docs/module-inventory.mdView on GitHub ↗
Complete source inventory
Generated by python3 scripts/testing/source_inventory.py --write. CI checks exact contents.
This lists every checked-in source module in these roots, including files with no recorded hits. A responsibility or suite listing does not mean 100% coverage. See testing for measured coverage and unverified paths.
Rust commerce and transport
| Module | Responsibility |
|---|---|
| src/accounts/address_restore.rs | Atomic restoration of the owning customer's address aggregate; geography, references and immutable order snapshots remain guarded. |
| src/accounts/address_store.rs | Tenant-owned address persistence, optimistic revisions and atomic default assignment. |
| src/accounts/addresses.rs | Store API address book uses independent customer sessions, never merchant credentials. |
| src/accounts/contacts.rs | Customer-editable contact fields; identity, price group and privileges remain server-owned. |
| src/accounts/demo.rs | Public synthetic customer fixture for newly provisioned demo shops; never fills real customer addresses. |
| src/accounts/metadata.rs | Standard customer read fields and indexed order metrics are derived from authoritative records. |
| src/accounts/mod.rs | Independent customer sessions, profile/password management and owning-account order history. |
| src/accounts/order_snapshot.rs | Checkout-owned immutable customer and address records; future account edits cannot rewrite an order. |
| src/accounts/orders.rs | Customer-owned order reads and receipts share one tenant/identity predicate and a public projection. |
| src/accounts/profile.rs | Typed customer-owned profile updates; price groups, email and merchant roles cannot be self-assigned. |
| src/agent.rs | Persistent grounded conversations and tenant-scoped semantic knowledge HTTP adapters. |
| src/apps/approval.rs | Operator service authority is bound to immutable package content, never to a merchant-chosen ID. |
| src/apps/asset_surfaces.rs | App file uploads reuse the product asset parser/store and require the current package plus either callback consent or a surface grant. |
| src/apps/cart_contributions.rs | Generic app contributions: configure a cart, bind package/data revisions and persist audited pricing inputs. |
| src/apps/commerce_hooks.rs | Typed pure commerce hooks share the compiled sandbox cache and receive explicit immutable snapshots, never SQL or credentials. |
| src/apps/compatibility.rs | Explicit read adapter for persisted v0.5 engraving carts; completed order snapshots remain unchanged. |
| src/apps/consent.rs | Package approval binds all requested permissions to a reviewed digest; current actor rights apply before every installation path. |
| src/apps/core_callbacks.rs | Narrow app callbacks delegate to the existing commerce owners and project PII only with separate consent. |
| src/apps/credentials.rs | App keys reuse the core integration-key store, current creator rights, expiry and immutable package digest. |
| src/apps/data.rs | Managed app tables: typed writes, optimistic revisions, bounded reads and local RLS context. |
| src/apps/distribution.rs | Signed publisher namespaces and tenant-local dependency/version gates. Operator service access still requires its separate exact digest pin. |
| src/apps/editor_contract.rs | Editor mounts, enumerated fields and tenant-owned core references; no app alters core tables. |
| src/apps/editor_tests.rs | Assistant fixture contracts exercise real validation, not only the client-side builder. |
| src/apps/egress.rs | Bounded origin clients pin resolved addresses for each connection and never use ambient HTTP proxies. |
| src/apps/event_contract.rs | Explicit event filters, bounded batches and signed public HTTPS delivery extend the existing leased outbox, not a second queue. |
| src/apps/event_projection.rs | Least-privilege event subscriptions and payload projections; merchant identity never implies app access. |
| src/apps/events.rs | Durable at-least-once app events, retry leases and stable event idempotency keys. |
| src/apps/evidence.rs | Private provenance-bearing app exports feed merchant retrieval and durable app events; never public PDP answers. |
| src/apps/evidence_routes.rs | Scoped merchant-only evidence retrieval; sources never enter public product answers. |
| src/apps/field_values.rs | Exact app field values reuse commerce money, rich content and tenant-owned assets; no HTML or float decimal coercion. |
| src/apps/form_layout.rs | Bounded twelve-column form geometry, presentation flags and tab order shared by every native app surface. |
| src/apps/gateway.rs | One permission-aware action gateway serves HTTP, UI and MCP; service egress is operator configured. |
| src/apps/hosted.rs | Persist hosted-app dependencies through the existing package installer; no private renderer or parallel registry. |
| src/apps/input_schema.rs | Bounded recursive action-input contract. Untyped managed fields still receive depth/size budgets. |
| src/apps/job_callbacks.rs | Long-job service callbacks disclose input only after current actor consent, package and lease checks. Late callbacks cannot commit. |
| src/apps/jobs.rs | Durable long actions piggyback on the existing outbox. Apps claim a fenced lease; unknown side effects are never retried automatically. |
| src/apps/manifest.rs | Strict package contract; identifiers and limits are checked before any schema DDL. |
| src/apps/manifest_validation.rs | Package capability, schema and action validation; no executable behavior is inferred from names. |
| src/apps/mod.rs | Versioned app packages: managed data, UI slots, agent tools and isolated service calls. |
| src/apps/native_data.rs | App record translations use configured shop languages and field-level main-language inheritance. |
| src/apps/native_view_tests.rs | Native schema security regressions: bindings, public writes, allowlists, bounded blocks and legacy digests. |
| src/apps/native_views.rs | Bounded native view definitions; every data binding resolves to the same authorized app action gateway. |
| src/apps/observability.rs | Bounded metadata-only app telemetry, storage usage and explicitly approved cursor-based event replay. |
| src/apps/ontology.rs | Namespaced graph views over current authorized app records; no duplicated source or public-claim authority. |
| src/apps/planning.rs | Registered managed app actions join the same preview/approve transaction as core changes. |
| src/apps/presentation.rs | Optional passive app artwork and localized summaries; omitted metadata preserves published legacy digests. |
| src/apps/registry.rs | Atomic installation and additive schema upgrades; immutable version digests preserve history. |
| src/apps/relations.rs | Multi-relations keep stable array wire values, composite tenant FKs and shared accounting; staging may clone cyclic graphs atomically. |
| src/apps/routes.rs | Tenant-scoped package lifecycle, generated data endpoints and a shared action adapter. |
| src/apps/runtime.rs | Generic pure-Wasm contribution executor; the installed package supplies all business predicates. |
| src/apps/schedules.rs | Durable UTC cron ticks emit namespaced outbox events; replicas lock due rows and staging never runs them. |
| src/apps/schema_changes.rs | Explicit, transactional field evolution. No raw migration SQL; bounded recovery snapshots precede DDL and every converted value is validated. |
| src/apps/schema_upgrade.rs | Apply a checked migration under tenant-local DDL locks with bounded recovery history and optimistic record revisions. |
| src/apps/secrets.rs | Digest-bound per-shop app secret rotation reuses platform authenticated encryption; no plaintext read endpoint. |
| src/apps/service_limits.rs | Non-queuing per-process bulkheads isolate slow apps without holding database connections. |
| src/apps/service_policy.rs | Operator-owned private origins permit isolated service networking without relaxing public egress. |
| src/apps/storage.rs | Attach the shared PostgreSQL accounting trigger to tenant-specific app tables before any write. |
| src/apps/surface_grants.rs | Short-lived UI grants bind a package, surface, actor and concrete editor object on the server. |
| src/apps/surface_tests.rs | Contract counterexamples reject cross-scope UI actions, unsafe URLs and mutating GET routes. |
| src/apps/surfaces.rs | App-owned UI surfaces and namespaced HTTP routes reuse the authorized action gateway. |
| src/apps/ui_bundles.rs | Operator-pinned, bounded self-contained UI bundles use the same actor/context grant as app actions. |
| src/apps/ui_logic.rs | Declarative UI code-behind validates a bounded AST; calls retain surface grants and server domain authorization. |
| src/apps/ui_logic_tests.rs | UI programs must keep static types, same-model saves, surface allowlists and acyclic ownership before install or preview. |
| src/apps/ui_logic_types.rs | Static UI expression types prevent control coercion and invoking save with a different model; runtime still validates actual values. |
| src/apps/webhook_scope.rs | Scope signed app ingress from its route before identity, tenant lifecycle and forced-RLS admission. |
| src/apps/webhooks.rs | Operator-signed incoming events: tenant-bound HMAC, five-minute freshness and atomic replay receipts. |
| src/assets/app_files.rs | Scoped app access to the existing asset store. Binary callbacks are explicit and private; publishing still uses the native asset lifecycle. |
| src/assets/download.rs | Public attachments honor sales-channel visibility; downloads require a paid, owned order snapshot. |
| src/assets/image_jobs.rs | Durable image jobs: tenant admission, revision-bound private previews and explicit publication, without automatic paid retries. |
| src/assets/image_provider.rs | Optional OpenAI Images adapter; bounded responses and decoded PNG output, no remote user URLs or leaked provider errors. |
| src/assets/ingestion.rs | Shared bounded multipart parser for product uploads and scoped app uploads; file validation/persistence stays in the asset owner. |
| src/assets/mod.rs | Product attachments and paid digital downloads: bounded binary persistence and tenant/account ACL. |
| src/assets/rich.rs | Safe structured rich content, never executable HTML. Same schema for merchant API and frontend. |
| src/assets/rich_document.rs | Allow-listed editor JSON with bounded depth and content; HTML/handlers/styles cannot enter the renderer. |
| src/assets/upload.rs | File admission, immutable bytes and explicit publishing; binary content never enters merchant list responses. |
| src/auth/abuse.rs | Database-backed account and trusted peer-prefix throttles shared by replicas; reserve before password hashing. |
| src/auth/broker.rs | Optional trusted identity exchange: signatures bind route, audience, expiry and one-use nonce. |
| src/auth/broker_credentials.rs | Explicit password setup/recovery or existing-password verification from a trusted, verified-email broker. |
| src/auth/broker_inference.rs | Trusted server-to-server inference inherits operator settings without disclosing any provider credentials. |
| src/auth/credentials.rs | Argon2 password operations run off the asynchronous request executor. |
| src/auth/dto.rs | Stable typed authentication envelopes; field validation remains in the shared credential owner. |
| src/auth/handoff.rs | One-time personal-session handoff to the Studio; no passwords or bearer tokens in links. |
| src/auth/identity.rs | Resolve the current credential and membership once; bootstrap and sandbox checks share the same boundary. |
| src/auth/integrations.rs | Expiring API/MCP keys are bounded to one workspace and intersect their creator's current membership. |
| src/auth/invitations.rs | Single-use, expiring invitations. Acceptance verifies an existing account password. |
| src/auth/members.rs | Workspace member visibility and immediately effective role/revocation changes. |
| src/auth/middleware.rs | Resolve sessions from PostgreSQL on every request: role changes/revocation work across replicas. |
| src/auth/mod.rs | Personal merchant accounts, tenant memberships, scoped sessions and role enforcement. |
| src/auth/permissions.rs | Fine-grained workspace overrides. Owners retain control; delegates cannot grant rights they lack. |
| src/auth/provision.rs | Reusable synthetic shop provisioning for initial signup and additional shops owned by the same merchant. |
| src/auth/registration.rs | Create an isolated merchant workspace from synthetic template data. |
| src/auth/route_policy.rs | Rights are registered beside each API method. Missing registrations always deny access. |
| src/auth/sessions.rs | Login/logout and personal workspace discovery. Only hashed opaque tokens persist. |
| src/automation_rules/comparison.rs | Original comparison primitives plus literal wildcard/zip operators; no regex or executable expressions. |
| src/automation_rules/containers.rs | Source line wrappers, quantified goods and all-line containers retain one selected line scope. |
| src/automation_rules/evaluation.rs | Evaluate native rule scopes from authoritative JSON facts with precise line/container selection. |
| src/automation_rules/fields.rs | Source custom fields retain typed equality and selection intersection; purchase prices use private server facts. |
| src/automation_rules/mod.rs | Source-named rule registry and checked evaluation; absent required facts are errors, including under NOT. |
| src/automation_rules/tests.rs | Regression cases cover missing authority under NOT, original quantifiers, dates, metadata types and registry bounds. |
| src/automation_rules/time.rs | Calendar comparisons use an explicit server clock, IANA zones and the original exclusive date-range end. |
| src/automation_rules/validation.rs | Bounded source payload validation against exported field/operator metadata and nested condition scopes. |
| src/bin/automation_rules.rs | JSON batch transport for comparisons with original Shopware rule classes; not a production authority endpoint. |
| src/bin/connectors.rs | Independent Rust standard-app service; no provider code executes in commerce request workers. |
| src/bin/context.rs | Bounded ports of original language-chain, rule priority and quantity selection. |
| src/bin/delivery.rs | Batch proportional-tax fixture transport for the original-PHP comparator. |
| src/bin/money_boundary.rs | Batch transport for comparing the actual legacy-to-integer checkout boundary against original Shopware totals. |
| src/bin/price.rs | Batch price fixture transport for the original-PHP differential comparator. |
| src/bin/rules.rs | Batch original-PHP numeric-rule comparison transport. |
| src/bin/verified_kernel.rs | Generated conformance driver; invokes the same production policy functions as the commerce server. |
| src/bootstrap.rs | Startup, additive migrations, persisted extensions and outbox worker. |
| src/capabilities/catalog.rs | Shared catalogue composes native capabilities and cognitive contracts without duplicating authorization. |
| src/capabilities/core_catalog.rs | Public HTTP/MCP capability catalogue, separate from authorization and dispatch. |
| src/capabilities.rs | Shared HTTP/MCP capability dispatch and tool authorization. |
| src/cart_model.rs | Persisted cart, item and customer-context types. |
| src/cart_mutation.rs | Optimistic cart mutations and quantity normalization. |
| src/cart_price.rs | Authoritative quantity pricing and localized checkout quote assembly. |
| src/cart_routes.rs | Store API cart and order route adapters. |
| src/cart_storage.rs | Cart creation, loading and input validation. |
| src/catalog_model.rs | Tenant product model and database hydration. |
| src/catalog_page.rs | Bounded tenant-scoped catalog reads. A cursor is a product ID, never an offset. |
| src/catalog_routes.rs | Health and localized catalogue HTTP routes. |
| src/categories/admin.rs | Revision-bound category writes, bounded translations and serialized cycle-safe tree moves. |
| src/categories/graph_query.rs | Saved category predicates select only current confirmed public source claims; no inference at browse time. |
| src/categories/mod.rs | Tenant-scoped category tree, localized navigation and product assignment boundaries. |
| src/categories/navigation.rs | Public navigation is localized and restricted to the selected channel's active category ancestry. |
| src/channel_metrics/reads.rs | One persisted diagnostic read shared by operator overview, shop dossiers and infrastructure. |
| src/channel_metrics.rs | Bounded, lossy diagnostic counters. Never use this buffer for business events. |
| src/chat_lease.rs | Short, cross-replica conversation leases; inference never retains a database transaction. |
| src/checkout_handoff.rs | Single-use checkout transfer for independent storefronts; no app-specific catalog or checkout rules. |
| src/checkout_page.rs | The existing checkout may be framed only by its registered tenant/channel storefront. |
| src/checkout_products.rs | Localized immutable checkout SKU snapshots read under the purchase transaction's locks. |
| src/cognition/advisor.rs | Buyer-admitted initial catalog/evidence context and bounded native response revalidation; no extra truth store. |
| src/cognition/autonomy.rs | Price-only optional autonomy, atomic unique-SKU daily quotas and a non-compounding day baseline. |
| src/cognition/claim_batches.rs | Bounded public claim intake/compilation shares current channel admission and source-bound evidence, without per-SKU HTTP round trips. |
| src/cognition/context.rs | Bounded localized catalog retrieval before inference; full catalog size never expands the prompt. |
| src/cognition/contracts.rs | Evidence APIs and MCP contracts dispatch into one authorized owner; the claim compiler rejects free prose. |
| src/cognition/evidence.rs | Source-bound claim lifecycle on the existing knowledge relation ledger; no model text becomes a confirmed fact automatically. |
| src/cognition/experiments/mod.rs | Controlled experiments use the existing storefront layout consumer and authoritative payment ledger. |
| src/cognition/experiments/model.rs | Preregistered fixed-horizon experiment parameters and conservative bounded-outcome inference. |
| src/cognition/experiments/report.rs | Delayed final experiment readout is derived from the existing live capture/refund ledger, never demo rewards. |
| src/cognition/extraction.rs | API/MCP/flow source extraction shares provider admission and quote checks; candidates require merchant review. |
| src/cognition/generations.rs | Restart-safe model-change intake: short locked cursor batches reuse the canonical embedding queue. |
| src/cognition/guardrails.rs | Merchant-owned guardrails in commerce settings; native currency amounts bind preview and execution. |
| src/cognition/indexing.rs | Durable bounded embedding jobs; short claims and revision fences keep provider latency outside PostgreSQL. |
| src/cognition/mod.rs | Evidence-based shop memory: event receipts, observed pairs, reviewable hypotheses and bounded context. |
| src/cognition/preferences.rs | Consent-bound private cart preference graph: typed bounded input, export, erasure and native advisor context. |
| src/cognition/projection.rs | Exactly-once local observation projection; associations retain order/event evidence and simulation labels. |
| src/cognition/recommendations.rs | Merchant-approved associations are consumed by the public shop without exposing order counts or identities. |
| src/cognition/routes.rs | Merchant memory endpoints and revision-bound experiment/dismissal decisions. |
| src/cognition/signed.rs | Public Ed25519 attestations bind exact native facts and channel context for five minutes; signatures do not guarantee source truth. |
| src/cognition/stream.rs | SSE transports real chat completion and waiting heartbeats; detached execution retains tenant scope and the existing durable chat lease. |
| src/cognition/tools.rs | Bounded agent read rounds use the same capability dispatcher and current actor rights; never execute writes. |
| src/commerce/app_adjustments.rs | Apply admitted integer app adjustments through native pricing/tax calculation; extensions cannot replace quote JSON. |
| src/commerce/catalog.rs | SKU loading with parent translation fallback. |
| src/commerce/configuration.rs | Tenant checkout configuration loading. |
| src/commerce/content_text.rs | Shared field-level content fallback for metadata and configurable object names. |
| src/commerce/context_routes.rs | Public method discovery and revision-checked checkout context changes. |
| src/commerce/customer_groups.rs | Tenant-owned translated customer groups preserve exact rule IDs and select an explicit existing price/tax presentation basis. |
| src/commerce/delivery.rs | Shipping costs, proportional taxes and calendar delivery windows. |
| src/commerce/detail.rs | Product family, context prices, gallery, properties and review aggregates. |
| src/commerce/fulfillment.rs | Revision-checked payment and delivery state transitions. |
| src/commerce/geography.rs | Bundled MIT country catalogue, tenant-owned overrides and typed region admission. |
| src/commerce/group_usage.rs | Removing a customer group rejects live customer, price and native/source-rule dependencies under the settings lock. |
| src/commerce/international_capabilities.rs | International configuration and translation MCP tools call the exact same scoped native handlers as HTTP. |
| src/commerce/inventory.rs | All-checkout allocation ledger; release is idempotent and always uses persisted quantities, never edited order JSON. |
| src/commerce/method_text.rs | Shared translated names and descriptions with field-wise shop-main-language inheritance. |
| src/commerce/method_usage.rs | Tenant-scoped dependency preflight and authoritative deletion guards; order snapshots remain immutable. |
| src/commerce/mod.rs | Native catalogue and checkout domains; pricing ports remain in the library. |
| src/commerce/order_fields.rs | Standard order read fields are projected from the authoritative quote/payment, never maintained twice. |
| src/commerce/order_machine.rs | Declarative order workflow schema. Extensions add states, never executable effects or payment truth. |
| src/commerce/order_workflow.rs | One server-derived action catalogue drives UI, HTTP and MCP; built-in business guards cannot be bypassed. |
| src/commerce/product_admin.rs | Central product list and identity/association writes; all persistence is tenant scoped. |
| src/commerce/product_channels.rs | Per-product channel visibility overrides remain indexed even when an open catalog contains millions of products. |
| src/commerce/product_create.rs | Product creation accepts validated stable import IDs; the shared domain save handler retains pricing, ownership and history checks. |
| src/commerce/product_edit.rs | Revision-bound multilingual product metadata: specifications, SEO, cross-selling and free shipping. |
| src/commerce/product_fields.rs | Native product administration writes priced fields under the same revision and inventory row lock. |
| src/commerce/product_languages.rs | Enabled content languages, NULL field inheritance and stable global language registration. |
| src/commerce/product_metadata.rs | Typed product edit payload and multilingual metadata including exact currency prices. |
| src/commerce/review_moderation.rs | Merchant authorization and review publication. |
| src/commerce/reviews.rs | Customer review submission with server-derived purchase verification. |
| src/commerce/selection.rs | Recover a quote after configuration changes without losing items or silently committing new choices. |
| src/commerce/settings_defaults.rs | Backward-compatible enrichment of existing configuration with bundled translated method labels. |
| src/commerce/settings_mutation.rs | Optimistic settings persistence and audit event. |
| src/commerce/settings_patch.rs | Transport-only sparse JSON differences: stable record IDs, explicit nulls, and deletion distinct from inheritance. |
| src/commerce/settings_release.rs | Selective staging units for channel settings; all final aggregates and method dependencies use native validators. |
| src/commerce/settings_routes.rs | Tenant configuration and operational read model. |
| src/commerce/settings_scope.rs | Scoped checkout configuration: basis row lock orders all override writes and authoritative checkout reads. |
| src/commerce/settings_validation.rs | Configuration validation and required availability invariants. |
| src/commerce/tax.rs | Destination tax-class resolution and net-preserving price conversion. |
| src/commerce/tax_context.rs | Tax conditions consume private authoritative pre-tax cart facts without a recursive quote. |
| src/commerce/tax_rules.rs | Priority-based destination rules; current tax law is merchant configuration, not bundled tax advice. |
| src/commerce/types.rs | Checkout selection and configuration data contracts. |
| src/component_runtime.rs | WIT-typed read-only commerce guest. Snapshots are prepared by domain owners; no WASI, HTTP, DB or merchant credentials reach components. |
| src/concierge.rs | Read-only storefront shopping advisor. |
| src/connectors/actions.rs | Existing standard-app actions and event/export endpoints share validated tenant-bound dispatch. |
| src/connectors/config.rs | Compile-time mail setting types plus bounded runtime validation and write-only credentials. |
| src/connectors/crypto.rs | Authenticated encryption binds config, OAuth verifiers, messages and receipts to tenant and app. |
| src/connectors/email.rs | Email app actions/events retain the published gateway, flow and MCP payload contract. |
| src/connectors/error.rs | Sanitized failures distinguish explicit rejection from ambiguous external side effects. |
| src/connectors/events.rs | One bounded event envelope feeds existing durable, idempotent connector queues; no parallel scheduler. |
| src/connectors/exports.rs | Tenant-scoped encrypted knowledge records and bounded monotonic exports preserve importer fences. |
| src/connectors/legacy.rs | Explicit offline SQLite export import: all records are rebound/encrypted atomically; ambiguous jobs stay uncertain. |
| src/connectors/mod.rs | Language-neutral app HTTP contract backed by a Rust-only standard connector runtime. |
| src/connectors/network.rs | Fixed provider endpoints, no redirects, bounded response streaming and loopback-only fixture overrides. |
| src/connectors/oauth.rs | Single-use tenant/app-bound OAuth state, PKCE, encrypted tokens and serialized refresh/disconnect. |
| src/connectors/providers/analytics.rs | Exact bounded GA4 source rows, quota metadata and stale-report tombstones; no invented causal claims. |
| src/connectors/providers/gmail.rs | Read-only Gmail incremental imports preserve high-water cursors, bounded windows and deletion evidence. |
| src/connectors/providers.rs | Provider-specific read imports and notification mapping stay outside the commerce kernel. |
| src/connectors/queue.rs | Atomic idempotent enqueue, fair tenant admission and lease-fenced SKIP LOCKED claims for many workers. |
| src/connectors/server.rs | Authenticated bounded app HTTP service with private OAuth callback and graceful worker lifetime. |
| src/connectors/smtp.rs | Pinned SMTP/STARTTLS/TLS with verified hostname, bounded dialogue and no retry after ambiguous DATA. |
| src/connectors/store.rs | PostgreSQL transactions carry local RLS context; config mutation serializes with in-flight delivery. |
| src/connectors/templates.rs | Bounded immutable envelopes and non-executable multilingual templates; HTML substitutions are escaped. |
| src/connectors/tests.rs | Actual Rust parsers, encryption and template consumers reject escalation/injection and preserve language behavior. |
| src/connectors/worker.rs | Distributed delivery workers fence settings and leases, retry only proven rejection, and drain on shutdown. |
| src/context.rs | Bounded behavioral ports of Shopware 6.7.14.2 context and product-cart selection. |
| src/currencies/capabilities.rs | Currency MCP operations reuse the native HTTP handlers and existing settings/catalog permissions. |
| src/currencies/jobs.rs | Bounded restart-safe fixed-price materialization with frozen FX, product locks and atomic checkpoints across replicas. |
| src/currencies/mod.rs | Tenant currency configuration, channel contexts and durable price generation; no FX network calls in checkout. |
| src/currencies/model.rs | Explicit currency scales and rational exchange-rate settings, inherited by sales-channel overrides. |
| src/currencies/pricing.rs | Exact rational minor-unit FX conversion at the isolated legacy calculator boundary; fixed prices are explicit decimal strings. |
| src/currencies/rates.rs | Bounded ECB reference-rate retrieval with exact decimal parsing; refresh runs outside checkout and never invents rates. |
| src/currencies/routes.rs | Native currency discovery, revision-safe selection and authenticated FX/price job operations. |
| src/currencies/tests.rs | Currency conversion adversaries and immutable source-price semantics, independent of live rate providers. |
| src/customer.rs | Customer credential verification and context rotation. |
| src/demo_catalog.rs | Public synthetic fashion template; provisioning copies only this versioned fixture into a new tenant. |
| src/developer/archive.rs | Recoverable App Studio project deletion; installed packages and app records retain their independent lifecycle. |
| src/developer/builds.rs | Immutable development versions are validated before storage; installation targets only private environments. |
| src/developer/drafts.rs | Actor-private, optimistic mutable autosaves; these never install or alter a published package. |
| src/developer/generation.rs | Structured provider output becomes a reviewable immutable manifest; it cannot write files or call shell tools. |
| src/developer/mod.rs | Prompt-generated declarative apps and native coding-agent handoff, never unsandboxed model code. |
| src/developer/preview.rs | F5 runs the shared native app runtime in an actor-private expiring staging clone; no build/version/release is created. |
| src/developer/routes.rs | Developer HTTP transport and coding-agent task export; explicit staging precedes live release. |
| src/discount.rs | Integer-cent proportional discount allocation; cumulative rounding conserves the exact basket discount. |
| src/documents/content.rs | Validate enabled-language source content and rebuild hash-bound chunks without inherited fabricated translations. |
| src/documents/ingestion.rs | Typed API and bounded upload write source hashes, chunks and graph relations atomically. |
| src/documents/lifecycle.rs | Revision-bound source detail, editing, archive/restore and publication; edits require a new public review. |
| src/documents/mod.rs | Source-bound knowledge ingestion, retrieval and product questions share tenant/product visibility. |
| src/documents/parser.rs | PDF extraction executes in a killable child process without inherited commerce credentials. |
| src/documents/preview.rs | No-provider retrieval preview shares product-question scope and locale rules; merchant sources never enter customer previews. |
| src/documents/product_knowledge.rs | Product-centred canonical facts and tenant-filtered graph evidence, independent of the overview's truncated sample. |
| src/documents/questions.rs | Product-specific read-only advice with authoritative price/specification snapshot and validated source citations. |
| src/documents/retrieval.rs | Bounded lexical/vector source retrieval; public questions use only explicitly published documents. |
| src/documents/tools.rs | Knowledge workspace/source MCP tools delegate to the same authorized HTTP operations and schemas. |
| src/documents/workspace.rs | Permission-filtered knowledge census, cursor source inventory and activity; totals never masquerade as sampled graph counts. |
| src/experience.rs | Persisted storefront layout policy and observed synthetic rewards. |
| src/extensions.rs | Merchant catalogue and Wasm extension activation/state. |
| src/foundation.rs | Application dependencies, error responses and request context helpers. |
| src/history/capability.rs | HTTP/MCP parity for history; per-entity read/write scopes are checked again at invocation time. |
| src/history/mod.rs | Uniform tenant-scoped history from transactional database snapshots; restoration delegates to existing domain validators. |
| src/history/product.rs | Rebuild a product edit from an audited snapshot; stock stays current and all associations/media pass normal admission. |
| src/history/restore.rs | Restore snapshots by replaying validated entity edits; financial effects and publication are never copied from historical state. |
| src/history/routes.rs | History summaries are bounded and permission-filtered; full snapshots and restore targets stay inside the owning shop. |
| src/http_json.rs | Bound untrusted provider JSON before allocation/deserialization; connection pooling remains with each existing service owner. |
| src/http_limits.rs | Bounded streaming responses for extension services and payment providers. |
| src/inference/protocol.rs | Self-hosted chat-completions adapter and opt-in provider prompt caching; neither caches private commerce responses. |
| src/inference/schema.rs | Provider wire adaptation for strict fixed-object schemas; dynamic JSON is encoded only on the model wire and restored before domain validation. |
| src/inference/settings.rs | Shared operator settings; AES-GCM secrets are never part of merchant/operator read responses. |
| src/inference/tests.rs | Provider response contracts, strict schemas and truncation rejection. |
| src/inference.rs | Provider adapters. Credentials stay on the server; domain validation is separate. |
| src/knowledge/embeddings.rs | Bounded batched embeddings: Ollama and OpenAI-compatible self-hosted endpoints, model-defined dimensions. |
| src/knowledge/relations.rs | Keep knowledge provenance and relations in the same transaction as canonical commerce data. |
| src/knowledge/rerank.rs | Optional TEI cross-encoder reranking on at most 24 tenant-hydrated texts; malformed or unavailable providers retain fused ordering. |
| src/knowledge/search.rs | Hybrid exact/lexical + dense RRF; hydrate current tenant rows and retrieve only connected evidence. |
| src/knowledge/vector_cache.rs | Bounded, short-lived collection geometry cache; only successful verification is cached. |
| src/knowledge/vectors.rs | Private Qdrant adapter: tenant/model filters, deterministic identities and durable PostgreSQL index queue. |
| src/knowledge.rs | Transactional PostgreSQL knowledge relations and separately indexed Qdrant retrieval. |
| src/legal/capabilities.rs | MCP legal tools delegate to the same ownership/permission-checked HTTP domain handlers. |
| src/legal/checkout.rs | Explicit document/digital acknowledgement and immutable order policy snapshots; transport-neutral checkout guard. |
| src/legal/consent.rs | Cart/channel-bound affirmative choices; stale/expired policy receipts never authorize processing. |
| src/legal/mod.rs | Connected legal/privacy boundary: configuration, consent, checkout snapshots and durable requests. |
| src/legal/model.rs | Bounded multilingual legal configuration; policy changes invalidate optional-purpose consent. |
| src/legal/product.rs | Explicit product safety/sector facts, with market-language fallback; no inference of certifications. |
| src/legal/requests.rs | Durable withdrawal/data-rights intake, tenant-scoped operator review and customer-held receipt access. |
| src/lib.rs | Reusable pricing, context, sandbox, graph and inference modules. |
| src/localization.rs | Shop locale resolution, translated catalog hydration and non-mutating merchant quote. |
| src/main.rs | Process lifetime only. See docs/source-map.md for domain responsibilities. |
| src/marketing/app_flows.rs | App flow dispatch uses the same permission/schema gateway as HTTP/MCP, with a stable job key. |
| src/marketing/catalog.rs | Native condition metadata, app action/event discovery and source-compatible condition import. |
| src/marketing/channel_access.rs | Single admission boundary for Store API, UCP/MCP and hosted storefronts; previews cannot purchase. |
| src/marketing/channel_preview.rs | One-use preview handoff becomes a host-only cookie, bound to current session, membership and channel revision. |
| src/marketing/channels.rs | Sales channels share a merchant tenant but bind independent catalog visibility, locale and cart identity. |
| src/marketing/condition_gateway.rs | Shared rule admission and authoritative context for tax and other native consumers. |
| src/marketing/customer_facts.rs | Customer rule authority is loaded by tenant and stable customer ID, with aggregate history and calendar age. |
| src/marketing/dependencies.rs | Inspect tenant-owned definition references and durable uses before configuration deletion. |
| src/marketing/facts.rs | Assemble private server-owned rule context once per quote/event; never publish customer facts in cart responses. |
| src/marketing/flow_access.rs | Every queued flow step rehydrates current membership; stored definitions never preserve revoked privileges. |
| src/marketing/flow_actions.rs | Native action schema and permissions use original Core names; no arbitrary SQL, shell or unguarded payment transitions. |
| src/marketing/flow_mutations.rs | Local flow mutations journal the effect in the same transaction; customer authority changes revoke existing sessions. |
| src/marketing/flow_text.rs | Shop-language validation and main-language fallback for both simple flows and graphical action nodes. |
| src/marketing/flows.rs | Durable order-event flows: conditions, shop notes and AI proposals; no unapproved model mutations. |
| src/marketing/gateway.rs | MCP automation tools call the same tenant-bound handlers and validators as HTTP; no separate mutation semantics. |
| src/marketing/jobs.rs | Read bounded tenant flow execution summaries without reloading rule/channel configuration on each Studio refresh. |
| src/marketing/lifecycle.rs | Revision-bound deletion and reference admission share HTTP/MCP authorization and tenant locks. |
| src/marketing/line_facts.rs | Rule line facts use immutable priced lines plus current tenant product metadata; protected values override metadata. |
| src/marketing/metadata.rs | Authorized revision-bound source facts for products, customers and orders; secrets and pricing authority are excluded. |
| src/marketing/mod.rs | Native rule conditions, coupons, durable flows and headless/storefront sales-channel boundaries. |
| src/marketing/pipeline.rs | A bounded acyclic flow graph models source-style true/false branches, ordered actions, delays and stop nodes. |
| src/marketing/pipeline_runtime.rs | Durable sequence execution records each action before dispatch, persists delay cursors and reports uncertain effects. |
| src/marketing/pipeline_tests.rs | Flow graph and source action schema regression tests reject unsafe graphs before any event dispatch. |
| src/marketing/promotions.rs | Server-authoritative coupons and automatic campaigns, with deterministic discounts and atomic usage limits. |
| src/marketing/routes.rs | Typed configuration CRUD, rule preview and revision-bound coupon edits. |
| src/marketing/rule_fields.rs | Typed rule fields share the original comparison operators and server-derived checkout/event facts. |
| src/marketing/rule_match.rs | Evaluate typed rule trees against server-owned cart, customer and event facts. |
| src/marketing/rule_snapshot.rs | Resolve only referenced tenant rule IDs with indexed batched reads; freeze active definitions and revisions into the event snapshot. |
| src/marketing/rule_tests.rs | Regression cases for native rule facts and original container boundaries. |
| src/marketing/rules.rs | Bounded Shopware-style boolean/numeric rule AST. Unknown operators/conditions fail closed. |
| src/mcp/transport.rs | MCP visibility and shared read-scope memoization, independent of internal planning tools. |
| src/mcp.rs | Typed MCP schemas and JSON-RPC transport. |
| src/migrations/schema.rs | Append-only ordered migration source catalogue; deployed checksums are never rewritten. |
| src/migrations.rs | Versioned setup is separate from serving; no catalog-wide startup repair. |
| src/money.rs | Exact signed minor-unit amounts with explicit currency scale; legacy Shopware float pricing stays isolated. |
| src/network_policy.rs | Shared DNS destination classification for app HTTP egress and approved SMTP providers. |
| src/operations/addresses.rs | Merchant/MCP address operations use identical customer ownership and revision checks to the Store API. |
| src/operations/company_logo.rs | Tenant-owned logo uploads: bounded decoding, metadata stripping, immutable PNG storage and linked public delivery. |
| src/operations/company_model.rs | Company profile admission, sparse channel inheritance and structured-address print projection. |
| src/operations/company_public.rs | Explicit public legal/brand projection; bank account, domestic tax ID and unlinked uploads remain private. |
| src/operations/customers.rs | Tenant-scoped paged CRM and revision-checked merchant changes; credentials never leave storage. |
| src/operations/guest_customers.rs | Merchant-only guest contact projection; order snapshots never create account authority. |
| src/operations/master_data.rs | Revisioned tenant company basis and sparse channel overrides, serialized with receipt issuance. |
| src/operations/mod.rs | Merchant CRM and fulfillment APIs, shared verbatim with MCP operations capabilities. |
| src/operations/orders.rs | Bounded order search, token-redacted detail and append-only operational notes. |
| src/operations/receipt_pdf.rs | Minimal paginated PDF serializer with WinAnsi Helvetica; snapshot retains complete Unicode originals. |
| src/operations/receipt_text.rs | Four-language document labels and authoritative snapshot-to-print projection. |
| src/operations/receipts.rs | Idempotent immutable invoices/delivery notes with transactional per-shop number ranges. |
| src/operations/routes.rs | HTTP/MCP rights for merchant CRM, fulfillment and company settings. |
| src/operations/workflow.rs | Revision-bound workflow configuration used by installed apps and selective sandbox releases. |
| src/order_checkout.rs | Atomic checkout, stock locks, extension policy and idempotency. |
| src/order_routes.rs | Merchant order read adapter. |
| src/outbox/control.rs | Tenant-authorized quarantine inspection and explicit retry; delivered or retired events cannot be replayed here. |
| src/outbox/retention.rs | Bounded retirement of duplicate delivered payloads; provenance IDs and unsettled app/flow work survive. |
| src/outbox.rs | Durable outbox and audit projection worker. |
| src/payments/accounts.rs | Merchant-authorized onboarding bridge; only authenticated provider responses establish account bindings. |
| src/payments/app_commands.rs | App/Flow/MCP payment actions enqueue core jobs; provider-bound attempts prevent cross-app command authority. |
| src/payments/contract.rs | Versioned app-owned payment methods; declarations never grant financial authority. |
| src/payments/generic_receipts.rs | Provider-neutral receipt admission and atomic allocation; verified evidence owns ledger transitions. |
| src/payments/mod.rs | Provider-independent payment ledger and durable workers; the PayPal adapter supports explicit Sandbox/Live environments. |
| src/payments/operations.rs | Durable idempotent payment commands, customer context binding and serial refund admission. |
| src/payments/paypal.rs | Native PayPal Orders v2 sandbox wire adapter; credentials never enter prompts or browser responses. |
| src/payments/provider.rs | Payment provider identity, tenant account configuration and immutable wire context. |
| src/payments/provider_configuration.rs | Pure startup validation of the native provider origin; no live credentials or provider calls. |
| src/payments/provider_webhooks.rs | Version-pinned HMAC notifications enqueue reconciliation; external event payloads never write monetary state. |
| src/payments/receipt_guard.rs | Bind integer provider receipt amounts and status to the formally checked exact-match predicate. |
| src/payments/registry.rs | Installed payment registry and immutable account/version snapshots; no remote calls inside checkout SQL. |
| src/payments/remote.rs | Dedicated payment RPC, pinned service version and operator-owned egress; never ordinary app-action receipts. |
| src/payments/return_urls.rs | Provider return/cancel URLs preserve the tenant and sales channel; navigation is never payment evidence. |
| src/payments/routes.rs | Customer payment status/capture and merchant refund operations share the durable command API. |
| src/payments/sessions.rs | Customer-bound, short-lived provider UI sessions; iframe messages are never ledger receipts. |
| src/payments/state.rs | One monotonic provider-neutral ledger state machine; evidence validation and authorization stay in receipt adapters. |
| src/payments/storage.rs | Transactional provider receipts and order state updates; external responses cannot invent amounts or tenants. |
| src/payments/webhooks.rs | PayPal verifies webhook signatures before inbox insertion; provider reconciliation confirms monetary state. |
| src/payments/worker.rs | Leased payment jobs; network runs after claim commit, fenced receipts prevent duplicate local effects. |
| src/performance/access_snapshot.rs | One fresh, server-owned admission read shared by domain, identity, availability, channel and proxy middleware. |
| src/performance/admission.rs | Bounded instance/tenant concurrency, durable UTC-day AI quotas, and low-cardinality latency telemetry. |
| src/performance/cache.rs | Bounded weighted LRU for immutable decoded read models; no network I/O under its mutex. |
| src/performance/cluster_lease.rs | Cluster-wide tenant resource leases. DB serialization protects admission; cancellation releases the fenced lease. |
| src/performance/delivery.rs | Native static bypass and bounded HTTP compression; credentials, streams and already encoded bodies stay intact. |
| src/performance/invalidation.rs | Commit-only outbox notifications eagerly evict replica caches; authoritative version probes survive missed events. |
| src/performance/languages.rs | Global language registry is versioned in the same transaction as every registry mutation. |
| src/performance/mod.rs | Shared read-context caching with authoritative versions; mutations and checkout locks stay outside memoization. |
| src/performance/pool.rs | Explicit per-process database budgets and bounded queue waits; invalid deployment values fail fast. |
| src/performance/row_security.rs | Bind each borrowed PostgreSQL connection to task scope, and reject unsafe strict-runtime roles. |
| src/performance/settings.rs | One MVCC snapshot validates base/override UUIDs; warm reads avoid transmitting or decoding JSON. |
| src/planner.rs | Grounded model planning, recorded inputs and proposed changes. |
| src/platform/ai.rs | Operator-only inference administration: optimistic revision, encrypted write-only keys and audit without secrets. |
| src/platform/auth.rs | Independent platform authorization: live personal sessions, current grants, no integration/bootstrap escalation. |
| src/platform/bootstrap.rs | Offline first-operator setup: migration-only process, supplied strong credentials, password proof for existing accounts. |
| src/platform/infrastructure.rs | Live control-plane telemetry: database probes and pool/cache diagnostics, explicit process-only scope. |
| src/platform/lifecycle.rs | Audited, reversible lifecycle; preserved commerce records and current revision prevent accidental overwrites. |
| src/platform/metrics.rs | Aggregate-only control-plane reads: real tenants, bounded pages, explicit currencies and simulated/confirmed amounts. |
| src/platform/mod.rs | Global SaaS control plane: operator-only aggregate statistics and audited shop provisioning. |
| src/platform/provision.rs | Operator shop creation commits ownership, settings and audit atomically; never issues another user's credentials. |
| src/platform/quotas.rs | Operator-only per-shop daily interactive AI limits, optimistic revisions and durable audit. |
| src/platform/resources.rs | Linux container resource readings; unavailable fields stay null on other hosts and the first CPU sample. |
| src/platform/shop_detail.rs | Operator shop dossier: registration, business identity, access roster, channels and measured HTTP activity. |
| src/pricing.rs | Behavioral port of Shopware 6.7.14.2 quantity calculators. |
| src/proposal_apply.rs | Transactional application of approved, revision-bound proposals. |
| src/proposal_model.rs | Typed proposals and validation before persistence or execution. |
| src/proposal_routes.rs | HTTP proposal creation, approval and task listing. |
| src/request_context.rs | Trusted request identity lives in extensions; HTTP headers carry transport inputs only. |
| src/routes.rs | HTTP transport registry; domain behavior lives in dedicated modules. |
| src/rule_comparison.rs | Behavioral port of Shopware 6.7.14.2 RuleComparison::numeric and FloatComparator's exact epsilon boundaries. |
| src/runtime_config.rs | Immutable process configuration, validated once at startup. Mutable shop/provider settings remain in PostgreSQL. |
| src/sandbox.rs | Pure Wasmtime guest execution with bounded resources and no host imports. |
| src/sandbox_cache.rs | Bounded tenant-policy compilation cache. Prepare outside commerce locks; verify the digest under the lock. |
| src/sandbox_engine.rs | One bounded Wasmtime engine per process, with independent fuel and wall-clock interruption. |
| src/scoped_pool.rs | The commerce database executor: transaction-local tenant scope, including direct queries and cancelled streams. |
| src/security_headers.rs | Common browser defenses on successful responses and errors, including reverse-proxy HTTPS deployments. |
| src/seed.rs | Idempotent synthetic template catalogue initialization. |
| src/shop_domains/frontend_bindings.rs | Revisioned aliases point to an existing tenant-owned Experience; origin selection remains operator-only. |
| src/shop_domains/frontend_editor.rs | Operator-owned editor navigation for hosted frontends; no private editor or identity implementation. |
| src/shop_domains/frontend_transport.rs | Stream generic hosted frontend responses and admit only explicitly allowlisted opaque shopper cookies. |
| src/shop_domains/frontends.rs | Generic operator-allowlisted frontend mounts. Host scope is derived from storage, never client headers. |
| src/shop_domains.rs | Resolve configured shop subdomains before authentication; reject unknown hosts and conflicting scopes. |
| src/staging/assets.rs | Binary assets are immutable, staged independently through metadata/digest units; paid entitlements never clone. |
| src/staging/categories.rs | Category release units and dependency-ordered tree publication; stock is never part of a catalog release. |
| src/staging/clone.rs | Clone only catalog/configuration into a private tenant; customer/order/payment state is excluded. |
| src/staging/company.rs | Selective company identity release copies only linked immutable logo bytes and validates the final company aggregate. |
| src/staging/documents.rs | Knowledge documents/chunks clone and publish with their source provenance; publication visibility is a reviewed unit. |
| src/staging/mod.rs | Private cloned shops, scope admission and selective atomic release of reviewed changes. |
| src/staging/release.rs | Selected units publish in one transaction with staged digests and live baseline conflict checks. |
| src/staging/snapshot.rs | Fixed publishable units: product content/translations, settings, experience and app packages. |
| src/storefront_pages.rs | Deep-link HTML transport for stable SKU URLs with optional localized SEO slugs. |
| src/studio/facts.rs | Consolidate dashboard reads without unbounded pool fan-out; preserve the existing API and currency/learning semantics. |
| src/studio/revenue.rs | Merchant turnover remains separated by invoice currency; historical values are never repriced with today's FX. |
| src/studio.rs | Verified merchant overview facts consumed by the chat and activity views. |
| src/tenant_scope.rs | Database lease context: unknown tasks fail closed; trusted workers explicitly retain their scope. |
| src/translations/apply.rs | Apply at most 50 reviewed drafts per request; stale products become conflicts rather than being overwritten. |
| src/translations/fields.rs | Translate only human-readable text; preserve identifiers, URLs, rich structure and source specification keys. |
| src/translations/mod.rs | Tenant-scoped, resumable AI translation drafts; applying is revision checked and emits native product events. |
| src/translations/routes.rs | Authorized translation job creation, progress, paginated drafts and resume/cancel controls. |
| src/translations/worker.rs | One leased product per step: keyset traversal, bounded inference and resumable provider errors. |
| src/ucp.rs | Selected UCP checkout adapters sharing the native cart. |
| src/verified_kernel.rs | Closed, side-effect-free commerce policies extracted to Lean; keep within the checked bool/u64 grammar. |
| src/work_signal.rs | One dedicated LISTEN connection per worker process. Commit notifications are hints; polling repairs lost hints. |
| src/workers.rs | Independently deployable worker roles; leases and durable receipts coordinate replicas. |
Studio, storefront, platform and shared frontend
| Module | Responsibility |
|---|---|
| frontend/src/admin/agents/AgentsView.tsx | AgentsView renders verified shop state and typed user actions. |
| frontend/src/admin/apps/AppAccess.tsx | Explicit consent for digest-bound server callback keys; plaintext is shown once and never persisted in the browser. |
| frontend/src/admin/apps/AppActivity.tsx | API-backed per-app call metadata, storage budgets and explicitly approved durable replay. |
| frontend/src/admin/apps/AppArtwork.tsx | Passive app artwork with independent failed-image fallbacks and deterministic local category covers. |
| frontend/src/admin/apps/AppConsent.tsx | Review the actual package and permission changes before installation; consent is enforced by the API. |
| frontend/src/admin/apps/AppDetails.tsx | AppDetails: Installed app details, activation, version, data and isolated interface. |
| frontend/src/admin/apps/AppEntity.tsx | Managed entity editor renders fields from the installed app contract. |
| frontend/src/admin/apps/AppInterfaces.tsx | Open registered native/isolated admin surfaces through the existing permission-filtered registry. |
| frontend/src/admin/apps/AppJobArtifact.tsx | Completed app exports read the existing tenant asset owner; private files never acquire a public URL. |
| frontend/src/admin/apps/AppJobs.tsx | Long actions use the same app/outbox contract, with progress and explicit uncertain-outcome review. |
| frontend/src/admin/apps/AppLibrary.tsx | Searchable installed/discovery app cards with category/status filters and real lifecycle actions. |
| frontend/src/admin/apps/AppSecrets.tsx | Metadata-only credentials screen; rotation sends plaintext once to the encrypted server store. |
| frontend/src/admin/apps/AppsManager.tsx | Installed package workspace: lifecycle, generated entities and shared agent actions. |
| frontend/src/admin/apps/ConnectorPanel.tsx | Native app workspace: OAuth, provider settings, durable jobs and private sources. |
| frontend/src/admin/apps/EmailPanel.tsx | Native email app settings, localized templates, safe previews and durable delivery receipts. |
| frontend/src/admin/apps/EmailProviderFields.tsx | EmailProviderFields: focused connector-settings view with explicit typed inputs and callbacks. |
| frontend/src/admin/apps/PaymentManager.tsx | Payment ledger, adapter readiness and explicit refund approval. |
| frontend/src/admin/apps/ProviderAccount.tsx | Shared installed-provider onboarding and channel connection controls for merchant Apps and App Studio. |
| frontend/src/admin/apps/app-types.ts | Installed package metadata used by app administration views. |
| frontend/src/admin/apps/email-languages.ts | Supported transactional email template languages. |
| frontend/src/admin/apps/library-model.ts | Shared app discovery metadata, safe artwork sources and localized search independent of rendering. |
| frontend/src/admin/assistant/MessageText.tsx | MessageText keeps merchant interaction separate from workspace orchestration. |
| frontend/src/admin/assistant/ProposalCard.tsx | ProposalCard keeps merchant interaction separate from workspace orchestration. |
| frontend/src/admin/assistant/SettingsDialog.tsx | SettingsDialog keeps merchant interaction separate from workspace orchestration. |
| frontend/src/admin/assistant/WorkspaceCopilot.tsx | Contextual drawer reuses the existing scoped conversation, permissions and proposal execution without unmounting editors. |
| frontend/src/admin/automation/AutomationDefinitions.tsx | Searchable, explicitly editable definitions with visible active state and version. |
| frontend/src/admin/automation/AutomationDelete.tsx | One confirmation and a server recheck; stale versions and used definitions never disappear silently. |
| frontend/src/admin/automation/AutomationEditor.tsx | AutomationEditor: focused form view with explicit typed inputs and callbacks. |
| frontend/src/admin/automation/AutomationView.tsx | Typed merchant rule/campaign/flow/channel forms with exact JSON available for advanced review. |
| frontend/src/admin/automation/CustomFieldCondition.tsx | Typed custom field conditions support text, numeric, Boolean and date values using original field payload names. |
| frontend/src/admin/automation/FlowActionFields.tsx | Focused source action forms expose only supported native parameters; app service dispatch stays in the app gateway. |
| frontend/src/admin/automation/FlowBuilder.tsx | Graphical event → condition tree → action pipeline, including installed app actions. |
| frontend/src/admin/automation/FlowCanvas.tsx | Branching flow canvas edits the actual server graph, including true/false edges, reusable actions and durable delays. |
| frontend/src/admin/automation/FlowExecution.tsx | Actual persisted execution traces show branch decisions, confirmed steps and the scheduled continuation. |
| frontend/src/admin/automation/FlowInputs.tsx | Schema-derived flow parameters; runtime-bound event fields are intentionally supplied by the server. |
| frontend/src/admin/automation/FlowTopology.tsx | Readable connected overview of the persisted graph; selecting a node opens its matching editor card. |
| frontend/src/admin/automation/JsonField.tsx | JSON editing retains incomplete input and invalidates the actual payload instead of silently saving the last valid value. |
| frontend/src/admin/automation/PromotionSchedule.tsx | Campaign scheduling uses ISO instants in the API and local times in the editor. |
| frontend/src/admin/automation/RuleBuilder.tsx | Visual recursive rule tree: AND/OR/NOT groups, typed facts and editable leaf conditions. |
| frontend/src/admin/automation/SourceRuleFields.tsx | Original metadata drives typed condition inputs, including nested source scopes; unsupported runtimes stay visibly disabled. |
| frontend/src/admin/automation/automation-types.ts | Automation editor contracts; content languages come from the selected shop. |
| frontend/src/admin/automation/lifecycle-i18n.ts | Shared lifecycle, starting-process and dependency vocabulary for every automation editor. |
| frontend/src/admin/automation/pipeline-types.ts | Stable graph data mirrors the Rust pipeline contract, with explicit true/false edges and persistent node identifiers. |
| frontend/src/admin/automation/source-rules.ts | Convert source condition nodes for the graphical editor without losing original payload fields. |
| frontend/src/admin/catalog/AiImageStudio.tsx | Optional image-provider jobs create private previews; applying a reviewed image is explicit and revision checked. |
| frontend/src/admin/catalog/CategoriesWorkspace.tsx | Localized category tree editor; parent moves and revisions are validated in the API. |
| frontend/src/admin/catalog/CategoryFactQuery.tsx | One saved predicate on current public evidence; reuses category CAS and the editor's selected content language. |
| frontend/src/admin/catalog/MediaDropzone.tsx | Accessible multi-file upload with drag/drop, visible progress and the same validated asset API as attachments. |
| frontend/src/admin/catalog/PairFields.tsx | Accessible key/value rows for product properties, specifications and variant options. |
| frontend/src/admin/catalog/ProductAssets.tsx | Bounded upload and explicit digest-bound publication of attachments and paid files. |
| frontend/src/admin/catalog/ProductCurrencyPrices.tsx | Exact per-currency decimals live in the same revisioned product draft, including variants. |
| frontend/src/admin/catalog/ProductDataView.tsx | Central catalog workspace: server-filtered cursor list, product details and hierarchical categories. |
| frontend/src/admin/catalog/ProductEditor.tsx | Revision-aware product aggregate editor: one save, translation tabs and product-scoped linked capabilities. |
| frontend/src/admin/catalog/ProductEditorExtras.tsx | Price-tax selection and permission-filtered extension slots attached to the product editor. |
| frontend/src/admin/catalog/ProductEditorNav.tsx | Core product tabs and installed app submenus share one accessible navigation. |
| frontend/src/admin/catalog/ProductLocalizedContent.tsx | Consistent main-language inheritance for product rich documents, specification groups and individual SEO fields. |
| frontend/src/admin/catalog/ProductMediaWorkspace.tsx | One product-media workspace: cover, ordered gallery, multilingual image metadata, drag/drop and optional reviewed AI drafts. |
| frontend/src/admin/catalog/ProductPanels.tsx | Native commerce, media, translated SEO/specifications and category panels for one editable product. |
| frontend/src/admin/catalog/ProductTextFields.tsx | Product text uses the shared single-language editor and field inheritance; product number stays language independent. |
| frontend/src/admin/catalog/ProductVariants.tsx | Native variant family browser with cursor pagination, explicit editing and a bounded creation wizard. |
| frontend/src/admin/catalog/ReferencePriceFields.tsx | Native reference-unit inputs feed the same server-calculated unit price displayed on product pages. |
| frontend/src/admin/catalog/RelatedProducts.tsx | Search-backed related-product selection, avoiding comma-separated opaque IDs. |
| frontend/src/admin/catalog/ReviewModeration.tsx | Product-scoped review publication; authoritative authorization stays in the API. |
| frontend/src/admin/catalog/TaxClassSelect.tsx | Assign a product to an actual tenant tax class; legacy standard/reduced mapping remains explicit. |
| frontend/src/admin/catalog/VariantGenerator.tsx | Reviewable, bounded batch creation uses saved parent data and keeps successful rows on partial failure. |
| frontend/src/admin/catalog/catalog-model.ts | Editable native product aggregate and defaults shared by creation, detail and variant workflows. |
| frontend/src/admin/catalog/media-model.ts | Pure gallery operations preserve order, explicit alt translations and upload bounds without fabricating language values. |
| frontend/src/admin/catalog/variant-family.ts | Cursor-based family lookup for duplicate review, bounded independently of the 50-row creation limit. |
| frontend/src/admin/catalog/variant-i18n.ts | Guided variant creation and editing vocabulary; content still follows shop language inheritance. |
| frontend/src/admin/catalog/variant-model.ts | Bounded option combinations and metadata-free child payloads shared by the guided variant creator. |
| frontend/src/admin/channels/ChannelActions.tsx | Lifecycle actions use shared dependency deletion and one-use preview admission. |
| frontend/src/admin/channels/ChannelCatalog.tsx | Catalog/language controls share the channel schema and content-language fallback. |
| frontend/src/admin/channels/ChannelConnections.tsx | Uses the existing tenant-owned frontend registry, not a parallel domain or Experience store. |
| frontend/src/admin/channels/ChannelEditor.tsx | Guided channel creation/editing reuses the native revisioned API and shared content-language inheritance. |
| frontend/src/admin/channels/ChannelProducts.tsx | Search-based channel product assignment, preserving selected IDs across server-filtered result pages. |
| frontend/src/admin/channels/ChannelSettings.tsx | Channel settings embed existing revision-aware identity and checkout editors with the channel selected. |
| frontend/src/admin/channels/SalesChannelsWorkspace.tsx | Discover and create channels separately from rules; shared settings and independent SaaS shops remain explicit. |
| frontend/src/admin/channels/channel-i18n.ts | Sales-channel onboarding and inherited settings vocabulary in all interface languages. |
| frontend/src/admin/channels/channel-model.ts | Existing sales-channel contract and safe storefront URLs; independent tenants remain a separate concept. |
| frontend/src/admin/channels/connection-i18n.ts | Domain lifecycle copy in every supported Studio language. |
| frontend/src/admin/customers/CustomersManager.tsx | CRM list and editable customer profile with linked order history. |
| frontend/src/admin/customers/GuestContact.tsx | Read-only checkout snapshots distinguish guest contacts from authenticated customer accounts. |
| frontend/src/admin/dashboard/OverviewView.tsx | OverviewView renders verified shop state and typed user actions. |
| frontend/src/admin/developer/AppActionAccess.tsx | Team permissions and MCP visibility are independent from public storefront reads and AI grounding. |
| frontend/src/admin/developer/AppAgentPanel.tsx | Coding agents receive the current Manifest IR and authoritative schema; imported edits round-trip to the canvas. |
| frontend/src/admin/developer/AppAssistant.tsx | Guided app kinds create normal editable manifests; all changes follow private-stage versioning. |
| frontend/src/admin/developer/AppAutomation.tsx | Editable triggers are declared alongside UI and actions; secrets remain operator-managed. |
| frontend/src/admin/developer/AppCanvas.tsx | Accessible click-to-add canvas with selectable blocks and keyboard-accessible ordering controls. |
| frontend/src/admin/developer/AppCodeBuffer.ts | Invalid local expressions block apply and mode changes until corrected; multiple editors report independently. |
| frontend/src/admin/developer/AppConnections.tsx | Route, tool, grounding and Flow Builder switches modify the shared executable manifest directly. |
| frontend/src/admin/developer/AppContextBinding.tsx | Native UI bindings connect the open host object to an indexed app field, never to a global JS context. |
| frontend/src/admin/developer/AppControlProperties.tsx | DataField and one-level container references are edited against the current typed model rather than free text. |
| frontend/src/admin/developer/AppDataEditor.tsx | Managed app models expose typed fields and opt-in public reads; removal cleans dependent bindings. |
| frontend/src/admin/developer/AppEditorNavigation.tsx | Consistent navigation between visual definitions, provider contracts and immutable versions. |
| frontend/src/admin/developer/AppEvents.tsx | Edits the validated subscription/filter/batch contract; delivery uses the existing leased outbox. |
| frontend/src/admin/developer/AppExpressionEditor.tsx | Expressions use typed source text and known form/control references, with a separate JSON editor for agent object ASTs. |
| frontend/src/admin/developer/AppFieldOptions.tsx | Core references and typed choice fields remain owned app data with a single content-language editor. |
| frontend/src/admin/developer/AppGeometry.tsx | F4 presentation properties use one content language; layout values remain bounded grid units. |
| frontend/src/admin/developer/AppGridCanvas.tsx | Drag/drop, snapping, resize and multi-selection share the published app geometry contract. |
| frontend/src/admin/developer/AppInspector.tsx | One content language edits app/view/block metadata; changing bindings updates the actual manifest. |
| frontend/src/admin/developer/AppInstructionEditor.tsx | Block instructions expose schema-aware targets; nested branches are edited recursively under the server's bounded AST contract. |
| frontend/src/admin/developer/AppLibrary.tsx | Saved app cards with explicit editing and recoverable project removal, independent of installed package/data lifecycle. |
| frontend/src/admin/developer/AppLogicEditor.tsx | A code-behind dialog edits one AST through visual blocks, BASIC syntax or agent JSON, then returns it to the manifest compiler. |
| frontend/src/admin/developer/AppMenuEditor.tsx | Menu and injection sites are the existing surfaces, with explicit action allowlists and live role scopes. |
| frontend/src/admin/developer/AppModelDiagram.tsx | Relationships use the same typed field.references contract as the form editor; no separate diagram state or database model. |
| frontend/src/admin/developer/AppModules.tsx | Pure server modules edit the same WIT component contract consumed by quotes and checkout; no browser eval or live service code. |
| frontend/src/admin/developer/AppOntology.tsx | Optional graph mappings edit the canonical manifest; native authorized record lists own the projection. |
| frontend/src/admin/developer/AppPayments.tsx | Visual payment contracts use the same manifest as coding agents; onboarding uses the protected API. |
| frontend/src/admin/developer/AppSchemaMigrations.tsx | Migration plans are explicit versioned agent-readable data, validated by the shared server compiler before any DDL. |
| frontend/src/admin/developer/AppStudioStatus.tsx | Shared status footer keeps validation, persistence and execution feedback beside the designer. |
| frontend/src/admin/developer/AppVersions.tsx | Saved version inspection, digest-approved stage install and conflict-aware package-only live release. |
| frontend/src/admin/developer/AppViewTabs.tsx | Native view navigation and creation are separate from workspace orchestration. |
| frontend/src/admin/developer/DeveloperView.tsx | Visual App Studio orchestrates modular editors over the same executable schema used by coding agents. |
| frontend/src/admin/developer/DeveloperWorkspace.tsx | Dedicated app and API workspaces retain App Studio state while switching the developer console. |
| frontend/src/admin/developer/SandboxContextPicker.tsx | Bounded server search selects an owned object for testing editor-bound apps in a private sandbox. |
| frontend/src/admin/developer/SandboxPreview.tsx | Preview resolves the installed registry first; a newer staged package cannot masquerade as an older build. |
| frontend/src/admin/developer/api/ApiExplorer.tsx | Source-derived static route explorer, runtime app discovery and isolated same-origin read tests. |
| frontend/src/admin/developer/api/IntegrationKeys.tsx | Personal, expiring, least-privilege integration keys; plaintext stays in component memory and is never reloaded. |
| frontend/src/admin/developer/api/api-i18n.ts | Four-language developer API console vocabulary; no credentials are persisted in UI storage. |
| frontend/src/admin/developer/app-model.ts | Pure schema edits preserve unsupported extension properties; compilation binds native UI to real actions. |
| frontend/src/admin/developer/app-validation.ts | Draft validation surfaces bounded manifest errors; authoritative installation remains in Rust. |
| frontend/src/admin/developer/asset-actions.ts | Native asset editors use the existing asset owner; generated actions remain explicit capabilities in the package. |
| frontend/src/admin/developer/assistant-model.ts | Assistants compile to the public manifest contract, with no hidden runtime or provider code. |
| frontend/src/admin/developer/basic-code.ts | Small BASIC-style surface syntax compiles into the same bounded AST as visual and agent edits; no JavaScript execution. |
| frontend/src/admin/developer/control-model.ts | Pure control construction and bounded code-behind discovery keep visual edits and agent manifests identical. |
| frontend/src/admin/developer/model-workspace.ts | Form wizard emits the standard manifest IR; the ordinary compiler supplies all actions, APIs and permission allowlists. |
| frontend/src/admin/developer/useAppPreview.ts | F5/hot reload uses the existing native runtime in an actor-private staging environment, never an immutable build. |
| frontend/src/admin/developer/useAppStudio.ts | Tenant-scoped build lifecycle; immutable saved snapshots gate sandbox previews and selected app-only releases. |
| frontend/src/admin/developer/useDesignerKeys.ts | Designer keyboard shortcuts leave native input and rich-editor undo behavior intact. |
| frontend/src/admin/developer/useDraftStorage.ts | Actor-private server autosaves serialize writes and preserve optimistic revisions across app switches. |
| frontend/src/admin/environments/EnvironmentManager.tsx | Private environment creation and digest-bound selective release. |
| frontend/src/admin/intelligence/EvidenceReview.tsx | Review source-bound candidates through shared HTTP/MCP contracts; changed sources block publication. |
| frontend/src/admin/intelligence/ExperimentStudio.tsx | Immutable experiment designs and lifecycle controls share the core HTTP/MCP owner and current settings rights. |
| frontend/src/admin/intelligence/ExternalKnowledge.tsx | Private connected-app evidence browser shows active-source provenance without exposing it to shoppers. |
| frontend/src/admin/intelligence/GuardrailSettings.tsx | Merchant AI boundaries edit the canonical revisioned commerce settings, never a second policy store. |
| frontend/src/admin/intelligence/KnowledgeExplorer.tsx | Product-centred evidence inspector reads canonical facts and graph relationships beyond overview sampling. |
| frontend/src/admin/intelligence/KnowledgeFacts.tsx | Canonical catalogue facts shown alongside graph evidence; prices and inventory come from current product state. |
| frontend/src/admin/intelligence/KnowledgeOverview.tsx | Whole-shop knowledge census, operational next steps and provenance activity; examples never masquerade as learned facts. |
| frontend/src/admin/intelligence/KnowledgePreview.tsx | No-model evidence preview makes customer/private retrieval boundaries and missing facts inspectable. |
| frontend/src/admin/intelligence/KnowledgeSources.tsx | Searchable cursor source library, guarded lifecycle decisions and single-language source editing. |
| frontend/src/admin/intelligence/KnowledgeView.tsx | Unified knowledge workspace connects sources, product evidence, observations and no-model retrieval previews. |
| frontend/src/admin/intelligence/MemoryView.tsx | Durable co-purchase evidence and revision-bound merchant decisions, with simulation labels and explicit confirmation. |
| frontend/src/admin/intelligence/SourceEditor.tsx | Single-language source editor with inherited fields, product lookup and private-first API/file ingestion. |
| frontend/src/admin/intelligence/knowledge-types.ts | Typed knowledge read models preserve source ownership, revisions, sampling and privacy boundaries. |
| frontend/src/admin/legal/ConsumerRequests.tsx | Permission-scoped consumer request queue and optimistic, recorded review actions. |
| frontend/src/admin/legal/LegalServices.tsx | Purpose inventory and provider disclosures edited in the selected content language. |
| frontend/src/admin/legal/LegalSettings.tsx | Central revisioned legal workspace, inherited channel settings, source-backed sector guidance and request review. |
| frontend/src/admin/legal/ProductCompliance.tsx | Product-owned multilingual regulatory facts; collected evidence never claims automatic product certification. |
| frontend/src/admin/orders/OrderDetail.tsx | Order workspace: server actions, exact-once commands, provider progress and visible event history. |
| frontend/src/admin/orders/OrderPaymentDelivery.tsx | Payment jobs are observed until confirmation. Delivery actions share the server state machine. |
| frontend/src/admin/orders/OrderWorkflow.tsx | Server-owned transitions: one source for permitted actions, labels and business guards. |
| frontend/src/admin/orders/OrdersManager.tsx | Order operations UI. All changes call the same domain endpoints exposed through MCP. |
| frontend/src/admin/orders/ReceiptPanel.tsx | Seller configuration and version-bound receipt creation/download. |
| frontend/src/admin/preview/PreviewDialog.tsx | PreviewDialog keeps merchant interaction separate from workspace orchestration. |
| frontend/src/admin/preview/PreviewPanel.tsx | PreviewPanel renders verified shop state and typed user actions. |
| frontend/src/admin/settings/CommerceSettings.tsx | One revisioned international settings aggregate: drafts survive navigation between countries, taxes, methods and languages. |
| frontend/src/admin/settings/CompanyField.tsx | One factual field with visible channel inheritance, an explicit reset and searchable geographic selection. |
| frontend/src/admin/settings/CompanyLogo.tsx | Private logo preview and bounded upload; attaching/removing is a draft change until the profile is saved. |
| frontend/src/admin/settings/CompanyTranslations.tsx | Brand and legal text use one content-language selector and independent language/channel inheritance. |
| frontend/src/admin/settings/CountriesSettings.tsx | Delivery-country selection and editable catalogue definitions, including tenant-owned subdivisions. |
| frontend/src/admin/settings/CountryDefinition.tsx | Country metadata and subdivision editing with multilingual names; custom definitions cannot invent ISO assignment. |
| frontend/src/admin/settings/CurrencySettings.tsx | Shop currency registry and inherited channel availability. Actions use saved revisions and native job APIs. |
| frontend/src/admin/settings/CustomerGroupsSettings.tsx | Customer groups share the translation/inheritance editor and revisioned settings aggregate. |
| frontend/src/admin/settings/DestinationRuleEditor.tsx | Geographical tax rule editor: country, subdivisions, postcode constraints, date window and persisted Rule Builder condition. |
| frontend/src/admin/settings/LanguageSettings.tsx | Shop main language and enabled locales with resumable provider-backed bulk product translation drafts. |
| frontend/src/admin/settings/MasterDataSettings.tsx | Structured company profile with single-language content, inherited channel scopes, logo drafts and revision-bound saves. |
| frontend/src/admin/settings/MethodRemoval.tsx | Dependency preflight is advisory; aggregate save repeats it under the checkout configuration lock. |
| frontend/src/admin/settings/MethodSettings.tsx | Master/detail shipping and payment configuration, translated content and searchable country availability. |
| frontend/src/admin/settings/SettingsSaveBar.tsx | Consistent settings save feedback, dirty state and permission-aware controls. |
| frontend/src/admin/settings/SettingsWorkspace.tsx | Independent settings workspace: grouped navigation, explicit dirty-draft guards and native API forms. |
| frontend/src/admin/settings/TaxSettings.tsx | Editable tax classes and explicit fallback/country rates with destination rules using native Rule Builder references. |
| frontend/src/admin/settings/TranslationJobs.tsx | Start catalogue translations, poll durable progress, review paginated drafts and apply bounded revision-checked batches. |
| frontend/src/admin/settings/company-types.ts | Typed company metadata and sparse per-channel inheritance contract; statutory facts are never auto-translated. |
| frontend/src/admin/settings/useCompanyContext.ts | Load enabled content languages, countries and channel choices without overwriting an edited draft on locale refresh. |
| frontend/src/admin/settings/useSettingsDraft.ts | Revisioned settings drafts survive locale refreshes, reject late loads and keep failed saves editable. |
| frontend/src/admin/shell/Merchant.tsx | Studio composition root: layout, scoped controller and modular workspace views. |
| frontend/src/admin/shell/StudioComposer.tsx | StudioComposer: focused Studio view; state and commands come from the session-scoped controller. |
| frontend/src/admin/shell/StudioContext.ts | Typed, local Studio context; never shared across a different mounted Studio. |
| frontend/src/admin/shell/StudioConversation.tsx | StudioConversation: focused Studio view; state and commands come from the session-scoped controller. |
| frontend/src/admin/shell/StudioHeader.tsx | StudioHeader: focused Studio view; state and commands come from the session-scoped controller. |
| frontend/src/admin/shell/StudioRoutes.tsx | StudioRoutes: focused Studio view; state and commands come from the session-scoped controller. |
| frontend/src/admin/shell/StudioSidebar.tsx | StudioSidebar: focused Studio view; state and commands come from the session-scoped controller. |
| frontend/src/admin/shell/StudioSignIn.tsx | Dedicated login page and blocking reauthentication dialog preserve mounted private editors. |
| frontend/src/admin/shell/navigation.ts | Typed built-in Studio navigation and locale-specific labels. |
| frontend/src/admin/shell/requests.ts | Authenticated Studio transport; staging changes only the tenant, never the principal. |
| frontend/src/admin/shell/studio-types.ts | studio types: Studio layout, session/workspace controller, authenticated transport and lazy workspace navigation. |
| frontend/src/admin/shell/useEntityNavigation.ts | Linked entity navigation keeps native editors, browser deep links and back paths in the same tenant scope. |
| frontend/src/admin/shell/useServerHealth.ts | Public server health is independent of the personal Studio session. |
| frontend/src/admin/shell/useStudioAccess.ts | Central Studio identity boundary: initial login, expiry suspension and same-account resume. |
| frontend/src/admin/shell/useStudioController.ts | Studio session/controller: authentication context, tenant/staging state and chat commands. |
| frontend/src/admin/shell/useStudioSession.ts | Revalidate visible Studio sessions and route authenticated failures to the active controller. |
| frontend/src/admin/storyfronts/StoryfrontConnections.tsx | Shared passive navigation from Apps and Storyfronts to the same authorized original editor. |
| frontend/src/admin/storyfronts/StoryfrontView.tsx | Discover the actual tenant-bound hosted frontends; keep the optional legacy app connector separate. |
| frontend/src/admin/storyfronts/storyfront-i18n.ts | Four-language navigation copy; mounted frontends are connections, not proof of publication. |
| frontend/src/admin/storyfronts/storyfront-model.ts | Passive operator URLs contain no browser credential; the destination editor authorizes its own owner. |
| frontend/src/admin/styles/api-console.css | Responsive developer key management and bounded API explorer using Studio theme tokens. |
| frontend/src/admin/styles/app-artwork.css | Category cover and app icon artwork, with local deterministic fallbacks. |
| frontend/src/admin/styles/app-assistant.css | Guided extension workspace: restrained colour, clear choices and responsive setup. |
| frontend/src/admin/styles/app-catalog.css | App library/detail presentation: bounded cards, passive artwork, accessible filters and theme-aware forms. |
| frontend/src/admin/styles/app-detail.css | Scoped app detail hierarchy, permission disclosure, data and integration forms. |
| frontend/src/admin/styles/app-library.css | App callback consent follows the same card and field rhythm as app configuration. |
| frontend/src/admin/styles/app-studio-inspector.css | App Studio binding indicators, empty canvas and properties inspector. |
| frontend/src/admin/styles/app-studio-panels.css | App Studio model, connection, agent and version panels. |
| frontend/src/admin/styles/app-studio-responsive.css | Responsive App Studio layouts and reduced-motion settings. |
| frontend/src/admin/styles/app-studio.css | App Studio: restrained light canvas, compact control density and responsive palette/inspector workspaces. |
| frontend/src/admin/styles/automation-lifecycle.css | Configuration workspace: readable definitions, clear selection and contextual actions. |
| frontend/src/admin/styles/automation.css | Actual graph nodes and original rule forms use the Studio theme and independent responsive columns. |
| frontend/src/admin/styles/catalog-editor.css | Visual editor and category workspace responsive styles. |
| frontend/src/admin/styles/catalog.css | Light, precise catalog workspace with accessible tables, focused detail panels and visual authoring. |
| frontend/src/admin/styles/commerce-manager.css | commerce manager: Studio visual system and merchant operational layouts. |
| frontend/src/admin/styles/company-settings.css | Company editor: structured addresses, visible scope inheritance and compact upload controls. |
| frontend/src/admin/styles/forms.css | Studio-owned form primitives load at the composition root, independent of lazy workspace history. |
| frontend/src/admin/styles/international-details.css | Destination rates, translation jobs and responsive international workbench layout. |
| frontend/src/admin/styles/international.css | International commerce workbench: compact master/detail records, calm colour and clear field hierarchy. |
| frontend/src/admin/styles/knowledge-evidence.css | Product evidence, retrieval excerpts, observed pairs and responsive knowledge layouts. |
| frontend/src/admin/styles/knowledge-sources.css | Knowledge source library/editor layouts: single-language forms and lifecycle controls. |
| frontend/src/admin/styles/knowledge.css | Unified knowledge workspace: evidence-first hierarchy, accessible cards and theme-aware responsive layouts. |
| frontend/src/admin/styles/legal-settings.css | Light legal workspace: compact readiness, sector chips, linked sources and single-language editors. |
| frontend/src/admin/styles/media-workspace.css | Gallery workspace: airy tiles, focused image inspector and accessible upload surfaces using Studio theme tokens. |
| frontend/src/admin/styles/operations.css | Operational screens share the studio's light surface and clear focus states. |
| frontend/src/admin/styles/provider-account.css | Shared provider onboarding layout works independently of the lazy-loaded visual App Studio. |
| frontend/src/admin/styles/sales-channels.css | Sales-channel cards, onboarding and scoped settings use the same responsive, accessible Studio design. |
| frontend/src/admin/styles/settings.css | Independent settings navigation, grouped native forms and save feedback in Studio theme tokens. |
| frontend/src/admin/styles/storyfronts.css | Tenant-bound Experience cards share Studio tokens and keep long hostnames inside mobile columns. |
| frontend/src/admin/styles/studio/01-studio.css | studio: studio styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/02-workspace-switch.css | studio: workspace-switch styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/03-welcome-symbol.css | studio: welcome-symbol styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/04-review-product-div.css | studio: review-product-div styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/05-page-intro-p.css | studio: page-intro-p styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/06-knowledge-stats-strong.css | studio: knowledge-stats-strong styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/07-connection-card.css | studio: connection-card styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/08-responsive.css | studio: responsive styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/09-responsive.css | studio: responsive styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio/10-studio-mobile-preview-button.css | studio: studio-mobile-preview-button styles. Source order is preserved by the entry stylesheet. |
| frontend/src/admin/styles/studio-sign-in.css | Dedicated access surface: responsive Vendune login and native modal reauthentication. |
| frontend/src/admin/styles/studio.css | Ordered studio stylesheet entry; domain rules live in the adjacent folder. |
| frontend/src/admin/styles/variants.css | Variant family and review table share the catalog's responsive theme and focus treatment. |
| frontend/src/admin/styles/workspace-copilot.css | Contextual assistant drawer inherits Studio tokens and contains the existing conversation on all viewport sizes. |
| frontend/src/admin/styles/workspace-polish.css | Consistent Studio density, readable hierarchy and independently scrollable navigation across workspaces. |
| frontend/src/admin/team/AccessManager.tsx | Fine-grained team overrides, revocable invitations and personal session inventory. |
| frontend/src/admin/team/PersonalAccountForm.tsx | PersonalAccountForm: focused account-form view with explicit typed inputs and callbacks. |
| frontend/src/admin/team/UsersManager.tsx | Users Manager: Personal accounts, memberships, roles, invitations and scoped developer access.. |
| frontend/src/application/ApplicationRouter.tsx | Select independent lazy applications; contain failed imports and reset boundaries on navigation. |
| frontend/src/main.tsx | Browser bootstrap only; application selection and error recovery live in application/. |
| frontend/src/platform/AdminHub.tsx | Public service directory. Links select a login surface without granting operator or merchant permissions. |
| frontend/src/platform/HTTPResponses.tsx | Exact HTTP outcomes; historical undifferentiated totals never become fabricated success rates. |
| frontend/src/platform/PlatformAI.tsx | Central inference editor; write-only secrets, optimistic revisions and explicit environment fallback. |
| frontend/src/platform/PlatformConsole.tsx | Independent platform control plane: personal operator access, bounded statistics and audited shop creation. |
| frontend/src/platform/PlatformDashboard.tsx | Aggregate statistics from PostgreSQL; recorded orders and confirmed money remain visibly separate. |
| frontend/src/platform/PlatformInfrastructure.tsx | Real infrastructure probes, bounded lifetime traffic and process-local resource counters. |
| frontend/src/platform/PlatformLanguage.tsx | Locale selector shared by operator sign-in and the workspace. |
| frontend/src/platform/PlatformShopDetail.tsx | Connected shop dossier and reversible lifecycle controls; confirmations are explicit and revision guarded. |
| frontend/src/platform/PlatformShops.tsx | Searchable shop directory and server-validated provisioning form. |
| frontend/src/platform/PlatformSignIn.tsx | Personal sign-in verifies the current operator grant before retaining a browser session. |
| frontend/src/platform/platform-api.ts | Tenant-independent operator API; credentials stay in the current browser session. |
| frontend/src/platform/styles/platform/01-platform-console.css | platform: platform-console styles. Source order is preserved by the entry stylesheet. |
| frontend/src/platform/styles/platform/02-platform-shop-stats-span.css | platform: platform-shop-stats-span styles. Source order is preserved by the entry stylesheet. |
| frontend/src/platform/styles/platform/03-control.css | Service hub and operational editors share the same accessible light workspace. |
| frontend/src/platform/styles/platform.css | Ordered platform stylesheet entry; domain rules live in the adjacent folder. |
| frontend/src/shared/api/agent-stream.ts | Decode bounded UTF-8 SSE chat frames; only a completed native result reaches the existing Studio state owner. |
| frontend/src/shared/api/download.ts | Authenticated binary download, never placing session credentials in a URL. |
| frontend/src/shared/api/merchant-session.ts | Private merchant-session rejection signals shared by all JSON transports. |
| frontend/src/shared/api/request-json.ts | Coalesce simultaneous identical core reads with complete identity; no persisted response cache. |
| frontend/src/shared/api/shop-api.ts | shop api: Typed commerce contracts, merchant/store transports and binary download helper. |
| frontend/src/shared/api/shop-scope.ts | Canonical shop hosts; Studio identity remains on the shared origin. Reserved service hosts never become tenant IDs. |
| frontend/src/shared/api/types.ts | Common JSON/multipart request contract for app surfaces and merchant operations. |
| frontend/src/shared/apps/AppFrame.tsx | Opaque-origin app UI. Its SDK can invoke only this app's declared, server-authorized actions. |
| frontend/src/shared/apps/AppSlot.tsx | Generic registered product configuration slot. App packages own labels, input names and business rules. |
| frontend/src/shared/apps/AppSurfaces.tsx | One registry read per workspace; app bundles load only when their surface is mounted. |
| frontend/src/shared/apps/native/NativeAppView.tsx | The same React renderer powers design preview, private sandbox, released admin modules and storefront surfaces. |
| frontend/src/shared/apps/native/NativeAssetField.tsx | Searchable tenant-owned files with private image preview and contextual multipart upload; no raw asset IDs need to be typed. |
| frontend/src/shared/apps/native/NativeBlocks.tsx | All native controls render from the same validated manifest, including one-level containers and code-behind buttons. |
| frontend/src/shared/apps/native/NativeControl.tsx | Typed VB-style controls read app records; edits stay local until an explicitly bound gateway action runs. |
| frontend/src/shared/apps/native/NativeDataBlock.tsx | One bounded keyset page per mounted data block; action requests remain tenant- and permission-scoped. |
| frontend/src/shared/apps/native/NativeField.tsx | One typed field editor for native forms; rich text uses the product editor and configured language inheritance. |
| frontend/src/shared/apps/native/NativeRecordForm.tsx | Native managed-record form retains revisions and inherited translations; it never executes schema code. |
| frontend/src/shared/apps/native/NativeRelationField.tsx | Related records load only through actions already granted to the current surface; no merchant-token side route. |
| frontend/src/shared/apps/native/NativeRuntime.tsx | Native controls share one local execution context; form records and gateway calls remain scoped by their existing owners. |
| frontend/src/shared/apps/native/geometry.ts | The twelve-column layout is the same manifest geometry for the designer and published renderer. |
| frontend/src/shared/apps/native/logic.ts | Bounded AST interpreter; no eval, globals, arbitrary URLs or implicit gateway permissions. |
| frontend/src/shared/apps/native/types.ts | The versioned Manifest is the shared intermediate representation for visual and agent edits. |
| frontend/src/shared/apps/useSurfaceGateway.ts | Bind native and isolated UI actions to the same short-lived server grant; credentials stay in the host. |
| frontend/src/shared/content/RichDescription.tsx | Safe rich blocks with native image/video rendering; no HTML interpretation or script execution. |
| frontend/src/shared/content/editor/EditorBuffer.ts | Unsaved Markdown source participates in the aggregate's save/navigation guard without becoming product content. |
| frontend/src/shared/content/editor/MarkdownSource.tsx | Live Markdown buffer updates the same structured product document; no raw HTML is rendered or persisted. |
| frontend/src/shared/content/editor/RichEditor.tsx | Actual Tiptap WYSIWYG editor with structured safe content, media, formatting and per-language drafts. |
| frontend/src/shared/content/editor/editor-document.ts | Canonical transport drops editor-only null attributes; description headings remain within the native H2/H3 contract. |
| frontend/src/shared/content/editor/editor-i18n.ts | Four-language controls for visual/Markdown editing without changing content-language inheritance. |
| frontend/src/shared/content/editor/markdown-content.ts | Markdown admission shares the public rich-document node/URL boundary; rich-only features never silently disappear. |
| frontend/src/shared/content/editor/rich-conversion.ts | Lossless import of legacy blocks into structured WYSIWYG content, preserving inline emphasis. |
| frontend/src/shared/content/rich-document.tsx | Safe structured editor rendering. Only known nodes/marks produce elements; URLs are never executable. |
| frontend/src/shared/customer/AddressBook.tsx | Tenant-owned address cards, defaults and revision-aware CRUD shared by account and CRM. |
| frontend/src/shared/customer/AddressCard.tsx | Human-readable address used in order snapshots and address books. |
| frontend/src/shared/customer/AddressFields.tsx | Structured accessible address editor; no hidden JSON or storefront-only duplicate model. |
| frontend/src/shared/customer/CustomerFields.tsx | Contact fields mirror the account API while access, identity and pricing remain separate. |
| frontend/src/shared/customer/GoogleAddressSearch.tsx | Opt-in Places widget fills editable address fields, rejects unsupported destinations and ignores stale replies. |
| frontend/src/shared/customer/customer-types.ts | Shared customer/address contracts; merchant and customer sessions use distinct request adapters. |
| frontend/src/shared/customer/google-address.ts | Google Places adapter: lazy public browser key, bounded loader and international address mapping. |
| frontend/src/shared/geography/CountryPicker.tsx | Locale-aware world catalogue adapter for the shared searchable entity picker. |
| frontend/src/shared/geography/EntityPicker.tsx | Accessible searchable country/region combobox; chips and group actions replace checkbox walls. |
| frontend/src/shared/geography/TranslationFields.tsx | Shared single-language fields for configurable object content; per-field null restores main-language inheritance. |
| frontend/src/shared/geography/geography-types.ts | World catalogue and tenant destination tax contracts; no inferred tax law. |
| frontend/src/shared/geography/geography.css | Shared country and region search: Studio and checkout use the same accessible controls. |
| frontend/src/shared/geography/useCountryCatalogue.ts | Request-scoped geography loading; stale requests cannot move country definitions across shops or sandboxes. |
| frontend/src/shared/history/EntityHistory.tsx | On-demand entity history, field comparisons and explicitly confirmed revision-checked restoration. |
| frontend/src/shared/history/history-model.ts | Bounded structural changes for database snapshots; no HTML from historical content is executed. |
| frontend/src/shared/history/history.css | Shared history deliberately stays secondary to editing and loads only when opened. |
| frontend/src/shared/i18n/ContentLanguage.tsx | One content-language selection per editor, distinct from interface language; no writes on selection or fallback. |
| frontend/src/shared/i18n/ContentLanguagePicker.tsx | Compact shared language switcher with explicit main-language context; selection never changes persisted content. |
| frontend/src/shared/i18n/LocalizedField.tsx | Single visible field for the editor's language, with main-language preview and explicit restore-to-inheritance. |
| frontend/src/shared/i18n/account-i18n.ts | Customer account vocabulary: one complete EN/DE/FR/ES contract for authentication and purchase care. |
| frontend/src/shared/i18n/app-access-i18n.ts | Explicit app callback consent and short-lived key management vocabulary. |
| frontend/src/shared/i18n/app-assistant-i18n.ts | App assistants and extension permissions use the same EN/DE/FR/ES vocabulary. |
| frontend/src/shared/i18n/app-events-i18n.ts | Subscription/filter/delivery vocabulary shared by Studio and coding agents. |
| frontend/src/shared/i18n/app-i18n.ts | App and evidence UI vocabulary, shared by store, merchant and payment components. |
| frontend/src/shared/i18n/app-library-i18n.ts | App library vocabulary and built-in summaries; no inferred connection or payment readiness. |
| frontend/src/shared/i18n/app-logic-i18n.ts | Designer controls, code-behind and debugger vocabulary ships in every bundled interface language. |
| frontend/src/shared/i18n/app-ontology-i18n.ts | Native app graph mapping controls share the Studio vocabulary and four interface languages. |
| frontend/src/shared/i18n/app-operations-i18n.ts | App operational vocabulary shared by installed apps and developer diagnostics; EN/DE/FR/ES. |
| frontend/src/shared/i18n/app-studio-i18n.ts | App Studio and native runtime vocabulary; every key ships EN/DE/FR/ES. |
| frontend/src/shared/i18n/automation-fields.ts | Localized labels for original rule and native flow parameter fields. |
| frontend/src/shared/i18n/automation-i18n.ts | Four-language automation editor vocabulary keeps source identifiers stable and user labels readable. |
| frontend/src/shared/i18n/automation-labels.ts | Source-named rule labels are localized independently from their stable integration identifiers. |
| frontend/src/shared/i18n/catalog-i18n.ts | Complete four-language catalog workspace vocabulary, separate from commerce data translations. |
| frontend/src/shared/i18n/checkout-i18n.ts | Checkout vocabulary: the same purchase and payment states in every supported UI language. |
| frontend/src/shared/i18n/cognitive-events-i18n.ts | Typed labels shared by the knowledge timeline and the native Flow Builder event catalogue. |
| frontend/src/shared/i18n/company-i18n.ts | Company identity, field inheritance and legal storefront vocabulary in four interface languages. |
| frontend/src/shared/i18n/connected-i18n.ts | Four-language vocabulary for connected apps, consent and visual automation. |
| frontend/src/shared/i18n/content-language.ts | Resolve editable translation keys without merging distinct regional locales or fabricating inherited values. |
| frontend/src/shared/i18n/control-i18n.ts | Complete vocabulary for the platform control plane and service hub. Technical provider/service IDs stay stable. |
| frontend/src/shared/i18n/crm-i18n.ts | Complete CRM/history vocabulary shared by settings, customer account and entity editors. |
| frontend/src/shared/i18n/currency-i18n.ts | Complete currency settings vocabulary, shared by storefront and channel editors. |
| frontend/src/shared/i18n/customer-i18n.ts | Account and address labels share four complete locales across storefront and studio. |
| frontend/src/shared/i18n/email-i18n.ts | Complete mail workspace vocabulary in English, German, French and Spanish. |
| frontend/src/shared/i18n/errors-i18n.ts | Localized request guidance across all transports; original diagnostics remain available to developer tools. |
| frontend/src/shared/i18n/experience-ui-i18n.ts | Shared four-language interaction vocabulary for contextual Studio help and storefront discovery. |
| frontend/src/shared/i18n/experiment-i18n.ts | Controlled-experiment vocabulary distinguishes observed cash from causal and margin claims. |
| frontend/src/shared/i18n/graph-navigation-i18n.ts | Saved fact navigation vocabulary; content terms use the editor's shared language inheritance. |
| frontend/src/shared/i18n/guardrail-i18n.ts | Typed four-language merchant AI policy vocabulary. |
| frontend/src/shared/i18n/i18n.tsx | i18n: Four-language locale context, UI dictionaries and translated API errors. |
| frontend/src/shared/i18n/international-i18n.ts | International settings vocabulary. Every key requires English, German, French and Spanish. |
| frontend/src/shared/i18n/knowledge-i18n.ts | Knowledge workspace vocabulary: sources, evidence and capabilities without fabricated learning claims. |
| frontend/src/shared/i18n/legal-i18n.ts | Complete EN/DE/FR/ES legal workspace and storefront vocabulary; documents use shop content languages. |
| frontend/src/shared/i18n/locales/de.ts | Merchant interface strings: de. |
| frontend/src/shared/i18n/locales/en.ts | Merchant interface strings: en. |
| frontend/src/shared/i18n/locales/es.ts | Merchant interface strings: es. |
| frontend/src/shared/i18n/locales/fr.ts | Merchant interface strings: fr. |
| frontend/src/shared/i18n/locales/shop-de.ts | Storefront and operational interface strings: de. |
| frontend/src/shared/i18n/locales/shop-en.ts | Storefront and operational interface strings: en. |
| frontend/src/shared/i18n/locales/shop-es.ts | Storefront and operational interface strings: es. |
| frontend/src/shared/i18n/locales/shop-fr.ts | Storefront and operational interface strings: fr. |
| frontend/src/shared/i18n/operations-i18n.ts | Operational commerce labels in all supported languages. |
| frontend/src/shared/i18n/payment-provider-i18n.ts | Payment contract editor and account onboarding vocabulary. |
| frontend/src/shared/i18n/platform-i18n.ts | Operator console translations. Every visible control has an explicit translation in all supported locales. |
| frontend/src/shared/i18n/preference-i18n.ts | Consent-bound private shopping-memory controls use typed interface text, separate from merchant product facts. |
| frontend/src/shared/i18n/product-legal-i18n.ts | Product safety and sector facts in EN/DE/FR/ES; values follow the shared content-language inheritance. |
| frontend/src/shared/i18n/shop-i18n.ts | Shared shop text hook; dictionaries live in focused locale files. |
| frontend/src/shared/i18n/studio-ui-i18n.ts | Studio navigation and settings guidance in all four supported interface languages. |
| frontend/src/shared/i18n/workbench-i18n.ts | Complete four-language vocabulary for environments, developer tools and knowledge ingestion. |
| frontend/src/shared/i18n/workspace-i18n.ts | Settings scopes, dependency confirmation and media workspace vocabulary in every supported interface language. |
| frontend/src/shared/legal/ExternalVideo.tsx | Optional external video is not contacted until the same shop privacy choice allows it. |
| frontend/src/shared/legal/consent-store.ts | Live consent registry starts denied; only validated server receipts unlock integrations. No legacy grant is trusted. |
| frontend/src/shared/legal/legal-types.ts | Channel-scoped legal policy, explicit optional purposes and durable consumer requests. |
| frontend/src/shared/legal/requirements.ts | Source-backed requirement catalogue; operational applicability is reviewed, never inferred as legal certification. |
| frontend/src/shared/money/fx-draft.ts | Draft-only FX preview matches the server rational/half-up boundary; checkout always uses its server quote. |
| frontend/src/shared/styles/app-surfaces.css | app surfaces: Shared customer, app and workbench styles; application workspaces must not import each other.. |
| frontend/src/shared/styles/apps.css | apps: Shared customer, app and workbench styles; application workspaces must not import each other.. |
| frontend/src/shared/styles/currencies.css | Currency cards use the Studio form grid, keyboard targets and responsive layouts. |
| frontend/src/shared/styles/customers.css | Shared light account/address workspace, responsive and keyboard-accessible. |
| frontend/src/shared/styles/markdown-editor.css | Shared visual/Markdown product editor treatment using existing Studio theme tokens. |
| frontend/src/shared/styles/native-app.css | Native app layouts share commerce design tokens; tables/forms remain bounded and responsive. |
| frontend/src/shared/styles/workbench.css | Merchant workbench uses the studio's light-blue design tokens and responsive review panels. |
| frontend/src/shared/ui/Brand.tsx | Shared Vendune identity; product branding is independent of tenant-owned company logos and session keys. |
| frontend/src/shared/ui/ConfirmDialog.tsx | Shared modal confirmation with focus containment, Escape, focus restoration and an explicit destructive action. |
| frontend/src/shared/ui/Icon.tsx | Icon: Presentational icons and catalogue artwork with explicit inputs.. |
| frontend/src/shared/ui/ProductArt.tsx | Product Art: Presentational icons and catalogue artwork with explicit inputs.. |
| frontend/src/shared/ui/WorkspaceBoundary.tsx | Contain a workspace render failure and let the user retry without losing the application shell. |
| frontend/src/shared/ui/brand.css | Shared vector brand sizing and typography for Studio and the operator console. |
| frontend/src/shared/ui/confirm-dialog.css | Modal surface shared by settings, media and future destructive actions. |
| frontend/src/storefront/account/AccountDownloads.tsx | Paid download entitlements are fetched by the server and retrieved with customer headers, never URL tokens. |
| frontend/src/storefront/account/AccountOrderDetail.tsx | Purchase detail uses immutable addresses, current fulfillment, issued PDFs and paid order entitlements. |
| frontend/src/storefront/account/AccountOrderList.tsx | Clickable purchase cards show the live server status and lead to a protected order detail. |
| frontend/src/storefront/account/AccountOverview.tsx | Account home connects recent purchases and default addresses to their dedicated management views. |
| frontend/src/storefront/account/AccountProfile.tsx | Focused profile and password forms report persistence and keep account identity outside editable contact data. |
| frontend/src/storefront/account/CustomerAccount.tsx | Responsive customer workspace separates authentication, address care and protected purchase details. |
| frontend/src/storefront/account/CustomerSignIn.tsx | Distinct sign-in and registration forms with correct autofill and an authenticated, rotated cart context. |
| frontend/src/storefront/account/ShoppingPreferences.tsx | Optional cart-private memory uses native consent, revisioned graph storage and explicit AI-sharing preference. |
| frontend/src/storefront/account/account-fields.css | Account form controls have explicit label spacing, consistent actions and shared address-editor integration. |
| frontend/src/storefront/account/account-polish.css | Brand-aware account presentation with a separate orientation panel and bounded, scrollable forms. |
| frontend/src/storefront/account/account-purchases.css | Purchase cards, fulfillment, documents and financial detail use one readable account layout. |
| frontend/src/storefront/account/account-types.ts | Shopper-only account responses deliberately exclude cart/session credentials and internal order activity. |
| frontend/src/storefront/account/account.css | Customer workspace: quiet fashion palette, clear purchase cards and an accessible mobile sheet. |
| frontend/src/storefront/account/useCustomerAccount.ts | Tenant-scoped account loading and mutation lifecycle; expired sessions clear private data and reopen sign-in. |
| frontend/src/storefront/analytics/ShopAnalytics.tsx | Customer consent and real GA4 ecommerce events; absent apps produce no external script. |
| frontend/src/storefront/catalog/ImagePlaceholder.tsx | Honest empty-media state for newly created products; never invent a product photograph. |
| frontend/src/storefront/catalog/MemoryRecommendations.tsx | Public consumer of merchant-approved learned associations, hydrated with current product state. |
| frontend/src/storefront/catalog/ProductAttachments.tsx | Public attachment list follows the active storefront tenant and channel; private downloads are never listed. |
| frontend/src/storefront/catalog/ProductPage.tsx | Product family, gallery, context pricing and moderated customer reviews. |
| frontend/src/storefront/catalog/ProductPurchase.tsx | ProductPurchase: focused pdp-purchase view with explicit typed inputs and callbacks. |
| frontend/src/storefront/catalog/ProductQuestion.tsx | Read-only product questions cite only tenant-owned, explicitly published source documents. |
| frontend/src/storefront/catalog/ProductReviews.tsx | ProductReviews: focused pdp-reviews view with explicit typed inputs and callbacks. |
| frontend/src/storefront/catalog/product-url.ts | Stable, collision-free product addresses: SKU identity plus the inherited localized SEO slug. |
| frontend/src/storefront/checkout/CheckoutDetails.tsx | Address book, guest contact and delivery/payment selection share the authoritative cart context API. |
| frontend/src/storefront/checkout/CheckoutIdentity.tsx | Inline guest/login/registration step rotates the cart on authentication and refreshes owning defaults. |
| frontend/src/storefront/checkout/CheckoutMethods.tsx | Method cards keep delivery and payment discoverable without concealing country restrictions. |
| frontend/src/storefront/checkout/CheckoutPanel.tsx | One-page checkout: server-reviewed selection, explicit purchase and durable provider handoff. |
| frontend/src/storefront/checkout/CheckoutProgress.tsx | Readable checkout progress reflects reviewed server state; it never implies payment confirmation. |
| frontend/src/storefront/checkout/CheckoutPurchase.tsx | Shared explicit purchase button: mobile dock and desktop review use the same form and server-review state. |
| frontend/src/storefront/checkout/CheckoutSummary.tsx | Sticky order review presents authoritative totals and discounts beside the purchase action. |
| frontend/src/storefront/checkout/EmbeddedPayment.tsx | A scoped provider frame receives a short-lived token; messages only trigger server reconciliation. |
| frontend/src/storefront/checkout/OrderCompletion.tsx | Dedicated completion page renders the accepted order snapshot and honest provider state, with no ID-only reads. |
| frontend/src/storefront/checkout/OrderConfetti.tsx | Finite CSS celebration after an accepted order; no timers, libraries or motion for reduced-motion users. |
| frontend/src/storefront/checkout/PaymentSession.tsx | Provider handoff and bounded durable-status polling; only verified server receipts confirm payment. |
| frontend/src/storefront/checkout/checkout-order.ts | Bind the purchase to the reviewed cart and total; the server remains the pricing authority. |
| frontend/src/storefront/checkout/embedded-checkout.ts | Only the registered embedding storefront receives the shopper cart receipt capability; it verifies with Core. |
| frontend/src/storefront/legal/CheckoutLegal.tsx | Current legal-document links and separate non-prechecked digital performance acknowledgement. |
| frontend/src/storefront/legal/ConsumerRequestForm.tsx | Public two-step declaration with immutable downloadable receipt; references never expose order data. |
| frontend/src/storefront/legal/LegalDocument.tsx | Published legal text uses selected content language/main-language inheritance; empty content is visible as missing. |
| frontend/src/storefront/legal/PrivacyProvider.tsx | Unified affirmative consent: server-validated receipt, channel boundaries, expiry and policy revalidation. |
| frontend/src/storefront/legal/ProductSafety.tsx | Explicit PDP safety/sector facts; no generated warning, certification or origin is invented. |
| frontend/src/storefront/shell/CatalogNavigation.tsx | Public category navigation uses the same tenant/channel tree as the listing API, with translated names. |
| frontend/src/storefront/shell/ChannelPreview.tsx | Explain the server-authorized, session-bound preview and clear its HttpOnly cookie on exit. |
| frontend/src/storefront/shell/CollectionView.tsx | CollectionView: storefront view composed from the scoped cart/controller. |
| frontend/src/storefront/shell/CompanyLegalPage.tsx | Directly reachable channel legal page; renders only the server's explicit public projection as text. |
| frontend/src/storefront/shell/ConciergeView.tsx | ConciergeView: storefront view composed from the scoped cart/controller. |
| frontend/src/storefront/shell/Storefront.tsx | Storefront composition root: cart context, routes, customer account and checkout. |
| frontend/src/storefront/shell/StorefrontContext.ts | Local storefront context, scoped to the mounted tenant and sales channel. |
| frontend/src/storefront/shell/StorefrontCurrency.tsx | Currency switching is a revision-bound server re-quote, scoped to tenant and sales channel. |
| frontend/src/storefront/shell/StorefrontHeader.tsx | StorefrontHeader: storefront view composed from the scoped cart/controller. |
| frontend/src/storefront/shell/StorefrontHome.tsx | StorefrontHome: storefront view composed from the scoped cart/controller. |
| frontend/src/storefront/shell/StorefrontLanguage.tsx | Shop-configured content languages, including custom locales; the interface keeps its supported language vocabulary. |
| frontend/src/storefront/shell/cart-commands.ts | Revision-bound quantity update, preserving SKU minimum and server pricing authority. |
| frontend/src/storefront/shell/channel-preview-i18n.ts | Personal preview copy in every supported language; exported through the shared translation catalogue. |
| frontend/src/storefront/shell/useCatalog.ts | Cursor catalogue loading, debounced filters and stale-response protection. |
| frontend/src/storefront/shell/useCompanyIdentity.ts | Channel-scoped public brand/legal identity; stale responses cannot leak across tenants or languages. |
| frontend/src/storefront/shell/useConsentedExperience.ts | Assign experiments only after current personalization consent; discard stale responses on withdrawal. |
| frontend/src/storefront/shell/usePersonalization.ts | Opt-in behavior signals and stable product ordering; no authoritative prices are changed. |
| frontend/src/storefront/shell/useStorefrontAnchors.ts | Restore native section navigation after SPA rendering, with cancellation and reduced-motion support. |
| frontend/src/storefront/shell/useStorefrontController.ts | Cart lifecycle, authoritative checkout commands and storefront coordination. |
| frontend/src/storefront/styles/checkout-fields.css | Checkout-owned form layout, independent of previously mounted account/admin stylesheets. |
| frontend/src/storefront/styles/checkout.css | One-page checkout: calm responsive workspace with a sticky, readable order review. |
| frontend/src/storefront/styles/company-identity.css | Public company branding and readable legal identity across storefront channels. |
| frontend/src/storefront/styles/experience-polish.css | Shared storefront interaction layer: stable navigation, editorial surfaces and catalogue-grounded AI discovery. |
| frontend/src/storefront/styles/legal.css | Responsive, equally weighted consent controls and readable legal/customer forms. |
| frontend/src/storefront/styles/order-completion.css | Order receipt page and finite transform-only celebration; honors reduced motion. |
| frontend/src/storefront/styles/shop/01--root.css | shop: -root styles. Source order is preserved by the entry stylesheet. |
| frontend/src/storefront/styles/shop/02-shop-product-image.css | shop: shop-product-image styles. Source order is preserved by the entry stylesheet. |
| frontend/src/storefront/styles/shop/03-availability-span.css | shop: availability-span styles. Source order is preserved by the entry stylesheet. |
| frontend/src/storefront/styles/shop/04-shop-stepper.css | shop: shop-stepper styles. Source order is preserved by the entry stylesheet. |
| frontend/src/storefront/styles/shop/05-shop-grid-comparison.css | shop: shop-grid-comparison styles. Source order is preserved by the entry stylesheet. |
| frontend/src/storefront/styles/shop.css | Ordered shop stylesheet entry; domain rules live in the adjacent folder. |
| frontend/src/storefront/styles/storefront-polish.css | Warm editorial surfaces and responsive navigation, catalogue and product pages. |
Independent apps, services and SDK
| Module | Responsibility |
|---|---|
| extensions/apps/catalog-export/server.py | Independent, language-neutral export example. Only scoped commerce callbacks; no core SQL or hosted Python dependency. |
| extensions/apps/engraving/configuration.wat | Engraving-owned rules: printable input is checked by the host; app defines length and fee. |
| extensions/apps/gift-message/configuration.wat | Gift-message-owned rules: printable input is checked by the host; app defines length and fee. |
| extensions/apps/product-lab/app.js | A complete guest surface can use any UI framework; this example needs no build or host imports. |
| extensions/apps/product-lab/index.html | Independent app entry; see extensions/README.md for its public contract. |
| extensions/apps/product-lab/server.py | App-owned code, SQLite structures and versioned browser UI; no commerce credentials reach the guest. |
| extensions/apps/service-example/index.html | Independent app entry; see extensions/README.md for its public contract. |
| extensions/apps/service-example/server.py | Standalone app service with its own UI and durable event inbox. Run separately from the core. |
| extensions/apps/storyfront/ui.html | Independent app entry; see extensions/README.md for its public contract. |
| extensions/budget-reserve.wat | Keep EUR 100 of the supplied budget unused. Inputs are integer cents. |
| extensions/company-limit.wat | Independent app entry; see extensions/README.md for its public contract. |
| extensions/minimum-order.wat | Business orders must reach EUR 50 and stay inside the supplied budget. |
| extensions/sdk/analytics.js | Consent-bound GA4 adapter for native and headless storefronts. Never send customer identities. |
| extensions/sdk/browser.js | Guest SDK: no merchant tokens or raw host API access; the host rechecks every action. |
| extensions/sdk/events.py | Language-neutral wire contract example: validate full batches and public HMAC envelopes before effects. |
| extensions/sdk/ui_bundle.py | Build self-contained vanilla example UIs from the shared SDK; no remote imports at runtime. |
| extensions/sdk/wit/snapshot-price.component.wat | Typed fixture: calls the real host cart snapshot and returns one percent of its subtotal. |
| extensions/single-order-cap.wat | Limit any individual business purchase to EUR 250, within its budget. |
Verification tools and fixtures
| Module | Responsibility |
|---|---|
| scripts/api_catalogue.py | Generate a drift-checked static HTTP route catalogue from the compiled Rust router declarations. |
| scripts/app_assets.py | Actual native scoped file upload, callback read, product/digest/key fences and public-file policy. |
| scripts/app_assistants.py | Real assistant packages: editor context, rights, MCP opt-out, cron, signed webhooks, flows and local service fixtures. |
| scripts/app_callbacks.py | Real app identity, separate PII consent, digest/creator fences and foreign-object tests. No paid services. |
| scripts/app_components.py | Real typed WIT host reads, all four quote hooks and checkout persistence/CAS/tenant negative cases. |
| scripts/app_consent.py | Installation/upgrade consent uses the actual reviewed digest and full permissions; no fixture auto-consent. |
| scripts/app_distribution.py | Real signed publisher packages exercise canonical CLI signing, consent, dependency update/deactivation and tenant containment. |
| scripts/app_events.py | Actual leased delivery: slow-service isolation, bounded batches, minimization, filter/replay and stale lease fencing. |
| scripts/app_export.py | Actual independent export app receives leased events, reads scoped products, uploads a private artifact and completes durable jobs. |
| scripts/app_inference.py | Opt-in real local model proposes a registered app operation; approval exercises the same managed writer. |
| scripts/app_jobs.py | Real long-action identity/idempotency/lease/CAS/tenant/quota checks, without external or paid effects. |
| scripts/app_ontology.py | Real native graph mapping contract through two-tenant API, MCP, permissions, references and revisions. |
| scripts/app_preview.py | F5 uses actual native APIs in a personal clone; no version publication, foreign-team access or release. Synthetic only. |
| scripts/app_relations.py | Real composite-FK multi-relations: per-tenant schemas, atomic quotas/revisions, hostile references and cyclic staging clone. |
| scripts/app_schema.py | Real installed-schema evolution, recovery snapshots, rollback on bad conversions and isolation of equal app IDs. |
| scripts/app_secrets.py | Encrypted tenant/app credentials and real incoming webhooks under strict non-owner RLS; synthetic local service only. |
| scripts/app_studio.py | Native App Studio exercised through real HTTP/PostgreSQL: shared IR, version isolation, data, routes, MCP and selective release. |
| scripts/app_surfaces.py | Actual app UI registry/API/MCP/data/staging and slow-service isolation against Rust/PostgreSQL. |
| scripts/apps.py | Real PostgreSQL app lifecycle, managed schema/RLS, typed API/MCP, cart and observation tests. |
| scripts/automation.py | Real HTTP/PostgreSQL branching automation, private facts, durable delays and revoked-actor regressions. No providers. |
| scripts/automation_differential.py | Compare actual original Shopware rule classes with native scopes using independent synthetic entities. |
| scripts/automation_lifecycle.py | Tenant-bound default configuration, revision-safe deletion and actual event-flow effects. |
| scripts/automation_registry.py | Rebuild the native rule catalog from pinned PHP reflection and explicitly reviewed scope bindings. |
| scripts/benchmark.py | Reproducible local HTTP + PostgreSQL benchmark, with response validation. |
| scripts/branding.py | Keep the public Vendune identity, shared vector assets and executable package/deployment paths consistent. |
| scripts/build_app_ui.py | Export deterministic example HTML and its operator uiDigests entry; never fetch remote resources. |
| scripts/build_site.py | Build marketing pages and the complete Markdown documentation for GitHub Pages. |
| scripts/catalog_management.py | Real HTTP/PostgreSQL catalog creation, categories, multilingual editor, visibility and staging regressions. Synthetic isolated shops only. |
| scripts/channel_management.py | Isolated HTTP regressions for revisioned channels, domain aliases and session-bound private previews; no providers. |
| scripts/check_site.py | Check the generated documentation's links and discovery metadata. |
| scripts/checkout_handoff.py | Exercise actual PostgreSQL checkout transfer, isolation, replay and durable ordering. |
| scripts/checkout_review.py | Real SQL checkout rejects unreviewed changes without orders or stock writes; synthetic fixture only. |
| scripts/cloud_benchmark.py | Bounded private-cloud HTTP load using the existing validated benchmark sampler. |
| scripts/cognitive_experiments.py | Real native consent/layout/payment paths with synthetic live-receipt fixtures, not a measured commerce experiment. |
| scripts/commerce.py | Real HTTP/PG tests for SKUs, moderated reviews, tax/shipping/payment and deliveries. |
| scripts/company_settings.py | Real HTTP company basis/channel inheritance, immutable issuer snapshots, bounded logos and private staging. No external services. |
| scripts/connected_apps.py | Real local OAuth/provider HTTP protocols, private-source PostgreSQL/AGE consumers and durable Slack flows. |
| scripts/connector_store_tests.py | Concurrent private state, settings/import fences and encrypted mailbox persistence. |
| scripts/connectors.py | Start the local connector apps with private generated keys; preserve all existing app services. |
| scripts/contention.py | Sell the remaining workshop desks under contention; separate synthetic tenant. |
| scripts/context_differential.py | Compare bounded context/tier/quantity ports with original Shopware methods. |
| scripts/crm_history.py | Real CRM groups/defaults, transaction-coalesced history, validated restore, tenant/role/MCP isolation. |
| scripts/currencies.py | Real tenant/channel multi-currency, precision, immutable order and durable fixed-price tests; no paid providers. |
| scripts/customer_accounts.py | Real registration/address/login/checkout lifecycle, ownership, CAS and immutable financial snapshots. |
| scripts/delivery_differential.py | Compare the original PercentageTaxRuleBuilder with the live Rust port. |
| scripts/demo/fixtures.py | Four-language, provider-free commerce playground definitions; no credentials or real customer data. |
| scripts/developer_documents.py | Local model wire fixtures verify app generation, provenance and document privacy, without paid providers. |
| scripts/differential.py | Independent PHP/Rust differential; fails on any money delta, not averaged error. |
| scripts/email_tests.py | Archived differential SMTP/TLS fixtures plus actual Rust/PostgreSQL/MCP/flow consumers. No external mail. |
| scripts/extensions.py | Activate actual Wasm policies and prove their effect on B2B checkout. |
| scripts/fashion_demo.py | Actual default signup, fashion variants/media/localization, isolated checkout and restart; synthetic data only. |
| scripts/formal/axioms.py | Audit owned proof sources and transitive Lean dependencies; no extra axioms are allowed. |
| scripts/formal/conformance.py | Compare compiled Rust production policies with Lean's extracted executable, |
| scripts/formal/extract.py | Fail-closed typed Rust-to-Lean extraction. Trusted boundary: this translator, |
| scripts/formal/mutations.py | Prove the verification gate rejects representative broken policies and stale/disconnected source bindings. |
| scripts/formal/registry.py | Explicit full-source inventory and reviewed adapter locks, not proof coverage claims. |
| scripts/formal/runners.py | Generate conformance drivers from parsed policy signatures, never a second policy implementation. |
| scripts/formal.py | Run extraction, Lean proofs/axiom audit, compiled conformance and complete source-inventory checks. |
| scripts/hosting_check.py | Check a deployed experimental SaaS HTTPS origin without credentials or real orders. |
| scripts/hosting_container.py | Smoke-test the built deployment image against an isolated database on the local Compose network. |
| scripts/identity_broker.py | Synthetic broker signatures, durable replay prevention, scoped frontend routing and private Studio handoff; no provider calls. |
| scripts/image_jobs.py | Real image jobs/bytes against a local Images fixture: private review, stale/tenant guards, edit multipart and no paid calls. |
| scripts/integration.py | Exercise the real HTTP -> Rust -> PostgreSQL path. Never contacts a PSP. |
| scripts/intelligence.py | Actual SQL knowledge persistence and optional live local inference integration. |
| scripts/international_commerce.py | International configuration at the real HTTP/PostgreSQL path; all rates and addresses are synthetic fixtures, not tax advice. |
| scripts/knowledge_workspace.py | Actual tenant-scoped knowledge lifecycle, multilingual retrieval, cursor census and selective staging; no model calls. |
| scripts/legal_privacy.py | Real tenant-scoped consent, checkout guards, declarations, MCP and flow consumers; no external providers. |
| scripts/lexical_search.py | Native lexical candidates: real forced-RLS plans, backfill, source edits and isolation. |
| scripts/load.py | Local HTTP latency sample. Does not claim production or Shopware speedup. |
| scripts/managed_search.py | Real PostgreSQL/Qdrant synchronization; synthetic embeddings test transport, not AI quality. |
| scripts/marketing_accounts.py | Real isolated shops: customer authority, limited coupons, event flows, channels and selected releases. No paid models. |
| scripts/mcp_stdio.py | Line-delimited MCP stdio bridge for Claude Desktop and other local clients. |
| scripts/merchant_operations.py | Real HTTP/PostgreSQL CRM, receipt, scoped-access and paid-download regressions. No PSP traffic. |
| scripts/migrate_connector_state.py | Explicit offline legacy-state migration; decrypted data crosses stdin only, never logs or temporary files. |
| scripts/money_boundary_differential.py | Gate the exact checkout boundary using totals from original Shopware calculators, never a PHP rewrite. |
| scripts/payment_providers.py | Provider-neutral financial ledger through real HTTP/PostgreSQL and a local private-service fixture. |
| scripts/payments.py | PayPal wire-contract and real Rust/PostgreSQL state tests. Local fixture, never real provider traffic. |
| scripts/platform.py | Real PostgreSQL/HTTP operator control-plane regression; synthetic accounts only, no paid providers. |
| scripts/platform_admin.py | Grant/revoke an existing personal operator offline. Credentials remain in environment; no signup can grant this role. |
| scripts/platform_control.py | Control-plane regressions on the real HTTP/database path; disposable synthetic shops and local model wire fixtures only. |
| scripts/platform_setup.py | Isolated production-mode bootstrap test. Creates/drops only a uniquely named synthetic database. |
| scripts/playground.py | Create an isolated local shop through personal-owner APIs; reruns preserve merchant edits and never call providers. |
| scripts/port.py | Named, reviewable port gates; never marks an untested unit as complete. |
| scripts/prepare_host.py | Prepare private first-host configuration; no server purchase, SSH, deployment or secret logging. |
| scripts/prepare_vercel.py | Render same-origin Vercel API proxy configuration; no credentials, deployments or account changes. |
| scripts/product_lab.py | Local full-app example lifecycle; private keys and independent code/data, no automatic installation. |
| scripts/production_foundations.py | Strict non-owner PostgreSQL runtime, pool isolation, inventory and two-replica invalidation regressions. |
| scripts/protocols.py | Protocol flows exercise the same commerce core; model smoke test is opt-in. |
| scripts/providers.py | Cloud wire-contract tests using local HTTP servers, NOT live cloud inference. |
| scripts/read_performance.py | Two real Rust replicas test coherent read caches; optional matched local HTTP baseline probe. |
| scripts/restart.py | Persist an API snapshot, restart server+DB externally, verify exact state. |
| scripts/rule_catalog.py | Inventory original Shopware conditions without claiming unsupported scopes are implemented. |
| scripts/rule_differential.py | Execute original Shopware numeric comparisons, including epsilon, null and unsupported operator semantics. |
| scripts/rust_connectors.py | Actual Rust/PostgreSQL multi-process notification, OAuth/import and adversarial fixtures; no external accounts. |
| scripts/scalability.py | Real HTTP/PG regression for bounded reads and concurrent cart edits. |
| scripts/security/core_hardening.py | Real replica regressions for auth admission, poison-event isolation, retention and bounded resource leases. |
| scripts/security/tenant_schema.py | Database adversarial checks: reject cross-shop links even when API predicates are accidentally omitted. |
| scripts/security_route_gate.py | Every static commerce Admin API method must have an adjacent explicit permission; new routes fail closed. |
| scripts/services.py | Standalone app process, opaque UI SDK transport, own SQLite inbox and independent durable worker. |
| scripts/settings_scopes.py | Real tenant/channel settings, immutable order dependencies, localized gallery and selective staging regressions. |
| scripts/site_markdown.py | Render every tracked Markdown document with repository-aware links and search. |
| scripts/staging.py | Real PG proof: private sandbox, immutable app versions, selective release and conflicts. No paid inference. |
| scripts/storefront_urls.py | Real HTTP product deep links and host isolation in disposable shops. |
| scripts/structure.py | Guard the documented Rust domain split and public extension examples. |
| scripts/studio.py | Actual Studio API, localization and original-kernel consumer checks. |
| scripts/tenant_isolation.py | Adversarial two-shop API/MCP/UCP/object and schema isolation with real personal/customer sessions. |
| scripts/testing/advisor_privacy.py | Concurrent privacy mutations across the real concierge/provider path; no live inference. |
| scripts/testing/advisor_sources.py | Actual channel-admitted advisor context and concurrent native source mutations; synthetic local model only. |
| scripts/testing/app_approval.py | Use the Rust manifest serializer for operator pins; never invent a second canonical digest. |
| scripts/testing/coverage_env.py | Convert trusted cargo-llvm-cov environment output to GitHub's environment-file syntax. |
| scripts/testing/coverage_report.py | Publish separate all-source coverage totals, untested files and enforce reviewed minimums. |
| scripts/testing/database.py | Use the same PostgreSQL fixtures through Docker or an explicitly selected native psql executable. |
| scripts/testing/extraction.py | Native document-event extraction, review boundary and shared AI quotas; local provider only. |
| scripts/testing/hotpath.py | Real HTTP wire bytes and SQL tracing checks for the existing read-performance suite. |
| scripts/testing/image_context.py | Check real Rust include! inputs against the production image's explicit build COPY set. |
| scripts/testing/intent_navigation.py | Exercise saved fact categories through native catalog/MCP, source review and selective staging; no models. |
| scripts/testing/inventory_batch.py | Concurrent two-product allocation/release on the actual HTTP path, reused by strict runtime verification. |
| scripts/testing/pooler.py | Owned real PgBouncer fixture: one backend, transaction pooling, never a forced privileged user. |
| scripts/testing/provider_fleet.py | Configure one encrypted synthetic provider for all test workers, then restore the isolated control-plane row. |
| scripts/testing/runtime.py | Owned synthetic server lifetime, child checks and loopback readiness for verification. |
| scripts/testing/sitecustomize.py | Opt-in subprocess instrumentation for synthetic verification; never loaded by production. |
| scripts/testing/source_inventory.py | Generate/check exact production and verification module inventory; listings are not coverage. |
| scripts/testing/tooling_tests.py | Ordered Studio layout. |
| scripts/transaction_pooler.py | Repeat the real strict-runtime and multi-replica regressions through a one-backend transaction pooler. |
| scripts/translations.py | Durable translation jobs against a local provider fixture, real SQL, native MCP and a cold restart; no paid calls. |
| scripts/users.py | Real multi-user, workspace isolation and role/revocation regression tests. |
| scripts/verify_integration.py | Single integration suite registry, isolated DB by default; never alters an existing shop. |