{\rtf1\ansi\deff0\nouicompat{\fonttbl{\f0\fnil\fcharset0 Calibri;}{\f1\fnil Calibri;}{\f2\fnil\fcharset1 Cambria Math;}} {\*\generator Riched20 10.0.19041}{\*\mmathPr\mmathFont2\mwrapIndent1440 }\viewkind4\uc1 \pard\sa200\sl276\slmult1\f0\fs22\lang9 You are a Senior Software Architect, Senior Backend Engineer, Senior DevOps Engineer, and Senior Security Engineer.\par \par Analyze the entire existing codebase and implement all required improvements directly in the project without breaking any existing functionality.\par \par Project Goal:\par Transform the current application into a Production-Ready SaaS foundation with strong security, scalability, maintainability, monitoring, and enterprise-grade architecture.\par \par ========================\par PHASE 1 \f1\emdash SECURITY HARDENING\par ============================\par \par 1. CORS Security\par \par * Remove any wildcard or fully open CORS configuration.\par * Allow requests only from approved frontend domains.\par * Support environment-based domain configuration.\par * Separate Development and Production configurations.\par \par 2. Helmet Security\par \par * Install and configure Helmet.\par * Enable all recommended security headers.\par * Configure Content Security Policy properly.\par \par 3. Rate Limiting\par \par * Implement express-rate-limit.\par * Create separate limits for:\par \par * Login\par * Register\par * Password Reset\par * API Requests\par * Return proper error responses.\par \par 4. Authentication Security\par \par * Audit JWT implementation.\par * Improve token validation.\par * Validate expiration handling.\par * Protect against token abuse.\par * Ensure secure secret management.\par \par 5. Cookie Security\par \par * Use:\par \par * httpOnly\par * secure\par * sameSite=strict\par * Environment-aware configuration.\par \par 6. CSRF Protection\par \par * Implement CSRF protection for cookie-based authentication.\par * Secure all sensitive endpoints.\par \par 7. Input Validation\par \par * Ensure every endpoint uses Zod validation.\par * Remove any unvalidated request body.\par * Sanitize user input.\par * Prevent injection attacks.\par \par 8. File Upload Security\par \par * Validate MIME types.\par * Validate file extensions.\par * Validate file size.\par * Block SVG uploads.\par * Prevent malicious file execution.\par * Implement upload scanning layer.\par \par 9. Security Logging\par \par * Log:\par \par * Login attempts\par * Failed authentication\par * Permission violations\par * Suspicious activity\par \par ========================\par PHASE 2 \emdash ROLE BASED ACCESS CONTROL\par ===================================\par \par Implement Enterprise RBAC.\par \par Roles:\par \par * Super Admin\par * Admin\par * Manager\par * Staff\par * User\par \par Requirements:\par \par * Permission matrix.\par * Middleware:\par authorize(...)\par * Route protection.\par * Page protection.\par * API protection.\par * Database-level role checks.\par \par Examples:\par \par * Only Super Admin can manage platform settings.\par * Admin can manage organization resources.\par * Staff can only access assigned resources.\par * Users can only access their own data.\par \par ========================\par PHASE 3 \emdash MULTI TENANT ARCHITECTURE\par ===================================\par \par Convert architecture to true SaaS multi-tenancy.\par \par Requirements:\par \par 1. Tenant Entity\par \par * Create Tenant model.\par \par 2. Tenant Isolation\par \par * Every record belongs to tenant.\par * Prevent cross-tenant access.\par \par 3. Tenant Middleware\par \par * Automatically resolve tenant.\par * Attach tenant context.\par \par 4. Database Protection\par \par * Every query must be tenant-aware.\par \par 5. Super Admin Bypass\par \par * Platform administrators can access all tenants.\par \par ========================\par PHASE 4 \emdash BACKEND ARCHITECTURE IMPROVEMENTS\par ===========================================\par \par Refactor into:\par \par Controller\par \f2\u8595?\f0\par Service\par \f2\u8595?\f0\par Repository\par \f2\u8595?\f0\par Prisma\par \par Requirements:\par \par * Controllers contain no business logic.\par * Services contain business logic.\par * Repositories handle database access.\par * Shared abstractions.\par * Dependency injection friendly structure.\par \par ========================\par PHASE 5 \f1\emdash OBSERVABILITY\par =======================\par \par 1. Logging\par \par * Implement Winston or Pino.\par * Structured JSON logs.\par * Environment aware.\par \par 2. Error Tracking\par \par * Integrate Sentry.\par * Capture exceptions.\par * Capture API failures.\par \par 3. Request Tracing\par \par * Track request lifecycle.\par * Add correlation IDs.\par \par 4. Health Checks\par Create endpoints:\par \par /health\par /health/database\par /health/storage\par \par ========================\par PHASE 6 \emdash DATABASE IMPROVEMENTS\par ===============================\par \par Review Prisma schema.\par \par Requirements:\par \par * Add indexes.\par * Add composite indexes.\par * Add foreign key constraints.\par * Optimize slow queries.\par * Remove redundant fields.\par * Improve relationships.\par * Add soft delete support.\par * Add audit fields:\par \par createdAt\par updatedAt\par createdBy\par updatedBy\par \par ========================\par PHASE 7 \emdash TESTING\par =================\par \par Implement:\par \par 1. Unit Tests\par \par * Services\par * Utilities\par * Validation\par \par 2. Integration Tests\par \par * API routes\par * Database interactions\par \par 3. Authentication Tests\par \par 4. Authorization Tests\par \par Target:\par Minimum 80% test coverage.\par \par ========================\par PHASE 8 \emdash DEVOPS\par ================\par \par 1. Docker\par \par * Production Dockerfile\par * Development Dockerfile\par \par 2. Docker Compose\par \par * API\par * PostgreSQL\par * Redis\par \par 3. Environment Validation\par \par * Validate env variables at startup.\par \par 4. CI/CD\par \par * GitHub Actions\par * Lint\par * Test\par * Build\par * Deploy\par \par ========================\par PHASE 9 \emdash PERFORMANCE\par =====================\par \par 1. Redis Caching\par 2. Query Optimization\par 3. Pagination\par 4. Lazy Loading\par 5. Compression Middleware\par 6. API Response Optimization\par \par ========================\par PHASE 10 \emdash SAAS READINESS\par =========================\par \par Implement missing SaaS features:\par \par 1. Team Management\par 2. Invitation System\par 3. User Management\par 4. Subscription Ready Architecture\par 5. Billing Ready Architecture\par 6. Audit Logs\par 7. Activity History\par 8. Notification Infrastructure\par 9. Email Infrastructure\par 10. Feature Flag System\par \par ========================\par FINAL DELIVERABLE\par =================\par \par Provide:\par \par 1. Full code implementation.\par 2. Updated folder structure.\par 3. Security report.\par 4. Scalability report.\par 5. Production readiness report.\par 6. Database optimization report.\par 7. List of all modified files.\par 8. List of all new files.\par 9. Migration instructions.\par 10. Deployment instructions.\par \par Important:\par Do not generate pseudo-code.\par Do not leave TODO comments.\par Implement production-quality code directly inside the existing project architecture.\par Preserve existing functionality while applying all improvements.\f0\lang9\par }