Vendune
docs/module-inventory.mdView on GitHub ↗

Complete source inventory

Generated by python3 scripts/testing/source_inventory.py --write. CI checks exact contents.

This lists every checked-in source module in these roots, including files with no recorded hits. A responsibility or suite listing does not mean 100% coverage. See testing for measured coverage and unverified paths.

Rust commerce and transport

Module Responsibility
src/accounts/address_restore.rs Atomic restoration of the owning customer's address aggregate; geography, references and immutable order snapshots remain guarded.
src/accounts/address_store.rs Tenant-owned address persistence, optimistic revisions and atomic default assignment.
src/accounts/addresses.rs Store API address book uses independent customer sessions, never merchant credentials.
src/accounts/contacts.rs Customer-editable contact fields; identity, price group and privileges remain server-owned.
src/accounts/demo.rs Public synthetic customer fixture for newly provisioned demo shops; never fills real customer addresses.
src/accounts/metadata.rs Standard customer read fields and indexed order metrics are derived from authoritative records.
src/accounts/mod.rs Independent customer sessions, profile/password management and owning-account order history.
src/accounts/order_snapshot.rs Checkout-owned immutable customer and address records; future account edits cannot rewrite an order.
src/accounts/orders.rs Customer-owned order reads and receipts share one tenant/identity predicate and a public projection.
src/accounts/profile.rs Typed customer-owned profile updates; price groups, email and merchant roles cannot be self-assigned.
src/agent.rs Persistent grounded conversations and tenant-scoped semantic knowledge HTTP adapters.
src/apps/approval.rs Operator service authority is bound to immutable package content, never to a merchant-chosen ID.
src/apps/asset_surfaces.rs App file uploads reuse the product asset parser/store and require the current package plus either callback consent or a surface grant.
src/apps/cart_contributions.rs Generic app contributions: configure a cart, bind package/data revisions and persist audited pricing inputs.
src/apps/commerce_hooks.rs Typed pure commerce hooks share the compiled sandbox cache and receive explicit immutable snapshots, never SQL or credentials.
src/apps/compatibility.rs Explicit read adapter for persisted v0.5 engraving carts; completed order snapshots remain unchanged.
src/apps/consent.rs Package approval binds all requested permissions to a reviewed digest; current actor rights apply before every installation path.
src/apps/core_callbacks.rs Narrow app callbacks delegate to the existing commerce owners and project PII only with separate consent.
src/apps/credentials.rs App keys reuse the core integration-key store, current creator rights, expiry and immutable package digest.
src/apps/data.rs Managed app tables: typed writes, optimistic revisions, bounded reads and local RLS context.
src/apps/distribution.rs Signed publisher namespaces and tenant-local dependency/version gates. Operator service access still requires its separate exact digest pin.
src/apps/editor_contract.rs Editor mounts, enumerated fields and tenant-owned core references; no app alters core tables.
src/apps/editor_tests.rs Assistant fixture contracts exercise real validation, not only the client-side builder.
src/apps/egress.rs Bounded origin clients pin resolved addresses for each connection and never use ambient HTTP proxies.
src/apps/event_contract.rs Explicit event filters, bounded batches and signed public HTTPS delivery extend the existing leased outbox, not a second queue.
src/apps/event_projection.rs Least-privilege event subscriptions and payload projections; merchant identity never implies app access.
src/apps/events.rs Durable at-least-once app events, retry leases and stable event idempotency keys.
src/apps/evidence.rs Private provenance-bearing app exports feed merchant retrieval and durable app events; never public PDP answers.
src/apps/evidence_routes.rs Scoped merchant-only evidence retrieval; sources never enter public product answers.
src/apps/field_values.rs Exact app field values reuse commerce money, rich content and tenant-owned assets; no HTML or float decimal coercion.
src/apps/form_layout.rs Bounded twelve-column form geometry, presentation flags and tab order shared by every native app surface.
src/apps/gateway.rs One permission-aware action gateway serves HTTP, UI and MCP; service egress is operator configured.
src/apps/hosted.rs Persist hosted-app dependencies through the existing package installer; no private renderer or parallel registry.
src/apps/input_schema.rs Bounded recursive action-input contract. Untyped managed fields still receive depth/size budgets.
src/apps/job_callbacks.rs Long-job service callbacks disclose input only after current actor consent, package and lease checks. Late callbacks cannot commit.
src/apps/jobs.rs Durable long actions piggyback on the existing outbox. Apps claim a fenced lease; unknown side effects are never retried automatically.
src/apps/manifest.rs Strict package contract; identifiers and limits are checked before any schema DDL.
src/apps/manifest_validation.rs Package capability, schema and action validation; no executable behavior is inferred from names.
src/apps/mod.rs Versioned app packages: managed data, UI slots, agent tools and isolated service calls.
src/apps/native_data.rs App record translations use configured shop languages and field-level main-language inheritance.
src/apps/native_view_tests.rs Native schema security regressions: bindings, public writes, allowlists, bounded blocks and legacy digests.
src/apps/native_views.rs Bounded native view definitions; every data binding resolves to the same authorized app action gateway.
src/apps/observability.rs Bounded metadata-only app telemetry, storage usage and explicitly approved cursor-based event replay.
src/apps/ontology.rs Namespaced graph views over current authorized app records; no duplicated source or public-claim authority.
src/apps/planning.rs Registered managed app actions join the same preview/approve transaction as core changes.
src/apps/presentation.rs Optional passive app artwork and localized summaries; omitted metadata preserves published legacy digests.
src/apps/registry.rs Atomic installation and additive schema upgrades; immutable version digests preserve history.
src/apps/relations.rs Multi-relations keep stable array wire values, composite tenant FKs and shared accounting; staging may clone cyclic graphs atomically.
src/apps/routes.rs Tenant-scoped package lifecycle, generated data endpoints and a shared action adapter.
src/apps/runtime.rs Generic pure-Wasm contribution executor; the installed package supplies all business predicates.
src/apps/schedules.rs Durable UTC cron ticks emit namespaced outbox events; replicas lock due rows and staging never runs them.
src/apps/schema_changes.rs Explicit, transactional field evolution. No raw migration SQL; bounded recovery snapshots precede DDL and every converted value is validated.
src/apps/schema_upgrade.rs Apply a checked migration under tenant-local DDL locks with bounded recovery history and optimistic record revisions.
src/apps/secrets.rs Digest-bound per-shop app secret rotation reuses platform authenticated encryption; no plaintext read endpoint.
src/apps/service_limits.rs Non-queuing per-process bulkheads isolate slow apps without holding database connections.
src/apps/service_policy.rs Operator-owned private origins permit isolated service networking without relaxing public egress.
src/apps/storage.rs Attach the shared PostgreSQL accounting trigger to tenant-specific app tables before any write.
src/apps/surface_grants.rs Short-lived UI grants bind a package, surface, actor and concrete editor object on the server.
src/apps/surface_tests.rs Contract counterexamples reject cross-scope UI actions, unsafe URLs and mutating GET routes.
src/apps/surfaces.rs App-owned UI surfaces and namespaced HTTP routes reuse the authorized action gateway.
src/apps/ui_bundles.rs Operator-pinned, bounded self-contained UI bundles use the same actor/context grant as app actions.
src/apps/ui_logic.rs Declarative UI code-behind validates a bounded AST; calls retain surface grants and server domain authorization.
src/apps/ui_logic_tests.rs UI programs must keep static types, same-model saves, surface allowlists and acyclic ownership before install or preview.
src/apps/ui_logic_types.rs Static UI expression types prevent control coercion and invoking save with a different model; runtime still validates actual values.
src/apps/webhook_scope.rs Scope signed app ingress from its route before identity, tenant lifecycle and forced-RLS admission.
src/apps/webhooks.rs Operator-signed incoming events: tenant-bound HMAC, five-minute freshness and atomic replay receipts.
src/assets/app_files.rs Scoped app access to the existing asset store. Binary callbacks are explicit and private; publishing still uses the native asset lifecycle.
src/assets/download.rs Public attachments honor sales-channel visibility; downloads require a paid, owned order snapshot.
src/assets/image_jobs.rs Durable image jobs: tenant admission, revision-bound private previews and explicit publication, without automatic paid retries.
src/assets/image_provider.rs Optional OpenAI Images adapter; bounded responses and decoded PNG output, no remote user URLs or leaked provider errors.
src/assets/ingestion.rs Shared bounded multipart parser for product uploads and scoped app uploads; file validation/persistence stays in the asset owner.
src/assets/mod.rs Product attachments and paid digital downloads: bounded binary persistence and tenant/account ACL.
src/assets/rich.rs Safe structured rich content, never executable HTML. Same schema for merchant API and frontend.
src/assets/rich_document.rs Allow-listed editor JSON with bounded depth and content; HTML/handlers/styles cannot enter the renderer.
src/assets/upload.rs File admission, immutable bytes and explicit publishing; binary content never enters merchant list responses.
src/auth/abuse.rs Database-backed account and trusted peer-prefix throttles shared by replicas; reserve before password hashing.
src/auth/broker.rs Optional trusted identity exchange: signatures bind route, audience, expiry and one-use nonce.
src/auth/broker_credentials.rs Explicit password setup/recovery or existing-password verification from a trusted, verified-email broker.
src/auth/broker_inference.rs Trusted server-to-server inference inherits operator settings without disclosing any provider credentials.
src/auth/credentials.rs Argon2 password operations run off the asynchronous request executor.
src/auth/dto.rs Stable typed authentication envelopes; field validation remains in the shared credential owner.
src/auth/handoff.rs One-time personal-session handoff to the Studio; no passwords or bearer tokens in links.
src/auth/identity.rs Resolve the current credential and membership once; bootstrap and sandbox checks share the same boundary.
src/auth/integrations.rs Expiring API/MCP keys are bounded to one workspace and intersect their creator's current membership.
src/auth/invitations.rs Single-use, expiring invitations. Acceptance verifies an existing account password.
src/auth/members.rs Workspace member visibility and immediately effective role/revocation changes.
src/auth/middleware.rs Resolve sessions from PostgreSQL on every request: role changes/revocation work across replicas.
src/auth/mod.rs Personal merchant accounts, tenant memberships, scoped sessions and role enforcement.
src/auth/permissions.rs Fine-grained workspace overrides. Owners retain control; delegates cannot grant rights they lack.
src/auth/provision.rs Reusable synthetic shop provisioning for initial signup and additional shops owned by the same merchant.
src/auth/registration.rs Create an isolated merchant workspace from synthetic template data.
src/auth/route_policy.rs Rights are registered beside each API method. Missing registrations always deny access.
src/auth/sessions.rs Login/logout and personal workspace discovery. Only hashed opaque tokens persist.
src/automation_rules/comparison.rs Original comparison primitives plus literal wildcard/zip operators; no regex or executable expressions.
src/automation_rules/containers.rs Source line wrappers, quantified goods and all-line containers retain one selected line scope.
src/automation_rules/evaluation.rs Evaluate native rule scopes from authoritative JSON facts with precise line/container selection.
src/automation_rules/fields.rs Source custom fields retain typed equality and selection intersection; purchase prices use private server facts.
src/automation_rules/mod.rs Source-named rule registry and checked evaluation; absent required facts are errors, including under NOT.
src/automation_rules/tests.rs Regression cases cover missing authority under NOT, original quantifiers, dates, metadata types and registry bounds.
src/automation_rules/time.rs Calendar comparisons use an explicit server clock, IANA zones and the original exclusive date-range end.
src/automation_rules/validation.rs Bounded source payload validation against exported field/operator metadata and nested condition scopes.
src/bin/automation_rules.rs JSON batch transport for comparisons with original Shopware rule classes; not a production authority endpoint.
src/bin/connectors.rs Independent Rust standard-app service; no provider code executes in commerce request workers.
src/bin/context.rs Bounded ports of original language-chain, rule priority and quantity selection.
src/bin/delivery.rs Batch proportional-tax fixture transport for the original-PHP comparator.
src/bin/money_boundary.rs Batch transport for comparing the actual legacy-to-integer checkout boundary against original Shopware totals.
src/bin/price.rs Batch price fixture transport for the original-PHP differential comparator.
src/bin/rules.rs Batch original-PHP numeric-rule comparison transport.
src/bin/verified_kernel.rs Generated conformance driver; invokes the same production policy functions as the commerce server.
src/bootstrap.rs Startup, additive migrations, persisted extensions and outbox worker.
src/capabilities/catalog.rs Shared catalogue composes native capabilities and cognitive contracts without duplicating authorization.
src/capabilities/core_catalog.rs Public HTTP/MCP capability catalogue, separate from authorization and dispatch.
src/capabilities.rs Shared HTTP/MCP capability dispatch and tool authorization.
src/cart_model.rs Persisted cart, item and customer-context types.
src/cart_mutation.rs Optimistic cart mutations and quantity normalization.
src/cart_price.rs Authoritative quantity pricing and localized checkout quote assembly.
src/cart_routes.rs Store API cart and order route adapters.
src/cart_storage.rs Cart creation, loading and input validation.
src/catalog_model.rs Tenant product model and database hydration.
src/catalog_page.rs Bounded tenant-scoped catalog reads. A cursor is a product ID, never an offset.
src/catalog_routes.rs Health and localized catalogue HTTP routes.
src/categories/admin.rs Revision-bound category writes, bounded translations and serialized cycle-safe tree moves.
src/categories/graph_query.rs Saved category predicates select only current confirmed public source claims; no inference at browse time.
src/categories/mod.rs Tenant-scoped category tree, localized navigation and product assignment boundaries.
src/categories/navigation.rs Public navigation is localized and restricted to the selected channel's active category ancestry.
src/channel_metrics/reads.rs One persisted diagnostic read shared by operator overview, shop dossiers and infrastructure.
src/channel_metrics.rs Bounded, lossy diagnostic counters. Never use this buffer for business events.
src/chat_lease.rs Short, cross-replica conversation leases; inference never retains a database transaction.
src/checkout_handoff.rs Single-use checkout transfer for independent storefronts; no app-specific catalog or checkout rules.
src/checkout_page.rs The existing checkout may be framed only by its registered tenant/channel storefront.
src/checkout_products.rs Localized immutable checkout SKU snapshots read under the purchase transaction's locks.
src/cognition/advisor.rs Buyer-admitted initial catalog/evidence context and bounded native response revalidation; no extra truth store.
src/cognition/autonomy.rs Price-only optional autonomy, atomic unique-SKU daily quotas and a non-compounding day baseline.
src/cognition/claim_batches.rs Bounded public claim intake/compilation shares current channel admission and source-bound evidence, without per-SKU HTTP round trips.
src/cognition/context.rs Bounded localized catalog retrieval before inference; full catalog size never expands the prompt.
src/cognition/contracts.rs Evidence APIs and MCP contracts dispatch into one authorized owner; the claim compiler rejects free prose.
src/cognition/evidence.rs Source-bound claim lifecycle on the existing knowledge relation ledger; no model text becomes a confirmed fact automatically.
src/cognition/experiments/mod.rs Controlled experiments use the existing storefront layout consumer and authoritative payment ledger.
src/cognition/experiments/model.rs Preregistered fixed-horizon experiment parameters and conservative bounded-outcome inference.
src/cognition/experiments/report.rs Delayed final experiment readout is derived from the existing live capture/refund ledger, never demo rewards.
src/cognition/extraction.rs API/MCP/flow source extraction shares provider admission and quote checks; candidates require merchant review.
src/cognition/generations.rs Restart-safe model-change intake: short locked cursor batches reuse the canonical embedding queue.
src/cognition/guardrails.rs Merchant-owned guardrails in commerce settings; native currency amounts bind preview and execution.
src/cognition/indexing.rs Durable bounded embedding jobs; short claims and revision fences keep provider latency outside PostgreSQL.
src/cognition/mod.rs Evidence-based shop memory: event receipts, observed pairs, reviewable hypotheses and bounded context.
src/cognition/preferences.rs Consent-bound private cart preference graph: typed bounded input, export, erasure and native advisor context.
src/cognition/projection.rs Exactly-once local observation projection; associations retain order/event evidence and simulation labels.
src/cognition/recommendations.rs Merchant-approved associations are consumed by the public shop without exposing order counts or identities.
src/cognition/routes.rs Merchant memory endpoints and revision-bound experiment/dismissal decisions.
src/cognition/signed.rs Public Ed25519 attestations bind exact native facts and channel context for five minutes; signatures do not guarantee source truth.
src/cognition/stream.rs SSE transports real chat completion and waiting heartbeats; detached execution retains tenant scope and the existing durable chat lease.
src/cognition/tools.rs Bounded agent read rounds use the same capability dispatcher and current actor rights; never execute writes.
src/commerce/app_adjustments.rs Apply admitted integer app adjustments through native pricing/tax calculation; extensions cannot replace quote JSON.
src/commerce/catalog.rs SKU loading with parent translation fallback.
src/commerce/configuration.rs Tenant checkout configuration loading.
src/commerce/content_text.rs Shared field-level content fallback for metadata and configurable object names.
src/commerce/context_routes.rs Public method discovery and revision-checked checkout context changes.
src/commerce/customer_groups.rs Tenant-owned translated customer groups preserve exact rule IDs and select an explicit existing price/tax presentation basis.
src/commerce/delivery.rs Shipping costs, proportional taxes and calendar delivery windows.
src/commerce/detail.rs Product family, context prices, gallery, properties and review aggregates.
src/commerce/fulfillment.rs Revision-checked payment and delivery state transitions.
src/commerce/geography.rs Bundled MIT country catalogue, tenant-owned overrides and typed region admission.
src/commerce/group_usage.rs Removing a customer group rejects live customer, price and native/source-rule dependencies under the settings lock.
src/commerce/international_capabilities.rs International configuration and translation MCP tools call the exact same scoped native handlers as HTTP.
src/commerce/inventory.rs All-checkout allocation ledger; release is idempotent and always uses persisted quantities, never edited order JSON.
src/commerce/method_text.rs Shared translated names and descriptions with field-wise shop-main-language inheritance.
src/commerce/method_usage.rs Tenant-scoped dependency preflight and authoritative deletion guards; order snapshots remain immutable.
src/commerce/mod.rs Native catalogue and checkout domains; pricing ports remain in the library.
src/commerce/order_fields.rs Standard order read fields are projected from the authoritative quote/payment, never maintained twice.
src/commerce/order_machine.rs Declarative order workflow schema. Extensions add states, never executable effects or payment truth.
src/commerce/order_workflow.rs One server-derived action catalogue drives UI, HTTP and MCP; built-in business guards cannot be bypassed.
src/commerce/product_admin.rs Central product list and identity/association writes; all persistence is tenant scoped.
src/commerce/product_channels.rs Per-product channel visibility overrides remain indexed even when an open catalog contains millions of products.
src/commerce/product_create.rs Product creation accepts validated stable import IDs; the shared domain save handler retains pricing, ownership and history checks.
src/commerce/product_edit.rs Revision-bound multilingual product metadata: specifications, SEO, cross-selling and free shipping.
src/commerce/product_fields.rs Native product administration writes priced fields under the same revision and inventory row lock.
src/commerce/product_languages.rs Enabled content languages, NULL field inheritance and stable global language registration.
src/commerce/product_metadata.rs Typed product edit payload and multilingual metadata including exact currency prices.
src/commerce/review_moderation.rs Merchant authorization and review publication.
src/commerce/reviews.rs Customer review submission with server-derived purchase verification.
src/commerce/selection.rs Recover a quote after configuration changes without losing items or silently committing new choices.
src/commerce/settings_defaults.rs Backward-compatible enrichment of existing configuration with bundled translated method labels.
src/commerce/settings_mutation.rs Optimistic settings persistence and audit event.
src/commerce/settings_patch.rs Transport-only sparse JSON differences: stable record IDs, explicit nulls, and deletion distinct from inheritance.
src/commerce/settings_release.rs Selective staging units for channel settings; all final aggregates and method dependencies use native validators.
src/commerce/settings_routes.rs Tenant configuration and operational read model.
src/commerce/settings_scope.rs Scoped checkout configuration: basis row lock orders all override writes and authoritative checkout reads.
src/commerce/settings_validation.rs Configuration validation and required availability invariants.
src/commerce/tax.rs Destination tax-class resolution and net-preserving price conversion.
src/commerce/tax_context.rs Tax conditions consume private authoritative pre-tax cart facts without a recursive quote.
src/commerce/tax_rules.rs Priority-based destination rules; current tax law is merchant configuration, not bundled tax advice.
src/commerce/types.rs Checkout selection and configuration data contracts.
src/component_runtime.rs WIT-typed read-only commerce guest. Snapshots are prepared by domain owners; no WASI, HTTP, DB or merchant credentials reach components.
src/concierge.rs Read-only storefront shopping advisor.
src/connectors/actions.rs Existing standard-app actions and event/export endpoints share validated tenant-bound dispatch.
src/connectors/config.rs Compile-time mail setting types plus bounded runtime validation and write-only credentials.
src/connectors/crypto.rs Authenticated encryption binds config, OAuth verifiers, messages and receipts to tenant and app.
src/connectors/email.rs Email app actions/events retain the published gateway, flow and MCP payload contract.
src/connectors/error.rs Sanitized failures distinguish explicit rejection from ambiguous external side effects.
src/connectors/events.rs One bounded event envelope feeds existing durable, idempotent connector queues; no parallel scheduler.
src/connectors/exports.rs Tenant-scoped encrypted knowledge records and bounded monotonic exports preserve importer fences.
src/connectors/legacy.rs Explicit offline SQLite export import: all records are rebound/encrypted atomically; ambiguous jobs stay uncertain.
src/connectors/mod.rs Language-neutral app HTTP contract backed by a Rust-only standard connector runtime.
src/connectors/network.rs Fixed provider endpoints, no redirects, bounded response streaming and loopback-only fixture overrides.
src/connectors/oauth.rs Single-use tenant/app-bound OAuth state, PKCE, encrypted tokens and serialized refresh/disconnect.
src/connectors/providers/analytics.rs Exact bounded GA4 source rows, quota metadata and stale-report tombstones; no invented causal claims.
src/connectors/providers/gmail.rs Read-only Gmail incremental imports preserve high-water cursors, bounded windows and deletion evidence.
src/connectors/providers.rs Provider-specific read imports and notification mapping stay outside the commerce kernel.
src/connectors/queue.rs Atomic idempotent enqueue, fair tenant admission and lease-fenced SKIP LOCKED claims for many workers.
src/connectors/server.rs Authenticated bounded app HTTP service with private OAuth callback and graceful worker lifetime.
src/connectors/smtp.rs Pinned SMTP/STARTTLS/TLS with verified hostname, bounded dialogue and no retry after ambiguous DATA.
src/connectors/store.rs PostgreSQL transactions carry local RLS context; config mutation serializes with in-flight delivery.
src/connectors/templates.rs Bounded immutable envelopes and non-executable multilingual templates; HTML substitutions are escaped.
src/connectors/tests.rs Actual Rust parsers, encryption and template consumers reject escalation/injection and preserve language behavior.
src/connectors/worker.rs Distributed delivery workers fence settings and leases, retry only proven rejection, and drain on shutdown.
src/context.rs Bounded behavioral ports of Shopware 6.7.14.2 context and product-cart selection.
src/currencies/capabilities.rs Currency MCP operations reuse the native HTTP handlers and existing settings/catalog permissions.
src/currencies/jobs.rs Bounded restart-safe fixed-price materialization with frozen FX, product locks and atomic checkpoints across replicas.
src/currencies/mod.rs Tenant currency configuration, channel contexts and durable price generation; no FX network calls in checkout.
src/currencies/model.rs Explicit currency scales and rational exchange-rate settings, inherited by sales-channel overrides.
src/currencies/pricing.rs Exact rational minor-unit FX conversion at the isolated legacy calculator boundary; fixed prices are explicit decimal strings.
src/currencies/rates.rs Bounded ECB reference-rate retrieval with exact decimal parsing; refresh runs outside checkout and never invents rates.
src/currencies/routes.rs Native currency discovery, revision-safe selection and authenticated FX/price job operations.
src/currencies/tests.rs Currency conversion adversaries and immutable source-price semantics, independent of live rate providers.
src/customer.rs Customer credential verification and context rotation.
src/demo_catalog.rs Public synthetic fashion template; provisioning copies only this versioned fixture into a new tenant.
src/developer/archive.rs Recoverable App Studio project deletion; installed packages and app records retain their independent lifecycle.
src/developer/builds.rs Immutable development versions are validated before storage; installation targets only private environments.
src/developer/drafts.rs Actor-private, optimistic mutable autosaves; these never install or alter a published package.
src/developer/generation.rs Structured provider output becomes a reviewable immutable manifest; it cannot write files or call shell tools.
src/developer/mod.rs Prompt-generated declarative apps and native coding-agent handoff, never unsandboxed model code.
src/developer/preview.rs F5 runs the shared native app runtime in an actor-private expiring staging clone; no build/version/release is created.
src/developer/routes.rs Developer HTTP transport and coding-agent task export; explicit staging precedes live release.
src/discount.rs Integer-cent proportional discount allocation; cumulative rounding conserves the exact basket discount.
src/documents/content.rs Validate enabled-language source content and rebuild hash-bound chunks without inherited fabricated translations.
src/documents/ingestion.rs Typed API and bounded upload write source hashes, chunks and graph relations atomically.
src/documents/lifecycle.rs Revision-bound source detail, editing, archive/restore and publication; edits require a new public review.
src/documents/mod.rs Source-bound knowledge ingestion, retrieval and product questions share tenant/product visibility.
src/documents/parser.rs PDF extraction executes in a killable child process without inherited commerce credentials.
src/documents/preview.rs No-provider retrieval preview shares product-question scope and locale rules; merchant sources never enter customer previews.
src/documents/product_knowledge.rs Product-centred canonical facts and tenant-filtered graph evidence, independent of the overview's truncated sample.
src/documents/questions.rs Product-specific read-only advice with authoritative price/specification snapshot and validated source citations.
src/documents/retrieval.rs Bounded lexical/vector source retrieval; public questions use only explicitly published documents.
src/documents/tools.rs Knowledge workspace/source MCP tools delegate to the same authorized HTTP operations and schemas.
src/documents/workspace.rs Permission-filtered knowledge census, cursor source inventory and activity; totals never masquerade as sampled graph counts.
src/experience.rs Persisted storefront layout policy and observed synthetic rewards.
src/extensions.rs Merchant catalogue and Wasm extension activation/state.
src/foundation.rs Application dependencies, error responses and request context helpers.
src/history/capability.rs HTTP/MCP parity for history; per-entity read/write scopes are checked again at invocation time.
src/history/mod.rs Uniform tenant-scoped history from transactional database snapshots; restoration delegates to existing domain validators.
src/history/product.rs Rebuild a product edit from an audited snapshot; stock stays current and all associations/media pass normal admission.
src/history/restore.rs Restore snapshots by replaying validated entity edits; financial effects and publication are never copied from historical state.
src/history/routes.rs History summaries are bounded and permission-filtered; full snapshots and restore targets stay inside the owning shop.
src/http_json.rs Bound untrusted provider JSON before allocation/deserialization; connection pooling remains with each existing service owner.
src/http_limits.rs Bounded streaming responses for extension services and payment providers.
src/inference/protocol.rs Self-hosted chat-completions adapter and opt-in provider prompt caching; neither caches private commerce responses.
src/inference/schema.rs Provider wire adaptation for strict fixed-object schemas; dynamic JSON is encoded only on the model wire and restored before domain validation.
src/inference/settings.rs Shared operator settings; AES-GCM secrets are never part of merchant/operator read responses.
src/inference/tests.rs Provider response contracts, strict schemas and truncation rejection.
src/inference.rs Provider adapters. Credentials stay on the server; domain validation is separate.
src/knowledge/embeddings.rs Bounded batched embeddings: Ollama and OpenAI-compatible self-hosted endpoints, model-defined dimensions.
src/knowledge/relations.rs Keep knowledge provenance and relations in the same transaction as canonical commerce data.
src/knowledge/rerank.rs Optional TEI cross-encoder reranking on at most 24 tenant-hydrated texts; malformed or unavailable providers retain fused ordering.
src/knowledge/search.rs Hybrid exact/lexical + dense RRF; hydrate current tenant rows and retrieve only connected evidence.
src/knowledge/vector_cache.rs Bounded, short-lived collection geometry cache; only successful verification is cached.
src/knowledge/vectors.rs Private Qdrant adapter: tenant/model filters, deterministic identities and durable PostgreSQL index queue.
src/knowledge.rs Transactional PostgreSQL knowledge relations and separately indexed Qdrant retrieval.
src/legal/capabilities.rs MCP legal tools delegate to the same ownership/permission-checked HTTP domain handlers.
src/legal/checkout.rs Explicit document/digital acknowledgement and immutable order policy snapshots; transport-neutral checkout guard.
src/legal/consent.rs Cart/channel-bound affirmative choices; stale/expired policy receipts never authorize processing.
src/legal/mod.rs Connected legal/privacy boundary: configuration, consent, checkout snapshots and durable requests.
src/legal/model.rs Bounded multilingual legal configuration; policy changes invalidate optional-purpose consent.
src/legal/product.rs Explicit product safety/sector facts, with market-language fallback; no inference of certifications.
src/legal/requests.rs Durable withdrawal/data-rights intake, tenant-scoped operator review and customer-held receipt access.
src/lib.rs Reusable pricing, context, sandbox, graph and inference modules.
src/localization.rs Shop locale resolution, translated catalog hydration and non-mutating merchant quote.
src/main.rs Process lifetime only. See docs/source-map.md for domain responsibilities.
src/marketing/app_flows.rs App flow dispatch uses the same permission/schema gateway as HTTP/MCP, with a stable job key.
src/marketing/catalog.rs Native condition metadata, app action/event discovery and source-compatible condition import.
src/marketing/channel_access.rs Single admission boundary for Store API, UCP/MCP and hosted storefronts; previews cannot purchase.
src/marketing/channel_preview.rs One-use preview handoff becomes a host-only cookie, bound to current session, membership and channel revision.
src/marketing/channels.rs Sales channels share a merchant tenant but bind independent catalog visibility, locale and cart identity.
src/marketing/condition_gateway.rs Shared rule admission and authoritative context for tax and other native consumers.
src/marketing/customer_facts.rs Customer rule authority is loaded by tenant and stable customer ID, with aggregate history and calendar age.
src/marketing/dependencies.rs Inspect tenant-owned definition references and durable uses before configuration deletion.
src/marketing/facts.rs Assemble private server-owned rule context once per quote/event; never publish customer facts in cart responses.
src/marketing/flow_access.rs Every queued flow step rehydrates current membership; stored definitions never preserve revoked privileges.
src/marketing/flow_actions.rs Native action schema and permissions use original Core names; no arbitrary SQL, shell or unguarded payment transitions.
src/marketing/flow_mutations.rs Local flow mutations journal the effect in the same transaction; customer authority changes revoke existing sessions.
src/marketing/flow_text.rs Shop-language validation and main-language fallback for both simple flows and graphical action nodes.
src/marketing/flows.rs Durable order-event flows: conditions, shop notes and AI proposals; no unapproved model mutations.
src/marketing/gateway.rs MCP automation tools call the same tenant-bound handlers and validators as HTTP; no separate mutation semantics.
src/marketing/jobs.rs Read bounded tenant flow execution summaries without reloading rule/channel configuration on each Studio refresh.
src/marketing/lifecycle.rs Revision-bound deletion and reference admission share HTTP/MCP authorization and tenant locks.
src/marketing/line_facts.rs Rule line facts use immutable priced lines plus current tenant product metadata; protected values override metadata.
src/marketing/metadata.rs Authorized revision-bound source facts for products, customers and orders; secrets and pricing authority are excluded.
src/marketing/mod.rs Native rule conditions, coupons, durable flows and headless/storefront sales-channel boundaries.
src/marketing/pipeline.rs A bounded acyclic flow graph models source-style true/false branches, ordered actions, delays and stop nodes.
src/marketing/pipeline_runtime.rs Durable sequence execution records each action before dispatch, persists delay cursors and reports uncertain effects.
src/marketing/pipeline_tests.rs Flow graph and source action schema regression tests reject unsafe graphs before any event dispatch.
src/marketing/promotions.rs Server-authoritative coupons and automatic campaigns, with deterministic discounts and atomic usage limits.
src/marketing/routes.rs Typed configuration CRUD, rule preview and revision-bound coupon edits.
src/marketing/rule_fields.rs Typed rule fields share the original comparison operators and server-derived checkout/event facts.
src/marketing/rule_match.rs Evaluate typed rule trees against server-owned cart, customer and event facts.
src/marketing/rule_snapshot.rs Resolve only referenced tenant rule IDs with indexed batched reads; freeze active definitions and revisions into the event snapshot.
src/marketing/rule_tests.rs Regression cases for native rule facts and original container boundaries.
src/marketing/rules.rs Bounded Shopware-style boolean/numeric rule AST. Unknown operators/conditions fail closed.
src/mcp/transport.rs MCP visibility and shared read-scope memoization, independent of internal planning tools.
src/mcp.rs Typed MCP schemas and JSON-RPC transport.
src/migrations/schema.rs Append-only ordered migration source catalogue; deployed checksums are never rewritten.
src/migrations.rs Versioned setup is separate from serving; no catalog-wide startup repair.
src/money.rs Exact signed minor-unit amounts with explicit currency scale; legacy Shopware float pricing stays isolated.
src/network_policy.rs Shared DNS destination classification for app HTTP egress and approved SMTP providers.
src/operations/addresses.rs Merchant/MCP address operations use identical customer ownership and revision checks to the Store API.
src/operations/company_logo.rs Tenant-owned logo uploads: bounded decoding, metadata stripping, immutable PNG storage and linked public delivery.
src/operations/company_model.rs Company profile admission, sparse channel inheritance and structured-address print projection.
src/operations/company_public.rs Explicit public legal/brand projection; bank account, domestic tax ID and unlinked uploads remain private.
src/operations/customers.rs Tenant-scoped paged CRM and revision-checked merchant changes; credentials never leave storage.
src/operations/guest_customers.rs Merchant-only guest contact projection; order snapshots never create account authority.
src/operations/master_data.rs Revisioned tenant company basis and sparse channel overrides, serialized with receipt issuance.
src/operations/mod.rs Merchant CRM and fulfillment APIs, shared verbatim with MCP operations capabilities.
src/operations/orders.rs Bounded order search, token-redacted detail and append-only operational notes.
src/operations/receipt_pdf.rs Minimal paginated PDF serializer with WinAnsi Helvetica; snapshot retains complete Unicode originals.
src/operations/receipt_text.rs Four-language document labels and authoritative snapshot-to-print projection.
src/operations/receipts.rs Idempotent immutable invoices/delivery notes with transactional per-shop number ranges.
src/operations/routes.rs HTTP/MCP rights for merchant CRM, fulfillment and company settings.
src/operations/workflow.rs Revision-bound workflow configuration used by installed apps and selective sandbox releases.
src/order_checkout.rs Atomic checkout, stock locks, extension policy and idempotency.
src/order_routes.rs Merchant order read adapter.
src/outbox/control.rs Tenant-authorized quarantine inspection and explicit retry; delivered or retired events cannot be replayed here.
src/outbox/retention.rs Bounded retirement of duplicate delivered payloads; provenance IDs and unsettled app/flow work survive.
src/outbox.rs Durable outbox and audit projection worker.
src/payments/accounts.rs Merchant-authorized onboarding bridge; only authenticated provider responses establish account bindings.
src/payments/app_commands.rs App/Flow/MCP payment actions enqueue core jobs; provider-bound attempts prevent cross-app command authority.
src/payments/contract.rs Versioned app-owned payment methods; declarations never grant financial authority.
src/payments/generic_receipts.rs Provider-neutral receipt admission and atomic allocation; verified evidence owns ledger transitions.
src/payments/mod.rs Provider-independent payment ledger and durable workers; the PayPal adapter supports explicit Sandbox/Live environments.
src/payments/operations.rs Durable idempotent payment commands, customer context binding and serial refund admission.
src/payments/paypal.rs Native PayPal Orders v2 sandbox wire adapter; credentials never enter prompts or browser responses.
src/payments/provider.rs Payment provider identity, tenant account configuration and immutable wire context.
src/payments/provider_configuration.rs Pure startup validation of the native provider origin; no live credentials or provider calls.
src/payments/provider_webhooks.rs Version-pinned HMAC notifications enqueue reconciliation; external event payloads never write monetary state.
src/payments/receipt_guard.rs Bind integer provider receipt amounts and status to the formally checked exact-match predicate.
src/payments/registry.rs Installed payment registry and immutable account/version snapshots; no remote calls inside checkout SQL.
src/payments/remote.rs Dedicated payment RPC, pinned service version and operator-owned egress; never ordinary app-action receipts.
src/payments/return_urls.rs Provider return/cancel URLs preserve the tenant and sales channel; navigation is never payment evidence.
src/payments/routes.rs Customer payment status/capture and merchant refund operations share the durable command API.
src/payments/sessions.rs Customer-bound, short-lived provider UI sessions; iframe messages are never ledger receipts.
src/payments/state.rs One monotonic provider-neutral ledger state machine; evidence validation and authorization stay in receipt adapters.
src/payments/storage.rs Transactional provider receipts and order state updates; external responses cannot invent amounts or tenants.
src/payments/webhooks.rs PayPal verifies webhook signatures before inbox insertion; provider reconciliation confirms monetary state.
src/payments/worker.rs Leased payment jobs; network runs after claim commit, fenced receipts prevent duplicate local effects.
src/performance/access_snapshot.rs One fresh, server-owned admission read shared by domain, identity, availability, channel and proxy middleware.
src/performance/admission.rs Bounded instance/tenant concurrency, durable UTC-day AI quotas, and low-cardinality latency telemetry.
src/performance/cache.rs Bounded weighted LRU for immutable decoded read models; no network I/O under its mutex.
src/performance/cluster_lease.rs Cluster-wide tenant resource leases. DB serialization protects admission; cancellation releases the fenced lease.
src/performance/delivery.rs Native static bypass and bounded HTTP compression; credentials, streams and already encoded bodies stay intact.
src/performance/invalidation.rs Commit-only outbox notifications eagerly evict replica caches; authoritative version probes survive missed events.
src/performance/languages.rs Global language registry is versioned in the same transaction as every registry mutation.
src/performance/mod.rs Shared read-context caching with authoritative versions; mutations and checkout locks stay outside memoization.
src/performance/pool.rs Explicit per-process database budgets and bounded queue waits; invalid deployment values fail fast.
src/performance/row_security.rs Bind each borrowed PostgreSQL connection to task scope, and reject unsafe strict-runtime roles.
src/performance/settings.rs One MVCC snapshot validates base/override UUIDs; warm reads avoid transmitting or decoding JSON.
src/planner.rs Grounded model planning, recorded inputs and proposed changes.
src/platform/ai.rs Operator-only inference administration: optimistic revision, encrypted write-only keys and audit without secrets.
src/platform/auth.rs Independent platform authorization: live personal sessions, current grants, no integration/bootstrap escalation.
src/platform/bootstrap.rs Offline first-operator setup: migration-only process, supplied strong credentials, password proof for existing accounts.
src/platform/infrastructure.rs Live control-plane telemetry: database probes and pool/cache diagnostics, explicit process-only scope.
src/platform/lifecycle.rs Audited, reversible lifecycle; preserved commerce records and current revision prevent accidental overwrites.
src/platform/metrics.rs Aggregate-only control-plane reads: real tenants, bounded pages, explicit currencies and simulated/confirmed amounts.
src/platform/mod.rs Global SaaS control plane: operator-only aggregate statistics and audited shop provisioning.
src/platform/provision.rs Operator shop creation commits ownership, settings and audit atomically; never issues another user's credentials.
src/platform/quotas.rs Operator-only per-shop daily interactive AI limits, optimistic revisions and durable audit.
src/platform/resources.rs Linux container resource readings; unavailable fields stay null on other hosts and the first CPU sample.
src/platform/shop_detail.rs Operator shop dossier: registration, business identity, access roster, channels and measured HTTP activity.
src/pricing.rs Behavioral port of Shopware 6.7.14.2 quantity calculators.
src/proposal_apply.rs Transactional application of approved, revision-bound proposals.
src/proposal_model.rs Typed proposals and validation before persistence or execution.
src/proposal_routes.rs HTTP proposal creation, approval and task listing.
src/request_context.rs Trusted request identity lives in extensions; HTTP headers carry transport inputs only.
src/routes.rs HTTP transport registry; domain behavior lives in dedicated modules.
src/rule_comparison.rs Behavioral port of Shopware 6.7.14.2 RuleComparison::numeric and FloatComparator's exact epsilon boundaries.
src/runtime_config.rs Immutable process configuration, validated once at startup. Mutable shop/provider settings remain in PostgreSQL.
src/sandbox.rs Pure Wasmtime guest execution with bounded resources and no host imports.
src/sandbox_cache.rs Bounded tenant-policy compilation cache. Prepare outside commerce locks; verify the digest under the lock.
src/sandbox_engine.rs One bounded Wasmtime engine per process, with independent fuel and wall-clock interruption.
src/scoped_pool.rs The commerce database executor: transaction-local tenant scope, including direct queries and cancelled streams.
src/security_headers.rs Common browser defenses on successful responses and errors, including reverse-proxy HTTPS deployments.
src/seed.rs Idempotent synthetic template catalogue initialization.
src/shop_domains/frontend_bindings.rs Revisioned aliases point to an existing tenant-owned Experience; origin selection remains operator-only.
src/shop_domains/frontend_editor.rs Operator-owned editor navigation for hosted frontends; no private editor or identity implementation.
src/shop_domains/frontend_transport.rs Stream generic hosted frontend responses and admit only explicitly allowlisted opaque shopper cookies.
src/shop_domains/frontends.rs Generic operator-allowlisted frontend mounts. Host scope is derived from storage, never client headers.
src/shop_domains.rs Resolve configured shop subdomains before authentication; reject unknown hosts and conflicting scopes.
src/staging/assets.rs Binary assets are immutable, staged independently through metadata/digest units; paid entitlements never clone.
src/staging/categories.rs Category release units and dependency-ordered tree publication; stock is never part of a catalog release.
src/staging/clone.rs Clone only catalog/configuration into a private tenant; customer/order/payment state is excluded.
src/staging/company.rs Selective company identity release copies only linked immutable logo bytes and validates the final company aggregate.
src/staging/documents.rs Knowledge documents/chunks clone and publish with their source provenance; publication visibility is a reviewed unit.
src/staging/mod.rs Private cloned shops, scope admission and selective atomic release of reviewed changes.
src/staging/release.rs Selected units publish in one transaction with staged digests and live baseline conflict checks.
src/staging/snapshot.rs Fixed publishable units: product content/translations, settings, experience and app packages.
src/storefront_pages.rs Deep-link HTML transport for stable SKU URLs with optional localized SEO slugs.
src/studio/facts.rs Consolidate dashboard reads without unbounded pool fan-out; preserve the existing API and currency/learning semantics.
src/studio/revenue.rs Merchant turnover remains separated by invoice currency; historical values are never repriced with today's FX.
src/studio.rs Verified merchant overview facts consumed by the chat and activity views.
src/tenant_scope.rs Database lease context: unknown tasks fail closed; trusted workers explicitly retain their scope.
src/translations/apply.rs Apply at most 50 reviewed drafts per request; stale products become conflicts rather than being overwritten.
src/translations/fields.rs Translate only human-readable text; preserve identifiers, URLs, rich structure and source specification keys.
src/translations/mod.rs Tenant-scoped, resumable AI translation drafts; applying is revision checked and emits native product events.
src/translations/routes.rs Authorized translation job creation, progress, paginated drafts and resume/cancel controls.
src/translations/worker.rs One leased product per step: keyset traversal, bounded inference and resumable provider errors.
src/ucp.rs Selected UCP checkout adapters sharing the native cart.
src/verified_kernel.rs Closed, side-effect-free commerce policies extracted to Lean; keep within the checked bool/u64 grammar.
src/work_signal.rs One dedicated LISTEN connection per worker process. Commit notifications are hints; polling repairs lost hints.
src/workers.rs Independently deployable worker roles; leases and durable receipts coordinate replicas.

Studio, storefront, platform and shared frontend

Module Responsibility
frontend/src/admin/agents/AgentsView.tsx AgentsView renders verified shop state and typed user actions.
frontend/src/admin/apps/AppAccess.tsx Explicit consent for digest-bound server callback keys; plaintext is shown once and never persisted in the browser.
frontend/src/admin/apps/AppActivity.tsx API-backed per-app call metadata, storage budgets and explicitly approved durable replay.
frontend/src/admin/apps/AppArtwork.tsx Passive app artwork with independent failed-image fallbacks and deterministic local category covers.
frontend/src/admin/apps/AppConsent.tsx Review the actual package and permission changes before installation; consent is enforced by the API.
frontend/src/admin/apps/AppDetails.tsx AppDetails: Installed app details, activation, version, data and isolated interface.
frontend/src/admin/apps/AppEntity.tsx Managed entity editor renders fields from the installed app contract.
frontend/src/admin/apps/AppInterfaces.tsx Open registered native/isolated admin surfaces through the existing permission-filtered registry.
frontend/src/admin/apps/AppJobArtifact.tsx Completed app exports read the existing tenant asset owner; private files never acquire a public URL.
frontend/src/admin/apps/AppJobs.tsx Long actions use the same app/outbox contract, with progress and explicit uncertain-outcome review.
frontend/src/admin/apps/AppLibrary.tsx Searchable installed/discovery app cards with category/status filters and real lifecycle actions.
frontend/src/admin/apps/AppSecrets.tsx Metadata-only credentials screen; rotation sends plaintext once to the encrypted server store.
frontend/src/admin/apps/AppsManager.tsx Installed package workspace: lifecycle, generated entities and shared agent actions.
frontend/src/admin/apps/ConnectorPanel.tsx Native app workspace: OAuth, provider settings, durable jobs and private sources.
frontend/src/admin/apps/EmailPanel.tsx Native email app settings, localized templates, safe previews and durable delivery receipts.
frontend/src/admin/apps/EmailProviderFields.tsx EmailProviderFields: focused connector-settings view with explicit typed inputs and callbacks.
frontend/src/admin/apps/PaymentManager.tsx Payment ledger, adapter readiness and explicit refund approval.
frontend/src/admin/apps/ProviderAccount.tsx Shared installed-provider onboarding and channel connection controls for merchant Apps and App Studio.
frontend/src/admin/apps/app-types.ts Installed package metadata used by app administration views.
frontend/src/admin/apps/email-languages.ts Supported transactional email template languages.
frontend/src/admin/apps/library-model.ts Shared app discovery metadata, safe artwork sources and localized search independent of rendering.
frontend/src/admin/assistant/MessageText.tsx MessageText keeps merchant interaction separate from workspace orchestration.
frontend/src/admin/assistant/ProposalCard.tsx ProposalCard keeps merchant interaction separate from workspace orchestration.
frontend/src/admin/assistant/SettingsDialog.tsx SettingsDialog keeps merchant interaction separate from workspace orchestration.
frontend/src/admin/assistant/WorkspaceCopilot.tsx Contextual drawer reuses the existing scoped conversation, permissions and proposal execution without unmounting editors.
frontend/src/admin/automation/AutomationDefinitions.tsx Searchable, explicitly editable definitions with visible active state and version.
frontend/src/admin/automation/AutomationDelete.tsx One confirmation and a server recheck; stale versions and used definitions never disappear silently.
frontend/src/admin/automation/AutomationEditor.tsx AutomationEditor: focused form view with explicit typed inputs and callbacks.
frontend/src/admin/automation/AutomationView.tsx Typed merchant rule/campaign/flow/channel forms with exact JSON available for advanced review.
frontend/src/admin/automation/CustomFieldCondition.tsx Typed custom field conditions support text, numeric, Boolean and date values using original field payload names.
frontend/src/admin/automation/FlowActionFields.tsx Focused source action forms expose only supported native parameters; app service dispatch stays in the app gateway.
frontend/src/admin/automation/FlowBuilder.tsx Graphical event → condition tree → action pipeline, including installed app actions.
frontend/src/admin/automation/FlowCanvas.tsx Branching flow canvas edits the actual server graph, including true/false edges, reusable actions and durable delays.
frontend/src/admin/automation/FlowExecution.tsx Actual persisted execution traces show branch decisions, confirmed steps and the scheduled continuation.
frontend/src/admin/automation/FlowInputs.tsx Schema-derived flow parameters; runtime-bound event fields are intentionally supplied by the server.
frontend/src/admin/automation/FlowTopology.tsx Readable connected overview of the persisted graph; selecting a node opens its matching editor card.
frontend/src/admin/automation/JsonField.tsx JSON editing retains incomplete input and invalidates the actual payload instead of silently saving the last valid value.
frontend/src/admin/automation/PromotionSchedule.tsx Campaign scheduling uses ISO instants in the API and local times in the editor.
frontend/src/admin/automation/RuleBuilder.tsx Visual recursive rule tree: AND/OR/NOT groups, typed facts and editable leaf conditions.
frontend/src/admin/automation/SourceRuleFields.tsx Original metadata drives typed condition inputs, including nested source scopes; unsupported runtimes stay visibly disabled.
frontend/src/admin/automation/automation-types.ts Automation editor contracts; content languages come from the selected shop.
frontend/src/admin/automation/lifecycle-i18n.ts Shared lifecycle, starting-process and dependency vocabulary for every automation editor.
frontend/src/admin/automation/pipeline-types.ts Stable graph data mirrors the Rust pipeline contract, with explicit true/false edges and persistent node identifiers.
frontend/src/admin/automation/source-rules.ts Convert source condition nodes for the graphical editor without losing original payload fields.
frontend/src/admin/catalog/AiImageStudio.tsx Optional image-provider jobs create private previews; applying a reviewed image is explicit and revision checked.
frontend/src/admin/catalog/CategoriesWorkspace.tsx Localized category tree editor; parent moves and revisions are validated in the API.
frontend/src/admin/catalog/CategoryFactQuery.tsx One saved predicate on current public evidence; reuses category CAS and the editor's selected content language.
frontend/src/admin/catalog/MediaDropzone.tsx Accessible multi-file upload with drag/drop, visible progress and the same validated asset API as attachments.
frontend/src/admin/catalog/PairFields.tsx Accessible key/value rows for product properties, specifications and variant options.
frontend/src/admin/catalog/ProductAssets.tsx Bounded upload and explicit digest-bound publication of attachments and paid files.
frontend/src/admin/catalog/ProductCurrencyPrices.tsx Exact per-currency decimals live in the same revisioned product draft, including variants.
frontend/src/admin/catalog/ProductDataView.tsx Central catalog workspace: server-filtered cursor list, product details and hierarchical categories.
frontend/src/admin/catalog/ProductEditor.tsx Revision-aware product aggregate editor: one save, translation tabs and product-scoped linked capabilities.
frontend/src/admin/catalog/ProductEditorExtras.tsx Price-tax selection and permission-filtered extension slots attached to the product editor.
frontend/src/admin/catalog/ProductEditorNav.tsx Core product tabs and installed app submenus share one accessible navigation.
frontend/src/admin/catalog/ProductLocalizedContent.tsx Consistent main-language inheritance for product rich documents, specification groups and individual SEO fields.
frontend/src/admin/catalog/ProductMediaWorkspace.tsx One product-media workspace: cover, ordered gallery, multilingual image metadata, drag/drop and optional reviewed AI drafts.
frontend/src/admin/catalog/ProductPanels.tsx Native commerce, media, translated SEO/specifications and category panels for one editable product.
frontend/src/admin/catalog/ProductTextFields.tsx Product text uses the shared single-language editor and field inheritance; product number stays language independent.
frontend/src/admin/catalog/ProductVariants.tsx Native variant family browser with cursor pagination, explicit editing and a bounded creation wizard.
frontend/src/admin/catalog/ReferencePriceFields.tsx Native reference-unit inputs feed the same server-calculated unit price displayed on product pages.
frontend/src/admin/catalog/RelatedProducts.tsx Search-backed related-product selection, avoiding comma-separated opaque IDs.
frontend/src/admin/catalog/ReviewModeration.tsx Product-scoped review publication; authoritative authorization stays in the API.
frontend/src/admin/catalog/TaxClassSelect.tsx Assign a product to an actual tenant tax class; legacy standard/reduced mapping remains explicit.
frontend/src/admin/catalog/VariantGenerator.tsx Reviewable, bounded batch creation uses saved parent data and keeps successful rows on partial failure.
frontend/src/admin/catalog/catalog-model.ts Editable native product aggregate and defaults shared by creation, detail and variant workflows.
frontend/src/admin/catalog/media-model.ts Pure gallery operations preserve order, explicit alt translations and upload bounds without fabricating language values.
frontend/src/admin/catalog/variant-family.ts Cursor-based family lookup for duplicate review, bounded independently of the 50-row creation limit.
frontend/src/admin/catalog/variant-i18n.ts Guided variant creation and editing vocabulary; content still follows shop language inheritance.
frontend/src/admin/catalog/variant-model.ts Bounded option combinations and metadata-free child payloads shared by the guided variant creator.
frontend/src/admin/channels/ChannelActions.tsx Lifecycle actions use shared dependency deletion and one-use preview admission.
frontend/src/admin/channels/ChannelCatalog.tsx Catalog/language controls share the channel schema and content-language fallback.
frontend/src/admin/channels/ChannelConnections.tsx Uses the existing tenant-owned frontend registry, not a parallel domain or Experience store.
frontend/src/admin/channels/ChannelEditor.tsx Guided channel creation/editing reuses the native revisioned API and shared content-language inheritance.
frontend/src/admin/channels/ChannelProducts.tsx Search-based channel product assignment, preserving selected IDs across server-filtered result pages.
frontend/src/admin/channels/ChannelSettings.tsx Channel settings embed existing revision-aware identity and checkout editors with the channel selected.
frontend/src/admin/channels/SalesChannelsWorkspace.tsx Discover and create channels separately from rules; shared settings and independent SaaS shops remain explicit.
frontend/src/admin/channels/channel-i18n.ts Sales-channel onboarding and inherited settings vocabulary in all interface languages.
frontend/src/admin/channels/channel-model.ts Existing sales-channel contract and safe storefront URLs; independent tenants remain a separate concept.
frontend/src/admin/channels/connection-i18n.ts Domain lifecycle copy in every supported Studio language.
frontend/src/admin/customers/CustomersManager.tsx CRM list and editable customer profile with linked order history.
frontend/src/admin/customers/GuestContact.tsx Read-only checkout snapshots distinguish guest contacts from authenticated customer accounts.
frontend/src/admin/dashboard/OverviewView.tsx OverviewView renders verified shop state and typed user actions.
frontend/src/admin/developer/AppActionAccess.tsx Team permissions and MCP visibility are independent from public storefront reads and AI grounding.
frontend/src/admin/developer/AppAgentPanel.tsx Coding agents receive the current Manifest IR and authoritative schema; imported edits round-trip to the canvas.
frontend/src/admin/developer/AppAssistant.tsx Guided app kinds create normal editable manifests; all changes follow private-stage versioning.
frontend/src/admin/developer/AppAutomation.tsx Editable triggers are declared alongside UI and actions; secrets remain operator-managed.
frontend/src/admin/developer/AppCanvas.tsx Accessible click-to-add canvas with selectable blocks and keyboard-accessible ordering controls.
frontend/src/admin/developer/AppCodeBuffer.ts Invalid local expressions block apply and mode changes until corrected; multiple editors report independently.
frontend/src/admin/developer/AppConnections.tsx Route, tool, grounding and Flow Builder switches modify the shared executable manifest directly.
frontend/src/admin/developer/AppContextBinding.tsx Native UI bindings connect the open host object to an indexed app field, never to a global JS context.
frontend/src/admin/developer/AppControlProperties.tsx DataField and one-level container references are edited against the current typed model rather than free text.
frontend/src/admin/developer/AppDataEditor.tsx Managed app models expose typed fields and opt-in public reads; removal cleans dependent bindings.
frontend/src/admin/developer/AppEditorNavigation.tsx Consistent navigation between visual definitions, provider contracts and immutable versions.
frontend/src/admin/developer/AppEvents.tsx Edits the validated subscription/filter/batch contract; delivery uses the existing leased outbox.
frontend/src/admin/developer/AppExpressionEditor.tsx Expressions use typed source text and known form/control references, with a separate JSON editor for agent object ASTs.
frontend/src/admin/developer/AppFieldOptions.tsx Core references and typed choice fields remain owned app data with a single content-language editor.
frontend/src/admin/developer/AppGeometry.tsx F4 presentation properties use one content language; layout values remain bounded grid units.
frontend/src/admin/developer/AppGridCanvas.tsx Drag/drop, snapping, resize and multi-selection share the published app geometry contract.
frontend/src/admin/developer/AppInspector.tsx One content language edits app/view/block metadata; changing bindings updates the actual manifest.
frontend/src/admin/developer/AppInstructionEditor.tsx Block instructions expose schema-aware targets; nested branches are edited recursively under the server's bounded AST contract.
frontend/src/admin/developer/AppLibrary.tsx Saved app cards with explicit editing and recoverable project removal, independent of installed package/data lifecycle.
frontend/src/admin/developer/AppLogicEditor.tsx A code-behind dialog edits one AST through visual blocks, BASIC syntax or agent JSON, then returns it to the manifest compiler.
frontend/src/admin/developer/AppMenuEditor.tsx Menu and injection sites are the existing surfaces, with explicit action allowlists and live role scopes.
frontend/src/admin/developer/AppModelDiagram.tsx Relationships use the same typed field.references contract as the form editor; no separate diagram state or database model.
frontend/src/admin/developer/AppModules.tsx Pure server modules edit the same WIT component contract consumed by quotes and checkout; no browser eval or live service code.
frontend/src/admin/developer/AppOntology.tsx Optional graph mappings edit the canonical manifest; native authorized record lists own the projection.
frontend/src/admin/developer/AppPayments.tsx Visual payment contracts use the same manifest as coding agents; onboarding uses the protected API.
frontend/src/admin/developer/AppSchemaMigrations.tsx Migration plans are explicit versioned agent-readable data, validated by the shared server compiler before any DDL.
frontend/src/admin/developer/AppStudioStatus.tsx Shared status footer keeps validation, persistence and execution feedback beside the designer.
frontend/src/admin/developer/AppVersions.tsx Saved version inspection, digest-approved stage install and conflict-aware package-only live release.
frontend/src/admin/developer/AppViewTabs.tsx Native view navigation and creation are separate from workspace orchestration.
frontend/src/admin/developer/DeveloperView.tsx Visual App Studio orchestrates modular editors over the same executable schema used by coding agents.
frontend/src/admin/developer/DeveloperWorkspace.tsx Dedicated app and API workspaces retain App Studio state while switching the developer console.
frontend/src/admin/developer/SandboxContextPicker.tsx Bounded server search selects an owned object for testing editor-bound apps in a private sandbox.
frontend/src/admin/developer/SandboxPreview.tsx Preview resolves the installed registry first; a newer staged package cannot masquerade as an older build.
frontend/src/admin/developer/api/ApiExplorer.tsx Source-derived static route explorer, runtime app discovery and isolated same-origin read tests.
frontend/src/admin/developer/api/IntegrationKeys.tsx Personal, expiring, least-privilege integration keys; plaintext stays in component memory and is never reloaded.
frontend/src/admin/developer/api/api-i18n.ts Four-language developer API console vocabulary; no credentials are persisted in UI storage.
frontend/src/admin/developer/app-model.ts Pure schema edits preserve unsupported extension properties; compilation binds native UI to real actions.
frontend/src/admin/developer/app-validation.ts Draft validation surfaces bounded manifest errors; authoritative installation remains in Rust.
frontend/src/admin/developer/asset-actions.ts Native asset editors use the existing asset owner; generated actions remain explicit capabilities in the package.
frontend/src/admin/developer/assistant-model.ts Assistants compile to the public manifest contract, with no hidden runtime or provider code.
frontend/src/admin/developer/basic-code.ts Small BASIC-style surface syntax compiles into the same bounded AST as visual and agent edits; no JavaScript execution.
frontend/src/admin/developer/control-model.ts Pure control construction and bounded code-behind discovery keep visual edits and agent manifests identical.
frontend/src/admin/developer/model-workspace.ts Form wizard emits the standard manifest IR; the ordinary compiler supplies all actions, APIs and permission allowlists.
frontend/src/admin/developer/useAppPreview.ts F5/hot reload uses the existing native runtime in an actor-private staging environment, never an immutable build.
frontend/src/admin/developer/useAppStudio.ts Tenant-scoped build lifecycle; immutable saved snapshots gate sandbox previews and selected app-only releases.
frontend/src/admin/developer/useDesignerKeys.ts Designer keyboard shortcuts leave native input and rich-editor undo behavior intact.
frontend/src/admin/developer/useDraftStorage.ts Actor-private server autosaves serialize writes and preserve optimistic revisions across app switches.
frontend/src/admin/environments/EnvironmentManager.tsx Private environment creation and digest-bound selective release.
frontend/src/admin/intelligence/EvidenceReview.tsx Review source-bound candidates through shared HTTP/MCP contracts; changed sources block publication.
frontend/src/admin/intelligence/ExperimentStudio.tsx Immutable experiment designs and lifecycle controls share the core HTTP/MCP owner and current settings rights.
frontend/src/admin/intelligence/ExternalKnowledge.tsx Private connected-app evidence browser shows active-source provenance without exposing it to shoppers.
frontend/src/admin/intelligence/GuardrailSettings.tsx Merchant AI boundaries edit the canonical revisioned commerce settings, never a second policy store.
frontend/src/admin/intelligence/KnowledgeExplorer.tsx Product-centred evidence inspector reads canonical facts and graph relationships beyond overview sampling.
frontend/src/admin/intelligence/KnowledgeFacts.tsx Canonical catalogue facts shown alongside graph evidence; prices and inventory come from current product state.
frontend/src/admin/intelligence/KnowledgeOverview.tsx Whole-shop knowledge census, operational next steps and provenance activity; examples never masquerade as learned facts.
frontend/src/admin/intelligence/KnowledgePreview.tsx No-model evidence preview makes customer/private retrieval boundaries and missing facts inspectable.
frontend/src/admin/intelligence/KnowledgeSources.tsx Searchable cursor source library, guarded lifecycle decisions and single-language source editing.
frontend/src/admin/intelligence/KnowledgeView.tsx Unified knowledge workspace connects sources, product evidence, observations and no-model retrieval previews.
frontend/src/admin/intelligence/MemoryView.tsx Durable co-purchase evidence and revision-bound merchant decisions, with simulation labels and explicit confirmation.
frontend/src/admin/intelligence/SourceEditor.tsx Single-language source editor with inherited fields, product lookup and private-first API/file ingestion.
frontend/src/admin/intelligence/knowledge-types.ts Typed knowledge read models preserve source ownership, revisions, sampling and privacy boundaries.
frontend/src/admin/legal/ConsumerRequests.tsx Permission-scoped consumer request queue and optimistic, recorded review actions.
frontend/src/admin/legal/LegalServices.tsx Purpose inventory and provider disclosures edited in the selected content language.
frontend/src/admin/legal/LegalSettings.tsx Central revisioned legal workspace, inherited channel settings, source-backed sector guidance and request review.
frontend/src/admin/legal/ProductCompliance.tsx Product-owned multilingual regulatory facts; collected evidence never claims automatic product certification.
frontend/src/admin/orders/OrderDetail.tsx Order workspace: server actions, exact-once commands, provider progress and visible event history.
frontend/src/admin/orders/OrderPaymentDelivery.tsx Payment jobs are observed until confirmation. Delivery actions share the server state machine.
frontend/src/admin/orders/OrderWorkflow.tsx Server-owned transitions: one source for permitted actions, labels and business guards.
frontend/src/admin/orders/OrdersManager.tsx Order operations UI. All changes call the same domain endpoints exposed through MCP.
frontend/src/admin/orders/ReceiptPanel.tsx Seller configuration and version-bound receipt creation/download.
frontend/src/admin/preview/PreviewDialog.tsx PreviewDialog keeps merchant interaction separate from workspace orchestration.
frontend/src/admin/preview/PreviewPanel.tsx PreviewPanel renders verified shop state and typed user actions.
frontend/src/admin/settings/CommerceSettings.tsx One revisioned international settings aggregate: drafts survive navigation between countries, taxes, methods and languages.
frontend/src/admin/settings/CompanyField.tsx One factual field with visible channel inheritance, an explicit reset and searchable geographic selection.
frontend/src/admin/settings/CompanyLogo.tsx Private logo preview and bounded upload; attaching/removing is a draft change until the profile is saved.
frontend/src/admin/settings/CompanyTranslations.tsx Brand and legal text use one content-language selector and independent language/channel inheritance.
frontend/src/admin/settings/CountriesSettings.tsx Delivery-country selection and editable catalogue definitions, including tenant-owned subdivisions.
frontend/src/admin/settings/CountryDefinition.tsx Country metadata and subdivision editing with multilingual names; custom definitions cannot invent ISO assignment.
frontend/src/admin/settings/CurrencySettings.tsx Shop currency registry and inherited channel availability. Actions use saved revisions and native job APIs.
frontend/src/admin/settings/CustomerGroupsSettings.tsx Customer groups share the translation/inheritance editor and revisioned settings aggregate.
frontend/src/admin/settings/DestinationRuleEditor.tsx Geographical tax rule editor: country, subdivisions, postcode constraints, date window and persisted Rule Builder condition.
frontend/src/admin/settings/LanguageSettings.tsx Shop main language and enabled locales with resumable provider-backed bulk product translation drafts.
frontend/src/admin/settings/MasterDataSettings.tsx Structured company profile with single-language content, inherited channel scopes, logo drafts and revision-bound saves.
frontend/src/admin/settings/MethodRemoval.tsx Dependency preflight is advisory; aggregate save repeats it under the checkout configuration lock.
frontend/src/admin/settings/MethodSettings.tsx Master/detail shipping and payment configuration, translated content and searchable country availability.
frontend/src/admin/settings/SettingsSaveBar.tsx Consistent settings save feedback, dirty state and permission-aware controls.
frontend/src/admin/settings/SettingsWorkspace.tsx Independent settings workspace: grouped navigation, explicit dirty-draft guards and native API forms.
frontend/src/admin/settings/TaxSettings.tsx Editable tax classes and explicit fallback/country rates with destination rules using native Rule Builder references.
frontend/src/admin/settings/TranslationJobs.tsx Start catalogue translations, poll durable progress, review paginated drafts and apply bounded revision-checked batches.
frontend/src/admin/settings/company-types.ts Typed company metadata and sparse per-channel inheritance contract; statutory facts are never auto-translated.
frontend/src/admin/settings/useCompanyContext.ts Load enabled content languages, countries and channel choices without overwriting an edited draft on locale refresh.
frontend/src/admin/settings/useSettingsDraft.ts Revisioned settings drafts survive locale refreshes, reject late loads and keep failed saves editable.
frontend/src/admin/shell/Merchant.tsx Studio composition root: layout, scoped controller and modular workspace views.
frontend/src/admin/shell/StudioComposer.tsx StudioComposer: focused Studio view; state and commands come from the session-scoped controller.
frontend/src/admin/shell/StudioContext.ts Typed, local Studio context; never shared across a different mounted Studio.
frontend/src/admin/shell/StudioConversation.tsx StudioConversation: focused Studio view; state and commands come from the session-scoped controller.
frontend/src/admin/shell/StudioHeader.tsx StudioHeader: focused Studio view; state and commands come from the session-scoped controller.
frontend/src/admin/shell/StudioRoutes.tsx StudioRoutes: focused Studio view; state and commands come from the session-scoped controller.
frontend/src/admin/shell/StudioSidebar.tsx StudioSidebar: focused Studio view; state and commands come from the session-scoped controller.
frontend/src/admin/shell/StudioSignIn.tsx Dedicated login page and blocking reauthentication dialog preserve mounted private editors.
frontend/src/admin/shell/navigation.ts Typed built-in Studio navigation and locale-specific labels.
frontend/src/admin/shell/requests.ts Authenticated Studio transport; staging changes only the tenant, never the principal.
frontend/src/admin/shell/studio-types.ts studio types: Studio layout, session/workspace controller, authenticated transport and lazy workspace navigation.
frontend/src/admin/shell/useEntityNavigation.ts Linked entity navigation keeps native editors, browser deep links and back paths in the same tenant scope.
frontend/src/admin/shell/useServerHealth.ts Public server health is independent of the personal Studio session.
frontend/src/admin/shell/useStudioAccess.ts Central Studio identity boundary: initial login, expiry suspension and same-account resume.
frontend/src/admin/shell/useStudioController.ts Studio session/controller: authentication context, tenant/staging state and chat commands.
frontend/src/admin/shell/useStudioSession.ts Revalidate visible Studio sessions and route authenticated failures to the active controller.
frontend/src/admin/storyfronts/StoryfrontConnections.tsx Shared passive navigation from Apps and Storyfronts to the same authorized original editor.
frontend/src/admin/storyfronts/StoryfrontView.tsx Discover the actual tenant-bound hosted frontends; keep the optional legacy app connector separate.
frontend/src/admin/storyfronts/storyfront-i18n.ts Four-language navigation copy; mounted frontends are connections, not proof of publication.
frontend/src/admin/storyfronts/storyfront-model.ts Passive operator URLs contain no browser credential; the destination editor authorizes its own owner.
frontend/src/admin/styles/api-console.css Responsive developer key management and bounded API explorer using Studio theme tokens.
frontend/src/admin/styles/app-artwork.css Category cover and app icon artwork, with local deterministic fallbacks.
frontend/src/admin/styles/app-assistant.css Guided extension workspace: restrained colour, clear choices and responsive setup.
frontend/src/admin/styles/app-catalog.css App library/detail presentation: bounded cards, passive artwork, accessible filters and theme-aware forms.
frontend/src/admin/styles/app-detail.css Scoped app detail hierarchy, permission disclosure, data and integration forms.
frontend/src/admin/styles/app-library.css App callback consent follows the same card and field rhythm as app configuration.
frontend/src/admin/styles/app-studio-inspector.css App Studio binding indicators, empty canvas and properties inspector.
frontend/src/admin/styles/app-studio-panels.css App Studio model, connection, agent and version panels.
frontend/src/admin/styles/app-studio-responsive.css Responsive App Studio layouts and reduced-motion settings.
frontend/src/admin/styles/app-studio.css App Studio: restrained light canvas, compact control density and responsive palette/inspector workspaces.
frontend/src/admin/styles/automation-lifecycle.css Configuration workspace: readable definitions, clear selection and contextual actions.
frontend/src/admin/styles/automation.css Actual graph nodes and original rule forms use the Studio theme and independent responsive columns.
frontend/src/admin/styles/catalog-editor.css Visual editor and category workspace responsive styles.
frontend/src/admin/styles/catalog.css Light, precise catalog workspace with accessible tables, focused detail panels and visual authoring.
frontend/src/admin/styles/commerce-manager.css commerce manager: Studio visual system and merchant operational layouts.
frontend/src/admin/styles/company-settings.css Company editor: structured addresses, visible scope inheritance and compact upload controls.
frontend/src/admin/styles/forms.css Studio-owned form primitives load at the composition root, independent of lazy workspace history.
frontend/src/admin/styles/international-details.css Destination rates, translation jobs and responsive international workbench layout.
frontend/src/admin/styles/international.css International commerce workbench: compact master/detail records, calm colour and clear field hierarchy.
frontend/src/admin/styles/knowledge-evidence.css Product evidence, retrieval excerpts, observed pairs and responsive knowledge layouts.
frontend/src/admin/styles/knowledge-sources.css Knowledge source library/editor layouts: single-language forms and lifecycle controls.
frontend/src/admin/styles/knowledge.css Unified knowledge workspace: evidence-first hierarchy, accessible cards and theme-aware responsive layouts.
frontend/src/admin/styles/legal-settings.css Light legal workspace: compact readiness, sector chips, linked sources and single-language editors.
frontend/src/admin/styles/media-workspace.css Gallery workspace: airy tiles, focused image inspector and accessible upload surfaces using Studio theme tokens.
frontend/src/admin/styles/operations.css Operational screens share the studio's light surface and clear focus states.
frontend/src/admin/styles/provider-account.css Shared provider onboarding layout works independently of the lazy-loaded visual App Studio.
frontend/src/admin/styles/sales-channels.css Sales-channel cards, onboarding and scoped settings use the same responsive, accessible Studio design.
frontend/src/admin/styles/settings.css Independent settings navigation, grouped native forms and save feedback in Studio theme tokens.
frontend/src/admin/styles/storyfronts.css Tenant-bound Experience cards share Studio tokens and keep long hostnames inside mobile columns.
frontend/src/admin/styles/studio/01-studio.css studio: studio styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/02-workspace-switch.css studio: workspace-switch styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/03-welcome-symbol.css studio: welcome-symbol styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/04-review-product-div.css studio: review-product-div styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/05-page-intro-p.css studio: page-intro-p styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/06-knowledge-stats-strong.css studio: knowledge-stats-strong styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/07-connection-card.css studio: connection-card styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/08-responsive.css studio: responsive styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/09-responsive.css studio: responsive styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio/10-studio-mobile-preview-button.css studio: studio-mobile-preview-button styles. Source order is preserved by the entry stylesheet.
frontend/src/admin/styles/studio-sign-in.css Dedicated access surface: responsive Vendune login and native modal reauthentication.
frontend/src/admin/styles/studio.css Ordered studio stylesheet entry; domain rules live in the adjacent folder.
frontend/src/admin/styles/variants.css Variant family and review table share the catalog's responsive theme and focus treatment.
frontend/src/admin/styles/workspace-copilot.css Contextual assistant drawer inherits Studio tokens and contains the existing conversation on all viewport sizes.
frontend/src/admin/styles/workspace-polish.css Consistent Studio density, readable hierarchy and independently scrollable navigation across workspaces.
frontend/src/admin/team/AccessManager.tsx Fine-grained team overrides, revocable invitations and personal session inventory.
frontend/src/admin/team/PersonalAccountForm.tsx PersonalAccountForm: focused account-form view with explicit typed inputs and callbacks.
frontend/src/admin/team/UsersManager.tsx Users Manager: Personal accounts, memberships, roles, invitations and scoped developer access..
frontend/src/application/ApplicationRouter.tsx Select independent lazy applications; contain failed imports and reset boundaries on navigation.
frontend/src/main.tsx Browser bootstrap only; application selection and error recovery live in application/.
frontend/src/platform/AdminHub.tsx Public service directory. Links select a login surface without granting operator or merchant permissions.
frontend/src/platform/HTTPResponses.tsx Exact HTTP outcomes; historical undifferentiated totals never become fabricated success rates.
frontend/src/platform/PlatformAI.tsx Central inference editor; write-only secrets, optimistic revisions and explicit environment fallback.
frontend/src/platform/PlatformConsole.tsx Independent platform control plane: personal operator access, bounded statistics and audited shop creation.
frontend/src/platform/PlatformDashboard.tsx Aggregate statistics from PostgreSQL; recorded orders and confirmed money remain visibly separate.
frontend/src/platform/PlatformInfrastructure.tsx Real infrastructure probes, bounded lifetime traffic and process-local resource counters.
frontend/src/platform/PlatformLanguage.tsx Locale selector shared by operator sign-in and the workspace.
frontend/src/platform/PlatformShopDetail.tsx Connected shop dossier and reversible lifecycle controls; confirmations are explicit and revision guarded.
frontend/src/platform/PlatformShops.tsx Searchable shop directory and server-validated provisioning form.
frontend/src/platform/PlatformSignIn.tsx Personal sign-in verifies the current operator grant before retaining a browser session.
frontend/src/platform/platform-api.ts Tenant-independent operator API; credentials stay in the current browser session.
frontend/src/platform/styles/platform/01-platform-console.css platform: platform-console styles. Source order is preserved by the entry stylesheet.
frontend/src/platform/styles/platform/02-platform-shop-stats-span.css platform: platform-shop-stats-span styles. Source order is preserved by the entry stylesheet.
frontend/src/platform/styles/platform/03-control.css Service hub and operational editors share the same accessible light workspace.
frontend/src/platform/styles/platform.css Ordered platform stylesheet entry; domain rules live in the adjacent folder.
frontend/src/shared/api/agent-stream.ts Decode bounded UTF-8 SSE chat frames; only a completed native result reaches the existing Studio state owner.
frontend/src/shared/api/download.ts Authenticated binary download, never placing session credentials in a URL.
frontend/src/shared/api/merchant-session.ts Private merchant-session rejection signals shared by all JSON transports.
frontend/src/shared/api/request-json.ts Coalesce simultaneous identical core reads with complete identity; no persisted response cache.
frontend/src/shared/api/shop-api.ts shop api: Typed commerce contracts, merchant/store transports and binary download helper.
frontend/src/shared/api/shop-scope.ts Canonical shop hosts; Studio identity remains on the shared origin. Reserved service hosts never become tenant IDs.
frontend/src/shared/api/types.ts Common JSON/multipart request contract for app surfaces and merchant operations.
frontend/src/shared/apps/AppFrame.tsx Opaque-origin app UI. Its SDK can invoke only this app's declared, server-authorized actions.
frontend/src/shared/apps/AppSlot.tsx Generic registered product configuration slot. App packages own labels, input names and business rules.
frontend/src/shared/apps/AppSurfaces.tsx One registry read per workspace; app bundles load only when their surface is mounted.
frontend/src/shared/apps/native/NativeAppView.tsx The same React renderer powers design preview, private sandbox, released admin modules and storefront surfaces.
frontend/src/shared/apps/native/NativeAssetField.tsx Searchable tenant-owned files with private image preview and contextual multipart upload; no raw asset IDs need to be typed.
frontend/src/shared/apps/native/NativeBlocks.tsx All native controls render from the same validated manifest, including one-level containers and code-behind buttons.
frontend/src/shared/apps/native/NativeControl.tsx Typed VB-style controls read app records; edits stay local until an explicitly bound gateway action runs.
frontend/src/shared/apps/native/NativeDataBlock.tsx One bounded keyset page per mounted data block; action requests remain tenant- and permission-scoped.
frontend/src/shared/apps/native/NativeField.tsx One typed field editor for native forms; rich text uses the product editor and configured language inheritance.
frontend/src/shared/apps/native/NativeRecordForm.tsx Native managed-record form retains revisions and inherited translations; it never executes schema code.
frontend/src/shared/apps/native/NativeRelationField.tsx Related records load only through actions already granted to the current surface; no merchant-token side route.
frontend/src/shared/apps/native/NativeRuntime.tsx Native controls share one local execution context; form records and gateway calls remain scoped by their existing owners.
frontend/src/shared/apps/native/geometry.ts The twelve-column layout is the same manifest geometry for the designer and published renderer.
frontend/src/shared/apps/native/logic.ts Bounded AST interpreter; no eval, globals, arbitrary URLs or implicit gateway permissions.
frontend/src/shared/apps/native/types.ts The versioned Manifest is the shared intermediate representation for visual and agent edits.
frontend/src/shared/apps/useSurfaceGateway.ts Bind native and isolated UI actions to the same short-lived server grant; credentials stay in the host.
frontend/src/shared/content/RichDescription.tsx Safe rich blocks with native image/video rendering; no HTML interpretation or script execution.
frontend/src/shared/content/editor/EditorBuffer.ts Unsaved Markdown source participates in the aggregate's save/navigation guard without becoming product content.
frontend/src/shared/content/editor/MarkdownSource.tsx Live Markdown buffer updates the same structured product document; no raw HTML is rendered or persisted.
frontend/src/shared/content/editor/RichEditor.tsx Actual Tiptap WYSIWYG editor with structured safe content, media, formatting and per-language drafts.
frontend/src/shared/content/editor/editor-document.ts Canonical transport drops editor-only null attributes; description headings remain within the native H2/H3 contract.
frontend/src/shared/content/editor/editor-i18n.ts Four-language controls for visual/Markdown editing without changing content-language inheritance.
frontend/src/shared/content/editor/markdown-content.ts Markdown admission shares the public rich-document node/URL boundary; rich-only features never silently disappear.
frontend/src/shared/content/editor/rich-conversion.ts Lossless import of legacy blocks into structured WYSIWYG content, preserving inline emphasis.
frontend/src/shared/content/rich-document.tsx Safe structured editor rendering. Only known nodes/marks produce elements; URLs are never executable.
frontend/src/shared/customer/AddressBook.tsx Tenant-owned address cards, defaults and revision-aware CRUD shared by account and CRM.
frontend/src/shared/customer/AddressCard.tsx Human-readable address used in order snapshots and address books.
frontend/src/shared/customer/AddressFields.tsx Structured accessible address editor; no hidden JSON or storefront-only duplicate model.
frontend/src/shared/customer/CustomerFields.tsx Contact fields mirror the account API while access, identity and pricing remain separate.
frontend/src/shared/customer/GoogleAddressSearch.tsx Opt-in Places widget fills editable address fields, rejects unsupported destinations and ignores stale replies.
frontend/src/shared/customer/customer-types.ts Shared customer/address contracts; merchant and customer sessions use distinct request adapters.
frontend/src/shared/customer/google-address.ts Google Places adapter: lazy public browser key, bounded loader and international address mapping.
frontend/src/shared/geography/CountryPicker.tsx Locale-aware world catalogue adapter for the shared searchable entity picker.
frontend/src/shared/geography/EntityPicker.tsx Accessible searchable country/region combobox; chips and group actions replace checkbox walls.
frontend/src/shared/geography/TranslationFields.tsx Shared single-language fields for configurable object content; per-field null restores main-language inheritance.
frontend/src/shared/geography/geography-types.ts World catalogue and tenant destination tax contracts; no inferred tax law.
frontend/src/shared/geography/geography.css Shared country and region search: Studio and checkout use the same accessible controls.
frontend/src/shared/geography/useCountryCatalogue.ts Request-scoped geography loading; stale requests cannot move country definitions across shops or sandboxes.
frontend/src/shared/history/EntityHistory.tsx On-demand entity history, field comparisons and explicitly confirmed revision-checked restoration.
frontend/src/shared/history/history-model.ts Bounded structural changes for database snapshots; no HTML from historical content is executed.
frontend/src/shared/history/history.css Shared history deliberately stays secondary to editing and loads only when opened.
frontend/src/shared/i18n/ContentLanguage.tsx One content-language selection per editor, distinct from interface language; no writes on selection or fallback.
frontend/src/shared/i18n/ContentLanguagePicker.tsx Compact shared language switcher with explicit main-language context; selection never changes persisted content.
frontend/src/shared/i18n/LocalizedField.tsx Single visible field for the editor's language, with main-language preview and explicit restore-to-inheritance.
frontend/src/shared/i18n/account-i18n.ts Customer account vocabulary: one complete EN/DE/FR/ES contract for authentication and purchase care.
frontend/src/shared/i18n/app-access-i18n.ts Explicit app callback consent and short-lived key management vocabulary.
frontend/src/shared/i18n/app-assistant-i18n.ts App assistants and extension permissions use the same EN/DE/FR/ES vocabulary.
frontend/src/shared/i18n/app-events-i18n.ts Subscription/filter/delivery vocabulary shared by Studio and coding agents.
frontend/src/shared/i18n/app-i18n.ts App and evidence UI vocabulary, shared by store, merchant and payment components.
frontend/src/shared/i18n/app-library-i18n.ts App library vocabulary and built-in summaries; no inferred connection or payment readiness.
frontend/src/shared/i18n/app-logic-i18n.ts Designer controls, code-behind and debugger vocabulary ships in every bundled interface language.
frontend/src/shared/i18n/app-ontology-i18n.ts Native app graph mapping controls share the Studio vocabulary and four interface languages.
frontend/src/shared/i18n/app-operations-i18n.ts App operational vocabulary shared by installed apps and developer diagnostics; EN/DE/FR/ES.
frontend/src/shared/i18n/app-studio-i18n.ts App Studio and native runtime vocabulary; every key ships EN/DE/FR/ES.
frontend/src/shared/i18n/automation-fields.ts Localized labels for original rule and native flow parameter fields.
frontend/src/shared/i18n/automation-i18n.ts Four-language automation editor vocabulary keeps source identifiers stable and user labels readable.
frontend/src/shared/i18n/automation-labels.ts Source-named rule labels are localized independently from their stable integration identifiers.
frontend/src/shared/i18n/catalog-i18n.ts Complete four-language catalog workspace vocabulary, separate from commerce data translations.
frontend/src/shared/i18n/checkout-i18n.ts Checkout vocabulary: the same purchase and payment states in every supported UI language.
frontend/src/shared/i18n/cognitive-events-i18n.ts Typed labels shared by the knowledge timeline and the native Flow Builder event catalogue.
frontend/src/shared/i18n/company-i18n.ts Company identity, field inheritance and legal storefront vocabulary in four interface languages.
frontend/src/shared/i18n/connected-i18n.ts Four-language vocabulary for connected apps, consent and visual automation.
frontend/src/shared/i18n/content-language.ts Resolve editable translation keys without merging distinct regional locales or fabricating inherited values.
frontend/src/shared/i18n/control-i18n.ts Complete vocabulary for the platform control plane and service hub. Technical provider/service IDs stay stable.
frontend/src/shared/i18n/crm-i18n.ts Complete CRM/history vocabulary shared by settings, customer account and entity editors.
frontend/src/shared/i18n/currency-i18n.ts Complete currency settings vocabulary, shared by storefront and channel editors.
frontend/src/shared/i18n/customer-i18n.ts Account and address labels share four complete locales across storefront and studio.
frontend/src/shared/i18n/email-i18n.ts Complete mail workspace vocabulary in English, German, French and Spanish.
frontend/src/shared/i18n/errors-i18n.ts Localized request guidance across all transports; original diagnostics remain available to developer tools.
frontend/src/shared/i18n/experience-ui-i18n.ts Shared four-language interaction vocabulary for contextual Studio help and storefront discovery.
frontend/src/shared/i18n/experiment-i18n.ts Controlled-experiment vocabulary distinguishes observed cash from causal and margin claims.
frontend/src/shared/i18n/graph-navigation-i18n.ts Saved fact navigation vocabulary; content terms use the editor's shared language inheritance.
frontend/src/shared/i18n/guardrail-i18n.ts Typed four-language merchant AI policy vocabulary.
frontend/src/shared/i18n/i18n.tsx i18n: Four-language locale context, UI dictionaries and translated API errors.
frontend/src/shared/i18n/international-i18n.ts International settings vocabulary. Every key requires English, German, French and Spanish.
frontend/src/shared/i18n/knowledge-i18n.ts Knowledge workspace vocabulary: sources, evidence and capabilities without fabricated learning claims.
frontend/src/shared/i18n/legal-i18n.ts Complete EN/DE/FR/ES legal workspace and storefront vocabulary; documents use shop content languages.
frontend/src/shared/i18n/locales/de.ts Merchant interface strings: de.
frontend/src/shared/i18n/locales/en.ts Merchant interface strings: en.
frontend/src/shared/i18n/locales/es.ts Merchant interface strings: es.
frontend/src/shared/i18n/locales/fr.ts Merchant interface strings: fr.
frontend/src/shared/i18n/locales/shop-de.ts Storefront and operational interface strings: de.
frontend/src/shared/i18n/locales/shop-en.ts Storefront and operational interface strings: en.
frontend/src/shared/i18n/locales/shop-es.ts Storefront and operational interface strings: es.
frontend/src/shared/i18n/locales/shop-fr.ts Storefront and operational interface strings: fr.
frontend/src/shared/i18n/operations-i18n.ts Operational commerce labels in all supported languages.
frontend/src/shared/i18n/payment-provider-i18n.ts Payment contract editor and account onboarding vocabulary.
frontend/src/shared/i18n/platform-i18n.ts Operator console translations. Every visible control has an explicit translation in all supported locales.
frontend/src/shared/i18n/preference-i18n.ts Consent-bound private shopping-memory controls use typed interface text, separate from merchant product facts.
frontend/src/shared/i18n/product-legal-i18n.ts Product safety and sector facts in EN/DE/FR/ES; values follow the shared content-language inheritance.
frontend/src/shared/i18n/shop-i18n.ts Shared shop text hook; dictionaries live in focused locale files.
frontend/src/shared/i18n/studio-ui-i18n.ts Studio navigation and settings guidance in all four supported interface languages.
frontend/src/shared/i18n/workbench-i18n.ts Complete four-language vocabulary for environments, developer tools and knowledge ingestion.
frontend/src/shared/i18n/workspace-i18n.ts Settings scopes, dependency confirmation and media workspace vocabulary in every supported interface language.
frontend/src/shared/legal/ExternalVideo.tsx Optional external video is not contacted until the same shop privacy choice allows it.
frontend/src/shared/legal/consent-store.ts Live consent registry starts denied; only validated server receipts unlock integrations. No legacy grant is trusted.
frontend/src/shared/legal/legal-types.ts Channel-scoped legal policy, explicit optional purposes and durable consumer requests.
frontend/src/shared/legal/requirements.ts Source-backed requirement catalogue; operational applicability is reviewed, never inferred as legal certification.
frontend/src/shared/money/fx-draft.ts Draft-only FX preview matches the server rational/half-up boundary; checkout always uses its server quote.
frontend/src/shared/styles/app-surfaces.css app surfaces: Shared customer, app and workbench styles; application workspaces must not import each other..
frontend/src/shared/styles/apps.css apps: Shared customer, app and workbench styles; application workspaces must not import each other..
frontend/src/shared/styles/currencies.css Currency cards use the Studio form grid, keyboard targets and responsive layouts.
frontend/src/shared/styles/customers.css Shared light account/address workspace, responsive and keyboard-accessible.
frontend/src/shared/styles/markdown-editor.css Shared visual/Markdown product editor treatment using existing Studio theme tokens.
frontend/src/shared/styles/native-app.css Native app layouts share commerce design tokens; tables/forms remain bounded and responsive.
frontend/src/shared/styles/workbench.css Merchant workbench uses the studio's light-blue design tokens and responsive review panels.
frontend/src/shared/ui/Brand.tsx Shared Vendune identity; product branding is independent of tenant-owned company logos and session keys.
frontend/src/shared/ui/ConfirmDialog.tsx Shared modal confirmation with focus containment, Escape, focus restoration and an explicit destructive action.
frontend/src/shared/ui/Icon.tsx Icon: Presentational icons and catalogue artwork with explicit inputs..
frontend/src/shared/ui/ProductArt.tsx Product Art: Presentational icons and catalogue artwork with explicit inputs..
frontend/src/shared/ui/WorkspaceBoundary.tsx Contain a workspace render failure and let the user retry without losing the application shell.
frontend/src/shared/ui/brand.css Shared vector brand sizing and typography for Studio and the operator console.
frontend/src/shared/ui/confirm-dialog.css Modal surface shared by settings, media and future destructive actions.
frontend/src/storefront/account/AccountDownloads.tsx Paid download entitlements are fetched by the server and retrieved with customer headers, never URL tokens.
frontend/src/storefront/account/AccountOrderDetail.tsx Purchase detail uses immutable addresses, current fulfillment, issued PDFs and paid order entitlements.
frontend/src/storefront/account/AccountOrderList.tsx Clickable purchase cards show the live server status and lead to a protected order detail.
frontend/src/storefront/account/AccountOverview.tsx Account home connects recent purchases and default addresses to their dedicated management views.
frontend/src/storefront/account/AccountProfile.tsx Focused profile and password forms report persistence and keep account identity outside editable contact data.
frontend/src/storefront/account/CustomerAccount.tsx Responsive customer workspace separates authentication, address care and protected purchase details.
frontend/src/storefront/account/CustomerSignIn.tsx Distinct sign-in and registration forms with correct autofill and an authenticated, rotated cart context.
frontend/src/storefront/account/ShoppingPreferences.tsx Optional cart-private memory uses native consent, revisioned graph storage and explicit AI-sharing preference.
frontend/src/storefront/account/account-fields.css Account form controls have explicit label spacing, consistent actions and shared address-editor integration.
frontend/src/storefront/account/account-polish.css Brand-aware account presentation with a separate orientation panel and bounded, scrollable forms.
frontend/src/storefront/account/account-purchases.css Purchase cards, fulfillment, documents and financial detail use one readable account layout.
frontend/src/storefront/account/account-types.ts Shopper-only account responses deliberately exclude cart/session credentials and internal order activity.
frontend/src/storefront/account/account.css Customer workspace: quiet fashion palette, clear purchase cards and an accessible mobile sheet.
frontend/src/storefront/account/useCustomerAccount.ts Tenant-scoped account loading and mutation lifecycle; expired sessions clear private data and reopen sign-in.
frontend/src/storefront/analytics/ShopAnalytics.tsx Customer consent and real GA4 ecommerce events; absent apps produce no external script.
frontend/src/storefront/catalog/ImagePlaceholder.tsx Honest empty-media state for newly created products; never invent a product photograph.
frontend/src/storefront/catalog/MemoryRecommendations.tsx Public consumer of merchant-approved learned associations, hydrated with current product state.
frontend/src/storefront/catalog/ProductAttachments.tsx Public attachment list follows the active storefront tenant and channel; private downloads are never listed.
frontend/src/storefront/catalog/ProductPage.tsx Product family, gallery, context pricing and moderated customer reviews.
frontend/src/storefront/catalog/ProductPurchase.tsx ProductPurchase: focused pdp-purchase view with explicit typed inputs and callbacks.
frontend/src/storefront/catalog/ProductQuestion.tsx Read-only product questions cite only tenant-owned, explicitly published source documents.
frontend/src/storefront/catalog/ProductReviews.tsx ProductReviews: focused pdp-reviews view with explicit typed inputs and callbacks.
frontend/src/storefront/catalog/product-url.ts Stable, collision-free product addresses: SKU identity plus the inherited localized SEO slug.
frontend/src/storefront/checkout/CheckoutDetails.tsx Address book, guest contact and delivery/payment selection share the authoritative cart context API.
frontend/src/storefront/checkout/CheckoutIdentity.tsx Inline guest/login/registration step rotates the cart on authentication and refreshes owning defaults.
frontend/src/storefront/checkout/CheckoutMethods.tsx Method cards keep delivery and payment discoverable without concealing country restrictions.
frontend/src/storefront/checkout/CheckoutPanel.tsx One-page checkout: server-reviewed selection, explicit purchase and durable provider handoff.
frontend/src/storefront/checkout/CheckoutProgress.tsx Readable checkout progress reflects reviewed server state; it never implies payment confirmation.
frontend/src/storefront/checkout/CheckoutPurchase.tsx Shared explicit purchase button: mobile dock and desktop review use the same form and server-review state.
frontend/src/storefront/checkout/CheckoutSummary.tsx Sticky order review presents authoritative totals and discounts beside the purchase action.
frontend/src/storefront/checkout/EmbeddedPayment.tsx A scoped provider frame receives a short-lived token; messages only trigger server reconciliation.
frontend/src/storefront/checkout/OrderCompletion.tsx Dedicated completion page renders the accepted order snapshot and honest provider state, with no ID-only reads.
frontend/src/storefront/checkout/OrderConfetti.tsx Finite CSS celebration after an accepted order; no timers, libraries or motion for reduced-motion users.
frontend/src/storefront/checkout/PaymentSession.tsx Provider handoff and bounded durable-status polling; only verified server receipts confirm payment.
frontend/src/storefront/checkout/checkout-order.ts Bind the purchase to the reviewed cart and total; the server remains the pricing authority.
frontend/src/storefront/checkout/embedded-checkout.ts Only the registered embedding storefront receives the shopper cart receipt capability; it verifies with Core.
frontend/src/storefront/legal/CheckoutLegal.tsx Current legal-document links and separate non-prechecked digital performance acknowledgement.
frontend/src/storefront/legal/ConsumerRequestForm.tsx Public two-step declaration with immutable downloadable receipt; references never expose order data.
frontend/src/storefront/legal/LegalDocument.tsx Published legal text uses selected content language/main-language inheritance; empty content is visible as missing.
frontend/src/storefront/legal/PrivacyProvider.tsx Unified affirmative consent: server-validated receipt, channel boundaries, expiry and policy revalidation.
frontend/src/storefront/legal/ProductSafety.tsx Explicit PDP safety/sector facts; no generated warning, certification or origin is invented.
frontend/src/storefront/shell/CatalogNavigation.tsx Public category navigation uses the same tenant/channel tree as the listing API, with translated names.
frontend/src/storefront/shell/ChannelPreview.tsx Explain the server-authorized, session-bound preview and clear its HttpOnly cookie on exit.
frontend/src/storefront/shell/CollectionView.tsx CollectionView: storefront view composed from the scoped cart/controller.
frontend/src/storefront/shell/CompanyLegalPage.tsx Directly reachable channel legal page; renders only the server's explicit public projection as text.
frontend/src/storefront/shell/ConciergeView.tsx ConciergeView: storefront view composed from the scoped cart/controller.
frontend/src/storefront/shell/Storefront.tsx Storefront composition root: cart context, routes, customer account and checkout.
frontend/src/storefront/shell/StorefrontContext.ts Local storefront context, scoped to the mounted tenant and sales channel.
frontend/src/storefront/shell/StorefrontCurrency.tsx Currency switching is a revision-bound server re-quote, scoped to tenant and sales channel.
frontend/src/storefront/shell/StorefrontHeader.tsx StorefrontHeader: storefront view composed from the scoped cart/controller.
frontend/src/storefront/shell/StorefrontHome.tsx StorefrontHome: storefront view composed from the scoped cart/controller.
frontend/src/storefront/shell/StorefrontLanguage.tsx Shop-configured content languages, including custom locales; the interface keeps its supported language vocabulary.
frontend/src/storefront/shell/cart-commands.ts Revision-bound quantity update, preserving SKU minimum and server pricing authority.
frontend/src/storefront/shell/channel-preview-i18n.ts Personal preview copy in every supported language; exported through the shared translation catalogue.
frontend/src/storefront/shell/useCatalog.ts Cursor catalogue loading, debounced filters and stale-response protection.
frontend/src/storefront/shell/useCompanyIdentity.ts Channel-scoped public brand/legal identity; stale responses cannot leak across tenants or languages.
frontend/src/storefront/shell/useConsentedExperience.ts Assign experiments only after current personalization consent; discard stale responses on withdrawal.
frontend/src/storefront/shell/usePersonalization.ts Opt-in behavior signals and stable product ordering; no authoritative prices are changed.
frontend/src/storefront/shell/useStorefrontAnchors.ts Restore native section navigation after SPA rendering, with cancellation and reduced-motion support.
frontend/src/storefront/shell/useStorefrontController.ts Cart lifecycle, authoritative checkout commands and storefront coordination.
frontend/src/storefront/styles/checkout-fields.css Checkout-owned form layout, independent of previously mounted account/admin stylesheets.
frontend/src/storefront/styles/checkout.css One-page checkout: calm responsive workspace with a sticky, readable order review.
frontend/src/storefront/styles/company-identity.css Public company branding and readable legal identity across storefront channels.
frontend/src/storefront/styles/experience-polish.css Shared storefront interaction layer: stable navigation, editorial surfaces and catalogue-grounded AI discovery.
frontend/src/storefront/styles/legal.css Responsive, equally weighted consent controls and readable legal/customer forms.
frontend/src/storefront/styles/order-completion.css Order receipt page and finite transform-only celebration; honors reduced motion.
frontend/src/storefront/styles/shop/01--root.css shop: -root styles. Source order is preserved by the entry stylesheet.
frontend/src/storefront/styles/shop/02-shop-product-image.css shop: shop-product-image styles. Source order is preserved by the entry stylesheet.
frontend/src/storefront/styles/shop/03-availability-span.css shop: availability-span styles. Source order is preserved by the entry stylesheet.
frontend/src/storefront/styles/shop/04-shop-stepper.css shop: shop-stepper styles. Source order is preserved by the entry stylesheet.
frontend/src/storefront/styles/shop/05-shop-grid-comparison.css shop: shop-grid-comparison styles. Source order is preserved by the entry stylesheet.
frontend/src/storefront/styles/shop.css Ordered shop stylesheet entry; domain rules live in the adjacent folder.
frontend/src/storefront/styles/storefront-polish.css Warm editorial surfaces and responsive navigation, catalogue and product pages.

Independent apps, services and SDK

Module Responsibility
extensions/apps/catalog-export/server.py Independent, language-neutral export example. Only scoped commerce callbacks; no core SQL or hosted Python dependency.
extensions/apps/engraving/configuration.wat Engraving-owned rules: printable input is checked by the host; app defines length and fee.
extensions/apps/gift-message/configuration.wat Gift-message-owned rules: printable input is checked by the host; app defines length and fee.
extensions/apps/product-lab/app.js A complete guest surface can use any UI framework; this example needs no build or host imports.
extensions/apps/product-lab/index.html Independent app entry; see extensions/README.md for its public contract.
extensions/apps/product-lab/server.py App-owned code, SQLite structures and versioned browser UI; no commerce credentials reach the guest.
extensions/apps/service-example/index.html Independent app entry; see extensions/README.md for its public contract.
extensions/apps/service-example/server.py Standalone app service with its own UI and durable event inbox. Run separately from the core.
extensions/apps/storyfront/ui.html Independent app entry; see extensions/README.md for its public contract.
extensions/budget-reserve.wat Keep EUR 100 of the supplied budget unused. Inputs are integer cents.
extensions/company-limit.wat Independent app entry; see extensions/README.md for its public contract.
extensions/minimum-order.wat Business orders must reach EUR 50 and stay inside the supplied budget.
extensions/sdk/analytics.js Consent-bound GA4 adapter for native and headless storefronts. Never send customer identities.
extensions/sdk/browser.js Guest SDK: no merchant tokens or raw host API access; the host rechecks every action.
extensions/sdk/events.py Language-neutral wire contract example: validate full batches and public HMAC envelopes before effects.
extensions/sdk/ui_bundle.py Build self-contained vanilla example UIs from the shared SDK; no remote imports at runtime.
extensions/sdk/wit/snapshot-price.component.wat Typed fixture: calls the real host cart snapshot and returns one percent of its subtotal.
extensions/single-order-cap.wat Limit any individual business purchase to EUR 250, within its budget.

Verification tools and fixtures

Module Responsibility
scripts/api_catalogue.py Generate a drift-checked static HTTP route catalogue from the compiled Rust router declarations.
scripts/app_assets.py Actual native scoped file upload, callback read, product/digest/key fences and public-file policy.
scripts/app_assistants.py Real assistant packages: editor context, rights, MCP opt-out, cron, signed webhooks, flows and local service fixtures.
scripts/app_callbacks.py Real app identity, separate PII consent, digest/creator fences and foreign-object tests. No paid services.
scripts/app_components.py Real typed WIT host reads, all four quote hooks and checkout persistence/CAS/tenant negative cases.
scripts/app_consent.py Installation/upgrade consent uses the actual reviewed digest and full permissions; no fixture auto-consent.
scripts/app_distribution.py Real signed publisher packages exercise canonical CLI signing, consent, dependency update/deactivation and tenant containment.
scripts/app_events.py Actual leased delivery: slow-service isolation, bounded batches, minimization, filter/replay and stale lease fencing.
scripts/app_export.py Actual independent export app receives leased events, reads scoped products, uploads a private artifact and completes durable jobs.
scripts/app_inference.py Opt-in real local model proposes a registered app operation; approval exercises the same managed writer.
scripts/app_jobs.py Real long-action identity/idempotency/lease/CAS/tenant/quota checks, without external or paid effects.
scripts/app_ontology.py Real native graph mapping contract through two-tenant API, MCP, permissions, references and revisions.
scripts/app_preview.py F5 uses actual native APIs in a personal clone; no version publication, foreign-team access or release. Synthetic only.
scripts/app_relations.py Real composite-FK multi-relations: per-tenant schemas, atomic quotas/revisions, hostile references and cyclic staging clone.
scripts/app_schema.py Real installed-schema evolution, recovery snapshots, rollback on bad conversions and isolation of equal app IDs.
scripts/app_secrets.py Encrypted tenant/app credentials and real incoming webhooks under strict non-owner RLS; synthetic local service only.
scripts/app_studio.py Native App Studio exercised through real HTTP/PostgreSQL: shared IR, version isolation, data, routes, MCP and selective release.
scripts/app_surfaces.py Actual app UI registry/API/MCP/data/staging and slow-service isolation against Rust/PostgreSQL.
scripts/apps.py Real PostgreSQL app lifecycle, managed schema/RLS, typed API/MCP, cart and observation tests.
scripts/automation.py Real HTTP/PostgreSQL branching automation, private facts, durable delays and revoked-actor regressions. No providers.
scripts/automation_differential.py Compare actual original Shopware rule classes with native scopes using independent synthetic entities.
scripts/automation_lifecycle.py Tenant-bound default configuration, revision-safe deletion and actual event-flow effects.
scripts/automation_registry.py Rebuild the native rule catalog from pinned PHP reflection and explicitly reviewed scope bindings.
scripts/benchmark.py Reproducible local HTTP + PostgreSQL benchmark, with response validation.
scripts/branding.py Keep the public Vendune identity, shared vector assets and executable package/deployment paths consistent.
scripts/build_app_ui.py Export deterministic example HTML and its operator uiDigests entry; never fetch remote resources.
scripts/build_site.py Build marketing pages and the complete Markdown documentation for GitHub Pages.
scripts/catalog_management.py Real HTTP/PostgreSQL catalog creation, categories, multilingual editor, visibility and staging regressions. Synthetic isolated shops only.
scripts/channel_management.py Isolated HTTP regressions for revisioned channels, domain aliases and session-bound private previews; no providers.
scripts/check_site.py Check the generated documentation's links and discovery metadata.
scripts/checkout_handoff.py Exercise actual PostgreSQL checkout transfer, isolation, replay and durable ordering.
scripts/checkout_review.py Real SQL checkout rejects unreviewed changes without orders or stock writes; synthetic fixture only.
scripts/cloud_benchmark.py Bounded private-cloud HTTP load using the existing validated benchmark sampler.
scripts/cognitive_experiments.py Real native consent/layout/payment paths with synthetic live-receipt fixtures, not a measured commerce experiment.
scripts/commerce.py Real HTTP/PG tests for SKUs, moderated reviews, tax/shipping/payment and deliveries.
scripts/company_settings.py Real HTTP company basis/channel inheritance, immutable issuer snapshots, bounded logos and private staging. No external services.
scripts/connected_apps.py Real local OAuth/provider HTTP protocols, private-source PostgreSQL/AGE consumers and durable Slack flows.
scripts/connector_store_tests.py Concurrent private state, settings/import fences and encrypted mailbox persistence.
scripts/connectors.py Start the local connector apps with private generated keys; preserve all existing app services.
scripts/contention.py Sell the remaining workshop desks under contention; separate synthetic tenant.
scripts/context_differential.py Compare bounded context/tier/quantity ports with original Shopware methods.
scripts/crm_history.py Real CRM groups/defaults, transaction-coalesced history, validated restore, tenant/role/MCP isolation.
scripts/currencies.py Real tenant/channel multi-currency, precision, immutable order and durable fixed-price tests; no paid providers.
scripts/customer_accounts.py Real registration/address/login/checkout lifecycle, ownership, CAS and immutable financial snapshots.
scripts/delivery_differential.py Compare the original PercentageTaxRuleBuilder with the live Rust port.
scripts/demo/fixtures.py Four-language, provider-free commerce playground definitions; no credentials or real customer data.
scripts/developer_documents.py Local model wire fixtures verify app generation, provenance and document privacy, without paid providers.
scripts/differential.py Independent PHP/Rust differential; fails on any money delta, not averaged error.
scripts/email_tests.py Archived differential SMTP/TLS fixtures plus actual Rust/PostgreSQL/MCP/flow consumers. No external mail.
scripts/extensions.py Activate actual Wasm policies and prove their effect on B2B checkout.
scripts/fashion_demo.py Actual default signup, fashion variants/media/localization, isolated checkout and restart; synthetic data only.
scripts/formal/axioms.py Audit owned proof sources and transitive Lean dependencies; no extra axioms are allowed.
scripts/formal/conformance.py Compare compiled Rust production policies with Lean's extracted executable,
scripts/formal/extract.py Fail-closed typed Rust-to-Lean extraction. Trusted boundary: this translator,
scripts/formal/mutations.py Prove the verification gate rejects representative broken policies and stale/disconnected source bindings.
scripts/formal/registry.py Explicit full-source inventory and reviewed adapter locks, not proof coverage claims.
scripts/formal/runners.py Generate conformance drivers from parsed policy signatures, never a second policy implementation.
scripts/formal.py Run extraction, Lean proofs/axiom audit, compiled conformance and complete source-inventory checks.
scripts/hosting_check.py Check a deployed experimental SaaS HTTPS origin without credentials or real orders.
scripts/hosting_container.py Smoke-test the built deployment image against an isolated database on the local Compose network.
scripts/identity_broker.py Synthetic broker signatures, durable replay prevention, scoped frontend routing and private Studio handoff; no provider calls.
scripts/image_jobs.py Real image jobs/bytes against a local Images fixture: private review, stale/tenant guards, edit multipart and no paid calls.
scripts/integration.py Exercise the real HTTP -> Rust -> PostgreSQL path. Never contacts a PSP.
scripts/intelligence.py Actual SQL knowledge persistence and optional live local inference integration.
scripts/international_commerce.py International configuration at the real HTTP/PostgreSQL path; all rates and addresses are synthetic fixtures, not tax advice.
scripts/knowledge_workspace.py Actual tenant-scoped knowledge lifecycle, multilingual retrieval, cursor census and selective staging; no model calls.
scripts/legal_privacy.py Real tenant-scoped consent, checkout guards, declarations, MCP and flow consumers; no external providers.
scripts/lexical_search.py Native lexical candidates: real forced-RLS plans, backfill, source edits and isolation.
scripts/load.py Local HTTP latency sample. Does not claim production or Shopware speedup.
scripts/managed_search.py Real PostgreSQL/Qdrant synchronization; synthetic embeddings test transport, not AI quality.
scripts/marketing_accounts.py Real isolated shops: customer authority, limited coupons, event flows, channels and selected releases. No paid models.
scripts/mcp_stdio.py Line-delimited MCP stdio bridge for Claude Desktop and other local clients.
scripts/merchant_operations.py Real HTTP/PostgreSQL CRM, receipt, scoped-access and paid-download regressions. No PSP traffic.
scripts/migrate_connector_state.py Explicit offline legacy-state migration; decrypted data crosses stdin only, never logs or temporary files.
scripts/money_boundary_differential.py Gate the exact checkout boundary using totals from original Shopware calculators, never a PHP rewrite.
scripts/payment_providers.py Provider-neutral financial ledger through real HTTP/PostgreSQL and a local private-service fixture.
scripts/payments.py PayPal wire-contract and real Rust/PostgreSQL state tests. Local fixture, never real provider traffic.
scripts/platform.py Real PostgreSQL/HTTP operator control-plane regression; synthetic accounts only, no paid providers.
scripts/platform_admin.py Grant/revoke an existing personal operator offline. Credentials remain in environment; no signup can grant this role.
scripts/platform_control.py Control-plane regressions on the real HTTP/database path; disposable synthetic shops and local model wire fixtures only.
scripts/platform_setup.py Isolated production-mode bootstrap test. Creates/drops only a uniquely named synthetic database.
scripts/playground.py Create an isolated local shop through personal-owner APIs; reruns preserve merchant edits and never call providers.
scripts/port.py Named, reviewable port gates; never marks an untested unit as complete.
scripts/prepare_host.py Prepare private first-host configuration; no server purchase, SSH, deployment or secret logging.
scripts/prepare_vercel.py Render same-origin Vercel API proxy configuration; no credentials, deployments or account changes.
scripts/product_lab.py Local full-app example lifecycle; private keys and independent code/data, no automatic installation.
scripts/production_foundations.py Strict non-owner PostgreSQL runtime, pool isolation, inventory and two-replica invalidation regressions.
scripts/protocols.py Protocol flows exercise the same commerce core; model smoke test is opt-in.
scripts/providers.py Cloud wire-contract tests using local HTTP servers, NOT live cloud inference.
scripts/read_performance.py Two real Rust replicas test coherent read caches; optional matched local HTTP baseline probe.
scripts/restart.py Persist an API snapshot, restart server+DB externally, verify exact state.
scripts/rule_catalog.py Inventory original Shopware conditions without claiming unsupported scopes are implemented.
scripts/rule_differential.py Execute original Shopware numeric comparisons, including epsilon, null and unsupported operator semantics.
scripts/rust_connectors.py Actual Rust/PostgreSQL multi-process notification, OAuth/import and adversarial fixtures; no external accounts.
scripts/scalability.py Real HTTP/PG regression for bounded reads and concurrent cart edits.
scripts/security/core_hardening.py Real replica regressions for auth admission, poison-event isolation, retention and bounded resource leases.
scripts/security/tenant_schema.py Database adversarial checks: reject cross-shop links even when API predicates are accidentally omitted.
scripts/security_route_gate.py Every static commerce Admin API method must have an adjacent explicit permission; new routes fail closed.
scripts/services.py Standalone app process, opaque UI SDK transport, own SQLite inbox and independent durable worker.
scripts/settings_scopes.py Real tenant/channel settings, immutable order dependencies, localized gallery and selective staging regressions.
scripts/site_markdown.py Render every tracked Markdown document with repository-aware links and search.
scripts/staging.py Real PG proof: private sandbox, immutable app versions, selective release and conflicts. No paid inference.
scripts/storefront_urls.py Real HTTP product deep links and host isolation in disposable shops.
scripts/structure.py Guard the documented Rust domain split and public extension examples.
scripts/studio.py Actual Studio API, localization and original-kernel consumer checks.
scripts/tenant_isolation.py Adversarial two-shop API/MCP/UCP/object and schema isolation with real personal/customer sessions.
scripts/testing/advisor_privacy.py Concurrent privacy mutations across the real concierge/provider path; no live inference.
scripts/testing/advisor_sources.py Actual channel-admitted advisor context and concurrent native source mutations; synthetic local model only.
scripts/testing/app_approval.py Use the Rust manifest serializer for operator pins; never invent a second canonical digest.
scripts/testing/coverage_env.py Convert trusted cargo-llvm-cov environment output to GitHub's environment-file syntax.
scripts/testing/coverage_report.py Publish separate all-source coverage totals, untested files and enforce reviewed minimums.
scripts/testing/database.py Use the same PostgreSQL fixtures through Docker or an explicitly selected native psql executable.
scripts/testing/extraction.py Native document-event extraction, review boundary and shared AI quotas; local provider only.
scripts/testing/hotpath.py Real HTTP wire bytes and SQL tracing checks for the existing read-performance suite.
scripts/testing/image_context.py Check real Rust include! inputs against the production image's explicit build COPY set.
scripts/testing/intent_navigation.py Exercise saved fact categories through native catalog/MCP, source review and selective staging; no models.
scripts/testing/inventory_batch.py Concurrent two-product allocation/release on the actual HTTP path, reused by strict runtime verification.
scripts/testing/pooler.py Owned real PgBouncer fixture: one backend, transaction pooling, never a forced privileged user.
scripts/testing/provider_fleet.py Configure one encrypted synthetic provider for all test workers, then restore the isolated control-plane row.
scripts/testing/runtime.py Owned synthetic server lifetime, child checks and loopback readiness for verification.
scripts/testing/sitecustomize.py Opt-in subprocess instrumentation for synthetic verification; never loaded by production.
scripts/testing/source_inventory.py Generate/check exact production and verification module inventory; listings are not coverage.
scripts/testing/tooling_tests.py Ordered Studio layout.
scripts/transaction_pooler.py Repeat the real strict-runtime and multi-replica regressions through a one-backend transaction pooler.
scripts/translations.py Durable translation jobs against a local provider fixture, real SQL, native MCP and a cold restart; no paid calls.
scripts/users.py Real multi-user, workspace isolation and role/revocation regression tests.
scripts/verify_integration.py Single integration suite registry, isolated DB by default; never alters an existing shop.