mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 04:15:04 +03:00
aedc46c8ad7c241dcd97d88ab4e58ec8bcfabb4e
3383
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
7058506661 |
chore(studio): migrate account/me and sign-in to TanStack routes
First two pages ported under the minimum-diff Path A strategy: the
TanStack route wraps the page default-exported from pages/ rather
than rewriting the body. Layout chains provided by pathless _app /
_auth pathless routes + sibling-file layouts, reading per-leaf props
(AccountLayout title, DefaultLayout headerTitle) from route
staticData via useMatches.
Supporting fixes:
- compat/next/router: add `query` (params + search) so components
like FeedbackDropdown that read `router.query.ref` keep working
under the shim.
- ConnectSheet content loader: switch to `import.meta.glob` for
Vite (the template path spans multiple directories so
dynamic-import-vars can't analyse it), guarded with
`import.meta.env.SSR` to keep the 37 content modules out of the
SSR graph — they reshuffle chunks enough to surface circular-dep
bugs in unrelated modules. Next/webpack falls through a try/catch
to the existing `import(\`./content/\${filePath}/content\`)`.
TANSTACK_MIGRATION.md tracks per-page status during the migration.
|
||
|
|
d1a7d64e63 |
[FE-3023] feat(studio): default privileges toggle at project creation (#45034)
<img width="783" height="414" alt="Screenshot 2026-04-20 at 3 02 37 PM" src="https://github.com/user-attachments/assets/a353c35a-3de5-4bfa-ab31-829c79c43165" /> Adds a "Default privileges for new entities" checkbox under "Enable Data API" in both the main create flow and the Vercel deploy-button flow. Default checked (current behaviour). When unchecked, runs `buildDefaultPrivilegesSql('revoke')` after the base init script so new entities in `public` aren't auto-granted to `anon` / `authenticated` / `service_role`. This PR decouples the two surfaces: - **`tableEditorApiAccessToggle`** — unchanged; still gates only the integrations → Data API settings UI. - **`dataApiRevokeOnCreateDefault`** (new) — controls only the default state of the new checkbox at project creation. `true` → checkbox unchecked by default (revoke runs); `false`/absent → checkbox checked by default (no behaviour change). The new flag is already live in PostHog at **0% rollout, off for everyone**, so shipping this PR changes nothing until the flag is explicitly flipped. ## Added - `apps/studio/hooks/misc/useDataApiRevokeOnCreateDefault.ts` — reads the new PostHog flag. Returns `false` in `IS_TEST_ENV` so existing E2E flows don't silently change default behaviour. - Checkbox UI in `SecurityOptions.tsx` (main flow) and `pages/integrations/vercel/[slug]/deploy-button/new-project.tsx` (Vercel flow), with copy matching the integrations → Data API settings page. - Tooltip + dimmed state for the main-flow checkbox when "Enable Data API" is unchecked (can't configure default privileges if Data API is off). - Telemetry: `dataApiDefaultPrivilegesGranted` (raw checkbox value) and `dataApiRevokeOnCreateDefaultEnabled` (raw flag, conditionally included using the existing raw-flag pattern so undefined flag state → omitted property, not `false`). - Vitest unit tests for the new hook. ## Changed - `pages/new/[slug].tsx`: removed the `false &&` rollback guard. Revoke SQL now runs only when `dataApi && !dataApiDefaultPrivileges`. Dropped the now-unused `useDataApiGrantTogglesEnabled` import. - `pages/integrations/vercel/[slug]/deploy-button/new-project.tsx`: this flow was **never rolled back** — it still ran revoke whenever `tableEditorApiAccessToggle` was on for a user. Now correctly gated on the new flag + checkbox state. - `packages/common/telemetry-constants.ts`: added the two new properties and corrected the `tableEditorApiAccessToggleEnabled` docstring (it no longer claims to control project-creation revoke behaviour). ## Kill switch Flipping `dataApiRevokeOnCreateDefault` to off in PostHog fully disables the revoke SQL for new projects without needing a redeploy — the checkbox just defaults to checked again. ## Follow-ups (not blockers) - joshenlim's review comments on PR 43704: (1) Auth Policies table row incorrectly showing "exposed via Data API" based on schema-level check instead of table-level at `apps/studio/components/interfaces/Auth/Policies/PolicyTableRow/index.tsx:64`; (2) Data API integrations page showing zero exposed tables even after exposing one. Both unrelated to this PR but will be more visible once the checkbox lands. - Once this flag fully rolls out, the old `tableEditorApiAccessToggle` docstring/comments elsewhere should stop claiming it controls project creation. ## To test - **Flag off (default state, simulates post-merge):** create a project with and without "Enable Data API" checked. The new "Default privileges for new entities" checkbox should default to **checked**. Submitting should produce an identical result to today — new tables in `public` are reachable via the Data API. - **Flag on (simulate rollout):** override the flag locally. The checkbox should default to **unchecked**. Creating a project with it unchecked should run the revoke SQL; create a new table in `public` afterwards and confirm it's not reachable via the Data API until grants are added. - **Enable Data API off:** the new checkbox should render disabled + dimmed with a tooltip reading "Enable the Data API to configure default privileges." The revoke SQL should not run in this case regardless of checkbox state. - **Vercel flow:** repeat at `/integrations/vercel/<slug>/deploy-button/new-project` — verify both checkbox states. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an "Automatically expose new tables and functions" checkbox to project creation and Vercel deploy flow; enabled only when Data API is available (disabled with tooltip otherwise) and affects initial project provisioning. * **Telemetry** * Tracks exposure of the default-privileges control and includes checkbox state and feature-flag status on project-creation submissions. * **Tests** * Added tests for flag behavior, exposure tracking, deduplication, and submission telemetry. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Sean Oliver <882952+seanoliver@users.noreply.github.com> |
||
|
|
bd55ad23a6 |
feat: iso27001 certificate (#44963)
Edit: Can be merged, mgmt api deployed Dashboard addition to frontend for access to the ISO 27001 certificate. View for Team customers: <img width="1737" height="1151" alt="image" src="https://github.com/user-attachments/assets/cd62d24f-8b6e-4600-9ded-943a170cd124" /> Resolves SEC-799 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * ISO 27001 certificate added to Documents with a Download action, confirmation modal, new-tab open on success, and error toast on failure. * Users without billing permission see a no-permission view; users missing entitlement see an “Upgrade to Team” prompt. * **Refactor** * Upgrade-to-Team flows for SOC2 and related upgrade UI standardized to use the shared upgrade component. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
08e9cdde5e |
docs: data api docs functions (#44412)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Replaces "stored procedures" with "functions" for everything related to the Data API. ## Additional context It's not accurate to call database functions "stored procedures". It may have been that way before Postgres 11, but now it causes confusion because PostgREST allows functions and not stored procedures. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Standardized terminology across docs, SDK guides, CLI/config specs, examples, UI, and config comments to use "database functions" instead of "stored procedures". * Updated API docs, CLI/config descriptions, Studio UI labels, help text, empty-state and navigation copy, RPC documentation, and example text for consistency. * Adjusted explanatory text and error/help messages to reflect the revised terminology. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9c716a6a48 |
fix(studio): make paused project dashboard view responsive on mobile (#45068)
Closes [FE-3040](https://linear.app/supabase/issue/FE-3040/fix-paused-project-dashboard-view-on-mobile) ## Summary The paused project dashboard card was locked to a fixed `w-[40rem]` (640px) width, causing horizontal overflow on mobile viewports. The Resume project button was pushed off-screen, which drove users into Project Settings → General, where the only visible action (Restart) is disabled for paused projects. ## Changes - `ProjectPausedState` card: `w-[40rem]` → `w-full max-w-[40rem]` - `CardFooter`: added `flex-wrap` so Resume + Upgrade-to-Pro/View-settings buttons stay visible on narrow screens - `PauseDisabledState` export-data footer: stacks on mobile, row layout on `sm:`+ - Parent wrappers (`ProjectLayout/index.tsx`, `Home.tsx`): added `px-4` so the card has breathing room from viewport edges ## Follow-up (not in this PR) The Linear issue also suggests adding a Resume action (or differentiated messaging) to Project Settings → General's "Project availability" section, so users who land there on a paused project have a clear path forward. Happy to tackle that separately. ## Test plan - [x] Paused Free-plan project on mobile viewport (≤640px): Resume + Upgrade buttons visible, text wraps within the card - [x] Paused Pro-plan project on mobile viewport: Resume + View settings buttons visible - [x] Non-restorable (>90 days paused) project on mobile: Recovery options list readable, "Download backups" dropdown visible and stacks below description - [x] Desktop (≥640px): card still renders at 40rem max width, layout unchanged - [x] Verified via `/project/[ref]` and `/project/[ref]/home` entry points ## Demo <img width="443" height="832" alt="image" src="https://github.com/user-attachments/assets/d5b7713e-c0b5-44e8-82fe-98c3308d5e8b" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Added horizontal padding to the paused project state interface and wrapper. * Made the export data section layout responsive, stacking vertically on mobile and horizontally on larger screens. * Updated the paused state card container styling to use responsive width constraints instead of fixed dimensions. * Adjusted footer element spacing, gap sizing, and wrapping behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bff92df845 |
convert fdw sql utilities to safesql (#45069)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved SQL query handling for vector bucket creation and Foreign Data Wrapper operations <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
485402640f |
fix schema visualizer animations (#45065)
The dashed-line animation between relations in the schema visualizer can get quite CPU-intensive for complicated schemas. Changed so it only runs on edges that target the selected relation, otherwise it's a solid line. Resolves FE-3005 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Relationships connected to selected tables now animate for enhanced visual feedback. * **Bug Fixes** * Improved edge selection behavior in the schema graph—single selections now register correctly. * Optimized default animation settings for schema connections. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a3e71ba888 |
feat(sso): add IdP-initiated login support with optional domains (#44033)
Implements comprehensive IdP-initiated login flow support, enabling organizations to configure SSO without email domains and support multiple SAML apps under the same domain (e.g., Dev/Staging/Prod environments). - Add "Enable SP-initiated login" toggle to SSOConfig.tsx - IdP-initiated flow is now always available (default) - SP-initiated flow is opt-in with domain requirement - Clear in-UI documentation explaining both flows - Make domains optional (only required when SP-initiated enabled) - Add form validation: domains required only if SP-initiated is ON - Fix org-switching bug: form now resets when switching organizations - Add organization.slug to useEffect dependencies - Prevent stale SSO config data from previous org being displayed - **IdP-initiated flow**: Users start login from identity provider dashboard - No domain configuration required - Enables multiple SAML apps per domain - Recommended default for enterprises - **SP-initiated flow**: Users start login at supabase.com (opt-in) - Requires email domain configuration - Maintains backward compatibility - **Both flows**: Can be enabled simultaneously for flexible access - Organizations can now create separate SSO providers for Dev/Staging/Prod - Each environment = separate SAML app in IdP - All using same email domain (e.g., company.com) - Users access via different IdP app tiles - No domain conflicts or subdomain requirements - Add 4 pages to SSO sidebar menu in NavigationMenu.constants.ts: - Understanding Login Flows (existing, now visible) - Choosing a Login Flow (existing, now visible) - Multiple SSO Providers (NEW comprehensive guide) - Testing and Best Practices (existing, now visible) Create comprehensive guide covering: - Multi-environment patterns (Dev/Staging/Prod with same domain) - Team separation, migration, and acquisition scenarios - Step-by-step setup for domainless providers - User access management and IDP app assignment strategies - Configuration synchronization and best practices - Troubleshooting common multi-provider issues Major expansion of testing-best-practices.mdx: - Fix outdated assumptions (domains no longer always required) - Add comprehensive login flow testing section: - IdP-initiated testing (no domains) - SP-initiated testing (with domains) - Domainless provider testing (multi-environment pattern) - Enhance auto-join testing with 8 detailed test phases: - Idempotency testing (no duplicate memberships) - Domainless configuration testing - Re-enablement testing (works on every login) - Add SSO account restrictions testing section - Add safe provider deletion testing with 4 test scenarios - Reorganize final checklist into 6 categorized sections Update azure.mdx, gsuite.mdx, okta.mdx: - Remove all "(coming soon)" references - Add guidance recommending IdP-initiated for multi-environment setups - Clarify domains are optional for IdP-initiated flow - Link to new Multiple SSO Providers guide **Domain Handling:** - Domains now optional in SSO provider configuration - Backend: `z.array(...).optional().default([])` - UI: Domains only required when SP-initiated toggle is ON - Empty array sent to API when SP-initiated disabled **Login Flow Logic:** - IdP-initiated: Always available, uses SAML assertion directly - SP-initiated: Requires domain lookup, opt-in only - Both flows can coexist with same SSO provider **Multi-Provider Support:** - Each provider has unique ACS URL - No domain conflicts (IdP-initiated doesn't check domains) - Enables unlimited providers per email domain - **Simplifies SSO setup**: No domain configuration needed by default - **Enables multi-environment**: Dev/Staging/Prod under same domain - **Improves UX**: One-click login from IdP dashboard - **Maintains compatibility**: SP-initiated still available as opt-in - **Better documentation**: Comprehensive guides for all scenarios ## UI ### SSO Disabled <img width="742" height="329" alt="sso-disabled" src="https://github.com/user-attachments/assets/73387777-181c-4206-9798-36f0d0790e4e" /> ### SSO Enabled - IdP-inititated (DEFAULT) <img width="742" height="1059" alt="sso-enabled-idp" src="https://github.com/user-attachments/assets/c189e08f-7642-4183-8853-dd5150b8a191" /> ### SSO Enabled - SP-intitiated <img width="727" height="1366" alt="sso-enabled-sp" src="https://github.com/user-attachments/assets/be5ad6dc-4803-446b-ae02-9edcbb5f42cd" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added comprehensive guides for SSO login flow selection, testing best practices, and configuring multiple providers * Updated provider-specific setup documentation (Okta, Azure, Google Workspace) with refined workflows and testing recommendations * **New Features** * Enhanced SSO configuration interface with SP-initiated login toggle and improved email domain management for flexible authentication flows <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Stockton <chris.stockton@supabase.io> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> |
||
|
|
8c4ae77ece |
fix: enum quotes (#45023)
## TL;DR
fixes enum create/update failures when names contain quotes
(also added a smol e2e)
## Ex:
<table>
<tr>
<td><strong>Before</strong></td>
<td><strong>After</strong></td>
</tr>
<tr>
<td>
<img width="424" height="178" alt="Before"
src="https://github.com/user-attachments/assets/d1815f4e-3879-4f8d-8d24-40d2c1f5563d"
/>
</td>
<td>
<img width="233" height="75" alt="After fix"
src="https://github.com/user-attachments/assets/f3f9b53c-b234-4e18-9b2d-db97ca4713d5"
/>
</td>
</tr>
</table>
## ref:
- closes https://github.com/supabase/supabase/issues/45022
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Fixed enumerated type description handling to preserve special
characters (quotes and apostrophes) without unintended escaping.
* **Tests**
* Extended enumerated types test coverage to include creation, updates,
and deletion of types with special characters in names and descriptions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
8f69a10cc9 |
fix(studio): reliable schema-aware SQL editor AI completions (#44730)
A variety of fixes and improvements to the Cmd+K AI completions endpoint in the [SQL Editor](https://supabase.com/dashboard/project/_/sql/new): - Pre-load table definitions for the public schema and any other schemas referenced in the editor, so the model has real column names without needing to fetch them dynamically - Replace the generic tool suite with a single streamlined `getSchemaDefinitions` tool the model can still call to look up additional schemas on demand without behavior differences across platform & self-hosted - Swap generic chat system prompt for a purpose-built `COMPLETION_PROMPT`; fix role (`assistant` → `user`) for consistency with other endpoints - Validate and type the request body with `zod`, which was previously untyped (`any`) - Improve Cmd+K behavior when nothing is selected — use the full editor content as context, return the complete query rather than just the changed fragment, and switch to a generation mode when the editor is blank - Escape single quotes in schema names when fetching entity definitions in `pg-meta` to prevent schema names from breaking out of the SQL string and injecting arbitrary content into the prompt ## Before Before, the SQL Editor would often hallucinate tables / columns that don't exist in the user's database making it less helpful if you don't know the exact table/column names. Even with maximum Assistant opt-in level on the org, it would often fail to call the necessary tools to gather database context. <img width="5062" height="1522" alt="image" src="https://github.com/user-attachments/assets/fbe1130f-6b5a-41a8-99d7-7268880af188" /> <img width="2540" height="658" alt="image" src="https://github.com/user-attachments/assets/a31c2967-7751-4fce-a9b7-60bd77660b1a" /> Sometimes it also silently fails and generates empty queries: <img width="1352" height="398" alt="CleanShot 2026-04-09 at 17 46 06@2x" src="https://github.com/user-attachments/assets/e17c103a-d47d-47e6-8c2e-101f0fae5651" /> Or echos back the user's prompt: <img width="1368" height="282" alt="CleanShot 2026-04-09 at 23 04 56@2x" src="https://github.com/user-attachments/assets/7dff6e64-f54e-45b5-8e86-5399e5a2fe41" /> ## After In this example, the completion correctly interpreted my request for "completed" todos as a query on the `completed_foo` column in my `public` schema, instead of assuming existence of a `completed` column. <img width="1452" height="838" alt="CleanShot 2026-04-09 at 17 43 13@2x" src="https://github.com/user-attachments/assets/7a575589-78b4-448d-810a-0330ff08ef8b" /> In this example, the completion was correctly aware of an `other` schema because it was detected in my existing query. I didn't have to select the text, it included the full query in context when unselected. Notice how it correctly used the `is_done` column when I asked for "completed" cakes: <img width="1372" height="534" alt="CleanShot 2026-04-09 at 17 39 07@2x" src="https://github.com/user-attachments/assets/e6b7eb6f-f3e8-4fa1-90a3-b5e34ddc14e4" /> Supersedes #44151 Closes AI-544 |
||
|
|
d272c15d8d |
[FE-2792] feat(studio): unify table exposure check on RLS policies page (#45041)
Fixes the RLS policies page showing self-contradictory or wrong
admonitions for tables with partial grants. Classifies each table using
the same `granted / custom / revoked` semantics used by the Data API
settings page so the two views agree on what counts as "exposed".
**Changed:**
- `PolicyTableRow` now uses `useTableApiAccessQuery` (shared cache with
the Table Editor sidebar) instead of a bespoke
`tables-roles-access-query`
- Boolean soup collapsed into a single `TableDataApiStatus`
discriminated union (`schema-not-exposed | no-grants | custom-grants |
publicly-readable | locked-by-rls | secured`) via a pure helper
- Admonition copy for `no-grants` and `locked-by-rls` updated; a table
with no policies but full grants now reads "No data will be returned via
the Data API as no RLS policies exist on this table." instead of the
earlier self-contradictory "can be accessed but no data will be
returned"
- `table-api-access-query.ts` now exposes a `grantStatus: 'granted' |
'custom'` on `access` entries — `granted` = all 3 API roles × all 4 CRUD
privileges (matches `getTableGrantsCTEs` in pg-meta)
**Added:**
- New `custom-grants` admonition: "This table has custom Data API
permissions — access may be restricted for some roles or operations."
- Unit tests for `getTableDataApiStatus`, `getTableAdmonitionMessage`,
and `isFullyGranted`
**Removed:**
- `data/tables/tables-roles-access-query.ts` and the `rolesAccess` key —
no more callers
## To test
On a project with the `public` schema exposed, for each scenario check
the admonition shown on `/project/{ref}/auth/policies`:
1. Table with full standard grants, RLS on, no policies → "No data will
be returned via the Data API as no RLS policies exist on this table."
2. Table with full standard grants, RLS off → yellow warning "can be
accessed by anyone"
3. Table with partial grants (e.g. only `GRANT SELECT ON t TO anon`) →
new "custom Data API permissions" admonition regardless of RLS state
4. Table with no anon/authenticated/service_role grants → "cannot be
accessed via the Data API"
5. Schema not in the exposed list → "schema not exposed" admonition with
link
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Tests**
* Added unit tests covering table Data API/RLS status classification and
API grant validation.
* **Refactor**
* Introduced a unified per-table API/RLS status model and reusable
utilities to derive display status and admonitions.
* Simplified UI logic to drive access indicators and warnings from the
new status.
* **Chores**
* Removed legacy role-based access query and its related keying logic.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
|
||
|
|
45fc609471 |
[FE-3034] feat(studio): render multi-line SQL error HINTs (#45038)
Preserve `formattedError` through the `ResponseError` path and fall back to splitting `error.message` on newlines so enhanced permission-denied HINTs from supabase/postgres#2084 render as separate lines in the SQL editor — users can actually read the GRANT example now. **Context:** postgres#2084 adds a multi-line HINT to SQLSTATE 42501 errors, telling users exactly how to grant access per-table. Today the SQL editor rendered the whole thing on one line because `formattedError` was stripped by the fetchers' error handling and the `message` fallback didn't split on `\n`. This PR fixes both. Blocks [FE-3023](https://linear.app/supabase/issue/FE-3023) — the project-creation toggle that flips default privileges; without readable HINTs users land on RLS debugging rabbit holes when they hit a permission denied. **Changed:** - `ResponseError` now carries an optional `formattedError` field; `ConnectionTimeoutError` / `UnknownAPIResponseError` thread it through. - `handleError` in `data/fetchers.ts` extracts `formattedError` from the raw error body and forwards it to the thrown subclass. - `UtilityTabResults.tsx` uses a new `getSqlErrorLines` helper — prefers `formattedError`, falls back to splitting `message` on newlines when it's multi-line (defense in depth since the exact field pg-meta populates for the HINT depends on the path). Copy button now uses the same lines. **Added:** - `getSqlErrorLines` pure helper + 9 unit tests. - 5 new tests in `handleError.test.ts` covering `formattedError` preservation on classified and unclassified errors. ## To test 1. Pull the branch, run `pnpm dev:studio`, open any project's SQL editor. 2. Run a query that triggers the enhanced HINT (requires postgres#2084 deployed on the DB — currently staging-only). Example: `select * from some_table_you_cant_read;` as a role without grants. 3. Expect the ERROR line, HINT line, and the `GRANT ...` example to each render on their own `<pre>` line, plus the Copy button to copy the full multi-line text. 4. Sanity check existing single-line errors (e.g. `select * from nonexistent_table`) still render as `Error: relation "nonexistent_table" does not exist` in the `<p>` fallback. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Improved SQL error message formatting in the editor for better readability and clarity. * **Refactor** * Centralized error formatting logic for more consistent error presentation across the application. * **Tests** * Added comprehensive test coverage for SQL error message parsing and formatting. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
1a0fc71151 |
fix: improve performances on large schema image export (#45042)
## Problem When users export a large schema, the UI becomes unresponsive for a long time. This is because the underlying `html-to-image` library calls `getComputedStyle` for every node. ## Solution - Upgrade `html-to-image` to its latest version - Use the new `includeStyleProperties` property to call `getComputedStyle` only once - Extract the image export logic into a new hook ## How to test - Open https://studio-staging-git-gildasgarcia-fe-2998-suggest-e7fb9e-supabase.vercel.app/dashboard/project/pdmusqfyrsascxykhlge/database/schemas?schema=auth - Rearrange tables so that they are all visible - Export the schema as png - It should takes (~10-15secs) - Do the same in this PR preview https://studio-staging-gy13zepyf-supabase.vercel.app/dashboard/project/pdmusqfyrsascxykhlge/database/schemas?schema=auth - It should takes ~3-5secs <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Improved schema export: more reliable PNG/SVG exports that better preserve visual styling, show progress state during downloads, and surface success/error notifications. * **Chores** * Updated image-export library to a newer version for improved compatibility and performance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2555e81dde |
fix(studio): don't scan dollar-quoted bodies for DDL in SQL editor (#45050)
Fixes a false positive in the CREATE-TABLE-without-RLS warning modal added in #45008. The warning was firing on `CREATE FUNCTION` statements because the `SELECT..INTO` detector was matching plpgsql variable assignments inside `$$…$$` function bodies. Reported example that triggered the modal with no table actually being created: ```sql create or replace function schema_checks() returns jsonb language plpgsql as $$ declare ret jsonb; begin select jsonb_build_object('value', 'ok') into ret; return ret; end; $$; ``` **Changed:** - `SQLEventParser.match()` now strips the body of `$tag$…$tag$` blocks before running detectors. Tags are kept as markers; content is blanked out so function bodies, DO blocks, and dollar-quoted string literals are never scanned as DDL. - Updated a pre-existing parser test that asserted the buggy behaviour (it expected `CREATE TABLE fake` inside a `$$…$$` string literal to be detected — `$$…$$` is a string literal in Postgres, not DDL). **Added:** - Regression tests in `SQLEditor.utils.test.ts` covering: the exact reported function, DO blocks with `select into`, `create table` text inside a function body, mixed top-level `CREATE TABLE` + function with `INTO` assignments, and custom `$body$…$body$` tags. - Parser-level regression test in `sql-event-parser.test.ts`. ## To test - In the SQL editor, paste the function from the Slack report and run it — the RLS warning modal should not appear. - Run `create table foo (id int8 primary key);` on its own — modal still appears as before. - Run `create table foo (id int8); create or replace function bar() returns int language plpgsql as $$ declare v int; begin select 1 into v; return v; end; $$;` — modal should flag only `foo`, not `v`. - Run an existing destructive query (`drop table x`) — unaffected, modal still works. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Parser no longer treats DDL/DML-like text inside PL/pgSQL functions, DO blocks, or dollar-quoted bodies (including nested/custom tags) as top-level CREATE TABLE/SELECT INTO, preventing false detections and UI warnings. * **Tests** * Added unit and e2e regression tests covering dollar-quoted blocks, nested dollar tags, DO blocks, SELECT INTO inside functions, and positive controls with a real top-level CREATE TABLE. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
d0d41e00d6 |
[FE-3035] fix(studio): show /rest/v1/ suffix on Data API overview URL (#45045)
The Data API overview page (`/integrations/data_api/overview`) was showing the project URL as `https://xxx.supabase.co`, but the documented Data API base URL is `https://xxx.supabase.co/rest/v1/`. This normalizes the URL so it matches the docs. **Changed:** - `getApiEndpoint` now appends `/rest/v1/` to the resolved endpoint (only used by the Data API overview card, so no other dashboard URLs are affected) ## To test - Visit `/dashboard/project/_/integrations/data_api/overview` and confirm the API URL field ends with `/rest/v1/` - Switch the database selector between primary, a read replica, and (if available) a load balancer — all should show a URL ending in `/rest/v1/` - With a custom domain active, the custom domain URL should also end with `/rest/v1/` Addresses [FE-3035](https://linear.app/supabase/issue/FE-3035/dashboard-data-api-page-shows-inconsistent-api-url) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Bug Fixes** * API endpoints are now properly normalized to ensure consistent path formatting with the `/rest/v1/` suffix across all endpoint sources. * Fixed URL handling for custom domain and load balancer endpoint selection. * Enhanced replica database URL handling to ensure correct trailing slash formatting. * **Tests** * Updated test expectations and added new test cases to verify proper endpoint normalization behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
865ffb8e01 |
fix(auth): remove border radius on user search input group (#45040)
Before: <img width="556" height="236" alt="Screenshot 2026-04-20 at 10 34 05" src="https://github.com/user-attachments/assets/c27ec1e8-0ca7-4abc-a548-73ad14ae241c" /> After: <img width="585" height="215" alt="Screenshot 2026-04-20 at 10 33 54" src="https://github.com/user-attachments/assets/63fecb2f-0305-43f1-9032-e470a2c29578" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Refactor** * Improved internal code organization for the user search component styling to enhance maintainability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b721a2d780 |
feat(studio): advisor signal items for banned IPs (#44372)
## What kind of change does this PR introduce? Feature. Resolves DEPR-430. ## What is the current behaviour? The homepage Advisor summary, shared Advisor panel, and top-nav Advisor indicator only surface lints and notifications. Banned IPs are not represented as dismissible Advisor items, so network bans are easy to miss unless a user visits Database Settings directly. The `public bucket allows listing` warning is no longer part of this PR. That warning will move to a follow-up Splinter `WARN` lint so it can flow through the standard lint surfaces instead of a bespoke Studio signal path. ## What is the new behaviour? - adds a new Advisor `signal` source for banned IPs on the platform homepage, in the shared Advisor panel, and in the top-nav Advisor indicator - keeps dismissals client-side only for now, scoped by project and exact IP fingerprint - keeps banned IP signals at `warning` severity because they still indicate suspicious traffic and remain actionable if a user wants to review or remove a ban - leaves `/project/[ref]/advisors/security` as follow-up work because that surface is still lint-native, and banned IPs are management-plane signals rather than Splinter lints | After | | --- | | <img width="1728" height="997" alt="Mallet Toolshed Supabase-65A60B4A-107E-4D79-B9A8-23F754BEAB08" src="https://github.com/user-attachments/assets/c08ecbbb-c302-43bd-81bb-6ba7eb18b7b3" /> | ## Reviewer testing notes 1. Use a throwaway project. 2. Get the database connection string for that project. 3. Attempt to connect with the wrong password 3-4 times until you hit an `ECONNREFUSED`-style error, which should mean your IP has been banned. 4. Refresh Studio and confirm the project overview shows the new `Banned IP address` signal. 5. Open the Advisor Center and confirm: - the top-nav Advisor dot turns warning yellow - the signal detail shows `Entity`, `Issue`, and `Resolve` - `Edit network bans`, `Dismiss`, and `Learn more` are present 6. Open Database Settings > Network bans and confirm your banned IP appears there and can be unbanned. 7. Note that `/project/[ref]/advisors/security` will not show this item. That page is still lint-only, and this banned IP work is a short-term client-side signal rather than a true lint. Longer term, we likely want a more durable event model here so banned IPs can power notifications, webhooks, emails, and other project-level alerts. --------- Co-authored-by: kemal <hello@kemal.earth> Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
a5f4a59e0e |
fix(studio): detect update-without-where on quoted table names (#45009)
The previous \`updateWithoutWhereRegex\` only matched bareword table identifiers (\`messages\`, \`public.messages\`) or a fully qualified \`"schema"."table"\` pair, so statements like \`UPDATE "messages" SET id = 1\` skipped the pre-execution warning entirely. **Changed:** - Broaden each identifier slot in \`updateWithoutWhereRegex\` to accept either a bareword or a double-quoted identifier independently — covers \`"messages"\`, \`"public".messages\`, \`public."messages"\`, \`"my table"\`, and \`"weird""name"\` (escaped quote). **Added:** - 6 unit tests covering single quoted, mixed quoted/bareword, spaces in identifiers, and escaped quotes — both with and without \`WHERE\`. ## To test - Run \`pnpm --filter studio test -- SQLEditor.utils.test.ts\` — should pass 79 tests - In the SQL editor, run \`UPDATE "messages" SET id = 1\` — warning modal should now appear - Same statement with \`WHERE id = 2\` appended — no warning <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved SQL UPDATE detection in the SQL Editor to handle double-quoted identifiers, schema-qualified names, names with spaces, and escaped quotes. * Prevented false positives by ignoring quoted string and identifier contents when checking for a WHERE clause. * **Tests** * Added comprehensive tests covering varied quoting/qualification scenarios and quoted-content edge cases. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
3aed9a9a2a |
feat(studio): warn before CREATE TABLE without RLS in SQL editor (#45008)
Adds a pre-execution warning in the SQL editor when a `CREATE TABLE` statement is run without enabling Row Level Security on the new table. Responds to the press call-out around SQL editor security. <img width="708" height="498" alt="Screenshot 2026-04-18 at 4 31 07 PM" src="https://github.com/user-attachments/assets/4f23ed5e-f32c-46f0-b0da-ac6d4c661c7c" /> **Added:** - Pre-execution check in `executeQuery` that detects `CREATE TABLE` statements without a matching `ALTER TABLE ... ENABLE ROW LEVEL SECURITY` in the same submitted SQL. - New "Run and enable RLS" action in the warning modal that rewrites the SQL to append `ALTER TABLE [schema.]<table> ENABLE ROW LEVEL SECURITY;` for each detected table before running. - Link in the modal to the RLS docs. **Changed:** - `RunQueryWarningModal` now renders `Dialog` directly (instead of `ConfirmationModal`) so it can show three buttons: Cancel / Run without RLS / Run and enable RLS. - `sqlEventParser` table-name regex now supports quoted identifiers containing spaces (e.g. `"My Table"`) and escaped quotes (e.g. `"user""table"`). The check runs against the SQL that's actually submitted, so partial-selection works correctly — selecting only the `CREATE TABLE` portion will trigger the warning even if there's a matching `ENABLE RLS` lower in the editor. ## To test - Open the SQL editor and run `create table foo (id int8 primary key);` → modal should appear with the RLS warning bullet and three buttons. - Click **Run and enable RLS** → query runs, table is created with RLS enabled. - Click **Run without RLS** → query runs as written, no RLS. - Run `create table foo (id int8); alter table foo enable row level security;` → no modal (RLS already enabled in same submission). - Run `create table public.bar (id int8); create table baz (id int8); alter table baz enable rls;` → modal flags only `public.bar`. - Select only the `create table` portion of a snippet that also enables RLS lower down and run the selection → modal should still fire. - Run an existing destructive query (`drop table x`) → modal still works as before with two buttons (Cancel / Run this query). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * SQL editor now detects CREATE TABLE statements missing Row Level Security (RLS) and shows counts and dynamic table/schema details in a redesigned warning dialog with updated pluralization and a “Learn more” link. * New actions: “Run without RLS” and, when available, “Run and enable RLS” which applies RLS and runs the query; editor can execute an overridden SQL payload when applying RLS changes. * **Tests** * Added comprehensive unit and e2e tests covering RLS detection, SQL augmentation, trigger handling, identifier parsing, and the “Run and enable RLS” flow. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
cacee2585b |
fix(studio): await saveRow and surface foreign row errors to UI and Sentry (#44950)
Fixes #44949 What kind of change does this PR introduce? [x] Bug fix (non-breaking change which fixes an issue) [ ] New feature (non-breaking change which adds functionality) Description This PR fixes a silent failure state in the Foreign Row Selector (SidePanelEditor.tsx). Previously, onSaveForeignRow called saveRow without awaiting it, and included an entirely empty catch block. This meant that any database write failures (RLS violations, network drops, foreign key constraint violations) were swallowed into the void. The user received no visual feedback that their save failed. Changes: Added await to saveRow to ensure the promise rejection is actually caught by the try/catch block. Added a toast.error notification to alert the user when the save fails. Added Sentry.captureException to ensure these silent failures are actually tracked in production observability. (Sentry was already imported in the file). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved error handling and user notifications when saving data in the table editor, ensuring failures are properly communicated and logged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a7341c70ea |
feat(shortcuts): add showInSettings flag to ShortcutDefinition (#44997)
Closes [FE-3021](https://linear.app/supabase/issue/FE-3021/hide-shortcut-in-settings-option-for-new-api). ## Summary - Adds an optional `showInSettings` field to `ShortcutDefinition` (defaults to `true`). - `HotkeySettings` filters out entries where `showInSettings === false` before rendering the Account → Preferences → Keyboard shortcuts list. - No registry entries are flipped in this PR — opt-in per shortcut as needed. ## Test plan - [x] Confirm all existing shortcuts still appear under Account → Preferences → Keyboard shortcuts. - [x] Temporarily set `showInSettings: false` on one entry and verify it disappears from the list. - [x] `pnpm --filter studio exec tsc --noEmit` passes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Keyboard shortcuts can now be selectively hidden from the Account preferences settings based on configuration. * **Refactor** * Updated keyboard shortcut filtering logic to respect visibility settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e8df67d5d5 |
chore: migrate shortcuts to new hooks API (#44955)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Cleanup shortcuts with new hooks <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Centralized keyboard shortcut system for consistent shortcut behavior across the app and moved preference toggles to a unified registry. * **New Features** * Added explicit shortcuts for Command Menu, AI Assistant, Inline Editor, and result copy/download actions. * Hotkey preferences UI now renders dynamically from the centralized shortcut list. * **Tests** * Test helpers updated to include the command menu provider for accurate shortcut behavior in tests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c04f2465e4 |
fix for connect modal being stuck loading for non JS frameworks (#44992)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? It makes the connect modal responsive to other non JS frameworks selection. ## What is the current behavior? Modal is stuck when non JS is selected. Closes #44985 ## What is the new behavior? It's now responsive: <img width="999" height="848" alt="Screenshot 2026-04-17 at 18 40 47" src="https://github.com/user-attachments/assets/e00449df-207a-401a-9e25-01944489de9c" /> <img width="976" height="959" alt="Screenshot 2026-04-17 at 18 40 59" src="https://github.com/user-attachments/assets/e5fcee6b-7f5e-4edb-8a00-629965026493" /> ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Internal optimization to the framework library resolution logic with no visible user-facing changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e63cca3b4a |
fix(studio): preserve EXTERNAL_PHONE_ENABLED on phone provider save (#44982)
## Summary
Toggling the Phone auth provider on in Studio appeared to save (success
toast) but snapped back to **Disabled** immediately. The backend value
never changed.
## Root cause
In `AuthProvidersFormValidation.tsx`, the phone schema's final
`.transform` replaced the parsed values with
`enabledSchema.parse(values)`:
```
.transform((values) => {
if (values.EXTERNAL_PHONE_ENABLED === true) {
return enabledSchema.parse(values) // ← strips EXTERNAL_PHONE_ENABLED
}
return values
})
```
`enabledSchema` is a `z.discriminatedUnion('SMS_PROVIDER', [...])` whose
branch schemas (twilio / twilio_verify / messagebird / vonage /
textlocal) don't declare `EXTERNAL_PHONE_ENABLED`. Zod objects strip
unknown keys by default, so the flag was dropped from the submitted
payload. The PATCH request to `/platform/auth/{ref}/config` went out
without `EXTERNAL_PHONE_ENABLED`, the backend kept its previous value,
and `form.reset` on the response snapped the toggle back to disabled.
Regression was introduced in #44865 (zod migration). The recent #44974
fix addressed the `shouldUnregister` side of the form but not this
transform.
## Fix
Spread `enabledSchema.parse(values)` and re-add `EXTERNAL_PHONE_ENABLED:
true` so the flag survives the transform.
## Test plan
- [x] On a project with no phone provider configured, pick an SMS
provider (e.g. Twilio), fill credentials, toggle Phone on, Save → toggle
stays **Enabled**, network tab shows `EXTERNAL_PHONE_ENABLED: true` in
PATCH payload and response
- [x] Toggle Phone off → stays **Disabled** (unchanged behavior)
- [x] Change SMS provider credentials while enabled → saves correctly
- [x] With SMS hook enabled, phone provider fields remain optional as
before
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Fixed an issue where phone authentication provider settings were not
being properly retained during form submission.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
3ed436de74 |
feat: new shortcuts hook with registrations (#44954)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Brand new hook APIs for registering shortcuts using tanstack hotkeys - Support for command menu injection when shortcut is added <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Centralized keyboard shortcuts system with per‑shortcut registration and per‑user enable/disable preferences stored locally * Added a "Copy results as Markdown" shortcut (Mod+Shift+M) * Shortcuts can be surfaced in the Command Menu with a visual shortcut badge for discoverability * **Documentation** * Legacy keyboard shortcut hooks marked as deprecated and documentation updated to point to the new shortcut API <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8ef6181ef7 |
fix(studio): show Vercel-specific copy in delete connection dialog (#44960)
## Summary - The delete confirmation dialog for integration connections hard-coded GitHub-specific copy about preview branches, even when deleting a Vercel connection. - Branch the dialog body on the connection `type` so Vercel connections explain that environment variable syncing to the Vercel project will stop. Fixes [FE-3006](https://linear.app/supabase/issue/FE-3006/deleting-vercel-connection-confirmation-dialog-incorrectly). ## Test plan - [x] Go to Organization > Integrations - [x] Set up a Vercel integration linking a Supabase project to a Vercel project - [x] Click Manage > Delete connection → dialog should reference Vercel env var syncing, not GitHub preview branches - [x] Repeat with a GitHub connection → dialog should still reference preview branches <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated integration disconnection confirmation messages to provide type-specific guidance, clarifying exactly what happens when stopping synchronization for each integration type. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bd04a59dec |
fix: phone provider (#44974)
fixes phone provider saves that showed success but did not persist the
enabled state
(smol regression from the refactor)
## ref:
- closes https://github.com/supabase/supabase/issues/44966
ig was introduced by
|
||
|
|
9c155a2192 |
feat: show installed marketplace apps and remove official badge from them (#44973)
This PR shows installed marketplace apps in the left pane on the integrations page and shows the `Installed` badge on the card. `Official` badge is not shown on marketplace listings. <img width="1652" height="892" alt="image" src="https://github.com/user-attachments/assets/16c0a218-1658-426e-9b5b-d28e44c5c3b6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed excessive spacing on the integrations page * Enhanced integration installation detection for improved accuracy * **Style** * Updated official badge display on integration cards <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b1531545fb |
security: migrate more files to safeSql (#44727)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Overhauled SQL generation across the Studio: queries and helpers now use safer, parameterized SQL construction for more robust and consistent behavior. * **Bug Fixes** * Improved trigger update flow so event values are normalized before saving, reducing errors when modifying webhooks/triggers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ae4f1551f0 |
chore: make new table filter bar the default (#44910)
## Summary - Makes the new table filter bar the permanent default by hardcoding `useIsTableFilterBarEnabled` to return `true` - Removes the feature preview toggle (opt-out) from the preview modal - Cleans up E2E tests: removes old filter UI test, removes `enableFilterBar` helper, fixes race condition in column-drop test - Old filter code paths are left in place for a follow-up cleanup PR Closes FE-2819 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Removed the table filter bar preview and its opt-in/local-storage preview key. * Cleared preview content from the feature preview modal. * **Tests** * Removed the UI filtering e2e test and associated preview opt-in helper. * Updated filter-bar e2e flows to adjust navigation/wait behavior (added explicit waits, removed redundant reloads). <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
0c931f8c58 |
fix(studio): use nuqs for database functions search to prevent caret jumping (#44909)
## Summary - Fixes the cursor jumping to end of input on every keystroke in the database functions search - Replaced manual `useParams` + `router.push` URL sync with `useQueryState` from nuqs, which updates state synchronously — matching the pattern already used for the other filters on this page - Removed the `setTimeout` hack in the SchemaSelector onChange that was only needed because of the async URL update Fixes FE-3000 ## Test plan - [x] Navigate to Database > Functions - [x] Type a search string, then click in the middle of the string and type — cursor should stay in place - [x] Verify search filtering still works correctly - [x] Verify switching schemas still clears the search input - [x] Verify the `?search=` query param is still reflected in the URL <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved responsiveness of schema selection in the Functions list—search filters now clear immediately when switching schemas, eliminating previous delays. * **Improvements** * Enhanced URL state synchronization for better consistency with browser history and navigation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c3119ea1ea |
chore: types cleanup for react 19 (#44941)
## Problem While trying to update `react` to version `19`, I noticed type related errors that can be fixed in version `18`, mostly usage of `JSX.Element` instead of `ReactNode`. ## Solution - Use `ReactNode` instead of `JSX.Element` - Fix some invalid usage of `rechart` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Refactor** * Standardized React component type annotations across the codebase for improved type consistency and flexibility. * Updated component prop types to accept a broader range of renderable content. * **Bug Fixes** * Adjusted chart layout positioning to improve visual alignment. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
16fd60134d |
chore: migrate auth providers form to zod (#44865)
## Problem We currently have 2 libraries for schema validation: `yup` that was used with `formik` and `zod` which is now the preferred one. ## Solution - Migrate the auth providers form to `zod` - Remove `yup` No visual changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Preserve empty numeric inputs in auth provider forms to avoid unintended conversion. * **Refactor** * Migrated auth provider form validation to a new validation system for more consistent rules. * Strengthened provider-specific validation (email, phone/SMS, OAuth, SAML, Web3), added improved SMS test-OTP/date checks, and adjusted initial handling for password-required-characters. * **Chores** * Removed an unused validation dependency from project packages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
02325f00e7 |
feat(studio): add Copy as CSV option to SQL editor results (#44911)
## Summary - Adds a new "Copy as CSV" action to the export dropdown in the SQL editor results panel, alongside the existing Copy as Markdown, Copy as JSON, and Download CSV options - Registers a `Shift+Cmd+C` keyboard shortcut for the action, with a toggle in Account > Preferences > Keyboard shortcuts - Works everywhere `DownloadResultsButton` is used: SQL editor, logs, query performance, and linter pages Fixes FE-2991 ## Test plan - [x] Run a SELECT query in the SQL editor, open the Export dropdown, and verify "Copy as CSV" appears between "Copy as JSON" and "Download CSV" - [x] Click "Copy as CSV" and verify CSV data is copied to clipboard - [x] Use `Shift+Cmd+C` shortcut and verify it copies CSV to clipboard - [x] Go to Account > Preferences > Keyboard shortcuts and verify the "Copy results as CSV" toggle is present and functional - [x] Disable the shortcut in preferences, verify `Shift+Cmd+C` no longer triggers the copy - [x] Verify the same option appears in the logs export dropdown <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added "Copy as CSV" action to the results download menu, allowing users to quickly copy query results in CSV format to the clipboard. * Introduced a new hotkey preference setting to enable/disable the Shift+Meta+C keyboard shortcut for copying results as CSV. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fdf8732727 |
fix: Include security_invoker in definition (#44936)
## TL;DR the table editor definition panel was showing incomplete SQL for views with `WITH (security_invoker = true)` ignoring the reloption and making it easy to accidentally strip it when recreating the view ## prob When viewing a security invoker view in the Table Editor, the Definition panel only showed `CREATE VIEW ... AS ...` without the `WITH (security_invoker = true)` clause which caused two issues: 1. the displayed SQL was incomplete and didn't match the actual view definition 2. users copying the SQL to recreate the view would unintentionally lose the security_invoker setting ## ex: | Before | After | |--------|-------| | `create view public.exposed_api as`<br>`select id, secret from public.rls_protected_table;` | `create view public.exposed_api with (security_invoker = true) as`<br>`select id, secret from public.rls_protected_table;` | ## ref: - closes https://github.com/supabase/supabase/issues/44934 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * View definitions now show the full CREATE statement (including materialized views and WITH (...) options) and preserve security options like security_invoker when viewed or opened in the SQL editor. * **Tests** * Added end-to-end test verifying security option preservation in view definitions and when opening them in the SQL editor. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e7860e9163 |
feat: request confirmation before applying auto-layout to the schema visualiser (#44932)
## Problem If users accidentally click the _Auto layout_ button in the schema visualiser, they immediately lose all their changes. ## Solution - Ask for confirmation before applying auto layout - Fix auto layout changes aren't persisted <img width="457" height="232" alt="image" src="https://github.com/user-attachments/assets/d58e2995-6537-43b4-9b99-b1447fb03e1f" /> ## How to test - Go to database/schema - Make changes to the layout - Refresh the page and check changes are still applied - Click the _Auto layout_ button and click _Cancel_ - Check auto layout wasn't applied - Refresh the page and check users changes are still applied - Click the _Auto layout_ button and click _Apply_ - Check auto layout was applied - Refresh the page and check auto layout changes are still applied <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a confirmation dialog for the "Auto layout" action so users can review and confirm before changes are applied. * **Bug Fixes** * Ensured layout fitting completes before node positions are saved, preventing incorrect or premature persistence. * **Style** * Simplified schema error rendering to present error messages more directly and clearly. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
0cb71a2497 |
feat: new marketplace db (#44574)
This PR integrates with the new marketplace db to allow Grafana (and other partners) OAuth apps to install from the integrations page. A demo of this working locally is available here: https://supabase.slack.com/archives/C01GN60J0BS/p1775551752479709. End to end flow is documented here: https://www.notion.so/supabase/Grafana-Integration-Flow-33a5004b775f80eeaf91c098beb8071f. TODO: - [ ] Make sure `NEXT_PUBLIC_MARKETPLACE_API_URL` variable is set to the new marketplace db. - [x] Test with the `marketplaceIntegrations` enabled and disabled in staging once https://github.com/supabase/platform/pull/31298 is merged and available in staging. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Add OAuth "Install integration" button that detects installed integrations and supports GET/POST install flows * Marketplace listings now include install links, installation method, partner info, and listing assets/logos * **Infrastructure** * Allow marketplace API origin for images and content in security and image config * Centralize marketplace types and switch marketplace data source for more reliable listings <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
0395fd969f |
chore: upgrade react-markdown (#44913)
## Problem We'd like to update react to `19` but many of our dependencies don't support it. ## Solution Update those dependencies. This PR focuses on `react-markdown` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Upgraded react-markdown to 10.1.0 (and remark-gfm to 4.0.0) across projects for improved Markdown support. * **Style** * Adjusted Markdown rendering so typography and spacing are applied via surrounding containers, improving consistent styling across docs and UI. * **New Content** * Added a new RSS feed item for a recent blog post. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d70ed2ef76 |
chore: Add new OAuth scopes for analytics config to studio (#44826)
## Summary Adds support for new OAuth scopes for reading and writing analytics config to the app creation dialog and consent screen. Depends on https://github.com/supabase/platform/pull/31539 |
||
|
|
35478cf47b |
feat: expose tax in upcoming invoice (#44732)
Display tax information in the upcoming invoice breakdown. - Show a "Tax" line item with amount and rate tooltip when tax is successfully calculated - Show a warning row when tax estimation fails, prompting users to verify their billing address - Update Current Costs and Projected Costs tooltips to indicate whether tax is included or could not be estimated ## Test plan - [ ] Verify tax row appears with correct amount when `tax_status` is `calculated` - [ ] Verify tax rate percentage shows in the tooltip (e.g., "Estimated tax at 10%...") - [ ] Verify warning row appears when `tax_status` is `failed` - [ ] Verify no tax row appears when `tax_status` is `not_applicable` - [ ] Verify "Applicable tax included." appears in Current/Projected Costs tooltips when tax is calculated - [ ] Verify "Tax could not be estimated and is not included." appears in tooltips when tax fails <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Upcoming invoices now include tax details and a tax status. * Billing breakdown shows projected tax and conditionally displays projected totals excluding tax when applicable. * If tax estimation fails, a “Tax — Could not be estimated” row appears and totals reflect the failure. * Added "Stripe Projects" as a billing partner option and clarified that projected amounts may be explicitly null. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
bacd524b22 |
chore: update react-hook-form (#44893)
## Problem We'd like to update react to `19` but many of our dependencies don't support it. ## Solution Update those dependencies. This PR focuses on `react-hook-form` ## How to test Play with some forms, especially those that use arrays of values (database/enumerated types for instance) and the highly dynamic ones (auth providers for instance) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Chores** * Bumped the form-handling library version across apps and packages for improved compatibility and stability. * **Refactor** * Improved component form typings and generics in the studio to increase type safety and reduce potential runtime issues. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1b1d05ff96 |
chore: upgrade vite to v8 and vitest to v4 (#44833)
Upgrade vite and vitest to their latest major versions across the
monorepo, along with related packages.
**Changed:**
- `vite` catalog: `^7.3.2` → `^8.0.8` (Rolldown replaces esbuild/Rollup)
- `vitest` catalog: `^3.2.0` → `^4.1.4`
- `@vitejs/plugin-react`: `^4.3.4` → `^6.0.1`
- `@vitest/coverage-v8`: `^3.2.0` → `^4.1.4`
- `@vitest/ui`: `^3.2.0` → `^4.1.4`
- `vite-tsconfig-paths`: `^4.3.2` / `^5.1.4` → `^6.1.1`
**Pinned to vite 7:**
- `apps/lite-studio` — `@react-router/dev` hasn't declared vite 8
support yet
- `blocks/vue` — Nuxt plugins (`vite-plugin-inspect`, `vite-dev-rpc`,
`vite-hot-client`, `vite-plugin-vue-tracer`) haven't declared vite 8
support yet
**Test fixes for vitest 4 breaking changes:**
- **`apps/studio/lib/api/snippets.utils.test.ts`** — Replaced
`vi.mock('fs/promises')` automock with an explicit factory. Vitest 4's
automocking doesn't create mock functions for getter-based exports on
Node built-ins, so `mockedFS.access.mockResolvedValue` etc. were
`undefined`.
- **`apps/studio/lib/api/self-hosted/functions/index.test.ts`** —
Changed `mockReturnValue` to `mockImplementation(function() { ... })`
for a constructor mock. Vitest 4 no longer allows `mockReturnValue` when
the mock is called with `new`.
- **`apps/studio/tests/pages/api/mcp/index.test.ts`** — Changed arrow
function to regular `function` in `mockImplementation` for
`StreamableHTTPServerTransport`. Arrow functions can't be constructors,
and vitest 4 now enforces this.
- **`packages/ui-patterns/vitest.setup.ts`** — Changed `ResizeObserver`
mock from arrow function to regular `function` for the same constructor
enforcement reason. This was crashing Radix popover rendering in jsdom.
## To test
- `pnpm test:studio` — all 226 test files should pass
- `pnpm --filter ui-patterns vitest run` — all 183 tests should pass
- `pnpm --filter www test -- --run` — all 19 tests should pass
- `pnpm --filter ui vitest run` — all tests should pass
- `pnpm --filter dev-tools vitest run` — all tests should pass
- `pnpm --filter ai-commands vitest run` — all tests should pass
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Standardized and updated development tooling versions and version
sources for consistent installs across the repo (Vite, Vitest,
vite-tsconfig-paths and related plugins/catalog entries).
* **Tests**
* Improved test mocks and typings (updated mock
factories/implementations and tightened spy/type assertions) to increase
test reliability and compatibility with updated tooling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
|
||
|
|
21584fe512 |
feat(studio): add backup cli instructions (#44621)
## Problem When a project is paused, in a failed state, or about to be deleted, users have no obvious way to take a logical backup of their data before proceeding. This is particularly risky at deletion time — once deleted, data is gone. ## Solution Introduce a new `LogicalBackupCliInstructions` component that surfaces ready-to-run `supabase db dump` commands pre-filled with the project's direct connection details. ### Where it appears | State | How | |---|---| | Project paused (restorable) | Inline in `ProjectPausedState` with a note to resume first | | Pause failed | Dialog via "Download backup" button when no backup is available | | Restore failed | Dialog via "Download backup" button when no backup is available | | Delete project modal | Inline in `DeleteProjectModal` for all plans | Not shown in `PauseDisabledState` (project paused 90+ days, compute stopped — `pg_dump` would fail anyway). ### What the component does - Fetches the project's direct connection settings via `useProjectSettingsV2Query` - Builds a connection URI with a `[YOUR-PASSWORD]` placeholder (password is never stored or displayed) - Shows three shell commands to dump roles, schema, and data separately — mirroring the [logical backup docs](https://supabase.com/docs/guides/platform/backups) - Optionally shows a **Reset database password** button (gated on `UPDATE projects` permission); shown in the paused state, hidden elsewhere via `showResetPassword={false}` - Includes inline guidance to percent-encode special characters in the password ### Shell safety The generated `--db-url` values are wrapped in single quotes to prevent shell metacharacter expansion when users paste and run the commands. `npx supabase login` is intentionally omitted — the `--db-url` flag authenticates directly against Postgres and does not require a Supabase account. ### Backup button behaviour in failed states The "Download backup" button in `PauseFailedState` and `RestoreFailedState` now always stays enabled: - **Backup available** — downloads immediately (unchanged) - **No backup / physical backups** — opens a dialog with CLI instructions instead of silently failing ## How to test **Delete project flow** 1. Open any project → Settings → General → Delete project 2. Verify the CLI backup section appears with the project's host, port, user, and db name pre-filled 3. Verify no Reset database password button is shown **Paused project** 1. Open a paused project (`ProjectPausedState`) — verify CLI instructions appear with the "Your project must be resumed before running these commands." note 2. Open a project paused for 90+ days (`PauseDisabledState`) — verify CLI instructions do not appear **Failed states** 1. Simulate a pause-failed or restore-failed state 2. If a downloadable backup exists — "Download backup" downloads it directly 3. Block the backup API or use a project with physical backups — "Download backup" should open the CLI instructions dialog **Error state** 1. Block the project settings API call (DevTools → Network → block request) 2. Verify an error message appears with a link to Database settings 3. Verify a loading skeleton shows while the request is in flight --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|
|
c39e284641 |
Observability: remove healthy/unhealthy badge from Service Health (#44771)
## Problem
The "Healthy / Unhealthy" badge on the Observability overview was
alarming — showing **UNHEALTHY** even when every bar in the chart looked
fine. Two root causes:
1. **The threshold is aggressive.** Any period where the aggregate error
rate is ≥ 1% flips the badge to "Unhealthy", even if that 1% came from a
short burst that is visually indistinguishable in the chart.
2. **Period-wide aggregation hides spikes.** The badge status is
computed over the entire selected time window (e.g. 24 h). A 5-minute
spike at 20% errors diluted across 24 h of mostly-clean traffic can push
the aggregate just over 1%, triggering "Unhealthy" while all chart bars
look green.
The badge wording ("Unhealthy") also implies a current service problem,
whereas the underlying metric is a historical aggregate — making it easy
to misread.
## Change
Remove the badge entirely. The per-row error/warning rate indicator
(e.g. `● 1.34% errors`) already surfaces the key signal without the
alarming label, and the bar chart lets users see the actual shape of
traffic over time.
## On spike visibility in charts
The charts already use **COUNT per time bucket** (not averages), so
individual bars faithfully represent event volume. The bucket
granularity does compress spikes for longer windows (hourly buckets for
1–3 day views, daily for 7-day), but that's a separate concern from the
badge. If we want to surface burst detection in the future, a better
approach would be per-bucket threshold highlighting rather than a single
period-wide badge.
https://claude.ai/code/session_01E1ejWyuR9BV4qcTyiGGVVY
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Removed the service health status indicator from the Service Health
Table.
* **New Features**
* Replaced per-row bar charts with a line chart showing error/warning
rates alongside OK series.
* Added a centered "No data" placeholder when chart data is empty and
preserved click interactions on chart points.
* Y-axis values now display as percentages.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude <noreply@anthropic.com>
|
||
|
|
5a66d00c5e |
feat(studio): update unhealthy project guards (#44855)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This enables the user to restart an unhealthy project as opposed to pausing and reactivating. cc @GaryAustin1 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added detection and dedicated UI for unhealthy projects with restart capability. * Enabled automatic recovery monitoring that dismisses unhealthy state once the project recovers. * **Bug Fixes** * Updated pause button to display appropriate message when project is unhealthy. * Extended restart functionality to support unhealthy project states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fa951a55a6 |
feat(studio): posthog events for scoped pats (#44850)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This is a follow up for both our classic and scoped PAT's to add events for tracking created and deleted. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Enhanced telemetry for access token creation and removal. * Creation events now include token type (classic or scoped), expiry setting, scope/resource access and permission counts when applicable. * Removal events now include token type (classic or scoped). * Instrumentation added across token creation and deletion flows to improve analytics and auditing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
73f678c730 |
fix: auth provider form for sms is invalid when using sms hook (#44820)
## Problem When users have enabled a SMS hook, they can't update the TOPT test values anymore. This is because `formik` sent disabled inputs values in the form payload while `react-hook-form` correctly does not. ## Solution Make the inputs read only instead of disabled ## How to test - Enable SMS auth - Add a SMS hook - Update the SMS auth settings <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Authentication provider form fields now use read-only mode instead of being disabled, preserving focus and interaction while preventing edits across text, secret, multiline, numeric, select, boolean, and datetime inputs. * A new optional read-only prop was added to form fields for consistent behavior. * **Fixes** * Initial form values recalculation was corrected so they update reliably when the selected provider changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8f14dc6b3f |
fix(studio): stop cron job creation when name validation fails (#44871)
Closes #44873 When creating a new cron job, `getDatabaseCronJob` is called to check if the name already exists. If that call throws (network error, DB connection issue), the catch block shows an error toast but doesn't return. Execution falls through to `upsertCronJob`, creating the job without validating name uniqueness. The fix adds `return` in the catch block so the mutation doesn't fire after a failed validation check. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed cron job validation error handling to properly halt processing when name validation fails and display appropriate error feedback. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
595061e20c |
fix(studio): show empty org warning when there are no active projects (#44870)
Closes #44872
The "Empty organization" admonition in the subscription upgrade dialog
checks `.length === 5` instead of `.length === 0`. The warning text says
"This organization has no active projects" but only shows for orgs with
exactly 5 active projects.
Introduced in #44494 (
|
||
|
|
fd427bbe09 |
fix(auth): remove banner from email notification templates (#44887)
Removes the "New" banner from the email notification templates section as the features has been GA-ed for ~6 months now. <img width="1844" height="758" alt="CleanShot 2026-04-15 at 10 30 33@2x" src="https://github.com/user-attachments/assets/4415f651-7274-4565-8e2d-4a66f8bbd100" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed the security notifications acknowledgement feature from the email templates interface, including the dismissible notification tip and associated state management. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |