## Summary 1. **Extract pure logic** out of the 1056-line `SQLEditor.tsx` monolith into unit-tested functions in `SQLEditor.utils.ts`. 2. **Remove `rawSql()` from the SQL editor** and tighten the untrusted→safe boundary per the `safe-sql-execution` model. ## Extracted functions (+ tests) - `getEditorSql(editor, snippetContent?)` — selection → full value → snippet fallback. Returns an **`UntrustedSqlFragment`** so editor/snippet SQL keeps its provenance. - `computeErrorHighlightLine(error, startLineNumber)` — parses the `LINE n:` marker + selection offset. - `assembleCompletionDiff(meta, text)` — before/selection/after assembly for the AI completion diff. - `buildExplainSql(sql, impersonatedRoleState)` — takes an already-safe fragment; EXPLAIN ANALYZE + role impersonation + rollback wrapping. - `buildDebugPromptText(sql, errorMessage)` — the assistant debug prompt string. ## Safe-SQL boundary - `rawSql()` is no longer used anywhere in the SQL editor. - `executeQuery` / `executeExplainQuery` now **require a `SafeSqlFragment`** — safe by construction, so they can never auto-run untrusted SQL. - `acceptUntrustedSql` promotion happens **only in the small run/explain gesture handlers** (`executeQueryFromButton`, `handleRunShortcut`, `handleRunExplain`, and the warning-modal confirm handlers), never buried in the long helpers. ## Verification - `vitest` — 156 pass (11 characterization + 145 utils, incl. new cases) - `pnpm --filter studio typecheck` — clean for all SQL editor files (two unrelated `@sentry/tanstackstart-react` module-resolution errors exist on current master pre-install; not touched by this PR) - `eslint` — 0 errors <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Enhancements** * Improved SQL execution and EXPLAIN workflows with safer handling at run and analysis actions. * Enhanced SQL selection and snippet handling in the editor. * Improved error highlighting to more accurately identify affected lines. * Refined completion previews and debugging prompts for clearer results. * EXPLAIN ANALYZE now supports rollback-wrapped execution and avoids duplicate wrapping. * **Bug Fixes** * Improved behavior when working with selected, empty, or missing SQL content. * Prevented existing EXPLAIN statements from being unnecessarily modified. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Supabase Studio
A dashboard for managing your self-hosted Supabase project, and used on our hosted platform. Built with:
What's included
Studio is designed to work with existing deployments - either the local hosted, docker setup, or our CLI. It is not intended for managing the deployment and administration of projects - that's out of scope.
As such, the features exposed on Studio for existing deployments are limited to those which manage your database:
- Table & SQL editors
- Saved queries are unavailable
- Database management
- Policies, roles, extensions, replication
- API documentation
Managing Project Settings
Project settings are managed outside of the Dashboard. If you use docker compose, you should manage the settings in your docker-compose file. If you're deploying Supabase to your own cloud, you should store your secrets and env vars in a vault or secrets manager.
How to contribute?
- Branch from
masterand name your branches with the following structure{type}/{branch_name}- Type:
chore | fix | feature - The branch name is arbitrary — just make sure it summarizes the work.
- Type:
- When you send a PR to
master, it will automatically tag members of the frontend team for review. - Review the contributing checklists to help test your feature before sending a PR.
- The Dashboard is under active development. You should run
git pullfrequently to make sure you're up to date.
Developer Quickstart
Note
Supabase internal use: To develop on Studio locally with the backend services, see the instructions in the internal
infrastructurerepo.
# You'll need to be on Node v20
# in /studio
## For external contributors
pnpm install # install dependencies
pnpm run dev # start dev server
## For internal contributors
## First clone the private supabase/platform repo and follow instructions for setting up mise
mise studio # Run from supabase/platform alongside `mise infra`
## For all
pnpm run test # run tests
pnpm run test -- --watch # run tests in watch mode
Running within a self-hosted environment
Follow the self-hosting guide to get started.
cd ..
cd docker
docker compose -f docker-compose.yml -f ./dev/docker-compose.dev.yml up
Once you've got that set up, update .env in the studio folder with the corresponding values.
POSTGRES_PASSWORD=
SUPABASE_ANON_KEY=
SUPABASE_SERVICE_KEY=
Then run the following commands to install dependencies and start the dashboard.
npm install
npm run dev
If you would like to configure different defaults for "Default Organization" and "Default Project", you will need to update the .env in the studio folder with the corresponding values.
DEFAULT_ORGANIZATION_NAME=
DEFAULT_PROJECT_NAME=