Commit Graph
370 Commits
Author SHA1 Message Date
issuedat cc6645a43b fix: providers sheet should have a minimum width (#39229) 2025-10-07 17:34:12 +02:00
Monica Khoury ab3a96026a fix: add quotes around policy names in SQL preview (#39320) 2025-10-07 12:17:12 +03:00
kemal.earth 422c7cee5d feat(studio): auth usage learn more section (#39295)
* feat: first draft of learn more section auth overview

* chore: remove unused null

* feat: add docs image

* feat: add url to logs

* chore: update docs image

* feat: image for logs and assistant too

* feat: hook up ask assistant button
2025-10-07 08:56:23 +01:00
issuedat 5219515c53 feat(auth): introduce toggle to make the email optional (#38788) 2025-10-03 12:22:05 +02:00
kemal.earth 685505a568 feat(studio): add auth overview feature flag (#39113)
* feat: basic auth overview page setup

Adds the route and layout for the Authentication Overview page.

* feat: add feature flag for auth overview

* chore: small clean up

* feat: add overview page header

* feat: create sections for auth overview page

Adds three high level components for the sections of the Auth overview page. Can break down further later

* feat: add conditional redirect for top level sidebar item

This adds a redirect based on whether overview page is enabled or not. For users who dont have it enabled they go to users as default when tapping authentication.

* feat: add redirect if overview is set to false

* fix: add loaded context for feature flag

* chore: clean up scaffolding mark up

* chore: remove unused important

* chore: placeholders for sections
2025-10-02 13:43:57 +01:00
Joshen LimandAlaister Young 75212d44e1 Chore/direct upgrade prompts to support based on flag (#39166)
* Add UpgradePlanButton which handles redirecting either to subscription page or support page

* Update upgrade CTAs to go to support if billing:all flag is disabled

* Nit

* Nit

* Smol fix

* Temp show plan upgrade support category

* revert as instructed

* asChild

---------

Co-authored-by: Alaister Young <a@alaisteryoung.com>
2025-10-02 04:46:06 +08:00
Joshen LimandCharis Lam 843234e153 Add flag to hide email and phone columns in auth users (#39151)
* add flag to hide email and phone columns in auth users

* fix: add authentication:show_email_phone_columns to required schema

---------

Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com>
2025-10-02 01:26:14 +08:00
Joshen Lim a2f695547b Fix auth pages error state consistency and missing loading states (#39092) 2025-10-01 17:26:47 +08:00
Stojan Dimitrovski f4c8ab62da fix: enabled/disabled indicator for web3 (#38709) 2025-10-01 10:44:25 +02:00
Joshen Lim 149963f168 Add callout for leaked password that its on the pro plan and above (#39102) 2025-09-30 21:25:25 +08:00
Saxon Fletcher 00702b7191 Give password protection visibility within auth protection (#39095)
password protection
2025-09-30 17:21:58 +08:00
Yadong (Adam) Zhang 9cfa6e8b53 fix: allow NumpadEnter key for search and pagination actions (#38889) 2025-09-26 18:59:05 +00:00
5f533247e1 Update docs url to env var (#38772)
* Update Supabase docs URLs to use env variable

Co-authored-by: a <a@alaisteryoung.com>

* Refactor: Use DOCS_URL constant for documentation links

This change centralizes documentation links using a new DOCS_URL constant, improving maintainability and consistency.

Co-authored-by: a <a@alaisteryoung.com>

* Refactor: Use DOCS_URL constant for all documentation links

This change replaces hardcoded documentation URLs with a centralized constant, improving maintainability and consistency.

Co-authored-by: a <a@alaisteryoung.com>

* replace more instances

* ci: Autofix updates from GitHub workflow

* remaining instances

* fix duplicate useRouter

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: alaister <10985857+alaister@users.noreply.github.com>
2025-09-26 10:16:33 +00:00
Joshen Lim d183b1eefc Fix missing parenthesis in policy editor (#38852) 2025-09-22 11:18:09 +07:00
Donghoon Nam e1040bfe77 fix: Correct learn more link on developer.apple.com (#38174) 2025-09-18 17:11:09 +00:00
Joshen Lim 1b91f5ae79 Address odd bug between data grid contextmenu and overlay (#38809)
* Address odd bug between data grid contextmenu and overlay

* nit

* Smol tweak
2025-09-18 18:54:28 +08:00
Chris StocktonandChris Stockton 9907fb25f4 fix(ui/auth-sessions): always show refresh token reuse interval (#38723)
* fix(ui/auth-sessions): always show refresh token reuse interval

The reuse interval input was previously hidden when rotation was disabled. This
caused confusion, since the interval still applies regardless of rotation
setting. Allow zero values for reuse interval as it is supported in auth server
and is used by some projects.

* Always render SECURITY_REFRESH_TOKEN_REUSE_INTERVAL field.
* Removed .positive() schema check to allow 0 values
* Improves alignment between dashboard UI and backend behavior

* chore: prettier

---------

Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
2025-09-16 09:20:33 -07:00
Joshen Lim d46525eac1 Chore/swap use check permissions with use async check project permissions part 8 (Season Finale) (#38619)
* Update perms checking in audit logs

* Deprecate useCheckPermissions, useIsPermissionsLoaded and useCheckProjectPermissions as they're no longer used

* Rename useAsyncCheckProjectPermissions to useAsyncCheckPermissions

* Fix TS
2025-09-16 17:05:57 +08:00
Stojan Dimitrovski 1d0d56a3f3 feat: web3 (ethereum) ui (#38623) 2025-09-15 11:57:03 +02:00
CharisandJoshen Lim 271ee3af6d fix: estimate number of users when count is large (#38638)
* fix: estimate number of users when count is large

In the Auth Users table, we always fetch an exact count of users. This
can be a problem for projects with many (>50K) users as the count(*)
might cause performance issues on the database. We already have logic on
the Table Editor to only run automatic count estimates (fetching the
exact count only if usr requests it), this change ports the same logic
over to Auth Users.

* Nit refactor

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-09-12 13:07:31 +08:00
Cemal Kılıç a12243d145 fix: update auth audit logs link (#38585) 2025-09-10 09:23:59 +00:00
Cemal KılıçandJoshen Lim 97c16123b1 feat(auth): add audit logs configuration page (#37409)
* feat(auth): add audit logs configuration page

* chore: prettier

* fix: config name

* Update auth audit logs settings page UI

* Update docs URL

* feat: use log template for auth audit logs

* Nit

* Nit

* Update field reference for auth audit logs

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-09-10 10:34:06 +02:00
Joshen Lim e955f69e2d Swap useCheckPermissions with useAsyncCheckProjectPermissions Part 5 (#38552)
Update auth pages
2025-09-09 22:07:55 +08:00
65b962e771 design system: text color contrast (#38343)
* Refactor Drawer component and add date-fns dependency

Refactored the Drawer component for improved slot-based structure, updated styles, and added 'use client' directive. Added 'date-fns' as a dependency in design-system, updated tsconfig paths for icons, and marked ToggleGroup as a client component.

* nit: add env for svg path

* fix: instructions

* accent color docs and basic tidy

* copy value feature

* improve color contrast

* increase contrast on text-warning in light mode

* update changelog

* replace outdated text-warning utility classes

* remove redundant warning-600

* minor design-system docs updates

* docs updates

* remove unused brand-button class

* update docs

* fix: restore brand default

* update docs brand text color

* low hanging branded text fruit

* Nit refactor and clean  up

* re-add Kemal’s README instructions for hot reload

---------

Co-authored-by: Jonathan Summers-Muir <MildTomato@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-09-09 11:45:08 +10:00
Joshen Lim f066c02c69 Shift refresh button to header in table editor and make realtime + API docs button smaller (#38463)
* Shift refresh button to header in table editor and make realtime button + api docs button smaller

* Fix ts
2025-09-08 14:15:39 +08:00
Joshen Lim ad9aa0eaa1 Fix policy header actions (#38233) 2025-08-28 10:51:15 +07:00
Stojan Dimitrovski ef78a07f01 feat: expose mfa setting for limiting aal1 sessions to 15 mins (#35886)
* feat: expose mfa setting for limiting aal1 sessions to 15 mins

* fix

* fix types
2025-08-27 20:04:16 +02:00
Saxon FletcherandJoshen Lim a299180c24 update realtime and storage policies (#38229)
* update realtime and storage policies

* Small refactors

* Tiny fix

* Fix typo

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-08-27 16:07:27 +07:00
Joshen Lim 4124f0ed98 Shift useFlag hook and configcat library to common package, remove from Studio (#38203)
* Shift useFlag hook and configcat library to common package, remove from studio

* Fix test

* Fix test
2025-08-27 13:42:20 +07:00
Saxon Fletcher 5e87a858ec Refine roles (#38225)
* refine roles

* copy
2025-08-27 15:41:06 +10:00
Saxon FletcherandJoshen Lim db4ae7e326 Refine the policies page (#38204)
* refine the policies page

* minor fixes

* Fix TS

* Do not transform table name in policy row table header

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-08-26 22:09:17 +07:00
Joshen Lim 7b1ac2a66e Chore/disable more sections 04 (#38064)
* Add flags for policies, third party auth, and manual linking + providers in sign in page

* Add flag for rate limitm page

* Add UnknownInterface components

* Update comment

* Flip flags to true

* Add flags for realtime policies and reports page

* Temp

* Add flag for sign in providers page

* Add flag for stripe wrapper

* Add flag for custom domains

* Add flag for dedicated ipv4 address addon

* Add empty state for realtime policies

* Add empty state for reports page

* Add flag for disable legacy JWT keys section

* Add flag for legacy jwt keys

* nit

* Remove ConnectionStringMoved call out

* Add flag for project settings log drains

* Add flag for subscription link in project settings

* Deprecate settings/auth page and redirect directly to auth page

* Flip back flags

* Add flags for account preferences analytics marketing and account deleetion

* Remove 'table_editor:enable_rls_toggle' flag and revert UI changes

* Remove 'authentication:policies' flag and revert UI changes

* Add flags for cmd K routes

* Add flags for instance size in infra settings

* Small refactor to DisplayApiSettings, decouple ToggleLegacyApiKeysPanel from it

* Have project_connection:javascript_example toggle code example title to TS

* add flag for templates dropdown in logs explorer

* UsesOverview only show link to providers page if providers is enabled

* API Docs UserManagement to only include docs on third party auth if providers is enabled

* Hide instance size on project card if flag is off

* Fix cmd k for roles, update redirect link from settings/auth to auth/providers
2025-08-22 16:17:43 +08:00
Joshen Lim 78fab83aee Chore/disable authentication segments (#38029)
* Add flags for policies, third party auth, and manual linking + providers in sign in page

* Add flag for rate limitm page

* Add UnknownInterface components

* Update comment

* Flip flags to true

* Add flag for sign in providers page
2025-08-20 19:34:41 +08:00
Alaister YoungandJoshen Lim a0f86b3010 feat: disable users features (#38020)
* feat: disable logs features

* feat: disable project homepage features

* feat: disable org features

* Nit fixes

* reenable billing

* feat: disable database features

* feat: disable users features

* Change create user flag to send invite

* Change create user flag to send invite flag

* Tiny nit

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-08-19 14:22:12 +08:00
Ignacio Dobronich 61379cbe2a chore: add confirmation modal when enabling SMS MFA (#37879) 2025-08-13 09:06:07 -03:00
Joshen LimandDrake Costa a897cc27f0 Part 1 of swapping useCheckPermissions with useAsyncCheckProjectPermissions (#37751)
* Part 1 of swapping useCheckPermissions with useAsyncCheckProjectPermissions

* Update apps/studio/hooks/misc/useCheckPermissions.ts

Co-authored-by: Drake Costa <drake@saeris.io>

* Address feedback

---------

Co-authored-by: Drake Costa <drake@saeris.io>
2025-08-11 11:53:15 +07:00
Stephen Morgan 18f3191b18 discourage email comparison (#37708) 2025-08-08 14:00:12 +07:00
Joshen Lim cab0585533 Fe 1799/consolidate to useselectedprojectquery and (#37684)
* Replace all usage of useProjectContext with useSelectedProjectQuery

* Replace all usage of useSelectedProject with useSelectedProjectQuery

* Replace all usage of useProjectByRef with useProjectByRefQuery

* Replace all usage of useSelectedOrganization with useSelectedOrganizationQuery

* Deprecate useSelectedProject, useSelectedOrganization, and useProjectByRef hooks

* Deprecate ProjecContext
2025-08-06 10:53:10 +07:00
Saxon FletcherandJoshen Lim c76707012d basic typography classes (#37613)
* basic typography classes

* Clean up classes for where we use h1 tags

* Clean up classes for where we use h2, h3, h4

* Clean up classes for where we use h6

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-08-04 20:55:34 +10:00
Ivan Vasilov eb95e36e50 fix: The mail confirm setting should be negated (#37615)
* The mail confirm setting should be negated.

* Fix the comments.
2025-08-01 10:22:13 +02:00
Joshen Lim 9a8bd0fae4 Chore/convert cron jobs to data grid (#37601)
* Use DataGrid for cron jobs interface instead of cards

* Deprecate CronJobCard and database-cron-jobs-run-query.ts

* Add tooltip for editing unnamed job

* Implement infinite scrolling to cron jobs + server side searching

* Deprecate database-cron-jobs-query, and add a singular database-cron-job-query

* Add hover card for cron job table cell command
2025-08-01 15:20:31 +08:00
Ivan VasilovandClaude 9fda63d9ba fix: Move confirm email setting from email provider to basic auth settings (#37573)
* Move confirm email setting from email provider to basic auth settings

- Remove MAILER_AUTOCONFIRM from email provider form validation
- Add confirm email setting to BasicAuthSettingsForm with proper form validation
- Maintain existing functionality while improving UX by grouping related settings

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>

* Update BasicAuthSettingsForm.tsx

* Fix the default value of email confirm.

* Remove unnecessary comment.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-07-31 09:50:09 +02:00
Ivan VasilovandJoshen Lim b3c6992e56 feat: Make the protected schemas dynamic, namespace schemas are now protected (#37290)
* Add hooks for async protected schemas.

* Migrate the ProtectedSchemaWarning to support the new implementation.

* sq

* Migrate all uses of protected schemas to the new approach.

* Delete extra file.

* Refactor the import foreign schema dialog to forbid protected and exposed schemas.

* Add the type to the protected schema.

* Revert ImportForeignSchemaDialog, it'll be addressed in another PR.

* Update apps/studio/hooks/useProtectedSchemas.ts

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>

* Fix a bad commit.

* Minor fixes.

* Fix the FDW delete mutation to handle names with numbers.

* Simplify the logic to skip a fetch.

* Minor fixes.

* Make the useIcebergFdwSchemasQuery work for all iceberg FDWs.

* Fix the tab schemas to always show in the Table Editor.

* Apply suggestion from @joshenlim

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>

* Fix a minor typo.

* Refactor ProtectedSchemaWarning to use Admonition, and standardise input field for target schema iceberg

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-07-30 11:38:50 +02:00
Joshen LimandAlaister Young b9a0908331 Refactor post calls from lib/common/fetch in auth pages to data/fetchers (#36506)
* Deprecate use of getWithTimeout, refactor BuildingState and RestoringState to use RQ

* Refactor profile-create-mutation to use data/fetchers, and edge-function-status-query to use fetch

* Shift post from lib/common/fetch, refactor bucket-object-download-mutation

* Address feedback

* Minor fix

* Refactor post calls from lib/common/fetch in auth pages to data/fetchers

* Add missing POST users endpoint + small fix when deleting user via context menu

* simplify handleFetchError

* allow handleFetchError to accept unknown

* non-breaking change

---------

Co-authored-by: Alaister Young <a@alaisteryoung.com>
2025-07-21 12:45:53 +08:00
Alaister Young dac0ee6575 chore: deep link feature preview modal (#37191)
* chore: deep link feature preview modal

* handle invalid keys gracefully

* default to first feature preview in query

* use nuqs
2025-07-16 14:38:33 +08:00
Saxon Fletcher 94c45c2863 AI UI refine and renaming (#36819)
* ui refinements

* rename chat

* copy

* prose message styles

* add icon back

* fix message save

* simplify empty state

* update suggestions

* pass through props

* button styles

* onboarding icons

* name button

* remove results

* current chat name

* use type

* fix down arrow

* re-add chat name
2025-07-08 12:09:11 +10:00
Chris StocktonandChris Stockton 8a4bca34a7 feat: add documentation and UI integration for Before User Created hook (#36567)
* feat: add documentation and UI integration for Before User Created hook

- Added new guide: `before-user-created-hook.mdx`, documenting usage, inputs,
  outputs, and multiple complete examples for HTTP and SQL.
- Updated navigation menu and hook index table to include the new hook.
- Hook is now listed as available on Free and Pro plans.

Studio changes:
- Registered `Before User Created` hook in `hooks.constants.ts` with proper
  title, slug, and configuration keys.
- Enabled Docs button linking to hook guide in both `CreateHookSheet` and `HookCard` components.
- Extended hook listing page to support docs access via `secondaryActions`.

This hook allows developers to intercept and reject user creation across all
flows (email/password, OAuth, SSO, SAML, anonymous) - enabling custom signup
logic like domain allowlists, geofencing, or account gating.

* fix: add subnet to mdx lint allowed list

* fix: incorporate feedback and spelling changes

* feat: add allow/deny domain and CIDR examples to before-user-created hook

This commit enhances the documentation for the before-user-created auth hook:
- Adds production-ready SQL examples for blocking or allowing signups by email domain (signup_email_domains) and IP address or CIDR (signup_networks)
- Introduces enum-based classification (allow vs deny) for both domain and network restrictions
- Adds full migration-style snippets for easy copy/paste into Supabase SQL Editor
- Includes updated HTTP examples that delegate to Postgres functions via Supabase client rpc()
- Adds environment setup guidance and edge function scaffolding

* fix: pnpm format

---------

Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
2025-07-02 14:54:07 -07:00
Joshen Lim c8dbc57051 Minor update to new API keys modal for disabling / reenabling legacy keys (#36554)
* Minor update to new API keys modal for disabling / reenabling legacy keys

* Minor update

* Refresh user count as well when clicking refresh in auth users management
2025-06-23 15:28:07 +08:00
Joshen Lim 1153a214c1 Fix delete button in users management (#36435) 2025-06-16 18:00:35 +08:00
Joshen LimandIvan Vasilov 27d9b44526 Consolidate copy to clipboard (#36353)
* Consolidate copy to clipboard

* Fix

* Fix some extra clipboard events.

* Fix the tests. Fix a small issue with the copy button.

* Fix

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2025-06-13 13:08:08 +02:00