Context
Supabase queries are written inline throughout backend/src/services and backend/src/routes. Missing .eq('user_id', ...) scoping has already produced real bugs (see the closed tag-helper and subscription-scoping issues), and because each call site rebuilds the query, a fix in one place does not protect the next one written.
Scope
- Create a repository per aggregate (subscriptions, payments, reminders, tags, audit, sessions) exposing intent-named methods.
- Make user scoping a required constructor argument of the repository so an unscoped query is not expressible.
- Move every direct
supabase.from(...) call in services and routes behind a repository.
- Add a lint rule banning
supabase.from outside **/repositories/**.
Acceptance criteria
Files / areas
backend/src/services, backend/src/routes, backend/src/repositories, eslint.config.mjs
Part of the SYNCRO v2 rewrite. Epic: D — Backend architecture.
Context
Supabase queries are written inline throughout
backend/src/servicesandbackend/src/routes. Missing.eq('user_id', ...)scoping has already produced real bugs (see the closed tag-helper and subscription-scoping issues), and because each call site rebuilds the query, a fix in one place does not protect the next one written.Scope
supabase.from(...)call in services and routes behind a repository.supabase.fromoutside**/repositories/**.Acceptance criteria
grep -r 'supabase.from' backend/src --include='*.ts'matches only files under a repositories directory.Files / areas
backend/src/services,backend/src/routes,backend/src/repositories,eslint.config.mjsPart of the SYNCRO v2 rewrite. Epic: D — Backend architecture.