mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
d4079083fc094ce176cf76d0e787edb2a6fa6170
36234
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
d4079083fc |
chore(studio): drop @supabase/postgres-meta in favor of @supabase/pg-meta (#45844)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor / dependency cleanup. ## What is the current behavior? `apps/studio` lists both `@supabase/pg-meta` (workspace package) as a runtime dep and `@supabase/postgres-meta` (external npm package, `^0.64.4`) as a devDependency. The external package is used only for type imports across 44 files — there is no runtime usage and no codegen pipeline that needs it. ## What is the new behavior? Every `Postgres*` type import (`PostgresTable`, `PostgresColumn`, `PostgresPolicy`, `PostgresTrigger`, `PostgresView`, `PostgresMaterializedView`, `PostgresForeignTable`, `PostgresSchema`, `PostgresPublication`, `PostgresRelationship`, `PostgresPrimaryKey`) is replaced with its `PG*` counterpart from `@supabase/pg-meta`, and the external dep is removed from \`apps/studio/package.json\`. Top-level type re-exports were added to \`packages/pg-meta/src/index.ts\` so consumers can import directly from the package root. Two latent issues surfaced by the stricter pg-meta types are also fixed: - \`data/foreign-tables/foreign-tables-query.ts\` was casting foreign-table results as \`PostgresView[]\`; corrected to \`PGForeignTable[]\`. - \`pg-meta\`'s \`PGTrigger\` Zod schema declared \`orientation\`/\`activation\` as \`z.string()\`, inconsistent with pg-meta's own \`getDatabaseTriggerUpdateSQL\` helper that requires the narrow literal unions; tightened to \`z.enum\`. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated internal TypeScript type definitions across the codebase to use the latest type system from `@supabase/pg-meta`. * Removed `@supabase/postgres-meta` dependency. * Enhanced type validation for database triggers and schemas to enforce stricter constraints. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45844) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6383150c3e |
fix(tests): flaky unit tests (#45852)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Typing each character by hand leads to slowness with multiple render cycles in CI - Update timeouts <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Improved test reliability and stability for the Support form page. Enhanced test synchronization and timing for UI interactions including form field prefilling, organization and project selection, category and severity assignment, form submission, error notifications, dashboard logging toggles, and attachment uploads. These enhancements strengthen test quality and help prevent regression issues in form functionality. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45852) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fe769bfe7e |
fix: escape quotes (#45848)
## TL;DR - closes https://github.com/supabase/supabase/issues/45860 - closes https://github.com/supabase/supabase/issues/45544 & supersedes https://github.com/supabase/supabase/pull/45543 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added explicit allowed facet fields and validation to prevent invalid facet usage. * **Bug Fixes** * Improved filter handling by coercing values to strings and properly escaping single quotes for array, scalar, and LIKE filters (including facet search), reducing query errors and injection risks. * Enhanced parsing of scheduled-job SQL commands to tolerate varied casing/whitespace and strip leading SELECT before processing. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45848) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
712cf7e60b |
feat(storage): add keyboard shortcuts for storage screens (#45837)
## Summary
Adds keyboard shortcuts to the Storage section, mirroring the
conventions already established for Auth Users and Database pages:
- **Storage navigation chords** (`S, F` / `S, A` / `S, V` / `S, 3`)
active only inside `StorageLayout`.
- **Files (bucket list) page** shortcuts for search, create, refresh,
reset filters, reset sort.
- **Storage Explorer** shortcuts for upload, new folder, view toggle,
refresh, search, multi-select download/move/delete, and an Escape
ladder.
- `ShortcutTooltip` wired into the relevant buttons so users can
discover keybinds on hover.
- Reload spinner is now driven by a shared store flag, so it shows
whether you click the button or fire the shortcut.
## Test plan
### Storage navigation chords
Active anywhere under `/project/<ref>/storage/*`.
| Keybind | Action |
|---------|--------|
| `S` then `F` | Go to Files |
| `S` then `A` | Go to Analytics buckets (platform + feature-flagged) |
| `S` then `V` | Go to Vector buckets (platform + feature-flagged) |
| `S` then `3` | Go to S3 settings (platform only) |
### Files (bucket list) page
At `/project/<ref>/storage/files`.
| Keybind | Action | Notes |
|---------|--------|-------|
| `Shift+F` | Focus search ("Search buckets") | Selects existing text |
| `Shift+N` | Create new bucket | Opens the create-bucket modal |
| `F` then `C` | Reset filters | Clears the search string |
| `Shift+R` | Refresh buckets | Refetches the bucket list |
| `S` then `C` | Reset bucket sort | Only fires when sort ≠ default
(Created at) |
### Storage Explorer (inside a bucket)
At `/project/<ref>/storage/files/buckets/<bucketId>`.
| Keybind | Action | Notes |
|---------|--------|-------|
| `Shift+F` | Focus search ("Search files") | Opens the search input if
hidden, then focuses |
| `Shift+R` | Refresh | Refetches all opened folders; spinner reflects
state |
| `I` then `F` | Upload files | Disabled w/o ` STORAGE_WRITE ` or at
bucket root with no folder |
| `I` then `N` | Create folder | Same permission gates as Upload |
| `V` then `C` | View as columns | |
| `V` then `L` | View as list | |
| `Shift+D` | Download selected | Only fires when ≥1 item selected;
single vs many handled |
| `Shift+M` | Move selected | Only fires when ≥1 item selected AND `
STORAGE_WRITE ` granted |
| `Mod+Backspace` | Delete selected | Only fires when ≥1 item selected
(` Mod ` = ⌘ on macOS / ` Ctrl ` on Win/Linux) |
| `Escape` | Clear selection | If ≥1 item selected |
| `Escape` | Close file preview | If no selection and preview pane open
|
| `Escape` | Close search | If no selection, no preview, and search is
open |
### Tips while testing
- [x] Chords (two-key sequences): press the first key, release, then
press the second key within ~1s
- [x] Hover any wired button (search, Refresh, Upload, Create folder,
View, Download, Move, Delete, the bucket Create button, sidebar items)
to see the keybind in a tooltip
- [x] Most actions also appear under "Shortcuts" in `Cmd+P`
- [x] Chords starting with a plain letter (` S, F ` / ` I, F ` / ` V, C
` / ` F, C ` / ` S, C `) won't fire while typing in an input — click out
first
- [x] `Escape` does fire from inside the search field (closes the
search)
- [x] `Cmd+/` opens the full shortcuts reference
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Keyboard shortcuts added across Storage: buckets (refresh, clear sort,
create, search), explorer (upload, create folder, refresh, download,
move, delete, clear search), and navigation shortcuts for
Files/Analytics/Vectors/S3.
* **UI**
* Shortcut keytips/tooltips added to relevant buttons and menu items for
discoverability.
* **Documentation/Tests**
* Shortcut reference sheet labels updated and covered by a new test.
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45837)
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
|
||
|
|
8ca04989c8 |
fix(studio): reports table footer overflow (#45885)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? A small bug that was causing the overflow of chart table footers to break on smaller viewports. Now fixed along with cell horizontal spacing. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Enhanced table layouts in the Reports section by enabling horizontal scrolling for API Routes and Cache Misses tables, ensuring all data is visible on various screen sizes. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45885) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e492477ad4 |
feat(marketing): add anti-spam protections to /go forms (DEBR-280) (#45842)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — anti-spam protection for all `/go` lead-gen forms. ## What is the current behavior? The shared `MarketingForm` used by every `/go` page has no spam protection: no honeypot, no captcha, no timing check, no dedupe. The Datadog NYC exec dinner form was getting probed with spam submissions ([DEBR-280](https://linear.app/supabase/issue/DEBR-280/reduce-spammy-submissions-on-exec-dinner-form)). ## What is the new behavior? Three layered defenses added to the shared `MarketingForm` + `submitFormAction` so every `/go` form is covered: 1. **Honeypot** — hidden `website` input (off-screen, `aria-hidden`, `tabIndex={-1}`). Server returns a fake success when filled so bots don't probe variations. The field is stripped from the payload before CRM fan-out. 2. **Minimum render-time check** — server rejects submissions that come back in under 3s with a fake success. 3. **Per-session email/form dedupe** — `sessionStorage` keyed by `formGuid`/`database_id` + email blocks double-submits; the success state is shown without re-hitting HubSpot/Customer.io/Notion. ## Additional context No new env vars or services required. Honeypot rejections are logged via \`console.warn\` for monitoring. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enhanced anti-spam protections (honeypot and minimum render time) to block bots. * Prevents accidental duplicate submissions within the same browser session. * Avoids creating duplicate contact/record entries when an existing email is found in storage. * **Other Improvements** * Cleaner event/context data sent to analytics for more accurate tracking. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45842) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1a52c4618f |
fix(www): mobile partner form blank panel on submit success (#45836)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? On the [AI Builders](https://supabase.com/solutions/ai-builders) page (and any other surface using the Talk to Partnerships form), submitting on mobile rendered a blank square instead of the submission confirmation. Linear: [DEBR-279](https://linear.app/supabase/issue/DEBR-279/mobile-partner-form-submit-state-renders-blank-panel). ## What is the new behavior? The success state in `TalkToPartnershipTeamForm` now drops `min-w-[300px]` (which overflowed narrow mobile viewports), removes the redundant `opacity-0`/`transition-opacity` pair that occasionally left the panel stuck at opacity 0 on iOS Safari, and removes the invalid `scale-1` class. The parent panel is now `flex flex-col` so the success message can use `flex-1` to center properly within the `min-h-[200px]` panel. ## Additional context The `animate-fade-in` keyframe already uses `both` fill-mode, so it handles the initial-to-final opacity transition without needing the extra `opacity-0` class. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated success-state container layout and styling with improved flex sizing and spacing behavior. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45836) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
71e94a1590 |
Add partner integration guide and mermaid diagrams (#45730)
- **Draft** - **Update** - **feat: add beautiful-mermaid and integration flow diagrams** - **Make mermaid theme match site** <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Mermaid diagram rendering in docs with themed SVG output. * **Documentation** * Added "Supabase Partner Integration Guide" covering simple and signed-redirect flows, JWT verification, sequence diagrams, and key guidance. * Updated site navigation to include the new partner integration guide. * **Chores** * Added Mermaid rendering dependency. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45730) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
8459c34202 |
fix(studio): export metric banner logos overflow (#45879)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? These logos began to overflow the more log drains we've added. Imported the animated logos from the empty state of log drains settings on free accounts. | Before | After | |--------|--------| | <img width="317" height="256" alt="Screenshot 2026-05-13 at 13 38 11" src="https://github.com/user-attachments/assets/46f04abc-fe33-48f2-8c1f-7d543c85b5a8" /> | <img width="638" height="540" alt="CleanShot 2026-05-13 at 13 47 11" src="https://github.com/user-attachments/assets/e49a9123-f486-45d8-9714-ef41402762d6" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Expanded support for additional telemetry and service integrations including OTLP, Amazon S3, Axiom, Last9, and Syslog in the Log Drains interface. * **Refactor** * Updated animated logo component to support flexible sizing and styling options, improving layout consistency across the metrics API banner. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45879) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
28f5484369 |
Prevent request billing owner for downgrade of plan (#45823)
Related PR: https://github.com/supabase/supabase/pull/45803 Opting for a simpler way to prevent requesting billing owners for downgrading of plan as such: <img width="933" height="258" alt="image" src="https://github.com/user-attachments/assets/604b8c2f-9341-4aec-885c-e2d9d2861b9f" /> Currently we're incorrectly showing a "Request to upgrade to Free" CTA ## To test - [ ] For a pro plan or above organization, and a user that has a "Developer" role, ensure that you're not able to downgrade the org nor send a upgrade request <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Clarified CTA behavior for users without billing update permission: downgrade actions now show a disabled button with an explicit tooltip, while non-downgrade upgrade attempts prompt a request to billing owners. Tooltip messaging has been refined across enterprise, free-tier, and marketplace-managed plans for clearer guidance. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45823) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2d47836f39 |
Joshen/fe 3213 make rls tester feedback callout more obvious (#45820)
## Context Minor nit to adjust the "Give feedback" button at the bottom to use default type + external link icon <img width="612" height="68" alt="image" src="https://github.com/user-attachments/assets/e74370cb-d284-4552-a69d-8c838f565af7" /> Also added telemetry for the "Run query" button <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added analytics tracking for RLS Tester query runs to better understand how the feature is used. * **Style** * Updated the "Give feedback" button in the RLS Tester to use the default button style and display an external-link icon for clarity. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45820) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
380c917b94 |
chore: Bump vulnerable dependencies (#45876)
- Bump various vulnerable dependencies, `nitropack`, `mermaid`, `hono`, `protobufjs`, `fast-xml-builder` and `fast-uri`. - Add `babel/core` to `studio` to stabilize the dependency resolving for `studio`. - Also deduped `cheerio`, `c12`, `browserslist`, `unstorage` and `@mdx-js/mdx` since they were present as multiple similar versions. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added development dependency for the studio application build tooling * Updated workspace configuration to refine dependency exclusion settings <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45876) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
376d85d7b2 |
fix(studio): query performance query column truncation (#45878)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Previously our Query Performance Query column was scrollable inline. This means if you have thicc scrollbars turned on via your OS, it would look a bit clunky. This fix truncates query, full query still viewable in the click through sheet. | Before | After | |--------|--------| | <img width="1106" height="1164" alt="cleanshot_2026-05-13_at_18 56 16_2x" src="https://github.com/user-attachments/assets/4718e8d7-d3c5-499b-a125-6192ac547bfe" /> | <img width="456" height="286" alt="Screenshot 2026-05-13 at 13 34 30" src="https://github.com/user-attachments/assets/7446afb5-c0d7-4272-905a-42c144334472" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Style** * Adjusted query column width in the query performance monitoring table for optimized layout. * **Bug Fixes** * Enhanced query display rendering with improved data type handling to prevent potential display issues. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45878) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
835284bca9 |
docs: link recursive functions guide from trace rate limit troublesho… (#45872)
**Documentation** * Added reference to the "Recursive Functions — What gets rate limited" guide in troubleshooting documentation to help users understand rate limiting behavior with recursive invocations. |
||
|
|
0abe792889 |
chore: Migrate the main Tailwind JS config to CSS (#45686)
This PR migrates the JS config for Tailwind into a CSS config. As such, all variables have been defined as CSS variables and they're using the specialized Tailwind syntax for generating utility classes. Beside the migration, these changes were also added: - Added `tailwind.config.css` to few packages to make the Tailwind Intellisense work. - Migrated away from Radix style color classes to our defined classes, the values will remain the same. - Most of the CSS is generated by scripts, they'll be removed in next PRs. * Removed redundant `border-light` classes from several components since it was undefined. * Removed redundant `text-strong` classes from several components since it was undefined. How to test: - Open all apps, compare the UI (mainly colors) to builds from #45417 and try to find a difference. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Harmonized color variable usages and updated UI color references (affects palettes, charts, gradients, hero illustrations, and scrollbars). * Tweaked border, tab, and selection visuals across components. * **New Features** * Added a suite of theme animations and refined typography presets used by site prose and docs. * **Refactor** * Overhauled Tailwind/theme configuration and color token generation for more consistent theming. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d6d644ec24 |
Update project name if dashboard is local CLI (#45864)
## Context Very minor one, just updates the project name for local CLI, to show "Supabase Studio (CLI)" instead of "Default project" which is a bit more meaningful <img width="1450" height="374" alt="image" src="https://github.com/user-attachments/assets/b6c60172-99e2-43b7-a095-2914248ed292" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Updates** * Refined Project dropdown styling in non-platform mode with improved spacing and text sizing * Default project name now dynamically displays as "Supabase Studio (CLI)" when applicable * Minor header layout tweaks for more consistent spacing and transitions * Improved local version indicator initialization for more reliable version display * **Other Updates** * Small code and organization refinements [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45864) <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45864) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9e0feb5740 |
fix: search on the partners/integrations page was still using misc db (#45866)
The `INTEGRATIONS_MARKETPLACE_DB` was not included in the client bundle (because it doesn't start with `NEXT_PUBLIC_`) which caused the client side search functions on the https://supabase.com/partners/integrations page to keep using the older misc db for search. Steps to reproduce: * Go to the https://supabase.com/partners/integrations page. * Search for `aikido`. * Click the only tile found for this search term. Notice that it takes you to `https://supabase.com/partners/integrations/aikido-security` which 404s. This is because that slug (`aikido-security`) is coming from the old misc db. The correct slug in the new db is `aikido`. Other fixes: * Corrected the tsv column name from `tsv` to `listing_tsv`. * Fixed search debouncing. |
||
|
|
bcfc666284 |
chore: migrate remaining old input usages (#45791)
## Problem We still use our old `Input` in some places. This means multiple components are bundled for the same use cases and we have some design differences across the application. ## Solution - [x] Migrate to the new ShadCN inputs - [x] Fix `<InputGroupButton>` cannot be used with components that triggers modal, popovers, dropdowns - [x] Fix `<FormLayout>` does not display errors for inputs that are not inside a React Hook Form - [x] Fix `InputGroup` invalid design ## Screenshots ### Table Editor - table edition sidepanel Before: <img width="758" height="1206" alt="image" src="https://github.com/user-attachments/assets/d4da4af0-a9d3-4967-935f-554233d7896b" /> After: <img width="747" height="1209" alt="image" src="https://github.com/user-attachments/assets/6286e6a0-317f-486c-a8b4-0e233706ba0f" /> ### Table Editor - row edition sidepanel Before: <img width="675" height="710" alt="image" src="https://github.com/user-attachments/assets/9fdfe819-6d62-40c8-bdc8-fa6051dab834" /> After: (I placed the TextArea button at the bottom because ShadCN reserves a full line space for it. It was weird at the top. <img width="674" height="714" alt="image" src="https://github.com/user-attachments/assets/611d5f8d-de12-4c16-ac38-bd9192cd6d73" /> ### Database settings - password reset modal Before: <img width="773" height="548" alt="image" src="https://github.com/user-attachments/assets/17f679a7-3aed-4cf9-8245-194a8a16823f" /> After: <img width="563" height="311" alt="image" src="https://github.com/user-attachments/assets/08888471-4cc8-4a3c-bf1e-8dce364f1aa6" /> ### Database - Event triggers Before: <img width="1134" height="453" alt="image" src="https://github.com/user-attachments/assets/e9d06d58-782c-4ccb-93c0-2ce1ca8c5748" /> After: <img width="1115" height="451" alt="image" src="https://github.com/user-attachments/assets/c437acb0-c602-4dd2-b249-66c7a7e739d6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Copy action now shows confirmation state (“Copy” → “Copied”) when copying error details. * **UI Improvements** * Unified form-field layouts and input-group composition across editors, settings, and integration forms for a more consistent experience. * Password-strength feedback moved into field layout for clearer messaging. * Improved inline input/button/dropdown behaviors and non-React-form error display. * **Removed** * Display configuration settings component. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45791) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
35571d242e |
chore: migrate <Collapsible> to shadcn <Collapsible> (#45819)
## Problem We have multiple `Collapsible` components. ## Solution Reduce their number by using only the one from shadcn. I haven't noticed any visual nor functional changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Migrated expandable/collapsible UI to a unified shadcn-based implementation for more consistent expand/collapse behavior across the app. * **Style** * Updated listbox check icon sizing and removed obsolete collapsible open/close animations. * **Chores** * Removed deprecated collapsible variants and consolidated UI component surface for simpler maintenance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0751fe2bf4 |
fix: logs explorer field references doesn't show all sources (#45828)
## Problem The field reference side panel doesn't show all sources: there are actually 11 items and users can't see them nor select them. ## Solution Use a combobox instead ## Screenshots Before: <img width="667" height="414" alt="image" src="https://github.com/user-attachments/assets/8017597f-e058-4306-8761-fb54d8c653ba" /> After: <img width="1306" height="1642" alt="image" src="https://github.com/user-attachments/assets/67579315-65cc-4bf9-9744-42f09b816772" /> <img width="1346" height="972" alt="image" src="https://github.com/user-attachments/assets/13df449a-0bb1-41e4-934d-0bb18e9f06d9" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Schema selector in the Logs Query Panel is now a searchable popover and shows the selected source in the button (or prompts “Select source...”). * Field table now displays fields for the chosen schema only. * **Refactor** * UI simplified for faster schema selection and clearer field reference browsing. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45828) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
de30257ed5 |
docs: update to reflect changes with rotating legacy secret (#45855)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Update to troubleshooting guide to reflect changes with legacy JWT secret. As we are no longer supporting rotation of legacy secret, guide has been updated to direct users to migrate to new JWT signing key and new API keys. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated troubleshooting guide for JWT secret management. Now recommends migrating to asymmetric JWT signing keys instead of rotating legacy anon, service, and JWT secrets, with a reference to the migration guide. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45855) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b5725fc760 |
docs: correct import statements in code examples (#45854)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Corrects import statements in code examples in troubleshooting guide. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated SSR package migration guide with corrected code examples for login/signup, client components, server components, and route handlers. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45854) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4211c97f35 |
docs: add context for invalidating storage signed urls (#45841)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Add context around storage signed URLs using separate signing key and invalidating/revoking URLs. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified Supabase Storage signed URLs are generated and validated independently from Auth JWT keys, remain valid until their expiration even if Auth keys change (rotation, disabling, or algorithm switch), and can only be revoked by contacting Supabase support. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45841) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a93eef6848 |
docs: move AI tools section (#45795)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an "AI Tools" guides section with landing, overview, and troubleshooting pages; guides render from Markdown. * **Documentation** * New AI Tools guides: local development, Quickstart, CLI overview, troubleshooting, and detailed overview pages. * **Chores** * Site navigation updated to include an AI Tools entry and renamed subsection to "AI"; added permanent redirects from prior Getting Started AI URLs to the new AI Tools locations. * **Bug Fixes** * Updated internal guide links so AI prompt pages point to the new AI Tools paths. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45795) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Greg Richardson <greg.nmr@gmail.com> |
||
|
|
205ab69061 |
feat(studio): move CLI login to connect interstitial (#45814)
## What kind of change does this PR introduce? Feature / UI refactor ## What is the current behaviour? The CLI browser login route still uses the older API authorisation layout and redirects missing or failed sign-in session states to generic 404/500 pages. ## What is the new behaviour? Moves `/cli/login` onto the shared connect interstitial layout as the next small stacked slice after the organisation invite work. This keeps the real CLI login contract intact while updating the surface: - creates the CLI login session from `session_id`, `public_key`, and optional `token_name` - redirects to the generated `device_code` - renders missing-parameter and session-creation failures in-card instead of redirecting away - keeps the 8-character verification code selectable and copyable as a single string - uses a full-width primary `Copy code` action This also adds the small shared interstitial helpers needed by this surface and adjusts `CopyButton` so the copied check icon inherits the primary button colour instead of turning green. This also removes the CLI version admonition: > Browser login flow requires Supabase CLI version 1.219.0 and above. I checked with our stats and the CLI team. The vast majority of users are on a newer version. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Authorize API access Supabase-D1E3CF26-BD59-4BB2-B457-B552EE47E3DA" src="https://github.com/user-attachments/assets/c89b8b13-fa98-41b7-8093-e59d15b2aa9e" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-C9977F21-88B8-441B-8A2C-09A9515935B0" src="https://github.com/user-attachments/assets/ca13b65a-3875-425c-b73b-8f2101c1e406" /> | | <img width="1024" height="759" alt="Supabase-F42FBEAF-F74D-4920-8A51-7C25004F66D5" src="https://github.com/user-attachments/assets/51adb1e6-a2fb-41fb-b36f-0ae466fe60e2" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-8159A1B1-2594-4183-AC35-FEF1EFD4EA37" src="https://github.com/user-attachments/assets/6f143218-795d-41c9-a8e1-52e529a6b988" /> | <img width="1024" height="759" alt="Supabase-2506E468-9F42-44B9-A5B7-BC4D3777F552" src="https://github.com/user-attachments/assets/a304fca5-cf26-4ae7-abe9-77cdbc21fba5" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-A0EE1239-A345-427C-9CF7-997037A8FC0E" src="https://github.com/user-attachments/assets/33118777-35f3-49d6-bc1e-30e7124b3677" /> | | <img width="1024" height="759" alt="Authorize API access Supabase-A7B84CA6-D230-4C3E-9227-DE21CE35375C" src="https://github.com/user-attachments/assets/78eb6296-035a-4201-b254-b97eda44443c" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-F55E26B2-609B-449C-9C64-08AA90AE3D1E" src="https://github.com/user-attachments/assets/ff7b3b4e-729c-4681-844d-2d5d94bfc084" /> | ## Testing instructions Use the Vercel preview URL for this PR once it is available. The examples below use `<preview-origin>` as a placeholder, for example `https://studio-git-dnywh-feat-cli-login-interstitial-supabase.vercel.app`. You need to be signed in to Studio to see these states because `/cli/login` is still behind `withAuth`. Ready state: - Open `<preview-origin>/cli/login?device_code=ABCD1234` - Check the page title is `Authorize CLI | Supabase` - Check the card title is `Authorize Supabase CLI` - Check the code fills the width, uses the normal sans font, and can be selected - Drag-select the code and copy it; the clipboard should contain `ABCD1234`, not one character per line - Click `Copy code`; the button should show the usual copied success state without a green check icon on the primary button Missing parameters state: - Open `<preview-origin>/cli/login` - Check the card says `Missing sign-in parameters` and names the missing `session_id` and `public_key` parameters - Open `<preview-origin>/cli/login?session_id=session-test` - Check it still stays in-card and names the missing `public_key` parameter instead of redirecting to `/404` Creation error state: - Open `<preview-origin>/cli/login?session_id=not-real&public_key=not-real&token_name=local-dev` - Check it stays in-card with `Unable to create CLI sign-in` instead of redirecting to `/500` - The exact error detail can vary by environment; the important bit is that the failure is shown inside the interstitial card Loading state: - This is transient because there are no production mocks in this slice - To inspect it manually, throttle the browser network before opening a session-creation URL such as `<preview-origin>/cli/login?session_id=not-real&public_key=not-real` Real CLI flow: - Run the browser login flow from Supabase CLI as usual - When the CLI opens a Studio URL, keep the path and query string but replace the origin with the PR preview origin - The page should create the login session and then route to `/cli/login?device_code=<8 character code>` - Enter that 8-character code back in the CLI prompt <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Redesigned CLI login flow with clearer state-driven screens and improved verification UI. * Added a small paired-logo component for centered logo pairs with a connector icon. * **Improvements** * Copy button behavior and styling refined for consistent visual feedback across variants. * **Tests** * New unit tests covering copy-button behavior and multiple CLI login UI flows. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45814) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9660b0075c |
refine organisation invite state helpers (#45813)
## What kind of change does this PR introduce? Code cleanup. Follow-up to #45774. ## What is the current behavior? The organisation invite interstitial derives invite states, titles, and descriptions from nested conditional logic in the component. That makes the component harder to scan and pushes too much state coverage into render tests. ## What is the new behavior? See #45774 for screenshots of the general UI before-and-after (which this one builds upon). That PR also contains testing instructions. Extracts the invite status and content decisions into small pure helpers, then covers those helpers with focused unit tests. The component keeps the user-facing render and interaction coverage, including the invalid lookup regression where a 404 should render the invalid invite state instead of raw backend copy. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved organization invite flow with enhanced error state handling for expired, invalid, and wrong-account scenarios. * Better consistency in error messages and user guidance throughout the invite process. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45813) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
36152cb7fe |
docs(ai): assistant evals development workflow (#45840)
Adds `README.md` to `apps/studio/evals` explaining the development workflow for updating offline and online evals for Studio's AI Assistant. Resolves AI-681 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added comprehensive documentation for Studio Assistant Evals, covering evaluation setup, configuration of scoring methods, and deployment workflows for both offline and online evaluation processes. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45840) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d143571586 |
feat(assistant): trace-level scorers + server-side tool execution with needsApproval (#45654)
## Motivation When Assistant runs a potentially destructive tool like `execute_sql`, it stops the LLM request and prompts for client-side approval and execution of the tool. After approval, a second request kicks off under a separate trace. This has made scoring and [Topics](https://www.braintrust.dev/blog/topics) classification challenging, as the generated `output` is split across stateless requests. The [span-level scoring](https://www.braintrust.dev/docs/evaluate/custom-code#score-spans) approach we've used thusfar (after the LLM call, we massage the result into an `output` payload that's stuck onto the root span) has been cumbersome and led to invalid scores / topics where only part of the assistant response is considered. It's also inefficient, as we're duplicating potentially large info (like the `search_docs` output) that already exists within the trace. An alternative to scoring spans is to [score traces](https://www.braintrust.dev/docs/evaluate/custom-code#score-traces). Braintrust [best practices](https://www.braintrust.dev/docs/evaluate/score-online#best-practices) advise: > Use span scope for evaluating individual operations or outputs. Use trace scope for evaluating multi-turn conversations, overall workflow completion, or when your scorer needs access to the full execution context. We've also received [direct guidance](https://supabase.slack.com/archives/C05QYJBLX89/p1777925770927149?thread_ts=1777905716.911979&cid=C05QYJBLX89) from their team to use this approach. ## Changes Migrates eval scorers from custom `AssistantEvalOutput` shape to trace-level scoring via `trace.getThread()` / `trace.getSpans()`, with thread parsing that scores the full latest Assistant turn and passes prior conversation separately where relevant. Moves `execute_sql` and `deploy_edge_function` from client-side execution after approval to AI SDK `needsApproval` + server-side `execute()`. SQL results returned to the model are gated by AI opt-in level, so row data is only included with `schema_and_log_and_data`; otherwise the tool returns the no-data-permissions sentinel. Adds `metadata.isFinalStep` to disambiguate multiple LLM requests within an "assistant" turn due to tool call requests/responses. For online evals, this means we should configure automations to only score traces with `metadata.isFinalStep = true` to ensure we're judging the complete generated response. Other minor kaizen changes: - Renamed `promptProviderOptions` to `systemProviderOptions` to clarify that this is associated with the "system" message and disambiguate from the root `providerOptions` - Adds `evals/trace-utils.ts` to handle Zod validation of the `unknown` span shapes from Braintrust, to more easily access typed inputs/output on tool spans. - Bumps AI SDK floor version `^6.0.116` → `^6.0.174` - Tweaked the "Conciseness" scorer to not unfairly dock points for the new `[called tool_name]` labels in serialized assistant response ## Verification In the studio staging build, I asked Assistant to create a todos table with 3 sample todos. I manually approved the `execute_sql` call and saw Assistant generate text before & after the call. In Braintrust I verified two traces were produced (see [filtered logs](https://www.braintrust.dev/app/supabase.io/p/Assistant/logs?v=Staging&tvt=trace&search={%22filter%22:[{%22text%22:%22metadata.environment%2520%253D%2520%27staging%27%22,%22label%22:%22metadata.environment%2520%253D%2520%27staging%27%22,%22originType%22:%22btql%22},{%22text%22:%22%2560Chat%2520ID%2560%2520%253D%2520%25221cb2ac45-e5e7-458c-9da4-3bf6863b8842%2522%22,%22label%22:%22Chat%2520ID%2520equals%25201cb2ac45-e5e7-458c-9da4-3bf6863b8842%22,%22originType%22:%22form%22}]})), the first with `metadata.isFinalStep = false` and the second with `metadata.isFinalStep = true`. In the Braintrust staging scorers, I ran the preview Completeness scorer on the second trace and verified it sees the complete Assistant response including markers for tool calls ([link to trace](https://www.braintrust.dev/app/supabase.io/p/Assistant%20(Staging%20Scorers)/trace?object_type=project_logs&object_id=b5214b62-ad1e-4929-9d5b-40b1daebe948&r=0ed0a4f8-8aff-4a34-bb1d-1df1d88a5070&s=ff9015f8-6bf7-4ab3-83a9-ca4e69e27e82)) <img width="1193" height="960" alt="CleanShot 2026-05-07 at 11 27 10@2x" src="https://github.com/user-attachments/assets/509d4858-c3a1-4068-986d-3aa4d5617d1a" /> I also tested the `deploy_edge_function` workflow and verified it still prompts for permission and warns on deployment of existing functions. **References** - https://www.braintrust.dev/docs/evaluate/custom-code#score-traces - https://ai-sdk.dev/docs/ai-sdk-core/tools-and-tool-calling#tool-execution-approval Supercedes https://github.com/supabase/supabase/pull/45556 and https://github.com/supabase/supabase/pull/45339 Closes AI-473 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Tool actions (SQL execution, edge-function deploy) now require explicit user Approve/Deny before proceeding. * **Improvements** * Assistant pauses for approval responses before sending follow-ups, giving clearer control over risky actions. * Deploy/replace flows show confirmation and clearer replace warnings. * Evaluation/scoring updated to use richer trace data for more accurate assistant performance signals. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
90d383f182 |
feat(studio): cross-link disk IO usage to observability charts (#45376)
## Problem Users on the Infrastructure activity tab see a Disk IO Bandwidth chart that plots burst budget percentage rather than real disk activity. The more granular IOPS and throughput charts live in Observability, but there is no path between the two pages — users either dismiss real warnings or file support tickets. Reported in [Linear DEBUG-64](https://linear.app/supabase/issue/DEBUG-64). ## Fix Two cross-links into Observability/Database: 1. **Below the Disk IO Bandwidth chart** ([InfrastructureActivity.tsx](apps/studio/components/interfaces/Settings/Infrastructure/InfrastructureActivity.tsx)) an Admonition with a "View detailed IOPS and throughput" button. Only shown for the disk IO section, not CPU/RAM. 2. **In the disk IO exhaustion banner's Troubleshoot dropdown** ([ResourceExhaustionWarningBanner.tsx](apps/studio/components/ui/ResourceExhaustionWarningBanner/ResourceExhaustionWarningBanner.tsx)) a "View metrics" item alongside Documentation and Ask AI Assistant. The banner part is wired via a new optional `metricsHref` on `ResourceWarningMessage`, so CPU/RAM warnings can opt in later by adding their own observability path. ## Test plan - [ ] Visit `/project/{ref}/settings/infrastructure` on a project that does not have dedicated I/O resources. Confirm the new Admonition appears under the Disk IO chart and the button navigates to `/project/{ref}/observability/database`. - [ ] On a project with dedicated I/O resources, confirm only the existing "dedicated I/O" Admonition shows (no double-Admonition). - [ ] Trigger (or mock) a `disk_io` resource warning; confirm the banner's Troubleshoot dropdown shows "View metrics" first and links to Observability. - [ ] Trigger a `cpu` or `ram` warning; confirm the dropdown does NOT show the new item. 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Clarifies that the disk IO consumption chart shows remaining burst budget, not real throughput. * Adds a quick-access button to jump to the Database Observability page for detailed read/write IOPS and throughput. * Adds a "View metrics" link in resource exhaustion warnings for disk IO issues (shown when a single warning is active). <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
420d4d0b5a |
feat(studio): add Disk IO Burst Balance chart to DB Report (#45516)
## Problem When users hit a disk IO exhaustion notification, they open the Database Observability report and find IOPS and throughput charts, but no view of the metric that actually fired the warning: the EBS burst credit balance. That signal is currently only available behind Custom Reports, so the warning feels disconnected from the visible data. > "The Dashboard actually shows them their burst budget, not their normal disk usage. It leads to a lot of confusion." — support > "Customers may receive an 'exhausting multiple resources' warning and it's confusing because all the charts are 'fine', but it's the burst credits exhaustion that fails them." — Maksym Reported in [Linear DEBUG-60](https://linear.app/supabase/issue/DEBUG-60). ## Fix Add a clearly-labeled "Disk IO Burst Balance" chart to [getReportAttributesV2](apps/studio/data/reports/database-charts.ts) plotting `disk_io_budget` (% remaining) on a 0-100 axis. Tooltip and titleTooltip explain the 5 MB/s throttle floor so users can correlate this chart with the exhaustion banner copy (also being updated in [supabase#45514](https://github.com/supabase/supabase/pull/45514)). The chart is hidden for compute variants that have dedicated I/O resources (4XL and above) since the burst credit pool does not apply there. Burstable variants (nano through 2XL) see the chart inline next to the existing IOPS and throughput charts. DEBUG-61 ("replace Disk IO Usage % chart with disk throughput") was already addressed in the V2 migration (the report only renders `disk-iops` and `disk-throughput`; the old burst-percentage chart is gone). I'll close that issue as completed once this lands. ## Test plan - [ ] Visit `/project/{ref}/observability/database` on a project running `nano`/`micro`/`small`/`medium`/`large`/`xlarge`/`2xlarge` compute. Confirm the new "Disk IO Burst Balance" chart appears between throughput and connections. - [ ] On a project running `4xlarge` or larger compute, confirm the chart is hidden (chart is omitted by `hide: !hasBurstableIO`). - [ ] Hover the chart and a data point. Confirm the title tooltip and inline attribute tooltip both surface the 5 MB/s throttle behaviour. - [ ] Series renders 0-100 on the Y-axis. 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a Disk IO Burst Balance chart to monitor remaining burst credits; displays percentage (0–100%) with tooltip referencing baseline throughput. Shown only for supported compute variants and when the feature flag is enabled. * **Bug Fixes / UI Improvements** * Improved chart header tooltip presentation: uses a unified tooltip, includes inline docs links when available, and avoids duplicate docs icons. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45516) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
11dbb8d7d1 |
fix(studio): use per-tier baseline throughput in disk IO banner copy (#45833)
## Problem The disk IO exhaustion banner copy added in #45514 hardcoded the throttle floor as **5 MB/s**, but that's only correct for nano. Every burstable compute tier has its own baseline, since `baselineThroughputMBps` in [`packages/shared-data/compute-disk-limits.ts`](packages/shared-data/compute-disk-limits.ts) is `toMBps(43)` for nano (which rounds to 5), `toMBps(87) = 11` for micro, and so on: | Tier | Throttle floor | |------|---------------| | nano | 5 MB/s | | micro | 11 MB/s | | small | 22 MB/s | | medium | 43 MB/s | | large | 79 MB/s | | xlarge | 148 MB/s | | 2xlarge | 297 MB/s | Caught during review of the equivalent change in #45516. ## Fix - Replace the hardcoded `5 MB/s` in `ResourceExhaustionWarningBanner.constants.ts` with a `{baseline}` placeholder in the `disk_io_exhaustion` banner copy. - In `ResourceExhaustionWarningBanner.tsx`, read the selected project's compute variant, look up `baselineThroughputMBps` in `COMPUTE_DISK`, and substitute the placeholder in both the title and description. Falls back to `'its baseline'` if the variant isn't in the map. `cardContent` for `disk_io_exhaustion` doesn't mention the floor, so no changes there. ## Test plan - [ ] use dev toolbar to toggle the disk io banner, should see different throttle floors based on instance - [ ] on micro: "...throttled to 11 MB/s..." - [ ] on medium: "...throttled to 43 MB/s..." <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Enhancements** * Disk I/O exhaustion warnings now display dynamic baseline values tailored to each project's configuration instead of a fixed threshold. * Warning and critical messages have been updated to reference the project-specific baseline and clarify that throughput returns to that baseline until the budget resets, improving clarity about throttling behavior and its duration. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45833) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
da44ab3088 |
feat(www): fetch partner integration listings from marketing-db (#45725)
This adds a layer of indirection to fetch partner integration listings for the marketing page from the new Marketplace DB, which will allow us to maintain these listings via the same admin UI we're building for in-app integration listings. Fixes INT-102 |
||
|
|
1fbed21528 |
chore: migrate old <Alert> usages to <Admonition> (#45797)
## Problem Some pages still use the old `<Alert>` component ## Solution - [x] Use the new `<Admonition>` - [x] Remove `<Alert>` ## Screenshots ### Table Editor - Disable RLS modal Before: <img width="582" height="527" alt="image" src="https://github.com/user-attachments/assets/bbc5b874-2569-4cd6-98c0-5edd5ac78e0f" /> After: <img width="543" height="505" alt="image" src="https://github.com/user-attachments/assets/bb1da899-2163-4b26-ba0b-74726e0cb5df" /> ### Organization Billing Before: <img width="1111" height="512" alt="image" src="https://github.com/user-attachments/assets/6fb410fb-9ac0-4fb7-8dde-e304ddee7ece" /> After: <img width="1103" height="531" alt="image" src="https://github.com/user-attachments/assets/6eda6ede-edc6-482f-ab9c-d085402cbd64" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Replaced Alert UIs with Admonition across billing, settings, storage, integrations, and editor interfaces. * Removed the deprecated AlphaPreview component. * **Chores** * Removed the Alert component from the UI library, including its styles, tests, and theme configuration. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45797) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
52237e1ae4 |
Open advanced settings + scroll to that collapsible if submitting has an error (#45818)
## Context Compute and Disk page: There's an odd scenario whereby down sizing the compute might involve some validation errors in the advanced settings, in which case because the advanced settings is in a collapsible and requires the user to scroll down, there's hence no visual indication of where the error is until the user opens the advanced settings to see the inline error. Am hence opting to open the advanced settings + scroll to it for this particular scenario, if submitting the form causes a validation issue on either IOPS, throughput or max disk size field inputs (the rest in this section do not have validation checks on that afaict and hence wouldn't be applicable to this scenario) ## To test Can be tested locally - Upsize compute to 8XL + change throughput to 750 - Once completed, try to down size to XL and hit "review changes" - It should be clear from a UX POV if there are any errors Also added an unrelated nit tidy up for ExitSurveyModal <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Advanced disk settings now auto-open and scroll into view (with a brief delay) when validation errors occur for throughput, IOPS, or size, improving error visibility. * **User Interface** * Improved advanced settings panel animation and separators for clearer visual boundaries. * Updated project deletion layout for the reason chooser and message input, providing a more consistent form appearance. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45818) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
602b879e4a |
Fix table editor editing a row, setting a timestamptz column to NULL doesn't work (#45824)
## Context There's a bug atm with the Table Editor whereby hitting "Set to NULL" on a date time format column, doesn't set it to `null` but rather an empty string - which then causes an error when trying to update the row, so this PR addresses that <img width="703" height="252" alt="image" src="https://github.com/user-attachments/assets/bdb7e73e-de85-44ea-9852-eeaef2faee4d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed date/time input field handling to properly support NULL value assignment. The "Set to NULL" action now correctly applies NULL values instead of empty strings in the table editor. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45824) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8255a63a86 | ref(etl): Improve error message handling (#45713) | ||
|
|
6bd4812348 |
Update humans.txt (#45638)
Added myself to humans.txt <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated team roster in public documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
0e6390df6c |
Add 'Richard Kasprzak' to the list of contributors (#45587)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Update to add 'Richard Kasprzak' to 'humans.txt' ## What is the current behavior? 'Richard Kasprzak' is not present in 'humans.txt' ## What is the new behavior? 'Richard Kasprzak' is present in 'humans.txt' <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated team roster information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
01734f473a |
Update humans.txt (#45506)
Update new joiner ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Update human.txt ## What is the current behavior? NA ## What is the new behavior? NA ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added new team member to public roster <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0b3e5686cd |
Add Marija Milicevic to humans.txt (#45577)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update ## What is the current behavior? Please link any relevant issues here. ## What is the new behavior? Feel free to include screenshots if it includes visual changes. ## Additional context Add any other context or screenshots. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added a new team member to the contributor list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
34170f6ed3 |
Add PierreD to humans.txt (#45598)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Add myself to the human list ## What is the current behavior? I am not in the list. ## What is the new behavior? I want to be in the list. ## Additional context I just joined the company... <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated contributor documentation <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bdc8d07632 |
chore: Add blockExoticSubdeps to prevent GitHub URLs and tarballs (#45817)
This pull request introduces a configuration update to the `pnpm-workspace.yaml` file. The most significant change is the addition of the `blockExoticSubdeps: true` setting, which helps prevent the installation of potentially problematic or non-standard subdependencies across the workspace. There is also a minor adjustment in the `overrides` section, but it does not result in any functional changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Enhanced package dependency configuration to prevent exotic subdependencies and improve installation reliability. * Reorganized dependency override specifications for consistency. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45817) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
44315b79e9 | chore(docs): add Julian Domke to humans.txt (#45815) | ||
|
|
7809574fc8 |
chore(docs): add Christian Funkhouser to humans.txt (#45810)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? An update to humans.txt ## What is the current behavior? When viewing humans.txt, Christian is not included. ## What is the new behavior? When viewing humans.txt, Christian _is_ included. ## Additional context Christian works here now, and wants to be a human, too. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated team contributor acknowledgments. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45810) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
791fc74412 |
feat(studio): shared connect layout for organisation invites (#45774)
## What kind of change does this PR introduce? Feature. Part of DEPR-279. ## What is the current behavior? The organization invite page has its own bespoke centered card and page-level Supabase logo. ## What is the new behavior? Introduces a minimal shared interstitial layout and migrates `/join` onto it as the first small connect-surface slice. The invite API and accept-invite mutation paths are unchanged. | Before | After | | --- | --- | | <img width="1024" height="794" alt="Supabase-F2325C57-D5DE-445D-8083-12EF8A1EE0CA" src="https://github.com/user-attachments/assets/b23dcc7a-c649-4b59-9393-9232d74f0c6b" /> | <img width="1024" height="794" alt="Join Organization Supabase-66CDA329-0531-4B12-AC32-A7E21931F876" src="https://github.com/user-attachments/assets/454917ce-1a96-4e50-b003-6c16a541b39a" /> | | <img width="1060" height="822" alt="CleanShot 2026-03-13 at 11 04 43@2x-2616AECB-8203-4439-A1CD-45AB18FC4CA8 1-584A0600-CCE0-4F16-9111-9BEB94BE85EC" src="https://github.com/user-attachments/assets/871c7dcb-120e-40cd-afc8-2cec95e4b7ae" /> | <img width="1024" height="794" alt="Join Organization Supabase-26AD978E-4CF9-4600-9885-082084349E94" src="https://github.com/user-attachments/assets/ee9bfaff-dde4-4366-abae-77dc8a95c4ef" /> | | <img width="1024" height="794" alt="Supabase-4993D74C-D62B-43B7-9681-826BE1591AC4" src="https://github.com/user-attachments/assets/1c411ae0-90e7-481d-a4cc-3eac26267291" /> | <img width="1024" height="794" alt="Join Organization Supabase-C84D4E4C-24F5-463D-B1D6-D11D3256596F" src="https://github.com/user-attachments/assets/688387a4-3c49-41db-b89c-7c5531e91aed" /> | | <img width="1024" height="794" alt="Supabase-D9BD2601-98A4-489D-A51D-CEB73F51FA6F" src="https://github.com/user-attachments/assets/6d1da65f-d655-4047-9f6a-db65f8c0a729" /> | <img width="1024" height="794" alt="Join Organization Supabase-50065F40-179A-4BD6-8F1D-6106FFD8A15C" src="https://github.com/user-attachments/assets/e61809f9-dcec-4e51-ba94-91b04010ec50" /> | ## Testing notes Staging invite emails are generated with the fixed staging dashboard origin, for example: ```text https://supabase.green/dashboard/join?token=...&slug=... ``` To test this PR preview with a real invite token, keep the path and query string from the email but replace the origin with the Vercel preview origin, for example: ```text https://studio-staging-git-dnywh-featconnect-interstitial-join-supabase.vercel.app/dashboard/join?token=...&slug=... ``` ### Manual state checks - **Signed out:** open the swapped invite URL in an incognito window or a browser signed out of Studio. Expected: `View invitation`, sign-in/create-account actions, and no loading skeleton hang. - **Wrong account:** sign in to the PR preview as an account that is not the invite recipient, then open the swapped invite URL. Expected: `Wrong account`, warning callout, and `Sign out`. - **Happy path:** sign in as the invited email address, then open the swapped invite URL. Expected: `Join {Organization}`, signed-in account row, `Accept invite`, and `Decline`. Accepting should join the organization. - **Invalid token:** alter one character in the token in the swapped invite URL. Expected: invalid invite state. - **No longer valid:** accept the invite once, then open the same swapped invite URL again. Expected: no-longer-valid/already-used state, depending on the backend response. ### Test-covered states Expired invites, generic backend error, loading, and create-account-disabled states are harder to force manually in staging. They are covered by `tests/components/OrganizationInvite.test.tsx`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Redesigned the organization invitation experience with an interstitial layout, clearer early-return flows for signed-out, loading, expired/invalid, wrong-account, and accepted-invite states; primary CTA now reads “Accept invite”. * Streamlined error and sign-out flows with clearer, focused messaging. * **New Features** * Added a reusable interstitial layout and compact account row for invitation screens. * **Tests** * Added comprehensive tests covering invite states, accept/decline actions, and error handling. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45774) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
13e6b04004 |
fix(studio): hide incorrect 'last paused' date in project paused state (#45805)
Hides the 'Project last paused on' date shown in the paused state for free-plan projects, as the date returned by the API is currently incorrect (API team is investigating) Related ticket: FE-3149 |
||
|
|
7092cac4a4 |
e2e: fk save shortcut (#45804)
adds coverage for: - #45761 which solved #45759 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added test coverage for keyboard shortcut save workflow in the column editor with foreign-key relationships. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45804) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e55411da5e |
feat(studio): Fly.io deprecation banner (#45778)
## Summary Adding an in-dashboard banner for the Fly.io May 31 suspension. Banner targets users on a Fly project (or with a Fly project in their currently-selected org) and surfaces a per-project breakdown of what's affected in a dialog. Detection is self-correcting: as soon as the user migrates off Fly, the banner disappears with no follow-up. <img width="557" height="502" alt="Screenshot 2026-05-11 at 5 08 22 PM" src="https://github.com/user-attachments/assets/7bafb712-3490-4555-9667-66e9909f1b1a" /> <img width="1675" height="536" alt="Screenshot 2026-05-11 at 3 55 06 PM" src="https://github.com/user-attachments/assets/6c1bf9d1-4dcc-4aac-a679-2ed477d2ed1c" /> ## Changes - **Detection hook** (`useFlyDeprecationProjects`): reads only from already-cached data — `useSelectedProjectQuery` for the current project, plus `useOrgProjectsInfiniteQuery` scoped to the selected org. Zero cross-org fan-out: worst case is one paginated query per session (the same one the project list page already makes). - **Banner component** (`FlyDeprecationBanner.tsx`): mounted in `AppBannerWrapper`. Dynamic title (primaries / branches / both), dialog lists affected projects with org name, numbered migration steps, links to backup/restore CLI + Dashboard backup + branching docs. List truncates to 5 entries with "…and N more." tail when more are affected. - **Telemetry**: `fly_deprecation_banner_exposed` and `fly_deprecation_banner_dismissed` events emitted via `useTrack` (auto-injects project + org groups). Properties: `primaryCount`, `branchCount`. CTA click tracking intentionally omitted — migration outcome is measured via warehouse `cloud_provider = 'FLY'` decay. - **LocalStorage**: dated dismissal key `FLY_DEPRECATION_2026_05_31`; orphan `FLY_POSTGRES_DEPRECATION_WARNING` from PR #33510 removed in the same change so users who dismissed the Feb 2025 banner still see this one. - **Support contact**: email `success@supabase.io` only (no support ticket link), per Brian's outreach copy in the Linear issues. ## Coverage trade-off Banner renders on project pages (selected-project check) and pages where the selected org's projects list is cached (org overview, project list). It does **not** render on `/dashboard` home or other pages without org context. Email outreach from GROWTH-817 / GROWTH-819 handles those users. This was a deliberate trade-off to avoid cross-org fan-out load. ## Lifecycle Banner expires `2026-06-01T00:00:00Z` (right after the May 31 deadline). Stale client bundles stop rendering it without a redeploy. Cleanup PR planned post-deadline to remove the component, hook, localStorage key, and telemetry events. ## Testing Tested on the Vercel preview with React Query cache overrides to mock a Fly project: - [x] Banner renders for a user with at least one project where `cloud_provider === 'FLY'` - [x] Banner does **not** render for a user with no Fly projects - [x] Banner does **not** render on `/sign-in` - [x] Title varies by primaries-only / branches-only / both - [x] Dialog lists affected projects with org name in parens - [x] Dialog list truncates to 5 with "…and N more." for larger sets - [x] Migration guide / Dashboard backup / branching links open in a new tab - [x] Dismiss (×) closes the banner and persists across hard reload (localStorage `fly-deprecation-2026-05-31-dismissed`) - [x] PostHog receives one `fly_deprecation_banner_exposed` per mount with `primaryCount` + `branchCount` and `$groups.organization` populated - [x] PostHog receives one `fly_deprecation_banner_dismissed` on close with the same property shape ## Linear - fixes GROWTH-817 - fixes GROWTH-819 |
||
|
|
a4f964e452 |
fix: in-arrears transition in upcoming invoice (#45765)
## Show notice when plan fee is prepaid for the upcoming invoice When a subscription's plan fee has already been billed for the current period (e.g. transitioning to in-arrears billing), the upcoming invoice no longer contains a plan line item. Previously this rendered as an empty plan row with a `-`, which was confusing. <img width="2178" height="538" alt="image" src="https://github.com/user-attachments/assets/1fa289d9-60ae-48b1-b779-34770bc2c242" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Billing breakdown now detects when the plan fee was already paid upfront, hides the redundant plan line, and notes only usage will be invoiced; shows the organization plan name when available. * Backup restoration: added an optional recovery time target for physical backups. * Expanded supported AWS instance types for deployments. * **UI** * Compute and Replica Compute docs links now use inline linking for a smoother in-app experience. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45765) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
10ce3b6664 | docs: Fix missing export in Expo React Native docs (#45800) |