53c0e095cf
The data layer is now reached through one pulled, version-pinned engagement (`.project/concepts/data-layer/contract_polyfill-surface.md`, @1ecf511e9d). That copy is the only reference: the provider's sources are never opened, and what the contract does not answer is a gap raised with it, never worked around here. Surface - `@ng-eventually/sdk` -> `@ng-eventually/polyfill`, one entry point. - `configure` loses `getSession`, `normalizeId`, `currentUser`; the session belongs to the package and its own `init` captures it. - Placement is named by scope alone -- a session is one user, so the app no longer passes an identity it had no way to obtain. This removes a constant that made every user collide on one owner's document. - `init(...)` then `await ensureIdentity()`, in that order, as one sequence: React runs child effects first, so the two calls sat in the wrong order and the contract now makes that throw. - `sessionId` relayed as `string | number`, `materialize` -> `read`. A rejection means "unknown", never "absent" Four places treated a caught error as an empty result. The worst wrote a duplicate participation: an unknown count read as zero defeated the idempotence guard of `joinEvent`. Also fixed: a per-document count, a silently dropped notification shown optimistically anyway, and a failed listing that left the owned-event set empty and disabled the materializer for the whole session. Shared identity is not a Festipod notion A browser context is one user. The per-scenario identity plant is deleted at its source and its five sites; what stays is the deployment's wallet file, which the contract requires an application to serve. Documentation The doctrine no longer describes how the data layer works underneath: five leaves whose subject was internals are gone, a dozen more are re-founded on the contract's own words, and two frozen arbitrations about a deleted screen were removed rather than left to mislead a future session. Test harness It can sign in at last: cucumber runs under node, which does not load `.env`, so the harness never received the wallet material and every scenario silently fell back to an empty local mode. A failed sign-in is now loud on both sides. The suite also releases what it opens and exits on its own -- runs were still resident hours after reporting, holding a browser and two servers. Known red: `@data` cannot be measured. The served wallet accumulates and nothing resets it; moving the browser profile aside does not, since the data lives in the wallet file, not the profile.
23 lines
1.3 KiB
YAML
23 lines
1.3 KiB
YAML
# Inter-repo contracts. Festipod is a CONSUMER only: it publishes no interface of its own,
|
|
# and it consumes exactly one — the SDK surface `@ng-eventually/polyfill` engages toward the
|
|
# applications built on it.
|
|
#
|
|
# The pulled copy under `into:` IS the specification Festipod codes against. An agent
|
|
# working here reads that copy and never opens the provider's own source: a gap is raised
|
|
# upstream (see `data-layer/rule_app-uses-sdk-surface-only`), never peeked around.
|
|
#
|
|
# `pullFrom:` names the canonical identity of the provider (its git remote URL + the
|
|
# repo-relative path of the leaf), so the manifest travels with the branch. Per-developer
|
|
# access to a local checkout lives in `.project/contracts.local.yaml`, which is never
|
|
# committed.
|
|
|
|
consume:
|
|
- contract: polyfill-surface
|
|
into: concepts/data-layer
|
|
type: git
|
|
pullFrom: https://gitea.reconnexion.apps.gueraud.net/Reconnexion/ng-eventually.git/.project/concepts/app-contract/contract_polyfill-surface.md
|
|
# The contract is published from the branch that carries it while that branch is still
|
|
# in flight; it moves to `main` once the provider lands it there. Flip this line then,
|
|
# and re-pull — the stamp records which commit the local copy actually came from.
|
|
ref: caps-p1a-and-virtual-user-boundary
|