- Add deployment-name branding to titles, mastheads, and OG tags
- Share one grant delivery-state query with lineage across grants
surfaces
- Show pool status/usage, org owners, and config readiness
- Make billing views projection-aware with recency and sync vocabulary
- Guard FedWiki creation without domains and render route-aware 404s
Enforce 10j's verified gaps (schema-hardening change):
- Migration 00010: partial unique indexes for one default pool and one
primary assignment per workspace, plus CHECKs pinning
pool/provider/subscription vocabularies and provider lifecycle
timestamps.
- Workspace creation shares a transactional provisioning function;
extension validates its target pool; last-tier deletion of a defaulted
ladder is guarded; signup completes plan-less on a broken ladder.
- Boot asserts integration slug parity and validates declared config
enums; Stripe invoice amounts are range-checked; domain cancellation
runs a final evidence probe; rule authoring is additive-only.
Add lifecycle_status = 'published' to the public-catalog queries
(plans and add-ons listings) and reject checkout before any Stripe
call unless the product behind the price clears the shared member
gate (published + active + public). The currently-enrolled ladder
rung stays renderable even if its product is later drafted or
retired, fetched directly so members keep seeing what they are on.
Introduce a single evaluateMemberGate definition shared by the
catalog paths and the operator readiness panel so the surfaces
cannot disagree about what is publishable for members.
Write the eight domain-model cards under `docs/models/`, mark M10 10i
Done, and update the design docs to v16. Also records Doc 44, which
ratifies Decisions 129-133 as amended, and the Doc-39 conformance
check that satisfied its gate.
Introduce `docs/models/` with the catalog index and its first card
(product-catalog), recording invariants, dimensions, and drift traps
per the Decision 141 documentation division. Add the model-cards
openspec change (proposal, design, spec, tasks) and sync the design
docs to v15: product kind taxonomy dissolved (Decisions 134–139),
Decisions 140–141 ratified, and product/pricing helpers updated. The
catalog is the single descriptive home for as-built models.
Configure the personal org-type default ladder and floor vacant pools so
the seeded dataset survives grant revocation. Let the modal mechanics
test
fall back to plan-ladder action triggers in full-suite order.
Put the fedwiki chain (init, render, farm, caddy) behind a fedwiki
compose profile symmetric with discourse's; the default composition is
neither, selected via COMPOSE_PROFILES in test/.env, so a default stack
no longer binds host 443.
Guard every script and walkthrough on service presence: shared
skipUnlessIntegrationEndpointReachable helper, seed-stack presence
checks (also repairing its unsourced .env and container-native render
invocation), generic root-owned testdata reclaim in teardown, discourse
coverage in verify-stack-isolation, and fedwiki's 8090 base in the port
probe.
Update stack docs and finalize status bookkeeping for all three
changes; archives the test-stack-integration-profiles change.
Run Docker runtime stage as non-root user app (UID 65532).
Add styled full-page 404/500 error rendering for navigation requests
while preserving plain-text responses for HTMX partials.
Reuse recent unconsumed OIDC login state to avoid state mismatch on
parallel login hits, and merge resource_access in role extraction.
Re-level template headings, add autocomplete tokens, and resolve
catalog resource display names.
Self-label test-stack secrets and document CSRF secret rotation.
Replace domain claims with open invoices, show monthly recurring
revenue,
count team organizations, and add more informative trend captions.
Use standard bordered cards and add a README screenshot with reversible
sample-data tooling.
Registry.ClaimExternal now enforces the plan gate itself via an injected
domains.ExternalClaimGate (pre-lock, typed refusals), so every entry
point — and any future consumer — inherits it from the allocation API.
One constructor in internal/server builds the gate from the entitlements
querier and connect target; it is injected into the member-facing
registry constructions in server.go and fedwiki.go and drives affordance
rendering on both surfaces. The duplicated helpers and resource-key
constants in fedwiki web and member_domains are gone; fedwiki no longer
reads entitlement tables for this gate at all.
Archives the change with the domains-registry spec delta (enforcement
location is now requirement-level: registry-inherited, surfaces derive).
Closes the entitlement-gate placement debt in issues.md; files the
separately-discovered operator force-release dead-end affordance bug
that a placed claim exposed in the domains walkthrough.
Domains leaves the member nav everywhere; GET /domains 302s to the
dashboard and domains.html is deleted. Claims are managed where they are
used: the fedwiki sites card embeds the core claims partial, a
server-conditional dashboard notice carries pending verifications (the
durable re-entry now that the page is gone), and the member_domains
partials retarget to 'closest .domains-surface' so multiple hosts coexist
on one page. Adding an external domain starts only from the create form;
the fedwiki banner slims to verified-unplaced one-click creates, since
the notice and embedded section own the pending state.
Verified at the surface end-to-end (stack + Chrome): nav absence,
redirect, notice lifecycle through claim-cancel, and cross-host swap
isolation with two claim views open. Archives the change with spec
deltas synced (domains-registry point-of-use rewrite, fedwiki-sites and
member-dashboard additions); files the entitlement-gate placement debt
in issues.md; adds the repo verify skill.
Sweep stranded pending claims at boot and on a Temporal schedule while
preserving evidence-based abandonment semantics.
Apply occupancy and name-policy checks to carves by operator-root owners
without affecting direct operator placements.
Resume only app-paused schedules so operator pauses survive restarts.
Apply dormancy handling to Discourse and FedWiki.
Remove the unused pool-scoped grant route, hide internal transition
errors, and update specs and tests to use the canonical grant endpoint.
Render grant extension controls only for active grant-backed provisions.
Scan for valid walkthrough subjects and skip when Discourse is
unreachable.
Add a fresh-stack target and document the supported e2e workflow.
Report malformed sequences on the validation page and topology health
strip. Normalize fulfillment and Stripe webhook fixtures to preserve
contiguous, zero-based ranks.
List every provider kind with direct settings and admin links, move
FedWiki
under the integrations route, and add in-shell operator 404s.
Report sync health from Temporal schedule executions and clear one-shot
settings feedback parameters after display.
Persist non-secret ConfigSpec overrides in core and apply them at boot
ahead of environment values and defaults. Validate typed and enum
values,
show pending restart state, and remove Stripe's unused provider config
table.
Re-resolve members absent after batch adds by forum user ID. Update
renamed
usernames and quarantine deleted users so they cannot block healthy
group
delivery. Align the fake with Discourse's partial-batch semantics.
Run group sync every minute with immediate triggering, and disable
first-post
typing heuristics that silence test users. Document how stale usernames
can
poison batch group convergence.
Classify resource keys as boolean or numeric, adapt the operator form to
the selected key, and derive rule types server-side to prevent
wrong-shape rules.
Render generic HTMX card shells from integration declarations. Move the
FedWiki UI into its partial, add Discourse forum status, and label
member
entitlements with provider attribution.
Stripe's webhook deduplication used ON CONFLICT on a partitioned table
where the unique key included received_at, which only collapsed
same-instant duplicates. Switch to WHERE NOT EXISTS to deduplicate
across time.
FedWiki's operator page failed to render because html/template's
escape analysis requires all referenced templates in the set, even on
untaken branches. Include partials/operator_lookup_result.html in the
parsed template set.
Move resolved issues to archive.
Deliver forum posting entitlements through managed group membership with
identity linkage, periodic reconciliation, webhook handling, and an
operator mapping surface.
Include fake and live test environments, setup documentation,
migrations,
and end-to-end coverage.
Persist pool-scoped grants using OR semantics across active provisions,
retaining lapsed rows for transition visibility. Add consumer queries,
DB-backed coverage, and plans for the dependent Discourse integration.
Preview affected orgs by position source and require keep or migrate for
default-sourced positions. Commit deletion, renumbering, and holder
reconciliation atomically while preserving other-source delivery.
Classify rank-zero changes for default ladders and require operators to
grandfather or migrate affected organizations before applying ranks.
Fix operator attribution during tier induction backfills and make the
grant
extension walkthrough's optional-form check panic-safe.
Only create schedules after Temporal NotFound and update after
concurrent
creation. Resolve the system workspace on every workflow run so
persisted
schedule arguments cannot retain stale IDs after database resets.
Replace product-kind branching and direct position writes with enclosed
database functions driven by structural product shape.
Migrate grant and provision data, unify operator issuance, update
subscription and expiry flows, and add migration and integration proofs.
Clarify provider vs integration terminology and document the in-tree
distribution model. Refresh M9 status, issue tracking, and lint/doc
links to
use the new language.
Add an explicit registry with capability hooks for migrations, routes,
workflows, config, and UI assets. Move FedWiki fully and Stripe's
separable
store, workflow, and webhook pieces under internal/integrations.
Drive startup wiring from declarations, including config validation,
secret
file pairs, CSRF exemptions, UI composition, and workflow startup. Move
integration DB roles and grants into their owning migration streams, and
route outbox writes through a shared enqueue helper.
Run goose once per migration source with its own
goose_db_version_<name> table and native file numbering.
Remove positional namespace assembly, update rollback/status behavior,
and document the OpenSpec decision.
Squash the pre-production migration history into fresh core, fedwiki,
and stripe baselines and reduce the canonical source list to those
three streams.
Update sqlc configs, generated queries, raw SQL, tests, and docs while
keeping provider tables schema-qualified.
BREAKING: existing local database volumes must be wiped because goose
version history restarts from the new baselines.
purchasability-sync-completion changes
Deferred live verification for ladder-tier-append and
multi-price-support to maintainer; stack left running. Validated
ladder-tier-append with openspec --strict. Closed purchasability
checklist issue and marked milestone 10c Done. Archived specs into
archive directory and created db-error-presentation spec. Updated
plan-ladder-management and price-management specs with tier append,
reorder, removal, and price default behavior.
Preserve stored ladder active state on update, and refresh
milestone/status
docs for the M10/M11 renumbering and audit debt tracking.
Hide inert ladder active controls
Preserve the stored ladder active flag on update, and remove active
status
from ladder list/topology views until retirement has real behavior.
Update audit and milestone docs for the M10 renumbering and 10h
completion.
Fix HTMX expired-session handling, CSP-blocked form behaviors, reorder
recovery, billing currency display, plan/checkout guards, FedWiki quota
edge cases, and operator/member empty/error states.
Add entitlement uniqueness migrations, canonical migration source
wiring,
and regression coverage for the remediated flows. Update status docs
with
the audit triage and model inventory.
Completes the purchasability create-to-sell journey with live-update UX.
- Extract readiness card into operator_product_readiness.html partial.
- Live-poll (hx-trigger every 3s) while a Stripe sync is pending; reply
HTTP 286 (htmx stop-polling) once terminal (synced/failed). Route:
GET /partials/operator/products/{productID}/readiness.
- Failed-state derivation: query integration.outbox for dead_letter rows
(create_stripe_product/price); render sync failure with the real outbox
error and a Retry button (hx-post to SyncProductToStripe, resets
dead_letter→pending).
- Rename 'Stripe-mapped price' row to 'Payment processing' with de-jargoned
detail/empty-state copy.
- Truthful Stripe-configured gate: OperatorPartialsHandler carries
StripeConfigured (set from cfg.StripeAPIKey/StripeWebhookSecret) instead
of guessing from stripeQ != nil.
- Render tests cover failed branch (badge + error + Retry), Stripe-off
empty-state, polling attrs present while pending/absent when terminal.
Plus status/: adversarial UX audit (56 confirmed findings, 16 high) and
cross-cutting audit entry in issues.md.
Closes: openspec/changes/purchasability-sync-completion
Seed Keycloak into a dedicated wikicafe app realm and repoint the
test OIDC, Temporal, and FedWiki wiring to it.
Label test credentials as throwaway, remove the unused realm export from
tracking, and have init write the embedded starter config.
Fail fast with aggregated config errors after resolving secret files,
before services initialize. Add Valkey session config, remove the unused
session-secret, and fix the production CSP env key.
Retry initial Temporal dials with bounded backoff and gate the test
Temporal service on healthy DB and Keycloak dependencies.
Rewrite the README around purpose, architecture, quickstart, and
status. Add contributing/security policies plus a docs index with
audience front matter across existing docs.
Move closed issues and completed milestone detail into status/archive.
Keep active issues and milestones lean, grouped by theme, and update the
status dashboard and maintenance guidance.