Commit Graph
7151 Commits
Author SHA1 Message Date
Danny White ed8ac5bb90 chore(design-system): preserve icon fill or stroke (#43417)
## What kind of change does this PR introduce?

Bug fix: custom icons now respect their source SVG’s stroke/fill and
stroke-width instead of always getting a global stroke.

## What is the current behavior?

Every custom icon gets `stroke="currentColor"` and `strokeWidth={2}`
from `createSupabaseIcon`, so fill-only logos get an extra stroke and
icons designed at `stroke-width="1"` (e.g. postgres, auth) render too
thick. Call sites and the design-system grid needed workarounds
(`strokeWidth={0}`, `FILL_ONLY_ICONS`, `STROKE_WIDTH_FROM_SOURCE`).

## What is the new behavior?

The icon build reads root SVG attributes (`fill`, `stroke`,
`stroke-width`, etc.) and passes them as per-icon defaults. Fill-only
icons (chatgpt, claude, axiom, last9) have `stroke="none"` in source and
render with no stroke; stroke icons keep their source stroke-width (e.g.
postgres at 1). No `strokeWidth={0}` or allowlists needed at call sites
or in the icon grid.

| Before | After |
| --- | --- |
| <img width="1826" height="552" alt="CleanShot 2026-03-05 at 10 53
31@2x-3D63CEF0-1132-44F5-A382-730346432F1E"
src="https://github.com/user-attachments/assets/9caf73fa-351b-4ea2-a420-b3339f934742"
/> | <img width="1814" height="552" alt="CleanShot 2026-03-05 at 10 53
40@2x-514FC8BD-D30F-4D23-B209-0ECD6D13A184"
src="https://github.com/user-attachments/assets/936ea5a5-dae0-413f-8545-b90a502cea69"
/> |

## Additional context

- Added `stroke="none"` to the four fill-only source SVGs;
sentry/grafana/otlp/datadog already had `stroke-width="0"`.
- `createSupabaseIcon` only applies `color`/`strokeWidth` when the
consumer passes them, so `svgDefaults` from the build are used
otherwise.
- Removed workarounds from `icons.tsx` and GuidesSidebar; updated
icons.mdx (defaults + fill-only guidance).
2026-03-09 10:26:59 +11:00
Cam MichieandCam Michie 3bd3c3412e Add name Cameron Michie to humans.txt (#43380)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Add my name to humans.txt

## What is the current behavior?

n/a
## What is the new behavior?

n/a
## Additional context

n/a

Co-authored-by: Cam Michie <cammichie@Cams-MacBook-Pro-2.local>
2026-03-06 12:21:21 +01:00
Taryn King 173a939cc3 chore(docs): add circuit breaker error reference (#43362)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Small docs update to troubleshooting guide. Adds circuit breaker error
to list of related errors that troubleshooting guide addresses.
2026-03-06 12:10:41 +01:00
Danny White a832d62785 chore(studio): update Claude icon and minify dark icons (#43422)
## What kind of change does this PR introduce?

- UI fixes and cleanup

## What is the current behavior?

- We use the _Anthropic_ logo for _Claude Code_ in the MCP connector
panel
- We have a bunch of redundant dark mode logos (visually the same as
their light mode siblings)

| Before | After |
| --- | --- |
| <img width="987" height="373" alt="Krosno Toolshed
Supabase-03CD5E6F-53E6-4282-9087-ACB9F67B6DDA"
src="https://github.com/user-attachments/assets/ca7b5d9c-2a2b-4520-8bd4-8cf26c759c73"
/> | <img width="987" height="373" alt="Krosno Toolshed
Supabase-53F3849B-2D86-494B-BE25-8D23EA050243"
src="https://github.com/user-attachments/assets/7bd2e9a6-82ae-48a1-9ef1-591b7a33632e"
/> |

## What is the new behavior?

- We use the _Claude_ logo for _Claude Code_
- Removed duplicative logos
- Made note of which MCP servers have a different logo for dark mode
2026-03-06 14:00:04 +11:00
Danny WhiteandJoshen Lim 503c01b5bc chore(studio): refactor oauth apps page and table (#43366)
## What kind of change does this PR introduce?

UI update.

## What is the current behavior?

The org’s /apps page is glaringly out of date compared to similar pages.
It uses old page and layout components.

## What is the new behavior?

- Refactored /apps to use latest
[layout](https://supabase.com/design-system/docs/ui-patterns/layout) and
[table](https://supabase.com/design-system/docs/components/table)
components

Unrelated minor changes snuck in:

- Global `pnpm format` to properly format recurring annoyances elsewhere
- Minor polish on org tiles (pictured)

| Before | After |
| --- | --- |
| <img width="1728" height="997" alt="OAuth Apps
Supabase-30B6CDAE-4954-40F8-886A-939797999AA6"
src="https://github.com/user-attachments/assets/163c2787-f6ab-4a0b-80aa-af81260bdf9f"
/> | <img width="1728" height="997" alt="OAuth Apps
Supabase-7DD241E0-262A-4817-91B2-D2A299F8EB93"
src="https://github.com/user-attachments/assets/29928305-9110-4256-8663-c3821e696587"
/> |
| <img width="1728" height="997" alt="OAuth Apps
Supabase-9870816A-8022-479D-8011-236A813249AB"
src="https://github.com/user-attachments/assets/32e41835-59bc-4d83-92eb-635b98c5f4a5"
/> | <img width="1728" height="997" alt="OAuth Apps
Supabase-21CFBC16-E850-44A6-BEFF-C4FBED8ACB43"
src="https://github.com/user-attachments/assets/6999e2a0-ea17-44cb-99f2-42f985354589"
/> |
| <img width="1152" height="664"
alt="Supabase-9DD87028-2D46-47D0-8546-240184E1711B"
src="https://github.com/user-attachments/assets/2c7d8b2a-280f-48d6-9f78-19c519cf4654"
/> | <img width="1152" height="664"
alt="Supabase-F1C92F66-C602-4DC9-B3B4-AE3FB673276E"
src="https://github.com/user-attachments/assets/0a24a98e-386f-4ada-b282-0a59b159bbab"
/> |

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-03-06 12:23:33 +11:00
Danny White 406be76af0 chore(docs): LLM icons (#43416)
## What kind of change does this PR introduce?

UI update.

## What is the current behavior?

https://github.com/supabase/supabase/pull/43355 introduced “Copy to
ChatGPT” and “Copy to Claude” buttons with the general `ExternalLink`
Lucide icon each.

## What is the new behavior?

Branded icons for each, so users can quickly skim the sidebar for their
LLM of choice.

| Before | After |
| --- | --- |
| <img width="1152" height="662" alt="Database Supabase
Docs-0BAB1226-CCD6-4022-9383-1C323C83475D"
src="https://github.com/user-attachments/assets/efba85e7-1b82-4faa-a460-fd1d07448064"
/> | <img width="1152" height="662" alt="Database Supabase
Docs-44494743-65AE-40BF-AE19-375A2E5F7665"
src="https://github.com/user-attachments/assets/968180b1-ef31-46d4-84d9-bf2819a24fc4"
/> |
2026-03-06 00:25:55 +00:00
Aaron Brooks c4eee6d63e chore: Add "Aaron Brooks" to humans.txt (#43363)
Hey, I can't help that my name is alphabetically the first — in school
this meant I always had to give presentations first. Not fun!

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

On-boarding addition of my name (Aaron Brooks) to humans.txt

## What is the current behavior?

Aaron Brooks is not part of humans.txt

## What is the new behavior?

Aaron Brooks is part of humans.txt
2026-03-05 12:37:40 -05:00
Thomas HammerlandChris Chinchilla dfdfe279df docs: Fix SQL queries in realtime documentation (#41519)
I'm relatively new to supabase, but in my current understanding the SQL
selects are inconsistent with the given example schema as the column is
named `room_topic` there.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

Yes.

## What kind of change does this PR introduce?

Updates documentation.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Documentation**
* Corrected authorization policy examples in realtime guides to use
accurate column references for topic-based access control in Broadcast
and Presence features.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-03-05 17:05:45 +01:00
Monica Khoury a51470ca52 docs(storage): add S3 CLI method for bulk storage operations (#43402)
Added an alternative approach using the Supabase S3-compatible API and
AWS CLI for bulk operations such as downloading, moving, and
reorganizing objects in a bucket.

Linear task:
https://linear.app/supabase/issue/DOCS-725/update-storage-troubleshooting-doc-with-bulk-operation-workaround.
2026-03-05 14:54:22 +01:00
Chris Chinchilla d6006f9d08 docs: Update Remix SSR example code (#43351)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
2026-03-05 14:20:15 +01:00
TheOtherBrian1 d272224bc3 docs: updating egress troubleshooting guide (#43420)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs Update

## What is the current behavior?

There is a troubleshooting guide on egress

## What is the new behavior?

Just made light modifications to the troubleshooting guide

## Additional context

None really. Just added a few small corrections and rewordings
2026-03-05 09:32:53 +01:00
Jeremias Menichelli 45fd69d9cf fix(Docs): Avoid empty URL on AI links (#43399) 2026-03-04 17:03:43 +00:00
Alex Hall aa73bf2f7b Add Alex Hall to humans.txt (#43393)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adding myself to humans.txt
2026-03-04 11:06:06 -05:00
Jeremias Menichelli 8b4bf646fc feat(Docs): Add copy as markdown and AI tools to guide (#43355) 2026-03-04 16:31:02 +01:00
Chris Chinchillaandcoderabbitai[bot] 558ed3859b docs: Update backup docs to be physical by default (#43188)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-03-04 13:32:41 +01:00
Chandana Anumula 088fca231d Update auto-generated-docs.mdx to display the new UI (#43373)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

Shows the old UI instructions and video

## What is the new behavior?

Updated with new UI instructions and video

## Additional context

Add any other context or screenshots.
2026-03-04 17:48:05 +05:30
Johan Bergström 69f1926023 chrore(docs): add myself to humans.txt (#43214) 2026-03-04 11:56:51 +00:00
Joaquim Moreno Prusi 33962ca6a4 chore: add myself to humans.txt (#43353)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds Joaquim Moreno to the `humans.txt` list.
2026-03-04 12:52:48 +01:00
Andrey A. 2fcf513ab6 fix: reformat yaml and clarify testing in self-hosted oauth how-to 2026-03-04 11:17:03 +01:00
Andrey A.andChris Chinchilla 001faf98b6 docs: add https proxy how-to for self-hosted (#43293)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Add a new how-to guide covering PR #43291
- Explain how to use an https proxy on top of [self-hosted
Supabase](https://supabase.com/docs/guides/self-hosting) API gateway
(Kong)

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-03-03 17:09:46 +00:00
28808d2c9f docs: add oauth and otp how-to guides for self-hosted (#43286)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Add two new how-to guides covering OAuth and OTP/MFA configuration for
[self-hosted Supabase](https://supabase.com/docs/guides/self-hosting)
- Add placeholder environment variables to `.env.example` and
`docker-compose.yml`

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-03-03 17:33:20 +01:00
Adam Mohammed d4263290cb Add Adam Mohammed to humans.txt (#43349)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

👋 Excited to start contributing!
2026-03-03 10:10:54 -05:00
Giuseppe Mandato eecae9c9d0 feat(humans): add giuseppe (#43346)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds @hitmands to the humans.txt
2026-03-03 16:04:38 +01:00
Joel Martin baffaa5f7b Add Joel Martin (me) to humans.txt (#43307)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

humans.txt addition (me)
2026-03-03 15:41:50 +01:00
Illia Basalaiev bb10862e07 chore: update jwt expiration link in the user sessions docs (#43338)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

This can be customized in your project's Auth settings in the Advanced
Settings section.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

This can be customized in your project's settings in the JWT Keys >
Legacy JWT Secret section.

- /docs/guides/auth/sessions
2026-03-03 12:18:01 +01:00
Kevin Grüneberg 589cdae7e5 chore: log drains on Pro Plan (#42435) 2026-03-03 19:10:23 +08:00
Chris ChinchillaandEmil Wåreus 92d7d20be1 docs: add information about storage in oauth app scope documentation (#43330)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

Recreation of https://github.com/supabase/supabase/pull/39706 as I am
unable to resolve the merge conflict in that PR.

---------

Co-authored-by: Emil Wåreus <emil.wareus47@gmail.com>
2026-03-03 11:32:10 +01:00
Chris Gwilliamsandgithub-actions[bot] 81415c6053 Blog: Add Timescale to pg_partman migration guide (#40037)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Blog post on using pg_partman instead of TimescaleDB to prepare for the
upcoming deprecation

## What is the current behavior?

## What is the new behavior?

Blog post to include migration information for those using Timescale

## Additional context

Not to be merged until pg_partman is released in 15 and 17 images


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a comprehensive pg_partman guide covering setup, time- and
integer-based partitioning, maintenance, automation, and resources.
* Added a migration guide for moving from TimescaleDB hypertables to
native PostgreSQL partitioning using pg_partman.
  * Updated TimescaleDB docs with migration notes and support guidance.
* **New Features**
* Listed pg_partman in the public extensions reference and added
navigation entries linking to the pg_partman guide and migration guide.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-03 11:47:50 +02:00
732180608a Fix some typos; update passages to conform to style guide (#43254)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

**YES**

## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

N/A

## What is the new behavior?

N/A

## Additional context

N/A

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-03 09:41:18 +00:00
Jeremias Menichelli f5667ac450 fix(Docs): Make code tags sync generated (#43282) 2026-03-02 18:37:25 +01:00
a2d0eafcc4 fix(docs): replace deprecated getSession with getClaims in Refine tutorial (#43203)
## What kind of change does this PR introduce?

Documentation update

## What is the current behavior?

The Refine tutorial uses `supabaseClient.auth.getSession()` in the
`authProvider.check` method to verify authentication. `getSession` is
deprecated and not recommended for auth verification.

## What is the new behavior?

Replaced `getSession()` with `getClaims()` which reads claims from the
locally cached JWT. This is the recommended approach as mentioned in the
issue.

## Files changed

- `apps/docs/content/guides/getting-started/tutorials/with-refine.mdx` —
Updated `check` method in the authProvider code example
-
`examples/user-management/refine-user-management/src/providers/auth-provider.ts`
— Updated the corresponding example code to match

Closes #42193

---------

Co-authored-by: gorillaworkout <bayudarmawan215@gmail.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-03-02 11:14:50 +01:00
supabase-supabase-autofixer[bot]andsupabase-releaser[bot] 73b829c2cd docs: update js sdk docs (2.98.0) (#43213)
Updates JS sdk documentation following stable release. 
Ran `make` in apps/docs/spec to regenerate tsdoc files.

**Details:**
- **Version:** `2.98.0`
- **Source:** `supabase-js-stable-release`
- **Changes:** Regenerated tsdoc files from latest spec files

🤖 Auto-generated from @supabase/supabase-js stable release.

Co-authored-by: supabase-releaser[bot] <223506987+supabase-releaser[bot]@users.noreply.github.com>
2026-02-27 11:04:51 +01:00
Danny White 0a96a5d0ce chore(studio): polish database settings (#42970)
## What kind of change does this PR introduce?

UI update

## What is the current behavior?

- Database settings uses an older, much wider, layout
- This will become problematic later on as more complex elements are
added to the page
- Titles and descriptions are inconsistently formatted

## What is the new behavior?

| Before | After |
| --- | --- |
| <img width="1728" height="994" alt="Oldie 2 Toolshed
Supabase-EE998752-3696-45E4-A842-9666049153D8"
src="https://github.com/user-attachments/assets/8f0004cf-3bb4-4b00-900a-b116b80371a6"
/> | <img width="1728" height="994" alt="Oldie 2 Toolshed
Supabase-7E86FD58-35BB-4912-8B2F-8C7AAA03B462"
src="https://github.com/user-attachments/assets/606b51b4-21a0-4b7b-870b-ac92ed363f3c"
/> |
2026-02-27 11:16:02 +11:00
Dovudkhon/ドフドコン 8d5e366387 Update a typo in the apps/docs/content/guides/storage/buckets by fixi… (#43130)
…ng 'a authorization' to 'an authorization'''

Fixed a minor grammatical error in
`apps/docs/content/guides/storage/buckets` where "a authorization" was
incorrectly used instead of "an authorization".

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

It is a typo fix in the docs

## What is the current behavior?

There are no issues concerning the performance. Just a minor grammar
mistake
## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

<img width="863" height="431" alt="Screenshot 2026-02-24 at 20 42 00"
src="https://github.com/user-attachments/assets/364a405c-ea60-41cf-a6ec-b83f0ed3f6ab"
/>

Add any other context or screenshots.
2026-02-26 15:27:45 +00:00
Chris PraasandChris Chinchilla e1b51dff81 added CLI example for generating types with self-hosted instance
Docs Update. Added a example for generating types with self-hosted
instance.

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-26 12:20:29 +01:00
Andrey A. aa1aa73200 update .env.example with better comments 2026-02-25 21:44:45 +01:00
Andrey A. b5cb4548b6 add a how-to for self-hosted edge functions 2026-02-25 21:44:19 +01:00
ce980f1724 Modified past webinars and landing page to include YouTube embeds (#43191)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

I modified previous webinars to include the following:
- A YouTube embed of the recording
- New "Watch the Recording" CTA buttons
- New slug for the go page `/vibe-coding-done-right-webinar`

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-25 20:17:00 +00:00
Ivan Vasilov 87ee98ed3d fix(proxy): remove first-referrer cookie stamping from Studio and Docs middleware (#43190)
Summary
- Reverts the middleware changes to `apps/studio` and `apps/docs` from
#43153 that caused full page reloads on every client-side navigation in
Studio
- Root cause: broadening the `middleware` matchers to match all routes
and returning `NextResponse.next()` unconditionally interferes with
client-side navigation in the multi-zone production setup (`www` proxies
`/dashboard/*` → Studio, `/docs/*` → Docs)
- Cookie stamping is unnecessary in Studio and Docs because `apps/www`
sits in front of both apps in production and already handles
first-referrer cookie attribution for all incoming traffic
- The `apps/www` middleware, packages/common cookie utilities, and
telemetry changes from #43153 are left intact

Test plan
- Verify client-side navigation works without full page reloads in
Studio (production or preview deploy)
- Verify first-referrer cookie is still stamped via `www` middleware on
initial visit
2026-02-25 20:56:50 +01:00
Charis d95127982d chore: add sean romberg to humans.txt (#43181) 2026-02-25 18:58:16 +00:00
Sean Oliver 75ec7c6e6b feat(growth): re-land first-referrer cookie attribution with fixed middleware matchers (#43153)
## Summary

Re-lands the first-referrer cookie feature from #42768 (reverted in
#43129) with middleware matcher fixes that prevent Studio traffic
interference.

**Tracks:** [GROWTH-651](https://linear.app/supabase/issue/GROWTH-651)

## What changed

New shared module in `packages/common/first-referrer-cookie.ts` that
handles stamping and parsing a first-referrer cookie (referrer, UTMs,
click IDs, landing URL). Each app's middleware calls
`stampFirstReferrerCookie` on the edge response — www and docs are the
primary entry points, Studio is a fallback for direct visits with UTMs.

On the telemetry side, `handlePageTelemetry` now takes an options object
instead of positional args, reads the cookie on initial pageview, and
overrides the referrer if the cookie captured an external source but the
current referrer is internal (i.e., the user navigated cross-app). Also
sends `first_referrer_cookie_present`/`consumed` properties so we can
observe the handoff in PostHog.

The docs middleware matcher was broadened from `/reference/:path*` to
all docs pages so we stamp cookies site-wide, not just on reference
paths.

## Root cause of original revert

Two layers:

1. **Matcher gap**: www middleware ran on `/dashboard/*` traffic in prod
due to Vercel Multi-Zone architecture (www is the gateway for
`supabase.com`, proxying `/dashboard` → Studio, `/docs` → Docs).
Middleware runs *before* rewrites, so www middleware executed on all
proxied traffic.

2. **`_next/data` interception**: The matcher didn't exclude
`_next/data` paths. Client-side navigation in Next.js fetches JSON via
`/_next/data/...` — middleware intercepted these, returned
`NextResponse.next()` with cookie mutations (which processes through the
middleware response pipeline), and this interfered with the JSON
responses, causing full page reloads in the SQL editor.

## How this PR fixes it

| Fix | Detail |
|---|---|
| Exclude `_next/data` | All three matchers (`www`, `docs`, `studio`)
exclude `_next/data` via negative lookahead |
| Exclude `dashboard` + `docs` from www | www middleware no longer runs
on proxied app traffic |
| `/api/` path guard in Studio | Broadened matcher requires explicit
path check for API route filtering |
| `NextResponse.next()` semantics | Cookie stamping only happens on
matched paths; unmatched paths never enter middleware |

### `NextResponse.next()` vs `undefined` nuance

Returning an explicit `NextResponse.next()` with cookie mutations
processes through Next.js's middleware response pipeline (headers are
merged, cookies are set). Returning `undefined` (i.e. the request never
matches the matcher) lets Next.js handle the request completely
untouched. The matcher exclusions ensure `_next/data` and proxied app
paths never enter middleware at all.

## Testing

- ✅ 22 unit tests for shared cookie utilities (all pass)
- ✅ Studio prod build succeeds, middleware recognized as `ƒ Proxy
(Middleware)`
- ✅ Playwright validation: client-side navigation works across 3 page
transitions, `_next/data` requests return 200 OK without middleware
interception, no full-page reloads
- ❌ www/docs SSG builds require platform backend services (expected —
same as master)
2026-02-25 09:24:32 -08:00
Charis 9923496486 chore: update prose linter (#43147) 2026-02-25 09:39:21 -05:00
Mert YEREKAPAN df8729a82b chore(studio): remove Flag component and related context/hooks (#43103)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore / dead code removal

## What is the current behavior?

The `apps/docs/components/Flag/` directory contained legacy feature flag
code that was never wired up:

- `FlagProvider.tsx` — all ConfigCat logic commented out; only wraps
children in an empty context
- `FlagContext.ts` — an empty `createContext({})` with no values ever
set
- `Flag.tsx` — a gate component that reads from the above empty context,
so flags always evaluate to falsy
- `hooks/useFlag.ts` — references the dead local `FlagContext` instead
of `common`'s `FeatureFlagContext`

The docs app already uses `FeatureFlagProvider` from the `common`
package (configured in `apps/docs/features/app.providers.tsx`), making
this entire local implementation obsolete.

Closes
[GROWTH-611](https://linear.app/supabase/issue/GROWTH-611/clean-up-deadlegacy-flag-code-in-docs-app)

## What is the new behavior?

The dead code is removed:

- `apps/docs/components/Flag/` directory deleted
- `apps/docs/hooks/useFlag.ts` deleted

Any code needing feature flags should import `useFlag` directly from
`common`.

## Additional context

No flag-gated features were affected — the old local implementation was
non-functional (context always resolved to `{}`), so removing it has no
behavioral impact.
2026-02-25 09:13:50 +00:00
slegarragaandChris Chinchilla d727d33db9 docs: replace deprecated getSession with getClaims in SolidJS tutorial (#43034)
Fixes #42192

Replaces the deprecated `getSession` call with `getClaims` in the
SolidJS tutorial documentation (`with-solidjs.mdx`).

Changes:
- `supabase.auth.getSession()` → `supabase.auth.getClaims()`
- `data.session` → `data.claims`

This follows the recommended migration pattern per the Supabase auth
docs, and is consistent with the same fix applied to the Refine tutorial
in #43006.

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-25 08:30:14 +01:00
Prashant SridharanandAlan Daniel b1f93226bb Added video embeds of previous webinars (#43134)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

We are now saving our old webinar videos as unlisted YouTube videos.

I added the video embeds to previous webinars.

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-02-24 21:52:32 +00:00
lmoss-sb 864f4216ac Add Lindsay, self, to humans.txt (#43152)
New hire to support team
2026-02-24 18:36:02 +00:00
Charis d72d70aec6 chore: add sana to humans.txt (#43143) 2026-02-24 14:28:05 +00:00
Cemal Kılıç d810b7772b feat(docs): token_endpoint_auth_method in OAuth server docs (#43128)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## Summary
The OAuth server supports three token endpoint authentication methods
(`none`, `client_secret_basic`, `client_secret_post`), but the docs only
showed `client_secret_post` implicitly without labeling it, and never
mentioned client_secret_basic (the actual default for confidential
clients per RFC 7591).

- Add `token_endpoint_auth_method` explanation with defaults/constraints
to the client registration section in getting-started.mdx
- Update registration examples (JS, Python, cURL) and response JSON to
include token_endpoint_auth_method
- Restructure token exchange and refresh token sections in
oauth-flows.mdx to show all three auth methods with clear labels
- Add `client_secret_basic` examples using HTTP Basic auth header
2026-02-24 17:29:47 +05:30
Ivan Vasilov 85e6b1143f chore: Revert "fix: persist first referrer across app boundaries (#42768)" (#43129)
This reverts commit
https://github.com/supabase/supabase/commit/04e63dfb2e00c43f8c57e538b8056aa647f4e5b4
since it was causing the Studio app to rerender the full page on every
link navigation.
2026-02-24 11:56:44 +00:00
Prashant SridharanandAlan Daniel 14d36e9480 Bolt webinar cta page (#43107)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

New Go landing page for the upcoming Bolt webinar. This is where we will
direct customers who want to learn more to go to request a meeting.

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-02-24 10:50:54 +00:00