fix(housekeeping): serialize commerce state edits
CI / check (pull_request) Successful in 1m39s
CI / deploy (pull_request) Skipped
CI / e2e (pull_request) Skipped

This commit is contained in:
Simo committed 2026-09-05 10:12:39 +02:00
1 parent 555bc75f9e
commit 4b88c6955b
6 files changed
+345 -37

No files matched your search

@@ -0,0 +1,38 @@
# Housekeeping backend review checkpoint
This is an incremental backend review, not a completion or deployment claim.
The current UI route matrix cannot establish operation-level parity.
## Delivered blocks
### Audit reasons and external outcomes (555bc75f)
- Content and Economy preserve normalized reasons through the real service and production audit adapters.
- Hotel preserves reasons through command, service and audit.
- Successful Hotel RCON execution with unavailable completion auditing returns partial completion with external completed; it does not emit a false RCON failure.
- Regressions were observed failing before implementation.
- Full pre-push suite: 1,877 passed, 5 skipped. TypeScript and scoped Biome passed. Remote CI check passed.
- Independent scoped review: no Critical or Important findings.
### Commerce editing concurrency
- ASE marketplace cancellation reads and checks the listing under a transaction-held row lock; inactive listings return CONFLICT.
- Legacy marketplace cancellation includes the row lock, update and staff activity in one transaction. Audit exceptions propagate for rollback.
- ASE and legacy voucher edits lock the record and reject caps below recorded usage. Legacy edits reject missing vouchers rather than reporting a successful no-op.
- Four ASE and two legacy regressions failed before fixes; the expanded focused suite has 14 passing tests.
- Tests execute real Drizzle SQL generation against controlled transport responses. They do not simulate MariaDB locking or prove live multi-connection behavior.
- Independent scoped review: no Critical or Important findings.
## Open backend work
| Area | Evidence / required follow-up |
| --- | --- |
| Voucher redemption | `src/actions/voucher.ts` reads eligibility, inserts used-row, delivers currency, then updates usage in separate operations. No atomic cap reservation. A failed reward can leave a consumed voucher. |
| Currency delivery | `src/lib/services/send-currency.ts` uses RCON followed by database fallback; socket dispatch is not emulator acknowledgment. Do not invent exactly-once guarantees or blindly replay increments. |
| Reason enforcement | Reason propagation is fixed for the named paths, but operation-level required-reason policies and denied/failure auditing still need a complete cross-entrypoint inventory. |
| Functional parity | Compare each query and mutation in Content, Economy, Hotel, People, System and Operations with retained legacy API/actions. A registered handler is not proof of complete functionality. |
| Commerce audit completeness | Review full before/after snapshots, voucher code-edit parity, and canonical audit coverage of legacy voucher actions. |
| Validation and references | Review bounded numeric/string inputs, missing targets, foreign references, bulk all-or-nothing behavior and duplicate conflicts per operation. |
| Live acceptance | Local DB and RCON refuse connections. This does not prevent source implementation; it prevents live integration claims. |
Keep PR 53 draft. Preserve legacy pages, local untracked files, production routing and the existing database contents.