caterium-app/ops
pavlov346346-source a281150f12 docs: record the missing sun_employee_prepare/finalize_v28 migration
sun_employee_prepare_v28 and sun_employee_finalize_v28 - the RPCs
caterium-create-employee's whole authorization model rests on - were
applied directly to the production database and were never committed,
so the actual authorization logic wasn't auditable from the repo.
Recorded verbatim via pg_get_functiondef() against the live database
on 2026-09-12 (read-only; nothing was re-applied). Confirmed both
match what the security audit inferred from the Edge Function's
error-message handling: caller identity + workspace-owner/platform-admin
check + plan/feature gates + member limits, all enforced here rather
than in the Edge Function itself.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-12 14:16:16 +03:00
..
sql docs: record the missing sun_employee_prepare/finalize_v28 migration 2026-09-12 14:16:16 +03:00
supabase-selfhosted Ops: add self-hosted Supabase stack for Timeweb Cloud migration 2026-09-11 16:20:45 +03:00
timeweb Ops: retarget Timeweb auto-deploy to app.caterium.ru, not the apex domain 2026-09-10 20:39:16 +03:00
prepare-catalog-photos.js Caterium v17.6.0 - GitHub Cloudflare autodeploy 2026-09-07 15:29:20 +03:00
server.js Caterium v17.6.0 - GitHub Cloudflare autodeploy 2026-09-07 15:29:20 +03:00