backend/docs/. They were accurate when the backend was a domain only API with three auth lanes. The code has moved on. This page lists what is stale in each file so you do not act on it. When a note and the code disagree, the code is right.
The big change behind most of it
The older notes describe this split: the web app owns identity and billing, the backend owns domain data, and the backend calls the web app to verify sessions. What the code does now:- better-auth runs inside the API process (
@repo/auth), served under/api/auth. - Billing runs inside the API process (
@repo/payments, the Polar webhook at/api/webhooks/payments, the oRPC payments procedures). - The oRPC procedures, mail, avatar storage, coach notifications and the auth database client all live in this repo as
@repo/*packages. - One Postgres database holds both the
authschema and thepublicschema.
docs/README.md that the service is “everything that is not authentication or billing” is no longer true.
README.md (docs index)
ARCHITECTURE.md
API_CONVENTIONS.md
The section on trainee health samples and the
HEART_RATE compatibility rules still matches the code.
ADDING_A_FEATURE.md
CODING_STANDARDS.md
The TypeScript settings, ESM and
.js import rule, naming conventions and the layering direction are all still accurate.
SECURITY.md
The canonical string, the header set, the 5 minute window, the Redis
SET NX EX nonce and the timing safe compare are all still accurate. Missing from the file: partner API keys, plan limits, coach permissions, the signing lane throttle and the archived studio checks.
TESTING.md
ENVIRONMENT.md
CI_AND_HOOKS.md
The hook files (.husky/pre-commit, commit-msg, pre-push) and .github/workflows/ci.yml exist as described. The workflows folder also has dev.yml, deploy-do.yml and cve-scheduled.yml, which the note does not mention.