# Project State ## Project Reference See: .planning/PROJECT.md (updated 2026-03-04) **Core value:** ISP owners can see exactly where their money is — who owes what, what's been collected, what's been spent, and what the business actually looks like financially — in real time. **Current focus:** Phase 1 - Foundation ## Current Position Phase: 1 of 5 (Foundation) Plan: 3 of 5 in current phase Status: In progress Last activity: 2026-03-04 — Completed 01-03-PLAN.md (tenant provisioning, Prisma middleware, RLS, isolation tests) Progress: [███░░░░░░░] 15% (3/20 plans across all phases) ## Performance Metrics **Velocity:** - Total plans completed: 3 - Average duration: 9.3 min - Total execution time: 28 min **By Phase:** | Phase | Plans | Total | Avg/Plan | |-------|-------|-------|----------| | 01-foundation | 3/5 complete | 28 min | 9.3 min | **Recent Trend:** - Last 5 plans: 01-01 (11 min), 01-02 (8 min), 01-03 (9 min) - Trend: stable at ~9 min/plan *Updated after each plan completion* ## Accumulated Context ### Decisions Decisions are logged in PROJECT.md Key Decisions table. Recent decisions affecting current work: - [Roadmap]: Accounting COA and JournalEntryService built in Phase 2 before first invoice — cannot be retrofitted - [Roadmap]: Inventory modeled as event-ledger (immutable movements) from Phase 4 — mutable quantity columns explicitly rejected - [Roadmap]: Collector balances derived from transaction log, never stored as mutable fields - [Roadmap]: PORT-05 (online payment) scaffolded in Phase 5 but payment gateway integration deferred to v2 per project out-of-scope decision - [01-01]: DATABASE_URL uses Docker service name `db` (for app container); DATABASE_URL_LOCAL uses `localhost:5432` (for host Prisma CLI) - [01-01]: tenantId is nullable on User — super-admins have no tenant scope, avoiding a separate SuperAdmin model - [01-01]: Email uniqueness is @@unique([email, tenantId]) — same email can exist across different tenants (realistic for ISP domain) - [01-01]: Grace period fields (suspendedAt, gracePeriodEndsAt) included on Tenant at schema creation — cannot be retrofit later - [01-02]: NextAuth v4 chosen over v5/Auth.js beta — credentials provider stability priority - [01-02]: JWT carries tenantId + roles directly — no DB lookup on each request, stateless multi-tenancy - [01-02]: Super-admin authorize uses OR [isSuperAdmin, tenant.status=ACTIVE] — one Prisma query handles both user types - [01-02]: Seed uses findFirst+create for super-admin (null tenantId) — PostgreSQL NULL != NULL in unique constraints, upsert would create duplicates - [01-02]: SessionProvider wrapped at root layout via Providers component — enables useSession() in all client components - [01-03]: withTenantContext() creates new $extends per call — correct pattern, $extends is lightweight and request-scoped context is right - [01-03]: findUnique cross-tenant protection routes through findFirst internally — Prisma unique key cannot have tenantId injected without changing where shape - [01-03]: RLS USING allows null app.current_tenant_id — super-admin mode (no tenant context) sees all rows - [01-03]: Initial migration baselined with migrate resolve --applied (schema was created via db push in 01-01) ### Pending Todos None. ### Blockers/Concerns - [Phase 1 research flag]: MikroTik RouterOS Node.js client library maintenance status is LOW confidence — verify `node-routeros` vs `mikronode` before implementing router integration (MikroTik integration is v2, but adapter interface should be planned) - [Phase 3 research flag]: Semaphore SMS API pricing/stability for 2026 is MEDIUM confidence — verify before any SMS work (SMS is v2, but abstraction layer design is relevant) - [01-03 resolved]: prisma-tenant.ts TypeScript errors fixed — Prisma $extends create/upsert required destructuring tenant relation before spreading tenantId ## Session Continuity Last session: 2026-03-04T10:45:22Z Stopped at: Completed 01-03-PLAN.md (tenant provisioning + Prisma middleware + RLS + isolation tests) Resume file: None