Skip to content

Production database migration receipt — 5 October 2026 ​

Project: New Debelu Marketplace (havugmqmyplqgbrlthhs, eu-central-2). The user renewed authorization to apply migrations through MCP and reconnected the owning Supabase account.

Applied successfully ​

19 Supabase MCP migration calls succeeded: local migrations 20261011000100 through 20261011001400 inclusive, 20261011001600, 20261011001900 through 20261011002100, and 20261011002400_align_manually_installed_command_functions.sql.

Migration 024 replaces only two older function definitions from manually installed campaign/refund workflows. Existing tables, rows, ownership and grants are preserved. Migration 000's retired legacy adjustment privilege was already absent. The full function definitions of manually installed 015 were already current; 017 and 018 were aligned by 024 instead of recreating their tables.

Local suffixRecorded remote version
001 support notification outbox20261005063815
002 moderation governance20261005063818
003 chunked audit exports20261005063819
004 order fee snapshots20261005063829
005 bounded notification status20261005063831
006 privacy export artifacts20261005063833
007 queue observations20261005063834
008 checkout payment intents20261005063836
009 payment investigation20261005063837
010 reviewed payout batches20261005063839
011 payout transfer intents20261005063841
012 moderation appeals20261005063843
013 payout exceptions20261005063845
014 payout reconciliation20261005063847
016 privilege hardening20261005063950
024 existing function alignment20261005064008
019 scoped erasure execution20261005064010
020 expanded privacy exports20261005064012
021 governed order status20261005064014

MCP recorded current-date versions and retained canonical local version names in migration names. Earlier manually installed baseline files are not fully represented in migration history. Reconcile that history before an automatic Supabase CLI push; do not blindly replay already installed DDL. Reserved future migrations 022/023 have no implementation files and were not applied.

Verification ​

All 134 latest command function bodies from local migrations 001–021 matched production after normalization of line endings. All 19 inspected command tables had RLS enabled, no anonymous/authenticated direct SELECT grants, and no service-role direct INSERT/UPDATE/DELETE/TRUNCATE grants. Reviewed command entry points deny anonymous/authenticated execution while allowing required service execution. Three fee snapshot columns and the capture trigger were present. Retired legacy financial adjustment and order helper execution remained denied.

Checkpoint ed4af09f passed both quality verification and full baseline/native database CI in run 37271444242. Hosted verification used schema/privilege reads; no real refund, payout, campaign delivery or privacy deletion was executed. Database installation does not establish application deployment or complete the wider enterprise program.

Existing security advisor findings requiring review ​

Supabase advisors continue to flag security-definer views public.vendor_product_stats, public.public_vendor_profiles and public.marketplace_products; legacy mutable function search paths; anonymous/authenticated definer function execution; and disabled leaked-password protection. These were not automatically modified during deployment. Command tables intentionally have no browser policies. Review intended access before changing policies or grants.

References: definer views, search paths, anonymous definer execution, password protection.

Released under Proprietary Enterprise License.