M2: the full job lifecycle — chat, hiring, geocoding, quotes, bookings, reviews
Closes the funnel. Before this the product could match two people and then stopped: `quotes`, `bookings` and `reviews` had tables and state machines and nothing that wrote a row, the entry deck's right swipe was wired to an empty handler, and every address resolved to the city centre. Jobs tab and chat - message router: thread, send, markRead, unreadTotal. A thread is a MATCH, not a job — one job with three interested pros is three private conversations. - Current/Past segments derived from ACTIVE_JOB_STATUSES, job detail listing the pros who accepted, and the conversation itself with attachments. Hiring from the deck - A right swipe on the entry deck opened nothing. It now resolves "which job?" through a sheet — sign in, pick an open job, or post one — and calls the same deck.swipe the per-job deck does, so the open-request cap and row lock apply exactly once. Swipes are vetoable so closing the sheet returns the card. Geocoding - ST_Distance and ST_DWithin rank and filter every deck, and both operands were placeholders. Addresses now resolve through Mapbox (permanent=true, which is what licenses storing the coordinates), the server resolves points rather than trusting client-supplied lat/lng, and every stored point records how it was obtained. A `city`-precision base cannot reach the verification queue. Quote -> booking -> review - The commercial chain, minus payments. Accepting a quote is the only place a booking is created; confirming completion is what unlocks reviews and moves the pro's completed_jobs. - Reviews publish double-blind with no sweeper: each is written with published_at already set to its embargo deadline and every read filters published_at <= now(), so it publishes itself. The second review pulls both forward. A silent counterparty cannot bury a bad review by never replying. State machine changes, both deliberate - booked -> matched: a cancelled booking is not a cancelled job. - scheduled -> awaiting_confirmation: in_progress is optional, so a pro who never tapped Start can still say the work is done. Test suite - api tests ran files in parallel against one database and failed roughly one run in three on whichever file lost the race. Serialised, and three fixtures that grabbed "the first client" pinned to the seeded accounts. Also includes work from a parallel session: admin verification queue, pro public profile and reviews read path, notification sending, denormalised stats recompute, search, and observability. 318 tests passing; typecheck and lint clean across 7 packages. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
+12
-41
@@ -1,48 +1,19 @@
|
||||
import { sendSms } from '@linkder/notify';
|
||||
|
||||
/**
|
||||
* SMS delivery for one-time codes.
|
||||
*
|
||||
* In development there is no provider and no spend: the code is logged to the
|
||||
* server console so you can sign in. That path is hard-gated on NODE_ENV so a
|
||||
* production deploy without Twilio credentials FAILS rather than silently
|
||||
* printing login codes into a log aggregator.
|
||||
* The transport itself now lives in @linkder/notify, so the API package can
|
||||
* reach it too — a tRPC procedure cannot import from `apps/web`, and the sign-in
|
||||
* code and a "somebody wants to hire you" text have no business going out
|
||||
* through two different Twilio clients with two different failure policies.
|
||||
*
|
||||
* The copy stays here. This is the one message that is part of the auth flow
|
||||
* rather than part of the product, and it says things the others must not.
|
||||
*/
|
||||
const isProduction = process.env.NODE_ENV === 'production';
|
||||
|
||||
export async function sendVerificationSms(to: string, code: string): Promise<void> {
|
||||
const sid = process.env.TWILIO_ACCOUNT_SID;
|
||||
const token = process.env.TWILIO_AUTH_TOKEN;
|
||||
const from = process.env.TWILIO_FROM_NUMBER;
|
||||
|
||||
if (!sid || !token || !from) {
|
||||
if (isProduction) {
|
||||
throw new Error(
|
||||
'SMS is not configured (TWILIO_ACCOUNT_SID / TWILIO_AUTH_TOKEN / TWILIO_FROM_NUMBER). ' +
|
||||
'Refusing to fall back to console logging in production.',
|
||||
);
|
||||
}
|
||||
console.info(`\n [dev SMS] verification code for ${to}: ${code}\n`);
|
||||
return;
|
||||
}
|
||||
|
||||
const response = await fetch(
|
||||
`https://api.twilio.com/2010-04-01/Accounts/${sid}/Messages.json`,
|
||||
{
|
||||
method: 'POST',
|
||||
headers: {
|
||||
Authorization: `Basic ${Buffer.from(`${sid}:${token}`).toString('base64')}`,
|
||||
'Content-Type': 'application/x-www-form-urlencoded',
|
||||
},
|
||||
body: new URLSearchParams({
|
||||
To: to,
|
||||
From: from,
|
||||
Body: `${code} is your Linkder code. It expires in 5 minutes. We will never ask you for it.`,
|
||||
}),
|
||||
},
|
||||
await sendSms(
|
||||
to,
|
||||
`${code} is your Linkder code. It expires in 5 minutes. We will never ask you for it.`,
|
||||
);
|
||||
|
||||
if (!response.ok) {
|
||||
// Never log the code itself in production.
|
||||
const detail = await response.text().catch(() => '<no body>');
|
||||
throw new Error(`Twilio rejected the message (${response.status}): ${detail}`);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user