The SDK now handles orphaned lock recovery via steal internally
(supabase-js#2106). Keep the BroadcastChannel observability wrapper for
Sentry signals. The steal-based orphaned lock recovery in
`debuggableNavigatorLock` (packages/common/gotrue.ts) (introduced in
https://github.com/supabase/supabase/pull/39868) is now redundant,
supabase-js#2106 handles this natively in the SDK.
Removes the `navigator.locks.request({ steal: true })` block while
keeping the BroadcastChannel wrapper that sends lock-holder stack traces
to Sentry.
Related: supabase/supabase-js#2106, supabase/supabase-js#2125
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES/NO
## What kind of change does this PR introduce?
Bug fix, feature, docs update, ...
## What is the current behavior?
Please link any relevant issues here.
## What is the new behavior?
Feel free to include screenshots if it includes visual changes.
## Additional context
Add any other context or screenshots.
Co-authored-by: Jordi Enric <37541088+jordienr@users.noreply.github.com>
## Context
In the new project home page, we have a stat for "Last migration" which
we're showing _when_ the last migration was applied. However:
- The timestamp for the migration is derived from the "version" column
of the migration (in the `supabase_migrations` table) which afaik is
derived from the migration's file name
- It'll be alright if the migration was generated via the CLI, but we
can't really enforce the name of the migration file if say they were
generated via AI, so this is technically a point of flakiness
- Reckon that it's more value to show _what_ was the last migration
rather than _when_ so opting to change the value here to show the name
of the last migration instead
### Before
<img width="620" height="311" alt="image"
src="https://github.com/user-attachments/assets/6876acb6-91d2-4ae3-8ce8-98375658c12c"
/>
### After
<img width="582" height="322" alt="image"
src="https://github.com/user-attachments/assets/a40f6635-2068-4edb-a91a-ccf03d8e4d3c"
/>
- Add a warning about spend cap not applied on brahching when enabling
github integration
- Reduce default concurrent branches to avoid extra costs incurring
<img width="1247" height="833" alt="Screenshot 2026-02-16 at 18 58 14"
src="https://github.com/user-attachments/assets/9e93161d-7d80-4e6b-a102-3791b309c897"
/>
Fixes: DEVWF-1144
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Chore / dead code removal
## What is the current behavior?
The `apps/docs/components/Flag/` directory contained legacy feature flag
code that was never wired up:
- `FlagProvider.tsx` — all ConfigCat logic commented out; only wraps
children in an empty context
- `FlagContext.ts` — an empty `createContext({})` with no values ever
set
- `Flag.tsx` — a gate component that reads from the above empty context,
so flags always evaluate to falsy
- `hooks/useFlag.ts` — references the dead local `FlagContext` instead
of `common`'s `FeatureFlagContext`
The docs app already uses `FeatureFlagProvider` from the `common`
package (configured in `apps/docs/features/app.providers.tsx`), making
this entire local implementation obsolete.
Closes
[GROWTH-611](https://linear.app/supabase/issue/GROWTH-611/clean-up-deadlegacy-flag-code-in-docs-app)
## What is the new behavior?
The dead code is removed:
- `apps/docs/components/Flag/` directory deleted
- `apps/docs/hooks/useFlag.ts` deleted
Any code needing feature flags should import `useFlag` directly from
`common`.
## Additional context
No flag-gated features were affected — the old local implementation was
non-functional (context always resolved to `{}`), so removing it has no
behavioral impact.
## What kind of change does this PR introduce?
UI update
## What is the current behavior?
- The vast majority of projects now have physical backups, not logical
- Physical backups are not downloadable
- But we show a disabled `Download` button for each physical backup
- This button has confusing multi-step instructions about `pg_dump` that
are
[inaccurate](https://supabase.slack.com/archives/C02BJ2239GA/p1771979586829419?thread_ts=1771887878.203199&cid=C02BJ2239GA)
## What is the new behavior?
- We only show the (enabled) `Download` button for logical backups
| Before | After |
| --- | --- |
| <img width="1024" height="563" alt="AWS Healthy Toolshed
Supabase-6FE7C23F-29D6-47B6-819A-84BC49927F3A"
src="https://github.com/user-attachments/assets/167441bf-3ead-4c86-89df-60ab89ce8b98"
/> | <img width="1024" height="563" alt="AWS Healthy Toolshed
Supabase-C9E763B7-B447-468E-B928-BB9AD5ABC588"
src="https://github.com/user-attachments/assets/3fccdf12-ba4e-424a-87ae-2294f1a3b7b1"
/> |
## Additional context
Support believes removing the button entirely will have less of a burden
than a better tooltip explanation.
## What kind of change does this PR introduce?
UI improvement
## What is the current behavior?
The session expired dialog is quite hard to parse when, for most people,
the ask is simple.
## What is the new behavior?
Improved session expired dialog:
- Refactored to use AlertDialog
- Clarified copywriting
- Uses the new AlertCollapsible to hide all the complicated debugging
steps under a toggle
- This component is documented in the design-system
| Before | After |
| --- | --- |
| <img width="1024" height="563"
alt="Supabase-B1728A05-DDD2-4A50-AED4-D62EAA2E7D7C"
src="https://github.com/user-attachments/assets/771f85d8-21ea-42b5-99f5-b9b05f5617dd"
/> | <img width="1024" height="563" alt="Storage Supabase"
src="https://github.com/user-attachments/assets/b2fcab68-fb29-4cb9-bd42-aecc57b9fa32"
/> |
| <img width="1024" height="563"
alt="Supabase-B1728A05-DDD2-4A50-AED4-D62EAA2E7D7C"
src="https://github.com/user-attachments/assets/771f85d8-21ea-42b5-99f5-b9b05f5617dd"
/> | <img width="1024" height="563" alt="Storage Supabase"
src="https://github.com/user-attachments/assets/babd3711-5fdf-43b9-be06-d96268a191fd"
/> |
## To test
In apps/studio/hooks/misc/withAuth.tsx:
```diff
- const [isSessionTimeoutModalOpen, setIsSessionTimeoutModalOpen] = useState(false)
+ const [isSessionTimeoutModalOpen, setIsSessionTimeoutModalOpen] = useState(true) // Mocked as true for UI testing
```
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
## Context
Since moving notifications to the Advisors Panel, we've been sending
`org_slug` and `project_ref` to the GET notifications endpoint, which
resulted in certain notifications not being returned such as those that
are user specific (no org slug nor project ref)
Am opting to remove both slug and ref filters for the notifications as
the notifications should be on a user level (irregardless if you're
within a project or not) - the Advisor's Panel's button in the layout
header would also suggest that notifications in there are not tied to an
org or project
## To test
This one's a bit tricky to test unless you have notifications on
staging, but i've double checked on prod with a curl command that
removing the org slug and project ref filters returns the correct
notifications
Fixes#42192
Replaces the deprecated `getSession` call with `getClaims` in the
SolidJS tutorial documentation (`with-solidjs.mdx`).
Changes:
- `supabase.auth.getSession()` → `supabase.auth.getClaims()`
- `data.session` → `data.claims`
This follows the recommended migration pattern per the Supabase auth
docs, and is consistent with the same fix applied to the Refine tutorial
in #43006.
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
## Problem
Finding a specific edge function is cumbersome when you have many of
then.
## Solution
Use a combobox instead of a select to allow filtering
## How to test
- Enable the cron extension
- Enable the pg_net extension
- Create a few edge functions
- Create a new cron job and select _Supabase edge functions_
You should be able to:
- select/unselect an edge function
- filter the list to reduce the number of edge functions displayed
## What kind of change does this PR introduce?
Feature. Resolves DEPR-390
## What is the current behavior?
Projects aren’t sortable in either the card or table view.
## What is the new behavior?
Projects are sortable in both:
- Card view: sort dropdown
- Table view: sort dropdown or table column headers
| Before | After |
| --- | --- |
| <img width="1382" height="797"
alt="Supabase-4D1BFE40-875D-494C-8F17-A68D92826458"
src="https://github.com/user-attachments/assets/c4f17b77-bc90-447f-90cd-78a11c2e4129"
/> | <img width="1382" height="797"
alt="Supabase-D8C0AC7C-A28D-4AA6-BA7C-0FCD61DB5D11"
src="https://github.com/user-attachments/assets/d926d03d-2702-48e5-9d1f-0e09d163079d"
/> |
| <img width="1382" height="797"
alt="Supabase-0A545C5C-40B5-47F7-9ACD-2200879BB95E"
src="https://github.com/user-attachments/assets/f2103c32-a150-4db7-a78a-8bd610e2a028"
/> | <img width="1382" height="797"
alt="Supabase-0F7AB608-2E86-4F0C-BB60-C85D9B7F3D57"
src="https://github.com/user-attachments/assets/baa63f14-4059-483d-a9d6-33663e5cff43"
/> |
## Additional context
I wonder if this is overkill given most folks only have 1–2 projects.
Some ideas:
- Only sortable in table view via column headers
- Conditional rendering for folks with 2+ projects
- Opt-in feature
- Feature-flag
I’ve opted to make it global and synced for now.
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
We are now saving our old webinar videos as unlisted YouTube videos.
I added the video embeds to previous webinars.
---------
Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
Updated AUP based on discussions with Legal and Abuse Ops.
A lot of wholesale changes based on recent events. Including numbering
in the clauses so these can be directly referred to in communication.
Currently `/org/_` redirects to `/general` (org settings) after picking
an org, this makes it redirect to the project list
## to test
- go to /dashboard/org/_
- select org
- redirects to project picker
## test 2
- go to /dashboard/org/_/general
- select org
- redirects to /org/whatever/general (settings)
This PR updates @supabase/*-js libraries to version 2.97.1-canary.3.
**Source**: manual
**Changes**:
- Updated @supabase/supabase-js to 2.97.1-canary.3
- Updated @supabase/auth-js to 2.97.1-canary.3
- Updated @supabase/realtime-js to 2.97.1-canary.3
- Updated @supabase/postgest-js to 2.97.1-canary.3
- Refreshed pnpm-lock.yaml
This PR was created automatically.
Co-authored-by: mandarini <6603745+mandarini@users.noreply.github.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
studio message update
## What is the current behavior?
Under the scheduled backups
dashboard/project/_/database/backups/scheduled, the current message is
"Your project uses PITR and full daily backups are no longer taken.
They're not needed, as PITR supports a superset of functionality, in
terms of the granular recovery that can be performed."
The new message mainly addresses the word "superset" since it implies no
trade-offs. However, having teams/enterprise plan, customers lose access
to 2+ weeks of daily backups and are only limited by the selected PITR
recovery duration. New message: "Your project uses PITR, and full daily
backups are no longer taken. PITR lets you restore to a specific time
(down to the second) within your selected PITR retention period."
---------
Co-authored-by: Illia Basalaiev <illiab@IMB3.local>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs update
## Summary
The OAuth server supports three token endpoint authentication methods
(`none`, `client_secret_basic`, `client_secret_post`), but the docs only
showed `client_secret_post` implicitly without labeling it, and never
mentioned client_secret_basic (the actual default for confidential
clients per RFC 7591).
- Add `token_endpoint_auth_method` explanation with defaults/constraints
to the client registration section in getting-started.mdx
- Update registration examples (JS, Python, cURL) and response JSON to
include token_endpoint_auth_method
- Restructure token exchange and refresh token sections in
oauth-flows.mdx to show all three auth methods with clear labels
- Add `client_secret_basic` examples using HTTP Basic auth header
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
New Go landing page for the upcoming Bolt webinar. This is where we will
direct customers who want to learn more to go to request a meeting.
---------
Co-authored-by: Alan Daniel <stylesshjs@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs update
## What is the current behavior?
A paragraph describing Realtime database connections appears immediately
before the "Database connections" section header, then again immediately
after it
## What is the new behavior?
Removed the first (pre-header) instance of the paragraph, so the
description appears only once, in its natural place beneath the section
header.
## Additional context
No visual changes, just a clarity/deduplication fix.
Removing "Public Alpha" status from the documentation to reflect current
status.
* [S3 Compatibility](https://supabase.com/features/s3-compatibility)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs update
## What is the current behavior?
Please link any relevant issues here.
## What is the new behavior?
## Additional context
## What kind of change does this PR introduce?
Component improvement
## What is the current behavior?
[Admonition](https://supabase.com/design-system/docs/fragments/admonition)
often passes `actions`, often Button(s). These either are stacked via
the `layout` prop `horizontal` or `vertical`. That binary choice often
means, given layout flex, awkward text wrapping.
## What is the new behavior?
Admonition now has a `"responsive"` value for the `layout` prop. When
`layout="responsive"`, the Alert root gets `@container` so the
Admonition is the container-query context. The Admonition stays
`vertical` when it’s narrow and switches to `horizontal` when its own
width reaches the `@md` container breakpoint, independent of page width.
## Additional context
See the _Disk Management_ section of Database Settings to see the single
in-situ example.
Video demo:
https://github.com/user-attachments/assets/318a4530-5ae4-43f3-99cf-b75967659ed3
Enable the install/uninstall integration button on the stripe sync
engine only if the user has permissions to create/delete edge function
secrets. This fixes a problem when non-admin/non-owner users try to
install the integration but it fails due to lack of permissions. For a
user without appropriate permissions a tool tip will be shown:
<img width="1344" height="977" alt="image"
src="https://github.com/user-attachments/assets/49c950cc-d76b-40b4-ab6e-cb8f193561cc"
/>
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Bug fix
## What is the current behavior?
The dropdown menu items in the ComputePricingCalculator component use a
hardcoded key value of `"custom-expiry"` for all plan items in the map
function. This causes React to not properly identify unique list items,
which can lead to rendering issues and state management problems when
multiple plans are displayed.
## What is the new behavior?
Changed the key prop from the hardcoded `"custom-expiry"` to
`plan.name`, which uniquely identifies each plan item. This ensures
React can properly track and render each dropdown menu item.
## Additional context
This is a common React anti-pattern where using a constant key for list
items prevents React from properly reconciling the virtual DOM. Using
`plan.name` as the key ensures each plan has a unique identifier for
proper rendering and state management.
https://claude.ai/code/session_01HDfar7A1XXJFJDchPPSQTK
Co-authored-by: Claude <noreply@anthropic.com>
## Summary
Fixes GROWTH-625.
Preserves first-touch attribution across app boundaries by persisting
external referrer context at the edge and consuming it on Studio's
initial pageview.
When users come from an external source to www/docs and then navigate to
Studio, Studio often only sees the internal `supabase.com` hop. This
change preserves the original external context so first-touch
attribution is retained.
## What changed
- **Shared first-referrer cookie utilities**
(`packages/common/first-referrer-cookie.ts`):
- `isExternalReferrer`, `buildFirstReferrerData`,
`serializeFirstReferrerCookie`, `parseFirstReferrerCookie`
- `hasPaidSignals` — detects click IDs (gclid, fbclid, etc.) and paid
utm_medium values
- `shouldRefreshCookie` — centralizes stamp-or-skip decision for all
apps
- `stampFirstReferrerCookie` — shared middleware helper used by all apps
(extracted from duplicated inline logic)
- **Edge middleware on all apps** — stamps cookie for external visitors,
refreshes on paid signals:
- `apps/www/middleware.ts` (simplified to use shared helper)
- `apps/docs/middleware.ts` (simplified to use shared helper)
- `apps/studio/proxy.ts` (integrated into existing proxy file)
- **Docs middleware matcher** — broadened from `/reference/:path*` to
all non-static paths so the first-referrer cookie is stamped on all docs
pages, not just reference paths
- **Telemetry** — Studio consumes cookie on initial pageview
(`packages/common/telemetry.tsx`). `handlePageTelemetry` refactored from
7 positional params to an options object for readability.
- **Tests** — 22 unit tests covering all utilities and edge cases
(including direct-navigation scenario)
## Behavior
- Writes `_sb_first_referrer` cookie when:
- cookie is not already set and request has an external referrer, OR
- cookie exists but incoming URL has paid traffic signals (click IDs or
paid utm_medium)
- Cookie: 365-day TTL, `domain=supabase.com`, `sameSite=lax`,
`secure=true` in production
- On first Studio pageview, if current referrer is internal and cookie
has external context:
- use persisted external referrer
- apply persisted UTM/click-id/landing-url attribution props
- Measurement properties: `first_referrer_cookie_present`,
`first_referrer_cookie_consumed`
## Manual testing
1. Visit `supabase.com/pricing?utm_source=google&utm_medium=cpc` from an
external referrer (or use DevTools to set a `Referer` header)
2. Check `_sb_first_referrer` cookie is set in Application > Cookies
3. Navigate to Studio (`supabase.com/dashboard`)
4. In PostHog (or browser network tab), verify the first `$pageview`
event has:
- `first_referrer_cookie_present: true`
- `first_referrer_cookie_consumed: true`
- `$utm_source: "google"`, `$utm_medium: "cpc"`
- `$referrer` points to the external source, not `supabase.com`
5. Verify subsequent route changes do NOT include
`first_referrer_cookie_*` properties
## Review feedback addressed
- Added `secure: true` flag on production cookies (Pam's first comment)
- Fixed inaccurate JSDoc on `utms` field — keys retain `utm_` prefix
(Pam's fourth comment)
- Added test coverage for edge cases: malformed URLs, multi-cookie
headers, http:// referrers (Pam's sixth comment)
- Docs matcher broadening: fast-path exit on cookie-exists check keeps
overhead minimal, exclusion list is correct
- Extracted shared middleware helper to eliminate duplication across 3
apps
- Refactored `handlePageTelemetry` from positional params to options
object
- Removed redundant null check in `hasPaidSignals`
- Added direct-navigation test case
- Deleted dead `apps/learn/middleware.ts`
- Fixed studio build: integrated cookie stamping into existing
`proxy.ts` (Next.js 16 rejects both middleware.ts and proxy.ts)
---------
Co-authored-by: pamelachia <26612111+pamelachia@users.noreply.github.com>
Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
YES
## What kind of change does this PR introduce?
Chore / dependency fix
## What is the current behavior?
`eslint-plugin-jsx-a11y` was referenced in `eslint.config.json` but was
not listed in `package.json`, causing module resolution errors in the
IDE.
## What is the new behavior?
The package is properly added to `package.json` so it resolves correctly
in both ESLint and the IDE.
This pull request standardizes the usage of props and value types for
the `ResizablePanelGroup` and `ResizablePanel` components across
multiple files in the codebase. Specifically, it replaces the deprecated
`direction` prop with `orientation`, and updates numeric prop values
(such as `defaultSize`, `minSize`, and `maxSize`) to be passed as
strings. This ensures consistency with the updated component API and
improves type safety.
**Component API Updates:**
* Replaced the `direction` prop with `orientation` for all usages of
`ResizablePanelGroup`
* Updated all `ResizablePanel` props (`defaultSize`, `minSize`,
`maxSize`) to be passed as strings instead of numbers, ensuring
compatibility with the latest API requirements.
* Removed deprecated or unnecessary props such as `order` from
`ResizablePanel` components, and ensured all size-related props are
consistently formatted as strings.
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES/NO
## What kind of change does this PR introduce?
Bug fix, feature, docs update, ...
## What is the current behavior?
Please link any relevant issues here.
## What is the new behavior?
Feel free to include screenshots if it includes visual changes.
## Additional context
Add any other context or screenshots.