Commit Graph
34789 Commits
Author SHA1 Message Date
Danny White be7cb44e01 feat(studio): invite multiple team members at once (#42637)
## What kind of change does this PR introduce?

- Feature
- Resolves DEPR-355

## What is the current behavior?

Only one email address can be invited to an organization at a time.

## What is the new behavior?

- Multiple email addresses can be invited (at a single scope) to an
organization at one time
	- List of email addresses detected via comma-separation
	- Pluralization on fields and labels
- Table and copywriting cleanup

| Before | After |
| --- | --- |
| <img width="808" height="691" alt="Supabase"
src="https://github.com/user-attachments/assets/f6450c26-968c-4ee8-bb7c-d6f6a3af1209"
/> | <img width="808" height="691" alt="8298"
src="https://github.com/user-attachments/assets/2d7e3869-b9d4-4a4f-89aa-ae55d67e794b"
/> |
| <img width="1024" height="560" alt="Supabase"
src="https://github.com/user-attachments/assets/9a255167-fcd3-4294-ba3a-9160bd500cff"
/> | <img width="1024" height="560" alt="Supabase"
src="https://github.com/user-attachments/assets/daba5bb8-eb12-43dc-86de-217e9baf0b72"
/> |

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added support for inviting multiple team members simultaneously via
comma-separated emails.

* **Improvements**
* Enhanced member management interface with clearer status indicators
(You, Invited, SSO, MFA enabled/disabled).
* Improved feedback messages for invitation outcomes and member status
changes.
* Updated member table layout with summary footer displaying member
count.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-26 16:27:53 +11:00
Andrey A. aa1aa73200 update .env.example with better comments 2026-02-25 21:44:45 +01:00
Andrey A. b5cb4548b6 add a how-to for self-hosted edge functions 2026-02-25 21:44:19 +01:00
ce980f1724 Modified past webinars and landing page to include YouTube embeds (#43191)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

I modified previous webinars to include the following:
- A YouTube embed of the recording
- New "Watch the Recording" CTA buttons
- New slug for the go page `/vibe-coding-done-right-webinar`

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-02-25 20:17:00 +00:00
Ivan Vasilov 87ee98ed3d fix(proxy): remove first-referrer cookie stamping from Studio and Docs middleware (#43190)
Summary
- Reverts the middleware changes to `apps/studio` and `apps/docs` from
#43153 that caused full page reloads on every client-side navigation in
Studio
- Root cause: broadening the `middleware` matchers to match all routes
and returning `NextResponse.next()` unconditionally interferes with
client-side navigation in the multi-zone production setup (`www` proxies
`/dashboard/*` → Studio, `/docs/*` → Docs)
- Cookie stamping is unnecessary in Studio and Docs because `apps/www`
sits in front of both apps in production and already handles
first-referrer cookie attribution for all incoming traffic
- The `apps/www` middleware, packages/common cookie utilities, and
telemetry changes from #43153 are left intact

Test plan
- Verify client-side navigation works without full page reloads in
Studio (production or preview deploy)
- Verify first-referrer cookie is still stamped via `www` middleware on
initial visit
2026-02-25 20:56:50 +01:00
Jeremias Menichelli fc35630951 fix(Config): Change strong tag font weight to supported font spec (#43183)
## What kind of change does this PR introduce?

Changes the base font weight for strong tags within the
tailwind/typography configuration.

## What is the current behavior?

I noticed that texts within our strong tags had an irregular stroke, and
problems on rendering. The main problem is we are using the default 600
weight value coming from the config of tailwind, while our Circular
custom font supports 400 and 600.

_See the first text in the list from the screen just, like "Multi
Protocol"._

<img width="717" height="555" alt="Screenshot 2026-02-25 at 16 10 29"
src="https://github.com/user-attachments/assets/1063f049-ba9d-45a4-9946-ec4a0e380c48"
/>


## What is the new behavior?

Strong tags now render with 500 font weight to prevent bad text
rendering.

<img width="674" height="505" alt="Screenshot 2026-02-25 at 16 12 56"
src="https://github.com/user-attachments/assets/383e895d-e2b7-4d92-9357-403396ca2722"
/>
2026-02-25 19:13:09 +00:00
Charis d95127982d chore: add sean romberg to humans.txt (#43181) 2026-02-25 18:58:16 +00:00
Ivan Vasilov b0adce51c4 fix(proxy): avoid unconditional NextResponse.next() in Studio middleware (#43189)
Summary
- Fixes full page reloads on every client-side navigation in Studio
caused by the first-referrer cookie middleware (#43153)
- In the multi-zone production setup (www proxies /dashboard/* →
Studio), returning `NextResponse.next()` unconditionally processes every
response through Next.js's middleware pipeline, interfering with
client-side navigation
- Now only returns NextResponse.next() when a cookie actually needs to
be stamped; returns undefined otherwise so Next.js handles the request
untouched
- Also fixes valid API routes (e.g. /api/ai/sql/generate-v4) falling
through to cookie-stamping code instead of passing through cleanly
2026-02-25 19:48:51 +01:00
Jordi Enric f9f0021401 fix iops chart max value (#43182)
The Y axis domain/range was being calculated incorrectly. 

Testing this is a bit painful. You need to: 
- using tweak-extension or similar overwrite the API response for the
IOPS chart and add a really big value
- reload the page
- the Y axis should adapt to that really big value even if it goes over
the disk max iops

See screenshots below

## before
- big data point wouldn't change the chart range 
- Y Axis max is 6k even tho we have a data point over 20k
<img width="1204" height="714" alt="CleanShot 2026-02-25 at 18 47 14@2x"
src="https://github.com/user-attachments/assets/881aff6e-22a2-408d-b2c4-5a27f3fda386"
/>

## after
- the Y axis shows the correct range
<img width="932" height="786" alt="CleanShot 2026-02-25 at 18 47 57@2x"
src="https://github.com/user-attachments/assets/6247c66e-4b3e-49e9-9f6b-086086913fab"
/>
2026-02-25 19:33:57 +01:00
Jordi Enric 785625c92f fix: add compact formatting to Y axis numbers in db charts (#43170)
In the db charts, numbers in the Y axis are not formatted, sometimes
these get too big and get cut-off.

## before
(in this example it is not cutoff because the number is not big enough)
<img width="1020" height="634" alt="CleanShot 2026-02-25 at 11 20 35@2x"
src="https://github.com/user-attachments/assets/bc29edcc-331f-44d1-934f-1553b895c338"
/>

## after
<img width="936" height="676" alt="CleanShot 2026-02-25 at 11 21 07@2x"
src="https://github.com/user-attachments/assets/eae4ea4c-b8cd-4fe4-a361-9b029955217b"
/>
2026-02-25 18:42:17 +01:00
Sean Oliver 75ec7c6e6b feat(growth): re-land first-referrer cookie attribution with fixed middleware matchers (#43153)
## Summary

Re-lands the first-referrer cookie feature from #42768 (reverted in
#43129) with middleware matcher fixes that prevent Studio traffic
interference.

**Tracks:** [GROWTH-651](https://linear.app/supabase/issue/GROWTH-651)

## What changed

New shared module in `packages/common/first-referrer-cookie.ts` that
handles stamping and parsing a first-referrer cookie (referrer, UTMs,
click IDs, landing URL). Each app's middleware calls
`stampFirstReferrerCookie` on the edge response — www and docs are the
primary entry points, Studio is a fallback for direct visits with UTMs.

On the telemetry side, `handlePageTelemetry` now takes an options object
instead of positional args, reads the cookie on initial pageview, and
overrides the referrer if the cookie captured an external source but the
current referrer is internal (i.e., the user navigated cross-app). Also
sends `first_referrer_cookie_present`/`consumed` properties so we can
observe the handoff in PostHog.

The docs middleware matcher was broadened from `/reference/:path*` to
all docs pages so we stamp cookies site-wide, not just on reference
paths.

## Root cause of original revert

Two layers:

1. **Matcher gap**: www middleware ran on `/dashboard/*` traffic in prod
due to Vercel Multi-Zone architecture (www is the gateway for
`supabase.com`, proxying `/dashboard` → Studio, `/docs` → Docs).
Middleware runs *before* rewrites, so www middleware executed on all
proxied traffic.

2. **`_next/data` interception**: The matcher didn't exclude
`_next/data` paths. Client-side navigation in Next.js fetches JSON via
`/_next/data/...` — middleware intercepted these, returned
`NextResponse.next()` with cookie mutations (which processes through the
middleware response pipeline), and this interfered with the JSON
responses, causing full page reloads in the SQL editor.

## How this PR fixes it

| Fix | Detail |
|---|---|
| Exclude `_next/data` | All three matchers (`www`, `docs`, `studio`)
exclude `_next/data` via negative lookahead |
| Exclude `dashboard` + `docs` from www | www middleware no longer runs
on proxied app traffic |
| `/api/` path guard in Studio | Broadened matcher requires explicit
path check for API route filtering |
| `NextResponse.next()` semantics | Cookie stamping only happens on
matched paths; unmatched paths never enter middleware |

### `NextResponse.next()` vs `undefined` nuance

Returning an explicit `NextResponse.next()` with cookie mutations
processes through Next.js's middleware response pipeline (headers are
merged, cookies are set). Returning `undefined` (i.e. the request never
matches the matcher) lets Next.js handle the request completely
untouched. The matcher exclusions ensure `_next/data` and proxied app
paths never enter middleware at all.

## Testing

- ✅ 22 unit tests for shared cookie utilities (all pass)
- ✅ Studio prod build succeeds, middleware recognized as `ƒ Proxy
(Middleware)`
- ✅ Playwright validation: client-side navigation works across 3 page
transitions, `_next/data` requests return 200 OK without middleware
interception, no full-page reloads
- ❌ www/docs SSG builds require platform backend services (expected —
same as master)
2026-02-25 09:24:32 -08:00
Charis 5a01291c23 feat(studio): smart incident banner targeting (#43112)
Feature enhancement — smarter incident banner targeting logic

## What is the current behavior?

Displaying the incident banner requires toggling a flag or environment
variable. Banners are shown to all users regardless of whether their
projects are in affected regions or whether the incident affects project
creation.

## What is the new behavior?

Banner visibility is now driven by `show_banner` metadata from the
StatusPage API — no manual flag or env var toggle needed. Per-user
targeting is then applied:
- Users with projects only see the banner when they have a database in
an affected region
- Users without projects only see the banner when the incident affects
project creation

Incident responses are enriched with cache data (`affected_regions`,
`affects_project_creation`) fetched from a Supabase table. Visibility
logic is extracted into a dedicated hook and pure utility function,
backed by unit tests.

## Additional context

Resolves FE-2562
2026-02-25 17:18:33 +00:00
AnaandAna Mogul ec332eb387 Add PrivateLink feature page (#42999)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

A new feature page

## What is the current behavior?

N/A

## What is the new behavior?

N/A

## Additional context

Add any other context or screenshots.

Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com>
2026-02-25 11:36:40 -05:00
Katerina Skroumpelou 996104a90b chore: remove steal fallback from debuggableNavigatorLock (#43172)
The SDK now handles orphaned lock recovery via steal internally
(supabase-js#2106). Keep the BroadcastChannel observability wrapper for
Sentry signals. The steal-based orphaned lock recovery in
`debuggableNavigatorLock` (packages/common/gotrue.ts) (introduced in
https://github.com/supabase/supabase/pull/39868) is now redundant,
supabase-js#2106 handles this natively in the SDK.

Removes the `navigator.locks.request({ steal: true })` block while
keeping the BroadcastChannel wrapper that sends lock-holder stack traces
to Sentry.

Related: supabase/supabase-js#2106, supabase/supabase-js#2125
2026-02-25 16:19:45 +00:00
Alan DanielandJordi Enric 5d409bfd48 fixes for go bolt webginar page (#43180)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES/NO

## What kind of change does this PR introduce?

Bug fix, feature, docs update, ...

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

## Additional context

Add any other context or screenshots.

Co-authored-by: Jordi Enric <37541088+jordienr@users.noreply.github.com>
2026-02-25 16:09:30 +00:00
Jordi Enric a9a6357227 fix: tests workflow blocking non-studio/ui prs (#43185) 2026-02-25 17:03:44 +01:00
kemal.earth e87fea1681 fix(studio): table padding on auth overview tables (#43176)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Very smol fix. Think a recent fix to chart/card padding bodged it, easy
fix for now.

| Before | After |
|--------|--------|
| <img width="888" height="313" alt="Screenshot 2026-02-25 at 14 08 33"
src="https://github.com/user-attachments/assets/875e3c5e-74c8-414d-a636-8ce4c67dea20"
/> | <img width="875" height="260" alt="Screenshot 2026-02-25 at 14 08
55"
src="https://github.com/user-attachments/assets/6e2e1214-d91f-4364-9fcf-a7cc5deb390d"
/> |
2026-02-25 15:35:48 +00:00
Joshen Lim 9568584fcc Show last migration's name instead of timestamp in new home page (#43115)
## Context

In the new project home page, we have a stat for "Last migration" which
we're showing _when_ the last migration was applied. However:
- The timestamp for the migration is derived from the "version" column
of the migration (in the `supabase_migrations` table) which afaik is
derived from the migration's file name
- It'll be alright if the migration was generated via the CLI, but we
can't really enforce the name of the migration file if say they were
generated via AI, so this is technically a point of flakiness
- Reckon that it's more value to show _what_ was the last migration
rather than _when_ so opting to change the value here to show the name
of the last migration instead

### Before
<img width="620" height="311" alt="image"
src="https://github.com/user-attachments/assets/6876acb6-91d2-4ae3-8ce8-98375658c12c"
/>

### After
<img width="582" height="322" alt="image"
src="https://github.com/user-attachments/assets/a40f6635-2068-4edb-a91a-ccf03d8e4d3c"
/>
2026-02-25 23:20:23 +08:00
Jordi EnricandJoshen Lim 26777710d2 remove fail-on-error (#43175)
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-02-25 22:45:33 +08:00
Charis 9923496486 chore: update prose linter (#43147) 2026-02-25 09:39:21 -05:00
Andrew Valleteau 5b4bc14754 feat(branching): reduce default branching limit for pro account (#42872)
- Add a warning about spend cap not applied on brahching when enabling
github integration
- Reduce default concurrent branches to avoid extra costs incurring

<img width="1247" height="833" alt="Screenshot 2026-02-16 at 18 58 14"
src="https://github.com/user-attachments/assets/9e93161d-7d80-4e6b-a102-3791b309c897"
/>

Fixes: DEVWF-1144
2026-02-25 15:36:25 +01:00
Jordi Enric 03351c784a chore: split tests running from coveralls upload (#43171)
this is so we can easily tell when tests failed vs when coveralls failed
in the PR checks / github action breakdown.

<img width="1510" height="316" alt="CleanShot 2026-02-25 at 11 28 00@2x"
src="https://github.com/user-attachments/assets/ed119654-0341-4554-a2a1-e95f4c7a0995"
/>
2026-02-25 20:53:19 +08:00
Mert YEREKAPAN df8729a82b chore(studio): remove Flag component and related context/hooks (#43103)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Chore / dead code removal

## What is the current behavior?

The `apps/docs/components/Flag/` directory contained legacy feature flag
code that was never wired up:

- `FlagProvider.tsx` — all ConfigCat logic commented out; only wraps
children in an empty context
- `FlagContext.ts` — an empty `createContext({})` with no values ever
set
- `Flag.tsx` — a gate component that reads from the above empty context,
so flags always evaluate to falsy
- `hooks/useFlag.ts` — references the dead local `FlagContext` instead
of `common`'s `FeatureFlagContext`

The docs app already uses `FeatureFlagProvider` from the `common`
package (configured in `apps/docs/features/app.providers.tsx`), making
this entire local implementation obsolete.

Closes
[GROWTH-611](https://linear.app/supabase/issue/GROWTH-611/clean-up-deadlegacy-flag-code-in-docs-app)

## What is the new behavior?

The dead code is removed:

- `apps/docs/components/Flag/` directory deleted
- `apps/docs/hooks/useFlag.ts` deleted

Any code needing feature flags should import `useFlag` directly from
`common`.

## Additional context

No flag-gated features were affected — the old local implementation was
non-functional (context always resolved to `{}`), so removing it has no
behavioral impact.
2026-02-25 09:13:50 +00:00
Danny White 87919a08e6 chore(studio): remove physical backups disabled download button (#43160)
## What kind of change does this PR introduce?

UI update

## What is the current behavior?

- The vast majority of projects now have physical backups, not logical
- Physical backups are not downloadable
- But we show a disabled `Download` button for each physical backup
- This button has confusing multi-step instructions about `pg_dump` that
are
[inaccurate](https://supabase.slack.com/archives/C02BJ2239GA/p1771979586829419?thread_ts=1771887878.203199&cid=C02BJ2239GA)

## What is the new behavior?

- We only show the (enabled) `Download` button for logical backups

| Before | After |
| --- | --- |
| <img width="1024" height="563" alt="AWS Healthy Toolshed
Supabase-6FE7C23F-29D6-47B6-819A-84BC49927F3A"
src="https://github.com/user-attachments/assets/167441bf-3ead-4c86-89df-60ab89ce8b98"
/> | <img width="1024" height="563" alt="AWS Healthy Toolshed
Supabase-C9E763B7-B447-468E-B928-BB9AD5ABC588"
src="https://github.com/user-attachments/assets/3fccdf12-ba4e-424a-87ae-2294f1a3b7b1"
/> |


## Additional context

Support believes removing the button entirely will have less of a burden
than a better tooltip explanation.
2026-02-25 16:43:40 +08:00
Danny WhiteandJoshen Lim 22ff9b2d81 chore(studio): session expired dialog (#43122)
## What kind of change does this PR introduce?

UI improvement

## What is the current behavior?

The session expired dialog is quite hard to parse when, for most people,
the ask is simple.

## What is the new behavior?

Improved session expired dialog:

- Refactored to use AlertDialog
- Clarified copywriting
- Uses the new AlertCollapsible to hide all the complicated debugging
steps under a toggle
	- This component is documented in the design-system

| Before | After |
| --- | --- |
| <img width="1024" height="563"
alt="Supabase-B1728A05-DDD2-4A50-AED4-D62EAA2E7D7C"
src="https://github.com/user-attachments/assets/771f85d8-21ea-42b5-99f5-b9b05f5617dd"
/> | <img width="1024" height="563" alt="Storage Supabase"
src="https://github.com/user-attachments/assets/b2fcab68-fb29-4cb9-bd42-aecc57b9fa32"
/> |
| <img width="1024" height="563"
alt="Supabase-B1728A05-DDD2-4A50-AED4-D62EAA2E7D7C"
src="https://github.com/user-attachments/assets/771f85d8-21ea-42b5-99f5-b9b05f5617dd"
/> | <img width="1024" height="563" alt="Storage Supabase"
src="https://github.com/user-attachments/assets/babd3711-5fdf-43b9-be06-d96268a191fd"
/> |

## To test

In apps/studio/hooks/misc/withAuth.tsx:

```diff
- const [isSessionTimeoutModalOpen, setIsSessionTimeoutModalOpen] = useState(false)
+ const [isSessionTimeoutModalOpen, setIsSessionTimeoutModalOpen] = useState(true) // Mocked as true for UI testing
```

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-02-25 16:27:48 +08:00
Joshen Lim 4f26af6259 Remove org slug and project ref filter for GET notifications request (#43167)
## Context

Since moving notifications to the Advisors Panel, we've been sending
`org_slug` and `project_ref` to the GET notifications endpoint, which
resulted in certain notifications not being returned such as those that
are user specific (no org slug nor project ref)

Am opting to remove both slug and ref filters for the notifications as
the notifications should be on a user level (irregardless if you're
within a project or not) - the Advisor's Panel's button in the layout
header would also suggest that notifications in there are not tied to an
org or project

## To test

This one's a bit tricky to test unless you have notifications on
staging, but i've double checked on prod with a curl command that
removing the org slug and project ref filters returns the correct
notifications
2026-02-25 16:09:21 +08:00
slegarragaandChris Chinchilla d727d33db9 docs: replace deprecated getSession with getClaims in SolidJS tutorial (#43034)
Fixes #42192

Replaces the deprecated `getSession` call with `getClaims` in the
SolidJS tutorial documentation (`with-solidjs.mdx`).

Changes:
- `supabase.auth.getSession()` → `supabase.auth.getClaims()`
- `data.session` → `data.claims`

This follows the recommended migration pattern per the Supabase auth
docs, and is consistent with the same fix applied to the Refine tutorial
in #43006.

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-25 08:30:14 +01:00
Gildas Garcia 65dfd228ad Allow filtering the list of available edge functions when creating/editing a cron job (#43138)
## Problem

Finding a specific edge function is cumbersome when you have many of
then.

## Solution

Use a combobox instead of a select to allow filtering

## How to test

- Enable the cron extension
- Enable the pg_net extension
- Create a few edge functions 
- Create a new cron job and select _Supabase edge functions_

You should be able to:
- select/unselect an edge function
- filter the list to reduce the number of edge functions displayed
2026-02-25 08:05:33 +01:00
Danny WhiteandJoshen Lim 487c74f174 feat(studio): sortable projects (#43118)
## What kind of change does this PR introduce?

Feature. Resolves DEPR-390

## What is the current behavior?

Projects aren’t sortable in either the card or table view.

## What is the new behavior?

Projects are sortable in both:

- Card view: sort dropdown
- Table view: sort dropdown or table column headers

| Before | After |
| --- | --- |
| <img width="1382" height="797"
alt="Supabase-4D1BFE40-875D-494C-8F17-A68D92826458"
src="https://github.com/user-attachments/assets/c4f17b77-bc90-447f-90cd-78a11c2e4129"
/> | <img width="1382" height="797"
alt="Supabase-D8C0AC7C-A28D-4AA6-BA7C-0FCD61DB5D11"
src="https://github.com/user-attachments/assets/d926d03d-2702-48e5-9d1f-0e09d163079d"
/> |
| <img width="1382" height="797"
alt="Supabase-0A545C5C-40B5-47F7-9ACD-2200879BB95E"
src="https://github.com/user-attachments/assets/f2103c32-a150-4db7-a78a-8bd610e2a028"
/> | <img width="1382" height="797"
alt="Supabase-0F7AB608-2E86-4F0C-BB60-C85D9B7F3D57"
src="https://github.com/user-attachments/assets/baa63f14-4059-483d-a9d6-33663e5cff43"
/> |

## Additional context

I wonder if this is overkill given most folks only have 1–2 projects.
Some ideas:

- Only sortable in table view via column headers
- Conditional rendering for folks with 2+ projects
- Opt-in feature
- Feature-flag

I’ve opted to make it global and synced for now.

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-02-25 10:47:56 +11:00
Prashant SridharanandAlan Daniel b1f93226bb Added video embeds of previous webinars (#43134)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

We are now saving our old webinar videos as unlisted YouTube videos.

I added the video embeds to previous webinars.

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-02-24 21:52:32 +00:00
Stephen Morgan e87117a04f chore: update to the AUP (#43114)
Updated AUP based on discussions with Legal and Abuse Ops. 

A lot of wholesale changes based on recent events. Including numbering
in the clauses so these can be directly referred to in communication.
2026-02-25 07:40:17 +13:00
lmoss-sb 864f4216ac Add Lindsay, self, to humans.txt (#43152)
New hire to support team
2026-02-24 18:36:02 +00:00
Francesco Sansalvadore 834ce5cb9b chore(studio): add Billing nav command (#42954) 2026-02-24 16:31:15 +01:00
Jordi Enric 9c8a8d25d1 fix: universal link redirects to general (#43131)
Currently `/org/_` redirects to `/general` (org settings) after picking
an org, this makes it redirect to the project list

## to test
- go to /dashboard/org/_
- select org
- redirects to project picker 

## test 2
- go to /dashboard/org/_/general
- select org
- redirects to /org/whatever/general (settings)
2026-02-24 16:10:30 +01:00
supabase-supabase-autofixer[bot]andmandarini 5570451040 feat: update @supabase/*-js libraries to v2.97.1-canary.3 (#43139)
This PR updates @supabase/*-js libraries to version 2.97.1-canary.3.

**Source**: manual

**Changes**:
- Updated @supabase/supabase-js to 2.97.1-canary.3
- Updated @supabase/auth-js to 2.97.1-canary.3
- Updated @supabase/realtime-js to 2.97.1-canary.3
- Updated @supabase/postgest-js to 2.97.1-canary.3
- Refreshed pnpm-lock.yaml

This PR was created automatically.

Co-authored-by: mandarini <6603745+mandarini@users.noreply.github.com>
2026-02-24 16:33:58 +02:00
Charis d72d70aec6 chore: add sana to humans.txt (#43143) 2026-02-24 14:28:05 +00:00
Illia BasalaievandIllia Basalaiev 6fa7e3517a improve PITR message on scheduled backups (#43132)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

studio message update

## What is the current behavior?

Under the scheduled backups
dashboard/project/_/database/backups/scheduled, the current message is
"Your project uses PITR and full daily backups are no longer taken.
They're not needed, as PITR supports a superset of functionality, in
terms of the granular recovery that can be performed."

The new message mainly addresses the word "superset" since it implies no
trade-offs. However, having teams/enterprise plan, customers lose access
to 2+ weeks of daily backups and are only limited by the selected PITR
recovery duration. New message: "Your project uses PITR, and full daily
backups are no longer taken. PITR lets you restore to a specific time
(down to the second) within your selected PITR retention period."

---------

Co-authored-by: Illia Basalaiev <illiab@IMB3.local>
2026-02-24 15:11:08 +02:00
Alaister Young 8b81bcdb50 [FE-2635] fix: fail build if assets upload fails (#43137)
Adds `set -eo pipefail` so any failed upload immediately exits the
script with a non-zero code, failing the Vercel build.
2026-02-24 20:53:14 +08:00
Cemal Kılıç d810b7772b feat(docs): token_endpoint_auth_method in OAuth server docs (#43128)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## Summary
The OAuth server supports three token endpoint authentication methods
(`none`, `client_secret_basic`, `client_secret_post`), but the docs only
showed `client_secret_post` implicitly without labeling it, and never
mentioned client_secret_basic (the actual default for confidential
clients per RFC 7591).

- Add `token_endpoint_auth_method` explanation with defaults/constraints
to the client registration section in getting-started.mdx
- Update registration examples (JS, Python, cURL) and response JSON to
include token_endpoint_auth_method
- Restructure token exchange and refresh token sections in
oauth-flows.mdx to show all three auth methods with clear labels
- Add `client_secret_basic` examples using HTTP Basic auth header
2026-02-24 17:29:47 +05:30
Ivan Vasilov 85e6b1143f chore: Revert "fix: persist first referrer across app boundaries (#42768)" (#43129)
This reverts commit
https://github.com/supabase/supabase/commit/04e63dfb2e00c43f8c57e538b8056aa647f4e5b4
since it was causing the Studio app to rerender the full page on every
link navigation.
2026-02-24 11:56:44 +00:00
Prashant SridharanandAlan Daniel 14d36e9480 Bolt webinar cta page (#43107)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

New Go landing page for the upcoming Bolt webinar. This is where we will
direct customers who want to learn more to go to request a meeting.

---------

Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
2026-02-24 10:50:54 +00:00
Nika Krasnov 1a3d818de6 docs(auth): fix typo in Google Auth scopes documentation (#43093)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update. Fix typo
2026-02-24 10:22:28 +00:00
lch-supa 5cbaad90af docs: remove duplicate paragraph in Realtime concepts (#43051)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update 

## What is the current behavior?

A paragraph describing Realtime database connections appears immediately
before the "Database connections" section header, then again immediately
after it

## What is the new behavior?

Removed the first (pre-header) instance of the paragraph, so the
description appears only once, in its natural place beneath the section
header.

## Additional context

No visual changes, just a clarity/deduplication fix.
2026-02-24 11:18:26 +01:00
heinzen94andGildas Garcia cb9e28f669 Adding myself to humans.txt (#43104)
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-02-24 11:15:43 +01:00
Kevin Strong-Holte 91928552bd Add Kevin Strong-Holte to humans.txt (#43113)
And then there were three.
2026-02-24 11:15:18 +01:00
Gildas Garcia a30188f914 Add Gildas Garcia to humans (#43125) 2026-02-24 11:14:53 +01:00
Timothy Lim d31534f8be chore(docs): Update download backup guide with more clarity and links (#43124) 2026-02-24 17:38:27 +08:00
Danny WhiteandJoshen Lim 1d46515edb chore(studio): misc design polish (#42966)
## What kind of change does this PR introduce?

UI polish

## What is the current behavior?

Various UI rough edges that are tiny but add up.

## What is the new behavior?

- Empty state for Data API: Replaced `Link` that had overly-specific
styles with `InlineLink`
- Copywriting improvements on Account

| Before | After |
| --- | --- |
| <img width="1024" height="560" alt="Integrations
Supabase-CDDA8DBC-57D8-4D43-A1BD-0D935D9F2442"
src="https://github.com/user-attachments/assets/1af9abb0-166b-490d-a07d-e4eb7144b558"
/> | <img width="1024" height="560" alt="Integrations
Supabase-E8CE34C7-D2AB-4842-93AB-04BD42D94CAC"
src="https://github.com/user-attachments/assets/f0d911ea-72c2-4e1e-8d16-7effb9847196"
/> |
| <img width="1024" height="560" alt="Account Settings Supabase"
src="https://github.com/user-attachments/assets/f12c76c7-5912-4bc3-8cbb-df27588add51"
/> | <img width="1024" height="560" alt="Account Settings Supabase"
src="https://github.com/user-attachments/assets/4c926313-9ff1-4e13-9546-c407dca4e7bf"
/> |

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-02-24 16:54:14 +08:00
Riccardo Busetti d6637aaf8b feat(etl): Improve copy for advanced settings (#43123) 2026-02-24 09:25:58 +01:00
Sreyas Udayavarman b2d20011c1 Update compatibility.mdx (#43121)
Removing "Public Alpha" status from the documentation to reflect current
status.

* [S3 Compatibility](https://supabase.com/features/s3-compatibility)

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

Please link any relevant issues here.

## What is the new behavior?

## Additional context
2026-02-24 13:37:56 +05:30