mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 20:35:07 +03:00
## What kind of change does this PR introduce? Feature. Resolves DEPR-430. ## What is the current behaviour? The homepage Advisor summary, shared Advisor panel, and top-nav Advisor indicator only surface lints and notifications. Banned IPs are not represented as dismissible Advisor items, so network bans are easy to miss unless a user visits Database Settings directly. The `public bucket allows listing` warning is no longer part of this PR. That warning will move to a follow-up Splinter `WARN` lint so it can flow through the standard lint surfaces instead of a bespoke Studio signal path. ## What is the new behaviour? - adds a new Advisor `signal` source for banned IPs on the platform homepage, in the shared Advisor panel, and in the top-nav Advisor indicator - keeps dismissals client-side only for now, scoped by project and exact IP fingerprint - keeps banned IP signals at `warning` severity because they still indicate suspicious traffic and remain actionable if a user wants to review or remove a ban - leaves `/project/[ref]/advisors/security` as follow-up work because that surface is still lint-native, and banned IPs are management-plane signals rather than Splinter lints | After | | --- | | <img width="1728" height="997" alt="Mallet Toolshed Supabase-65A60B4A-107E-4D79-B9A8-23F754BEAB08" src="https://github.com/user-attachments/assets/c08ecbbb-c302-43bd-81bb-6ba7eb18b7b3" /> | ## Reviewer testing notes 1. Use a throwaway project. 2. Get the database connection string for that project. 3. Attempt to connect with the wrong password 3-4 times until you hit an `ECONNREFUSED`-style error, which should mean your IP has been banned. 4. Refresh Studio and confirm the project overview shows the new `Banned IP address` signal. 5. Open the Advisor Center and confirm: - the top-nav Advisor dot turns warning yellow - the signal detail shows `Entity`, `Issue`, and `Resolve` - `Edit network bans`, `Dismiss`, and `Learn more` are present 6. Open Database Settings > Network bans and confirm your banned IP appears there and can be unbanned. 7. Note that `/project/[ref]/advisors/security` will not show this item. That page is still lint-only, and this banned IP work is a short-term client-side signal rather than a true lint. Longer term, we likely want a more durable event model here so banned IPs can power notifications, webhooks, emails, and other project-level alerts. --------- Co-authored-by: kemal <hello@kemal.earth> Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
78 lines
2.8 KiB
TypeScript
78 lines
2.8 KiB
TypeScript
import { Lightbulb } from 'lucide-react'
|
|
import { useMemo } from 'react'
|
|
import { cn } from 'ui'
|
|
|
|
import { SIDEBAR_KEYS } from '@/components/layouts/ProjectLayout/LayoutSidebar/LayoutSidebarProvider'
|
|
import { useAdvisorSignals } from '@/components/ui/AdvisorPanel/useAdvisorSignals'
|
|
import { ButtonTooltip } from '@/components/ui/ButtonTooltip'
|
|
import { useProjectLintsQuery } from '@/data/lint/lint-query'
|
|
import { useNotificationsV2Query } from '@/data/notifications/notifications-v2-query'
|
|
import { useSidebarManagerSnapshot } from '@/state/sidebar-manager-state'
|
|
|
|
export const AdvisorButton = ({ projectRef }: { projectRef?: string }) => {
|
|
const { toggleSidebar, activeSidebar } = useSidebarManagerSnapshot()
|
|
|
|
const { data: lints } = useProjectLintsQuery({ projectRef })
|
|
const { data: signalItems } = useAdvisorSignals({ projectRef })
|
|
|
|
const { data: notificationsData } = useNotificationsV2Query({
|
|
filters: {},
|
|
limit: 20,
|
|
})
|
|
const notifications = useMemo(() => {
|
|
return notificationsData?.pages.flatMap((page) => page) ?? []
|
|
}, [notificationsData?.pages])
|
|
const hasUnreadNotifications = notifications.some((x) => x?.status === 'new')
|
|
const hasCriticalNotifications = notifications.some((x) => x?.priority === 'Critical')
|
|
const hasSignals = signalItems.length > 0
|
|
const hasCriticalSignals = signalItems.some((item) => item.severity === 'critical')
|
|
|
|
const hasCriticalIssues =
|
|
hasCriticalNotifications ||
|
|
hasCriticalSignals ||
|
|
(Array.isArray(lints) && lints.some((lint) => lint.level === 'ERROR'))
|
|
const hasWarningIssues = hasSignals && !hasCriticalIssues
|
|
|
|
const isOpen = activeSidebar?.id === SIDEBAR_KEYS.ADVISOR_PANEL
|
|
|
|
const handleClick = () => {
|
|
toggleSidebar(SIDEBAR_KEYS.ADVISOR_PANEL)
|
|
}
|
|
|
|
return (
|
|
<div className="relative">
|
|
<ButtonTooltip
|
|
type="outline"
|
|
size="tiny"
|
|
id="advisor-center-trigger"
|
|
className={cn(
|
|
'rounded-full w-[32px] h-[32px] flex items-center justify-center p-0 group',
|
|
isOpen && 'bg-foreground text-background'
|
|
)}
|
|
onClick={handleClick}
|
|
tooltip={{
|
|
content: {
|
|
text: 'Advisor Center',
|
|
},
|
|
}}
|
|
>
|
|
<Lightbulb
|
|
size={16}
|
|
strokeWidth={1.5}
|
|
className={cn(
|
|
'text-foreground-light group-hover:text-foreground',
|
|
isOpen && 'text-background group-hover:text-background'
|
|
)}
|
|
/>
|
|
</ButtonTooltip>
|
|
{hasCriticalIssues ? (
|
|
<span className="absolute top-1.5 right-1.5 w-1.5 h-1.5 rounded-full bg-destructive" />
|
|
) : hasWarningIssues ? (
|
|
<span className="absolute top-1.5 right-1.5 w-1.5 h-1.5 rounded-full bg-warning" />
|
|
) : hasUnreadNotifications ? (
|
|
<span className="absolute top-1.5 right-1.5 w-1.5 h-1.5 rounded-full bg-brand" />
|
|
) : null}
|
|
</div>
|
|
)
|
|
}
|