mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
7b4e3aba01bc8ac94ef2d07a9160deca8564b12a
20454
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
7b4e3aba01 |
fix(studio): show service role key in ConnectSheet for projects using legacy keys (#50516)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix #50515 ## What is the new behavior? ConnectSheet now falls back to the legacy `service_role` key for projects using legacy JWT keys. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved secret-key resolution by falling back to the service key when a secret key is unavailable. * Prevented attempts to reveal a secret when no secret key identifier exists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
337ffaeb22 |
Reset pooling size value to default size if field left blank and saved (#50524)
## Context As per PR title - for the Database Settings -> Connection Pool Just sends the default value (as per the placeholder) to the PATCH request when saving while leaving the pool size field blank <img width="724" height="391" alt="image" src="https://github.com/user-attachments/assets/448c1bf9-4857-467e-8180-637f291321dd" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved connection pooling updates when a project reference or high availability setting is unavailable. - Ensured the default pool size is correctly submitted when no explicit value is provided. - Restored the maximum client connection setting accurately after successful updates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7fb2e8cd42 |
fix(docs): repeated shiki grammar registration (#50501)
## What kind of change does this PR introduce? bug fix alternative to #50492 ## What is the current behavior? [#50239](https://github.com/supabase/supabase/pull/50239) introduced repeated shiki grammar registration. duplicate injection rules accumulate between code blocks, slowing later tutorials enough to hit the 60-second build timeout ## What is the new behavior? - reuses one highlighter with all languages loaded once - restores previous highlighting approach + startup cost while keeping the page-size savings replay | before #50239 | after #50239 | this pr -- | -- | -- | -- cold, including initialization | 2.99 s | 6.96 s | 2.94 s warm | 0.37 s | 5.90 s | 0.36 s <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Enhancements * Code blocks now preload syntax highlighting for all supported bundled languages, including SQL, Markdown, and TypeScript. * Highlighting uses a shared configuration and theme for consistent rendering across code blocks. * Concurrent code block renders share a single highlighter initialization. * Language handling and syntax-highlighted output are more consistent across supported, unsupported, aliased, and plain-text code blocks. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
b5f174a6f9 |
docs: warn against installing PostGIS in the public schema (#50509)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update ## What is the current behavior? Gap in the docs that agents misinterpret ## What is the new behavior? <img width="1566" height="718" alt="CleanShot 2026-09-17 at 12 13 59@2x" src="https://github.com/user-attachments/assets/d50b4228-b0ec-4cca-94d3-ec083720a04a" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added guidance to install PostGIS in a dedicated schema rather than `public`. - Clarified that installing PostGIS in `public` exposes the `spatial_ref_sys` table through the Data API. - Explained that related security advisor warnings are expected and do not indicate user data exposure. - Added steps for moving PostGIS to another schema, including backup precautions and an option to contact Support. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> |
||
|
|
fe0afd66b8 |
docs(cron): document how to clean up cron.job_run_details (#50211)
cron.job_run_details grows unbounded and is never pruned automatically, even after a job is unscheduled. Add an example that schedules a daily cleanup job, and link it from the existing disk-usage caution. ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update ## What is the current behavior? No mention of the _necessary_ regular cleanups ## What is the new behavior? This is now explicitly called out with a weekly clean-up example <img width="1620" height="654" alt="CleanShot 2026-09-10 at 11 41 25@2x" src="https://github.com/user-attachments/assets/2f78a051-5994-4f8a-95c2-c96c64679bed" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated the cron quickstart guide with guidance on cleaning up job run history. - Added an example showing how to schedule a daily cleanup job that removes records older than seven days. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
68d7387e94 |
chore: Update tanstack icons (#50504)
Update the icons for Tanstack in studio and docs. See: - https://docs-git-chore-update-tanstack-icons-supabase.vercel.app/docs - https://studio-staging-git-chore-update-tanstack-icons-supabase.vercel.app/dashboard/project/_?showConnect=true&framework=tanstack |
||
|
|
71d58cba7f |
Joshenlim/fe 4401 re sql editor silently points to the primary instead of (#50513)
## Context Fixes the following 2 issues with the database selection in the SQL Editor - An errant `useEffect` was resetting the `selectedDatabaseId` back to the primary every time the `databases` list from `useReadReplicasQuery` changed reference (not just on first load). - `QuerySourceMenu` kept showing "Read Replica" even after selection had reverted - Was using local storage value as the `identifier` for `DatabaseParametersSubMenu`, when it should use the valtio store as the source of truth <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - The SQL Editor now remembers the last selected database between sessions. - Your saved database selection is restored when available; otherwise, the project’s primary database is selected automatically. - Query source settings now stay synchronized with the database currently selected in the SQL Editor. - **Bug Fixes** - Background database refreshes no longer unexpectedly reset your selected read replica to the primary database. - Database selection now waits for saved preferences to load, preventing a brief incorrect selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
459436e87f |
docs: update compute size descriptions (CPU column, pg_restore guidance) (#49996)
## What kind of change does this PR introduce? Docs update: aligns compute descriptions with the current compute options. Fixes PROD-655 ## What is the new behavior? - compute-and-disk: CPU column now shows "Shared" (Nano–Medium) and "Dedicated · N vCPUs" (Large and above), matching the pricing page - migrating-to-supabase/postgres: pg_restore -j guidance keyed to the vCPU count per compute size - which-version-of-postgres: uses show server_version;, which gives simpler, architecture-agnostic output - High-CPU troubleshooting guide: recommends upgrading compute size instead of naming specific instance types billing-on-supabase: "64 cores" → "64 vCPUs" - Section anchors unchanged (deep-linked from other pages) ## Self-review Content-only MDX change: - pnpm lint:mdx: no findings in the changed files (all reported errors/warnings are pre-existing in unrelated files) - pnpm build:guides-markdown: builds clean; generated .md exports for the changed pages verified - All pages verified rendering in the local dev app on current master - Swept apps/docs for remaining core-count / instance-type mentions in compute descriptions <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated PostgreSQL version-checking instructions to use `show server_version;` with simplified output. * Clarified compute sizing terminology using shared and dedicated CPU allocations and vCPU-based descriptions. * Updated billing guidance to describe scaling up to 64 vCPUs. * Revised database restore guidance with current compute tiers and recommended parallelization settings. * Simplified high-CPU troubleshooting guidance to recommend temporarily scaling CPU capacity. * Added writing guidance to consistently use “vCPU” and “vCPUs” for Supabase compute resources. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
be9ec25270 |
Update unified logs queries to fetch status, method and pathname properly for storage logs (#50465)
## Context As per PR title - those 3 properties (status, method, and pathname) were missing from the table view but available in the detailed panel view ### Before <img width="1118" height="575" alt="image" src="https://github.com/user-attachments/assets/e6d3bb70-8ce9-4a7b-9e07-eae7acb6896d" /> ### After <img width="988" height="555" alt="image" src="https://github.com/user-attachments/assets/309b4e5a-88e1-41d9-8cee-4ae56a1afa15" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Unified Logs now correctly displays HTTP methods, paths, and status codes for storage-service entries. * Updated log filters to support storage-service values for equality, inequality, wildcard, LIKE, and ILIKE searches. * Improved pathname prefix matching across supported log backends. * Preserved correct handling of authentication statuses and worker Compute fields. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6434c48999 |
feat(studio): migrate Auth reports to OTEL (#50469)
## Problem Auth observability charts always queried the legacy logs.all endpoint, even when the OTEL reports rollout was enabled. The existing OTEL SQL also had ClickHouse correctness and parity gaps around timestamp aliasing, JSON types, provider paths, missing values, and error-code attributes. ## Fix Route the ten Auth-specific charts through the OTEL query builders and logs.all.otel endpoint when otelReports is enabled. Preserve the BigQuery fallback, partition React Query caches by backend, and leave the shared API gateway charts on the legacy endpoint. Correct the OTEL queries by qualifying source timestamps, using typed and nullable JSON extraction, preserving missing actor and duration semantics, selecting the right provider path for each event shape, preferring the canonical Auth error-code attribute with a legacy fallback, and applying bounded result limits. Two-minute report intervals now use minute-level SQL buckets instead of falling through to hourly buckets. ## How to test - Run `CI=1 pnpm --filter studio exec vitest run data/reports/v2/auth.config.otel.test.ts hooks/misc/__tests__/useReportDateRange.test.ts` - Run `pnpm --filter studio run lint:ratchet` - Run `pnpm --filter studio run typecheck` - Expected result: all checks pass and generated OTEL SQL preserves legacy report semantics. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Auth observability charts can now use OpenTelemetry data when enabled, while retaining the existing reporting source otherwise. - Switching the data source automatically refreshes the relevant charts. - **Bug Fixes** - Improved Auth observability accuracy for provider, duration, actor, and error-code reporting. - Added safeguards to keep report queries within the supported result limit. - Corrected minute-level grouping for two-minute analytics intervals and three-hour date ranges. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
055cc7b956 |
docs: state disk limits as per-size minimums, align burst copy (#50016)
## What kind of change does this PR introduce? Docs update: states disk limits as per-size minimums and aligns burst copy across pages. Follow-up to #49996 (compute descriptions). Fixes PROD-658 ## What is the current behavior? - The disk limits table and surrounding prose describe a narrower set of configurations than a compute size can run on - Burst thresholds are inconsistent across pages (three different variants), and one section contradicts itself - Burst is described as CPU behavior, when the burst users observe is disk IO ## What is the new behavior? - `shared-data/compute-disk-limits.ts`: Medium baseline throughput adjusted to 39 MB/s: the lowest value across configurations - `compute-and-disk`: disk limits presented as minimums ("at least"); burst described as disk IO drawing on a disk IO budget; consistent thresholds: burst available up to 2XL, baseline equals maximum from 8XL - Troubleshooting guides (`exhaust-disk-io`, `failed-to-retrieve-tables`, `interpreting-supabase-grafana-io-charts`) aligned to the same threshold; `failed-to-retrieve-tables` keeps the ~30-minutes-per-day burst window with the corrected size range - Section anchors unchanged ## Self-review - Values verified against the AWS EBS-optimized performance data (`describe-instance-types`) for every configuration per size; content cross-checked with the internal runbooks (linked in PROD-658) - `supa-mdx-lint`: no findings in changed files - `pnpm build:guides-markdown` clean; generated `.md` exports show the new values and prose - All changed pages verified rendering in the local dev app - `pnpm typecheck` passes (shared-data + docs) - Note: `compute-disk-limits.ts` also feeds Studio (disk validation, IO budget tooltips). The only value change (Medium 43 → 39 MB/s) surfaces there as one chart tooltip label; conservative direction. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Clarified the differences between shared and dedicated CPU resources. - Updated disk I/O guidance to explain baseline and burst limits as minimums. - Documented disk I/O bursting for compute sizes up to 2XL, including expected duration and limitations. - Clarified that 8XL and larger compute sizes have consistent performance without burst capacity. - Updated the documented baseline throughput for medium compute resources. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
593e95345a |
www: update compute size descriptions (Compute column, vCPU units) (#49998)
## What kind of change does this PR introduce? www update: aligns compute descriptions on the pricing surfaces with the current compute options. Counterpart to the docs update in #49996. Fixes PROD-654 ## What is the new behavior? - Pricing compute table: the CPU and Dedicated columns are merged into a single Compute column — "Shared compute" for Micro–Medium, "Dedicated · N vCPUs" for Large and above (the `dedicated` key is removed from `PricingAddOnTable.json`) - Pricing calculator: the instance summary line uses the new Compute value directly - Pricing compute section headline: "64 cores" → "64 vCPUs" - `/pricing.md`, `/llms-full.txt`, `/llms/pricing.txt`: generated markdown mirrors the new table - `/database.md`: describes the compute range as Micro to 16XL+ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Pricing Updates** - Compute pricing tables now label the column “Compute” and show shared compute or dedicated vCPU counts. - Removed the separate “Dedicated” column from compute add-on tables. - Dedicated-plan values now display consistently across desktop and mobile layouts. - Compute instance details no longer repeat the “CPU” label after the CPU value. - Updated scaling language to refer to “64 vCPUs.” - Simplified technical details by removing specific core-count examples while retaining configurable sizing and autoscaling information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
77ee1ec127 |
chore(studio): describe compute CPU by size tier (#50401)
## What kind of change does this PR introduce? Copy/label update in Studio's compute surfaces. ## Description Compute CPU descriptions now branch on the compute size tier: - Sizes below Large read **"Shared compute"** (no core count) - Large and up read **"Dedicated · N vCPUs"** — the unit is always vCPU Changes: - New `lib/compute-labels.ts` helper (`isSharedComputeSize`, `getComputeCpuLabel`) with unit tests - Compute badge hover card, compute size picker, and project-creation selector use the new labels - `new-project.constants.ts` cpu strings updated accordingly - ">16XL" card: "Custom CPU" → "Custom compute"; upsell copy now says "64 vCPUs" - The synthetic Nano/Micro addon `meta` no longer has `cpu_cores`/`cpu_dedicated`; removed the now-unused cpu fields from the hardcoded instance specs - Project-creation sub-text: "Larger, dedicated compute available after creation" ## Tests - New unit tests for the label helper - Infrastructure settings page test now asserts the rendered labels Fixes PROD-663 Related #49998 #49996 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **User Interface** * Updated compute-size labels to use “Shared compute” and vCPU terminology. * Clarified dedicated compute options and availability messaging. * Updated custom instance and upgrade labels, including “Custom compute” and “64 vCPUs.” * **Consistency** * Standardized compute labels across project creation, infrastructure settings, and compute details. * **Tests** * Added coverage verifying shared and dedicated compute classifications and displayed labels. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
c2d8b08299 |
MFA Recovery codes: UI tweaks (#50488)
## What kind of change does this PR introduce? Admonition is not the right UI to tell users how many are still available. ## What is the current behavior? No recovery codes yet: <img width="724" height="499" alt="image" src="https://github.com/user-attachments/assets/db9d47af-3a81-42d2-8cf0-9302816ceb21" /> After: <img width="758" height="525" alt="image" src="https://github.com/user-attachments/assets/68acc4bf-372f-4472-a3e4-a8263a8993d0" /> ## What is the new behavior? No recovery codes yet: <img width="720" height="556" alt="image" src="https://github.com/user-attachments/assets/48ce08a7-9650-428b-be5d-b8bb7ef5b720" /> After: <img width="720" height="541" alt="image" src="https://github.com/user-attachments/assets/35a8698d-9a6f-44cb-91c8-2ddb8d0f3a7b" /> When low number of codes available: <img width="733" height="548" alt="image" src="https://github.com/user-attachments/assets/d60017ba-ada6-47bb-9f83-a2a65674f800" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Recovery codes now appear in a dedicated section when enabled, separate from multi-factor authentication settings. - Recovery-code status updates are announced to screen readers for improved accessibility. - Available recovery codes are displayed in a clearer card-based layout once status information is available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7ab3f32625 |
feat(studio): rebuild the pipeline overview (#49630)
## What kind of change does this PR introduce? Studio UI improvement. ## What is the current behavior? The pipeline Overview uses bespoke loading, metrics, table-state and empty-state layouts that shift while data resolves and repeat status information from the detail header. ## What is the new behavior? Rebuilds the Overview around stable **Pipeline health** and **Replicated tables** sections. It adds layout-matched loading geometry, prioritised pipeline notices, initial-sync progress, clearer empty states, and accessible loading announcements. Complete pipeline configuration remains deferred to #49631. | Before | After | | --- | --- | | <img width="1024" height="759" alt="54861" src="https://github.com/user-attachments/assets/56e5cc5a-5d49-44c8-94d7-e1f1e0c827d5" /> | <img width="1024" height="759" alt="Replication Database Agua Basket Supabase" src="https://github.com/user-attachments/assets/43b6d0f6-6fd5-47f9-b3e5-788a33511304" /> | This is the final independent slice in the review series: #50443, #50444, #50445, #50446, then this PR. Each PR targets `master` and can merge on its own. Rebase this PR as earlier slices merge. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline. 2. Throttle the initial requests and confirm **Pipeline health** and **Replicated tables** keep their final geometry while loading. 3. Check running, initial-sync, stopped, failed, disconnected and unavailable states. 4. Confirm the Overview contains Pipeline health and Replicated tables only, without a Configuration section. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Reorganized replication pipeline status into Pipeline health and Replicated tables sections. - Added loading skeletons with accessible status announcements. - Added clearer notices for pipeline health, failed or disconnected pipelines, paused updates, lag, and synchronization progress. - Improved empty states when table data is unavailable or the pipeline is inactive. - Added options to view logs and reset failed tables. - **Tests** - Added coverage for loading behavior, pipeline notices, table counts, synchronization progress, and empty states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0043e6f53b |
feat(studio): add Explorer onboarding and startup preference (#50493)
<img width="1454" height="920" alt="image" src="https://github.com/user-attachments/assets/a289b618-2bd2-4957-ac49-71d4e372d2cc" /> ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. Yes. ## What kind of change does this PR introduce? Feature. ## What is the current behavior? Explorer always opens on its start page, without onboarding or a startup preference. ## What is the new behavior? Adds one-time onboarding with wireframe option cards and a collapsed Learn more section. Users can start on the Explorer start page or in a new SQL query tab, and change that choice in Account preferences → Dashboard. Preferences persist per account in the browser. ## Additional context How to test: 1. With Explorer enabled and fresh browser storage, open Explorer and select either startup option. Confirm Open Explorer follows the selection and onboarding stays dismissed after reload. 2. Change Explorer startup in Account preferences → Dashboard, then reopen Explorer. SQL query should create one normal query tab; Start page should restore the pinned home tab. 3. Use the keyboard to select an option and toggle Learn more. Expand it in a short viewport and check that the page scrolls normally. Validation: 235 tests pass, including 20 new cases; Studio typecheck and formatting pass. The local production build was stopped during compilation and was not verified locally. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added an Explorer onboarding experience with startup-view selection, guidance, and a Learn more section. - Added Explorer settings to choose between the Start page and SQL query views. - Explorer preferences now persist across sessions and accounts. - Explorer can open directly to a new SQL query when selected. - The Explorer Home tab is shown based on the selected startup preference. - **Accessibility** - Reduced-motion settings now disable the Explorer loading animation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2a46c00653 |
feat(studio): polish replicated table controls (#50446)
## What kind of change does this PR introduce? Studio UI improvement. ## What is the current behavior? Replicated tables use badge-heavy rows, fixed name sorting, prominent per-row reset buttons, and inconsistent restart terminology. ## What is the new behavior? Adds table and status sorting, accessible search feedback, concise state details, table action menus, and consistent **Reset** terminology. Failed-table reset remains unavailable when there are no failed tables or another reset is running. | Before | After | | --- | --- | | <img width="1872" height="356" alt="CleanShot 2026-09-16 at 13 36 51@2x" src="https://github.com/user-attachments/assets/6546f089-f6f8-4ff2-9509-ec44a2dee973" /> | <img width="1840" height="452" alt="CleanShot 2026-09-16 at 13 36 30@2x" src="https://github.com/user-attachments/assets/6e36b1e6-baee-4aea-80e9-e5e4a3fc8a75" /> | This is an independent slice extracted from #49630. The related review series is #50443, #50444, #50445, this PR, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline with replicated tables. 2. Sort by **Table** and **Status**, then search for a table and clear the search with Escape. 3. Open a table’s action menu and confirm its reset and Table Editor actions. 4. Confirm **Reset failed tables only** is unavailable when the pipeline has no failed tables. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added sortable Table and Status columns to the replication pipeline view. * Added options to reset all tables or only failed tables. * Added clearer replication lag details and status indicators. * Added dropdown actions for resetting tables and opening the Table Editor. * Added Escape-to-clear support for search. * **Bug Fixes** * Improved empty search results with a clear “No results found” message. * Error details are now displayed separately for easier access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a5dcf3b57c |
feat(studio): rebuild pipeline health summary (#50445)
## What kind of change does this PR introduce? Studio UI improvement. ## What is the current behavior? Pipeline health is presented as a dense custom metrics panel with repeated connection information and per-table lag details mixed into the pipeline summary. ## What is the new behavior? Moves the pipeline-level slot status, lag, WAL retention, and last check-in into a standard detail section. It removes repeated connection content and keeps table-specific state with the replicated tables. | Before | After | | --- | --- | | <img width="1816" height="274" alt="CleanShot 2026-09-16 at 13 34 43@2x" src="https://github.com/user-attachments/assets/eceed5bb-8af2-4a3b-83a9-7849f1554fbe" /> | <img width="1830" height="506" alt="CleanShot 2026-09-16 at 13 34 15@2x" src="https://github.com/user-attachments/assets/498c4390-17e2-45e5-a923-cb4a7cfd5978" /> | _Note that the page spacing may feel a bit funny. This is handled in https://github.com/supabase/supabase/pull/49630_ This is an independent slice extracted from #49630. The related review series is #50443, #50444, this PR, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a running pipeline. 2. Confirm **Pipeline health** shows slot status, lag, WAL retention remaining, and last check-in. 3. Confirm unlimited WAL retention is labelled **Unlimited** and a caught-up pipeline is labelled **Caught up**. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## UI Improvements - Added a dedicated Pipeline Health section summarizing WAL status, slot status, and replication lag. - Replaced the inline metrics layout with responsive detail cards and clearer supporting descriptions. - Added tooltips for lag values and relative reply times, including precise timestamps. - Updated lag labels and status indicators for improved clarity. - Added concise explanations for reserved, extended, unreserved, lost, and unknown WAL states. - Improved presentation of pipeline details with optional contextual descriptions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3e2d54eccb |
feat(studio): add Warehouse table management and disable (#50195)
## What kind of change does this PR introduce? Feature and UI polish. ## What is the current behavior? Warehouse setup uses a schema accordion for table selection. Once Warehouse is enabled, users cannot remove replicated tables or disable Warehouse from Studio. ## What is the new behavior? - Replaces the schema accordion with one grouped, searchable table selector. - Still allows for **Select all** and **Clear** actions for each schema. - Starts first-time setup with no tables selected and preselects current replicated tables when editing. - Adds support for removing previously replicated tables. - Adds a confirmed **Disable Warehouse** action. - Tracks successful Warehouse enable and disable actions. Disabling Warehouse removes its replication pipeline, publication, catalogue access, and foreign tables. Copied data remains in DuckLake storage until the user deletes it. Re-enabling a table rebuilds its data rather than reusing the retained copy. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Integrations Test US East 1 testdw Supabase" src="https://github.com/user-attachments/assets/bded025b-1d45-41dc-8a35-9159baf8f9b7" /> | <img width="1024" height="759" alt="Integrations test Teamer Supabase" src="https://github.com/user-attachments/assets/69026d94-98a0-4878-ab58-2e9697296d93" /> | | <img width="1280" height="1323" alt="Integrations Test testdw Supabase" src="https://github.com/user-attachments/assets/3f71e754-1a87-4d58-a7b9-dd39d3e0ac5a" /> | <img width="1280" height="1323" alt="Integrations Regular AWS Teamer Supabase" src="https://github.com/user-attachments/assets/758ed48e-9ed6-45d3-ae94-e171147a21d5" /> | | _Feature did not exist_ | <img width="1024" height="759" alt="Integrations Regular AWS Teamer Supabase" src="https://github.com/user-attachments/assets/c977ac57-8b0c-4482-882b-69ad7602b5df" /> | ## Additional context Platform support for updating and disabling Warehouse was added in [supabase/platform#38190](https://github.com/supabase/platform/pull/38190). ### To test 1. Open `/project/{ref}/integrations/warehouse/overview` before setup. 2. Confirm **Tables to replicate** starts at zero and **Enable Warehouse** is disabled until a table is selected. 3. Confirm each schema's **Select all** and **Clear** actions update every table in that schema. 4. Enable Warehouse with a partial selection and wait for setup to complete. 5. Edit the selection, add and remove replicated tables, then confirm the saved selection is reflected in the publication. 6. Disable Warehouse, confirm the retention warning, and verify the integration returns to its initial state. 7. Re-enable Warehouse and confirm selected tables are rebuilt. 8. Trigger a replication pipeline limit error and confirm the inline guidance links to Database Replication. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added the ability to disable Warehouse from the setup panel. - Warehouse setup now starts with no table selections. - Editing a setup preselects replicated tables and supports updating selections, including removing tables. - Added searchable schema and table selection with screen-reader count announcements. - Added telemetry tracking for initial Warehouse enablement. - **Bug Fixes** - Warehouse disable failures now show an error while keeping the confirmation dialog open for retry. - Configuration updates now refresh related data automatically. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7880c2f079 |
fix(studio): explorer chat and notebook layout refinements (#50453)
Five layout fixes across Explorer chat, notebooks, and the sidebar. ### Chat - **Conversation fade overlapped the scrollbar.** The top and bottom gradients are positioned against the conversation's padding box, which includes the scroll container's scrollbar gutter, so `inset-x-0` painted them over the scrollbar. They now stop at the conversation's content gutter, which `Conversation` owns for both the content and the fades. - **Composer background bled past the input's radius.** The form paints the surface behind the textarea but had no radius of its own, so its square corners showed outside the `rounded-lg` input. It now shares the radius. - **Message parts used two different widths.** Wide parts come down to `max-w-3xl` so every part shares a column, matching `AssistantQueryCell` and `AssistantNotebookPreview`. `isWide` / `isWideMessagePart` stay in place with both widths equal, so a part can diverge again later without rebuilding the mechanism. ### Notebooks - **Cell controls sat at the container edge.** Each cell centred itself at its own max width while the grip and add-cell button stayed at the far left of the full-width row, leaving a large gap. `SortableSection` takes a `sectionWidth` and carries its control gutter twice — once as the controls, once as padding on the other side — so the section stays centred with its controls immediately beside it. Cell widths are unchanged (prose `48rem`, query `72rem`); set them equal and the two cell types' controls line up on their own. The controls stay in flow rather than floating in an outside gutter, so on a viewport narrower than the cap the row just fills the space instead of clipping the controls into the padding. ### Sidebar - **Search icon didn't line up with the menu row icons.** The row box already sits flush with the search input's box, so rows moved from `pl-3` to `pl-2` to put their icons on the same 8px offset the search icon uses. Spacing between the input and the list now matches the 12px side padding. ### Testing `pnpm --filter studio run typecheck`, Prettier, and 378 tests across `Explorer`, `ProjectHome`, `AIAssistantPanel`, and `ExplorerLayout` pass. ESLint warning counts are unchanged from master. These were reasoned from layout rather than checked in a browser, so they're worth a look on a preview before merge. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Updated Explorer layouts with flexible, configurable widths for notebook and query sections. * Refined navigation spacing and padding across Explorer views. * Centered and standardized AI Assistant preview, query, and message content widths. * Improved chat form styling with rounded corners. * Adjusted conversation spacing and fade overlays to avoid overlapping the scrollbar. * Preserved full-width behavior where appropriate while keeping controls aligned. * **Tests** * Updated layout tests to reflect revised width and alignment behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
c15b0836d8 |
fix(studio): bump realtime max_concurrent_users soft limit (#50438)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bump realtime max_concurrent_users soft limit to 300k <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Increased the maximum supported concurrent clients from 50,000 to 300,000 when plan entitlements allow it. * **Bug Fixes** * Improved validation for concurrent-client limits, including clearer handling of entitlement-based and unlimited limits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
babebc959c |
fix(studio): improve pipeline destination logo legibility (#50496)
## What kind of change does this PR introduce? UI polish for Pipeline destination logos. ## What is the current behavior? The Snowflake mark does not use the available SVG canvas, and destination marks appear overly inset in the pipeline detail header. ## What is the new behavior? The Snowflake asset uses more of its canvas, and the large `DestinationLogo` variant renders a 32px mark inside its existing 56px frame. Small logos used in lists, diagrams, and destination pickers remain unchanged. | Before | After | | --- | --- | | <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 46 51@2x" src="https://github.com/user-attachments/assets/83e7ab5e-c9f3-4410-99c1-4f3596b9e027" /> | <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 48 33@2x" src="https://github.com/user-attachments/assets/d354dd46-80be-48f6-b2d9-277ee930eaaa" /> | ## To test 1. Open `/project/<ref>/database/replication` with a Snowflake pipeline and confirm its logo renders clearly in the list. 2. Open that pipeline's child route and confirm the destination logo fills more of the header square without changing the square itself. 3. Check another destination's child route and confirm its large logo uses the same sizing. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Increased the size of the large destination logo mark for improved visibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
20d09b4a72 |
docs(auth): clarify OAuth 2.1 server pricing is included in Auth MAUs (#49753)
OAuth 2.1 server had a single pricing statement anywhere, and it said the feature is free during beta. This states the actual model everywhere the feature is documented or sold: there is no separate charge, and users who sign in through the OAuth server count toward Auth MAUs. - docs getting started: replace the "free during beta" sentence with the MAU-based pricing statement - docs overview: add a Pricing section linking to the MAU usage guide and the pricing page - docs MCP authentication: note that agents authenticate as existing users, and MAUs count per distinct user, so multiple agents for one user count once - www pricing comparison table: add an "OAuth 2.1 Server" row (included on all plans) with a tooltip, and extend the MAU tooltip to cover OAuth server sign-ins <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that OAuth 2.1 Server is available on all plans without a separate charge. * Explained that OAuth sign-ins count toward Monthly Active Users (MAUs), with multiple agents for one user counted once. * Added links to MAU and pricing guidance. * **Pricing** * Added OAuth 2.1 Server as a plan feature and updated billing descriptions for greater clarity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e21e0c73bb |
refactor(studio): simplify pipeline error details (#50444)
## What kind of change does this PR introduce? Studio UI refactor. ## What is the current behavior? Failed replicated tables spread retry timing and error details across several visually heavy blocks. ## What is the new behavior? Condenses retry timing and failure details into a clearer table-level presentation without changing retry behaviour or pipeline mutations. | Before | After | | --- | --- | | <img width="1842" height="594" alt="CleanShot 2026-09-16 at 12 55 52@2x" src="https://github.com/user-attachments/assets/fb6f6a3f-2e81-411e-9d49-ed4cf8cc66e7" /> | <img width="1824" height="328" alt="CleanShot 2026-09-16 at 15 16 21@2x" src="https://github.com/user-attachments/assets/bad558c4-2d4c-4d1b-bb68-32ad4d5b348f" /> | | _Not applicable._ | <img width="832" height="662" alt="CleanShot 2026-09-16 at 15 16 29@2x" src="https://github.com/user-attachments/assets/540a5d55-f99f-4c1e-9a57-5ab2ac31e44e" /> | This is an independent slice extracted from #49630. The related review series is #50443, this PR, #50445, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline with a failed table. 2. Confirm the table row presents its failure and retry timing without expanding the row unnecessarily. 3. Open the error details dialog and confirm the underlying error remains available. This is difficult to test unless you have a properly-failing table. You can instead do the following locally: 1. Check out `dnywh/tmp/pipelines-running-fixture`. 2. Open `/project/<ref>/database/replication/<pipelineId>`. 3. Use the floating pipeline-state switcher in the bottom-right. 4. Select _Running, some tables errored_. |
||
|
|
0b002892d7 |
refactor(studio): simplify pipeline reset dialogs (#50443)
## What kind of change does this PR introduce? Studio UI refactor. ## What is the current behavior? Pipeline table reset dialogs repeat explanatory content and use more layout than the reset decision needs. ## What is the new behavior? Simplifies the single-table and batch reset confirmations while preserving their cost estimate, destructive consequences, and existing reset mutations. | Before | After | | --- | --- | | <img width="854" height="1090" alt="CleanShot 2026-09-16 at 12 54 36@2x" src="https://github.com/user-attachments/assets/f9eef09b-89d1-4747-bc4c-e81fb64c584b" /> | <img width="840" height="742" alt="CleanShot 2026-09-16 at 17 01 11@2x" src="https://github.com/user-attachments/assets/fa45728c-ec66-45c8-9fef-9d2eb8310d4d" /> | This is an independent slice extracted from #49630. The related review series is this one, #50444, #50445, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline. 2. Reset one replicated table and confirm the dialog explains that destination data will be deleted and resynchronised. 3. Choose **Reset all tables** and confirm the batch dialog shows the same concise treatment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## UI Updates * **UI Updates** * Renamed replication “restart” actions to “reset” across dialogs, buttons, notifications, and cost estimates. * Updated messaging to clarify whether the pipeline will start or restart automatically after resetting. * Added clearer initial-sync guidance for all, some, or none of the affected tables. * Improved reset cost estimate messaging, including when no additional initial-sync charge applies. * Updated reset dialogs with clearer titles, descriptions, loading states, and error messages. * Disabled reset actions when pipeline status is unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cc540ff302 |
feat(studio): add safe theme colour controls (#49804)
## What kind of change does this PR introduce? Feature. ## What is the current behaviour? Studio Appearance preferences only select a theme mode. The underlying theme colours cannot be adjusted, and the existing proof of concept allowed unsafe combinations and introduced a bespoke Slider variant. ## What is the new behaviour? - Preserves the existing System, Dark, Light, and Classic Dark theme options. Classic Dark remains a fixed preset. - Adds four theme colour controls using the existing Supabase Slider unchanged. Each control presents a consistent 0 to 100 scale mapped to bounded light and dark ranges. - Previews colour changes while dragging and persists them once the interaction finishes, including rapid pointer gestures. - Stores light and dark overrides separately, validates stored values, clamps legacy values, and removes overrides that return to their shipped defaults. - Adds concise descriptions for Chroma, Contrast, Surface, and Elevation step, with a scoped Reset action shown only when the active theme differs from its defaults. - Keeps Slider in a stable shared chunk so production builds do not create a circular dependency between generated UI chunks. | Before | After | | --- | --- | | <img width="1448" height="1284" alt="CleanShot 2026-09-15 at 14 33 53@2x" src="https://github.com/user-attachments/assets/d55151c7-b2a9-40c6-9468-e77ae685ac38" /> | <img width="1454" height="1958" alt="CleanShot 2026-09-15 at 17 48 47@2x" src="https://github.com/user-attachments/assets/9d302e67-76cc-4341-948c-81713dea2e93" /> | ## To test 1. Open `/account/me` and scroll to Appearance. 2. Switch between System, Dark, Light, and Classic Dark. Confirm the same four modes remain available in the account theme menu. 3. Confirm Classic Dark retains its existing appearance and does not show theme colour controls. 4. In System, Dark, or Light, move each Theme colors slider to both ends. Confirm the dashboard previews the change, remains readable, and the theme cards do not shift or remount. 5. Reload the page and confirm colour changes persist separately for Light and Dark. 6. Return all sliders to their defaults, or select Reset, and confirm the Reset action disappears. 7. In System mode, change the operating system theme and confirm each resolved mode restores its own colour settings. --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
91e23a0f2d |
docs: define detection checks and specialist monitoring prompts (#50075)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. Yes. ## What kind of change does this PR introduce? Documentation update. ## What is the current behavior? Specialist monitoring prompts leave some comparison windows, baselines, thresholds, and missing-data behavior undefined. This can produce reports or forecasts without sufficient evidence. ## What is the new behavior? Detection checks define inputs, comparison windows, thresholds, units, missing-data behavior, and next investigation steps. Query regressions require comparable snapshots and reset history; capacity forecasts require saved measurements and a matching confirmed limit. Health, Security, Performance, and Capacity prompts fetch and follow the shared detection checks automatically. They record finding, clear, or unable to assess, preserve alert state, and suppress unchanged repeats. Missing history or failed access cannot become a healthy result. Specialist pages retain their diagrams and the sections What it watches, When it watches, What it will output, and Set up the agent. Setup explains the necessary documentation access and saved state; optional links explain report triggers. Prompt and provider setup tabs remain available in HTML and Markdown. The Hire an agent overview and Generalist page and prompt remain unchanged. Prompt Markdown exports use the Markdown serializer to safely contain nested code fences, preserving the full Generalist prompt and its SQL examples. Both prompt exporters have parser-based round-trip coverage. ## Additional context Full docs suite: 215 passed, 2 skipped against a freshly reset disposable Supabase stack. Typecheck, targeted ESLint, formatting, and guides Markdown generation also pass after the export fix. Earlier validation: production docs build, docs typecheck, targeted ESLint, formatting, and guides Markdown generation pass. All four specialist exports contain their diagrams, setup sections, enhanced prompts, and provider instructions. The Health page diagram and setup tab were checked in the browser. Changed pages have no MDX lint violations; existing repository-wide violations remain. The unchanged detection SQL was previously smoke-tested in a disposable sandbox. Hosted MCP runs, scheduler persistence, notifications, and agent evals are outside this validation. Evals remain outside this change. Stage 3 of 3; depends on stage 2. Stack: #50073 → #50074 → #50075. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Reworked observability guidance around hourly, read-only monitoring checks. - Updated health, security, performance, and usage monitors to identify new findings, data gaps, regressions, and resource growth. - Added clearer setup instructions for linked documentation, saved measurements, and alert state. - Replaced the issue-detection guide with standardized outcomes: finding, clear, or unable to assess. - Added explicit thresholds, evidence details, investigation links, and verification steps for turning detections into diagnoses. - **Improvements** - Standardized monitoring prompts and presentation across supported agent types. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
e8547352c5 |
docs(auth): answer the four most repeated SSR auth questions (#50289)
Closes DOCS-1313 Closes FDBKIN-4573 Closes FDBKIN-15214 Closes FDBKIN-10628 ## Problem Four asks come up repeatedly in feedback intake. The Eval is green and this feedback cannot be included in the Eval. Using the Evals work as an excuse to action on the feedback. 😄 Readers can't tell which auth call verifies a token and which only reads stored state. They don't know that the response the cookies were written to is the response they have to return, because that only ever existed as a code comment. Nobody is warned that refreshing in two places burns a single-use refresh token, which surfaces as users being signed out at random. And nothing in `apps/docs` says `proxy.ts` is Next.js 16 and later, so a reader on 15 writes a file the framework never calls. ## Solution - Add the fact that `getClaims()` refreshes a session close to expiring before it verifies. It was only in the typedoc remarks, and it is what makes the double refresh warning make sense. - Say that `setAll` rebuilds `supabaseResponse` on every write, so a response built earlier is stale, and show how to copy the cookies onto a different one. - Warn that a second refresh outside the reuse window revokes the session, linking refresh token reuse detection. - Note that `proxy.ts` is Next.js 16 and later, and that the file is `middleware.ts` before that. - Name the file in the proxy fence in `examples/prompts/nextjs-supabase-auth.md`, which gave agents the export name and no path. The auth methods partial is shared by five other pages, so that first change surfaces there too. ## Manual testing 1. Open the [SSR client guide](https://docs-git-docs-ssr-client-feedback-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client) on the deploy preview. The Next.js panel carries the version note, the refresh warning, and the response guidance. 2. Select the refresh token reuse detection link. It resolves to the sessions guide. 3. Open the [Next.js Auth prompt](https://docs-git-docs-ssr-client-feedback-supabase.vercel.app/docs/guides/ai-tools/ai-prompts/nextjs-supabase-auth). The proxy section names the file and says it is `proxy.ts` on Next.js 16 and later. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation - Clarified that `getClaims` refreshes sessions when access tokens are near expiration, helping server-rendered sessions remain active. - Expanded Next.js SSR guidance for session-refresh setup, including file placement and version-specific naming. - Added warnings about refresh-token reuse and session revocation after repeated refreshes outside the reuse window. - Added guidance for preserving authentication cookies and cache-related headers when returning updated responses. - Clarified that refreshed tokens should be passed to Server Components to keep sessions active. - Clarified the required session-refresh handler export and example filename. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a4106b01f5 |
docs(auth): correct what getClaims verifies, and fix the Express env setup (#50288)
## Problem These findings came from a technical audit and verification of the claims in the doc. I found two accuracy problems: - **The guide said `getClaims()` is safe to trust** because it "validates the JWT signature against the project's published public keys every time". That only describes projects on asymmetric signing keys. With a symmetric secret it calls the Auth server instead, which the page's own partial already said. The advanced guide then read as a flat contradiction: `getUser()` was "the only way" to know a session is valid. The real distinction is revocation, not verification. - **Running the Express sample verbatim doesn't work.** In the docs sandbox, it printed `SUPABASE_URL = undefined`, so `createServerClient` received undefined for both the URL and the key. The env var tab installed dotenv twice, once inline and once through the package manager tabs, and its "And initialize it" lead-in was followed by the second install rather than any initialization. The route sample then required dotenv without calling `config()`. ## Solution - Say what `getClaims()` verifies against in each signing key mode. - Reframe the advanced guide's `getUser()` answer around session revocation, so the two pages stop contradicting each other. - Switch the advanced guide's two middleware snippets from `getUser()` to `getClaims()`, matching the guide. - Rename its `Next.js middleware` heading and CloudFront bullet, which the proxy rename missed. - Load dotenv on the first line of the Express entry point, and drop the duplicate install. - Tag both Express fences `js`. They are CommonJS, not TypeScript. - Update the stale "middleware refreshing user sessions" comment in the rendered Next.js `server.ts` sample. ## Manual testing 1. Open the [SSR client guide](https://docs-git-docs-ssr-client-accuracy-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client) on the deploy preview, then the Express tab. dotenv is installed once, followed by `require('dotenv').config()`. 2. Open the [advanced guide](https://docs-git-docs-ssr-client-accuracy-supabase.vercel.app/docs/guides/auth/server-side/advanced-guide). The Next.js heading reads `Next.js proxy` and both snippets call `getClaims()`. Part of DOCS-1313. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Clarified the difference between token validation and detecting revoked server-side sessions. - Updated Next.js guidance and examples to use “proxy” terminology. - Refined CloudFront caching guidance for authenticated routes. - Improved Express setup instructions, including dotenv loading and JavaScript examples. - Expanded explanations of signing-key verification. - Updated Astro and Nuxt examples to forward cache headers correctly. - Updated session-refresh guidance in the Next.js example to reference the proxy. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7bec687917 |
docs(auth): regroup the SSR client guide and cut repetition (#50287)
## Problem `_partials/auth_methods.mdx` was included six times in this one page. Radix unmounts inactive tab panels, so a browser reader sees it three times on the default Next.js view, and the generated markdown that agents read contained all six. That was about 25% of the 33.5 KB export, and it put the same `Summary of the methods` heading in the table of contents three times over. The page is also 900+ lines with no intro outline, the per-framework recaps were `h2` inside an `h2` section, and six of the nine panels had no step headings at all. ## Solution - Include the auth methods partial once, under a new `Choosing an auth method` section grouped with `Caching considerations`, and point to it from the procedure. This follows the mixed information types rule in `apps/docs/CONTRIBUTING.md`. - Add an intro outline linking the section groups and saying when to read the two reference sections. - Demote the eight in-tab `Congratulations` headings to `h3` so they nest under `Create a client`. - Add a `Create the Supabase clients` heading to Astro, Remix, Nuxt, React Router, Express, and Hono, and the recap Hono was missing. No claims changed here, only placement. ## Manual testing 1. Open the [SSR client guide](https://docs-git-docs-ssr-client-structure-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client) on the deploy preview. The table of contents lists `Summary of the methods` once. 2. Select each of the five links in the intro paragraph. Each one scrolls to its section. 3. Select each framework tab. Every panel has a step heading and a recap. Part of DOCS-1313. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added an introductory setup overview covering installation, environment variables, client creation, authentication methods, and caching. - Added dedicated guidance for choosing an authentication method. - Added Astro SSR and client sections, along with a complete Hono recap. - Reorganized framework headings for clearer navigation. - Consolidated authentication guidance by removing duplicate content from individual framework sections. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
91b7df64c2 |
fix(ui): report clipboard write failures instead of rejecting (#50292)
Closes DOCS-1390 ## Problem Sentry [DOCS-AA](https://supabase.sentry.io/issues/7727380816/) reports `NotAllowedError: Failed to execute 'write' on 'Clipboard': Write permission denied.` as an unhandled promise rejection. The error names `write`, not `writeText`, which places it in the `ClipboardItem` branch of `copyToClipboard`. That branch has two problems: - The write runs inside a `setTimeout`, so the surrounding `try/catch` has already returned by the time it executes. A denied write routes to the promise's `reject`. - No caller attaches a `catch`. All call sites either fire-and-forget or `await` inside an async handler with no `try/catch`, so the rejection surfaces as an unhandled rejection. The user-visible effect is worse than the Sentry noise. On that branch the copy fails with no feedback at all, because the `toast.error` in the outer `catch` is unreachable from inside the `setTimeout`. The `writeText` branch does show the toast, so the two paths disagree. The issue is filed against auth docs, where it surfaced, but the fix belongs in `packages/ui`. The same branch runs in Studio and www. ## Solution - Handle the failure inside the `setTimeout`, where it happens: report it and resolve. - `copyToClipboard` no longer rejects on either path, matching what the `writeText` branch already did. No caller relied on rejection. - Add regression tests for a denied write on both branches. ## Manual testing 1. Run the unit tests. Four `copyToClipboard` cases pass, including the two new denial cases. ``` pnpm --filter studio exec vitest run lib/helpers.test.ts -t copyToClipboard ``` 2. Confirm the new test is a real guard. Revert `clipboard.ts` and rerun. The write case fails with `promise rejected ... instead of resolving`. 3. Confirm the ratchet is unchanged. ``` pnpm --filter studio run lint:ratchet ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Clipboard write failures now display an error notification instead of causing an unhandled rejection. * Copy operations resolve consistently when clipboard access is denied or unavailable, including Safari clipboard support. * Failed copy attempts no longer trigger completion callbacks, preventing misleading success behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cf5bf65361 |
docs(auth): tighten the voice in the SSR client guide (#50286)
## Problem
The SSR client guide, like all guides, have drifted from our style rules
and writing best practices.
This PR is to do an inline edit without re-arranging any sections.
## Solution
- Open with what the guide does, then the SSR context.
- Delete the `{/* TODO: Can this be consolidated? */}` comment.
- Remove the three em dashes and the parenthetical asides in prose.
- Rewrite the Next.js danger callout to lead with the consequence:
anyone can forge the session cookie.
- Give Astro, Remix, Nuxt, React Router, and Express the same bulleted
recap Next.js, SvelteKit, and TanStack already had.
## Manual testing
1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-style-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview. The first sentence says what the guide does.
2. Select each framework tab. Every panel ends with a bulleted recap.
Part of DOCS-1313.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Documentation**
- Updated server-side authentication guidance across supported
frameworks.
- Clarified cookie-based session storage, SSR package usage, and
cache-header handling.
- Added guidance on protecting against forged cookies and verifying
sessions with `getClaims()`.
- Expanded framework setup and authentication flow summaries for Astro,
Remix, Nuxt, React Router, Express, and TanStack Start.
- Clarified TanStack route protection, redirects, and server-side
authorization requirements.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
3e6b40b238 |
chore(docs): revise CONTRIBUTING for common pitfalls with Information types (#50357)
## Problem Our CONTRIBUTING and WORD_LIST is doing a pretty good job at improving contributor documentation, but I consistently see some issues: - **Uses "This guide":** "This guide..." is no longer recommended based on discussions with Nik. Instead, recommendation is to omit those words while still including a value statement. I still do not recommend including a definition of the title term as an opening sentence. - **Mixed information types:** I still often see mixed information types or wordy, chunky paragraphs. Without a definition in place, my agent mistakenly thought there was just "Procedure, Context, and Reference." ## Solution - **A new Information types section** that clearly outlines definitions and usage with cross-references so that this guidance is not easily missed. - **Removed "This guide"** recommendation in favor of a value statement. Additionally added a clear rule about how to spell numbers consistently and gave more guidance about how to structure a large topic. ## Manual testing 1. Open [apps/docs/CONTRIBUTING.md](https://github.com/supabase/supabase/blob/docs/value-statements-and-counts/apps/docs/CONTRIBUTING.md) on this branch. The Information types section renders its table, the Recommendations list, and both fenced examples. 2. Click the two `Information types` links, one in General principles and one under Guides. Both jump to the section. 3. Open [apps/docs/WORD_LIST.md](https://github.com/supabase/supabase/blob/docs/value-statements-and-counts/apps/docs/WORD_LIST.md). The `numbers` entry sits under N, ahead of `numbers in product versions`. 4. Run `npx prettier --check apps/docs/CONTRIBUTING.md apps/docs/WORD_LIST.md` from the repo root. It reports no formatting changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Expanded the contribution guide with Information Mapping guidance for procedures, processes, principles, concepts, structures, and facts. - Clarified paragraph and section grouping, page-level classification, recommended ordering, navigation, transitions, outcomes, and connective prose. - Added guidance to use value-focused introductions and bold “Recommended” and “Not recommended” labels. - Added number-formatting guidance, including numeral usage, ranges, fractions, and when to omit step or item counts. - Updated related entries in the documentation word list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8dc9206f56 | docs(self-hosted): add custom oauth providers guide (#49971) | ||
|
|
9bf43188f1 | feat: Create first scaffolding around search v2 and feature flag addition (#50236) | ||
|
|
795b67b611 |
Docs/clone project r2np clarifications (#50471)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? r2np docs clarifications to https://supabase.com/docs/guides/platform/clone-project ## What is the new behavior? <img width="910" height="692" alt="image" src="https://github.com/user-attachments/assets/41026106-48c6-48bf-aca3-d2ff982c938d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated project restore guidance to clarify that binary restores copy the entire database and may immediately run extensions, scheduled jobs, webhooks, and wrappers. * Added guidance for using logical restores when definitions need inspection or removal beforehand. * Documented that manual dead-tuple recovery is unsupported due to potential constraint violations and data corruption. * Added recommended recovery paths for deleted rows using physical backups or point-in-time recovery. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
127e21b926 |
Changes by create-pull-request action (#44860)
Automated changes by [create-pull-request](https://github.com/peter-evans/create-pull-request) GitHub action Co-authored-by: ivasilov <568291+ivasilov@users.noreply.github.com> |
||
|
|
dca96ae929 |
docs: add the Deno optional peer note to the server installing page (#50412)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs, one new section on the `@supabase/server` Installing page. ## What is the current behavior? The Deno install instructions stop at `deno add jsr:@supabase/server`. A user who then imports `@supabase/server/middleware/postgres` on Deno or Edge Functions passes `deno check` and fails at startup with `Could not find package 'pg'`, because Deno resolves an optional peer only when the user's own code imports it. Nothing on the page says so. ## What is the new behavior? A new "Optional peer dependencies on Deno" row under the JSR section explains why, shows the bare `import 'pg'` at the top of the entry module, gives the `deno info` check, and notes the `--minimum-dependency-age 0` flag for same-day releases. Both hand-maintained copies of the partial are updated and stay identical: the spec partial for the reference site and the `docs/ref` copy for the markdown build. ## Additional context `pg` is the only optional peer a user can hit today. The MCP entry will add another once it ships and gets documented then. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Deno installation guidance for Postgres middleware that requires the optional `pg` dependency. * Clarified that importing `pg` directly is necessary for Deno to resolve it at runtime. * Added commands for verifying package resolution and handling Deno’s minimum dependency age checks. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2db6fbf410 |
test(studio): add e2e coverage for the storage move picker (#50460)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Tests, plus one small test hook in Studio. ## What is the current behavior? The Storage file explorer's move dialog was recently reworked: the free-text "Path to new directory" input was replaced with an embedded folder picker (folder browsing, bucket-wide folder search, a responsive breadcrumb, and a confirm button that targets the folder currently open). That work shipped with unit and component tests, but nothing exercises it end to end against a real bucket. ## What is the new behavior? New `e2e/studio/features/storage-move.spec.ts` with seven tests: | Test | What it covers | | --- | --- | | moves a file into a folder picked from the explorer | The core path: open the picker, click a folder, confirm, and assert the file left the root and landed in the destination | | offers folders only, never files, as destinations | Files are excluded from the listing entirely | | blocks confirming a move into the folder the file already sits in | The confirm button reports `aria-disabled` when the destination matches the source | | finds a nested folder by search and moves into it | Bucket-wide folder search, including the "`<folder>` in `<location>`" row label | | reports when a search matches no folders | The empty-search message instead of a blank list | | collapses the middle of a deep path into a breadcrumb dropdown | The responsive breadcrumb: bucket and the two deepest folders stay inline, the middle collapses, and picking a collapsed folder navigates to it | | walks back up the path with the up-one-level button | Disabled at the bucket root, and drops the deepest folder otherwise | Supporting changes: - `utils/storage/queries.ts` gains `uploadObject` and `seedBucket`. Storage has no standalone folders — a folder exists because an object sits under that prefix — so seeding a folder tree means uploading objects at the paths a test needs. Doing this through the API keeps setup off the UI, which is both faster and less flaky than clicking through "Create folder" for each level. - `utils/storage/client.ts` accepts a string body so object uploads can send raw content alongside the existing JSON requests. - `utils/storage-helpers.ts` gains `openMoveDialog` and `confirmMove`. - `MoveItemsFolderPicker.tsx` gains `data-testid="folder-picker-list"` on its list container. ## Additional context **Why the `data-testid`.** Once a path is deep enough for the breadcrumb to collapse, the breadcrumb renders crumb buttons whose accessible names are folder names — so `getByRole('button', { name: 'beta' })` scoped to the dialog can match either a folder row or a breadcrumb crumb depending on depth. Scoping row lookups to the list container removes that ambiguity. This follows the e2e guidance about adding explicit test hooks where a component lacks an unambiguous accessible name. **These tests have not been executed.** They were written against the merged implementation and verified as far as the environment allows: - `npx playwright test --list` collects all seven - `tsc --noEmit` is clean for the new spec and helpers (the pre-existing errors in `column-editor-types.spec.ts`, `table-editor.spec.ts`, and `wait-for-response-with-timeout.ts` are untouched) - Studio's unit and component tests (82) still pass, and typecheck, eslint, prettier, the lint ratchet, and knip are all clean The suite needs Docker to bring up the local Supabase stack, which wasn't available where this was authored, so a real run in CI is the first actual execution. Selectors were all read off the merged source rather than guessed, but timing assumptions in particular deserve attention on the first CI run. **One thing this surfaced, not fixed here.** The success toast reads `Successfully moved 1 files to docs` — it doesn't singularize. The tests assert on `/Successfully moved/` rather than the full string so they don't encode that, but it's worth a follow-up. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns --- _Generated by [Claude Code](https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns)_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Tests** - Expanded end-to-end coverage for moving files between folders in Storage. - Validated folder selection, nested-folder search, empty search results, collapsed breadcrumbs, and navigation to parent folders. - Confirmed files are excluded from destination choices and moving to the current folder is prevented. - Added coverage for creating isolated test buckets, uploading fixture files, and confirming successful move operations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
0e7cfac721 |
fix(shared-data): restore sign-in testimonial with correct avatar (#50466)
<!-- ccr-slack-attribution --> _Requested by **Alaister Young** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1789557911237269?thread_ts=1789557911.237269&cid=C0161K73J1J)_ ## Before The Studio sign-in page (`apps/studio/components/layouts/SignInLayout/SignInLayout.tsx`) shows a rotating testimonial next to the auth form, picking one tweet object from `packages/shared-data/tweets.ts` and rendering its `text`, `handle`, and `img_url` together. Two entries in the data file pointed at the *same* avatar image file (`JwLEqyeo_400x400.jpg`): one attributed to `orlandopedro_` and one to `pontusab`, despite being different people with different quotes. That file was confirmed (byte-for-byte) to actually be `pontusab`'s real photo, so `orlandopedro_` had no correct avatar checked in. ## First attempt The initial fix (this PR's first commit) removed the `orlandopedro_` entry entirely, since no verified avatar was available for that handle at the time, following this repo's precedent (PR #38500) for resolving this class of bug by deleting the erroneous entry. ## Correction Jordi confirmed the correct profile picture for `orlandopedro_` in the Slack thread, so instead of leaving the entry deleted, this PR now **restores** it with the correct avatar: - Added `apps/www/public/images/twitter-profiles/ZjIOtCGg_400x400.jpg` (downloaded from the user-provided URL), following the existing filename convention used by other entries in that directory (the image's own Twitter CDN slug + `_400x400.jpg`). - Restored the `orlandopedro_` object in `packages/shared-data/tweets.ts` (same quote text, handle, and URL as originally) with `img_url` now pointing at the new, correct image file. The `pontusab` entry is untouched throughout. ## Test plan - Verified the restored object diffs as an exact re-add of the originally removed entry, with only `img_url` changed to the new file. - Verified the downloaded image is a valid 400x400 JPEG. - Verified brace/object structure of `tweets.ts` is balanced after the edit. - Could not run `pnpm install` in this environment (blocked on `npm.jsr.io`), so lint/prettier/build were not executed; verified the diff manually instead. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01A1PbXuRBeaC7G3Mgb7X3eY --- _Generated by [Claude Code](https://claude.ai/code/session_01A1PbXuRBeaC7G3Mgb7X3eY)_ --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
a133ef60a6 |
fix(studio): correct the Assistant's blocked-tool privacy message (#50411)
When the Assistant calls a tool that's blocked on permissions, the response had two problems. First, it told users their data goes to Amazon Bedrock when production inference [routes to OpenAI](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/pages/api/ai/sql/generate-v4.ts#L170-L172). It now says "third-party AI providers" like the [opt-in settings](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/components/interfaces/Organization/GeneralSettings/AIOptInLevelSelector.tsx#L84-L88) do. I verified that was the last user-facing Bedrock mention. Second, HIPAA-restricted projects got that same copy telling them to change data opt-in settings, but for those projects `getAIDetails` [forces their level to `disabled`](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/lib/ai/ai-details.ts#L70-L73). They get separate copy now to prevent confusion. Closes AI-1154 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added HIPAA-aware AI controls for eligible projects. - AI opt-in is automatically disabled when HIPAA requirements apply. - Privacy messages now distinguish standard AI opt-in restrictions from HIPAA-related restrictions. - AI-assisted SQL and tool experiences consistently apply HIPAA restrictions when determining available capabilities. - **Bug Fixes** - Improved handling of AI settings for HIPAA-sensitive projects and invalid project or organization configurations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9cdd412bab | feat(stripe-atlas): mock-up dashboard to enable live testing (#50327) | ||
|
|
4432a8beb4 |
chore(studio): update Explorer feature preview copy (#50250)
Updates the Explorer feature preview copy to explain the SQL Editor transition, Notebooks, and Snippet migration plans. Adds feedback questions and moves the preview image above the content. Validation: Prettier and `git diff --check` passed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated the Explorer preview layout by moving the preview image below the introductory text. - Replaced feedback questions with a clear overview of what enabling the preview provides, including SQL Editor replacement and Notebooks management through the dashboard and Assistant. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
240bfce7f6 |
[FE-4198] feat(studio): select a range of logs with shift-click (#50381)
Shift-clicking a log row checkbox now selects every row between the last clicked row and the clicked one, so you can grab a consecutive block of logs to copy without checking each one. Applies everywhere the shared `LogTable` renders: Postgres/API/Auth/Edge Functions logs and the Logs Explorer. **Added:** - `getShiftClickSelection` in `Logs.utils.ts`: pure helper that computes the next selection from the ordered row keys, the current selection, the anchor row, and the clicked row. Adds the inclusive range in either direction. If the whole range is already selected it deselects the range instead. Falls back to a plain toggle when there's no usable anchor. Covered by unit tests, plus `LogTable` component tests for range select, the no-anchor fallback, anchor clearing, and range deselect. **Changed:** - `LogTable` tracks the last toggled row as the range anchor (a ref, since it's only read in handlers). The anchor is set by plain clicks, shift-clicks, and the Shift+Space row toggle, and cleared whenever the selection becomes empty (toggling off the last row, plain row click, Escape, action bar clear, select-all then deselect-all, or a new query loading). - The checkbox cell handles `onClick` instead of `onCheckedChange` so the shift key is available. Keyboard Space on a focused checkbox still toggles it, since Radix dispatches a click for it. - A shift mousedown on the checkbox cell is prevented so the browser doesn't start a text selection across rows. Unified Logs has its own row selection (TanStack Table) and is not changed here. ## To test - Open any log page with a decent number of rows, e.g. Postgres logs. Click one checkbox, then shift-click a checkbox several rows below. Every row in between should be checked and the action bar should show the count. Repeat upward. - Shift-click a range that's already fully selected: the range should clear, and rows outside it stay as they were. - Plain-click a row's message text (not the checkbox): side panel opens and the selection clears. A following shift-click should just toggle that one row. - Press Escape or the action bar's clear button, then shift-click: also just a single toggle. - Focus a row with the arrow keys, press Shift+Space, then shift-click a lower checkbox: the range should extend from the keyboard-toggled row. - Tab to a checkbox and press Space: it should still toggle. - After a shift-click, confirm no text is highlighted across the rows. - Copy as JSON/Markdown/CSV still copies the selected rows in display order. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added shift-click range selection to the logs table for selecting or deselecting consecutive rows. - Preserved single-row selection when range selection is unavailable. - Improved selection behavior when clearing selections or changing log queries, preventing stale range anchors. - **Tests** - Added coverage for forward and reverse range selection, deselection, partial selections, fallback behavior, and input immutability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
99be7f92ce |
feat(studio): add Privacy Policy update notice (#50397)
## Summary Adds a compact Privacy Policy update notice for signed-in Studio users on organization landing pages. - Shows on `/org`, `/organizations`, and `/org/:slug` - Opens the approved policy explanation in a dialog - Links to the Privacy Policy and `privacy@supabase.com` - Persists acknowledgement in a dated local storage key - Stays off project and organization settings routes so it cannot cover product controls ## Why The Privacy Policy changes the data controller from Supabase, Inc. to Supabase Pte. Ltd. User rights and protections are unchanged. This restores the established authenticated Studio notification pattern: - [#35923](https://github.com/supabase/supabase/pull/35923): May 2025 Privacy Policy notice - [#43681](https://github.com/supabase/supabase/pull/43681) and [#43889](https://github.com/supabase/supabase/pull/43889): March 2026 Privacy Policy notice and design pass - [#45632](https://github.com/supabase/supabase/pull/45632): May 2026 Terms of Service notice - [#48524](https://github.com/supabase/supabase/pull/48524): current reusable Studio banner stack ## Release order The policy content and Studio notice deploy independently. Keep this PR in draft until [#50392](https://github.com/supabase/supabase/pull/50392) is approved, merged, and live. The notice appears immediately when this Studio change deploys. ## To test 1. Open Studio on `/organizations` or an organization project-list page. 2. Confirm the compact Privacy Policy notice appears. 3. Open **Learn more** and confirm the dialog copy and both links. 4. Select **Understood** or close the notice. 5. Reload and confirm the notice remains dismissed. 6. Remove `privacy-policy-update-2026-09-16-dismissed` from local storage and confirm the notice returns. 7. Open a project route and confirm the notice is absent. ## Verification - Prettier passes on changed files. - ESLint passes on changed Studio files. - Focused Vitest suites pass: 25 tests. - Studio Unit Tests & Build Check passes. - TypeScript & Lint, UI Tests, Studio Docker Build, dead-code, ratchet, and validation workflows pass. - All four self-hosted Studio E2E shards pass for both router implementations. - All deploy previews pass. - The Studio preview rendered the compact notice on the organization landing page without console errors. The dialog and dismissal flow still need an authenticated browser pass after the session redirected to sign-in. A direct local Studio TypeScript check reaches one existing unrelated error in `packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx`; no changed file reports an error and the required TypeScript CI workflow passes. ## Measurement Success means signed-in users can find the updated policy from the organization landing experience without interrupting project work. The dated dismissal key confirms acknowledgement locally. CI protects the non-blocking route scope, and Privacy can monitor questions sent to `privacy@supabase.com` after release. --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com> |
||
|
|
adca15deab |
chore(www): add Privacy Policy v4 (data controller entity, Freebuff cookie) (#50392)
<!-- ccr-slack-attribution --> _Requested by **Sofia Calado** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1789462983606899)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update — a new version (v4) of the Privacy Policy legal page, added following the existing versioned-legal-page pattern (v1-v3 already present, selectable via a version dropdown). ## What is the current behavior? Before: On `/privacy`, the latest selectable version is "Version 3 — May 13, 2026". That text names "Supabase, Inc" as the entity you're dealing with — both in the opening paragraph ("Thank you for your interest in Supabase, Inc., ...") and again as the named data controller in the EEA/UK/Switzerland disclosures section ("Supabase, Inc is the data controller..."). The Section 8 cookie table (EEA cookies) lists nine cookies/rows (Stripe x3, Cloudflare x2, Youtube, hCaptcha, Posthog, Google Analytics 4, Google Ads, `_sb_first_referrer`) and does not mention Freebuff anywhere. ## What is the new behavior? After: `/privacy` gains a new "Version 4" entry in the dropdown, at the top of the list (selected by default). Reading Version 4, the same two passages instead name "Supabase Pte. Ltd." as the entity/data controller. The Section 8 cookie table gains one additional row for "Freebuff" (Type: Advertising; dropped when you visit the Site after interacting with a Freebuff ad; 30-day duration; purpose: measuring ad campaign performance and attributing conversions to ad clicks upon consent; linking to the Freebuff Privacy Policy), formatted identically to the existing rows. Versions 1-3 are unchanged and remain selectable. ## Additional context Two changes, scoped exactly as requested: 1. **Data controller entity**: every "Supabase, Inc" / "Supabase Inc." reference that names the data controller is replaced with "Supabase Pte. Ltd." — at the top of the policy and in the EEA disclosures section. No other "Supabase" references (e.g. plain brand mentions) were touched. 2. **Freebuff cookie row**: added to the Section 8 (EEA cookies) table, matching the existing table's markdown formatting exactly. **Open question — effective date needs Sofia/Nicole's input before merge.** No effective date was given for v4. The version-selector component (`LegalDocVersions`) requires a non-empty `effectiveDate` string per version to render (used both in the dropdown label and, for a single-version page, an on-page line) — there's no way to add the version without wiring some string. Following the pattern's convention of never inventing a plausible-looking date, `effectiveDate` is set to the literal placeholder `'TBD'` for v4 in `apps/www/pages/privacy.tsx`. **This must be replaced with a real effective date before this PR merges** — flagging for Sofia Calado / Nicole Kramer to confirm. **Validation**: `pnpm --filter=www build` fails in this sandbox due to an unrelated prebuild step (`docs` app's `build:federated-content` script needs live GitHub API credentials to fetch tags — 401 Bad credentials — not related to this change). `tsc --noEmit` on `apps/www` ran clean of any error touching `privacy.tsx` or the privacy `.mdx` files (all reported errors are pre-existing, about unrelated missing generated assets/images). As a direct substitute, all four `apps/www/data/legal/privacy/*.mdx` files (v1-v4) were compiled through the app's actual MDX pipeline (`@mdx-js/mdx` with the same `remark-code-hike` + `remark-gfm` + `rehype-slug` config as `next.config.mjs`) and all compiled successfully, confirming the new table syntax and content are valid MDX/GFM. Files touched: - `apps/www/data/legal/privacy/v4.mdx` (new) - `apps/www/pages/privacy.tsx` (added v4 to the `versions` array) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01BzHiVEUzjvrwxgnxCrrER1 --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
5e8e551e2c |
fix(www): include app routes in sitemap (#50277)
I added static App Router pages to the www sitemap, including the homepage, pricing, and product pages. The generator previously scanned only Pages Router and content files; it now strips route groups, excludes dynamic segments, and emits these URLs without lastmod. **Note:** The pre-existing Pages Router `/opt-out/[ref]` entry remains outside this change. ## To test Tested on the [www preview](https://zone-www-dot-com-git-pamela-growth-1214-app-rou-1d4879-supabase.vercel.app/sitemap_www.xml): - [x] Open `/sitemap_www.xml`: expect the homepage, `/pricing`, and product routes once each, without route-group names or lastmod on those entries. - [x] Compare the sitemap's changelog URLs with `/changelog-rss.xml`: expect every RSS item link to remain included, including text-slug entries. - [x] Open `/sitemap.xml`: expect the existing www and docs sitemap links. ## Linear - fixes GROWTH-1214 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Sitemap generation now includes static pages built with the Next.js App Router. - Route groups are correctly omitted from generated URLs. - Dynamic App Router routes are excluded from the sitemap. - **Bug Fixes** - Improved sitemap coverage and URL accuracy for applications using both App Router and Pages Router pages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c52fca1340 |
MFA Recovery codes: enforce recovery codes generation after setting up an MFA (#50343)
## What kind of change does this PR introduce? Afters users set up an MFA, automatically generate recovery codes ## How to test - On an account that doesn't have recovery codes generated yet, add a new MFA - When you finished verifying the MFA, it should automatically open the recovery codes modal introduced in previous PRs <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved the two-factor authentication setup flow by checking the latest recovery-code enrollment status before generating codes. - Recovery codes are now generated and displayed after verification when they are enabled but not yet enrolled. - Loading indicators now reflect recovery-code status checks, providing clearer feedback during setup. - **Improvements** - Updated the recovery-code confirmation message to explain how codes can restore access after losing access to an MFA app and remind users to store them securely. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ee3fbc4e61 |
Joshenlim/fe 4383 consolidate tablerow no search result state (#50389)
### Context Just some housekeeping/consolidate refactors. There's a number of places where we render the same "no result" empty state for tables. So this PR just consolidates that into a reusable component `TableRowNoResults` to reduce duplication. Opting to save this under `components/ui` instead of the `ui` package as this is more of a derivation of `TableRow` than a primitive <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **UI Improvements** - Standardized empty search-result messages across database, functions, storage, and vector bucket tables. - Search terms now appear consistently when no matching records are found. - Added an accessible label to the vector bucket row actions menu. - Improved the storage explorer loading layout so content expands to use available vertical space. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
881a7d3151 |
fix(studio): show only the disabled reason on the invite members button (#50426)
The invite members button sits inside two Radix tooltip roots — the keyboard-shortcut tooltip and the disabled-reason tooltip — which both anchor to the same element and stack on top of each other when the user lacks invite permission. Widened the existing `tooltipOpen` condition so the shortcut tooltip stays closed whenever a disabled reason is showing, and hoisted that reason into one variable so the tooltip text and the suppression condition can't drift. Fixes FE-4393 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Disabled member invitations now prevent the invite button and keyboard shortcut from opening the invite dialog. * Invite controls display the appropriate disabled-feature or permission warning. * Shortcut tooltips are hidden when invitations are unavailable or the user lacks permission. * **Tests** * Added coverage for disabled invitations, permission warnings, dialog prevention, and shortcut tooltip visibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Fixes: https://github.com/supabase/supabase/issues/49859 |