This document outlines completed prototype milestones and the prioritized engineering roadmap required before deploying SnellCoin to real-world or production environments (derived from the Full Project Review).
- Supabase Storage Migration: Photos uploaded via HTML5 Canvas compression to
actions_imagesbucket instead of raw Base64 database strings. - Base Sepolia Gasless Minting: ERC-721 token minting with Viem admin transaction relayers.
- Mock Stub Development Mode: Zero-crypto local development mode when Web3 keys are absent.
- Supabase Magic Link & OAuth: Passwordless authentication with automatic profile creation triggers.
- Realtime WebSockets: Live UI updates when deeds are approved without client-side polling.
- Botanical UX & Design System: Scandinavian aesthetic, toast notifications, and non-gamified terminology.
- GitHub Pages Documentation: Comprehensive architectural case study and learning guides in
/docs.
These items are essential before exposing any live deployment to untrusted public users or connecting funded mainnet wallets:
- SEC-001 / SEC-002: Server-Side Authentication Boundary
- Verify caller's Supabase session and authorization inside
/api/web3/mint,/api/profile, and/api/transactions/send. - Derive user identity strictly from the verified session token rather than caller-supplied JSON bodies.
- Verify caller's Supabase session and authorization inside
- SEC-003: Granular RLS Ownership Policies
- Key
public.userstoauth.users.id(UUID) rather than raw email strings. - Enforce ownership policies using
auth.uid() = user_idto prevent cross-user modifications.
- Key
- ARCH-001: Idempotent Minting State Machine
- Implement a transactional server-owned outbox workflow (
pending -> minting -> confirmed/failed). - Enforce unique idempotency keys per deed so network drops or retries cannot produce duplicate NFTs.
- Wait for on-chain transaction confirmation receipts before updating database states.
- Implement a transactional server-owned outbox workflow (
- SUPPLY-001: Dependency Upgrades & Audit Cleanliness
- Upgrade dependencies to resolve known vulnerabilities identified in
npm audit.
- Upgrade dependencies to resolve known vulnerabilities identified in
- ARCH-002: Ledger Migration & Atomic RPC
- Commit versioned SQL migrations for
ledger_transactionsand the atomicprocess_transactionRPC.
- Commit versioned SQL migrations for
- ARCH-003: Direct IPFS Image Pinning
- Pin raw image bytes directly to IPFS before metadata creation, linking the resulting
ipfs://image CID inside the metadata JSON.
- Pin raw image bytes directly to IPFS before metadata creation, linking the resulting
- ARCH-005: Reproducible Solidity & Foundry Suite
- Add a dedicated Foundry/Hardhat project for contract compilation, automated unit tests, and bytecode verification.
- SEC-004 & SEC-006: Runtime Schema Validation & Storage Quotas
- Validate all API request payloads with Zod schemas.
- Restrict storage upload mime-types, file sizes, and user-scoped paths.
- Add automated unit and integration tests (Next.js route handlers, Supabase RLS tests).
- Set up GitHub Actions CI workflow for linting, typechecking, testing, and secret scanning.
- Implement structured server-side logging and operational health check endpoints.