- Remove the 'Restoring is non-destructive' admonition from the
bottom of the Versions tab
- Refactor getMockObjectVersions to accept the bucket's current
cap and expiryDays and adapt its output so version-list labels
are always consistent with the policy:
* Never returns a version older than the retention window
(no 'Past Nd limit' surprises when the user set fewer days)
* Never returns more noncurrent versions than the cap
(no '#3 of 2' when the user tightened the cap)
- Anchor all version timestamps to the real clock via
daysAgoFromNow so the mock stays fresh regardless of when the
prototype is opened, instead of drifting away from the fixed
BASE_DATE
- Wire useObjectVersionsQuery to look up the bucket's protection
and pass it into the mock on every fetch, so policy edits from
the bucket modal reflect in the panel next time it opens
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Show expiration policy context directly in the Versions tab:
- Cap badge and retention badge in the header section
- Combined mode indicator (both/either) when both policies are set
- At-cap and nearing-cap warnings
- Per-version VersionExpiryIndicator showing days remaining and
cap position (#N of M) with warning colors based on combined
and/or policy logic
- Pre-computed noncurrent indices for efficient lookup
- Versioning-suspended admonition banner
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Call trigger() after each field.onChange so zod validation runs
immediately as the user types, surfacing errors via FormMessage
- Simplify the S3 cap error message to 'Cannot exceed 100 versions'
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Add S3_MAX_NONCURRENT_VERSIONS constant (100) and enforce it in
superRefineBucketProtection independently of plan limits
- Remove HTML min attributes from both inputs so only Supabase inline
errors (FormMessage via FormItemLayout) appear — no browser tooltips
- Plan-specific bounds still enforced as before; the S3 cap is checked
first with a distinct error message
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- 'both' mode: show a second example where one condition isn't met,
making it clear the version is kept because both must be exceeded
- 'either' mode: show two examples — one where only the version cap
is exceeded, one where only the age limit is exceeded — to
illustrate that either condition alone triggers deletion
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Days only: show a version at days+1 (deleted) vs days-1 (kept)
- Versions only: show versions+1 total, oldest one gets deleted
- Both conditions: show versions+1 at days+1, explain the and/or logic
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Change InputGroupText suffix from 'max' to 'versions' on the retained
noncurrent versions input
- Show 'See how this works' explainer when either expiration field has a
value, not only when both are set
- Add context-specific explainer text for days-only, versions-only, and
both-conditions cases
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Replace custom raw <input> elements with FormItemLayout + InputGroup +
FormInputGroupInput + InputGroupAddon pattern from the design system
- Use layout='flex-row-reverse' for label-left, input-right alignment
- Both version_expiry_days and max_noncurrent_versions default to empty
(no prefill on toggle)
- Add warning Admonition when no expiration policy is configured to
alert about ongoing storage costs
- Remove unused useFormState import and prefill logic
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Replace the standard form-field layout with the design-handoff UI:
- Sentence builder paragraph that adapts to which fields are filled
(both empty → 'retained indefinitely', one filled → describes that
condition, both filled → sentence with inline toggle)
- Inline [both | either] pill toggle embedded in the sentence text
when both conditions are set (maps to ExpirationMode 'and' / 'or')
- Compact number inputs with suffix labels ('days' / 'max'),
right-aligned text, and em-dash placeholder
- Collapsible 'See how this works' section with a dynamic example
that uses the actual input values and updates on toggle
- Both fields are now optional — empty means 'no limit' for that
condition. Validation only checks min/max when a value is provided.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Replace bg-border-stronger (oklch with alpha) with solid hsl values:
- Light mode: hsl(0 0% 80%) — neutral mid-gray
- Dark mode: hsl(0 0% 30%) — neutral mid-gray
This prevents the accentuated color at the intersection where
the vertical and horizontal lines overlap.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Lift expandedVersionIds state to DeletedFilesContext (shared between
DeletedFilesList and FileExplorerHeader)
- Move 'Expand all' / 'Collapse all' buttons from the table header into
the FileExplorerHeader top bar with outline button variant
- Change tree-connector line color from bg-foreground-muted to
bg-border-stronger for a subtler appearance
- Increase gap between horizontal tree branch and version title text
(pl-[22px] → pl-[36px], w-[11px] → w-[8px])
- Apply same tree line changes to standalone Trash page (TrashList)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Tree connector lines use bg-foreground-muted instead of bg-border for
better visibility
- Horizontal branch shortened from w-[15px] to w-[11px], creating a 4px
gap between the line end and the version text (text still aligns with
parent name)
- Replaced the icon-only expand/collapse toggle in the table header with
two separate text buttons: 'Expand all' and 'Collapse all', separated
by a dot divider
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Replace CornerDownRight icon with CSS tree-connector lines for nested
version rows. Each version draws:
- A vertical line from the top border to the junction point (center)
- A horizontal branch from the junction to the version text
- For non-last versions, the vertical line continues to the bottom
border, connecting seamlessly with the next row
- For the last version, the vertical line stops at the junction (└ shape)
Lines are positioned at left-[23px] to align with the parent row's
chevron center (16px cell padding + 7px icon center). Version text
starts at pl-[22px] to align with the parent row's name text.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Version rows are now selectable via checkboxes for batch multi-selection,
using composite keys (objectId::versionId) in the shared selection state
- Clicking a version row opens the preview panel with version-specific
metadata (version ID, action, created date, size) and a 'no preview
available' placeholder
- Aligned CornerDownRight icon with parent row chevron and version text
with parent name text (both use gap-x-2 and size-14 icons)
- Added expand/collapse all toggle button in the table header top right
(ChevronsUpDown / ChevronsDownUp icons)
- Restore and delete actions on version rows now perform real client-side
effects: version-level mock store mutations + query cache invalidation
- Removed the Expires column from both DeletedFilesList and TrashList
- Extended DeletedFilesContext with selectedDeletedVersion state
- Added version-level mutation functions to protection-mocks.ts
- Added useTrashVersionRestoreMutation and useTrashVersionDeleteMutation
hooks to bucket-trash-query.ts
- Updated Trash page (standalone) with version-level mutation wiring
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- PreviewPane: add Info hint below Delete button when versioning is
active, explaining that deleting soft-deletes the object and all
versions and they can be restored from the deleted versions view
- VersionHistory: add Get URL (Copy) icon button on every version row
alongside existing Download/Restore/Delete actions
- DeletedFilesList & TrashList: implement collapsible nested grouping
for noncurrent versions under parent objects with ChevronRight/Down
expand toggle, version count badge, and per-version Restore/Delete
actions on hover
- protection-mocks: expand mock data from 8 to 12 trash objects with
richer version histories (up to 6 noncurrent versions per object)
to properly showcase the nested deleted versions UI
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Task A: Add ExpirationMode (and/or) toggle between retention-days and
max-versions fields in bucket settings. 'and' = single S3 lifecycle policy
(both conditions must be met), 'or' = two independent rules (either triggers).
Wired into form schema, create/edit bucket modals, and mock store.
Task B: Move 'Show deleted versions' toggle from breadcrumb bar into the
file explorer table header, right of the search input. Switch is on the left
of the label text.
Task C: Add noncurrent version rows beneath each deleted object in TrashList.
Nested rows have left indentation with a CornerDownRight icon and lighter
background. Added DeletedObjectVersion interface and mock data to
protection-mocks.ts. Updated all user-facing terminology from 'files' to
'versions' across Trash, TrashList, TrashSelectionBar, DeletedFilesList,
DeletedFilesHeaderSelection, DeletedFilePreviewPane, and bucket page tabs.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Reverted the timeline row's Restore action back to its icon-only
text-variant button — the ask to make Restore a default-variant
button was about the "Back to latest" action in the version
preview banner, not the per-row action in the Versions tab
- The version preview banner's action is now labeled Restore, styled
as a default-variant button, and actually restores the previewed
version as current (instead of just clearing the preview)
- Versioning can no longer be turned fully "off" on a bucket that's
ever had it enabled — it moves to a new suspended state instead,
matching how bucket versioning actually behaves. Suspending only
stops new noncurrent versions from being created; nothing already
retained is deleted, so the destructive typed-confirmation flow for
disabling versioning is gone
- Added `hasVersioningHistory` (enabled OR suspended) alongside the
existing `isBucketVersioned` (enabled only) and repointed every
surface that manages or warns about retained version/trash data to
the former, since a suspended bucket can still be sitting on plenty
of it
- Bucket list "Versioning" column, plan-downgrade admonition, and the
Versions tab now all reflect the three states (Enabled / Suspended /
never enabled)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Versions tab in file preview now only shows when the current bucket
has object versioning enabled, instead of the global feature flag
- Renamed the current-version badge from Latest to Current
- Previewing-version banner now puts the version date on its own line
- Restore action is now a labeled default-variant button instead of
an icon-only text button
- Hover-underline moved from the timeline dot to the version date, and
the currently-previewed version is now highlighted by coloring its
date text and dot to match the brand color
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Usage breakdown & chart:
- Split "Object versions" into "Noncurrent versions" and "Soft-deleted files"
in the Storage Size breakdown, in the mock data model, and in the chart's
stacked bars.
- Wire the mock retention series into the Storage Size chart itself so the
daily bars actually visualize the live / noncurrent / soft-deleted split,
not just the inline breakdown.
Edge cases:
- Tightening retention (fewer days or fewer versions than the bucket already
has) shows an inline admonition in the edit modal explaining that some
retained data will be permanently expired on save.
- EmptyBucketModal: when the bucket is versioned, the destructive banner
copy and an extra warning admonition call out that emptying also purges
every noncurrent version and soft-deleted file.
- DeleteBucketModal: appends a note that all versions and soft-deleted files
will be lost, when the bucket is versioned.
- Plan downgrade auto-disable-and-purge: on the buckets list, an effect
detects when the org plan no longer supports versioning and invokes a new
purgeVersioningOnPlanDowngrade() helper that flips every enabled bucket in
the mock store back to disabled and clears the shared trash store, then
shows a warning admonition listing the affected buckets.
- Public bucket + versioning: inline admonition in the modal explains that
public buckets expose every version by default and points to an RLS-based
mitigation (filter storage.objects by an isCurrent metadata flag).
Version cap indicator:
- In VersionHistory, show a `{count} / {cap} noncurrent` badge when a cap is
configured, with contextual copy at ≥80% and at cap explaining that older
versions auto-expire on the next overwrite.
Copy:
- Reword "Noncurrent version retention" and "Max noncurrent versions"
descriptions to be concise/factual instead of using "this many" phrasing.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Disabling object versioning on a bucket that already has it enabled now
requires typing the bucket name in a destructive TextConfirmModal,
warning that every noncurrent version and soft-deleted file will be
permanently deleted once saved. New buckets (never had versioning) skip
this since there's nothing to lose. An inline Admonition also reflects
the staged, not-yet-saved change in the form.
- Resume a (snapshot-free, adapted for this branch's object-level-only
scope) version of the org Usage page's Storage Size breakdown: a
Live objects vs Object versions split, a "retained recovery data"
warning, and a per-bucket breakdown of retained bytes. Backed by a new
mock retention-usage query (data/storage/protection/storage-retention-usage-query.ts),
rendered via the Storage Size category's additionalInfo slot in
/org/[slug]/usage.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Prefill "Noncurrent version retention" and "Max noncurrent versions"
with the plan's default values when the Object versioning switch is
turned on (only if the fields are still empty), so users can save
immediately instead of starting from a blank input.
- In the deleted files view, render the preview panel as an absolutely
positioned overlay over the rows instead of a flex sibling that
shrinks the table. Rows keep their full width and stay horizontally
scrollable underneath the panel.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Show an "Enabled" badge instead of "object-level" text under the
buckets list "Versioning" column, since only object-level versioning
exists in this scope.
- Tighten vertical padding on deleted files table rows (px-4 py-2
instead of the default p-4).
- Only show the "Show deleted files" toggle for buckets with versioning
enabled; move the Switch to the right of its label.
- Move isShowingDeleted from local useState to a nuqs query param
(?deletedFiles=true) so the deleted files view is linkable/bookmarkable.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Fix "Cannot read properties of undefined (reading 'content')" crash:
the snapshot-removal pass dropped the required `tooltip` prop from two
ButtonTooltip calls (TrashList's per-row delete, Trash's "Delete all
permanently"). Swap both to plain Button since no dynamic tooltip is
needed there.
- Rework DeletedFilesList (the "Show deleted files" switch view, now
the default buckets page) from stacked card rows into a proper single-line
Table matching the Files/Deleted files tab's TrashList row styling and
column headers (Object, Original location, Deleted, Size, Expires).
- Add per-row Restore/Delete permanently actions that only reveal on row
hover, alongside the existing multiselect checkbox and click-to-preview
behavior.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Snapshots aren't implemented in this branch yet, so drop the
heldBySnapshot field from TrashObject/ObjectVersion mocks and all
related UI: disabled states, tooltips, badges, and copy across the
deleted files list/preview, version history, and bulk trash actions.
Delete-all/permanent-delete mutations now act on every selected/listed
item unconditionally.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Bucket versioning: create/edit bucket modals now write to an in-memory
mock store (setMockBucketProtection) on save, so the buckets list
"Versioning" column reflects the change immediately. Resets on page
refresh since it's plain module state (no real API yet).
- Deleted files: restore/permanent-delete mutations now actually mutate
the trash mock store instead of no-op delaying, so the deleted files
list updates after restoring or hard-deleting items.
- Added 5 more dummy trash entries (8 total) with varied held/expiry
states.
- Changed all "Delete permanently"/"Delete all permanently" trigger
buttons to the `danger` Button variant.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Reduce per-item bottom padding from pb-8 to pb-4
- Remove the hover/selected background on each version row entirely;
instead underline the timeline dot on hover to signal interactivity
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Move min/max/required validation for version_expiry_days and
max_noncurrent_versions into a shared superRefine (BucketDataProtectionFields.schema.ts),
called from each modal's own superRefine, instead of imperative
validateVersioningFields() + form.setError() calls in onSubmit. Errors
now surface the same way as the rest of the form (FormItemLayout/FormMessage),
matching Studio's established form-error convention.
- Switch the fields to the '' empty-sentinel + z.coerce.number() union
pattern (per the react-hook-form skill) instead of z.string().optional(),
keeping inputs fully controlled without special-casing undefined.
- Build each modal's schema dynamically via useMemo(() => schema(planLimits), ...)
since the versioning bounds depend on the async-loaded org plan.
- Replace destructured useFormContext().watch() with useWatch({ control, name })
in BucketDataProtectionFields, avoiding the ratcheted no-use-watch lint warning.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
The bucket page at /storage/files/buckets/[bucketId] now shows the
"Show deleted files" switch experience (previously only at bucketsV2).
The Files/Deleted files tabbed view moves to /storage/files/bucketsV2
instead. Route files are untouched since they import by page path, not
by component name.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Move versioning fields (retention days, max noncurrent versions) from
local useState into the parent form via react-hook-form + zod, fixing
the bug where clearing an input forced it back to "0" and blocked
typing a fresh single digit
- Show a validation error on submit if versioning is enabled but a
field is left empty
- Gate object versioning by org billing plan: disable the toggle and
show an upgrade prompt on the Free plan (which also doesn't support
lifecycle policy management); enforce plan-specific min/max ranges
for retention days and max versions on Pro/Team/Enterprise
- Add getVersioningPlanLimits() + validateVersioningFields() helpers
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Shows "object-level" for buckets with versioning enabled, "-" otherwise,
based on the existing isBucketVersioned() mock helper. Snapshots-level
versioning will be added in a future iteration.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Deleted files batch actions:
- Move Restore/Delete permanently buttons into the StorageExplorer header
row (same position as the normal file selection bar)
- Show "X items selected" text on the far left, actions on the far right
- Update select-all row to show "Select/Unselect all X files" label
Bucket versioning fields:
- Use FormItemLayout with flex-row-reverse layout for retention and max
versions fields (label left, input right)
- Use InputGroup with InputGroupAddon for unit suffixes ("days", "versions")
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Reduce vertical gap between detail fields from space-y-6 to space-y-3
- Make Restore/Delete permanently actions sticky at the bottom with a
border-t separator, only the preview + details area scrolls
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
- Move "Show deleted files" toggle from StorageExplorer header to
page-level breadcrumbs as a Switch control, left of Policies button
- Add checkbox multiselect for deleted files with bulk Restore/Delete
permanently actions and shift-click range selection
- Keep search input visible when showing deleted files, with contextual
placeholder text
- Add file preview thumbnail to deleted file preview pane
- Change "Delete permanently" button to default variant (matching Restore)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Add an alternative bucket view at /storage/files/bucketsV2/[bucketId]
that replaces the separate Files/Deleted files tabs with a unified
StorageExplorer. A "Deleted files" toggle button in the header's
actions bar (left of Navigate) switches between live files and
soft-deleted items inline.
When showing deleted files:
- The file listing is replaced with a DeletedFilesList showing all
soft-deleted objects with name, size, deletion time, and origin
- Clicking a deleted item opens a dedicated DeletedFilePreviewPane
with Original location, Deleted at, Deleted by, Size, Expires,
and Restore / Delete permanently actions
- Upload, search, view options, and folder creation are hidden
The existing bucket page is unchanged (wrapped in DeletedFilesProvider
with enabled=false). The bucketsV2 route is navigable only via URL.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
Scoped-down storage protection prototype with three features:
- Bucket-level versioning policy (retention days, max versions) in create/edit modals
- Object version history in the file preview pane with restore/delete actions
- Per-bucket deleted files (trash) view with bulk selection, restore, and permanent delete
All data is mock-backed behind the STORAGE_PROTECTION_ENABLED feature flag.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TiUEvmC84bRsteqsWXHY2p
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Adds a cross-link from the Database overview's "Next steps" section to
the Deployment & Branching guide, so readers who land on Database
looking for Branching docs can find them without guessing at top-level
nav.
Closes DOCS-1263.
## What is the current behavior?
- Linear item:
[DOCS-1263](https://linear.app/supabase/issue/DOCS-1263/add-deployment-and-branching-cross-link-on-database-overview-next)
- User feedback: someone looking for Branching docs expected them under
Products → Database. The canonical docs live under Build → Deployment &
Branching (`/guides/deployment`, with Branching at
`/guides/deployment/branching`). That placement stays correct (it's a
preview/deploy workflow, not a Database product guide) — the miss is
that Database overview's "Next steps" grid has no link out to it.
## What is the new behavior?
- Added a "Deployment & Branching" card to `databaseNextSteps` in
`apps/docs/data/content-listings/database.data.ts`, linking to
`/guides/deployment` (the Deployment & Branching hub, not a
Branching-only link)
- No nav changes, no URL redirects, no Features sidebar work
## Additional context
- Worktree:
`~/GitHub/supabase/supabase-worktrees/nrichers/docs-1263-add-deployment-branching-cross-link-on-database-overview`
- Change is a single data-file addition (`databaseNextSteps` array),
rendered on `/guides/database/overview` via `<ContentListings
id="database-next-steps" />`
- Verification: reviewed diff for correct schema shape (matches existing
`ContentListingGroup` items, e.g. the existing cross-product `Backups` →
`/guides/platform/backups` entry)
### Proof: Database overview "Next steps" now links out to Deployment &
Branching
**Verified:** docs preview deploy (pass) · both URLs return `200` · new
card renders next to "Roles and permissions" and links to
`/guides/deployment`
### Before & After
| [Before
(production)](https://supabase.com/docs/guides/database/overview) |
[After (PR
preview)](https://docs-git-nikrichers-docs-1263-add-deployment-br-fd2915-supabase.vercel.app/docs/guides/database/overview)
|
|
-------------------------------------------------------------------------------------------------------------------------------------------------------
|
-----------------------------------------------------------------------------------------------------------------------------------------------------
|
|

|

|
- **Before:** https://supabase.com/docs/guides/database/overview
- **After:**
https://docs-git-nikrichers-docs-1263-add-deployment-br-fd2915-supabase.vercel.app/docs/guides/database/overview
### Test plan
- [x] Visit `/guides/database/overview` on the PR preview and confirm
the "Next steps" grid shows a **Deployment & Branching** card
- [x] Confirm the card links to `/guides/deployment` (not
`/guides/deployment/branching`)
- [x] Confirm no other Next steps cards, nav items, or redirects changed
Co-authored-by: Nik Richers <nik@validmind.ai>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs fix/update
## What is the current behavior?
Shows pricing information that is not accurate/approved yet
## What is the new behavior?
helpful docs, which indicate pricing may be relevant and the future and
already directs users to help management tools
## Additional context
NA
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated Logs pricing and quota guidance to clarify that details may
change before billing enforcement begins.
* Replaced preliminary pricing tables and billing examples with notices
that finalized information will be published later.
* Expanded usage optimization guidance for log ingestion and querying,
including filtering, time ranges, polling, and database logging
recommendations.
* Directed readers to per-SKU pages for the latest pricing, quotas,
billing, and optimization information.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
This is a docs-only content update to the `/docs/guides/security`
landing page and its neighboring guides. It adds a dedicated GDPR
compliance guide, and surfaces ISO 27001 and DDoS protection coverage
that Supabase already provides but wasn't listed anywhere in the docs
security guide.
Closes DOCS-354.
## What is the current behavior?
- In `/docs/guides/security`, there is no mention of GDPR, ISO 27001 or
DPA request potential, despite Supabase docs covering these partially in
one place or another.
- Confirmed by auditing `apps/docs/content/`: zero mentions of GDPR/data
residency, zero DPA content or link to `/legal/dpa`, zero ISO 27001
mentions, and only incidental/wrong-audience mentions of DDoS protection
(a pen-testing exclusion, a Storage CDN aside, a fail2ban
troubleshooting article for banned users).
- `regions.mdx` only frames region choice as a performance decision,
with no data-residency/compliance angle.
- This is a parallel docs-side counterpart to #48403 (marketing
`/security` page content additions), which is adding the same GDPR/Data
Residency/DPA/DDoS topics on `apps/www`. This PR does not modify
`apps/www` — see that PR for the marketing-page changes.
## What is the new behavior?
- New guide: `apps/docs/content/guides/security/gdpr-compliance.mdx`
covering data residency (including the nuance that the "Europe" general
region grouping includes non-EU jurisdictions UK and Switzerland) and
the Data Processing Agreement (DPA), linked to `/legal/dpa`.
- Added to the sidebar nav under Security → Compliance, alongside SOC 2
and HIPAA.
- `apps/docs/content/guides/security.mdx`: added an ISO 27001 paragraph
(dashboard certificate link, matching the existing SOC 2/HIPAA pattern)
and a GDPR pointer paragraph to `## Compliance`; added a DDoS protection
paragraph (Cloudflare CDN + fail2ban) to `## Platform configuration`.
- `apps/docs/content/guides/platform/regions.mdx`: added a "Data
residency" section clarifying that general region groupings may span
non-matching jurisdictions, and specific regions should be used when
strict jurisdictional residency is required.
## Additional context
- Worktree:
`~/GitHub/supabase/supabase-worktrees/nikrichers/docs-354-security-landing-page`
- Note: Supabase's subprocessor list was considered for the GDPR guide
but omitted — both candidate links
(`/legal/customer-resources/subprocessor-list` and
`/legal/privacy#subprocessors`) are not yet publishable/live. Follow up
once Legal publishes that page.
**Verification:**
| Check | Result |
| ------------------------------------ |
-----------------------------------------------------------------------------------------------------
|
| `pnpm lint:mdx` on changed/new files | Pass (0 errors, 0 warnings on
touched files) |
| `pnpm build:guides-markdown` | Fails on `master` too (unrelated
missing `ai-skills.json` generated file) — not caused by this change |
| Local render (`pnpm dev:docs`) | All three pages return 200; new copy,
nav entry, and all links/anchors verified to resolve |
### Proof:
Reviewers should believe: the security landing page and regions guide
now list GDPR/ISO 27001/DDoS coverage that was previously missing, and
the new GDPR guide renders correctly with working links, where before it
404'd.
### Before & After
**`/docs/guides/security`** — ISO 27001, GDPR, and DDoS paragraphs now
present:
| [Before (production)](https://supabase.com/docs/guides/security) |
[After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security)
|
|
-----------------------------------------------------------------------------------------------------------------------------------------------------
|
---------------------------------------------------------------------------------------------------------------------------------------------------
|
|

|

|
**`/docs/guides/platform/regions`** — new "Data residency" section:
| [Before
(production)](https://supabase.com/docs/guides/platform/regions) |
[After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/platform/regions)
|
|
---------------------------------------------------------------------------------------------------------------------------------------------------
|
-------------------------------------------------------------------------------------------------------------------------------------------------
|
|

|

|
**`/docs/guides/security/gdpr-compliance`** — net-new page, no
production URL exists yet (404 before this PR):
| Before (production) | [After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security/gdpr-compliance)
|
| ------------------- |
-------------------------------------------------------------------------------------------------------------------------------------------
|
| |

|
### Test plan
```text
- [ ] Visit /docs/guides/security — confirm ISO 27001, GDPR, and DDoS paragraphs render under the right headings
- [ ] Visit /docs/guides/security/gdpr-compliance — confirm it renders and appears in the sidebar under Compliance (next to SOC 2, HIPAA)
- [ ] Visit /docs/guides/platform/regions — confirm the new "Data residency" section renders before "General regions"
- [ ] Confirm links resolve: /docs/guides/security/gdpr-compliance, /docs/guides/platform/regions#specific-regions, /legal/dpa, /dashboard/org/_/documents
```
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Documentation
- Added a GDPR Compliance entry to the Compliance navigation.
- Updated security documentation with ISO 27001 certification details,
clearer GDPR guidance, and expanded protection information.
- Clarified regional data residency guidance, including primary project
data and GDPR considerations.
- Made minor wording and formatting improvements to the GDPR compliance
guide.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Nik Richers <nik@validmind.ai>
## Context
As per PR title - should not have any visual nor functional change
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Changes**
- Standardized infrastructure, region, and database configuration around
AWS-based environments.
- Removed Fly.io-specific region and provider options from project
creation, instance sizing, and infrastructure settings.
- Enabled disk validation, spend-cap eligibility, backup restoration,
and extension setup consistently across supported projects.
- Updated billing and region displays to use the applicable AWS
configuration.
- **Bug Fixes**
- Corrected project-specific restrictions that could incorrectly hide
configuration and billing controls.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Context
Adds a banner toast for the database connections feature preview
<img width="315" height="322" alt="image"
src="https://github.com/user-attachments/assets/8caaab88-10a0-4a06-b678-25fc9c44dd81"
/>
## Other changes
As the observability page currently has a number of banner toasts
(metrics API, unified logs, index advisor for query performance), am
opting to REMOVE the metrics API's banner toast by virtue of how long
its been around for. Mainly to prevent over stacking of banner toasts as
it can be annoying.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added a dismissible Database Connections banner with SQL examples and
a link to its feature preview.
* Banner dismissal and CTA interactions are now tracked.
* Dismissed banners can reappear when reintroduced.
* **Bug Fixes**
* Banners are hidden after the feature is enabled or dismissed.
* Improved banner handling to prevent duplicate active banners.
* **Changes**
* Replaced the Metrics API banner with the Database Connections banner.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Added C# examples across API, authentication, database, Realtime, and
Storage guides.
* Expanded authentication coverage for passwordless, phone, anonymous,
identity linking, SSO, sign-out, and social login providers.
* Added database examples for queries, functions, joins, JSON, arrays,
search, PostGIS, and custom schemas.
* Added Realtime examples for broadcasts, presence, subscriptions, and
database changes.
* Added Storage examples for buckets, uploads, downloads,
transformations, CDN purging, and resumable transfers.
* Included C# error-handling guidance and relevant reference links.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs update.
Getting Started page is the most visited page in the docs at the moment:
https://supabase.com/docs/guides/getting-started.
Looking at all 19 guides, they appear to have drifted apart because
there was never a written standard for what a quickstart must contain.
Additionally, we are missing some frameworks, languages, and ORMs
quickstarts.
Phase 1 (this PR) fixes broken numbering, duplicated steps, and dead-end
pages. Later phases bring all 19 guides into line with a single
"definition of done" contract (error handling in samples, env vars
everywhere, consistent Connect-panel pattern). The end goal is that
every quickstart, regardless of framework, gives the same complete,
trustworthy path from zero to a working app.
## What is the new behavior?
1. SvelteKit and Hono cards added to the [homepage
grid](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs)
(FrameworkQuickstarts.tsx). Only added the most popular missing
frameworks to the grid.
2.
[Rails](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#2-install-agent-skills-optional):
Add missing second step (Agent Skills), add next steps at the end (point
6)
3.
[Laravel](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#6-set-up-the-postgres-connection-details):
Remove duplicated instruction to create project from step 6.
4.
[Refine](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/refine#5-update-supabaseclient-with-environment-variables):
In step 5, create .env file (VITE_SUPABASE_URL,
VITE_SUPABASE_PUBLISHABLE_KEY), and the client reads them via
import.meta.env, matching the Vite-based refine-supabase preset.
5.
[Hono](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/hono#6-set-up-the-required-environment-variables)
TODO resolved: In step 6, add the "Open Connect panel" Button with the
generic api_settings.mdx partial call, identical to the Flask and Expo
pattern.
6. Next steps added to the 9 guides missing it at the end of the guide,
linking to the framework tutorial or Auth, UI components, data import,
and Storage (Flutter, Kotlin, Laravel, Nuxt, RedwoodJS, Refine, Ruby on
Rails, SolidJS, and Vue).
7. Remove 4 stale screenshots from RedwoodJS and Refine, along with
their now-orphaned image assets under apps/docs/public/img/. The
surrounding text already covers what they showed; they weren't
Connect-panel screens, so the Button pattern didn't apply as a
replacement.
8. Add [Supabase Agent
Skills](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#4-install-agent-skills-optional)
purpose and benefits for the user
9. Start all guides from creating Supabase project
## Additional context
Add any other context or screenshots.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
## Documentation
- Added SvelteKit and Hono quickstarts with icons and documentation
links.
- Expanded Agent Skills guidance across framework quickstarts, including
current authentication, SSR, and migration patterns.
- Improved project creation, Connect panel, API configuration, and
credential setup instructions.
- Added framework-specific “Next steps” resources for Auth, database
imports, Storage, UI components, and libraries.
- Clarified PostgreSQL SSL, password encoding, connection, and
environment-variable requirements.
- Replaced outdated screenshots with clearer setup guidance and relevant
examples.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Context
Given that our number of feature previews have been expanding, am opting
to group them into categories for easier understanding of the context of
each feature preview.
Ideally we're able to tag all feature previews into categories (or add
more categories), but leaving the unclassified ones under "others" for
now
<img width="936" height="661" alt="image"
src="https://github.com/user-attachments/assets/b48bd9a2-fe33-4cb0-9288-1cd9c8264da0"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Feature previews are now organized into expandable categories.
* Observability and database previews are grouped for easier browsing.
* Uncategorized previews remain available under an “Others” section.
* Existing feature selection options and sorting behavior are preserved.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## What kind of change does this PR introduce?
Bug fix stacked on #48478.
## What is the current behavior?
Storage Explorer renders the custom closed-folder icon at `1.5` but
leaves the Lucide open-folder icon at its default `2`. The duplicated
file-picker implementation also uses a different set of stroke-width
overrides.
## What is the new behavior?
A shared `StorageRowIcon` renders loading, open and closed folder,
image, audio, video and generic file icons at `1.5` across Storage
Explorer, row editing and the bucket file picker.
Test by comparing open and closed folders and file-type rows in Storage
Explorer and the bucket file picker.
| Before | After |
| --- | --- |
| <img width="524" height="336" alt="CleanShot 2026-08-03 at 18 38
06@2x"
src="https://github.com/user-attachments/assets/15eb8b9f-69fc-4eee-8428-d7ec26dce8dc"
/> | <img width="522" height="328" alt="CleanShot 2026-08-03 at 18 39
20@2x"
src="https://github.com/user-attachments/assets/17b7dddd-8d36-421c-8356-c9c1bd7456e8"
/> |
| _Thicker image and file icon compared to folder icon_ | _Every icon
has the same stroke thickness_ |
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Improvements**
* Standardized file, folder, media, and loading icons across storage
views.
* Improved visual consistency with unified icon sizing, styling, and
stroke width.
* **Tests**
* Added coverage for loading, folder, media, and generic file icon
states.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Context
As per PR title - brings Database Connections into feature preview
Should be working for both hosted + self-host/local
Also adjusts existing feature previews to remove "New"
- Platform webhooks
- Temporary database access
<img width="600" alt="image"
src="https://github.com/user-attachments/assets/b18ae8ca-ce0b-4649-975c-e70749a87dcd"
/>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added a Database Connections preview highlighting live activity, query
blocking detection, session termination, and AI-assisted summaries.
* Added access to project-specific observability connections from the
preview.
* Added a Database Connections entry to the observability menu when
enabled.
* **Improvements**
* Updated feature previews and labels, including changes to “new” status
indicators.
* Added controls to manage Database Connections preview visibility.
* **Bug Fixes**
* Improved blocker detection so results respect the selected role
filters.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->