Skip to content

[v2][backend] Introduce a repository layer to remove direct Supabase calls from services #1262

Description

@Calebux

Context

Supabase queries are written inline throughout backend/src/services and backend/src/routes. Missing .eq('user_id', ...) scoping has already produced real bugs (see the closed tag-helper and subscription-scoping issues), and because each call site rebuilds the query, a fix in one place does not protect the next one written.

Scope

  • Create a repository per aggregate (subscriptions, payments, reminders, tags, audit, sessions) exposing intent-named methods.
  • Make user scoping a required constructor argument of the repository so an unscoped query is not expressible.
  • Move every direct supabase.from(...) call in services and routes behind a repository.
  • Add a lint rule banning supabase.from outside **/repositories/**.

Acceptance criteria

  • Every aggregate has a repository with user scoping enforced at construction.
  • grep -r 'supabase.from' backend/src --include='*.ts' matches only files under a repositories directory.
  • A lint rule enforces that boundary in CI.
  • Repository methods have unit tests, including tests that a cross-user read returns nothing.

Files / areas

backend/src/services, backend/src/routes, backend/src/repositories, eslint.config.mjs


Part of the SYNCRO v2 rewrite. Epic: D — Backend architecture.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programarea:architectureArchitecture and structurearea:backendBackend services and platformarea:dataDatabase and migrationspriority:p0Highest priorityv2-rewriteSYNCRO v2 rewrite program

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions