P04 산모 예약 채팅 실제 backend 부분 검증
P04 누적 구현·회귀 ledger 펼치기
P04-mother-reservation-chat은 RED/partial이다. 최신 실제 산모 대여 선택 검증 pin은
contract b487fafdfa01aa6971908426a9e43c5d2a90bce9, backend
288e14a788b88e8a319280de02f877dc1573667e, frontend
93b8c2e1f459e08538e92b94184834c90f0ed322이다. 실제 local
GoTrue/PostgREST/Supabase DB, production Supabase adapter와 FastAPI transport, Astro 7
production build/preview를 같은 origin으로 제공하는 reverse proxy를 한 경로로 연결했다.
Backend 5-actor acceptance와 실제 Chromium
desktop/mobile은 terminal PATCH의 production 26-publisher orchestration, exact-set
materialization, 14-section partial final review를 같은 구현에서 통과했다. 산모 가족의 예약
sponsorship·결제 위임과 기존 예약의 연장 가능 여부는 production
query/adapter/inbox/materializer가 발행하며 raw grant·delegation·reservation id는 내부
authority lineage에만 보존한다.
최신 계약·서명 기술 pin은 contract
ba6df817c78eeb8589c07fe83f8c31d9474e4558, backend
731f321d0564cdee752fd86b8a7b926fec09ac92, frontend
e833eb15932bb4655f8eb9377854051b585a0ac6다. Backend는 no-seed immutable
contract bundle publication, exact 표시문구/document/wording digest, DB canonical confirm
time, stored draft/review/current-bundle 재검증, accepted evidence·booking handoff·waiting
payment obligation·outbox의 atomic replay/tamper guard와 owner/draft/review/bundle-bound
signature evidence의 one-time READY → CONSUMED 전이를 유지한다. 여기에 bounded raw
image/png 입력, PNG container·CRC·dimension·blank/polyglot 검증, metadata 제거 canonical
PNG, private Storage upsert=false, digest 확인, READY 등록, 응답 유실 reconciliation과
PENDING/expired READY cleanup을 연결했다.
Supabase CLI 2.109.1 전체 재생은 migration 320/320, latest
20260719120000, DB lint/auth schema/storage migrations, actual pinned Storage API
POST→GET digest 일치→immutable collision→anonymous fail-closed→DELETE→missing,
production Storage adapter roundtrip, PENDING orphan cleanup, READY consume-vs-cleaner
2-session race, catalog 7, exact-26, contract/signature smoke와 disposable cleanup을
통과했다. Backend 7,250 passed, Ruff PASS, Tach all/exact diagnostics 0,
changed P04 Vulture confidence-100 candidate 0이다. 이 backend harness는 실제 Storage와
DB authority를 증명하지만 owner browser 경로를 실행하지 않았다. 아래 browser pack도
mock API와 synthetic 법률 값만 사용하므로 두 GREEN gate를 합친 실제
browser→FastAPI→private Storage→READY→atomic confirm 증거로 해석하면 안 된다.
최신 browser pack은 backend 35f67ff9에서 수집된 역사적 current-pin 증거다.
Backend 8e37ab8a의 regional-support amount slice와 8b214509의 accepted discount-only
booking handoff는 현재 운영 v4+ catalog가 proven-empty라 선택 화면을 조작하지 않았고 새
Chromium/WebP를 수집하지 않았다.
Backend 4f1eea71은 final-review의 missingFactPaths를 단일 권위로 사용해
disabledReasonCodes와 capability reason을 파생한다. Support/promotion 판단도
supportAndDiscountDecisions라는 명시적 missing fact가 됐다. 기술 권위가 모두 준비된
fixture에서는 거짓 booking/payment 차단이 제거되고
serviceContract.acceptance와 contract_acceptance_missing만 남는다. Frontend
1c7bd8b2는 이 서버 reason code 네 개를 정확한 한국어 안내로 표시한다. 이 코드는 새
runtime/browser/WebP 증거가 아니라 fail-closed readiness 계약을 정밀화한 코드 gate다.
Backend 31ac8845의 현재 full-history gate는 수동 DB 검증을
pnpm run supabase:test:customer-reservation-full-replay 단일 게이트로 고정했다. 격리된
Supabase PostgreSQL에 pinned GoTrue와 Storage의 공식 선행 스키마를 설치하고 repository의
현재 migration 315개를 처음부터 재생한 뒤 public-schema lint error 0, exact-26
materializer smoke, latest migration 20260718180000, 컨테이너·network·임시 디렉터리
cleanup을 모두 확인했다. Supabase CLI의 non-fatal pg-delta catalog-cache warning은
기록하되 PASS를 가리지 않는다. 이 증거는 local disposable DB 전용이며 stage/production
적용, actor/browser/WebP, legal acceptance를 주장하지 않는다.
Backend 9d8c6e14는 같은 clean full-history gate에서 voucher-plan population,
private-care price publication, owner promotion entitlement, reviewed-empty regional support,
rental equipment, service priority, personality catalog의 rollback-scoped smoke 7개를 추가로
실행한다. 실제 결과는 rental option 5, priority option 3, personality question/option
6/12, publisher registry 26이며 exact-26도 그 뒤 다시 통과했다.
Backend 44417324는 rental smoke를 version publication까지 확장했다. Pricing-owned
payload로 대체 revision을 발행하고 DB가 fingerprint/count를 계산하며, exact replay는
idempotent receipt를 반환하고 same-key fact drift는 거절한다. Append-only supersession에
따라 2026-07-31은 기존 5개, 2026-08-01은 대체 2개를 반환한다. 이 대체 데이터는
rollback-scoped smoke fixture이지 운영 상품으로 발행한 사실이 아니다.
Backend 31ac8845는 active Supabase session에서 publisher를 파생하고 accepted
hq_settlement:price_catalog_management#manage 권한을 SpiceDB에서 검사하는
POST /hq/rental-equipment-catalog-revisions를 실제 FastAPI main/OpenAPI에 연결했다.
다른 권한자의 exact replay는 최초 publisher 감사값을 바꾸지 않는다. Backend 2e273307은 동일 authority로
현재 유효 revision을 읽는 GET /hq/rental-equipment-catalog?effectiveOn=... query를
추가하고 기존 service-role reader를 재사용한다. Frontend 4996253d는 이 GET과 POST를
same-origin server boundary로 연결하며 브라우저에 bearer token을 노출하지 않고 cross-site
발행 POST를 backend 전달 전에 거절한다. Current backend 4c9dd40f와 frontend
3dd5779는 disposable real GoTrue HQ/비권한 actor, accepted SpiceDB 관계,
PostgREST·migrated Supabase PostgreSQL, production FastAPI/Astro composition과 Chromium을
route interception 없이 연결했다. 실제 UI 발행 5 → 6, exact replay, altered replay
503과 DB 무변경, 비권한 GET/POST 403, direct SQL 계보, desktop/mobile WebP와
actor/relationship/runtime cleanup을 통과해 본사 대여용품 관리 하위 게이트를 닫았다.
Frontend는 한 채팅 timeline에서 완료 카드와 현재 카드 하나만 순차 표시하고, 저장 후 새
카드로 자동 scroll/focus하며, 완료 카드 안에서 다시 편집한다. 실제 owner 산모가 desktop과
390px mobile에서 열 단계를 각각 저장해 revision 11과 final review HTTP 200에 도달했다.
최종 검토는 confirmationReady=false, 확정 버튼 비활성, 읽을 수 있는 단일 열 경고를
표시한다. 연락처 편집은 revision 12로 전진하면서 입력한 열 카드 자체는 보존하고,
branch/plan/calendar/price/payment/contract/final-review 파생 권위 11개만 무효화한 뒤 exact
revision 12 final review를 다시 읽었다. 수평 overflow, console warning/error, page error,
failed request는 desktop/mobile 모두 0이다.
같은 실제 runtime에서 branch operator와 caregiver가 예약 draft 생성을 각각 시도해
HTTP 403, draft 카드 0, 내부 권한값을 노출하지 않는 동일한 안전 문구를 확인했다.
다른 산모가 owner draft를 session resume하려 한 actual GET은 403, draft 카드 0,
resume key 삭제를 통과했다. 페이지 초기화 뒤 resume GET의 Authorization header를 test-owned
방식으로 제거한 케이스는 actual FastAPI 401, 안전한 세션 만료 문구, 재시도 버튼, resume key
삭제를 통과했다. 이는 wall-clock token expiry 자체의 증거는 아니다.
Contract는 customerIntakeDisplaySnapshot을 exact-root required section으로 추가해
최종검토를 14 sections로 만들고, 비연속 baby sequence·malformed pet shape·
catalogLineage 공개 누출을 거부한다. Backend는 내부 accepted
customerIntakeSnapshot의 defensive copy로 공개 projection을 만들며 raw authority와
catalog lineage는 계속 internal-only다. Pending priceQuote.lines=[]는 오직
confirmationReadiness.ready=false이고 missing path가 priceQuote일 때만 TypeScript
계약에서도 허용하며, ready projection의 빈 quote line은 계속 거부한다. Contract gate는
TypeScript 486, Python 82; backend full 7,040; frontend full 91 files / 580 tests,
evidence runner lint, Astro check/build가 통과했다. 최신 실제 browser evidence pack은 공개 파일
45개, manifest asset 44개와 animated WebP 6개이며 raw token, raw idempotency key,
실제 개인정보를 포함하지 않는다. Production source completeness, 실제 승인된 non-empty
regional-support actor/runtime proof, legal/contract acceptance, confirmation-ready confirm,
deploy는 미완이다.
현재 backend pin은 member_management/customer_authenticated_session의 verified
Supabase Auth subject를 backend-owned CustomerAccountLinkProof와
CustomerAuthenticatedSessionProjection으로 한 번만 해석한다. P04 actor bridge는
orchestration에 있고 booking identity도 같은 proof를 소비하며 member/profile drift를
거부한다. Repository Supabase CLI로 disposable DB의 전체 migration chain을 올린 뒤 새 RPC의
exact 6-field proof, anon=false·authenticated=false·service_role=true,
withdrawal_pending SQLSTATE 42501을 확인했다. 새
pricing_settlement/payment / PaymentActorContext는 같은 proof의 account/profile/member/revision
typed fact를 소비하고 immutable payment actor snapshot에 lineage를 동결한다. Direct mother
payment는 mutable generic role row 없이 동작하며 family/operator payment도 mother account
비활성 시 fail-closed다. Resolver는 owning Pricing Settlement adapter slice로 이동했다.
Backend 7e2b86db는 Layer-first security_audit/customer_session_recovery context를
추가했다. Draft resume GET은 missing bearer, invalid scheme/session, not found, ownership
mismatch, expired/inactive, active recovery를 닫힌 reason으로 기록하고 성공 시 exact draft
revision을 보존한다. Security Audit application이 raw actor/draft reference를 SHA-256으로
변환한 뒤에만 append-only Supabase ledger에 저장하며 bearer/access token과 resume key는
이벤트·컬럼에 없다. Disposable DB의 전체 migration chain에서 service_role=INSERT+SELECT
ACL, update/truncate 42501, anon/authenticated 42501, privileged update/delete 55000,
forbidden raw column 0을 확인했다. Backend 35f67ff9는 같은 account-link proof와 accepted
draft/review lineage로 직접 산모의 mother/booker/payer party를 만들고 expected new-booking
revision 1을 동결한다. Public HTTP는 이 binding을 받지 않고 trusted Restate payload만
전달한다. Supabase wrapper RPC는 기존 booking/payment 저장과 append-only party snapshot을 한
transaction에서 실행한다. 실제 disposable DB에서 initial save/exact replay, drift 40001,
stale expected revision의 booking/payment/snapshot 전체 rollback, update 55000,
service-role-only ACL을 통과했다. Full backend는 7028 passed, focused regression은
76 passed; Tach exact/external 진단 0, Vulture 100 후보 0이다. 이어 같은 backend
35f67ff9와 frontend 4371660 pin으로 disposable GoTrue/PostgREST/Supabase/FastAPI/Astro
browser regression을 새로 실행했다. Desktop/mobile 열 단계, edit/reprojection, actual
422/409, branch/caregiver create 403, foreign-mother/missing-header resume 403/401이
모두 다시 통과했고 p04-live-browser-35f67ff pack으로 고정했다. Confirm이 계속 비활성이므로
새 party snapshot의 confirmation 경로 자체를 browser에서 실행한 증거는 아니다.
Backend b8b5d8ea2bb2edfe1057ec457ec142db090156ff의 새 acceptance는 disposable
Supabase DB, GoTrue, PostgREST, production FastAPI transport를 실제로 통과했다. 다섯 actor,
열 PATCH, draft revision 11, contribution materialization 26/26, final review HTTP
200, exact authority section 14, internal retained-intake lineage 8을 확인했다. 공개
payload의 catalogLineage 누출은 0이다. 단 branch calendar profile과 legal authority를
임의 생성하지 않았고, catalog source 일부는 p04-test-owned fixture다. 그래서
confirmationReady=false이며 branchServiceAreaDecision, eligibleServicePlan,
eligibleServicePlan.serviceOfferingAvailabilityDecision, priceQuote,
reservationCreationChargeSnapshotHandoff, paymentPreparation,
serviceContract.acceptance는 unresolved다. 이 backend-only 실행 뒤 frontend
43716602ec918217a5eb7171b2b19d5d59801de6에서 실제 Chromium screenshot과 animated WebP를
추가 수집했지만, test-owned source authority를 production authority로 승격하지 않았고
온라인 배포도 하지 않았다.
현재 pin은 승인된 voucher-plan population의 실제 consume_type_value와 source position을 읽는
Layer-first query, guarded Supabase RPC/adapter, orchestration bridge를 추가했다. Supabase CLI로
migration을 적용하고 기존 승인 population smoke에서 A-가-1형을 조회했으며, 누락 축은
fail-closed임을 확인했다. 이 증거는 새 browser/5-actor rerun이 아니라 source-authority DB gate다.
현재 pin은 authenticated owner의 유효한 issued/restored reservation-discount entitlement를
읽어 promotion_entitlements를 발행한다. browser에는 hashed reference만 보이고 raw entitlement
UUID와 exact revision은 내부 authority lineage에만 남는다. 실제 DB smoke로 owner 격리,
proven-empty catalog, redemption/revision 변경 뒤 frozen authority 철회를 검증했다.
현재 pin은 민간서비스 원본
source-refs/sanmopia-admin/static/dist/excel/price/2026_normal_260119.xlsx와
Spreadsheet_model.php:4807-4981을 anti-corruption parser로 정규화했다. 원본 SHA-256은
ad3235e4f35108936c816046ec2da4522a3ff189c8c7b3f9a6443b79b07dd65b이고 실제
20행 모두 ready_to_publish, issue 0이다. PHP의 숫자 DB id, 암묵 empty(), 반복 update/insert,
24개월 미만 강제 null을 이식하지 않았다. stable code, 선언형 component 규칙, 명시적 파생금액,
삭제 marker 정규화, 미지 값 fail-closed를 SSOT로 뒀다. 아직 durable source approval과
실제 workbook 20행의 운영 batch 발행은 없다. 최신 pin은 그 normalized entry set을 duration 4개,
work schedule 2개, service option 10개로 투영하고 durations·work_schedules·
service_options publisher를 등록했다. publication RPC가 DB time과 canonical fingerprint를
소유하며 published batch/entry는 불변이다. 대표 entry 2개의 rollback-scoped 실제 DB smoke로
최초 publish, exact replay, 변조 거부, registry 22/26, residue 0을 검증했다. production final
review는 자동 exact-set preparation과 당시 나머지 4개 publisher가 없어 fail-closed 503이었다.
현재 pin은 voucher 출산순위/제공인력도 승인된 단일 population에서 source order로 읽는다.
Constdata_model.php:258-291의 숫자 id 감산과 사태아 switch를 계약에 복사하지 않고, workbook
stable delivery code 8개를 한 domain presentation policy가 label·workforce count로 투영한다.
Spreadsheet_model.php:4997-5011의 별칭 땜질도 source adapter 경계에서 제거했다. guarded RPC,
Layer-first query/adapter, contribution publisher를 trusted preparation에 연결했고 실제 DB smoke로
approval lineage, source position, service-role-only 실행, registry 22/26, rollback을 검증했다.
동시에 voucher parser의 P:W 오프셋 결함을 PHP의 실제 Q:X 계약에 맞춘 named column map으로
수정했다. 원본 2026_voucher_260119.xlsx는 SHA-256
621a7667b326a3184bea2910b7fc49bbda553c93061d3f91af42d3cb70562a8c이며 실제
198/198 entry, issue 0, baby group 4개, delivery code 8개로 ready_to_publish다. production
final review는 자동 exact-set refresh와 나머지 publisher가 없어 계속 fail-closed 503이다.
현재 pin은 additional_services.rental_options도 구버전의 숫자 DB id와 화면별 요금 분기를
공개 계약에 복사하지 않고 발행한다. 실제 source는 Constdata_model.php:380-387,
views/survey/a17_1.php:276-315, views/service/step3_normal.php:190-240,
config/constants.php:109, 관리자 Spreadsheet_model.php:663-699다. stable option key 5개가
욜로건강쿠션·좌욕기·찜질팩·유축기·탕온계를 source 순서대로 보존한다. 장비료는 유축기만
15,000원, 왕복 배송비는 선택 개수와 무관하게 예약 단위 최대 1회 10,000원, 지점 확인은
유축기만 필요하다. 이 규칙과 정산용 RentalEquipmentChargeCatalog는 동일한 승인 revision을
읽는다. guarded RPC는 catalog/source-evidence SHA-256, 5행 연속 순서, service-role-only 권한,
불변성을 검증한다. 실제 DB smoke는 option 5개와 registry 22/26, rollback을 통과했다.
구버전 LIST_RENTAL_TB의 live numeric id는 browser option에 노출하지 않는다.
Backend 44417324부터 용품 명칭·요금·지점확인 여부·배송비는 새 immutable revision payload로
발행할 수 있다. 새 revision은 직전 revision을 supersede하되 과거 row를 수정하지 않는다.
발효일 조회가 계보를 따라 한 revision만 선택하므로 기존 예약의 catalog lineage와 신규 예약의
상품 구성이 동시에 보존된다. Current backend 4c9dd40f는 service-role command/RPC,
HQ 인증 POST, SpiceDB authority, production main composition과 actual acceptance harness까지
연결한다. Frontend 3dd5779의 관리자 편집 UI는
실제 actor evidence에서 real HQ actor,
GET/POST/backend/DB, desktop/mobile Chromium/WebP와 cleanup을 통과했다. Backend
7f51408b는 이어 실제 예약 선택을 immutable selection revision으로 동결하고 같은 revision의
quote line·payable·charge handoff·accepted booking command·Restate input·finalized charge
snapshot까지 연결했다. catalog 밖/중복 선택, 지점 확인 누락, quote line 또는 pricing lineage
변조는 fail-closed다. P04에는 authenticated mother browser의 실제 legal confirmation과
Supabase accepted evidence·booking handoff·lineage·replay 증거가 아직 필요하다. 실제 예약
처리, 배정, 결제, 서비스, 출퇴근, 보고서/document, 지급·정산 소비는 P05-P13이 각각 소유한다.
현재 pin은 caregiver_matching.priorities도 source-reviewed catalog로 발행한다. 실제 source는
Constdata_model.php:400-429, views/service/smart_matching_1.php:126-174,
views/survey/smart_matching_1.php:225-270, Smart_matching_model.php:205-228,
controllers/api/Service.php:630-637이다. 구버전 0/1/2 코드는 각각
postpartum_care, newborn_care, household_care stable key로 바뀐다. 한 domain catalog가
ordered_unique, 최대 3개, 중복·미지 key 거부, 기존 CaregiverServicePreference priority 변환을
소유하므로 채팅 UI와 matching 알고리즘에 별도 표가 생기지 않는다. guarded RPC는 option 3개와
source anchor 5개, 두 SHA-256, 연속 순서, service-role-only 권한, 불변성을 검증한다. 실제 DB
smoke는 registry 23/26과 rollback을 통과했다. numeric source code는 browser option에 노출하지
않는다.
현재 pin은 caregiver_matching.personalities도 source-reviewed catalog로 발행한다. 실제 source는
views/survey/a25.php:58-210, Constdata_model.php:433-461,
views/service/smart_matching_2.php:45-135, static/js/smart_matching_2.js:1-57,
controllers/api/Service.php:643-671, Smart_matching_model.php:238-267,
Manager_model.php:88-106이다. 구버전의 numeric DB id와 blind two-row grouping 대신 6문항,
12개의 question.answer stable key를 사용한다. 한 domain catalog가 six-by-two shape,
exactly_one_per_question, 중복·미지 key 거부, 기존 CaregiverPersonalityAnswer 변환을
소유한다. 오탈자·띄어쓰기 4건은 명시적 normalization note와 catalog fingerprint에 포함된다.
guarded RPC는 option 12개, source anchor 7개, 두 SHA-256, 연속 순서, service-role-only 권한,
불변성을 검증한다. 실제 DB smoke는 registry 24/26과 rollback을 통과했다. numeric source id는
browser option에 노출하지 않는다.
현재 pin은 contract_and_payment_preference.support_programs도 source-reviewed regional-benefit
catalog로 발행한다. 실제 source는 step3_voucher.php:140-225, Service.php:333-367,
Reservation_model.php:1763-1813, static/js/step3.js:619-628, static/js/step3.js:886-942,
static/js/step3_voucher.js:80-135다. 구버전은 완주군 지원을 주소 문자열, price version <= 3,
5일 차감·가산, DOM 숨김값, 옵션 label 분기로 흩어놨고 영등포구 할인은 2023-02-01에 제거됐지만
stale JS/model 분기가 남아 있다. 현대 구현은 이 분기를 복사하지 않고 RegionalBenefitRule의
region code, price-catalog version window, source evidence, revision key를 SSOT로 둔다. v4+는
검토된 empty revision이고, v1~v3은 정확 option row/price authority가 없으면 fail-closed다.
guarded RPC는 source anchor 7개, catalog/source fingerprint, service-role-only 권한, 불변성,
publisher 25/26을 검증했다. 이 regional-benefit pin의 full regression은 6,816 passed다.
현재 pin은 caregiver_matching.recommendations도 기존 CaregiverCandidateRecommendationSet
authority에서 읽어 발행한다. 구버전은 Service.php:594-623에서 추천 관리사 5명을 만들고
reservation_check_data.php:147-219, reservation_check_data.js:1-21에서 raw MANAGER_ID_PK를
hidden input과 carousel data-id로 노출했다. 현대 구현은 새 알고리즘을 만들지 않고 frozen
recommendation set의 decision revision을 catalog authority로 사용한다. Browser option은 opaque
selectionReference만 받으며 raw candidate/profile id는 internal selection authority lineage에만
남는다. 실제 DB migration과 exact-26 materializer smoke, catalog smokes, DB lint, Ruff/Tach,
Vulture, full regression 6,820 passed를 통과했다. 이 증거는 새 browser/WebP run이 아니다.
현재 pin 121f786c은 마지막 writable PATCH 뒤 server-built final-review projection을 기록한다.
GET final-review는 더 이상 projection recorder 부재 때문에 막히지 않는다. a7dbc0e7의 13-section
partial projection에 이어, 실제 draft의 산모 연락처, 자택/서비스 주소, 선택한 service offering,
duration, work schedule, 추가서비스, 대여용품, 관리사 선택 mode, payment method를 catalog label과
함께 retained display facts로 바인딩한다. a759da44는 desired start, 선택 토요일, 선택 공휴일을
검증·중복제거·정렬해 serviceOccurrences와 partial serviceEndOn에 반영한다. 단 projection은
confirmation_ready=false, authoritative_projection_partial, booking_handoff_missing,
payment_handoff_missing을 명시한다. 70ea0ca3은 final-review 전용 branch query port를
application/branch_operations/features/organization/queries에 두고, 현재 draft revision의
catalog-preparation authority가 가리키는 source branch, 실제 sanmopia_branch_profiles, revisioned
service-area policy를 orchestration에서 합성한다. exact→parent→시도 lookup, matched rule/depth,
coverage profile, impossible-area veto, address fingerprint를 그대로 projection에 넣으며 이때만
branchServiceAreaDecision missing fact와 BRANCH_COVERAGE invalidation을 제거한다. 준비 권위가
없으면 기존 partial/missing 상태를 유지하고, 권위는 있는데 branch/profile/policy scope가 틀리면
fail-closed다. 98bf0283은 여기서 보존한 calendar profile key/raw rule key, current catalog
serviceDayCount, effective Supabase calendar profile, national/branch holiday를 기존 calendar
domain에 연결한다. 해결되면 requested-date placeholder 대신 billable occurrence, skipped
weekend/holiday를 반영한 end date, policy revision/fingerprint를 기록하고 plan/calendar
missing/invalidation만 제거한다. legacy option metadata 또는 current profile이 없으면 기존 partial을
유지한다. quote, payment, contract acceptance, booking handoff authority는 아직 missing이다.
affected context 회귀는 192 passed, full Python regression은 6,835 passed;
Ruff/Tach exact/external/Vulture gate를 통과했다. 새 migration, 새 actor/browser/WebP run은 아니다.
a4c6ffbd는 다음 retained fact인 priceQuote를 기존 pricing owner에 연결한다. Voucher day
catalog는 exact priceCatalogEntryCode를, private-care duration/work-schedule catalog는
applicableEntryCodes를 보존한다. Final-review bridge는 private 두 집합의 교집합 또는 voucher의
exact entry로 current effective Supabase publication을 조회하고 기존
PriceCatalogQuotePolicy로만 금액·지원·정산 line을 만든다. Option catalog에는 금액을 복사하지
않고 option key도 가격 권위로 해석하지 않는다. Exact matching entry가 하나일 때만
priceQuote missing/invalidation을 제거한다. Metadata/publication이 없거나 후보가 다수면 partial,
형식·catalog lineage가 충돌하면 fail-closed다. Focused 24 passed, full 6,841 passed, Ruff,
Tach exact/external을 통과했다. Vulture 100%의 7건은 이번 변경 밖의 기존 finding이다. 새
actor/browser/WebP/schema/deploy 증거는 아니다.
4166ddf1은 pricing owner 아래 feature-local query로
ReservationCreationChargeSnapshotHandoff를 만든다. Draft revision, exact catalog/version/entry,
customer payable amount를 canonical fingerprint에 넣어 replay-safe handoff id, revision 1, KRW,
customer share, pricing revision key를 만든다. Authoritative quote와 handoff가 함께 해결될 때만
handoff missing fact를 제거한다. 이 객체는 booking 완료 snapshot이 아니다. Confirm transaction이
reservation acceptance, finalized charge snapshot, ADR-020 obligation, payment handoff, outbox를
원자적으로 생성하는 gate는 계속 열려 있다. Focused 11 passed, full 6,843 passed, Ruff,
Tach exact/external을 통과했다. 신규 actor/browser/WebP/schema/deploy 증거는 아니다.
121f786c은 선택 payment method, current draft-scoped payment catalog, authoritative quote
payable amount를 pricing-owned query에 넣어 paymentPreparation을 확정한다. Current catalog 밖
method는 fail-closed다. 따라서 계약이 허용한다는 이유만으로 legacy에서 비활성인 bank parity를
주장하지 않는다. 해결되면 eligible labels, paymentRequired, unchanged payable amount를 기록하고
payment preparation missing/invalidation만 제거한다. Provider 호출, 결제 완료, ADR-020 obligation,
payment handoff는 만들지 않으며 global payment_handoff_missing은 유지한다. Focused 13 passed,
full 6,847 passed, Ruff/Tach exact/external을 통과했다. 신규 actor/browser/WebP/schema/deploy
증거는 아니다.
8e7b88bf는 payable confirm에서 위 charge/payment projection을 다시 대조해 ADR-020
waiting obligation과 공개 ReservationCreationPaymentHandoff를 만든다. Obligation에는 selected
method, eligible method set, reservation.customer_share.deposit, exact payable amount, KRW,
charge id/revision, pricing revisions, draft/review revisions를 동결한다. Supabase wrapper 한
statement 안에서 draft confirmation·acceptance·command·outbox와 obligation을 기록하므로 불일치는
전체 rollback이다. Provider는 호출하지 않고 paid 상태도 만들지 않는다. Focused 32 passed,
full 6,851 passed, Ruff/Tach exact/external PASS다. Vulture 100은 기존 7건만 보고했다.
Migration 20260718103000은 healthy P04 disposable DB에 Supabase CLI로 적용됐고 DB lint error는
0이다. Clean full-history reset은 Realtime bootstrap exit 134와 초기 auth.jwt() 부재로
미완이다. P04 소유의 accepted legal evidence·booking handoff·readiness 활성화와
actor/browser/WebP는 아직 없다. Booking workflow의 실제 후속 처리는 P05 이후가 소유한다.
d29f6b7a는 이미 draft-scoped exact catalog에 동결된 관리사 추천 decision을 final review가
다시 pending으로 버리던 틈을 닫는다. caregiver_matching.recommendations가 정확히 하나이고
authority reference/revision, opaque selection reference, enabled option, non-empty label이 모두
현재 draft intent와 일치할 때만 caregiverCandidateDecision을 materialize한다. 특정 추천 선택은
선택된 opaque reference가 현재 후보 집합에 실제 존재해야 하며 stale decision revision, 중복
reference, disabled/malformed option은 fail-closed로 missing/invalidation을 유지한다. Browser raw
candidate/profile id를 새 권위로 삼지 않고 기존 frozen catalog만 소비한다. Focused 6 passed,
full 6,853 passed, 공개 Python contract validation, Ruff, Tach exact/external PASS다. Vulture
100은 Python 3.12+ 문법 parser diagnostics와 기존 7건만 보고했고 이번 변경 신규 finding은 없다.
이는 caregiver 조각만 닫은 것으로 global readiness, booking/legal/support 권위나 새
actor/browser/WebP 증거가 아니다.
7a345e7b는 support program과 promotion entitlement 두 current catalog가 모두 정확히 존재하고
draft의 두 요청 목록이 실제 빈 배열일 때 supportAndDiscountDecisions=[]를 권위 있는 empty
decision으로 인정해 support invalidation만 제거한다. Catalog가 없거나 요청이 하나라도 있으면
금액을 0원으로 꾸미지 않고 unresolved를 유지한다. 선택된 지원/쿠폰은 pricing owner의 금액·정책
revision 결속이 필요하다. Focused 8 passed, full 6,855 passed, Ruff, Tach exact/external,
변경 파일 Vulture confidence 100 finding 0을 통과했다. 새 actor/browser/WebP 증거는 아니다.
867ba51f는 선택된 promotion entitlement를 Pricing Settlement owner query로 다시 해결한다.
Frozen catalog revision은 authenticated owner의 live entitlement source revision과 일치해야 하며,
선택 reference는 browser 순서가 아니라 catalog source order로 정렬된다. 여러 쿠폰은 순서대로
적용하되 총 할인은 reviewed customer payable을 넘지 않고 각 결과는 full/partial/not-applied와
opaque decision revision으로 남는다. 할인된 payable과 customer credit은 final-review quote,
charge snapshot handoff, payment preparation, atomic waiting-obligation 입력까지 같은 금액을 쓴다.
Legacy PHP의 다중 쿠폰 합산과 0원 floor 근거는
Reservation_model.php:1200-1205, :1261-1262,
pre_reservation_payment.php:123-127, modal_change_payment.php:5-13이다. Selected regional
support는 아직 pricing-owner amount rule이 없어 base quote와 handoff도 생성하지 않는다.
Full regression 6,864 passed, Ruff lint와 변경 9파일 format, Tach exact/external, 변경 production
Vulture confidence 100 finding 0을 통과했다. 새 migration, actor/browser/WebP/deploy 증거는 아니다.
b7894b89는 confirm 뒤 이미 DB에 기록되던 outbox의 claim/complete/fail RPC를 typed production
adapter와 runtime에 연결한다. Claim은 available/occurred/id 순서를 DB에 맡기고 attempt count를
CAS revision으로 사용한다. Complete/fail은 exact attempt와 단일 반환 row만 수락하며 malformed
payload/lifecycle은 거부한다. Focused 6 passed, full 6,868 passed, Ruff/Tach exact/external,
새 production Vulture confidence 100 finding 0이다. Accepted projection을 booking command로
변환하고 workflow를 실행하는 consumer는 아직 없다.
0676b50e는 다음 consumer가 사용할 booking execution input을 하드코딩 없이 동결한다. Stable
offering, private duration/work schedule 또는 voucher service-day, exact price-entry code,
authoritative service-day count가 versioned mother-booking context에서 정확히 한 option과 일치해야 한다.
Label, source order, opaque value, reservation_amount_hint는 매핑 authority가 아니다. Legacy
service_type_detail_id, working_type_id, service_day_list_id는 public final-review에
노출하지 않고 별도 internal projection으로 persistence round-trip한다. Missing lineage, zero match,
duplicate match는 partial을 유지한다. Full 6,876 passed, focused mapping/persistence/runtime 45 passed
및 persistence round-trip 16 passed, Ruff, Tach exact/external, changed-production Vulture confidence
100 finding 0이다. 새 migration, browser, WebP, deploy 증거는 아니다.
60334ee0는 booking command의 timezone-aware schedule을 임의 자정으로 만들지 않도록 internal mapping에
serviceStartLocalTime, serviceEndLocalTime, serviceTimezoneName,
workingTimePolicyRevisionKey를 필수화한다. Legacy terms
sanmopia_web/application/views/about/terms.php:259-268의 출퇴근 평일/토요일, 입주, 협의 조정 규칙이
근거다. Missing/invalid time 또는 IANA timezone lineage는 mapping unavailable로 fail-closed한다.
Assembly 517cd210은 test-owned stage seed에 stable selection/price/time lineage를 추가했다. Focused
29 passed, full 6,876 passed, Ruff/Tach exact/external, 새 production Vulture confidence 100
finding 0이다. Seed 실행이나 deploy는 하지 않았다.
384a97a6는 관리사 선택을 첫 후보로 임의 치환하지 않는다. Caregiver Matching query가 current
owner/draft request/decision/revision을 다시 읽고 specific opaque selection 또는 frozen rank one을
exact resolve한다. Raw candidate_profile_id는 publisher/public catalog에 넣지 않고 application
내부에만 유지하며, canonical positive execution ID만 internal final-review handoff에 기록한다.
Stale/unknown/ambiguous/non-numeric mapping은 partial이다. Focused 20 passed, full
6,881 passed, Ruff/Tach exact/external, changed-production Vulture confidence 100 finding
0이다. Outbox consumer, booking workflow, browser, WebP, deploy 증거는 아니다.
045c145b는 confirm 뒤 active draft query로는 읽을 수 없는 accepted final-review projection을
processing outbox의 exact attempt에서 읽는 service-role-only RPC와 adapter를 추가한다. Outbox,
command, draft, booking request, projection revision, reviewed fingerprint가 모두 일치해야 immutable
snapshot을 반환한다. Migration 20260718113000은 repository에만 있으며 local/stage/production
Supabase에는 적용하지 않았다.
d23b1842는 그 handoff를 기존 ReservationBookingWorkflow에 실제 연결한다. Named orchestration은
accepted branch, versioned execution mapping과 branchId, selected caregiver, ISO local time/IANA
timezone, price quote, payment eligibility/payable, branch coverage를 current operational context와
재대조한다. 첫 후보 fallback, label/order/amount-hint authority, browser raw numeric ID는 허용하지
않는다. 내부 bearer job POST /internal/customer-reservation-booking-handoff-runs가 pending outbox를
claim하고 exact workflow replay를 포함해 start한 뒤 같은 attempt를 CAS complete/fail한다. Focused
15 passed, full 6,900 passed, Ruff, Tach exact/external PASS다. Vulture confidence 100의 5건은
기존 Protocol parameter false positive이고 새 consumer finding은 없다. 단 ADR-032 legal
acceptance가 production confirm/outbox 생성 전단을 아직 막고, accepted service-term/offering
side-effect assembly, migration 적용, real DB actor E2E,
browser/WebP/deploy는 이 pin 당시 미완이었다.
be9ec4f9는 accepted serviceOccurrences를 quote와 독립된 표시 배열로 버리지 않고 기존 booking
domain의 ServiceTermPlan으로 동결한다. Occurrence 개수는 accepted quote service-day count와 같아야
하고 sequence는 1..N, 날짜는 엄격 오름차순·accepted 기간 내부, 마지막 날짜는 accepted end date여야
한다. service-calendar-profile:*과 service-calendar-policy:* revision도 정확히 하나씩 요구한다.
따라서 기존 booking workflow가 이미 소유한 occurrence-ledger persistence를 그대로 사용하며 legacy
numeric service ID나 browser label로 날짜를 다시 계산하지 않는다. Focused 25 passed, full
6,902 passed, Ruff, Tach exact/external, changed-file Vulture confidence 100 PASS다. 실제 workflow
DB 실행 증거는 아니며 accepted offering availability와 consumer-impact side-effect assembly는
이 pin 당시 명시 계약이 없어 열려 있었다.
b1beee53는 accepted-booking delivery의 durable recovery를 추가한다. Service-role-only RPC는
exact failed attempt 또는 server-owned 15분 cutoff보다 오래된 processing attempt만 pending으로
복구한다. Attempt count는 다음 claim을 위해 보존하며 source status, claim time, error, reason,
actor, exact delivery snapshot을 immutable audit에 기록한다. Advisory lock과 attempt/status CAS로
동일 idempotency key 경합을 직렬화하고 exact replay는 저장된 결과를 반환한다. Bearer internal
route는 safe 404/409/503을 제공하며 DB detail은 노출하지 않는다. Focused 60 passed, full
6,917 passed, Ruff, Tach exact/external, changed-production Vulture confidence 100 PASS다.
Migration 20260718124500은 scoped disposable PostgreSQL 17.6에 verbatim 적용했고 Supabase CLI
schema lint error 0이다. Local stage/production에는 적용하지 않았고 clean full-history replay,
actual actor/browser/WebP/deploy 증거도 아니다.
fcad4c50는 accepted offering availability와 consumer-impact assembly를 로컬 booking workflow에
연결한다. Service-offering catalog contribution은 offering key, availability state, handoff kind,
unavailable reason, message key, policy revision, source evidence를 catalog fingerprint에 포함한다.
Final-review materializer는 exact enabled selected option, full-reservation handoff, 정확한 policy
source revision만 internal booking mapping에 동결하며 공개 final-review contract는 늘리지 않는다.
Accepted-handoff translator는 같은 lineage를 재검증하고 application-owned 단일 builder로
daily_report, settlement, service_calendar 세 consumer fact를 만든다. 기존 public booking
API도 같은 builder를 재사용한다. Affected 123 passed, full 6,919 passed, Ruff, Tach
exact/external PASS다. Changed-production Vulture confidence 100은 새 finding 0, 기존
Protocol parameter false positive 15건이다. 이 slice에는 migration, 실제 Supabase consumer
E2E, actor/browser/WebP/deploy가 없다. Consumer actual E2E는 P08/P10/P12-P13에서 검증한다.
3ac941d5는 마지막 writable PATCH와 그 exact replay에서 pre-PATCH catalog snapshot을 final
review에 재사용하던 경로를 제거했다. Application은 feature-local port만 의존하고, runtime이
명시적으로 조립한 orchestration이 저장된 현재 draft revision의 preparation authority를 확인한 뒤
26개 contribution을 materialize하고 owner-scoped provider에서 snapshot을 다시 읽는다. 그 fresh
snapshot만 final-review materializer에 전달된다. Cross-owner 호출은 contribution write 전에
거부되고, 현재 revision의 preparation authority가 없으면 값을 추정하지 않고 fail-closed하며 같은
PATCH replay가 준비를 다시 시도한다. Focused 21 passed, Tach affected 411 passed, full
6,921 passed, Ruff와 Tach dependency/interface/external gate가 PASS다. Vulture confidence
100의 13건은 기존 port Protocol parameter 후보이며 삭제 근거로 쓰지 않았다. 이 slice는
authority 생성 adapter 0/5나 모든 draft activation을 만들지 않았고 migration, 실제 Supabase
actor E2E, browser/WebP, deploy도 실행하지 않았다.
026a8ba4는 다섯 preparation source 중 reservation_state를 실제 runtime에 조립했다. 기존
customer_action_availability의 owner source-state와 revisioned mapping SSOT가 raw legacy 상태코드를
현대 lifecycle로 해석한다. 따라서 active pre-reservation은 pre_reservation 또는
pre_reservation_payment_pending lifecycle 결과로만 판단하고, 취소된 과거 pre-reservation flag를
현재 상태로 오인하지 않는다. 연장 intent는 같은 owner catalog의 exact opaque selection과 일치할
때만 continuation으로 확정하며 raw reservation id는 lineage 밖으로 내보내지 않는다. Extension
catalog publisher와 preparation source는 runtime에서 같은 query handler를 공유한다. Focused
11 passed, Tach affected 116 passed, full 6,925 passed, Ruff와 Tach
dependency/interface/external PASS, Vulture confidence 100 새 후보 0이다. Source adapter는
1/5이며 나머지 branch coverage, service-offering policy, price version, voucher criteria와
record-authority activation은 미완이다. Migration, 실제 Supabase actor/browser/WebP/deploy는 없다.
dcced6ad는 preparation branch_coverage source를 실제 runtime에 추가해 source adapter를
2/5로 전진시킨다. 기존 Supabase core branch의 active flag, active office lifecycle, positive
legacy compatibility id를 모두 요구하고 headquarters-internal profile은 제외한다. 고객 service
address와 desired start date를 각 후보의 revisioned service-area policy에 넣으며, 정확히 한
available 후보만 선택한다. 후보 0개/복수, 상담전용, 불가, missing policy, 중복 id, malformed
lineage는 모두 fail-closed다. Draft가 branch id를 제출하거나 첫 DB row를 고르는 fallback은 없다.
주소는 customer_input evidence로 fingerprint되고 원문은 preparation lineage에 복사되지 않는다.
Focused 10 passed, Tach affected 603 passed/6,308 deselected, full 6,932 passed,
Ruff/Tach dependency/interface/exact/external PASS, changed-production Vulture confidence 100
후보 0이다. SQL migration, actual Supabase actor/browser/WebP/deploy는 없고 나머지 세 source와
record-authority activation은 미완이다.
7af3496b는 preparation service_offering_policy source를 runtime에 추가해 source adapter를
3/5로 전진시킨다. Draft의 exact serviceOfferingKey를 catalog/branch/region/business-date
scope로 조회하고, effective row가 정확히 하나일 때만 선택한다. Service program,
service-type detail code, policy revision, inclusive pre-reservation day threshold는
source_reference.catalog_preparation_policy의 DB-owned 필수 메타데이터다. Label, DB row order,
legacy numeric id, 코드 기본값으로 추론하지 않는다. 메타데이터 누락, 후보 0개/복수, stale row,
selection drift는 fail-closed다. Source-row UUID, catalog version, policy revision,
updated_at, evidence key를 fingerprint/lineage에 동결한다. Concrete Supabase adapter는
main에서 application port로 주입해 orchestration이 adapter를 직접 import하지 않는다. Targeted
16 passed, Tach affected 254 passed/6,668 deselected, full 6,943 passed,
Ruff/Tach dependency/interface/exact/external PASS, changed-production Vulture confidence 100
후보 0이다. pnpm Supabase CLI 2.109.1은 준비됐지만 local stack container가 없어 DB/actor
검증은 실행하지 않았다. SQL migration, browser/WebP/deploy는 없고 price version, voucher
criteria, record-authority activation은 미완이다.
0809dc25는 preparation price_catalog_version source를 runtime에 추가해 source adapter를
4/5로 전진시킨다. 정규화 price import batch는 구버전
LIST_PRICE_VERSION_TB.PRICE_VERSION_LIST_ID_PK의 exact positive identity를
source_price_version_id로 직접 받아야 하며, catalog label/year/row order에서 번호를 만들지
않는다. Supabase CLI로 생성한 migration은 이 필드를 추가하고 누락된 batch의 published 전환을
차단한다. Pricing owner query는 요청 program과 희망 서비스 시작일에 유효한 published batch가
정확히 하나일 때만 선택한다. Voucher batch는 같은 batch의 published plan revisions에서
price_version_key도 정확히 하나여야 한다. 누락 source id, 후보 0개/복수, 중복 voucher key,
미래 publication/update, effective-date drift는 모두 fail-closed다. Batch UUID, source id,
program, catalog/version, effective window, publication, DB fingerprint, update timestamp를
lineage에 동결한다. Focused 50 passed, pricing/Supabase 184 passed, Tach affected
731 passed/6,205 deselected, full 6,957 passed, Ruff/Tach PASS, changed-production
Vulture confidence 100 후보 0이다. Local Supabase stack container가 없어 migration apply와
actor DB smoke는 실행하지 않았다. Voucher criteria, record-authority activation,
actual Supabase actor/browser/WebP/deploy는 미완이다.
68ce17dc는 다섯 번째 preparation source인 voucher_plan_criteria를 runtime에
조립해 source composition을 5/5로 닫는다. Browser가 제출한 baby/delivery/income option
key를 label, prefix, legacy id로 해석하지 않는다. Baby option은 draft에 동결된
birth.baby_types exact catalog revision과 source-backed quantity bounds로 실제 아기 수를
검증한다. Delivery/workforce와 income key는 승인된 voucher population catalog에서 exact-one으로
찾고, 두 catalog의 source revision, population, price batch/version, consume-type revision,
fingerprint가 모두 같아야 한다. 이어 같은 canonical axes의 exact published voucher-plan
revision을 다시 읽어 payload와 effective window를 교차검증한다. Unknown/guessed option,
baby-count 충돌, batch/version drift, ambiguous selection, incoherent revision, 미래 publication은
전부 fail-closed다. Pricing/reservation focused 140 passed, full 6,967 passed, Ruff/Tach
dependency/interface/exact/external PASS, changed-production Vulture confidence 100 후보 0이다.
새 SQL migration과 actual Supabase actor/browser/WebP/deploy는 실행하지 않았다. Source 5/5는
record activation을 뜻하지 않는다. 현재 v2 persistence guard가 preparation 평가일과 미래 서비스
시작일 기준 voucher quote date를 같게 강제하므로, 날짜 위상을 분리하기 전에는 실제 record를
활성화하지 않는다.
0934462d는 v3 persistence에서 두 날짜 위상을 분리하고 terminal PATCH/exact replay의
record-authority를 runtime에 활성화한다. evaluated_on은 DB가 계산한 현재 Asia/Seoul
영업일과 같아야 하고, quoted_on은 draft에 저장된
service_schedule.desiredServiceStartOn과 같아야 한다. 같은 RPC가 persisted
serviceOfferingKey, baby 배열 개수와 canonical baby type, 다섯 source lineage, source
window를 다시 검증한다. 성공한 경우에만 exact 26 contribution을 발행·재조회하며 record 실패는
그 이전에 fail-closed다. Scoped PostgreSQL 17에서 v1→v2→v3를 순차 적용하고 평가일
2026-07-18, 미래 견적일 2026-08-17을 실제 record/load해 projection revision 1,
동일 fingerprint를 확인했다. Focused 65 passed, 예약 생성 영역 425 passed, Tach affected
229 passed/6,727 deselected, full 6,977 passed, Ruff/Tach PASS, changed-production
Vulture confidence 100 후보 0이다. 이는 local Supabase stack이나 실제 actor 실행이 아닌
scoped PostgreSQL smoke다. Migration은 repository에만 있고 actual Supabase
actor/browser/WebP/deploy는 실행하지 않았다.
상위 결정은
ADR-031과
ADR-033이다. 기계 기준은
workflow/sanmopia_actor_chain.v1.yaml, 실행기는 backend
scripts/supabase_customer_reservation_creation_live_acceptance.py가 소유한다.
실제 owner browser → private Storage → atomic confirm 통합 증거
Section titled “실제 owner browser → private Storage → atomic confirm 통합 증거”증거 디렉터리:
/evidence/mother-family-conversational-booking/p04-live-signature-c6eb6f2c-ffacc939/.
manifest.json은
frontend ffacc93939528f0e21d098d8fdf41bef3f978f07, contract
132e1a4e1077770247a17397efffceeb0699c045, backend
c6eb6f2c467c4ca1d3fd1855d2abc11b74e4416b, 실행 전 assembly
aa47eb5500e6cb6bfe71820272d13a82f3f4bd78를 고정한다. Public artifact는 manifest 포함
56개이며 시각 asset 53개를 수동 개인정보 검수했다.
Supabase CLI 2.109.1 full replay는 migration 321/321, latest
20260719123000, public DB lint, Auth schema, Storage migration·object digest roundtrip,
signature orphan cleanup, confirm-vs-cleaner race, catalog smoke 7, exact-26,
contract/signature smoke, live acceptance, fixture teardown와 container/network/temp cleanup을
모두 통과했다. 실제 Chromium은 desktop/mobile 각각 새 test-owned draft를 사용해 열 카드를
순차 완료하고 계약 동의, raw PNG canonicalization, private immutable upload, READY 등록,
READY → CONSUMED, atomic acceptance·booking/payment handoff·outbox, 동일 confirm
HTTP 201 replay와 DB cardinality 1/1/1을 검증했다.
Actual 422, stale 409 explicit refresh, branch/caregiver 403, foreign mother 403,
missing-header 401, 단일 현재 카드, 완료 섹션 편집, 자동 focus/scroll, horizontal overflow
0도 같은 run에서 재검증했다. P05 소유 booking-status GET의 명시적 404 두 건은 예상
경계로 별도 기록했고, 그 외 console warning/error, page error, failed request는 0이다.




계약 동의·서명 capture provisional UI와 실제 backend 기술 증거
Section titled “계약 동의·서명 capture provisional UI와 실제 backend 기술 증거”증거 디렉터리:
/evidence/mother-family-conversational-booking/p04-signature-capture-ui-731f321d-e833eb15/.
manifest.json은
frontend e833eb15, contract ba6df817, backend 731f321d, 증거 수집 전 assembly
c80be389를 고정한다. 공개 파일 59, manifest asset 58이며
status=provisional, completionClaim=false,
runtimeEnvironment=local_astro_mocked_api다.
실제 Chromium은 desktop/mobile에서 현재 카드 수 1, 자동 scroll/focus, 완료 섹션 편집,
서버 주도 downstream invalidation, actual UI validation/conflict 상태 보존을 통과했다.
계약 화면은 서버 payload의 정확한 표시문구, bundle/retention revision, 필수·선택 item을
보여주고 필수 item 전에는 confirm을 막는다. Pointer/touch/keyboard canvas가 desktop
1440×1100과 mobile 390×844에서 raw PNG를 각각 세 번 mock transport에 보내며,
item·review binding 변경은 등록 상태를 즉시 폐기하고 clear/redraw를 요구한다. 등록 직후
브라우저 메모리의 Blob과 canvas pixel은 제거되고 중립 성공 placeholder로 치환된다.
Raw signature reference input은 없고 reference·PNG body·authorization·idempotency key 값은
공개 artifact에 남지 않는다. 예상 밖 console warning/error와 failed request는 0이다.




Backend 731f321d의 실제 disposable gate는 위 mock과 독립적으로 canonical PNG
POST/GET digest, private bucket, immutable collision, anonymous existence hiding, Storage
adapter, READY 등록, orphan cleanup, consume-vs-cleaner race와 tombstone을 검증한다.
이전 required-signature fail-closed pack은
새 pack으로 덮지 않고 역사 evidence로 보존한다.
최신 실제 산모 대여 선택 증거
Section titled “최신 실제 산모 대여 선택 증거”증거 디렉터리:
/evidence/mother-family-conversational-booking/p04-live-rental-288e14a7-93b8c2e1/.
manifest.json은
공개 asset 44개, 공개 파일 45개, 실제 production transport, 실제 산모 대여 선택,
대여 quote·charge lineage와 completionClaim=false를 함께 고정한다.
run-summary.json은
desktop/mobile 각각 열 카드와 revision 11, final review 200, 선택 key
health_cushion_rental, 장비료 0원, 예약 단위 왕복 배송비 10,000원, 고객 부담금
210,000원, rental catalog/selection SHA-256 두 개를 기록한다.



1개 · 배송비 포함 210,000원 · confirm disabled이 run은 voucher 일정에서 private duration/work 축을 전송하지 않고 voucher day만
저장한다. terminal PATCH가 source-owned voucher/rental catalog를 준비한 뒤 생성 시각을
확정하므로, 같은 요청이 방금 기록한 권위를 “미래 권위”로 잘못 거절하지 않는다.
공개 quote line은 pinned 계약의 여섯 필드만 내보내고 내부 정책 revision은
pricingRevisionKeys의 rental-catalog:sha256:*와 rental-selection:sha256:*로 보존한다.
Desktop 연락처 편집은 열 입력을 유지하면서 파생 권위 11개만 무효화·재투영했다.
Actual 422, stale 409, branch/caregiver 403, foreign mother 403, missing header 401
시나리오도 같은 pack에서 다시 통과했다.
이전 single-chat browser 증거
Section titled “이전 single-chat browser 증거”증거 디렉터리:
/evidence/mother-family-conversational-booking/p04-live-browser-35f67ff/.
manifest.json은
status=provisional, completionClaim=false,
runtimeEnvironment=disposable_local_supabase_gotrue_postgrest_fastapi_astro를 고정한다.
run-summary.json은
desktop/mobile revision 11, final review 200, confirm disabled와 desktop 연락처 편집 뒤
revision 12 reprojection, actual 422 current-card 유지, actual stale 409의 명시적
refresh·수동 재저장, branch/caregiver create 403, foreign-mother resume GET 403,
test-owned missing-header resume GET의 actual 401을 기록한다.








이 pack은 stateful route mock이 아니다. Browser cookie의 actual GoTrue access token,
Astro production build/preview의 true same-origin reverse proxy, production FastAPI route와
production Supabase adapter를 통과한다. 422 입력은 browser의 한 outgoing PATCH를 의도적으로
schema-invalid payload로 바꿨지만 FastAPI 응답, UI 복구, durable draft 무변경은 실제다.
단 source authority 일부는 명시적 disposable test-owned fixture이고 final review는 partial이다.
그러므로 production-source completeness나 confirmation-ready 성공을 증명하지 않는다.
이전 partial 실행도 삭제하지 않는다.
5-actor backend pack과
이전 browser pack은
역사 증거 인덱스이며, b4f6d46 validation/conflict pack과 9c506d2 non-mother create
authorization pack과 직전 4371660 current-frontend pack도 보존한다. 현재 browser 판정과
backend pin은 위 35f67ff pack이 소유한다.
현재 증거 결론
Section titled “현재 증거 결론”| 경계 | 실제 결과 | P04에서 증명하는 것 | 아직 증명하지 않는 것 |
|---|---|---|---|
| 통합 계약·서명 confirmation | desktop/mobile 새 owner draft 각각 actual canvas → canonical PNG → private Storage → READY → atomic confirm 201; exact replay 201, evidence/consumption/command cardinality 각 1, READY→CONSUMED, digest 일치 | 인증 산모 브라우저와 production FastAPI/PostgREST/Storage adapter, DB transaction을 한 run에서 연결한 P04 기술 A→Z | 실제 법무 승인 payload, production source authority, deployment, clean four-repository canonical pin |
| 산모 session/account link·recovery/party binding | verified Auth subject → exact mother/member/profile/revision proof → typed payment actor context → immutable payment lineage; resume decision → digest-only append-only audit; accepted draft/review → mother/booker/payer + expected revision 1 snapshot; service-role-only RPC/table, privacy lifecycle fail-closed | P04·booking·payment가 같은 backend-owned account link를 소비하고 member/profile drift 및 inactive mother payment를 거부하며 recovery success/denial과 booking party/revision lineage를 raw credential 없이 보존. Current-pin browser 회귀는 기존 resume UI를 다시 통과 | confirm이 비활성이므로 party snapshot을 만드는 browser confirmation 경로, sponsored-party binding |
| 역할·인증 | owner mother, foreign mother, branch operator, caregiver, family member 5명 | bearer 기반 산모 소유권, 비산모 거부, 가족권한 source identity | 배포 환경 identity |
| authorization | 미인증 401, branch/caregiver create 403, foreign mother owner draft read 403; actual browser branch/caregiver POST 403, foreign-mother resume GET 403, missing-header resume GET 401, 모든 draft card 0, safe copy·resume-key purge | route와 durable owner boundary, 비산모 create/read 거부 및 세션 header 상실의 실제 UI 복구 | wall-clock token expiry |
| validation | actual browser PATCH 422, 현재 applicant_authority 카드·safe message 유지, persisted revision 1·completed 0·input 무변경 | closed schema 실패 원자성과 current-card recovery | 모든 카드별 오류 조합과 production-source-complete run |
| conflict | actual stale PATCH 409, expected 1/current 2, blind retry 0, explicit GET 뒤 수동 저장 revision 3 | CAS 충돌, 최신 projection 명시적 refresh, 사용자 검토 없는 재PATCH 금지 | 모든 step concurrent edit와 confirmation conflict |
| exact replay | create·step PATCH replay와 desktop/mobile actual confirmation replay 201; acceptance·booking/payment handoff·outbox·signature consumption 중복 0 | 동일 key가 revision이나 durable result cardinality를 중복 증가시키지 않음 | 실제 법무 승인 bundle을 사용한 production replay |
| 가족 신청권한 | sponsorship 1개, delegated payment 1개, opaque reference 2개 | raw grant ID를 browser option으로 노출하지 않고 Member Management authority를 catalog에 바인딩 | 권한 철회 UI와 booking 이후 payer snapshot |
| 연장 신청권한 | eligible source 1개, opaque option 1개, catalog authority revision 3 | 레거시 연장 가능 조건을 source-owned state mapping으로 결정하고 raw reservation id를 browser에서 숨김 | 연장 예약 confirm과 원본·신규 예약 연결 |
| 프로모션 권한 | owner-scoped catalog, proven-empty owner, opaque/raw split, 변경 뒤 revoke, source-order 다중 할인과 payable cap | 유효 상태·기간·revision을 source-owned DB에서 결정하고 raw entitlement UUID와 browser 순서를 가격 권위에서 제거하며 quote·charge·payment amount를 일치시킴 | 실제 산모 actor/browser 선택과 provider 결제 |
| 민간요금 원본 | actual workbook 20/20, issue 0, source SHA/commit pin, projection 4/2/10, publication DB smoke PASS | 구버전 요금·기간·근무형태·추가요금 의미를 정규 domain catalog entry로 보존하고 세 source-owned catalog를 동일 batch fingerprint에 결속 | 실제 workbook 20행 운영 batch 발행, automatic preparation, quote/booking 사용 |
| voucher 출산순위·제공인력 | actual workbook 198/198, issue 0, baby group 4, stable delivery code 8, approved-population DB smoke PASS | 숫자 DB id와 조건 switch 대신 source code·domain label/workforce policy·approved lineage를 한 catalog에 결속 | 실제 산모 actor/browser 선택, 자동 refresh, quote/booking 사용 |
| 대여용품 | source-reviewed option 5, 장비료 0/15,000원, 예약당 왕복 배송비 최대 1회 10,000원; 실제 HQ UI 5 → 6, exact replay, altered replay 거절·DB 무변경, 비권한 GET/POST 403, revision 2·supersession 1·evidence 1, cleanup PASS; backend 7f51408b selection→quote→handoff→booking workflow→finalized charge code gate PASS | 숫자 DB id와 PHP 화면·엑셀 분기를 stable key·승인 revision·공유 정산 catalog로 치환. 용품/비목 변경은 catalog revision 변경으로 처리하고 코드 하드코딩을 금지한다. 실제 HQ actor와 production adapter/composition 및 responsive UI가 같은 immutable publication을 소비한다. 예약 명령은 offering·선택·catalog revision·quote line·charge handoff를 exact 검증하고 finalized rental line에 catalog policy version을 보존한다. | authenticated mother의 legal confirmation과 실제 Supabase accepted evidence·booking handoff·lineage·replay. 후속 결제·서비스·문서·정산 실행은 각 후속 phase 소유 |
| 관리사 서비스 우선순위 | source-reviewed option 3, ordered unique 최대 3개, source anchor 5개, DB smoke PASS | 숫자 0/1/2, 반복 select, 순차 insert를 stable key·승인 revision·공유 matching policy로 치환 | 실제 산모 actor/browser 선택, personality/recommendation 결합, final review/booking 사용 |
| 관리사 성향 | source-reviewed question 6, option 12, exactly one per question, source anchor 7, DB smoke PASS | numeric DB id, blind pair grouping, 반복 markup, delete/reinsert를 stable key·승인 revision·공유 matching policy로 치환 | 실제 산모 actor/browser 선택, recommendation 결합, final review/booking 사용 |
| 관리사 추천 | frozen recommendation set, decision revision 9, opaque selection reference, exact-26 DB smoke PASS | raw MANAGER_ID_PK hidden input/carousel data-id를 browser 권위로 복사하지 않고 internal lineage로 격리 | 실제 산모 actor/browser 선택, final review/booking assignment handoff |
| 지역 지원 프로그램 | source-reviewed v4+ empty revision, source anchor 7, DB smoke PASS; backend 8e37ab8a가 exact catalog fingerprint·preparation region/branch/price-version과 고정/비율/component 금액 공식을 재검증해 selected option의 quote·credit·charge revision을 계산하고 backend 8b214509가 완전한 accepted discount-only decision을 internal booking mapping과 command에 전달 | 완주군/영등포구 조건 분기를 주소 문자열·DOM·price-version 하드코딩이 아니라 region code·version window·승인 revision으로 치환; option JSON에 금액을 복사하지 않고 pricing SSOT만 사용; application consumer contract가 public review/quote/catalog lineage를 exact 검증 | 실제 승인된 non-empty option row와 실제 산모 actor/browser 선택, accepted booking handoff에 exact support lineage 동결; 후속 booking 처리·정산 소비는 P05/P12-P13 소유 |
| happy-path core | API와 actual desktop/mobile browser 각각 열 step, revision 1 → 11, completedStepCount: 10 | draft transport·normalization·persistence·단일 채팅 순차 disclosure | production-source-complete final review와 booking handoff |
| final review | contract-valid partial projection, draft/catalog-derived display facts, actual browser HTTP 200, readable warning, confirm disabled, confirmationReady.ready: false | retained step facts, branch/profile/policy scope, source-owned partial authority와 UI fail-closed 표시 | 모든 draft의 preparation activation, contract/legal/finalized-booking authority, real non-empty regional-support runtime proof, confirmation-ready final review |
| browser integration | actual GoTrue cookie → Astro production build/preview same-origin proxy → production FastAPI → PostgREST/Supabase, desktop/mobile 10-step, actual 422/409, 단일 현재 카드, 자동 focus/scroll, overflow·console·page·failed request 0 | mocked route나 CSP 우회가 아닌 실제 local integration, partial review 렌더링, 완료 연락처 편집 뒤 revision 12 exact reprojection | production source rows, confirmation-ready legal confirm과 booking handoff |
| edit/reprojection | 연락처 변경 뒤 completed input 10개 보존, 파생 authority section 11개 invalidation, revision 12 final review 재조회 | 입력 SSOT와 파생 권위 invalidation을 분리하고 사용자가 이후 답을 다시 입력하지 않음 | 모든 step별 dependency 반례와 concurrent edit |
| cleanup | 이전 5-actor pack은 Auth/draft/source/contribution 0/0/0/0; current-pin browser run은 종료 직전 test-owned Auth 11, draft 6, recovery audit 4를 확인한 뒤 private fixture 삭제, tmpfs DB/Auth/REST 컨테이너·네트워크 제거, 4327/4328/55434–55437 포트 폐쇄 | 영속 운영 DB에 test-owned runtime residue 없음; 공개 WebP/PNG/manifest만 보존 | production 환경 cleanup |
실행 중 생성된 사용자·draft 식별자와 bearer token은 disposable이며 문서에 저장하지 않는다.
실제 열 단계
Section titled “실제 열 단계”applicant_authoritymother_contactservice_addressesbirth_and_babiescare_environmentservice_offeringservice_scheduleadditional_servicescaregiver_matchingcontract_and_payment_preference
각 PATCH는 expected revision과 별도 idempotency key를 보냈고 revision을 정확히 하나씩
증가시켰다. stale write는 draft_revision_mismatch로 거부됐다.
운영 catalog registry
Section titled “운영 catalog registry”Fresh migration 뒤 실제 DB registry 조회 결과는 다음 26개다.
| Catalog key | Source-owned producer |
|---|---|
applicant_authority.delegated_payment_references | member_management.family_payment_delegation |
applicant_authority.eligible_extension_source_reservations | reservation_operations.customer_action_availability |
applicant_authority.sponsorship_references | member_management.family_sponsorship |
birth.baby_genders | reservation_operations.birth_information |
birth.baby_types | reservation_operations.birth_information |
birth.care_center_terms | reservation_operations.birth_information |
birth.delivery_types | reservation_operations.birth_information |
birth.older_child_counts | reservation_operations.birth_information |
care_environment.pet_sizes | reservation_operations.customer_reservation_creation.legacy_php_reference_options |
care_environment.pet_species | reservation_operations.customer_reservation_creation.legacy_php_reference_options |
caregiver_matching.personalities | caregiver_assignment.caregiver_matching_profile.personality_answers |
caregiver_matching.recommendations | caregiver_assignment.caregiver_matching |
caregiver_matching.religions | reservation_operations.customer_reservation_creation.legacy_php_reference_options |
caregiver_matching.priorities | caregiver_assignment.caregiver_matching_profile.service_priorities |
additional_services.service_options | pricing_settlement.price_catalog_import |
additional_services.rental_options | pricing_settlement.pricing.rental_equipment |
contract_and_payment_preference.payment_methods | pricing_settlement.payment_product_plan |
contract_and_payment_preference.promotion_entitlements | pricing_settlement.promotion_entitlement |
contract_and_payment_preference.support_programs | pricing_settlement.regional_benefit.support_programs |
mother_contact.emergency_relationships | reservation_operations.customer_reservation_creation.legacy_php_reference_options |
service_offering.offerings | reservation_operations.service_offering_availability |
service_offering.voucher_delivery_rank_and_workforce | pricing_settlement.price_catalog_import |
service_offering.voucher_income_types | pricing_settlement.price_catalog_import |
service_schedule.durations | pricing_settlement.price_catalog_import |
service_schedule.voucher_service_days | pricing_settlement.price_catalog_import |
service_schedule.work_schedules | pricing_settlement.price_catalog_import |
Publisher registry 26/26은 production orchestration coverage다. 운영 source fact
completeness와 같은 뜻이 아니다. 이번 actual run은 repository에 없는 운영/legacy authority를
추측하지 않고 명시적인 p04-test-owned source fixture로 transport와 publisher 경로만 검증했다.
레거시 PHP에서 확인한 source lookup 이름은 LIST_RENTAL_TB, LIST_PREFERENCE_TB,
LIST_MANAGER_PERSONALITY_TB, LIST_ADD_OPTION_NORMAL_TB,
LIST_ADD_OPTION_VOUCHER_TB, LIST_VOUCHER_CONSUME_TYPE_TB다. 원본 MySQL
dump/seed 또는 승인된 운영 publication이 없으면 production source import는 계속 fail-closed다.
A→Z 검증 절차
Section titled “A→Z 검증 절차”-
A — 현재 phase와 immutable backend 고정
P01
P03 PASS, P04 RED, P05P13 blocked인지 YAML과 문서에서 확인하고 backend SHA를 기록한다. -
B — legacy intake 축 대조
reservation_check_data.php,reservation_payment.php와 lookup 이름을 읽어 열 step의 field가 누락·혼합·임의 생성되지 않았는지 대조한다. -
C — fresh schema 재생
disposable local Supabase DB를 reset하고 full migration이 적용되는지 확인한다. 분석용 SQL 복제 DB를 제품 authority로 쓰지 않는다.
-
D — 실제 identity authority 기동
local GoTrue와 PostgREST를 기동하고 owner mother, foreign mother, branch operator, caregiver, family member 다섯 test-owned identity를 생성한다.
-
E — actor projection seed
production actor resolver가 읽는 profile/role projection, active family membership·sponsorship· payment delegation, 연장 가능한 source reservation과 state-mapping revision을 넣는다. body에서 role, mother id, owner id, raw grant/reservation id를 받지 않는다.
-
F — production adapter composition
FastAPI route에 Supabase HTTP draft store, Auth resolver, catalog/final-review resolver를 연결한다.
-
G — 미인증·비산모 거부
unauthenticated create
401, branch/caregiver create403과 primary state 무변경을 확인한다. -
H — 산모별 owner 격리
foreign mother는 자기 draft를 만들 수 있지만 owner mother draft GET은
403이어야 한다. -
I — test-owned source authority 격리
branch/offering, voucher/private-care price, birth option, caregiver recommendation 등 repository에 없는 운영 source fact는 명시적인 test-owned identity로 넣는다. 그 뒤 26개 production publisher를 모두 실행한다. Fixture는 transport·validation·persistence를 증명할 뿐 운영 source completeness나 confirmation readiness를 증명하지 않는다.
-
J — draft create와 exact replay
owner create
201뒤 같은 key/payload replay가 같은 outcome을 반환하며 draft를 중복 생성하지 않는지 확인한다. -
K — typed validation
잘못된
applicant_authorityPATCH가422이고 revision과 step input이 그대로인지 확인한다. -
L — 열 step 순차 PATCH
각 step을 expected revision으로 저장하고
nextRequiredStepKey가 다음 카드로 이동하는지 확인한다. -
M — stale revision conflict
과거 revision PATCH가 typed
409이고 accepted answer와 하위 state를 바꾸지 않는지 확인한다. -
N — PATCH exact replay
accepted step의 동일 key/payload replay가 revision과 command replay cardinality를 늘리지 않는지 확인한다.
-
O — durable cardinality
draft 하나가 revision
11, completed step10, owner command replay11인지 실제 DB에서 읽는다. -
P — partial final review fail-closed
terminal PATCH가 current revision authority record → 26 publishers → exact-set materialize → projection으로 이어지고 final review가
200인지 확인한다. 동시에 test-owned source로confirmationReady를 꾸미지 않고 정확히false인지, unresolved 7개 authority fact가 그대로 남는지 확인한다. 이 상태에서는 confirm을 호출하지 않는다. -
Q — cleanup
backend와 browser 증거 수집이 끝난 뒤 전용 Auth users, draft, replay row와
sanmopia-p04-*container, port55434~55437이 모두0인지 확인한다. -
R — architecture·dead-code gate
layer-first import와 explicit public port를 Tach로 검사하고 Vulture confidence 100 finding은 삭제 권한이 아닌 검토 근거로만 사용한다.
-
S — production publisher completion
source owner별 26개 publisher가 모두 등록됐는지 확인한다. 이 조건만으로 P04 PASS를 주장하지 않고 automatic snapshot refresh와 final-review success로 이어지는지 별도 검증한다.
-
T — automatic snapshot preparation
create/edit가 현재 26개 contribution exact set을 자동 materialize하고 수정 dependency만 invalidate/refresh하는지 검증한다.
-
U — production final review
test fixture 없이 열 step 뒤 server-built final review가
200이고 모든 retained legacy field와 source lineage를 보여주는지 검증한다. -
V — atomic legal confirmation과 booking handoff
산모가 그린 raw PNG는 bounded stream으로 받고 MIME·magic·크기·dimension·blank/polyglot을 검증한 뒤 metadata를 제거한 canonical PNG만 전용 private Storage에
upsert=false로 저장한다. 서버가 현재 owner/draft/review/fingerprint/bundle/선택 item에서 binding을 만들고 READY metadata를 등록하며 opaque reference만 브라우저에 반환한다. 그 다음 서버 승인 bundle의 exact 표시문구·문서 revision/digest, item별 결정, 서명 evidence와 customer reservation, payment-ready obligation/handoff, audit/outbox가 한 idempotent transaction인지 실제 Supabase에서 검증한다. 동일 confirm은 accepted evidence와 booking handoff를 중복 만들지 않고, signature/document/wording 또는 expected revision drift는 전체 무변경 conflict여야 한다. Handoff에는 service/caregiver/time/quote/payment/coverage와 report/document/settlement가 나중에 검증할 immutable lineage를 동결한다. P05-P13 command를 이 단계에서 실행해 P04 PASS를 증명하지 않는다. Backendc6eb6f2c, contract132e1a4e, frontendffacc939의 disposable run은 actual authenticated owner browser에서 upload validator·private bucket·READY registration·one-time consumption과 atomic confirm을 desktop/mobile 모두 연결해 기술 경계를 GREEN으로 닫았다. 사용한 contract publication은 synthetic test-owned라 법적 P04 acceptance는 계속 RED다. -
W — 실제 single-chat Chromium desktop
한 채팅뷰에서 현재 카드 하나만 열리고 저장마다 다음 카드가 나타나며 자동 scroll되는지 실제 backend network로 캡처한다. Frontend
ffacc939의 Astro production build/preview same-origin 경로에서 partial flow와 별도 confirmation-ready draft를 모두 통과했다. Production-source-complete legal confirmation run은 남았다. -
X — 실제 mobile·편집 회귀
완료 섹션 편집, dependent invalidation, validation, conflict refresh를 mobile viewport에서 검증하고 horizontal overflow·예상 밖 console·failed request가
0인지 확인한다. Current run은 mobile 10-step과 overflow/error0, desktop 연락처 편집·revision12reprojection, actual422, stale409, desktop/mobile signature confirmation까지 통과했다. P05 소유 status endpoint의 expected404는 별도 boundary로 보존한다. -
Y — redaction-reviewed animated WebP
success, edit, validation, conflict, authorization의 상태 전이를 WebP로 만들고 token·PII·disposable id를 제거한 뒤 이 페이지에 포함한다. Actual local desktop/mobile success,
422validation, mobile409conflict, branch/caregiver403authorization WebP와 redaction manifest를 등록했다. Current pack은 desktop/mobile 실제 signature confirmation WebP와 성공 PNG까지 포함하며 시각 asset53개 수동 privacy review를 완료했다. Production legal confirmation WebP는 남았다. -
Z — clean four-repository pin과 PASS 전환
assembly/contract/backend/frontend의 immutable clean pin, machine manifest, Chromium/WebP와 cleanup을 같은 run에 고정한 뒤에만 P04를 PASS로 바꾸고 P05를 RED로 연다.
본사 대여용품 관리자 UI supplemental evidence
Section titled “본사 대여용품 관리자 UI supplemental evidence”
Backend 4c9dd40f·frontend 3dd5779의
A→Z 실제 actor 절차와 모바일 카드 증거는
real GoTrue·SpiceDB·PostgREST·Supabase PostgreSQL, production adapter/composition,
route-interception 없는 Astro production Chromium을 연결한다. Material rail·desktop table,
390px 별도 세로 카드, exact replay·conflict·unauthorized·DB 계보·cleanup을 통과했다.
본사 대여용품 관리 하위 게이트는 GREEN이지만 P04 전체 상태는 바꾸지 않는다.
남은 완료 조건
Section titled “남은 완료 조건”- terminal PATCH/replay의 current-revision exact-set refresh와 preparation source
composition
5/5, v3 date split, record→publish→reload runtime activation은 local Supabase migration과 5-actor actual HTTP run까지 완료; 승인된 production source fact 증거는 미완 - test-owned source fixture 없는 production final review
200와confirmationReady=true - signature metadata의 exact owner/draft/review/fingerprint/bundle/item binding, append-only READY→CONSUMED, same-idempotency replay, cross-command reuse·tamper 거절
- backend raw PNG bounded validation → canonicalization → 전용 private Storage immutable upload → READY 등록 → opaque reference 반환; PENDING/expired READY cleanup과 cleaner race
- mock browser에서 item/edit/review/projection/bundle 변경 시 frontend reference 즉시 폐기, desktop/mobile draw·clear·retry·uploading·ready·stale conflict 실증
- 실제 authenticated owner browser → production FastAPI → private Storage → READY → atomic confirm을 desktop/mobile 하나의 disposable full replay로 검증
- 실제 법무 승인 bundle을 사용한 legal acceptance와 confirm replay/conflict
- 실제 non-empty regional-benefit 선택·quote가 booking handoff의 immutable lineage에 동결
- production-source-complete 법무 confirmation run의 authenticated mother desktop/mobile 재검증
- synthetic test-owned confirmation-ready success와 기존 validation·conflict를 포함한 desktop/mobile redaction-reviewed WebP 수집
- actual HQ actor의 current rental GET → revision 편집 → immutable POST → exact replay/conflict/unauthorized → DB receipt/history → desktop/mobile WebP → cleanup
- selected rental stable key → immutable selection revision → quote/payable → charge handoff pricing revision → accepted booking command → Restate input → finalized charge line policy version code gate; unknown/duplicate/branch-unconfirmed/tampered lineage 거절
- authenticated mother browser의 rental 선택 → 실제 Supabase draft/materialization → voucher price quote/payable → immutable charge handoff → desktop/mobile final review와 WebP
- confirmation-ready legal confirm → 실제 Supabase accepted evidence·booking handoff· payment-ready obligation/outbox → exact replay/conflict → payment/service/report/document/ settlement용 immutable rental revision lineage 동결
- clean assembly/contract/backend/frontend immutable pins
이 항목이 모두 닫히기 전 P04의 공식 상태는 RED다. P05 booking 처리부터 P13 HQ 정산까지의 실제 실행은 각 phase가 current가 된 뒤 자체 actor/state 증거로 닫는다.
최신 검증 요약
Section titled “최신 검증 요약”- current contract follow-up:
5efda8a1는 import/type entry와 test-artifact 제외를 복구했고,50d8e430은 같은 approval packet과 source bytes를 재검증한 뒤 전체 packet을 key-order 독립 canonical JSON으로 내보내는 public API/CLI handoff를 추가했다. Contract full은55 suites / 518 tests, production artifact114, test artifact0, 연속 build aggregate SHA 동일이다. 이 handoff는 DB write를 하지 않으며 production publisher나 실제 법률 승인 값을 추가하지 않으므로 P04 phase 판정은 그대로다. - current frontend follow-up:
d2529845는 산모 최종검토에서 bundle·retention·signature revision, wording/document digest, MIME 같은 내부 메타를 숨기고 승인 문구·필수/선택·서명 동작만 남겼다. Colocated51, frontend full631tests와 Astro 7.1 check/build가 통과했다. Mocked desktop/mobile actor replay도 단일 현재 카드, 순차 reveal, 자동 scroll/focus, 완료 답변 편집, 동의·서명 A→Z, console/failed request0을 통과했다. 이 UI-only replay는 아래ffacc939integrated backend pack을 대체하지 않으므로 current pin의 actual full replay는 아직 필요하다. - current integrated technical replay: contract
132e1a4e, backendc6eb6f2c, frontendffacc939; Supabase CLI2.109.1, migration321/321, latest20260719123000, DB lint/Auth/Storage/catalog/exact-26/contract/signature/race PASS. Desktop/mobile 실제 owner browser가 private Storage READY→CONSUMED, atomic confirm201, exact replay201, durable evidence/consumption/command1/1/1, actual422/409/403/401, 단일 카드·자동 focus/scroll·overflow0을 통과했다.p04-live-signature-c6eb6f2c-ffacc939은 public file56, visual asset53과 manual privacy review를 고정한다. Full replay backend85f127ef재실행의cleanup-source-receipt.json과cleanup-manifest.json은 browser manifest/run-summary SHA와 container/network/process/private fixture/temp 잔여0을 고정한다. 이 cleanup PASS는 법무·운영 권위를 대신하지 않으므로 P04 phase RED다. Synthetic legal authority와 dirty assembly authoring state 때문에status=provisional,completionClaim=false, P04 RED다. - current contract/signature technical gate: contract
ba6df817, backend731f321d, frontende833eb15; no-seed immutable bundle publication/current/exact query, exact wording/document/retention/signature-policy snapshot, DB canonical command time, stored draft/review/current-bundle locking, exact-bound signature READY→CONSUMED, canonical PNG/private Storage/READY registration, orphan cleanup과 cleaner race, acceptance·booking/payment handoff·outbox atomic replay/tamper guard. Supabase CLI2.109.1, migration320/320, latest20260719120000, DB lint/auth/storage, catalog smoke7, exact-26, contract/signature smoke PASS. Python7,250, Ruff PASS, Tach all/exact diagnostics0, changed P04 Vulture 100 candidate0 - provisional signature UI pack:
p04-signature-capture-ui-731f321d-e833eb15, 파일59, asset58, desktop/mobile sequential reveal·auto scroll/focus·완료 섹션 편집, canvas raw PNG upload 각3, binding invalidation·redraw·mock confirm, console/page/failed request0. Mocked API와 synthetic legal values라 backend runtime/confirm, durable persistence, 법무 승인, deployment proof는 모두false - current pins: contract
b487fafdfa01aa6971908426a9e43c5d2a90bce9; backend288e14a788b88e8a319280de02f877dc1573667e; frontend93b8c2e1f459e08538e92b94184834c90f0ed322 - current actual mother rental gate
288e14a7+93b8c2e1: real owner browser가health_cushion_rental을 선택하고 source-owned voucher/rental catalog를 terminal PATCH에서 준비한 뒤 final review200에 도달했다. Voucher schedule은 private 축을 null로 유지하고 10 service occurrences를 계산한다. Quote는 장비료0, 왕복 배송비10,000, customer payable210,000이며 charge handoff에 rental catalog/selection SHA-256을 보존한다. Desktop/mobile 열 단계, 자동 focus/scroll, 편집/reprojection, actual422/409/403/401, 공개 파일45, manifest asset44, console/page/failed request0PASS. Backend full7,087, frontend95 files / 592 tests, Ruff/lint/Astro check/build, Tach diagnostic0PASS. Vulture 100 후보 1건은 실제 구현·호출되는 Protocol 인자의 오탐이다. Confirm은 legal acceptance와 booking handoff 부재로 의도대로 비활성이라 P04는 RED다. - latest actual local backend/browser evidence pin
35f67ff9: disposable GoTrue/PostgREST/Supabase + production FastAPI transport, actors5, completed steps10, revision11, production publisher materialization26/26, final review200, authority sections14, internal retained-intake lineage8, public lineage leak0, confirmation readyfalse - current backend code gate
4f1eea71:missingFactPaths에서 confirmation blocker를 파생하고supportAndDiscountDecisions를 명시적 권위로 추적한다. 기술 권위 전체 fixture는serviceContract.acceptance만 missing이고 reason은authoritative_projection_partial,contract_acceptance_missing만 남는다. Targeted14 passed, full7,040 passed, Tach affected457 passed/6,562 deselected, dependency/interface/exact/external diagnostics0; Vulture 100 후보 3건은 sourceProtocol의evaluated_at구현·전달·호출을 확인한 false positive다. - current full-history DB gate
31ac8845: pinned PostgreSQL/GoTrue/Storage bootstrap 뒤 repository migration315/315, latest20260718180000, Supabase public-schema lint error0, exact-26 materializer smoke, disposable resource cleanup PASS; stage/production·actor/browser/WebP 실행 아님 - current data-driven catalog gate
31ac8845: 같은315/315clean replay 위 voucher/private-care/promotion/regional-support/rental/priority/personality smoke7/7; rental은 기존 option5와 replacement option2, first publish/different-author exact replay/original-publisher preservation/conflict/history 분기까지 검증; priority3, personality6 questions / 12 options, publisher26, exact-26와 cleanup PASS - current HQ rental actual gate
4c9dd40f+3dd5779: real GoTrue HQ/비권한 actor → accepted HQ manage SpiceDB → production adapter/composition → actual GET/UI edit/POST5 → 6→ exact replay → altered replay503/DB 무변경 → 비권한 GET/POST403→ direct SQL revision2/supersession1/evidence1→ desktop table/mobile cards/overflow·error0→ actor/relation/runtime cleanup PASS; route interceptionfalse - current admin UI
3dd5779: Material rail, TanStack desktop table, separate mobile cards, immutable revision editor, same-origin server boundary, cross-site POST rejection;95 files / 591 tests, lint, Astro 7 check/build PASS - current rental evidence:
live-4c9dd40f-3dd5779은 actual WebP6개와 DB JSON을 고정한다. 본사 관리 하위 게이트는 GREEN이다. Backend7f51408b는 selection/quote/booking/finalized-charge code gate를 닫았지만 authenticated mother browser의 legal/final confirm과 실제 accepted evidence·booking handoff 미완으로completionClaim: false; settlement/document actual 실행은 후속 phase 소유 - current backend regression
7f51408b: Python7,079 passed; focused rental/booking/HTTP/charge153 passed; Ruff PASS; Tach MCP dependency/interface/exact/external diagnostic0; Vulture MCP confidence-100 새 contract/query candidate0 - accepted regional-support gate
8b214509: selected regional-support quote amount SSOT와 complete accepted discount-only booking handoff를 보존한다. 현재 v4+ production catalog가 proven-empty라 non-empty production rule/actor/browser evidence는 없다. - current fail-closed authority model:
branchServiceAreaDecision,eligibleServicePlan,eligibleServicePlan.serviceOfferingAvailabilityDecision,caregiverCandidateDecision,priceQuote,supportAndDiscountDecisions,reservationCreationChargeSnapshotHandoff,paymentPreparation,serviceContract.acceptance를 실제 resolve 결과에 따라 추적한다. Test-owned source facts를 운영 권위로 승격하지 않는다. - latest actual local browser at backend
35f67ff9: GoTrue cookie → Astro production build/preview same-origin proxy → production FastAPI/PostgREST/Supabase, desktop/mobile 10-step, revision11, 14-section partial final review200, confirm disabled, warning readable-width PASS, single current card·focus/scroll PASS, overflow/console/page/failed request0; 연락처 edit는 revision12, completed inputs10개 보존, derived authority11개 invalidation 뒤 exact revised review reload PASS; actual422는 current card와 persisted revision1을 보존; actual stale409는 blind PATCH 없이 explicit GET 뒤 수동 revision3저장 PASS; branch/caregiver actual create는 각각403; foreign mother actual owner-draft resume GET은403; test-owned missing-header resume GET은 actual401; 모두 draft card0, safe copy, cross-session resume key purge PASS - latest browser evidence:
p04-live-browser-35f67ff, public files45, manifest asset entries44, animated WebP6개(desktop/mobile success·desktop422·mobile409·branch/caregiver create403·foreign mother/missing-header resume403/401)와 readiness/edit screenshot,status=provisional,completionClaim=false, production source completeness/confirmation readiness/deployment prooffalse; backend35f67ff9browser-evidence pin이며 confirm-disabled 경계라 party snapshot 생성은 실행하지 않음 - terminal PATCH/replay final-review catalog: 저장된 current draft revision으로 prepare → exact-26 materialize → owner-scoped reload → projection; pre-PATCH snapshot 재사용 제거, cross-owner pre-write 거부, authority 부재 fail-closed
- preparation sources
5/5: reservation state는 revisioned legacy-state mapping과 owner exact opaque extension selection을 사용하고, branch coverage는 active core/office 후보를 revisioned service-area policy로 평가해 exact-one available만 선택하며, service-offering policy는 exact effective row의 DB-owned program/detail/revision/day-threshold 메타데이터만 허용하고, price catalog version은 published import batch의 explicitsource_price_version_id와 voucher uniqueprice_version_key만 허용하며, voucher criteria는 persisted baby catalog quantity authority와 approved delivery/income population 및 exact published revision을 한 lineage로 교차검증 - catalog preparation v3: DB Seoul 평가일과 persisted desired-service-start 견적일 분리, persisted offering/baby facts 재검증, terminal PATCH/replay에서 five-source record → exact-26 publish → owner-scoped reload; scoped PostgreSQL actual record/load PASS, actual Supabase 적용은 미검증
- direct local PostgreSQL migration: production publisher
26/26 - 승인 voucher population DB smoke: source-order
0, keyconsume_type_a_ga_1, labelA-가-1형, 누락 축 fail-closed, transaction rollback - smoke 뒤 voucher source revision/population/catalog revision
0/0/0; 이전 5-actor cleanup의 Auth/draft/source/contribution0/0/0/0유지 - 실제 actor run: 5 actors, 10 completed steps, draft revision
1 → 11 - 가족권한: production catalog
2, selectable option2, opaque reference2, raw authority는 내부 lineage에만 보존 - 연장권한: production catalog
1, selectable option1, catalog/selection reference opaque, raw reservation id는 내부 lineage에만 보존 - HTTP 분기: unauthenticated
401, branch/caregiver403, foreign owner read403, validation422, stale revision409, final review partial projection - session recovery audit: success exact revision + 7 denial reason, digest-only event/row, authority outage를 customer denial로 오기록하지 않음, audit unavailable은 HTTP
503fail-closed - booking party authority: account-link proof + accepted draft/review lineage로 direct mother의 mother/booker/payer roles와 expected new-booking revision
1을 생성; public input 거부, trusted Restate 전달, booking/payment/snapshot atomic save, exact replay, drift/stale rollback, append-only service-role-only ACL actual DB PASS - final-review retained display facts: mother contact, service address, service offering label, duration/work schedule labels, additional service/rental labels, requested service occurrences, caregiver selection mode, selected payment method
- accepted retained intake snapshot: emergency contact, birth/babies, pet facts와 exact option label·catalog/authority lineage를 fingerprinted internal mapping에 동결; accepted booking translator는 current operational care environment 대신 이 snapshot만 소비해 검토 후 drift를 차단
- public retained-intake review: 14번째 required
customerIntakeDisplaySnapshot이 internal snapshot에서 public-safe contact/birth/baby/pet display를 투영하고 raw authority·catalog lineage를 제외; frontend는 responsive 세로 카드와 section-local edit로 바인딩 - accepted service offering: full availability decision을 catalog fingerprint에 보존하고 exact enabled selected option/full-reservation handoff/policy source revision만 internal booking mapping에 동결; lineage drift는 fail-closed
- final-review branch coverage: current preparation authority가 있을 때 source branch → branch profile → revisioned policy query, lookup keys/matched depth/rule/profile/veto/address fingerprint 유지; authority absent면 missing 유지
- final-review service calendar: structured catalog
serviceDayCount+ branch calendar profile + effective Supabase profile + national/matching-branch holiday가 있을 때 기존 domain으로 billable occurrence/end date/policy fingerprint 계산; authority absent면 plan/calendar missing 유지 - final-review price quote: voucher exact entry 또는 private duration/work-schedule entry 교집합 + current effective Supabase publication + 기존 pricing domain으로 quote; exact 1개가 아니면 partial 유지
- final-review charge handoff: draft revision + exact price catalog/version/entry + payable amount로 replay-safe id와 pricing revision을 생성; quote 없으면 missing 유지
- atomic payable confirmation: exact charge/payment projection을 재검증하고 waiting ADR-020 obligation + 공개 payment handoff + acceptance/outbox를 한 Supabase transaction에 기록
- payment boundary: P04는 provider를 호출하거나 paid로 표시하지 않는다. Legal confirmation과 accepted booking handoff/readiness activation은 미완이며, 실제 booking 처리와 payment execution은 P05/P07 소유
- promotion entitlement DB smoke: owner 격리, proven-empty owner, opaque browser/raw internal authority split, redeem/revision 변경 뒤 revoke, outer rollback
- private-care publication DB smoke: 대표 entry
2, first publish/replay/immutability PASS, publisher22/26, rollback residue0; Supabase DB lint error0 - voucher delivery DB smoke: approved single population, source position
0, stable delivery code, service-role-only execution, publisher22/26, outer rollback PASS - rental equipment DB smoke: source-reviewed 기존 option
5, replacement option2, stable key/source order, 장비료·배송비·지점확인 규칙, server-computed fingerprint/count, service-role-only publication/load RPC, immutable revision/supersession rows, first publish/exact replay/same-key conflict/history selection, publisher22/26, outer rollback PASS - service priority DB smoke: source-reviewed option
3, stable key/source order, ordered unique/max3, source anchor5, service-role-only RPC, immutable rows, publisher23/26, outer rollback PASS - personality DB smoke: source-reviewed question
6, option12, exactly one per question, source anchor7, stablequestion.answerkey, service-role-only RPC, immutable rows, publisher24/26, outer rollback PASS - regional benefit support DB smoke: source-reviewed v4+ empty revision, 완주군 v1~v3 fail-closed, source anchor
7, service-role-only RPC, immutable rows, publisher26/26, outer rollback PASS - caregiver recommendation catalog: frozen recommendation-set decision authority, opaque browser selection reference, raw candidate/profile id internal-only, publisher
26/26, exact-26 materializer smoke PASS - final-review caregiver decision: exact frozen catalog authority/reference/revision와 specific opaque selection을 재검증; stale/duplicate/disabled/malformed는 missing 유지
- final-review empty support: support/promotion current catalog 둘 다 존재하고 요청 둘 다 빈 배열일 때만 empty decision 확정; 선택 요청은 pricing authority 전까지 invalidation 유지
- final-review selected promotion: live owner catalog revision 재검증, catalog source-order 다중 적용, reviewed payable cap, opaque decision revision, quote/charge/payment amount 일치
- selected regional support amount: backend
8e37ab8a가 exact approved revision과 preparation authority를 다시 읽고 fixed/rate/component 공식을 pricing domain에서 계산해 quote·customer credit·charge handoff revision에 반영; browser amount 입력 경로 없음. backend8b214509는 전체 benefit/component/effect/source/settlement/decision lineage를 internal-only mapping에 동결하고 consumer-owned application contract로 public decision, quote credit line, charge pricing revision, catalog revision을 exact 검증한 뒤 booking command에 전달한다. Discount-only 선택은support_decisions_resolved=true; 서비스일/종료일/own-price 효과는 zero가 아니면 계속 fail-closed - confirmation outbox delivery: production runtime claim/complete/fail + attempt CAS PASS; exact accepted handoff reader와 booking command 변환/workflow start/replay까지 로컬 코드·테스트 PASS
- confirmation outbox recovery: exact failed/stale-processing attempt만 pending 복구, 15분 server cutoff, attempt 보존, advisory-lock/idempotency replay, source error와 exact delivery snapshot recovery audit PASS
- accepted service occurrence ledger: quote day count, contiguous sequence, ordered/in-range dates, exact calendar revisions를 검증한
ServiceTermPlan이 기존 booking occurrence-ledger 경로에 연결됨; real DB workflow 실행은 미검증 - accepted consumer-impact assembly: application-owned 단일 SSOT builder가
daily_report,settlement,service_calendar세 consumer fact를 만들고 기존 booking workflow assembly/persistence 경로에 로컬 연결됨 - booking execution mapping: stable selection + exact price/day + versioned source lineage로 internal legacy tuple exact-one PASS; label/order/amount-hint 비권위, public numeric ID 비노출
- booking working-time authority: ISO local start/end + IANA timezone + policy revision 필수; numeric working-type 시간 추론 금지, missing/invalid lineage fail-closed
- caregiver execution selection: current owner/request/decision/revision + specific opaque selection 또는 frozen rank one exact resolve; public raw ID 비노출, stale/unknown/non-numeric fail-closed
- voucher parser actual source:
2026_voucher_260119.xlsx, SHA-256621a7667b...62a8c,198/198, issue0, baby group4, stable delivery code8 - Python full regression: current pin
7,067 passed; final-review blocker targeted regression14 passed; Tach affected457 passed/6,562 deselected; dependency/interface/exact/external0 diagnostics - Frontend full regression:
95 files / 591 tests; lint, Astro 7 check, production build PASS. 서버 reason code 네 개의 한국어 문구를 exact test로 고정 - private-care parser: actual workbook
20/20, issue0; projected duration/work/service option4/2/10 - Ruff, Tach dependency/interface/exact/external PASS; Vulture confidence 100의
evaluated_at3건은 branch/plan/price sourceProtocol구현·전달·호출을 확인한 false positive라 삭제하지 않음 - Supabase migration
20260718103000: healthy P04 disposable DB 적용 PASS; DB lint--fail-on errorerror 0, 기존 warning만 유지 - Supabase migration
20260718113000: repository commit만 완료, local/stage/production 미적용 - Supabase migration
20260718124500: scoped disposable PostgreSQL 17.6에 verbatim 적용, failed/stale/replay/conflict/권한 smoke PASS, Supabase CLI schema lint error0; local/stage/production 미적용 - Supabase migration
20260718130000: v1→v2→v3 disposable Supabase DB 적용과 split-date record/load PASS;pnpm exec supabase migration listlocal/remote 일치, DB lint error0; stage/production 미적용 - Supabase migration
20260718153000: repository CLI로 disposable current full migration chain 적용 PASS;service_roleACL exactar, update/truncate·anon/authenticated42501, privileged update/delete55000, forbidden raw credential/reference column0; stage/production 미적용 - Supabase migration
20260718162556: repository CLI로 disposable full migration chain 적용 PASS; exact customer account-link proof, service-role-only grant, privacy lifecycle42501fail-closed; stage/production 미적용 - Supabase migration
20260718170000: repository CLI로 disposable full migration chain 적용 PASS; initial save/exact replay, drift·stale revision40001, booking/payment/snapshot rollback, immutable update55000, booking/payment/snapshot1/1/1, service-role-only ACL PASS; local/stage/production 미적용 - accepted offering/consumer-impact slice: schema migration 없음
- accepted retained-intake freeze/public-display slice: schema migration 없음
- clean full-history reset: backend
31ac8845의 disposable AppArmor-scoped PostgreSQL과 pinned GoTrue/Storage bootstrap에서 migration315/315, latest20260718180000, lint, seven catalog smokes, exact-26, cleanup PASS - 온라인 배포 없음. 최신 actual local screenshot/WebP는 backend/Supabase/browser integration
proof지만 production source completeness와 confirmation-ready acceptance로 승격하지 않는다.
기존
customer-reservation-draft-chat-fb69309mocked-API pack은 역사 UI 회귀 자료다.