Commit Graph
38602 Commits
Author SHA1 Message Date
d9cfdcd741 feat(studio): deep-link folders and files in the storage explorer (#50413)
| | PR | Base | Branch |
| --- | --- | --- | --- |
| 1 | #50476 | `master` | pre-existing correctness fixes |
| 2 | **this PR** | `fix/storage-explorer-listing-and-scroll` |
`?path`/`?preview` deep-linking |
| 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link
test |
| 4 | #50480 | `test/storage-deep-link-e2e` | copy path / copy link row
actions |

## What is the current behavior?
The file explorer doesn't keep track of folder navigation.
Files and folders paths aren't shareable

## What is the new behavior?
With this PR:
- nav state is stored via params
  - "path" to store folder path (if nested folder paths)
  - "preview" to store the selected filename
- back/forward nav history
- file url opens correct folder/file


[https://github.com/user-attachments/assets/](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[0cfb7fcc-2c6e](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[528d5c1d-a1b9](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[-](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[4f5a-950d](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[4061-9b67](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[-](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)[060c8eb2027b](https://github.com/user-attachments/assets/0cfb7fcc-2c6e-4f5a-950d-060c8eb2027b)[a41dd98716e0](https://github.com/user-attachments/assets/528d5c1d-a1b9-4061-9b67-a41dd98716e0)

## Steps to review
- Open bucket in Storage File Explorer
- navigate between files and folders and notice url params change
- reload page, it should reopen where you left off
- hitting back/forward on the browser history should follow file/folder
navigation history

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com>
2026-09-18 09:45:32 +02:00
Anthony Lio 222127b5c2 fix(ui-patterns): multi select cropped caret + extra padding (#50323)
## What kind of change does this PR introduce?

bug fix on multi select ui patterns component following up with #49986

## What is the current behavior?

- extra left padding on medium size
- cropped caret on tiny size

## What is the new behavior?

- updates multi select style padding + caret
- refactors test

`caret`
| state | preview |
| -------|------|
| before | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/14af14f6-348a-44be-b0ae-42fdb9a4f4ce"
/> |
| after | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/44dab5ae-944d-43fe-8c4e-0af44a0e1fc7"
/> |

`padding`
| state | preview |
| -------|------|
| before | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/b1ad7f66-9952-463d-aebb-01fee8748aef"
/>|
| after | <img width="594" height="362" alt="image"
src="https://github.com/user-attachments/assets/a5891c45-67b3-4926-97c5-a2ad7027bd5c"
/> |


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Multi-select triggers now display the selected value while retaining
the placeholder when empty.
* Improved sizing, spacing, and minimum widths across multi-select
controls for more consistent layouts.
* Delete controls now provide clearer click targets and hover feedback.
* Decorative chevron icons are hidden from assistive technologies for
improved accessibility.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 10:38:27 +03:00
Joshen Lim 45381bf857 Double clicking items in explorer nav should persist their tabs (#50558)
## Context

As per PR title - this behaviour exists in the Table Editor and SQL
Editor but was just missing in the Explorer

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Double-click chats or notebooks in the Explorer to pin their tabs as
permanent.
  * Pin recent chats and notebooks directly from the Home view.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 14:51:59 +08:00
Saxon FletcherandClaude Opus 5 252f69e451 chore(studio): refine Explorer sidebar, onboarding, and notebooks (#50555)
## Summary

A round of small Explorer refinements.

**Sidebar**
- Adds a **Run SQL** row (with a `+` icon) above Notebooks in the
Explorer sidebar; opens a new query tab.

**Assistant**
- Assistant query cells now have the same **Save** dropdown as query
tabs (add to an existing notebook or create a new one). It shows only
when Explorer is enabled, and not while the query is still streaming.
- `SaveQueryDropdown` takes an optional `source`, so logs queries are
saved as log cells (keeping their time range) instead of database cells.
This also fixes saving logs queries from query tabs.
- The "Drafting notebook..." notice (and the notebook loading/status
rows) now span the full message width; `delete_notebook` parts use the
wide layout like create/update.

**Onboarding**
- Replaces the single page with a four-step walkthrough: Welcome to
Explorer (with a **Preview** badge), Run SQL, Notebooks, and Chat with
your project. Each step has an icon, heading, and short description,
with step dots and **Skip** / **Back** / **Next** buttons; the last step
ends with **Continue to Explorer**.
- Removes the "Choose how Explorer opens" choice (still available in
Account preferences) and the collapsible "Learn more" section. Skipping
or finishing still respects the saved startup preference.
- Deletes `ExplorerOnboardingLearnMore`, `ExplorerHomePreference`, and
`ExplorerHomePreview`, which were only used by onboarding.

**Notebooks**
- Query cells use the same max width as markdown cells (`48rem`, was
`72rem`).
- "Add query cell" / "Add markdown cell" are now **Add query** / **Add
markdown** everywhere; the buttons at the bottom of a notebook are
larger (34px, 18px icons).

## Test plan

- [ ] Explorer sidebar: **Run SQL** opens a new query tab
- [ ] Assistant: generate SQL, use **Save** to add it to a new and an
existing notebook; repeat with a logs query and confirm a log cell is
created
- [ ] Assistant: ask for a notebook and confirm the drafting notice is
full width
- [ ] Clear `hasCompletedOnboarding` in Explorer preferences and step
through onboarding (Next / Back / Skip); finishing or skipping respects
the startup preference set in Account preferences
- [ ] Notebook: query cells line up with markdown cell width; bottom add
buttons are larger


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added a **Run SQL** shortcut to Explorer navigation.
- Assistant query results can now be saved to notebooks, including log
queries.

- **Improvements**
- Updated Explorer onboarding with guided steps, progress navigation,
and visual previews.
  - Shortened Explorer action labels and refined control sizing.
- Reduced notebook query layout width and adjusted assistant notebook
displays.

- **Changes**
- Removed the Explorer startup preference selector and onboarding “Learn
more” section.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-18 14:38:29 +08:00
Joshen Lim 501666e504 Explorer home chat to present a Run SQL secondary action if value is detected to be a SQL query (#50560)
## Context

We previously introduced a behaviour for the explorer home tab's chat
form to run a SQL Query if the input is detected to be a SQL query.

Adjusting it to shift that behaviour into a secondary action instead

<img width="740" height="210" alt="image"
src="https://github.com/user-attachments/assets/d4b1fec1-f38c-426f-8108-b50ead1a61ca"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* SQL statements entered in Explorer can be run directly with a
dedicated “Run SQL” action.
* Assistant forms support context-specific submit icons, labels,
tooltips, and accessibility text.

* **Bug Fixes**
  * Improved SQL detection for multi-statement queries.
* Prevented mixed SQL and conversational text from being treated as
executable SQL.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 14:35:35 +08:00
Anthony Lio 85f19367ec fix(ui): button popup layout shift on click (#50468)
## What kind of change does this PR introduce?

Bug fix on ui button component

## What is the current behavior?

button scale transition is applied when a popup get displayed causing a
slight layout shift (popup position change on active state)

## What is the new behavior?

- prevents scale transition on button displaying popup

| state | preview |
| -------|------|
| before | <video
src="https://github.com/user-attachments/assets/d736f27c-0d0e-4dfa-877f-6b22a09db15e"
/> |
| before | <video
src="https://github.com/user-attachments/assets/762de503-ac54-48cb-b689-8a0f8e83cc4c"
/> |

## Test
1. visit `/project/default/explorer/query/${id}` or `
/docs/guides/ai-tools/mcp`


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Dropdown and other menu-trigger buttons no longer shrink when clicked.
  * The press-scale animation remains available for standard buttons.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 08:51:09 +03:00
Saxon FletcherandClaude Opus 5 e7c76aad99 fix(docs): redirect monitoring-and-debugging.md to observability.md (#50561)
## What

Adds an explicit redirect from
`/docs/guides/monitoring-and-debugging.md` to
`/docs/guides/observability.md`.

## Why

The catch-all `/docs/guides/monitoring-and-debugging/:match*` rule
handles the bare path and subpages, but the root `.md` URL currently
ends up at `/docs/guides/observability/.md`, which 404s:

| URL | Before |
| --- | --- |
| `/docs/guides/monitoring-and-debugging.md` | 308 →
`/docs/guides/observability/.md` (404) |
| `/docs/guides/monitoring-and-debugging` | 308 →
`/docs/guides/observability/` ✓ |
| `/docs/guides/monitoring-and-debugging/logs.md` | 308 →
`/docs/guides/observability/logs.md` ✓ |

The new rule sits before the catch-all so it matches first, mirroring
the existing `observability/access-data.md` rule.

## Testing

- [ ] On the preview, `/docs/guides/monitoring-and-debugging.md`
redirects to `/docs/guides/observability.md` and returns 200

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Added a permanent redirect from the legacy monitoring and debugging
guide URL to the observability guide.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-18 13:15:29 +08:00
edec85d1ca fix(pipelines): Make pipeline actions and status updates reliable (#50085)
## Summary

Make pipeline actions and status feedback reliable while requests are
running or fail. Let the backend coordinate table resets and restarts,
keep stopped pipelines stopped after resets or settings changes, and
refresh the UI from confirmed backend state.

## Pipeline actions and recovery

- Reset one table, all errored tables, or all tables through the
rollback endpoint without separate frontend stop/start requests. Explain
which destination data is deleted, which rows are copied again, initial
sync charges, and the skip-initial-sync setting.
- Keep pending feedback until the action and a fresh status read finish,
including across navigation and polling errors. Prevent overlapping
actions and disable start/stop controls when status is unavailable or
transitioning.
- Close the creation form once the pipeline is created. If its initial
start fails, users can retry Start on the existing pipeline without
creating a duplicate.
- Wait for confirmed shutdown before deletion; a shutdown error or
timeout leaves deletion retryable. Keep failed version updates open and
avoid reporting success.
- Clarify recovery guidance and pending labels, suppress duplicate error
toasts, and hide stale table errors during transitions.

## Status updates and shared UI

- Poll pipeline status and table metrics one second after each response,
share in-flight reads, pause dashboard polling in background tabs, and
respect rate-limit backoff. The shutdown waiter continues in the
background.
- Refresh metadata after mutations even when an older read is in flight,
while preserving shared polling requests. Refresh affected data after
failures that may follow a committed reset or settings change.
- Move pending request state into the shared, project-keyed
`DatabaseLayout` so the list, detail page, and diagram stay consistent.
The surrounding database-page changes update named imports in both
Next.js and TanStack routes.
- Simplify action, status, and form rendering; announce status changes
to assistive technology; and sort table statuses without mutating cached
data.

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-18 11:32:48 +08:00
Saxon FletcherandClaude Opus 5 b1d2efd99e feat(library): add starter app guides (#50368)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature, docs.

Part 2 of 6 in a stack that splits the library redesign into reviewable
pieces.

## What is the current behavior?

The library documents individual blocks. Nothing answers "I have no
project yet" — a reader who wants a working app has to assemble one from
block guides and figure out the scaffolding themselves.

## What is the new behavior?

Four starter guides under `/docs/starters`, each starting from an empty
directory and ending with a running app on Supabase:

- **Next.js starter** — composes the library's own password-based auth
block.
- **SaaS starter** — the community subscription-payments template, with
Stripe setup.
- **AI chat app** — the community Vercel AI SDK template.
- **Flutter starter** — the user-management example, with profiles and
avatar uploads.

They reuse the existing doc route, so the sidebar, command menu,
Markdown export and `llms.txt` pick them up with no new plumbing. The
framework selector already renders nothing for pages that declare no
framework variants, so a starter page shows none.

## Additional context

The starter pages are added here in the current site's page layout; the
last PR in the stack converts them to the new one along with every other
guide.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added a Starter Apps section to the side navigation and command menu.
- Added links for Next.js, SaaS, AI Chat, and Flutter starter projects,
marked as new.

- **Documentation**
  - Added setup and deployment guides for the Next.js and SaaS starters.
- Added an AI Chat App guide covering configuration, local verification,
and deployment.
- Added a Flutter starter guide covering authentication, profiles,
avatars, deep links, and hosted setup.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-18 10:38:49 +10:00
Ivan Vasilov 7fd37e6150 chore: Bump shadcn (#50517)
This PR bumps `shadcn` and regenerates all blocks with the latest CLI.
The blocks have no meaningful change (only a json property reorder).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated internal development tooling used by the UI library and Vue
blocks.
* **Tests**
* Improved type consistency in registry-related test utilities,
supporting more reliable validation without changing user-facing
behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-18 10:38:49 +10:00
abbac3b852 refactor(library): resolve registry dependencies from one source of truth (#50367)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Refactor, bug fix.

Part 1 of 6 in a stack that splits the library redesign into reviewable
pieces. This one is the foundation the rest build on and has no visual
change.

## What is the current behavior?

Three build steps each reimplement "where does this registry file land
in the user's project": `process-registry`'s `getDefaultPath`,
`registry/utils`' `uniqBy` on `file.path`, and the Markdown exporter.
They disagree, which produces real bugs:

- A Vue block whose files come from `node_modules/@supabase/vue-blocks/`
keeps its package path, so the installer writes the package folder into
the user's project.
- `registryItemAppend` builds its `docs` string from `(item.docs,
items.flatMap(...))` — a comma expression, so the item's own docs are
discarded.
- A name collision between a block file and its client's file silently
keeps one of the two.
- Install commands guess the CLI family from substrings in the item
name, so `infinite-query-composable` — a Vue block with neither "vue"
nor "nuxtjs" in its name — gets the React CLI.
- Production Vue installs use `@supabase/<name>`, but the `@supabase`
namespace is registered with shadcn, not shadcn-vue.
- `build:registry`, `build:content`, `build:markdown` and `build:llms`
run in parallel, but the last three read `public/r`.

## What is the new behavior?

`lib/registry-resolution.ts` owns installed-path derivation, first-party
dependency naming, deduplication, and cycle detection, and every
consumer calls it. `build-registry` validates the whole registry against
shadcn's schema and resolves every item, so a broken reference fails the
build instead of shipping. `clean-registry` throws rather than logging
past a failure.

Pages declare their install `framework` explicitly instead of it being
inferred, and production Vue installs use the absolute registry URL.

The build steps are serialized behind `build:prepare`, and a new
`library-tests.yml` workflow runs the library's tests, checks the
generated registry is committed, and builds the app.

## Additional context

Regenerated registry artifacts are the mechanical result of the
resolution fix — the Vue client items and the OAuth consent items that
gained their client's docs.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added explicit React and Vue framework selection for library blocks
and installation commands.
* Improved registry resolution, dependency handling, path validation,
and Vue file normalization.
* Added support for reliable local, preview, and production registry
URLs.

* **Documentation**
* Updated Vue and Nuxt installation documentation to identify the Vue
framework explicitly.

* **Bug Fixes**
* Preserved combined documentation and validated generated registry
content more consistently.

* **Tests**
* Added coverage for installation commands, registry resolution,
dependency handling, and generated artifacts.

* **Chores**
  * Added automated pull-request checks for library tests and builds.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-09-18 10:38:48 +10:00
51b6908236 tsguide(realtime): add guide to isolate client vs server issues (#49933)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Troubleshooting docs addition.

## What is the current behavior?

This is troubleshooting documentation on how to diagnose missing
real-time messages and isolate whether it is a client-side or
server-side issue.

## What is the new behavior?

Adds a step-by-step troubleshooting guide for Realtime. This helps check
isolate connection and message delivery issues using:?

Realtime Inspector: to confirm server-side dispatch.
Browser DevTools: to confirm client-side receipt via WebSockets.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a Supabase Realtime troubleshooting guide for isolating
server-side, client-side, and network-related subscription issues.
* Covers Realtime Inspector checks for subscriptions, broadcasts, and
presence; authorization and RLS validation; client configuration;
WebSocket traffic in browser developer tools; network connection
verification; and preparing diagnostic details for Support.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: krishnasaivandavasi <241076000+krishnasaivandavasi@users.noreply.github.com>
2026-09-17 15:02:21 -06:00
Pamela Chia 64ab76262e feat(studio): exhaustion banner links to metrics (#50276) 2026-09-17 22:23:10 +02:00
AnaandAna 57197ad800 chore(www): update Select Hackathon schedule page (#50543)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Content updates to the Select Hackathon go page
(`/go/select-2026/hackathon-2026-schedule`)

## What is the current behavior?

The page shows placeholder wifi/help-desk details and an earlier
schedule.

## What is the new behavior?

- Section heading `RUN OF SHOW` renamed to `SCHEDULE`
- Demos moved from 6:15 PM to 6:30 PM
- Wifi network set to `Y Combinator`, password set to `makesomething`
- Help desk location set to `booth and mentors`

## Additional context

N/A

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Updated the Hackathon 2026 day-of schedule with revised demo timing.
  * Added Wi-Fi access details for attendees.
  * Updated the help desk location information.
  * Renamed the schedule section header for clarity.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Ana <ana1337x@users.noreply.github.com>
2026-09-17 15:18:43 -04:00
ŁUKASZ KORBASIEWICZ 804e7cda5c docs: add pg_net schema troubleshooting (#50390)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

It adds a new troubleshooting section to the `pg_net` extension
documentation.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Added troubleshooting guidance for resolving a Security Advisor
warning when `pg_net` is installed in the `public` schema.
- Documented that `pg_net` must be dropped and recreated in the
`extensions` schema.
- Added a warning that this process deletes queued requests and stored
responses, including requests that have not yet been sent.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 21:10:44 +02:00
Roman Fernando Cuellar b9800ccf16 Add Roman Cuellar to the list of contributors (#50416)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds new employee as part of onboarding

## What is the current behavior?

N/A

## What is the new behavior?

N/A

## Additional context

N/A


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added Román Cuellar to the team member listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 11:36:26 -06:00
Pamela Chia 66d4b4c19b chore(studio): remove expired tos update banner (#50533) 2026-09-18 00:52:40 +08:00
Francesco SansalvadoreandClaude Opus 5 c8a9a7a630 fix(studio): correct storage explorer listing pagination and column scroll (#50476)
| | PR | Base | Branch |
| --- | --- | --- | --- |
| 1 | **this PR** | `master` | pre-existing correctness fixes |
| 2 | #50413 | `fix/storage-explorer-listing-and-scroll` |
`?path`/`?preview` deep-linking + copy row actions |
| 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link
test |
| 4 | #50480 | `test/storage-deep-link-e2e` | copy path / copy link row
actions |

To read the whole change in one view:

```bash
git diff master...test/storage-deep-link-e2e -- apps/studio e2e
```

## What is the current behavior?

Four independent bugs in the storage explorer, all pre-existing on
`master`:

- `hasMoreItems` is derived from the *formatted* listing, but
`formatFolderItems` drops the `.emptyFolderPlaceholder` — so a full page
can format to `LIMIT - 1` and stop pagination a page early.
- A failed listing is indistinguishable from an empty folder, so a fetch
error reads as "this folder has nothing in it".
- `fetchFoldersByPath` commits its result against whichever bucket is
selected when the requests resolve. Switching buckets mid-flight files
the old bucket's items under the new bucket's name — and because
`columns[0].name` then matches, nothing downstream notices and
refetches.
- The horizontal auto-scroll never runs its guard (`if
(fileExplorerRef)` is always truthy), scrolls relatively so repeated
runs drift, and depends on the `columns` array identity — so a
background refetch yanks the view back to the right. It also scrolls in
list view, where there is nothing to scroll.

## What is the new behavior?

Each of the above is fixed at its source. Pagination and the
exhaustiveness check now compare the raw page length; listings carry an
`isComplete` flag; `fetchFoldersByPath` captures the bucket id at entry
and discards a stale result; the scroll is absolute, guarded, keyed on
`columns.length`, and skipped in list view.

Two new test files cover the parts that were silently wrong before:
`state/storage-explorer.test.ts` (MSW, the bucket race) and
`FileExplorer.test.tsx` (scroll geometry, with the container's layout
defined by hand since jsdom reports everything as zero-sized). Both were
checked by reverting the fix and confirming they fail.

## Additional context

`fetchFoldersByPath` also starts returning `{ missingPaths }` here.
Nothing reads it yet — the first consumer is in PR 2 — but it shares a
hunk with the `isComplete` work, so separating it would mean two PRs
editing the same lines. It is backward-compatible: all three existing
call sites ignore the return value.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Bug Fixes

- Improved Storage Explorer column-view scrolling so the newest column
remains visible, including when the preview pane opens.
- Prevented folder results from a previously selected bucket from
appearing after switching buckets during loading.
- Improved handling of incomplete or partial folder listings to avoid
incorrectly treating failed results as empty folders.
- Preserved the correct scroll position when using list view.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 17:05:23 +02:00
kemal.earth 24e8333c54 feat(studio): flag for unavailable regions (#50473)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds feature flag for controlling region unavailability.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Region options now display availability badges, tooltips, and
status-specific notices.
* Restricted regions remain selectable so users can review their
availability status.
* Project creation provides a clear field-level message when a selected
region is unavailable and prompts users to choose another region.

* **Bug Fixes**
* Region availability messaging now consistently reflects platform
status and configured restrictions.
  * Availability warnings clear after selecting an eligible region.
  * Region checks now cover both dynamic and static provider regions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 14:42:58 +01:00
Inder Singh 7b4e3aba01 fix(studio): show service role key in ConnectSheet for projects using legacy keys (#50516)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix #50515

## What is the new behavior?

ConnectSheet now falls back to the legacy `service_role` key for
projects using legacy JWT keys.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved secret-key resolution by falling back to the service key when
a secret key is unavailable.
* Prevented attempts to reveal a secret when no secret key identifier
exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 07:36:30 -06:00
Joshen Lim 337ffaeb22 Reset pooling size value to default size if field left blank and saved (#50524)
## Context

As per PR title - for the Database Settings -> Connection Pool
Just sends the default value (as per the placeholder) to the PATCH
request when saving while leaving the pool size field blank
<img width="724" height="391" alt="image"
src="https://github.com/user-attachments/assets/448c1bf9-4857-467e-8180-637f291321dd"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Bug Fixes**
- Improved connection pooling updates when a project reference or high
availability setting is unavailable.
- Ensured the default pool size is correctly submitted when no explicit
value is provided.
- Restored the maximum client connection setting accurately after
successful updates.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 13:22:13 +00:00
Anthony LioandAli Waseem 7fb2e8cd42 fix(docs): repeated shiki grammar registration (#50501)
## What kind of change does this PR introduce?

bug fix alternative to #50492

## What is the current behavior?

[#50239](https://github.com/supabase/supabase/pull/50239) introduced
repeated shiki grammar registration. duplicate injection rules
accumulate between code blocks, slowing later tutorials enough to hit
the 60-second build timeout

## What is the new behavior?
- reuses one highlighter with all languages loaded once
- restores previous highlighting approach + startup cost while keeping
the page-size savings

replay | before #50239 | after #50239 | this pr
-- | -- | -- | --
cold, including initialization | 2.99 s | 6.96 s | 2.94 s
warm | 0.37 s | 5.90 s | 0.36 s




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Enhancements

* Code blocks now preload syntax highlighting for all supported bundled
languages, including SQL, Markdown, and TypeScript.
* Highlighting uses a shared configuration and theme for consistent
rendering across code blocks.
* Concurrent code block renders share a single highlighter
initialization.
* Language handling and syntax-highlighted output are more consistent
across supported, unsupported, aliased, and plain-text code blocks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-09-17 07:07:35 -06:00
Maksym Ionutsaandcoderabbitai[bot] b5f174a6f9 docs: warn against installing PostGIS in the public schema (#50509)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

Gap in the docs that agents misinterpret

## What is the new behavior?

<img width="1566" height="718" alt="CleanShot 2026-09-17 at 12 13 59@2x"
src="https://github.com/user-attachments/assets/d50b4228-b0ec-4cca-94d3-ec083720a04a"
/>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added guidance to install PostGIS in a dedicated schema rather than
`public`.
- Clarified that installing PostGIS in `public` exposes the
`spatial_ref_sys` table through the Data API.
- Explained that related security advisor warnings are expected and do
not indicate user data exposure.
- Added steps for moving PostGIS to another schema, including backup
precautions and an option to contact Support.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-09-17 15:06:39 +02:00
Maksym Ionutsa fe0afd66b8 docs(cron): document how to clean up cron.job_run_details (#50211)
cron.job_run_details grows unbounded and is never pruned automatically,
even after a job is unscheduled. Add an example that schedules a daily
cleanup job, and link it from the existing disk-usage caution.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

No mention of the _necessary_ regular cleanups

## What is the new behavior?

This is now explicitly called out with a weekly clean-up example

<img width="1620" height="654" alt="CleanShot 2026-09-10 at 11 41 25@2x"
src="https://github.com/user-attachments/assets/2f78a051-5994-4f8a-95c2-c96c64679bed"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Updated the cron quickstart guide with guidance on cleaning up job run
history.
- Added an example showing how to schedule a daily cleanup job that
removes records older than seven days.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 15:06:23 +02:00
Ivan Vasilov 68d7387e94 chore: Update tanstack icons (#50504)
Update the icons for Tanstack in studio and docs. See:
- https://docs-git-chore-update-tanstack-icons-supabase.vercel.app/docs
-
https://studio-staging-git-chore-update-tanstack-icons-supabase.vercel.app/dashboard/project/_?showConnect=true&framework=tanstack
2026-09-17 06:53:29 -06:00
Joshen Lim 71d58cba7f Joshenlim/fe 4401 re sql editor silently points to the primary instead of (#50513)
## Context

Fixes the following 2 issues with the database selection in the SQL
Editor
- An errant `useEffect` was resetting the `selectedDatabaseId` back to
the primary every time the `databases` list from `useReadReplicasQuery`
changed reference (not just on first load).
- `QuerySourceMenu` kept showing "Read Replica" even after selection had
reverted
- Was using local storage value as the `identifier` for
`DatabaseParametersSubMenu`, when it should use the valtio store as the
source of truth

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- The SQL Editor now remembers the last selected database between
sessions.
- Your saved database selection is restored when available; otherwise,
the project’s primary database is selected automatically.
- Query source settings now stay synchronized with the database
currently selected in the SQL Editor.

- **Bug Fixes**
- Background database refreshes no longer unexpectedly reset your
selected read replica to the primary database.
- Database selection now waits for saved preferences to load, preventing
a brief incorrect selection.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 12:34:13 +00:00
Lukas BernertandClaude Fable 5 459436e87f docs: update compute size descriptions (CPU column, pg_restore guidance) (#49996)
## What kind of change does this PR introduce?

Docs update: aligns compute descriptions with the current compute
options.

Fixes PROD-655

## What is the new behavior?

- compute-and-disk: CPU column now shows "Shared" (Nano–Medium) and
"Dedicated · N vCPUs" (Large and above), matching the pricing page
- migrating-to-supabase/postgres: pg_restore -j guidance keyed to the
vCPU count per compute size
- which-version-of-postgres: uses show server_version;, which gives
simpler, architecture-agnostic output
- High-CPU troubleshooting guide: recommends upgrading compute size
instead of naming specific instance types
billing-on-supabase: "64 cores" → "64 vCPUs"
- Section anchors unchanged (deep-linked from other pages)

## Self-review

Content-only MDX change:

- pnpm lint:mdx: no findings in the changed files (all reported
errors/warnings are pre-existing in unrelated files)
- pnpm build:guides-markdown: builds clean; generated .md exports for
the changed pages verified
- All pages verified rendering in the local dev app on current master
- Swept apps/docs for remaining core-count / instance-type mentions in
compute descriptions

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated PostgreSQL version-checking instructions to use `show
server_version;` with simplified output.
* Clarified compute sizing terminology using shared and dedicated CPU
allocations and vCPU-based descriptions.
  * Updated billing guidance to describe scaling up to 64 vCPUs.
* Revised database restore guidance with current compute tiers and
recommended parallelization settings.
* Simplified high-CPU troubleshooting guidance to recommend temporarily
scaling CPU capacity.
* Added writing guidance to consistently use “vCPU” and “vCPUs” for
Supabase compute resources.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-17 14:34:01 +02:00
Joshen Lim be9ec25270 Update unified logs queries to fetch status, method and pathname properly for storage logs (#50465)
## Context

As per PR title - those 3 properties (status, method, and pathname) were
missing from the table view but available in the detailed panel view

### Before
<img width="1118" height="575" alt="image"
src="https://github.com/user-attachments/assets/e6d3bb70-8ce9-4a7b-9e07-eae7acb6896d"
/>


### After
<img width="988" height="555" alt="image"
src="https://github.com/user-attachments/assets/309b4e5a-88e1-41d9-8cee-4ae56a1afa15"
/>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Unified Logs now correctly displays HTTP methods, paths, and status
codes for storage-service entries.
* Updated log filters to support storage-service values for equality,
inequality, wildcard, LIKE, and ILIKE searches.
  * Improved pathname prefix matching across supported log backends.
* Preserved correct handling of authentication statuses and worker
Compute fields.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 20:04:07 +08:00
Jordi Enric 6434c48999 feat(studio): migrate Auth reports to OTEL (#50469)
## Problem

Auth observability charts always queried the legacy logs.all endpoint,
even when the OTEL reports rollout was enabled. The existing OTEL SQL
also had ClickHouse correctness and parity gaps around timestamp
aliasing, JSON types, provider paths, missing values, and error-code
attributes.

## Fix

Route the ten Auth-specific charts through the OTEL query builders and
logs.all.otel endpoint when otelReports is enabled. Preserve the
BigQuery fallback, partition React Query caches by backend, and leave
the shared API gateway charts on the legacy endpoint.

Correct the OTEL queries by qualifying source timestamps, using typed
and nullable JSON extraction, preserving missing actor and duration
semantics, selecting the right provider path for each event shape,
preferring the canonical Auth error-code attribute with a legacy
fallback, and applying bounded result limits. Two-minute report
intervals now use minute-level SQL buckets instead of falling through to
hourly buckets.

## How to test

- Run `CI=1 pnpm --filter studio exec vitest run
data/reports/v2/auth.config.otel.test.ts
hooks/misc/__tests__/useReportDateRange.test.ts`
- Run `pnpm --filter studio run lint:ratchet`
- Run `pnpm --filter studio run typecheck`
- Expected result: all checks pass and generated OTEL SQL preserves
legacy report semantics.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **New Features**
- Auth observability charts can now use OpenTelemetry data when enabled,
while retaining the existing reporting source otherwise.
- Switching the data source automatically refreshes the relevant charts.

- **Bug Fixes**
- Improved Auth observability accuracy for provider, duration, actor,
and error-code reporting.
- Added safeguards to keep report queries within the supported result
limit.
- Corrected minute-level grouping for two-minute analytics intervals and
three-hour date ranges.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 13:44:39 +02:00
Lukas Bernert 055cc7b956 docs: state disk limits as per-size minimums, align burst copy (#50016)
## What kind of change does this PR introduce?

Docs update: states disk limits as per-size minimums and aligns burst
copy across pages. Follow-up to #49996 (compute descriptions).

Fixes PROD-658

## What is the current behavior?

- The disk limits table and surrounding prose describe a narrower set of
configurations than a compute size can run on
- Burst thresholds are inconsistent across pages (three different
variants), and one section contradicts itself
- Burst is described as CPU behavior, when the burst users observe is
disk IO

## What is the new behavior?

- `shared-data/compute-disk-limits.ts`: Medium baseline throughput
adjusted to 39 MB/s: the lowest value across configurations
- `compute-and-disk`: disk limits presented as minimums ("at least");
burst described as disk IO drawing on a disk IO budget; consistent
thresholds: burst available up to 2XL, baseline equals maximum from 8XL
- Troubleshooting guides (`exhaust-disk-io`,
`failed-to-retrieve-tables`, `interpreting-supabase-grafana-io-charts`)
aligned to the same threshold; `failed-to-retrieve-tables` keeps the
~30-minutes-per-day burst window with the corrected size range
- Section anchors unchanged

## Self-review

- Values verified against the AWS EBS-optimized performance data
(`describe-instance-types`) for every configuration per size; content
cross-checked with the internal runbooks (linked in PROD-658)
- `supa-mdx-lint`: no findings in changed files
- `pnpm build:guides-markdown` clean; generated `.md` exports show the
new values and prose
- All changed pages verified rendering in the local dev app
- `pnpm typecheck` passes (shared-data + docs)
- Note: `compute-disk-limits.ts` also feeds Studio (disk validation, IO
budget tooltips). The only value change (Medium 43 → 39 MB/s) surfaces
there as one chart tooltip label; conservative direction.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Clarified the differences between shared and dedicated CPU resources.
- Updated disk I/O guidance to explain baseline and burst limits as
minimums.
- Documented disk I/O bursting for compute sizes up to 2XL, including
expected duration and limitations.
- Clarified that 8XL and larger compute sizes have consistent
performance without burst capacity.
- Updated the documented baseline throughput for medium compute
resources.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 12:26:45 +02:00
Lukas Bernert 593e95345a www: update compute size descriptions (Compute column, vCPU units) (#49998)
## What kind of change does this PR introduce?

www update: aligns compute descriptions on the pricing surfaces with the
current compute options. Counterpart to the docs update in #49996.

Fixes PROD-654

## What is the new behavior?

- Pricing compute table: the CPU and Dedicated columns are merged into a
single Compute column — "Shared compute" for Micro–Medium, "Dedicated ·
N vCPUs" for Large and above (the `dedicated` key is removed from
`PricingAddOnTable.json`)
- Pricing calculator: the instance summary line uses the new Compute
value directly
- Pricing compute section headline: "64 cores" → "64 vCPUs"
- `/pricing.md`, `/llms-full.txt`, `/llms/pricing.txt`: generated
markdown mirrors the new table
- `/database.md`: describes the compute range as Micro to 16XL+


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Pricing Updates**
- Compute pricing tables now label the column “Compute” and show shared
compute or dedicated vCPU counts.
  - Removed the separate “Dedicated” column from compute add-on tables.
- Dedicated-plan values now display consistently across desktop and
mobile layouts.
- Compute instance details no longer repeat the “CPU” label after the
CPU value.
  - Updated scaling language to refer to “64 vCPUs.”
- Simplified technical details by removing specific core-count examples
while retaining configurable sizing and autoscaling information.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 12:22:07 +02:00
Lukas BernertandClaude Fable 5 77ee1ec127 chore(studio): describe compute CPU by size tier (#50401)
## What kind of change does this PR introduce?

Copy/label update in Studio's compute surfaces.

## Description

Compute CPU descriptions now branch on the compute size tier:

- Sizes below Large read **"Shared compute"** (no core count)
- Large and up read **"Dedicated · N vCPUs"** — the unit is always vCPU

Changes:

- New `lib/compute-labels.ts` helper (`isSharedComputeSize`,
`getComputeCpuLabel`) with unit tests
- Compute badge hover card, compute size picker, and project-creation
selector use the new labels
- `new-project.constants.ts` cpu strings updated accordingly
- ">16XL" card: "Custom CPU" → "Custom compute"; upsell copy now says
"64 vCPUs"
- The synthetic Nano/Micro addon `meta` no longer has
`cpu_cores`/`cpu_dedicated`; removed the now-unused cpu fields from the
hardcoded instance specs
- Project-creation sub-text: "Larger, dedicated compute available after
creation"

## Tests

- New unit tests for the label helper
- Infrastructure settings page test now asserts the rendered labels

Fixes PROD-663

Related #49998 #49996


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **User Interface**
* Updated compute-size labels to use “Shared compute” and vCPU
terminology.
  * Clarified dedicated compute options and availability messaging.
* Updated custom instance and upgrade labels, including “Custom compute”
and “64 vCPUs.”
* **Consistency**
* Standardized compute labels across project creation, infrastructure
settings, and compute details.
* **Tests**
* Added coverage verifying shared and dedicated compute classifications
and displayed labels.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-17 12:18:48 +02:00
Vaibhav 1e444589c6 fix(self-hosted): standardize function auth responses (#48012) 2026-09-17 10:10:01 +02:00
Gildas Garcia c2d8b08299 MFA Recovery codes: UI tweaks (#50488)
## What kind of change does this PR introduce?

Admonition is not the right UI to tell users how many are still
available.

## What is the current behavior?

No recovery codes yet:

<img width="724" height="499" alt="image"
src="https://github.com/user-attachments/assets/db9d47af-3a81-42d2-8cf0-9302816ceb21"
/>

After:
<img width="758" height="525" alt="image"
src="https://github.com/user-attachments/assets/68acc4bf-372f-4472-a3e4-a8263a8993d0"
/>

## What is the new behavior?

No recovery codes yet:
<img width="720" height="556" alt="image"
src="https://github.com/user-attachments/assets/48ce08a7-9650-428b-be5d-b8bb7ef5b720"
/>

After:
<img width="720" height="541" alt="image"
src="https://github.com/user-attachments/assets/35a8698d-9a6f-44cb-91c8-2ddb8d0f3a7b"
/>

When low number of codes available:
<img width="733" height="548" alt="image"
src="https://github.com/user-attachments/assets/d60017ba-ada6-47bb-9f83-a2a65674f800"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Improvements**
- Recovery codes now appear in a dedicated section when enabled,
separate from multi-factor authentication settings.
- Recovery-code status updates are announced to screen readers for
improved accessibility.
- Available recovery codes are displayed in a clearer card-based layout
once status information is available.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 09:36:19 +02:00
Danny White 7ab3f32625 feat(studio): rebuild the pipeline overview (#49630)
## What kind of change does this PR introduce?

Studio UI improvement.

## What is the current behavior?

The pipeline Overview uses bespoke loading, metrics, table-state and
empty-state layouts that shift while data resolves and repeat status
information from the detail header.

## What is the new behavior?

Rebuilds the Overview around stable **Pipeline health** and **Replicated
tables** sections. It adds layout-matched loading geometry, prioritised
pipeline notices, initial-sync progress, clearer empty states, and
accessible loading announcements. Complete pipeline configuration
remains deferred to #49631.

| Before | After |
| --- | --- |
| <img width="1024" height="759" alt="54861"
src="https://github.com/user-attachments/assets/56e5cc5a-5d49-44c8-94d7-e1f1e0c827d5"
/> | <img width="1024" height="759" alt="Replication Database Agua
Basket Supabase"
src="https://github.com/user-attachments/assets/43b6d0f6-6fd5-47f9-b3e5-788a33511304"
/> |

This is the final independent slice in the review series: #50443,
#50444, #50445, #50446, then this PR. Each PR targets `master` and can
merge on its own. Rebase this PR as earlier slices merge.

## To test

1. Open `/project/<ref>/database/replication` and select a pipeline.
2. Throttle the initial requests and confirm **Pipeline health** and
**Replicated tables** keep their final geometry while loading.
3. Check running, initial-sync, stopped, failed, disconnected and
unavailable states.
4. Confirm the Overview contains Pipeline health and Replicated tables
only, without a Configuration section.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Reorganized replication pipeline status into Pipeline health and
Replicated tables sections.
  - Added loading skeletons with accessible status announcements.
- Added clearer notices for pipeline health, failed or disconnected
pipelines, paused updates, lag, and synchronization progress.
- Improved empty states when table data is unavailable or the pipeline
is inactive.
  - Added options to view logs and reset failed tables.

- **Tests**
- Added coverage for loading behavior, pipeline notices, table counts,
synchronization progress, and empty states.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 16:31:04 +10:00
Saxon Fletcher 0043e6f53b feat(studio): add Explorer onboarding and startup preference (#50493)
<img width="1454" height="920" alt="image"
src="https://github.com/user-attachments/assets/a289b618-2bd2-4957-ac49-71d4e372d2cc"
/>


## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

Yes.

## What kind of change does this PR introduce?

Feature.

## What is the current behavior?

Explorer always opens on its start page, without onboarding or a startup
preference.

## What is the new behavior?

Adds one-time onboarding with wireframe option cards and a collapsed
Learn more section. Users can start on the Explorer start page or in a
new SQL query tab, and change that choice in Account preferences →
Dashboard. Preferences persist per account in the browser.

## Additional context

How to test:
1. With Explorer enabled and fresh browser storage, open Explorer and
select either startup option. Confirm Open Explorer follows the
selection and onboarding stays dismissed after reload.
2. Change Explorer startup in Account preferences → Dashboard, then
reopen Explorer. SQL query should create one normal query tab; Start
page should restore the pinned home tab.
3. Use the keyboard to select an option and toggle Learn more. Expand it
in a short viewport and check that the page scrolls normally.

Validation: 235 tests pass, including 20 new cases; Studio typecheck and
formatting pass.

The local production build was stopped during compilation and was not
verified locally.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added an Explorer onboarding experience with startup-view selection,
guidance, and a Learn more section.
- Added Explorer settings to choose between the Start page and SQL query
views.
  - Explorer preferences now persist across sessions and accounts.
  - Explorer can open directly to a new SQL query when selected.
- The Explorer Home tab is shown based on the selected startup
preference.
- **Accessibility**
  - Reduced-motion settings now disable the Explorer loading animation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 15:53:18 +10:00
Danny White 2a46c00653 feat(studio): polish replicated table controls (#50446)
## What kind of change does this PR introduce?

Studio UI improvement.

## What is the current behavior?

Replicated tables use badge-heavy rows, fixed name sorting, prominent
per-row reset buttons, and inconsistent restart terminology.

## What is the new behavior?

Adds table and status sorting, accessible search feedback, concise state
details, table action menus, and consistent **Reset** terminology.
Failed-table reset remains unavailable when there are no failed tables
or another reset is running.

| Before | After |
| --- | --- |
| <img width="1872" height="356" alt="CleanShot 2026-09-16 at 13 36
51@2x"
src="https://github.com/user-attachments/assets/6546f089-f6f8-4ff2-9509-ec44a2dee973"
/> | <img width="1840" height="452" alt="CleanShot 2026-09-16 at 13 36
30@2x"
src="https://github.com/user-attachments/assets/6e36b1e6-baee-4aea-80e9-e5e4a3fc8a75"
/> |

This is an independent slice extracted from #49630. The related review
series is #50443, #50444, #50445, this PR, then #49630.

## To test

1. Open `/project/<ref>/database/replication` and select a pipeline with
replicated tables.
2. Sort by **Table** and **Status**, then search for a table and clear
the search with Escape.
3. Open a table’s action menu and confirm its reset and Table Editor
actions.
4. Confirm **Reset failed tables only** is unavailable when the pipeline
has no failed tables.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added sortable Table and Status columns to the replication pipeline
view.
  * Added options to reset all tables or only failed tables.
  * Added clearer replication lag details and status indicators.
* Added dropdown actions for resetting tables and opening the Table
Editor.
  * Added Escape-to-clear support for search.

* **Bug Fixes**
* Improved empty search results with a clear “No results found” message.
  * Error details are now displayed separately for easier access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 14:54:08 +10:00
Danny White a5dcf3b57c feat(studio): rebuild pipeline health summary (#50445)
## What kind of change does this PR introduce?

Studio UI improvement.

## What is the current behavior?

Pipeline health is presented as a dense custom metrics panel with
repeated connection information and per-table lag details mixed into the
pipeline summary.

## What is the new behavior?

Moves the pipeline-level slot status, lag, WAL retention, and last
check-in into a standard detail section. It removes repeated connection
content and keeps table-specific state with the replicated tables.

| Before | After |
| --- | --- |
| <img width="1816" height="274" alt="CleanShot 2026-09-16 at 13 34
43@2x"
src="https://github.com/user-attachments/assets/eceed5bb-8af2-4a3b-83a9-7849f1554fbe"
/> | <img width="1830" height="506" alt="CleanShot 2026-09-16 at 13 34
15@2x"
src="https://github.com/user-attachments/assets/498c4390-17e2-45e5-a923-cb4a7cfd5978"
/> |

_Note that the page spacing may feel a bit funny. This is handled in
https://github.com/supabase/supabase/pull/49630_

This is an independent slice extracted from #49630. The related review
series is #50443, #50444, this PR, #50446, then #49630.

## To test

1. Open `/project/<ref>/database/replication` and select a running
pipeline.
2. Confirm **Pipeline health** shows slot status, lag, WAL retention
remaining, and last check-in.
3. Confirm unlimited WAL retention is labelled **Unlimited** and a
caught-up pipeline is labelled **Caught up**.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## UI Improvements

- Added a dedicated Pipeline Health section summarizing WAL status, slot
status, and replication lag.
- Replaced the inline metrics layout with responsive detail cards and
clearer supporting descriptions.
- Added tooltips for lag values and relative reply times, including
precise timestamps.
- Updated lag labels and status indicators for improved clarity.
- Added concise explanations for reserved, extended, unreserved, lost,
and unknown WAL states.
- Improved presentation of pipeline details with optional contextual
descriptions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 14:52:46 +10:00
Danny White 3e2d54eccb feat(studio): add Warehouse table management and disable (#50195)
## What kind of change does this PR introduce?

Feature and UI polish.

## What is the current behavior?

Warehouse setup uses a schema accordion for table selection. Once
Warehouse is enabled, users cannot remove replicated tables or disable
Warehouse from Studio.

## What is the new behavior?

- Replaces the schema accordion with one grouped, searchable table
selector.
- Still allows for **Select all** and **Clear** actions for each schema.
- Starts first-time setup with no tables selected and preselects current
replicated tables when editing.
	- Adds support for removing previously replicated tables.
- Adds a confirmed **Disable Warehouse** action.
- Tracks successful Warehouse enable and disable actions.

Disabling Warehouse removes its replication pipeline, publication,
catalogue access, and foreign tables. Copied data remains in DuckLake
storage until the user deletes it. Re-enabling a table rebuilds its data
rather than reusing the retained copy.

| Before | After |
| --- | --- |
| <img width="1024" height="759" alt="Integrations Test US East 1 testdw
Supabase"
src="https://github.com/user-attachments/assets/bded025b-1d45-41dc-8a35-9159baf8f9b7"
/> | <img width="1024" height="759" alt="Integrations test Teamer
Supabase"
src="https://github.com/user-attachments/assets/69026d94-98a0-4878-ab58-2e9697296d93"
/> |
| <img width="1280" height="1323" alt="Integrations Test testdw
Supabase"
src="https://github.com/user-attachments/assets/3f71e754-1a87-4d58-a7b9-dd39d3e0ac5a"
/> | <img width="1280" height="1323" alt="Integrations Regular AWS
Teamer Supabase"
src="https://github.com/user-attachments/assets/758ed48e-9ed6-45d3-ae94-e171147a21d5"
/> |
| _Feature did not exist_ | <img width="1024" height="759"
alt="Integrations Regular AWS Teamer Supabase"
src="https://github.com/user-attachments/assets/c977ac57-8b0c-4482-882b-69ad7602b5df"
/> |

## Additional context

Platform support for updating and disabling Warehouse was added in
[supabase/platform#38190](https://github.com/supabase/platform/pull/38190).

### To test

1. Open `/project/{ref}/integrations/warehouse/overview` before setup.
2. Confirm **Tables to replicate** starts at zero and **Enable
Warehouse** is disabled until a table is selected.
3. Confirm each schema's **Select all** and **Clear** actions update
every table in that schema.
4. Enable Warehouse with a partial selection and wait for setup to
complete.
5. Edit the selection, add and remove replicated tables, then confirm
the saved selection is reflected in the publication.
6. Disable Warehouse, confirm the retention warning, and verify the
integration returns to its initial state.
7. Re-enable Warehouse and confirm selected tables are rebuilt.
8. Trigger a replication pipeline limit error and confirm the inline
guidance links to Database Replication.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added the ability to disable Warehouse from the setup panel.
  - Warehouse setup now starts with no table selections.
- Editing a setup preselects replicated tables and supports updating
selections, including removing tables.
- Added searchable schema and table selection with screen-reader count
announcements.
  - Added telemetry tracking for initial Warehouse enablement.

- **Bug Fixes**
- Warehouse disable failures now show an error while keeping the
confirmation dialog open for retry.
  - Configuration updates now refresh related data automatically.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 14:17:00 +10:00
Saxon FletcherandClaude Opus 5 7880c2f079 fix(studio): explorer chat and notebook layout refinements (#50453)
Five layout fixes across Explorer chat, notebooks, and the sidebar.

### Chat

- **Conversation fade overlapped the scrollbar.** The top and bottom
gradients are positioned against the conversation's padding box, which
includes the scroll container's scrollbar gutter, so `inset-x-0` painted
them over the scrollbar. They now stop at the conversation's content
gutter, which `Conversation` owns for both the content and the fades.
- **Composer background bled past the input's radius.** The form paints
the surface behind the textarea but had no radius of its own, so its
square corners showed outside the `rounded-lg` input. It now shares the
radius.
- **Message parts used two different widths.** Wide parts come down to
`max-w-3xl` so every part shares a column, matching `AssistantQueryCell`
and `AssistantNotebookPreview`. `isWide` / `isWideMessagePart` stay in
place with both widths equal, so a part can diverge again later without
rebuilding the mechanism.

### Notebooks

- **Cell controls sat at the container edge.** Each cell centred itself
at its own max width while the grip and add-cell button stayed at the
far left of the full-width row, leaving a large gap. `SortableSection`
takes a `sectionWidth` and carries its control gutter twice — once as
the controls, once as padding on the other side — so the section stays
centred with its controls immediately beside it. Cell widths are
unchanged (prose `48rem`, query `72rem`); set them equal and the two
cell types' controls line up on their own.

The controls stay in flow rather than floating in an outside gutter, so
on a viewport narrower than the cap the row just fills the space instead
of clipping the controls into the padding.

### Sidebar

- **Search icon didn't line up with the menu row icons.** The row box
already sits flush with the search input's box, so rows moved from
`pl-3` to `pl-2` to put their icons on the same 8px offset the search
icon uses. Spacing between the input and the list now matches the 12px
side padding.

### Testing

`pnpm --filter studio run typecheck`, Prettier, and 378 tests across
`Explorer`, `ProjectHome`, `AIAssistantPanel`, and `ExplorerLayout`
pass. ESLint warning counts are unchanged from master.

These were reasoned from layout rather than checked in a browser, so
they're worth a look on a preview before merge.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **UI Improvements**
* Updated Explorer layouts with flexible, configurable widths for
notebook and query sections.
  * Refined navigation spacing and padding across Explorer views.
* Centered and standardized AI Assistant preview, query, and message
content widths.
  * Improved chat form styling with rounded corners.
* Adjusted conversation spacing and fade overlays to avoid overlapping
the scrollbar.
* Preserved full-width behavior where appropriate while keeping controls
aligned.

* **Tests**
* Updated layout tests to reflect revised width and alignment behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 11:39:30 +08:00
Eduardo GurgelandJoshen Lim c15b0836d8 fix(studio): bump realtime max_concurrent_users soft limit (#50438)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bump realtime max_concurrent_users soft limit to 300k

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Increased the maximum supported concurrent clients from 50,000 to
300,000 when plan entitlements allow it.

* **Bug Fixes**
* Improved validation for concurrent-client limits, including clearer
handling of entitlement-based and unlimited limits.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-17 03:12:28 +00:00
Danny White babebc959c fix(studio): improve pipeline destination logo legibility (#50496)
## What kind of change does this PR introduce?

UI polish for Pipeline destination logos.

## What is the current behavior?

The Snowflake mark does not use the available SVG canvas, and
destination marks appear overly inset in the pipeline detail header.

## What is the new behavior?

The Snowflake asset uses more of its canvas, and the large
`DestinationLogo` variant renders a 32px mark inside its existing 56px
frame. Small logos used in lists, diagrams, and destination pickers
remain unchanged.

| Before | After |
| --- | --- |
| <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 46
51@2x"
src="https://github.com/user-attachments/assets/83e7ab5e-c9f3-4410-99c1-4f3596b9e027"
/> | <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 48
33@2x"
src="https://github.com/user-attachments/assets/d354dd46-80be-48f6-b2d9-277ee930eaaa"
/> |

## To test

1. Open `/project/<ref>/database/replication` with a Snowflake pipeline
and confirm its logo renders clearly in the list.
2. Open that pipeline's child route and confirm the destination logo
fills more of the header square without changing the square itself.
3. Check another destination's child route and confirm its large logo
uses the same sizing.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Increased the size of the large destination logo mark for improved
visibility.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 11:07:31 +08:00
Wen Bo Xie 20d09b4a72 docs(auth): clarify OAuth 2.1 server pricing is included in Auth MAUs (#49753)
OAuth 2.1 server had a single pricing statement anywhere, and it said
the feature is free during beta. This states the actual model everywhere
the feature is documented or sold: there is no separate charge, and
users who sign in through the OAuth server count toward Auth MAUs.

- docs getting started: replace the "free during beta" sentence with the
MAU-based pricing statement
- docs overview: add a Pricing section linking to the MAU usage guide
and the pricing page
- docs MCP authentication: note that agents authenticate as existing
users, and MAUs count per distinct user, so multiple agents for one user
count once
- www pricing comparison table: add an "OAuth 2.1 Server" row (included
on all plans) with a tooltip, and extend the MAU tooltip to cover OAuth
server sign-ins

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified that OAuth 2.1 Server is available on all plans without a
separate charge.
* Explained that OAuth sign-ins count toward Monthly Active Users
(MAUs), with multiple agents for one user counted once.
  * Added links to MAU and pricing guidance.

* **Pricing**
* Added OAuth 2.1 Server as a plan feature and updated billing
descriptions for greater clarity.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 10:49:36 +08:00
Danny White e21e0c73bb refactor(studio): simplify pipeline error details (#50444)
## What kind of change does this PR introduce?

Studio UI refactor.

## What is the current behavior?

Failed replicated tables spread retry timing and error details across
several visually heavy blocks.

## What is the new behavior?

Condenses retry timing and failure details into a clearer table-level
presentation without changing retry behaviour or pipeline mutations.

| Before | After |
| --- | --- |
| <img width="1842" height="594" alt="CleanShot 2026-09-16 at 12 55
52@2x"
src="https://github.com/user-attachments/assets/fb6f6a3f-2e81-411e-9d49-ed4cf8cc66e7"
/> | <img width="1824" height="328" alt="CleanShot 2026-09-16 at 15 16
21@2x"
src="https://github.com/user-attachments/assets/bad558c4-2d4c-4d1b-bb68-32ad4d5b348f"
/> |
| _Not applicable._ | <img width="832" height="662" alt="CleanShot
2026-09-16 at 15 16 29@2x"
src="https://github.com/user-attachments/assets/540a5d55-f99f-4c1e-9a57-5ab2ac31e44e"
/> |

This is an independent slice extracted from #49630. The related review
series is #50443, this PR, #50445, #50446, then #49630.

## To test

1. Open `/project/<ref>/database/replication` and select a pipeline with
a failed table.
2. Confirm the table row presents its failure and retry timing without
expanding the row unnecessarily.
3. Open the error details dialog and confirm the underlying error
remains available.

This is difficult to test unless you have a properly-failing table. You
can instead do the following locally:

1. Check out `dnywh/tmp/pipelines-running-fixture`.
2. Open `/project/<ref>/database/replication/<pipelineId>`.
3. Use the floating pipeline-state switcher in the bottom-right.
4. Select _Running, some tables errored_.
2026-09-17 12:17:52 +10:00
Danny White 0b002892d7 refactor(studio): simplify pipeline reset dialogs (#50443)
## What kind of change does this PR introduce?

Studio UI refactor.

## What is the current behavior?

Pipeline table reset dialogs repeat explanatory content and use more
layout than the reset decision needs.

## What is the new behavior?

Simplifies the single-table and batch reset confirmations while
preserving their cost estimate, destructive consequences, and existing
reset mutations.

| Before | After |
| --- | --- |
| <img width="854" height="1090" alt="CleanShot 2026-09-16 at 12 54
36@2x"
src="https://github.com/user-attachments/assets/f9eef09b-89d1-4747-bc4c-e81fb64c584b"
/> | <img width="840" height="742" alt="CleanShot 2026-09-16 at 17 01
11@2x"
src="https://github.com/user-attachments/assets/fa45728c-ec66-45c8-9fef-9d2eb8310d4d"
/> |

This is an independent slice extracted from #49630. The related review
series is this one, #50444, #50445, #50446, then #49630.

## To test

1. Open `/project/<ref>/database/replication` and select a pipeline.
2. Reset one replicated table and confirm the dialog explains that
destination data will be deleted and resynchronised.
3. Choose **Reset all tables** and confirm the batch dialog shows the
same concise treatment.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## UI Updates

* **UI Updates**
* Renamed replication “restart” actions to “reset” across dialogs,
buttons, notifications, and cost estimates.
* Updated messaging to clarify whether the pipeline will start or
restart automatically after resetting.
* Added clearer initial-sync guidance for all, some, or none of the
affected tables.
* Improved reset cost estimate messaging, including when no additional
initial-sync charge applies.
* Updated reset dialogs with clearer titles, descriptions, loading
states, and error messages.
  * Disabled reset actions when pipeline status is unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-17 12:13:51 +10:00
cc540ff302 feat(studio): add safe theme colour controls (#49804)
## What kind of change does this PR introduce?

Feature.

## What is the current behaviour?

Studio Appearance preferences only select a theme mode. The underlying
theme colours cannot be adjusted, and the existing proof of concept
allowed unsafe combinations and introduced a bespoke Slider variant.

## What is the new behaviour?

- Preserves the existing System, Dark, Light, and Classic Dark theme
options. Classic Dark remains a fixed preset.
- Adds four theme colour controls using the existing Supabase Slider
unchanged. Each control presents a consistent 0 to 100 scale mapped to
bounded light and dark ranges.
- Previews colour changes while dragging and persists them once the
interaction finishes, including rapid pointer gestures.
- Stores light and dark overrides separately, validates stored values,
clamps legacy values, and removes overrides that return to their shipped
defaults.
- Adds concise descriptions for Chroma, Contrast, Surface, and Elevation
step, with a scoped Reset action shown only when the active theme
differs from its defaults.
- Keeps Slider in a stable shared chunk so production builds do not
create a circular dependency between generated UI chunks.

| Before | After |
| --- | --- |
| <img width="1448" height="1284" alt="CleanShot 2026-09-15 at 14 33
53@2x"
src="https://github.com/user-attachments/assets/d55151c7-b2a9-40c6-9468-e77ae685ac38"
/> | <img width="1454" height="1958" alt="CleanShot 2026-09-15 at 17 48
47@2x"
src="https://github.com/user-attachments/assets/9d302e67-76cc-4341-948c-81713dea2e93"
/> |

## To test

1. Open `/account/me` and scroll to Appearance.
2. Switch between System, Dark, Light, and Classic Dark. Confirm the
same four modes remain available in the account theme menu.
3. Confirm Classic Dark retains its existing appearance and does not
show theme colour controls.
4. In System, Dark, or Light, move each Theme colors slider to both
ends. Confirm the dashboard previews the change, remains readable, and
the theme cards do not shift or remount.
5. Reload the page and confirm colour changes persist separately for
Light and Dark.
6. Return all sliders to their defaults, or select Reset, and confirm
the Reset action disappears.
7. In System mode, change the operating system theme and confirm each
resolved mode restores its own colour settings.

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-09-17 10:33:59 +10:00
Saxon FletcherandClaude Opus 5 91e23a0f2d docs: define detection checks and specialist monitoring prompts (#50075)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

Yes.

## What kind of change does this PR introduce?

Documentation update.

## What is the current behavior?

Specialist monitoring prompts leave some comparison windows, baselines,
thresholds, and missing-data behavior undefined. This can produce
reports or forecasts without sufficient evidence.

## What is the new behavior?

Detection checks define inputs, comparison windows, thresholds, units,
missing-data behavior, and next investigation steps. Query regressions
require comparable snapshots and reset history; capacity forecasts
require saved measurements and a matching confirmed limit.

Health, Security, Performance, and Capacity prompts fetch and follow the
shared detection checks automatically. They record finding, clear, or
unable to assess, preserve alert state, and suppress unchanged repeats.
Missing history or failed access cannot become a healthy result.

Specialist pages retain their diagrams and the sections What it watches,
When it watches, What it will output, and Set up the agent. Setup
explains the necessary documentation access and saved state; optional
links explain report triggers. Prompt and provider setup tabs remain
available in HTML and Markdown. The Hire an agent overview and
Generalist page and prompt remain unchanged.

Prompt Markdown exports use the Markdown serializer to safely contain
nested code fences, preserving the full Generalist prompt and its SQL
examples. Both prompt exporters have parser-based round-trip coverage.

## Additional context

Full docs suite: 215 passed, 2 skipped against a freshly reset
disposable Supabase stack. Typecheck, targeted ESLint, formatting, and
guides Markdown generation also pass after the export fix.

Earlier validation: production docs build, docs typecheck, targeted
ESLint, formatting, and guides Markdown generation pass. All four
specialist exports contain their diagrams, setup sections, enhanced
prompts, and provider instructions. The Health page diagram and setup
tab were checked in the browser. Changed pages have no MDX lint
violations; existing repository-wide violations remain.

The unchanged detection SQL was previously smoke-tested in a disposable
sandbox. Hosted MCP runs, scheduler persistence, notifications, and
agent evals are outside this validation. Evals remain outside this
change.

Stage 3 of 3; depends on stage 2.

Stack: #50073 → #50074 → #50075.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Reworked observability guidance around hourly, read-only monitoring
checks.
- Updated health, security, performance, and usage monitors to identify
new findings, data gaps, regressions, and resource growth.
- Added clearer setup instructions for linked documentation, saved
measurements, and alert state.
- Replaced the issue-detection guide with standardized outcomes:
finding, clear, or unable to assess.
- Added explicit thresholds, evidence details, investigation links, and
verification steps for turning detections into diagnoses.
- **Improvements**
- Standardized monitoring prompts and presentation across supported
agent types.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-17 08:48:51 +10:00
Miranda Limonczenko e8547352c5 docs(auth): answer the four most repeated SSR auth questions (#50289)
Closes DOCS-1313
Closes FDBKIN-4573
Closes FDBKIN-15214
Closes FDBKIN-10628

## Problem

Four asks come up repeatedly in feedback intake. The Eval is green and
this feedback cannot be included in the Eval. Using the Evals work as an
excuse to action on the feedback. 😄

Readers can't tell which auth call verifies a token and which only reads
stored state. They don't know that the response the cookies were written
to is the response they have to return, because that only ever existed
as a code comment. Nobody is warned that refreshing in two places burns
a single-use refresh token, which surfaces as users being signed out at
random. And nothing in `apps/docs` says `proxy.ts` is Next.js 16 and
later, so a reader on 15 writes a file the framework never calls.

## Solution

- Add the fact that `getClaims()` refreshes a session close to expiring
before it verifies. It was only in the typedoc remarks, and it is what
makes the double refresh warning make sense.
- Say that `setAll` rebuilds `supabaseResponse` on every write, so a
response built earlier is stale, and show how to copy the cookies onto a
different one.
- Warn that a second refresh outside the reuse window revokes the
session, linking refresh token reuse detection.
- Note that `proxy.ts` is Next.js 16 and later, and that the file is
`middleware.ts` before that.
- Name the file in the proxy fence in
`examples/prompts/nextjs-supabase-auth.md`, which gave agents the export
name and no path.

The auth methods partial is shared by five other pages, so that first
change surfaces there too.

## Manual testing

1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-feedback-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview. The Next.js panel carries the version note, the
refresh warning, and the response guidance.
2. Select the refresh token reuse detection link. It resolves to the
sessions guide.
3. Open the [Next.js Auth
prompt](https://docs-git-docs-ssr-client-feedback-supabase.vercel.app/docs/guides/ai-tools/ai-prompts/nextjs-supabase-auth).
The proxy section names the file and says it is `proxy.ts` on Next.js 16
and later.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation

- Clarified that `getClaims` refreshes sessions when access tokens are
near expiration, helping server-rendered sessions remain active.
- Expanded Next.js SSR guidance for session-refresh setup, including
file placement and version-specific naming.
- Added warnings about refresh-token reuse and session revocation after
repeated refreshes outside the reuse window.
- Added guidance for preserving authentication cookies and cache-related
headers when returning updated responses.
- Clarified that refreshed tokens should be passed to Server Components
to keep sessions active.
- Clarified the required session-refresh handler export and example
filename.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 12:48:23 -07:00
Miranda Limonczenko a4106b01f5 docs(auth): correct what getClaims verifies, and fix the Express env setup (#50288)
## Problem

These findings came from a technical audit and verification of the
claims in the doc.

I found two accuracy problems:

- **The guide said `getClaims()` is safe to trust** because it
"validates the JWT signature against the project's published public keys
every time". That only describes projects on asymmetric signing keys.
With a symmetric secret it calls the Auth server instead, which the
page's own partial already said. The advanced guide then read as a flat
contradiction: `getUser()` was "the only way" to know a session is
valid. The real distinction is revocation, not verification.

- **Running the Express sample verbatim doesn't work.** In the docs
sandbox, it printed `SUPABASE_URL = undefined`, so `createServerClient`
received undefined for both the URL and the key. The env var tab
installed dotenv twice, once inline and once through the package manager
tabs, and its "And initialize it" lead-in was followed by the second
install rather than any initialization. The route sample then required
dotenv without calling `config()`.

## Solution

- Say what `getClaims()` verifies against in each signing key mode.
- Reframe the advanced guide's `getUser()` answer around session
revocation, so the two pages stop contradicting each other.
- Switch the advanced guide's two middleware snippets from `getUser()`
to `getClaims()`, matching the guide.
- Rename its `Next.js middleware` heading and CloudFront bullet, which
the proxy rename missed.
- Load dotenv on the first line of the Express entry point, and drop the
duplicate install.
- Tag both Express fences `js`. They are CommonJS, not TypeScript.
- Update the stale "middleware refreshing user sessions" comment in the
rendered Next.js `server.ts` sample.

## Manual testing

1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-accuracy-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview, then the Express tab. dotenv is installed once,
followed by `require('dotenv').config()`.
2. Open the [advanced
guide](https://docs-git-docs-ssr-client-accuracy-supabase.vercel.app/docs/guides/auth/server-side/advanced-guide).
The Next.js heading reads `Next.js proxy` and both snippets call
`getClaims()`.

Part of DOCS-1313.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Clarified the difference between token validation and detecting
revoked server-side sessions.
  - Updated Next.js guidance and examples to use “proxy” terminology.
  - Refined CloudFront caching guidance for authenticated routes.
- Improved Express setup instructions, including dotenv loading and
JavaScript examples.
  - Expanded explanations of signing-key verification.
  - Updated Astro and Nuxt examples to forward cache headers correctly.
- Updated session-refresh guidance in the Next.js example to reference
the proxy.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 12:31:11 -07:00
Miranda Limonczenko 7bec687917 docs(auth): regroup the SSR client guide and cut repetition (#50287)
## Problem

`_partials/auth_methods.mdx` was included six times in this one page.
Radix unmounts inactive tab panels, so a browser reader sees it three
times on the default Next.js view, and the generated markdown that
agents read contained all six. That was about 25% of the 33.5 KB export,
and it put the same `Summary of the methods` heading in the table of
contents three times over.

The page is also 900+ lines with no intro outline, the per-framework
recaps were `h2` inside an `h2` section, and six of the nine panels had
no step headings at all.

## Solution

- Include the auth methods partial once, under a new `Choosing an auth
method` section grouped with `Caching considerations`, and point to it
from the procedure. This follows the mixed information types rule in
`apps/docs/CONTRIBUTING.md`.
- Add an intro outline linking the section groups and saying when to
read the two reference sections.
- Demote the eight in-tab `Congratulations` headings to `h3` so they
nest under `Create a client`.
- Add a `Create the Supabase clients` heading to Astro, Remix, Nuxt,
React Router, Express, and Hono, and the recap Hono was missing.

No claims changed here, only placement.

## Manual testing

1. Open the [SSR client
guide](https://docs-git-docs-ssr-client-structure-supabase.vercel.app/docs/guides/auth/server-side/creating-a-client)
on the deploy preview. The table of contents lists `Summary of the
methods` once.
2. Select each of the five links in the intro paragraph. Each one
scrolls to its section.
3. Select each framework tab. Every panel has a step heading and a
recap.

Part of DOCS-1313.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added an introductory setup overview covering installation,
environment variables, client creation, authentication methods, and
caching.
  - Added dedicated guidance for choosing an authentication method.
- Added Astro SSR and client sections, along with a complete Hono recap.
  - Reorganized framework headings for clearer navigation.
- Consolidated authentication guidance by removing duplicate content
from individual framework sections.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 12:12:06 -07:00