Phase D: ProShop correctness (write gate, retry-safe push, ALL3 read) #3

Merged
parley merged 1 commit from finish/phase-d-proshop into develop 2026-08-16 20:37:17 +00:00
Owner

Summary

  • Process kill-switch ALLOY_PROSHOP_WRITES_ENABLED (default off) and shop writes_enabled and client mutation guard and company allowlist default ALL3
  • Push is lookup-or-adopt (part/estimate); IDs committed after each step; template ops skipped
  • Push failures are 403/422/502/503 — no HTTP 200 with {status: failed}
  • Sync watermark does not advance when any record failed; ProShop down → 502
  • ALL3 is a company code on the live Inno instance, not a tenant
  • Launch depth recorded: estimate + WO only (no quote / addCustomerPo)
  • D4 live write blocked: this OAuth client is read-only (invalid_scope on :w/:rw)

No frontend / Phase E/F. No worktrees.

Evidence

  • VERIFY: docs/plans/2026-08-01-phase-d-proshop/VERIFY.md
  • Local: ruff check backend clean; pytest -m "not postgres" 229 passed
  • Local postgres: not run (Docker/OrbStack down this session) — CI postgres job is the remote lane
  • ALL3 read: probe-all3.py green (ALL3 / Alloy_TEST / ALL3-12345)
  • Residuals: D4 write IDs wait on OAuth write entitlement

Test plan

  • CI backend green
  • CI postgres green (migration 006_phase_d_proshop)
  • Do not enable writes in staging until SCOPES.md has a live WRITE_SCOPE
## Summary - Process kill-switch `ALLOY_PROSHOP_WRITES_ENABLED` (default off) **and** shop `writes_enabled` **and** client mutation guard **and** company allowlist default `ALL3` - Push is lookup-or-adopt (part/estimate); IDs committed after each step; template ops skipped - Push failures are 403/422/502/503 — no HTTP 200 with `{status: failed}` - Sync watermark does not advance when any record failed; ProShop down → 502 - ALL3 is a **company code** on the live Inno instance, not a tenant - Launch depth recorded: estimate + WO only (no quote / `addCustomerPo`) - **D4 live write blocked:** this OAuth client is read-only (`invalid_scope` on `:w`/`:rw`) No frontend / Phase E/F. No worktrees. ## Evidence - VERIFY: `docs/plans/2026-08-01-phase-d-proshop/VERIFY.md` - Local: `ruff check backend` clean; `pytest -m "not postgres"` **229 passed** - Local postgres: not run (Docker/OrbStack down this session) — CI postgres job is the remote lane - ALL3 read: `probe-all3.py` green (`ALL3` / Alloy_TEST / `ALL3-12345`) - Residuals: D4 write IDs wait on OAuth write entitlement ## Test plan - [ ] CI backend green - [ ] CI postgres green (migration `006_phase_d_proshop`) - [ ] Do not enable writes in staging until `SCOPES.md` has a live `WRITE_SCOPE`
Phase D: ProShop write gate, lookup-or-adopt push, honest errors
All checks were successful
CI / Backend (ruff + pytest) (pull_request) Successful in 1m37s
CI / Backend (Postgres RLS) (pull_request) Successful in 27s
05dbe2d315
App writes require process ALLOY_PROSHOP_WRITES_ENABLED, shop
writes_enabled, client.writes_enabled, and company allowlist (default
ALL3). Push looks up or adopts part/estimate IDs and commits them
before later steps. Failures are 403/422/502/503, not HTTP 200.
Sync does not advance the watermark when any record failed.

ALL3 read probe is green. Live write is blocked: this OAuth client
returns 403 invalid_scope for :w/:rw. Evidence in
docs/reference/proshop-api/ and VERIFY.md. No frontend / Phase E.
parley merged commit a6750a3625 into develop 2026-08-16 20:37:17 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
numencore/alloy!3
No description provided.