Commit Graph
38035 Commits
Author SHA1 Message Date
Joshen LimandCharis 9a3500aad2 Set up infinite loading for notebooks (#49321)
## Context

Sets up infinite loading for notebooks with the `InfiniteListDefault`
component

Also adds the notebook and chats count on the explorer home nav
<img width="275" height="137" alt="image"
src="https://github.com/user-attachments/assets/c3f16e8f-f520-4107-a188-43b1abcca043"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Explorer navigation now displays accurate notebook and chat counts.
* Notebook lists support infinite scrolling, loading indicators, and
improved active-state styling.
  * Notebook navigation remains available as additional items load.

* **Bug Fixes**
* Corrected default markdown cell formatting by removing unintended
leading spaces from headings and notes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Charis <26616127+charislam@users.noreply.github.com>
2026-08-21 11:15:26 +08:00
Joshen Lim 6779bf52e1 Joshenlim/fe 4208 explorer templates need to be properly set up (#49322)
## Context

Set up Explorer templates properly for notebooks and chat. Tried (with
the help of Claude) to come up with templates that are generic enough
for most projects to sort of pick up and use, or even pick up to study
how notebooks are meant to be used.

Feel free to play around on the preview to check out the content of each
template! 🙂

<img width="768" height="232" alt="image"
src="https://github.com/user-attachments/assets/590893c4-9772-437d-980f-05ea62ffef81"
/>

<img width="1918" height="955" alt="image"
src="https://github.com/user-attachments/assets/2114e73e-dc44-403d-a998-e87c8d328516"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added ready-to-use chat templates for sample data, security policies,
and notebook creation.
* Added notebook templates for database health, user growth, and error
investigation workflows.
* Explorer cards now dynamically create chats and notebooks from
selected templates.
* Templates include guided prompts, queries, logs, charts, and relevant
notebook content.
* **Bug Fixes**
* Improved generated log cell identifiers for more reliable notebook
creation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 11:06:20 +08:00
Danny White 417b0fe13e feat(studio): show read replicas moved notice on Replication (#49355)
## What kind of change does this PR introduce?

Feature / communication. Resolves
[PIPE-1008](https://linear.app/supabase/issue/PIPE-1008/communicate-read-replica-move-changelog-leftover-ui-docs).

## What is the current behavior?

Database → Replication is now Pipelines-only. The “Read replicas have
moved” callout only appears inside the New destination sheet, so users
who land on Replication looking for replicas can miss it.
Getting-started already points create at Infrastructure but does not say
the management surface moved.

## What is the new behavior?

Replication shows the moved callout at the top of the page (flag-gated),
with a _Go to Infrastructure_ CTA. The same callout remains in the
destination-type sheet. Getting-started adds a short note that
management moved from Replication to Infrastructure.

This Admonition is dismissible, with its state stored in local storage.

| Before | After |
| --- | --- |
| <img width="1024" height="759" alt="64555"
src="https://github.com/user-attachments/assets/7084bd51-2f48-4a83-ac2a-89bdd3f23804"
/> | <img width="1024" height="759" alt="Replication Database Chisel
Toolshed Supabase"
src="https://github.com/user-attachments/assets/9b26c23a-1b44-4711-919b-c7000f155190"
/> |



## To test

`infrastructure:read_replicas` on by default.

1. Open [Database →
Replication](https://studio-staging-git-danny-pipe-1008-replication-moved-notice-supabase.vercel.app/dashboard/project/_/database/replication)
(preview URL once deployed). Confirm the note “Read replicas have moved”
and Go to Infrastructure.
2. Click the CTA: lands on Settings → Infrastructure.
3. Open New destination: callout still appears under the type selector.
4. Docs preview: getting-started Creating a Read Replica section shows
the move note.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a callout informing users that read replicas are now managed
through Infrastructure.
* Added a direct link to the Infrastructure page from database
replication settings.
* Added the option to dismiss the callout, with dismissal saved per
project.
* Displayed the callout on the replication page and destination
selection view.

* **Bug Fixes**
* Updated callout visibility behavior to respect project settings and
prior dismissal.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 02:59:28 +00:00
Danny White 6ac5bf6b86 feat(studio): point replica deep links at Infrastructure and recommend compute (#48921)
## What kind of change does this PR introduce?

Feature. Stack 5 of 5 (tip) for
[PIPE-1007](https://linear.app/supabase/issue/PIPE-1007/move-read-replicas-out-of-replication-into-infrastructure).

## What is the current behavior?

Selectors still open Replication with `destinationType=Read+Replica`.
Compute eligibility actions leave the add-replica flow without carrying
a recommended size into the Infrastructure form.

## What is the new behavior?

DatabaseSelector and the SQL submenu open Infrastructure
`?addReplica=true`. Change to Small/XL compute waits for the sheet to
close, pre-selects that size, then focuses and scrolls the
Infrastructure form to Compute without shifting the page footer.

## Additional context

Last stack PR. [#49043](https://github.com/supabase/supabase/pull/49043)
has merged. Please review, but do not merge until 2→4 are also approved.
Then merge [#49044](https://github.com/supabase/supabase/pull/49044) →
[#49045](https://github.com/supabase/supabase/pull/49045) →
[#49046](https://github.com/supabase/supabase/pull/49046) → this PR in
succession, and drop the `do-not-merge` labels.

Update the read replicas getting-started doc in the same sitting so it
points only at Infrastructure (it currently also links Database →
Replication).

Remaining stack:
[#49044](https://github.com/supabase/supabase/pull/49044) →
[#49045](https://github.com/supabase/supabase/pull/49045) →
[#49046](https://github.com/supabase/supabase/pull/49046) → this PR

## To test

`infrastructure:read_replicas` is an enabled-feature, on by default.
There is no Feature Preview or ConfigCat switch. You should already see
the Infrastructure Read replicas section. If you do not, your profile
lists `infrastructure:read_replicas` in `disabled_features`.

1.
[Infrastructure](https://studio-staging-git-dnywh-choreread-replicas-in-829a4b-supabase.vercel.app/dashboard/project/_/settings/infrastructure):
topology, Read replicas, Scaling.
2. Add read replica. If blocked on compute, Change to Small compute:
sheet closes, Small is selected and focused, the price footer is dirty,
and no blank page gap appears.
3. From the SQL editor database selector, Add replica should open
Infrastructure, not Replication.
2026-08-21 12:44:41 +10:00
Danny WhiteandJeremias Menichelli bb086a84b8 feat(studio): remove read replicas from Replication (#49046)
## What kind of change does this PR introduce?

Feature. Stack 4 of 5 for
[PIPE-1007](https://linear.app/supabase/issue/PIPE-1007/move-read-replicas-out-of-replication-into-infrastructure).
Contributes to PIPE-1008.

## What is the current behavior?

Database / Replication lists, creates, and diagrams read replicas
alongside pipelines.

## What is the new behavior?

Replication is pipelines-only. No replica rows, type, or diagram nodes.
`?destinationType=Read+Replica` redirects to Infrastructure. A short
callout points create-mode users at the new home.

## Additional context

Please review, but do not merge until
[#48921](https://github.com/supabase/supabase/pull/48921) is ready to
follow immediately. The flag is already on, so this PR is the
user-facing cutover off Replication.

## To test

`infrastructure:read_replicas` is an enabled-feature, on by default.
There is no Feature Preview or ConfigCat switch. You should already see
the Infrastructure Read replicas section. If you do not, your profile
lists `infrastructure:read_replicas` in `disabled_features`.

Open [Database /
Replication](https://studio-staging-git-danny-pipe-1007-04-cut-from-77ef95-supabase.vercel.app/dashboard/project/_/database/replication?destinationType=Read+Replica).
You should land on Infrastructure with the add-replica sheet, not a
replica destination type. The Replication page itself should be
pipelines-only.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added guidance directing users to Infrastructure to create read
replicas.
  * Added automatic redirection for legacy read-replica links.

* **Updates**
* Replication destinations now focus exclusively on external analytics
and pipeline destinations.
* Updated destination selection, empty states, descriptions, and
diagrams to reflect the streamlined experience.
* Removed read replicas from the replication destination list and
related creation flow.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
2026-08-21 12:44:41 +10:00
Danny White 7fd7ace118 feat(studio): add Infrastructure replica detail route and redirects (#49045)
## What kind of change does this PR introduce?

Feature. Stack 3 of 5 for
[PIPE-1007](https://linear.app/supabase/issue/PIPE-1007/move-read-replicas-out-of-replication-into-infrastructure).

## What is the current behavior?

Replica detail lives at `/database/replication/replica/:id`.

## What is the new behavior?

Detail moves to `/settings/infrastructure/replica/:id`. Old URLs
redirect. List and diagram View/Manage replica links follow.

## Additional context

Stacked on [#49044](https://github.com/supabase/supabase/pull/49044).
Please review, but do not merge. Merge 2→5 in succession once they are
all reviewed, so users never sit on a split create/list vs detail path.

Replication still lists and creates replicas until
[#49046](https://github.com/supabase/supabase/pull/49046).

## To test

`infrastructure:read_replicas` is an enabled-feature, on by default.
There is no Feature Preview or ConfigCat switch. You should already see
the Infrastructure Read replicas section. If you do not, your profile
lists `infrastructure:read_replicas` in `disabled_features`.

From
[Infrastructure](https://studio-staging-git-danny-pipe-1007-03-detail-redirects-supabase.vercel.app/dashboard/project/_/settings/infrastructure),
open View replica on a row. Confirm you land on
`/settings/infrastructure/replica/:id`. If you have an old bookmark,
`/database/replication/replica/:id` should redirect there.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added read replica management to Infrastructure settings, including
replica creation, status monitoring, details, restart, and removal
actions.
* Added eligibility guidance and estimated pricing details during
replica setup.
* Added support for topology and replica information within
infrastructure configuration.
* **Improvements**
* Legacy database replication links now permanently redirect to the
corresponding Infrastructure pages.
* Added clearer empty, loading, error, and transition states for read
replica management.
* **Tests**
* Expanded coverage for replica navigation, redirects, eligibility
warnings, and empty states.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 12:44:41 +10:00
Danny White e9abda6c79 feat(studio): add read replicas section on Infrastructure (#49044)
## What kind of change does this PR introduce?

Feature. Stack 2 of 5 for
[PIPE-1007](https://linear.app/supabase/issue/PIPE-1007/move-read-replicas-out-of-replication-into-infrastructure).

## What is the current behavior?

Settings / Infrastructure only covers compute and disk.

## What is the new behavior?

Adds topology, a Read replicas list, and the add-replica sheet on
Infrastructure. Still gated on `infrastructure:read_replicas`.

| Before | After |
| --- | --- |
| <img width="1279" height="1323" alt="Infrastructure Settings Chisel
Toolshed Supabase"
src="https://github.com/user-attachments/assets/34e7b414-a326-415b-984c-00ae0000f46e"
/> | <img width="1279" height="1323" alt="Infrastructure Settings Chisel
Toolshed Supabase"
src="https://github.com/user-attachments/assets/547cd7ac-435e-45d1-80ad-2f35476f579f"
/> |

## Additional context

[#49043](https://github.com/supabase/supabase/pull/49043) is merged.
This PR targets `master`.

Please review, but do not merge. `infrastructure:read_replicas` is
already on, so merging this alone would show replicas on both
Infrastructure and Replication. Merge 2→5
([#49045](https://github.com/supabase/supabase/pull/49045),
[#49046](https://github.com/supabase/supabase/pull/49046),
[#48921](https://github.com/supabase/supabase/pull/48921)) in succession
once they are all reviewed.

Replica detail still uses the old Replication URL until #49045.

## To test

`infrastructure:read_replicas` is an enabled-feature, on by default in
`enabled-features.json`. There is no Feature Preview or ConfigCat
switch. On this preview you should already see it: Settings →
Infrastructure shows topology and a Read replicas section. If those are
missing, your profile lists `infrastructure:read_replicas` in
`disabled_features` (from `/platform/profile`), and you cannot flip it
in the UI.

Open [Settings /
Infrastructure](https://studio-staging-git-danny-pipe-1007-02-infra-section-supabase.vercel.app/dashboard/project/_/settings/infrastructure).
Confirm the topology, Read replicas section, and Add read replica sheet.
Replication should still list replicas too.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added infrastructure topology visibility to project infrastructure
settings.
* Added read replica management, including status monitoring, empty
states, creation flow, documentation access, and discard-change
confirmation.
* Infrastructure settings now include read replicas alongside compute
and disk configuration.
* Added flexible placement for supplemental disk overview and scaling
content.

* **Bug Fixes**
* Simplified project configuration rendering for more reliable display.

* **Tests**
  * Added coverage for enabled and disabled read replica states.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 12:44:40 +10:00
fb4c3ec6d4 feat(studio): add dev toolbar launcher to account settings menu (#49285)
## What kind of change does this PR introduce?

Feature

## What is the current behavior?

The dev toolbar is only discoverable via `window.devToolbar()` in the
browser console, or by having your email on the `devToolbarDefaultOn`
ConfigCat flag. Once enabled, Studio shows a floating trigger button.

## What is the new behavior?

In local and staging Studio, the account/settings dropdown (avatar menu)
includes a **Local tools** section above **Theme** with a **Dev
toolbar** checkbox toggle.

- **On**: shows the floating orb (persists via localStorage, same as
`window.devToolbar()`)
- **Off**: hides the orb and dismisses the toolbar

Open the panel itself via the orb once it is visible. Production builds
are unchanged (`isAvailable` is false and the menu item is hidden).

| After |
| --- |
| <img width="226" height="204" alt="CleanShot 2026-08-20 at 12 46
38@2x"
src="https://github.com/user-attachments/assets/c846b119-626d-48f5-9a02-aef4d006326c"
/> |
| <img width="558" height="1024" alt="CleanShot 2026-08-20 at 12 47
04@2x"
src="https://github.com/user-attachments/assets/4b3dd22b-537b-4874-821d-c202033c4ad7"
/> |

## Manual testing

Run `pnpm dev:studio` and open http://localhost:8082.

1. **Find the entry point:** top-right avatar/settings menu → **Local
tools** → **Dev toolbar** (above **Theme**). Should not appear in
production builds.
2. **Turn it on:** check **Dev toolbar**. A green floating orb should
appear (default bottom-right).
3. **Open the panel:** click the orb. The **Dev Toolbar** sheet should
open with Events and Flags tabs.
4. **Event count:** navigate around Studio (e.g. open a project, switch
pages). The orb badge should increment and stay readable in light and
dark mode.
5. **Turn it off:** reopen the avatar menu and uncheck **Dev toolbar**.
The orb and panel should disappear.
6. **Close vs hide:** with the toolbar on, open the sheet and use
**Close** (X). The orb should remain; only the sheet closes.

Optional: confirm `window.devToolbar()` in the browser console still
enables the orb.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a Local tools option to enable the development toolbar when
available.
* Toolbar activation and dismissal preferences now persist between
sessions.
* Added clearer event-count badges with responsive sizing for larger
counts.

* **Improvements**
  * Simplified toolbar controls by removing the separate hide option.
* Improved toolbar availability handling across local and production
environments.

* **Tests**
* Expanded coverage for activation, persistence, visibility, and
event-count badges.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Danny White <dnywh@users.noreply.github.com>
Co-authored-by: Sean Oliver <882952+seanoliver@users.noreply.github.com>
2026-08-21 10:53:50 +10:00
Pamela Chia 10c425ad0b feat(www): markdown copy/ask affordances (#48475) 2026-08-21 08:51:11 +08:00
Saxon Fletcher e605178a63 feat(studio): render assistant log query results (#49293)
<img width="1510" height="862" alt="image"
src="https://github.com/user-attachments/assets/f7157bad-9b23-4d73-a9aa-2a7a7c179318"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature and bug fix.

## What is the current behavior?

`query_logs` can return rows to the assistant, but the chat UI does not
hydrate those rows into the query result by default. The query only
becomes visible after clicking **Run query**, even though the same SQL
and time range work when rerun manually.

## What is the new behavior?

- Renders `query_logs` tool output through a dedicated logs message part
using the shared assistant query cell.
- Parses the exact MCP untrusted-data envelope into the initial query
result, without changing what the assistant model receives.
- Preserves the logs source and time range for manual reruns.
- Infers a useful table or chart presentation from the returned rows
while retaining explicit display settings.
- Adds focused tests for MCP result parsing, timestamps, errors, query
source handling, and visualization inference.

## How to test

1. Check out this PR and run Studio against a project that has recent
logs. Generate some project activity first, such as an API request, if
needed.
2. Open the AI Assistant and ask: `Show log counts by minute for the
last 15 minutes and summarize any spikes.`
3. Wait for `query_logs` to finish. Verify the query cell appears with
results already populated; do not click **Run query** first.
4. Verify the aggregate result opens as a chart, then switch to the
table view and confirm the underlying rows are present.
5. Click **Run query** and verify the query runs successfully again
using the same logs source and 15-minute time range.
6. Ask: `Show the 20 most recent log entries from the last 15 minutes.`
Verify this non-aggregate result opens as a table with rows already
populated.
7. Confirm the assistant's written summary agrees with the displayed
rows and does not report zero rows when results are visible.

## Additional context

This is the top PR in stack #49294 and depends on the back-end knowledge
change in #49292.

Verified with 59 focused tests across assistant context, Studio/MCP
tools, query display, and logs result parsing.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added AI Assistant support for querying and displaying application
logs.
* Added automatic visualization selection, including charts for
time-based and categorical data.
* Added source-aware query handling with dedicated titles, time ranges,
and result displays.
  * Added clearer loading, parsing, and error states for log queries.

* **Bug Fixes**
* Improved handling of streamed results, source changes, and query
display updates.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 09:30:55 +10:00
Saxon Fletcher aa2897f712 feat(studio): teach assistant to query ClickHouse logs (#49292)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature and bug fix.

## What is the current behavior?

The assistant can call `query_logs`, but it is not given the ClickHouse
schema and query-writing guidance it needs. It also lacks a current UTC
reference for producing the absolute timestamps required by the tool,
which can lead to valid queries being run against the wrong time range
and reported as returning zero rows.

## What is the new behavior?

- Adds a dedicated `logs` knowledge topic backed by the shared
ClickHouse schema and query guidance.
- Requires the assistant to load that knowledge before using
`query_logs`.
- Includes the current UTC time in project context so relative requests
can be converted to correct absolute tool parameters.
- Covers the new knowledge flow and context with focused tests and
updates the assistant eval expectation.

## How to test

1. Check out this PR and run Studio against a project that has recent
logs. Generate some project activity first, such as an API request, if
needed.
2. Open the AI Assistant and ask: `Show log counts by minute for the
last 15 minutes and summarize any spikes.`
3. Expand the assistant's tool activity and verify it loads the `logs`
knowledge topic before calling `query_logs`.
4. Inspect the `query_logs` input and verify:
- `iso_timestamp_start` and `iso_timestamp_end` are absolute UTC
timestamps ending in `Z`.
   - The timestamps cover approximately the requested 15-minute window.
- The SQL uses ClickHouse syntax, includes a `LIMIT`, and does not put
the time range in the SQL `WHERE` clause.
5. Verify the assistant's summary reflects the rows returned by
`query_logs` instead of reporting zero rows when results are present.

## Additional context

This is the bottom PR in stack #49294. The front-end visualization is
added separately in #49293.

Verified with 59 focused tests across assistant context, Studio/MCP
tools, query display, and logs result parsing.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added AI-assisted project log querying through the `query_logs` tool.
- Added logs knowledge guidance for time ranges, schema discovery, query
limits, and concise result summaries.
- Project context now includes the current UTC timestamp to improve
relative time-range interpretation.
- Improved notebook assistance with safer table verification and
appropriate handling of log queries.

- **Bug Fixes**
- Prevented incorrect SQL timestamp filtering and enabled cross-service
searches without requiring a source filter.
  - Added validation for supported knowledge topics.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 09:30:54 +10:00
Miranda LimonczenkoandClaude Opus 5 70715790b8 chore(www): unpublish and redirect the legacy launch week pages (#49335)
Closes
[FE-4226](https://linear.app/supabase/issue/FE-4226/unpublish-and-redirect-legacy-launch-week-pages)

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content removal.

## What is the current behavior?

`/launch-week/x`, `/launch-week/12`, `/launch-week/13`, and
`/launch-week/14` are still published. Each one carries its own page
component and a ticket flow for a launch week that ended. The
accessibility scan flags them, and they hold no SEO value.

This follows #49281, which took down `/launch-week/6` on the same
pattern.

## What is the new behavior?

- Delete the `/launch-week/x`, `/12`, `/13`, and `/14` page routes.
- Redirect each path to its recap blog post, matching the destinations
agreed in `#team-marketing`.
- Point the Launch Week 12, 13, and 14 blog summary components at
`/launch-week` instead of their deleted pages. `LWXSummary` already does
this.
- Drop the `disableStickyNav` and `showLaunchWeekNavMode` checks in
`Nav` that only matched the deleted routes.
- Drop the Launch Week X branches in `useDarkLaunchWeeks` and `_app`.

| Source | Destination |
| --- | --- |
| `/launch-week/x` | `/blog/launch-week-x-best-launches` |
| `/launch-week/12` | `/blog/launch-week-12-top-10` |
| `/launch-week/13` | `/blog/launch-week-13-top-10` |
| `/launch-week/14` | `/blog/launch-week-14-top-10` |

## Additional context

`/launch-week/7` and `/launch-week/8` stay published. Neither has a
recap post to redirect to, so they need a destination decision before
they come down.

The `components/LaunchWeek/{X,12,13,14}` trees stay. `BlogPostRenderer`
imports the summary component from each one, and those summaries read
the same `Releases/data` modules the deleted pages used. The stage and
nav components under those directories are now unreachable, so they need
their own dead-code audit.

Assets under `public/images/launchweek/` are untouched, same as #49281.

## Manual testing

Preview:
https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app

1. Open
[/launch-week/x](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/x).
It returns a 308 and lands on `/blog/launch-week-x-best-launches`.
2. Open
[/launch-week/12](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/12).
It returns a 308 and lands on `/blog/launch-week-12-top-10`.
3. Open
[/launch-week/13](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/13).
It returns a 308 and lands on `/blog/launch-week-13-top-10`.
4. Open
[/launch-week/14](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/14).
It returns a 308 and lands on `/blog/launch-week-14-top-10`.
5. On each of those blog posts, the launch week summary card header
links to `/launch-week`.
6. Open
[/launch-week](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week),
[/launch-week/7](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/7),
and
[/launch-week/8](https://zone-www-dot-com-git-www-redirect-legacy-launch-weeks-supabase.vercel.app/launch-week/8).
All still load.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 15:33:09 -07:00
Charis 717927f4f2 fix(studio): AI assistant notebooks no longer set an invalid database_identifier (#49326)
## Summary

- The AI assistant's `create_notebook`/`update_notebook` tools could set
a `database_cell`'s `database_identifier` to a value that doesn't
correspond to any real database, because no tool exposes a project's
actual read-replica identifiers to the model.
- An unresolvable `database_identifier` silently breaks the cell:
`QueryEditor`'s connection-string lookup fails to find a match, and
running the cell fails with `Unable to run query: Connection string is
missing` — even though the exact same SQL runs fine when pasted into a
manually-created cell (which never sets this field).
- Fix: strip `database_identifier` from the agent-facing schema
(`agentCellSchema` in `notebook-schema.ts`) entirely, so the model can
no longer emit it at all. **This is a temporary fix** until we wire in
real read-replica support for the AI assistant (e.g. a tool exposing a
project's valid replica identifiers) — the field can be reintroduced
once the model has a legitimate source of truth to pull a valid
identifier from.
- Updated tests that relied on agent cells carrying
`database_identifier` to reflect the new behavior, and added a
regression test asserting `agentNotebookSchema` rejects a
`database_cell` with that field set.

Resolves FE-4224

## Test plan

- [x] `notebook-schema.test.ts`, `notebook-operations.test.ts`,
`notebook-tools.test.ts`, `AssistantNotebookPreview.test.tsx`,
`AssistantNotebookPreview.utils.test.ts` all pass
- [x] `tsc --noEmit` clean
- [x] Prettier clean on touched files

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved handling of database notebook cells when database metadata is
unavailable.
* Cells without database identifiers now display “No metadata” instead
of an incorrect replica identifier.
* Prevented invalid database identifiers from being accepted in
agent-generated notebook content.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 16:26:12 -04:00
Charis ebd616fa90 fix(studio): auto-retry notebook updates on stale/invalid conflicts (#49323)
## Summary

- **Removed dead client-side refresh UI** in
`NotebookProposalRenderer.tsx` and its test — the diff preview is always
computed from live data, so the check was redundant with the tool's
server-side re-validation
- **Added typed `NotebookToolError`** in `notebook-tools.ts` with
structured metadata (`{ exposeToAssistant: boolean }`) validated by a
zod schema with a literal discriminant tag (`tag:
'notebook_tool_error'`) — tracks the two retryable failures: staleness
conflict and invalid operations (unknown cell id)
- **Encoded errors in `generate-v4.ts` onError** — the one place in the
pipeline that holds the live `Error` before it becomes a string in the
persisted message
- **Extracted and fixed message history filter** into new
`generate-assistant-response.utils.ts` — any tool-error whose
`errorText` decodes against the `NotebookToolError` schema is let
through (with `errorText` rewritten to plain prose so the model sees the
message, not JSON), while other errors stay filtered as before

Net effect: the assistant detects the specific, actionable rejection
reason and retries on its own with no dead button or human intervention
needed.

## Test plan

- Existing unit tests in `NotebookProposalRenderer.test.tsx` pass (dead
button test removed)
- New unit tests in `notebook-tools.test.ts` cover encode/decode
round-trips and error discrimination
- New unit tests in `generate-assistant-response.utils.test.ts` cover
message history filtering with all error states
- `pnpm typecheck` is clean
- `pnpm --filter studio run lint:ratchet` passes (no new ESLint
warnings)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Notebook update errors now provide clearer, structured explanations to
the AI assistant.
* Assistant responses preserve relevant notebook error details while
filtering invalid or temporary tool states.
* **Bug Fixes**
* Improved handling of stale notebook revisions and invalid notebook
update operations.
* Notebook proposal rendering proceeds without an unnecessary refresh
step.
* **Tests**
* Expanded coverage for notebook errors, message filtering,
serialization, and error handling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 16:08:19 -04:00
Ali Waseem 5d3b84945e fix(studio): derive switch-to-preview refs from the branch (FE-4219) (#49320)
"Switch to preview" in the delete flow read its refs from the selected
project, so on the branching overview `parent_project_ref` was undefined
and the handler bailed with a `console.error` — persistent branches
couldn't be deleted.

Both refs now come from the `branch` prop, and the not-ready state shows
on the confirm button instead of the console. Covered by a new MSW test
that fails against the old code.

Fixes FE-4219

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved switching branches to Preview mode by using the selected
branch’s project information.
  * Prevented confirmation when no branch is available.
* Preserved success notifications and modal closing after a successful
switch.

* **Tests**
* Added coverage for successful updates, API failures, error feedback,
request details, and disabled confirmation states.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 14:55:38 -04:00
Miranda LimonczenkoandClaude Opus 5 ebd399ff87 fix(www): use li instead of ol in launch week summary lists (#49279)
Closes
[FE-4096](https://linear.app/supabase/issue/FE-4096/launch-week-summary-lists-ol-inside-ul-link-where-li-belongs-6-copies)

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Accessibility bug fix.

## What is the current behavior?

The launch week summary card renders at the bottom of launch week blog
posts. Its two lists are invalid HTML in six copies of the component.

- Each entry is an `<ol>` nested directly inside a `<ul>`. Only `<li>`
is a valid child of `<ul>`.
- The `<Link>` sits inside the `<ol>` rather than inside an `<li>`, so
there are no list items at all.

Screen readers announce a list of empty items wrapping nested lists
instead of a flat list of links.

## What is the new behavior?

- Swap every `<ol>` for an `<li>` in the six summary components: LW X,
11, 12, 13, 14, and 15.
- Class names and keys carry over unchanged. No visual change.

## Additional context

The blog posts stay published. This is a markup fix only.

## Manual testing

1. Open [the Launch Week 15 top 10
post](https://zone-www-dot-com-git-www-fix-lw-summary-lists-supabase.vercel.app/blog/launch-week-15-top-10)
on the deploy preview.
2. Scroll to the Launch Week 15 summary card below the article. It shows
a Main Stage list and a Build Stage list.
3. Inspect either list. Every direct child of the `<ul>` is an `<li>`,
and no `<ol>` appears inside.
4. Repeat on [the Launch Week 12 Wasm FDW
post](https://zone-www-dot-com-git-www-fix-lw-summary-lists-supabase.vercel.app/blog/postgres-foreign-data-wrappers-with-wasm)
for the Launch Week 12 card.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 11:43:51 -07:00
Miranda LimonczenkoandClaude Opus 5 6edef9f067 chore(www): unpublish the Launch Week 6 page (#49281)
Closes
[FE-4100](https://linear.app/supabase/issue/FE-4100/www-remove-httpssupabasecomlaunch-week6)

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Content removal.

## What is the current behavior?

`/launch-week/6` is still published. Launch Week 6 ran in December 2022.
The page carries its own 1,085-line component, two CSS modules, and a
Supabase client that reads the `lw6_creators` and `lw6_tickets` tables.

## What is the new behavior?

- Delete the `/launch-week/6` page, its CSS modules, its day data, and
its types.
- Redirect `/launch-week/6` to `/blog/launch-week-6-wrap-up`, which
holds the same content.
- Drop the Launch Week 6 card from the archive section on
`/launch-week/8`, leaving Launch Week 7.

## Additional context

Scope is Launch Week 6 only. Whether the other launch week pages come
down is still open with marketing.

Assets under `public/images/launchweek/` are untouched. Several are
shared across launch weeks, so they need their own audit.

## Manual testing

1. Open
[https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/6](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/6)
on the deploy preview. It returns a 308 and lands on
`/blog/launch-week-6-wrap-up`.
2. Open [the Launch Week 7
page](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/7).
It still loads.
3. Open [the Launch Week 8
page](https://zone-www-dot-com-git-www-remove-launchweek-supabase.vercel.app/launch-week/8)
and scroll to "Previous Launch Weeks". Only the Launch Week 7 card
shows.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 11:42:30 -07:00
Joshen Lim 7d28bcc26b joshenlim/fe 4204 notebooks intellisense toggle (#49300)
## Context

Adds an intellisense toggle for explorer notebooks similar to SQL editor
+ have QueryEditor render definitions via `useAddDefinition`
<img width="259" height="162" alt="image"
src="https://github.com/user-attachments/assets/278fdabd-1a24-4769-972e-1bce29060463"
/>

So intellisense will be running in the QueryEditor if intellisense is
enabled + source selected is database, otherwise will not run.

<img width="982" height="411" alt="image"
src="https://github.com/user-attachments/assets/19497aa0-36fc-49ab-853d-cb938b5b18e7"
/>


Also updated `useAddDefinition` logic to flush the table columns +
functions cache in react query
- For context in the past we had users run into browser performance
issues when definitions were loaded if their database is really big
- Hence why we originally added this intellisense toggle
- But we previously also required users to refresh the browser after
disabling intellisense, as a manual way to flush the cache
- So this change should remove the need to refresh the browser after
disabling intellisense

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added PostgreSQL IntelliSense with definitions, formatting, and code
completions in SQL editors.
* Added a notebook option to enable or disable IntelliSense, with the
preference saved between sessions.
  * Improved the notebook’s empty-state appearance.

* **Bug Fixes**
* Improved IntelliSense cleanup and prevented duplicate registrations
when disabled.
* Improved query execution state handling while background IntelliSense
data loads.

* **Tests**
* Added coverage for shared registration, cleanup, preference
persistence, and IntelliSense-related query handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 01:47:39 +08:00
Joshen Lim 9738035fec Hook up recently updated list (#49296)
## Context

As per PR title: recently updated list just comprises of notebooks and
chats
Note: known API issue that save a notebook doesn't update its
`updated_at` value, so you'll notice that if you save a notebook it
doesn't move up the recently updated list

<img width="281" height="270" alt="image"
src="https://github.com/user-attachments/assets/f637a593-09a7-4df4-85b7-43637f04738d"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added a home view displaying recently updated notebooks and chats.
  * Recent items are sorted by update time and limited to five entries.
  * Added relative timestamps in minutes, hours, or days.
* Chat entries open directly, while notebook entries link to their
explorer view.
  * Added an empty state when no recent items are available.

* **Bug Fixes**
  * Excluded unsupported chat types from recent-item results.
  * Improved handling of unavailable timestamps.

* **Tests**
* Added coverage for sorting, filtering, limits, and relative-time
formatting.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-21 00:02:53 +08:00
Charis e7c3cad8de feat(evals): add notebook eval cases and forbiddenTools scorer capability (#49104)
## Summary

- Added ~11 new eval cases for Notebooks AI assistant evals, including:
basic notebook cell creation, multi-cell composition
(markdown+database+log), log cell time ranges, row_limit defaults, chart
config, destructive SQL safety warnings, and hallucination guards for
nonexistent tables
- Extended `toolUsageScorer` with deterministic `forbiddenTools` field
to score both required and forbidden tool usage, enabling eval cases to
assert tool choice (e.g., `execute_sql` vs `create_notebook`) without
LLM-as-judge
- Extended SQL validators
(`sqlSyntaxScorer`/`sqlIdentifierQuotingScorer`) to validate SQL inside
`create_notebook` database cells (log cells deliberately excluded as
they use ClickHouse dialect)
- Fixed two real assistant issues in `NOTEBOOKS_PROMPT`: (a) reuse
`CLICKHOUSE_LOGS_COMPLETION_INSTRUCTIONS` and schema section to prevent
incorrect BigQuery-style SQL in logs queries, (b) require schema
verification before writing `database_cell` to prevent queries against
nonexistent tables

Resolves FE-4087

## Test plan

- All 11 new eval cases run live against OpenAI via Braintrust; traces
inspected and validated
- Existing unit tests, lint, and typecheck pass

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added support for creating notebooks with database, Markdown, chart,
and log cells.
* Improved handling of reusable notebook requests versus one-off SQL
queries.
* Added guidance for modern ClickHouse SQL and absolute log time ranges.

* **Bug Fixes**
* Improved SQL validation, row-limit enforcement, and destructive-query
safety.
  * Prevented invalid or nonexistent-table queries from being accepted.
  * Improved validation of notebook cell types and tool usage.
  * Improved handling of ClickHouse log queries and database-cell SQL.
* Improved evaluation reliability by limiting concurrent test execution.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 15:58:58 +00:00
Jordi Enric 2e65e82ef4 docs(platforms): query logs via the ClickHouse endpoint (#49299)
The `logs.all` Management API endpoint runs BigQuery SQL and is being
retired next month. The Platforms guide was the only hand-written doc
still pointing at it.

Repoints the debugging example at `GET
/v1/projects/{ref}/analytics/endpoints/logs`, which serves the same data
as a single `logs` table keyed by `source`, with structured fields in
the `log_attributes` map, and converts the query to the ClickHouse
dialect.

Verified by running the example's exact SQL and curl shape against a
real project on the OTEL logs endpoint: 100 rows, with `status_code` and
`path` populated.

The generated API specs still list `logs.all`; those regenerate from the
platform side.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Updated the Supabase for Platforms integration guide’s
debugging-projects example.
- Revised the example to use the analytics logs endpoint and unified
logs table.
- Added ClickHouse SQL filtering for edge logs, structured log
attributes, and HTTP errors.
- Improved the example’s alignment with current log query and analytics
capabilities.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 17:55:00 +02:00
Jordi Enric 6c6ac567b1 feat(studio): workers list behind the workers flag (FE-4188) (#49193)
## What

The Workers list page at `/project/[ref]/workers`, behind
`useFlag('workers')`. Reads `GET /v2/projects/{ref}/workers`.

- Sidebar and command-menu entries, both hidden when the flag is off
- Name search, state and access filters, pagination
- Read-only

Gating, in order: flag off redirects to the project home; a 404 from the
API means the project is outside the alpha allow-list ("not enabled for
this project"); a 403 means the caller lacks the permission
(`NoPermission`); anything else is an `AlertError`.

`parseWorker` in `data/workers/workers.utils.ts` is the only place the
API shape becomes the view model. It validates with zod, so a drifted
response fails the query instead of half-rendering a row.

## How to test

Only on the **Mockamaster** project in staging — it is the one project
in the alpha allow-list, and standing a worker up anywhere else is
involved right now.

1. Staging dashboard → Mockamaster → **Compute** in the sidebar
2. Expect the `dashboard-test` worker: state `Active`, runtime Deno,
private, US West, 2 GB · 1 vCPU · 1 inst
3. Open any other project's `/workers` URL → "Compute is not enabled for
this project"
4. Turn the `workers` flag off → the sidebar entry disappears and the
URL redirects to the project home

Closes FE-4188
2026-08-20 17:54:57 +02:00
Ali WaseemandJordi Enric 01d12e83c1 docs: migrate logs queries to ClickHouse and link to the SQL Editor (#49273)
The 47 BigQuery-era logs queries across these 20 pages error on the
ClickHouse-backed logs engine ("Backend error! Retry your query."). This
converts them per the rules in `apps/studio/lib/ai/clickhouse-logs.ts`
and repoints every Logs Explorer link at the SQL Editor with the query
source set to **Logs**, since the Logs Explorer is being retired. Also
fixes two stale PostgreSQL 12 links in the tables guide.

Each of the 14 prefilled links was verified to decode back to exactly
the SQL shown on its page. One caveat for review:
`response.headers.proxy_status` in `postgrest-error-codes.mdx` is
unverified — it isn't in the published field reference, and the test
project had no `edge_logs` traffic to confirm against.

Fixes DOCS-1331

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Updated database, storage, API, and Edge Function logging guides to
use the SQL Editor and current Logs interface.
- Replaced legacy Log Explorer and BigQuery examples with current query
syntax and structured log fields.
- Refreshed troubleshooting queries for error diagnosis, filtering,
aggregation, and performance analysis.
- Improved examples with clearer source filters, status handling,
request details, joins, and result limits.
- Updated PostgreSQL documentation links and clarified how API error
codes appear in responses.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jordi Enric <jordi.err@gmail.com>
2026-08-20 17:07:25 +02:00
fadymak 344656edc5 fix(auth): add limits to session timouts and reuse inverval (#49312)
Currently, sessions timeouts and reuse interval inputs accepted any
values. This PR caps:

- absolute session timeout to 1 year
- inactivity timeout to 1 year
- refresh token reuse interval to 300 seconds

Since these maximums are introduced _after_ some projects have values
that exceed the new limits, we allow the users to save the form if their
values exceed the max but are unchanged. However, if they decide to
change the value, it must fit within the limits.

<img width="1195" height="402" alt="Screenshot 2026-08-20 at 15 45 49"
src="https://github.com/user-attachments/assets/192420e8-4878-4e4b-9d82-0d1cc4074728"
/>

<img width="1194" height="512" alt="Screenshot 2026-08-20 at 15 46 06"
src="https://github.com/user-attachments/assets/bb333c54-daa3-46ac-b144-96263428f4d7"
/>

<img width="1168" height="323" alt="Screenshot 2026-08-20 at 15 46 35"
src="https://github.com/user-attachments/assets/ae38fcf6-bc73-453f-a61b-2d6f2d0ecfee"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Added clear maximum-value guidance for session and refresh-token
settings.
* Existing projects with previously configured values above new limits
can retain those values while making unrelated changes.
* Removed session-related settings from the protection authentication
form.

* **Bug Fixes**
* Improved validation for session timeouts, JWT expiration, and
refresh-token reuse intervals.
* Added clearer validation messages and support for reducing previously
over-limit values.

* **Tests**
* Expanded coverage for boundary values, invalid inputs, saved settings,
and submitted configuration updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 14:30:41 +00:00
Joshen Lim 2893c783d5 Hook up APIs for Notebooks CRUD (#49254)
## Context

API changes are ready so hooking up the endpoints for full CRUD UX E2E
- Can create notebooks
- Can load notebooks
- Can delete notebooks
- Can update notebooks
2026-08-20 22:23:20 +08:00
65033221fb feat(studio): add logs.all deprecation banner (#49059)
Informational banner for the `logs.all` Management API removal on Sept
23, in the Logs and Observability sections.

* Untargeted. Whether a project calls the endpoint is behaviour that no
API response carries, so precise targeting needs a mgmt-api change (we
aimed for speed and less complexity here). Copy is informational rather
than "action required" since most viewers won't be affected.
* Uses `BannerStack` (bottom-right card) rather than the top header
banner, at priority 4 so it renders as the front card. Note this pushes
`database-connections-banner` (p2) and `index-advisor-banner` (p3) into
peek slivers on Observability.
* Short Notice card: title, one line of copy with `logs.all` inline, and
a Learn more link to the changelog.
* Waits for localStorage before showing, and BannerStack ignores stale
dismiss timers when a banner is revived (avoids flash-then-disappear on
refresh).
* Dismiss is browser-level; self-expires Sept 24 via
`LogsAllDeprecationExpiry`.
* Cleanup tracked in GROWTH-1104.
* Tested in staging.

Check in:

- /project/_/logs (unified logs)
- /project/_/logs/explorer
- /project/_/observability

| After |
| --- |
| <img width="626" height="528" alt="CleanShot 2026-08-20 at 12 29
49@2x"
src="https://github.com/user-attachments/assets/2044966d-bc83-4f88-ac75-1b8ff80be08d"
/> | <img width="622" height="440" alt="CleanShot 2026-08-20 at 12 28
33@2x"
src="https://github.com/user-attachments/assets/1dc768cd-837c-4a5a-a3fa-7b6986fe5876"
/> |

Resolves GROWTH-1093.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## New Features
* Added a dismissible notice about the `logs.all` endpoint retirement on
September 23, 2026.
* The notice appears on relevant Logs and Observability pages with
streamlined migration guidance.
* Clarified that dashboard logs remain unchanged.
* Dismissal preferences are saved, and notices remain visible or are
removed reliably during navigation.

## Telemetry
* Added tracking for notice display and dismissal interactions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Danny White <dnywh@users.noreply.github.com>
2026-08-20 14:17:20 +00:00
Ali Waseem e5f12b4252 fix(docs): fix step code block spacing and Prisma guide tabs (#49263)
Two fixes for the [Prisma
guide](https://supabase.com/docs/guides/database/prisma):

- `StepHikeCompact.Code` marked its whole subtree `not-prose`, so the
labels and admonitions that steps interleave with their code samples
rendered at 16px with zero margins, flush against the samples and tab
bars. Dropping `not-prose` restores body typography and spacing;
back-to-back samples now get a gap too, since they have no prose between
them.
- The guide's three outer tab groups omitted `type`, so they fell back
to pill styling — the only pills among 395 `<Tabs>` in the content tree.

Fixes DOCS-1327

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Improved spacing and prose behavior for code samples in the
documentation.
  * Preserved existing code margin customizations.
* Updated Prisma guide tabs with a consistent compact, underlined
appearance.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 08:09:20 -06:00
Charis 474bf5da4a fix(studio): reset rename form between same-named SQL snippets (#49275)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

In the SQL Editor, when two snippets are both named "Untitled query" and
one is renamed, the rename modal's state is not reset afterwards.
Opening the rename modal for the second snippet prefills the input with
the first snippet's new name, and the second snippet can't be renamed at
all because the "Rename query" button stays disabled.

`RenameQueryModal` fed the snippet to react-hook-form through the
`values` option, which only re-runs its reset when the values object
deep-changes. Two snippets with the same name (and no description)
produce a deep-equal object, so switching between them never resets the
form — it keeps the previously renamed name and stays non-dirty.

## What is the new behavior?

The form is mounted per snippet (`key={snippet.id}`) with plain
`defaultValues`, so no form state can carry over between snippets
regardless of name collisions. `SQLEditorNav` derives modal visibility
from the selected snippet and clears it on cancel/complete, matching
`SearchList`.

Covered by a new component test in `RenameQueryModal.test.tsx` that
renames one "Untitled query", reopens the modal for a second one, and
asserts the field resets and the second rename submits.

## Additional context

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed the rename dialog retaining input from a previously renamed
snippet.
* Ensured the rename form resets correctly after successful submission
and when switching between snippets.
* **Tests**
* Added regression coverage for renaming multiple untitled snippets with
the same original name.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 09:09:45 -04:00
David Camacho Cateura 1a483ab255 feat: Show all partner audit logs fields (#49305)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Changes to the audit logs UI

## What is the current behavior?

Partner related fields in the audit logs are not shown

## What is the new behavior?

- Shows all partner related fields in the audit logs
- Also uses the new fields to compute the user name



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Audit log entries now display partner names, installation IDs, user
emails, and user IDs when available.
* Partner identity and email are shown when standard actor details are
unavailable.
  * Partner names are consistently formatted for clearer display.
* Entries without partner information continue to display cleanly
without blank or confusing actor details.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 14:39:38 +02:00
Pamela Chia 65e786ba13 feat(docs): manifest-gated markdown alternate helper (#48389) 2026-08-20 19:18:47 +08:00
Saxon Fletcher a045804e73 OAuth Consent Block (#48917)
<img width="1510" height="860" alt="image"
src="https://github.com/user-attachments/assets/36a748b7-bdeb-4685-8bb1-da911711874b"
/>


Introduces a new OAuth consent block in preparation for offering more
MCP focused blocks that require authentication and consent. The general
approach for this is to decouple consent block from authentication block
but provide guidance on how to use both. The alternative is to add auth
as a dependency to consent but apps may already have their own
authentication UI / flows.

The block is also positioned as a general OAuth Consent vs MCP Consent
as it can be put to use for other use cases outside of MCP on projects
who want to make use of the OAuth 2.1 Server offering.

A couple of changes outside of the block itself were required:
- Updated the Auth blocks to allow for a `next` param to redirect users
to after signing in
- Updated middleware so next param is correctly passed through to sign
in

## How to test

Requires Docker and a Supabase CLI recent enough to support
`[auth.oauth_server]` (verified on 2.109.0 / GoTrue v2.192.0).

### 1. Local Supabase with the OAuth server enabled

In your `supabase/config.toml`, edit the existing `[auth.oauth_server]`
section — `supabase init` already writes one, and adding a second fails
with `table oauth_server already exists`:

```toml
[auth.oauth_server]
enabled = true
authorization_url_path = "/oauth/consent"
allow_dynamic_registration = true
```

Set `site_url` to wherever your test app runs (e.g.
`http://localhost:3100`), then `supabase start`. Grab the API URL and
publishable key from `supabase status`.

### 2. A consumer app with the blocks installed

The consent block ships no login route by design, so pair it with an
auth block:

```bash
npx create-next-app@latest consent-test --ts --tailwind --app --yes
```

```bash
cd consent-test && npx shadcn@latest init -d -y && npx shadcn@latest add https://supabase.com/library/r/password-based-auth-nextjs.json https://supabase.com/library/r/oauth-consent-nextjs.json
```

To test this branch before it deploys, run `pnpm --filter ui-library
dev` and use `http://localhost:3004/library/r/...` instead. If you
changed anything under `registry/default/blocks/oauth-consent/**`, run
`pnpm --filter ui-library build:registry` first — shadcn fetches the
generated `public/r/*.json`, not the source.

Put `NEXT_PUBLIC_SUPABASE_URL` and
`NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY` in `.env.local` and start the app
on the port you set as `site_url`.

### 3. Register an OAuth client and start a real authorization request

```bash
curl -s -X POST http://127.0.0.1:54321/auth/v1/oauth/clients/register -H "Content-Type: application/json" -d '{"client_name":"Test Client","redirect_uris":["http://localhost:3100/callback"],"grant_types":["authorization_code"],"response_types":["code"],"scope":"openid profile email"}'
```

Then open the authorize URL in a browser (not curl — you need the
redirect chain and cookies):

```
http://127.0.0.1:54321/auth/v1/oauth/authorize?client_id=<id>&response_type=code&redirect_uri=http://localhost:3100/callback&scope=openid+profile+email&state=xyz&code_challenge=<challenge>&code_challenge_method=S256
```

Auth mints the `authorization_id` and redirects to
`<site_url>/oauth/consent?authorization_id=…`. An MCP client pointed at
your app is an even better driver, since that's the real consumer shape.

### 4. Cases to walk

| Case | Expected |
| --- | --- |
| Signed out, hit the authorize URL | Lands on
`/auth/login?next=%2Foauth%2Fconsent%3Fauthorization_id%3D…`; after
login, returns to the consent screen |
| Consent screen | Shows client name, redirect URI, signed-in email, and
requested scopes from `getAuthorizationDetails` |
| Allow access | Redirects to `redirect_uri` with `code` and your
original `state`; the code exchanges at `/oauth/token` for a real access
token |
| Deny | Redirects with `error=access_denied` and your `state` |
| Re-run the same authorize URL after approving | Skips the screen,
straight to callback with a new code |
| Visit `/oauth/consent` with no `authorization_id` | "This page needs
an authorization_id" |
| Stale or bogus `authorization_id` | Error shown, buttons still usable
|
| Double-click Allow | Exactly one `POST
/oauth/authorizations/<id>/consent` |

Test the react, react-router, or tanstack variant the same way if you're
touching them — the hook is duplicated per framework, so a fix in one
doesn't carry.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added an OAuth 2.1 consent experience with client details, requested
scopes, redirect URI, and approve/deny actions.
* Added OAuth consent examples and registry blocks for Next.js, React,
React Router, and TanStack Start.
* Added OAuth documentation, navigation, and framework support across
the UI library.
* **Bug Fixes**
* Login flows now safely preserve valid same-origin redirect
destinations while rejecting unsafe URLs.
* OAuth routes can handle consent flows before authentication and
redirect safely to sign-in.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 20:05:35 +10:00
Saxon Fletcher 81bccd6862 notebook preview refine (#49288)
<img width="840" height="507" alt="image"
src="https://github.com/user-attachments/assets/d0f4667f-a7bb-4afe-95b2-a9e224adcbb5"
/>

<img width="848" height="597" alt="image"
src="https://github.com/user-attachments/assets/beb0c239-d36c-4103-ab07-8a3872ba3f30"
/>

Updates how we display Notebooks in Assistant to be more in line with
our AssistantQueryCell.

## To test:
- Open Assistant and ask it to create a test notebook and note the new
styling

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added unified, read-only notebook previews for create and update
proposals.
* Preview cells now support expandable content, clearer type icons,
metadata, and “Show more” controls.
  * Added before-and-after metadata comparisons for replaced cells.
* Integrated previews into confirmation cards with approval, skip, and
refresh actions.
  * Added skip-only confirmation flows when approval is unavailable.

* **Bug Fixes**
* Improved handling of parse failures, stale notebooks, invalid changes,
and loading errors.

* **Style**
* Refined confirmation card layouts, borders, spacing, and footer
presentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 19:51:20 +10:00
Inder Singh 768cf11b9c feat(self-hosted): add pgbouncer override (#49052) 2026-08-20 11:21:54 +02:00
Danny White facc2df09e chore(design-system): generate and ignore registry output (#49290)
## What kind of change does this PR introduce?

Chore. Stops committing generated design-system registry output
([DEPR-647](https://linear.app/supabase/issue/DEPR-647/generate-and-ignore-design-system-registry-output)).

## What is the current behavior?

`apps/design-system/__registry__` is build output from `registry/`, but
the chart snapshots and index are committed. That makes reviews noisy,
and a forgotten `build:registry` leaves `master` out of date until
someone else regenerates it.

## What is the new behavior?

`pnpm dev` and `pnpm typecheck` generate `__registry__` automatically.
The directory is gitignored, and the previously tracked snapshots are
removed. `pnpm build` still generates it as before.

## To test

- From the repo root, run `pnpm --filter=design-system
generate:registry` and confirm
`apps/design-system/__registry__/index.tsx` is created locally and is
untracked.
- Run `pnpm dev:design-system`, open
[http://localhost:3003](http://localhost:3003), and open any component
docs page with a live preview (for example Charts). Previews and source
panels should still load.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified when the component registry is generated and how to
regenerate it.
* Expanded component documentation guidance, including content sources
and generated-file editing restrictions.

* **Chores**
* Improved registry generation across development, type checking,
builds, and cleanup.
* Generated registry files are now excluded from version control and
linting.
* Improved reliability when creating and refreshing generated registry
files.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 18:34:46 +10:00
Pamela Chia 9ae6e54dd5 fix(www): exclude redirected slugs from generated markdown (#48476)
11 of the generated `MD_PAGES` entries are blog slugs whose HTML pages
308-redirect away via `apps/www/lib/redirects.js` before any `<head>`
renders. They can never carry an alternate tag and Accept negotiation
never fires (Next.js `redirects()` runs before middleware), so their
`.md` siblings are orphaned content reachable only by guessing the
suffixed URL. Six of them duplicate live, correctly-tagged pages
(`/customers/*`, `/pricing`).

**Changed:**
- `generateMdContent.mjs` derives an exclusion set from
`lib/redirects.js` at generation time: any unconditional exact-match
redirect source (wildcard/param patterns and conditional `has`/`missing`
redirects are skipped) drops the matching slug from both `MD_CONTENT`
and `MD_PAGES`. The build log names every excluded slug, currently the
11 known ones.
- Self-maintaining by design (per the decision recorded on the issue): a
future redirected post auto-excludes on the next build, and removing a
redirect brings its `.md` sibling back. The MDX sources stay in the
repo; nothing is deleted.
- Effect on the 11 slugs: alternate tags stay absent (nothing rendered
them anyway), and explicit `.md` URLs go from serving orphaned markdown
to 404, the same external effect deletion would have had.

## To test

Tested locally:
- [x] `node scripts/generateMdContent.mjs` logs `🚫 Excluded 11
redirected slugs: ...` naming exactly the 11 known slugs; output drops
483 → 472 pages
- [x] Generated file carries no MD_CONTENT/MD_PAGES key for any excluded
slug (raw URL mentions inside other posts' bodies remain, as expected)
- [x] `apps/www` vitest: 71/71 (GROWTH-1013 drift tests unaffected)

Post-merge:
- [ ] `https://supabase.com/blog/case-study-xendit.md` returns 404
(previously 200 orphaned markdown); `https://supabase.com/pricing.md`
still 200

## Linear
- fixes GROWTH-1022


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Excluded content with valid exact-path redirects from generated
documentation.
  * Preserved content associated with conditional or wildcard redirects.
* Updated generated page counts and output statistics to reflect the
filtered content.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 15:23:13 +08:00
Joshen Lim dde45ab06c Joshenlim/fe 4195 explorer queryeditor cmd k completion support (#49248)
## Context

Adds the inline AI completion functionality into Explorer QueryEditor,
similar to what we've got for the existing SQL editor
- Shifts the `ResizableAIWidget` and `InlineWidget` components out of
the SQL Editor folder into `components/ui/AiEditor` to be used by both
SQL Editor and Query Editor
- Consolidates the "proposal" logic that was initially set up for the
Clickhouse Migration functionality with this Inline AI stuff
- Also added the prompt into the proposal header (Refer to the
screenshots below)
- SQL Editor didn't have this - but figured this is useful as context
for the user

<img width="935" height="352" alt="image"
src="https://github.com/user-attachments/assets/3f71539a-dda1-4763-be08-a850bdc8aec6"
/>

Source selected: Database
<img width="922" height="357" alt="image"
src="https://github.com/user-attachments/assets/81e772e6-dcc9-440d-83db-49d0d487dd13"
/>

Source selected: Logs
<img width="920" height="345" alt="image"
src="https://github.com/user-attachments/assets/83f1dae3-cf62-4424-be42-b06e70cb366d"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added AI-assisted SQL generation with contextual prompts and
OS-specific guidance.
- Review generated SQL changes in a diff, then accept, reject, or cancel
suggestions.
- Added inline, resizable AI prompt controls with loading and submission
states.
  - Added the Ctrl/Cmd+Shift+K shortcut to run AI SQL generation.

- **Improvements**
  - Added options to disable query execution and run custom actions.
  - Renamed “Recent” to “Recently updated.”
  - Improved editor widget positioning and display behavior.
  - Added clearer error notifications when AI generation fails.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 14:05:38 +08:00
Joshen Lim cf2322d198 Add delete chat functionality to explorer chats (#49250)
## Context

Just realised that chats in the new Explorer UI have no delete
functionality so this patches it
<img width="296" height="184" alt="image"
src="https://github.com/user-attachments/assets/90a79b6b-55a8-4122-8cd8-05fc13e9f4a5"
/>

Also added a confirmation modal for deletion
<img width="473" height="266" alt="image"
src="https://github.com/user-attachments/assets/56a1e400-2a1c-48b7-b6b8-0104af49b1a9"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
  - Added an option to delete Explorer chats from the chat toolbar.
- Added a confirmation prompt before permanently deleting chat history.
  - Added success feedback after deletion is completed.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 13:14:13 +08:00
CharisandJoshen Lim 8bdfe03fe7 refactor(studio): drop notebook type widening now that the API supports it (#49272)
## Summary

- Regenerates `packages/api-types` for the content endpoints now that
the Platform API's `notebook` content type has landed (list/get/upsert
`type` enums, plus `UpsertContentBody`'s notebook cell shape with
`_id`/`y_series`). Unrelated schema drift from the same regen
(Warehouse, SSO, notification exceptions, etc.) is excluded — only the
content-endpoint hunks are applied.
- Removes every local widening cast added while the API support was
pending (`content-query.ts`, `content-infinite-query.ts`,
`notebook-query.ts`, `notebook-upsert-mutation.ts`,
`sql-folders-query.ts`).
- What remains is scoped and renamed to match: draft ids
(`generateDraftId`/`isDraftId`), used only for cells created client-side
in the editor before their first save, dropped before they'd ever reach
the backend as a fake `_id`.

## Test plan

- [x] `pnpm typecheck` — clean
- [x] `pnpm --filter studio test` — full suite passes (518 files / 5471
tests)
- [x] `pnpm --filter studio run lint:ratchet` — no new warnings
- [x] `pnpm format` / prettier — clean

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved notebook cell tracking during editing, reordering, insertion,
and deletion.
* Preserved existing cell identifiers while removing temporary draft
identifiers before saving.
* Improved chart configuration for selecting and displaying multiple
Y-axis series.
  * Strengthened notebook validation and content persistence behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-08-20 13:06:41 +08:00
Joshen Lim b9ad5cede7 Bump monaco to 4.80 rc (#49265)
## Context

Resolves FE-4209

Client crash occurs when re-ordering a QueryCell in the new explorer UI
with the error "InstantiationService has been disposed"

Investigated this with Claude which eluded that it's a bug that's within
the Monaco package which `4.8.0-rc.3` actually patched hence opting to
upgrade the package. Verified that monaco still functions as expected +
re-ordering query cells in the explorer UI no longer crashes

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated the Monaco Editor integration to release candidate version
4.8.0-rc.3.
  * No visible end-user functionality changes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-20 12:26:31 +08:00
Saxon FletcherandCursor fd8ccf85b7 feat(studio): render assistant SQL with AssistantQueryCell (#49170)
<img width="1512" height="861" alt="image"
src="https://github.com/user-attachments/assets/404c9a27-dc10-497e-a5ec-003cd4b9705a"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature.

## What is the current behavior?

Assistant `execute_sql` tool parts and markdown SQL fences render
through `DisplayBlockRenderer`. The confirm footer is gated to the last
part of the last message, so a pending SQL approval can disappear if the
assistant keeps writing.

## What is the new behavior?

SQL tool parts and markdown fences use `AssistantQueryCell` inside
`Confirm`. The footer follows the same manual-approval helpers as Edge
Functions. `DisplayBlockRenderer` is removed.

## Additional context

Top of stack #49171. Base: `feat/assistant-query-cell` (#49169).

Does not wrap notebook create/update proposals. That depends on
[#49159](https://github.com/supabase/supabase/pull/49159) merging first.

## Test plan

- [ ] `execute_sql` approval shows Run query / Skip on the Confirm card
under the editor
- [ ] Footer still shows if the assistant writes text after the SQL tool
part
- [ ] Markdown SQL fences render as AssistantQueryCell without a confirm
footer
- [ ] After skip, the query cell remains so the user can run it locally
- [ ] Edge Function confirm from #49168 still works

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-20 11:35:35 +10:00
Saxon FletcherandCursor 6e64ad039c feat(studio): add AssistantQueryCell on the shared QueryEditor (#49169)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature.

## What is the current behavior?

Notebooks and query tabs use `QueryEditor`. Assistant SQL still uses
`DisplayBlockRenderer` / `QueryBlock`.

## What is the new behavior?

Adds `AssistantQueryCell`, a local-state wrapper around the shared
`QueryEditor` (`variant="viewport"`, `isRunDisabled` while confirming).
Nothing is wired into the conversation yet — that is #49170 — so this PR
is the reusable cell plus the small editor/report-container hooks it
needs.

## Additional context

Part of stack #49171. Base: `feat/assistant-confirm` (#49168).

## Test plan

- [ ] `AssistantQueryCell.utils.test.ts` passes
- [ ] Query editor still runs in Explorer notebooks / query tabs
- [ ] No assistant conversation UI change in this PR (still
DisplayBlockRenderer)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-20 11:35:35 +10:00
bd76d7fc34 feat(studio): wrap assistant Edge Function approval in a Confirm card (#49168)
<img width="1512" height="862" alt="image"
src="https://github.com/user-attachments/assets/79a6d4dc-dcd2-489f-97d7-3ee7a0196b7d"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature / UI refactor.

## What is the current behavior?

Assistant Edge Function approval nests `ConfirmFooter` under the
function block. `addToolApprovalResponse` is wired whenever state is
`approval-requested`, including automatic approvals.

## What is the new behavior?

Introduces a `Confirm` card that owns the frame, with the footer
attached below the body. Edge Function approval uses that card.
Interactive Approve/Deny only runs for manual `approval-requested` parts
(`!approval.isAutomatic`), matching the [AI SDK tool-approvals `useChat`
guidelines](https://ai-sdk.dev/docs/agents/tool-approvals).

SQL still uses `DisplayBlockRenderer` until #49170. `ConfirmFooter` is
inlined into `Confirm` so SQL can keep importing the named footer until
that PR.

## Additional context

Part of stack #49171. Base: `chore/ai-sdk-7` (#49167).

Notebook proposal Confirm wrapping is **not** in this stack — that file
lives on [#49159](https://github.com/supabase/supabase/pull/49159).
Follow up after that stack merges.

## Test plan

- [ ] Deploy-edge-function tool part shows Confirm with Skip / Deploy
- [ ] Existing-function replace warning still requires the second
confirm
- [ ] After approve, footer morphs to loading and buttons disable
- [ ] `Confirm.utils.test.ts` and `EdgeFunctionRenderer.test.tsx` pass

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added confirmation cards for AI-assisted actions, including approve
and cancel controls.
* Improved handling of manual approval requests for SQL execution,
notebook changes, and Edge Function deployment.
* Added support for customizing report and Edge Function block styling.

* **Bug Fixes**
* Automatic approvals no longer appear as pending manual confirmations.
  * Skipped SQL actions now provide clearer messaging.

* **Tests**
* Expanded coverage for approval states, confirmation controls, and
automatic decisions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 11:35:34 +10:00
claude[bot]andClaude 8a33c094b4 chore(www): add /evals to the sitemap (#49226)
<!-- ccr-slack-attribution -->
_Requested by **Sean Oliver** · [Slack
thread](https://supabase.slack.com/archives/C07P3AU3J2D/p1787036390117589?thread_ts=1787036390.117589&cid=C07P3AU3J2D)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore. One entry added to the www sitemap generator.

## What is the current behavior?

`https://supabase.com/evals` is missing from `sitemap_www.xml`, so
search crawlers are never told the page exists. `robots.txt` doesn't
block it, they just have no way to find it from the sitemap.

The reason is that `/evals` is served by a separate Vercel project and
only reaches supabase.com through a proxy rewrite in
`apps/www/lib/rewrites.js`:

```js
{
  source: '/evals',
  destination: 'https://supabase-evals.vercel.app',
},
```

`apps/www/internals/generate-sitemap.mjs` builds its URL list by
globbing local route source files (`pages/**`, `_blog/*.mdx`,
prerendered `.next/server/pages/**`, etc.) and never resolves rewrites.
There is no page file behind `/evals`, so the globs can't discover it.

Closes GROWTH-1113.

## What is the new behavior?

`https://supabase.com/evals` appears once in the generated
`sitemap_www.xml`, with the same `<changefreq>weekly</changefreq>` and
`<priority>0.5</priority>` as every other entry in the file (no entry in
this sitemap carries a `<lastmod>`).

The entry is a small named const spread into the final `urlset` join,
next to `changelogDetailUrls` — the existing precedent in this file for
URLs with no page file behind them. Nothing else in the script changed,
and the sitemap index output (`sitemap.xml`) is byte-identical.

```diff
+  // /evals is a separate app proxied onto supabase.com via a rewrite in lib/rewrites.js,
+  // so it has no page file for the globs above to find. Hardcode it here.
+  const proxiedAppUrls = [
+    `
+        <url>
+            <loc>https://supabase.com/evals</loc>
+            <changefreq>weekly</changefreq>
+            <priority>0.5</priority>
+        </url>
+      `,
+  ]
+
   const sitemap = `
     <?xml version="1.0" encoding="UTF-8"?>
     <urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
-        ${[...staticUrls, ...changelogDetailUrls].join('')}
+        ${[...staticUrls, ...changelogDetailUrls, ...proxiedAppUrls].join('')}
     </urlset>
     `
```

This only makes the URL discoverable. Whether the page content itself is
crawlable is separate work, tracked in the evals repo.

## Additional context

Verification, run locally against this branch. The generator runs
standalone (`node ./internals/generate-sitemap.mjs` from `apps/www`); a
missing `.next` just means the globs match fewer pages, and the missing
changelog RSS is caught internally.

I generated `sitemap_www.xml` from `master` and from this branch and
diffed the two. The added entry is the only difference:

```
3271a3272,3277
>
>   <url>
>     <loc>https://supabase.com/evals</loc>
>     <changefreq>weekly</changefreq>
>     <priority>0.5</priority>
>   </url>
```

Exactly one occurrence, with its neighbouring entry for context:

```
$ grep -c '<loc>https://supabase.com/evals</loc>' public/sitemap_www.xml
1

  <url>
    <loc>https://supabase.com/terms</loc>
    <changefreq>weekly</changefreq>
    <priority>0.5</priority>
  </url>

  <url>
    <loc>https://supabase.com/evals</loc>
    <changefreq>weekly</changefreq>
    <priority>0.5</priority>
  </url>
</urlset>
```

Other checks:

- Both outputs parse as well-formed XML (Python `xml.dom.minidom`):
`sitemap_www.xml` has 545 `<url>` elements, `sitemap.xml` parses OK.
- `sitemap.xml` (the sitemap index) is identical to the pre-change
output; `diff` reports no changes.
- `npx prettier --check internals/generate-sitemap.mjs` → "All matched
files use Prettier code style!"
- Both generated sitemaps are gitignored (`apps/www/.gitignore` lines
29-30), confirmed with `git check-ignore`. `git status` shows only
`apps/www/internals/generate-sitemap.mjs`, so no generated file is in
the commit.
- No test, snapshot, or fixture anywhere in the repo references the
sitemap generator, so there was nothing to run. Its only caller is
`apps/www`'s `postbuild` script.

Not run: `pnpm --filter=www build`. It fails during "Collecting page
data" on a clean `master` checkout in this environment too, so the
failure is pre-existing and unrelated, and this change needs no build to
verify.

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-19 23:15:29 +01:00
Miranda LimonczenkoandClaude Opus 5 6368f00ca0 docs(database): restructure the RLS guide by information type (#49017)
## Problem

The guide alternated between context, procedure, and reference on almost
every heading. A reader who wanted to write a policy passed through four
context or reference sections to reach one. A reader who wanted the
model had to skip three procedures.

## Solution

- Group into three sections by information type: `Understand Row Level
Security`, `Secure a table with RLS`, and `RLS reference`, with a
navigation intro.
- Merge the four policy sections. They repeated the same setup block,
burying the clause that differed. One setup block now precedes four
short policy examples.
- Move the auto-enable recipe into `event-triggers.mdx`, whose stub
section's entire body was a link back here.
- Relocate the stranded `auth.uid()` caution into the `auth.uid()`
reference.
- Lift the revoke-and-grant procedure out of the danger admonition and
merge it with the two other places that taught `enable row level
security`.
- Point the Grafana IO chart entry at the performance guide. Its
`#rls-performance-recommendations` anchor went away when tuning split
out in #49016.

765 lines to 582. 30 headings to 25.

Headings are demoted rather than renamed wherever anything links to
them. Every inbound anchor in the repo still resolves; the only one
removed, `#auto-enable-rls-for-new-tables`, was referenced solely by the
`event-triggers.mdx` stub this PR replaces.

## Note on the history

Rebuilt from `master` after #49011, #49015, and #49016 merged. The
branch previously carried those 10 commits plus rebase churn against
them.

Rebasing naively would have reverted review feedback from #49016
(`70fa812`), which removed the benchmarks table and the "This guide"
opener from the performance guide. Those are deliberately not restored
here. The only changes to that file are two missing `await`s and a join
predicate that was a tautology while unqualified.

The three PRs stacked on this one (#49268, #49269, #49270) have been
rebased onto the new base.

## Manual testing

1. Open the [Row Level Security
guide](https://docs-git-docs-rls-restructure-supabase.vercel.app/docs/guides/database/postgres/row-level-security)
on the preview. Three top-level sections appear in the table of
contents.
2. Select each link in the intro. All three jump to their section.
3. Open [Event
triggers](https://docs-git-docs-rls-restructure-supabase.vercel.app/docs/guides/database/postgres/event-triggers).
The auto-enable section holds the full recipe instead of a link.
4. Open the [performance
guide](https://docs-git-docs-rls-restructure-supabase.vercel.app/docs/guides/database/postgres/row-level-security-performance).
No benchmarks table, and the three bullets at the top link into the RLS
guide.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reworked the Row Level Security guide with clearer guidance on grants,
policies, permissions, performance, testing, views, and secure
functions.
* Added a complete example for automatically enabling RLS on newly
created public tables.
* Improved SQL examples and clarified table references in RLS
performance guidance.
* Corrected grammar in the Grafana chart troubleshooting documentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 14:51:06 -07:00
2bc6144aec fix(studio): guard unguarded requester.name reads on the OAuth authorize and apps pages (#49267)
<!-- ccr-slack-attribution -->
_Requested by **Ali Waseem** · [Slack
thread](https://supabase.slack.com/archives/C063LNYJJKS/p1787146439389169)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix.

## What is the current behavior?

Opening `/authorize` for an OAuth app whose `name` the platform API
omitted crashed the entire page with `TypeError: Cannot read properties
of undefined (reading 'toLowerCase')`
([SUPABASE-APP-K7E](https://supabase.sentry.io/issues/7679644991/)). The
user got a full-page error instead of a consent screen, and could
neither authorize nor decline.

The same class of crash hit the project-level OAuth apps list
([SUPABASE-APP-JB1](https://supabase.sentry.io/issues/7502074939/)).
Typing in the search box called `.toLowerCase()` on `client_name` for
every app, so one app registered without a name broke search for the
whole list.

The project-claim page crashed the same way, reading the first character
of the name for the fallback avatar.

## What is the new behavior?

The trusted-partner helpers treat a missing name as "no trusted partner
matched" and return `null`. The apps filter treats a missing name or
client ID as "does not match the search string". The claim page falls
back to a placeholder initial instead of indexing into `undefined`.

The authorize page now renders normally, minus the optional
partner-impersonation caution, which cannot be evaluated without a name.

Three changes:

-
`apps/studio/components/interfaces/Organization/OAuthApps/OAuthApps.utils.ts`
— `findTrustedPartnerByName` accepts `string | null | undefined` and
returns `null` early on a falsy name; `getOAuthImpersonationWarning`'s
`name` param widened to match (its existing `if (!namedPartner) return
null` already handles the rest).
- `apps/studio/components/interfaces/Auth/OAuthApps/oauthApps.utils.ts`
— `filterOAuthApps` optional-chains `client_name` and `client_id` before
`.toLowerCase()`, defaulting each match to `false`.
-
`apps/studio/components/interfaces/Organization/ProjectClaim/confirm.tsx`
— `{requester.name?.[0] ?? '?'}` for the fallback avatar initial.

Each is a separate commit so any one can be dropped independently.

## Additional context

### Root cause, not fixed here

`apps/studio/data/api-authorization/api-authorization-query.ts:37`
returns `data as ApiAuthorizationResponse`, an unchecked cast with no
runtime validation, even though the openapi-fetch client already types
the endpoint from the generated schema. Both the generated
`GetOAuthAuthorizationResponse` and the hand-written local type declare
`name: string` as required, so this was invisible to TypeScript.

The durable fix is to derive the type from the schema and drop the cast,
which is the house pattern elsewhere in `apps/studio/data`, and to
correct the OpenAPI spec at source if the API can legitimately omit
`name`. Left out deliberately to keep this cherry-pickable.

### Not in scope

`requester.scopes` is optional in the schema but required in the local
type, and is read unguarded in several places. Defaulting it to `[]`
would tell a user an app requested no permissions on a live consent
screen, so it needs a product decision rather than a drive-by guard.

### Testing

No local checks were run. This clone has no `node_modules` and `pnpm
install` is blocked in the environment, so `npm run build`, typecheck,
lint, Prettier and tests were all left to CI. Please treat CI as the
verification for this PR.

There is also a coverage gap worth noting:
`apps/studio/tests/components/ApiAuthorization.test.tsx:48-62` hardcodes
`name: 'Test App'` in `createMockAuthResponse`, and no test omits the
field, which is why none of these crashes were caught.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01P489vrPdHcJfMfzCGM9rZ5)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-19 14:23:54 -06:00
Miranda LimonczenkoandClaude Opus 5 edf50668aa docs(database): split RLS tuning into its own guide (#49016)
Stacked on #49015, which is stacked on #49011. Review those first.

## Problem

The Row Level Security guide spent 225 lines and 5 benchmark tables on
performance, 29% of the page. The `RLS Performance and Best Practices`
troubleshooting entry already covers the same six tips with the same
numbers, from the same source. Neither page tells you how to check
whether RLS is your bottleneck in the first place.

Four of the six tips are not tuning advice. Indexes, `select`-wrapping,
role scoping, and `security definer` safety change whether a policy is
correct and safe, not just fast.

## Solution

- Add `guides/database/postgres/row-level-security-performance`. It
carries the client-filter rule, the join-rewrite rule, all 5 benchmark
tables merged into one, and a new `Diagnose whether RLS is the
bottleneck` section: toggle RLS off to confirm it's the cost, then read
the plan under an impersonated role. That diagnostic exists in the
troubleshooting entry and has never been in the guide.
- Keep every rule that affects correctness on the RLS guide, grouped
under `Write policies that scale`. These are also the four the
`build-docs-002-rls-guide` eval grades, and an agent reads the guide
top-down.
- Repoint the Grafana IO troubleshooting entry at the new page.
- Rewrite `More resources` as `Related content`. Every link now says
what it is and when to use it. Adds `Advanced pgTAP testing`, the
deepest RLS testing content in the docs, which nothing here linked.
Drops discussion 14576: locked, mislabeled here as "RLS Guide and Best
Practices" when it is "RLS **Performance** and Best Practices", and
superseded by the troubleshooting entry and this new page.

**Ownership rule** so the two pages don't drift: the RLS guide owns the
rule and the correct form. The performance page owns the measurement and
the optimizer explanation. If a sentence on the performance page tells
you what to write, it belongs on the guide.

Scoped out of this PR: `More resources` was assigned to the restructure
PR in the plan, but the 14576 link is what this PR supersedes, so
leaving it would ship a stale pointer.

## Manual testing

1. Open the [RLS performance
guide](https://docs-git-docs-rls-performance-split-supabase.vercel.app/docs/guides/database/postgres/row-level-security-performance)
on the preview. It appears in the left nav under Database, Access and
security, directly below Row Level Security.
2. Select the three rule links in its intro. Each lands on the matching
section of the RLS guide.
3. Open the [Row Level Security
guide](https://docs-git-docs-rls-performance-split-supabase.vercel.app/docs/guides/database/postgres/row-level-security)
and go to `Write policies that scale`. It holds indexes,
`select`-wrapping, and role scoping, with one link out to the
performance page.
4. Open the [Grafana IO troubleshooting
entry](https://docs-git-docs-rls-performance-split-supabase.vercel.app/docs/guides/troubleshooting/interpreting-supabase-grafana-io-charts-MUynDR)
and select the RLS performance guide link. It lands on the new page.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added a dedicated guide for diagnosing and improving PostgreSQL Row
Level Security performance.
* Expanded guidance on indexing, query filters, role targeting, function
usage, and avoiding costly policy joins.
* Updated the Row Level Security guide with streamlined, scalable policy
recommendations and links to related resources.
* Added the new performance guide to the Database documentation
navigation.
* Updated troubleshooting guidance to reference the dedicated
performance guide.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 10:41:08 -07:00
kanadandClaude Fable 5 1b01a9c8af feat: table for collecting interfaces feedback (#48420)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Database migration — adds a table for collecting free-form product
feedback submitted from Supabase interfaces (starting with the CLI and
the MCP server), including support for deleting a submission via a
server-issued token.

## What is the current behavior?

There is no destination for feedback submitted from the CLI or MCP
server. The existing `feedback` and `feedback_comments` tables are
scoped to the docs feedback widget, so interface feedback would
otherwise end up as ad-hoc GitHub issues — with no way to revoke
something submitted by accident (e.g. a secret key pasted into the
message).

## What is the new behavior?

Adds `public.interfaces_feedback`:

| Column | Type | Notes |
| --- | --- | --- |
| `id` | `bigint` identity | primary key (not exposed through the API) |
| `created_at` | `timestamptz` | `not null default now()` |
| `feedback` | `text` | `not null`, ≤ 1000 chars — the free-form
feedback |
| `delete_token` | `uuid` | server-generated, `unique not null`;
authorizes deleting the row |
| `user_agent` | `text` | ≤ 255 chars; interface + version, also
identifies the source interface |
| `user_id` | `text` | optional, ≤ 255 chars; unverified,
interface-defined identifier |
| `project_ref` | `text` | optional, ≤ 255 chars |
| `metadata` | `jsonb` | ≤ 8 KB catch-all |

**Submission** happens exclusively through a `SECURITY DEFINER`
function, `submit_interfaces_feedback(...)`, which inserts the row and
returns the server-generated `delete_token` exactly once. There is no
insert grant or policy on the table itself, so clients cannot insert
directly or supply their own token — the function is the only door.
Execute is revoked from `PUBLIC` and granted to `anon` only (both
statements matter: local and hosted databases have different default
function ACLs).

**Deletion** is a hard `DELETE` authorized by presenting the token in an
`x-feedback-token` request header. RLS policies compare the row's
`delete_token` against that header (`current_setting('request.headers',
...)`) — the URL filter is never the security boundary; a request
without the matching header affects zero rows, even with no filter or
someone else's token in the filter. Tokens never expire (the delete
right shouldn't lapse). The header is cast to `uuid` and compared
against the untransformed column, so lookups use the unique index on
`delete_token` even for header-only reads; a malformed token header is
rejected with a `400` (`22P02`), consistent with what a malformed URL
filter value already returns.

**Context gate (defense-in-depth)**: rows submitted with a `project_ref`
and/or `user_id` additionally require the matching
`x-feedback-project-ref` / `x-feedback-user-id` headers — on both reads
and deletes — so a leaked bare token can neither read the submission
text back nor remove the row. A `NULL` column imposes no requirement:
context-free rows keep token-only behavior, and extra headers sent
against them are ignored (this keeps clients that always send their
current context from being locked out of rows submitted without it).
These are client-supplied, unverified values, so the gate is a knowledge
factor rather than an identity check; clients should persist
`{delete_token, project_ref, user_id}` together at submit time and
re-present them byte-exact (`project_ref`/`user_id` are compared as
plain text).

**Reads** are limited to `grant select (feedback, delete_token)` behind
the same token-scoped policy: a token-holder can preview their own
submission text before deleting and confirm the delete matched (`Prefer:
count=exact` → `Content-Range: */1` vs `*/0`). No other columns are
readable by any API role; `delete_token` needs select because PostgREST
requires a WHERE clause on deletes and filter columns require select
privilege.

Verified locally via `supabase db reset` + the local REST API: token
issuance, token-scoped preview and delete, zero-row results for
missing/wrong/malformed tokens (including a victim's token in the filter
without the header), the full context-gate matrix (project+user,
project-only, and context-free rows, incl. lenient extra-header
behavior), denied direct inserts and column reads, length caps enforced
through the function, and no execute for `authenticated`.

## Additional context

Linear tickets: [CLI-1946](https://linear.app/supabase/issue/CLI-1946),
[CLI-1999](https://linear.app/supabase/issue/CLI-1999)

The client-side flows (`supabase feedback add` / `feedback delete` in
the CLI, and the MCP tool) land separately in their respective repos and
will call the RPC / DELETE endpoint described above.

Supersedes #48378 — recreated on a fresh git branch so that the Supabase
preview branch used for testing this table isn't shared with unrelated
work.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added support for collecting and storing feedback submitted through
interfaces.
* Feedback can include submission source, timestamps, user details,
project references, and additional metadata.
* Added secure feedback submission with controlled access to protect
submitted information.
* Added support for authorized feedback removal using a secure deletion
token.
* Added safeguards to validate feedback content and restrict access to
permitted information.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-19 10:32:51 -07:00
Charis 4343e21da0 feat(studio): tighten the notebook diff preview (#49218)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

UI refactor of the notebook create/update preview in the AI Assistant
panel, plus a small additive prop on the shared `CodeBlock`.

## What is the current behavior?

The assistant's notebook diff renders each cell as its own bordered box
with a gap between them, under a `6 cells` line that is easy to miss.
Cells can't be collapsed, each one carries a repeated `ADDED` badge and
a nested "Show more" toggle, and long markdown scrolls sideways instead
of wrapping.

## What is the new behavior?

<img width="796" height="1076" alt="CleanShot 2026-08-18 at 14 41 30@2x"
src="https://github.com/user-attachments/assets/45e58c6c-48f2-404b-8699-757ee96a4a8d"
/>

- The whole diff is one card: a distinct header row (notebook name,
summary, expand/collapse all) over cells glued together by dividers.
- Every cell is a `Collapsible`. Added and replaced cells open by
default; unchanged, moved, and removed cells stay as single rows but are
now inspectable instead of being content-free.
- The per-row badge is replaced by a colored gutter glyph (`+` `−` `~`
`↕`) with a tooltip naming the change type. The change type reaches the
accessible name via `aria-label` on the row.
- The nested "Show more" toggle inside each cell is gone — the row
itself is the only control.
- `CodeBlock` gains a `wrapLongLines` prop (default `false`, no change
for existing callers), used here so markdown and SQL soft-wrap. The
highlighter sets `white-space` inline on the `<code>` element, so a
class on the `<pre>` can't do this.

## Additional context

Towards FE-4143

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Notebook previews now display titles, notebook icons, and clearer
bordered layouts.
* Added per-cell expand/collapse controls, including “Expand all” and
“Collapse all.”
  * Long code lines can now wrap for improved readability.

* **Improvements**
* Added mode-based fallback labels when notebook titles are unavailable.
* Newly added and replaced cells expand by default, while unchanged
cells remain collapsed.
* Improved change markers, tooltips, removed-cell styling, and notebook
proposal preview spacing.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-19 12:11:10 -04:00
bb094f96c8 docs(mcp): revise authentication note to match style guide (#49219)
<img width="769" height="212" alt="Screenshot 2026-08-18 at 12 17 18 PM"
src="https://github.com/user-attachments/assets/38ce6606-84ae-4833-a7d9-7a1931fdd773"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update. Copy and dedupe.

## What is the current behavior?

Gave this a style edit. Basically, saw this note breaking a lot of style
rules at once (`login` instead of `log in`, future tense, and also
breaking timelessness) and couldn't help myself for submitting a
revision. 😅

## What is the new behavior?

Preview:
https://docs-git-cursor-revise-mcp-auth-note-bbe8-supabase.vercel.app/docs/guides/ai-tools/mcp

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Miranda Limonczenko <czenko@users.noreply.github.com>
2026-08-19 08:56:09 -07:00
Donna Alexandra 452227e5d2 Add Donna Alexandra to humans.txt (#49258)
Part of my onboarding to add myself to humans.txt

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update to add new joiner (me!)

## What is the current behavior?

N/A

## What is the new behavior?

I am part of the team. :)

## Additional context

Part of the onboarding process.
2026-08-19 08:22:17 -07:00