Both shims still degrade to a plain <img> (Vite has no Next image
optimizer), but the prop surface now matches the real APIs so consumer
code compiles and behavioural defaults line up with Next.
Added across both:
- forwardRef so callers can take an HTMLImageElement ref.
- \`loader\` prop that, when provided, is called with { src, width,
quality } to build the final src URL.
- \`onLoadingComplete\` callback fired on image load, plus an effect
that fires it on mount when the image is already cached.
- \`unoptimized\` accepted-and-dropped (no optimizer to disable).
- \`sizes\`, \`quality\`, \`placeholder\`, \`blurDataURL\` typed and accepted.
- \`priority\` now drives loading='eager' + fetchPriority='high';
\`loading\` honoured when explicitly set, otherwise defaults to 'lazy'
matching Next.
- Object-form src ({ src, width, height }) supported in addition to
string.
next/image-specific: \`fill\` flag still stretches the image to its
container.
next/legacy/image-specific: \`layout\` / \`objectFit\` / \`objectPosition\`
preserved.
Comprehensive replacement for the prior thin (NextResponse.json + type
NextRequest = Request) shim. Most of this surface isn't exercised at
runtime under TanStack — middleware doesn't run, App Router routes
only ever called .json() — but the imports need to resolve to real
values so consumers compile and don't crash if invoked.
NextResponse:
- json (existing)
- next(init?) — returns an empty 200 placeholder. Middleware calls this
to "continue", and accepts a request: { headers } bag we strip before
handing to Response().
- redirect(url, init?) — sets Location header, defaults to 307, validates
the status against the redirect set Next allows.
- rewrite(destination, init?) — encodes the rewrite via the
x-middleware-rewrite header that Next's runtime expects.
- error() — 500 placeholder.
NextRequest is now a runtime value (alias to the Request constructor)
so value imports compile cleanly under verbatimModuleSyntax /
isolatedModules, in addition to the existing type alias.
NextMiddleware and MiddlewareConfig type stubs added so type-only
imports of those don't need to special-case the shim.
- Add the .preload() static that Next stamps on the returned component
so consumers can trigger the loader ahead of render (e.g. on hover).
- Cache the loader promise so preload() + render share one import
rather than triggering two. Matches Next's behaviour.
- Accept-and-drop \`suspense\` and \`loadableGenerated\` options so call
sites passing them don't fail TypeScript.
- Forward ref so consumers using anchor refs (focus management, etc.)
keep working.
- Map Next's \`replace\` prop to TanStack's \`replace\` option (was being
dropped silently).
- Map Next's \`prefetch\` prop to TanStack's \`preload\`:
prefetch=true | "auto" → preload="intent" (closest to Next's
hover-prefetch default in production)
prefetch=false → preload=false
prefetch undefined → use TanStack's default
- Honour \`legacyBehavior\`: clone the single child element with the
resolved \`href\` and merged onClick, so consumers passing their own
custom anchor child get the same behaviour Next provides. Previously
legacyBehavior was silently ignored, which produced nested-anchor
output for some shadcn primitives.
- \`passHref\` without legacyBehavior is documented as a no-op in modern
usage (TanStackLink renders the anchor anyway).
Comprehensive replacement for the prior thin shim. Adds the full
app-router useRouter (replace / refresh / back / forward / prefetch
in addition to push), useParams (was missing — already imported by
studio source), useSelectedLayoutSegment / useSelectedLayoutSegments
(approximated from active matches' route id), notFound / redirect /
permanentRedirect / RedirectType.
`refresh()` maps to TanStack invalidate(). `redirect`/`notFound` throw
errors tagged with the same Symbol.for('next.*') digests Next uses, so
any code that introspects `err.digest` continues to recognize them.
Client-side `redirect` also performs a real navigation since we have no
RSC renderer to intercept the throw.
Comprehensive replacement for the prior thin shim. Adds the full
pages-router useRouter surface so call sites that reach for less common
fields don't blow up at render:
State: pathname, route, query, asPath, basePath, isReady (always true —
TanStack resolves params synchronously), isFallback / isPreview /
isLocaleDomain (static false, no equivalent), locale / locales /
defaultLocale / domainLocales (undefined, no i18n wiring), events.
Methods: push/replace now accept Next's (url, as?, options?) signature
and return Promise<boolean>. UrlObject inputs are flattened the same
way next/link already does (pathname + search + hash). Adds reload,
back, forward, prefetch (mapped to TanStack preloadRoute, errors
swallowed to match Next's fire-and-forget), beforePopState (accepted
and discarded — escape hatch nothing in studio currently uses).
Memoize the returned object so callers using it as an effect dep don't
re-run on every parent render.
next/compat/router (Next's NextRouter|null variant) re-exports the
single useRouter to keep the surface in sync. We always have a router
under TanStack so the null return path doesn't apply.
Next's pages-router useRouter() returns both \`pathname\` and \`route\`
holding the bracketed route pattern (always the same value in pages
mode). Our compat shim only exposed \`pathname\`, so studio call sites
that read \`router.route\` (AppLayout/BranchLink, AppLayout/ProjectDropdown)
got \`undefined\` and crashed when sanitizeRoute() did \`route.split('/')\`.
Surfaced when opening the project selector dropdown — BranchLink
errored at render and tripped the route's ErrorBoundary.
Mirror \`pathname\` into \`route\` in both shims (next/router and
next/compat/router).
New tracker doc (peer to TANSTACK_MIGRATION.md) for circular-import
findings hit during the migration so they can be lifted into a follow-up
PR. Convention going forward: one fix per commit, source comments
prefixed with "Circular-dep workaround:" for grep, and an entry in this
file recording symptom / root cause / commit / what a real fix would
look like.
First entry documents the cva-not-a-function chunk cycle in the ui
package and the manualChunks workaround that already lives in
vite.config.ts (commit 3662e52f62). Investigation summary (madge clean,
no source-level 'ui' self-imports inside packages/ui/src/, no Rolldown
circular warnings) explains why no source-level fix is being attempted
on the migration branch — the cycle is purely a Rolldown chunk-output
artifact, and the structural alternatives (splitting the ui barrel,
moving TreeView/utilities to sub-exports) are all breaking changes
across the monorepo.
Also retags the existing comment in apps/studio/vite.config.ts to start
with "Circular-dep workaround:" so it's discoverable.
- Adds routes/project/$ref/database/triggers.tsx as a sub-shell that
inlines the inner part of DatabaseTriggersLayout (PageLayout + the
permission gate + nav items). Can't re-use DatabaseTriggersLayout
directly because it internally wraps in <DatabaseLayout title="Triggers">,
which would double-wrap under the database.tsx shell. The Next-side
component is left untouched.
- Adds 3 leaves: triggers/{index,data,event} as Path-A re-exports.
- Forces `class-variance-authority` into its own chunk via Rolldown
manualChunks. Without this, adding the triggers shell nudges Rolldown
into a chunk layout where TreeView is split out and imports `cva`
back from the `ui` chunk while `ui` imports `TreeView` — a bundle-
level circular dep that leaves `cva` undefined when TreeView's
top-level cva(...) initializer runs at SSR prerender. Source has no
cycle; this is purely a chunking artifact. Pinning cva to its own
chunk breaks the cycle and is robust against future chunk shifts.
6 routes — tables, publications, replication — each with an index leaf
and a dynamic-segment leaf. All Path-A re-exports under DatabaseLayout
sibling-file shell.
styles/fonts.css holds the @font-face declarations for the Vite/TanStack
build (the Next pipeline loads the same fonts via next/font). The earlier
Tailwind-v4 cleanup aligned __root.tsx imports with pages/_app.tsx and
dropped this file along the way — but pages/_app.tsx never imported it
because Next handles fonts via next/font, not CSS @font-face. Without
the import the .woff2 files still load (referenced from src() in fonts.css
once it's in the graph), but the @font-face rules never make it into the
document, so the browser falls back to system fonts (Helvetica Neue on
macOS).
routes/__root.tsx renders <FeaturePreviewModal />, which transitively
calls useBannerStack(). Master's pages/_app.tsx wraps the tree in
BannerStackProvider around FeaturePreviewContextProvider; the TanStack
root was missing that wrapper, so SSR prerender of `/` threw
"useBannerStack must be used within BannerStackProvider" and the build
failed at the prerender stage.
Mirror the master ordering: BannerStackProvider directly inside
CommandProvider, around FeaturePreviewContextProvider.
Master migrated all apps to Tailwind v4 + CSS-first config via
@tailwindcss/postcss; the rename `styles/main.css` → `styles/globals.css`
plus removal of `toast.css` / `typography.css` / theme imports broke the
CSS imports in `routes/__root.tsx`.
- Update __root.tsx CSS imports to mirror the post-merge pages/_app.tsx
list (drops fonts.css/main.css/toast.css/typography.css/themes/* and
uses globals.css).
- Add `@tailwindcss/vite` 4.2.4 as a devDep and wire it into the Vite
plugin pipeline. The Tailwind v4 PostCSS plugin doesn't compose with
Vite's built-in postcss-import (which tries to resolve
`@import 'tailwindcss'` as a relative path and ENOENTs on it). The
dedicated Vite plugin intercepts before postcss-import.
- Disable Vite's PostCSS auto-discovery (`css.postcss = { plugins: [] }`)
so the studio postcss.config.cjs (still used by `build:next`) doesn't
also run @tailwindcss/postcss against the same CSS under Vite.
- routes/project/$ref.tsx: DefaultLayout-only shell. ProjectLayoutWithAuth
is intentionally NOT placed here — every product layout (DatabaseLayout,
AuthLayout, StorageLayout, …) already renders withAuth(... ProjectLayout
...) internally, so a shell-level wrapper would double-wrap product
pages. The home page wraps itself in ProjectLayoutWithAuth instead.
- routes/project/$ref/index.tsx: re-exports pages/project/[ref]/index.tsx
inside <ProjectLayoutWithAuth>.
- routes/project/$ref/database.tsx: DatabaseLayout sibling-file layout,
reads databaseLayoutTitle from leaf staticData.
- routes/project/$ref/database/schemas.tsx: re-exports
pages/project/[ref]/database/schemas.tsx with staticData title.
This unblocks the rest of the project shell — remaining /project/[ref]/**
pages can come over via the established Path A pattern. Migration doc
updated with the shell delta.
Conflicts:
- apps/studio/components/interfaces/ConnectSheet/ConnectStepsSection.tsx:
keep new Admonition block from master + ComponentType import from HEAD.
- apps/studio/package.json: keep Vite-based scripts + extra radix deps +
@tanstack/devtools-vite + @tailwindcss/container-queries from HEAD.
- pnpm-workspace.yaml: keep React 19 / @types/react 19 catalog from HEAD,
take master's Next 16.2.6 / Tailwind 4 / and other new catalog entries.
- pnpm-lock.yaml: regenerated via pnpm install.
Swap the project-creation revoke from custom `db_sql` over to the new
`data_api_revoke_default_privileges` API field. Same behaviour, just
delegated to the platform so non-studio flows (branches, CLI, terraform)
can apply the same revoke logic — addresses
[FE-3145](https://linear.app/supabase/issue/FE-3145/swap-frontend-to-use-revoke-default-privileges-flag).
Backend support landed in supabase/platform#32158 and
supabase/platform#32493 (FUP that decoupled the flag from
`data_api_use_api_schema`).
**Changed:**
- `apps/studio/data/projects/project-create-mutation.ts` — accepts
`dataApiRevokeDefaultPrivileges` and forwards it as
`data_api_revoke_default_privileges`
- `apps/studio/pages/new/[slug].tsx` — drops the inline
`buildDefaultPrivilegesSql('revoke')` injection in `dbSql`, passes the
flag instead
-
`apps/studio/pages/integrations/vercel/[slug]/deploy-button/new-project.tsx`
— same swap on the Vercel deploy-button flow
- `packages/api-types/types/platform.d.ts` — adds the new field to
`CreateProjectBody`
**Preserved:**
- The `dataApiRevokeOnCreateDefault` PostHog flag still gates the
default checkbox state and telemetry — only the SQL application changes
- `data_api_use_api_schema: false` stays as-is — projects keep `public`
+ `graphql_public` exposed, no project-shape change
## To test
- Project creation form (`/new/<org>`):
- With PostHog flag off: "Automatically expose new tables" defaults to
checked → request body has `data_api_revoke_default_privileges: false`
- Manually uncheck the box → request body has
`data_api_revoke_default_privileges: true`, project ends up with revoked
default grants on `public`
- With "Enable Data API" off → `data_api_revoke_default_privileges:
false` (no point revoking when nothing's exposed)
- Vercel deploy-button flow
(`/integrations/vercel/<slug>/deploy-button`):
- Same checkbox behaviour as above
- Migration SQL from the GitHub repo still runs as `db_sql` separately
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added support for a dedicated `dataApiRevokeDefaultPrivileges` option
during project creation.
* **Refactor**
* Simplified Data API privilege configuration by using a dedicated
parameter instead of SQL-based management across project creation flows.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
<img width="1289" height="863" alt="image"
src="https://github.com/user-attachments/assets/d661f107-b358-4894-8531-80441d60ab91"
/>
GitHub integration is now available on the free plan and so we'd like to
start promoting code-first workflows as much as possible. One way to do
that is to set the tone straight away by asking a user to connecting
their GitHub repository to a project as part of project creation.
This PR:
- decouples GitHub connection and repo selection into a separate
component we can make use of in integration settings and project
creation.
- Adds new GitHub fields to project creation form and sends them off to
project creation endpoint
- Pre-fills project name based on repo selection
To test locally:
- Ensure you have GitHub integration set up locally (using ngrok etc)
- Ensure you are on the connected platform branch
- Open create a new project page
- Connect GitHub as part of the creation form and select a repo
- Create the project and wait for status to be healthy
- Check project settings integrations page and ensure repo is connected
Note:
- this requires changes on the management api end to accept new GitHub
fields
- it might make sense to pull out GitHub connection/authorization from
GitHub repository selection but in the current state they are tied
together.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Release Notes
* **New Features**
* GitHub repository selection now available during project creation with
integrated authorization flow
* GitHub connection status and compute availability indicators now
displayed on project dashboard
* Project name auto-populates from selected GitHub repository name when
available
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Refactors our help sidebar within Studio to include the actual support
form itself when contact is selected. This PR also cleans up the initial
state of the sidebar and the options within.
## To test:
- Open an org and click the help icon top right
- Click contact support
- Submit a support ticket
- Click done to return to support sidebar state
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Support form V3 and support sidebar with status button; direct-email
helper and URL prefill
* Success screen supports onFinish callback and customizable finish
label
* AI Assistant and Help options accept optional click callbacks;
resource items gain keyboard/accessibility support
* **Refactor**
* Help panel split into home/support views with back navigation
* Support components accept flexible align/className props and
layout/styling tweaks
* Initial URL params loader added for support form
* **Tests**
* New/updated tests for support flows, success screen, and help options
interactions
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
## What kind of change does this PR introduce?
UI chore.
## What is the current behavior?
The Keyboard shortcuts sheet renders shortcut definitions from the
static registry, so contextual Database navigation shortcuts appear in
the sheet even when `DatabaseLayout` is not active. This makes the
Navigation section noisy as more product-specific navigation shortcuts
are added.
## What is the new behavior?
The shortcuts sheet now reads the mounted, enabled shortcut set at
runtime. Global navigation remains under Navigation when it is the only
navigation scope, and splits into _**Global** Navigation_ plus
_**Database** Navigation_ when contextual database shortcuts are active.
This also replaces the one-off `DatabaseNavShortcuts` component with a
reusable `ProductMenuShortcuts` registrar so future product layouts can
register scoped navigation shortcuts from their product menu model.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added keyboard shortcut support for product menu navigation items with
router integration
* **Improvements**
* Keyboard shortcuts are now organized into logical groups (Global
Navigation and Database Navigation)
* Shortcut reference dynamically displays only active shortcuts instead
of static definitions
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Ali Waseem <waseema393@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Refactor + feature
## What is the current behavior?
The AWS Activate offer page used a one-off `HubSpotFormEmbed` component
(an iframe-style HubSpot script embed) living under
`apps/www/_go/lead-gen/components/`. It was single-destination (HubSpot
only) and not reusable. Closes
[DEBR-266](https://linear.app/supabase/issue/DEBR-266).
## What is the new behavior?
Adds a reusable `MarketingForm` component to the `marketing` package
that fans out submissions to HubSpot, Customer.io, and Notion in
parallel via the existing `submitFormAction` server action. The go-page
`FormSection` is now a thin adapter on top of `MarketingForm`, and
`aws-activate-offer.tsx` uses `MarketingForm` directly. The legacy
`HubSpotFormEmbed` is deleted.
## Additional context
- `MarketingForm` is exported from `marketing` so it can be used outside
go pages.
- Customer.io / Notion fan-out for AWS Activate is wired but not yet
configured — drop in `crm.customerio` / `crm.notion` blocks once
[DEBR-265](https://linear.app/supabase/issue/DEBR-265) lands.
- The original HubSpot embed had conditional field formatting which the
new form does not replicate; verify HubSpot field internal names
(`firstname`, `lastname`, `email`, `company`, `aws_account_id`) match
the target form before merging.
- Requires `HUBSPOT_PORTAL_ID` env to point at portal `19953346` (was
previously hardcoded in the embed).
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* New reusable marketing form with responsive two-column layout,
validation, error display, success UI or redirect, optional
title/description and markdown disclaimer.
* Added URL and checkbox field types plus conditional field visibility.
* HubSpot embed accepts typed props and improves script loading with
retry and clearer error logging.
* **Refactor**
* Forms consolidated into a shared marketing module; form sections now
delegate to the shared form component.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
This PR bumps `next` in `www` app to fix a vulnerability.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated framework to the latest patch version, incorporating bug fixes
and performance improvements from recent releases.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Bug fix — copy + visibility logic on the org Usage page.
## What is the current behavior?
On `/org/<slug>/usage` during a grace period, customers see two banners
that read as contradictory:
1. *"Organization plan has exceeded its quota — grace period until
{date}."*
2. *"You have not exceeded your Pro Plan quota in this billing cycle."*
<img width="1680" height="372" alt="image"
src="https://github.com/user-attachments/assets/13826260-55dd-4b55-a3dc-5afc51e6436e"
/>
Both are individually correct. The first is sticky from the previous
cycle's overage (`org.restriction_status`); the second is a live scan
over the current cycle. Neither anchors to which cycle it's talking
about, so together they read like the dashboard contradicting itself.
Surfaced by support off SU-368527 and SU-368395.
## What is the new behavior?
- Top chrome banner copy: *"Organization exceeded its quota in the
previous billing cycle / You have a grace period until {date} to bring
usage back under quota."*
- Inline `<Restriction />` grace-period alert switches from "is over its
quota" to "went over its quota in the previous billing cycle." Same
temporal anchor.
- The "…in this billing cycle" summary line in `<TotalUsage>` is hidden
whenever `restriction_status` is set. Mirrors the precedence rule
`<Restriction />` already applies internally — backend status flag wins
over the live cycle scan.
<img width="1678" height="937" alt="CleanShot 2026-05-06 at 12 58 02"
src="https://github.com/user-attachments/assets/df55eaed-1029-4f39-bea0-df77bcc5151e"
/>
## Additional context
Left the `gracePeriodOver` copy alone on purpose — it doesn't make a
current-overage claim, so there's nothing to contradict, and adding
"previous cycle" would muddy which cycle "previous" refers to.
**Verified**
- Lint and typecheck pass on `apps/studio`.
**Before merge**
- [ ] Load a grace-period org locally: confirm new copy on top banner
and inline `<Restriction />`, and that the "not exceeded in this billing
cycle" line is gone.
- [ ] Copy review with support — happy to workshop wording.
GROWTH-823
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Updates**
* Updated grace period alert messaging to clarify organization quota
status
* Refined date formatting in billing restriction notifications
* Modified usage display to conditionally hide certain information when
account restrictions are active
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Bumped Next.js versions used by docs and the workspace.
* Adjusted workspace dependency exclusion list to add Next-related
entries and remove a prior exclusion.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Expanded blog docs to show broader Web Request/Response runtime
compatibility, explicitly including Edge Functions, Vercel Functions,
and Cloudflare Workers.
* Added runtime-specific examples and dependency declaration guidance.
* Updated FAQ to clarify framework support (beyond Hono) and to broaden
wording around agentic coding tools receiving full API context.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
<img width="1244" height="1146" alt="CleanShot 2026-05-07 at 17 07 32"
src="https://github.com/user-attachments/assets/475cce46-a066-4a8b-a0e0-82261e1e4e73"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Improvements**
* Public key display in JWT key details now shows a pretty-printed JWKS
(JSON Web Key Set) with updated JWKS-oriented labeling.
* The key textarea is wrapped in a positioned container for improved
layout and readability.
* **New Features**
* Added an overlaid Copy button labeled “Copy JWKS” to copy the
displayed JWKS directly from the key details view.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Adds prompt guardrails and evals to prevent the AI assistant from asking
users to share sensitive data (API keys, `.env` contents, etc.) and to
warn when credentials are shared.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Stronger safety behavior: assistant now refuses requests to share full
environment files, asks for variable names only, and directs users to
secure secret-management tooling.
* Immediate warning and guidance if credentials or other sensitive
values are pasted in chat, without repeating exposed secrets.
* **Behavior**
* Clarified evaluation rules so responses more consistently follow the
new safety guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
The dashboard's timezone picker (#45517) propagates to log timestamps
and the shared TimestampInfo component, but observability and reports
charts still render their X-axis labels, range labels, and tooltip
headers in the browser's local timezone. The result is jarring once a
user picks a non-local timezone: hover a chart and you get one tz, hover
a log row and you get another.
## Fix
Routes all display-side timestamp formatting in the chart layer through
the existing picker-aware helpers (\`useFormatDateTime\` /
\`formatDateTime\`) so chart UI matches the rest of the dashboard.
- **ComposedChart.utils** \`CustomTooltip\` (the hotspot — drives every
observability dashboard tooltip): reads the active timezone via
\`useTimezone\` for both the header label and the formatted timestamp.
- **AreaChart** / **BarChart**: introduce a \`formatChartDate\` helper
that honours each component's existing \`displayDateInUtc\` prop,
otherwise routes through the picker.
- **ChartBlock**: the two recharts \`labelFormatter\` arrows now close
over \`useFormatDateTime\`.
- **ChartHighlightActions**: range labels in the zoom dropdown migrated
to the same hook.
Intentionally untouched (must stay UTC):
- \`ChartHandler\` / \`ChartBlock\` \`startDate\`/\`endDate\` (API range
params, day boundary).
- \`ChartBlock.tsx:166\` explicit \`.utc()\` data-key normalisation.
- \`useFillTimeseriesSorted\` and friends (range math, no display).
## How to test
- Sign in. Open the avatar dropdown, pick a timezone different from your
browser local (e.g. Asia/Tokyo).
- Visit any project, then \`/project/<ref>/reports/database\` (or any
\`/observability/...\` page).
- Hover any chart series — the tooltip header should display the chosen
IANA name and times in that timezone.
- Click-drag a range on a chart to open the zoom dropdown — start/end
labels in the menu should also be in the chosen timezone.
- Switch back to "Auto detect" and confirm everything reverts to
browser-local.
- For an AreaChart/BarChart that uses \`displayDateInUtc\` (e.g. some
legacy reports), confirm those still render in UTC regardless of picker.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Standardized date/time formatting across charts, tooltips, axis
labels, header/footer labels, and highlight range labels in Reports and
chart components.
* Switched to a shared, timezone-aware formatter that respects UTC
display mode or the selected picker/timezone, ensuring consistent,
human-readable timestamps throughout the UI.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Summary
- Adds `syslog` as a new log drain destination type in Studio
- Implements RFC 5424 syslog over TCP or TLS with octet-counting framing
(backed by the existing Logflare syslog backend)
- All fields match the Logflare backend config: `host`, `port`, `tls`,
`structured_data`, `cipher_key`, `ca_cert`, `client_cert`, `client_key`
- TLS cert fields (CA cert, client cert, client key) are shown only when
the TLS toggle is on
- Cross-field validation: `client_cert` and `client_key` must be
provided together
- Gated behind a `syslogLogDrain` feature flag (consistent with other
drain types)
closes FE-2865
## Test plan
- go to log drains
- create a syslog log drain
- it creates it
🤖 Generated with [Claude Code](https://claude.com/claude-code)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Syslog added as a new log drain destination with configurable host,
port (0–65535), TLS toggle, and optional RFC5424 structured data.
* Supports CA and client certificate/key input for TLS or mTLS; client
certificate and key must be provided together.
* Form validation, inline defaults, initial values for Syslog fields,
and availability controlled by a feature flag.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Tailwind 4 applies `divide` a little bit differently, so a small fix
applied here to get it back to how it looked.
| Header | Header |
|--------|--------|
| <img width="485" height="488" alt="Screenshot 2026-05-07 at 16 41 18"
src="https://github.com/user-attachments/assets/d7f678fb-1179-4153-99fa-bfbe247fe519"
/> | <img width="485" height="487" alt="Screenshot 2026-05-07 at 16 41
24"
src="https://github.com/user-attachments/assets/a2ce53d4-5296-475c-a4d8-38b0820e820c"
/> |
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Style**
* Adjusted metadata header spacing and list item padding in the Query
Performance interface for improved visual consistency and layout
alignment.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
This PR migrates all tailwind configs in the apps to be CSS configs.
They import a shared CSS Tailwind config from the `config` package
(which in turns imports the old JS config).
The shared JS config will be migrated to CSS in a followup PR.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Centralized Tailwind into a config-driven entrypoint and updated the
app build flow to use the new build step; many apps now import unified
global styles.
* **Style**
* Migrated global styles to a Tailwind v4-style setup, added
project-wide content scanning, consolidated theme imports, standardized
theme tokens (including new --container-site max-width), and added a
small prose utility to remove paragraph margins.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Small docs update on new postgres logs behaviour
part of O11Y-1519
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Added a "Limits and Caveats" section clarifying Supabase
Platform-specific behavior for PostgreSQL RAISEd log messages: platform
log events are truncated at 100,000 characters (no truncation for
self-hosting), and certain internal PostgreSQL connection logs generated
by infrastructure services are omitted (these omissions do not apply to
self-hosted deployments).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs update
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated authentication guide for Turnstile CAPTCHA setup with
simplified, more direct instructions for configuring the widget and
obtaining keys.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
This PR syncs the latest troubleshooting guides from the
supabase/troubleshooting repository.
Co-authored-by: github-docs-bot <github-docs-bot@supabase.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs update
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated the Figma OAuth social login setup guide with corrected links
to the Figma Developers portal for accurate authentication
configuration.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
- Fix `secret_access_key` value as publishableKey is not currently
supported
- Add variable values for local dev
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Enhanced S3 authentication guide with local development setup details
and credential examples for access-key and session-token flows
* Added environment-specific configuration notes for local and
self-hosted deployments
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## TL;DR
fixes cron losing http body/headers when values contain backslashes,
broken by:
- #45560
parser now handles escape-string literals (`E'...'`) emitted by
`literal()`
## ex:
Before:
https://github.com/user-attachments/assets/9f7c3c13-5c49-448d-aac1-b64e27e269f4
After:
https://github.com/user-attachments/assets/2c517c4d-9eaa-412f-9b40-5eaacc2c2b2d
## ref:
- closes https://github.com/supabase/supabase/issues/45674
- broken by / adds upto: #45560
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Release Notes
* **Bug Fixes**
* Improved reliability of cron job HTTP POST request parsing when using
special characters and escape sequences in headers and body parameters.
* Enhanced support for extracting headers from cron job commands
configured with escaped SQL literals.
* **Tests**
* Added test coverage for HTTP cron job command parsing with escaped SQL
string literals and special character handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Adding Michelle :)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated project team member documentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Summary
- Adds a hardcoded `BANNER_EXPIRES_AT` constant to `NoticeBanner` so
long-lived tabs running an old client bundle stop displaying outdated
notices once the relevant date passes.
- Self-suppresses on every bundle that ever shipped — no server-side
flag flip, no refresh, no over-suppression on unrelated deploys.
- The existing `showNoticeBanner` ConfigCat boolean stays in place as
the emergency kill-switch.
For future banners, set `BANNER_EXPIRES_AT` to the time the notice
should stop rendering (e.g. end of a maintenance window, or a generous
tail after a TOS effective date).
Closes
[FE-3175](https://linear.app/supabase/issue/FE-3175/suppress-stale-maintenance-banner-on-old-client-bundles).
## Test plan
- [x] Locally set `BANNER_EXPIRES_AT` to a past date and confirm the
banner does not render.
- [x] Set it to a future date and confirm the banner renders as before.
- [x] Confirm flipping `showNoticeBanner` off in ConfigCat still hides
the banner.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added automatic expiration for notice banners, ensuring outdated
notices no longer display after a specified date.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
We run the e2e tests across two shards to reduce their duration.
However, one takes longer than the other.
## Solution
Use a currently hidden Playwright feature to balance their load
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Upgraded Playwright test dependency to a newer version for refreshed
test tooling and fixes.
* Adjusted end-to-end test shard weighting to rebalance distribution
across parallel runs.
* **Tests**
* Stabilized several end-to-end editor interactions to make E2E flows
more reliable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
We have lots of duplicated/deprecated components.
## Solution
- Migrate to new ones
- Fix invalid HTML
## Screenshots
Before (translate the hovered card up, first item in the screenshot):
<img width="2842" height="1178" alt="image"
src="https://github.com/user-attachments/assets/298b51ba-2f4e-4caa-888e-d0de7b22eb7f"
/>
After (same as the features page):
<img width="2824" height="954" alt="image"
src="https://github.com/user-attachments/assets/b34637a7-ed6f-4997-8bb1-a133d4a736ac"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Updated the Company page layout with modernized UI components and
simplified markup structure for improved clarity and consistency across
the Team, Investors, and Press sections.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Clarified anonymous-account linking guide: example now explicitly
checks that the current session is anonymous and exits early if not,
preventing unintended linking steps.
* Enhanced resumable uploads guide: added a note explaining why the
example reads the local session token to forward it for server-side
validation when interacting with direct storage endpoints.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Updates the documented CPU time limit from 200ms to the correct value of
2000ms (2 seconds) for Edge Functions in the shutdown guide.
**References:**
- Source:
https://github.com/supabase/edge-runtime/blob/main/.cargo/config.toml#L7
- Docs: https://supabase.com/docs/guides/functions/limits#runtime-limits
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated edge function shutdown reasons documentation to reflect an
increased CPU time limit of 2000 milliseconds (previously 200
milliseconds).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs update
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated custom OAuth provider quota documentation to clarify
plan-based limitations. Free plan projects can add up to 3 custom
providers, while Pro plan and above have unlimited providers.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the CONTRIBUTING.md file.
YES
## What kind of change does this PR introduce?
Docs update
## What is the current behavior?
- The React quickstart example does not handle errors when fetching
data.
- The local development guide uses inconsistent capitalization for
"docker".
## What is the new behavior?
- Adds basic error handling (`error` check) in the React quickstart
example to improve reliability.
- Fixes capitalization from "docker" → "Docker" for consistency with
official naming.
## Additional context
These are small improvements to enhance clarity and developer experience
in the docs.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Enhanced React quickstart guide with error handling for database
queries to prevent invalid data processing
* Corrected capitalization in local development guide
<!-- end of auto-generated comment: release notes by coderabbit.ai -->