Serverless Migration Plan (Supabase)
Superseded — kept for history only
This page was written in January 2026 and is not a description of how the system works today. It is kept so the reasoning behind early decisions stays readable. Current behaviour is described in Architecture. Do not build from this page.
Goal
Remove the Node server and move all API responsibilities into Supabase features: - Client-side queries with RLS - Postgres functions and triggers for business rules - Edge Functions for privileged operations (service role)
Route Mapping
Auth
- register/login/refresh/change-password: Supabase Auth client
- customer exchange (session -> app user): Edge Function (service role)
- password reset: Supabase Auth reset flow or Edge Function
Inventory, Groups, Agents, Hotels, Food
- CRUD: client-side Supabase with RLS
- Assignments: Postgres functions for atomic capacity/inventory updates
Sales, Requests, Operations, Finance, Tickets, Visa
- Writes with business rules: Postgres functions + triggers
- Reads: client-side Supabase with RLS
- Status history: triggers on status fields
Reports
- SQL views or Postgres functions
Users and Permissions
- Admin mutations: Edge Functions (service role)
- Reads: client-side Supabase with RLS
Storage
- Uploads: Supabase Storage from client
- Signed URLs / virus scan: Edge Functions
Edge Functions to Implement
- customer-exchange: validate session, create User/Customer/Role
- admin-users: create users, reset passwords, manage roles
- permissions-admin: assign role permissions and user overrides
- signed-url: create signed URLs for sensitive files
- lead-intake: captcha validation + lead insert + email
- upload-scan: optional AV scanning (clamav/virustotal)
Postgres Functions (Examples)
- assign_group_booking(booking_id, group_id)
- create_booking_from_request(request_id, payload)
- post_payment(booking_id, amount, method, reference)
- issue_ticket(ticket_id, payload)
- change_visa_status(visa_case_id, status)
RLS Baseline
- Customers: only their own data
- Agents: their own customers/bookings
- Staff: role-based access
- Admin: full access
Decommission Steps
1) Implement functions and triggers 2) Update frontend to call Supabase directly 3) Remove Node server package and deployment 4) Audit for missing rules