Skip to content

Backend pipeline handoff

Status: Active Last reviewed: 2026-09-07

Current continuation boundary

The user requested an efficient wrap-up after the backend audit expanded too far. The accepted manual-payment repair was committed as 9e5d67c7. The user then authorized only the account-switching/offline-queue continuation, coordinated with Claude. Its live orchestration handoff owns current progress, evidence and the stopping boundary. No additional backend area is open. This is a handoff, not whole-backend acceptance.

The isolated worktree is /home/sungkyu08/Dev/twomore-v2-venue-pipeline, on codex/venue-pipeline-20260906. The original dirty checkout was preserved. No changes were pushed or deployed by this continuation. No hosted database, payment-provider or Expo push calls are claimed.

Integrated changes

The venue work includes contribution and correction review, stable court identity, protected closure/reopening, evidence-aware maintenance, resumable operator commands, owner applications, review, transfer consent, revocation, private history/export, and current certification in the app. Ordinary reliable venue information does not require an owner badge. Certification is reserved for reviewed owner authority; stale persisted state cannot restore a badge. A reliable source family can support a fact. See the venue ownership audit and pipeline audit.

Venue application integration is committed through f3ff531b, with earlier server/client and pipeline commits on this branch. The latest integrated slice is manual-payment authority: migrations 00629–00631 and seven permanent SQL suites. It protects dues bindings, independent confirmation, historical payment evidence and authorized manual settlement. See the payment audit for behavior and limitations.

The payment integration passed the full yarn check: 758 script tests with two existing skips, 393 Jest suites / 5,614 cases, workspace types and repository gates. The seven payment SQL suites separately passed 218 assertions in author and independent local clones. Seven unrelated failures from the wider SQL rehearsal were reproduced without these migrations; they remain fixture/environment gaps.

Retained drafts

All paths in this section are relative to .audit/backend-pipelines-20260906/. These ignored files exist only in this retained worktree. Queue runtime and permanent regressions have now been copied into canonical source for integration; the original drafts remain provenance. Notification drafts remain unintegrated. Preserve the worktree and these directories when resuming.

AreaSurviving workRemaining boundary
Account ownership and offline queueQ1, Q2 and all 15 producers are integrated locally; original drafts remain in queue-auth-q1/, queue-auth-q2/ and queue-auth-producers/.Local checks pass. Claude review and merged-result validation remain.
Session and replay integrationQ3 native/web lifecycle and replay are integrated with permanent regressions. queue-auth-q3/ retains the reviewed source freeze.Independent focused review and local repository checks pass. See the live orchestration handoff for Claude review.
Notification deliverypush-delivery-diagnostic/, push-delivery-review/, push-sql-characterization/, push-sql-review/: actual worker and SQL defects reproduced.Implement and audit atomic dispatch admission, token-registration ownership, durable quota and receipt reconciliation.
Notification parsing/transportpush-worker-draft/: bounded Expo response parsing and transport; 32 tests pass on both Node 20 and Node 22, with strict types/lint.Independent review and database/worker integration; no live provider or device proof.

Queue transport and all 15 producer actions have independent draft-level tests. The latest cold-bootstrap and session changes require their own final joined receipt; earlier acceptance must not be substituted for later changed sources. Read each directory's receipt/findings before promotion. Original failed probes and corrected fixture runs are retained.

Next bounded work

  1. Claude reviews the completed account-switching/offline queue slice and validates the combined branch after integration. The local gate passes; no rollout has occurred. Web multi-tab ownership remains a separate gap.
  2. Fix payment adapter acknowledgment: an RLS-filtered update can affect no rows while a void-returning adapter reports success. Immutable action receipts and stale-intent/version checks are another payment slice, not solved by the guards.
  3. Implement the notification protocol from the retained SQL/API proposal. Current defects include ignored losing claims, batch quota overflow, unsafe token reassignment and stale receipts clearing replacement registrations. Do not activate this draft or claim exactly-once provider delivery.

Further membership, score/rating, privacy/media and reference-data pipeline work is deferred. The entire backend has not been audited or repaired.

Existing release boundaries

Venue source completeness remains 2,324 / 2,325 Naver records; the missing source gate stays closed. Government response-shape proof and native share-sheet transfer remain incomplete. Web production build passed during venue integration; mobile preflight reports existing dependency mismatches. Browser/device, accessibility, managed-auth and hosted rollout acceptance are separate from local test success.

Markdown remains the source of truth. Run yarn docs:check before handoff.