* Add `@supabase/ssr` to catalog
* Use `catalog:` version of `@supabase/ssr` across repo
* Add workflow to update `@supabase/ssr`
* Switch runners for package and docs updates to `ubuntu-latest` (free,
lighter)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Centralized `@supabase/ssr` versioning across the workspace via the
package catalog.
* Updated CI workflow runners to a more consistent execution
environment.
* Added an automated workflow to streamline updating the `@supabase/ssr`
package and refreshing dependency lockfiles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
When users have enabled a SMS hook, they can't update the TOPT test
values anymore.
This is because `formik` sent disabled inputs values in the form payload
while `react-hook-form` correctly does not.
## Solution
Make the inputs read only instead of disabled
## How to test
- Enable SMS auth
- Add a SMS hook
- Update the SMS auth settings
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Improvements**
* Authentication provider form fields now use read-only mode instead of
being disabled, preserving focus and interaction while preventing edits
across text, secret, multiline, numeric, select, boolean, and datetime
inputs.
* A new optional read-only prop was added to form fields for consistent
behavior.
* **Fixes**
* Initial form values recalculation was corrected so they update
reliably when the selected provider changes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## Additional context
Onboarding
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated team credits and contributors information.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Updates verbiage throughout docs to use postgres over postgresql.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated terminology throughout documentation, guides, and resources
for consistent product naming across all user-facing materials,
including page titles, descriptions, and reference documentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
There was no way to trigger resource warning banners in the dev toolbar,
making it hard to test different warning states (warn/critical,
read-only mode) without manually mocking API responses or waiting for
real exhaustion events.
## Fix
- Adds an ExtraTab extension point to DevToolbar so Studio can inject
custom tabs without coupling the package to app-specific hooks
- Adds a ResourceWarningsTab in Studio with per-type off/warn/crit
toggles for disk IO, CPU, memory, disk space, and auth rate limit
warnings, plus a read-only mode toggle
- Auth rate limit only exposes warn (no crit) since critical is not a
valid API return value
- The tab component is dynamically imported so it stays out of
production bundles, controlled by the same NEXT_PUBLIC_ENVIRONMENT guard
used by the toolbar
## How to test
1. Run Studio locally or open a Vercel preview deployment
2. Open the browser console and run window.devTelemetry() to enable the
toolbar
3. Click the toolbar trigger to open the panel
4. Switch to the "Warnings" tab
5. Toggle any warning type to "Warn" or "Crit" and confirm the banner
appears at the top of the page
6. Toggle read-only mode on and confirm the read-only banner appears
7. Click "Reset to real data" and confirm banners return to their actual
state
8. Confirm the Auth Rate Limit row only has Off and Warn buttons (no
Crit)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* New "Warnings" tab in the developer toolbar (enabled in local and
staging) for managing resource warning banners.
* Per-resource severity overrides (Off / Warning / Critical) with
immediate preview in the toolbar.
* Local "read-only" toggle to simulate read-only mode.
* "Reset to real data" clears overrides, disables the local toggle, and
refreshes server state.
* Tab loads lazily and shows a disabled/loading state if org/project
context is unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Closes#44873
When creating a new cron job, `getDatabaseCronJob` is called to check if
the name already exists. If that call throws (network error, DB
connection issue), the catch block shows an error toast but doesn't
return. Execution falls through to `upsertCronJob`, creating the job
without validating name uniqueness.
The fix adds `return` in the catch block so the mutation doesn't fire
after a failed validation check.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Fixed cron job validation error handling to properly halt processing
when name validation fails and display appropriate error feedback.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
Closes#44872
The "Empty organization" admonition in the subscription upgrade dialog
checks `.length === 5` instead of `.length === 0`. The warning text says
"This organization has no active projects" but only shows for orgs with
exactly 5 active projects.
Introduced in #44494 (b9e83b25).
The adjacent `.length === 1` check for the single-project note is
correct, confirming this is a count comparison that should be `0`.
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Added a comprehensive "Taxes" FAQ explaining when sales tax/VAT/GST is
charged (jurisdiction and billing-address dependent), invoice
presentation, prepaid credit treatment, and marketplace purchases
* Clarified rollout timeline and advance email notices (May 1–June 30,
2026)
* Explained Tax ID requirements, where to provide them, handling
missing/incorrect addresses, and tax-exemption submission process
* Added a corresponding pricing FAQ entry and dedicated support path for
tax questions
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Removes the "New" banner from the email notification templates section
as the features has been GA-ed for ~6 months now.
<img width="1844" height="758" alt="CleanShot 2026-04-15 at 10 30 33@2x"
src="https://github.com/user-attachments/assets/4415f651-7274-4565-8e2d-4a66f8bbd100"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Removed the security notifications acknowledgement feature from the
email templates interface, including the dismissible notification tip
and associated state management.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Adding my name to the file
## What is the current behavior?
Currently, my name is not there in the file
## What is the new behavior?
This adds my name to the file
## Additional context
NA
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated team roster information with a new team member addition.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Blog post title update
## What is the current behavior?
Blog post titled "Stripe Sync Engine: from supabase to stripe" at
/blog/stripe-sync-engine-donation.
## What is the new behavior?
- Title updated to "We're transferring the Stripe Sync Engine to Stripe"
- Description updated to match new framing
- Slug changed to stripe-sync-engine-transfer
(/blog/stripe-sync-engine-transfer)
- Image directory renamed to match new slug
## Additional context
N/A
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Published a blog post announcing the transfer of the Stripe Sync
Engine repository to its upstream maintainer, with full metadata and
narrative covering timeline, continuity guarantees, licensing (Apache
2.0), redirects, and continued one‑click dashboard support. It lists new
capabilities (coupons sync, branching support, immediate sync on
install, one‑click upgrades, SSL enforcement, restricted admin controls,
improved install UX, clearer errors, and dashboard visibility of
function source).
* Updated the public blog RSS feed to include the new post and recent
entries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Ana <ana1337x@users.noreply.github.com>
## Summary
Reorder AddPaymentMethodForm and PaymentMethodSelection to use a dry run
validation → Stripe payment setup → real update flow:
- Validate address and tax ID via `dry_run: true` before touching Stripe
- Proceed with Stripe payment method creation / 3DS only if validation
passes
- Persist the customer profile update with dry run disabled after Stripe
succeeds
- Add `dry_run` support
to `useOrganizationCustomerProfileUpdateMutation`
- Add `getFormValues()` to `PaymentMethodElementRef` to read address and
tax ID form state
- Delete the now-unused `organization-tax-id-update-mutation.ts`
## Test plan
### Adding a Payment Method
From the billing dashboard `/org/_/billing`:
- [ ] Add a payment method with a valid tax ID: should dry-run
validate, then create the payment method via Stripe, then persist the
billing profile
- [ ] Add a payment method with an invalid tax ID: should show a
validation error from the dry run and not proceed to Stripe payment
setup
- [ ] Add a payment method with the "primary billing address" checkbox
unchecked: should skip the customer profile update entirely and only
create the payment method
- [ ] Add a payment method where Stripe 3DS fails: billing profile
should not be persisted (only the dry run ran)
### Credit Top Up
- [ ] Top up credits with a new payment method and valid tax ID: should
dry-run validate, then create the payment method, then process the
top-up
- [ ] Top up credits with a new payment method and invalid tax ID:
should show a validation error from the dry run and not proceed to
Stripe payment method creation
### Plan Upgrade
- [ ] Upgrade plan with a new payment method and valid tax ID: should
dry-run validate before creating the payment method
- [ ] Upgrade plan with a new payment method and invalid tax ID: should
show a validation error and not proceed to Stripe
- [ ] Upgrade plan with an existing payment method: should proceed
without dry-run validation
## Problem
When creating a project, if users select a region then change the
compute size, the region is reset.
## Solution
Only applies the recommended region if users have not selected one
explicitly.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Improved form state handling by extracting and using granular form
operations for more reliable, consistent updates and reduced unnecessary
re-renders.
* **Bug Fixes**
* Auto-fill and region recommendation behavior is gentler: fields are
only auto-populated when untouched, region defaults avoid overwriting
edits, region errors reset defaults safely, and empty recommendations
are normalized to an empty string.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Ali Waseem <waseema393@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
This connects the Advisor from the splinter repo. Below are the list of
changes:
- Register advisor which should appear in both the legacy Advisors and
Advisors sidebar.
- Adds a "Dismiss" button to the admonition inside the bucket view.
- Makes the check for select policy on public buckets tiny bit
stricter/truer.
This is awaiting the [PR](https://github.com/supabase/splinter/pull/152)
in splinter going in!
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added a security lint that flags public storage buckets allowing
listing, with a direct "View bucket" link.
* Users can dismiss public-bucket warnings per project+bucket for 14
days via a Dismiss button.
* **Improvements**
* Tightened policy detection to better target bucket-scoped select
policies and avoid unrelated matches.
* **Telemetry**
* Added events for policy removal and dismiss-button clicks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Update TypeScript example to use createAuth0Client factory function and
ID tokens as the primary approach. Add warning about Auth0 silently
stripping non-namespaced custom claims from access tokens.
Ref: supabase/supabase-js#1770
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated Auth0 integration to a newer client initialization pattern.
* Switched examples to use the ID token instead of access tokens for
Supabase and added explicit failure behavior when the ID token is
missing.
* Updated Auth0 Action guidance to set the claim on the ID token.
* Added a caution that Supabase requires the literal "role" claim and
that non-namespaced custom claims are stripped from access tokens.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
- Call the new `POST /platform/organizations/preview-creation` endpoint
when creating an organization on a paid plan to show a tax breakdown
before submission
- Preview is triggered reactively when the user completes the billing
address in the Stripe AddressElement (debounced, same pattern as
subscription upgrades)
- Displays plan price, tax line (with percentage), and total due today -
hides the plan price row when there's no tax adjustment
## Test plan
- [ ] Create a new org on the Free plan - no preview should appear
- [ ] Create a new org on Pro/Team - fill in billing address with all
fields including name
- [ ] Verify tax preview appears after address is complete (1s
debounce)
- [ ] Verify tax line shows for taxable jurisdictions (NY Zip Code
10001), hidden for non-taxable
- [ ] Verify plan price row is hidden when total equals plan price (no
tax)
- [ ] Change address country - verify preview updates
- [ ] Add a tax ID - verify preview updates
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Pricing preview during organization signup that shows plan price
differences, tax details (rate/amount or estimation failure), and “Total
due today.”
* Preview updates reactively based on selected plan and spend cap (PRO
without spend cap treated as PAYG) and appears only for paid plans after
preview initialization.
* Debounced billing address and tax ID input collection for accurate
previews; panel opacity reduced while fetching.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Adding myself to humans of supabase
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES/NO
## What kind of change does this PR introduce?
Bug fix, feature, docs update, ...
## What is the current behavior?
Please link any relevant issues here.
## What is the new behavior?
Feel free to include screenshots if it includes visual changes.
## Additional context
Add any other context or screenshots.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated contributor information.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
- Removed a webinar from the on demand page
- Made some changes to the Startups solution page at the request of the
startups team
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Adjusted event availability settings
* Updated page messaging and call-to-action text on the startups
solution page
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Some small styling brush ups and experimental for internal telemetry
tools.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Developer toolbar redesigned with compact event/flag lists, “Copy
JSON” per event, and a fixed draggable trigger that snaps and remembers
its position. Toolbar is now available in staging and local
environments.
* **Bug Fixes**
* ConfigCat readiness wait ensures flags load correctly.
* Feature flag loading made resilient so one provider’s failure won’t
block the other.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Sean Oliver <882952+seanoliver@users.noreply.github.com>
Fixes the intermittent TS2345 build failure on Vercel where `nextConfig`
(typed via next@16) is not assignable to `withBundleAnalyzer`'s
parameter (typed via next@15).
**Root cause**
The monorepo has two Next.js versions — studio uses next@16 (via
catalog) while www and docs use next@15. On Vercel, pnpm sometimes
resolves `@next/bundle-analyzer`'s `next` peer types to v15 instead of
v16. The `NextConfig` type changed between versions: next@16 widens the
`headers` return type to `Header[] | Promise<Header[]>`, but next@15
expects `Promise<Header[]>` only. When the config object is annotated as
`NextConfig` (from next@16), its `headers` property gets the wider type
— which is not assignable to the narrower next@15 type expected by the
wrapper function.
**Fix**
Switch from `: NextConfig` type annotation to `satisfies NextConfig`.
With `satisfies`, TypeScript preserves the narrow inferred types from
the object literal (e.g. `async headers()` infers as `() =>
Promise<Header[]>`) while still validating the shape. These narrower
types are assignable to both next@15 and next@16 `NextConfig`, so the
build succeeds regardless of which version the wrapper functions resolve
to.
Also adds `as const` to `basePath: false` in the rewrites config, since
without the type annotation TypeScript would widen `false` to `boolean`,
which doesn't satisfy the `Rewrite` type's literal `false` requirement.
**Changed:**
- `const nextConfig: NextConfig = { ... }` → `const nextConfig = { ... }
satisfies NextConfig`
- `basePath: false` → `basePath: false as const` in rewrites
## To test
- Typecheck passes locally: `pnpm typecheck --filter=studio`
- Verify the next Vercel deploy doesn't hit the TS2345 error
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Improved TypeScript type safety in build configuration with better
type narrowing and inference.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
## TL;DR
fixes an inconsistent UI state where the image transformations toggle
could appear enabled + blur
even when the feature is unavailable for that account
## ex:
| Before | After |
| --- | --- |
| enabled and blurred | disabled and blurred |
| <img width="1295" height="389" alt="Before: image transformations
toggle appears enabled while blurred"
src="https://github.com/user-attachments/assets/2f9617b3-9f45-4cdd-8ba7-a360e1ba9754"
/> | <img width="1316" height="386" alt="After: image transformations
toggle appears disabled and blurred"
src="https://github.com/user-attachments/assets/f6be26fd-1390-49c9-b30c-880344eaeca8"
/> | |
## ref:
- closes https://github.com/supabase/supabase/issues/44844
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Fixed the image transformation toggle so it visually reflects both the
user's entitlement and the saved setting, ensuring the control
accurately shows when the feature is available and enabled.
* Preserved the existing disabled behavior for users without access or
update rights so functionality remains unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
We currently have 2 libraries for schema validation: `yup` that was used
with `formik` and `zod` which is now the preferred one.
## Solution
- Migrate to `zod`
- Fix validation isn't applied on email template form
- Fix `react-hook-form` form state usage
No visual changes.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Switched form validation to a unified Zod-based approach across
authentication UIs.
* **Improvements**
* Template editor and email templates now validate via provided Zod
schemas.
* SMTP and captcha settings receive conditional validation, improved
numeric handling, and clearer required-field behavior.
* Validation import/style consistency tidied.
* **Bug Fixes**
* Consistent dirty-state detection so Save/Cancel visibility and
enabled/disabled behavior are reliable across auth forms.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Context
Have Branching 2.0 as the default behaviour + remove it from feature
preview
Behaviour should match staging / prod if branching 2.0 feature preview
is toggled on
## To test
- [ ] Test branching flow in general for any oddities
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Removed the Branching 2.0 preview and cleared its persisted preview
setting; branching UI and branch editing are now available without
opt‑in.
* Simplified branch management flows and empty states by removing
preview-dependent conditions and tooltips.
* Made GitHub branch sync optional in create/edit forms and simplified
validation and submit behavior.
* "Create merge request" and related branch actions now render
consistently across the UI.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
A simple way to allow for opening doc search results in a new tab
<img width="530" height="542" alt="image"
src="https://github.com/user-attachments/assets/d2a3b420-ec61-4b94-a94b-b3f2bc160f7b"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Improvements**
* Documentation search now respects Ctrl/Cmd-click to open links in a
new tab.
* Documentation, reference, and troubleshooting pages open in-app or in
a new tab depending on modifier key; same-tab navigation closes the
search menu, new-tab does not.
* Integration and external discussion links follow the same modifier-key
behavior; the search menu only closes for same-tab navigation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Switch studio's package.json to `"type": "module"` so the package runs
as native ESM. This aligns the runtime module system with what we
actually write (`import`/`export`), improves tree-shaking, and reduces
friction with ESM-only dependencies.
**Changed:**
- `next.config.js` → `next.config.ts` – ESM imports/exports, proper TS
types, fixed type narrowing on redirect `has` and `basePath` fields
- `csp.js` → `csp.ts` – `module.exports.getCSP` → named `export
function`
- `tailwind.config.js` → `tailwind.config.ts` – ESM imports
- `postcss.config.js` – `module.exports` → `export default` (stays `.js`
since PostCSS doesn't support TS configs)
**Removed:**
- Unused `path` import in next config
- Deprecated Sentry `hideSourceMaps` option (default behavior in Sentry
v10)
**Added:**
- Type declaration for `config/tailwind.config` CJS package
## To test
- A general smoke test of studio should suffice
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Modernized the Studio package to ES module style and improved
TypeScript typings and config declarations to reduce build/runtime
issues.
* Updated styling and post-processing configuration format for more
consistent tooling behavior.
* **Chores**
* Updated code ownership entries to reflect migrated/renamed
configuration files.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
This pull request introduces improvements to the project's build and
cache management processes. The main changes focus on enhancing the
cleaning of build artifacts and optimizing Turbo's caching behavior.
**Build and cache improvements:**
* Updated the `clean` script in `package.json` to also remove the
`.turbo/cache` directory, ensuring a more thorough cleanup of build
artifacts.
* Added a `cacheMaxAge` setting of 14 days to `turbo.jsonc`, which
controls how long Turbo's cache is retained, helping to balance cache
efficiency and disk usage.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Optimized build system caching configuration with extended cache
validity period (14 days) to improve build performance through longer
retention of build artifacts and reduced unnecessary recompilation.
* Enhanced cleanup procedures for build artifacts, cached files, and
temporary data to maintain a consistent and clean build environment.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Remove `@headlessui/react` as a direct dependency from both
`apps/studio` and `packages/ui`. It's incompatible with React 19 (at the
pinned v1 version) and overlaps with our existing Radix/shadcn
primitives.
The only usage was the `<Transition>` component in 3 files + a dead
`Overlay` component in `packages/ui`.
**Removed:**
- `@headlessui/react` from `apps/studio/package.json` and
`packages/ui/package.json`
- Dead `packages/ui/src/lib/Overlay/` directory (not exported or
imported anywhere)
**Changed:**
- `ChooseFunctionForm.tsx` — replaced `Transition` with a shadcn
`Accordion` for the "View definition" toggle
- `FileExplorerColumn.tsx` — replaced `Transition` with `framer-motion`
`AnimatePresence` for drag-over overlay
- `PreviewPane.tsx` — removed `Transition` wrapper entirely (wasn't
visually animating on prod), replaced with simple conditional render
Note: `@headlessui/react` will remain in `pnpm-lock.yaml` as a
transitive dependency of `@graphiql/react` and
`@graphiql/plugin-doc-explorer` — that's expected and not something we
control.
## To test
- **Triggers page** (`/dashboard/project/_/database/triggers`): Create
or edit a trigger, click "Choose a function" to open the side panel.
Click "View definition" on a function row — the SQL definition should
expand/collapse with a smooth height animation. Clicking the row itself
should still select the function.
- **Storage explorer**
(`/dashboard/project/_/storage/buckets/<bucket>`): Navigate into a
folder, drag a file over the column — the drag overlay should fade
in/out smoothly.
- **Storage file preview**
(`/dashboard/project/_/storage/buckets/<bucket>`): Click on a file — the
preview pane should appear on the right (no animation, same as current
prod behaviour).
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Replaced several transition wrappers with new animation/mounting
behavior for overlays, preview panes, and drag-over UI to improve
consistency and responsiveness.
* Swapped the function-definition toggle for an Accordion and updated
click handling to prevent accidental row selection.
* Removed the legacy overlay component, its context, and associated
overlay styling.
* **Chores**
* Removed HeadlessUI dependency from project packages.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Previously, when a user performed a client-side navigation to the
passkeys page, the settings would not be shown despite passkeys being
enabled. This was a result of the stale form data being passed as the
initial values.
This PR removes the `useEffect` in favour of the `values` prop.
* Use latest 2.x version of `@supabase/supabase-js` in all examples
* Use `latest` version of `@supabase/ssr` in all examples
* Remove lock files from examples
* Add examples lock files in .gitignore
The rationale is:
- Lock files are not actively maintained/updated (or the versions in the
package.json files for that matter)
- They pin an arbitrary version (from the end-user perspective)
- Removes the need to manually update the versions and reinstall
- Consistency
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Release Notes
* **Chores**
* Broadened Supabase SDK dependency version constraints across example
projects for greater flexibility with compatible updates
* Updated some SSR package dependencies to track latest releases
* Added gitignore rules for dependency lock files in example directories
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Came up in a conversation with @pamelachia about what growth eng should
actually look for when reviewing dev toolbar PRs. We realized the review
criteria were all in my head and not documented anywhere, so this adds a
Claude skill that surfaces a checklist when PRs touch the relevant
files.
### What it covers
- Environment guards (tree-shaking ternaries, `IS_LOCAL_DEV` runtime
checks) — especially relevant since we're expanding visibility to
staging/preview
- Flag override cookies (`x-ph-flag-overrides`, `x-cc-flag-overrides`)
and the read/write sync across dev-tools, posthog-client, and
feature-flags
- Telemetry event subscription (`subscribeToEvents` /
`emitToDevListeners`) side-effect safety
- SSE server telemetry stream and cross-repo implications
- App-level mounting across studio, www, docs
- Also calls out a CODEOWNERS gap: `posthog-client.ts` and
`feature-flags.tsx` aren't assigned to growth-eng, so PRs touching only
those files won't auto-request review
### Testing
Verified the skill is discovered by Claude Code from the repo root.
Content reviewed against the actual code in `packages/dev-tools/` and
`packages/common/`.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Added internal review guidelines for development-toolbar changes,
covering build-time hiding outside local dev, local feature-flag
override handling, client telemetry listener expectations,
server-sent-event stream safety and reconnection, and app-level
mounting/props validation to ensure correct runtime behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Only wrap with `withSentryConfig` when running on Vercel (`VERCEL ===
'1'`), matching the existing pattern used for HSTS headers on line 510.
The Sentry webpack plugin's `runAfterProductionCompile` step adds ~24s
to local production builds for source map upload that isn't needed
outside of deployments.
**Changed:**
- Gate `withSentryConfig` on `process.env.VERCEL === '1'` in addition to
`NEXT_PUBLIC_IS_PLATFORM === 'true'`
## To test
- Run `pnpm build:studio` locally with `NEXT_PUBLIC_IS_PLATFORM=true` –
confirm no `runAfterProductionCompile` step
- Verify Vercel preview deploys still upload source maps to Sentry
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Refined configuration so error-tracking is enabled only in the
designated deployment environment (adds an additional environment
check).
* Adjusted build-tooling to be conditionally enabled on the platform
flag, and ensured non-tracked builds export the platform-aware
configuration consistently.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
## Summary
- Reset the table rows query after the user confirms loading data on a
high-cost table, so React Query re-executes the fetch without the
preflight check
- Close the confirmation dialog after the user clicks "I understand,
proceed"
**Root cause:** `preflightCheck` is intentionally excluded from the
React Query query key (to avoid duplicate cache entries). When the user
clicked "Load data", the preflight flag flipped to `false` but the query
key stayed the same — so React Query returned the cached error instead
of refetching.
## Test plan
- [x] Navigate to a table with high estimated query cost (triggers "Data
not loaded to protect database performance")
- [x] Click "Load data" → "I understand, proceed"
- [x] Verify the dialog closes and table data loads
- [x] Verify the warning does not reappear for the same table in the
same session
To test this you can run this locally with COST_THRESHOLD set to a low
value (< 10)
Fixes FE-2979
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Confirming the high-cost warning now closes the dialog and proceeds
with loading as expected.
* Improved query cache key composition so queries reflect the full set
of relevant parameters for correct caching.
* Loading from the grid error now properly clears related cached results
and proceeds when the user confirms.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
#44798 removed these entries. An explicit `pnpm add turbo
--workspace-root` re-added these entries. Otherwise, for a clean build,
I'm seeing this:
```
Turborepo did not find the correct binary for your platform.
We will attempt to install it now.
Installation has failed.
***
Turborepo failed to start.
Turborepo detected that you are running:
darwin arm64
***
We were not able to find the binary at:
@turbo/darwin-arm64/bin/turbo
or: turbo-darwin-arm64/bin/turbo
```
## Summary
- The `availableTaxIds` memo and
preselect `useEffect` in `NewPaymentMethodElement` depended on the
full `stripeAddress` object. Since the
Stripe `AddressElement` fires `onChange` on every keystroke (org name,
street, city, etc.), this created a new object reference each time,
causing the memo to recompute and the effect to re-fire, which
cleared `tax_id_value` to `''`.
- Narrowed both dependencies to `addressCountry`, so the tax ID is only
reset when the billing country actually changes.
- Used a `prevCountryRef` to distinguish initial mount from country
changes: on mount we preserve any existing `currentTaxId`, on country
change we always reset to the new country's default.
## Test plan
- [ ] New org flow: select paid plan, check "purchasing as a business",
fill in tax ID value, type in org name / address fields - tax ID should
persist
- [ ] New org flow: change country - tax ID selector should update to
the new country's default
- [ ] Plan upgrade flow: open upgrade dialog with existing tax ID, type
in address fields - tax ID should persist
- [ ] Plan upgrade flow: change country - tax ID should reset to new
country's default
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Tax ID handling is now country-aware and updates correctly when the
billing country changes.
* Address name and country persist across form remounts, preventing
accidental resets when toggling purchase mode.
* Tax ID selection/reset logic refined to avoid overwriting existing tax
IDs on initial load and to choose appropriate defaults after country
changes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Adding a toggle feature to the Features page to enable users to see self
hosted features only.
## What is the current behavior?
N/A
## What is the new behavior?
<img width="1690" height="1168" alt="Screenshot 2026-01-21 at 7 16
12 PM"
src="https://github.com/user-attachments/assets/49938c82-e023-4126-b627-77a47f87bfc5"
/>
## Additional context
N/A
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added self-hosted feature filtering. Users can now toggle a checkbox
to show only features available on self-hosted deployments.
* Filter selections are preserved when sharing or bookmarking links.
* Clear all filters action now includes resetting the self-hosted
filter.
<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Ana Mogul <anamogulsupa@Anas-MacBook-Pro.local>
Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
Increases the minimum credit top-up to $300.
### Testing
- Head to `/org/_/billing`
- Assert that you're not able to do a top-up for less than $300
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Updates**
* Increased the minimum credit top-up amount from 100 USD to 300 USD.
Form defaults and placeholder text updated to reflect the new minimum.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Feature
## What is the current behavior?
After subscribing to the newsletter in the footer, users only see
"Thanks for subscribing!" with no indication of what to expect next.
## What is the new behavior?
After a successful newsletter signup, a secondary message is shown:
"You'll hear from us when we publish our next newsletter issue." This
sets expectations that they will receive emails when new issues are
published.
## Additional context
Small UX improvement to the footer newsletter form success state.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Release Notes
* **New Features**
* Enhanced newsletter subscription confirmation message with additional
details about when the next issue will be published.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Bug fix (image)
## What is the current behavior?
The blog thumbnail for the Agent Skills post is 1200x630 with the "Agent
Skills" text flush at the bottom edge. When rendered in the blog grid
(`aspect-[1.91/1]`) and featured view (`aspect-[3/2]`) with
`object-cover`, the text gets cropped.
<img width="3256" height="1282" alt="image (1)"
src="https://github.com/user-attachments/assets/86cbbe57-3e34-4164-9db4-9ed6c74fb897"
/>
## What is the new behavior?
The thumbnail is resized to 2400x1600 with the content vertically
centered, matching the dimensions used by other blog post thumbnails
(e.g. 100K GitHub stars). The text is no longer cut off in any view.
<img width="1510" height="731" alt="image"
src="https://github.com/user-attachments/assets/5256bc27-9830-4bc3-8d24-fbad1beea8ff"
/>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
## Summary by CodeRabbit
* **New Features**
* Added Passkeys configuration page to manage WebAuthn relying-party
settings and enable/disable passkey auth.
* Added a Beta "Passkeys" item to the Auth settings menu.
* Enabled saving passkey-related authentication parameters.
* **Tests**
* Added test coverage to ensure the Passkeys menu appears or is omitted
based on feature flags.
* **Chores**
* Removed an unused import to tidy the code.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: fadymak <dev@fadymak.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs - [CLI Config
Reference](https://supabase.com/docs/guides/local-development/cli/config#auth.mfa.totp.enroll_enabled)
## What is the current behavior?
Default values in the cli config reference for mfa totp are set as
`true` which is not correct.
## What is the new behavior?
Changed to use `false` and match the default `config.toml`.
<img width="868" height="723" alt="Screenshot 2026-04-01 at 15 53 54"
src="https://github.com/user-attachments/assets/5e3e33a0-5edb-44d6-a013-4327aef537b4"
/>
## Additional context
Fixes: https://github.com/supabase/cli/issues/3737
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated CLI configuration defaults for TOTP multi-factor
authentication. TOTP enrollment and verification are now disabled by
default. Users relying on these features may need to manually enable
them in their configuration if required.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Summary
- The Free Plan section in `database-size.mdx` was ambiguous — it said
"when you exceed the 500 MB limit" without specifying which limit
- Clarified that the 500 MB threshold is the **database size** limit
(actual Postgres data), while Free Plan projects include 1 GB of total
disk space
- This explains why read-only mode triggers before total disk usage is
reached
Closes#43487
## Test plan
- [ ] Documentation renders correctly at
`/docs/guides/platform/database-size`
- [ ] Wording is unambiguous about database size vs disk size
distinction
🤖 Generated with [Claude Code](https://claude.com/claude-code)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Clarified Free Plan read-only mode: the 500 MB threshold applies to
database size (Postgres data), not overall disk usage.
* Made Pro Plan instructions explicit: upgrading increases the database
size quota rather than a generic disk limit.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs update
## What is the new behavior?
The error message returned by the edge runtime has changed in
production. Updated the docs to reference the newer message
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated troubleshooting guide for 401 error responses with improved
error message clarity and example scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->