Stands up packages/api so the swipe path stops trusting its caller, and
puts the auth library behind an interface we own.
- packages/api: tRPC v11 with a Session type WE define, not one
re-exported from an auth library. Swapping providers means rewriting
one SessionResolver, not touching a router.
- Procedure layers: public / protected / client / pro / verifiedPro /
admin. Admin routes 404 rather than 403 so they cannot be probed.
- deck router replaces the untrusted server action. Ownership is checked
on every operation and returns NOT_FOUND, never FORBIDDEN, so job ids
cannot be enumerated. 23 tests, mostly authorization.
- packages/storage: presigned direct-to-R2 uploads. The server picks the
key, so a caller can only write under their own user id. 14 tests.
Three defects found and fixed:
- The lazy db Proxy failed drizzle's is(db, PgDatabase) because it did
not trap getPrototypeOf. Auth adapters dispatch on exactly that check,
so this would have failed at runtime inside third-party code. Fixed
and pinned with a regression test.
- The open-request cap was a read-then-write race: concurrent swipes
could both read 4 and both insert. Now one transaction with the job
row locked. The cap is checked before the tombstone is written, so a
rejected swipe leaves no trace and the card stays on the deck.
- superjson was configured in two of the three required places. Without
the QueryClient dehydrate/hydrate pair, RSC-prefetched data arrives as
a raw envelope with no type error to warn you.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Greenfield scaffold for Linkder, a swipe-to-hire marketplace for local
professional services.
- pnpm/turbo monorepo: apps/web, packages/{shared,db}
- Postgres 16 + PostGIS via docker compose (ports 5442/6389 to avoid
clashing with other local stacks)
- Drizzle schema, 23 tables, geography(Point,4326) with GiST indexes
- Domain core in packages/shared: integer-cent money, status transition
graphs, deck ranking weights, cancellation policy — 46 unit tests
- Deck query: filtering in Postgres on the GiST index, ranking in JS so
the weights stay tunable — 18 integration tests against a seeded DB
- Deterministic seed placing pros at known distances, including three
that must NOT appear on a deck (out of radius, unverified, away)
- Next.js 15 app shell with a working swipe deck
- CI: typecheck, lint, test, build against live postgres+redis
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>