Closes the funnel. Before this the product could match two people and then stopped: `quotes`, `bookings` and `reviews` had tables and state machines and nothing that wrote a row, the entry deck's right swipe was wired to an empty handler, and every address resolved to the city centre. Jobs tab and chat - message router: thread, send, markRead, unreadTotal. A thread is a MATCH, not a job — one job with three interested pros is three private conversations. - Current/Past segments derived from ACTIVE_JOB_STATUSES, job detail listing the pros who accepted, and the conversation itself with attachments. Hiring from the deck - A right swipe on the entry deck opened nothing. It now resolves "which job?" through a sheet — sign in, pick an open job, or post one — and calls the same deck.swipe the per-job deck does, so the open-request cap and row lock apply exactly once. Swipes are vetoable so closing the sheet returns the card. Geocoding - ST_Distance and ST_DWithin rank and filter every deck, and both operands were placeholders. Addresses now resolve through Mapbox (permanent=true, which is what licenses storing the coordinates), the server resolves points rather than trusting client-supplied lat/lng, and every stored point records how it was obtained. A `city`-precision base cannot reach the verification queue. Quote -> booking -> review - The commercial chain, minus payments. Accepting a quote is the only place a booking is created; confirming completion is what unlocks reviews and moves the pro's completed_jobs. - Reviews publish double-blind with no sweeper: each is written with published_at already set to its embargo deadline and every read filters published_at <= now(), so it publishes itself. The second review pulls both forward. A silent counterparty cannot bury a bad review by never replying. State machine changes, both deliberate - booked -> matched: a cancelled booking is not a cancelled job. - scheduled -> awaiting_confirmation: in_progress is optional, so a pro who never tapped Start can still say the work is done. Test suite - api tests ran files in parallel against one database and failed roughly one run in three on whichever file lost the race. Serialised, and three fixtures that grabbed "the first client" pinned to the seeded accounts. Also includes work from a parallel session: admin verification queue, pro public profile and reviews read path, notification sending, denormalised stats recompute, search, and observability. 318 tests passing; typecheck and lint clean across 7 packages. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Linkder
Swipe-to-hire marketplace for local professional services. A client describes a job once, then swipes through verified local pros — plumbers, electricians, handymen. A right swipe sends the job to that pro; the pro accepts; chat, quote, booking, escrow payment and reviews all happen in the app.
Web first. The API layer is designed so a React Native app can reuse it verbatim.
Status
M0 — foundation. Complete and verified.
| Milestone | State |
|---|---|
| M0 Foundation — monorepo, Postgres+PostGIS, schema, CI, app shell | ✅ done |
| M1 Auth & profiles | ⬜ next |
| M2 Verification & admin queue | ⬜ |
| M3 The deck (jobs, swipes, requests, matches) | 🟡 deck query + swipe UI working; needs auth + tRPC |
| M4 Chat & scheduling | ⬜ |
| M5 Payments & escrow | ⬜ |
| M6 Reviews & ranking | ⬜ |
| M7 Launch readiness | ⬜ |
Quick start
pnpm install
cp .env.example .env # ports 5442 / 6389 to avoid clashing with other local stacks
pnpm services:up # postgres+postgis and redis in docker
pnpm db:migrate
pnpm db:seed
pnpm dev # http://localhost:3000
The landing page lists the seeded job. Open its deck to swipe.
Layout
apps/web Next.js 15 (App Router) — client, pro and admin UIs
apps/worker BullMQ worker (M3+): request expiry, payouts, reminders
packages/shared money, state machines, ranking weights, zod schemas — no I/O, fully unit tested
packages/db Drizzle schema, migrations, the deck query
packages/api tRPC routers (M1) — the contract mobile will reuse
packages/ui shared components (M1)
Where the important decisions live
packages/shared/src/state-machines.ts— every legal status transition. Mutations must callassertTransition; nothing jumps fromscheduledtocompletedbecause a payload said so.packages/shared/src/ranking.ts— the deck scoring weights. This is the product; expect to tune it weekly against booking conversion.packages/shared/src/money.ts— integer cents only.splitChargealways sums back to the original amount.packages/db/src/queries/deck.ts— the deck query. Filtering runs in Postgres on a GiST index (ST_DWithin), ranking runs in JS so the weights stay tunable.
Testing
pnpm test # everything
pnpm --filter @linkder/shared test # 46 unit tests, no database needed
pnpm --filter @linkder/db test # 18 integration tests, needs a seeded database
The seed is deterministic: every pro sits at a known distance and bearing from the city centre, and the fixture job sits exactly at the centre. So the expected deck is an exact list, not a vague "roughly the nearby ones". The seed deliberately includes pros that must not appear:
| Pro | Why they must be excluded |
|---|---|
| Pau Ribas | 22 km away but only travels 5 km |
| Unverified Ulla | 1 km away, verification still pending |
| Away Arnau | verified, but is_accepting_jobs = false |
Notes and gotchas
- PostGIS type generation. drizzle-kit quotes type names it does not recognise, which turns
geography(Point,4326)into an invalid quoted identifier.packages/db/scripts/fix-postgis.mjsunquotes them and runs automatically as part ofpnpm db:generate. If you ever rundrizzle-kit generatedirectly, run the script afterwards. - Geography, not geometry. Distances come back in metres and
ST_DWithinis correct anywhere without picking a projection per city. Do not replace it with hand-rolled haversine — it will not use the GiST index. - Ports. Postgres is on
5442and Redis on6389, not the defaults, so the stack can run alongside other local projects. - The swipe write is currently a Next server action (
apps/web/src/app/deck/[jobId]/actions.ts) and trusts the caller. It moves into a tRPC procedure with a real session check in M1/M3. It must not ship as-is. pnpm db:seedtruncates everything. It is for local and CI only.
Before taking real money
Flagged in the plan, unresolved by design — these are business decisions, not code:
- Escrow. Holding client funds between charge and transfer is escrow-adjacent. Stripe Connect separate charges & transfers is the sanctioned marketplace pattern, but confirm the specific flow, merchant-of-record and VAT/invoicing position for your jurisdiction with Stripe.
- Cold start. 30–50 verified pros must exist in the launch city before any client opens the app. An empty deck kills the product on day one. This is the real launch blocker, not code.
- Trade liability. Licence and insurance checks are the legal exposure of the whole business. The admin review queue in M2 is not an afterthought.