mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 20:35:07 +03:00
## What kind of change does this PR introduce? Feature. Resolves DEPR-430. ## What is the current behaviour? The homepage Advisor summary, shared Advisor panel, and top-nav Advisor indicator only surface lints and notifications. Banned IPs are not represented as dismissible Advisor items, so network bans are easy to miss unless a user visits Database Settings directly. The `public bucket allows listing` warning is no longer part of this PR. That warning will move to a follow-up Splinter `WARN` lint so it can flow through the standard lint surfaces instead of a bespoke Studio signal path. ## What is the new behaviour? - adds a new Advisor `signal` source for banned IPs on the platform homepage, in the shared Advisor panel, and in the top-nav Advisor indicator - keeps dismissals client-side only for now, scoped by project and exact IP fingerprint - keeps banned IP signals at `warning` severity because they still indicate suspicious traffic and remain actionable if a user wants to review or remove a ban - leaves `/project/[ref]/advisors/security` as follow-up work because that surface is still lint-native, and banned IPs are management-plane signals rather than Splinter lints | After | | --- | | <img width="1728" height="997" alt="Mallet Toolshed Supabase-65A60B4A-107E-4D79-B9A8-23F754BEAB08" src="https://github.com/user-attachments/assets/c08ecbbb-c302-43bd-81bb-6ba7eb18b7b3" /> | ## Reviewer testing notes 1. Use a throwaway project. 2. Get the database connection string for that project. 3. Attempt to connect with the wrong password 3-4 times until you hit an `ECONNREFUSED`-style error, which should mean your IP has been banned. 4. Refresh Studio and confirm the project overview shows the new `Banned IP address` signal. 5. Open the Advisor Center and confirm: - the top-nav Advisor dot turns warning yellow - the signal detail shows `Entity`, `Issue`, and `Resolve` - `Edit network bans`, `Dismiss`, and `Learn more` are present 6. Open Database Settings > Network bans and confirm your banned IP appears there and can be unbanned. 7. Note that `/project/[ref]/advisors/security` will not show this item. That page is still lint-only, and this banned IP work is a short-term client-side signal rather than a true lint. Longer term, we likely want a more durable event model here so banned IPs can power notifications, webhooks, emails, and other project-level alerts. --------- Co-authored-by: kemal <hello@kemal.earth> Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
169 lines
5.8 KiB
TypeScript
169 lines
5.8 KiB
TypeScript
import { AlertTriangle, ChevronRight, Inbox } from 'lucide-react'
|
|
import { Badge, Button, cn } from 'ui'
|
|
import { GenericSkeletonLoader } from 'ui-patterns'
|
|
|
|
import type { AdvisorItem } from './AdvisorPanel.types'
|
|
import {
|
|
formatItemDate,
|
|
getAdvisorItemSecondaryText,
|
|
getAdvisorPanelItemDisplayTitle,
|
|
severityBadgeVariants,
|
|
severityColorClasses,
|
|
severityLabels,
|
|
tabIconMap,
|
|
} from './AdvisorPanel.utils'
|
|
import { EmptyAdvisor } from './EmptyAdvisor'
|
|
import type { Notification } from '@/data/notifications/notifications-v2-query'
|
|
import type { AdvisorSeverity, AdvisorTab } from '@/state/advisor-state'
|
|
|
|
const NoProjectNotice = () => {
|
|
return (
|
|
<div className="absolute top-28 px-6 flex flex-col items-center justify-center w-full gap-y-2">
|
|
<Inbox className="text-foreground-muted" strokeWidth={1} />
|
|
<div className="text-center">
|
|
<p className="heading-default">Project required</p>
|
|
<p className="text-foreground-light text-sm">
|
|
Select a project to view security and performance advisories
|
|
</p>
|
|
</div>
|
|
</div>
|
|
)
|
|
}
|
|
|
|
interface AdvisorPanelBodyProps {
|
|
isLoading: boolean
|
|
isError: boolean
|
|
filteredItems: AdvisorItem[]
|
|
activeTab: AdvisorTab
|
|
severityFilters: AdvisorSeverity[]
|
|
onItemClick: (item: AdvisorItem) => void
|
|
onClearFilters: () => void
|
|
hiddenItemsCount: number
|
|
hasAnyFilters: boolean
|
|
hasProjectRef?: boolean
|
|
}
|
|
|
|
export const AdvisorPanelBody = ({
|
|
isLoading,
|
|
isError,
|
|
filteredItems,
|
|
activeTab,
|
|
severityFilters,
|
|
onItemClick,
|
|
onClearFilters,
|
|
hiddenItemsCount,
|
|
hasAnyFilters,
|
|
hasProjectRef = true,
|
|
}: AdvisorPanelBodyProps) => {
|
|
// Show notice if no project ref and trying to view project-specific tabs
|
|
if (!hasProjectRef && activeTab !== 'messages' && activeTab !== 'all') {
|
|
return <NoProjectNotice />
|
|
}
|
|
|
|
if (isLoading) {
|
|
return (
|
|
<div>
|
|
<GenericSkeletonLoader className="w-full p-4" />
|
|
</div>
|
|
)
|
|
}
|
|
|
|
if (isError) {
|
|
return (
|
|
<div className="h-full mx-4 flex flex-col items-center justify-center gap-y-2">
|
|
<AlertTriangle className="text-destructive" />
|
|
<div className="flex flex-col items-center justify-center">
|
|
<h4 className="text-base font-normal text-foreground-light">Error loading advisories</h4>
|
|
<p className="text-sm text-foreground-lighter">Please try again later.</p>
|
|
</div>
|
|
</div>
|
|
)
|
|
}
|
|
|
|
if (filteredItems.length === 0) {
|
|
return (
|
|
<EmptyAdvisor
|
|
activeTab={activeTab}
|
|
hasFilters={hasAnyFilters}
|
|
onClearFilters={onClearFilters}
|
|
/>
|
|
)
|
|
}
|
|
|
|
return (
|
|
<>
|
|
<div className="flex flex-col">
|
|
{filteredItems.map((item) => {
|
|
const SeverityIcon = tabIconMap[item.tab as Exclude<AdvisorTab, 'all'>]
|
|
const severityClass = severityColorClasses[item.severity]
|
|
const isNotification = item.source === 'notification'
|
|
const notification = isNotification ? (item.original as Notification) : null
|
|
const isUnread = notification?.status === 'new'
|
|
|
|
const primaryText = getAdvisorPanelItemDisplayTitle(item)
|
|
const secondaryText = getAdvisorItemSecondaryText(item)
|
|
const metadataText =
|
|
secondaryText ?? (item.createdAt ? formatItemDate(item.createdAt) : undefined)
|
|
// Date strings (e.g. "a few seconds ago") come from formatItemDate and
|
|
// need sentence-case capitalisation; entity strings (lint / signal) don't.
|
|
const metadataCapitalize = secondaryText === undefined && item.createdAt !== undefined
|
|
|
|
return (
|
|
<div key={`${item.source}-${item.id}`} className="border-b">
|
|
<Button
|
|
type="text"
|
|
className={cn(
|
|
'justify-start w-full block rounded-none h-auto py-3 px-4 hover:text-foreground',
|
|
isUnread && 'bg-surface-100/50'
|
|
)}
|
|
onClick={() => onItemClick(item)}
|
|
>
|
|
<div className="flex items-center justify-between gap-2">
|
|
<div className="flex items-center gap-3 overflow-hidden">
|
|
<SeverityIcon
|
|
size={16}
|
|
strokeWidth={1.5}
|
|
className={cn('flex-shrink-0', severityClass)}
|
|
/>
|
|
<div className="text-left flex flex-col gap-0.5 truncate flex-1 min-w-0">
|
|
<div className="truncate">{primaryText}</div>
|
|
{metadataText && (
|
|
<div className="flex items-center gap-1 text-xs text-foreground-light">
|
|
<span
|
|
className={cn('truncate', metadataCapitalize && 'capitalize-sentence')}
|
|
>
|
|
{metadataText}
|
|
</span>
|
|
</div>
|
|
)}
|
|
</div>
|
|
</div>
|
|
<div className="flex items-center gap-2 flex-shrink-0">
|
|
{item.severity === 'critical' && (
|
|
<Badge variant={severityBadgeVariants[item.severity]}>
|
|
{severityLabels[item.severity]}
|
|
</Badge>
|
|
)}
|
|
<ChevronRight
|
|
size={16}
|
|
strokeWidth={1.5}
|
|
className="flex-shrink-0 text-foreground-lighter"
|
|
/>
|
|
</div>
|
|
</div>
|
|
</Button>
|
|
</div>
|
|
)
|
|
})}
|
|
</div>
|
|
{severityFilters.length > 0 && hiddenItemsCount > 0 && (
|
|
<div className="px-4 py-3">
|
|
<Button type="text" className="w-full" onClick={onClearFilters}>
|
|
Show {hiddenItemsCount} more issue{hiddenItemsCount !== 1 ? 's' : ''}
|
|
</Button>
|
|
</div>
|
|
)}
|
|
</>
|
|
)
|
|
}
|