The repo carries hand written notes under backend/docs/. They were accurate when the backend was a domain only API with three auth lanes. The code has moved on. This page lists what is stale in each file so you do not act on it. When a note and the code disagree, the code is right.

The big change behind most of it

The older notes describe this split: the web app owns identity and billing, the backend owns domain data, and the backend calls the web app to verify sessions. What the code does now:
  • better-auth runs inside the API process (@repo/auth), served under /api/auth.
  • Billing runs inside the API process (@repo/payments, the Polar webhook at /api/webhooks/payments, the oRPC payments procedures).
  • The oRPC procedures, mail, avatar storage, coach notifications and the auth database client all live in this repo as @repo/* packages.
  • One Postgres database holds both the auth schema and the public schema.
So the statement in docs/README.md that the service is “everything that is not authentication or billing” is no longer true.

README.md (docs index)

ARCHITECTURE.md

API_CONVENTIONS.md

The section on trainee health samples and the HEART_RATE compatibility rules still matches the code.

ADDING_A_FEATURE.md

CODING_STANDARDS.md

The TypeScript settings, ESM and .js import rule, naming conventions and the layering direction are all still accurate.

SECURITY.md

The canonical string, the header set, the 5 minute window, the Redis SET NX EX nonce and the timing safe compare are all still accurate. Missing from the file: partner API keys, plan limits, coach permissions, the signing lane throttle and the archived studio checks.

TESTING.md

ENVIRONMENT.md

CI_AND_HOOKS.md

The hook files (.husky/pre-commit, commit-msg, pre-push) and .github/workflows/ci.yml exist as described. The workflows folder also has dev.yml, deploy-do.yml and cve-scheduled.yml, which the note does not mention.

Root CLAUDE.md of the workspace

The assistant context file at the workspace root repeats the old picture and has a few extra stale points: