnpm dev:studio`. Also check the assistant
sidebar, which shares the feed.

## Validation

- 170 assistant/Explorer tests and one shared CodeBlock test passed;
formatting and Studio lint passed (two existing warnings).
- Browser checks covered both route entry points, viewport
state/geometry, and scroll behavior.
- Review fixes: 23 focused tests, lint, formatting, and full Studio
typechecking passed. Full production builds were not verified.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] No docs content changed; docs authoring skills are not applicable.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Performance**
* Improved responsiveness in the AI assistant by reducing unnecessary
updates while messages stream and conversation history is displayed.
* Optimized query previews, message rendering, and code blocks to keep
the interface smoother during use.
* **Bug Fixes**
* Improved handling of message edits and deletions during generation,
and preserved the latest response when generation is stopped.
* Improved conversation scrolling behavior while keeping conversation
content and scroll areas working as expected.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-25 18:09:34 +10:00
Alaister YoungandAlaister Young a47397d5fe fix(common): restore narrow Feature type (#50850)
The platform API now types `ProfileResponse.disabled_features` as
`string[]` (since #48981), which collapsed the `Feature` union to plain
`string`, so `isFeatureEnabled` accepted any string and typos went
uncaught.

**Changed:**
- `Feature` is now a local `RuntimeFeature` union (the profile-driven
flags) plus the keys of `enabled-features.json`, instead of deriving
from the API type
- `useIsFeatureEnabled` casts the merged runtime disabled list to
`Feature[]`, since the profile field is now `string[]`

The runtime feature list duplicates what the backend knows. Once the
enum is restored in the API spec, `Feature` can go back to deriving from
the generated type.

## To test

- `pnpm typecheck` passes
- Passing a bogus string to `useIsFeatureEnabled` / `isFeatureEnabled`
is now a type error
- Nothing behavioral changes, so a quick sanity check that the sidebar /
billing / org settings still render is enough


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **No user-facing changes**
* This update does not change the app’s visible features or behavior. It
includes internal typing adjustments only.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
2026-09-25 17:21:38 +10:00
+8 e273d2b818 chore(studio): move Explorer SQL Editor link to sidebar footer (#50829)
## What

- Moves the temporary "Switch to SQL Editor" button out of the Explorer
sidebar header into a footer section ("Looking for snippets?") with a
short explanation and an **Open SQL Editor** button.
- Replaces the header slot with a menu for the Explorer startup
preference (**Start page** / **SQL query**), instead of linking out to
account preferences.

## How to test

1. Enable the Explorer feature preview and open
`/project/<ref>/explorer`.
2. **Header menu:** click the ⋮ button next to the Explorer title. Pick
**SQL query**, then check that **Explorer startup** on `/account/me`
shows the same value (and vice versa).
3. **Footer:** click **Open SQL Editor**. You should land in the SQL
Editor with the **Back to Explorer** button in its title bar.
4. Open **Notebooks** or **Chats** in the sidebar and check that the
menu and footer are hidden there, like the old button was.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Choose whether the Explorer opens to the Start page or SQL query from
the Explorer preferences menu. Your selection is saved and retained when
you reopen the menu.
  * Access the SQL Editor from the Explorer’s sidebar footer.
* Explorer preferences are available from the Explorer navigation
header.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Tyler <dshukertjr@gmail.com>
Co-authored-by: Nik Richers <nrichers@gmail.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Jordi Enric <37541088+jordienr@users.noreply.github.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Co-authored-by: Katerina Skroumpelou <mandarini@users.noreply.github.com>
Co-authored-by: Franek <franek@ferly.co.uk>
Co-authored-by: Franek Richardson <franek@supabase.io>
Co-authored-by: Michał Olszewski <35968924+charconstpointer@users.noreply.github.com>
Co-authored-by: Steven Eubank <47563310+smeubank@users.noreply.github.com>
Co-authored-by: Anthony Lio <lionnet.ant@gmail.com>
Co-authored-by: Joey Lei <6957385+leizerbeam@users.noreply.github.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
Co-authored-by: Samir Ketema <6003000+samirketema@users.noreply.github.com>
Co-authored-by: K-Dog (Kevin) <k.grueneberg1994@gmail.com>
2026-09-25 14:31:46 +08:00