Source responsibilities and verification map
main.rs contains process setup and the module registry. It delegates migrations
and dependencies to bootstrap.rs and transports to routes.rs. HTTP, MCP and
UCP invoke shared operations, rather than independently reimplementing checkout.
Small modules use a crate-level shared type/import facade; SQL helpers remain
internal. commerce/ and auth/ group their types, validation and operations.
structure.py prevents Rust modules from exceeding 320 lines and keeps main.rs
under 120. Every Rust source starts with a responsibility comment.
The table lists executable behavioral coverage, not percentage line coverage. Pure rules use Rust tests; API/domain/storage modules are exercised against real PostgreSQL, Qdrant and (where enabled) the real local model. Tests include rejected inputs and state effects. A module's presence does not count as a test.
The maintained full inventory, including all newly added Rust files, frontend feature folders, independent services and SDKs, is module-inventory.md. Coverage percentages and explicit remaining gaps are in testing.md. The tables below describe selected behavioral suites and must not be read as 100% coverage.
Production foundations
The illustrated architecture guide connects ingress,
tenant scope, stock/money/payment transactions, outbox projections, AI and deployment.
New boundaries live in money.rs, tenant_scope.rs, performance/{row_security,
admission,invalidation}.rs, commerce/inventory.rs, payments/state.rs,
platform/quotas.rs and migrations/schema.rs. Unit tests, the strict
production_foundations suite, payment fixtures and original-Shopware money boundary
comparison cover their effects; asynchronous SQL and provider code remain unproved.
International configuration and language boundaries
commerce/geography.rs owns catalogue/overlay/address admission; tax_rules.rs
owns guarded destination selection and tax_context.rs its private Rule Builder
facts. settings_defaults.rs, method_text.rs, content_text.rs and
product_languages.rs own compatibility defaults, translations and language
registration. international_capabilities.rs shares native HTTP operations with MCP.
translations/{routes,worker,fields,apply}.rs own durable translation lifecycle,
text-only inference and locked revision-checked apply. The real PostgreSQL suites
international_commerce.py and translations.py plus catalog tests cover these
paths. frontend/src/shared/geography owns controls reused in Studio and checkout.
See international commerce for the exact contract.
Rust behavioral test map
| File | Responsibility | Coverage |
|---|---|---|
src/agent.rs |
Persistent grounded conversations and tenant-scoped semantic knowledge HTTP adapters. | intelligence.py + providers.py + live studio.py + users.py + restart.py |
src/auth/credentials.rs |
Argon2 password operations run off the asynchronous request executor. | users.py + Rust credential/role tests; restart.py + extensions.py for replicated policy |
src/auth/invitations.rs |
Single-use, expiring invitations. Acceptance verifies an existing account password. | users.py + Rust credential/role tests; restart.py + extensions.py for replicated policy |
src/auth/members.rs |
Workspace member visibility and immediately effective role/revocation changes. | users.py + Rust credential/role tests; restart.py + extensions.py for replicated policy |
src/auth/middleware.rs |
Resolve sessions from PostgreSQL on every request: role changes/revocation work across replicas. | users.py + Rust credential/role tests; restart.py + extensions.py for replicated policy |
src/auth/mod.rs |
Personal merchant accounts, tenant memberships, scoped sessions and role enforcement. | users.py + Rust credential/role tests; restart.py + extensions.py for replicated policy |
src/auth/registration.rs |
Create an isolated merchant workspace from synthetic template data. | users.py + Rust credential/role tests; restart.py + extensions.py for replicated policy |
src/auth/sessions.rs |
Login/logout and personal workspace discovery. Only hashed opaque tokens persist. | users.py + Rust credential/role tests; restart.py + extensions.py for replicated policy |
src/bin/context.rs |
Bounded ports of original language-chain, rule priority and quantity selection. | context_differential.py + Rust selectors + studio.py |
src/bin/delivery.rs |
Batch proportional-tax fixture transport for the original-PHP comparator. | original-PHP differential scripts |
src/bin/price.rs |
Batch price fixture transport for the original-PHP differential comparator. | original-PHP differential scripts |
src/bootstrap.rs |
Startup, additive migrations, persisted extensions and outbox worker. | integration.py + users.py + extensions.py + restart.py |
src/capabilities.rs |
Shared HTTP/MCP capability dispatch and tool authorization. | protocols.py + integration.py + commerce.py + users.py |
src/cart_model.rs |
Persisted cart, item and customer-context types. | integration.py + commerce.py + protocols.py + users.py + restart.py |
src/cart_mutation.rs |
Optimistic cart mutations and quantity normalization. | integration.py + commerce.py + protocols.py + users.py + restart.py |
src/cart_price.rs |
Authoritative quantity pricing and localized checkout quote assembly. | integration.py + commerce.py + protocols.py + users.py + restart.py |
src/cart_routes.rs |
Store API cart and order route adapters. | integration.py + commerce.py + protocols.py + users.py + restart.py |
src/cart_storage.rs |
Cart creation, loading and input validation. | integration.py + commerce.py + protocols.py + users.py + restart.py |
src/catalog_model.rs |
Tenant product model and database hydration. | server startup/build + integration.py + structure.py |
src/catalog_routes.rs |
Health and localized catalogue HTTP routes. | server startup/build + integration.py + structure.py |
src/commerce/catalog.rs |
SKU loading with parent translation fallback. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/configuration.rs |
Tenant checkout configuration loading. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/context_routes.rs |
Public method discovery and revision-checked checkout context changes. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/delivery.rs |
Shipping costs, proportional taxes and calendar delivery windows. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/detail.rs |
Product family, context prices, gallery, properties and review aggregates. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/fulfillment.rs |
Revision-checked payment and delivery state transitions. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/mod.rs |
Native catalogue and checkout domains; pricing ports remain in the library. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/review_moderation.rs |
Merchant authorization and review publication. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/reviews.rs |
Customer review submission with server-derived purchase verification. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/selection.rs |
Recover a quote after configuration changes without losing items or silently committing new choices. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/settings_mutation.rs |
Optimistic settings persistence and audit event. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/settings_routes.rs |
Tenant configuration and operational read model. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/settings_validation.rs |
Configuration validation and required availability invariants. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/tax.rs |
Destination tax-class resolution and net-preserving price conversion. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/commerce/types.rs |
Checkout selection and configuration data contracts. | commerce.py + Rust settings/recovery tests + delivery_differential.py |
src/concierge.rs |
Read-only storefront shopping advisor. | providers.py + live intelligence.py/studio.py + protocols.py |
src/context.rs |
Bounded behavioral ports of Shopware 6.7.14.2 context and product-cart selection. | context_differential.py + Rust selectors + studio.py |
src/customer.rs |
Customer credential verification and context rotation. | server startup/build + integration.py + structure.py |
src/experience.rs |
Persisted storefront layout policy and observed synthetic rewards. | integration.py + protocols.py + studio.py + restart.py |
src/extensions.rs |
Merchant catalogue and Wasm extension activation/state. | integration.py + users.py + extensions.py + restart.py |
src/foundation.rs |
Application dependencies, error responses and request context helpers. | protocols.py + integration.py + commerce.py + users.py |
src/inference.rs |
Provider adapters. Credentials stay on the server; domain validation is separate. | Rust parsing/schema tests + providers.py + live intelligence.py/studio.py |
src/knowledge.rs |
Transactional PostgreSQL relations and private Qdrant retrieval with authoritative tenant/model/digest hydration. | intelligence.py + studio.py + users.py + restart.py |
src/lib.rs |
Reusable pricing, context, sandbox, graph and inference modules. | server startup/build + integration.py + structure.py |
src/localization.rs |
Shop locale resolution, translated catalog hydration and non-mutating merchant quote. | studio.py + context_differential.py + commerce.py |
src/main.rs |
Process lifetime only. See docs/source-map.md for domain responsibilities. | server startup/build + integration.py + structure.py |
src/mcp.rs |
Typed MCP schemas and JSON-RPC transport. | protocols.py + integration.py + commerce.py + users.py |
src/order_checkout.rs |
Atomic checkout, stock locks, extension policy and idempotency. | integration.py + commerce.py + protocols.py + users.py + restart.py |
src/order_routes.rs |
Merchant order read adapter. | integration.py + commerce.py + protocols.py + users.py + restart.py |
src/outbox.rs |
Durable outbox and audit projection worker. | integration.py + protocols.py + studio.py + restart.py |
src/planner.rs |
Grounded model planning, recorded inputs and proposed changes. | providers.py + live intelligence.py/studio.py + protocols.py |
src/pricing.rs |
Behavioral port of Shopware 6.7.14.2 quantity calculators. | differential.py + delivery_differential.py + Rust numeric regressions + commerce.py |
src/proposal_apply.rs |
Transactional application of approved, revision-bound proposals. | providers.py + live intelligence.py/studio.py + protocols.py |
src/proposal_model.rs |
Typed proposals and validation before persistence or execution. | providers.py + live intelligence.py/studio.py + protocols.py |
src/proposal_routes.rs |
HTTP proposal creation, approval and task listing. | providers.py + live intelligence.py/studio.py + protocols.py |
src/routes.rs |
HTTP transport registry; domain behavior lives in dedicated modules. | protocols.py + integration.py + commerce.py + users.py |
src/sandbox.rs |
Pure Wasmtime guest execution with bounded resources and no host imports. | Rust guest boundary tests + protocols.py + extensions.py + restart.py |
src/seed.rs |
Idempotent synthetic template catalogue initialization. | integration.py + users.py + extensions.py + restart.py |
src/studio.rs |
Verified merchant overview facts consumed by the chat and activity views. | studio.py + users.py |
src/ucp.rs |
Selected UCP checkout adapters sharing the native cart. | protocols.py + integration.py + commerce.py + users.py |
New v0.5 modules
| File | Responsibility | Coverage |
|---|---|---|
src/apps/cart_contributions.rs |
Generic app-to-cart contribution contract, revision binding and order read model. | apps.py + services.py + providers.py + app_inference.py |
src/apps/data.rs |
Managed app tables: typed writes, optimistic revisions, bounded reads and local RLS context. | apps.py + services.py + providers.py + app_inference.py |
src/apps/events.rs |
Durable at-least-once app events, retry leases and stable event idempotency keys. | apps.py + services.py + providers.py + app_inference.py |
src/apps/gateway.rs |
One permission-aware action gateway serves HTTP, UI and MCP; service egress is operator configured. | apps.py + services.py + providers.py + app_inference.py |
src/apps/manifest.rs |
Strict package contract; identifiers and limits are checked before any schema DDL. | apps.py + services.py + providers.py + app_inference.py |
src/apps/mod.rs |
Versioned app packages: managed data, UI slots, agent tools and isolated service calls. | apps.py + services.py + providers.py + app_inference.py |
src/apps/planning.rs |
Registered managed app actions join the same preview/approve transaction as core changes. | apps.py + services.py + providers.py + app_inference.py |
src/apps/registry.rs |
Atomic consent-bound installation, explicit tenant schema migrations and immutable version digests. | apps.py + services.py + providers.py + app_inference.py |
src/apps/routes.rs |
Tenant-scoped package lifecycle, generated data endpoints and a shared action adapter. | apps.py + services.py + providers.py + app_inference.py |
src/cognition/context.rs |
Bounded localized catalog retrieval before inference; full catalog size never expands the prompt. | apps.py + live intelligence.py/studio.py + restart.py |
src/cognition/mod.rs |
Evidence-based shop memory: event receipts, observed pairs, reviewable hypotheses and bounded context. | apps.py + live intelligence.py/studio.py + restart.py |
src/cognition/projection.rs |
Exactly-once local observation projection; associations retain order/event evidence and simulation labels. | apps.py + live intelligence.py/studio.py + restart.py |
src/cognition/recommendations.rs |
Merchant-approved associations are consumed by the public shop without exposing order counts or identities. | apps.py + live intelligence.py/studio.py + restart.py |
src/cognition/routes.rs |
Merchant memory endpoints and revision-bound experiment/dismissal decisions. | apps.py + live intelligence.py/studio.py + restart.py |
src/payments/mod.rs |
Provider-independent payment ledger and durable workers; the first adapter is explicitly PayPal Sandbox. | payments.py (local wire fixture) + Rust integer-money tests |
src/payments/operations.rs |
Durable idempotent payment commands, customer context binding and serial refund admission. | payments.py (local wire fixture) + Rust integer-money tests |
src/payments/paypal.rs |
Native PayPal Orders v2 sandbox wire adapter; credentials never enter prompts or browser responses. | payments.py (local wire fixture) + Rust integer-money tests |
src/payments/provider.rs |
Payment provider identity, tenant account configuration and immutable wire context. | payments.py (local wire fixture) + Rust integer-money tests |
src/payments/routes.rs |
Customer payment status/capture and merchant refund operations share the durable command API. | payments.py (local wire fixture) + Rust integer-money tests |
src/payments/storage.rs |
Transactional provider receipts and order state updates; external responses cannot invent amounts or tenants. | payments.py (local wire fixture) + Rust integer-money tests |
src/payments/webhooks.rs |
PayPal verifies webhook signatures before inbox insertion; provider reconciliation confirms monetary state. | payments.py (local wire fixture) + Rust integer-money tests |
src/payments/worker.rs |
Leased payment jobs; network runs after claim commit, fenced receipts prevent duplicate local effects. | payments.py (local wire fixture) + Rust integer-money tests |
src/chat_lease.rs |
Short, cross-replica conversation leases; inference never retains a database transaction. | providers.py |
src/workers.rs |
Independently deployable worker roles; leases and durable receipts coordinate replicas. | services.py + payments.py |
src/http_limits.rs |
Bounded streaming responses for extension services and payment providers. | services.py + payments.py + build |
Frontend
| File/group | Responsibility | Verification |
|---|---|---|
application/ApplicationRouter.tsx |
Application routing and lazy entry recovery | Production typecheck/build; browser navigation |
Storefront.tsx |
Catalog, adaptive display and cart orchestration | Browser collection→detail→cart flow; underlying HTTP suites |
ProductPage.tsx |
Gallery, SKU option matrix, server tiers/properties/reviews | Browser variant/image/quantity/sold-out checks; commerce.py |
storefront/checkout/CheckoutPanel.tsx |
One-page address/delivery/payment, server quote review and explicit order placement | Browser selection, empty/filled cart and simulated order; commerce.py |
shop-api.ts, shop-i18n.ts, shop.css |
Typed shop contracts, four-language text, scoped styles | Typecheck, browser language switching and layout inspection |
Merchant.tsx |
Merchant workspace/session and chat orchestration | Browser personal sign-in/navigation/reload; users.py + real chat HTTP tests |
SettingsDialog.tsx, ProposalCard.tsx, PreviewDialog.tsx, MessageText.tsx |
Focused merchant interactions | Build, browser interactions; proposal execution through HTTP tests |
OverviewView.tsx, KnowledgeView.tsx, AgentsView.tsx, PreviewPanel.tsx |
API-backed activity, graph, protocol setup and server quote | Build, browser views; studio.py/intelligence.py |
admin/catalog/ReviewModeration.tsx + admin/orders/OrderWorkflow.tsx, UsersManager.tsx |
Tax/shipping/payment/reviews/orders and personal/team access | Browser rendering/sign-in; commerce.py + users.py |
i18n.tsx, locales/{en,de,fr,es,shop-*}.ts |
Merchant locale context and separate typed dictionaries | Typechecked equal keys and four localized API views |
Icon.tsx, ProductArt.tsx, scoped CSS |
Reusable authored visuals | Build and screenshots; gallery asset HTTP resolution |
Browser interactions were checked with the actual local app. They are not a committed automated browser regression suite. Accessibility, assistive-device coverage, all mobile breakpoints and exhaustive visual diffs remain additional work; do not infer those from screenshots or typechecking.
App frontend modules: AppsManager/AppEntity manage lifecycle/data;
AppFrame provides the constrained iframe SDK bridge; AppSlot personalizes
products; PaymentSession/PaymentManager display customer/provider state;
admin/intelligence/KnowledgeView and MemoryRecommendations connect
evidence to approved suggestions.
app-i18n supplies four-language host vocabulary; apps.css scopes their layout.
Verification: strict build plus actual browser navigation/data/configuration,
backed by apps.py, services.py, payments.py and providers.py. No automated
visual/iframe-browser regression suite is claimed.
Persistence, fixtures and tooling
Migrations 001–005 retain the earlier core/graph/context model. 006 adds SKU metadata, review storage and commerce settings; 007 initializes synthetic demo commerce once; 008 adds personal users/memberships/invitations/sessions; 009 corrects template variant capacity and the authored example review. Migrations are additive; existing stock/orders/prices are retained. Migration 010 adds managed app metadata/DDL, event deliveries, knowledge evidence and payment attempts/jobs/inbox/reservations; core monetary quotes retain their original shape. No production Shopware store is imported by these migrations.
fixtures/demo-catalog.json and demo-settings.json are fixed public templates
for new workspaces, not exports of current merchant state. frontend/public/media
contains 33 authored SVG illustrations. Four executable WAT policies and their
limitations are documented in extensions/README.md.
The original Shopware reference lives in reference/ (Composer-pinned source
and independent PHP runners). porting/units.json and scripts/port.py select
incremental migration gates. scripts/dev.sh starts the isolated local demo;
mcp_stdio.py bridges explicit client credentials. CI builds/types/lints/tests,
executes original PHP comparisons and the real DB suites. Private state,
credentials and DB backups remain ignored in .run, .env and local work.
See shopware-parity.md for exact equivalence boundaries and security.md for production gaps. No 100% code-coverage or full Shopware compatibility claim is made.
| File | Responsibility | Verification |
|---|---|---|
src/apps/runtime.rs |
Generic cached Wasm ABI execution; no app business rules. | Rust Wasm boundary tests + apps.py |
src/apps/compatibility.rs |
Explicit adapter for pre-1.1 engraving cart records; completed snapshots stay immutable. | Rust compatibility regression |
extensions/apps/engraving/configuration.wat |
App-owned text-length and fee acceptance rules. | Rust guest tests + apps.py |
extensions/apps/gift-message/configuration.wat |
Independent app with its own length/fee limits and input field. | apps.py real taxed checkout |
| src/checkout_handoff.rs | Generic expiring, single-use transfer of an authoritative cart; rotates tokens. | checkout_handoff.py real PostgreSQL concurrency/order checks |
| extensions/apps/storyfront/manifest.json | Storyfront app capabilities, separate service and merchant UI contract. | Installed package + actual connector/browser flow; see storyfront.md |
Workbench and additional commerce domains
| Files | Responsibility | Tests |
|---|---|---|
src/staging/{clone,snapshot,documents,release,mod}.rs |
Private clones, publishable units, document provenance and selected conflict-checked atomic releases | staging.py, marketing_accounts.py |
src/developer/{generation,builds,routes,mod}.rs |
Structured model schema, immutable versions, restricted runtimes, staging/import/MCP tasks | developer_documents.py, staging.py, Rust validation tests |
src/documents/{ingestion,parser,retrieval,questions,mod}.rs |
Bounded PDF/text ingestion, private/public sources, actual graph/chunks/vector retrieval and cited PDP answers | developer_documents.py including real PDF child process |
src/accounts/{mod,profile}.rs, customer.rs, cart_storage.rs |
Separate customer sessions, profile/password/history and trusted identity reuse | marketing_accounts.py, commerce.py |
src/auth/provision.rs, registration.rs |
Shared synthetic template provisioning for first and additional owned shops | marketing_accounts.py, users.py |
src/marketing/{rules,promotions,flows,channels,routes,mod}.rs |
Bounded AST, authoritative campaigns, durable note/proposal jobs and sales-channel scope | Rust rule tests, marketing_accounts.py, developer_documents.py |
src/rule_comparison.rs, src/bin/rules.rs, reference/rules.php |
Original Shopware numeric comparison behavior, independent batch oracle | rule_differential.py: 1,280 comparisons |
src/discount.rs |
Exact-cent proportional basket discount allocation | Rust conservation/bounds tests, concurrent coupon HTTP checkout |
src/commerce/product_edit.rs |
Revision-bound translations and advanced metadata; own product/reference validation | marketing_accounts.py and selected release |
src/experience.rs |
Persisted layout policy plus owned-session signal ranking/clearing | intelligence.py, marketing_accounts.py |
frontend/src/admin/{developer,environments,storyfronts,automation,catalog}/ |
Dedicated merchant workbench forms and review surfaces | Strict frontend build, actual browser review |
frontend/src/storefront/account/CustomerAccount.tsx, admin/intelligence/KnowledgeSources.tsx, admin/intelligence/SourceEditor.tsx, storefront/catalog/ProductQuestion.tsx |
Customer account editing/history and private upload/cited shopper questions | Native HTTP suites and browser forms |
frontend/src/shared/i18n/{workbench-i18n,errors-i18n}.ts, frontend/tests/locales.mjs |
Four-language typed vocabulary and exact/fallback errors | Locale parity/nonempty/error tests |
deploy/*, scripts/prepare_vercel.py |
Self-hosted image/TLS network and credential-free Vercel API rewrite generation | Container build/start and Compose/static checks |
Migrations 011, 013–015 add source documents/chunks, environment/release/build
records, customer sessions/profiles, rules/promotions/flows/channels/product
metadata and anonymous behavior signals. Migration 012 contains checkout handoff.
The domain file guard remains enforced: Rust modules at most 320 lines, main.rs
at most 120 lines, each module starts with its responsibility comment.
Bounded reads and setup
| File | Responsibility | Behavioral verification |
|---|---|---|
src/catalog_page.rs, src/catalog_search.sql, src/catalog_channel.sql |
Tenant cursor pages, literal localized server search and enforced limits. | scalability.py: complete traversal, later-page search, mixed-field language fallback, wildcards, tenant boundaries; million-product HTTP benchmark |
src/channel_metrics.rs |
Capped best-effort diagnostic buffer and bounded bulk writes. | Rust buffer-bound test + persisted counters in scalability.py |
src/performance/, migrations/037-read-context-cache.sql |
Atomic settings/override/registry version probes, bounded decoded LRU, explicit read memoization, pool budgets and cache policies. | read_performance.py: two real Rust replicas, direct writes, override/delete/recreate/rollback, languages, revocation, restart, overload/recovery; Rust eviction/policy tests |
frontend/src/shared/api/request-json.ts |
Same in-flight read shared by scoped Studio/storefront transports, immutable per-caller result and mutation barriers. | request-json.test.ts: actual transports, tenant/user/locale/channel/cart/customer keys, failures and pre-write-read barriers |
src/migrations.rs |
Serialized checksummed setup and fixed demo seed; no catalog-wide restart scan. | Fresh database full suites; manual serve/migrate/readiness and independent-worker restart checks |
scalability.py also checks a 120-variant family, last-page reviews, deep links,
64 cart edits with 32 clients and competing optimistic revisions. Independent
processes were restarted against the million-product database, with warm database
caches; this is not a machine/database cold-start or failover test.
Customer/merchant operations addition
| Source | Responsibility and behavioral tests |
|---|---|
src/accounts/{contacts,metadata,addresses,address_store,order_snapshot,demo}.rs, profile.rs, customer.rs, cart_storage.rs |
Typed contacts, indexed order metrics, composite-owned address books/CAS/defaults, login context defaults and immutable order copies. customer_accounts.py tests the entire buyer path and negative ownership cases. |
src/operations/{customers,orders,addresses,workflow,receipts,receipt_text,receipt_pdf}.rs |
Bounded CRM/order details, shared MCP address operations, workflow settings, central issuer settings, audited notes and immutable multilingual document issuance. merchant_operations.py + customer_accounts.py. |
src/commerce/{order_machine,order_workflow,order_fields,fulfillment}.rs |
Extensible validated state graph, eligible next actions/business guards, authoritative standard order projection and idempotent committed state transitions/events. Unit tests and actual concurrent workflow/flow/app effects. |
src/commerce/product_fields.rs |
Revision-bound native priced/media/property fields; quantity/tier/media validation in the central product write transaction. Product editor integration tests. |
src/assets/*, src/staging/assets.rs |
Immutable MIME-checked upload bytes, publication digests, paid owning order download entitlement, typed rich blocks and selective asset release. merchant_operations.py. |
src/auth/{permissions,integrations,members,invitations,middleware}.rs |
Fifteen scopes, per-shop hashed expiring keys, immediate revocation and non-escalating delegation. Permission units and HTTP/MCP negative tests. |
src/payments/{paypal,provider,storage,worker,routes}.rs |
Per-shop Sandbox/Live wallet configuration, pinned official attribution, durable jobs and pending-refund GET recovery. Local wire fixture payments.py; no live PSP proof. |
frontend/src/shared/customer/, storefront/{account,checkout}/, admin/customers/ |
Same four-language contact/address interactions in buyer account, checkout and merchant CRM. Strict frontend build, locale tests and browser review. |
frontend/src/admin/orders/ |
Direct eligible commands, same-job payment polling, immutable address/document views and event activity. |
frontend/src/admin/settings/, frontend/src/admin/apps/ |
Central configuration and issuer, app categories and individual package workspaces; operational layouts use the full available width. |
Migrations 016–021 |
Operations/documents/assets, fine-key storage, state-machine/idempotency storage, explicit schema repair, customer IDs/addresses/default foreign keys and explicitly synthetic demo-address backfill. Applied entries remain immutable/checksummed. |
The file guard verifies every Rust module's responsibility header and maximum
320 lines (main.rs maximum 120). Tests cover the listed actual behaviors;
this does not claim every source line or every original Shopware operation is covered.
Formal policy extraction
| File | Responsibility | Verification |
|---|---|---|
src/verified_kernel.rs |
37 pure production admission/cap policies | 80 Lean theorems; compiled Rust/Lean conformance; broken-policy mutations |
src/bin/verified_kernel.rs |
Generated JSON comparison driver calling the real policy module | 6,227 comparison cases; generated drift guard |
src/payments/receipt_guard.rs |
Checked amount conversion and provider receipt policy binding | payments.py; reviewed binding, not a proof of the parser |
All 353 Rust modules have explicit status and review inventory in
proof/manifest.json. The 34 consumer modules are
reviewed bindings, not whole-module proofs. See the
exact formal coverage and remaining gaps.
Connected provider apps and automation
| Files | Responsibility |
|---|---|
src/connectors/{server,oauth,network,store,providers}.rs |
Independent app runtime, provider OAuth/API, encrypted private state and durable jobs |
extensions/apps/{gmail,google-analytics,slack}/manifest.json |
Versioned app API/MCP capabilities and scopes |
src/apps/evidence.rs, src/apps/evidence_routes.rs |
Tenant-private incremental imports, retrieval, polling and purge fences |
src/knowledge.rs |
Private PostgreSQL source and product provenance, separated from public graph |
src/planner.rs |
Actual private-source model context and persisted task evidence |
src/marketing/{rules,rule_match,rule_fields,catalog,app_flows,flows}.rs |
Condition schema, original comparison/facts, upstream import, app-aware durable flow execution |
frontend/src/admin/apps/ConnectorPanel.tsx, admin/automation/{RuleBuilder,FlowBuilder}.tsx, storefront/analytics/ShopAnalytics.tsx |
Multilingual app details, recursive graphical automation, consent and commerce events |
extensions/sdk/analytics.js |
Reusable consent-bound GA4 adapter for headless frontends |
scripts/{connected_apps,connector_store_tests,rule_differential}.py |
Actual provider/model wire path, state fences and original PHP comparison regressions |
The upstream condition-by-condition status is recorded in reference/rule-catalog.json.
Platform control plane
| File | Responsibility | Coverage |
|---|---|---|
src/platform/auth.rs |
Independent platform authorization: live personal sessions, current grants, no integration/bootstrap escalation. | platform.py + platform_setup.py + hosting_container.py; auth conjunction additionally extracted to Lean |
src/platform/bootstrap.rs |
Offline first-operator setup: migration-only process, supplied strong credentials, password proof for existing accounts. | platform.py + platform_setup.py + hosting_container.py; auth conjunction additionally extracted to Lean |
src/platform/metrics.rs |
Aggregate-only control-plane reads: real tenants, bounded pages, explicit currencies and simulated/confirmed amounts. | platform.py + platform_setup.py + hosting_container.py; auth conjunction additionally extracted to Lean |
src/platform/mod.rs |
Global SaaS control plane: operator-only aggregate statistics and audited shop provisioning. | platform.py + platform_setup.py + hosting_container.py; auth conjunction additionally extracted to Lean |
src/platform/provision.rs |
Operator shop creation commits ownership, settings and audit atomically; never issues another user's credentials. | platform.py + platform_setup.py + hosting_container.py; auth conjunction additionally extracted to Lean |
Frontend: PlatformConsole coordinates state; PlatformSignIn owns personal login;
PlatformLanguage selects locales; PlatformDashboard renders factual metrics;
PlatformShops owns directory/provisioning views; platform-api is the typed
transport and platform-i18n contains complete operator UI translations.
The production-mode Docker smoke test checks the packaged server and frontend.
Full-app surfaces and execution admission
| Files | Responsibility | Verification |
|---|---|---|
src/apps/{surfaces,surface_tests}.rs |
UI contract registry, namespaced route/action adapter, scope and mutating GET rejection | app_surfaces.py, Rust contract tests, extracted read admission proof |
src/apps/service_limits.rs, foundation.rs, bootstrap.rs |
Shared non-queuing per-process/per-tenant-app service limits | Slow-service real-cart/second-tenant test and Rust drop/reuse test |
src/apps/{data,registry,planning,gateway}.rs, src/planner.rs |
JSONB, indexed bounded pages, direct revision binding, selected bounded AI context and unified actions | Deep-page approved local-model wire fixture; existing app/service/staging regressions |
frontend/src/shared/apps/{AppSurfaces,AppFrame}.tsx, extensions/sdk/browser.js |
New Studio/shop navigation and context-aware opaque UI bridge | Actual multilingual browser question/module/page and frontend/tests/app-sdk.mjs |
extensions/apps/product-lab/*, scripts/product_lab.py |
Independent app code/storage/UI/container and private optional launcher | app_surfaces.py, actual non-root resource-limited container smoke |
frontend/src/application/ApplicationRouter.tsx + main.tsx |
Separate lazy Studio/storefront/platform loading and root error recovery | Strict production frontend build |
Every host location and limit is listed in the full app contract. External app code, service declarations and frontend behavior remain outside the partial Lean proofs. No new core database migration was required for these optional manifest fields and generated app tables.
Source rule and durable flow migration
| Module | Behavior | Evidence / remaining boundary |
|---|---|---|
automation_rules/*, reference/automation-{catalog,rules}.php |
Source-named native comparison, typed custom fields, quantities/containers and calendar conditions | 432 actual original-class cases across 74 classes; full catalog/API parity remains unproved |
marketing/{facts,line_facts,customer_facts,rule_snapshot}.rs |
Private tenant-owned facts, variant metadata inheritance and frozen referenced-rule versions | Real cart preview and event flow tests; source UUID and every original field/scope require further migration |
marketing/{pipeline,pipeline_runtime,flow_actions,flow_mutations,flow_access}.rs |
DAG admission, branches/actions/delays, step receipts, actual domain writes and current rights | scripts/automation.py real HTTP/PostgreSQL checks; all original triggers/configurations and external exactly-once effects remain open |
frontend/src/admin/automation/*, shared/i18n/automation-*.ts |
Connected graph, typed localized rule/action editors and stable graph transformations | Four-language component tests, source payload round-trips, dangling-edge and JSON draft regressions |
See automation for the precise supported/disabled catalog and action mappings.
Reproducible local playground
| Source | Responsibility | Verification |
|---|---|---|
scripts/playground.py, scripts/demo/fixtures.py |
Create a separate personal-owner shop through loopback HTTP; seed translated rules/coupon/channel/flow/app, preserve edits and private resumable state | scripts/automation.py: invoke the actual CLI, repeat after a merchant edit, exercise both order branches and real invoice records; tooling_tests.py: remote-origin and symlink/permission negative tests |
The merchant walkthrough is playground.md. Its sample flow uses no model or external delivery provider. The exact current source inventory is generated separately.
Integrated catalog and category management (2026-10-05)
| File/group | Responsibility | Regression evidence |
|---|---|---|
commerce/product_admin.rs, product_admin.sql, product_channels.rs, product_edit.rs, product_fields.rs |
Bounded merchant queries, product/variant creation, atomic revision saves, inventory/pricing and category/channel assignments | catalog_management.py, commerce.py, merchant_operations.py, frontend catalog-management tests |
categories/{mod,admin,navigation}.rs, listing.sql, migrations 026/027 |
Tenant-safe translated tree, navigation roots, membership, nested product listings, indexed search | Rust validation tests; real category/cycle/visibility/locale/channel HTTP tests |
assets/rich_document.rs, shared rich-document.tsx, admin RichEditor.tsx |
Safe structured WYSIWYG admission and storefront rendering | Rust unsafe-content negatives, actual React renderer tests, browser save/reload |
admin/catalog/{ProductDataView,ProductEditor,ProductPanels,ProductMediaWorkspace,MediaDropzone,AiImageStudio,ProductVariants,RelatedProducts,CategoriesWorkspace}.tsx |
One list/create/detail workspace, gallery/SKU/category workflows | Strict build, architecture constraints, unit tests and real synthetic browser creation |
staging/categories.rs, snapshot.rs, release.rs |
Dependency-ordered category/product release, preserved live stock and rebound live asset scope | catalog_management.py, staging.py, Rust URL-scope regression |
operations/mod.rs, mcp.rs, marketing/flows.rs |
HTTP/MCP shared operations and product-event durable consumers | Actual MCP creation followed by completed product-created flow |
Original Shopware mapping, supported features and remaining gaps.
Company identity, per-channel inheritance, logos and legal storefront/issuer consumers: company settings module map. Real integration suite: scripts/company_settings.py; UI regressions: frontend/tests/unit/company-settings.test.tsx.
Scoped checkout settings, method dependency guards, selective staging and product media jobs: module map and verification.
Knowledge sources, product graph evidence, observed decisions and retrieval preview: domain ownership and verification. Real suites: knowledge_workspace.py, developer_documents.py, apps.py, connected_apps.py; component regressions: knowledge-workspace.test.tsx.
Managed storage/search integration: managed_search.py verifies ordinary PostgreSQL, real Qdrant, hostname scope, durable deletion/retry and lexical fallback with synthetic embeddings. It does not measure AI quality.
Connected CRM and entity history
history/{mod,routes,capability,restore,product}.rs owns trusted attribution,
scoped paging, MCP parity and restoration through domain handlers. Migrations
034/035 capture transaction-coalesced aggregate snapshots.
accounts/address_restore.rs owns validated address-book restoration;
commerce/{customer_groups,group_usage}.rs owns group definitions, price basis
and dependency admission. shared/history/ is reused by native editors and
admin/shell/useEntityNavigation.ts owns scoped entity/back paths.
scripts/crm_history.py and frontend/tests/unit/crm-history.test.tsx cover these
paths, alongside existing customer, merchant, automation and staging suites.
See history boundaries.
Guided app extension path
App assistants compile the shared Manifest in frontend/src/admin/developer/assistant-model.ts. Product/customer/order mounts reuse the native renderer with explicit object context. src/apps/editor_contract.rs owns field/context and direct-route scopes; src/apps/planning.rs filters merchant grounding and rechecks app proposal access at bind/apply. src/apps/schedules.rs and webhooks.rs persist emitted events/receipts via migration 036. scripts/app_assistants.py and app_surfaces.py exercise actual private stages, public/MCP boundaries, service fixtures, event/Flow writes, restart and scope rejection; frontend assistant tests cover editing and regional language inheritance. See guide and upstream extension requirements.
Platform control plane
| Modules | Responsibility | Verification |
|---|---|---|
src/platform/{ai,lifecycle,shop_detail,infrastructure,resources}.rs |
Encrypted shared inference settings, reversible shop admission, dossiers and actual diagnostics | platform.py → platform_control.py; resources/crypto Rust tests; availability policy extracted to Lean |
src/inference/{settings,tests}.rs |
Replica cache, authenticated encryption, inherited provider readiness and native protocol contracts | Rust tests + two-shop/fresh-process local provider fixture + provider/document/image/translation suites |
frontend/src/platform/{AdminHub,PlatformAI,PlatformShopDetail,PlatformInfrastructure}.tsx |
Public service directory and independent operator workspaces | platform-control.test.tsx, real browser review, build/architecture/localization |
src/shop_domains.rs, frontend/src/shared/api/shop-scope.ts |
Canonical shop links and actual hostname admission; protected URLs retain origin | HTTP Host regressions + shop-scope.test.ts |
src/channel_metrics.rs, src/studio.rs |
Bounded diagnostic counters and measured HTTP timings | Rust unit tests + actual persisted timing fixture |
Default fashion fixture
src/demo_catalog.rs copies the public Nord Atelier fixture into newly provisioned tenants and seeds an opt-in built-in demo once. src/auth/provision.rs controls whether catalog insertion is requested. src/knowledge/relations.rs chooses catalog-specific curated links. scripts/fashion_demo.py checks signup, localized names/navigation, actual images, all three coat sizes, tenant-separated stock, simulated checkout and a fresh-process restart. See the complete demo contract.
Trusted private experience boundary
src/auth/{broker,broker_inference,handoff}.rs owns route-bound signatures, one-use personal login and inherited inference. src/shop_domains/frontends.rs owns guarded public mounts and credential-stripping proxying. src/commerce/product_create.rs accepts stable import IDs through the normal product save pipeline. scripts/identity_broker.py covers actual HTTP/PostgreSQL ownership, replay, scope, paused-shop and restart behavior. See configuration and trust boundaries.
src/storefront_pages.rs: direct product URL HTML admission using existing tenant/channel policy.frontend/src/storefront/catalog/product-url.ts: localized product URLs, legacy SKU routes and collection navigation.
European operation
src/legal/ owns privacy policy/receipt, guarded checkout snapshots, sector facts and consumer request review. frontend/src/{admin,shared,storefront}/legal/ connects their actual interface and consent consumers. Migration 048 scopes receipts, logs and review audits; the email connector and Flow Builder consume their outbox events. See the complete behavior map and limits.
Hosted frontend transport
src/shop_domains/frontend_transport.rs streams the fixed, authenticated external frontend response with backpressure and an 8 MB cumulative body limit. SSE starts before upstream EOF; a body failure closes the stream. HOSTED_FRONTEND_COOKIE_NAMES defaults empty and optionally permits at most eight opaque anonymous shopper cookies. Login credentials remain stripped. Cookies returned to the browser must be host-only, Secure, HttpOnly and SameSite=Lax; redirects must be relative. This generic adapter contains no private Storyfront implementation. identity_broker exercises routing, foreign-shop denial, cookie filtering, paused shops and streaming through the real HTTP service. The network adapter remains outside the Lean proof boundary.
src/auth/broker_credentials.rs owns explicit trusted-email password enrollment/recovery
and existing-password verification. Migration 052 marks new broker accounts pending;
sessions.rs reports that state and handoff.rs enforces enrollment before Studio
entry. scripts/identity_broker.py checks real login, ownership, replay and revocation.
See merchant password enrollment.
Channel access and frontend bindings
marketing/channel_access.rs is the shared Store API/UCP/MCP/hosted admission boundary; channel_preview.rs owns personal, one-use browser previews. auth/middleware.rs strips forged preview principals and adds the validated request marker consumed by catalog, cart, navigation and legal paths. shop_domains/frontend_bindings.rs owns revisioned tenant/Experience alias CRUD; it reuses hosted_frontends, not another domain registry. The private renderer remains in the private integration repository. See channel management for behavior and limits.
HTTP failure diagnostics
src/channel_metrics.rs owns the bounded interval buffer and single bulk flush;
src/channel_metrics/reads.rs shares exact status aggregation across operator
overview, shop dossiers and infrastructure. src/studio.rs supplies status and
sanitized route-template logs after authentication admission. Migration 056
preserves historical totals and adds only a bounded status-code histogram.
frontend/src/platform/HTTPResponses.tsx presents access refusals, other 4xx,
5xx and unclassified history with the shared translated vocabulary.
channel_metrics unit tests, scripts/platform_control.py and
http-responses.test.tsx cover classification, real persistence, tenant-scoped
reads, historical preservation and display. See the measurement boundary.
Core hardening owners
src/request_context.rs,src/auth/{route_policy,identity,abuse,dto}.rsandidentity.sql: trusted Principal, explicit method rights, one current grant lookup, persistent login admission and typed auth requests.src/scoped_pool.rs,src/performance/{pool,row_security,cluster_lease}.rs,src/runtime_config.rs: local transaction scope, guarded session borrows, validated startup contracts and shared resource/connection budgets.src/sandbox_cache.rs,src/apps/runtime.rs,src/assets/image_provider.rs: bounded Wasm compilation/execution cache and blocking-pool image processing.src/work_signal.rs,src/outbox.rs,src/outbox/{control,retention}.rs,retention.sqland migration 057: commit hints, isolated retries/quarantine, permission-checked recovery and bounded retention.deploy/sql/provision-runtime.sh,scripts/security/core_hardening.py,scripts/testing/pooler.py,scripts/transaction_pooler.py: least-privilege provisioning and actual two-replica/one-backend PgBouncer regression paths.
All eighteen findings, shared architecture and exact limits.
Request-hotpath consolidation (2026-10-08)
| Owner | Responsibility | Real verification |
|---|---|---|
src/performance/access_snapshot.{rs,sql}; src/auth/identity.{rs,sql} |
One current shop/channel/mount snapshot, joined personal identity/channel lookup; immutable request ownership | read_performance, channel_management, identity_broker, tenant_isolation |
src/performance/delivery.rs; frontend/scripts/precompress.mjs |
Native-only zero-SQL assets, secret-free compression opt-in, deterministic gzip/Brotli variants with correct Vary, MIME and range contracts |
read_performance; frontend precompression unit tests |
src/performance/{settings,mod}.rs |
Immutable Arc<Settings> cache ownership; mutable copies only where necessary |
Two-replica version/delete/recreate/revocation and checkout/currency regressions |
src/commerce/{inventory.rs,inventory_release.sql}; src/order_checkout.rs |
Batched deduction/allocation/release; persisted quantities and sorted product locks | production_foundations with simultaneous opposite-order baskets and cancellation replay |
src/studio/{facts.rs,overview.sql,revenue.rs}; src/studio.rs |
Consolidated bounded facts and three parallel read branches; unchanged currency-separated API | studio, read_performance nonempty mixed-currency before/after response checks |
scripts/testing/{hotpath,inventory_batch}.py |
Helpers in existing integration suites, wire/query measurements and real concurrent checkout effects | Existing verification registry; no separate runtime or benchmark engine |
Raw measurements and exact limits; SQL/async adapters remain unproved despite explicit source-review locks.
App-platform ownership
The connected extension contract and file-level ownership are maintained in
App platform, App Studio and
App security. The generated module inventory
lists every actual Rust/frontend/example source, including modules without measured
coverage. Rich descriptions now share frontend/src/shared/content/editor/; do not
create a separate app editor or catalog-only implementation.
Connected cognition foundation
The cognitive commerce guide maps migrations 071–078, bounded retrieval/model protocols, original registry read tools, native guardrail apply, evidence/signatures, controlled layout trials and private cart preferences. Its audit tracker identifies still-unimplemented recommendations. The generated module inventory includes every new source; no complete-core proof or 100% behavioral coverage is implied.
Forced-RLS lexical candidates
migrations/079-knowledge-lexical-indexes.sql owns transactional word projection
backfill/triggers and composite source containment. src/knowledge/search.sql
and src/documents/search.sql narrow candidates, then hydrate/rank/admit current
native records. src/documents/retrieval.rs remains the public/private retrieval
adapter. scripts/lexical_search.py, registered in the existing integration suite
registry, checks real non-owner plans, native edits, withdrawal, source deletion
and foreign-context rejection. These are rebuildable indexes, not another source
registry. See the performance and migration boundary.
src/apps/ontology.rs: validated namespaced app-node/edge metadata and bounded projections of current authorized native records; no second graph fact store.frontend/src/admin/developer/AppOntology.tsx: shared-language mapping controls over the exact human/agent app manifest.scripts/app_ontology.py: real API/MCP tenant, permission, reference and revision regression.
Checkout continuity source owners
| Source | Responsibility | Regression evidence |
|---|---|---|
src/checkout_products.rs |
Locked localized product/variant order snapshots using the catalog inheritance helper | scripts/checkout_handoff.py German variant and immutable label checks |
src/checkout_page.rs |
Exact registered tenant/channel origin framing admission | Same suite: foreign origin, tenant, channel and invalid origin rejection |
frontend/src/storefront/checkout/embedded-checkout.ts |
Exact-origin shopper completion and close messages | Frontend embedded-checkout unit tests |
| Private original Storyfront bag and runtime client | Verify completed Core cart; remove only purchased quantities once; keep cancellation intact | Original cart-store and rust-commerce tests, live acceptance recorded separately |