Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
This reverts commit488b6e57c4, reversing changes made tob506b4499a.
This commit is contained in:
1 parent
488b6e57c4
commit
b1ddda66ff
802 files changed
+61370
-76659
No files matched your search
@@ -1,74 +0,0 @@
|
||||
# Housekeeping pre-cutover verification
|
||||
|
||||
Verified on 2026-08-30 at 19:50 CEST against branch commit `65a62867`.
|
||||
|
||||
## Outcome
|
||||
|
||||
The pre-cutover gate passed. The replacement Housekeeping workspace has complete route coverage, passes the automated suite and production build, and rendered successfully across the required desktop, tablet, and mobile viewports. The remaining environmental limitations are recorded below and do not hide a failed dependency or a failed state.
|
||||
|
||||
## Environment
|
||||
|
||||
- Windows and PowerShell, local non-production environment.
|
||||
- Repository system Node.js was `26.7.0`, which does not match `.nvmrc`. Because the protected NVM installation could not be updated without administrator rights, every recorded gate used the official portable Node.js `26.8.1` distribution with pnpm `11.24.0`.
|
||||
- The database was used read-only for the browser verification. No mutation command or database write was executed.
|
||||
- Redis was not configured. RCON was unavailable during the preview and the workspace represented that dependency as a partial provider warning.
|
||||
- The temporary `AUTH_SECRET` used by the build and local preview was restored or removed after each command.
|
||||
|
||||
## Automated gates
|
||||
|
||||
| Gate | Result | Evidence |
|
||||
| --- | --- | --- |
|
||||
| Toolchain | Pass | `pnpm toolchain:check` reported Node.js `26.8.1` aligned with `.nvmrc`; pnpm was `11.24.0`. |
|
||||
| Migration matrix and runtime parity | Pass | `137/137` valid; discovered, mapped, and verified routes were all `137`; `2` legacy removals were accounted for; no gaps. |
|
||||
| Housekeeping suite | Pass | `109` test files, `841` tests. |
|
||||
| Full suite | Pass | `266` test files passed and `3` skipped; `1,741` tests passed and `5` skipped; statement coverage `24.55%` (`7,737/31,510`). |
|
||||
| TypeScript | Pass | `pnpm typecheck` exited successfully. |
|
||||
| Cumulative Biome | Pass | `450` changed JavaScript, TypeScript, JSON, and JSONC files checked in `12` batches; no fixes remained. |
|
||||
| Patch hygiene | Pass | `git diff --check` exited successfully. |
|
||||
| Production build | Pass | Next.js `16.3.3` compiled, typechecked, and generated `239/239` static pages. `AUTH_SECRET` restoration was confirmed. |
|
||||
|
||||
The production build emitted two non-blocking environmental warnings: `REDIS_URL` is unset, and Turbopack traced a dynamic translation-file path in `mutation-runtime-external.ts`. Both are explicit in the build output and must be considered for the deployment environment.
|
||||
|
||||
## Runtime boundary correction
|
||||
|
||||
The first real browser run found a React Server Components boundary failure because provider definitions containing a `load` function were passed into a client component. A failing projection test was added first. The workspace now projects definitions to serializable widget options before crossing the client boundary, while preserving the domain import contract by locating the projection in the shared preferences foundation.
|
||||
|
||||
The correction is covered by commits `cb77b2d3` and `1ae59bcc`. Cumulative Biome corrections are isolated in `b9c47aa8` and `65a62867`. The corrected browser matrix below rendered without the error boundary.
|
||||
|
||||
## Browser and responsive matrix
|
||||
|
||||
The canonical route for each domain was tested at `1440x900`, `1024x768`, `390x844`, and `320x568` with an authorized rank-7 fixture.
|
||||
|
||||
| Domain | Canonical route | Heading | Viewports | Runtime result |
|
||||
| --- | --- | --- | --- | --- |
|
||||
| Operations | `/ase-next` | Operations workspace | 4/4 | HTTP 200, Housekeeping root present, no error boundary or horizontal overflow. |
|
||||
| People | `/ase-next/people/users` | Users | 4/4 | HTTP 200, Housekeeping root present, no error boundary or horizontal overflow. |
|
||||
| Content | `/ase-next/content/editorial/articles` | Editorial content | 4/4 | HTTP 200, Housekeeping root present, no error boundary or horizontal overflow. |
|
||||
| Economy | `/ase-next/economy/catalog` | Catalog | 4/4 | HTTP 200, Housekeeping root present, no error boundary or horizontal overflow. |
|
||||
| Hotel | `/ase-next/hotel/rooms` | Rooms | 4/4 | HTTP 200, Housekeeping root present, no error boundary or horizontal overflow. |
|
||||
| System | `/ase-next/system/access/permissions` | Access control | 4/4 | HTTP 200, Housekeeping root present, no error boundary or horizontal overflow. |
|
||||
|
||||
All `24/24` canonical route/viewport combinations passed with zero page errors and zero horizontal overflow. The screenshots are retained outside the repository at `C:\Users\simol\.codex\visualizations\2026\08\24\01a03498-f8e9-70d2-9180-2ef86d73ebb6\housekeeping-task24`.
|
||||
|
||||
An initial exploratory pass used the non-canonical domain roots `/ase-next/{domain}` and correctly received 404 responses. Those invalid routes were excluded and replaced by the canonical routes shown above.
|
||||
|
||||
## Access, states, and command safety
|
||||
|
||||
| Scenario | Result |
|
||||
| --- | --- |
|
||||
| Anonymous access | Redirected to `/login`; no Housekeeping root rendered. |
|
||||
| Authenticated rank-1 access | Failed closed with `Page not found`; no Housekeeping root rendered. |
|
||||
| Authenticated rank-7 access | All 24 browser combinations rendered successfully. |
|
||||
| Real partial provider state | RCON outage surfaced as `Unable to load Housekeeping`; sibling workspace content remained usable. |
|
||||
| Real empty state | Operations recent work rendered `Nothing available`. |
|
||||
| Loading, error, forbidden, partial, empty, and ready UI states | Covered by the targeted smoke suite. |
|
||||
| Safe and sensitive command dispatch | Covered in tests, including intent, preflight, success, and failure paths; no real mutation was submitted. |
|
||||
| Provider timeout isolation | Covered at the two-second abort boundary with sibling preservation. |
|
||||
| Preferences | Schema, upsert, corruption recovery, and reconciliation covered. |
|
||||
| Studio | All ten kinds, authorization, outage, audit route, lifecycle ordering, and page states covered. |
|
||||
|
||||
The targeted state and safety run passed `11` files and `98` tests.
|
||||
|
||||
## Cutover readiness
|
||||
|
||||
This evidence verifies the preview implementation only. It does not claim a production deployment or live service health. With the recorded limitations accepted, the branch is ready for the route cutover from `/ase-next` to `/ase` and removal of the legacy `/admin` and `/mod` page trees.
|
||||
@@ -1,66 +0,0 @@
|
||||
# Housekeeping final cutover verification
|
||||
|
||||
Verified on 2026-08-30 CEST on branch `codex/housekeeping-complete` after production commit `222535e1`.
|
||||
|
||||
## Outcome
|
||||
|
||||
The Housekeeping replacement is complete and the administration UI has been cut over atomically to `/ase`. The former `/admin`, `/mod`, and `/ase-next` UI trees are absent and do not redirect. Internal `/api/admin/*` endpoints remain intentionally available behind their existing permission gates.
|
||||
|
||||
This report verifies the branch and local production build. It does not claim that the branch is merged, deployed, or healthy in production.
|
||||
|
||||
## Delivered cutover
|
||||
|
||||
- `2b8f73a9` moved the canonical workspace to `src/app/ase`, removed the three legacy UI roots, removed the preview gate, and deleted the superseded UI and dependency surface.
|
||||
- `222535e1` closed the final authorization findings: logo writes require `admin.settings.edit`; generic media deletion cannot traverse into nested asset namespaces; hierarchy bypasses use `isSuperAdmin`; bulk ban/unban require `admin.users.ban`; every bulk target is checked before mutation; configured rank identifiers are no longer capped at 7 and must exist in `permission_ranks`.
|
||||
- The historical migration matrix remains as an auditable 137-row record while the physical legacy-root scanner reports zero retained UI pages.
|
||||
|
||||
## Final automated gates
|
||||
|
||||
| Gate | Result | Evidence |
|
||||
| --- | --- | --- |
|
||||
| Toolchain | Pass | `pnpm toolchain:check`: Node.js `26.8.1` aligned with `.nvmrc`. |
|
||||
| Migration and runtime parity | Pass | `137/137` historical rows valid; legacy UI pages present `0`; runtime discovered/mapped/verified `137/137/137`; removals `2`. |
|
||||
| Housekeeping suite | Pass | `109` test files and `843` tests passed. |
|
||||
| Security regression set | Pass | The focused People production workflow passed `60/60` tests after the review-driven coverage additions. The earlier four-file final-finding set passed `95/95`. |
|
||||
| Full suite | Pass | `262` files passed and `3` skipped; `1,649` tests passed and `5` skipped. Coverage: statements `31.53%`, branches `26.16%`, functions `36.55%`, lines `32.90%`. |
|
||||
| TypeScript | Pass | `pnpm typecheck` exited successfully. |
|
||||
| Dead-code boundary | Pass | `pnpm knip` reported no included file, dependency, dev-dependency, unlisted dependency, or binary findings. |
|
||||
| Changed-file quality | Pass | Biome checked all `9` final-review files with no remaining fixes; `git diff --check` passed. |
|
||||
| Production build | Pass | Next.js `16.3.3` compiled, typechecked, generated `129/129` pages, and exposed `/ase` plus `/ase/[domain]/[[...segments]]` as the only administration UI routes. |
|
||||
|
||||
The build used an ephemeral local `AUTH_SECRET` because production validation correctly rejects the development environment without one. It was set only in the build process and was not written to `.env`.
|
||||
|
||||
## Route and access probes
|
||||
|
||||
The post-cutover local server returned:
|
||||
|
||||
| Route | Result |
|
||||
| --- | --- |
|
||||
| `/admin` | `404`, no redirect |
|
||||
| `/admin-next` | `404`, no redirect |
|
||||
| `/ase-next` | `404`, no redirect |
|
||||
| `/mod` | `404`, no redirect |
|
||||
| `/ase` | `307` to `/login` for an anonymous request |
|
||||
| `/api/health` | `200` |
|
||||
|
||||
The production route manifest independently confirms that `/ase` is the only administration UI root while the retained `/api/admin/*` backend endpoints remain present.
|
||||
|
||||
## Visual evidence boundary
|
||||
|
||||
The authenticated pre-cutover workspace passed all `24/24` domain and viewport combinations at `1440x900`, `1024x768`, `390x844`, and `320x568`; details and screenshot locations are recorded in `2026-08-26-housekeeping-pre-cutover.md`.
|
||||
|
||||
The final cutover moved that verified workspace to `/ase` without redesigning the rendered workspace. A new authenticated post-cutover browser session was not created because doing so would have required minting or impersonating a privileged session. Final validation therefore combines the existing authenticated visual matrix with the post-cutover source move, route manifest, automated UI tests, and anonymous access probes. No live mutation was submitted.
|
||||
|
||||
## Known non-blocking environment debt
|
||||
|
||||
- `REDIS_URL` is unset locally, so the build warns that multi-instance rate limits, settings cache, and JWT invalidation would fall back to process memory. Production must provide Redis.
|
||||
- Turbopack warns that dynamic translation-file access in `mutation-runtime-external.ts` broadens filesystem tracing. The build still completes, but deployment bundle size should be monitored.
|
||||
- The repository-wide `pnpm lint` remains affected by the existing Windows CRLF baseline. The final changed-file Biome gate and `git diff --check` pass; no unrelated whole-repository formatting churn was introduced.
|
||||
|
||||
## Independent review
|
||||
|
||||
A second read-only review of `222535e1` found no Critical or Important findings and assessed the change as ready to merge. Its two Minor recommendations were both implemented: hierarchy denial now runs against ban, unban, currency, and badge bulk operations, and the production workflow now proves a successful super-admin assignment to an existing configured rank above 7.
|
||||
|
||||
## Release state
|
||||
|
||||
The implementation and local release gates are complete. The branch is suitable for continued review in draft PR #52; merge and deployment remain separate operator decisions.
|
||||
File diff suppressed because it is too large.
Load diff
@@ -1,422 +0,0 @@
|
||||
# Housekeeping Completion and Atomic Cutover Design
|
||||
|
||||
**Status:** Approved in conversation on 2026-08-26
|
||||
**Delivery branch:** `codex/housekeeping-complete`
|
||||
**Delivery shape:** one final pull request
|
||||
**Cutover:** atomic, with no compatibility redirects
|
||||
|
||||
## Relationship to the existing design
|
||||
|
||||
This specification completes the program described by
|
||||
`2026-08-24-housekeeping-modernization-design.md` after the merged Inventory &
|
||||
Foundation subproject. The existing foundation is not the finished product: it
|
||||
provides the 137-route migration matrix, capability-aware contracts, validated
|
||||
domain manifests, shell primitives, and a non-production preview.
|
||||
|
||||
This document defines the remaining implementation and the final cutover. Where
|
||||
delivery details differ, this document is authoritative for phases 02 onward.
|
||||
The master architecture remains authoritative for domain ownership and product
|
||||
behavior.
|
||||
|
||||
This completion specification supersedes the earlier documents only for the
|
||||
route namespace: the new surface uses `/ase`, never `/admin`, as its canonical
|
||||
production root.
|
||||
|
||||
## Approved decisions
|
||||
|
||||
- Build complete verticals behind the existing non-production gate.
|
||||
- Keep all remaining work on one branch and deliver it through one final pull
|
||||
request.
|
||||
- Implement in vertical slices rather than UI-first placeholders.
|
||||
- Keep current `/admin` and `/mod` behavior unchanged until the final cutover
|
||||
commit.
|
||||
- At cutover, make the new Command Deck live at `/ase`, remove the legacy
|
||||
`/admin`, `/admin-next`, and `/mod` trees, and remove obsolete legacy routes
|
||||
without redirects.
|
||||
- Use hybrid personalization: mandatory content is capability-derived; operators
|
||||
may pin and reorder allowed shortcuts and optional widgets.
|
||||
- Add only backward-compatible database migrations before cutover.
|
||||
|
||||
## Outcomes
|
||||
|
||||
The completed program must:
|
||||
|
||||
1. Give every one of the 137 legacy routes a verified canonical destination or
|
||||
an explicit removal decision.
|
||||
2. Replace the fragmented admin and moderator surfaces with one capability-aware
|
||||
Command Deck.
|
||||
3. Deliver real workflows for all retained administration responsibilities, not
|
||||
wrappers around legacy pages.
|
||||
4. Provide global search, safe commands, derived operational inboxes, recent
|
||||
work, favorites, and optional widgets.
|
||||
5. Enforce the existing ACL model on navigation, reads, mutations, commands,
|
||||
search results, inbox items, and widgets.
|
||||
6. Produce durable and sanitized audit evidence for sensitive operations.
|
||||
7. Preserve a release-level rollback path without destructive database rollback.
|
||||
|
||||
## Delivery model
|
||||
|
||||
All work is committed to `codex/housekeeping-complete`, based on the latest
|
||||
`origin/main`. No pull request is opened until every vertical and the cutover are
|
||||
implemented, reviewed, and verified.
|
||||
|
||||
The foundation currently exposes `/admin-next`. The first completion change
|
||||
renames that preview tree and its links to `/ase-next`; the preview remains
|
||||
unavailable when `NODE_ENV=production`. Development and test environments use
|
||||
`/ase-next` to exercise the new shell before cutover. The final cutover publishes
|
||||
the canonical `/ase` tree and removes the preview entry; it does not weaken the
|
||||
production preview gate before that point.
|
||||
|
||||
The branch is built in this order:
|
||||
|
||||
1. access, audit, error, and preference core;
|
||||
2. People, moderation, and support;
|
||||
3. Content and engagement;
|
||||
4. Economy and catalog;
|
||||
5. Hotel, world, and operational systems;
|
||||
6. Command Deck operations and cross-domain composition;
|
||||
7. atomic route cutover and legacy removal.
|
||||
|
||||
## Canonical route structure
|
||||
|
||||
After cutover the public administration route tree is:
|
||||
|
||||
```text
|
||||
/ase Operations workspace
|
||||
/ase/people/* users, tickets, CFH, bans, moderation, teams
|
||||
/ase/content/* articles, events, polls, media, engagement
|
||||
/ase/economy/* catalog, shop, transactions, vouchers, values
|
||||
/ase/hotel/* rooms, furni, badges, radio, emulator, Studio
|
||||
/ase/system/* settings, ACL, logs, DevOps, maintenance
|
||||
```
|
||||
|
||||
`/ase` is the operational home, not a duplicate menu page. `/admin`,
|
||||
`/admin-next`, and `/mod` have no route after cutover. A workflow has one
|
||||
canonical owner and one canonical destination; the new tree must not retain
|
||||
duplicate hubs or aliases.
|
||||
|
||||
## Module ownership
|
||||
|
||||
`src/features/housekeeping/foundation` owns only cross-cutting composition:
|
||||
|
||||
- request-scoped actor and capability context;
|
||||
- registry and navigation projection;
|
||||
- Command Deck chrome and page-state primitives;
|
||||
- command dispatch contracts;
|
||||
- search and inbox orchestration;
|
||||
- preference reconciliation;
|
||||
- shared error and audit envelopes.
|
||||
|
||||
Each domain owns its routes, pages, query services, commands, search providers,
|
||||
inbox sources, widgets, and domain-specific validation. Domains communicate with
|
||||
the foundation through the published contracts. They do not import another
|
||||
domain's internal modules.
|
||||
|
||||
The foundation must not import database clients, server actions, or domain page
|
||||
modules. Server-only domain adapters may import data and action services.
|
||||
|
||||
## Domain manifests
|
||||
|
||||
Every manifest registers real, non-placeholder definitions for:
|
||||
|
||||
- canonical routes and contextual navigation;
|
||||
- safe and sensitive commands;
|
||||
- entity-search providers;
|
||||
- derived-inbox sources;
|
||||
- mandatory and optional widgets;
|
||||
- localization keys and capability requirements.
|
||||
|
||||
Registry validation rejects duplicate IDs across all provider categories,
|
||||
duplicate routes, invalid ownership, missing localization, unknown capability
|
||||
slugs, invalid widget kinds, and commands without an owning domain.
|
||||
|
||||
The migration matrix and manifests are linked by contract tests. Every retained
|
||||
matrix row must resolve to one registered route or workflow. Every manifest
|
||||
capability set must cover the capabilities attributed to its matrix rows.
|
||||
|
||||
## Authorization flow
|
||||
|
||||
Each request creates one capability context from `getAdminContext()`. The context
|
||||
contains the authenticated actor and immutable effective permission slugs.
|
||||
Rank is informational and may influence presentation defaults only; it is never
|
||||
used as a new authorization threshold.
|
||||
|
||||
Authorization is applied at every layer:
|
||||
|
||||
1. registry projection removes inaccessible domains and routes;
|
||||
2. provider orchestration calls only permitted providers;
|
||||
3. providers filter inaccessible results and items;
|
||||
4. page loaders revalidate their required capability;
|
||||
5. command execution revalidates capability and input on the server;
|
||||
6. the underlying mutation service retains its own permission guard.
|
||||
|
||||
Client state, hidden navigation, preferences, or a previously loaded page never
|
||||
authorize an operation.
|
||||
|
||||
## Commands and audit
|
||||
|
||||
Commands use typed input schemas and typed success/error results. Safe commands
|
||||
may execute directly from the palette. Sensitive commands open a dedicated
|
||||
contextual confirmation flow and require a reason when the command contract says
|
||||
so.
|
||||
|
||||
The existing `admin_audit_log` remains the canonical audit store. An additive
|
||||
migration adds nullable `correlation_id varchar(64)`, `outcome varchar(32)`,
|
||||
`reason text`, and `domain varchar(32)` columns plus an index on
|
||||
`correlation_id`. Existing `action`, `target`, `target_id`, `before`, `after`,
|
||||
`diff`, `ip_address`, and actor fields remain in use.
|
||||
|
||||
- Database mutations write mutation and audit evidence in the same transaction
|
||||
whenever the affected service uses the same database connection.
|
||||
- Sensitive external or file operations persist an audit intent before
|
||||
execution and a final outcome afterward. Failure to persist the intent blocks
|
||||
execution.
|
||||
- Audit payloads pass through the existing recursive secret redaction.
|
||||
- Every command result and audit record carries the same correlation ID.
|
||||
- Failed, denied, and partially completed sensitive operations are audited.
|
||||
|
||||
## Preferences
|
||||
|
||||
No suitable user-scoped HK preference store currently exists. Add
|
||||
`housekeeping_user_preferences` with:
|
||||
|
||||
- `user_id int` as the primary key and unique owner;
|
||||
- `schema_version int not null default 1`;
|
||||
- `payload longtext not null`, containing validated JSON presentation state;
|
||||
- `created_at datetime` and `updated_at datetime` timestamps.
|
||||
|
||||
The payload stores pinned route/command IDs, shortcut order, widget order, and
|
||||
enabled optional widget IDs. It never stores permissions, authorization
|
||||
decisions, workflow state, or inbox status.
|
||||
|
||||
Every read reconciles stored IDs against the current registry and effective
|
||||
capabilities. Unknown, removed, or unauthorized entries are dropped before the
|
||||
payload reaches the UI. Mandatory widgets cannot be disabled.
|
||||
|
||||
## Command Deck experience
|
||||
|
||||
The shell has four stable regions:
|
||||
|
||||
1. a compact six-domain rail;
|
||||
2. domain-owned contextual navigation;
|
||||
3. a global search and command field with keyboard access;
|
||||
4. an operational workspace for pages, inboxes, recent work, and widgets.
|
||||
|
||||
Desktop and mobile share the same semantic hierarchy. Mobile collapses the rail
|
||||
and contextual navigation without changing route ownership or available
|
||||
actions. Focus order, landmarks, headings, active-state uniqueness, keyboard
|
||||
navigation, reduced motion, and semantic theme tokens are tested contracts.
|
||||
|
||||
Loading, empty, partial, error, forbidden, and ready states use the shared page
|
||||
state primitives. Partial provider failure is visible without replacing valid
|
||||
results from other providers.
|
||||
|
||||
## Search
|
||||
|
||||
Search supports navigation, entity results, and commands. It is not a raw
|
||||
database search endpoint.
|
||||
|
||||
- A term shorter than two trimmed characters performs navigation/command
|
||||
matching only.
|
||||
- Entity providers have a two-second timeout and a maximum of 25 results each.
|
||||
- The combined entity response is capped at 50 results before client rendering.
|
||||
- Providers run only when their declared capability is satisfied.
|
||||
- Results include stable ID, owner, type, title, optional description, canonical
|
||||
href, and capability metadata.
|
||||
- Provider errors produce a typed partial result and do not fail unrelated
|
||||
providers.
|
||||
- Search terms and result payloads are not written to audit logs by default.
|
||||
|
||||
## Derived operational inbox
|
||||
|
||||
The inbox is a read model over domain-owned work: tickets, CFH reports, alerts,
|
||||
emulator errors, operational anomalies, and other existing live states. It does
|
||||
not introduce a second assignment or task-status system.
|
||||
|
||||
Each inbox item exposes stable source/item IDs, domain, type, title, priority,
|
||||
age, state, canonical href, available actions, and required capability. Source
|
||||
items are deduplicated by the pair `(sourceId, itemId)`.
|
||||
|
||||
Sources run independently with a two-second timeout. The composed response
|
||||
contains successful items plus per-source errors. The server caps the result at
|
||||
200 items after capability filtering and deterministic priority/age ordering.
|
||||
|
||||
## Recent work, favorites, and widgets
|
||||
|
||||
Recent work is derived from the operator's existing audit events and canonical
|
||||
route visits; it does not create workflow state. Favorites and ordering come
|
||||
from the reconciled preference payload.
|
||||
|
||||
Mandatory widgets are supplied by the system according to capability and cannot
|
||||
be removed. Optional widgets can be enabled and reordered. Widget loaders are
|
||||
server-side, capability-checked, independently timed out, and represented as
|
||||
partial failures rather than shell failures.
|
||||
|
||||
## Vertical scope
|
||||
|
||||
### Access, audit, and system core
|
||||
|
||||
- command dispatcher and confirmation model;
|
||||
- audit extension and correlation IDs;
|
||||
- typed error taxonomy and boundary mapping;
|
||||
- preference repository and reconciliation;
|
||||
- shared provider orchestration and timeout behavior;
|
||||
- System routes for ACL, settings, logs, DevOps, and maintenance.
|
||||
|
||||
### People, moderation, and support
|
||||
|
||||
- user discovery, details, editing, password/reset controls, account relations,
|
||||
bans, and permitted staff actions;
|
||||
- help tickets and moderator tickets;
|
||||
- CFH queues and details;
|
||||
- moderation actions, team views, and ban workflows;
|
||||
- People search providers, inbox sources, commands, and widgets.
|
||||
|
||||
This vertical proves that all retained `/mod` responsibilities work inside the
|
||||
new capability model before `/mod` is removed.
|
||||
|
||||
### Content and engagement
|
||||
|
||||
- articles, events, polls, media, navigation content, tags, banners, and related
|
||||
editorial tools;
|
||||
- Content search, commands, inbox sources, and widgets;
|
||||
- consolidation of duplicate editorial hubs into canonical workflows.
|
||||
|
||||
### Economy and catalog
|
||||
|
||||
- catalog and item management, Builder Club catalog, maintenance, shop,
|
||||
transactions, vouchers, subscriptions, marketplace, and value tools;
|
||||
- Economy search, commands, anomaly sources, and widgets;
|
||||
- existing specialized editors remain components of canonical workflows rather
|
||||
than parallel navigation roots.
|
||||
|
||||
### Hotel, world, and operational systems
|
||||
|
||||
- rooms and room furni, badges, sounds, radio, emulator controls, imports, and
|
||||
Studio tools;
|
||||
- Hotel search, commands, operational sources, and widgets;
|
||||
- long-running operations retain progress/error behavior and gain consistent
|
||||
capability and audit envelopes.
|
||||
|
||||
### Operations composition
|
||||
|
||||
- global search and command palette;
|
||||
- derived inbox and partial-source reporting;
|
||||
- recent work and favorites;
|
||||
- mandatory operational summaries and optional widgets;
|
||||
- no duplicate mutation logic: actions route to the owning domain command.
|
||||
|
||||
## Error model
|
||||
|
||||
All HK services return typed errors from this stable set:
|
||||
|
||||
- `UNAUTHENTICATED`;
|
||||
- `FORBIDDEN`;
|
||||
- `VALIDATION`;
|
||||
- `NOT_FOUND`;
|
||||
- `CONFLICT`;
|
||||
- `RATE_LIMITED`;
|
||||
- `DEPENDENCY_UNAVAILABLE`;
|
||||
- `TIMEOUT`;
|
||||
- `INTERNAL`.
|
||||
|
||||
User messages are localized and do not expose internal details. Server logs and
|
||||
audit evidence include correlation IDs. Expected domain errors do not rely on
|
||||
framework exception text. Unknown errors are sanitized at the boundary and
|
||||
logged once.
|
||||
|
||||
## Database changes
|
||||
|
||||
Allowed pre-cutover migrations are additive only:
|
||||
|
||||
1. nullable HK audit metadata columns on `admin_audit_log`;
|
||||
2. the `housekeeping_user_preferences` table and its unique user index.
|
||||
|
||||
No legacy table or column is dropped or repurposed in this program. Removal of
|
||||
legacy UI routes is an application cutover, not a destructive data migration.
|
||||
|
||||
## Atomic cutover
|
||||
|
||||
The final cutover commit is created only after all vertical gates pass. It:
|
||||
|
||||
1. moves the completed shell and Operations workspace from `/ase-next` to
|
||||
`/ase`;
|
||||
2. changes domain preview hrefs to canonical `/ase/<domain>` hrefs;
|
||||
3. updates internal links, navigation configuration, and authorization fallback
|
||||
destinations;
|
||||
4. removes the legacy `/admin`, `/admin-next`, and `/mod` route trees plus every
|
||||
legacy route marked `REMOVE`;
|
||||
5. removes legacy pages whose behavior moved or merged into canonical routes;
|
||||
6. removes the temporary preview entry and flag if no longer used by tests;
|
||||
7. adds no compatibility redirects.
|
||||
|
||||
The cutover must leave no links, imports, route discovery entries, or tests that
|
||||
depend on removed UI modules.
|
||||
|
||||
## Verification strategy
|
||||
|
||||
Each vertical uses TDD and has four gates:
|
||||
|
||||
1. contract and authorization tests;
|
||||
2. domain query/command behavior tests, including denied and failure paths;
|
||||
3. page and accessibility behavior tests;
|
||||
4. cumulative Housekeeping and repository verification.
|
||||
|
||||
The final branch requires:
|
||||
|
||||
- the migration matrix reporting 137/137 valid with every retained row linked to
|
||||
a canonical implementation;
|
||||
- mutation-sensitive authorization, provider, command, audit, and preference
|
||||
tests;
|
||||
- full project tests, Housekeeping tests, typecheck, semantic Biome, targeted
|
||||
formatting checks, and `git diff --check`;
|
||||
- production build with temporary environment restoration;
|
||||
- visual verification at desktop and mobile widths for every domain and shared
|
||||
state;
|
||||
- route-level smoke checks for canonical `/ase` pages, denied access, and
|
||||
removal of `/admin`, `/admin-next`, `/mod`, and obsolete routes;
|
||||
- a broad whole-branch code review followed by one reviewed fix wave if needed.
|
||||
|
||||
Repository-wide pre-existing formatter debt is reported separately and must not
|
||||
be hidden by mass-formatting unrelated files.
|
||||
|
||||
## Merge, deployment, and rollback
|
||||
|
||||
The single pull request targets `main` only after all final gates pass. Merging
|
||||
is the atomic release boundary; no partial vertical is intentionally exposed to
|
||||
production operators.
|
||||
|
||||
After merge, the deployment pipeline must complete and `/api/health` must be
|
||||
verified live. A push or successful build alone is not deployment evidence.
|
||||
|
||||
Rollback deploys the prior application release. Because database changes are
|
||||
additive and ignored by the prior release, rollback does not require manual data
|
||||
reversal. If audit or preference migrations themselves fail, deployment stops
|
||||
before serving the cutover release.
|
||||
|
||||
## Explicit non-goals
|
||||
|
||||
- A new task-assignment system for inbox items.
|
||||
- A replacement authentication or ACL model.
|
||||
- Rank-based authorization thresholds.
|
||||
- Compatibility redirects for removed `/admin`, `/admin-next`, or `/mod`
|
||||
routes.
|
||||
- Destructive cleanup of legacy database data.
|
||||
- Rewriting specialized domain engines that already work; they are integrated
|
||||
behind consistent domain contracts instead.
|
||||
- Unrelated CMS redesign or repository-wide formatting cleanup.
|
||||
|
||||
## Completion criteria
|
||||
|
||||
The program is complete only when:
|
||||
|
||||
- all retained legacy capabilities are available through canonical new routes;
|
||||
- all six manifests contain real routes/providers/widgets rather than empty
|
||||
placeholders;
|
||||
- the Command Deck search, commands, inbox, preferences, recent work, and widgets
|
||||
operate against real domain services;
|
||||
- capability enforcement and audit evidence cover every exposed read and
|
||||
mutation path;
|
||||
- `/ase` serves the new HK; `/admin`, `/admin-next`, `/mod`, and removed legacy
|
||||
routes are unreachable; and no compatibility redirects exist;
|
||||
- final local, CI, deployment, health, and visual evidence are all recorded.
|
||||
Reference in new issue
Block a user