1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
# Codegen policy for integrations.
#
# `user_owned` globs are hand-written files that live inside generator-owned trees but are
# NOT schema-derived. `metaphor schema generate [--force]` skips them wholesale (never reads,
# merges, or deletes them). Everything else in src/ is regenerated from schema/models.
#
# Re-exports/declarations that must sit alongside generated code live inside
# `// <<< CUSTOM ... // END CUSTOM` markers (service/mod.rs, presentation/http/mod.rs, lib.rs)
# and are preserved by the marker mechanism, not listed here.
#
# Add your hand-authored services, handlers, tests, and docs below as you write them.
user_owned:
- "src/application/service/integrations_events.rs"
- "src/application/service/integrations_ports.rs"
- "src/application/service/integrations_write_service.rs"
# The OAuth credential port (edge-free trait + secret-bearing TokenBundle) through which the
# OAuth flow reaches the credential store — declared here so the generator never touches it.
- "src/application/service/integrations_oauth_ports.rs"
# The one OAuth generation core (authorize/callback/complete/disconnect/status/refresh over the
# port + validated endpoints) and its verb-shaped HTTP surface — hand-authored, user-owned.
- "src/application/service/integrations_oauth.rs"
- "src/presentation/http/oauth_handler.rs"
# Outbound safety + scheduler (hand-authored): the fail-closed endpoint guard (provider
# registry, allowlist validation, OAuth transport port + reqwest implementation) and the
# refresh-before-expiry job the scheduled_jobs declaration names.
- "src/infrastructure/http/**"
- "src/infrastructure/jobs/**"
# Guard + scheduler probes (endpoint-rule matrix, DNS-range refusal, refresh/claim behavior).
- "tests/oauth_guard_scheduler_probes.rs"
# The one-OAuth-generation proof suite (state fence, gauntlet, honest expiry,
# port discipline, route fence, fail-closed authorization).
- "tests/oauth_generation_probes.rs"
# Own the hand-written integrations SQL (the connector registration + gate reads, the
# (connector, business_key) dedup claim + re-read, the mapped/ignored/failed transitions on both the
# receive and the retry path) that the write service orchestrates. Declared here — not renamed with a
# `_custom` suffix — so the generator skips them wholesale; this declaration is what makes editing
# them legitimate.
- "src/infrastructure/persistence/integration_connector_repository.rs"
- "src/infrastructure/persistence/integration_event_repository.rs"
- "tests/integrations_golden_cases.rs"
- "tests/integrations_payment_seam.rs"
- "tests/integrity_probes.rs"
# Shared test doubles (fake OAuth credential store, transport fakes as they land) + the
# port/fake semantics tests — hand-authored, never generated.
- "tests/common/**"
- "tests/oauth_port_fakes.rs"
- "scripts/**"
# Hand-authored behavior (services + their HTTP surface). Examples:
# - "src/application/service/onboarding_service.rs"
# - "src/presentation/http/guarded_routes.rs"
# Behavior tests (the golden cases / oracle) + BDD features.
- "tests/features/**"
# - "tests/*_golden_cases.rs"
# - "tests/integrity_probes.rs"
# Hand-authored module documentation.
- "docs/**"
# Hand-authored migrations (the tenancy strip — the strip's ordering guard is
# hand-authored logic, not schema-derived emission).
- "migrations/20260911120000_strip_tenancy.up.sql"
- "migrations/20260911120000_strip_tenancy.down.sql"