Implement coordinator recipient resolution
epic-peer-mentor-pause-foundation-task-006 — Implement the coordinator resolution logic in CoordinatorNotificationService: given a mentor_id, query the chapter membership table to identify the mentor's chapter(s), then resolve all active coordinator user_ids for those chapters. Cache chapter-to-coordinator mappings with a short TTL to reduce redundant queries on bulk operations.
Acceptance Criteria
Technical Requirements
Execution Context
Tier 3 - 413 tasks
Can start after Tier 2 completes
Implementation Notes
Implement a private _coordinatorCache =
Expose a void invalidateChapterCache(String chapterId) and a void clearAllCache() method. Subscribe to Supabase auth state changes via supabase.auth.onAuthStateChange and call clearAllCache() on sign-out.
Testing Requirements
Unit tests (flutter_test + mocktail): mock Supabase queries and verify correct filters are applied (role = coordinator, status = active, correct chapter_ids). Test deduplication when a coordinator is in multiple chapters. Test empty result when mentor has no chapters. Test cache hit: call resolveCoordinatorsForMentor twice with same mentorId and verify the Supabase mock is only called once.
Test cache invalidation: call invalidate, then verify a fresh query is made. Test multi-chapter mentor: mock two chapter memberships and verify coordinators from both chapters are merged. Minimum 85% line coverage.
Supabase RLS policies for status reads and writes must correctly distinguish between a mentor editing their own status and a coordinator editing another mentor's status within the same chapter. Incorrect policies could allow cross-chapter data leakage or silently block legitimate status updates, causing hard-to-diagnose runtime failures.
Mitigation & Contingency
Mitigation: Write RLS policies with explicit role checks (auth.uid() = mentor_id OR chapter_coordinator_check()) and verify with integration tests that cover same-chapter coordinator access, cross-chapter denial, and self-access. Review policies with a second developer before merging.
Contingency: If policy errors surface after merge, temporarily widen policy to coordinator role globally while a targeted fix is authored; use Supabase audit logs to trace any unauthorised access during the interim.
CoordinatorNotificationService must correctly resolve which coordinator(s) are responsible for a given mentor's chapter. If the chapter-coordinator mapping is incomplete or a mentor belongs to multiple chapters (as with NHF multi-chapter memberships), the service could fail to notify or duplicate notifications to the wrong coordinators.
Mitigation & Contingency
Mitigation: Use the existing chapter membership data model and query all active coordinator roles for each of the mentor's chapters. Add a de-duplication step before dispatch. Write integration tests with fixtures covering single-chapter, multi-chapter, and no-coordinator edge cases.
Contingency: If resolution logic proves too complex at this stage, fall back to notifying all coordinators in the organisation until a proper chapter-scoped resolver can be delivered in a follow-up task.
Adding new columns to peer_mentors in production could conflict with existing application code that does SELECT * queries if new non-nullable columns without defaults are introduced, causing unexpected failures in unrelated screens.
Mitigation & Contingency
Mitigation: Make all new columns nullable or provide safe defaults. Use additive migration strategy with no column renames or drops. Run migration against a staging copy of production data before applying to live.
Contingency: Prepare a rollback migration script that drops only the new columns; coordinate with the team to deploy the rollback and hotfix immediately if production issues are detected.