1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
# Codegen policy for catalog.
#
# `user_owned` globs are hand-written files that live inside generator-owned trees but are
# NOT schema-derived. `metaphor schema generate [--force]` skips them wholesale (never reads,
# merges, or deletes them). Everything else in src/ is regenerated from schema/models.
#
# Re-exports/declarations that must sit alongside generated code live inside
# `// <<< CUSTOM ... // END CUSTOM` markers (service/mod.rs, presentation/http/mod.rs, lib.rs)
# and are preserved by the marker mechanism, not listed here.
#
# Add your hand-authored services, handlers, tests, and docs below as you write them.
user_owned:
# Validated write path + guarded route composition (closes the CRUD-bypass hole).
- "src/application/service/catalog_write_service.rs"
- "src/presentation/http/guarded_routes.rs"
# Module entrypoints carry hand-written safety gates the generator template does
# NOT emit, so they must survive `metaphor schema generate` (verified: regen strips
# the cfg attributes otherwise):
# - src/lib.rs #[cfg(any(test, feature = "unguarded"))] on all_crud_routes / routes
# - src/routes/mod.rs same gate on create_stateless_routes / get_routes /
# create_combined_routes / get_routes_with_state
# Trade-off: adding a NEW entity means manually wiring its service into
# CatalogModule (src/lib.rs) and its routes into the composers (src/routes/mod.rs) —
# the generator no longer updates these two files for you.
- "src/lib.rs"
- "src/routes/mod.rs"
# Repositories own the hand-written catalog SQL (item/variant lookups, validated inserts,
# in-tx variant lifecycle, tenant-agnostic EXISTS probes) orchestrated by catalog_write_service.
# Declared here — not renamed with a `_custom` suffix — so the generator skips them wholesale;
# this declaration is what makes editing them legitimate. Mirrors the backbone-banking pattern
# (exchange_rate_repository.rs, fx_gain_loss_repository.rs).
- "src/infrastructure/persistence/item_repository.rs"
- "src/infrastructure/persistence/item_group_repository.rs"
- "src/infrastructure/persistence/item_variant_repository.rs"
- "src/infrastructure/persistence/uom_repository.rs"
- "src/infrastructure/persistence/uom_conversion_repository.rs"
- "src/infrastructure/persistence/attribute_repository.rs"
- "src/infrastructure/persistence/attribute_value_repository.rs"
- "src/infrastructure/persistence/brand_repository.rs"
# Behavior tests (the golden cases / oracle) + route-level integrity probes + BDD features
# + codegen-invariant guards (hand-written safety gates that regen would otherwise strip)
# + the tenancy posture probe (half-fence pin: RLS flags armed, module ships no policy).
- "tests/catalog_golden_cases.rs"
- "tests/item_lookup.rs"
- "tests/integrity_probes.rs"
- "tests/codegen_invariants.rs"
- "tests/tenancy_posture_probe.rs"
- "tests/features/**"
# UoM parent-store tree (ADR-0023): domain conversion primitive (chain assembly,
# cross-tree typed failure, caller-declared rounding) + its golden-case suite.
# The application-side orchestration lives in catalog_write_service (above).
- "src/domain/services/uom_tree.rs"
- "tests/uom_tree_golden_cases.rs"
# Hand-written migrations the generator cannot re-derive from the schema: the UoM
# parent-store tree (ADR-0023), the standard_cost column add, and the protected-units
# delete guard (a BEFORE DELETE trigger, not expressible as a generated column DDL).
# None carries a generator marker, so a `--force` regen leaves them be — declared here
# so the ownership is explicit rather than an artifact of the marker scheme.
- "migrations/20260823000001_uom_parent_store_tree.up.sql"
- "migrations/20260823000001_uom_parent_store_tree.down.sql"
- "migrations/20260825000001_add_standard_cost_to_item.up.sql"
- "migrations/20260825000001_add_standard_cost_to_item.down.sql"
- "migrations/20260906000001_uom_protected_units.up.sql"
- "migrations/20260906000001_uom_protected_units.down.sql"
# The guarded company-artifact strip — the strip's ordering guard is hand-authored logic
# (decorator-first: never drop the last tenancy key on a populated table), and the UoM
# tree's company-keyed FK is re-keyed by hand around the column drop.
- "migrations/20260911130000_strip_tenancy.up.sql"
- "migrations/20260911130000_strip_tenancy.down.sql"
# Hand-authored module documentation.
- "docs/**"