mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 02:45:07 +03:00
d95ff5bda979f910698edf0741a9ccbe92fbbbfb
38975
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
d95ff5bda9 |
docs(design-system): rewrite sidebar page for monorepo tokens (#51165)
## Problem The design-system Sidebar page was mostly an upstream shadcn paste: first-person voice, a broken `/blocks` link, missing structure images, CLI install steps that do not match this monorepo, and a long changelog / data-fetching tutorial that do not apply here. Separately, it still taught classic shadcn **HSL channel** variables plus `hsl(var(--sidebar-*))`. In this monorepo those tokens are **full colours**. Mixing the two patterns produces invalid CSS. Related call-site cleanup: https://github.com/supabase/supabase/pull/51161 ## Solution - Rewrite the Sidebar docs as a shorter monorepo guide: import from `'ui'`, structure, theming, provider / sidebar props, menu building blocks, controlled mode, state styling. - Move Studio’s `--sidebar-*` aliases into shared `packages/ui` compat CSS so every app on the shared theme gets working `bg-sidebar` utilities. - Drop the duplicate definitions from Studio `globals.css`. Left alone on purpose: brand / destructive channel tokens and docs that correctly use `hsl(var(--brand-…))`. ## Review instructions Design-system preview: [design-system](https://design-system-git-dnywh-docssidebar-full-colour-tokens-supabase.vercel.app/) 1. [Live Sidebar docs](https://supabase.com/design-system/docs/components/sidebar) · [Preview Sidebar docs](https://design-system-git-dnywh-docssidebar-full-colour-tokens-supabase.vercel.app/design-system/docs/components/sidebar). Confirm the page is no longer the upstream essay: no broken images, no `/blocks` link, imports from `'ui'`, theming shows full-colour aliases. 2. Smoke Studio: left nav should look unchanged (same aliases, now from compat.css). 3. Optional: in DevTools, confirm `--sidebar-background` resolves to a full `oklch(...)` colour. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) |
||
|
|
272bb26635 |
fix(studio): remove duplicate status page link in incident banner (#51305)
## Problem During active incidents, the Studio status banner read: > We are investigating a technical issue · Follow the status page for updates Status page The trailing "Status page" goes alongside plain-text copy that already mentioned "status page". ## Solution Match the emergency-override and legacy banners: make "status page" the inline link inside the sentence, and drop the trailing link. Added a regression test covering the link text and href. | Figure | | --- | | <img width="1280" height="288" alt="6696" src="https://github.com/user-attachments/assets/e267f0d0-5484-45a5-969f-03e184b903dd" /> | | _Before_ | | <img width="1280" height="288" alt="47231" src="https://github.com/user-attachments/assets/2beee89e-3674-43f5-9d13-6dc04d153549" /> | | _After_ | ## Review instructions As of writing this: we have an active indident so you could just log in to the [staging preview](https://studio-staging-git-dnywh-dd493a51-supabase.vercel.app/). Otherwise: 1. Open `apps/studio/components/layouts/AppLayout/StatusBanner.tsx` and confirm the incident description is `Follow the [status page] for updates` with no trailing "Status page" link. 2. Optionally run `pnpm --filter studio exec vitest run components/layouts/AppLayout/StatusBanner.test.tsx`. 3. If you have a local Studio with an active incident (or `ongoingIncident` override), confirm the banner shows a single linked "status page" and no duplicate trailing link. |
||
|
|
b5c865521f |
feat(studio): notify users about the Terms of Service update (#51302)
## Problem Dashboard users need a notice about the Terms of Service update alongside #51106 and #51107. ## Solution Reuse the organisation landing-page notice pattern from #50397. A compact “We've updated our Terms of Service.” notice opens the explanation and agreement link through **Learn more**. Closing the notice or choosing **Got it** remembers dismissal in the browser with a new version-specific key. ```text Organisation landing page Notice → Learn more → Explanation and Terms of Service link Close / Got it → Remember dismissal ``` | After | | --- | | <img width="628" height="444" alt="CleanShot 2026-10-06 at 14 47 46@2x" src="https://github.com/user-attachments/assets/72922712-321f-4972-b20c-1a075e0745d0" /> | | _Banner_ | | <img width="1078" height="718" alt="CleanShot 2026-10-06 at 16 58 18@2x" src="https://github.com/user-attachments/assets/2109c2ab-e9b7-4855-8acb-42d5232cd002" /> | | _Dialog_ | ## Review instructions 1. Open `/organizations` or an organisation's `/org/<slug>` landing page in the hosted Studio preview. Expect the compact notice. 2. Click **Learn more**. Expect the explanation and a link to the Terms of Service. Escape closes the dialog without dismissing the notice. 3. Choose **Got it**, then reload. The notice stays dismissed. Repeat in a fresh browser profile using **Close banner**. 4. Open a project or an organisation settings page. The notice should not appear. |
||
|
|
fb382b3018 |
Add Terms of Service v4 (effective October 5, 2026) (#51107)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_ ## Problem Commercial & Product Counsel supplied a new version of the Supabase Terms of Service to be published as Version 4, effective October 5, 2026 (the same date the Enterprise Terms v4 update takes effect, once the code freeze lifts). ## Solution Adds `apps/www/data/legal/terms/v4.mdx` with the new agreement text (transcribed from the supplied source document) and registers it as the newest version in `apps/www/pages/terms.tsx`'s versions array, dated October 5, 2026. Versions 1-3 are untouched. The new text also defines "Supplemental Terms" and links it, at the one point the source hyperlinks it, to `/legal/customer-resources/supplemental-terms`. ## Review instructions 1. Open the Vercel preview link for `/terms` below. 2. Confirm "Version 4" appears as the newest tab/version, dated October 5, 2026, with the updated agreement text. 3. Do not merge — this PR is held until the code freeze lifts on October 5, 2026 (see PRs #51100 and #51106 for the related Enterprise Terms / Supplemental Terms work landing the same day). ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC --- _Generated by [Claude Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
c006499d48 |
Add Enterprise Terms v4 (effective October 5, 2026) (#51106)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_ ## Problem The Enterprise SaaS Subscription Agreement at `/enterprise-terms` needed a new version reflecting legal's latest draft, which introduces a "Supplemental Terms" defined term, a standalone "Supabase" contracting-entity definition (to support marketplace purchases), a new Beta Releases warranty carve-out, and related marketplace billing/refund language. ## Solution Before: `/enterprise-terms` had three versions (v1–v3), with v3 dated August 1, 2026, and no concept of "Supplemental Terms" anywhere in the agreement. After: adds **Version 4, effective October 5, 2026** as the newest entry in the page's `versions` array (v1–v3 untouched): - `apps/www/data/legal/enterprise-terms/v4.mdx` — new versioned MDX, transcribed from legal's source document and following this directory's existing formatting conventions (bold section numbers/defined terms, `##`/`###` headings, no frontmatter or h1 — the h1 is rendered by `PageHeader`). - `apps/www/pages/enterprise-terms.tsx` — imports `v4.mdx` and adds it to the front of the `versions` array with `effectiveDate: 'October 5, 2026'`. How: the new v4 text is a faithful transcription of legal's draft onto the existing v3 structure, so the diff is easy to review against v3 — the substantive additions are the "Supabase" entity definition (1.9), the "Supplemental Terms" defined term (1.13) and its references in Section 2.1 (license scope) and Section 14.1 (order of precedence), a new Section 10.5 (Beta Releases), and marketplace-related payment/refund language in Section 5.1. The "Supplemental Terms" defined term is a live markdown link to the new `/legal/customer-resources/supplemental-terms` page (shipped separately in #51100) at its point of definition (Section 1.13), matching how the source document hyperlinks it. ## Review instructions 1. Open the `zone-www-dot-com` preview's `/enterprise-terms` page and confirm the version selector defaults to "Version 4 — October 5, 2026". 2. Confirm Section 1.13 "Supplemental Terms" renders as a live link to `/legal/customer-resources/supplemental-terms`. 3. Confirm Version 3 (and v1–v2) still render unchanged via the version selector. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] N/A — no docs topic edited (this is versioned legal content, not `apps/docs`) --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
363dbdf1ad |
Use Flick Games' real logo files (#51364)
## Problem #51285 (Flick Games case study) merged before the customer's actual logo files were in hand. It shipped with a derived black/white wordmark instead. ## Solution Swaps in the real brand assets Ian Masters sent directly (`FLICK_black_2048.png` / `FLICK_white_2048.png`) for `on-light`/`on-dark` at `apps/www/public/images/customers/logos/`. Tracked in [MARKET-2252](https://linear.app/supabase/issue/MARKET-2252/case-study-flick-games-sept-23). ## Review instructions 1. Open the preview link for `/customers/flick-games`. 2. Check the logo renders correctly in both light and dark mode. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
ab383421c5 |
fix(studio): show sign-in banner based on Dashboard component [FE-3443] (#51283)
## Summary * Makes sign-in banner visible on unauthenticated pages * Show only when one of the affected components is Dashboard * Works only when new status page (under feature flag) is being used * Regression fix: Auth pages without the status banner (sign-up, sign-in-mfa, sign-in-recovery-code, sign-in-sso, sign-in-partner, forgot-password, forgot-password-mfa, reset-password) no longer reserve dead space at the top for a banner they don't render ## Test plan - [X] TypeScript: `tsc --noEmit` passes clean, no type errors - [X] Unit tests: All new/existing tests pass in `apps/studio/lib/status-page/status-page.utils.test.ts` and `apps/studio/components/layouts/AppLayout/StatusBanner.utils.test.ts` (697 files / 7833 tests, no regressions) - [X] Manual verification: Sign-in page still renders the banner correctly when an incident affecting Dashboard is active; no layout regression **Related:** [FE-3443](https://linear.app/supabase/issue/FE-3443/only-show-sign-in-incident-banner-when-relevant) |
||
|
|
28f59449c3 |
[FE-4543] fix(studio): remove outdated resize downtime warning (#51344)
## Summary Removes the "Resizes may require more downtime than normal on this project." warning from the disk/compute review dialog. This warning was added for cross-architecture migrations during resize operations, which are no longer performed, and has caused unnecessary customer support inquiries. ## Closes FE-4543 https://linear.app/supabase/issue/FE-4543 |
||
|
|
32b16b7397 | Add Connor Davis to humans.txt (#51360) | ||
|
|
1a992761c1 |
chore(docs): Add Lovro Mažgon to humans.txt (#51354)
Add myself to humans.txt |
||
|
|
9a4ab14be2 |
chore: add John Jarvis to humans.txt (#51182)
## Problem John Jarvis is missing from `humans.txt`. ## Solution Add John Jarvis to `apps/docs/public/humans.txt`. ## Review instructions Confirm the name is spelled correctly in the team list. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added John Jarvis to the team list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9d1661dec1 |
chore: Reorganize the Files buckets code (#51350)
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
|
|
c0c51dc168 |
test(logs): stabilize pathname refresh assertion DEBUG-230 (#51351)
## Problem The Studio unit test added in #51112 failed on master because the `/after` element returned by `findByText` was detached by a rerender before `toBeInTheDocument` ran. The failure repeated across all three test attempts in [this job](https://github.com/supabase/supabase/actions/runs/37480673016/job/112327649118). ## Fix Retry the DOM lookup and assertion together with `waitFor`, so each attempt checks the current element synchronously. Keep the existing timeout and assertions covering pathname refresh before the URL updates. ## How to test - Run `pnpm --filter studio exec vitest run components/interfaces/UnifiedLogs/UnifiedLogs.test.tsx`. - Expected result: pathname options refresh after selecting POST and the test passes. - Prettier and `git diff --check` pass. Local Vitest was blocked before assertions by the available dependency tree using React 18 instead of React 19; ESLint was blocked by a missing `@eslint/compat` dependency. CI validation is pending. |
||
|
|
d2ffd76395 |
perf(logs): load pathname facet counts on demand DEBUG-230 (#51112)
## Problem Unified Logs included a pathname aggregation in every initial sidebar count query, even when the pathname filter was closed. This issue is tracked in [DEBUG-230](https://linear.app/supabase/issue/DEBUG-230/fetch-sidebar-counts-only-when-needed). ## Fix Remove pathname aggregation from the initial ClickHouse and BigQuery count queries while keeping the existing shared count scans. Fetch scoped pathname options through the existing facet query when the filter opens or its search changes. Order limited pathname results by count, validate response rows with Zod, and retain selected paths during loading and validation errors. Use live sidebar filters while their URL update is pending and URL filters after navigation. Cache results by project and filter scope, and wait for feature flags before requesting options. ## How to test - Open Unified Logs, then open Pathname and search. Confirm options load on demand. - Change the time range, another filter, or navigate through browser history. Confirm the options reflect the current scope. - Close and reopen Pathname without changing the scope. Confirm cached options return. - Run the pathname filter component tests and Studio typecheck. |
||
|
|
240e954390 | fix(www): fix partners links and 404 redirects (#51294) | ||
|
|
eb20a4674d |
getTableDefinitionSql to escape SQL identifiers (#51258)
## Context Similar to domain to https://github.com/supabase/supabase/pull/51256 - `getTableDefinitionSql` doesn't escape SQL identifiers, which generates invalid SQL on the dashboard's table editor for the "Copy table schema" CTA, or the table definition tab. Also fixes the "Copy table schema" CTA which was missing the `scoped` parameter when calling `getTableDefinition` Changes here addresses this issue, can test with a table named like `test"table` |
||
|
|
1da25a7e72 |
chore(hipaa): self-serve PITR (#51342)
There is no reason why HIPAA customers cannot self-serve PITR add-on. Instead of telling customers to reach out to support, let them self-serve it. - Docs also wrongfully stated the need for Small compute add-on. - Ability to self-serve PITR - Only 28-day PITR available - Price is now also correct and displays $0 (pending backend change) When enabled (marked as HIPAA compliant): <img width="1128" height="216" alt="Screenshot 2026-10-06 at 1 53 01 PM" src="https://github.com/user-attachments/assets/d83982e7-c71b-4236-ab29-67f85fc40f39" /> When not enabled (marked as HIPAA compliant): <img width="1132" height="255" alt="Screenshot 2026-10-06 at 1 53 55 PM" src="https://github.com/user-attachments/assets/f182813b-2163-4905-8cdf-9c69983ec1b9" /> <img width="772" height="542" alt="Screenshot 2026-10-06 at 1 56 08 PM" src="https://github.com/user-attachments/assets/2cd59439-74b9-49d6-90d1-47c8d1722c9f" /> |
||
|
|
23e7bbcdc6 |
Joshenlim/fe 3359 fix user permission UI for orgs with thousands of projects (#51329)
## Context Adds virtualization to the organization team members page - browser performance was facing issues for organizations with a large amount of members (e.g 1000+), primarily due to some computation within `MemberActions.tsx`, so virtualization addresses this by controlling the number of member rows being rendered in the DOM at any one time. <img width="1182" height="435" alt="image" src="https://github.com/user-attachments/assets/e3da7036-c1c8-4d73-a363-85ecbdb79179" /> ## Unrelated changes - Updated `TeamSettings` to use the `PageContainer` components for UI consistency - Updated user `ProfileImage` to render the first alphabet of the email, rather than a generic user icon <img width="275" height="126" alt="image" src="https://github.com/user-attachments/assets/17eae3b1-c527-4b8f-afcd-c5151bdaf869" /> - Updated row heights of member rows to be more smaller - Updated MFA column to use tooltips with a clearer CTA for members that don't have MFA enabled <img width="332" height="144" alt="image" src="https://github.com/user-attachments/assets/a479af31-7fec-454d-b64e-e6314fd6d55e" /> - Added a filter for MFA status <img width="375" height="177" alt="image" src="https://github.com/user-attachments/assets/fd87105e-524d-4ded-b471-769592be96c7" /> ## To test - Can override the content for the `members` network request with the following sample JSON, main thing is just to test that initial load + searching should not run into any significant browser performance issues. [members-response-1000.json](https://github.com/user-attachments/files/33100317/members-response-1000.json) - Can also test on production that this mock response does indeed cause browser performance issues as well |
||
|
|
6ecf98671a |
docs(platform): add Platform Webhooks guide and event catalog (#51098)
## Problem Platform Webhooks (org- and project-level event notifications over the Management API) has no public documentation. CTRL-1017 asks for a docs page plus a specification of the available event types, so partners can integrate without reading the OpenAPI spec or asking engineering directly. Closes CTRL-1017. ## Solution **New guide covering the Management API path, plus an event catalog.** Adds `apps/docs/content/guides/platform/webhooks.mdx`: concepts and scoping, creating an endpoint, Standard Webhooks signature verification and secret rotation, test events, and delivery/retry/ordering behavior. Adds `apps/docs/content/guides/platform/webhooks/events.mdx`: the events reference. - Full payload documentation for the 8 project-lifecycle event types, and a name-and-trigger table for the 12 branch, member, and billing types whose payload fields aren't documented. - Documents `*` for subscribing to every event. - Access framing states the criterion: available to organizations on an early access allowlist, with the `403` / `access_disabled` response for everyone else. - Nav entry under Platform > Project & Account Management, after Personal Access Tokens, gated by `fullPlatformEnabled`. **The page deliberately omits the dashboard UI.** See the first row of the table below. ## Needs review before merge | Item | Detail | | -------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **The Studio webhooks UI is not wired to the API, so this page documents the Management API only** | `PlatformWebhooksPage.tsx:29` imports `PLATFORM_WEBHOOKS_MOCK_DATA`; `PlatformWebhooks.store.ts` has no async or network code and hardcodes `createdBy: 'mock-user@supabase.io'`; nothing in `apps/studio` references `webhooks/endpoints` or `webhooks/deliveries`, even though `api-types/types/api-v2.d.ts` carries those paths 24 times. #43276 (DEPR-340) described it as "UI-only (with mock data)", and the `DEPR-340-backend-integration-tracker.md` it pointed to is no longer in the tree. A dashboard section can be added once the UI calls the API. | | Possible reference slug collision | Project- and org-scoped operations share identical `summary` values (both "Create endpoint", both "List endpoints"). The page links to the reference introduction and names the **Project webhooks** / **Organization webhooks** tags rather than deep-linking a generated page. | ## Preview links **Verified:** the new page returns 200 on the preview; the same path returns 404 on production, confirming net-new content; the nav entry renders on the preview build. ### Proof: new page renders on the PR preview [Open the new page on preview](https://docs-git-nikrichers-ctrl-1017-set-up-public-doc-fa3960-supabase.vercel.app/docs/guides/platform/webhooks) <img width="2295" height="8039" alt="Screenshot 2026-10-05 at 11-47-06 Platform Webhooks Supabase Docs" src="https://github.com/user-attachments/assets/7b1440d3-207d-4828-8593-77140bdcd73f" /> <img width="2295" height="12000" alt="Screenshot 2026-10-05 at 11-48-49 Platform Webhook Events Supabase Docs" src="https://github.com/user-attachments/assets/2808a88e-558e-4f73-a12a-01382cd3f6a2" /> ## Review instructions 1. Open the [PR preview](https://docs-git-nikrichers-ctrl-1017-set-up-public-doc-fa3960-supabase.vercel.app/docs/guides/platform/webhooks) and confirm the page renders as shown. 2. Confirm **Platform Webhooks** appears under **Platform > Project & Account Management** in the sidebar, after **Personal Access Tokens**. 3. Confirm the five internal-guide values in the second row of the needs-review table. 4. Decide with the Control Plane team whether the Studio UI ships wired to the API, which determines when a dashboard section gets added: Studio UI is slated for Q4, so it will not be shipped together. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a Platform Webhooks guide covering endpoint setup, event delivery, signature verification, test events, retries, retention, idempotency, ordering, and listener best practices. * Documented project and organization event types, payload schemas, event scopes, and versioning, plus access restrictions for organizations outside the allowlist. * **Navigation** * Added Platform Webhooks links, including Overview and Events, to the platform navigation when the full platform is enabled. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> Co-authored-by: Paweł Gulbinowicz <pawel.gulbinowicz@supabase.io> Co-authored-by: Paweł Gulbinowicz <zamotany@users.noreply.github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> |
||
|
|
089133cc2c |
feat(storage): add bucket object versioning form fields (FE-4161) (#49203)
| # | Branch | Base | | - | ------ | ---- | | 1 | `feat/storage-versioning-private-alpha` — merged | `master` | | 2 | `feat/storage-versioning/002-bucket-form-fields` ◀ | `master` | | 3 | `feat/storage-versioning/003-bucket-modals` | 2 | | 4 | `feat/storage-versioning/004-object-versions-data` | 3 | | 5 | `feat/storage-versioning/005-file-preview-versions` | 4 | | 6 | `feat/storage-versioning/006-billing-storage-retention` | 5 | | 7 | `feat/storage-versioning/007-archived-objects-data` | 6 | | 8 | `feat/storage-versioning/008-archived-rows` | 7 | | 9 | `feat/storage-versioning/009-archived-preview-pane` | 8 | | 10 | `feat/storage-versioning/010-replace-file` | 9 | ## [2/10] Storage object versioning: bucket form fields The object versioning + lifecycle policy form section for the create and edit bucket modals. Mounted onto the ui in PR 3 #49205 - `BucketVersioningFields` — the versioning switch and the suspension / public-bucket / retention-tightening warnings - `LifecyclePolicySection` — the retention window and version cap inputs - `ExpirationModeToggle` — how the two conditions combine (and / or) - `BucketVersioningFields.schema.ts` — zod fields the parent modals spread into their own schema, plus `superRefineBucketVersioning` - `BucketVersioningFields.utils.ts` — retention-tightening detection - `StorageVersioning.constants.ts` — versioning state and expiration mode types, the prefill defaults, and `getBucketVersioningState` Note: a single s3 lifecycle policy expects both `version_expiry_days` and `max_noncurrent_versions` and always evaluate the two fields within the same policy with an AND logic. To enable both AND and OR/EITHER logic, we save two distinct s3 policies so we can enforce the OR logic. See demos and how to reproduce in #49205 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary * **New Features** * Eligible projects with the preview enabled can configure object versioning for storage buckets, including version expiration, retained-version limits, and “and/or” lifecycle conditions. * Settings default to 30 days and 10 retained versions, with validation for retention values and requirements for setting a version limit. * Notices highlight public buckets, missing lifecycle conditions, suspending existing versioning, and changes that tighten retention limits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
12afe39999 |
Docs/troubleshoot pg net privileges (#51275)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? New troubleshooting guides related to the current pg_net and pg_dump extensions' behaviour. ## What is the current behavior? ## What is the new behavior? Preview: - [Revoking access to pg_net objects has no effect: no privileges could be revoked](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/revoking-access-to-pg_net-objects-has-no-effect-0bbc16) - [Database roles can read request headers queued by pg_net](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/database-roles-can-read-request-headers-queued-by-pg_net-ad6357) - [pg_dump fails with 'query would be affected by row-level security policy'](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/pg_dump-fails-with-query-would-be-affected-by-row-level-security-policy-1d5783) - [Custom role inherits privileges that were not explicitly granted](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/custom-role-inherits-privileges-that-were-not-explicitly-granted-ddaa1c) |
||
|
|
20d752517f | feat(docs): record search v2 rollout exposure (#51300) | ||
|
|
53a637a359 |
fix(studio): don't watch Next's .next build output in TanStack dev (#51308)
## Problem Switching a local checkout from `STUDIO_FRAMEWORK=next` to `tanstack` leaves `apps/studio/.next` behind, including a full `node_modules` copy under `.next/standalone`. Vite's dev server watches all of it, logging hundreds of `page reload .next/server/pages/...` lines and wasting file handles. ## Change Add `**/.next/**` to `server.watch.ignored` in `apps/studio/vite.config.ts`. Vite's default ignores (`.git`, `node_modules`) still apply. ## Verification With a stale `.next` present, ran `STUDIO_FRAMEWORK=tanstack pnpm run dev`, touched `.next/server/pages/account/me.html`: no reload logged (previously ~220 `.next` reloads on startup). |
||
|
|
dc95335a8d |
Joshenlim/fe 4068 warn users ai assistant history can be wiped (#51260)
## Context Chats with the AI Assistant is currently stored locally on the browser and not synced across devices which caused a bit of confusion for some users when they realised they couldn't access their chat histories on different devices. (Ideal state tbh is to persist the chat conversations, but that'll need support on the BE) PR here just adds a foot note to both the chat history dropdown in the side panel + chat nav for the explorer regarding this - opting for something with a small footprint <img width="293" height="322" alt="image" src="https://github.com/user-attachments/assets/284ee0c1-16bf-432b-b473-29ee048ed4cc" /> <img width="392" height="956" alt="image" src="https://github.com/user-attachments/assets/e5eb1409-fa63-4dae-9439-86facbe41277" /> --------- Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
2538f7eb29 |
Fix unescaped SQL identifiers in row export (#51256)
## Context Resolves https://github.com/supabase/supabase/issues/49977 Addresses an issue in `formatTableRowsToSQL` to use `ident` for schema, table, and column name which will handle escaping of SQL identifiers. Can verify fix by creating a table like `test"table`, then adding some rows, and selecting either Copy as SQL or Export as SQL |
||
|
|
b6d4239010 |
Update Supplemental Terms placeholder text (#51301)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_ ## Problem **Before:** The Supplemental Terms page (`/legal/customer-resources/supplemental-terms`) says "Content coming soon." **After:** The page shows "Check here for any feature specific terms that we may need to release, or clauses that allow for compliance with geography specific laws that we may introduce." ## Solution Replaces the placeholder body in `apps/www/data/legal/customer-resources/supplemental-terms/v1.mdx` with the supplied text, as a plain paragraph. Nothing else changes. ## Review instructions 1. Open the Vercel preview link for `/legal/customer-resources/supplemental-terms`. 2. Confirm the page shows the new text instead of "Content coming soon." ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC --- _Generated by [Claude Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
be1ba651ed |
Add branching nav items to cmd k (#51255)
## Context Adds a couple of branching nav items to Command K - Create new branch - Branch management - Merge requests - Github Connection (For branching) - Branching feedback Switch branch is still available, and only visible after a branch has been created (status quo) <img width="610" height="531" alt="image" src="https://github.com/user-attachments/assets/3068184e-889d-44ed-8cf6-2afd59ffb109" /> |
||
|
|
642a02db49 |
Prevent enabling spend cap if org has projects with RRs (#51253)
## Context Prevents organizations from enabling spend cap if the org has projects with read replicas - We currently gate creation of read replicas to ensure that orgs have spend caps disabled, but were missing the guard for the other way around <img width="662" height="378" alt="image" src="https://github.com/user-attachments/assets/44ad036c-4c1b-48e8-beb7-f16f6170c9fb" /> ## Other changes involved - Refactored to use new `Sheet` and `Table` components in `SpendCapSidePanel` |
||
|
|
20d6f2197f |
chore(studio): remove privacy policy notice (#51299)
I removed the Studio Privacy Policy update notice that #50397 added on 2026-09-16, when Privacy Policy v4 took effect. It has been up for almost three weeks, and the ToS v4 banner (#51109) goes out next. I did the same in #44380, removing the March 2026 privacy notice after 15 days. This is the exact inverse of #50397: the banner component and its test, the banner ID, the dismissal local storage key, and the org-landing path helper that only this notice used. ## To test Tested on Vercel preview: - [ ] In a fresh browser profile (no `privacy-policy-update-2026-09-16-dismissed` key), open `/organizations`: expect no Privacy Policy notice - [ ] Open `/org/<slug>`: expect no Privacy Policy notice and the project list renders normally - [ ] Open a project's Logs page: expect the logs deprecation banner behavior unchanged (only shows before its expiry) ## Linear - fixes GROWTH-1322 |
||
|
|
a629c9c1ac |
Add hidden Supplemental Terms legal page (#51100)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_ ## Problem No page existed yet for the upcoming "Supplemental Terms" document. Nicole Kramer (Commercial & Product Counsel) needs a stable, linkable URL to reference from future Terms of Service / Enterprise SaaS Subscription Agreement updates, before the legal content itself is ready. The page needs to be reachable by direct URL but not surfaced in the visible Legal Hub nav yet, matching the existing "hidden" precedent used for `/enterprise-terms`. ## Solution Added a new page at `/legal/customer-resources/supplemental-terms`: - `apps/www/pages/legal/customer-resources/supplemental-terms.tsx` — a page component mirroring the existing Data Processing Addendum page (`apps/www/pages/legal/customer-resources/data-processing-addendum.tsx`): `DefaultLayout` + `PageHeader` (h1 "Supplemental Terms") + `LegalDocVersions` rendering a single MDX version. - `apps/www/data/legal/customer-resources/supplemental-terms/v1.mdx` — placeholder body content (`_Content coming soon._`), no frontmatter/h1, following this repo's existing legal MDX convention (the h1 is rendered by `PageHeader`, not the MDX itself). Nicole will fill in the actual legal content later. **On "hidden":** I investigated the actual codebase state before implementing, since the two precedents named didn't turn out to work the same way: - `/enterprise-terms` is genuinely hidden — it is not linked anywhere in `apps/www/pages/legal/index.tsx`'s Legal Hub listing, and its `NextSeo` meta sets `noindex: true, nofollow: true`. - The Data Processing Addendum and Subprocessor List pages, by contrast, **are** linked in the visible Legal Hub listing (`apps/www/pages/legal/index.tsx`, "Customer Legal Resources" section) — they are not hidden today. Given that, this PR mirrors the DPA/Subprocessor List *structural* pattern (route under `/legal/customer-resources/`, page-component + versioned-MDX content) since that's what "under Customer Legal Resources" means structurally in this codebase, but mirrors `enterprise-terms`' *hidden* mechanism: the new page's `NextSeo` meta sets `noindex: true, nofollow: true`, and — importantly — **no entry was added** to the `sections` array in `apps/www/pages/legal/index.tsx`, so it does not appear in the visible Legal Hub or any nav. The page is reachable only via its direct URL. Terms of Service and the Enterprise SaaS Subscription Agreement pages were not touched. ## Review instructions 1. Confirm `/legal/customer-resources/supplemental-terms` renders with h1 "Supplemental Terms" and placeholder body text. 2. Confirm the page does **not** appear anywhere on `/legal` (the Legal Hub listing). 3. Confirm `apps/www/pages/terms.tsx` / `apps/www/pages/enterprise-terms.tsx` (and their MDX content) are unchanged. ## Checklist - [x] I have read CONTRIBUTING.md - [ ] N/A — no docs topic edited (legal page content is a placeholder, not docs content) --- 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC --- _Generated by [Claude Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
81da60392e |
feat(www): add multigres alpha form to /database (#51298)
The Multigres private alpha request form only lives at /go/multigres-early-access (#51053), and nothing on the product site links to it. I added the same form to /database, the way /compute embeds its waitlist form. The new section sits at the bottom of the page, directly above the closing "Start your project" CTA: the go page's hero copy, the alpha caveats, and a "Learn about Multigres" link to multigres.com on the left, the form on the right. Fields, disclaimer, and redirect are read from the go page definition. The form posts `{ slug: 'multigres-early-access', formId: 'form' }`, so the server resolves the existing CRM config and submissions land in the same database as the go page. **Note:** the section throws at build time if the go page or its form section is removed, so retiring the go page means removing this section in the same change. ## To test Tested on Vercel preview: - [ ] Open /database and scroll to the bottom: expect a "Private alpha / Multigres on Supabase" section directly above "Build in a weekend, scale to millions", with the email and organization slug form, the alpha caveats, and the Privacy Policy disclaimer - [ ] Click "Learn about Multigres": expect multigres.com to open in a new tab - [ ] Resize to a phone width: expect the text stacked above the form card with no horizontal scroll - [ ] Open /go/multigres-early-access: expect its page and form unchanged - [ ] After merge, submit a test request from supabase.com/database: expect a redirect to /go/multigres-early-access/thank-you and a new row in the Multigres requests database ## Linear - fixes GROWTH-1321 |
||
|
|
22cdd05492 | fix: update disk maxSize in pricing page (#51295) | ||
|
|
d21c20eae6 |
docs: add Multigres early access request link to the Multigres docume… (#51297)
…ntation ## Problem Currently there's no way for users to request access to private alpha for Multigres. ## Solution Add a link to the form to fillout for customers to get access. ## Checklist Check all before review: - [X] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [X] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) Co-authored-by: Aditya Maruvada <aditya@Adityas-MacBook-Pro.local> |
||
|
|
5cc0450950 |
fix(www): plate State of Startups Sign in over the aurora (#51163)
## Problem On `/state-of-startups`, the nav starts transparent over the aurora. Default buttons use a translucent fill in dark mode, so Sign in (and Dashboard) look see-through. ## Solution Wrap those default nav buttons in `FloatingPlate`. Primary “Start your project” is already opaque and unchanged. | Before | After | | --- | --- | | <img width="1024" height="759" alt="23474_296a1f8f952ae7f73ae9205e5db6bb9cda4cf0a904bc2d440d6395b5f12346ab" src="https://github.com/user-attachments/assets/c247cdaa-06b0-46ad-b1f8-cee3e06fde8e" /> | <img width="1024" height="759" alt="State of Startups 2026 Supabase" src="https://github.com/user-attachments/assets/e9a1a0e0-9f2f-427f-a7d3-75e4e1cbba63" /> | ## Review instructions In dark mode: 1. [Live /state-of-startups](https://supabase.com/state-of-startups) · [Preview /state-of-startups](https://zone-www-dot-com-git-dnywh-fixsos-sign-in-float-91d2b1-supabase.vercel.app/state-of-startups) 2. At the top of the page (transparent nav, before scrolling), check Sign in: opaque plate, aurora does not show through the fill. 3. Scroll until the nav gains a solid background: Sign in should still look normal. Ideally you could sign in and confirm the now ‘Dashboard’ button gets the same plate treatment. But that’s not possible until merge. |
||
|
|
36364e7df3 |
fix(www): stop wrapping oklch semantic tokens in hsl() (#51161)
## Problem Semantic colour tokens (`--border-*`, `--foreground-*`, `--background-*`) now resolve to full `oklch(...)` values. Call sites that still wrapped them in `hsl(var(--…))` are invalid CSS and drop the colour (Partners ambient grid was the clearest case). Brand / destructive / warning channel tokens still correctly use `hsl(var(--…))` and were left alone. Presence avatar stack polish is in https://github.com/supabase/supabase/pull/51164. ## Solution - Use bare `var(--…)`, `currentColor`, or Tailwind utilities for semantic tokens. Opacity cases use `oklch(from var(--…) l c h / …)`. - Partners grid: fix, and then use `text-foreground/20` in light, `text-foreground/30` in dark for optical correction. | Before | After | | --- | --- | | <img width="1860" height="1106" alt="CleanShot 2026-10-02 at 16 29 08@2x" src="https://github.com/user-attachments/assets/4554b0c9-22cf-4b06-bbe3-798e8b15304e" /> | <img width="1852" height="1112" alt="CleanShot 2026-10-02 at 16 28 44@2x" src="https://github.com/user-attachments/assets/20ccbc80-5eaa-49e6-8f94-48b99dc01474" /> | | <img width="1024" height="759" alt="20701" src="https://github.com/user-attachments/assets/a4e578cf-5adb-4f7a-a53b-870a51f5f948" /> | <img width="1024" height="759" alt="59176" src="https://github.com/user-attachments/assets/dda3fc2d-d86b-45a5-adca-403223cc5f33" /> | ## Review instructions 1. [Live /partners](https://supabase.com/partners) · [Preview /partners](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/partners). Ambient dashed grid under the hero (light and dark). 2. [Live /database](https://supabase.com/database) · [Preview /database](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/database). Postgres elephant idle outline should be muted grey, not black. Hover still brand green. 3. [Live /state-of-startups](https://supabase.com/state-of-startups) · [Preview /state-of-startups](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/state-of-startups). Chart **More AI-generated code, less likely to be monetizing yet**: horizontal gridlines at 0/25/50/75/100% should render. 4. Storage / Edge Functions changes are correctness-only (shadows, idle borders, a top fade). Near-invisible to the naked eye; skip unless debugging. |
||
|
|
0cb8bd95dd |
feat(studio): add spot colour control to Appearance (#50782)
## Problem The theme's primary hue can change in CSS, but Appearance had no way to try other spot colours. That makes it hard to find controls whose colour still depends on the fixed Supabase brand palette. ## Solution Add a **Spot color** control under Appearance → Theme colors (employee-only via ConfigCat `appearanceSpotColor`, targeted to Supabase Team Email). ### Spot color UX - Rainbow spectrum track with a thin outline so pale tracks stay visible - Live trifecta swatches for `--primary-solid`, `--primary`, and `--primary-bright` (darkest → lightest) next to the degree readout - Drag updates are rAF-batched so React paint and CSS preview stay to one frame ### Canvas tint coupling - `--surface-hue` is derived in CSS as `calc(var(--primary-hue) + var(--surface-hue-offset))` - Dark: offset `0` (same hue as spot) - Light: offset `180` (complementary canvas tint; brand green ≈157.5° → rose ≈337.5°) - No JS override of `--surface-hue`. Changing Spot color moves primary controls and the low-chroma canvas tint together ### Other theme sliders - Renamed **Color intensity** → **Surface tint** (it only drives the neutral ramp via `--chroma`, not spot chroma) - Meaning-shaped tracks for every knob (spectrum, grey→tint, soft→hard, dark→light, flat→lift) - Same outline treatment on those tracks | Before | After | | --- | --- | | <img width="1476" height="2174" alt="CleanShot 2026-10-05 at 15 02 21@2x" src="https://github.com/user-attachments/assets/d08b0fa8-32af-450e-adce-861f59c9d6ca" /> | <img width="1474" height="2354" alt="CleanShot 2026-10-05 at 14 56 35@2x" src="https://github.com/user-attachments/assets/9a1e6183-a4ba-4c8e-a458-bb0eea946db8" /> | | _Anyone else_ | _With staff flag, custom settings_ | ## Review instructions 1. Confirm ConfigCat flag `appearanceSpotColor` is on for your staff account (or flip it in the Dev Toolbar). 2. Open `/account/me` → **Appearance → Theme colors**. 3. Without the flag: Spot color is hidden; other theme sliders still work. 4. With the flag: drag Spot color in light and dark. Primary controls and canvas tint should move together; Supabase brand assets should stay fixed. 5. Raise Surface tint and confirm the canvas hue follows the complementary (light) or same-hue (dark) offset. 6. Refresh, switch modes, and use **Reset** to check persistence and defaults. |
||
|
|
17512de71d |
docs(database): connect security definer to the default execute grant (#50817)
Closes DOCS-1319 Part 4 of 4 in stack #50823. This PR carries **additions**: content the page never had. Style, structure, and snippet fixes land below it in #50820, #50821, and #50822. ## Problem Developers and AI agents read the Database functions guide. The guide shows how to write a function inside the database. A function runs in one of two modes. In `invoker` mode it runs as the caller. In `definer` mode it runs as the creator. The guide gives one rule for `definer` mode. The rule is to set the `search_path`. A reader who obeys that rule still gets an unsafe function. I wrote a function that obeys the rule. I pinned the search path to the empty string. Then I called it three times. | Caller | Result | | --- | --- | | The order's owner | 4330 cents, correct | | A different signed-in customer | 8660 cents, another customer's order | | Nobody, no session at all | 8660 cents | Every role can call a new function in `public`. The guide states that fact under Function privileges. It never connects the fact to the `definer` rule. A reader has no reason to look. Customers report the same failure. AI tools choose `definer` mode. The function then answers the front end with no session. The hole is hard to find, because no policy is involved in it. ## Solution - **Joins the two halves in the Security definer subsection.** A `danger` admonition states three facts: - The function runs with its creator's privileges. - A function created in the Dashboard or by a migration is owned by `postgres`, which bypasses Row Level Security. - Every role can call the function by default. The admonition then gives the fix. Check ownership inside the function body, and narrow the execute privilege as well. - **Applies the regrant to both ways of restricting execute.** The `grant execute` block sat inside the second way. A reader who took the first way saw no way to restore their own app's access. **Not changed:** the existing definer paragraph, the page structure, and the Function privileges statements. The lower PRs in the stack own those. **No eval re-run.** The guide scored 6 of 6 on three baseline runs, so the score has no room to move. All three runs chose `invoker` mode. The eval never enters the branch this PR fixes. Measuring it needs a new check, not a re-run. **Diff size:** one file, 15 lines added and 4 removed. ## Manual testing 1. Open the [Security definer vs invoker section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker) on the deploy preview. The admonition renders as a red `danger` panel below the definer paragraph. The two fixes appear as bullets. 2. Click the `Function privileges` link inside the admonition. It jumps to the [Function privileges section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#function-privileges) on the same page. 3. Read that section. The `grant execute` block sits after the numbered list. It applies to both ways of restricting execute. 4. Run `pnpm build:guides-markdown` from `apps/docs`. Read `apps/docs/public/markdown/guides/database/functions.md`. The admonition appears as a `Danger:` paragraph. Discard the `manifest.json` change. 5. Run `npx prettier --check apps/docs/content/guides/database/functions.mdx`. Clean. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded guidance on the security risks of `security definer` functions, including their privileges, interaction with Row Level Security, and default execution access. * Added recommendations for checking data ownership and restricting execution to intended roles. * Clarified that pinning `search_path` does not limit execution privileges. * Presented the function-privileges example separately from the default-privileges instructions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Preview links | Site | Live | Preview | Search for | | --- | --- | --- | --- | | Docs | [/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions) | [/docs/guides/database/functions](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions) | `every signed-in caller` | ## Review instructions This PR adds one admonition and moves one code block. The question is whether the admonition is correct and whether an agent reading the page would act on it. 1. Open the preview at [Security definer vs invoker](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker). A red `danger` panel sits below the definer paragraph. 2. **Read the first paragraph for accuracy.** It claims the function runs with its creator's privileges, that a function created in the Dashboard or by a migration is owned by `postgres`, and that `postgres` bypasses Row Level Security. This matches [Use security definer functions](https://supabase.com/docs/guides/database/postgres/row-level-security#use-security-definer-functions) in the RLS guide. Flag any drift. 3. **Read the two bullets for sufficiency.** The ownership check is the primary fix. The execute grant is listed as a complement, not an alternative, because granting to `authenticated` still returns any user's row to every signed-in caller. Confirm the wording can't be read as "either one is enough." 4. Click the `Function privileges` link inside the admonition. It jumps down the same page. 5. In the Function privileges section, confirm the `grant execute` block sits after the numbered list rather than inside item 2, so it applies to both ways of restricting execute. 6. **Check the agent-facing copy.** Open [the markdown export](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions.md) and find `Danger:`. This is what an agent reads, and it is the audience this PR exists for. **If you only have two minutes:** do steps 3 and 6. Step 3 is the correctness of the advice. Step 6 is whether the audience that prompted the ticket actually receives it. **A note on running SQL from this page.** Don't hand-paste from the rendered page. Blocks are split across tabs, and the Data tab in Returning data sets holds markdown tables that look pasteable but are not SQL. Use the `.md` export of the page, which flattens every tab in page order. #50822 has a copy-paste command for this. |
||
|
|
d8b0a3e87f |
docs(database): make the guide's snippets run in document order (#50822)
Part 3 of 4 in stack #50823. This PR carries **technical revision only**: claims that produce a wrong outcome for a reader. ## Problem This PR came from running a technical assessment using `/test-the-docs`. A reader pastes the guide top to bottom. Two snippets fail. The `planets` table uses a `serial` primary key, then the seed sets ids explicitly. Explicit ids don't advance the sequence, so it stays at 0. The `add_planet('Jakku')` example then draws id 1, which the seed already used: ``` ERROR: duplicate key value violates unique constraint "planets_pkey" DETAIL: Key (id)=(1) already exists. ``` The `security definer` example re-creates `hello_world` with `create` rather than `create or replace`, so it collides with the function from Basic functions: ``` ERROR: function "hello_world" already exists with same argument types ``` The Data tab spells the planet Tatooine. The SQL tab spells it Tattoine. Two debugging snippets read `attendance_table` and `some_table`. No fence creates either, and neither is marked as omitted. ## Solution - **Seeds `planets` and `people` without explicit ids.** The sequence advances, so `add_planet` succeeds. This also settles Tattoine against Tatooine. - **Uses `create or replace` in the definer example**, so it no longer collides. - **Marks the two assumed tables** in the debugging snippets with a comment. - **Points the CREATE FUNCTION link at the current Postgres docs.** It pointed at 9.1, while the intro already links the current version of the same page. **Verification.** I ran every `sql` fence from the guide in document order against Postgres 15 in a throwaway container, with `anon` and `authenticated` created first. Before these changes, two fences errored. After them, the sequence runs clean. ## Manual testing 1. Start a throwaway Postgres: `docker run --rm -d --name pgcheck -e POSTGRES_PASSWORD=pw postgres:15`. 2. Create the Supabase roles the guide references: `docker exec -i pgcheck psql -U postgres -c "create role anon; create role authenticated;"`. 3. Paste every `sql` block from the guide, in page order, into `docker exec -i pgcheck psql -U postgres`. No statement errors. 4. Run `select * from planets;`. Tatooine, Alderaan, Kashyyyk, and Jakku, with sequential ids. 5. Remove it: `docker rm -f pgcheck`. ## Preview links | Site | Live | Preview | Search for | | --- | --- | --- | --- | | Docs | [/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions) | [/docs/guides/database/functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/functions) | `('Tatooine')` | | Docs | New page, 404 in production | [/docs/guides/database/debugging-functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/debugging-functions) | `assumes an attendance_table` | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Clarified the required column types in database function examples. - Expanded guidance on function return values, including `INSERT`, `UPDATE`, and `DELETE` statements with `RETURNING` clauses. - Updated SQL examples to show table creation and automatically generated IDs, corrected the spelling of “Tatooine,” and refreshed the PostgreSQL reference link. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8b148f93c1 |
docs(database): regroup the database functions guide and split out debugging (#50821)
Part 2 of 4 in stack #50823. This PR carries **structure only**: moves, regrouping, and the connective text the new shape needs. Reworded prose already landed in #50820. ## Problem This PR is running a structure edit. A reader arrives from search and has to find one thing. The guide gave them eight top-level headings, no grouping, and no opening outline. The style guide caps a group at 5 ± 1. Four of those headings are the action path: Getting started, Basic functions, Returning data sets, and Passing parameters. Nothing marked them as one sequence. `Suggestions` held four unrelated things: an Edge Functions comparison, two security topics, and a three-part debugging reference. The heading names nothing the reader is doing. Debugging was the largest thing on the page. It sat at H3 with three H4 children, and it shared only the word "function" with the rest of the guide. ## Solution - **Groups the four procedures** under `Create a database function`, so the action path is one unbroken sequence. - **Moves the Edge Functions comparison ahead of the procedures.** A reader choosing between the two needs it before the steps, not after them. - **Groups the two security sections** under `Secure a database function`. - **Splits debugging onto its own page**, `guides/database/debugging-functions`. It is registered in the Database sidebar and cross-referenced from the guide. - **Folds `Deep dive` into `Resources`.** Two trailing headings did one job. - **Adds an opening outline** linking each group and saying when to use it. - **Renames the frontmatter title** to sentence case, `Database functions`. ## Manual testing 1. Open the [guide on the deploy preview](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions). Five top-level headings, with the opening outline linking each group. 2. Open the [new debugging page](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions). It appears in the Database sidebar under Managing database functions. 3. Follow a repointed link. Open [Postgres log config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config) and click Database Function Logging. It lands on the new page at General logging. 4. Run `pnpm build:guides-markdown` from `apps/docs`. Both pages appear under `public/markdown/guides/database/`. Discard the `manifest.json` change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a guide to debugging Postgres database functions, with examples for logging, error handling, and inspecting query results. * Added the guide to Database navigation and updated related resources to link to it. * Reorganized the database functions guide to clarify function creation, security, and privileges. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Preview links | Site | Live | Preview | Search for | | --- | --- | --- | --- | | Docs | [/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions) | [/docs/guides/database/functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions) | `Secure a database function` | | Docs | New page, 404 in production | [/docs/guides/database/debugging-functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions) | `Debugging database functions` | | Docs | [/docs/guides/database/postgres/postgres-log-config](https://supabase.com/docs/guides/database/postgres/postgres-log-config) | [/docs/guides/database/postgres/postgres-log-config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config) | `Database Function Logging` | ## Review instructions This PR moves content. The risk is a broken link, not bad prose. 1. Open the preview of the guide. Count the top-level headings in the right-hand outline. There are five, down from eight. 2. Read the four bullets at the top of the page. Each links to a group, and each says when to use it. Click all four and confirm each lands on its section. 3. Open the new debugging page from the second row. Confirm it appears in the left sidebar under **Managing database functions**. 4. **Check the three locked anchors.** Append each to the preview guide URL and confirm the page jumps: `#quick-demo`, `#security-definer-vs-invoker`. Then append `#general-logging` to the **debugging page** URL. Four other pages link to these. 5. Open the Postgres log config preview from the third row. Find **Database Function Logging** in the Resources list and click it. It lands on the new debugging page, not on a dead anchor. 6. Compare the prose against the live page. **No sentence should have changed** beyond the new opening outline and the cross-reference to the debugging page. **If you only have two minutes:** do steps 4 and 5. A moved section that leaves a dead anchor is the failure this PR could cause. **A note on running SQL from this page.** Don't hand-paste from the rendered page. Blocks are split across tabs, and the Data tab in Returning data sets holds markdown tables that look pasteable but are not SQL. Use the `.md` export of the page, which flattens every tab in page order. #50822 has a copy-paste command for this. |
||
|
|
a9078612f2 |
fix(www): stop cross-zone link prefetch (#51066)
About 95% of the 404s served on supabase.com are App Router RSC prefetches (`?_rsc=`) that www `<Link>`s fire at paths another zone serves: `/docs`, `/dashboard`, `/library`, and the footer's `humans.txt`, `lawyers.txt` and `security.txt`. Next.js can't prefetch or client-navigate across multi-zone boundaries, so each prefetch 404s even though the link itself works. I turned every www link into another zone into a plain `<a>` and added a lint rule so new ones stay that way. **Changed:** - **Cross-zone links are plain anchors**: links that always leave www (literal `/docs`, `/dashboard` and `.txt` hrefs, absolute `https://supabase.com/dashboard` URLs, the `getDashboardCtaHref` CTAs) render `<a>`. Renderers whose href comes from data (nav, footer, plan and add-on CTAs, product cards) branch on `isCrossZoneHref`, which reads the zone list from `lib/rewrites.js`. In-zone links stay `<Link>` and keep prefetching. - **New literal links can't regress**: `www/no-cross-zone-link` errors on a `next/link` `<Link>` whose literal or template href points at another zone. It evaluates `lib/rewrites.js` as production, so `/docs` counts in every environment. - **Click tracking survives the full navigation**: `sign_in_button_clicked`, `start_project_button_clicked` and `www_pricing_plan_cta_clicked` now send with `keepalive`, like `sign_in_submitted` already did, so an immediate page load can't cancel them. The mobile nav Sign in and Start your project buttons used `legacyBehavior`, which never called their `onClick`: PostHog has no `Mobile Nav` location for either event in the last 30 days. Those clicks report from this PR on. - **Typecheck no longer crashes**: the functions page's default export inferred a type through `RealtimeLogs`'s unexported `Props`, which makes the native TypeScript compiler panic during `tsc --noEmit`. I exported `Props`. **Note:** the lint rule only sees literal hrefs. A new renderer whose href comes from data needs its own `isCrossZoneHref` branch, and review is the only check on that. ## To test `/docs` is only rewritten on production and absolute `https://supabase.com/...` links are cross-origin on a preview, so the preview proves the relative non-docs cases (`/dashboard*`, `/library`, the footer .txt files). `/docs/...` prefetches still appear on the preview because it has no docs rewrite. Tested on Vercel preview: - [x] Open `/` with the network tab filtered to `_rsc` and scroll to the footer: no requests for `/dashboard*`, `/library`, `/design-system`, `/kb`, `/evals`, `/humans.txt`, `/lawyers.txt` or `/.well-known/security.txt`, while in-zone ones such as `/pricing`, `/features` and `/blog` still appear - [x] Same check on `/pricing`, `/auth`, `/database`, `/storage`, `/realtime`, `/edge-functions`, `/blog` and a blog post: no `_rsc` requests to `/dashboard*`, `/library` or the footer .txt files - [x] Open the Developers dropdown on desktop and the mobile menu at 390px: no new `_rsc` requests to `/dashboard*` or `/library` - [x] Click header Docs, footer Humans.txt, the hero Start your project button and the pricing Free plan button: each lands where it did before (`/docs`, `/humans.txt` text, `https://supabase.com/dashboard/sign-up`, `https://supabase.com/dashboard/new?plan=free`). Signed out, the Free plan button lands on the dashboard sign-in with `plan=free&returnTo=%2Fnew` - [x] Click the hero Start your project button: the `/platform/telemetry/event` POST with `start_project_button_clicked` completes with a 2xx after the page starts navigating. 201 with the navigation held; on the real navigation the event still reached staging PostHog - [x] At 390px, open the mobile menu and click Sign in: a `/platform/telemetry/event` POST with `sign_in_button_clicked` and `buttonLocation: "Mobile Nav"` fires. Start your project in the same menu also sends `start_project_button_clicked` with `buttonLocation: "Mobile Nav"` - [ ] Signed in, load `/`: no `/dashboard/projects?_rsc=` request (not run: the preview origin has no signed-in session) - [x] Open the desktop Product dropdown and the Product section of the 390px mobile menu: Compute shows its Private Alpha badge and the other products show none (checks the master merge into `MenuItem`) After deploy, `/` and `/pricing` on supabase.com show no `_rsc` requests to `/docs*`, `/dashboard*` or `/library`. After a full day, the share of supabase.com 404s carrying `_rsc=` should drop from about 95% to under 10%, and `sign_in_button_clicked` and `start_project_button_clicked` should start showing a `Mobile Nav` location in PostHog. ## Linear - fixes GROWTH-1294 |
||
|
|
63c165311e |
docs(functions): act on the Edge Function auth eval findings (#50886)
Closes DOCS-1318 ## Problem An agent was asked to build an Edge Function returning the order history for whoever is signed in and calling it. Three runs, all correct: each one used the page's `auth: 'user'` pattern and read through the caller-scoped client. The eval scores 7 of 7, including the guide-read check. These are the gaps that showed up around it. | Finding | What the page does now | Why it matters | | --- | --- | --- | | Two clients, no guidance | The first example destructures `supabase` and `supabaseAdmin` together and labels the second "bypasses RLS (service role)" | A reader skimming for the client to use sees two, and one of them is wrong for that section | | No consequence named | "Bypasses RLS" is the strongest phrasing anywhere | A handler querying a shared table through the privileged client without a filter returns every user's rows. The page never said so | | `verify_jwt` as a value to set | Appears six times, five of them as something to change | Switching it off to clear a 401 in development is a reported failure. The page never said the default is the safe one | ## Solution - **Say which client to reach for**, in the section where both are handed over. - **Name the outcome** in a `danger` admonition: a handler that queries a shared table through `ctx.supabaseAdmin` without filtering by the caller's ID returns every user's rows. - **Frame `verify_jwt = true` as the default to leave alone** on user-facing functions, and say what turning it off costs. - **Say every project starts with a secret key named `default`.** **Not asserted here:** the eval is not re-run. It was already at 7 of 7, so there is no headroom to measure an improvement. A candidate new check is proposed on DOCS-1318. ## Preview links | Site | Live | Preview | Search for | | ---- | ---- | ------- | ---------- | | Docs | [/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth) | [/docs/guides/functions/auth](https://docs-git-docs-functions-auth-eval-findings-supabase.vercel.app/docs/guides/functions/auth) | returns every user's rows | ## Review instructions 1. Open the live and preview links side-by-side. 2. Read Authenticated user calls on the preview. See a paragraph on choosing between `ctx.supabase` and `ctx.supabaseAdmin`, then a `danger` admonition naming the every-user's-rows outcome. 3. See the same section say to leave `verify_jwt = true` on for user-facing functions. 4. Read the note under Service-to-service calls. See it mention the `default` secret key. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that `secret` and `publishable` authentication modes accept the `default` key, and documented how default, wildcard, and additional keys are handled. * Explained that JWT verification is enabled by default and that disabling it leaves `withSupabase` as the only caller-verification step. * Added guidance that admin queries bypass row-level security and should be scoped to the caller when accessing shared tables. * Clarified that service-to-service authentication with `secret` validates only the `default` key. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
259dbe11f1 |
docs/functions auth structure (#50885)
## Problem Restructure the topic based off of the PRed Style Guide. ## Solution - **Group the seven sections into three.** A concept opener, `Choose an auth mode`, holds the mode table. `Secure your function` holds the six patterns. `Environment variables` stays last as the fact group. - **Add an intro outline** linking the three groups, and a group introduction for the patterns. - **Move the Authorization headers link below the mode table**, so the sentence that introduces the table sits next to it. - **Correct the content listing entry** to match the page's own title. **Anchors:** every heading text is unchanged. Five headings move from `##` to `###`, which preserves the slug. The in-page link to `#external-webhooks` and the two existing redirects in `apps/www/lib/redirects.js` all still resolve. Verified by grepping the repo for `functions/auth#` before and after. ## Preview links | Site | Live | Preview | Search for | | ---- | ---- | ------- | ---------- | | Docs | [/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth) | [/docs/guides/functions/auth](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions/auth) | Choose an auth mode | | Docs | [/docs/guides/functions](https://supabase.com/docs/guides/functions) | [/docs/guides/functions](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions) | Securing Edge Functions | ## Review instructions 1. Open the live and preview links side-by-side. 2. See three top-level entries in the preview's table of contents, with six nested under `Secure your function`. 3. Load `/docs/guides/functions/auth#external-webhooks` on the preview. See the page jump to that section. 4. Open the second preview link. See the listing card read "Securing Edge Functions" rather than "With supabase-js". ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized the authentication guide with a table of contents and clearer sections on choosing an auth mode and securing a function. * Clarified that the guide covers all supported auth modes, combining modes, and custom error responses. * Renamed the guide listing to “Securing Edge Functions” and updated its description to mention declaring accepted credentials. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
dcf266c360 | feat(docs): update search v2 ui (#51175) | ||
|
|
47fd296fc1 |
Add Flick Games case study (#51285)
## Problem New customer case study for the Case Studies content track: Flick Games, an indie UK games studio running Art of Solitaire and Goalman on Supabase. ## Solution Adds `apps/www/_customers/flick-games.mdx` plus the logo (on-light/on-dark) and quote-avatar assets. Content is ready for design/eng review. Tracked in [MARKET-2252](https://linear.app/supabase/issue/MARKET-2252/case-study-flick-games-sept-23). ## Review instructions 1. Open the preview link for `/customers/flick-games`. 2. Check the logo renders correctly in both light and dark mode, and that both quote avatars load. 3. Read through for tone and flow. ## Checklist - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [ ] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs [style guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide) 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
09a245d72d |
[FE-4520] fix(studio): hide Realtime setup for published tables (#51152)
The Realtime Inspector now checks the Realtime publication before showing setup guidance. Projects with published tables get the join-channel view even before this Inspector session receives any messages; unconfigured projects keep the setup guide. Setup guidance also stays hidden while publications are loading or unavailable. Joining a channel and displaying received messages retain their existing behavior. Addresses [FE-4520](https://linear.app/supabase/issue/FE-4520/realtime-inspector-ui-implies-i-am-not-using-realtime-despite-already). ## To test - With no tables in `supabase_realtime`, open Realtime → Inspector and confirm the setup guide appears. - Enable Realtime on a table and confirm a client receives a database change. Open the Inspector without joining a channel: it should show “Join a channel to start listening to messages” and no setup guide. - Join a channel, trigger a table change, and check the event and payload appear. Stop listening and confirm messages remain visible. - Open Policies, then return to the Inspector and confirm the setup guide stays hidden for the configured project. - Join a broadcast-only channel with no incoming messages and confirm the messages view appears immediately. ## Validation Reproduced the original prompt locally with a working Realtime table, then verified the fix in the browser, including an independent client subscription, a live INSERT in the Inspector, navigation, stopping, and the unconfigured state. Temporary test data and services were cleaned up. All nine new regression tests pass; four fail against the original code. Typecheck, formatting, lint ratchet, Knip, and the case-sensitivity check pass. The full Studio suite passed 7,799 tests with one unrelated Explorer test failure; that test passed on a focused rerun alongside the Inspector tests. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * The Realtime inspector keeps the messages view visible while publication status is loading or unavailable, and when a channel is joined or messages are present. * Setup guidance appears only after publications load successfully and confirm that Realtime is unavailable, with no channel or messages to show. This includes cases where there are no publications, the Realtime publication has no tables, or only a differently named publication exists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
a5688423d0 |
docs(cli): restructure and tighten the CLI getting started guide (#50736)
Closes DOCS-1320 Was the bottom of a two-PR stack. The commit from #50680 moved here, so that PR is closed and this one carries both changes. ## Problem The CLI getting started guide had accumulated structural and prose problems, none of which change what the page claims: - **Nine flat H2 headings**, with Beta channel and Updating the Supabase CLI sitting between installing and running. A first-time reader crossed about 150 lines of beta and upgrade tabs before reaching `supabase init`. - **The introduction opened with a two-step procedure under no heading**, listing `init` and `start` before the CLI is installed. Its first sentence named the tool and where it runs rather than what the reader gets. - **Running a local Supabase project ran concept, fact, procedure, and process together** as one stretch of prose, so the two commands the reader has to run sat in paragraphs between the Docker background and the first-run note. - **Task headings mixed gerunds with imperatives:** Installing, Running, Stopping, and Updating next to Access and Manage. - **No navigation.** A long guide that mixes information types opened straight into commands, with no outline of its major groups. The sidebar contents is not a substitute: it isn't part of the document, and the generated markdown an agent reads has no sidebar at all. - **Four more sequences were prose.** Installing via npm, installing a Linux package, the pre-upgrade backup, and opting out of telemetry each had to be followed in order with nothing marking the order. - **Smaller things:** the Studio screenshot's alt text named the topic its heading already states, two links used "note above" and "here" as their text, and an admonition restated where `sb_publishable_...` comes from. ## Solution Twelve commits, one change type each, plus a master merge and its fixup. - **Style.** The install-method callout drops from four blocks to two paragraphs and uses the documented `title` prop. Active voice on the Postgres, analytics, and telemetry instructions. Descriptive link text. Alt text that describes the Studio screenshot rather than naming it. Cut the admonition restating `sb_publishable_...`. - **Structure.** Beta channel and Updating the Supabase CLI move out of the getting started path. - **Grouping.** Local setup goes under Set up a local project, updating and beta builds under Change your CLI version. The intro's `init` and `start` list gets a Quickstart heading. - **Value statement.** The opening sentence now says what the reader gets. - **Procedure format.** Running a local Supabase project leads with the container runtime prerequisite, then four numbered actions, then the first-run download as an outcome. Starting the container runtime is its own step, since the old prose only assumed it with "with a container runtime running". - **Imperative headings.** Install, Run, Access, Stop, Update, Use the beta channel. - **Four more procedures.** npm install, Linux packages, the pre-upgrade backup, and telemetry opt-out. The three pre-upgrade commands were one unexplained block inside an admonition, so each step now says what its command does. Re-enabling telemetry moves to a sentence, since it's the reverse action rather than a step. - **Intro navigation** listing the major groups, each line saying what the reader gets from it. - **Connect to a hosted project** (from #50680). A new section between Stop local services and Change your CLI version, saying the stack runs only on the reader's machine and nothing reaches a hosted project until they sign in and link one, then pointing at the page that owns the procedure. No commands. The `init` step gains a sentence saying it creates local files only, and the value statement and intro navigation cover the added goal. - **Style guide and word list fixes** from an audit of the page against `CONTRIBUTING.md` and `WORD_LIST.md`. `directory` over `folder` in command-line contexts, `might` over `may`, present tense over `will`, a noun after `this`, no `above` as a pointer, concrete verbs over `manage`, no time-relative `latest`, no parentheses for supplementary information, and an impact-first `caution` on the pre-upgrade callout. The container runtime list becomes a table of tool and platforms, and the group heading becomes Change your CLI version. ## Preview links | Site | Live | Preview | Search for | | ---- | ---- | ------- | ---------- | | Docs | [/docs/guides/local-development/cli/getting-started](https://supabase.com/docs/guides/local-development/cli/getting-started) | [/docs/guides/local-development/cli/getting-started](https://docs-git-docs-cli-getting-started-edits-supabase.vercel.app/docs/guides/local-development/cli/getting-started) | Change your CLI version, Connect to a hosted project | ## Manual testing 1. Open the docs preview link above. 2. Read the introduction. It opens with a value statement, then links the four major groups. Under Quickstart, the install-method callout explains how the install method changes the command you run. 3. Read the On this page list. It nests: Quickstart, Set up a local project with four sections under it, Change your CLI version with two sections under it, Telemetry, Learn more. 4. Check Run a local Supabase project renders four numbered steps, with code blocks inside steps 3 and 4. Check the npm tab of Install the Supabase CLI renders three, and How to opt out renders two. 5. Load the page at `#installing-the-supabase-cli`, `#beta-channel`, and `#updating-the-supabase-cli`. All three land on their sections despite the renamed headings. 6. Load the legacy path `/docs/guides/cli/getting-started#updating-the-supabase-cli`. It redirects to the current path and keeps the fragment. 7. Check the introduction's group list includes Connect to a hosted project, and that the section appears in the On this page list between Stop local services and Change your CLI version. 8. Check that section is two sentences and a pointer, with no commands. 9. In Run a local Supabase project, select the "Connect to a hosted project" link in step 3. The page scrolls to that section. 10. Follow both outbound links from the new section and confirm they resolve, including the `#configure-github-actions` fragment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized the local development guide with a clearer quickstart, setup steps, service access instructions, and CLI version guidance. * Expanded installation examples to include bun and clarified package-runner commands. * Clarified upgrade, backup, container cleanup, and telemetry instructions. * Added a reference to the Microsoft Writing Style Guide. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
53ecbf9f2a |
chore: Add telemetry to search v2 user actions (#51146)
## Problem We need to collect data from search v2 experiment usage. ## Solution Add telemetry to search v2 modal being opened, closing, sending a query and clicking a search v2 result. <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions 1. Open the preview link and add the search v2 flag query: `?docs-search-v2=search-v2-active` 2. Trigger all actions mentioned above 3. Telemetry data should be sent on the network tab ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Documentation search activity is now recorded when the dialog opens from the keyboard shortcut or search input, and when it closes. Search submissions include the query and whether results were found; selected results include their destination and the highlighted query. This adds visibility into key search interactions without changing how search results or highlighting work. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
42dc4dbe90 |
chore: Add observability to search_v2 route (#51149)
## Problem Our new Search V2 edge function can fail, we want to know when that happens. ## Solution Added the common Sentry wrapping plus try/catch strategy to the edge function so we can add alerts to our Sentry dashboards and report channels. <!-- ## Preview links If relevant, include links to changed pages for easy review access. Copy the preview base URL from the Vercel bot comment on this PR. Use the following table as an example template. | Site | Live | Preview | Search for | | -------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------- | | WWW | [/blog/your-post](https://supabase.com/blog/your-post) | [/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post) | unique phrase from the change | | Docs | [/docs/guides/your-page](https://supabase.com/docs/guides/your-page) | [/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page) | unique phrase from the change | | Studio | [/dashboard](https://supabase.com/dashboard) | [/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard) | unique phrase from the change | | Design system | [/design-system](https://supabase.com/design-system) | [/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system) | unique phrase from the change | | UI library | [/library](https://supabase.com/library) | [/library](https://ui-library-git-branch-name-supabase.vercel.app/library) | unique phrase from the change | | Knowledge base | [/kb/guides/your-page](https://supabase.com/kb/guides/your-page) | [/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page) | unique phrase from the change | --> <!-- ## Additional context Optionally add any other context or screenshots. --> ## Review instructions There's no way to reproduce this for the moment. ## Checklist Check all before review: - [x] I have read [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) - [x] If I wrote a new docs topic or edited an existing topic, I used the `/write-the-docs` or `/edit-the-docs` skill, which references [WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md) and the docs [CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md) guide <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Search requests that encounter unexpected server-side errors now receive a handled 500 response instead of an unhandled failure. Errors returned by the search service also produce a 500 response, making failure behavior more consistent for clients. The search query and result-limit behavior remain unchanged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d7cac841c4 |
docs: state the adapter removal date in the server frameworks guide (#51276)
The server frameworks guide still said the adapters "will be deprecated soon" and would be "removed in a future major". They have been deprecated since `@supabase/server` 1.9.0, with `@deprecated` tags shipping in 1.9.1, and the removal date is December 1, 2026. This PR updates the two sentences to state that date and drops the wording about the release shape, which is not decided. |
||
|
|
7d04c43082 |
fix(logs): default unified logs to otel DEBUG-228 (#51089)
## Problem Unified Logs could start legacy BigQuery requests while ConfigCat loaded, then switch to OTEL when the flag resolved. ## Fix Default Unified Logs to OTEL unless otelUnifiedLogs is explicitly false. Use that selection for list, count, chart, facet, detail, download, and manual refresh requests. Keep BigQuery as an explicit opt-out until the legacy backend is removed. ## Validation - Studio typecheck passed locally. - Existing Unified Logs utility tests passed (21 tests). - The focused Unified Logs query test file was removed as requested; backend-selection and manual-refresh regressions are no longer covered by that suite. - CI checks are running on the current head. Tracks [DEBUG-228](https://linear.app/supabase/issue/DEBUG-228/prevent-bq-queries-before-the-feature-flag-loads). |