Closes the funnel. Before this the product could match two people and then
stopped: `quotes`, `bookings` and `reviews` had tables and state machines and
nothing that wrote a row, the entry deck's right swipe was wired to an empty
handler, and every address resolved to the city centre.
Jobs tab and chat
- message router: thread, send, markRead, unreadTotal. A thread is a MATCH, not
a job — one job with three interested pros is three private conversations.
- Current/Past segments derived from ACTIVE_JOB_STATUSES, job detail listing the
pros who accepted, and the conversation itself with attachments.
Hiring from the deck
- A right swipe on the entry deck opened nothing. It now resolves "which job?"
through a sheet — sign in, pick an open job, or post one — and calls the same
deck.swipe the per-job deck does, so the open-request cap and row lock apply
exactly once. Swipes are vetoable so closing the sheet returns the card.
Geocoding
- ST_Distance and ST_DWithin rank and filter every deck, and both operands were
placeholders. Addresses now resolve through Mapbox (permanent=true, which is
what licenses storing the coordinates), the server resolves points rather than
trusting client-supplied lat/lng, and every stored point records how it was
obtained. A `city`-precision base cannot reach the verification queue.
Quote -> booking -> review
- The commercial chain, minus payments. Accepting a quote is the only place a
booking is created; confirming completion is what unlocks reviews and moves
the pro's completed_jobs.
- Reviews publish double-blind with no sweeper: each is written with
published_at already set to its embargo deadline and every read filters
published_at <= now(), so it publishes itself. The second review pulls both
forward. A silent counterparty cannot bury a bad review by never replying.
State machine changes, both deliberate
- booked -> matched: a cancelled booking is not a cancelled job.
- scheduled -> awaiting_confirmation: in_progress is optional, so a pro who
never tapped Start can still say the work is done.
Test suite
- api tests ran files in parallel against one database and failed roughly one
run in three on whichever file lost the race. Serialised, and three fixtures
that grabbed "the first client" pinned to the seeded accounts.
Also includes work from a parallel session: admin verification queue, pro
public profile and reviews read path, notification sending, denormalised stats
recompute, search, and observability.
318 tests passing; typecheck and lint clean across 7 packages.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Stands up packages/api so the swipe path stops trusting its caller, and
puts the auth library behind an interface we own.
- packages/api: tRPC v11 with a Session type WE define, not one
re-exported from an auth library. Swapping providers means rewriting
one SessionResolver, not touching a router.
- Procedure layers: public / protected / client / pro / verifiedPro /
admin. Admin routes 404 rather than 403 so they cannot be probed.
- deck router replaces the untrusted server action. Ownership is checked
on every operation and returns NOT_FOUND, never FORBIDDEN, so job ids
cannot be enumerated. 23 tests, mostly authorization.
- packages/storage: presigned direct-to-R2 uploads. The server picks the
key, so a caller can only write under their own user id. 14 tests.
Three defects found and fixed:
- The lazy db Proxy failed drizzle's is(db, PgDatabase) because it did
not trap getPrototypeOf. Auth adapters dispatch on exactly that check,
so this would have failed at runtime inside third-party code. Fixed
and pinned with a regression test.
- The open-request cap was a read-then-write race: concurrent swipes
could both read 4 and both insert. Now one transaction with the job
row locked. The cap is checked before the tombstone is written, so a
rejected swipe leaves no trace and the card stays on the deck.
- superjson was configured in two of the three required places. Without
the QueryClient dehydrate/hydrate pair, RSC-prefetched data arrives as
a raw envelope with no type error to warn you.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>