Skip to content

[pull] master from supabase:master - #1289

Merged
pull[bot] merged 9 commits into
code:masterfrom
supabase:master
Sep 28, 2026
Merged

pull[bot] merged 9 commits into
code:masterfrom
supabase:master

Conversation

@pull

@pull pull Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

fsansalvadore and others added 9 commits September 28, 2026 13:56
The `elastic` icon wasn't following the same styling of other icons in
our design system.
This PR uniforms it.

| Before           | After              |
| -------------- | ------ |
| <img width="121" height="81" alt="Screenshot 2026-09-28 at 13 46 47"
src="https://github.com/user-attachments/assets/f22f53b0-4b13-4d7a-b6f3-ce92664782de"
/> | <img width="104" height="90" alt="Screenshot 2026-09-28 at 13 47
18"
src="https://github.com/user-attachments/assets/39edc6f3-614a-4c12-8dd6-31ba953507be"
/> |

Link to preview icon:
https://design-system-git-chore-elastic-icon-supabase.vercel.app/design-system/docs/icons
Automated weekly decrease of ESLint ratchet baselines.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
## Problem

The `@supabase/server` reference goes straight from Installing to the
generated API reference. It has no worked example. The middleware
reference has a "Usage examples" page in that spot (#50461).

## Solution

A new "Usage examples" partial sits between Installing and the generated
reference. It has three examples, taken from the server repo's
`docs/getting-started.md`:

- **Protect an endpoint with a user JWT:** `withSupabase({ auth: 'user'
})`, its CORS handling, and `ctx.supabase` vs `ctx.supabaseAdmin`.
- **Serve a public endpoint:** `auth: 'none'`, plus the `verify_jwt =
false` setting Edge Functions need.
- **Build the context yourself:** `createSupabaseContext` returning `{
data, error }`.

Files:

- `spec/reference/server/v1/partials/usage-examples.mdx` and its
`docs/ref/server/` mirror
- `usage-examples` added to `partialsOrder` in
`spec/reference/server/v1/config.json`

Every claim is checked against the source code in `supabase/server`,
`supabase/middleware`, and `supabase/cli`.

## Preview links

| Site | Preview |
| ---- | ------- |
| Docs |
[/docs/reference/server/usage-examples](https://docs-git-docs-server-usage-examples-supabase.vercel.app/docs/reference/server/usage-examples)
|

## Review instructions

1. Open the preview link.
2. Check that "Usage examples" appears in the sidebar between Installing
and the generated reference.
3. Check that the three examples render with the code on the right.

## Checklist

- [ ] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added server usage examples for protecting endpoints, serving public
endpoints, and creating Supabase context manually.
* Documented runtime requirements, JWT verification settings, CORS
behavior, and the differences between caller-scoped and admin access.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Cleaned up the `compute` icon which wasn't aligned and perfectly
isometric.

| Before           | After              |
| -------------- | ------ |
| <img width="240" height="209" alt="Screenshot 2026-09-28 at 12 56 10"
src="https://github.com/user-attachments/assets/ffe0232f-5933-4310-886f-2de8caa53712"
/> | <img width="269" height="208" alt="Screenshot 2026-09-28 at 12 56
13"
src="https://github.com/user-attachments/assets/0e4ab8ab-6818-473b-a786-42ca3aae32e4"
/> |
…50977)

<!-- ccr-slack-attribution -->
_Requested by **Charis Lam** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790599888647059?thread_ts=1790599888.647059&cid=C0161K73J1J)_

## Problem

The Studio ESLint "ratchet"
(`apps/studio/scripts/ratchet-eslint-rules.ts`, baseline in
`apps/studio/.github/eslint-rule-baselines.json`, tracked rules in
`apps/studio/scripts/ratchet-rules.json`) lets certain rules stay at
`warn` severity while CI blocks the *count* of violations from
increasing. Several of those tracked rules had already reached a
baseline of 0 allowed violations, meaning there's nothing left to
ratchet — they should be enforced directly instead of tracked
indirectly.

## Solution

**Before:** `no-restricted-imports`, `jsx-a11y/aria-props`,
`jsx-a11y/aria-proptypes`, `jsx-a11y/role-supports-aria-props`,
`jsx-a11y/anchor-has-content`, `jsx-a11y/aria-role`,
`jsx-a11y/no-aria-hidden-on-focusable`, `jsx-a11y/tabindex-no-positive`,
`jsx-a11y/no-distracting-elements`, and `react-hook-form/no-use-watch`
were all tracked in the ratchet baseline with a count of 0, and (apart
from `no-restricted-imports`, see below) configured as ESLint `warn` in
`apps/studio/eslint.config.cjs`.

**After:** each of those rules is removed from
`apps/studio/.github/eslint-rule-baselines.json` (both the `rules` count
and the now-empty `ruleFiles` entry) and from
`apps/studio/scripts/ratchet-rules.json`. Their severity in
`apps/studio/eslint.config.cjs` is bumped from `warn` to `error` so
they're enforced directly by lint going forward instead of being tracked
via the ratchet. `no-restricted-imports` was a special case: a later
config block in `apps/studio/eslint.config.cjs` already overrides the
shared `warn` default with `error` (confirmed via `eslint
--print-config`), so only the ratchet bookkeeping needed removing for
that rule — no severity change was needed.

Promoting `jsx-a11y/role-supports-aria-props` to `error` surfaced one
real violation that the ratchet's non-test-file filter had been hiding:
a mock `<button>` in `LocalDropdown.test.tsx` set `aria-checked`, which
that role doesn't support. Removed the unused `aria-checked` attribute
from the mock (it wasn't asserted on by any test).

Every other rule still tracked by the ratchet (e.g.
`@typescript-eslint/no-explicit-any`, `react-hooks/exhaustive-deps`,
`no-restricted-exports`, …) has a baseline above 0 and was left
untouched.

### How verified

- `pnpm --filter studio run lint:ratchet` → `Stable: No regressions for
selected rules.`
- `pnpm --filter studio run lint` → `0 errors, 2430 warnings` (no new
errors from the severity bumps)
- `npx vitest run components/interfaces/LocalDropdown.test.tsx` → 3/3
passing after the mock fix
- `npx prettier --check` on all touched files → clean
- `npx tsc --noEmit` shows one pre-existing, unrelated error in
`packages/ui-patterns` (reproduced identically on `master` before this
change)

## Review instructions

1. Confirm `apps/studio/.github/eslint-rule-baselines.json` and
`apps/studio/scripts/ratchet-rules.json` no longer list the 10 rules
named above.
2. Confirm those same rules (except `no-restricted-imports`, already
`error`) are now `'error'` in `apps/studio/eslint.config.cjs`.
3. Run `pnpm --filter studio run lint:ratchet` and `pnpm --filter studio
run lint` locally to confirm both pass.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP

---
_Generated by [Claude
Code](https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP)_

Co-authored-by: Claude <noreply@anthropic.com>
## Problem

on monitoring agent pages the prompt lives in a "prompt" tab next to
agent ones, while each agent tab ended with "paste the prompt" users
have to work out that the prompt is sitting in that previous tab

## Solution

this pr is a proposal to set agent setup as a two stepper `1` for the
prompt panel `2` holds the agent tabs:

- extracts prompt into a first step
- moves agent tabs within their own step
- polishes agent docs to match recent ui updates
- sets `prompt` as an anchor link within agent tabs 

| state | preview |
| -------|------|
| before | <img width="823" height="452" alt="image"
src="https://github.com/user-attachments/assets/a6a01832-ea73-48c1-b31d-25a0ef970e4e"
/> |
| after | <img width="823" height="716" alt="image"
src="https://github.com/user-attachments/assets/f5014ad0-1555-4578-b4b1-5bf2733b4d37"
/> |

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. visit
[/automate-with-agents/health](https://docs-git-docs-agent-setup-stepper-supabase.vercel.app/docs/guides/observability/automate-with-agents/health#set-up-the-agent)

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Agent setup instructions are organized into prompt-copying and
scheduling steps, with links to harness documentation.
  * Code tabs support icons and controlled selection.
  * Source code samples support adjustable footer notches.
* **Bug Fixes**
  * Step numbers now display the correct shadow.
* Links to page anchors now scroll to, focus, and highlight their
targets, while respecting reduced-motion preferences.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
)

<!-- ccr-slack-attribution -->
_Requested by **Charis Lam** · [Slack
thread](https://supabase.slack.com/archives/C0161K73J1J/p1790599888647059?thread_ts=1790599888.647059&cid=C0161K73J1J)_

## Problem

The weekly "Decrease studio lint ratchet baselines" workflow
(`.github/workflows/studio-lint-ratchet-decrease.yml`) mechanically
decreases each tracked ESLint rule's baseline count in
`apps/studio/.github/eslint-rule-baselines.json` and opens/updates a PR.
When a rule's count reaches exactly 0, there's nothing left to ratchet —
a human (or agent) needs to remove it from ratchet tracking
(`apps/studio/scripts/ratchet-rules.json` and the baseline file) and
bump its ESLint severity to `error`, as was just done manually in
#50977. Nobody is currently notified when this threshold is crossed, so
it can sit unnoticed.

## Solution

**Before:** the job silently commits the decreased baselines and
opens/updates its PR with no signal that any rule just hit 0.

**After:** a new step runs after the baseline commit/PR step, only when
that step found changes (via a new `id: decrease-baselines` and a
`changed` step output, added without touching the existing decrease
logic itself — just capturing its existing control flow into an output).
It parses the final `apps/studio/.github/eslint-rule-baselines.json` on
disk for any rule whose count is exactly `0`. If any are found, it posts
a Slack message via `curl` to a webhook, tagging `@Claude` in
`#team-frontend` with the rule names and a link to the PR the job just
created/updated, asking it to do the same triage as #50977 (remove from
ratchet tracking, bump severity to `error`). If no rule is at 0, it
skips silently.

The webhook URL comes from a new repo secret,
`secrets.SLACK_TEAM_FRONTEND_WEBHOOK_URL`, which **does not exist yet**.
**A human needs to create a Slack incoming webhook for #team-frontend
and add its URL as the `SLACK_TEAM_FRONTEND_WEBHOOK_URL` repository
secret before this step will actually post anything.** Until then, the
step detects the missing/empty secret and only logs a `::warning::`,
exiting 0 — it will never fail the job.

## Review instructions

1. Read `.github/workflows/studio-lint-ratchet-decrease.yml`: confirm
the existing decrease/commit/PR step is unchanged except for the added
`id: decrease-baselines` and the two `echo ... >> "$GITHUB_OUTPUT"`
lines that record whether anything changed and the PR URL.
2. Confirm the new final step only runs `if:
steps.decrease-baselines.outputs.changed == 'true'`.
3. Confirm the new step parses
`apps/studio/.github/eslint-rule-baselines.json`'s `rules` map for
entries equal to `0`, and skips (exit 0, no curl) when none are found.
4. Confirm the `curl` call is gated on `SLACK_WEBHOOK_URL` being
non-empty, and that a failed `curl` only emits `::warning::` rather than
failing the step (`set -euo pipefail` is still safe because the failure
is inside an `if !`).
5. Note that this PR alone does not make the notification fire:
`SLACK_TEAM_FRONTEND_WEBHOOK_URL` must be provisioned as a repo secret
(Settings → Secrets and variables → Actions) from a Slack incoming
webhook for #team-frontend first.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01LZThbcWV5U1r5cvUDKPVQP

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Charis Lam <26616127+charislam@users.noreply.github.com>
…50872)

## Summary
- Adds a fallback message ("Taking longer than expected?... contact
support@supabase.io") shown after 7s if Studio fails to fully load, for
the Next.js runtime — mirrors the existing TanStack-only
`ShellFallback`, which had no Next.js equivalent
- Fixes the support email in the existing TanStack `ShellFallback` (was
`support@supabase.com`, should be `support@supabase.io`)
- Extracts the shared copy (message, email, delay) into one file so both
fallbacks stay in sync

## Why
Linear FE-4460: users reported the Dashboard going completely blank with
no way to reach support when a JS chunk failed to load. The Next.js
runtime (the current default) had no fallback at all for this case.

## Test plan
- [ ] Normal page load: fallback never appears
- [ ] Simulated stuck boot (mount signal disabled): fallback appears
after 7s with correct copy/email, no layout bugs
- [ ] Same two checks on the TanStack runtime
(`STUDIO_FRAMEWORK=tanstack`)
- [ ] `pnpm --filter studio run typecheck` / `lint:ratchet` pass

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a loading fallback that appears if the app takes too long to
load, with guidance to clear browser cookies and reload.
* On self-hosted platforms, the fallback includes a support contact
link.
  * The fallback is automatically hidden once the app loads.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
…API (#50931)

## Summary

* Adds `/api/status-page` (Next route + TanStack wrapper), backed by the
[incident.io](<http://incident.io>) Widget API, annotating each item
with `visible`, `show_banner`, and (for scheduled maintenances)
`banner_lead_days`.
* Deployment-mode visibility is driven by a new
`status_page:visibility_field_ids` custom-content key.
* Widget array parsing is fault-tolerant: a malformed item in one array
is dropped and logged rather than failing the whole response, so one bad
item can't hide a real ongoing incident.
* 429s from [incident.io](<http://incident.io>) are retried with
equal-jitter exponential backoff, respecting `Retry-After`, up to 2
retries.
* Nothing consumes this endpoint yet — it replaces no existing behavior
and changes nothing user-visible. Later PRs (this is PR 1 of a stack)
wire up consumers behind the `incidentIoStatusPage` ConfigCat flag.

Part of
[FE-4057](https://linear.app/supabase/issue/FE-4057/frontend-bannerbot-reconfigured)
— see Linear for full design context.

## Test plan

- [X] `pnpm --filter studio run typecheck`
- [X] `pnpm --filter studio run lint:ratchet`
- [X] `pnpm knip --workspace apps/studio`
- [X] `pnpm test:prettier`
- [X] `pnpm --filter studio exec vitest run status-page` — 44 tests
passing, including a regression test built from a real production
[incident.io](<http://incident.io>) payload that initially failed to
parse, and a compile-time type-safety regression test for the
array-parsing helper

Co-authored-by: Claude Code
[charis@supabase.io](<mailto:charis@supabase.io>)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a status page that displays ongoing incidents and maintenance,
with visibility and banner settings based on linked incident details.
* Status page data is available through a new API endpoint, with caching
for successful responses and degraded results.
* **Bug Fixes**
* Status page data can still display when some linked incident details
are unavailable; affected results are marked as degraded.
* Improved handling of invalid widget entries so they don’t prevent
valid items from being processed.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Code <charis@supabase.io>
@pull pull Bot locked and limited conversation to collaborators Sep 28, 2026
@pull pull Bot added the ⤵️ pull label Sep 28, 2026
@pull
pull Bot merged commit b2cf369 into code:master Sep 28, 2026
3 of 23 checks passed
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Sep 28, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

⤵️ pull documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants