Skip to content

feat(public-orders): anonymous publicGetOrderOffer read behind the share URL - #683

Open
dmeiser wants to merge 4 commits into
fm/KW-PUBLIC-ORDERS-SETTINGS-1from
fm/KW-PUBLIC-ORDERS-OFFER-1
Open

dmeiser wants to merge 4 commits into
fm/KW-PUBLIC-ORDERS-SETTINGS-1from
fm/KW-PUBLIC-ORDERS-OFFER-1

Conversation

@dmeiser

@dmeiser dmeiser commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Intent

"we're building this" — the public order placement feature described in data/KW-PUBLIC-ORDERS/spec.md. This slice builds the first thing a buyer ever touches: the anonymous read that turns a share URL into a real page. Given a bare profile id and the token from the URL, it answers what the seller is offering — who they are, which campaign, the catalog to pick from, and the payment methods they allowed — including a short-lived presigned image for each method that has a QR code. No login, no account, no money.

The spec is the design of record: read §5.3 (public read), §7, §9, §10.2 and §11 before you start. Two measured facts are settled and must not be re-derived: an object type reachable from a key-only field must itself carry the key directive or its fields are denied to the buyer caller, and AppSync's auth directives are an exclusive per-field allow-list — a signed-in caller is refused on a key-only field. The six public types and their markers already exist from the schema slice; you are writing the handler behind one of them.

What Changed

  • Add src/handlers/public_orders_offer.py, the handler behind the publicGetOrderOffer public field: given a bare profile id and URL token it locates the profile through profileId-index (GSI as locator only, strongly consistent re-reads to disambiguate a transfer projection), confirms the row with a consistent base-table GetItem, compares the token with hmac.compare_digest, then GetItems the anchor campaign by canonical id, its catalog, and the owner account's preferences.paymentMethods — answering an identical NOT_FOUND on every negative branch, intersecting the seller's allowlist with stored methods case-insensitively, and pre-signing short-lived QR image URLs (with token/S3-key log redaction enforced at the handler boundary).
  • Wire it as a direct UNIT resolver (lambda_unit_resolver.js) on a new PublicOrdersDS Lambda datasource, register the public-orders Lambda function across dev/ephemeral/prod, and add a scoped lambda_public_orders_execution IAM role (read-only GetItem/Query on profiles/campaigns/catalogs/accounts, deliberately no orders access, plus s3:GetObject on payment-qr-codes/* for the buyer's pre-signed GETs) with matching ephemeral recovery-import lines.
  • Add unit coverage for the handler, role scope, and resolver wiring (including the lambda_unit_resolver field table and a refactor of the public-settings wiring helpers), and update docs/SCHEMA.md and AGENTS.md to reflect the landed offer read.

Risk Assessment

✅ Low: The offer read is tightly scoped (read-only domain role, uniform NOT_FOUND across all negative branches, constant-time token compare, explicit-key pre-signing with zero S3 calls, token/key scrubbed from every log surface) and is pinned by behavioral moto tests plus static IAM and schema-directive contract tests; only minor informational items were found.

Testing

Built a disposable moto-backed local AWS stack and drove the real resolver/pipeline code, the real lambda_unit_resolver.js, and the real public_orders_offer Lambda handler through 11 live scenarios (share-URL offer with a fetched pre-signed QR image, identical-NOT_FOUND probing, ambiguous-projection and anchor/catalog guards, allowlist intersection, disable/re-enable token stability, owner-only gate, enable validation, first-enable race CONFLICT, log hygiene), plus live runs of the integration-env CLI for both API-key present/absent stacks — all passed — corroborated by 170 targeted unit-test passes; the real AppSync auth layer and the not-yet-emitted cap error could not be driven live (expired AWS session / no emitting path on this branch) and are reported as untested.

  • Live validation: ✅ go - 11 of 13 scenarios driven live against the product
Scenario Result Live Evidence
Buyer opens the share URL and gets the full offer — seller, campaign (bare id), catalog products in catalog order with malformed rows dropped — plus a pre-signed QR image URL that fetches the real ima… ✅ pass live transcripts/live_calls.json (happy-path publicGetOrderOffer entry with identity: null) and transcripts/qr_fetch.txt (HTTP 200, 70 bytes, PNG magic, Expires ≈ now+900s); scenario_results.json scenari…
Probing cannot distinguish never-enabled, unknown, disabled, or wrong-token profiles — every negative branch returns the identical NOT_FOUND 'Offer not available' ✅ pass live transcripts/negative_offer_errors.json (11 probes, one distinct response) + live_calls.json error entries
Ambiguous post-transfer profileId-index projection serves nothing instead of guessing an owner ✅ pass live scenario_results.json post-transfer-ambiguous-profile-projection-is-not-found-not-a-guess + 'Ambiguous profileId-index projection' WARNING in transcripts/offer_lambda_stdout.txt
Inactive, deleted, and dangling anchor campaigns and a soft-deleted catalog block the offer, while a campaign missing isActive still serves (back-compat) ✅ pass live scenario_results.json inactive-or-dangling-anchor-and-soft-deleted-catalog-block-the-offer (6 checks) with live_calls.json probe entries
Payment methods are the case-insensitive allowlist intersection (un-stored dropped, Cash not force-added, legacy full-URL QR row presigned) and empty product/method lists are still a successful offer ✅ pass live scenario_results.json allowlist-intersection-legacy-qr-url-and-empty-lists-still-succeed (6 checks); allowlist changes made through the real settings pipeline
Disabling revokes the offer but keeps the share token, re-enabling restores the same URL, and the off-switch works even over a dead anchor ✅ pass live scenario_results.json disable-revokes-the-offer-but-keeps-the-share-token-re-enable-restores-it (8 checks)
The owner-only settings gate refuses a stranger, a WRITE-share collaborator, and an unknown profile with an identical FORBIDDEN, and refused mutations change nothing ✅ pass live scenario_results.json owner-only-settings-gate-refuses-collaborator-stranger-and-unknown-identically (8 checks) + FORBIDDEN entries in live_calls.json
Enabling refuses a missing/foreign/inactive campaign, a deleted catalog, a missing method list, and an unaccepted acknowledgement — writing nothing on any rejection ✅ pass live scenario_results.json enabling-rejects-missing-campaign-foreign-campaign-inactive-catalog-no-methods-no-ack (8 checks), ending with profile B still never-enabled
A concurrent first enable loses with CONFLICT instead of overwriting the winner's token — one token stands ✅ pass live scenario_results.json concurrent-first-enable-second-writer-gets-conflict-not-double-mint (3 checks); writer2's conditioned UpdateItem fails on attribute_not_exists(publicOrders.#token) exactly as d…
Offer logs never contain the share token or the QR object key on any branch ✅ pass live scenario_results.json logs-never-contain-the-share-token-or-the-qr-object-key (5 checks) over transcripts/offer_lambda_stdout.txt
The integration-env generator threads TEST_APPSYNC_API_KEY/VITE_APPSYNC_API_KEY when the stack exposes appsync_api_key and cleanly omits them (commented placeholder, --check green) when it does not ✅ pass live transcripts/generate_integration_env_live.txt (both fixture runs plus --check exits 0) and generated files under evidence/…/envgen/
On the real AppSync endpoint, a signed-in Cognito caller is refused on the @aws_api_key-only public field while an API-key caller passes, and every public type carries the key directive so sub-fields… ⏸️ untested no Requires a deployed AppSync API: aws sts get-caller-identity fails with 'Your session has expired. Please reauthenticate using aws login' — re-authentication is interactive and writes user-level cre…
The frontend maps PUBLIC_ORDER_LIMIT_EXCEEDED to the friendly campaign-cap message a buyer would see ⏸️ untested no No live surface exists on this branch: by recorded decision F2 (accepted, no change) no code path emits PUBLIC_ORDER_LIMIT_EXCEEDED yet — the publicCreateOrder write slice that owns the cap is a later…
Evidence: Live validation report (scenarios, harness description, untested reasons, F2 acceptance)
# Live validation report — public orders offer slice (fm/KW-PUBLIC-ORDERS-OFFER-1)

Target commit `8dedc4e2471310ff48939f98b096cbd8ead7adc2` (base `4a187037`).
Intent: the anonymous read behind `/o/<profileId>/<token>` — `publicGetOrderOffer`
plus the owner-only settings surface it depends on. No login, no account, no money.

## How it was driven (disposable environment, built for this run)

The AWS layer is unreachable from this step (see Untested below), so the harness
stands up the product's runtime locally and drives the **real product code**:

- `harness/stack.py` — a moto `ThreadedMotoServer` on localhost: real HTTP
  DynamoDB + S3 endpoints, created with the project's own table schemas
  (`tests/unit/table_schemas.py`) and seeded with a seller account, two profiles,
  campaigns, catalogs, QR PNG objects, and a WRITE share row. The product is
  pointed at it through its own isolation mechanism (`DYNAMODB_ENDPOINT`,
  `S3_ENDPOINT` — `src/utils/boto.py`, `src/utils/dynamodb.py`), with dummy
  credentials and an empty `AWS_CONFIG_FILE` (the operator's `~/.aws` is never read).
- `harness/driver.mjs` — executes the **real AppSync pipeline root resolvers and
  pipeline functions** (`tofu/application/appsync/js-resolvers/*.js`) in the exact
  order declared in `resolvers_queries.tf` / `resolvers_mutations.tf`, issuing
  their datastore requests over HTTP to the local DynamoDB; and for the offer,
  runs the **real `lambda_unit_resolver.js`** `request()`/`response()`, feeds its
  Invoke payload to the **real Python Lambda handler**
  (`src/handlers/public_orders_offer.py`, imported the way the Lambda zip does)
  in a subprocess, and fetches the pre-signed QR URL over HTTP from local S3.
  An `@aws-appsync/utils` shim (`harness/appsync_utils.js`) provides the runtime
  primitives (real clock, real `autoId`, `util.error`, `runtime.earlyReturn`) —
  it stands in for the AppSync *service*, not for any product logic.
- The operator CLI `scripts/generate_integration_env.py` was driven directly
  with `--outputs-json` fixtures (with and without `appsync_api_key`).

46 GraphQL-shaped calls were recorded in `transcripts/live_calls.json`
(20 offer queries, 26 settings pipeline calls); 11 scenarios × 60 checks all
passed (`transcripts/scenario_results.json`).

## Scenarios (all live except the two noted)

| # | Scenario | Result |
|---|----------|--------|
| 1 | Share URL serves the full offer (seller, campaign, catalog order, malformed rows dropped) and the pre-signed QR URL fetches the real image (HTTP 200, PNG bytes, expiry ≈ 900 s) | pass (live) |
| 2 | Probing never-enabled / unknown / disabled / wrong-token all return the identical `NOT_FOUND "Offer not available"` (11 negative probes, one distinct response) | pass (live) |
| 3 | Ambiguous post-transfer `profileId-index` projection → `NOT_FOUND`, no owner guess; unique projection serves again | pass (live) |
| 4 | Inactive, deleted, and dangling anchor campaigns + soft-deleted catalog block the offer; a campaign without `isActive` still serves (back-compat) | pass (live) |
| 5 | Allowlist intersection (case-insensitive, un-stored dropped, Cash not force-added), legacy full-URL QR row, empty product/method lists still a successful offer | pass (live) |
| 6 | Disable revokes the offer but keeps the share token; re-enable reuses the same token/URL; disable is allowed even over a dead anchor | pass (live) |
| 7 | Owner-only settings gate: stranger, WRITE-share collaborator, unknown profile all refused with the identical `FORBIDDEN`; refused mutations write nothing | pass (live) |
| 8 | Enable validation: missing/foreign/inactive campaign, deleted catalog, missing methods, stale acknowledgement → typed errors, nothing written | pass (live) |
| 9 | Concurrent first enable: the second writer gets `CONFLICT`, one token stands | pass (live) |
| 10 | Offer logs never contain the share token or the QR object key (success + all negative branches; the helper's `Generated GET URL` line is suppressed) | pass (live) |
| 11 | `generate_integration_env.py` threads `TEST_APPSYNC_API_KEY`/`VITE_APPSYNC_API_KEY` when the stack exposes `appsync_api_key`, omits them (commented placeholder) when it does not; `--check` passes both ways | pass (live) |
| 12 | API-key directive exclusivity + public-type closure on the **real AppSync endpoint** | untested |
| 13 | Frontend maps `PUBLIC_ORDER_LIMIT_EXCEEDED` to the friendly cap message | untested |

\### Untested reasons

- **12 — real AppSync auth layer.** Needs a deployed stack: `aws sts
  get-caller-identity` fails with "Your session has expired. Please reauthenticate
  using 'aws login'" — re-auth is interactive and writes user-level credential
  state, which is outside this step's boundary; the ephemeral deploy path requires
  the GitHub Actions `ephemeral` environment's AWS role, which this step cannot
  assume. The behavior itself is one of the intent's pre-measured facts (not to be
  re-derived), is pinned live in CI by
  `tests/integration/resolvers/publicAuthModes.integration.test.ts`, and the
  type-closure half passes its semantic guard here
  (`tests/unit/test_public_api_key_surface.py`, run in this step).
- **13 — no emitting path or page.** By recorded decision (F2, accepted with no
  change) `PUBLIC_ORDER_LIMIT_EXCEEDED` is deliberately registered on both sides
  ahead of the `publicCreateOrder` write slice that will emit it, and this branch
  has no public buyer page that reads the mapping — there is nothing to drive
  live. It is pinned by `frontend/tests/lib/apollo.test.ts` (unit).

## Supporting targeted tests run in this step

- `uv run pytest tests/unit/test_public_orders_handlers.py
  tests/unit/test_public_settings_pipeline_wiring.py
  tests/unit/test_public_orders_role_scope.py tests/unit/test_public_api_key_surface.py
  tests/unit/test_errors.py --no-cov` → **69 passed, 1 skipped**
- `uv run pytest tests/unit/test_lambda_unit_resolver_wiring.py
  tests/unit/test_generate_integration_env.py tests/unit/test_ephemeral_reliability.py
  --no-cov` → **101 passed**
- `node --import ./register-loader.mjs --test` over the seven new/changed settings
  resolver tests → **79 passed, 0 failed**

## F2 acceptance (recorded decision)

`PUBLIC_ORDER_LIMIT_EXCEEDED` in `src/utils/errors.py` +
`frontend/src/lib/apollo.ts` is accepted as deliberately forward-placed and
**unchanged**: both sides are pinned by tests ahead of the write slice that will
emit the code. It is dead code on this branch by design (scenario 13 above).

The disposable moto stack was torn down; the worktree is clean
(`git status --porcelain` empty). All harness files and transcripts live under
this evidence directory only.
Evidence: All recorded GraphQL request/response transcripts (46 calls: 20 offer queries, 26 settings pipeline calls)
[
  {
    "kind": "offer",
    "query": "{ publicGetOrderOffer(profileId: \"11111111-2222-4333-8444-555555555555\", token: \"ffffffff-0000-4000-8000-0000000000ff\") { sellerName campaignId campaignName products { productId productName price description sortOrder } paymentMethods { name qrCodeUrl } } }",
    "identity": null,
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "NOT_FOUND",
          "message": "Offer not available",
          "extensions": {
            "errorCode": "NOT_FOUND"
          }
        }
      ]
    }
  },
  {
    "kind": "offer",
    "query": "{ publicGetOrderOffer(profileId: \"66666666-7777-4888-9999-00000000000b\", token: \"ffffffff-0000-4000-8000-0000000000ff\") { sellerName campaignId campaignName products { productId productName price description sortOrder } paymentMethods { name qrCodeUrl } } }",
    "identity": null,
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "NOT_FOUND",
          "message": "Offer not available",
          "extensions": {
            "errorCode": "NOT_FOUND"
          }
        }
      ]
    }
  },
  {
    "kind": "offer",
    "query": "{ publicGetOrderOffer(profileId: \"no-such-profile-9999\", token: \"ffffffff-0000-4000-8000-0000000000ff\") { sellerName campaignId campaignName products { productId productName price description sortOrder } paymentMethods { name qrCodeUrl } } }",
    "identity": null,
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "NOT_FOUND",
          "message": "Offer not available",
          "extensions": {
            "errorCode": "NOT_FOUND"
          }
        }
      ]
    }
  },
  {
    "kind": "settings",
    "field": "updateProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555",
      "enabled": true,
      "campaignId": "22222222-3333-4444-8555-666666666666",
      "allowedPaymentMethods": [
        "VENMO",
        "Cash",
        "Google Pay"
      ],
      "acknowledgementsAccepted": true
    },
    "response": {
      "data": {
        "updateProfilePublicOrderSettings": {
          "enabled": true,
          "campaignId": "CAMPAIGN#22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "campaignState": "OK",
          "allowedPaymentMethods": [
            "VENMO",
            "Cash",
            "Google Pay"
          ],
          "shareToken": "bbaeb12b-ba76-4636-8b25-7b10a256c636",
          "publicOrderCount": 0,
          "acknowledgedAt": "2026-10-05T19:26:28Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "settings",
    "field": "updateProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555",
      "enabled": true,
      "campaignId": "22222222-3333-4444-8555-666666666666",
      "allowedPaymentMethods": [
        "VENMO",
        "Cash",
        "Google Pay"
      ],
      "acknowledgementsAccepted": true
    },
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "CONFLICT",
          "message": "Public order settings were already saved; try again",
          "extensions": {
            "errorType": "CONFLICT"
          }
        }
      ]
    }
  },
  {
    "kind": "settings",
    "field": "getProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555"
    },
    "response": {
      "data": {
        "getProfilePublicOrderSettings": {
          "enabled": true,
          "campaignId": "CAMPAIGN#22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "campaignState": "OK",
          "allowedPaymentMethods": [
            "VENMO",
            "Cash",
            "Google Pay"
          ],
          "shareToken": "bbaeb12b-ba76-4636-8b25-7b10a256c636",
          "publicOrderCount": 0,
          "acknowledgedAt": "2026-10-05T19:26:28Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "settings",
    "field": "getProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555"
    },
    "response": {
      "data": {
        "getProfilePublicOrderSettings": {
          "enabled": true,
          "campaignId": "CAMPAIGN#22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "campaignState": "OK",
          "allowedPaymentMethods": [
            "VENMO",
            "Cash",
            "Google Pay"
          ],
          "shareToken": "bbaeb12b-ba76-4636-8b25-7b10a256c636",
          "publicOrderCount": 0,
          "acknowledgedAt": "2026-10-05T19:26:28Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "settings",
    "field": "getProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000003",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555"
    },
    "response": {
      "data": {
        "getProfilePublicOrderSettings": null
      },
      "errors": [
        {
          "errorType": "FORBIDDEN",
          "message": "Only the profile owner can manage public order settings",
          "extensions": {
            "errorType": "FORBIDDEN"
          }
        }
      ]
    },
    "pipelineError": {
      "type": "FORBIDDEN",
      "message": "Only the profile owner can manage public order settings",
      "errorInfo": null
    }
  },
  {
    "kind": "settings",
    "field": "getProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000004",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555"
    },
    "response": {
      "data": {
        "getProfilePublicOrderSettings": null
      },
      "errors": [
        {
          "errorType": "FORBIDDEN",
          "message": "Only the profile owner can manage public order settings",
          "extensions": {
            "errorType": "FORBIDDEN"
          }
        }
      ]
    },
    "pipelineError": {
      "type": "FORBIDDEN",
      "message": "Only the profile owner can manage public order settings",
      "errorInfo": null
    }
  },
  {
    "kind": "settings",
    "field": "getProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000003",
    "args": {
      "profileId": "99999999-0000-4000-8000-000000000000"
    },
    "response": {
      "data": {
        "getProfilePublicOrderSettings": null
      },
      "errors": [
        {
          "errorType": "FORBIDDEN",
          "message": "Only the profile owner can manage public order settings",
          "extensions": {
            "errorType": "FORBIDDEN"
          }
        }
      ]
    },
    "pipelineError": {
      "type": "FORBIDDEN",
      "message": "Only the profile owner can manage public order settings",
      "errorInfo": null
    }
  },
  {
    "kind": "settings",
    "field": "updateProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000003",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555",
      "enabled": false
    },
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "FORBIDDEN",
          "message": "Only the profile owner can manage public order settings",
          "extensions": {
            "errorType": "FORBIDDEN"
          }
        }
      ]
    },
    "pipelineError": {
      "type": "FORBIDDEN",
      "message": "Only the profile owner can manage public order settings",
      "errorInfo": null
    }
  },
  {
    "kind": "settings",
    "field": "updateProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000004",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555",
      "enabled": false
    },
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "FORBIDDEN",
          "message": "Only the profil

... [24635 bytes truncated] ...

 "2026-10-05T19:26:28Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "offer",
    "query": "{ publicGetOrderOffer(profileId: \"11111111-2222-4333-8444-555555555555\", token: \"bbaeb12b-ba76-4636-8b25-7b10a256c636\") { sellerName campaignId campaignName products { productId productName price description sortOrder } paymentMethods { name qrCodeUrl } } }",
    "identity": null,
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "NOT_FOUND",
          "message": "Offer not available",
          "extensions": {
            "errorCode": "NOT_FOUND"
          }
        }
      ]
    }
  },
  {
    "kind": "settings",
    "field": "getProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555"
    },
    "response": {
      "data": {
        "getProfilePublicOrderSettings": {
          "enabled": false,
          "campaignId": "CAMPAIGN#22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "campaignState": "OK",
          "allowedPaymentMethods": [
            "VENMO",
            "Cash",
            "Google Pay"
          ],
          "shareToken": "bbaeb12b-ba76-4636-8b25-7b10a256c636",
          "publicOrderCount": 0,
          "acknowledgedAt": "2026-10-05T19:26:28Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "settings",
    "field": "updateProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555",
      "enabled": true,
      "campaignId": "22222222-3333-4444-8555-666666666666",
      "allowedPaymentMethods": [
        "VENMO",
        "Cash",
        "Google Pay"
      ],
      "acknowledgementsAccepted": true
    },
    "response": {
      "data": {
        "updateProfilePublicOrderSettings": {
          "enabled": true,
          "campaignId": "CAMPAIGN#22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "campaignState": "OK",
          "allowedPaymentMethods": [
            "VENMO",
            "Cash",
            "Google Pay"
          ],
          "shareToken": "bbaeb12b-ba76-4636-8b25-7b10a256c636",
          "publicOrderCount": 0,
          "acknowledgedAt": "2026-10-05T19:26:33Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "offer",
    "query": "{ publicGetOrderOffer(profileId: \"11111111-2222-4333-8444-555555555555\", token: \"bbaeb12b-ba76-4636-8b25-7b10a256c636\") { sellerName campaignId campaignName products { productId productName price description sortOrder } paymentMethods { name qrCodeUrl } } }",
    "identity": null,
    "response": {
      "data": {
        "publicGetOrderOffer": {
          "sellerName": "Casey's Cookies",
          "campaignId": "22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "products": [
            {
              "productId": "p1",
              "productName": "Small Box",
              "price": 12.5,
              "description": "A small box",
              "sortOrder": 1
            },
            {
              "productId": "p2",
              "productName": "Large Box",
              "price": 24,
              "description": null,
              "sortOrder": 2
            },
            {
              "productId": "p3",
              "productName": "No-Sort Item",
              "price": 5,
              "description": null,
              "sortOrder": null
            }
          ],
          "paymentMethods": [
            {
              "name": "Venmo",
              "qrCodeUrl": "http://127.0.0.1:32877/kernelworx-exports-ue1-dev/payment-qr-codes/a1b2c3d4-0000-4000-8000-000000000001/venmo-qr.png?AWSAccessKeyId=testing&Signature=pxoFKXpzGwr89Hd1CozSFpDT7tw%3D&x-amz-security-token=testing&Expires=1791229293"
            },
            {
              "name": "Cash",
              "qrCodeUrl": null
            }
          ]
        }
      }
    }
  },
  {
    "kind": "offer",
    "query": "{ publicGetOrderOffer(profileId: \"11111111-2222-4333-8444-555555555555\", token: \"bbaeb12b-ba76-4636-8b25-7b10a256c636\") { sellerName campaignId campaignName products { productId productName price description sortOrder } paymentMethods { name qrCodeUrl } } }",
    "identity": null,
    "response": {
      "data": null,
      "errors": [
        {
          "errorType": "NOT_FOUND",
          "message": "Offer not available",
          "extensions": {
            "errorCode": "NOT_FOUND"
          }
        }
      ]
    }
  },
  {
    "kind": "settings",
    "field": "updateProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555",
      "enabled": false
    },
    "response": {
      "data": {
        "updateProfilePublicOrderSettings": {
          "enabled": false,
          "campaignId": "CAMPAIGN#22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "campaignState": "INACTIVE",
          "allowedPaymentMethods": [
            "VENMO",
            "Cash",
            "Google Pay"
          ],
          "shareToken": "bbaeb12b-ba76-4636-8b25-7b10a256c636",
          "publicOrderCount": 0,
          "acknowledgedAt": "2026-10-05T19:26:33Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "settings",
    "field": "updateProfilePublicOrderSettings",
    "identitySub": "a1b2c3d4-0000-4000-8000-000000000001",
    "args": {
      "profileId": "11111111-2222-4333-8444-555555555555",
      "enabled": true,
      "campaignId": "22222222-3333-4444-8555-666666666666",
      "allowedPaymentMethods": [
        "VENMO",
        "Cash",
        "Google Pay"
      ],
      "acknowledgementsAccepted": true
    },
    "response": {
      "data": {
        "updateProfilePublicOrderSettings": {
          "enabled": true,
          "campaignId": "CAMPAIGN#22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "campaignState": "OK",
          "allowedPaymentMethods": [
            "VENMO",
            "Cash",
            "Google Pay"
          ],
          "shareToken": "bbaeb12b-ba76-4636-8b25-7b10a256c636",
          "publicOrderCount": 0,
          "acknowledgedAt": "2026-10-05T19:26:33Z",
          "ackVersion": 1
        }
      }
    }
  },
  {
    "kind": "offer",
    "query": "{ publicGetOrderOffer(profileId: \"11111111-2222-4333-8444-555555555555\", token: \"bbaeb12b-ba76-4636-8b25-7b10a256c636\") { sellerName campaignId campaignName products { productId productName price description sortOrder } paymentMethods { name qrCodeUrl } } }",
    "identity": null,
    "response": {
      "data": {
        "publicGetOrderOffer": {
          "sellerName": "Casey's Cookies",
          "campaignId": "22222222-3333-4444-8555-666666666666",
          "campaignName": "Fall Cookie Sale",
          "products": [
            {
              "productId": "p1",
              "productName": "Small Box",
              "price": 12.5,
              "description": "A small box",
              "sortOrder": 1
            },
            {
              "productId": "p2",
              "productName": "Large Box",
              "price": 24,
              "description": null,
              "sortOrder": 2
            },
            {
              "productId": "p3",
              "productName": "No-Sort Item",
              "price": 5,
              "description": null,
              "sortOrder": null
            }
          ],
          "paymentMethods": [
            {
              "name": "Venmo",
              "qrCodeUrl": "http://127.0.0.1:32877/kernelworx-exports-ue1-dev/payment-qr-codes/a1b2c3d4-0000-4000-8000-000000000001/venmo-qr.png?AWSAccessKeyId=testing&Signature=a76i5Yvu1Pe9rOxzECil0El15iI%3D&x-amz-security-token=testing&Expires=1791229294"
            },
            {
              "name": "Cash",
              "qrCodeUrl": null
            }
          ]
        }
      }
    }
  }
]
  • Evidence: Per-scenario check results (11 scenarios, 60 checks, all pass) (local file: ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/transcripts/scenario_results.json)
Evidence: Pre-signed QR URL fetch evidence (HTTP 200, PNG bytes, ~900s expiry)
URL: http://127.0.0.1:32877/kernelworx-exports-ue1-dev/payment-qr-codes/a1b2c3d4-0000-4000-8000-000000000001/venmo-qr.png?AWSAccessKeyId=testing&Signature=FKFNm20eI5eOLDZnP70M6kIH8es%3D&x-amz-security-token=testing&Expires=1791229289
HTTP 200, 70 bytes, PNG magic: true
Evidence: Captured Lambda handler log output across all offer calls (token/key absence evidence)






{"timestamp": "2026-10-05T19:26:29.077618+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "0488bd99-3127-4bb0-b306-dab615a11d34", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 2}




{"timestamp": "2026-10-05T19:26:29.660730+00:00", "level": "WARNING", "message": "Ambiguous profileId-index projection", "correlationId": "7889b551-6b44-4d82-8e14-eddd37830b57", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "projections": 2, "confirmed": 2}


{"timestamp": "2026-10-05T19:26:30.007310+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "fd919525-b88c-45f2-9296-a89f0a7d287e", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 2}






{"timestamp": "2026-10-05T19:26:30.944812+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "a25dd69b-75f9-48d8-ad22-2a118c599ec0", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 2}






{"timestamp": "2026-10-05T19:26:31.876794+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "86784755-2c5f-460c-94c8-14c815ff25ae", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 2}


{"timestamp": "2026-10-05T19:26:32.259613+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "f473c22c-0c40-42d5-b3ab-dbfaa215ba23", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 2}


{"timestamp": "2026-10-05T19:26:32.592338+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "af91589d-2c2d-45f9-bc48-e69c24172806", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 0}


{"timestamp": "2026-10-05T19:26:32.885552+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "0227d643-2c99-4f11-95e2-76cdf2ac9141", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 0, "payment_methods": 0}




{"timestamp": "2026-10-05T19:26:33.561378+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "602f7952-0089-4f65-a639-8cb78ec11850", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 2}




{"timestamp": "2026-10-05T19:26:34.282439+00:00", "level": "INFO", "message": "Public order offer served", "correlationId": "ca917389-3c06-49ae-9d9b-6af5202f2c4a", "profile_id": "PROFILE#11111111-2222-4333-8444-555555555555", "campaign_id": "CAMPAIGN#22222222-3333-4444-8555-666666666666", "products": 3, "payment_methods": 2}
Evidence: All 11 negative offer probes returning one identical error
[
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  },
  {
    "errorType": "NOT_FOUND",
    "message": "Offer not available"
  }
]
Evidence: generate_integration_env.py live CLI runs (API-key present and absent, plus --check)
=== Case A: stack WITH appsync_api_key ===
📝 Creating ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/env_with.env from template ~/.no-mistakes/worktrees/0e3f105a97cb/01M46KEY6RQ3MS0XE2K417MGTA/.env.example
📝 Creating ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/frontend_with.env from template ~/.no-mistakes/worktrees/0e3f105a97cb/01M46KEY6RQ3MS0XE2K417MGTA/frontend/.env.example
✅ Integration test environment config generated
~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/env_with.env:TEST_APPSYNC_ENDPOINT=https://abc123.appsync-api.us-east-1.amazonaws.com/graphql
~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/env_with.env:TEST_APPSYNC_API_KEY=da2-abcdef0123456789
~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/frontend_with.env:VITE_APPSYNC_API_KEY=da2-abcdef0123456789
-- --check mode:
✅ ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/env_with.env: all 6 managed key(s) ok
✅ ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/frontend_with.env: all 8 managed key(s) ok
check exit=0
=== Case B: stack WITHOUT appsync_api_key ===
⚠️  appsync_api_key output is absent from this stack's state; the stack has not yet deployed the public-orders feature, so TEST_APPSYNC_API_KEY/VITE_APPSYNC_API_KEY are omitted
📝 Creating ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/env_no.env from template ~/.no-mistakes/worktrees/0e3f105a97cb/01M46KEY6RQ3MS0XE2K417MGTA/.env.example
📝 Creating ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/frontend_no.env from template ~/.no-mistakes/worktrees/0e3f105a97cb/01M46KEY6RQ3MS0XE2K417MGTA/frontend/.env.example
✅ Integration test environment config generated
API-key lines found (want 0): 1 1
⚠️  appsync_api_key output is absent from this stack's state; the stack has not yet deployed the public-orders feature, so TEST_APPSYNC_API_KEY/VITE_APPSYNC_API_KEY are omitted
ℹ️  ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/env_no.env: TEST_APPSYNC_API_KEY skipped (not in the stack's outputs)
✅ ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/env_no.env: all 5 managed key(s) ok
ℹ️  ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/frontend_no.env: VITE_APPSYNC_API_KEY skipped (not in the stack's outputs)
✅ ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/envgen/frontend_no.env: all 7 managed key(s) ok
check exit=0

NOTE: the "API-key lines found: 1 1" counts above are the PRESERVED template
placeholder line, commented out by the generator:
  # TEST_APPSYNC_API_KEY=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx: not in this stack's outputs; omitted
so no API-key variable is actually set when the stack lacks the output; the
generator's own --check reports "TEST_APPSYNC_API_KEY skipped" and exits 0.
Evidence: Targeted pytest run 1 (69 passed, 1 skipped)
.................................................................s....   [100%]
69 passed, 1 skipped in 9.00s
Evidence: Targeted pytest run 2 (101 passed)
........................................................................ [ 71%]
.............................                                            [100%]
101 passed in 17.08s
Evidence: AppSync JS settings-resolver node tests (79 passed)
✔ write_public_order_settings_fn request (10.158099ms)
▶ write_public_order_settings_fn response
  ✔ maps a failed first-enable guard to CONFLICT with no overwrite (0.220282ms)
  ✔ maps a ConditionalCheckFailed message the same way (0.161984ms)
  ✔ re-raises any other datasource error unchanged (0.152486ms)
  ✔ returns the updated item on success (0.125365ms)
✔ write_public_order_settings_fn response (0.874137ms)
ℹ tests 79
ℹ suites 12
ℹ pass 79
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 165.673167
  • Evidence: Reproducible live harness (moto stack, pipeline executor, Lambda invoker) (local file: ~/.no-mistakes/evidence/01M46KEY6RQ3MS0XE2K417MGTA/harness/driver.mjs)

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

⚠️ **Review** - 3 infos
  • ℹ️ tofu/application/modules/iam/main.tf:761 - The public-orders role grants dynamodb:Query on the campaigns table plus its GSI (locals at lines 727-729), but the offer handler never issues a campaign Query - the behavioral scope test (tests/unit/test_public_orders_role_scope.py) pins the exact call sequence to a single profiles Query plus four GetItems. The same file's own orders-access comment states 'unused permissions on a domain role are a liability', which this grant contradicts; it is read-only and the role is single-purpose, so exposure is bounded, but the grant exists only for a hypothetical future slice. Sibling axis: the s3:GetObject grant (line 783) IS load-bearing (pre-signed GETs authorize against the signing role), so only the campaigns Query is surplus.
  • ℹ️ src/utils/errors.py:62 - PUBLIC_ORDER_LIMIT_EXCEEDED is registered here and mapped in frontend/src/lib/apollo.ts:207, but no code path on this branch emits it - the publicCreateOrder write slice that owns the per-campaign cap is a later slice. Deliberate forward placement (both sides pinned by tests so the code cannot drift out of sync), currently dead until that slice lands.
  • ℹ️ tests/unit/test_public_orders_role_scope.py:340 - Newly added source-content-only assertions over Terraform source: test_public_orders_is_mapped_to_the_role_in_all_three_environments raw-substring-matches '"public-orders" = module.iam.lambda_public_orders_execution_role_arn' against each environment main.tf, and tests/unit/test_public_settings_pipeline_wiring.py:46/:58 locate the owner gate's data_source/code with regex over resource blocks. Both files otherwise parse the same artifacts semantically with python-hcl2, and test_monolithic_role_retirement.py:178 already covers the env role-map wiring via an hcl2 parse that extracts function keys dynamically - so the substring test is both fragile and redundant. Refine to the hcl2 parse (or drop the env-mapping test in favor of the existing dynamic coverage).

🔧 Fix applied.
3 infos still open:

  • ℹ️ tofu/application/modules/iam/main.tf:761 - The public-orders role grants dynamodb:Query on the campaigns table plus its GSI (locals at lines 727-729), but the offer handler never issues a campaign Query - the behavioral scope test (tests/unit/test_public_orders_role_scope.py) pins the exact call sequence to a single profiles Query plus four GetItems. The same file's own orders-access comment states 'unused permissions on a domain role are a liability', which this grant contradicts; it is read-only and the role is single-purpose, so exposure is bounded, but the grant exists only for a hypothetical future slice. Sibling axis: the s3:GetObject grant (line 783) IS load-bearing (pre-signed GETs authorize against the signing role), so only the campaigns Query is surplus.
  • ℹ️ src/utils/errors.py:62 - PUBLIC_ORDER_LIMIT_EXCEEDED is registered here and mapped in frontend/src/lib/apollo.ts:207, but no code path on this branch emits it - the publicCreateOrder write slice that owns the per-campaign cap is a later slice. Deliberate forward placement (both sides pinned by tests so the code cannot drift out of sync), currently dead until that slice lands.
  • ℹ️ tests/unit/test_public_orders_role_scope.py:340 - Newly added source-content-only assertions over Terraform source: test_public_orders_is_mapped_to_the_role_in_all_three_environments raw-substring-matches '"public-orders" = module.iam.lambda_public_orders_execution_role_arn' against each environment main.tf, and tests/unit/test_public_settings_pipeline_wiring.py:46/:58 locate the owner gate's data_source/code with regex over resource blocks. Both files otherwise parse the same artifacts semantically with python-hcl2, and test_monolithic_role_retirement.py:178 already covers the env role-map wiring via an hcl2 parse that extracts function keys dynamically - so the substring test is both fragile and redundant. Refine to the hcl2 parse (or drop the env-mapping test in favor of the existing dynamic coverage).
✅ **Test** - passed

✅ No issues found.

  • Live validation: ✅ go - 11 of 13 scenarios driven live against the product
Scenario Result Live Evidence
Buyer opens the share URL and gets the full offer — seller, campaign (bare id), catalog products in catalog order with malformed rows dropped — plus a pre-signed QR image URL that fetches the real ima… ✅ pass live transcripts/live_calls.json (happy-path publicGetOrderOffer entry with identity: null) and transcripts/qr_fetch.txt (HTTP 200, 70 bytes, PNG magic, Expires ≈ now+900s); scenario_results.json scenari…
Probing cannot distinguish never-enabled, unknown, disabled, or wrong-token profiles — every negative branch returns the identical NOT_FOUND 'Offer not available' ✅ pass live transcripts/negative_offer_errors.json (11 probes, one distinct response) + live_calls.json error entries
Ambiguous post-transfer profileId-index projection serves nothing instead of guessing an owner ✅ pass live scenario_results.json post-transfer-ambiguous-profile-projection-is-not-found-not-a-guess + 'Ambiguous profileId-index projection' WARNING in transcripts/offer_lambda_stdout.txt
Inactive, deleted, and dangling anchor campaigns and a soft-deleted catalog block the offer, while a campaign missing isActive still serves (back-compat) ✅ pass live scenario_results.json inactive-or-dangling-anchor-and-soft-deleted-catalog-block-the-offer (6 checks) with live_calls.json probe entries
Payment methods are the case-insensitive allowlist intersection (un-stored dropped, Cash not force-added, legacy full-URL QR row presigned) and empty product/method lists are still a successful offer ✅ pass live scenario_results.json allowlist-intersection-legacy-qr-url-and-empty-lists-still-succeed (6 checks); allowlist changes made through the real settings pipeline
Disabling revokes the offer but keeps the share token, re-enabling restores the same URL, and the off-switch works even over a dead anchor ✅ pass live scenario_results.json disable-revokes-the-offer-but-keeps-the-share-token-re-enable-restores-it (8 checks)
The owner-only settings gate refuses a stranger, a WRITE-share collaborator, and an unknown profile with an identical FORBIDDEN, and refused mutations change nothing ✅ pass live scenario_results.json owner-only-settings-gate-refuses-collaborator-stranger-and-unknown-identically (8 checks) + FORBIDDEN entries in live_calls.json
Enabling refuses a missing/foreign/inactive campaign, a deleted catalog, a missing method list, and an unaccepted acknowledgement — writing nothing on any rejection ✅ pass live scenario_results.json enabling-rejects-missing-campaign-foreign-campaign-inactive-catalog-no-methods-no-ack (8 checks), ending with profile B still never-enabled
A concurrent first enable loses with CONFLICT instead of overwriting the winner's token — one token stands ✅ pass live scenario_results.json concurrent-first-enable-second-writer-gets-conflict-not-double-mint (3 checks); writer2's conditioned UpdateItem fails on attribute_not_exists(publicOrders.#token) exactly as d…
Offer logs never contain the share token or the QR object key on any branch ✅ pass live scenario_results.json logs-never-contain-the-share-token-or-the-qr-object-key (5 checks) over transcripts/offer_lambda_stdout.txt
The integration-env generator threads TEST_APPSYNC_API_KEY/VITE_APPSYNC_API_KEY when the stack exposes appsync_api_key and cleanly omits them (commented placeholder, --check green) when it does not ✅ pass live transcripts/generate_integration_env_live.txt (both fixture runs plus --check exits 0) and generated files under evidence/…/envgen/
On the real AppSync endpoint, a signed-in Cognito caller is refused on the @aws_api_key-only public field while an API-key caller passes, and every public type carries the key directive so sub-fields… ⏸️ untested no Requires a deployed AppSync API: aws sts get-caller-identity fails with 'Your session has expired. Please reauthenticate using aws login' — re-authentication is interactive and writes user-level cre…
The frontend maps PUBLIC_ORDER_LIMIT_EXCEEDED to the friendly campaign-cap message a buyer would see ⏸️ untested no No live surface exists on this branch: by recorded decision F2 (accepted, no change) no code path emits PUBLIC_ORDER_LIMIT_EXCEEDED yet — the publicCreateOrder write slice that owns the cap is a later…
  • REPO=$PWD .venv/bin/python &lt;evidence&gt;/harness/stack.py — disposable moto ThreadedMotoServer with real table schemas + S3 QR objects, torn down after the run
  • node --import &lt;evidence&gt;/harness/loader.mjs &lt;evidence&gt;/harness/driver.mjs &lt;evidence&gt; &lt;repo&gt; — 11 live scenarios, 60 checks, all passing; output in transcripts/scenario_results.json and transcripts/live_calls.json (20 offer queries, 26 settings pipeline calls)
  • Pre-signed QR URL fetched over HTTP from local S3 inside the driver → HTTP 200, 70 bytes, PNG magic: true (transcripts/qr_fetch.txt)
  • Log-hygiene scan over all captured Lambda subprocess output → transcripts/offer_lambda_stdout.txt (9 Public order offer served lines, zero token/key occurrences, Generated GET URL suppressed)
  • uv run pytest tests/unit/test_public_orders_handlers.py tests/unit/test_public_settings_pipeline_wiring.py tests/unit/test_public_orders_role_scope.py tests/unit/test_public_api_key_surface.py tests/unit/test_errors.py -q --no-cov → 69 passed, 1 skipped
  • uv run pytest tests/unit/test_lambda_unit_resolver_wiring.py tests/unit/test_generate_integration_env.py tests/unit/test_ephemeral_reliability.py -q --no-cov → 101 passed
  • node --import ./register-loader.mjs --test verify_public_settings_owner_fn.test.js lookup_public_settings_campaign_fn.test.js validate_public_settings_write_fn.test.js validate_public_settings_catalog_fn.test.js write_public_order_settings_fn.test.js get_profile_public_order_settings_pipeline_resolver.test.js update_profile_public_order_settings_pipeline_resolver.test.js → 79 passed, 0 failed
  • uv run python scripts/generate_integration_env.py --outputs-json &lt;fixture&gt; --out &lt;file&gt; --frontend-out &lt;file&gt; and the same with --check, once with appsync_api_key in the outputs and once without → transcripts/generate_integration_env_live.txt
  • aws sts get-caller-identity → 'Your session has expired. Please reauthenticate using 'aws login'' (documented blocker for the real-AppSync scenario)
⚠️ **Document** - 1 info
  • ℹ️ src/utils/errors.py:62 - Recorded acceptance (F2): PUBLIC_ORDER_LIMIT_EXCEEDED is deliberately registered in ErrorCode and mapped in frontend/src/lib/apollo.ts ahead of the publicCreateOrder write slice that will emit it; both sides are pinned by tests so they cannot drift. Dead until that slice lands, by design — no change made.
⚠️ **Lint** - 1 info
  • ℹ️ tests/unit/test_appsync_pipeline_functions.py:1 - Pre-existing ruff format --check drift on six test files untouched by this change (test_appsync_pipeline_functions.py, test_appsync_resolver_order.py, test_except_syntax.py, test_exports_bucket_lifecycle.py, test_list_unit_catalogs_env_isolation.py, test_waf_managed_rule_action_rollout.py). CI gates only ruff check, which passes. Left alone as out of scope; a repo-wide ruff format src/ tests/ pass would clear them.
✅ **Push** - passed

✅ No issues found.

Adds the public-orders Lambda behind publicGetOrderOffer: GSI locate -> strongly
consistent profile confirm -> hmac.compare_digest token check -> anchor campaign
GetItem -> catalog GetItem -> allowlist intersection, with QR keys pre-signed
from the stored key explicitly. New scoped lambda_public_orders_execution role
(read-only on profiles/campaigns/catalogs/accounts, no orders access, plus
s3:GetObject on payment-qr-codes/* for the pre-signed buyer GETs), wired as a
unit resolver through lambda_unit_resolver.js in all three environments.
@dmeiser
dmeiser added this pull request to stack #682 October 5, 2026 20:08
@dmeiser
dmeiser deployed to ephemeral October 5, 2026 20:30 — with GitHub Actions Active
@dmeiser
dmeiser deployed to ephemeral October 6, 2026 13:41 — with GitHub Actions Active
@dmeiser dmeiser added the no-release No release/version bump expected from this change label Oct 6, 2026

This branch was successfully deployed

1 active deployment
ephemeral — bcef93c5 Deployed Oct 6, 2026 by dmeiser via Ephemeral tests for PR #1041
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-release No release/version bump expected from this change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant