# Backend implementation tasks Status date: 2026-07-23 ## Phase 1 - isolated backend baseline - [x] Create `E:\workspace\server\saas-voc-server` as an independent Git repository. - [x] Keep `moshengqi-server` and `future-server` read-only. - [x] Add strict environment validation without credential fallbacks. - [x] Add pooled PostgreSQL access and an idempotent migration runner. - [x] Add an independent Parse Server application configuration. - [x] Add the initial domestic VOC schema, constraints, foreign keys, and indexes. - [x] Seed the `demashi` workspace and JD source metadata. - [x] Add health, sync, job-status, and snapshot endpoints. - [x] Add Fmode timeout/retry/authentication behavior behind a server-only client. - [x] Add unit tests and compile under strict TypeScript settings. - [ ] Run migrations against a newly provisioned PostgreSQL database. - [ ] Smoke-test the HTTP service under the supported Node 22 runtime. ## Phase 2 - case-data persistence - [x] Add a batch importer for the normalized Demashi dataset. - [ ] UPSERT 2,817 operating products, 38 relation stubs, and 9,717 daily metric rows in bounded batches. - [ ] UPSERT 40 competitor relations with deterministic relation keys. - [ ] Verify snapshot totals against `demashi-summary.json`. - [x] Switch `DomesticDatasetService` between static case mode and backend API mode. - [ ] Run the existing 29-route desktop/mobile audit against API mode. ## Phase 3 - real JD source contract - [ ] Make one quota-controlled JD search request through the existing Fmode gateway. - [ ] Confirm the exact JD product-detail path, parameters, response envelope, and error codes. - [ ] Confirm the exact JD review path, pagination fields, and any async task/status flow. - [ ] Save sanitized response fixtures without credentials or personal data. - [ ] Implement JD product and review adapters against those fixtures. - [ ] Process queued jobs with partial-failure events and bounded retries. - [ ] UPSERT source results and expose truthful progress through the job endpoint. ## Phase 4 - deployable closure - [ ] Provision a dedicated PostgreSQL database and least-privilege runtime role. - [ ] Provision independent Parse application credentials. - [ ] Put TLS and same-origin reverse proxying in front of `/parse` and `/api/domestic-voc`. - [ ] Add authentication/authorization before enabling the frontend `AuthGuard`. - [ ] Add backup, restore, retention, and failed-job replay procedures. - [ ] Resolve or formally accept remaining moderate Parse transitive advisories. - [ ] Complete end-to-end acceptance with Demashi product detail and real review evidence. ## Explicitly deferred - Multi-platform adapters beyond JD. - Multi-tenant billing and complex role management. - Scheduled full-catalog crawling. - AI reports, sentiment, pain points, or recommendations without review evidence. - Any reuse of the cross-border production database or credentials.