01# Document the intended URL chain
Separate the app start URL, provider callback, Supabase callback, and final return path.
02# Correct Supabase URL configuration
Set a production-safe Site URL and add only the approved application redirect patterns.
03# Generate redirectTo from trusted configuration
Use an explicit environment value or validated origin rather than a leftover localhost constant.
04# Test each environment independently
Verify preview, production platform URL, and custom domain without broad wildcard allowances.
Preserve the current working revision, change one proven boundary, and verify the published path in a clean session.