Skip to content

Latest commit

聽

History

History
56 lines (42 loc) 路 3.37 KB

File metadata and controls

56 lines (42 loc) 路 3.37 KB

SnellCoin Backlog & Production Roadmap

This document outlines completed prototype milestones and the prioritized engineering roadmap required before deploying SnellCoin to real-world or production environments (derived from the Full Project Review).


馃煝 Prototype Milestones Completed

  • Supabase Storage Migration: Photos uploaded via HTML5 Canvas compression to actions_images bucket instead of raw Base64 database strings.
  • Base Sepolia Gasless Minting: ERC-721 token minting with Viem admin transaction relayers.
  • Mock Stub Development Mode: Zero-crypto local development mode when Web3 keys are absent.
  • Supabase Magic Link & OAuth: Passwordless authentication with automatic profile creation triggers.
  • Realtime WebSockets: Live UI updates when deeds are approved without client-side polling.
  • Botanical UX & Design System: Scandinavian aesthetic, toast notifications, and non-gamified terminology.
  • GitHub Pages Documentation: Comprehensive architectural case study and learning guides in /docs.

馃敶 Future Work: P0 Production Hardening (Required for Mainnet/Live)

These items are essential before exposing any live deployment to untrusted public users or connecting funded mainnet wallets:

  • SEC-001 / SEC-002: Server-Side Authentication Boundary
    • Verify caller's Supabase session and authorization inside /api/web3/mint, /api/profile, and /api/transactions/send.
    • Derive user identity strictly from the verified session token rather than caller-supplied JSON bodies.
  • SEC-003: Granular RLS Ownership Policies
    • Key public.users to auth.users.id (UUID) rather than raw email strings.
    • Enforce ownership policies using auth.uid() = user_id to prevent cross-user modifications.
  • ARCH-001: Idempotent Minting State Machine
    • Implement a transactional server-owned outbox workflow (pending -> minting -> confirmed/failed).
    • Enforce unique idempotency keys per deed so network drops or retries cannot produce duplicate NFTs.
    • Wait for on-chain transaction confirmation receipts before updating database states.
  • SUPPLY-001: Dependency Upgrades & Audit Cleanliness
    • Upgrade dependencies to resolve known vulnerabilities identified in npm audit.

馃煛 Future Work: P1 Architectural & Integrity Polish

  • ARCH-002: Ledger Migration & Atomic RPC
    • Commit versioned SQL migrations for ledger_transactions and the atomic process_transaction RPC.
  • ARCH-003: Direct IPFS Image Pinning
    • Pin raw image bytes directly to IPFS before metadata creation, linking the resulting ipfs:// image CID inside the metadata JSON.
  • ARCH-005: Reproducible Solidity & Foundry Suite
    • Add a dedicated Foundry/Hardhat project for contract compilation, automated unit tests, and bytecode verification.
  • SEC-004 & SEC-006: Runtime Schema Validation & Storage Quotas
    • Validate all API request payloads with Zod schemas.
    • Restrict storage upload mime-types, file sizes, and user-scoped paths.

馃數 Future Work: P2 Quality, Testing & CI/CD

  • Add automated unit and integration tests (Next.js route handlers, Supabase RLS tests).
  • Set up GitHub Actions CI workflow for linting, typechecking, testing, and secret scanning.
  • Implement structured server-side logging and operational health check endpoints.