# Task: Cleanup alert router — remove DB calls, consolidate ## Goal Remove all remaining direct database calls from `routers/alerts.py`. The router should now be a thin HTTP layer only. ## Requirements ### Changes to `src/backend/routers/alerts.py` 1. Remove direct imports of `execute_query`, `execute_command`, `execute_one` from `database` 2. Remove the `_require_watchlist_owner()` helper function (moved to AlertService) 3. Ensure all endpoints use `AlertService` exclusively 4. The router should only contain: - Route decorators and signatures - Auth extraction (`current_user["id"]`) - Service method calls - Response model wrapping 5. The file should be ~60-80 lines (down from ~200+) ### Service layer additions if needed If AlertService is missing a helper method the router needs, add it: - `build_watchlist_in_clause(user_id)` — returns (placeholders, params) for user's watchlists - Any other query helper needed by the listing endpoint ## Acceptance Criteria 1. `routers/alerts.py` has no direct `execute_query`/`execute_command`/`execute_one` calls 2. File is under 100 lines 3. All alert tests still pass: `pytest tests/test_alerts.py --tb=short` 4. No import errors ## Files to Modify - `src/backend/routers/alerts.py` - `src/backend/services/alert_service.py` (if new helpers needed) ## Files to Read First - `src/backend/routers/alerts.py` — current state - `src/backend/services/alert_service.py` — current service