Commit Graph
38975 Commits
Author SHA1 Message Date
Danny White d95ff5bda9 docs(design-system): rewrite sidebar page for monorepo tokens (#51165)
## Problem

The design-system Sidebar page was mostly an upstream shadcn paste:
first-person voice, a broken `/blocks` link, missing structure images,
CLI install steps that do not match this monorepo, and a long changelog
/ data-fetching tutorial that do not apply here.

Separately, it still taught classic shadcn **HSL channel** variables
plus `hsl(var(--sidebar-*))`. In this monorepo those tokens are **full
colours**. Mixing the two patterns produces invalid CSS.

Related call-site cleanup:
https://github.com/supabase/supabase/pull/51161

## Solution

- Rewrite the Sidebar docs as a shorter monorepo guide: import from
`'ui'`, structure, theming, provider / sidebar props, menu building
blocks, controlled mode, state styling.
- Move Studio’s `--sidebar-*` aliases into shared `packages/ui` compat
CSS so every app on the shared theme gets working `bg-sidebar`
utilities.
- Drop the duplicate definitions from Studio `globals.css`.

Left alone on purpose: brand / destructive channel tokens and docs that
correctly use `hsl(var(--brand-…))`.

## Review instructions

Design-system preview:
[design-system](https://design-system-git-dnywh-docssidebar-full-colour-tokens-supabase.vercel.app/)

1. [Live Sidebar
docs](https://supabase.com/design-system/docs/components/sidebar) ·
[Preview Sidebar
docs](https://design-system-git-dnywh-docssidebar-full-colour-tokens-supabase.vercel.app/design-system/docs/components/sidebar).
Confirm the page is no longer the upstream essay: no broken images, no
`/blocks` link, imports from `'ui'`, theming shows full-colour aliases.
2. Smoke Studio: left nav should look unchanged (same aliases, now from
compat.css).
3. Optional: in DevTools, confirm `--sidebar-background` resolves to a
full `oklch(...)` colour.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)
2026-10-07 10:36:41 +11:00
Danny White 272bb26635 fix(studio): remove duplicate status page link in incident banner (#51305)
## Problem

During active incidents, the Studio status banner read:

> We are investigating a technical issue · Follow the status page for
updates Status page

The trailing "Status page" goes alongside plain-text copy that already
mentioned "status page".

## Solution

Match the emergency-override and legacy banners: make "status page" the
inline link inside the sentence, and drop the trailing link. Added a
regression test covering the link text and href.

| Figure |
| --- |
| <img width="1280" height="288" alt="6696"
src="https://github.com/user-attachments/assets/e267f0d0-5484-45a5-969f-03e184b903dd"
/> |
| _Before_ |
| <img width="1280" height="288" alt="47231"
src="https://github.com/user-attachments/assets/2beee89e-3674-43f5-9d13-6dc04d153549"
/> |
| _After_ |

## Review instructions

As of writing this: we have an active indident so you could just log in
to the [staging
preview](https://studio-staging-git-dnywh-dd493a51-supabase.vercel.app/).

Otherwise:

1. Open `apps/studio/components/layouts/AppLayout/StatusBanner.tsx` and
confirm the incident description is `Follow the [status page] for
updates` with no trailing "Status page" link.
2. Optionally run `pnpm --filter studio exec vitest run
components/layouts/AppLayout/StatusBanner.test.tsx`.
3. If you have a local Studio with an active incident (or
`ongoingIncident` override), confirm the banner shows a single linked
"status page" and no duplicate trailing link.
2026-10-06 23:16:25 +00:00
Danny White b5c865521f feat(studio): notify users about the Terms of Service update (#51302)
## Problem

Dashboard users need a notice about the Terms of Service update
alongside #51106 and #51107.

## Solution

Reuse the organisation landing-page notice pattern from #50397. A
compact “We've updated our Terms of Service.” notice opens the
explanation and agreement link through **Learn more**. Closing the
notice or choosing **Got it** remembers dismissal in the browser with a
new version-specific key.

```text
Organisation landing page
  Notice → Learn more → Explanation and Terms of Service link
  Close / Got it → Remember dismissal
```

| After |
| --- |
| <img width="628" height="444" alt="CleanShot 2026-10-06 at 14 47
46@2x"
src="https://github.com/user-attachments/assets/72922712-321f-4972-b20c-1a075e0745d0"
/> |
| _Banner_ |
| <img width="1078" height="718" alt="CleanShot 2026-10-06 at 16 58
18@2x"
src="https://github.com/user-attachments/assets/2109c2ab-e9b7-4855-8acb-42d5232cd002"
/> |
| _Dialog_ |

## Review instructions

1. Open `/organizations` or an organisation's `/org/<slug>` landing page
in the hosted Studio preview. Expect the compact notice.
2. Click **Learn more**. Expect the explanation and a link to the Terms
of Service. Escape closes the dialog without dismissing the notice.
3. Choose **Got it**, then reload. The notice stays dismissed. Repeat in
a fresh browser profile using **Close banner**.
4. Open a project or an organisation settings page. The notice should
not appear.
2026-10-07 09:09:01 +11:00
claude[bot]andClaude fb382b3018 Add Terms of Service v4 (effective October 5, 2026) (#51107)
<!-- ccr-slack-attribution -->
_Requested by **Nicole Kramer** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_

## Problem

Commercial & Product Counsel supplied a new version of the Supabase
Terms of Service to be published as Version 4, effective October 5, 2026
(the same date the Enterprise Terms v4 update takes effect, once the
code freeze lifts).

## Solution

Adds `apps/www/data/legal/terms/v4.mdx` with the new agreement text
(transcribed from the supplied source document) and registers it as the
newest version in `apps/www/pages/terms.tsx`'s versions array, dated
October 5, 2026. Versions 1-3 are untouched. The new text also defines
"Supplemental Terms" and links it, at the one point the source
hyperlinks it, to `/legal/customer-resources/supplemental-terms`.

## Review instructions

1. Open the Vercel preview link for `/terms` below.
2. Confirm "Version 4" appears as the newest tab/version, dated October
5, 2026, with the updated agreement text.
3. Do not merge — this PR is held until the code freeze lifts on October
5, 2026 (see PRs #51100 and #51106 for the related Enterprise Terms /
Supplemental Terms work landing the same day).

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC


---
_Generated by [Claude
Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-07 09:07:10 +11:00
claude[bot]andClaude c006499d48 Add Enterprise Terms v4 (effective October 5, 2026) (#51106)
<!-- ccr-slack-attribution -->
_Requested by **Nicole Kramer** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_

## Problem

The Enterprise SaaS Subscription Agreement at `/enterprise-terms` needed
a new version reflecting legal's latest draft, which introduces a
"Supplemental Terms" defined term, a standalone "Supabase"
contracting-entity definition (to support marketplace purchases), a new
Beta Releases warranty carve-out, and related marketplace billing/refund
language.

## Solution

Before: `/enterprise-terms` had three versions (v1–v3), with v3 dated
August 1, 2026, and no concept of "Supplemental Terms" anywhere in the
agreement.

After: adds **Version 4, effective October 5, 2026** as the newest entry
in the page's `versions` array (v1–v3 untouched):

- `apps/www/data/legal/enterprise-terms/v4.mdx` — new versioned MDX,
transcribed from legal's source document and following this directory's
existing formatting conventions (bold section numbers/defined terms,
`##`/`###` headings, no frontmatter or h1 — the h1 is rendered by
`PageHeader`).
- `apps/www/pages/enterprise-terms.tsx` — imports `v4.mdx` and adds it
to the front of the `versions` array with `effectiveDate: 'October 5,
2026'`.

How: the new v4 text is a faithful transcription of legal's draft onto
the existing v3 structure, so the diff is easy to review against v3 —
the substantive additions are the "Supabase" entity definition (1.9),
the "Supplemental Terms" defined term (1.13) and its references in
Section 2.1 (license scope) and Section 14.1 (order of precedence), a
new Section 10.5 (Beta Releases), and marketplace-related payment/refund
language in Section 5.1. The "Supplemental Terms" defined term is a live
markdown link to the new `/legal/customer-resources/supplemental-terms`
page (shipped separately in #51100) at its point of definition (Section
1.13), matching how the source document hyperlinks it.

## Review instructions

1. Open the `zone-www-dot-com` preview's `/enterprise-terms` page and
confirm the version selector defaults to "Version 4 — October 5, 2026".
2. Confirm Section 1.13 "Supplemental Terms" renders as a live link to
`/legal/customer-resources/supplemental-terms`.
3. Confirm Version 3 (and v1–v2) still render unchanged via the version
selector.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] N/A — no docs topic edited (this is versioned legal content, not
`apps/docs`)

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-07 09:06:49 +11:00
363dbdf1ad Use Flick Games' real logo files (#51364)
## Problem

#51285 (Flick Games case study) merged before the customer's actual logo
files were in hand. It shipped with a derived black/white wordmark
instead.

## Solution

Swaps in the real brand assets Ian Masters sent directly
(`FLICK_black_2048.png` / `FLICK_white_2048.png`) for
`on-light`/`on-dark` at `apps/www/public/images/customers/logos/`.
Tracked in
[MARKET-2252](https://linear.app/supabase/issue/MARKET-2252/case-study-flick-games-sept-23).

## Review instructions

1. Open the preview link for `/customers/flick-games`.
2. Check the logo renders correctly in both light and dark mode.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-06 14:19:34 -07:00
Charis ab383421c5 fix(studio): show sign-in banner based on Dashboard component [FE-3443] (#51283)
## Summary

* Makes sign-in banner visible on unauthenticated pages
  * Show only when one of the affected components is Dashboard
  * Works only when new status page (under feature flag) is being used
* Regression fix: Auth pages without the status banner (sign-up,
sign-in-mfa, sign-in-recovery-code, sign-in-sso, sign-in-partner,
forgot-password, forgot-password-mfa, reset-password) no longer reserve
dead space at the top for a banner they don't render

## Test plan

- [X] TypeScript: `tsc --noEmit` passes clean, no type errors
- [X] Unit tests: All new/existing tests pass in
`apps/studio/lib/status-page/status-page.utils.test.ts` and
`apps/studio/components/layouts/AppLayout/StatusBanner.utils.test.ts`
(697 files / 7833 tests, no regressions)
- [X] Manual verification: Sign-in page still renders the banner
correctly when an incident affecting Dashboard is active; no layout
regression

**Related:**
[FE-3443](https://linear.app/supabase/issue/FE-3443/only-show-sign-in-incident-banner-when-relevant)
2026-10-06 15:56:48 -04:00
Charis 28f59449c3 [FE-4543] fix(studio): remove outdated resize downtime warning (#51344)
## Summary

Removes the "Resizes may require more downtime than normal on this
project." warning from the disk/compute review dialog. This warning was
added for cross-architecture migrations during resize operations, which
are no longer performed, and has caused unnecessary customer support
inquiries.

## Closes
FE-4543

https://linear.app/supabase/issue/FE-4543
2026-10-06 15:34:15 -04:00
Connor Davis 32b16b7397 Add Connor Davis to humans.txt (#51360) 2026-10-06 15:21:43 -04:00
Lovro Mažgon 1a992761c1 chore(docs): Add Lovro Mažgon to humans.txt (#51354)
Add myself to humans.txt
2026-10-06 18:44:08 +02:00
John Jarvis 9a4ab14be2 chore: add John Jarvis to humans.txt (#51182)
## Problem

John Jarvis is missing from `humans.txt`.

## Solution

Add John Jarvis to `apps/docs/public/humans.txt`.

## Review instructions

Confirm the name is spelled correctly in the team list.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added John Jarvis to the team list.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-06 09:34:55 -07:00
Ivan VasilovandClaude Sonnet 5.5 9d1661dec1 chore: Reorganize the Files buckets code (#51350)
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-06 15:29:35 +00:00
Jordi Enric c0c51dc168 test(logs): stabilize pathname refresh assertion DEBUG-230 (#51351)
## Problem

The Studio unit test added in #51112 failed on master because the
`/after` element returned by `findByText` was detached by a rerender
before `toBeInTheDocument` ran. The failure repeated across all three
test attempts in [this
job](https://github.com/supabase/supabase/actions/runs/37480673016/job/112327649118).

## Fix

Retry the DOM lookup and assertion together with `waitFor`, so each
attempt checks the current element synchronously. Keep the existing
timeout and assertions covering pathname refresh before the URL updates.

## How to test

- Run `pnpm --filter studio exec vitest run
components/interfaces/UnifiedLogs/UnifiedLogs.test.tsx`.
- Expected result: pathname options refresh after selecting POST and the
test passes.
- Prettier and `git diff --check` pass. Local Vitest was blocked before
assertions by the available dependency tree using React 18 instead of
React 19; ESLint was blocked by a missing `@eslint/compat` dependency.
CI validation is pending.
2026-10-06 09:11:00 -06:00
Jordi Enric d2ffd76395 perf(logs): load pathname facet counts on demand DEBUG-230 (#51112)
## Problem

Unified Logs included a pathname aggregation in every initial sidebar
count query, even when the pathname filter was closed. This issue is
tracked in
[DEBUG-230](https://linear.app/supabase/issue/DEBUG-230/fetch-sidebar-counts-only-when-needed).

## Fix

Remove pathname aggregation from the initial ClickHouse and BigQuery
count queries while keeping the existing shared count scans. Fetch
scoped pathname options through the existing facet query when the filter
opens or its search changes. Order limited pathname results by count,
validate response rows with Zod, and retain selected paths during
loading and validation errors. Use live sidebar filters while their URL
update is pending and URL filters after navigation. Cache results by
project and filter scope, and wait for feature flags before requesting
options.

## How to test

- Open Unified Logs, then open Pathname and search. Confirm options load
on demand.
- Change the time range, another filter, or navigate through browser
history. Confirm the options reflect the current scope.
- Close and reopen Pathname without changing the scope. Confirm cached
options return.
- Run the pathname filter component tests and Studio typecheck.
2026-10-06 16:38:30 +02:00
Pamela Chia 240e954390 fix(www): fix partners links and 404 redirects (#51294) 2026-10-06 07:14:38 -07:00
Joshen Lim eb20a4674d getTableDefinitionSql to escape SQL identifiers (#51258)
## Context

Similar to domain to https://github.com/supabase/supabase/pull/51256 -
`getTableDefinitionSql` doesn't escape SQL identifiers, which generates
invalid SQL on the dashboard's table editor for the "Copy table schema"
CTA, or the table definition tab.

Also fixes the "Copy table schema" CTA which was missing the `scoped`
parameter when calling `getTableDefinition`

Changes here addresses this issue, can test with a table named like
`test"table`
2026-10-06 21:34:36 +08:00
K-Dog (Kevin) 1da25a7e72 chore(hipaa): self-serve PITR (#51342)
There is no reason why HIPAA customers cannot self-serve PITR add-on.
Instead of telling customers to reach out to support, let them
self-serve it.

- Docs also wrongfully stated the need for Small compute add-on.
- Ability to self-serve PITR
- Only 28-day PITR available
- Price is now also correct and displays $0 (pending backend change)

When enabled (marked as HIPAA compliant):
<img width="1128" height="216" alt="Screenshot 2026-10-06 at 1 53 01 PM"
src="https://github.com/user-attachments/assets/d83982e7-c71b-4236-ab29-67f85fc40f39"
/>

When not enabled (marked as HIPAA compliant):
<img width="1132" height="255" alt="Screenshot 2026-10-06 at 1 53 55 PM"
src="https://github.com/user-attachments/assets/f182813b-2163-4905-8cdf-9c69983ec1b9"
/>

<img width="772" height="542" alt="Screenshot 2026-10-06 at 1 56 08 PM"
src="https://github.com/user-attachments/assets/2cd59439-74b9-49d6-90d1-47c8d1722c9f"
/>
2026-10-06 15:11:55 +02:00
Joshen Lim 23e7bbcdc6 Joshenlim/fe 3359 fix user permission UI for orgs with thousands of projects (#51329)
## Context

Adds virtualization to the organization team members page - browser
performance was facing issues for organizations with a large amount of
members (e.g 1000+), primarily due to some computation within
`MemberActions.tsx`, so virtualization addresses this by controlling the
number of member rows being rendered in the DOM at any one time.

<img width="1182" height="435" alt="image"
src="https://github.com/user-attachments/assets/e3da7036-c1c8-4d73-a363-85ecbdb79179"
/>


## Unrelated changes
- Updated `TeamSettings` to use the `PageContainer` components for UI
consistency
- Updated user `ProfileImage` to render the first alphabet of the email,
rather than a generic user icon
<img width="275" height="126" alt="image"
src="https://github.com/user-attachments/assets/17eae3b1-c527-4b8f-afcd-c5151bdaf869"
/>
- Updated row heights of member rows to be more smaller
- Updated MFA column to use tooltips with a clearer CTA for members that
don't have MFA enabled
<img width="332" height="144" alt="image"
src="https://github.com/user-attachments/assets/a479af31-7fec-454d-b64e-e6314fd6d55e"
/>
- Added a filter for MFA status  
<img width="375" height="177" alt="image"
src="https://github.com/user-attachments/assets/fd87105e-524d-4ded-b471-769592be96c7"
/>


## To test
- Can override the content for the `members` network request with the
following sample JSON, main thing is just to test that initial load +
searching should not run into any significant browser performance
issues.

[members-response-1000.json](https://github.com/user-attachments/files/33100317/members-response-1000.json)
- Can also test on production that this mock response does indeed cause
browser performance issues as well
2026-10-06 06:41:39 -06:00
6ecf98671a docs(platform): add Platform Webhooks guide and event catalog (#51098)
## Problem

Platform Webhooks (org- and project-level event notifications over the
Management API) has no public documentation. CTRL-1017 asks for a docs
page plus a specification of the available event types, so partners can
integrate without reading the OpenAPI spec or asking engineering
directly.

Closes CTRL-1017.

## Solution

**New guide covering the Management API path, plus an event catalog.**

Adds `apps/docs/content/guides/platform/webhooks.mdx`: concepts and
scoping, creating an endpoint, Standard Webhooks signature verification
and secret rotation, test events, and delivery/retry/ordering behavior.

Adds `apps/docs/content/guides/platform/webhooks/events.mdx`: the events
reference.

- Full payload documentation for the 8 project-lifecycle event types,
and a name-and-trigger table for the 12 branch, member, and billing
types whose payload fields aren't documented.
- Documents `*` for subscribing to every event.
- Access framing states the criterion: available to organizations on an
early access allowlist, with the `403` / `access_disabled` response for
everyone else.
- Nav entry under Platform > Project & Account Management, after
Personal Access Tokens, gated by `fullPlatformEnabled`.

**The page deliberately omits the dashboard UI.** See the first row of
the table below.

## Needs review before merge

| Item | Detail |
|
--------------------------------------------------------------------------------------------------
|
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
|
| **The Studio webhooks UI is not wired to the API, so this page
documents the Management API only** | `PlatformWebhooksPage.tsx:29`
imports `PLATFORM_WEBHOOKS_MOCK_DATA`; `PlatformWebhooks.store.ts` has
no async or network code and hardcodes `createdBy:
'mock-user@supabase.io'`; nothing in `apps/studio` references
`webhooks/endpoints` or `webhooks/deliveries`, even though
`api-types/types/api-v2.d.ts` carries those paths 24 times. #43276
(DEPR-340) described it as "UI-only (with mock data)", and the
`DEPR-340-backend-integration-tracker.md` it pointed to is no longer in
the tree. A dashboard section can be added once the UI calls the API. |
| Possible reference slug collision | Project- and org-scoped operations
share identical `summary` values (both "Create endpoint", both "List
endpoints"). The page links to the reference introduction and names the
**Project webhooks** / **Organization webhooks** tags rather than
deep-linking a generated page. |

## Preview links

**Verified:** the new page returns 200 on the preview; the same path
returns 404 on production, confirming net-new content; the nav entry
renders on the preview build.

### Proof: new page renders on the PR preview

[Open the new page on
preview](https://docs-git-nikrichers-ctrl-1017-set-up-public-doc-fa3960-supabase.vercel.app/docs/guides/platform/webhooks)

<img width="2295" height="8039" alt="Screenshot 2026-10-05 at 11-47-06
Platform Webhooks Supabase Docs"
src="https://github.com/user-attachments/assets/7b1440d3-207d-4828-8593-77140bdcd73f"
/>

<img width="2295" height="12000" alt="Screenshot 2026-10-05 at 11-48-49
Platform Webhook Events Supabase Docs"
src="https://github.com/user-attachments/assets/2808a88e-558e-4f73-a12a-01382cd3f6a2"
/>


## Review instructions

1. Open the [PR
preview](https://docs-git-nikrichers-ctrl-1017-set-up-public-doc-fa3960-supabase.vercel.app/docs/guides/platform/webhooks)
and confirm the page renders as shown.
2. Confirm **Platform Webhooks** appears under **Platform > Project &
Account Management** in the sidebar, after **Personal Access Tokens**.
3. Confirm the five internal-guide values in the second row of the
needs-review table.
4. Decide with the Control Plane team whether the Studio UI ships wired
to the API, which determines when a dashboard section gets added: Studio
UI is slated for Q4, so it will not be shipped together.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a Platform Webhooks guide covering endpoint setup, event
delivery, signature verification, test events, retries, retention,
idempotency, ordering, and listener best practices.
* Documented project and organization event types, payload schemas,
event scopes, and versioning, plus access restrictions for organizations
outside the allowlist.
* **Navigation**
* Added Platform Webhooks links, including Overview and Events, to the
platform navigation when the full platform is enabled.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
Co-authored-by: Paweł Gulbinowicz <pawel.gulbinowicz@supabase.io>
Co-authored-by: Paweł Gulbinowicz <zamotany@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-10-06 14:30:16 +02:00
089133cc2c feat(storage): add bucket object versioning form fields (FE-4161) (#49203)
| # | Branch | Base |
| - | ------ | ---- |
| 1 | `feat/storage-versioning-private-alpha` — merged | `master` |
| 2 | `feat/storage-versioning/002-bucket-form-fields` ◀ | `master` |
| 3 | `feat/storage-versioning/003-bucket-modals` | 2 |
| 4 | `feat/storage-versioning/004-object-versions-data` | 3 |
| 5 | `feat/storage-versioning/005-file-preview-versions` | 4 |
| 6 | `feat/storage-versioning/006-billing-storage-retention` | 5 |
| 7 | `feat/storage-versioning/007-archived-objects-data` | 6 |
| 8 | `feat/storage-versioning/008-archived-rows` | 7 |
| 9 | `feat/storage-versioning/009-archived-preview-pane` | 8 |
| 10 | `feat/storage-versioning/010-replace-file` | 9 |

## [2/10] Storage object versioning: bucket form fields

The object versioning + lifecycle policy form section for the create and
edit bucket modals.
Mounted onto the ui in PR 3 #49205 

- `BucketVersioningFields` — the versioning switch and the suspension /
public-bucket / retention-tightening warnings
- `LifecyclePolicySection` — the retention window and version cap inputs
- `ExpirationModeToggle` — how the two conditions combine (and / or)
- `BucketVersioningFields.schema.ts` — zod fields the parent modals
spread into their own schema, plus `superRefineBucketVersioning`
- `BucketVersioningFields.utils.ts` — retention-tightening detection
- `StorageVersioning.constants.ts` — versioning state and expiration
mode types, the prefill defaults, and `getBucketVersioningState`

Note: a single s3 lifecycle policy expects both `version_expiry_days`
and `max_noncurrent_versions` and always evaluate the two fields within
the same policy with an AND logic. To enable both AND and OR/EITHER
logic, we save two distinct s3 policies so we can enforce the OR logic.

See demos and how to reproduce in #49205 

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **New Features**
* Eligible projects with the preview enabled can configure object
versioning for storage buckets, including version expiration,
retained-version limits, and “and/or” lifecycle conditions.
* Settings default to 30 days and 10 retained versions, with validation
for retention values and requirements for setting a version limit.
* Notices highlight public buckets, missing lifecycle conditions,
suspending existing versioning, and changes that tighten retention
limits.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-06 14:24:50 +02:00
Illia Basalaiev 12afe39999 Docs/troubleshoot pg net privileges (#51275)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

New troubleshooting guides related to the current pg_net and pg_dump
extensions' behaviour.

## What is the current behavior?

## What is the new behavior?

Preview:
- [Revoking access to pg_net objects has no effect: no privileges could
be
revoked](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/revoking-access-to-pg_net-objects-has-no-effect-0bbc16)
- [Database roles can read request headers queued by
pg_net](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/database-roles-can-read-request-headers-queued-by-pg_net-ad6357)
- [pg_dump fails with 'query would be affected by row-level security
policy'](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/pg_dump-fails-with-query-would-be-affected-by-row-level-security-policy-1d5783)
- [Custom role inherits privileges that were not explicitly
granted](https://docs-git-docs-troubleshoot-pg-net-privileges-supabase.vercel.app/docs/guides/troubleshooting/custom-role-inherits-privileges-that-were-not-explicitly-granted-ddaa1c)
2026-10-06 11:03:42 +02:00
Pamela Chia 20d752517f feat(docs): record search v2 rollout exposure (#51300) 2026-10-06 01:35:45 -07:00
Beng Eu 53a637a359 fix(studio): don't watch Next's .next build output in TanStack dev (#51308)
## Problem

Switching a local checkout from `STUDIO_FRAMEWORK=next` to `tanstack`
leaves `apps/studio/.next` behind, including a full `node_modules` copy
under `.next/standalone`. Vite's dev server watches all of it, logging
hundreds of `page reload .next/server/pages/...` lines and wasting file
handles.

## Change

Add `**/.next/**` to `server.watch.ignored` in
`apps/studio/vite.config.ts`. Vite's default ignores (`.git`,
`node_modules`) still apply.

## Verification

With a stale `.next` present, ran `STUDIO_FRAMEWORK=tanstack pnpm run
dev`, touched `.next/server/pages/account/me.html`: no reload logged
(previously ~220 `.next` reloads on startup).
2026-10-06 14:38:04 +08:00
Joshen LimandGildas Garcia dc95335a8d Joshenlim/fe 4068 warn users ai assistant history can be wiped (#51260)
## Context

Chats with the AI Assistant is currently stored locally on the browser
and not synced across devices which caused a bit of confusion for some
users when they realised they couldn't access their chat histories on
different devices. (Ideal state tbh is to persist the chat
conversations, but that'll need support on the BE)

PR here just adds a foot note to both the chat history dropdown in the
side panel + chat nav for the explorer regarding this - opting for
something with a small footprint
<img width="293" height="322" alt="image"
src="https://github.com/user-attachments/assets/284ee0c1-16bf-432b-b473-29ee048ed4cc"
/>
<img width="392" height="956" alt="image"
src="https://github.com/user-attachments/assets/e5eb1409-fa63-4dae-9439-86facbe41277"
/>

---------

Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-10-06 11:37:26 +08:00
Joshen Lim 2538f7eb29 Fix unescaped SQL identifiers in row export (#51256)
## Context

Resolves https://github.com/supabase/supabase/issues/49977

Addresses an issue in `formatTableRowsToSQL` to use `ident` for schema,
table, and column name which will handle escaping of SQL identifiers.

Can verify fix by creating a table like `test"table`, then adding some
rows, and selecting either Copy as SQL or Export as SQL
2026-10-06 11:35:01 +08:00
claude[bot]andClaude b6d4239010 Update Supplemental Terms placeholder text (#51301)
<!-- ccr-slack-attribution -->
_Requested by **Nicole Kramer** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_

## Problem

**Before:** The Supplemental Terms page
(`/legal/customer-resources/supplemental-terms`) says "Content coming
soon."

**After:** The page shows "Check here for any feature specific terms
that we may need to release, or clauses that allow for compliance with
geography specific laws that we may introduce."

## Solution

Replaces the placeholder body in
`apps/www/data/legal/customer-resources/supplemental-terms/v1.mdx` with
the supplied text, as a plain paragraph. Nothing else changes.

## Review instructions

1. Open the Vercel preview link for
`/legal/customer-resources/supplemental-terms`.
2. Confirm the page shows the new text instead of "Content coming soon."

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC


---
_Generated by [Claude
Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-06 03:20:55 +00:00
Joshen Lim be1ba651ed Add branching nav items to cmd k (#51255)
## Context

Adds a couple of branching nav items to Command K
- Create new branch
- Branch management
- Merge requests
- Github Connection (For branching)
- Branching feedback

Switch branch is still available, and only visible after a branch has
been created (status quo)

<img width="610" height="531" alt="image"
src="https://github.com/user-attachments/assets/3068184e-889d-44ed-8cf6-2afd59ffb109"
/>
2026-10-06 11:12:53 +08:00
Joshen Lim 642a02db49 Prevent enabling spend cap if org has projects with RRs (#51253)
## Context

Prevents organizations from enabling spend cap if the org has projects
with read replicas - We currently gate creation of read replicas to
ensure that orgs have spend caps disabled, but were missing the guard
for the other way around
<img width="662" height="378" alt="image"
src="https://github.com/user-attachments/assets/44ad036c-4c1b-48e8-beb7-f16f6170c9fb"
/>

## Other changes involved
- Refactored to use new `Sheet` and `Table` components in
`SpendCapSidePanel`
2026-10-06 11:12:35 +08:00
Pamela Chia 20d6f2197f chore(studio): remove privacy policy notice (#51299)
I removed the Studio Privacy Policy update notice that #50397 added on
2026-09-16, when Privacy Policy v4 took effect. It has been up for
almost three weeks, and the ToS v4 banner (#51109) goes out next. I did
the same in #44380, removing the March 2026 privacy notice after 15
days.

This is the exact inverse of #50397: the banner component and its test,
the banner ID, the dismissal local storage key, and the org-landing path
helper that only this notice used.

## To test

Tested on Vercel preview:
- [ ] In a fresh browser profile (no
`privacy-policy-update-2026-09-16-dismissed` key), open
`/organizations`: expect no Privacy Policy notice
- [ ] Open `/org/<slug>`: expect no Privacy Policy notice and the
project list renders normally
- [ ] Open a project's Logs page: expect the logs deprecation banner
behavior unchanged (only shows before its expiry)

## Linear
- fixes GROWTH-1322
2026-10-05 19:24:14 -07:00
claude[bot]andClaude a629c9c1ac Add hidden Supplemental Terms legal page (#51100)
<!-- ccr-slack-attribution -->
_Requested by **Nicole Kramer** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790784371448999)_

## Problem

No page existed yet for the upcoming "Supplemental Terms" document.
Nicole Kramer (Commercial & Product Counsel) needs a stable, linkable
URL to reference from future Terms of Service / Enterprise SaaS
Subscription Agreement updates, before the legal content itself is
ready. The page needs to be reachable by direct URL but not surfaced in
the visible Legal Hub nav yet, matching the existing "hidden" precedent
used for `/enterprise-terms`.

## Solution

Added a new page at `/legal/customer-resources/supplemental-terms`:

- `apps/www/pages/legal/customer-resources/supplemental-terms.tsx` — a
page component mirroring the existing Data Processing Addendum page
(`apps/www/pages/legal/customer-resources/data-processing-addendum.tsx`):
`DefaultLayout` + `PageHeader` (h1 "Supplemental Terms") +
`LegalDocVersions` rendering a single MDX version.
- `apps/www/data/legal/customer-resources/supplemental-terms/v1.mdx` —
placeholder body content (`_Content coming soon._`), no frontmatter/h1,
following this repo's existing legal MDX convention (the h1 is rendered
by `PageHeader`, not the MDX itself). Nicole will fill in the actual
legal content later.

**On "hidden":** I investigated the actual codebase state before
implementing, since the two precedents named didn't turn out to work the
same way:
- `/enterprise-terms` is genuinely hidden — it is not linked anywhere in
`apps/www/pages/legal/index.tsx`'s Legal Hub listing, and its `NextSeo`
meta sets `noindex: true, nofollow: true`.
- The Data Processing Addendum and Subprocessor List pages, by contrast,
**are** linked in the visible Legal Hub listing
(`apps/www/pages/legal/index.tsx`, "Customer Legal Resources" section) —
they are not hidden today.

Given that, this PR mirrors the DPA/Subprocessor List *structural*
pattern (route under `/legal/customer-resources/`, page-component +
versioned-MDX content) since that's what "under Customer Legal
Resources" means structurally in this codebase, but mirrors
`enterprise-terms`' *hidden* mechanism: the new page's `NextSeo` meta
sets `noindex: true, nofollow: true`, and — importantly — **no entry was
added** to the `sections` array in `apps/www/pages/legal/index.tsx`, so
it does not appear in the visible Legal Hub or any nav. The page is
reachable only via its direct URL.

Terms of Service and the Enterprise SaaS Subscription Agreement pages
were not touched.

## Review instructions

1. Confirm `/legal/customer-resources/supplemental-terms` renders with
h1 "Supplemental Terms" and placeholder body text.
2. Confirm the page does **not** appear anywhere on `/legal` (the Legal
Hub listing).
3. Confirm `apps/www/pages/terms.tsx` /
`apps/www/pages/enterprise-terms.tsx` (and their MDX content) are
unchanged.

## Checklist

- [x] I have read CONTRIBUTING.md
- [ ] N/A — no docs topic edited (legal page content is a placeholder,
not docs content)

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC

---
_Generated by [Claude
Code](https://claude.ai/code/session_01K2vqszbsJiMJPABAnLMgaC)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-06 13:09:25 +11:00
Pamela Chia 81da60392e feat(www): add multigres alpha form to /database (#51298)
The Multigres private alpha request form only lives at
/go/multigres-early-access (#51053), and nothing on the product site
links to it. I added the same form to /database, the way /compute embeds
its waitlist form.

The new section sits at the bottom of the page, directly above the
closing "Start your project" CTA: the go page's hero copy, the alpha
caveats, and a "Learn about Multigres" link to multigres.com on the
left, the form on the right. Fields, disclaimer, and redirect are read
from the go page definition. The form posts `{ slug:
'multigres-early-access', formId: 'form' }`, so the server resolves the
existing CRM config and submissions land in the same database as the go
page.

**Note:** the section throws at build time if the go page or its form
section is removed, so retiring the go page means removing this section
in the same change.

## To test
Tested on Vercel preview:
- [ ] Open /database and scroll to the bottom: expect a "Private alpha /
Multigres on Supabase" section directly above "Build in a weekend, scale
to millions", with the email and organization slug form, the alpha
caveats, and the Privacy Policy disclaimer
- [ ] Click "Learn about Multigres": expect multigres.com to open in a
new tab
- [ ] Resize to a phone width: expect the text stacked above the form
card with no horizontal scroll
- [ ] Open /go/multigres-early-access: expect its page and form
unchanged
- [ ] After merge, submit a test request from supabase.com/database:
expect a redirect to /go/multigres-early-access/thank-you and a new row
in the Multigres requests database

## Linear
- fixes GROWTH-1321
2026-10-05 18:50:48 -07:00
Ignacio Dobronich 22cdd05492 fix: update disk maxSize in pricing page (#51295) 2026-10-05 22:46:23 -03:00
Aditya MaruvadaandAditya Maruvada d21c20eae6 docs: add Multigres early access request link to the Multigres docume… (#51297)
…ntation

## Problem

Currently there's no way for users to request access to private alpha
for Multigres.

## Solution

Add a link to the form to fillout for customers to get access.


## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [X] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

Co-authored-by: Aditya Maruvada <aditya@Adityas-MacBook-Pro.local>
2026-10-05 17:16:16 -07:00
Danny White 5cc0450950 fix(www): plate State of Startups Sign in over the aurora (#51163)
## Problem

On `/state-of-startups`, the nav starts transparent over the aurora.
Default buttons use a translucent fill in dark mode, so Sign in (and
Dashboard) look see-through.

## Solution

Wrap those default nav buttons in `FloatingPlate`. Primary “Start your
project” is already opaque and unchanged.

| Before | After |
| --- | --- |
| <img width="1024" height="759"
alt="23474_296a1f8f952ae7f73ae9205e5db6bb9cda4cf0a904bc2d440d6395b5f12346ab"
src="https://github.com/user-attachments/assets/c247cdaa-06b0-46ad-b1f8-cee3e06fde8e"
/> | <img width="1024" height="759" alt="State of Startups 2026
Supabase"
src="https://github.com/user-attachments/assets/e9a1a0e0-9f2f-427f-a7d3-75e4e1cbba63"
/> |

## Review instructions

In dark mode:

1. [Live /state-of-startups](https://supabase.com/state-of-startups) ·
[Preview
/state-of-startups](https://zone-www-dot-com-git-dnywh-fixsos-sign-in-float-91d2b1-supabase.vercel.app/state-of-startups)
2. At the top of the page (transparent nav, before scrolling), check
Sign in: opaque plate, aurora does not show through the fill.
3. Scroll until the nav gains a solid background: Sign in should still
look normal.

Ideally you could sign in and confirm the now ‘Dashboard’ button gets
the same plate treatment. But that’s not possible until merge.
2026-10-06 10:46:59 +11:00
Danny White 36364e7df3 fix(www): stop wrapping oklch semantic tokens in hsl() (#51161)
## Problem

Semantic colour tokens (`--border-*`, `--foreground-*`,
`--background-*`) now resolve to full `oklch(...)` values. Call sites
that still wrapped them in `hsl(var(--…))` are invalid CSS and drop the
colour (Partners ambient grid was the clearest case).

Brand / destructive / warning channel tokens still correctly use
`hsl(var(--…))` and were left alone.

Presence avatar stack polish is in
https://github.com/supabase/supabase/pull/51164.

## Solution

- Use bare `var(--…)`, `currentColor`, or Tailwind utilities for
semantic tokens. Opacity cases use `oklch(from var(--…) l c h / …)`.
- Partners grid: fix, and then use `text-foreground/20` in light,
`text-foreground/30` in dark for optical correction.

| Before | After |
| --- | --- |
| <img width="1860" height="1106" alt="CleanShot 2026-10-02 at 16 29
08@2x"
src="https://github.com/user-attachments/assets/4554b0c9-22cf-4b06-bbe3-798e8b15304e"
/> | <img width="1852" height="1112" alt="CleanShot 2026-10-02 at 16 28
44@2x"
src="https://github.com/user-attachments/assets/20ccbc80-5eaa-49e6-8f94-48b99dc01474"
/> |
| <img width="1024" height="759" alt="20701"
src="https://github.com/user-attachments/assets/a4e578cf-5adb-4f7a-a53b-870a51f5f948"
/> | <img width="1024" height="759" alt="59176"
src="https://github.com/user-attachments/assets/dda3fc2d-d86b-45a5-adca-403223cc5f33"
/> |

## Review instructions

1. [Live /partners](https://supabase.com/partners) · [Preview
/partners](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/partners).
Ambient dashed grid under the hero (light and dark).
2. [Live /database](https://supabase.com/database) · [Preview
/database](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/database).
Postgres elephant idle outline should be muted grey, not black. Hover
still brand green.
3. [Live /state-of-startups](https://supabase.com/state-of-startups) ·
[Preview
/state-of-startups](https://zone-www-dot-com-git-dnywh-fixhsl-oklch-semanti-9bc03a-supabase.vercel.app/state-of-startups).
Chart **More AI-generated code, less likely to be monetizing yet**:
horizontal gridlines at 0/25/50/75/100% should render.
4. Storage / Edge Functions changes are correctness-only (shadows, idle
borders, a top fade). Near-invisible to the naked eye; skip unless
debugging.
2026-10-06 10:28:36 +11:00
Danny White 0cb8bd95dd feat(studio): add spot colour control to Appearance (#50782)
## Problem

The theme's primary hue can change in CSS, but Appearance had no way to
try other spot colours. That makes it hard to find controls whose colour
still depends on the fixed Supabase brand palette.

## Solution

Add a **Spot color** control under Appearance → Theme colors
(employee-only via ConfigCat `appearanceSpotColor`, targeted to Supabase
Team Email).

### Spot color UX
- Rainbow spectrum track with a thin outline so pale tracks stay visible
- Live trifecta swatches for `--primary-solid`, `--primary`, and
`--primary-bright` (darkest → lightest) next to the degree readout
- Drag updates are rAF-batched so React paint and CSS preview stay to
one frame

### Canvas tint coupling
- `--surface-hue` is derived in CSS as `calc(var(--primary-hue) +
var(--surface-hue-offset))`
- Dark: offset `0` (same hue as spot)
- Light: offset `180` (complementary canvas tint; brand green ≈157.5° →
rose ≈337.5°)
- No JS override of `--surface-hue`. Changing Spot color moves primary
controls and the low-chroma canvas tint together

### Other theme sliders
- Renamed **Color intensity** → **Surface tint** (it only drives the
neutral ramp via `--chroma`, not spot chroma)
- Meaning-shaped tracks for every knob (spectrum, grey→tint, soft→hard,
dark→light, flat→lift)
- Same outline treatment on those tracks

| Before | After |
| --- | --- |
| <img width="1476" height="2174" alt="CleanShot 2026-10-05 at 15 02
21@2x"
src="https://github.com/user-attachments/assets/d08b0fa8-32af-450e-adce-861f59c9d6ca"
/> | <img width="1474" height="2354" alt="CleanShot 2026-10-05 at 14 56
35@2x"
src="https://github.com/user-attachments/assets/9a1e6183-a4ba-4c8e-a458-bb0eea946db8"
/> |
| _Anyone else_ | _With staff flag, custom settings_ |

## Review instructions

1. Confirm ConfigCat flag `appearanceSpotColor` is on for your staff
account (or flip it in the Dev Toolbar).
2. Open `/account/me` → **Appearance → Theme colors**.
3. Without the flag: Spot color is hidden; other theme sliders still
work.
4. With the flag: drag Spot color in light and dark. Primary controls
and canvas tint should move together; Supabase brand assets should stay
fixed.
5. Raise Surface tint and confirm the canvas hue follows the
complementary (light) or same-hue (dark) offset.
6. Refresh, switch modes, and use **Reset** to check persistence and
defaults.
2026-10-06 10:11:26 +11:00
Miranda Limonczenko 17512de71d docs(database): connect security definer to the default execute grant (#50817)
Closes DOCS-1319

Part 4 of 4 in stack #50823. This PR carries **additions**: content the
page never had.
Style, structure, and snippet fixes land below it in #50820, #50821, and
#50822.

## Problem

Developers and AI agents read the Database functions guide. The guide
shows how to write a function inside the database.

A function runs in one of two modes. In `invoker` mode it runs as the
caller. In `definer` mode it runs as the creator.

The guide gives one rule for `definer` mode. The rule is to set the
`search_path`. A reader who obeys that rule still gets an unsafe
function.

I wrote a function that obeys the rule. I pinned the search path to the
empty string. Then I called it three times.

| Caller | Result |
| --- | --- |
| The order's owner | 4330 cents, correct |
| A different signed-in customer | 8660 cents, another customer's order
|
| Nobody, no session at all | 8660 cents |

Every role can call a new function in `public`. The guide states that
fact under Function privileges. It never connects the fact to the
`definer` rule. A reader has no reason to look.

Customers report the same failure. AI tools choose `definer` mode. The
function then answers the front end with no session. The hole is hard to
find, because no policy is involved in it.

## Solution

- **Joins the two halves in the Security definer subsection.** A
`danger` admonition states three facts:
  - The function runs with its creator's privileges.
- A function created in the Dashboard or by a migration is owned by
`postgres`, which bypasses Row Level Security.
  - Every role can call the function by default.

The admonition then gives the fix. Check ownership inside the function
body, and narrow the execute privilege as well.

- **Applies the regrant to both ways of restricting execute.** The
`grant execute` block sat inside the second way. A reader who took the
first way saw no way to restore their own app's access.

**Not changed:** the existing definer paragraph, the page structure, and
the Function privileges statements. The lower PRs in the stack own
those.

**No eval re-run.** The guide scored 6 of 6 on three baseline runs, so
the score has no room to move. All three runs chose `invoker` mode. The
eval never enters the branch this PR fixes. Measuring it needs a new
check, not a re-run.

**Diff size:** one file, 15 lines added and 4 removed.

## Manual testing

1. Open the [Security definer vs invoker
section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker)
on the deploy preview. The admonition renders as a red `danger` panel
below the definer paragraph. The two fixes appear as bullets.
2. Click the `Function privileges` link inside the admonition. It jumps
to the [Function privileges
section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#function-privileges)
on the same page.
3. Read that section. The `grant execute` block sits after the numbered
list. It applies to both ways of restricting execute.
4. Run `pnpm build:guides-markdown` from `apps/docs`. Read
`apps/docs/public/markdown/guides/database/functions.md`. The admonition
appears as a `Danger:` paragraph. Discard the `manifest.json` change.
5. Run `npx prettier --check
apps/docs/content/guides/database/functions.mdx`. Clean.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded guidance on the security risks of `security definer`
functions, including their privileges, interaction with Row Level
Security, and default execution access.
* Added recommendations for checking data ownership and restricting
execution to intended roles.
* Clarified that pinning `search_path` does not limit execution
privileges.
* Presented the function-privileges example separately from the
default-privileges instructions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions)
| `every signed-in caller` |

## Review instructions

This PR adds one admonition and moves one code block. The question is
whether the admonition is correct and whether an agent reading the page
would act on it.

1. Open the preview at [Security definer vs
invoker](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker).
A red `danger` panel sits below the definer paragraph.
2. **Read the first paragraph for accuracy.** It claims the function
runs with its creator's privileges, that a function created in the
Dashboard or by a migration is owned by `postgres`, and that `postgres`
bypasses Row Level Security. This matches [Use security definer
functions](https://supabase.com/docs/guides/database/postgres/row-level-security#use-security-definer-functions)
in the RLS guide. Flag any drift.
3. **Read the two bullets for sufficiency.** The ownership check is the
primary fix. The execute grant is listed as a complement, not an
alternative, because granting to `authenticated` still returns any
user's row to every signed-in caller. Confirm the wording can't be read
as "either one is enough."
4. Click the `Function privileges` link inside the admonition. It jumps
down the same page.
5. In the Function privileges section, confirm the `grant execute` block
sits after the numbered list rather than inside item 2, so it applies to
both ways of restricting execute.
6. **Check the agent-facing copy.** Open [the markdown
export](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions.md)
and find `Danger:`. This is what an agent reads, and it is the audience
this PR exists for.

**If you only have two minutes:** do steps 3 and 6. Step 3 is the
correctness of the advice. Step 6 is whether the audience that prompted
the ticket actually receives it.

**A note on running SQL from this page.** Don't hand-paste from the
rendered page. Blocks are split across tabs, and the Data tab in
Returning data sets holds markdown tables that look pasteable but are
not SQL. Use the `.md` export of the page, which flattens every tab in
page order. #50822 has a copy-paste command for this.
2026-10-05 15:18:01 -07:00
Miranda Limonczenko d8b0a3e87f docs(database): make the guide's snippets run in document order (#50822)
Part 3 of 4 in stack #50823. This PR carries **technical revision
only**: claims that produce a wrong outcome for a reader.

## Problem

This PR came from running a technical assessment using `/test-the-docs`.

A reader pastes the guide top to bottom. Two snippets fail.

The `planets` table uses a `serial` primary key, then the seed sets ids
explicitly. Explicit ids don't advance the sequence, so it stays at 0.
The `add_planet('Jakku')` example then draws id 1, which the seed
already used:

```
ERROR:  duplicate key value violates unique constraint "planets_pkey"
DETAIL:  Key (id)=(1) already exists.
```

The `security definer` example re-creates `hello_world` with `create`
rather than `create or replace`, so it collides with the function from
Basic functions:

```
ERROR:  function "hello_world" already exists with same argument types
```

The Data tab spells the planet Tatooine. The SQL tab spells it Tattoine.

Two debugging snippets read `attendance_table` and `some_table`. No
fence creates either, and neither is marked as omitted.

## Solution

- **Seeds `planets` and `people` without explicit ids.** The sequence
advances, so `add_planet` succeeds. This also settles Tattoine against
Tatooine.
- **Uses `create or replace` in the definer example**, so it no longer
collides.
- **Marks the two assumed tables** in the debugging snippets with a
comment.
- **Points the CREATE FUNCTION link at the current Postgres docs.** It
pointed at 9.1, while the intro already links the current version of the
same page.

**Verification.** I ran every `sql` fence from the guide in document
order against Postgres 15 in a throwaway container, with `anon` and
`authenticated` created first. Before these changes, two fences errored.
After them, the sequence runs clean.

## Manual testing

1. Start a throwaway Postgres: `docker run --rm -d --name pgcheck -e
POSTGRES_PASSWORD=pw postgres:15`.
2. Create the Supabase roles the guide references: `docker exec -i
pgcheck psql -U postgres -c "create role anon; create role
authenticated;"`.
3. Paste every `sql` block from the guide, in page order, into `docker
exec -i pgcheck psql -U postgres`. No statement errors.
4. Run `select * from planets;`. Tatooine, Alderaan, Kashyyyk, and
Jakku, with sequential ids.
5. Remove it: `docker rm -f pgcheck`.

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/functions)
| `('Tatooine')` |
| Docs | New page, 404 in production |
[/docs/guides/database/debugging-functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/debugging-functions)
| `assumes an attendance_table` |




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
  - Clarified the required column types in database function examples.
- Expanded guidance on function return values, including `INSERT`,
`UPDATE`, and `DELETE` statements with `RETURNING` clauses.
- Updated SQL examples to show table creation and automatically
generated IDs, corrected the spelling of “Tatooine,” and refreshed the
PostgreSQL reference link.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:18:00 -07:00
Miranda Limonczenko 8b148f93c1 docs(database): regroup the database functions guide and split out debugging (#50821)
Part 2 of 4 in stack #50823. This PR carries **structure only**: moves,
regrouping, and the connective text the new shape needs. Reworded prose
already landed in #50820.

## Problem

This PR is running a structure edit.

A reader arrives from search and has to find one thing. The guide gave
them eight top-level headings, no grouping, and no opening outline. The
style guide caps a group at 5 ± 1.

Four of those headings are the action path: Getting started, Basic
functions, Returning data sets, and Passing parameters. Nothing marked
them as one sequence.

`Suggestions` held four unrelated things: an Edge Functions comparison,
two security topics, and a three-part debugging reference. The heading
names nothing the reader is doing.

Debugging was the largest thing on the page. It sat at H3 with three H4
children, and it shared only the word "function" with the rest of the
guide.

## Solution

- **Groups the four procedures** under `Create a database function`, so
the action path is one unbroken sequence.
- **Moves the Edge Functions comparison ahead of the procedures.** A
reader choosing between the two needs it before the steps, not after
them.
- **Groups the two security sections** under `Secure a database
function`.
- **Splits debugging onto its own page**,
`guides/database/debugging-functions`. It is registered in the Database
sidebar and cross-referenced from the guide.
- **Folds `Deep dive` into `Resources`.** Two trailing headings did one
job.
- **Adds an opening outline** linking each group and saying when to use
it.
- **Renames the frontmatter title** to sentence case, `Database
functions`.

## Manual testing

1. Open the [guide on the deploy
preview](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions).
Five top-level headings, with the opening outline linking each group.
2. Open the [new debugging
page](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions).
It appears in the Database sidebar under Managing database functions.
3. Follow a repointed link. Open [Postgres log
config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config)
and click Database Function Logging. It lands on the new page at General
logging.
4. Run `pnpm build:guides-markdown` from `apps/docs`. Both pages appear
under `public/markdown/guides/database/`. Discard the `manifest.json`
change.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a guide to debugging Postgres database functions, with examples
for logging, error handling, and inspecting query results.
* Added the guide to Database navigation and updated related resources
to link to it.
* Reorganized the database functions guide to clarify function creation,
security, and privileges.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions)
| `Secure a database function` |
| Docs | New page, 404 in production |
[/docs/guides/database/debugging-functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions)
| `Debugging database functions` |
| Docs |
[/docs/guides/database/postgres/postgres-log-config](https://supabase.com/docs/guides/database/postgres/postgres-log-config)
|
[/docs/guides/database/postgres/postgres-log-config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config)
| `Database Function Logging` |

## Review instructions

This PR moves content. The risk is a broken link, not bad prose.

1. Open the preview of the guide. Count the top-level headings in the
right-hand outline. There are five, down from eight.
2. Read the four bullets at the top of the page. Each links to a group,
and each says when to use it. Click all four and confirm each lands on
its section.
3. Open the new debugging page from the second row. Confirm it appears
in the left sidebar under **Managing database functions**.
4. **Check the three locked anchors.** Append each to the preview guide
URL and confirm the page jumps: `#quick-demo`,
`#security-definer-vs-invoker`. Then append `#general-logging` to the
**debugging page** URL. Four other pages link to these.
5. Open the Postgres log config preview from the third row. Find
**Database Function Logging** in the Resources list and click it. It
lands on the new debugging page, not on a dead anchor.
6. Compare the prose against the live page. **No sentence should have
changed** beyond the new opening outline and the cross-reference to the
debugging page.

**If you only have two minutes:** do steps 4 and 5. A moved section that
leaves a dead anchor is the failure this PR could cause.

**A note on running SQL from this page.** Don't hand-paste from the
rendered page. Blocks are split across tabs, and the Data tab in
Returning data sets holds markdown tables that look pasteable but are
not SQL. Use the `.md` export of the page, which flattens every tab in
page order. #50822 has a copy-paste command for this.
2026-10-05 15:18:00 -07:00
Pamela Chia a9078612f2 fix(www): stop cross-zone link prefetch (#51066)
About 95% of the 404s served on supabase.com are App Router RSC
prefetches (`?_rsc=`) that www `<Link>`s fire at paths another zone
serves: `/docs`, `/dashboard`, `/library`, and the footer's
`humans.txt`, `lawyers.txt` and `security.txt`. Next.js can't prefetch
or client-navigate across multi-zone boundaries, so each prefetch 404s
even though the link itself works. I turned every www link into another
zone into a plain `<a>` and added a lint rule so new ones stay that way.

**Changed:**
- **Cross-zone links are plain anchors**: links that always leave www
(literal `/docs`, `/dashboard` and `.txt` hrefs, absolute
`https://supabase.com/dashboard` URLs, the `getDashboardCtaHref` CTAs)
render `<a>`. Renderers whose href comes from data (nav, footer, plan
and add-on CTAs, product cards) branch on `isCrossZoneHref`, which reads
the zone list from `lib/rewrites.js`. In-zone links stay `<Link>` and
keep prefetching.
- **New literal links can't regress**: `www/no-cross-zone-link` errors
on a `next/link` `<Link>` whose literal or template href points at
another zone. It evaluates `lib/rewrites.js` as production, so `/docs`
counts in every environment.
- **Click tracking survives the full navigation**:
`sign_in_button_clicked`, `start_project_button_clicked` and
`www_pricing_plan_cta_clicked` now send with `keepalive`, like
`sign_in_submitted` already did, so an immediate page load can't cancel
them. The mobile nav Sign in and Start your project buttons used
`legacyBehavior`, which never called their `onClick`: PostHog has no
`Mobile Nav` location for either event in the last 30 days. Those clicks
report from this PR on.
- **Typecheck no longer crashes**: the functions page's default export
inferred a type through `RealtimeLogs`'s unexported `Props`, which makes
the native TypeScript compiler panic during `tsc --noEmit`. I exported
`Props`.

**Note:** the lint rule only sees literal hrefs. A new renderer whose
href comes from data needs its own `isCrossZoneHref` branch, and review
is the only check on that.

## To test
`/docs` is only rewritten on production and absolute
`https://supabase.com/...` links are cross-origin on a preview, so the
preview proves the relative non-docs cases (`/dashboard*`, `/library`,
the footer .txt files). `/docs/...` prefetches still appear on the
preview because it has no docs rewrite.

Tested on Vercel preview:
- [x] Open `/` with the network tab filtered to `_rsc` and scroll to the
footer: no requests for `/dashboard*`, `/library`, `/design-system`,
`/kb`, `/evals`, `/humans.txt`, `/lawyers.txt` or
`/.well-known/security.txt`, while in-zone ones such as `/pricing`,
`/features` and `/blog` still appear
- [x] Same check on `/pricing`, `/auth`, `/database`, `/storage`,
`/realtime`, `/edge-functions`, `/blog` and a blog post: no `_rsc`
requests to `/dashboard*`, `/library` or the footer .txt files
- [x] Open the Developers dropdown on desktop and the mobile menu at
390px: no new `_rsc` requests to `/dashboard*` or `/library`
- [x] Click header Docs, footer Humans.txt, the hero Start your project
button and the pricing Free plan button: each lands where it did before
(`/docs`, `/humans.txt` text, `https://supabase.com/dashboard/sign-up`,
`https://supabase.com/dashboard/new?plan=free`). Signed out, the Free
plan button lands on the dashboard sign-in with
`plan=free&returnTo=%2Fnew`
- [x] Click the hero Start your project button: the
`/platform/telemetry/event` POST with `start_project_button_clicked`
completes with a 2xx after the page starts navigating. 201 with the
navigation held; on the real navigation the event still reached staging
PostHog
- [x] At 390px, open the mobile menu and click Sign in: a
`/platform/telemetry/event` POST with `sign_in_button_clicked` and
`buttonLocation: "Mobile Nav"` fires. Start your project in the same
menu also sends `start_project_button_clicked` with `buttonLocation:
"Mobile Nav"`
- [ ] Signed in, load `/`: no `/dashboard/projects?_rsc=` request (not
run: the preview origin has no signed-in session)
- [x] Open the desktop Product dropdown and the Product section of the
390px mobile menu: Compute shows its Private Alpha badge and the other
products show none (checks the master merge into `MenuItem`)

After deploy, `/` and `/pricing` on supabase.com show no `_rsc` requests
to `/docs*`, `/dashboard*` or `/library`. After a full day, the share of
supabase.com 404s carrying `_rsc=` should drop from about 95% to under
10%, and `sign_in_button_clicked` and `start_project_button_clicked`
should start showing a `Mobile Nav` location in PostHog.

## Linear
- fixes GROWTH-1294
2026-10-05 15:17:04 -07:00
Miranda Limonczenko 63c165311e docs(functions): act on the Edge Function auth eval findings (#50886)
Closes DOCS-1318

## Problem

An agent was asked to build an Edge Function returning the order history
for whoever is signed in and calling it. Three runs, all correct: each
one used the page's `auth: 'user'` pattern and read through the
caller-scoped client. The eval scores 7 of 7, including the guide-read
check.

These are the gaps that showed up around it.

| Finding | What the page does now | Why it matters |
| --- | --- | --- |
| Two clients, no guidance | The first example destructures `supabase`
and `supabaseAdmin` together and labels the second "bypasses RLS
(service role)" | A reader skimming for the client to use sees two, and
one of them is wrong for that section |
| No consequence named | "Bypasses RLS" is the strongest phrasing
anywhere | A handler querying a shared table through the privileged
client without a filter returns every user's rows. The page never said
so |
| `verify_jwt` as a value to set | Appears six times, five of them as
something to change | Switching it off to clear a 401 in development is
a reported failure. The page never said the default is the safe one |


## Solution

- **Say which client to reach for**, in the section where both are
handed over.
- **Name the outcome** in a `danger` admonition: a handler that queries
a shared table through `ctx.supabaseAdmin` without filtering by the
caller's ID returns every user's rows.
- **Frame `verify_jwt = true` as the default to leave alone** on
user-facing functions, and say what turning it off costs.
- **Say every project starts with a secret key named `default`.**

**Not asserted here:** the eval is not re-run. It was already at 7 of 7,
so there is no headroom to measure an improvement. A candidate new check
is proposed on DOCS-1318.

## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth)
|
[/docs/guides/functions/auth](https://docs-git-docs-functions-auth-eval-findings-supabase.vercel.app/docs/guides/functions/auth)
| returns every user's rows |

## Review instructions

1. Open the live and preview links side-by-side.
2. Read Authenticated user calls on the preview. See a paragraph on
choosing between `ctx.supabase` and `ctx.supabaseAdmin`, then a `danger`
admonition naming the every-user's-rows outcome.
3. See the same section say to leave `verify_jwt = true` on for
user-facing functions.
4. Read the note under Service-to-service calls. See it mention the
`default` secret key.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified that `secret` and `publishable` authentication modes accept
the `default` key, and documented how default, wildcard, and additional
keys are handled.
* Explained that JWT verification is enabled by default and that
disabling it leaves `withSupabase` as the only caller-verification step.
* Added guidance that admin queries bypass row-level security and should
be scoped to the caller when accessing shared tables.
* Clarified that service-to-service authentication with `secret`
validates only the `default` key.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:14:27 -07:00
Miranda Limonczenko 259dbe11f1 docs/functions auth structure (#50885)
## Problem

Restructure the topic based off of the PRed Style Guide.

## Solution

- **Group the seven sections into three.** A concept opener, `Choose an
auth mode`, holds the mode table. `Secure your function` holds the six
patterns. `Environment variables` stays last as the fact group.
- **Add an intro outline** linking the three groups, and a group
introduction for the patterns.
- **Move the Authorization headers link below the mode table**, so the
sentence that introduces the table sits next to it.
- **Correct the content listing entry** to match the page's own title.

**Anchors:** every heading text is unchanged. Five headings move from
`##` to `###`, which preserves the slug. The in-page link to
`#external-webhooks` and the two existing redirects in
`apps/www/lib/redirects.js` all still resolve. Verified by grepping the
repo for `functions/auth#` before and after.


## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth)
|
[/docs/guides/functions/auth](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions/auth)
| Choose an auth mode |
| Docs |
[/docs/guides/functions](https://supabase.com/docs/guides/functions) |
[/docs/guides/functions](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions)
| Securing Edge Functions |

## Review instructions

1. Open the live and preview links side-by-side.
2. See three top-level entries in the preview's table of contents, with
six nested under `Secure your function`.
3. Load `/docs/guides/functions/auth#external-webhooks` on the preview.
See the page jump to that section.
4. Open the second preview link. See the listing card read "Securing
Edge Functions" rather than "With supabase-js".

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reorganized the authentication guide with a table of contents and
clearer sections on choosing an auth mode and securing a function.
* Clarified that the guide covers all supported auth modes, combining
modes, and custom error responses.
* Renamed the guide listing to “Securing Edge Functions” and updated its
description to mention declaring accepted credentials.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:14:27 -07:00
Anthony Lio dcf266c360 feat(docs): update search v2 ui (#51175) 2026-10-05 20:33:19 +00:00
47fd296fc1 Add Flick Games case study (#51285)
## Problem

New customer case study for the Case Studies content track: Flick Games,
an indie UK games studio running Art of Solitaire and Goalman on
Supabase.

## Solution

Adds `apps/www/_customers/flick-games.mdx` plus the logo
(on-light/on-dark) and quote-avatar assets. Content is ready for
design/eng review. Tracked in
[MARKET-2252](https://linear.app/supabase/issue/MARKET-2252/case-study-flick-games-sept-23).

## Review instructions

1. Open the preview link for `/customers/flick-games`.
2. Check the logo renders correctly in both light and dark mode, and
that both quote avatars load.
3. Read through for tone and flow.

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-05 12:23:52 -07:00
09a245d72d [FE-4520] fix(studio): hide Realtime setup for published tables (#51152)
The Realtime Inspector now checks the Realtime publication before
showing setup guidance. Projects with published tables get the
join-channel view even before this Inspector session receives any
messages; unconfigured projects keep the setup guide.

Setup guidance also stays hidden while publications are loading or
unavailable. Joining a channel and displaying received messages retain
their existing behavior.

Addresses
[FE-4520](https://linear.app/supabase/issue/FE-4520/realtime-inspector-ui-implies-i-am-not-using-realtime-despite-already).

## To test

- With no tables in `supabase_realtime`, open Realtime → Inspector and
confirm the setup guide appears.
- Enable Realtime on a table and confirm a client receives a database
change. Open the Inspector without joining a channel: it should show
“Join a channel to start listening to messages” and no setup guide.
- Join a channel, trigger a table change, and check the event and
payload appear. Stop listening and confirm messages remain visible.
- Open Policies, then return to the Inspector and confirm the setup
guide stays hidden for the configured project.
- Join a broadcast-only channel with no incoming messages and confirm
the messages view appears immediately.

## Validation

Reproduced the original prompt locally with a working Realtime table,
then verified the fix in the browser, including an independent client
subscription, a live INSERT in the Inspector, navigation, stopping, and
the unconfigured state. Temporary test data and services were cleaned
up.

All nine new regression tests pass; four fail against the original code.
Typecheck, formatting, lint ratchet, Knip, and the case-sensitivity
check pass. The full Studio suite passed 7,799 tests with one unrelated
Explorer test failure; that test passed on a focused rerun alongside the
Inspector tests.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* The Realtime inspector keeps the messages view visible while
publication status is loading or unavailable, and when a channel is
joined or messages are present.
* Setup guidance appears only after publications load successfully and
confirm that Realtime is unavailable, with no channel or messages to
show. This includes cases where there are no publications, the Realtime
publication has no tables, or only a differently named publication
exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-05 12:05:21 -07:00
Miranda Limonczenko a5688423d0 docs(cli): restructure and tighten the CLI getting started guide (#50736)
Closes DOCS-1320

Was the bottom of a two-PR stack. The commit from #50680 moved here, so
that PR is closed and this one carries both changes.

## Problem

The CLI getting started guide had accumulated structural and prose
problems, none of which change what the page claims:

- **Nine flat H2 headings**, with Beta channel and Updating the Supabase
CLI sitting between installing and running. A first-time reader crossed
about 150 lines of beta and upgrade tabs before reaching `supabase
init`.
- **The introduction opened with a two-step procedure under no
heading**, listing `init` and `start` before the CLI is installed. Its
first sentence named the tool and where it runs rather than what the
reader gets.
- **Running a local Supabase project ran concept, fact, procedure, and
process together** as one stretch of prose, so the two commands the
reader has to run sat in paragraphs between the Docker background and
the first-run note.
- **Task headings mixed gerunds with imperatives:** Installing, Running,
Stopping, and Updating next to Access and Manage.
- **No navigation.** A long guide that mixes information types opened
straight into commands, with no outline of its major groups. The sidebar
contents is not a substitute: it isn't part of the document, and the
generated markdown an agent reads has no sidebar at all.
- **Four more sequences were prose.** Installing via npm, installing a
Linux package, the pre-upgrade backup, and opting out of telemetry each
had to be followed in order with nothing marking the order.
- **Smaller things:** the Studio screenshot's alt text named the topic
its heading already states, two links used "note above" and "here" as
their text, and an admonition restated where `sb_publishable_...` comes
from.

## Solution

Twelve commits, one change type each, plus a master merge and its fixup.

- **Style.** The install-method callout drops from four blocks to two
paragraphs and uses the documented `title` prop. Active voice on the
Postgres, analytics, and telemetry instructions. Descriptive link text.
Alt text that describes the Studio screenshot rather than naming it. Cut
the admonition restating `sb_publishable_...`.
- **Structure.** Beta channel and Updating the Supabase CLI move out of
the getting started path.
- **Grouping.** Local setup goes under Set up a local project, updating
and beta builds under Change your CLI version. The intro's `init` and
`start` list gets a Quickstart heading.
- **Value statement.** The opening sentence now says what the reader
gets.
- **Procedure format.** Running a local Supabase project leads with the
container runtime prerequisite, then four numbered actions, then the
first-run download as an outcome. Starting the container runtime is its
own step, since the old prose only assumed it with "with a container
runtime running".
- **Imperative headings.** Install, Run, Access, Stop, Update, Use the
beta channel.
- **Four more procedures.** npm install, Linux packages, the pre-upgrade
backup, and telemetry opt-out. The three pre-upgrade commands were one
unexplained block inside an admonition, so each step now says what its
command does. Re-enabling telemetry moves to a sentence, since it's the
reverse action rather than a step.
- **Intro navigation** listing the major groups, each line saying what
the reader gets from it.
- **Connect to a hosted project** (from #50680). A new section between
Stop local services and Change your CLI version, saying the stack runs
only on the reader's machine and nothing reaches a hosted project until
they sign in and link one, then pointing at the page that owns the
procedure. No commands. The `init` step gains a sentence saying it
creates local files only, and the value statement and intro navigation
cover the added goal.
- **Style guide and word list fixes** from an audit of the page against
`CONTRIBUTING.md` and `WORD_LIST.md`. `directory` over `folder` in
command-line contexts, `might` over `may`, present tense over `will`, a
noun after `this`, no `above` as a pointer, concrete verbs over
`manage`, no time-relative `latest`, no parentheses for supplementary
information, and an impact-first `caution` on the pre-upgrade callout.
The container runtime list becomes a table of tool and platforms, and
the group heading becomes Change your CLI version.


## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/local-development/cli/getting-started](https://supabase.com/docs/guides/local-development/cli/getting-started)
|
[/docs/guides/local-development/cli/getting-started](https://docs-git-docs-cli-getting-started-edits-supabase.vercel.app/docs/guides/local-development/cli/getting-started)
| Change your CLI version, Connect to a hosted project |

## Manual testing

1. Open the docs preview link above.
2. Read the introduction. It opens with a value statement, then links
the four major groups. Under Quickstart, the install-method callout
explains how the install method changes the command you run.
3. Read the On this page list. It nests: Quickstart, Set up a local
project with four sections under it, Change your CLI version with two
sections under it, Telemetry, Learn more.
4. Check Run a local Supabase project renders four numbered steps, with
code blocks inside steps 3 and 4. Check the npm tab of Install the
Supabase CLI renders three, and How to opt out renders two.
5. Load the page at `#installing-the-supabase-cli`, `#beta-channel`, and
`#updating-the-supabase-cli`. All three land on their sections despite
the renamed headings.
6. Load the legacy path
`/docs/guides/cli/getting-started#updating-the-supabase-cli`. It
redirects to the current path and keeps the fragment.
7. Check the introduction's group list includes Connect to a hosted
project, and that the section appears in the On this page list between
Stop local services and Change your CLI version.
8. Check that section is two sentences and a pointer, with no commands.
9. In Run a local Supabase project, select the "Connect to a hosted
project" link in step 3. The page scrolls to that section.
10. Follow both outbound links from the new section and confirm they
resolve, including the `#configure-github-actions` fragment.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Reorganized the local development guide with a clearer quickstart,
setup steps, service access instructions, and CLI version guidance.
* Expanded installation examples to include bun and clarified
package-runner commands.
* Clarified upgrade, backup, container cleanup, and telemetry
instructions.
  * Added a reference to the Microsoft Writing Style Guide.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 11:22:13 -07:00
Jeremias Menichelli 53ecbf9f2a chore: Add telemetry to search v2 user actions (#51146)
## Problem

We need to collect data from search v2 experiment usage.

## Solution

Add telemetry to search v2 modal being opened, closing, sending a query
and clicking a search v2 result.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. Open the preview link and add the search v2 flag query:
`?docs-search-v2=search-v2-active`
2. Trigger all actions mentioned above
3. Telemetry data should be sent on the network tab


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Documentation search activity is now recorded when the dialog opens
from the keyboard shortcut or search input, and when it closes. Search
submissions include the query and whether results were found; selected
results include their destination and the highlighted query. This adds
visibility into key search interactions without changing how search
results or highlighting work.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 13:22:22 -03:00
Jeremias Menichelli 42dc4dbe90 chore: Add observability to search_v2 route (#51149)
## Problem

Our new Search V2 edge function can fail, we want to know when that
happens.

## Solution

Added the common Sentry wrapping plus try/catch strategy to the edge
function so we can add alerts to our Sentry dashboards and report
channels.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

There's no way to reproduce this for the moment.


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Search requests that encounter unexpected server-side errors now
receive a handled 500 response instead of an unhandled failure. Errors
returned by the search service also produce a 500 response, making
failure behavior more consistent for clients. The search query and
result-limit behavior remain unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 13:22:12 -03:00
Katerina Skroumpelou d7cac841c4 docs: state the adapter removal date in the server frameworks guide (#51276)
The server frameworks guide still said the adapters "will be deprecated
soon" and would be "removed in a future major". They have been
deprecated since `@supabase/server` 1.9.0, with `@deprecated` tags
shipping in 1.9.1, and the removal date is December 1, 2026. This PR
updates the two sentences to state that date and drops the wording about
the release shape, which is not decided.
2026-10-05 16:08:24 +00:00
Jordi Enric 7d04c43082 fix(logs): default unified logs to otel DEBUG-228 (#51089)
## Problem

Unified Logs could start legacy BigQuery requests while ConfigCat
loaded, then switch to OTEL when the flag resolved.

## Fix

Default Unified Logs to OTEL unless otelUnifiedLogs is explicitly false.
Use that selection for list, count, chart, facet, detail, download, and
manual refresh requests. Keep BigQuery as an explicit opt-out until the
legacy backend is removed.

## Validation

- Studio typecheck passed locally.
- Existing Unified Logs utility tests passed (21 tests).
- The focused Unified Logs query test file was removed as requested;
backend-selection and manual-refresh regressions are no longer covered
by that suite.
- CI checks are running on the current head.

Tracks
[DEBUG-228](https://linear.app/supabase/issue/DEBUG-228/prevent-bq-queries-before-the-feature-flag-loads).
2026-10-05 17:43:15 +02:00