mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
f012dfa850f032cd9fffc81dd031a22b75784397
38441
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
f012dfa850 |
fix(www): sitemap lists all changelog slugs (#50275)
The www sitemap generator reads changelog URLs from the build-generated RSS feed but only accepted links whose slug starts with a number, the shape `computeChangelogEntrySlug` produces solely for entries carrying `legacy_gh_discussion`. Every changelog entry authored since that migration has a plain text slug and was silently missing from `sitemap_www.xml`. I widened the link match to any non-empty slug; the RSS builder is the only producer of that file and emits exactly one link per item, so no other filter is needed. I added a text-slug RSS item to the fixture-driven sitemap test and asserted that the changelog URL list equals the RSS item list, so a future filter that drops entries fails the suite. **Note:** text-slug entries now pass through the same fail-the-build pubDate check that numeric-prefixed entries already did after #50198. A changelog entry with no `publish_date` and no date-prefixed filename would produce an unparseable pubDate and stop the www build. The alternative, shipping the URL without lastmod, is a one-line change. I kept the gate because every current changelog entry carries a date-prefixed filename, the changelog repo documents that convention, and the build error names the entry URL. ## To test Tested on Vercel preview: - [x] Count `<item>` blocks in `<preview>/changelog-rss.xml`, then count `/changelog/` locs in `<preview>/sitemap_www.xml`, expect the two counts to match - [x] Search the preview sitemap for `/changelog/pipelines`, expect one `<loc>` entry with a `<lastmod>` date - [x] Search the preview sitemap for a numeric-prefixed entry such as `/changelog/47796-developer-update-july-2026`, expect it still present ## Linear - fixes GROWTH-1212 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Changelog pages with text-based slugs are now correctly recognized in the sitemap. - Sitemap entries for these changelog pages now use their RSS publication dates. - RSS links are matched more reliably, ensuring all valid changelog URLs are included. - Invalid publication dates are rejected instead of producing incorrect sitemap metadata. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ea203f70df |
fix(studio): use configured gp3 max-IOPS ceiling (#50269)
## Summary * GP3 IOPS calculation was hardcoded to 16,000 instead of reading from DISK_LIMITS config * AWS updated the real ceiling to 80,000, making the hardcoded constant stale * Users with large multi-TB GP3 disks were incorrectly blocked from provisioning above 16,000 IOPS ## Test plan - [X] Updated unit tests for `calculateMaxIopsAllowedForDiskSizeWithGp3` now assert correct behavior: scaling linearly (100 GB → 50,000 IOPS) and capping at new 80,000 ceiling (1000 GB → 80,000 IOPS) - [X] All 26 tests in DiskManagement.test.ts pass locally - [X] Manually verify Infrastructure Settings > Disk IOPS field no longer blocks GP3 disks above 16,000 IOPS up to 80,000 Closes [FE-4379](https://linear.app/supabase/issue/FE-4379/update-iops-limits-for-new-aws-disk-capacity) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Updated GP3 disk performance calculations to support up to 80,000 IOPS. - Disk sizes below the minimum threshold continue to receive the correct 3,000 IOPS floor. - Larger disks now scale linearly until reaching the updated maximum IOPS limit. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ed4162e055 |
feat(www): add Select Hackathon day-of go page (#50243)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - Adds a new `/go` page for the Select Hackathon (Oct 3, 2026, YC) at `supabase.com/go/select-2026/hackathon` - New page definition `apps/www/_go/events/select-2026/hackathon.tsx` (`lead-gen` template) - Registers it in the go page registry `apps/www/_go/index.tsx` ## What is the current behavior? There is no day-of one-pager for the Select Hackathon on the site. ## What is the new behavior? - A day-of one-pager rendered as a `selecthackathon2026.sql` code-block section (run of show, wifi, how to submit, prizes) - `noIndex` by default (day-of page, not for search) - Removable after Select 2026 (tagged in the registry alongside the other `select-2026` go pages) ## Additional context `hackathon.supabase.com` is handled at DNS/Vercel and can point at this path. wifi network/password and help-desk location are still placeholders pending final details. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a dedicated Supabase Select Hackathon 2026 schedule page. * Includes event timing, Wi‑Fi details, submission instructions, prize information, and mentor support guidance. * Updated the run of show to list sponsor arrival at 9:00 AM and doors opening/check-in at 9:15 AM. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ana <ana1337x@users.noreply.github.com> |
||
|
|
3de0e3a614 |
fix(docs): a11y alt text on Colab badge (#50222)
## What kind of change does this PR introduce? a11y fix ## What is the current behavior? Colab badge image is missing alt attribute leaving both image and the link unnamed _ screen reader users have no way to tell what the link does ## What is the new behavior? - adds `alt="Open in Colab"`, matching the text rendered inside the SVG so voice control users can activate it by its visible label ## Test 1. visit [/docs/guides/ai/google-colab](https://supabase.com/docs/guides/ai/google-colab) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Improved accessibility across AI guides and quickstarts by adding descriptive alternative text to “Open in Colab” badge images. - Updated Google Colab, LlamaIndex, face similarity, hello world, and text deduplication documentation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2e861b5415 |
fix(docs): guides table overflow (#50221)
## What kind of change does this PR introduce? bug fix of table usage within guides ## What is the current behavior? table markup is used within the observability guide causing overflow of the content ## What is the new behavior? favors table component usage within mdx guide to fix the overflow and enable scroll | state | preview | | -------|------| | before | <img width="1171" height="668" alt="image" src="https://github.com/user-attachments/assets/bdbb905e-0ea9-4cde-b20b-84b4ef9a4137" /> | | after | <img width="1171" height="668" alt="image" src="https://github.com/user-attachments/assets/9e062222-1dad-49da-bdbe-616d89703301" /> | ## Test 1. visit [/docs/guides/observability/log-field-reference](https://supabase.com/docs/guides/observability/log-field-reference?queryGroups=source&source=edge_logs) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Improved table rendering in the log field reference documentation. - Updated documentation tables to use the shared table presentation for a more consistent layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c4c5f58eef |
fix: update the Flutter repo links on readme.md (#50266)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This PR updates the link and the text of the Flutter sub-libraries from the archived repo to the new sub-directory inside the monorepo. |
||
|
|
15f80e5f9d |
fix(docs): restore browser crash reporting to sentry (#50231)
## Problem Docs discarded every browser exception because its third-party stack-frame filter never returned a value from its predicate. Errors captured by the page error boundaries were discarded too. ## Fix Use Studio's Sentry SDK tagging approach with a matching webpack application key, retaining page-crashing exceptions even when their frames are classified as third-party. Preserve consent and platform checks, and pass the source-map upload token through Turbo. ## How to test - Run `pnpm --filter docs run test:local:unwatch lib/sentry-client.test.ts` with the documented local Supabase prerequisites satisfied. Eleven filter regression checks passed locally using an isolated Vitest configuration. - On a production-mode preview with the docs DSN configured, accept telemetry consent and trigger a temporary client render error. Verify that the docs Sentry project receives it with `globalErrorBoundary: true` and readable stack traces. - Verify that third-party-only errors are filtered and declining consent suppresses browser reports. Prettier, focused filter/test TypeScript checks, and an in-memory transport check using the real Sentry SDK passed. Full app typecheck and lint are blocked locally by existing dependency/generated-file drift; the standard docs suite requires unavailable Docker access. Live Sentry ingestion and source-map uploads still need deployment verification. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved error monitoring to distinguish documentation app boundary crashes from other exceptions. - Reduced noise in error reports by filtering third-party-only errors and respecting platform and consent settings. - Preserved reporting for first-party failures and critical application crashes. - **Chores** - Improved Sentry build and deployment configuration for more consistent error tracking. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
74daa990bc |
Update humans.txt with new employee (Aditya) (#50212)
Add Aditya Maruvada to humans.txt ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Add new employee (Aditya) to the list. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Aditya Maruvada to the team member list. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e315fbcb53 |
feat(www): emit sitemap lastmod from content dates (#50198)
I added content dates to `sitemap_www.xml` and `dateModified` to blog
JSON-LD so crawlers can compare freshness with page metadata. Both use
`updated` when present, otherwise the publication date.
**Changed:**
- **Consistent dates:** I use the same frontmatter parser for the blog
page and sitemap. It preserves authored dates across quoting and
timezones and rejects JavaScript frontmatter.
- **Invalid dates stop the build:** I reject impossible calendar days,
out-of-range times and offsets, malformed dates, and `updated` before
publication. Content changes run the generator in CI.
- **Authoring:** I documented optional `updated` for substantive
revisions. Events, static pages, and `/evals` omit `<lastmod>`.
**Note:** Changelog dates come from RSS. Existing sitemap omissions for
nonnumeric changelog slugs (GROWTH-1212) and app-router pages
(GROWTH-1214) remain separate.
## To test
On the preview:
- [x] Open `/sitemap_www.xml`: blog, alternatives, customer stories, and
included changelog entries should carry `YYYY-MM-DD` lastmod values.
Verified on the
|
||
|
|
66c6da82fe |
fix(studio): refine Explorer query surfaces and tab styling (#50249)
Explorer query surfaces now use `bg-card` in light mode and `bg-muted` in dark mode, including embedded notebook/chat queries and query tab toolbars. Notebook Run buttons match query tabs, with `ml-1` spacing on both. Fix doubled tab separators by applying the leading border only to the first tab. ### How to test 1. Open Explorer with multiple query, notebook, and chat tabs. Switch, reorder, and close tabs; confirm each separator stays one pixel wide. 2. In light and dark mode, inspect query tabs and embedded notebook/chat queries: backgrounds should be card in light mode and muted in dark mode, including their toolbars. 3. Compare notebook and query Run buttons: matching default styling and spacing. Run a read-only query such as `select 1` in both and check loading and results. 4. Check SQL Editor and Table Editor tab separators, since the tab component is shared. Validation: Prettier passed for all four changed files. Manual checks above have not been run. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Style** - Refined notebook and query run button styling, including spacing and tooltip placement. - Improved query editor panel backgrounds across light and dark themes. - Updated tab border rendering for more consistent visual alignment. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
85573164f4 |
docs: document that branches are secure by default (#50193)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the current behavior? The branching docs don't mention that new branches are created without default privileges on the `public` schema. Linear: BRA-189 ## What is the new behavior? - Working with branches: new "Default privileges on branches" section covering the keep-enabled path (initial migration grants) and the revoke path (new migration). - Troubleshooting: new entry for `42501` permission denied errors on a new branch. ## Additional context None. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added troubleshooting guidance for permission-denied errors affecting tables or functions on new branches. - Explained how migrations can restore intended default privileges on the `public` schema. - Added workflows for retaining or revoking default privileges, including dashboard configuration, migration-history repair, and access-management steps. - Added examples for granting or revoking access to sequences, functions, and tables. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
c6a1c2052c |
feat(www): cross-list openapi and mcp endpoint (#50180)
`/.well-known/ard.json` advertises the Management API OpenAPI spec and the MCP server, but `/llms.txt` listed neither and `/.well-known/api-catalog` listed only the Management API. I added both resources to the two surfaces that were missing them, so an agent finds the same spec and endpoint whichever discovery file it reads first. **Changed:** - **llms.txt gains an `## API and agent resources` section**: two described links, the same-origin `/openapi.json` spec and `https://mcp.supabase.com/mcp`, from a small list in `lib/agent-resources.ts`. A named heading rather than `## Optional`, since llmstxt.org defines Optional as links an agent may skip. The descriptions restate ard.json's on purpose; ard.json is curated to the ARD schema and stays untouched. - **api-catalog lists the MCP endpoint**: added as a catalog `item` plus its own linkset member carrying `service-doc` (the MCP guide) and `service-meta` (the OAuth protected-resource metadata the endpoint's 401 response already points at). - **Tests cover what the two files advertise**: `ard-catalog.test.ts` now parses api-catalog, checks that its `item` list and its anchored members agree, and runs every same-origin URL from api-catalog and the llms.txt resource list through the existing dead-URL resolver (public file, app route, rewrite, or docs guide). The www tests workflow now checks out `apps/docs/content/guides` (the directory the llms.txt route already reads at runtime) and runs on changes to it, so moving a guide that a catalog links to fails that PR rather than the next www one. **Note:** `/openapi.json` is an external rewrite served uncached on every request (338 KB). I tried `Cache-Control` and then the documented `x-vercel-enable-rewrite-caching` + `CDN-Cache-Control` pair on that path; the preview kept returning `x-vercel-cache: MISS`, so both are reverted. Caching the alias is a separate change. ## To test Tested on Vercel preview: - [x] `curl -s <preview>/llms.txt | tail -5`: expect an `## API and agent resources` heading followed by the OpenAPI spec link and the MCP server link; the diff against production `llms.txt` is those appended lines only - [x] `curl -s <preview>/.well-known/api-catalog | jq '.linkset[2]'`: expect a member anchored at `https://mcp.supabase.com/mcp` with `service-doc` and `service-meta`, served as `application/linkset+json` ## Linear - fixes GROWTH-1207 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added API and agent resource links to `llms.txt`, including the Management API specification and MCP server. - Added the Supabase MCP server to the API catalog with service documentation and metadata links. - **Tests** - Expanded catalog validation to cover API catalog entries, agent resources, and documentation guide links. - Updated pull request checks to run when guide content changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4f10a55983 |
docs: add troubleshooting guide for password auth failures after rotation (#50122)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update (new troubleshooting entry + cross-links). ## What is the current behavior? There's no public troubleshooting entry for a transient `password authentication failed` (`28P01`) error through the Shared Pooler (Supavisor) right after a database password rotation. The closest existing entry only covers the IP-lockout circuit-breaker case (`FATAL: Circuit breaker open`), and the generic FAQ answer for "FATAL: Password authentication failed" in `connecting-to-postgres.mdx` reads as "your credentials are simply wrong," with no mention that this is expected right after a legitimate rotation. ## What is the new behavior? - New entry: `supavisor-error-password-authentication-failed-after-password-rotation.mdx` — explains this is expected, by-design pooler-cache behavior (not a bug), scopes it to SCRAM/password auth (not JIT), and walks through confirming the new password via a direct connection before contacting support. - Cross-links added from the existing circuit-breaker entry, the "How do I reset my Supabase database password?" entry, and the FAQ in `connecting-to-postgres.mdx`. ## Additional context Prettier check passes on all 4 touched files. `lint:mdx` (`supa-mdx-lint`) could not be run locally due to a pre-existing, unrelated native-module issue (`node-pty` missing its compiled binary for this platform) — expected to run in CI. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Added troubleshooting guidance for `28P01` password authentication failures after database password rotation. * Clarified Shared Pooler credential-refresh behavior, affected connection patterns, the built-in `postgres` role, and unaffected JIT access-token connections. * Added steps to verify credentials, retry connections, handle rate limits, and avoid repeated rotations. * Added guidance for updating credentials across live application instances and cross-references between related troubleshooting guides. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Changed docs * the new guide: [docs-git-docs-supavisor-password-rotation-troub-026280-supab/…/supavisor-error-password-authentication-failed-after-password-rotation](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/supavisor-error-password-authentication-failed-after-password-rotation) * mention the new guide + info on auth_error Circuit Breaker [docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/…/fatal-password-authentication-failed](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/fatal-password-authentication-failed) * mention the new guide: [docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/…/how-do-i-reset-my-supabase-database-password…](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/how-do-i-reset-my-supabase-database-password-oTs5sB) * mention of the new guide: [docs-git-docs-supavisor-password-rotation-troub-026280-supabase.ver/…/supavisor-error-circuit-breaker-open-after-password-rotation…](https://docs-git-docs-supavisor-password-rotation-troub-026280-supabase.vercel.app/docs/guides/troubleshooting/supavisor-error-circuit-breaker-open-after-password-rotation-0fdb72) --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Nik Richers <nrichers@gmail.com> Co-authored-by: felipe stival <14948182+v0idpwn@users.noreply.github.com> Co-authored-by: Codesmith <codesmith-bot@users.noreply.github.com> |
||
|
|
2bd67ef91b |
Chore/team members rendering optimizations (#50255)
## Context Follow up to https://github.com/supabase/supabase/pull/50238 which addressed some rendering issues for organization team settings. The changes in 50238 improved the performance of searching members, but there's still a bit of client side latency. There shouldn't be any functional changes from the changes here, just refactoring - `MemberRow` wrapped in `memo` so unaffected rows skip re-rendering - Memoized a number of variables in `MembersView` so they only recompute when filtered members/user/role actually change, not on every render - In `MemberRow`, replaced per-role `.find()` chains with Map-based lookups and memoized the whole per-role derivation - Fixed a mutating in-place `.sort()` in `organization-roles-query.ts`'s select that was silently rewriting the shared RQ cache entry - Added `TeamSettingsDataContext` + reduce prop drilling for `MemberRow` + `MemberActions` - Removed an any cast on member.metadata?.origin in MemberRow, replaced with explicit Boolean(...) coercion Organization team settings page should work as per status quo including searching. The searching was the main issue so these are hoping to alleviate the performance issues. It's quite hard to test unless you've got an organization with a 150 + members though (< 100 you don't really see any issues). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Improvements** - Improved the Team Settings member list for more consistent role and project information. - Member role links now provide more direct navigation to associated projects. - Improved performance when displaying and sorting team members. - Added an accessible label to the member actions menu. - **Bug Fixes** - Prevented organization role data from being unexpectedly changed while it is sorted. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
476d4a5851 |
refactor(ui): drop redundant Button variant="default" props (#50161)
## What kind of change does this PR introduce? Mechanical cleanup on top of the Button default-variant change (#50160). ## What is the current behavior? Many callsites still pass `variant="default"` even though that is now the component default. ## What is the new behavior? Removes redundant static `variant="default"` from legacy `Button` and `ButtonTooltip` callsites. Keeps explicit defaults where they document the API: - `button-default.tsx` and `button-sizes.tsx` demos - `DocsButton`, which pins neutral styling at the wrapper boundary ## To test Studio: - [Auth → Rate Limits](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/auth/rate-limits): dirty the form so Cancel appears; Cancel stays neutral, Save stays green - [Project Settings → API Keys](https://studio-staging-2s957kwc4-supabase.vercel.app/dashboard/project/_/settings/api-keys): `DocsButton` in the header actions stays neutral Design system: - [Design system → Button](https://design-system-git-dnywh-dc924ac1-supabase.vercel.app/design-system/docs/components/button): `button-default` / `button-sizes` still show explicit default styling; Primary (green) is restricted to the Primary section (and `asChild`) WWW: - [www → Brand assets](https://zone-www-dot-com-git-dnywh-dc924ac1-supabase.vercel.app/brand-assets): Download logo kit / Download button kit stay neutral |
||
|
|
82d7d347c4 |
fix(studio): eliminate per-row query duplication on org team page (#50238)
## Summary * Fixes extreme slowness (browser-crashing on filter) on `/org/[slug]/team` for orgs with 200+ members. * Root cause: `MemberRow`/`MemberActions` each independently subscribed to org-wide React Query data (roles, projects, permissions, feature flags) and rendered a hidden `UpdateRolesPanel` per row. Filtering caused hundreds of duplicate query observers to mount/unmount on every keystroke, each scheduling its own stale-timeout bookkeeping and blocking the main thread for multiple seconds. * Hoisted all org-wide data fetching (`useOrganizationRolesV2Query`, `useOrgProjectsInfiniteQuery`, `usePermissionsQuery`, `useSelectedOrganizationQuery`, `useIsFeatureEnabled`) to `MembersView` and passed the results down as props. * Replaced the per-row `useAsyncCheckPermissions` hook calls in `MemberActions` with the underlying pure `doPermissionsCheck` function memoized locally, removing their internal query subscriptions. * Simplified `useGetRolesManagementPermissions` to stop calling a query-fetching fallback hook that was unreachable given all current call sites already pass `permissions`/`orgSlug` directly. * Replaced 200 hidden per-row `UpdateRolesPanel` instances with a single shared instance owned by `MembersView`, opened via an `onManageAccess` callback. * Cached the regex built by `doPermissionsCheck`'s `toRegexpString` instead of rebuilding it on every permission check. Diagnosed from two Chrome performance traces of the team page while typing in the filter box (multi-second main-thread blocking tasks traced to React Query `QueryObserver` mount/unmount storms). ## Test plan - [X] `tsc --noEmit` clean (only one pre-existing, unrelated error in `packages/ui-patterns`) - [X] `eslint` clean on all changed files (only pre-existing warnings) - [X] `vitest run tests/components/Organization/TeamSettings` — 51 tests pass - [X] Manually verify filtering is smooth on an org with 200+ members <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Team Settings provides centralized member access and role management. * Members can update roles through the access-management panel. * **Improvements** * Permission checks now more accurately handle organization and project scopes, including wildcard patterns. * Member search is debounced for smoother filtering while typing. * Access-management actions use current organization members, roles, permissions, and feature settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
9b1dddde11 |
Scoped PAT: add api_gateway_keys_secret_read and data_api_config_secret_read permissions (#50134)
## What kind of change does this PR introduce? Surface the new scoped personal access token permissions published in `@supabase/shared-types` 0.1.95 (added by https://github.com/supabase/platform/pull/38060, now deployed). **Stacked on #50234**, which regenerates the Management API types so Studio's scope type includes the new ids. This PR targets that branch and will retarget to `master` when it merges. ## What's in here - Bump `@supabase/shared-types` to 0.1.95 (Studio and shared-data). - Catalog entries in `packages/shared-data/scoped-access-token-permissions.ts`: - **API Key Secrets** (`api_gateway_keys_secret_read`): gates `?reveal=true` on the API keys endpoints. Renamed from "JWT secret", which described the wrong thing. - **Data API JWT Secret** (`data_api_config_secret_read`): gates the `jwt_secret` field on the PostgREST config endpoint. - **Compute** (`workers_read` / `workers_write`): shared-types 0.1.95 also publishes the workers scopes, so they surface in the catalog now. Named to match Studio's product naming (#50208). - Minimum roles for the four new ids in `FGA_SCOPE_MINIMUM_ROLE`, transcribed from the OpenFGA model (secret reads: developer; workers read: readonly; workers write: developer). - Docs generator (`generateAccessControlPartials.mts`): - Drop the workers exclusion now that the scopes are live. - When an endpoint lists alternative permission sets (for example API keys read alone, or read plus secret read for reveal), a row's footnote now only considers the alternatives that include that row's own scope. Previously the API Key Secrets row would have said "Requires API Keys (Read), or API Keys (Read) and API Key Secrets (Read)". - Regenerated PAT guide tables. The committed Management API specs predate the secret scopes, so this also includes the same spec refresh the weekly docs bot performs (`chore(docs): refresh the Management API specs`, kept as its own commit). Besides the new rows it picks up two new upstream endpoints under Advisors and the branch rows. ## Verified - `pnpm --filter studio typecheck` clean on top of #50234. - Access token test suite passes, including the guard that the role table covers exactly the ids shared-types publishes. - Partial regeneration is idempotent, so the Docs Tests stale-table gate passes. ## Follow-ups (not in this PR) - `apps/docs/content/guides/getting-started/api-keys.mdx` says a fine-grained token needs `api_gateway_keys_read` for the `?reveal=true` example. It now also needs `api_gateway_keys_secret_read`. - `project:api_gateway_keys` still says "Read exposes API keys" in its risk reason, which overstates it now that secret values sit behind a separate scope. Rewording may mean revisiting its risk level. - The comment in `ComputeLayout.tsx` about shared-types not exposing `workers_read` is stale. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added permission support for API key secrets, Data API JWT secrets, and compute workers. * Added API endpoints to run project advisors and create branches. * Added support for additional log-drain destinations, including S3, Last9, and OTLP. * Added storage object versioning information to project configuration responses. * **Documentation** * Updated access-control documentation for new permissions, worker operations, advisor runs, and branch creation. * Clarified Data API configuration and secret descriptions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
737b8595f2 |
Update API types (#50234)
## Problem platform, v1 and v2 have been already completely migrated and introduced some changes. Some types have been renamed, some outputs and inputs updated. ## Solution - Update the API types - Fix the TS errors ## Update Taking this over to unblock #50134, which needs the new scoped token permission ids from the regenerated types. - Merged `master`. - Regenerated `api-v2.d.ts` from the production spec. The previous files came from a local API that exposed a webhook events endpoint production doesn't have yet. Production has since added standardized 400 error responses on the v2 organization endpoints. `api-v1.d.ts` and `platform.d.ts` already matched production. - Fixed `verify-production-types`. It formatted the regenerated files in a temp directory outside the repository, so Prettier fell back to its defaults and the comparison could never match the committed files. It now passes the repository config explicitly. `pnpm api:verify-types` passes on this branch. - Verified locally: `pnpm typecheck`, `pnpm api:verify-types`, Studio unit tests. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Preserved descriptions when saving, sharing, moving, or unsharing notebooks, reports, SQL snippets, and saved queries. * Improved handling of empty or null values across notebook descriptions, billing usage, pooler settings, and infrastructure fields. * Improved read-replica connection handling, including read-only connection strings. * Updated storage configuration and capability handling to match current settings. * **API and Compatibility** * Updated organization, project, storage, OAuth, billing, and infrastructure data handling to match current API responses. * OAuth app creation and updates now require scopes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> |
||
|
|
8ac64a4349 |
Add copy notebook as markdown action (#50200)
## Context Adds a "Copy as Markdown" CTA for notebooks <img width="265" height="198" alt="image" src="https://github.com/user-attachments/assets/5eccf36e-24ea-4d2f-b1cf-72d5353b70a2" /> Query cell titles will be rendered as h3 tags and labelled either Postgres or Logs - Clickhouse (with time range) The query content will then be rendered as triple backticks with `sql` e.g ` ```sql...``` ` Query results will be copied to markdown if the query has been run, will otherwise be omitted Also, if the query was updated (e.g content, source, etc) after it was run (as the result is hence stale), result will also be omitted e.g: | Notebook | Markdown | | --- | --- | | <img width="1291" height="630" alt="image" src="https://github.com/user-attachments/assets/c49f23e5-c70b-46dd-a298-6e1a90cd30d7" /> | <img width="731" height="536" alt="image" src="https://github.com/user-attachments/assets/4bbe3041-bd8e-42d3-86d2-1691e7a6bc7b" /> | | <img width="1220" height="832" alt="image" src="https://github.com/user-attachments/assets/67de523a-18f7-4f1b-b764-7f0f3152f9e7" /> | <img width="757" height="803" alt="image" src="https://github.com/user-attachments/assets/d217504b-bee6-4088-9049-87ff647b9bc7" /> | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Markdown export for notebook queries, results, errors, and time ranges. * Added error notifications when copying notebook content fails. * **Bug Fixes** * Prevented stale query results after relevant source or time-range changes. * Improved Markdown export for queries containing backticks. * Escaped backslashes, pipes, and line breaks in Markdown tables. * **Style** * Adjusted spacing for empty query-result messages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7c681da0d2 |
Explorer home to run query in query tab if input in chat form is a sql query (#50204)
### Context As per PR title - figured this might be a nice convenience. Submitting a SQL query in the chat form on the explorer home page will open the query in a query tab and run it <img width="854" height="632" alt="image" src="https://github.com/user-attachments/assets/57dc7538-74b5-4801-a7ed-83c1cfaf123f" /> <img width="872" height="519" alt="image" src="https://github.com/user-attachments/assets/597ce0eb-76d4-4f12-83db-20b628c03904" /> ### To test - [ ] Run a couple of SQL statements in the home tab - should open it in query tab and run it - [ ] Run a couple of non-SQL statements in the home tab, should default to opening in a chat tab <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit - **New Features** - SQL statements submitted from the Explorer home screen now open in a query tab and run automatically. - Natural-language prompts continue to open in the chat experience. - Queries restored from drafts can automatically run once the editor is ready. - **Bug Fixes** - Improved recognition of SQL with leading whitespace, comments, and common statement formats while avoiding misclassification of conversational prompts. - Draft-based auto-run behavior now waits until the query editor is ready. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
103051a149 |
Add role impersonation check for CSV imports (#50213)
### Context Resolves [https://github.com/supabase/supabase/issues/28820](<https://github.com/supabase/supabase/issues/28820>) CSV imports via the table editor is currently missing the role impersonation check. Assuming you've got a table that has a column which references `auth.users` + default values to `auth.uid() + not nullable` (e.g `user_id`), if you try to manually add a row while impersonating a user and leaving the `user_id` input field NULL, the newly inserted row will default to the user ID of the impersonated user <img src="https://github.com/user-attachments/assets/f6eb7e24-50e4-42aa-b6e6-64c50e195be7 " alt="image" width="685" data-linear-height="255" /> However, because CSV imports are missing the role impersonation check, importing data with a CSV that has null values for `user_id` column will throw a NOT NULL postgres error. PR here adds the role impersonation check and resolves ^ this particular behaviour ### To test - [X] Create a table that references the `auth.users` table ``` create table public.empty ( id uuid primary key default gen_random_uuid(), user_id uuid not null references auth.users(id) on delete cascade default auth.uid(), note text ); ``` - [ ] Import data via CSV via the table editor using this CSV while impersonating a user [empty_test_import_no_user_id.csv](<https://github.com/user-attachments/files/32053194/empty_test_import_no_user_id.csv>) - [ ] Should pass without any errors, inserted rows should have `user_id` filled as the impersonated user's ID * Can also verify first on staging that doing this will throw a not null error ## Summary by CodeRabbit * **Bug Fixes** * Spreadsheet imports in the table editor now respect the currently selected role-impersonation state, ensuring imported rows are processed with the appropriate permissions. * Manually inserted or pasted rows now use the active role-impersonation settings, providing consistent permission handling across table editing workflows. |
||
|
|
e57aae3c83 |
feat(design-system): document disabled controls and add focusableWhenDisabled (#50068)
## What kind of change does this PR introduce? Docs update, with supporting `ui` and Studio changes. ## What is the current behaviour? Disabled buttons with tooltips use native `disabled`, which removes them from the tab order. Keyboard users cannot focus the control or read the tooltip explaining why an action is blocked. The design system also lacked guidance on keeping disabled actions discoverable and explaining why they are unavailable. ## What is the new behaviour? - Adds a **Disabled controls** section to the accessibility docs, with live examples for a focusable disabled button and visible page-level context - Adds `focusableWhenDisabled` to `Button`, keeping `disabled` as the semantic state while using `aria-disabled`, retaining keyboard focus, and guarding click handlers - Updates Studio's `ButtonTooltip` to make disabled buttons with tooltip text focusable automatically Also includes earlier design-system fixes on this branch: - Centralises `BASE_PATH` with a `/design-system` fallback so asset URLs work without a local `.env` file - Fixes sidebar hover and active tokens in design-system and ui-library, aligned with Studio's `InnerSideMenuItem` ## To test **Design system** 1. Open the [accessibility preview](https://design-system-git-fix-design-system-docs-and-nav-fixes-supabase.vercel.app/design-system/docs/accessibility) 2. Scroll to **Disabled controls** 3. Tab to the **disabled-focusable** example. Confirm the button remains focusable, looks disabled, and shows its tooltip on focus 4. Confirm the **disabled-unavailable-with-notice** example shows the admonition and focusable disabled button pattern **Studio (optional, requires a High Availability project)** 5. Go to Settings → General → **Pause project**. Tab to the button and confirm it remains focusable, looks disabled, and shows the HA tooltip on focus 6. Go to Database → Backups and find **Restore** on a scheduled backup row. Confirm the same behaviour |
||
|
|
6c3e8a6a4e |
Add Brent Graveland to humans.txt (#50240)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? docs update, adding myself to the list of contributors <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Brent Graveland to the team roster. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9c67468326 |
docs: update terraform docs pinned version (#50233)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? There have been [many updates](https://github.com/supabase/terraform-provider-supabase/compare/v1.1.3...v1.11.0) to our terraform provider since the docs were last updated. This PR updates the pinned version of [our terraform docs](https://supabase.com/docs/guides/deployment/terraform) to the latest version. ## What is the current behavior? [Outdated terraform docs](https://supabase.com/docs/guides/deployment/terraform) ## What is the new behavior? [Updated terraform docs](https://docs-git-kanad-2026-09-10-bump-terraform-docs-version-supabase.vercel.app/docs/guides/deployment/terraform) ## Additional context n/a <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated Terraform documentation content to use provider version `v1.11.0`. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
f3bd8ee7e3 | fix(docs): reduce reference page response size (#50235) | ||
|
|
c427615234 |
fix(pg-meta): pair composite foreign key columns correctly (#41080)
## TL;DR Correctly pairs composite foreign key columns when loading table metadata. ## What's hurting? The tables introspection query matched every source column in a composite foreign key with every target column. For `(user_id, tenant_id) → (id, tenant_id)`, it returned four relationships instead of the correct two, causing incorrect relationship metadata in the Table Editor... ## Now fixed Source and target columns are paired by ordinal position using a lateral multi-array `unnest`. Regression coverage now verifies adversarial column ordering, and the existing performance guard exercises thousands of composite foreign keys... PS: local stress test found no performance regression or unexpected sequential scans. ## Ref - Closes #41068 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Corrected foreign-key relationship detection for composite keys, ensuring source and target columns are paired accurately. * Improved catalog relationship queries to remain within performance limits for composite-key tables. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Andrew Valleteau <avallete@users.noreply.github.com> |
||
|
|
3c3daf8f10 | fix(warehouse): avoid confusion in tests containing fake credentials, make it more obvious it's fake (#50207) | ||
|
|
d513d013c5 |
chore(studio): poll state to keep ui in sync (#50216)
Poll compute data to keep ui in sync - every 3s when state is transitioning - every 10s when idle ## To test - open compute - deploy compute instance via cli - check ui updates automatically while state changes (new -> active -> deleting -> removal) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Compute data now refreshes automatically, with faster updates while instances are building or being deleted. * Added clearer manual refresh feedback in the compute interface. * **Improvements** * Improved compute table layout with fixed column sizing and truncated long instance names. * Region and resource columns remain responsive while maintaining consistent widths. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
9a9228a9f8 |
Assistant panel maximize CTA to open in explorer only if explorer preview is enabled (#50203)
### Context As per PR title - currently the assistant panel's maximize CTA defaults to opening in explorer, which might be confusing for users who don't have the explorer feature preview enabled <img width="581" height="190" alt="image" src="https://github.com/user-attachments/assets/9a9b6129-164e-4e3e-a14e-66ecafe8e5ff" /> <img width="574" height="157" alt="image" src="https://github.com/user-attachments/assets/ffff0a49-3357-4e5f-8cc0-be2f94263128" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Updated the AI assistant’s maximize control with context-sensitive actions. * When Explorer preview is enabled, the control opens the active conversation in Explorer. * When Explorer preview is disabled, the control maximizes or minimizes the assistant panel. * Updated the control’s label, accessibility text, and keyboard shortcut to reflect the available action. * Maximized AI Assistant panels now use the full available width, while other sidebars retain responsive sizing. * **Bug Fixes** * Improved sidebar behavior on mobile and overlay layouts to prevent unwanted resizing or collapsing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0bf22ee6fc |
chore(studio): update product naming (#50208)
workers -> compute <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added the Compute experience for deploying, viewing, managing, and monitoring compute instances. - Added Compute navigation, instance detail pages, secrets, logs, deployment dialogs, generated snippets, and CLI commands. - Added filtering, status, availability, and data-loading support for compute instances. - **Updates** - Updated labels, icons, links, feature controls, unified logs, and secret-deletion messaging to use Compute terminology. - Compute routes now replace the previous Workers routes and pages. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3635ab15ff |
Standardize icon for maximise in editor panel (#50210)
### Context Just a tiny UI nit to standardise the maximise icon in Editor Panel, matching that of the Assistant Panel <img width="443" height="138" alt="image" src="https://github.com/user-attachments/assets/b1827b86-03c0-4312-b7b2-c6e2f5761a96" /> <img width="438" height="147" alt="image" src="https://github.com/user-attachments/assets/fc33d4d5-931d-49bd-b46d-d39e45860c52" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Style** - Updated the maximize control icon for a clearer visual representation. - **Accessibility** - Updated the control label and tooltip to say “Open in SQL editor” for improved clarity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0bebe50a76 |
fix(studio): serialize SQL folder deletion IDs (#50223)
## Summary * serialize SQL folder IDs as the comma-delimited API query value * add regression coverage for the folder deletion request ## Testing * `pnpm --filter studio exec vitest run data/content/sql-folders-delete-mutation.test.ts` * `pnpm exec prettier --check apps/studio/data/content/sql-folders-delete-mutation.ts apps/studio/data/content/sql-folders-delete-mutation.test.ts` * `pnpm --filter studio exec eslint data/content/sql-folders-delete-mutation.ts data/content/sql-folders-delete-mutation.test.ts` * `pnpm --filter studio exec tsc --noEmit --pretty false` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed SQL snippet folder deletion requests so multiple selected folders are processed correctly. * Improved request handling by formatting folder identifiers consistently when submitting bulk deletions. * **Tests** * Added coverage to verify that deleting multiple SQL snippet folders sends the expected folder identifiers. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
7ca208918d | docs(auth): fix documentation of self hosted auth (#36681) | ||
|
|
028e05205b |
docs: warn that default signOut scope revokes all sessions (#50119)
Warn that default signOut scope revokes all sessions. Motivation: https://github.com/supabase/ssr/issues/68 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that signing out without a specified scope ends all sessions by default. * Added guidance for using a local sign-out scope to preserve sessions on other devices and browsers. * Documented the invalid refresh token errors that may occur when other sessions are revoked. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
045f29ecb6 |
chore: bump @supabase/server to 1.6.0 in mcp-server block (#50205)
Bumps the pinned `@supabase/server` version from 1.5.1 to 1.6.0 in the mcp-server registry block (`index.ts` and `tools/types.ts`), and regenerates the corresponding `mcp-server.json` registry file to match. No API usage changes; the block still only imports `withOAuthProtectedResource`, `withSupabase`, and `SupabaseContext` from the package root. Also adds a `.gitignore` entry for the `deno.lock` generated locally under this block's directory, since it's a local artifact and not needed for the registry block to work. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Chores** - Updated the Supabase server dependency to version 1.6.0 for the MCP server. - Excluded the local-only lockfile from version control. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
fd863ee15d | feat(kb): Expose markdown alternatives for articles and topics pages (#50135) | ||
|
|
c145f3e046 |
fix(docs): guide nav collapsible parity (#49945)
## What kind of change does this PR introduce? visual parity fix and refresh + component extraction (stacked on #49942) ## What is the current behavior? guide and reference sidebars each hand-roll their own collapsible section visuals ## What is the new behavior? - adds `NavSection` composition components (`NavSectionCaret`, `NavSectionContent`, `NavSectionList`) shared by both navs via radix `asChild`, so the rail, caret, and motion have a single source of truth - fixes ui drift between both so navs get the same left rail beside expanded children, the same caret and animation - enhances link click area so space between rows is part of the click target | state | preview | | -------|------| | before | <img width="430" height="288" alt="image" src="https://github.com/user-attachments/assets/0052d4b7-7793-43cf-8416-2a5445b95148" /> | | after | <img width="430" height="288" alt="image" src="https://github.com/user-attachments/assets/42713ee3-e147-4e53-a58d-3f3de278264d" /> | ## How to test? 1. run `pnpm dev:docs` 2. open [guide page](http://localhost:3001/docs/guides/integrations/build-a-supabase-oauth-integration) 3. open [reference page](http://localhost:3001/docs/reference/dart/introduction) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added animated expand/collapse behavior and rotating caret indicators to documentation navigation sections. * Added active-child indicators for clearer navigation context. * **Improvements** * Standardized spacing, borders, and animation styles across guide and reference navigation. * Improved collapsible animations to support varying content sizes more reliably. * Navigation items without links or child content, including disabled nested items, are no longer displayed. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
bdd4b8d369 |
fix(docs): guides sidebar a11y elements (#49942)
## What kind of change does this PR introduce? bug fix (accessibility) + test coverage ## What is the current behavior? the guides sidebar renders invalid list markup: group headers and dividers sit directly under the root `ul`, and accordion links render as `li` elements without an owning list fixes [DOCS-1279](https://linear.app/supabase/issue/DOCS-1279/guides-sidebar-put-li-elements-directly-in-the-ul) ## What is the new behavior? - sidebar renders a semantic hierarchy: every `ul` has only `li` children, every `li` has an immediate list parent, and the menu header sits outside the item list. pure markup change, - docs e2e scans the guide navigation separately from the article and blocks the `list` and `listitem` axe rules there against sample pages that include different usages (flat links, grouped links, nested accordion) ## How to test? run the docs dev server, then the scoped a11y suite: ```bash pnpm dev:docs pnpm e2e:docs:a11y ``` ## Follow up visuals and behavior are unchanged here but better parity between guide/reference is handled in the stacked pr <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved documentation navigation rendering for nested guide items, active states, and disabled entries. * Ensured navigation groups and child links use valid, testable list structures. * **Tests** * Added coverage verifying that guide navigation changes run the appropriate documentation pages. * Confirmed unrelated documentation changes can be skipped by the end-to-end workflow. * **Chores** * Updated documentation test scope detection to include guide navigation changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a78472ba7c | chore: Add support for admonition in gfm alert notation (#50093) | ||
|
|
5d78b1da1a |
fix(docs): a11y projectconfigvariables (#50002)
## What kind of change does this PR introduce? bug fix for accessibility, fixes [docs-1280](https://linear.app/supabase/issue/DOCS-1280/projectconfigvariables-label-the-readonly-inputs-and-name) ## What is the current behavior? the project url and api key fields in `ProjectConfigVariables` have no associated label, so a screen reader announces an edit field with no indication of which value it holds ## What is the new behavior? - associates a `<label>` with each readonly input, so the fields announce as "project url" and "publishable key" - names each copy button after the value it copies - drops `role="combobox"` from the trigger, keeping the `aria-haspopup`, `aria-expanded` and `aria-controls` radix already supplies - names the trigger from its content instead of `aria-label`, so it announces the current selection - names the shared `CommandInput` reset button and hides its icons ## test - `pnpm dev:docs` - `/docs/guides/getting-started/quickstarts/nextjs` (`url` + `publishable`) - `/docs/guides/auth/server-side/creating-a-client`, branch selector, needs a branching-enabled project - `/docs/guides/observability/log-drains` - `api_settings` in any getting-started quickstart ## Additional context reverses part of #49952 as that pr added `aria-label` to satisfy `button-name`, but did replace the accessible name rather than adding to it _ the sr-only prefix added here keeps the rule passing and announces the selection <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Accessibility** * Improved screen reader support for variable configuration controls, including clearer labels and copy-status announcements. * Enhanced combobox and search interactions with accessible labeling, empty-result announcements, and clearer reset-button names. * Decorative icons and visual-only messages are now hidden from assistive technologies. * **Tests** * Added accessibility coverage for search input icons and the clear-search control. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1966209483 |
chore(deps): upgrade vitest to v5 (#49994)
Upgrades Vitest from 4.1.4 to 5.0.0 across the monorepo, fixes the handful of things v5 turned into hard errors, and drops the `vi.clearAllMocks()` boilerplate that v5's `clearMocks` default makes redundant. **Changed:** - `vitest`, `@vitest/ui`, `@vitest/coverage-v8` 4.1.4 → 5.0.0 (catalog) - `vi.mock` calls that lived inside `beforeAll`/`beforeEach`/test bodies moved to module scope (v5 throws on nested calls). Affects the Studio and docs setup files and four Studio tests. - `detectBrowser` test restores `navigator` via `vi.unstubAllGlobals()` instead of assigning `global.navigator`, which now reaches jsdom's getter-only property. - `RowEditor.utils.test.ts` restores its `JSON.stringify` spy. It used to leak a throwing mock for the rest of the file, which v5's coverage provider now trips over. A later test in the same file had been asserting the leak's side effect (valid JSON reported as invalid) and now asserts the correct behavior. - `@testing-library/jest-dom` 6.6 → 7.0.1. Its vitest type augmentation resolves through a peer now, so it lands on each package's own `vitest` instead of whichever copy pnpm hoisted. Fixes `toBeInTheDocument` type errors in dev-tools after the reshuffle. - `@testing-library/react` 16.0.0 → 16.3.3 for the React 19 peer range. - `vite: catalog:` added to dev-tools, www, and common. Without it they resolved a newer vite than the catalog pin, which forked a second vitest instance in the lockfile. There's now one. - ai-commands custom matcher types use v5's `Matchers<R, T>` form. - 110 test files: `vi.clearAllMocks()` removed from `beforeEach`/`afterEach` hooks, along with hooks that only did that and the imports they left unused. Calls that also reset/restore mocks are untouched. Second commit, mechanical. **Added:** - `.vitest/` to the root gitignore (v5 writes JSON/JUnit/HTML reporter output there) **Removed:** - `vite-tsconfig-paths` catalog entry and deps. Vitest 5 resolves tsconfig paths itself. Release-age note: this sat in draft with a temporary `minimumReleaseAgeExclude` entry for `vitest` and `@vitest/*` while 5.0.0 was inside the workspace's 3-day `minimumReleaseAge` window. That window has closed, so the exclusion is gone and nothing bypasses the release-age gate. **Perf** (local, medians of 3 runs, same machine): | Suite | v4.1.4 | v5.0.0 | |---|---|---| | studio | 144.1s | 141.7s (-2%) | | studio `--coverage` | 156.9s | 146.4s (-7%) | | ui-patterns | 6.27s | 5.07s (-19%) | | ui `--coverage` | 3.35s | 2.14s (-36%) | | www | 0.89s | 0.47s (-47%) | Studio is dominated by jsdom environment setup per file, which v5 doesn't change. `vitest doctor` recommends keeping the current pool config: the vm pools and `isolate: false` all break tests. ## To test - `pnpm install --frozen-lockfile` succeeds with no `minimumReleaseAgeExclude` entry for vitest. - CI: Studio unit tests, ui, ui-patterns, www, docs, and typecheck/lint should all be green. The lint ratchet was checked locally: warning counts on touched Studio files are identical to master. - `pnpm test:studio` locally passes with coverage (588 files, 6240 tests). - Open a Studio test that uses `toBeInTheDocument` in your editor and confirm no type errors on jest-dom matchers, in Studio and in `packages/dev-tools`. - Known pre-existing failures unrelated to this PR: one dev-tools test (`getEventCountBadge` capped pill) fails on master too. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Tests - Improved test coverage for JSON validation and mobile navigation behavior. - Updated test setup, cleanup, environment configuration, and matcher support across application and shared package suites. - Removed obsolete coverage for alternate MCP transport selection. ## Chores - Streamlined TypeScript path resolution and Vitest reporter output handling. - Updated testing libraries and Vitest tooling across documentation, Studio, website, and shared packages. - Added Vitest reporter output to ignored files. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com> Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com> |
||
|
|
de2f8bbd03 |
fix(docs): prima guide yarn panel display npx (#50186)
## What kind of change does this PR introduce? bug fix in prisma guide page code example ## What is the current behavior? yarn panel display `npx` command in code example ## What is the new behavior? favor `yarn` command in yarn panel code example | state | preview | | -------|------| | before | <img width="760" height="315" alt="image" src="https://github.com/user-attachments/assets/d7dc9004-9618-48ff-9b6c-4b7da4e8c44e" /> | | after | <img width="760" height="315" alt="image" src="https://github.com/user-attachments/assets/a7cee65f-2038-4f5a-81e3-1cb627cb73b9" /> | ## Test 1. visit `/docs/guides/database/prisma` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated Yarn Prisma command examples to use Yarn-specific syntax for project initialization, migrations, database pulls, migration diffs, migration resolution, and client generation. * npm, pnpm, and Bun examples remain unchanged. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e6bd407e88 |
fix(docs): collapsible details component (#50065)
## What kind of change does this PR introduce? nitpick ui bug fix in docs of the collapsible details component + commentary ## What is the current behavior? 1. data / response / notes collapsibles on reference pages grow taller when you expand them + also get double padding: the panel pads the content, and the code block pads itself again inside it 2. commentary that follows a snippet in the example column renders unstyled, since that column has no prose context. it comes out larger than the description column and inline code stays as plain text ## What is the new behavior? ├ adds `CodeBlock` a `compact` variant that get appropriate styling when used within collapsible | state | preview | | -------|------| | before | <video src="https://github.com/user-attachments/assets/8b70e1c6-9e0e-4371-a2b2-eb4a3d580247" /> | | after | <video src="https://github.com/user-attachments/assets/1e5cdd46-ce7d-4d2d-ac6a-6da680df37e5" /> | ├ wraps example column in prose so trailing commentary matches the description font size + inline code styling | state | preview | | -------|------| | before | <img width="1142" height="404" alt="image" src="https://github.com/user-attachments/assets/8d0f1ac0-087d-47f7-b35d-b8798d589fdb" /> | | after | <img width="1142" height="404" alt="image" src="https://github.com/user-attachments/assets/b9ba4202-a8dd-407d-b535-f34d83f5b24b" /> | ## Test - visits `/docs/reference/javascript/using-filters-gt` - visits `/docs/reference/server/middleware-withsupabaseadminclient` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Documentation code blocks can now be displayed in a compact format without borders or extra spacing. - Reference documentation supports customizing code block presentation. - **Style** - Improved formatting for example content, including prose wrapping, spacing, and code block margins. - Refined collapsible documentation sections with clearer spacing, hover and focus states, and open/close animations. - Code-only collapsible content now uses a more compact layout, while text content receives consistent typography and padding. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d9742d707f |
chore(studio): refine Explorer sidebar breadcrumbs (#50188)
Moves Explorer’s back navigation and create actions into a reusable sidebar breadcrumb header. Reduces product-menu headings globally to `text-sm` and keeps breadcrumb links free of padding, borders, and backgrounds. ### How to test 1. Open `/project/<ref>/explorer` and confirm the header shows Explorer and the SQL Editor switch action. 2. Open Notebooks and Chats. Confirm the header shows `Explorer > Notebooks/Chats` and the corresponding create action works. 3. Return using the Explorer breadcrumb with a click or Tab + Enter. Check that the label stays aligned and has no hover background. 4. Open another product, such as Database, and confirm its sidebar heading uses the smaller font size. 5. At a mobile viewport, open the menu and repeat the notebook/chat actions and back navigation without closing the sheet. Confirm the header stays current and disappears when returning to the main menu or opening another product. Validation: 18 focused tests, typecheck, formatting, and lint ratchet passed. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a shared Explorer sidebar header with breadcrumbs and contextual actions for creating notebooks and chats. - Added keyboard-accessible navigation between the Explorer overview and notebook or chat sections. - Added support for customized product menu headers across project layouts. - **Improvements** - Centralized Explorer navigation and actions in the shared sidebar layout. - Improved mobile menu updates when navigating between Explorer resources. - Refined Explorer home layout and drag-handle behavior across screen sizes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
b8b92fe566 |
fix(www): careers page error (#50185)
## What kind of change does this PR introduce?
bug fix careers page on anchor link click
## What is the current behavior?
on `/careers`, clicking "open positions", scrolling down and back up,
then clicking it again crashes the page
## What is the new behavior?
destructuring defaults on the page props, so an empty-props render is
harmless instead of fatal _ prefetch still returns `{}`, but the
sequence now renders normally instead of throwin
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved the careers page so it renders correctly when job listings,
placeholder job details, or contributor information are unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
|
||
|
|
84db103ebb | ci(api): verify generated types against production (#49993) | ||
|
|
c708e1128f |
fix(ui-patterns): reveal hover-only copy controls on keyboard focus (#50083)
## What kind of change does this PR introduce? bug fix + a11y _ follow-up to the UI review on #50045 ## What is the current behavior? **`CodeBlock`**: the copy control lives in an `opacity-0 group-hover:opacity-100` wrapper with no focus rule, so it stays invisible when a keyboard user tabs to it, button is focusable and pressable, just not visible **`DataInputs/Input`**: same wrapper, but the parent `InputGroup` declares a *named* group (`group/input-group`), so the unnamed `group-hover:` matched nothing. With `showCopyOnHover` the button was invisible at all times, hover included. Only consumer today is the Edge Functions "Download via CLI" popover. ## What is the new behavior? ├ adds `group-focus-within:opacity-100` to `CodeBlock` | state | preview | | -------|------| | before | <img width="800" height="450" alt="image" src="https://github.com/user-attachments/assets/04645fbd-3b43-4291-afe3-ba56ab961dac" /> | | after | <img width="800" height="450" alt="image" src="https://github.com/user-attachments/assets/880b49aa-2244-4b78-9fbd-f554770e3a3b" /> | ├ retargets both variants at the named group: `group-hover/input-group:` + `group-focus-within/input-group:` in `Input` | state | preview | | -------|------| | before | <img width="542" height="261" alt="image" src="https://github.com/user-attachments/assets/0ff85a85-5ef8-41e4-a3f0-34f7982770c4" /> | | after | <img width="542" height="261" alt="image" src="https://github.com/user-attachments/assets/8ce84ea7-bcb6-47ba-a7e6-a35f6edbd332" /> | ## Testing 1. visits `/docs/guides/ai-tools/plugins#manual-installation` 2. tabs into the code block <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Accessibility Improvements** - Copy buttons in code blocks and input fields are now revealed when the component or its contents receive keyboard focus, in addition to appearing on hover. - Improved keyboard discoverability and access to copy actions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
c33d255eba |
chore(studio): refine assistant empty states (#50191)
<img width="1062" height="712" alt="image" src="https://github.com/user-attachments/assets/44c82e00-94b4-405a-b2ef-cbc08401c4db" /> <img width="1583" height="962" alt="image" src="https://github.com/user-attachments/assets/b19b9fd8-24b1-48d6-8b31-11fba9911b9a" /> ## What kind of change does this PR introduce? UI refinement. ## What is the current behavior? The assistant sidebar and Explorer chat use different empty states. ## What is the new behavior? Share a centered empty state with chat-focused prompts, use-case icons, and a “Use your own agent” footer. Simplify prompt cards and align Explorer Home styling. ## Additional context Studio typecheck, targeted ESLint, and Prettier pass. E2E selectors updated; browser verification pending. Local build stopped after showing no progress during compilation. I have read CONTRIBUTING.md. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Redesigned Explorer and AI Assistant onboarding with project-focused chat prompts. * Added personalized chat template icons and updated suggested actions. * Added an option to connect and use an external agent through Claude, OpenAI, or Cursor. * Improved chat composer placement and empty-chat guidance. * **Style** * Action cards now support layouts without descriptions and adjust alignment automatically. * **Tests** * Updated end-to-end coverage for the revised assistant interface. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1131e3e2ce |
fix(ui): default Button variant to default instead of primary (#50160)
## What kind of change does this PR introduce? Bug fix / design-system alignment for the legacy `Button` from `ui`. ## What is the current behavior? Omitting `variant` on the legacy `Button` falls back to brand-green `primary`. That makes accidental greens easy, and it is hard to spot the real main action on busy pages. ## What is the new behavior? - Legacy `Button` now defaults to neutral `default` - Intentional primary CTAs (create, save, submit, marketing CTAs, and matching `ButtonTooltip` usages) now set `variant="primary"` so their appearance is unchanged - Neutral actions that previously relied on the old fallback (cancel, close, back, dashboard nav, and similar) become grey/white - Design-system docs updated; regression tests cover the new default `Button_Shadcn_` is unchanged. It already uses its own CVA default. This is PR 1 of 2 in a stack. PR 2 drops now-redundant `variant="default"` props. ## To test Studio (http://localhost:8082): - `/sign-in`: Sign in stays green - Open a project → Database → Tables: New table stays green - Auth → Users → Invite: Invite user stays green; Cancel / dismiss controls stay neutral - Project Settings → General: edit a field so Cancel and Save appear. Cancel is neutral, Save is green Design system (http://localhost:3003): - Components → Button: default demo is neutral; primary demo is green; featured preview is the default variant Marketing (optional): - www header: Start your project stays green; logged-in Dashboard is neutral <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Style** - Buttons now default to a neutral style, while primary actions across Studio, documentation, marketing pages, forms, dialogs, and error states use prominent primary styling. - Updated button examples and previews clarify the distinction between default and primary variants. - Event registration now includes a directional arrow icon. - **Tests** - Added coverage confirming default button styling and explicit primary styling behave as expected. - Updated related test fixtures to use primary styling where appropriate. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
30ab816ff4 |
feat(studio): make the Connect framework and client selectors searchable (#50072)
## What kind of change does this PR introduce? Feature. ## What is the current behavior? The Framework and Client selectors in the Connect sheet are plain selects. Neither is scannable at its current length, and Client is the worse of the two at 19 options. ## What is the new behavior? Both are searchable comboboxes. Each keeps its selection, filters as you type, matches on the underlying key as well as the label so `nextjs` finds `Next.js`, and announces its empty state to screen readers. | Before | After | | --- | --- | | <img width="1182" height="1250" alt="CleanShot 2026-09-07 at 14 47 12@2x" src="https://github.com/user-attachments/assets/6243c549-03cc-41bf-8b3c-a186ca0e93b5" /> | <img width="1178" height="1162" alt="CleanShot 2026-09-07 at 14 46 42@2x" src="https://github.com/user-attachments/assets/d7ca5e72-3f8b-48e5-b20f-84382e4e4fd7" /> | Placeholder, search and empty-state copy now sit on the field definition in the schema, next to the label, so one combobox component serves both fields without guessing at plurals. Client keeps its icons hidden, matching what the select did. The comment about MCP images being unoptimized still stands, so this is not the PR to turn them on. Radix Select brings its own scroll lock, so replacing it with a popover would have regressed touch scrolling in the sheet. #50103 moved that guard into `CommandList` and has merged, so this branch now carries the feature only. ## To test - Open the Connect sheet on the deploy preview. - Open the Framework selector, search for `native`, confirm only React Native remains, select it, and confirm the generated connection instructions update. - Search `nextjs` and confirm Next.js matches on its key. - Switch to the MCP tab and open Client. Search `cur` and confirm Cursor matches. - Confirm both lists cap their height and scroll, and that the sheet behind stays put. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Framework selection now uses a searchable combobox for easier navigation of long lists. * Search results clear automatically when the combobox closes. * Long framework lists appear in a contained, scrollable area. * **Accessibility** * Screen readers announce when no frameworks match the search. * Improved combobox and listbox relationships support assistive technologies. * The dropdown opens as a modal layer to keep focus within the selection experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |