profiles.id referenced auth.users. Sign-in goes through Auth.js now and
creates nothing there, so a new colleague could sign in, receive an
app_users row, and then be impossible to authorise: the profiles row needed
to grant HR access could not be inserted. She would see "Kein HR-Zugriff"
with no way to change it.
All eight foreign keys in the public schema now point at app_users, walked
from the catalogue rather than written out — their names come from different
migrations and one transcribed wrongly means it silently stays behind. The
delete behaviour is preserved: profiles still cascades from the account,
audit and note fields do not, because an entry must not vanish when an
account is removed.
Every referenced value was already present in app_users, so nothing moved;
only the guarantee changed. A backfill from profiles runs first anyway, for
copies of this database where someone created something in between.
The check at the end does the thing that matters: it creates a second
account with a profile and removes it again. Counting constraints would have
passed while the actual case still failed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>