-- Gravity Browser Agent durable task state. Run once in the existing project. create table if not exists public.agent_tasks ( id text primary key, task_type text not null, status text not null, revision bigint not null default 0, idempotency_key text unique, params_encrypted text, public_payload jsonb not null default '{}'::jsonb, created_at timestamptz not null default now(), started_at timestamptz, finished_at timestamptz, deadline_at timestamptz, heartbeat_at timestamptz, updated_at timestamptz not null default now() ); create table if not exists public.agent_events ( task_id text not null references public.agent_tasks(id) on delete cascade, sequence bigint not null, event_type text not null, payload jsonb not null default '{}'::jsonb, created_at timestamptz not null default now(), primary key (task_id, sequence) ); create table if not exists public.agent_checkpoints ( task_id text primary key references public.agent_tasks(id) on delete cascade, revision bigint not null, encrypted_state text not null, expires_at timestamptz, updated_at timestamptz not null default now() ); create table if not exists public.agent_artifacts ( id text primary key, task_id text not null references public.agent_tasks(id) on delete cascade, filename text not null, media_type text, size_bytes bigint, metadata jsonb not null default '{}'::jsonb, expires_at timestamptz, created_at timestamptz not null default now() ); alter table public.agent_tasks enable row level security; alter table public.agent_events enable row level security; alter table public.agent_checkpoints enable row level security; alter table public.agent_artifacts enable row level security; -- The backend uses the service role. No anon/authenticated client policies are -- intentionally created; mobile clients must go through the authenticated API.