Production database migration receipt — 5 October 2026
Project: New Debelu Marketplace (havugmqmyplqgbrlthhs, eu-central-2). The user renewed authorization to apply migrations through MCP and reconnected the owning Supabase account.
Applied successfully
19 Supabase MCP migration calls succeeded: local migrations 20261011000100 through 20261011001400 inclusive, 20261011001600, 20261011001900 through 20261011002100, and 20261011002400_align_manually_installed_command_functions.sql.
Migration 024 replaces only two older function definitions from manually installed campaign/refund workflows. Existing tables, rows, ownership and grants are preserved. Migration 000's retired legacy adjustment privilege was already absent. The full function definitions of manually installed 015 were already current; 017 and 018 were aligned by 024 instead of recreating their tables.
| Local suffix | Recorded remote version |
|---|---|
| 001 support notification outbox | 20261005063815 |
| 002 moderation governance | 20261005063818 |
| 003 chunked audit exports | 20261005063819 |
| 004 order fee snapshots | 20261005063829 |
| 005 bounded notification status | 20261005063831 |
| 006 privacy export artifacts | 20261005063833 |
| 007 queue observations | 20261005063834 |
| 008 checkout payment intents | 20261005063836 |
| 009 payment investigation | 20261005063837 |
| 010 reviewed payout batches | 20261005063839 |
| 011 payout transfer intents | 20261005063841 |
| 012 moderation appeals | 20261005063843 |
| 013 payout exceptions | 20261005063845 |
| 014 payout reconciliation | 20261005063847 |
| 016 privilege hardening | 20261005063950 |
| 024 existing function alignment | 20261005064008 |
| 019 scoped erasure execution | 20261005064010 |
| 020 expanded privacy exports | 20261005064012 |
| 021 governed order status | 20261005064014 |
MCP recorded current-date versions and retained canonical local version names in migration names. Earlier manually installed baseline files are not fully represented in migration history. Reconcile that history before an automatic Supabase CLI push; do not blindly replay already installed DDL. Reserved future migrations 022/023 have no implementation files and were not applied.
Verification
All 134 latest command function bodies from local migrations 001–021 matched production after normalization of line endings. All 19 inspected command tables had RLS enabled, no anonymous/authenticated direct SELECT grants, and no service-role direct INSERT/UPDATE/DELETE/TRUNCATE grants. Reviewed command entry points deny anonymous/authenticated execution while allowing required service execution. Three fee snapshot columns and the capture trigger were present. Retired legacy financial adjustment and order helper execution remained denied.
Checkpoint ed4af09f passed both quality verification and full baseline/native database CI in run 37271444242. Hosted verification used schema/privilege reads; no real refund, payout, campaign delivery or privacy deletion was executed. Database installation does not establish application deployment or complete the wider enterprise program.
Existing security advisor findings requiring review
Supabase advisors continue to flag security-definer views public.vendor_product_stats, public.public_vendor_profiles and public.marketplace_products; legacy mutable function search paths; anonymous/authenticated definer function execution; and disabled leaked-password protection. These were not automatically modified during deployment. Command tables intentionally have no browser policies. Review intended access before changing policies or grants.
References: definer views, search paths, anonymous definer execution, password protection.