User Management Service: CRUD and Role Transition Logic
epic-admin-portal-core-services-task-006 — Implement UserManagementService with full CRUD operations for admin users. Enforce business rules for role transitions (e.g., peer mentor to coordinator), validate role eligibility, prevent invalid state combinations, and return actionable validation errors to the admin UI.
Acceptance Criteria
Technical Requirements
Execution Context
Tier 2 - 518 tasks
Can start after Tier 1 completes
Implementation Notes
User creation flow: call the Supabase Edge Function (create-admin-user) which calls supabaseAdmin.auth.admin.createUser() server-side, then inserts the users table row in the same Edge Function to ensure atomicity. Use Supabase's .upsert() with onConflict for idempotent retries. Role transition eligibility check: run all 3 condition queries in parallel (Future.wait), collect failures, throw RoleTransitionException if any fail — do not short-circuit on first failure so the admin sees all reasons at once. Soft delete: use a Supabase RPC function (soft_delete_user) to atomically anonymise PII and set status in a single DB round-trip, avoiding race conditions.
Pagination: use Supabase's .range(from, to) with a consistent .order('full_name') to ensure stable pagination. Expose the service via a Riverpod StateNotifierProvider that holds pagination state (current page, total count, filter state) so the UI can implement infinite scroll.
Testing Requirements
Unit tests (flutter_test) with mocked Supabase client and mocked Edge Function caller. Test each role transition rule independently with a factory that constructs users in specific states (active/paused, with/without recent activities, with/without pending reimbursements). Test soft delete: verify PII fields are overwritten and status is set to deleted. Test scope enforcement: mock OrgHierarchyService to return a subtree that excludes the target user's org, assert InsufficientScopeException is thrown.
Integration tests: full create→read→update→soft-delete cycle against a Supabase test project. Test the Edge Function integration with a real test deployment.
OrgHierarchyNavigator rendering NHF's full 1,400-chapter tree in a single widget may cause Flutter frame-rate drops below 60 fps on mid-range devices, making the navigator unusable for NHF national admins.
Mitigation & Contingency
Mitigation: Implement lazy expansion: only load immediate children on node expand rather than the full tree upfront. Use virtual scrolling for long sibling lists. Test with a synthetic 1,400-node dataset on a low-end Android device during development.
Contingency: If lazy expansion is insufficient, replace the tree widget with a paginated drill-down navigator (select level → select child) that avoids rendering more than 50 nodes at a time.
Bufdir may update their required export column structure or file format during or after development. If the AdminExportService hardcodes the current Bufdir schema, any format change requires a code release rather than a config update.
Mitigation & Contingency
Mitigation: Drive the Bufdir column mapping from a configuration repository rather than hardcoded constants. Abstract column definitions into a named schema config so that format changes require only a config update and re-deployment without service logic changes.
Contingency: If Bufdir format changes post-launch, release a config update within one sprint. If the change is structural (new required sections), scope a targeted service update and communicate timeline to partner organisations.
Role transition side-effects in UserManagementService (e.g., certification expiry removing mentor from chapter listing, pause triggering coordinator notification) may interact with external services like HLF's website sync. Incomplete side-effect handling could leave the system in an inconsistent state.
Mitigation & Contingency
Mitigation: Model side-effects as explicit domain events published after the primary state change is persisted. Implement event handlers as idempotent operations so re-processing is safe. Write integration tests that assert all side-effects fire correctly for each role transition type.
Contingency: If a side-effect fails after the primary change is persisted, log the failure with full context and trigger a manual reconciliation alert to the on-call team. Provide an admin-accessible re-trigger action for failed side-effects.
If AdminStatisticsService cache TTL is set too long, org_admin may see significantly stale KPI values (e.g., a mentor newly paused an hour ago still appears as active), undermining trust in the dashboard.
Mitigation & Contingency
Mitigation: Default cache TTL to 5 minutes with a manual refresh action on the dashboard. Implement cache invalidation triggered by UserManagementService write operations that affect counted entities.
Contingency: If staleness causes org admin complaints post-launch, reduce TTL to 60 seconds and introduce a real-time Supabase subscription for high-impact counters (paused mentors, expiring certifications).