mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
ebfec0df36033914faeae789bfeb3d2ecec8b10b
36258
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
ebfec0df36 |
Improve click targets on property actions (#45936)
## Context When opening the logs detail panel, some of the fields can be clicked to add them as a filter. However the existing UX is that the clickable part is just the text which makes it target small <img width="233" height="127" alt="image" src="https://github.com/user-attachments/assets/1d876bcc-05cf-464c-bdbe-907229be0586" /> Am opting the following: - Make the whole row clickable - Make all rows clickable with the main action being "Copy {column}" - Only filterable columns will have the option to "Add as filter" ### After <img width="483" height="153" alt="image" src="https://github.com/user-attachments/assets/9d6e5479-fdbb-4609-839c-2bb7ad571b57" /> <img width="473" height="152" alt="image" src="https://github.com/user-attachments/assets/f22197df-fa59-4e01-be00-2557260374f8" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Row actions now consistently wrap rows and show a filter icon next to the label when a resolved filter is available; copy menu displays "Copy {label}". * **Style** * Standardized icon sizes and adjusted dropdown/row spacing; simplified text wrap/truncate behavior for field values; minor status text color refinement. * **Bug Fixes** * Dropdown row-action rendering made more robust to ensure menu wrappers render reliably. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45936) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ec21e68eee |
studio(logs): use safe sql escaping for new logs queries (#45887)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Introduced a safe SQL fragment system and helpers to build composable, validated log queries and aggregations. * **Refactor** * Rewrote unified log query builders and inspection flows to use the new safe fragments and identifier/literal validators. * **Bug Fixes** * Improved validation and error handling for filter keys and literal escaping to prevent malformed or injectable queries. * **Tests** * Added tests covering identifier quoting, value escaping, and rejection of invalid filter inputs. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45887) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c104beabb6 |
fix(docs,www): redirect feature status page to /features (#43224)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Redirect + link cleanup: deprecating the docs feature status page in favour of the marketing features page. ## What is the current behavior? supabase.com/docs/guides/getting-started/features is a standalone docs page with a flat feature status table. The existing /docs/features short URL redirects to this docs page. A self-hosted troubleshooting article links to the old docs page. ## What is the new behavior? /docs/guides/getting-started/features and /docs/features both permanently redirect to /features (supabase.com/features) The self-hosted troubleshooting article now links to /features The features.mdx file is left in place; the redirect intercepts all traffic before it renders ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Reorganized navigation menu and documentation link paths * Updated feature-related links across guides and troubleshooting sections * Added redirect rules to maintain backward compatibility with previous URLs <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana Mogul <ana1337x@users.noreply.github.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
eb915e99f8 |
Joshen/debug 76 fix sticky hover state on log rows (#45933)
## Context The original problem was that some log rows remain in the hover state after the cursor moves away I was just cleaning up some of the styles and noticed that it doesn't seem to happen anymore so thinking this might have fixed it haha 😅 ## Changes involved - Remove `group-hover` background color change behaviour in `TableCell` in `ui` - `TableRow` should handle the background color instead, hence the changes in `UnifiedLogs.utils` too - Remove unnecessary `renderLiveRows` in `DataTableInfinite` -> the prop isn't being passed anywhere ## To test - [ ] The sticky hover state happens when you hover over the rows very quickly, so just make sure there's no "stale" hover state in any row eg: <img width="400" alt="image" src="https://github.com/user-attachments/assets/b4a91bc6-d269-4ee6-b222-b0476b9feffa" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Standardized hover styling for log rows and table cells to use direct hover rules for more consistent visual feedback. * Adjusted table cell hover/transition behavior to simplify styling while preserving layout and checkbox spacing. * Streamlined the data table API by removing the custom live-row rendering override. * Made the resizable panel’s minimum size dynamic based on dock position. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45933) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b56ba64d2e |
fix: tooltip dates (#45922)
## TL;DR fixes one day off observability tooltip ## before: <img width="227" height="159" alt="image" src="https://github.com/user-attachments/assets/6cc8653f-2304-4d63-bf53-af01425c0d96" /> ## after: <img width="288" height="200" alt="image" src="https://github.com/user-attachments/assets/9aa35e63-2fbc-42aa-82c8-1a3b158e6f40" /> ## ref: - closes https://github.com/supabase/supabase/issues/45921 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved chart tooltip date label formatting: tooltips now detect ISO-like date strings and format them consistently, while preserving previous formatting for other values. This change ensures correct, readable dates in both bar and line chart tooltips within reports. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45922) <!-- review_stack_entry_end --> <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45922) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
51c1de7c18 | fix(self-hosted): use curl -f in analytics healthcheck (#45929) | ||
|
|
5195415de1 |
chore(privacy): update privacy terms (#45900)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Minor updates to add customer.io <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a comprehensive privacy policy page with detailed privacy notices, including sections on data collection, sharing, user controls, cookies, retention, security, and regional disclosures. * Updated existing privacy policy with refreshed information, expanded marketing and advertising purposes, and clarified third-party service provider details. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45900) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ea03214d3d |
Support dock position (#45919)
## Context Added an option to change dock position when a row is selected in unified logs Just note that this involves the `LogsListPanel` - i'm not too sure how this will look like tbh as I don't have any logs in my unified logs UI that match the criteria to render the `LogsListPanel` (e.g there could be a scenario where we have 3 panes side by side) <img width="1452" height="955" alt="image" src="https://github.com/user-attachments/assets/21c1a576-7f63-463f-88bf-04c05691995b" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Users can now toggle the service flow panel dock position between bottom and right alignment * Dock preference is automatically saved and persists across sessions * **Bug Fixes** * Improved logs data validation in the logs list panel for more reliable rendering <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45919) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cf49bc74ef |
Update copy for adding filter from log details (#45918)
## Context
Just updates the copy for adding filters from the log details in unified
logs. "Include" was vague so opting for something more clearer, "Add as
filter for {column}"
### Before
<img width="199" height="130" alt="image"
src="https://github.com/user-attachments/assets/b5e0231c-99de-42a3-9cf2-66e0d9558379"
/>
### After
<img width="262" height="140" alt="image"
src="https://github.com/user-attachments/assets/8e8e3889-443c-4566-b118-7a13eb60f3b1"
/>
<img width="235" height="146" alt="image"
src="https://github.com/user-attachments/assets/e23b15ff-dd35-4e47-9d17-a82c8b898534"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved data table filter dropdown UI with clearer action labels and
properly sized icons for checkbox and input filter types.
* Expanded filter dropdown menu width for better visual clarity and
usability.
<!-- review_stack_entry_start -->
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45918)
<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
98ecf8001e |
Use font mono for unified log rows (#45917)
## Context Opting to use `font-mono` and `tracking-tight` for all the data within the unified logs table to improve readability ### Before <img width="1451" height="956" alt="image" src="https://github.com/user-attachments/assets/8c3f51b8-40bb-4e84-b1b3-af4d69e92224" /> ### After <img width="1450" height="959" alt="image" src="https://github.com/user-attachments/assets/5cb64864-fdf8-4c97-8caf-a440aa405b3d" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Refined the visual styling of the Unified Logs table columns for improved readability, including updated typography and letter spacing for the Date, Method, Pathname, and Event message columns. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45917) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1b3a88a323 |
Opt to use Code2 icon instead of BookHeart for unified logs postgrest rows (#45916)
## Context We use the `Code2` icon for the Data API integration, so opting to use the same icon for Postgrest in unified logs for consistency <img width="538" height="176" alt="image" src="https://github.com/user-attachments/assets/cd98d781-be60-4d09-9dcb-6f064c58f446" /> ### Before <img width="422" height="87" alt="image" src="https://github.com/user-attachments/assets/4c7024ad-b5a7-48aa-8f27-46bb8cd94b57" /> ### After <img width="434" height="89" alt="image" src="https://github.com/user-attachments/assets/4bc18b10-53ee-4c57-89e3-52f45cc8fc07" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Updated the icon representation for PostgreSQL REST API logs to enhance visual clarity and user recognition. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45916) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
597ad2ba56 |
Fix width of unified logs table to fit viewport, which fixes centering of load more button (#45914)
## Context Load more button in unified logs was off center because the `table` element was exceeded the viewport width. The fix needed was hence to adjust the width of the `table` to only take up the remaining width of the viewport which then fixes the positioning of the load more button. ### Before <img width="1446" height="204" alt="image" src="https://github.com/user-attachments/assets/fcd99e18-ede8-4454-b612-91b4384fb3e1" /> ### After <img width="1450" height="274" alt="image" src="https://github.com/user-attachments/assets/d5f56383-bdb0-4418-a36f-242e72fe3a5b" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated table container styling and layout properties for improved rendering. * Enhanced table header cell structure with improved styling attributes. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45914) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8ee2f90d65 |
Target hover background color change for unified log rows to the cell (#45915)
## Context The `TableCell` component from `ui` has a `group-hover:bg-surface-200` class name ([ref](https://github.com/supabase/supabase/blob/master/packages/ui/src/components/shadcn/ui/table.tsx#L152)), hence the original class names in `UnifiedLog.utils.ts` which targets only the table row's background color on hover doesn't work. Hence fix is to target the `td` element on row hover to apply the background color change Although separately, i'm wondering whether it makes more sense for the hover bg color change to be applied on the `tr` instead of `td` ### Before <img width="1182" height="61" alt="image" src="https://github.com/user-attachments/assets/78939525-7832-4c4f-8985-e856715a731b" /> ### After <img width="1211" height="79" alt="image" src="https://github.com/user-attachments/assets/5726063d-d06a-439c-90d8-a27407a94a05" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Enhanced hover interactions for warning and error log rows with improved dark mode styling consistency. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45915) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
59c550ac49 |
Improve loading state for unified logs (#45913)
## Context Improves loading state for unified logs ### Before <img width="1451" height="957" alt="image" src="https://github.com/user-attachments/assets/97280982-1358-4234-bcf4-d3e6590040b9" /> ### After <img width="1451" height="956" alt="image" src="https://github.com/user-attachments/assets/b28eb3a8-e7eb-4fc9-bd0d-d0c8d40933ec" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Organization slug field now displays as read-only. * Data table loading states now show skeleton rows with shimmer effect instead of spinner. * Empty state displays simplified "No results found" message. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45913) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
897043952a |
feat: add edge function secret installation method (#45826)
Adds a new method of installation detection for partners like Doppler. Doppler creates edge function secrets with specific names (`DOPPLER_CONFIG`, `DOPPLER_ENVIRONMENT`, and `DOPPLER_PROJECT`). This method allows the dashboard to check for the presence of such a secret to show the installation status. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Support for edge-function-secret-based OAuth identification and verification. * Installation checks adapt to the selected installation method and only fetch required credentials when needed. * Integration detection can validate installations via API key prefixes or matching edge-function secret names. * **Chores** * Shared helper utilities and types exported to streamline installation checks and mappings. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45826) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
19e0b36650 | feat(logs): migrate unified logs queries to OTEL endpoint DEBUG-71 (#45642) | ||
|
|
2efaf8e5c1 |
chore(upcoming invoice): min amount / no plan fee (#45877)
Prep work for new platform plan <img width="733" height="120" alt="Screenshot 2026-05-13 at 8 25 29 PM" src="https://github.com/user-attachments/assets/5667bb86-e317-44f7-86ac-07a8c5cc1994" /> |
||
|
|
fd01c665e2 |
feat(studio): move Stripe Projects to connect interstitial (#45862)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature update. Resolves DEPR-553. ## What is the current behavior? Stripe Projects login still uses the older `APIAuthorizationLayout` surface, so it does not match the newer shared connect interstitial pattern used by organisation invites and CLI login. ## What is the new behavior? Moves `/partners/stripe/projects/login` onto the shared `InterstitialLayout` while preserving the existing `ar_id` account request lookup, confirmation mutation, wrong-account sign-out path, and missing-parameter redirect. The temporary reviewer mocks have been removed after approval. ## Testing instructions Automated checks run locally: - `pnpm --dir apps/studio exec prettier --write pages/partners/stripe/projects/login.tsx components/layouts/InterstitialLayout.tsx` - `pnpm --dir apps/studio exec eslint pages/partners/stripe/projects/login.tsx components/layouts/InterstitialLayout.tsx` - `git diff --check` `pnpm --dir apps/studio exec tsc --noEmit` was also run earlier on this branch, but still fails on existing unrelated issues in `components/interfaces/Integrations/Landing/useAvailableIntegrations.tsx` and `packages/common/marketplace-client.ts`. Manual Stripe Projects testing requires a real account request. Opening `/partners/stripe/projects/login` without an `ar_id` redirects to `/404` by design. If you need the real flow: 1. Use the Stripe staging provider. In the Stripe CLI flow, run `export DEV_MODE=true` so the provider is `Supabase_Staging_Env`. 2. From a local project directory, run `stripe projects init` and complete the Stripe setup flow. 3. Run `stripe projects add Supabase_Staging_Env`. 4. When the browser opens the Supabase authorization URL, keep the generated path and query string exactly as-is, including `ar_id`, but replace only the origin with this PR preview deployment origin. Note: the staging Stripe Projects flow can still incur real Stripe costs; use the staging provider and coordinate refunds with team billing if needed. ## Additional context This is a deliberately small stacked slice toward the broader shared connect interstitial work. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **User Interface** * Redesigned Stripe authorization login page with improved layout and visual state management * Enhanced account row component to support flexible action buttons and styling * Added clearer messaging and UI states for authorization scenarios (pending, success, errors, and account mismatches) <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45862) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2acceffdc8 |
blog(www): add Saxon Fletcher as author on branching post (#45884)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Adds Saxon Fletcher as a co-author on the branching without Git blog post - Adds Saxon Fletcher entry to Authors.json ## What is the current behavior? The blog post lists joshenlim and qiao as authors only. ## What is the new behavior? - Saxon Fletcher is added as a third author on the post - Saxon Fletcher's author profile is added to Authors.json with GitHub username SaxonF ## Additional context N/A <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Blog post frontmatter updated to credit an additional contributor. * Added a new author profile to the site’s author data. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45884) <!-- review_stack_entry_end --> <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45884) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Ana <ana1337x@users.noreply.github.com> |
||
|
|
5a41d0155e |
chore: integration UI refinement (#45507)
This PR: * Refactors integrations page implementation to make it simpler and easier to understand. * Integration category pages from marketplace db show category name and description. * Shows featured integrations coming from the marketplace db at the top of the page. * Hides empty categories: https://linear.app/supabase/issue/INT-113/hide-empty-categories-on-dashboard-integrations-page Below design related fixes will be done in a separate PR: https://github.com/supabase/supabase/pull/45856. So this PR is ready to merge with current fixes. <details> ~~Design fixes needed after consulting with the design team:~~ - [ ] ~~Do not use inverted colors on images for featured integrations. This leads to inconsistent images for the featured marketplace listings. E.g. Grafana listing shown in the featured listings:~~ <img width="463" height="260" alt="image" src="https://github.com/user-attachments/assets/76816807-667f-44b0-b68c-5e1ca342be1f" /> ~~vs shown on it's own page:~~ <img width="909" height="667" alt="image" src="https://github.com/user-attachments/assets/00efda48-3e4e-4b05-87ad-cbbce9047c94" /> - [ ] ~~The images on featured marketplace integrations should not be truncated as seen in the first image above.~~ - [ ] ~~The **Install integration** button feels floating far out on the right.~~ - [ ] ~~The description under the title is too long and truncated. Requested by Doppler here: https://supabase.slack.com/archives/C0AL11JG5MG/p1778009104728819?thread_ts=1777654129.027269&cid=C0AL11JG5MG~~ - [ ] ~~The content section doesn't render bulleted lists correctly.~~ </details> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Dedicated "Featured Integrations" section on the integrations page. * Integrations can be marked as featured to appear in the featured section. * **Improvements** * Sidebar shows only categories that contain integrations. * Integration image handling improved for featured cards. * Updated loading placeholders for integrations to provide a smoother loading experience. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45507) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Saxon Fletcher <saxonafletcher@gmail.com> |
||
|
|
095b618297 |
Updated dinner details for NYC Exec Dinner (#45901)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Updated dinner date and time for NYC dinner go page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Executive Dinner now shows the date (June 10, 2026) and revised times: cocktails at 6:30 PM, dinner at 7:00 PM. * **New Features** * RSVP form adds optional Job Title and Phone Number fields; company placeholder set to “ACME, Inc.” * **UI** * Event details now display a dedicated Date block and show Location after the date. * **Integrations** * RSVP integrations updated to include the new fields. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45901) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2d2cc95caa |
studio: add SafeSql foundation utilities (1/7) (#45897)
## Summary First in a stack of seven PRs migrating the remaining `executeSql` call sites to `SafeSqlFragment`. This PR lands pure additions — shared types and helpers that later PRs import. - `apps/studio/lib/postgres-types.ts` — `SafePostgresColumn` / `SafePostgresTable` wrappers over `PGColumn` / `PGTable` that brand `check` as `SafeSqlFragment` and add the optional `format_schema` field - `apps/studio/lib/sql.ts` — `trimSafeSqlFragment` overload set that preserves the brand through `.trim()` - `apps/studio/lib/type-helpers.ts` — refine `DeepReadonly` so primitives pass through unchanged - `apps/studio/components/ui/SafeSqlInput.tsx` — `<Input>` wrapper that emits `SafeSqlFragment` via `rawSql` No consumers in this PR. The next PRs in the stack pick these up. ## Stack This is PR 1 of 7. The full sequence: 1. **This PR** — Foundation utilities 2. `charis/safe-sql-last/2` — pg-meta columns + ColumnTypeRef cascade 3. `charis/safe-sql-last/3` — pg-meta non-column SafeSql (functions/policies/triggers) 4. `charis/safe-sql-last/4` — Studio reports / query performance / privileges 5. `charis/safe-sql-last/6` — Stragglers + remaining tests 6. `charis/safe-sql-last/7` — Flip `executeSql` signature from `string` to `SafeSqlFragment` ## Test plan - [x] `pnpm typecheck` passes for the Studio target on this branch - [x] No runtime behavior changes — only type-level additions and a new unused component <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Introduced SafeSqlInput component providing secure and validated SQL query input handling with built-in constraints and error prevention. * **Refactor** * Enhanced internal type definitions and utilities for Postgres metadata handling and SQL operations to improve code reliability and maintainability. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45897) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0dd23ba5a6 | docs: clarify path to database password reset in dashboard (#45853) | ||
|
|
9b86b6ca25 |
test: cron coverage (#45895)
adds coverage for: - https://github.com/supabase/supabase/pull/45848 which solved/closed: https://github.com/supabase/supabase/issues/45860 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Enhanced test coverage for parsing SQL commands with lowercase statements to ensure robust handling of case-insensitive input. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45895) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d4079083fc |
chore(studio): drop @supabase/postgres-meta in favor of @supabase/pg-meta (#45844)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Refactor / dependency cleanup. ## What is the current behavior? `apps/studio` lists both `@supabase/pg-meta` (workspace package) as a runtime dep and `@supabase/postgres-meta` (external npm package, `^0.64.4`) as a devDependency. The external package is used only for type imports across 44 files — there is no runtime usage and no codegen pipeline that needs it. ## What is the new behavior? Every `Postgres*` type import (`PostgresTable`, `PostgresColumn`, `PostgresPolicy`, `PostgresTrigger`, `PostgresView`, `PostgresMaterializedView`, `PostgresForeignTable`, `PostgresSchema`, `PostgresPublication`, `PostgresRelationship`, `PostgresPrimaryKey`) is replaced with its `PG*` counterpart from `@supabase/pg-meta`, and the external dep is removed from \`apps/studio/package.json\`. Top-level type re-exports were added to \`packages/pg-meta/src/index.ts\` so consumers can import directly from the package root. Two latent issues surfaced by the stricter pg-meta types are also fixed: - \`data/foreign-tables/foreign-tables-query.ts\` was casting foreign-table results as \`PostgresView[]\`; corrected to \`PGForeignTable[]\`. - \`pg-meta\`'s \`PGTrigger\` Zod schema declared \`orientation\`/\`activation\` as \`z.string()\`, inconsistent with pg-meta's own \`getDatabaseTriggerUpdateSQL\` helper that requires the narrow literal unions; tightened to \`z.enum\`. ## Additional context <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated internal TypeScript type definitions across the codebase to use the latest type system from `@supabase/pg-meta`. * Removed `@supabase/postgres-meta` dependency. * Enhanced type validation for database triggers and schemas to enforce stricter constraints. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45844) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6383150c3e |
fix(tests): flaky unit tests (#45852)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Typing each character by hand leads to slowness with multiple render cycles in CI - Update timeouts <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Improved test reliability and stability for the Support form page. Enhanced test synchronization and timing for UI interactions including form field prefilling, organization and project selection, category and severity assignment, form submission, error notifications, dashboard logging toggles, and attachment uploads. These enhancements strengthen test quality and help prevent regression issues in form functionality. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45852) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fe769bfe7e |
fix: escape quotes (#45848)
## TL;DR - closes https://github.com/supabase/supabase/issues/45860 - closes https://github.com/supabase/supabase/issues/45544 & supersedes https://github.com/supabase/supabase/pull/45543 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added explicit allowed facet fields and validation to prevent invalid facet usage. * **Bug Fixes** * Improved filter handling by coercing values to strings and properly escaping single quotes for array, scalar, and LIKE filters (including facet search), reducing query errors and injection risks. * Enhanced parsing of scheduled-job SQL commands to tolerate varied casing/whitespace and strip leading SELECT before processing. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45848) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
712cf7e60b |
feat(storage): add keyboard shortcuts for storage screens (#45837)
## Summary
Adds keyboard shortcuts to the Storage section, mirroring the
conventions already established for Auth Users and Database pages:
- **Storage navigation chords** (`S, F` / `S, A` / `S, V` / `S, 3`)
active only inside `StorageLayout`.
- **Files (bucket list) page** shortcuts for search, create, refresh,
reset filters, reset sort.
- **Storage Explorer** shortcuts for upload, new folder, view toggle,
refresh, search, multi-select download/move/delete, and an Escape
ladder.
- `ShortcutTooltip` wired into the relevant buttons so users can
discover keybinds on hover.
- Reload spinner is now driven by a shared store flag, so it shows
whether you click the button or fire the shortcut.
## Test plan
### Storage navigation chords
Active anywhere under `/project/<ref>/storage/*`.
| Keybind | Action |
|---------|--------|
| `S` then `F` | Go to Files |
| `S` then `A` | Go to Analytics buckets (platform + feature-flagged) |
| `S` then `V` | Go to Vector buckets (platform + feature-flagged) |
| `S` then `3` | Go to S3 settings (platform only) |
### Files (bucket list) page
At `/project/<ref>/storage/files`.
| Keybind | Action | Notes |
|---------|--------|-------|
| `Shift+F` | Focus search ("Search buckets") | Selects existing text |
| `Shift+N` | Create new bucket | Opens the create-bucket modal |
| `F` then `C` | Reset filters | Clears the search string |
| `Shift+R` | Refresh buckets | Refetches the bucket list |
| `S` then `C` | Reset bucket sort | Only fires when sort ≠ default
(Created at) |
### Storage Explorer (inside a bucket)
At `/project/<ref>/storage/files/buckets/<bucketId>`.
| Keybind | Action | Notes |
|---------|--------|-------|
| `Shift+F` | Focus search ("Search files") | Opens the search input if
hidden, then focuses |
| `Shift+R` | Refresh | Refetches all opened folders; spinner reflects
state |
| `I` then `F` | Upload files | Disabled w/o ` STORAGE_WRITE ` or at
bucket root with no folder |
| `I` then `N` | Create folder | Same permission gates as Upload |
| `V` then `C` | View as columns | |
| `V` then `L` | View as list | |
| `Shift+D` | Download selected | Only fires when ≥1 item selected;
single vs many handled |
| `Shift+M` | Move selected | Only fires when ≥1 item selected AND `
STORAGE_WRITE ` granted |
| `Mod+Backspace` | Delete selected | Only fires when ≥1 item selected
(` Mod ` = ⌘ on macOS / ` Ctrl ` on Win/Linux) |
| `Escape` | Clear selection | If ≥1 item selected |
| `Escape` | Close file preview | If no selection and preview pane open
|
| `Escape` | Close search | If no selection, no preview, and search is
open |
### Tips while testing
- [x] Chords (two-key sequences): press the first key, release, then
press the second key within ~1s
- [x] Hover any wired button (search, Refresh, Upload, Create folder,
View, Download, Move, Delete, the bucket Create button, sidebar items)
to see the keybind in a tooltip
- [x] Most actions also appear under "Shortcuts" in `Cmd+P`
- [x] Chords starting with a plain letter (` S, F ` / ` I, F ` / ` V, C
` / ` F, C ` / ` S, C `) won't fire while typing in an input — click out
first
- [x] `Escape` does fire from inside the search field (closes the
search)
- [x] `Cmd+/` opens the full shortcuts reference
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Keyboard shortcuts added across Storage: buckets (refresh, clear sort,
create, search), explorer (upload, create folder, refresh, download,
move, delete, clear search), and navigation shortcuts for
Files/Analytics/Vectors/S3.
* **UI**
* Shortcut keytips/tooltips added to relevant buttons and menu items for
discoverability.
* **Documentation/Tests**
* Shortcut reference sheet labels updated and covered by a new test.
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45837)
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
|
||
|
|
8ca04989c8 |
fix(studio): reports table footer overflow (#45885)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? A small bug that was causing the overflow of chart table footers to break on smaller viewports. Now fixed along with cell horizontal spacing. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Enhanced table layouts in the Reports section by enabling horizontal scrolling for API Routes and Cache Misses tables, ensuring all data is visible on various screen sizes. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45885) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e492477ad4 |
feat(marketing): add anti-spam protections to /go forms (DEBR-280) (#45842)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — anti-spam protection for all `/go` lead-gen forms. ## What is the current behavior? The shared `MarketingForm` used by every `/go` page has no spam protection: no honeypot, no captcha, no timing check, no dedupe. The Datadog NYC exec dinner form was getting probed with spam submissions ([DEBR-280](https://linear.app/supabase/issue/DEBR-280/reduce-spammy-submissions-on-exec-dinner-form)). ## What is the new behavior? Three layered defenses added to the shared `MarketingForm` + `submitFormAction` so every `/go` form is covered: 1. **Honeypot** — hidden `website` input (off-screen, `aria-hidden`, `tabIndex={-1}`). Server returns a fake success when filled so bots don't probe variations. The field is stripped from the payload before CRM fan-out. 2. **Minimum render-time check** — server rejects submissions that come back in under 3s with a fake success. 3. **Per-session email/form dedupe** — `sessionStorage` keyed by `formGuid`/`database_id` + email blocks double-submits; the success state is shown without re-hitting HubSpot/Customer.io/Notion. ## Additional context No new env vars or services required. Honeypot rejections are logged via \`console.warn\` for monitoring. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Enhanced anti-spam protections (honeypot and minimum render time) to block bots. * Prevents accidental duplicate submissions within the same browser session. * Avoids creating duplicate contact/record entries when an existing email is found in storage. * **Other Improvements** * Cleaner event/context data sent to analytics for more accurate tracking. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45842) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1a52c4618f |
fix(www): mobile partner form blank panel on submit success (#45836)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? On the [AI Builders](https://supabase.com/solutions/ai-builders) page (and any other surface using the Talk to Partnerships form), submitting on mobile rendered a blank square instead of the submission confirmation. Linear: [DEBR-279](https://linear.app/supabase/issue/DEBR-279/mobile-partner-form-submit-state-renders-blank-panel). ## What is the new behavior? The success state in `TalkToPartnershipTeamForm` now drops `min-w-[300px]` (which overflowed narrow mobile viewports), removes the redundant `opacity-0`/`transition-opacity` pair that occasionally left the panel stuck at opacity 0 on iOS Safari, and removes the invalid `scale-1` class. The parent panel is now `flex flex-col` so the success message can use `flex-1` to center properly within the `min-h-[200px]` panel. ## Additional context The `animate-fade-in` keyframe already uses `both` fill-mode, so it handles the initial-to-final opacity transition without needing the extra `opacity-0` class. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated success-state container layout and styling with improved flex sizing and spacing behavior. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45836) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
71e94a1590 |
Add partner integration guide and mermaid diagrams (#45730)
- **Draft** - **Update** - **feat: add beautiful-mermaid and integration flow diagrams** - **Make mermaid theme match site** <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Mermaid diagram rendering in docs with themed SVG output. * **Documentation** * Added "Supabase Partner Integration Guide" covering simple and signed-redirect flows, JWT verification, sequence diagrams, and key guidance. * Updated site navigation to include the new partner integration guide. * **Chores** * Added Mermaid rendering dependency. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45730) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> |
||
|
|
8459c34202 |
fix(studio): export metric banner logos overflow (#45879)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? These logos began to overflow the more log drains we've added. Imported the animated logos from the empty state of log drains settings on free accounts. | Before | After | |--------|--------| | <img width="317" height="256" alt="Screenshot 2026-05-13 at 13 38 11" src="https://github.com/user-attachments/assets/46f04abc-fe33-48f2-8c1f-7d543c85b5a8" /> | <img width="638" height="540" alt="CleanShot 2026-05-13 at 13 47 11" src="https://github.com/user-attachments/assets/e49a9123-f486-45d8-9714-ef41402762d6" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Expanded support for additional telemetry and service integrations including OTLP, Amazon S3, Axiom, Last9, and Syslog in the Log Drains interface. * **Refactor** * Updated animated logo component to support flexible sizing and styling options, improving layout consistency across the metrics API banner. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45879) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
28f5484369 |
Prevent request billing owner for downgrade of plan (#45823)
Related PR: https://github.com/supabase/supabase/pull/45803 Opting for a simpler way to prevent requesting billing owners for downgrading of plan as such: <img width="933" height="258" alt="image" src="https://github.com/user-attachments/assets/604b8c2f-9341-4aec-885c-e2d9d2861b9f" /> Currently we're incorrectly showing a "Request to upgrade to Free" CTA ## To test - [ ] For a pro plan or above organization, and a user that has a "Developer" role, ensure that you're not able to downgrade the org nor send a upgrade request <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Clarified CTA behavior for users without billing update permission: downgrade actions now show a disabled button with an explicit tooltip, while non-downgrade upgrade attempts prompt a request to billing owners. Tooltip messaging has been refined across enterprise, free-tier, and marketplace-managed plans for clearer guidance. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45823) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2d47836f39 |
Joshen/fe 3213 make rls tester feedback callout more obvious (#45820)
## Context Minor nit to adjust the "Give feedback" button at the bottom to use default type + external link icon <img width="612" height="68" alt="image" src="https://github.com/user-attachments/assets/e74370cb-d284-4552-a69d-8c838f565af7" /> Also added telemetry for the "Run query" button <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added analytics tracking for RLS Tester query runs to better understand how the feature is used. * **Style** * Updated the "Give feedback" button in the RLS Tester to use the default button style and display an external-link icon for clarity. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45820) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
380c917b94 |
chore: Bump vulnerable dependencies (#45876)
- Bump various vulnerable dependencies, `nitropack`, `mermaid`, `hono`, `protobufjs`, `fast-xml-builder` and `fast-uri`. - Add `babel/core` to `studio` to stabilize the dependency resolving for `studio`. - Also deduped `cheerio`, `c12`, `browserslist`, `unstorage` and `@mdx-js/mdx` since they were present as multiple similar versions. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Added development dependency for the studio application build tooling * Updated workspace configuration to refine dependency exclusion settings <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45876) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
376d85d7b2 |
fix(studio): query performance query column truncation (#45878)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Previously our Query Performance Query column was scrollable inline. This means if you have thicc scrollbars turned on via your OS, it would look a bit clunky. This fix truncates query, full query still viewable in the click through sheet. | Before | After | |--------|--------| | <img width="1106" height="1164" alt="cleanshot_2026-05-13_at_18 56 16_2x" src="https://github.com/user-attachments/assets/4718e8d7-d3c5-499b-a125-6192ac547bfe" /> | <img width="456" height="286" alt="Screenshot 2026-05-13 at 13 34 30" src="https://github.com/user-attachments/assets/7446afb5-c0d7-4272-905a-42c144334472" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Style** * Adjusted query column width in the query performance monitoring table for optimized layout. * **Bug Fixes** * Enhanced query display rendering with improved data type handling to prevent potential display issues. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45878) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
835284bca9 |
docs: link recursive functions guide from trace rate limit troublesho… (#45872)
**Documentation** * Added reference to the "Recursive Functions — What gets rate limited" guide in troubleshooting documentation to help users understand rate limiting behavior with recursive invocations. |
||
|
|
0abe792889 |
chore: Migrate the main Tailwind JS config to CSS (#45686)
This PR migrates the JS config for Tailwind into a CSS config. As such, all variables have been defined as CSS variables and they're using the specialized Tailwind syntax for generating utility classes. Beside the migration, these changes were also added: - Added `tailwind.config.css` to few packages to make the Tailwind Intellisense work. - Migrated away from Radix style color classes to our defined classes, the values will remain the same. - Most of the CSS is generated by scripts, they'll be removed in next PRs. * Removed redundant `border-light` classes from several components since it was undefined. * Removed redundant `text-strong` classes from several components since it was undefined. How to test: - Open all apps, compare the UI (mainly colors) to builds from #45417 and try to find a difference. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Harmonized color variable usages and updated UI color references (affects palettes, charts, gradients, hero illustrations, and scrollbars). * Tweaked border, tab, and selection visuals across components. * **New Features** * Added a suite of theme animations and refined typography presets used by site prose and docs. * **Refactor** * Overhauled Tailwind/theme configuration and color token generation for more consistent theming. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d6d644ec24 |
Update project name if dashboard is local CLI (#45864)
## Context Very minor one, just updates the project name for local CLI, to show "Supabase Studio (CLI)" instead of "Default project" which is a bit more meaningful <img width="1450" height="374" alt="image" src="https://github.com/user-attachments/assets/b6c60172-99e2-43b7-a095-2914248ed292" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Updates** * Refined Project dropdown styling in non-platform mode with improved spacing and text sizing * Default project name now dynamically displays as "Supabase Studio (CLI)" when applicable * Minor header layout tweaks for more consistent spacing and transitions * Improved local version indicator initialization for more reliable version display * **Other Updates** * Small code and organization refinements [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45864) <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45864) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9e0feb5740 |
fix: search on the partners/integrations page was still using misc db (#45866)
The `INTEGRATIONS_MARKETPLACE_DB` was not included in the client bundle (because it doesn't start with `NEXT_PUBLIC_`) which caused the client side search functions on the https://supabase.com/partners/integrations page to keep using the older misc db for search. Steps to reproduce: * Go to the https://supabase.com/partners/integrations page. * Search for `aikido`. * Click the only tile found for this search term. Notice that it takes you to `https://supabase.com/partners/integrations/aikido-security` which 404s. This is because that slug (`aikido-security`) is coming from the old misc db. The correct slug in the new db is `aikido`. Other fixes: * Corrected the tsv column name from `tsv` to `listing_tsv`. * Fixed search debouncing. |
||
|
|
bcfc666284 |
chore: migrate remaining old input usages (#45791)
## Problem We still use our old `Input` in some places. This means multiple components are bundled for the same use cases and we have some design differences across the application. ## Solution - [x] Migrate to the new ShadCN inputs - [x] Fix `<InputGroupButton>` cannot be used with components that triggers modal, popovers, dropdowns - [x] Fix `<FormLayout>` does not display errors for inputs that are not inside a React Hook Form - [x] Fix `InputGroup` invalid design ## Screenshots ### Table Editor - table edition sidepanel Before: <img width="758" height="1206" alt="image" src="https://github.com/user-attachments/assets/d4da4af0-a9d3-4967-935f-554233d7896b" /> After: <img width="747" height="1209" alt="image" src="https://github.com/user-attachments/assets/6286e6a0-317f-486c-a8b4-0e233706ba0f" /> ### Table Editor - row edition sidepanel Before: <img width="675" height="710" alt="image" src="https://github.com/user-attachments/assets/9fdfe819-6d62-40c8-bdc8-fa6051dab834" /> After: (I placed the TextArea button at the bottom because ShadCN reserves a full line space for it. It was weird at the top. <img width="674" height="714" alt="image" src="https://github.com/user-attachments/assets/611d5f8d-de12-4c16-ac38-bd9192cd6d73" /> ### Database settings - password reset modal Before: <img width="773" height="548" alt="image" src="https://github.com/user-attachments/assets/17f679a7-3aed-4cf9-8245-194a8a16823f" /> After: <img width="563" height="311" alt="image" src="https://github.com/user-attachments/assets/08888471-4cc8-4a3c-bf1e-8dce364f1aa6" /> ### Database - Event triggers Before: <img width="1134" height="453" alt="image" src="https://github.com/user-attachments/assets/e9d06d58-782c-4ccb-93c0-2ce1ca8c5748" /> After: <img width="1115" height="451" alt="image" src="https://github.com/user-attachments/assets/c437acb0-c602-4dd2-b249-66c7a7e739d6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Copy action now shows confirmation state (“Copy” → “Copied”) when copying error details. * **UI Improvements** * Unified form-field layouts and input-group composition across editors, settings, and integration forms for a more consistent experience. * Password-strength feedback moved into field layout for clearer messaging. * Improved inline input/button/dropdown behaviors and non-React-form error display. * **Removed** * Display configuration settings component. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45791) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> |
||
|
|
35571d242e |
chore: migrate <Collapsible> to shadcn <Collapsible> (#45819)
## Problem We have multiple `Collapsible` components. ## Solution Reduce their number by using only the one from shadcn. I haven't noticed any visual nor functional changes. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Migrated expandable/collapsible UI to a unified shadcn-based implementation for more consistent expand/collapse behavior across the app. * **Style** * Updated listbox check icon sizing and removed obsolete collapsible open/close animations. * **Chores** * Removed deprecated collapsible variants and consolidated UI component surface for simpler maintenance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0751fe2bf4 |
fix: logs explorer field references doesn't show all sources (#45828)
## Problem The field reference side panel doesn't show all sources: there are actually 11 items and users can't see them nor select them. ## Solution Use a combobox instead ## Screenshots Before: <img width="667" height="414" alt="image" src="https://github.com/user-attachments/assets/8017597f-e058-4306-8761-fb54d8c653ba" /> After: <img width="1306" height="1642" alt="image" src="https://github.com/user-attachments/assets/67579315-65cc-4bf9-9744-42f09b816772" /> <img width="1346" height="972" alt="image" src="https://github.com/user-attachments/assets/13df449a-0bb1-41e4-934d-0bb18e9f06d9" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Schema selector in the Logs Query Panel is now a searchable popover and shows the selected source in the button (or prompts “Select source...”). * Field table now displays fields for the chosen schema only. * **Refactor** * UI simplified for faster schema selection and clearer field reference browsing. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45828) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
de30257ed5 |
docs: update to reflect changes with rotating legacy secret (#45855)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/NO ## What kind of change does this PR introduce? Update to troubleshooting guide to reflect changes with legacy JWT secret. As we are no longer supporting rotation of legacy secret, guide has been updated to direct users to migrate to new JWT signing key and new API keys. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated troubleshooting guide for JWT secret management. Now recommends migrating to asymmetric JWT signing keys instead of rotating legacy anon, service, and JWT secrets, with a reference to the migration guide. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45855) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b5725fc760 |
docs: correct import statements in code examples (#45854)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Corrects import statements in code examples in troubleshooting guide. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated SSR package migration guide with corrected code examples for login/signup, client components, server components, and route handlers. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45854) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4211c97f35 |
docs: add context for invalidating storage signed urls (#45841)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Add context around storage signed URLs using separate signing key and invalidating/revoking URLs. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified Supabase Storage signed URLs are generated and validated independently from Auth JWT keys, remain valid until their expiration even if Auth keys change (rotation, disabling, or algorithm switch), and can only be revoked by contacting Supabase support. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45841) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a93eef6848 |
docs: move AI tools section (#45795)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an "AI Tools" guides section with landing, overview, and troubleshooting pages; guides render from Markdown. * **Documentation** * New AI Tools guides: local development, Quickstart, CLI overview, troubleshooting, and detailed overview pages. * **Chores** * Site navigation updated to include an AI Tools entry and renamed subsection to "AI"; added permanent redirects from prior Getting Started AI URLs to the new AI Tools locations. * **Bug Fixes** * Updated internal guide links so AI prompt pages point to the new AI Tools paths. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45795) <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Greg Richardson <greg.nmr@gmail.com> |
||
|
|
205ab69061 |
feat(studio): move CLI login to connect interstitial (#45814)
## What kind of change does this PR introduce? Feature / UI refactor ## What is the current behaviour? The CLI browser login route still uses the older API authorisation layout and redirects missing or failed sign-in session states to generic 404/500 pages. ## What is the new behaviour? Moves `/cli/login` onto the shared connect interstitial layout as the next small stacked slice after the organisation invite work. This keeps the real CLI login contract intact while updating the surface: - creates the CLI login session from `session_id`, `public_key`, and optional `token_name` - redirects to the generated `device_code` - renders missing-parameter and session-creation failures in-card instead of redirecting away - keeps the 8-character verification code selectable and copyable as a single string - uses a full-width primary `Copy code` action This also adds the small shared interstitial helpers needed by this surface and adjusts `CopyButton` so the copied check icon inherits the primary button colour instead of turning green. This also removes the CLI version admonition: > Browser login flow requires Supabase CLI version 1.219.0 and above. I checked with our stats and the CLI team. The vast majority of users are on a newer version. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Authorize API access Supabase-D1E3CF26-BD59-4BB2-B457-B552EE47E3DA" src="https://github.com/user-attachments/assets/c89b8b13-fa98-41b7-8093-e59d15b2aa9e" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-C9977F21-88B8-441B-8A2C-09A9515935B0" src="https://github.com/user-attachments/assets/ca13b65a-3875-425c-b73b-8f2101c1e406" /> | | <img width="1024" height="759" alt="Supabase-F42FBEAF-F74D-4920-8A51-7C25004F66D5" src="https://github.com/user-attachments/assets/51adb1e6-a2fb-41fb-b36f-0ae466fe60e2" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-8159A1B1-2594-4183-AC35-FEF1EFD4EA37" src="https://github.com/user-attachments/assets/6f143218-795d-41c9-a8e1-52e529a6b988" /> | <img width="1024" height="759" alt="Supabase-2506E468-9F42-44B9-A5B7-BC4D3777F552" src="https://github.com/user-attachments/assets/a304fca5-cf26-4ae7-abe9-77cdbc21fba5" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-A0EE1239-A345-427C-9CF7-997037A8FC0E" src="https://github.com/user-attachments/assets/33118777-35f3-49d6-bc1e-30e7124b3677" /> | | <img width="1024" height="759" alt="Authorize API access Supabase-A7B84CA6-D230-4C3E-9227-DE21CE35375C" src="https://github.com/user-attachments/assets/78eb6296-035a-4201-b254-b97eda44443c" /> | <img width="1024" height="759" alt="Authorize CLI Supabase-F55E26B2-609B-449C-9C64-08AA90AE3D1E" src="https://github.com/user-attachments/assets/ff7b3b4e-729c-4681-844d-2d5d94bfc084" /> | ## Testing instructions Use the Vercel preview URL for this PR once it is available. The examples below use `<preview-origin>` as a placeholder, for example `https://studio-git-dnywh-feat-cli-login-interstitial-supabase.vercel.app`. You need to be signed in to Studio to see these states because `/cli/login` is still behind `withAuth`. Ready state: - Open `<preview-origin>/cli/login?device_code=ABCD1234` - Check the page title is `Authorize CLI | Supabase` - Check the card title is `Authorize Supabase CLI` - Check the code fills the width, uses the normal sans font, and can be selected - Drag-select the code and copy it; the clipboard should contain `ABCD1234`, not one character per line - Click `Copy code`; the button should show the usual copied success state without a green check icon on the primary button Missing parameters state: - Open `<preview-origin>/cli/login` - Check the card says `Missing sign-in parameters` and names the missing `session_id` and `public_key` parameters - Open `<preview-origin>/cli/login?session_id=session-test` - Check it still stays in-card and names the missing `public_key` parameter instead of redirecting to `/404` Creation error state: - Open `<preview-origin>/cli/login?session_id=not-real&public_key=not-real&token_name=local-dev` - Check it stays in-card with `Unable to create CLI sign-in` instead of redirecting to `/500` - The exact error detail can vary by environment; the important bit is that the failure is shown inside the interstitial card Loading state: - This is transient because there are no production mocks in this slice - To inspect it manually, throttle the browser network before opening a session-creation URL such as `<preview-origin>/cli/login?session_id=not-real&public_key=not-real` Real CLI flow: - Run the browser login flow from Supabase CLI as usual - When the CLI opens a Studio URL, keep the path and query string but replace the origin with the PR preview origin - The page should create the login session and then route to `/cli/login?device_code=<8 character code>` - Enter that 8-character code back in the CLI prompt <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Redesigned CLI login flow with clearer state-driven screens and improved verification UI. * Added a small paired-logo component for centered logo pairs with a connector icon. * **Improvements** * Copy button behavior and styling refined for consistent visual feedback across variants. * **Tests** * New unit tests covering copy-button behavior and multiple CLI login UI flows. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45814) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9660b0075c |
refine organisation invite state helpers (#45813)
## What kind of change does this PR introduce? Code cleanup. Follow-up to #45774. ## What is the current behavior? The organisation invite interstitial derives invite states, titles, and descriptions from nested conditional logic in the component. That makes the component harder to scan and pushes too much state coverage into render tests. ## What is the new behavior? See #45774 for screenshots of the general UI before-and-after (which this one builds upon). That PR also contains testing instructions. Extracts the invite status and content decisions into small pure helpers, then covers those helpers with focused unit tests. The component keeps the user-facing render and interaction coverage, including the invalid lookup regression where a 404 should render the invalid invite state instead of raw backend copy. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Improved organization invite flow with enhanced error state handling for expired, invalid, and wrong-account scenarios. * Better consistency in error messages and user guidance throughout the invite process. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45813) <!-- end of auto-generated comment: release notes by coderabbit.ai --> |