GMSM-USA: Community Platform for GMSM America
Production community platform for GMSM America, a nationwide US religious and cultural organization of several hundred families that previously coordinated through spreadsheets and WhatsApp threads. Built solo as volunteer work for the community; live since April 2026 and in daily use. Built around one constraint: most members have no email address, so authentication is a custom phone-number credential layer (bcrypt-hashed in the browser, stored against a synthetic email so Supabase Auth, the credentials table, and the directory record share one UUID) with Google OAuth and account identity linking alongside it. Families register as households rather than individuals — 79 households cover 293 people, 86% of all member records, behind 136 login accounts. Authorization is enforced in PostgreSQL, not the client: 47 row-level security policies, 20 security-definer RPCs, three-tier RBAC driven by a unit-tested permission matrix, and database triggers that reject writes to closed events. Signup collapsed from three sequential client writes into a single atomic Postgres function after a failure mid-flow left orphaned auth users unrecoverable. Real-time updates run over Supabase WebSocket channels backed by Postgres logical replication, gated on auth state. Two-tier caching (in-memory session cache with in-flight request deduplication over a localStorage stale-while-revalidate layer) clears on sign-out for shared family computers. 89 kB gzipped initial JS via route-level code splitting across 12 pages. 340 active members across 45 states and 93 cities; 463 registrations across 17 events including a 14-city national tour. 78 files, ~26k lines of frontend, ~3.1k lines of SQL, 43 migrations, 9 tables, 68 unit tests.