Skip to content

Serverless Migration Plan (Supabase)

Superseded — kept for history only

This page was written in January 2026 and is not a description of how the system works today. It is kept so the reasoning behind early decisions stays readable. Current behaviour is described in Architecture. Do not build from this page.

Goal

Remove the Node server and move all API responsibilities into Supabase features: - Client-side queries with RLS - Postgres functions and triggers for business rules - Edge Functions for privileged operations (service role)

Route Mapping

Auth

  • register/login/refresh/change-password: Supabase Auth client
  • customer exchange (session -> app user): Edge Function (service role)
  • password reset: Supabase Auth reset flow or Edge Function

Inventory, Groups, Agents, Hotels, Food

  • CRUD: client-side Supabase with RLS
  • Assignments: Postgres functions for atomic capacity/inventory updates

Sales, Requests, Operations, Finance, Tickets, Visa

  • Writes with business rules: Postgres functions + triggers
  • Reads: client-side Supabase with RLS
  • Status history: triggers on status fields

Reports

  • SQL views or Postgres functions

Users and Permissions

  • Admin mutations: Edge Functions (service role)
  • Reads: client-side Supabase with RLS

Storage

  • Uploads: Supabase Storage from client
  • Signed URLs / virus scan: Edge Functions

Edge Functions to Implement

  • customer-exchange: validate session, create User/Customer/Role
  • admin-users: create users, reset passwords, manage roles
  • permissions-admin: assign role permissions and user overrides
  • signed-url: create signed URLs for sensitive files
  • lead-intake: captcha validation + lead insert + email
  • upload-scan: optional AV scanning (clamav/virustotal)

Postgres Functions (Examples)

  • assign_group_booking(booking_id, group_id)
  • create_booking_from_request(request_id, payload)
  • post_payment(booking_id, amount, method, reference)
  • issue_ticket(ticket_id, payload)
  • change_visa_status(visa_case_id, status)

RLS Baseline

  • Customers: only their own data
  • Agents: their own customers/bookings
  • Staff: role-based access
  • Admin: full access

Decommission Steps

1) Implement functions and triggers 2) Update frontend to call Supabase directly 3) Remove Node server package and deployment 4) Audit for missing rules