Expand description
The hand-authored integrations write path (user-owned; survives regen).
The connector hub: receive an inbound provider event idempotently on (connector, external_id) —
providers deliver webhooks at-least-once, so a retry must not re-map (double-apply a payment / create a
duplicate order) — map it to an internal action via a TargetPort, or record it as intentionally
ignored. Posts NO GL. Integrations reaches a module only through its public contract (the port).
Tenancy (ADR-0029): the module is tenant-agnostic — its tables carry no company column and this
service invents no scope. Transactions bind the ambient org scope when the composing service
resolved one; standalone statements ride the request-dedicated connection when one is bound and
run plainly on the pool otherwise, so a decorated deployment’s org fence (org_unit_id + RLS +
the decorator’s per-unit uniques) enforces isolation and an unscoped write fails closed. The
company_id that remains on the boundary shapes here is the documented legacy twin: the
webhook names it, and it routes to the two still-company-shaped edges — the TargetPort
(target modules may still be company-fenced) and the outbox/event payloads (the relay keeps a
tenant column).
Structs§
- Failed
Event - A failed event, surfaced so an operator can see + retry an unbooked action without touching the ledger.
- Inbound
Event - An inbound provider event (already parsed into
payload). - Integrations
Write Service - NewConnector
- Receive
Outcome