mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
edec85d1ca681f8bf55cfb8d780c947d52ec7976
6453
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
edec85d1ca |
fix(pipelines): Make pipeline actions and status updates reliable (#50085)
## Summary Make pipeline actions and status feedback reliable while requests are running or fail. Let the backend coordinate table resets and restarts, keep stopped pipelines stopped after resets or settings changes, and refresh the UI from confirmed backend state. ## Pipeline actions and recovery - Reset one table, all errored tables, or all tables through the rollback endpoint without separate frontend stop/start requests. Explain which destination data is deleted, which rows are copied again, initial sync charges, and the skip-initial-sync setting. - Keep pending feedback until the action and a fresh status read finish, including across navigation and polling errors. Prevent overlapping actions and disable start/stop controls when status is unavailable or transitioning. - Close the creation form once the pipeline is created. If its initial start fails, users can retry Start on the existing pipeline without creating a duplicate. - Wait for confirmed shutdown before deletion; a shutdown error or timeout leaves deletion retryable. Keep failed version updates open and avoid reporting success. - Clarify recovery guidance and pending labels, suppress duplicate error toasts, and hide stale table errors during transitions. ## Status updates and shared UI - Poll pipeline status and table metrics one second after each response, share in-flight reads, pause dashboard polling in background tabs, and respect rate-limit backoff. The shutdown waiter continues in the background. - Refresh metadata after mutations even when an older read is in flight, while preserving shared polling requests. Refresh affected data after failures that may follow a committed reset or settings change. - Move pending request state into the shared, project-keyed `DatabaseLayout` so the list, detail page, and diagram stay consistent. The surrounding database-page changes update named imports in both Next.js and TanStack routes. - Simplify action, status, and form rendering; announce status changes to assistive technology; and sort table statuses without mutating cached data. --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
64ab76262e | feat(studio): exhaustion banner links to metrics (#50276) | ||
|
|
66d4b4c19b | chore(studio): remove expired tos update banner (#50533) | ||
|
|
c8a9a7a630 |
fix(studio): correct storage explorer listing pagination and column scroll (#50476)
| | PR | Base | Branch | | --- | --- | --- | --- | | 1 | **this PR** | `master` | pre-existing correctness fixes | | 2 | #50413 | `fix/storage-explorer-listing-and-scroll` | `?path`/`?preview` deep-linking + copy row actions | | 3 | #50478 | `feat/storage-nav-improvement` | end-to-end deep-link test | | 4 | #50480 | `test/storage-deep-link-e2e` | copy path / copy link row actions | To read the whole change in one view: ```bash git diff master...test/storage-deep-link-e2e -- apps/studio e2e ``` ## What is the current behavior? Four independent bugs in the storage explorer, all pre-existing on `master`: - `hasMoreItems` is derived from the *formatted* listing, but `formatFolderItems` drops the `.emptyFolderPlaceholder` — so a full page can format to `LIMIT - 1` and stop pagination a page early. - A failed listing is indistinguishable from an empty folder, so a fetch error reads as "this folder has nothing in it". - `fetchFoldersByPath` commits its result against whichever bucket is selected when the requests resolve. Switching buckets mid-flight files the old bucket's items under the new bucket's name — and because `columns[0].name` then matches, nothing downstream notices and refetches. - The horizontal auto-scroll never runs its guard (`if (fileExplorerRef)` is always truthy), scrolls relatively so repeated runs drift, and depends on the `columns` array identity — so a background refetch yanks the view back to the right. It also scrolls in list view, where there is nothing to scroll. ## What is the new behavior? Each of the above is fixed at its source. Pagination and the exhaustiveness check now compare the raw page length; listings carry an `isComplete` flag; `fetchFoldersByPath` captures the bucket id at entry and discards a stale result; the scroll is absolute, guarded, keyed on `columns.length`, and skipped in list view. Two new test files cover the parts that were silently wrong before: `state/storage-explorer.test.ts` (MSW, the bucket race) and `FileExplorer.test.tsx` (scroll geometry, with the container's layout defined by hand since jsdom reports everything as zero-sized). Both were checked by reverting the fix and confirming they fail. ## Additional context `fetchFoldersByPath` also starts returning `{ missingPaths }` here. Nothing reads it yet — the first consumer is in PR 2 — but it shares a hunk with the `isComplete` work, so separating it would mean two PRs editing the same lines. It is backward-compatible: all three existing call sites ignore the return value. 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Bug Fixes - Improved Storage Explorer column-view scrolling so the newest column remains visible, including when the preview pane opens. - Prevented folder results from a previously selected bucket from appearing after switching buckets during loading. - Improved handling of incomplete or partial folder listings to avoid incorrectly treating failed results as empty folders. - Preserved the correct scroll position when using list view. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
24e8333c54 |
feat(studio): flag for unavailable regions (#50473)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Adds feature flag for controlling region unavailability. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Region options now display availability badges, tooltips, and status-specific notices. * Restricted regions remain selectable so users can review their availability status. * Project creation provides a clear field-level message when a selected region is unavailable and prompts users to choose another region. * **Bug Fixes** * Region availability messaging now consistently reflects platform status and configured restrictions. * Availability warnings clear after selecting an eligible region. * Region checks now cover both dynamic and static provider regions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7b4e3aba01 |
fix(studio): show service role key in ConnectSheet for projects using legacy keys (#50516)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix #50515 ## What is the new behavior? ConnectSheet now falls back to the legacy `service_role` key for projects using legacy JWT keys. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved secret-key resolution by falling back to the service key when a secret key is unavailable. * Prevented attempts to reveal a secret when no secret key identifier exists. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
337ffaeb22 |
Reset pooling size value to default size if field left blank and saved (#50524)
## Context As per PR title - for the Database Settings -> Connection Pool Just sends the default value (as per the placeholder) to the PATCH request when saving while leaving the pool size field blank <img width="724" height="391" alt="image" src="https://github.com/user-attachments/assets/448c1bf9-4857-467e-8180-637f291321dd" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved connection pooling updates when a project reference or high availability setting is unavailable. - Ensured the default pool size is correctly submitted when no explicit value is provided. - Restored the maximum client connection setting accurately after successful updates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
68d7387e94 |
chore: Update tanstack icons (#50504)
Update the icons for Tanstack in studio and docs. See: - https://docs-git-chore-update-tanstack-icons-supabase.vercel.app/docs - https://studio-staging-git-chore-update-tanstack-icons-supabase.vercel.app/dashboard/project/_?showConnect=true&framework=tanstack |
||
|
|
71d58cba7f |
Joshenlim/fe 4401 re sql editor silently points to the primary instead of (#50513)
## Context Fixes the following 2 issues with the database selection in the SQL Editor - An errant `useEffect` was resetting the `selectedDatabaseId` back to the primary every time the `databases` list from `useReadReplicasQuery` changed reference (not just on first load). - `QuerySourceMenu` kept showing "Read Replica" even after selection had reverted - Was using local storage value as the `identifier` for `DatabaseParametersSubMenu`, when it should use the valtio store as the source of truth <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - The SQL Editor now remembers the last selected database between sessions. - Your saved database selection is restored when available; otherwise, the project’s primary database is selected automatically. - Query source settings now stay synchronized with the database currently selected in the SQL Editor. - **Bug Fixes** - Background database refreshes no longer unexpectedly reset your selected read replica to the primary database. - Database selection now waits for saved preferences to load, preventing a brief incorrect selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
be9ec25270 |
Update unified logs queries to fetch status, method and pathname properly for storage logs (#50465)
## Context As per PR title - those 3 properties (status, method, and pathname) were missing from the table view but available in the detailed panel view ### Before <img width="1118" height="575" alt="image" src="https://github.com/user-attachments/assets/e6d3bb70-8ce9-4a7b-9e07-eae7acb6896d" /> ### After <img width="988" height="555" alt="image" src="https://github.com/user-attachments/assets/309b4e5a-88e1-41d9-8cee-4ae56a1afa15" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Unified Logs now correctly displays HTTP methods, paths, and status codes for storage-service entries. * Updated log filters to support storage-service values for equality, inequality, wildcard, LIKE, and ILIKE searches. * Improved pathname prefix matching across supported log backends. * Preserved correct handling of authentication statuses and worker Compute fields. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6434c48999 |
feat(studio): migrate Auth reports to OTEL (#50469)
## Problem Auth observability charts always queried the legacy logs.all endpoint, even when the OTEL reports rollout was enabled. The existing OTEL SQL also had ClickHouse correctness and parity gaps around timestamp aliasing, JSON types, provider paths, missing values, and error-code attributes. ## Fix Route the ten Auth-specific charts through the OTEL query builders and logs.all.otel endpoint when otelReports is enabled. Preserve the BigQuery fallback, partition React Query caches by backend, and leave the shared API gateway charts on the legacy endpoint. Correct the OTEL queries by qualifying source timestamps, using typed and nullable JSON extraction, preserving missing actor and duration semantics, selecting the right provider path for each event shape, preferring the canonical Auth error-code attribute with a legacy fallback, and applying bounded result limits. Two-minute report intervals now use minute-level SQL buckets instead of falling through to hourly buckets. ## How to test - Run `CI=1 pnpm --filter studio exec vitest run data/reports/v2/auth.config.otel.test.ts hooks/misc/__tests__/useReportDateRange.test.ts` - Run `pnpm --filter studio run lint:ratchet` - Run `pnpm --filter studio run typecheck` - Expected result: all checks pass and generated OTEL SQL preserves legacy report semantics. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Auth observability charts can now use OpenTelemetry data when enabled, while retaining the existing reporting source otherwise. - Switching the data source automatically refreshes the relevant charts. - **Bug Fixes** - Improved Auth observability accuracy for provider, duration, actor, and error-code reporting. - Added safeguards to keep report queries within the supported result limit. - Corrected minute-level grouping for two-minute analytics intervals and three-hour date ranges. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
77ee1ec127 |
chore(studio): describe compute CPU by size tier (#50401)
## What kind of change does this PR introduce? Copy/label update in Studio's compute surfaces. ## Description Compute CPU descriptions now branch on the compute size tier: - Sizes below Large read **"Shared compute"** (no core count) - Large and up read **"Dedicated · N vCPUs"** — the unit is always vCPU Changes: - New `lib/compute-labels.ts` helper (`isSharedComputeSize`, `getComputeCpuLabel`) with unit tests - Compute badge hover card, compute size picker, and project-creation selector use the new labels - `new-project.constants.ts` cpu strings updated accordingly - ">16XL" card: "Custom CPU" → "Custom compute"; upsell copy now says "64 vCPUs" - The synthetic Nano/Micro addon `meta` no longer has `cpu_cores`/`cpu_dedicated`; removed the now-unused cpu fields from the hardcoded instance specs - Project-creation sub-text: "Larger, dedicated compute available after creation" ## Tests - New unit tests for the label helper - Infrastructure settings page test now asserts the rendered labels Fixes PROD-663 Related #49998 #49996 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **User Interface** * Updated compute-size labels to use “Shared compute” and vCPU terminology. * Clarified dedicated compute options and availability messaging. * Updated custom instance and upgrade labels, including “Custom compute” and “64 vCPUs.” * **Consistency** * Standardized compute labels across project creation, infrastructure settings, and compute details. * **Tests** * Added coverage verifying shared and dedicated compute classifications and displayed labels. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
c2d8b08299 |
MFA Recovery codes: UI tweaks (#50488)
## What kind of change does this PR introduce? Admonition is not the right UI to tell users how many are still available. ## What is the current behavior? No recovery codes yet: <img width="724" height="499" alt="image" src="https://github.com/user-attachments/assets/db9d47af-3a81-42d2-8cf0-9302816ceb21" /> After: <img width="758" height="525" alt="image" src="https://github.com/user-attachments/assets/68acc4bf-372f-4472-a3e4-a8263a8993d0" /> ## What is the new behavior? No recovery codes yet: <img width="720" height="556" alt="image" src="https://github.com/user-attachments/assets/48ce08a7-9650-428b-be5d-b8bb7ef5b720" /> After: <img width="720" height="541" alt="image" src="https://github.com/user-attachments/assets/35a8698d-9a6f-44cb-91c8-2ddb8d0f3a7b" /> When low number of codes available: <img width="733" height="548" alt="image" src="https://github.com/user-attachments/assets/d60017ba-ada6-47bb-9f83-a2a65674f800" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Recovery codes now appear in a dedicated section when enabled, separate from multi-factor authentication settings. - Recovery-code status updates are announced to screen readers for improved accessibility. - Available recovery codes are displayed in a clearer card-based layout once status information is available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7ab3f32625 |
feat(studio): rebuild the pipeline overview (#49630)
## What kind of change does this PR introduce? Studio UI improvement. ## What is the current behavior? The pipeline Overview uses bespoke loading, metrics, table-state and empty-state layouts that shift while data resolves and repeat status information from the detail header. ## What is the new behavior? Rebuilds the Overview around stable **Pipeline health** and **Replicated tables** sections. It adds layout-matched loading geometry, prioritised pipeline notices, initial-sync progress, clearer empty states, and accessible loading announcements. Complete pipeline configuration remains deferred to #49631. | Before | After | | --- | --- | | <img width="1024" height="759" alt="54861" src="https://github.com/user-attachments/assets/56e5cc5a-5d49-44c8-94d7-e1f1e0c827d5" /> | <img width="1024" height="759" alt="Replication Database Agua Basket Supabase" src="https://github.com/user-attachments/assets/43b6d0f6-6fd5-47f9-b3e5-788a33511304" /> | This is the final independent slice in the review series: #50443, #50444, #50445, #50446, then this PR. Each PR targets `master` and can merge on its own. Rebase this PR as earlier slices merge. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline. 2. Throttle the initial requests and confirm **Pipeline health** and **Replicated tables** keep their final geometry while loading. 3. Check running, initial-sync, stopped, failed, disconnected and unavailable states. 4. Confirm the Overview contains Pipeline health and Replicated tables only, without a Configuration section. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Reorganized replication pipeline status into Pipeline health and Replicated tables sections. - Added loading skeletons with accessible status announcements. - Added clearer notices for pipeline health, failed or disconnected pipelines, paused updates, lag, and synchronization progress. - Improved empty states when table data is unavailable or the pipeline is inactive. - Added options to view logs and reset failed tables. - **Tests** - Added coverage for loading behavior, pipeline notices, table counts, synchronization progress, and empty states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0043e6f53b |
feat(studio): add Explorer onboarding and startup preference (#50493)
<img width="1454" height="920" alt="image" src="https://github.com/user-attachments/assets/a289b618-2bd2-4957-ac49-71d4e372d2cc" /> ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. Yes. ## What kind of change does this PR introduce? Feature. ## What is the current behavior? Explorer always opens on its start page, without onboarding or a startup preference. ## What is the new behavior? Adds one-time onboarding with wireframe option cards and a collapsed Learn more section. Users can start on the Explorer start page or in a new SQL query tab, and change that choice in Account preferences → Dashboard. Preferences persist per account in the browser. ## Additional context How to test: 1. With Explorer enabled and fresh browser storage, open Explorer and select either startup option. Confirm Open Explorer follows the selection and onboarding stays dismissed after reload. 2. Change Explorer startup in Account preferences → Dashboard, then reopen Explorer. SQL query should create one normal query tab; Start page should restore the pinned home tab. 3. Use the keyboard to select an option and toggle Learn more. Expand it in a short viewport and check that the page scrolls normally. Validation: 235 tests pass, including 20 new cases; Studio typecheck and formatting pass. The local production build was stopped during compilation and was not verified locally. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added an Explorer onboarding experience with startup-view selection, guidance, and a Learn more section. - Added Explorer settings to choose between the Start page and SQL query views. - Explorer preferences now persist across sessions and accounts. - Explorer can open directly to a new SQL query when selected. - The Explorer Home tab is shown based on the selected startup preference. - **Accessibility** - Reduced-motion settings now disable the Explorer loading animation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2a46c00653 |
feat(studio): polish replicated table controls (#50446)
## What kind of change does this PR introduce? Studio UI improvement. ## What is the current behavior? Replicated tables use badge-heavy rows, fixed name sorting, prominent per-row reset buttons, and inconsistent restart terminology. ## What is the new behavior? Adds table and status sorting, accessible search feedback, concise state details, table action menus, and consistent **Reset** terminology. Failed-table reset remains unavailable when there are no failed tables or another reset is running. | Before | After | | --- | --- | | <img width="1872" height="356" alt="CleanShot 2026-09-16 at 13 36 51@2x" src="https://github.com/user-attachments/assets/6546f089-f6f8-4ff2-9509-ec44a2dee973" /> | <img width="1840" height="452" alt="CleanShot 2026-09-16 at 13 36 30@2x" src="https://github.com/user-attachments/assets/6e36b1e6-baee-4aea-80e9-e5e4a3fc8a75" /> | This is an independent slice extracted from #49630. The related review series is #50443, #50444, #50445, this PR, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline with replicated tables. 2. Sort by **Table** and **Status**, then search for a table and clear the search with Escape. 3. Open a table’s action menu and confirm its reset and Table Editor actions. 4. Confirm **Reset failed tables only** is unavailable when the pipeline has no failed tables. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added sortable Table and Status columns to the replication pipeline view. * Added options to reset all tables or only failed tables. * Added clearer replication lag details and status indicators. * Added dropdown actions for resetting tables and opening the Table Editor. * Added Escape-to-clear support for search. * **Bug Fixes** * Improved empty search results with a clear “No results found” message. * Error details are now displayed separately for easier access. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a5dcf3b57c |
feat(studio): rebuild pipeline health summary (#50445)
## What kind of change does this PR introduce? Studio UI improvement. ## What is the current behavior? Pipeline health is presented as a dense custom metrics panel with repeated connection information and per-table lag details mixed into the pipeline summary. ## What is the new behavior? Moves the pipeline-level slot status, lag, WAL retention, and last check-in into a standard detail section. It removes repeated connection content and keeps table-specific state with the replicated tables. | Before | After | | --- | --- | | <img width="1816" height="274" alt="CleanShot 2026-09-16 at 13 34 43@2x" src="https://github.com/user-attachments/assets/eceed5bb-8af2-4a3b-83a9-7849f1554fbe" /> | <img width="1830" height="506" alt="CleanShot 2026-09-16 at 13 34 15@2x" src="https://github.com/user-attachments/assets/498c4390-17e2-45e5-a923-cb4a7cfd5978" /> | _Note that the page spacing may feel a bit funny. This is handled in https://github.com/supabase/supabase/pull/49630_ This is an independent slice extracted from #49630. The related review series is #50443, #50444, this PR, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a running pipeline. 2. Confirm **Pipeline health** shows slot status, lag, WAL retention remaining, and last check-in. 3. Confirm unlimited WAL retention is labelled **Unlimited** and a caught-up pipeline is labelled **Caught up**. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## UI Improvements - Added a dedicated Pipeline Health section summarizing WAL status, slot status, and replication lag. - Replaced the inline metrics layout with responsive detail cards and clearer supporting descriptions. - Added tooltips for lag values and relative reply times, including precise timestamps. - Updated lag labels and status indicators for improved clarity. - Added concise explanations for reserved, extended, unreserved, lost, and unknown WAL states. - Improved presentation of pipeline details with optional contextual descriptions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3e2d54eccb |
feat(studio): add Warehouse table management and disable (#50195)
## What kind of change does this PR introduce? Feature and UI polish. ## What is the current behavior? Warehouse setup uses a schema accordion for table selection. Once Warehouse is enabled, users cannot remove replicated tables or disable Warehouse from Studio. ## What is the new behavior? - Replaces the schema accordion with one grouped, searchable table selector. - Still allows for **Select all** and **Clear** actions for each schema. - Starts first-time setup with no tables selected and preselects current replicated tables when editing. - Adds support for removing previously replicated tables. - Adds a confirmed **Disable Warehouse** action. - Tracks successful Warehouse enable and disable actions. Disabling Warehouse removes its replication pipeline, publication, catalogue access, and foreign tables. Copied data remains in DuckLake storage until the user deletes it. Re-enabling a table rebuilds its data rather than reusing the retained copy. | Before | After | | --- | --- | | <img width="1024" height="759" alt="Integrations Test US East 1 testdw Supabase" src="https://github.com/user-attachments/assets/bded025b-1d45-41dc-8a35-9159baf8f9b7" /> | <img width="1024" height="759" alt="Integrations test Teamer Supabase" src="https://github.com/user-attachments/assets/69026d94-98a0-4878-ab58-2e9697296d93" /> | | <img width="1280" height="1323" alt="Integrations Test testdw Supabase" src="https://github.com/user-attachments/assets/3f71e754-1a87-4d58-a7b9-dd39d3e0ac5a" /> | <img width="1280" height="1323" alt="Integrations Regular AWS Teamer Supabase" src="https://github.com/user-attachments/assets/758ed48e-9ed6-45d3-ae94-e171147a21d5" /> | | _Feature did not exist_ | <img width="1024" height="759" alt="Integrations Regular AWS Teamer Supabase" src="https://github.com/user-attachments/assets/c977ac57-8b0c-4482-882b-69ad7602b5df" /> | ## Additional context Platform support for updating and disabling Warehouse was added in [supabase/platform#38190](https://github.com/supabase/platform/pull/38190). ### To test 1. Open `/project/{ref}/integrations/warehouse/overview` before setup. 2. Confirm **Tables to replicate** starts at zero and **Enable Warehouse** is disabled until a table is selected. 3. Confirm each schema's **Select all** and **Clear** actions update every table in that schema. 4. Enable Warehouse with a partial selection and wait for setup to complete. 5. Edit the selection, add and remove replicated tables, then confirm the saved selection is reflected in the publication. 6. Disable Warehouse, confirm the retention warning, and verify the integration returns to its initial state. 7. Re-enable Warehouse and confirm selected tables are rebuilt. 8. Trigger a replication pipeline limit error and confirm the inline guidance links to Database Replication. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added the ability to disable Warehouse from the setup panel. - Warehouse setup now starts with no table selections. - Editing a setup preselects replicated tables and supports updating selections, including removing tables. - Added searchable schema and table selection with screen-reader count announcements. - Added telemetry tracking for initial Warehouse enablement. - **Bug Fixes** - Warehouse disable failures now show an error while keeping the confirmation dialog open for retry. - Configuration updates now refresh related data automatically. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7880c2f079 |
fix(studio): explorer chat and notebook layout refinements (#50453)
Five layout fixes across Explorer chat, notebooks, and the sidebar. ### Chat - **Conversation fade overlapped the scrollbar.** The top and bottom gradients are positioned against the conversation's padding box, which includes the scroll container's scrollbar gutter, so `inset-x-0` painted them over the scrollbar. They now stop at the conversation's content gutter, which `Conversation` owns for both the content and the fades. - **Composer background bled past the input's radius.** The form paints the surface behind the textarea but had no radius of its own, so its square corners showed outside the `rounded-lg` input. It now shares the radius. - **Message parts used two different widths.** Wide parts come down to `max-w-3xl` so every part shares a column, matching `AssistantQueryCell` and `AssistantNotebookPreview`. `isWide` / `isWideMessagePart` stay in place with both widths equal, so a part can diverge again later without rebuilding the mechanism. ### Notebooks - **Cell controls sat at the container edge.** Each cell centred itself at its own max width while the grip and add-cell button stayed at the far left of the full-width row, leaving a large gap. `SortableSection` takes a `sectionWidth` and carries its control gutter twice — once as the controls, once as padding on the other side — so the section stays centred with its controls immediately beside it. Cell widths are unchanged (prose `48rem`, query `72rem`); set them equal and the two cell types' controls line up on their own. The controls stay in flow rather than floating in an outside gutter, so on a viewport narrower than the cap the row just fills the space instead of clipping the controls into the padding. ### Sidebar - **Search icon didn't line up with the menu row icons.** The row box already sits flush with the search input's box, so rows moved from `pl-3` to `pl-2` to put their icons on the same 8px offset the search icon uses. Spacing between the input and the list now matches the 12px side padding. ### Testing `pnpm --filter studio run typecheck`, Prettier, and 378 tests across `Explorer`, `ProjectHome`, `AIAssistantPanel`, and `ExplorerLayout` pass. ESLint warning counts are unchanged from master. These were reasoned from layout rather than checked in a browser, so they're worth a look on a preview before merge. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **UI Improvements** * Updated Explorer layouts with flexible, configurable widths for notebook and query sections. * Refined navigation spacing and padding across Explorer views. * Centered and standardized AI Assistant preview, query, and message content widths. * Improved chat form styling with rounded corners. * Adjusted conversation spacing and fade overlays to avoid overlapping the scrollbar. * Preserved full-width behavior where appropriate while keeping controls aligned. * **Tests** * Updated layout tests to reflect revised width and alignment behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
c15b0836d8 |
fix(studio): bump realtime max_concurrent_users soft limit (#50438)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bump realtime max_concurrent_users soft limit to 300k <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Increased the maximum supported concurrent clients from 50,000 to 300,000 when plan entitlements allow it. * **Bug Fixes** * Improved validation for concurrent-client limits, including clearer handling of entitlement-based and unlimited limits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
babebc959c |
fix(studio): improve pipeline destination logo legibility (#50496)
## What kind of change does this PR introduce? UI polish for Pipeline destination logos. ## What is the current behavior? The Snowflake mark does not use the available SVG canvas, and destination marks appear overly inset in the pipeline detail header. ## What is the new behavior? The Snowflake asset uses more of its canvas, and the large `DestinationLogo` variant renders a 32px mark inside its existing 56px frame. Small logos used in lists, diagrams, and destination pickers remain unchanged. | Before | After | | --- | --- | | <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 46 51@2x" src="https://github.com/user-attachments/assets/83e7ab5e-c9f3-4410-99c1-4f3596b9e027" /> | <img width="780" height="160" alt="CleanShot 2026-09-17 at 12 48 33@2x" src="https://github.com/user-attachments/assets/d354dd46-80be-48f6-b2d9-277ee930eaaa" /> | ## To test 1. Open `/project/<ref>/database/replication` with a Snowflake pipeline and confirm its logo renders clearly in the list. 2. Open that pipeline's child route and confirm the destination logo fills more of the header square without changing the square itself. 3. Check another destination's child route and confirm its large logo uses the same sizing. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Increased the size of the large destination logo mark for improved visibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e21e0c73bb |
refactor(studio): simplify pipeline error details (#50444)
## What kind of change does this PR introduce? Studio UI refactor. ## What is the current behavior? Failed replicated tables spread retry timing and error details across several visually heavy blocks. ## What is the new behavior? Condenses retry timing and failure details into a clearer table-level presentation without changing retry behaviour or pipeline mutations. | Before | After | | --- | --- | | <img width="1842" height="594" alt="CleanShot 2026-09-16 at 12 55 52@2x" src="https://github.com/user-attachments/assets/fb6f6a3f-2e81-411e-9d49-ed4cf8cc66e7" /> | <img width="1824" height="328" alt="CleanShot 2026-09-16 at 15 16 21@2x" src="https://github.com/user-attachments/assets/bad558c4-2d4c-4d1b-bb68-32ad4d5b348f" /> | | _Not applicable._ | <img width="832" height="662" alt="CleanShot 2026-09-16 at 15 16 29@2x" src="https://github.com/user-attachments/assets/540a5d55-f99f-4c1e-9a57-5ab2ac31e44e" /> | This is an independent slice extracted from #49630. The related review series is #50443, this PR, #50445, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline with a failed table. 2. Confirm the table row presents its failure and retry timing without expanding the row unnecessarily. 3. Open the error details dialog and confirm the underlying error remains available. This is difficult to test unless you have a properly-failing table. You can instead do the following locally: 1. Check out `dnywh/tmp/pipelines-running-fixture`. 2. Open `/project/<ref>/database/replication/<pipelineId>`. 3. Use the floating pipeline-state switcher in the bottom-right. 4. Select _Running, some tables errored_. |
||
|
|
0b002892d7 |
refactor(studio): simplify pipeline reset dialogs (#50443)
## What kind of change does this PR introduce? Studio UI refactor. ## What is the current behavior? Pipeline table reset dialogs repeat explanatory content and use more layout than the reset decision needs. ## What is the new behavior? Simplifies the single-table and batch reset confirmations while preserving their cost estimate, destructive consequences, and existing reset mutations. | Before | After | | --- | --- | | <img width="854" height="1090" alt="CleanShot 2026-09-16 at 12 54 36@2x" src="https://github.com/user-attachments/assets/f9eef09b-89d1-4747-bc4c-e81fb64c584b" /> | <img width="840" height="742" alt="CleanShot 2026-09-16 at 17 01 11@2x" src="https://github.com/user-attachments/assets/fa45728c-ec66-45c8-9fef-9d2eb8310d4d" /> | This is an independent slice extracted from #49630. The related review series is this one, #50444, #50445, #50446, then #49630. ## To test 1. Open `/project/<ref>/database/replication` and select a pipeline. 2. Reset one replicated table and confirm the dialog explains that destination data will be deleted and resynchronised. 3. Choose **Reset all tables** and confirm the batch dialog shows the same concise treatment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## UI Updates * **UI Updates** * Renamed replication “restart” actions to “reset” across dialogs, buttons, notifications, and cost estimates. * Updated messaging to clarify whether the pipeline will start or restart automatically after resetting. * Added clearer initial-sync guidance for all, some, or none of the affected tables. * Improved reset cost estimate messaging, including when no additional initial-sync charge applies. * Updated reset dialogs with clearer titles, descriptions, loading states, and error messages. * Disabled reset actions when pipeline status is unavailable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cc540ff302 |
feat(studio): add safe theme colour controls (#49804)
## What kind of change does this PR introduce? Feature. ## What is the current behaviour? Studio Appearance preferences only select a theme mode. The underlying theme colours cannot be adjusted, and the existing proof of concept allowed unsafe combinations and introduced a bespoke Slider variant. ## What is the new behaviour? - Preserves the existing System, Dark, Light, and Classic Dark theme options. Classic Dark remains a fixed preset. - Adds four theme colour controls using the existing Supabase Slider unchanged. Each control presents a consistent 0 to 100 scale mapped to bounded light and dark ranges. - Previews colour changes while dragging and persists them once the interaction finishes, including rapid pointer gestures. - Stores light and dark overrides separately, validates stored values, clamps legacy values, and removes overrides that return to their shipped defaults. - Adds concise descriptions for Chroma, Contrast, Surface, and Elevation step, with a scoped Reset action shown only when the active theme differs from its defaults. - Keeps Slider in a stable shared chunk so production builds do not create a circular dependency between generated UI chunks. | Before | After | | --- | --- | | <img width="1448" height="1284" alt="CleanShot 2026-09-15 at 14 33 53@2x" src="https://github.com/user-attachments/assets/d55151c7-b2a9-40c6-9468-e77ae685ac38" /> | <img width="1454" height="1958" alt="CleanShot 2026-09-15 at 17 48 47@2x" src="https://github.com/user-attachments/assets/9d302e67-76cc-4341-948c-81713dea2e93" /> | ## To test 1. Open `/account/me` and scroll to Appearance. 2. Switch between System, Dark, Light, and Classic Dark. Confirm the same four modes remain available in the account theme menu. 3. Confirm Classic Dark retains its existing appearance and does not show theme colour controls. 4. In System, Dark, or Light, move each Theme colors slider to both ends. Confirm the dashboard previews the change, remains readable, and the theme cards do not shift or remount. 5. Reload the page and confirm colour changes persist separately for Light and Dark. 6. Return all sliders to their defaults, or select Reset, and confirm the Reset action disappears. 7. In System mode, change the operating system theme and confirm each resolved mode restores its own colour settings. --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
91b7df64c2 |
fix(ui): report clipboard write failures instead of rejecting (#50292)
Closes DOCS-1390 ## Problem Sentry [DOCS-AA](https://supabase.sentry.io/issues/7727380816/) reports `NotAllowedError: Failed to execute 'write' on 'Clipboard': Write permission denied.` as an unhandled promise rejection. The error names `write`, not `writeText`, which places it in the `ClipboardItem` branch of `copyToClipboard`. That branch has two problems: - The write runs inside a `setTimeout`, so the surrounding `try/catch` has already returned by the time it executes. A denied write routes to the promise's `reject`. - No caller attaches a `catch`. All call sites either fire-and-forget or `await` inside an async handler with no `try/catch`, so the rejection surfaces as an unhandled rejection. The user-visible effect is worse than the Sentry noise. On that branch the copy fails with no feedback at all, because the `toast.error` in the outer `catch` is unreachable from inside the `setTimeout`. The `writeText` branch does show the toast, so the two paths disagree. The issue is filed against auth docs, where it surfaced, but the fix belongs in `packages/ui`. The same branch runs in Studio and www. ## Solution - Handle the failure inside the `setTimeout`, where it happens: report it and resolve. - `copyToClipboard` no longer rejects on either path, matching what the `writeText` branch already did. No caller relied on rejection. - Add regression tests for a denied write on both branches. ## Manual testing 1. Run the unit tests. Four `copyToClipboard` cases pass, including the two new denial cases. ``` pnpm --filter studio exec vitest run lib/helpers.test.ts -t copyToClipboard ``` 2. Confirm the new test is a real guard. Revert `clipboard.ts` and rerun. The write case fails with `promise rejected ... instead of resolving`. 3. Confirm the ratchet is unchanged. ``` pnpm --filter studio run lint:ratchet ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Clipboard write failures now display an error notification instead of causing an unhandled rejection. * Copy operations resolve consistently when clipboard access is denied or unavailable, including Safari clipboard support. * Failed copy attempts no longer trigger completion callbacks, preventing misleading success behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
127e21b926 |
Changes by create-pull-request action (#44860)
Automated changes by [create-pull-request](https://github.com/peter-evans/create-pull-request) GitHub action Co-authored-by: ivasilov <568291+ivasilov@users.noreply.github.com> |
||
|
|
2db6fbf410 |
test(studio): add e2e coverage for the storage move picker (#50460)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Tests, plus one small test hook in Studio. ## What is the current behavior? The Storage file explorer's move dialog was recently reworked: the free-text "Path to new directory" input was replaced with an embedded folder picker (folder browsing, bucket-wide folder search, a responsive breadcrumb, and a confirm button that targets the folder currently open). That work shipped with unit and component tests, but nothing exercises it end to end against a real bucket. ## What is the new behavior? New `e2e/studio/features/storage-move.spec.ts` with seven tests: | Test | What it covers | | --- | --- | | moves a file into a folder picked from the explorer | The core path: open the picker, click a folder, confirm, and assert the file left the root and landed in the destination | | offers folders only, never files, as destinations | Files are excluded from the listing entirely | | blocks confirming a move into the folder the file already sits in | The confirm button reports `aria-disabled` when the destination matches the source | | finds a nested folder by search and moves into it | Bucket-wide folder search, including the "`<folder>` in `<location>`" row label | | reports when a search matches no folders | The empty-search message instead of a blank list | | collapses the middle of a deep path into a breadcrumb dropdown | The responsive breadcrumb: bucket and the two deepest folders stay inline, the middle collapses, and picking a collapsed folder navigates to it | | walks back up the path with the up-one-level button | Disabled at the bucket root, and drops the deepest folder otherwise | Supporting changes: - `utils/storage/queries.ts` gains `uploadObject` and `seedBucket`. Storage has no standalone folders — a folder exists because an object sits under that prefix — so seeding a folder tree means uploading objects at the paths a test needs. Doing this through the API keeps setup off the UI, which is both faster and less flaky than clicking through "Create folder" for each level. - `utils/storage/client.ts` accepts a string body so object uploads can send raw content alongside the existing JSON requests. - `utils/storage-helpers.ts` gains `openMoveDialog` and `confirmMove`. - `MoveItemsFolderPicker.tsx` gains `data-testid="folder-picker-list"` on its list container. ## Additional context **Why the `data-testid`.** Once a path is deep enough for the breadcrumb to collapse, the breadcrumb renders crumb buttons whose accessible names are folder names — so `getByRole('button', { name: 'beta' })` scoped to the dialog can match either a folder row or a breadcrumb crumb depending on depth. Scoping row lookups to the list container removes that ambiguity. This follows the e2e guidance about adding explicit test hooks where a component lacks an unambiguous accessible name. **These tests have not been executed.** They were written against the merged implementation and verified as far as the environment allows: - `npx playwright test --list` collects all seven - `tsc --noEmit` is clean for the new spec and helpers (the pre-existing errors in `column-editor-types.spec.ts`, `table-editor.spec.ts`, and `wait-for-response-with-timeout.ts` are untouched) - Studio's unit and component tests (82) still pass, and typecheck, eslint, prettier, the lint ratchet, and knip are all clean The suite needs Docker to bring up the local Supabase stack, which wasn't available where this was authored, so a real run in CI is the first actual execution. Selectors were all read off the merged source rather than guessed, but timing assumptions in particular deserve attention on the first CI run. **One thing this surfaced, not fixed here.** The success toast reads `Successfully moved 1 files to docs` — it doesn't singularize. The tests assert on `/Successfully moved/` rather than the full string so they don't encode that, but it's worth a follow-up. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns --- _Generated by [Claude Code](https://claude.ai/code/session_01Q94G7pWso6vQn5FQz6TUns)_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Tests** - Expanded end-to-end coverage for moving files between folders in Storage. - Validated folder selection, nested-folder search, empty search results, collapsed breadcrumbs, and navigation to parent folders. - Confirmed files are excluded from destination choices and moving to the current folder is prevented. - Added coverage for creating isolated test buckets, uploading fixture files, and confirming successful move operations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
a133ef60a6 |
fix(studio): correct the Assistant's blocked-tool privacy message (#50411)
When the Assistant calls a tool that's blocked on permissions, the response had two problems. First, it told users their data goes to Amazon Bedrock when production inference [routes to OpenAI](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/pages/api/ai/sql/generate-v4.ts#L170-L172). It now says "third-party AI providers" like the [opt-in settings](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/components/interfaces/Organization/GeneralSettings/AIOptInLevelSelector.tsx#L84-L88) do. I verified that was the last user-facing Bedrock mention. Second, HIPAA-restricted projects got that same copy telling them to change data opt-in settings, but for those projects `getAIDetails` [forces their level to `disabled`](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/lib/ai/ai-details.ts#L70-L73). They get separate copy now to prevent confusion. Closes AI-1154 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added HIPAA-aware AI controls for eligible projects. - AI opt-in is automatically disabled when HIPAA requirements apply. - Privacy messages now distinguish standard AI opt-in restrictions from HIPAA-related restrictions. - AI-assisted SQL and tool experiences consistently apply HIPAA restrictions when determining available capabilities. - **Bug Fixes** - Improved handling of AI settings for HIPAA-sensitive projects and invalid project or organization configurations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9cdd412bab | feat(stripe-atlas): mock-up dashboard to enable live testing (#50327) | ||
|
|
4432a8beb4 |
chore(studio): update Explorer feature preview copy (#50250)
Updates the Explorer feature preview copy to explain the SQL Editor transition, Notebooks, and Snippet migration plans. Adds feedback questions and moves the preview image above the content. Validation: Prettier and `git diff --check` passed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Updated the Explorer preview layout by moving the preview image below the introductory text. - Replaced feedback questions with a clear overview of what enabling the preview provides, including SQL Editor replacement and Notebooks management through the dashboard and Assistant. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
240bfce7f6 |
[FE-4198] feat(studio): select a range of logs with shift-click (#50381)
Shift-clicking a log row checkbox now selects every row between the last clicked row and the clicked one, so you can grab a consecutive block of logs to copy without checking each one. Applies everywhere the shared `LogTable` renders: Postgres/API/Auth/Edge Functions logs and the Logs Explorer. **Added:** - `getShiftClickSelection` in `Logs.utils.ts`: pure helper that computes the next selection from the ordered row keys, the current selection, the anchor row, and the clicked row. Adds the inclusive range in either direction. If the whole range is already selected it deselects the range instead. Falls back to a plain toggle when there's no usable anchor. Covered by unit tests, plus `LogTable` component tests for range select, the no-anchor fallback, anchor clearing, and range deselect. **Changed:** - `LogTable` tracks the last toggled row as the range anchor (a ref, since it's only read in handlers). The anchor is set by plain clicks, shift-clicks, and the Shift+Space row toggle, and cleared whenever the selection becomes empty (toggling off the last row, plain row click, Escape, action bar clear, select-all then deselect-all, or a new query loading). - The checkbox cell handles `onClick` instead of `onCheckedChange` so the shift key is available. Keyboard Space on a focused checkbox still toggles it, since Radix dispatches a click for it. - A shift mousedown on the checkbox cell is prevented so the browser doesn't start a text selection across rows. Unified Logs has its own row selection (TanStack Table) and is not changed here. ## To test - Open any log page with a decent number of rows, e.g. Postgres logs. Click one checkbox, then shift-click a checkbox several rows below. Every row in between should be checked and the action bar should show the count. Repeat upward. - Shift-click a range that's already fully selected: the range should clear, and rows outside it stay as they were. - Plain-click a row's message text (not the checkbox): side panel opens and the selection clears. A following shift-click should just toggle that one row. - Press Escape or the action bar's clear button, then shift-click: also just a single toggle. - Focus a row with the arrow keys, press Shift+Space, then shift-click a lower checkbox: the range should extend from the keyboard-toggled row. - Tab to a checkbox and press Space: it should still toggle. - After a shift-click, confirm no text is highlighted across the rows. - Copy as JSON/Markdown/CSV still copies the selected rows in display order. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added shift-click range selection to the logs table for selecting or deselecting consecutive rows. - Preserved single-row selection when range selection is unavailable. - Improved selection behavior when clearing selections or changing log queries, preventing stale range anchors. - **Tests** - Added coverage for forward and reverse range selection, deselection, partial selections, fallback behavior, and input immutability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
99be7f92ce |
feat(studio): add Privacy Policy update notice (#50397)
## Summary Adds a compact Privacy Policy update notice for signed-in Studio users on organization landing pages. - Shows on `/org`, `/organizations`, and `/org/:slug` - Opens the approved policy explanation in a dialog - Links to the Privacy Policy and `privacy@supabase.com` - Persists acknowledgement in a dated local storage key - Stays off project and organization settings routes so it cannot cover product controls ## Why The Privacy Policy changes the data controller from Supabase, Inc. to Supabase Pte. Ltd. User rights and protections are unchanged. This restores the established authenticated Studio notification pattern: - [#35923](https://github.com/supabase/supabase/pull/35923): May 2025 Privacy Policy notice - [#43681](https://github.com/supabase/supabase/pull/43681) and [#43889](https://github.com/supabase/supabase/pull/43889): March 2026 Privacy Policy notice and design pass - [#45632](https://github.com/supabase/supabase/pull/45632): May 2026 Terms of Service notice - [#48524](https://github.com/supabase/supabase/pull/48524): current reusable Studio banner stack ## Release order The policy content and Studio notice deploy independently. Keep this PR in draft until [#50392](https://github.com/supabase/supabase/pull/50392) is approved, merged, and live. The notice appears immediately when this Studio change deploys. ## To test 1. Open Studio on `/organizations` or an organization project-list page. 2. Confirm the compact Privacy Policy notice appears. 3. Open **Learn more** and confirm the dialog copy and both links. 4. Select **Understood** or close the notice. 5. Reload and confirm the notice remains dismissed. 6. Remove `privacy-policy-update-2026-09-16-dismissed` from local storage and confirm the notice returns. 7. Open a project route and confirm the notice is absent. ## Verification - Prettier passes on changed files. - ESLint passes on changed Studio files. - Focused Vitest suites pass: 25 tests. - Studio Unit Tests & Build Check passes. - TypeScript & Lint, UI Tests, Studio Docker Build, dead-code, ratchet, and validation workflows pass. - All four self-hosted Studio E2E shards pass for both router implementations. - All deploy previews pass. - The Studio preview rendered the compact notice on the organization landing page without console errors. The dialog and dismissal flow still need an authenticated browser pass after the session redirected to sign-in. A direct local Studio TypeScript check reaches one existing unrelated error in `packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx`; no changed file reports an error and the required TypeScript CI workflow passes. ## Measurement Success means signed-in users can find the updated policy from the organization landing experience without interrupting project work. The dated dismissal key confirms acknowledgement locally. CI protects the non-blocking route scope, and Privacy can monitor questions sent to `privacy@supabase.com` after release. --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com> |
||
|
|
c52fca1340 |
MFA Recovery codes: enforce recovery codes generation after setting up an MFA (#50343)
## What kind of change does this PR introduce? Afters users set up an MFA, automatically generate recovery codes ## How to test - On an account that doesn't have recovery codes generated yet, add a new MFA - When you finished verifying the MFA, it should automatically open the recovery codes modal introduced in previous PRs <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved the two-factor authentication setup flow by checking the latest recovery-code enrollment status before generating codes. - Recovery codes are now generated and displayed after verification when they are enabled but not yet enrolled. - Loading indicators now reflect recovery-code status checks, providing clearer feedback during setup. - **Improvements** - Updated the recovery-code confirmation message to explain how codes can restore access after losing access to an MFA app and remind users to store them securely. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ee3fbc4e61 |
Joshenlim/fe 4383 consolidate tablerow no search result state (#50389)
### Context Just some housekeeping/consolidate refactors. There's a number of places where we render the same "no result" empty state for tables. So this PR just consolidates that into a reusable component `TableRowNoResults` to reduce duplication. Opting to save this under `components/ui` instead of the `ui` package as this is more of a derivation of `TableRow` than a primitive <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **UI Improvements** - Standardized empty search-result messages across database, functions, storage, and vector bucket tables. - Search terms now appear consistently when no matching records are found. - Added an accessible label to the vector bucket row actions menu. - Improved the storage explorer loading layout so content expands to use available vertical space. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
881a7d3151 |
fix(studio): show only the disabled reason on the invite members button (#50426)
The invite members button sits inside two Radix tooltip roots — the keyboard-shortcut tooltip and the disabled-reason tooltip — which both anchor to the same element and stack on top of each other when the user lacks invite permission. Widened the existing `tooltipOpen` condition so the shortcut tooltip stays closed whenever a disabled reason is showing, and hoisted that reason into one variable so the tooltip text and the suppression condition can't drift. Fixes FE-4393 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Disabled member invitations now prevent the invite button and keyboard shortcut from opening the invite dialog. * Invite controls display the appropriate disabled-feature or permission warning. * Shortcut tooltips are hidden when invitations are unavailable or the user lacks permission. * **Tests** * Added coverage for disabled invitations, permission warnings, dialog prevention, and shortcut tooltip visibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Fixes: https://github.com/supabase/supabase/issues/49859 |
||
|
|
7ab2a0d84f |
Fix TextConfirmModal does not reset its state (#50406)
## Problem `TextConfirmModal` does not reset its state after closing, whether users confirmed or not. If they would restart the action, the confirmation text they may have entered is kept, preventing the secure confirmation. Also fixed an accessibility issue as we didn't enable the submit button until the form was valid ## Solution Reset the form state whenever the dialog opens. ## How to test - On https://studio-staging-git-gildasgarcia-design-505-rese-196b28-supabase.vercel.app/dashboard/account/security - Either: - Add an MFA if you haven't already - Generate recovery codes if you already have an MFA - Click the _Regenerate recovery codes_ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Text confirmation dialogs now reset their input whenever opened or closed, ensuring a fresh form for each use. - Confirmation actions remain available unless the dialog is processing a submission. - Copy-to-clipboard actions now provide an accessible announcement when text has been copied. - **Tests** - Added coverage for successful confirmation, cancellation, invalid submissions, input reset behavior, and recovery-code regeneration retries. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7fce0a12d9 |
feat(design-system): first pass at db report chart colours (#46787)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This is a first draft at introducing semantic colours to our Observability charts. This moves away from just random colours being assigned to prop after prop. They're only scoped to the Database reports right now, but if it flows nice, we can open it up to the other reports too. This also aims to tone down some of the harsher colours in our charts, such as the orange which sometimes can look like a warning metric/prop. | Before | After | |--------|--------| | <img width="839" height="336" alt="Screenshot 2026-06-10 at 09 14 56" src="https://github.com/user-attachments/assets/222747c5-973b-4165-aa53-df7b93412ad3" /> | <img width="950" height="341" alt="Screenshot 2026-09-14 at 18 14 47" src="https://github.com/user-attachments/assets/836f3ddd-4a97-4064-b8cf-3a3b435417ac" /> | cc @supabase/design for additional thoughts. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added semantic chart color roles with light and dark theme variants for consistent visualizations. * Standardized colors and fills across database, networking, storage, and connection charts. * Maximum-value lines now use configured chart colors when available. * Added chart palette reference and stress-test examples. * Added stacked bar charts, customizable margins, and gradient-filled line charts. * Improved multi-series bar chart focus and date-range footer alignment. * **Documentation** * Documented the chart palette, theme variants, accessibility guidance, and usage recommendations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> |
||
|
|
92fdb1d3c5 |
feat: update storage move UI (#50346)
Update path selection as destination where to move files in the Storage File Explorer. ## What is the current behavior? Currently you need to write out the entire path by hand, which is error prone and quirky. <img width="727" height="436" alt="Screenshot 2026-09-14 at 15 49 11" src="https://github.com/user-attachments/assets/2bb8fc78-d973-4b17-9343-08df23b67d2a" /> ## What is the new behavior? This PR adds a ui that lets the user select any folder as the destination of the file move. <img width="923" height="606" alt="Screenshot 2026-09-15 at 11 40 00" src="https://github.com/user-attachments/assets/2f4c50f8-3c11-4896-832e-b1e99defc9af" /> https://github.com/user-attachments/assets/261ac24e-ec24-4bcf-ad47-72bc48e27bab To test: - go to Storage File explorer and pick a file to "move" (action in the dropdown menu) - mov file to any other folder in the same bucket selecting destination folder from the ui in the dialog - both empty folder or also a folder with sub-folders can be destinations, as any selected folder becomes the active destination (notice the cta changing when selecting a folder) - batch move multiple items via multi-select (already supported, but using the updated ui now) - only folders should appear in this ui - destination folders can be searched using the search input <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Replaced the move-items path field with an interactive folder browser. - Browse, select, and search folders by name or path, with pagination and loading or empty states. - Navigate using breadcrumbs, including collapsed-path menus for deeply nested folders. - Receive warnings when folder search results are incomplete for very large buckets. - See clearer destination labels and protection against moving items to their current location. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
232ce7e68c |
docs: focus Logs on the unified view and export queryable fields (#50073)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. Yes. ## What kind of change does this PR introduce? Documentation update and a small Studio copy correction. ## What is the current behavior? The Logs guide mixes unified filtering with retired SQL Explorer instructions, and the Markdown field reference loses query semantics. ## What is the new behavior? The Logs guide mixed filtering and event inspection with the retired SQL Logs Explorer workflow. It now documents the unified Logs view: default sources, filter semantics, event details, Live, sharing, bounded exports, and missing results. The log field reference uses one mapping for HTML and Markdown, preserving source IDs, query expressions, and source/query types. The Studio User-filter empty state and comments now match its Auth and API Gateway scope. ## Additional context Validation: shared-field mapping tests, guides Markdown generation, docs typecheck, targeted docs/Studio ESLint, formatting, and browser inspection of the field table. Exported Markdown includes the source IDs and usable ClickHouse expressions. Repository-wide MDX lint has existing failures; changed pages have no reported violations. Self-review: hosted Studio filtering and log ingestion were checked against the implementation, not exercised against a hosted project. The documentation assumes the unified Logs experience is the default. Stage 1 of 3. Review and merge from the bottom of the stack. Stack: #50073 → #50074 → #50075. Production docs build also passes at the stack tip after standard reference generation. Initial CI note: the spelling action failed while building its container because Debian package downloads returned 404, before checking content. The stack has no merge conflicts. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded the log field reference with ClickHouse fields, nested-field query examples, types, schema references, and capture limits. * Reworked the Logs guide with clearer instructions for filtering, event inspection, live mode, sharing, exports, retention, and missing results. * Clarified service and Postgres log behavior and updated navigation and metadata. * **Bug Fixes** * Corrected user-filtering guidance and empty-state messaging to identify Auth and API Gateway logs as supported sources. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Steven Eubank <eubank.steven88@gmail.com> Co-authored-by: Steven Eubank <47563310+smeubank@users.noreply.github.com> |
||
|
|
e296d0ae4f |
Joshenlim/fe 4373 add ilike comparator for pathname in unified logs (#50386)
## Context In unified logs, filtering on pathname can benefit using the `ilike` comparator so this PR adds support for that <img width="423" height="247" alt="image" src="https://github.com/user-attachments/assets/31e5f09b-7506-4588-90e3-ee705f805d43" /> FilterBar is also updated to omit facet values if the selected comparator is `ilike`, otherwise it doesn't really make sense to show a dropdown of values for users to select as the value for `ilike` filtering. <img width="240" height="62" alt="image" src="https://github.com/user-attachments/assets/b5fc97e7-d826-4184-8b70-bfb4875d1822" /> The facet values should still show if the selected comparator is an equals comparator <img width="391" height="154" alt="image" src="https://github.com/user-attachments/assets/7ccded04-3db1-4406-af40-4377ffe3bd8d" /> Related to https://github.com/supabase/supabase/pull/50394 - am also updating ilike comparator logic for unified logs to implicitly wrap the provided string with `%`, but only if the string doesn't already contain a `%` or `_` for UX convenience. (Unified logs already had this behaviour, except the latter part RE omitting default `%` if string already has) - this affects pathname and event_message searching <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Added case-insensitive pathname filtering for logs with ILIKE and NOT ILIKE. * Added pathname support for comparison and pattern-matching operators. * Preserved user-provided `%` and `_` wildcard patterns in searches. * **Bug Fixes** * Corrected BigQuery pathname filtering for consistent case-insensitive matching. * Prevented misleading exact-value suggestions for pattern-based searches. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b1a9e072ec |
Update table editor ilike related comparators to implicitly wrap filter string with % if not provided (#50394)
### Context For table editor - the `ilike` related comparators expect users to input a `%` in the filter string, which for non-developers might not be intuitive. Hence opting to implicitly wrap the filter string with `%` in the query when filtering if non provided <img width="1182" height="755" alt="image" src="https://github.com/user-attachments/assets/819c39f5-fcbf-4213-95b3-3ad1ee901f47" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved pattern-match filters so bare text values perform contains matching by automatically wrapping them with wildcards. * Preserved explicit wildcard patterns using `%` or `_` without adding additional wildcards. * Improved handling of empty values for non-text filters while retaining existing numeric filter validation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
229d04d65c |
feat(studio): give pipeline pages a standard detail header (#50253)
## What kind of change does this PR introduce? Studio page-layout polish. This follows the merged destination-brand and pipelines-list work in #50251 and #50252, and now targets `master` directly. ## What is the current behaviour? Pipeline child pages use a bespoke heading, provide limited destination context, and shift substantially while pipeline and destination data load. ## What is the new behaviour? Adds standard breadcrumbs and page-header composition, destination identity, the primary-database-to-destination path, lifecycle actions, and child-route integration. Layout-matched loading placeholders keep the header geometry stable until the resolved pipeline data is available. Removes the legacy Overview header and actions now owned by the shared page shell, and restores standard content gutters around the existing metrics and tables. Pipeline action errors are handled once by the layout, avoiding duplicate notifications from the underlying mutations. Pipeline actions are also temporarily disabled while a table reset is running to prevent conflicting requests. | Before | After | | --- | --- | | <img width="1131" height="801" alt="Replication Database ETL BigTable ETL Team Supabase" src="https://github.com/user-attachments/assets/3f0ebab0-7244-4aa1-81ac-8847f5f86d4a" /> | <img width="1131" height="801" alt="Replication Database Agua Basket Supabase" src="https://github.com/user-attachments/assets/bcbbd150-2a3d-468d-9cb9-652a6de2040b" /> | ## To test 1. Open a pipeline at `/project/<ref>/database/replication/<pipeline-id>`. 2. Confirm there is one page header with one set of actions, followed by a consistently padded Overview body. 3. Confirm the breadcrumbs, destination logo and name, status, source-to-destination path, primary lifecycle action, and overflow actions. 4. Start, stop, or restart the pipeline and confirm its status and available actions update appropriately. 5. Reset a replicated table and confirm the pipeline lifecycle, update, and overflow actions remain disabled until the reset finishes. 6. Throttle the initial pipeline and destination requests and confirm the header retains its final geometry without showing fallback data. 7. Check the page at desktop and phone widths. --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
10eaab766f |
fix(studio): filter on every column when viewing a composite FK record (#50256)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Bug fix ## What is the current behavior? In the Table Editor, the "View referencing record" arrow on a foreign key cell builds its filter from the table's `relationships` list. That list is one entry per source-by-target column combination, and the formatter takes the first entry whose source column matches the clicked cell, then filters the referenced table on that single target column. For a composite foreign key this fails in two ways: - The value from the clicked column can be applied to the wrong target column (whichever target column happens to be listed first for that source column). - Only one of the key columns is ever filtered on, so the peek and the "Open table" link return zero rows or too many rows. This is distinct from #41068 / #41080, which fixed the cartesian expansion in the shared `tables.ts` introspection query. The bug reproduces with that fix in place because the mis-pairing happens in Studio when building the filter. Reported by a customer via support. ### Reproduction Run this in the SQL editor. The referenced column list `(org_id, bucket_id)` is deliberately not in the referenced table's physical column order, which is what exposes the bug. ```sql create schema if not exists dcs; -- bucket_id declared first, org_id second create table dcs.org_metering_buckets ( bucket_id bigint not null, org_id bigint not null, primary key (org_id, bucket_id) ); create table dcs.machine_storage_usage_buckets ( org_id bigint not null, org_metering_bucket_id bigint not null, constraint machine_storage_usage_buckets_org_metering_bucket_fkey foreign key (org_id, org_metering_bucket_id) references dcs.org_metering_buckets (org_id, bucket_id) ); insert into dcs.org_metering_buckets (bucket_id, org_id) values (901, 1), (902, 1), (903, 2); insert into dcs.machine_storage_usage_buckets (org_id, org_metering_bucket_id) values (1, 901), (1, 902), (2, 903); ``` 1. Open `dcs.machine_storage_usage_buckets` in the Table Editor (select the `dcs` schema). 2. Hover the `org_id` cell on the row where `org_id = 2`. 3. Click the "View referencing record" arrow. 4. Click "Open table" in the popover. **Before this PR:** the popover shows "No results were returned". "Open table" opens `dcs.org_metering_buckets` with a single filter `bucket_id = 2`, which matches nothing. **After this PR:** the popover shows the one row `(bucket_id = 903, org_id = 2)`. "Open table" opens `dcs.org_metering_buckets` with two filters, `org_id = 2` and `bucket_id = 903`, and the URL carries two `filter=` params. Clicking the arrow on the `org_metering_bucket_id` cell of the same row produces the same result. Extra checks worth doing while you are there: - Set one of the two key columns to NULL on a row. The arrow should disappear for both key cells on that row, since a row with a null key column does not reference anything under MATCH SIMPLE. - A single-column foreign key (any existing table) should behave exactly as before. ## What is the new behavior? - New `ForeignKeyFormatter.utils.ts` with two pure functions. `findColumnForeignKeyConstraint` locates the constraint on the current table that contains the clicked column. `getReferencingRecordFilters` pairs each source column with the target column at the same ordinal position and builds one equality filter per pair from the row's values, keeping the existing bytea-to-hex handling per column. It returns no filters when any key column is null. - `ForeignKeyFormatter` now reads the foreign key constraints query, which returns ordinally paired source and target column arrays, instead of the `relationships` list. The grid already fetches that query for the same schema, so it is served from the React Query cache. - `ReferenceRecordPeek` takes a `filters` array instead of a single column and value. Both the peek query and the "Open table" link use the full set, and the link emits one URI-encoded `filter=` param per column. - Unit tests cover the reproduction above, single-column keys, bytea values, null and missing values, falsy-but-valid values such as `0`, and malformed constraints. ## Additional context The table-editor introspection SQL in `packages/pg-meta/src/sql/studio/table-editor/table.ts` and `tables-paginated.ts` still expands composite foreign keys as a cartesian product. #41080 only fixed the shared `tables.ts` query. The arrow no longer depends on that data, but it can still mislabel the referenced column elsewhere in Studio, so that is left for a follow-up rather than widening this change into pg-meta SQL. Before: <img width="836" height="504" alt="Screenshot 2026-09-14 at 11 22 49" src="https://github.com/user-attachments/assets/4645d64f-9bcb-44b0-b5b1-ab11ba7436db" /> After: <img width="873" height="570" alt="Screenshot 2026-09-14 at 11 23 14" src="https://github.com/user-attachments/assets/f2c47121-fd75-4efe-a370-28015c1b674e" /> 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01SkH86UV1KD4Xs5k9vt43tW <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved foreign-key record previews to correctly identify referenced records across schemas and tables. * Added support for composite foreign keys, ensuring previews and “Open table” links apply all required column filters. * Improved handling of binary values and incomplete or null foreign-key data. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> |
||
|
|
5b099ee03f |
chore: share Sentry browser-noise filters between studio and docs FE-4392 (#50407)
Studio and docs each kept their own Sentry `ignoreErrors` list, so browser-extension and DOM-mutation noise that Studio already filtered still reached Sentry from docs. Moved the app-agnostic filters (network, extension DOM mutation, non-Error throws, cross-origin script errors) into `packages/common/sentry.ts` and spread them into both client configs, leaving app-specific entries local. Docs will stop reporting extension-driven `insertBefore`/`removeChild` crashes, matching Studio's existing behavior — `ignoreErrors` drops events before `beforeSend` runs, so the error-boundary exemption no longer applies to them. Fixes FE-4392 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Reduced non-actionable browser noise in error monitoring by filtering known network, browser extension, DOM-manipulation, cross-origin, and non-error failures. - Applied consistent filtering across the documentation site and studio error tracking. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
254da82c3a |
feat: surface role risks (#50410)
## TL;DR Bolds the consequences in the Owner and Administrator role descriptions, and adds a confirmation step before an invite for either role is sent. https://github.com/user-attachments/assets/c8fb53ae-66c3-4862-865e-f2ff9fb84a8e ## ref: - recurring in the community: organizations losing access to their own projects after inviting someone as owner eg: https://discord.com/channels/839993398554656828/1545087567706193970/1545102402871492759 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a confirmation step when inviting members as Owners or Administrators. - Invitations are sent only after the elevated-role warning is confirmed. - Confirmation behavior is consistent for form submissions and keyboard-triggered invitations. - **Updates** - Refined role permission descriptions, including clearer details about elevated access and project deletion capabilities. - Improved role descriptions shown during member invitations and role selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
24f89f3967 |
MFA Recovery codes: allow users to regenerate their codes (#50336)
## What kind of change does this PR introduce? Once users have recovery codes generated, allow them to regenerate the codes. This PR also automatically check the _I have copied the codes_ after clicking the _Copy to clipboard button_. > [!NOTE] > The _Delete my recovery codes_ button only appear on local and staging environments ## How to test - On an account that already have recovery codes generated - You should see an admonition showing the remaining codes available and allowing you to regenerate the codes ## Screenshots <img width="706" height="193" alt="image" src="https://github.com/user-attachments/assets/001bfa87-74f5-4867-8564-09cb6f91adb6" /> <img width="425" height="277" alt="image" src="https://github.com/user-attachments/assets/711b139c-f806-4da2-a240-fa7e7fd8acd0" /> <img width="548" height="353" alt="image" src="https://github.com/user-attachments/assets/d6521a09-3a7f-4198-b162-9effc218fee6" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a recovery-code modal with copy-to-clipboard support and confirmation before closing. - Added an option to regenerate MFA recovery codes with a confirmation step. - Recovery-code controls now appear when existing codes are available. - Added loading, success, error, and retry states for recovery-code generation and regeneration. - **Bug Fixes** - Updated the recovery-code generation error message to more accurately describe the failed action. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b824acdfd2 |
feat(project-creation): support Kubernetes cluster override for internal project creation (#49956)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature, internal ## What is the current behavior? When creating a project, the worker will use load balancing to decide where to deploy a cluster. ## What is the new behavior? An internal user can choose a specific cluster and even bypass the CORDONED state by forcing deployment. ## Additional context This PR adds kubernetesClusterId and kubernetesClusterForce to the internal-only project creation form for K8S cloud providers, gated by schema validation (provider-restricted; force requires an ID) and cleared automatically on provider change. The override is a one-time creation-time steer, not a persistent pin, and the UI copy reflects that. Includes the matching kubernetes_cluster_id/kubernetes_cluster_force request fields in the generated platform API types. <img width="1620" height="1352" alt="image" src="https://github.com/user-attachments/assets/bd8965a1-cec8-4428-aac1-46d0bf3b89d3" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Kubernetes cluster ID entry during project creation for supported cloud providers. * Added an option to force deployment to a specified cluster. * Clarified that eligible clusters must meet status and filesystem requirements. * **Bug Fixes** * Prevented invalid or outdated Kubernetes settings from being submitted when the provider or cluster selection changes. * Treated blank or whitespace-only cluster IDs as unset. * Prevented force-deployment requests without a cluster ID or for unsupported providers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3bac7165bd |
chore(studio): move the TanStack Start deploy onto Nitro (#50030)
Moves the Studio TanStack Start build off the hand-rolled Vercel setup (an `api/server.js` function shim, rewrites in `vercel.ts`, a custom `?dpl=` skew-protection Vite plugin, and `scripts/serve.js` for self-hosted) and onto Nitro, which TanStack Start documents as its deployment path. Documents are served from the static SPA shell on the CDN; only `/api/*` and `/_serverFn/*` invoke the function. **Removed:** - `api/server.js`, `scripts/serve.js`, `scripts/smoke-server.mjs` - The `skewProtectionDpl` Vite plugin, `renderBuiltUrl`, and the `vite:preloadError` reload backstop in `router.tsx` (TanStack Router already reloads once on a failed lazy import) - Rewrites, `functions`, `outputDirectory`, and `cleanUrls` from `vercel.ts` (redirects and headers stay) - `magic-string` and `@jridgewell/remapping` devDependencies, the `preview` script **Added:** - `nitro` plugin in `vite.config.ts`. Preset is auto-detected: `.vercel/output` on Vercel, a self-contained node server in `.output` everywhere else. `vercel.immutableStaticFiles` puts hashed chunks under `/_vercel/immutable/` so tabs opened before a redeploy keep loading their chunks; `functions.maxDuration: 300` carries over the old function timeout - `scripts/vercel-spa-routes.ts`: Nitro module that rewrites the generated Build Output routes (documents -> `_shell.html`, allow-list -> `__server`, missing chunk -> 404, base-path prefixes), with a unit test - `server.ts`: TanStack Start server entry that initializes Sentry before the route tree loads and wraps the handler with `wrapFetchWithSentry` **Changed:** - `start:tanstack` runs `.output/server/index.mjs` directly with Node's `--env-file-if-exists` for the `.env` cascade. Node doesn't expand `$VAR` references, so `scripts/generateLocalEnv.js` now writes literal values into `.env.test` - Dockerfile's TanStack stage copies `.output` instead of running `pnpm deploy`; the `server.js` shim loads `.env` and imports the Nitro server - `NEXT_PUBLIC_BASE_PATH` (the platform's `/dashboard`) only sets the router basepath; Vite's `base` stays at the root so chunks can use the immutable store. The routes module emits prefixed rules for `/dashboard/api/*` and `/dashboard/_serverFn/*` and rewrites `public/` files requested under the prefix back to the root - Self-hosted security headers come from a Nitro `routeRules` entry; on Vercel they stay in `vercel.ts` - `tslib` is inlined for the build only: Nitro's dev runner has no interop for its CJS wrapper - Monaco's worker chunks follow the client assets dir so they land in the immutable store too Verified on the `studio-staging` preview (`STUDIO_FRAMEWORK=tanstack` is scoped to this branch there): documents come back as the static shell, `/dashboard/api/*` hits the function, `public/` files resolve under the prefix, a missing immutable chunk 404s. Across two deployments of this branch, the older deployment's chunks still load from the immutable store and requests carrying its `__vdpl` cookie are answered by that deployment. Self-hosted path covered by the TanStack E2E job and the Docker build job. ## To test - On the `studio-staging` preview: `/dashboard/project/<ref>` should show `content-disposition: inline; filename="_shell.html"` and a single-region `x-vercel-id`; `/dashboard/api/get-utc-time` a two-region id - Sign in and click through a few pages, including one that opens Monaco (SQL editor) so the worker chunks load - After the next deploy, a tab left open on the previous one should still navigate (lazy chunks) and call the API without errors - Self-hosted: `STUDIO_FRAMEWORK=tanstack pnpm --filter studio build && pnpm --filter studio start`, then check `/api/platform/profile` and that responses carry the security headers <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Production TanStack deployments now run on Nitro’s self-contained server output. * Vercel routing serves static pages first while directing API and server-function requests appropriately. * Server-function requests can include deployment identification for consistent handling. * Local environment generation now writes resolved configuration values. * **Bug Fixes** * Improved handling of missing static assets and SPA fallback routing. * Server-side error monitoring now captures request errors in the new runtime. * **Refactor** * Replaced the legacy production server and smoke-test workflow with Nitro-based startup. * Removed automatic reload handling for stale client assets. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
fa7c223209 |
fix(studio): use Compute management endpoints FUNC-896 (#50393)
## Problem Studio still called the legacy `/workers` Management API routes and used the old `project_worker` response contract, so Compute instances could not be listed or retrieved after the API rename. The production API type check also detected drift in the v1 and platform declarations. ## Fix - Regenerate the v1, v2, and platform API declarations from the deployed schemas. - Update Studio list and detail queries to `/compute`. - Align typed fixtures with the Compute response schemas and `project_compute_instance` resource type. - Update platform response type references to the generated `_Output` schema names. ## How to test - Run `pnpm api:verify-types`. - Run `pnpm --filter api-types test`. - Run `pnpm --filter studio test data/compute/compute.utils.test.ts "tests/pages/project/[ref]/compute/index.test.tsx"`. - Run `pnpm --filter studio typecheck`. - Run `pnpm --filter common typecheck`. - Run `pnpm --filter studio lint:ratchet`. Expected result: production API declarations are synchronized, and Studio requests the `/compute` list and detail endpoints and renders `project_compute_instance` responses successfully. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Updated API response handling across profiles, backups, notifications, integrations, warehouses, access tokens, payments, and other Studio workflows for more accurate serialized data. * Compute instance pages and queries now use the compute-specific API endpoints and response data. * Improved feature-flag type handling when disabled feature data is unavailable. * **Tests** * Updated automated coverage and fixtures to reflect current compute and API response formats. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c228ca4f61 |
fix(studio): restore function deployment annotations FE-3921 (#50362)
## Problem The Edge Function overview converted the numeric deployment timestamp to a string before parsing it as a date. This produced an invalid date, so the invocations chart omitted the deployment annotation. ## Fix Preserve the numeric timestamp returned by the API and allow the annotation helper to parse both numeric and string timestamps. Show deployment details in an accessible tooltip when hovering or focusing the rocket marker, and add regression coverage for numeric timestamps and the existing invalid, missing, and out-of-range cases. ## How to test - Run the focused EdgeFunctionOverview utility test suite. - Open an Edge Function whose latest deployment is within the selected chart interval. - Hover or focus the rocket marker. - Expected result: the invocations chart shows the dashed deployment line and rocket marker, and the marker tooltip shows the deployment time. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Invocation update annotations now display correctly when function update times are provided as numbers. - Timestamps at the start of the Unix epoch are now supported. - Annotations no longer appear when update times are invalid or chart data is incomplete. - **Accessibility** - Deployment markers in invocation charts are now keyboard-focusable and include accessible labels. - Deployment timestamps are available in a tooltip on hover or focus. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |