Skip to content

feat(web): frontend intent and authoritative status (A05) - #32

Merged
kapustazh merged 4 commits into
developfrom
milestone/a05-frontend-intent-status
Sep 8, 2026
Merged

kapustazh merged 4 commits into
developfrom
milestone/a05-frontend-intent-status

Conversation

@kapustazh

@kapustazh kapustazh commented Sep 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds A05 minimal operator frontend for business intent creation and authoritative status polling over frozen OpenAPI v1, replacing the placeholder asset with the built Vite SPA and configuring automated builds in Cloudflare Workers Builds.

Scope and acceptance criteria

  • The change is limited to the stated milestone or issue.
  • Acceptance criteria are listed and satisfied:
    • Minimal accessible React/Vite UI consuming frozen OpenAPI v1 types (apps/web).
    • Creates and replays one stable Business Intent ID.
    • Distinguishes 202 Accepted, 200 Replayed, and 409 Payload Conflict.
    • Formats and parses 6-decimal USDC using string/BigInt arithmetic without floating point.
    • Displays authoritative states with bounded polling and backoff.
    • Disables payment retry on UNKNOWN and offers reconciliation enqueue only.
    • Holds bearer token in volatile component memory only without persistence.
    • Disables production source maps.
    • Replaces Cloudflare assets with built SPA.
    • Wrangler build.command automates Vite SPA build during Cloudflare Workers Builds.
    • All markdown conforms to markdownlint without bare URLs.
    • All package and root tests, lint, typecheck, and build pass.
  • No unrelated cleanup is included.

Product and security invariants

  • Tenant isolation remains fail-closed.
  • Sponsor authorization, auditability, and daily caps remain enforced where applicable.
  • Recipients cannot modify sponsor controls or access sponsor-only data.
  • No secret, token, production identifier, or personal data is committed or pasted into review prompts.
  • Any non-applicable invariant is explained below.

Invariant notes:

  • A05 is an operator frontend interface with no settlement execution or signing capabilities.
  • Enforces stable business_intent_id across replays.
  • At UNKNOWN settlement state, only reconciliation is available; blind retry is blocked.
  • Money representation is strictly BigInt / string units.
  • Service token is ephemeral in React state and never persisted to localStorage, sessionStorage, or cookies.

Validation

Commands and results:

pnpm --filter @oneshot/web test: PASS (27 tests)
pnpm --filter @oneshot/web lint: PASS (0 issues)
pnpm --filter @oneshot/web typecheck: PASS (0 issues)
pnpm --filter @oneshot/web build: PASS (0.42 kB HTML, 3.77 kB CSS, 206.76 kB JS, 0 source maps)
pnpm format:check: PASS
pnpm lint: PASS (0 issues)
pnpm typecheck: PASS (0 issues)
pnpm check:generated: PASS ("Generated contracts are current")
pnpm exec wrangler deploy --dry-run: PASS (custom build runs vite build, reads 4 files from apps/web/dist)
pnpm test: PASS (576 tests passed across 43 files)
npx markdownlint-cli2 "**/*.md": PASS (94 files, 0 errors)

Independent review evidence

Gate A — exact candidate tree before push

  • Base commit SHA: 1250dec

  • Candidate tree SHA: 8e3158fec77b9e48e0531fa0df22ce0d42be8caf

  • Candidate commit SHA (if already committed but unpushed): 70f984f

  • Reviewer tool: free-pi-cli

  • Reviewer model: glm-5.3-flash

  • Verdict: VERDICT: PASS

  • Findings or residual risks:

    • Non-blocking: vitest config root include for tsx test files, client.ts error typing, polling exhaustion status.
    • Residual risks: Postgres integration tests run in CI; UI is verified with unit tests and fakes.
  • The reviewed tree equals the committed tree.

Gate B — exact remote PR head

  • Pull request URL/number: feat(web): frontend intent and authoritative status (A05) #32 (feat(web): frontend intent and authoritative status (A05) #32)

  • Remote head commit SHA: 493e5cd

  • Remote head tree SHA: 8e3158fec77b9e48e0531fa0df22ce0d42be8caf

  • Reviewer tool: free-pi-cli

  • Reviewer model: glm-5.3-flash

  • Verdict: VERDICT: PASS

  • Findings or residual risks:

    • Non-blocking: Empty retry commit preserves tree equality; App.tsx client recreation on token update; UI tested against unit fakes with Postgres integration running in CI.
  • Gate B reviewed the current remote head and matches Gate A's approved tree, or a fresh Gate A was run for the changed tree.

  • Agent policy / repository-policy and all applicable CI checks pass.

Risk and rollback

Human merge

  • A human owner has reviewed the evidence and will perform the merge.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
oneshot 493e5cd Sep 08 2026, 01:34 PM

@kapustazh
kapustazh marked this pull request as ready for review September 8, 2026 13:44
@kapustazh
kapustazh merged commit 4afd709 into develop Sep 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant