📋 Project Management Foundation (Risk, Tech Debt, & Assumptions)

This document serves as the project management ledger for SplitDee, tracking operational risks, technical debt, project assumptions, and constraints.
เอกสารฉบับนี้ทำหน้าที่เป็นสมุดจดบันทึกประเด็นด้านบริหารโครงการของ SplitDee สำหรับติดตามและควบคุมความเสี่ยง การสะสมหนี้ทางเทคนิค และข้อสมมติฐานเบื้องต้น


🇹🇭 ภาษาไทย (สำหรับผู้ใช้งาน)

1. บัญชีเฝ้าระวังความเสี่ยงโครงการ (Risk Register)

  • ความเสี่ยงการปลอมแปลงสลิปโอนเงิน (R-SEC-001): สมาชิกลุ่มแอบแชะภาพตัดต่อยอดเงิน หรือส่งใบหลักฐานการโอนเก่ามาส่งซ้ำเพื่อปิดยอด ➔ บรรเทาโดยต่อเชื่อม API ตรวจ Statement ธนาคารจริง (เช่น SlipOK) และเช็กเลขอ้างอิงทำรายการห้ามซ้ำ
  • ค่าบริการเช็กสลิปโอนเงินผ่านระบบธนาคารภายนอก (R-COST-002): บริการตรวจสอบธนาคารภายนอกคิดค่าบริการต่อครั้งสแกน ซึ่งอาจสร้างภาระเงินให้โครงการ ➔ บรรเทาโดยจำกัดสิทธิ์ส่งตรวจวันละ 10 ครั้งต่อบัญชี และเปิดฟังก์ชันให้เจ้าหนี้กดอนุมัติมือเปรียบเทียบสเตตเมนต์จริงได้เอง
  • แอปพลิเคชันหรือแชทตอบสนองล่าช้า (R-PERF-003): ลูกหนี้ไม่ได้รับการ์ดแจ้งเตือนบิลตั้งหารเนื่องจากเน็ตหน่วงช้า ➔ บรรเทาโดยใช้ WebSockets ซิงค์แชทสดขณะผู้ใช้เปิดแอป และสลับเป็นคลาวด์ FCM ส่ง Push ทันทีที่เครื่องพักปิดแอปเบื้องหลัง
  • เพื่อนยกเลิกถอนแอปเนื่องจากโมจิ HP ตาย (R-GAM-004): สมาชิกกลุ่มถอนแอปทิ้งเนื่องจากสัตว์เลี้ยงโมจิป่วยจากการค้างจ่ายบิลของเพื่อนร่วมห้อง ➔ บรรเทาโดยปรับระดับคำเตือน HP, เปิด Vacation Mode ล็อก HP ชั่วคราว และปรับ UI เน้นการแจกโบนัส XP เมื่อจ่ายเงินเร็วแทน

2. บัญชีหนี้สินทางเทคนิคที่ต้องรีแฟคเตอร์ (Technical Debt Log)

  • รหัส TD-SEC-001 (การยกเลิกสิทธิ์ Token กลางคัน): ปัจจุบัน JWT Token ถูกปล่อยให้หมดอายุตามเวลาทั่วไป ➔ แผนงาน: ปรับปรุงใช้ระบบ Redis Blacklist จัดเก็บและเพิกถอนสิทธิ์ไอดีโทเค็นที่ผู้ใช้กดออกจากระบบก่อนถึงกำหนด (แก้ใน Sprint 2)
  • รหัส TD-DB-002 (ดัชนีคีย์ junction): ขาดดัชนีคีย์ (Index) บนตารางความสัมพันธ์ทางอ้อม ➔ แผนงาน: เพิ่ม composite indices บนตารางเชื่อมสมาชิกกลุ่มและสัดส่วนหนี้ค้างจ่าย (แก้ใน Sprint 1)
  • รหัส TD-CHAT-003 (แชทแบบดึงเช็ก): หน้าจอห้องแชทใช้วิธีดึงเช็กข้อมูลซ้ำๆ แทนการรันสด ➔ แผนงาน: ปรับใช้ WebSockets ในห้องสนทนาหลัก (แก้ใน Sprint 3)

3. ข้อตกลงเบื้องต้นและข้อจำกัดของโครงการ (Assumptions & Constraints)

  • ข้อตกลง: สมมติว่าผู้ใช้งานชาวไทยทุกคนมีบัญชีแอปพลิเคชันธนาคารบนมือถือที่รองรับพร้อมเพย์, กล้องถ่ายภาพมีความละเอียดเหมาะสม และยอมรับว่า SplitDee ไม่ได้ทำหน้าที่เป็นตัวกลางโอนเงิน (โอนเงินจริงเกิดภายนอกระบบ)
  • ข้อจำกัด: ระบบจำเป็นต้องใช้ฐานข้อมูล PostgreSQL เพื่อความเสถียรทางการเงิน, ไม่รองรับการทำงานสำคัญขณะออฟไลน์เนื่องจากต้องเชื่อมระบบธนาคารจริง และแอปหน้าบ้าน Flutter ต้องรองรับ Android 9.0+ และ iOS 15+ เป็นขั้นต่ำ

🇬🇧 English (For AI Agents)

1. Risk Register

  • R-SEC-001 (Security): Slip verification spoofing (e.g. photo-edited slips). Impact: High, Probability: Medium. Mitigation: Query verified bank check APIs (SlipOK/EasySlip).
  • R-COST-002 (Financial): High transactional costs on slip validation APIs. Impact: Medium, Probability: High. Mitigation: Set daily scan limits and enable manual creditor approval.
  • R-PERF-003 (Performance): Notification delays due to background client termination. Impact: Medium, Probability: Medium. Mitigation: Hybrid WebSockets + FCM push notifications.
  • R-GAM-004 (Engagement): High attrition due to harsh pet HP penalties. Impact: High, Probability: Medium. Mitigation: Vacation Mode toggle and early settlement rewards.

2. Technical Debt Log

  • TD-SEC-001: Missing JWT revocation database/cache (currently tokens expire after standard TTL). Target: End of Sprint 2. Action: Set up a Redis-based blacklist system storing JTI claims of logged-out accounts.
  • TD-DB-002: Missing compound indexes on relational junction tables. Target: End of Sprint 1. Action: Add composite indices to PostgreSQL schemas for group_members and expense_shares queries.
  • TD-CHAT-003: Polling used for chat updates instead of real-time server pushing. Target: Sprint 3. Action: Refactor presentation layer to use WebSocket connections.

3. Project Assumptions

  1. PromptPay Access: Users have access to Thai mobile banking apps supporting PromptPay QR transfers.
  2. Image Quality: Captured slip photos have readable Mini-QR codes.
  3. No Direct Ledger: Platform processes zero funds. All settlements occur externally.

4. Constraints

  1. Relational Database: PostgreSQL required for database transactional integrity.
  2. Offline Mode: Major actions blocked offline due to real-time verification requirements.
  3. Platform Version: Flutter mobile client must support Android 9.0+ and iOS 15+.