mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
77bf0a4ec9c19b2ea260e17e91b4308d87152e87
37053
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
77bf0a4ec9 |
chore: more dead code cleanup (#47312)
## Problem There's still more unused code in the repository which slows down everything: - checkouts - tooling - probably builds (not sure how good turbopack is at handling this) ## Solution - remove old unused code - remove more recent code after checking git history to ensure it's not unfinished/ongoing work <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Removed several outdated UI components and helper utilities to streamline the app. * Cleaned up unused analytics, database, and observability hooks and queries. * **Refactor** * Simplified data table, unified logs, and assistant panel internals by removing legacy display and navigation pieces. * **Bug Fixes** * Reduced the chance of showing stale or inconsistent status, chart, and metric views by eliminating obsolete display paths. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b1b29ad011 |
Fix: improve accessibility for icon buttons (#47214)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix (accessibility improvement) ## What is the current behavior? Icon-only buttons do not have explicit accessible names for screen readers. ## What is the new behavior? All icon-only buttons now have explicit accessible names using visually hidden text (sr-only), ensuring proper screen reader support. ## Additional context Tooltip text is preserved or added for visual users. No visual changes were introduced. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Added hover tooltips across the database editor and SQL editor, including “More options” menus, table filter controls, and the “Create a new query” action. * **Accessibility** * Improved button accessibility by adding/expanding `aria-label`s for Intellisense, favorites (add/remove), and “Prettify SQL.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1392cc0952 |
Temporarily disable network bans and network restrictions on HA (#47325)
Temporarily disables network bans and network restrictions on HA projects until they are supported. Requires https://github.com/supabase/supabase/pull/47322 to be merged first. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added High Availability-aware empty and notice states for database settings screens. * Introduced project-aware handling so unavailable actions are clearly indicated in High Availability projects. * Added support for filtering out unsupported schemas when High Availability is enabled. * **Bug Fixes** * Disabled network restriction and banned IP actions when they are not available, with clearer tooltip messaging. * Updated action states so access controls and unban options consistently reflect project permissions and High Availability status. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Alaister Young <alaister@users.noreply.github.com> |
||
|
|
1ec86503fa |
fix: make mfa lockout risk clear in dashboard (#47330)
## Problem Lots of users are getting locked out of their accounts, with no way to get back in. The current warning after setting up an MFA is not visible enough: <img width="1484" height="836" alt="image" src="https://github.com/user-attachments/assets/944093f0-b912-4eb9-9955-a012be1a5248" /> ## Solution First part of the solution is to make the warning more visible: <img width="1612" height="930" alt="image" src="https://github.com/user-attachments/assets/06d334dc-ee6a-4bf3-a8b3-3d4282a275b7" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated the two-factor authentication setup warning to use a clearer warning style and horizontal layout. * Improved the guidance shown when only one authenticator app is configured, making the message easier to read. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3ffc446824 |
chore: delete unused bucket picker dialogs (#47331)
## Problem Cleaning up dead code. Those two dialogs are not used. Other components in their directories are though. ## Solution Remove them <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Removed two storage picker dialog components from the app. * This may affect how bucket and file selection screens are presented in the Studio interface. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7b5e976c9f |
chore: manage CodeRabbit config in .coderabbit.yaml (#47328)
Sets up `.coderabbit.yaml` so our CodeRabbit configuration lives in the repo — version-controlled, visible to contributors, and reviewable — instead of split between the dashboard and nowhere. Three parts: 1. **Skills as code guidelines** — wires our `.claude/skills/` into reviews. 2. **Path instructions** — migrates the telemetry rules out of the CodeRabbit dashboard UI. 3. **Path filters** — skips machine-generated files so reviews focus on hand-written code. Supersedes #47327 (closed). ## 1. Skills as review guidelines CodeRabbit's code-guidelines feature reads guideline files and, by default, **directory-scopes** them — a file applies only to its own folder and below. Our skills live in `.claude/skills/` (no code), so they'd never reach `apps/studio`. The `applyTo` field on `filePatterns` decouples *where the guideline lives* from *which code it governs*, so we point CodeRabbit straight at the skills: | Skills | Apply to | | --- | --- | | `studio-best-practices`, `studio-ui-patterns`, `vercel-composition-patterns`, `studio-queries`, `studio-error-handling` | `apps/studio/**/*.{ts,tsx}` | | `studio-testing`, `studio-mock-api-tests` | `apps/studio/**/*.test.{ts,tsx}` | | `studio-e2e-tests` | `e2e/studio/**/*.spec.ts` | Skills stay the **single source of truth** — consumed directly, no duplicated/generated copy. ## 2. Path instructions (migrated from the dashboard) Moved the two existing telemetry path instructions into the file so they're version-controlled: - `packages/common/telemetry-constants.ts` — event-naming enforcement (`[object]_[verb]` snake_case, approved verb list, camelCase props, `useSendEventMutation` flag, JSDoc + union-type checks). - `apps/studio/components/**/*.tsx` — only suggest PostHog tracking for growth-relevant interactions, not passive/UI-only ones. ## 3. Path filters (skip generated files) Excludes machine-generated / vendored paths from review (mirrors `.prettierignore`): API types, generated DB types, route trees, design-system / icons / ui-library registries, generated icon components, and the lockfile. Keeps reviews focused on hand-written code and preserves OSS rate-limit budget on large codegen diffs. ## Notes - Cost is \$0 — CodeRabbit Pro (incl. code guidelines) is free for public repos. - `vitest` skill left out (generic framework reference, not our conventions). - The `telemetry-standards` skill is intentionally **not** also wired as a guideline — the migrated path instruction above is the curated version; wiring both would double up. ## To test - PR touching `apps/studio/**/*.tsx` → CodeRabbit cites Studio conventions - PR touching `e2e/studio/**/*.spec.ts` → cites E2E conventions - PR editing `telemetry-constants.ts` with a bad verb / non-camelCase prop → flagged - PR that regenerates e.g. `packages/api-types/types/**` → those files not reviewed - Confirm Studio guidelines don't bleed into unrelated areas (docs, www) ## Follow-ups (not here) - Extend `filePatterns` to other scopes: `dev-toolbar-review` → `packages/dev-tools/**` - Optionally skip bot PRs via `auto_review.ignore_title_keywords` - Move any remaining dashboard settings into this file as we find them <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added/updated automated review configuration to disable org-level inheritance and enable automatic issue enrichment. * Excluded generated/vendor artifacts (e.g., lockfiles, API/type outputs, generated docs/www, UI registry/icon sources) from review. * Added path-scoped review guidance for telemetry event naming/verification and tighter review focus for production UI event-tracking suggestions. * Extended internal coding guidelines to apply local skill docs across Studio source, unit/component tests, and Studio Playwright E2E specs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
791fa6fa1b |
Temporarily disable backups and realtime on HA (#47323)
Temporarily disables backups/pitr and realtime on HA projects until they are supported. Requires https://github.com/supabase/supabase/pull/47322 to be merged first. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added reusable High Availability empty-state and notice components for consistent messaging across the studio. * High Availability projects now show a dedicated blocked state in Realtime and PITR views. * Updated schema handling so certain schemas are hidden when High Availability is enabled. * **Bug Fixes** * Improved loading behavior on the PITR page by waiting for project, backup, and entitlement checks. * Refined upgrade messaging to better match the user’s current access level. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Alaister Young <alaister@users.noreply.github.com> |
||
|
|
01902156ce |
Temporarily disable replication on HA (#47324)
Temporarily disables replication on HA projects until they are supported. Requires https://github.com/supabase/supabase/pull/47322 to be merged first. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added reusable High Availability UI components for an empty-state message and an availability notice. * Introduced shared High Availability helpers to determine availability status and adjust schema lists accordingly. * Updated the replication page to use the new High Availability flow with a dedicated empty state when enabled. * **Bug Fixes** * Improved High Availability detection consistency, including safer fallback behavior when project data is missing or null. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Alaister Young <alaister@users.noreply.github.com> |
||
|
|
143769afac |
feat(studio): shared High Availability disabled hook and UI primitives (#47322)
Add generic building blocks for blocking features on High Availability projects: - useHighAvailability hook: HA state only (isHighAvailability, isPending) - HighAvailabilityDisabledEmptyState (full-page empty state) - HighAvailabilityDisabledSectionNotice (in-section admonition) The components carry a generic default title/description; consuming pages pass their own copy via props. HA state is read from the project's high_availability flag (same source as the High Availability badge on the project home page). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added clearer messaging for features that aren’t available in High Availability projects. * Introduced a standard High Availability status check to help the app adapt what it shows. * **Bug Fixes** * Hid non-applicable schema options when High Availability is enabled, reducing confusion in selection lists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
072add9945 |
[FE-3682] feat(studio): warn on Vercel preview/dev env var sync (#47298)
Clarifies what the Vercel environment-variable sync toggles actually do and guards the risky path. Enabling Preview/Development sync pushes this project's **production** credentials into those Vercel environments — previously this wasn't clear, so users expected isolated preview deployments and were surprised when previews hit production. Addresses **FE-3682** (support case SU-385292). **Changed:** - Reworded the sync section: a single heading + intro that makes clear the toggles sync this project's production credentials to the selected Vercel environments, and that most projects only need `production`. - Recommend Branching for preview isolation, linking to the in-dashboard branches page (`/project/<ref>/branches`) instead of docs. - Switched the toggle rows to `FormItemLayout` (`flex-row-reverse`) for consistent layout/spacing; descriptions now clarify these are the **Vercel** environments. **Added:** - Inline `Admonition` warning when Preview/Development sync is enabled, with branching-aware copy (a "Not recommended with Branching" variant when Branching is on, explaining production creds are used until a branch finishes provisioning). - Confirmation dialog before saving whenever Preview/Development sync is on, naming exactly which credentials get exposed (project ref, API URL, anon + service role keys, DB connection strings). Production-only saves skip the dialog. ## Screenshots <img width="707" height="630" alt="Screenshot 2026-06-25 at 6 43 23 PM" src="https://github.com/user-attachments/assets/30d45527-5a48-44c2-bdb7-2e576f5e4c7d" /> **Default state (production only)** <img width="704" height="786" alt="Screenshot 2026-06-25 at 6 43 46 PM" src="https://github.com/user-attachments/assets/75a12f65-99d0-4aad-9360-a7a6e6c91ca1" /> **Preview + Development enabled — inline warning (no Branching)** <img width="535" height="373" alt="Screenshot 2026-06-25 at 6 44 18 PM" src="https://github.com/user-attachments/assets/29d75804-fa93-402b-8cee-1faedd0ac9c7" /> **Confirmation dialog (no Branching)** <img width="705" height="824" alt="Screenshot 2026-06-25 at 6 48 09 PM" src="https://github.com/user-attachments/assets/c3f7bf97-7c6e-4be4-9a5b-90d422b03f81" /> **Inline warning — Branching enabled** <img width="530" height="415" alt="Screenshot 2026-06-25 at 6 48 20 PM" src="https://github.com/user-attachments/assets/a5ede69e-6186-488e-bf1e-49007b231201" /> **Confirmation dialog — Branching enabled** ## To test - Open a project's **Integrations → Vercel** settings with a connected Vercel project (the project-scoped connection form). - Toggle **Preview** and/or **Development** on → inline warning appears; toggle both off → it disappears. - On a project with **Branching enabled**, confirm the warning shows the "Not recommended with Branching" variant. - Click **Save** with Preview/Dev on → confirmation dialog appears naming the credentials. **Cancel** aborts (no save), **Sync credentials** saves. - Save with **only Production** on → no dialog, saves directly. - Confirm the **Branching** links navigate to `/project/<ref>/branches`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a confirmation step before syncing Preview or Development environment variables. * Improved the sync settings UI with clearer descriptions and a warning message when these environments are enabled. * Made the sync flow aware of project branching status, with guidance that adapts to the project setup. * **Bug Fixes** * Improved the save flow so successful updates now reset the form, close the dialog, and show a success message consistently. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
f6afd8b2e4 |
Use CodeEditor in AIEditor (#47297)
## Context More clean up / housekeeping - to use `CodeEditor` in `AIEditor` and remove duplicated logic <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Expanded supported editor file types, including CSS, CSV, and JavaScript (with improved syntax highlighting). * The updated editor experience now provides a readily available “run query” action. * **UI Improvements** * Tightened editor panel spacing and adjusted padding for a cleaner layout. * **Bug Fixes** * Improved file-to-language detection so files open with the correct syntax highlighting more consistently. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5cb81123ae |
refactor(studio): move SQL editor save trigger into a scheduler + provider (5/9) (#47316)
## What
PR 5 of a stacked refactor. Moves *when to save* out of a module-load
`subscribe` and into an injectable **scheduler** armed by a headless
**provider**, splits the save queue, and adds an unsaved-close warning.
### Scheduler (`sql-editor-save-scheduler.ts`)
`createSaveScheduler({ state, saveMechanism, notify, getSaveMode })`
owns the save *policy*:
- **auto** mode drains the dirty snippet queue as edits land; **manual**
mode (the seam for a future opt-in; defaults to `auto`) leaves snippets
queued until `requestSave`. Folder saves always drain.
- `start()` returns an unsubscribe; `requestSave(id)` is the
explicit-save entry.
### Provider (`sql-editor-save-coordinator.tsx`)
Headless `SqlEditorSaveCoordinatorProvider` instantiates the mechanism
(invalidation via the **React Query client from context**, not the
global `getQueryClient`) + scheduler, `start()`s it in an effect
(start/stop with the provider), and exposes `requestSave` via
`useSqlEditorSaveCoordinator()`. Mounted in `ProjectContext` (under the
app's QueryClientProvider). Cmd+S and the SavingIndicator Retry now go
through `requestSave`.
### Queue split
`needsSaving` (snippets) and `pendingFolderSaves` (folders) are separate
queues, drained independently — the old snippet-vs-folder `if/else` is
gone.
### Unsaved-close warning
A `beforeunload` guard triggers the browser's native "Leave site?"
prompt while any snippet's `status !== 'saved'` (failed / in-flight /
never-saved).
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Improved SQL editor saving with a centralized save flow, including
automatic/manual save handling and immediate “Save Query” requests.
* Added unsaved-change detection so the app can warn before closing or
reloading when edits are still pending.
* **Bug Fixes**
* Retry actions now use the updated save flow for more reliable
re-saving.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
f2f346dfde |
feat(docs): add page documenting free project pausing behavior (#47279)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the new behavior? Adds a page to Platform > Project & Account Management subsection to covers project pausing behavior for the Free plan. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a new “Project Pausing” guide link under **Platform → Project & Account Management**. * Published a new guide explaining Free Plan automatic project pausing, the 7-day inactivity determination, the warning/confirmation email flow, how to prevent pausing via activity, restoration within 90 days, and how to avoid future pauses by upgrading. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> |
||
|
|
e9888de2c0 |
Updated Supabase Pipelines blog post images (#47314)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? OG and thumb image update ## What is the current behavior? Old image: "Supabase ETL" ## What is the new behavior? Refreshed images with "Supabase Pipelines" ## Additional context Add any other context or screenshots. |
||
|
|
968fa3f052 |
chore: remove old Input component (#47259)
## Problem Every inputs and textarea have been migrated to the new shadcn components. This `Input` is no longer needed ## Solution - Delete it - Clean up the `defaultTheme` accordingly <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Breaking Changes** * Removed the built-in Input component from the UI library, including its attached TextArea export. * Removed input styling support from the default theme (standard/error variants and related icon/action/textarea spacing). * Cleared the Input module styles, so prior textarea action UI styling is no longer available. * Removed the Reports filtering UI in Studio (including the popover component and the associated report-filter hook), which may affect report filtering screens. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
235e56e0c7 |
Updated brand-assets.zip (#47310)
Added full white and black logos in .png and .svg formats to brand-assets.zip linked at https://supabase.com/brand-assets ## I have read the CONTRIBUTING.md file. YES ## What kind of change does this PR introduce? Asset update ## What is the current behavior? The brand-assets.zip downloadable on supabase.com/brand-assets contains the previous set of brand logos. ## What is the new behavior? Updated brand-assets.zip with the latest brand assets, including full white and black logo variants in .png and .svg (DEBR-337). ## Additional context File replaced at apps/www/public/brand-assets.zip. Served statically — no code changes required. |
||
|
|
d5bceb8db8 |
feat(studio): route Logs Explorer to OTEL endpoint via flag DEBUG-145 (#47265)
## Problem The Logs Explorer (SQL editor) queries the BigQuery-backed `logs.all` endpoint and exposed a manual "OTEL endpoint" toggle behind a separate flag. ## Fix - Drive the explorer endpoint purely from the `otelLegacyLogs` flag: on -> `logs.all.otel`, off -> `logs.all`. - Remove the manual toggle from `LogsQueryPanel` (and its `showChToggleInLogExplorer` gate). ## Dependencies None. Standalone, behind `otelLegacyLogs` (off by default), so no user-facing change. Part of DEBUG-145 (split from #47087). Note: PR for the deterministic BigQuery->ClickHouse rewrite + banner builds on top of this one. ## How to test - Enable `otelLegacyLogs`, open `/project/[ref]/logs/explorer`, confirm queries hit the OTEL endpoint and run. Toggle off, confirm BigQuery path unchanged. Confirm the old manual OTEL switch is gone. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Simplified the Logs Explorer experience by removing the OTEL endpoint toggle from query settings. * OTEL behavior now follows the configured feature flag, driving the editor’s initial placeholder/query shape. * On first load, the editor automatically switches to the OTEL placeholder only if the content is still the untouched default (not after user navigation or custom edits). <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
d46a9c43fd |
feat(Auth/EmailTemplates): Add SiteURL variable for notifications (#46393)
This will make email templates more consistent and may be merged after https://github.com/supabase/auth/pull/2532 is deployed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Authentication notification emails now include access to site URL references. This enhancement applies to multiple notification types: password change alerts, email change confirmations, phone number change notifications, identity linking and unlinking events, and multi-factor authentication enrollment and unenrollment notifications. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46393?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Chris Stockton <chris.stockton@supabase.io> |
||
|
|
0038f303f2 |
Track is initialized in feature preview context (#47309)
## Context Noticed that while default opted into unified logs, if you refresh while on the page, you'll get redirected back to the old logs URL (logs/explorer) Happening due to a inconsistent tracking of loading states for feature flags and feature previews. Just need to track whether the feature previews have been initialized <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved the loading behavior for unified logs preview so it only finishes loading after preview settings are fully initialized. * Added a more reliable initialization state to better reflect when feature-based defaults are ready. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
16526bd6bf |
refactor(studio): extract SQL editor save mechanism + model folder lifecycle (4/9) (#47276)
## What
PR 4 of a stacked refactor of the SQL editor snippet/folder state. It
pulls the persistence logic out of the store into an injectable
mechanism, and replaces the folder `'new-folder'` id sentinel with an
explicit lifecycle — plus a concurrency bug fix that surfaced along the
way.
### Save mechanism (`sql-editor-save.ts`)
`createSaveMechanism({ state, upsertContent, createSQLSnippetFolder,
updateSQLSnippetFolder, invalidate, notify, debounceMs })` → `{
saveSnippet, createFolder, updateFolder }`. The store's subscribe now
dispatches to it; *when* to save still lives in the subscribe (the
scheduler/provider move is PR 5). Per-id debounce cache lives in the
factory closure (no module-global leak).
- **`saveSnippet`** reads the live store snippet, guards
`isLoadedSnippet` so a content-less snippet can **never PUT an empty
body** (directly unit-tested), then builds the payload + drives status
transitions + gated invalidation.
- **`toast` is injected** as a `Notifier` (new generic DI contract in
`lib/notifier.ts`) — the mechanism no longer imports sonner.
- **create vs rename are two named-arg functions**, not an `isNew`
branch; rollback is deterministic per operation instead of matching on
`error.message` text.
- **caught errors are `unknown`**, narrowed via the existing
`getErrorMessage` util with a generic fallback — no `any`.
### Folder lifecycle (replaces the `NEW_FOLDER_ID` sentinel)
- **`FolderStatus`** enum (`new_editing | new_saving | editing | saving
| idle`) collapses the persistence and progress axes into one enum —
same pattern as `SnippetStatus` — with `isNewFolder` / `isFolderEditing`
/ `isFolderSaving` predicates. Tagging a folder as new/persisted is now
an explicit field, not an id convention.
- New placeholders get a **unique local id** (`crypto.randomUUID`);
`NEW_FOLDER_ID` is deleted, which also lifts the accidental
one-unsaved-folder-at-a-time limit.
### Bug fix: folder-rename rollback race
The shared `lastUpdatedFolderName` field let two in-flight renames
clobber each other's rollback target (and a shared `finally` could wipe
it). Replaced by a **per-folder `previousName`** on
`StateSnippetFolder`, so concurrent renames of different folders are
isolated. A new test runs two failing renames concurrently and asserts
each restores its own previous name.
## Tests
`sql-editor-save.test.ts` (mechanism — fakes + fake timers, incl.
content-less no-PUT and concurrent-rename isolation) and
folder-lifecycle predicate tests. `pnpm --filter studio typecheck`
clean; 82 state/sql-editor unit tests pass.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Improved SQL editor folder handling with clearer create, rename, and
save states.
* Added a more consistent notification flow for successful and failed
save actions.
* **Bug Fixes**
* Improved rollback handling when folder renames fail, helping restore
the previous name reliably.
* Updated save behavior to better protect against duplicate or
out-of-order updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
7007a8e5e8 |
fix(studio): raise body size limit for saving SQL snippets (#47032)
## What kind of change does this PR introduce? Bug fix — closes #45060. ## What is the current behavior? Saving a large SQL snippet from the SQL Editor fails when the content exceeds ~1 MB. The content API route (`PUT /platform/projects/{ref}/content`) relies on Next.js's default API body-parser limit of `1mb`, so large snippets — for example a multi-thousand-line RPC — are rejected with a `413 Payload Too Large` before the handler runs, and the snippet can't be saved. ## What is the new behavior? The route now sets an explicit body size limit of `5mb`, matching the limit already used by the AI SQL endpoint (`pages/api/ai/sql/generate-v4.ts`). Large SQL snippets save successfully, and the value is consistent with existing SQL-handling routes in the app. ```ts export const config = { api: { bodyParser: { sizeLimit: '5mb', }, }, } ``` ## Additional context - Only the content route's `PUT` handler accepts the snippet body; the sibling `item/[id].ts` route doesn't take a content body, so no change is needed there. - Supersedes the stale #45101 (no activity in ~8 weeks); this version documents the rationale and aligns the limit with the existing precedent in the codebase. --- - [x] I have read the [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/studio/CONTRIBUTING.md) guidelines. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed an issue preventing users from uploading or processing large content, such as SQL snippets, which would previously result in rejection errors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ccf84da968 |
Ensure that pathname in unified logs is solely server side filtered (#47307)
## Context Filtering on pathname in unified logs shows no data despite the network request returning some data Happening due to missing `filterFn` on pathname in `Columns.tsx` (should just return true so that the react table doesn't bother with client side filtering, since filtering is done on the server side) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Updated log table filter handling for several always-visible columns, with no change to the displayed data or user experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2bac064adf |
Joshen/fe 3697 progressively default opt in to unified logs (#47296)
## Context We're progressively opting in users to use the new Unified Logs UI 🙂🙏 ## Changes involved - [ ] Removed flag for controlling visibility of unified logs feature preview - [ ] Added flag for controlling default opt in behaviour of unified logs - [ ] Small tweak to Unified Logs banner is default opted in (Just show "New" and more info CTA) - Disabling, then enabling again will thereafter show the existing "Go back to old logs CTA" <img width="290" height="166" alt="image" src="https://github.com/user-attachments/assets/a2c46ce1-63c3-490c-bc7d-fc1254982dbe" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Unified Logs preview now derives default opt-in state from a new default-opt-in flag and exposes `isDefaultOptIn`. * **Bug Fixes** * Removed eligibility-based gating so the “Beta” badge and Unified Logs banner render consistently across logs screens. * Unified Logs banner was refactored to handle enable/disable and navigation internally, while remaining shown unconditionally. * **Tests** * Updated mocks and assertions to reflect the revised preview/banner enablement and dismissal logic. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
0a797ef4ea |
feat(studio): add creation funnel telemetry (#47291)
## Summary Adds frontend funnel telemetry to the organization-creation and project-creation flows in Studio, so each is measurable as a funnel (form exposed → completed) entirely from frontend events. Feeds the KPI 3 FE Benchmark Friction dashboard. Org creation had zero frontend funnel events before this (only a backend event that fires across every surface), and project creation had no clean form-view impression. ## Changes - Define `organization_creation_form_exposed`, `organization_creation_completed`, and `project_creation_form_exposed` in the telemetry constants. - Fire `organization_creation_form_exposed` when the new-org form renders, gated on the profile resolving so pre-auth redirects are not counted. Fire `organization_creation_completed` from the create success callback, covering both the free and the paid pending-payment-intent paths, attaching the new org slug as the organization group. - Fire `project_creation_form_exposed` once the org and the create-project permission have resolved, so it anchors on the form being visible rather than the route loading. Project completion reuses the existing client-side success event, so no duplicate completion event was added. ## Notes I chose exposed → completed over exposed → submitted. The org slug only exists after the create API resolves, so the completion event is the only org-funnel event that can carry the organization group; a submit-time event cannot, which would break org-level segmentation. A pageview is not a sufficient exposure anchor either: pageview capture is off, and the manual pageview fires on route change before the form is interactive (pre-auth redirect, async permission load, the no-org redirect). The `completed` verb follows the repo's approved-verb list (`.claude/skills/telemetry-standards`); the repo previously migrated `branch_merge_succeeded` to `branch_merge_completed` for the same reason. ## Testing Tested on the preview deploy: - [x] `/dashboard/new` while signed in → `organization_creation_form_exposed` fires once. - [x] Create a free org → `organization_creation_completed` fires with the organization group set. - [x] `/dashboard/new/[slug]` with create permission → `project_creation_form_exposed` fires once with `surface=main` and the organization group. - [x] No event re-fires on re-render or tab refocus. Post-deploy: confirm in PostHog prod (project 34344) via HogQL that each event fires with the expected properties and the organization / project group set. ## Linear - fixes FE-3690 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added improved tracking for organization and project creation flows, including when forms are shown and when organization creation completes. * Captures creation metadata to support better reporting on onboarding and setup progress. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2d0bcd4714 |
feat(telemetry): classify funnel creation errors (#47293)
## Summary The KPI-3 friction dashboard needs to know *why* users hit errors on the signup, project-creation, and org-creation funnels, not just that they did. The existing `dashboard_error_created` event already fires for these paths (10% sampled, with `$pathname`), but carries no reason: ~98.5% of events have no `errorType` and no property carries an error message. This adds PII-safe classification computed client-side from a controlled vocabulary, so raw error text never leaves the browser. Validation errors (previously invisible, since they are inline form errors that never raise a toast) are now captured on invalid submit. ## Changes - Extend `dashboard_error_created` with `origin`, `errorCategory`, `errorReason`, `errorCode`, and a `form` source value - Add a pure, unit-tested classifier (`funnel-errors.ts`) and a 10%-sampled tracking hook (`use-track-funnel-error.ts`); the classifier maps errors to stable slugs and emits only slugs + HTTP status, never raw message text - Classify signup errors (API failures + validation) in `SignUpForm` - Classify project-creation errors (API failures, OrioleDB guard, validation) in the new-project wizard - Classify org-creation errors (API failures, payment/card declines, confirm-subscription, validation) in `NewOrgForm` ## Testing 13 unit tests cover every classifier branch (validation / api / network / payment, status-code handling, message-pattern matching, and fallbacks). To verify on the Vercel preview (events are 10% sampled; set the sample rate to 1 locally to observe each fire): - Signup with a weak but non-empty password: `origin=signup, source=form, errorCategory=validation, errorReason=password_invalid` - Signup with an already-registered email: `origin=signup, source=toast, errorCategory=api, errorReason=email_already_registered` - New project with an empty name: `origin=project_creation, source=form, errorReason=project_name_invalid` - New org with an empty name: `origin=org_creation, source=form, errorReason=org_name_missing` - New org with a declined test card: `origin=org_creation, errorCategory=payment` PII: raw `error.message` is never sent; only controlled slugs and HTTP status. Dashboard consumers must filter `origin IS NOT NULL` so these do not collide with the generic toast events the global tracker still emits. ## Linear - fixes FE-3691 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added improved, categorized telemetry for signup, project creation, and organization creation errors, including payment, subscription-change, and validation failures. * Extended dashboard error events with optional structured diagnostics (origin, category, reason, and optional error code) and support for form-origin reporting. * **Bug Fixes** * Improved project-creation handling to record a validation telemetry event when an Oriole image is unavailable. * Ensured payment-related and subscription-change failures are captured consistently alongside existing user toasts. * **Tests** * Added unit tests covering API/network/validation/Stripe error classification and reason mapping. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e0ba04caf4 |
feat(studio): migrate per-service log pages to OTEL endpoint behind a flag DEBUG-145 (#47264)
## Problem The legacy per-service log pages (postgres, auth, api, edge functions, storage, realtime, cron, etc.) and the single-log detail panel query the BigQuery-backed `logs.all` analytics endpoint. We are moving these reads onto the OTEL ClickHouse endpoint (`logs.all.otel`). ## Fix - Add `Logs.utils.otel.ts`: ClickHouse query builders (rows/count/chart/single) + row mappers that target the single `logs` table keyed by `source`, reading fields from the `log_attributes` map and aliasing columns to the leaf names the renderers expect. - Parameterize `buildWhereClauses` / `genWhereStatement` in `Logs.utils.ts` so the OTEL builders reuse the shared nested AND/OR filter grouping. Defaults keep the BigQuery behavior unchanged. - Gate `useLogsPreview` (rows, count, chart) and `useSingleLog` (detail) on the new `otelLegacyLogs` flag. BigQuery stays the default when the flag is off. - Extract the OTEL timestamp parser into `parseOtelTimestamp` (`otel-inspection.utils.ts`) and reuse it in `unified-logs-infinite-query.ts` (replaces an inline copy of the same logic; no behavior change). ## Dependencies None. Standalone, safe to merge on its own. Behind `otelLegacyLogs` (off by default), so no user-facing change. Part of DEBUG-145 (split from #47087). ## How to test - In staging, go to Legacy Logs. - All logs pages should work the same as before. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added OTEL-backed logs support for preview, count, chart, and single-log details when enabled. * **Bug Fixes** * Improved timestamp parsing/normalization for OTEL data to ensure correct display and pagination. * Enhanced filtering behavior, including safer handling of unknown filter keys and invalid values across OTEL queries. * Improved single-log result shaping to preserve expected API/database metadata in OTEL mode. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
bce47daeea |
docs: Only build reference docs if feature is enabled (#47273)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reference documentation generation now only includes feature-enabled SDK pages, so published docs better match what’s available. * Legacy SDK reference pages are now shown selectively based on enabled feature flags. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f34aa108d5 |
chore: dead code cleanup (#47294)
## Problem There's still more unused code in the repository which slows down everything: - checkouts - tooling - probably builds (not sure how good turbopack is at handling this) ## Solution - remove old unused code - remove more recent code after checking git history to ensure it's not unfinished/ongoing work <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Removed several unused interface, onboarding, and helper components from the studio app. * Cleaned up outdated branching, integrations, query performance, support, and table/grid UI elements. * Removed a few unused utility hooks and key-mapping logic. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
afe405962e |
Joshen/fe 3698 observability overview links to logs should use unified logs (#47295)
## Context Found some links pointing to the old logs pages. Should point to unified logs if unified logs have been enabled Also deprecates the old `ServiceStatus` file that's no longer used <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated observability “logs” links to open the correct view when unified logs are enabled, including service-specific filtering. * Fixed navigation from log views to correctly preserve query strings. * Refreshed project service status log links and health indicators to stay consistent with the latest unified logs behavior. * **Refactor** * Consolidated service status UI and related logic into the project home experience, replacing the prior shared implementation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8e2ce64c69 |
Add Burhan A to humans.txt (#47277)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Bug fix, feature, docs update, ... ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the site’s credits/team listing to include an additional team member name. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6946ec2b2d |
build(studio): Next-compat shims (stack 2/6, from #46424) (#47110)
**Stack 2/6** of the TanStack Start migration (#46424). Stacked on **#47107** (S1) — review that first; this PR's diff is just the compat shims. > [!NOTE] > Purely additive. Next never imports these files — under TanStack they're wired in via Vite aliases (`next/*` → `@/compat/next/*`). No routes consume them yet (that begins in stack 3). ## What's in this PR `apps/studio/compat/next/*` — drop-in shims so the existing pages-router code runs unchanged under TanStack Start: - `link`, `router`, `navigation`, `head`, `image`, `legacy/image`, `script`, `dynamic`, `server`, `_router-events` — React/runtime shims over `@tanstack/react-router`. - `api.ts` — `toWebHandler`, which adapts a pages-router API handler `(req, res)` into a TanStack server-route Web `fetch` handler. ## Verification On top of S1: `studio` typecheck ✓, lint (0 errors) ✓. Next build is unaffected (nothing imports these under tsc). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added broad Next.js compatibility support for routing, links, dynamic imports, images, scripts, head metadata, navigation hooks, server responses, and API handlers. * Improved handling of redirects, pathname/search params, base paths, and event callbacks for smoother app behavior. * **Tests** * Added coverage for URL resolution and dynamic route interpolation to verify Next-style routing behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
1059b726ce |
use Admonition instead of deprecated NoticeBar (#47262)
## Problem The `NoticeBar` component is flagged as deprecated and should be replaced by `Admonition` ## Solution - Refactor `NoticeBar` usages to `Admonition` (no visual changes detected) - Delete `NoticeBar` You can see one easily in _Project Settings/Compute and Disks_ and opening the _Advanced disk settings_ collapsible section <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Updated disk management alerts and guidance to use a newer, more consistent notification style. * Improved visibility of messages for pending disk changes, permission limits, AWS availability, and advanced disk requirements. * Refreshed the compute-size upgrade prompt with the same updated alert styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ef148b6504 |
fix(studio): org MFA enforcement toggle visibility and UX (DEPR-606) (#47285)
## What kind of change does this PR introduce? Bug fix. Resolves DEPR-606. ## What is the current behavior? On org Security settings, the MFA enforcement switch could appear on without a green track. Users without personal MFA saw a disabled toggle with a tooltip. ## What is the new behavior? - Switch checked state renders correctly (removed tooltip trigger from the switch). - Users who need personal MFA first see an admonition with a link to account security instead of a disabled toggle. I felt this was a better user experience and more straightforward than the alternative: fighting the TooltipTrigger’s `data-state` conflict with the Switch’s checked state. | Before | After | | --- | --- | | <img width="1024" height="563" alt="Security Organization Settings Toolshed Supabase-4413F7B1-C7DC-4958-8C6F-ADEFDE4F310C" src="https://github.com/user-attachments/assets/8c71b0d8-db49-4af5-874b-5372df03379d" /> | <img width="1024" height="563" alt="Security Organization Settings Toolshed Supabase-ADD5BC82-B433-4EA0-A6BB-874703150663" src="https://github.com/user-attachments/assets/3c6d3545-fd58-426b-afaf-edd8f7ac4789" /> | | <img width="1024" height="563" alt="Security Organization Settings Toolshed Supabase-F57ED4AA-5A56-4F6A-8F35-569CAC26AFA2" src="https://github.com/user-attachments/assets/2bc49f34-7819-49fa-ac32-7e59678041fd" /> | <img width="1024" height="563" alt="Security Organization Settings Toolshed Supabase-AA795D85-1C17-4C08-9ED1-BBF08C28F2B4" src="https://github.com/user-attachments/assets/db1822b0-17fc-42df-bdec-0935e46ab5ff" /> | | <img width="1024" height="563" alt="Security Organization Settings Toolshed Supabase-8D8A196F-FA27-4FD3-BC52-DB933E61D59A" src="https://github.com/user-attachments/assets/bae30a9e-eda9-4a97-845c-0c4751f03a05" /> | <img width="1024" height="563" alt="Security Organization Settings Toolshed Supabase-5BD4F063-B402-4E03-ACE4-254BB28C232C" src="https://github.com/user-attachments/assets/0a3c4d6b-2981-47e9-9679-56bfcd7faf5d" /> | ## Additional context Test on `/org/<slug>/security` in light mode with and without personal MFA enabled. Or just hardcode the ternaries to see the various states on local. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added clearer guidance for organization security settings when MFA must first be enabled on a personal account. * Improved loading behavior while member data is fetched. * **Bug Fixes** * Prevented the MFA enforcement form from showing until personal MFA requirements are met. * Refined the MFA toggle disabled logic to apply only when appropriate. * **UI Improvements** * Replaced the MFA tooltip with an in-page notice. * Updated the primary action button label from “Save changes” to “Save.” <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
9f7d300354 |
Check flags loaded before fetching region data (#47289)
## Context
Realised that we were calling both `useDefaultRegionQuery` and
`useOrganizationAvailableRegionsQuery` in the new project page.
`smartRegionEnabled` defaults to `false` at the beginning while the
flags are still being loaded, to this calls `useDefaultRegionQuery`. But
once the flags are loaded and `smartRegionEnabled` becomes `true`, then
the other hook is called
## Changes involved
- Checks that the flags are loaded first before calling either hooks to
prevent unnecessarily triggering both
- Adjust `defaultRegion` to remove hardcode
- Check smart region first, then default back to default specific region
- Renamed variables to be clearer:
- `autoDefaultRegion` (check based on location)
- `fixedDefaultRegion` (hardcoded in repo)
- Update `useEffect` on `regionError` to only reset the region value if
the default value is not undefined
- Also just a tiny nit to re-arrange to group the `useEffects` together
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Region selection now waits for feature flags to load before fetching
default and “smart” region options, preventing premature or incorrect
region choices.
* New project setup now updates the database region and smart
recommendations more consistently, with improved fallback behavior when
region lookup fails.
* AWS Nimbus default region is now environment-aware: non-prod uses
Southeast Asia, while prod uses East US.
* Default privilege settings now stay in sync more reliably during
setup, updating only when appropriate.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
772b3bb36e |
Adjust connection logs toggle for unified logs, flip it to true by default (#47258)
## Context For unified logs, postgres connection logs are being filtered out by default previously from this [PR](https://github.com/supabase/supabase/pull/46371) due to its noise. We're opting to show the connection logs by default instead so this PR changes that behaviour + adjusts the connection logs filter UI In particular this is timely as we're adjusting how the DB will log connections based on this [changelog](https://github.com/orgs/supabase/discussions/47197), and we'd want to make sure that users can find their connection logs easily ## Changes involved - [ ] Search parameter renamed to `show_connection_logs` so that we don't need to flip its boolean value for the checkbox - [ ] `show_connection_logs` is subsequently `true` by default - [ ] Shift connection logs filter to a nested option under Postgres log type - Makes it more visual that connection logs are related to the Postgres service - Currently its hidden all the way in the bottom under "Misc" which can be easily missed - <img width="302" height="151" alt="image" src="https://github.com/user-attachments/assets/e3e61ac7-aa16-4769-a89e-e911daacea27" /> - <img width="289" height="156" alt="image" src="https://github.com/user-attachments/assets/c70ac7c4-d2f7-4961-a6d6-6653c59d8548" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Unified Logs now supports expandable, nested “Log Type” filter options for drilling into connection-related entries. * **UI Improvements** * Connection logs are visible by default; the visibility control has been integrated into the main filter experience. * Filter panels are now streamlined, and key filters (such as “Level”, “Status”, and “Method”) have been reordered and adjusted for a cleaner default state. * **Bug Fixes** * Updated Unified Logs query/test behavior to match the new connection-log visibility logic. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3c26fd071b |
docs: Improve readability of page elements by LLM and AI tools (#47275)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Improved AI, database, storage, and platform guides with clearer explanations and more detailed workflow steps. * Added descriptive captions and accessible alt text for multiple diagrams and benchmark charts. * Expanded MFA, connection, replication, partitioning, and integration docs with clearer decision points and setup/login flow guidance. * Clarified database schema and seed-data examples to better explain how tables and relationships fit together. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io> |
||
|
|
32764ec483 |
docs(realtime): broadcast replay retention limits - REAL-874 (#47270)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs to expose current Realtime Broadcast Replay limits. -- Fixes REAL-874 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified how broadcast replay storage retention works, including the daily-partition behavior and that replays are dropped after 72 hours (messages are available for at least 72 hours and up to ~4 days depending on send time). * Updated the “Limits by plan” table with broadcast replay retention (72 hours) and broadcast replay messages per request (25) across all plans. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
631209f7ce |
chore: Bump vulnerable dependencies (#47269)
Bump several packages: - Bump all instances of dompurify (patch version bump) - Bump `posthog-js` to get a newer version of `@opentelemetry/core` - Bump `@sentry/nextjs` to get a newer version of `@opentelemetry/core` - Bump `redocly-cli` to get a newer version of `@opentelemetry/core` - Bump `undici` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated several project dependencies to newer versions, including documentation tooling, analytics, and error-tracking packages. * These updates may improve stability, compatibility, and access to the latest fixes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
32d1bdd534 |
fix(studio): reduce doc link density in auth email template builder (#47250)
## I have read the CONTRIBUTING.md file. YES ## What kind of change does this PR introduce? - Studio UI update (auth email template builder) - Docs update (hosted email templates guide + local dev cross-link) Closes DOCS-1086. ## What is the current behavior? - Linear item: Reduce link density in the template builder UI - Page header shows a **Terminology** link and **Docs** button (local development guide) - Template variables footer shows **Terminology** · **Local development** - Local development editing is only mentioned in one sentence on the hosted docs page; easy to miss once Studio no longer links there directly ## What is the new behavior? - Page header: **Docs** button only → `/guides/auth/auth-email-templates` - Template variables: single **Terminology** link → `#terminology` (variable pills still have hover tooltips) - Hosted docs: **Editing email templates** split into hosted vs local/self-hosted, with a callout linking to the local development guide - Local dev guide: opening paragraph links back to the hosted guide for shared terminology and patterns ### Proof: Template builder has fewer outbound doc links | Before | After | |--------|-------| | Header Terminology + Docs (local dev guide); footer Terminology · Local development <img width="1440" height="1100" alt="image" src="https://github.com/user-attachments/assets/3325f43b-5830-4b85-ba56-2ba4c5b04bcd" /> | Docs button only (hosted guide); single Terminology link above variables <img width="1440" height="1100" alt="image" src="https://github.com/user-attachments/assets/90c8cfff-89bd-46d5-b336-2f9dd50d37e3" /> | **Before (`origin/master`)** - Header: **Terminology** link + **Docs** button → local development guide - Template variables: **Terminology** · **Local development** **After (this PR)** - Header: **Docs** button only → [Email templates](https://docs-git-nikrichers-docs-1086-reduce-link-densi-bf6705-supabase.vercel.app/docs/guides/auth/auth-email-templates) (preview) - Template variables: single **Terminology** link → [Terminology](https://supabase.com/docs/guides/auth/auth-email-templates#terminology) - Local development path documented at [Editing email templates](https://docs-git-nikrichers-docs-1086-reduce-link-densi-bf6705-supabase.vercel.app/docs/guides/auth/auth-email-templates#editing-email-templates) (preview; replacing the in-builder Local development link) **Capture notes:** Content-area screenshots were captured locally from component markup because the template editor body requires platform auth config in self-hosted Studio. Local files: worktree `.pr-screenshots/template-builder-links-{before,after}.png`. ### Proof: Docs clarify local development path **Verified:** Vercel docs preview (pass) · `supa-mdx-lint` (pass) | Page | Before (production) | After (PR preview) | |------|---------------------|--------------------| | Email templates — Editing | [Editing email templates](https://supabase.com/docs/guides/auth/auth-email-templates#editing-email-templates) | [Editing email templates](https://docs-git-nikrichers-docs-1086-reduce-link-densi-bf6705-supabase.vercel.app/docs/guides/auth/auth-email-templates#editing-email-templates) | | Customizing email templates | [Customizing email templates](https://supabase.com/docs/guides/local-development/customizing-email-templates) | [Customizing email templates](https://docs-git-nikrichers-docs-1086-reduce-link-densi-bf6705-supabase.vercel.app/docs/guides/local-development/customizing-email-templates) | ## Additional context ### Test plan - [ ] Open **Authentication → Emails → Confirm sign up** on a hosted project - [ ] Confirm header has **Docs** only (no Terminology link) - [ ] Confirm **Docs** opens `/docs/guides/auth/auth-email-templates` - [ ] In source view, confirm template variables show one **Terminology** link (no Local development) - [ ] Hover variable pills — tooltips still explain each placeholder - [ ] Compare [production Editing email templates](https://supabase.com/docs/guides/auth/auth-email-templates#editing-email-templates) vs [preview](https://docs-git-nikrichers-docs-1086-reduce-link-densi-bf6705-supabase.vercel.app/docs/guides/auth/auth-email-templates#editing-email-templates) — hosted vs local/self-hosted sections and local dev callout are clear - [ ] Compare [production Customizing email templates](https://supabase.com/docs/guides/local-development/customizing-email-templates) vs [preview](https://docs-git-nikrichers-docs-1086-reduce-link-densi-bf6705-supabase.vercel.app/docs/guides/local-development/customizing-email-templates) — intro links back to hosted email templates guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Documentation** * Clarified how to edit authentication email templates for hosted vs. self-hosted and local development setups. * Added clearer navigation to template terminology and customization guidance, with updated examples and notes. * **New Features** * Updated the email template UI to use centralized documentation links for the terminology section. * **Tests** * Added coverage to ensure the “Terminology” docs anchor stays consistent. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|
|
3db42a805f |
Joshen/fe 3652 replace direct renders of editor component from monaco to (#47268)
## Context Part of consolidating all our code editors - removes all direct renders of the `Editor` component and use `CodeEditor` instead ## UIs affected - [ ] Query performance advisor -> query block - [ ] Table Editor -> Table definition - [ ] Table Editor -> Text + JSON editor (From RowEditorSidePanel, expand input field) - [ ] Auth -> RLS -> Create/edit policy code sections - [ ] Storage policies -> Anywhere that has a code section <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Rolled out a consistent PostgreSQL code editor experience across policy, storage policy, trigger function, table definitions, and query performance screens. * Updated policy/template previews to use the shared editor for cleaner read-only viewing. * **Bug Fixes** * Removed extra left padding in the query performance editor wrapper. * Improved the JSON editor action control with clearer icon behavior. * **Refactor** * Standardized editor usage by replacing legacy SQL/Monaco-based editors with the shared CodeEditor and simplifying related editor components. * Updated CodeEditor capabilities (read-only handling, wrapper styling, markdown support) and tightened editor prop contracts. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3b935e6924 |
chore: remove stray PR screenshots from docs-1080 (#47282)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Repo cleanup. Removes stray PR-review screenshots that were accidentally committed to `.github/pr-screenshots/docs-1080/` during the DOCS-1080 work. ## What is the current behavior? Three PNGs remain in master under `.github/pr-screenshots/docs-1080/` after PR #47252 merged: - `pr1-hipaa-compliance.png` - `pr1-logs.png` - `pr1-postgres-connection-logging.png` These were review artifacts and shouldn't live in the repo. ## What is the new behavior? - Deletes the three PNGs. - Leaves the `.github/pr-screenshots/` directory otherwise untouched. ## Additional context Cleanup only — no code or docs change. ### Test plan - [ ] Confirm the three files are gone from master after merge. - [ ] Confirm no other file in the repo references those paths. Co-authored-by: Nik Richers <nik@validmind.ai> |
||
|
|
6431a2cf80 |
fix: outdated link for api keys in data api docs (#47278)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated the **API settings** link in the documentation intro to take users to the correct project settings page. * Cleaned up the surrounding text formatting so the sentence reads more naturally. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
032bd09b0c |
feat(studio): use theme-aware OAuth requester logos (#47138)
## What kind of change does this PR introduce? Bug fix. - Follow-up work to FE-3640 - Contributes to DEPR-604 ## What is the current behavior? Known dynamic OAuth requesters on `/dashboard/authorize` relied on OAuth-specific hard-coded icon assets that were dark-mode only. Cursor did not have separate light/dark assets in the shared MCP icon registry, Perplexity only had a light tile asset with baked-in padding, and OpenAI used the older blossom mark. ## What is the new behavior? Known OAuth requester logos now resolve through the shared MCP icon registry while preserving the existing `SupabaseLogo` treatment for paired authorisation screens. Cursor uses transparent SVG light/dark variants, Perplexity has cropped transparent SVG light/dark variants, and OpenAI/ChatGPT uses the newer monoblossom SVG in black/white variants. Claude remains static until a suitable variant is available. Unknown requester icons still render from the provided URL and fall back to the requester initial if the image fails. | Before | After | | --- | --- | | <img width="828" height="636" alt="Authorize OpenAI Supabase-E2A05664-589F-458F-8452-9CEE008D558A" src="https://github.com/user-attachments/assets/140021b1-ff05-4092-98ef-2eae94ff2ddb" /> | <img width="828" height="636" alt="Authorize OpenAI Supabase-EC7E00BD-439A-45D1-8E55-240B227C6897" src="https://github.com/user-attachments/assets/93e603f2-5cbf-4219-b692-d36ac98e8d2a" /> | | <img width="828" height="636" alt="66 Authorize OpenAI Supabase-CB31FF76-86DB-43A6-A426-46B99B8B1B91" src="https://github.com/user-attachments/assets/b261416e-39b8-40b3-87fd-461653aa0334" /> | <img width="828" height="636" alt="Authorize OpenAI Supabase-EAFCF2F2-5CEA-4FE6-8AC0-819F764B414E" src="https://github.com/user-attachments/assets/35ad7525-0fa9-4438-b117-4e70b78eb719" /> | ## To test 1. Navigate to `http://localhost:8082/authorize?auth_id=test-auth-id` 2. Open DevTools → Network 3. Find `/platform/oauth/authorizations/test-auth-id` 4. Right-click → Override content 5. Replace the response body with: ```js { "name": "Perplexity", "website": "https://perplexity.ai", "icon": null, "domain": "perplexity.ai", "scopes": [], "expires_at": "2026-12-31T23:59:59.000Z", "approved_at": null, "registration_type": "dynamic" } ``` 6. Then change "name" to Cursor, Claude, ChatGPT, or OpenAI and refresh to inspect each logo <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * OAuth app requester logos now dynamically adapt to light and dark themes, with improved logo selection for known requesters. * Cursor now uses a distinct dark icon variant. * Added Perplexity client icon support. * **Bug Fixes** * Improved logo rendering robustness: if a logo can’t be loaded, the UI falls back to the requester’s initial. * **Tests** * Expanded coverage for theme-aware logo rendering and icon variant handling, including unknown-icon and fallback scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
50989ac999 |
chore: update org not found message to not collide w/ auth.js (#47192)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Error messages were failing due to a error code collision with Auth.js in supabase + gotrue, fix that so the error is not suppressed <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Bug Fixes** * Removed the "Organization not found" error message that appeared when navigating to invalid organization slugs. * Streamlined redirect behavior for empty organization lists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1bc9ac5940 |
bug: table editor default value background color (#47083)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Supabase Studio > Table Editor > New/Edit Table ## What is the current behavior? The `Default Value` has a white background and not matching the same styling: <img width="776" height="837" alt="Screenshot 2026-06-18 at 13 20 12" src="https://github.com/user-attachments/assets/b48674d9-20cd-409a-8e9f-387d4fe9f87a" /> ## What is the new behavior? Input matches the other styling: <img width="776" height="837" alt="Screenshot 2026-06-18 at 13 20 25" src="https://github.com/user-attachments/assets/30cef35a-cab7-4141-bc9c-851e0881d8cb" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated styling for input fields in the table column editor to provide a cleaner appearance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
74ddbc7453 |
Joshen/fe 3685 show a timestamp for failed restart messages in the (#47274)
## Context For notifications which affect a specific project, there's currently no indication of when the notification was created at all, so this PR addresses that ## Changes involved - For notifications, show created at timestamp in header description - Was previously showing project ref if present in notification metadata, but it's repeated information as the affected project is mentioned in the context section - It'll still show the project ref in the list view, change is only in the detail view (after clicking on a notification) ### Before <img width="400" alt="image" src="https://github.com/user-attachments/assets/e8ce247c-afa4-46df-832f-856d34ce82fd" /> <img width="400" alt="image" src="https://github.com/user-attachments/assets/2e0a6c8a-3bb4-4c05-ae13-36b8a92e7ff0" /> ### After No change for notifications list view <img width="400" alt="image" src="https://github.com/user-attachments/assets/e741b607-c5ef-4cd0-9985-5957f2b52bfc" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved how advisor panel details are displayed, ensuring timestamps and secondary text appear in the right situations. * Hidden metadata when no relevant information is available, reducing clutter in the panel. * **Style** * Updated a link layout in notification details for cleaner, more consistent formatting. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
df7a0ca3f7 | feat(replication): Evaluate new product name (#47066) | ||
|
|
d5653f1f92 |
refactor(studio): unify snippet save + persistence into SnippetStatus (3/9) (#47251)
## What PR 3 of a stacked refactor of the SQL editor snippet state. Replaces the two overlapping pieces of snippet lifecycle state — the `savingStates` map (`IDLE|UPDATING|UPDATING_FAILED`) and the `isNotSavedInDatabaseYet` boolean — with a single `SnippetStatus` enum. ## Status is attached at the data layer (never absent) - `SnippetStatus` + `SnippetWithContent` now live in `data/content`. The snippet queries attach `status: 'saved'` via a typed `withSavedStatus()` helper, and `upsertContent` returns `SnippetWithContent` so move/rename responses carry status too. - A SQL-typed `getSqlSnippetById`/`useSqlSnippetByIdQuery` returns `SnippetWithContent` (the generic `useContentIdQuery` stays for Reports, which use it). `[id].tsx` loads content with **no casting**. - `'new'` is attached on local creation (`createSqlSnippetSkeletonV2`). ## Behavior Behavior-preserving for the existing auto-save flow (faithful mapping of both old fields, including the replication-lag swallow). One incidental fix: the read-only/saving indicator now also covers a brand-new snippet's first save (previously only re-saves of persisted snippets had distinct saving/failed states in some paths). ## Tests New `sql-editor-lifecycle.test.ts` (29 tests) covering every predicate and transition; existing rules tests updated. `pnpm --filter studio typecheck` clean; 52 state/sql-editor unit tests pass. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Refactor** * Restructured SQL snippet persistence tracking, replacing boolean flags with a comprehensive status system for clearer visibility into save progress. * Enhanced saving indicator UI to reflect accurate snippet save states. * **Tests** * Added test coverage for snippet persistence state transitions and lifecycle scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a6e79ebacb |
chore: delete Button alternative deprecated variant (#47260)
## Problem The `alternative` variant for `<Button>` has been deprecated but is still used in a few places. ## Solution - Migrate usages to the recommended `primary` variant - Delete the `alternative` variant <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated several buttons across forms, logs, recent queries, and release headers to use the primary visual style. * Button styling is now more consistent throughout the app, with a cleaner default emphasis for key actions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
30cdd18db5 | fix: add migrations endpoint duration is 5 minutes (#43350) |