This directory is the canonical cross-system documentation for the active Håfa Recipes product.
Last reviewed: 2026-08-19
-
- What Håfa Recipes is
- Why it exists
- Who it serves
- Current architecture and product principles
-
- Verified findings and evidence
- Severity and confidence
- Security, privacy, AI, reliability, data, UX, accessibility, testing, and operations
- Items that were checked and found to be sound
-
- Ordered implementation releases
- Task IDs, rationale, dependencies, and acceptance criteria
- Explicit non-goals and deferred work
-
Decision: defer private chat-image delivery
- Scope of the accepted risk
- Interim controls
- Revisit date and triggers
-
Decision: no dedicated staging environment
- Local/development and production boundaries
- Required protection against accidental production access
-
Decision: focused admin and moderation surface
- Admin MVP scope
- Authorization, reversibility, and audit requirements
-
AI model governance and rollout runbook
- Why one model should not handle every AI task
- Evaluation and rollout criteria
-
Database invariants and canonical sources runbook
- Canonical URL rules, concurrency constraints, schema verification, deployment, and rollback
- Durable account and recipe cleanup behavior
- Queue states, alerts, verification, and safe recovery
- Local PostgreSQL and synthetic seed setup
- Preview/production target rules and visible environment labels
- Dependency audit triage and accepted upstream findings
- Server-enforced admin and user-safety APIs
- Visibility, reversibility, privacy, audit, deployment, and rollback rules
- Recipe media CDN runbook
- CloudFront, WAF, OAC, DNS, rollout, verification, and rollback
- The documents above describe the current product and active plan.
ARCHITECTURE_AND_MIGRATION_PROGRAM.mdis authoritative for the monorepo and Clerk identity migration.mobile/ROADMAP.mdis a historical idea list; it contains shipped and stale items and is not the execution tracker.- Git history and release tags remain the release record until a canonical mobile changelog is added.
- Detailed deployment and migration runbooks remain authoritative for the narrow procedures they describe.
- Model IDs in code or old documentation are not a model strategy. The active model policy is in the audit and roadmap.
When work is completed:
- Update the matching task in
IMPROVEMENT-ROADMAP.md. - Add or update automated tests and operational verification.
- Update the appropriate release notes for user-visible changes.
- If a risk is accepted or a major technical choice changes, add or supersede an ADR in
docs/decisions/. - Re-run the relevant audit checks rather than marking findings complete from code inspection alone.
- Public recipe: visible in Discover and accessible without owning the recipe.
- Private recipe: accessible only to its owner and explicitly authorized collaborators.
- Extraction: converting a video, website, or image into structured recipe data.
- Derived data: nutrition, cost, tags, meal types, or cached totals calculated from canonical recipe content.
- Release gate: a condition that must pass before the related release is shipped.