sun_employee_prepare_v28 and sun_employee_finalize_v28 - the RPCs caterium-create-employee's whole authorization model rests on - were applied directly to the production database and were never committed, so the actual authorization logic wasn't auditable from the repo. Recorded verbatim via pg_get_functiondef() against the live database on 2026-09-12 (read-only; nothing was re-applied). Confirmed both match what the security audit inferred from the Edge Function's error-message handling: caller identity + workspace-owner/platform-admin check + plan/feature gates + member limits, all enforced here rather than in the Edge Function itself. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| sql | ||
| supabase-selfhosted | ||
| timeweb | ||
| prepare-catalog-photos.js | ||
| server.js | ||