1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
# Codegen policy for mail.
#
# `user_owned` globs are hand-written files that live inside generator-owned trees but are
# NOT schema-derived. `metaphor schema generate [--force]` skips them wholesale (never reads,
# merges, or deletes them). Everything else in src/ is regenerated from schema/models.
#
# Re-exports/declarations that must sit alongside generated code live inside
# `// <<< CUSTOM ... // END CUSTOM` markers (service/mod.rs, presentation/http/mod.rs, lib.rs)
# and are preserved by the marker mechanism, not listed here.
#
# Add your hand-authored services, handlers, tests, and docs below as you write them.
user_owned:
# Hand-written files the audit found undeclared; declared so a schema
# regeneration cannot delete them.
- "src/infrastructure/persistence/reaction_repository.rs"
- "src/infrastructure/persistence/presence_repository.rs"
- "src/infrastructure/persistence/message_edit_repository.rs"
- "src/infrastructure/persistence/gc_repository.rs"
- "src/infrastructure/persistence/attachment_repository.rs"
- "src/infrastructure/persistence/guest_repository.rs"
# Hand-authored behavior (services + their HTTP surface). Examples:
# - "src/application/service/onboarding_service.rs"
# - "src/presentation/http/guarded_routes.rs"
# --- messaging increment-1 hand-written behavior (Agent B) -------------------
# The bus-derived platform constants: the ADR-0014 posture-4 nil-sentinel company
# id, the server-side channel-key constructors, and the in-tx outbox stage helper.
- "src/domain/event/constants.rs"
# Hand-authored write services (the message_post notify pump MAIL-M16/B, follower
# policies MAIL-M10, activity chaining MAIL-M17, the sms queue SM-M1/2 + MMB-4,
# the mail queue MAIL-M2 + MMB-4, alias resolution MAIL-M33).
- "src/application/service/sms_ports.rs"
- "src/application/service/message_write_service.rs"
- "src/application/service/follower_write_service.rs"
- "src/application/service/activity_write_service.rs"
- "src/application/service/sms_write_service.rs"
- "src/application/service/mail_queue_write_service.rs"
- "src/application/service/alias_write_service.rs"
# Hand-written messaging SQL (services orchestrate, repositories hold SQL — the
# module rule). Distinct names from the generated per-entity repositories; these
# are raw-SQL runtime queries (no sqlx macros, so no .sqlx cache needed).
- "src/infrastructure/persistence/message_pipeline_repository.rs"
- "src/infrastructure/persistence/follower_repository.rs"
- "src/infrastructure/persistence/activity_repository.rs"
- "src/infrastructure/persistence/sms_queue_repository.rs"
- "src/infrastructure/persistence/mail_queue_repository.rs"
- "src/infrastructure/persistence/alias_resolution_repository.rs"
# --- messaging increment-2 hand-written behavior --------------------------------
# The delivery surface: discuss/chatter services, the /sms/status webhook,
# the chatter ACL seam (MAIL-B1), SSE realtime, guest middleware, and the
# guarded routers. Declared BEFORE any file lands (regen-safety contract).
- "src/application/service/channel_write_service.rs"
- "src/application/service/channel_member_write_service.rs"
- "src/application/service/typing_service.rs"
- "src/application/service/reaction_write_service.rs"
- "src/application/service/message_edit_service.rs"
- "src/application/service/guest_write_service.rs"
- "src/application/service/presence_write_service.rs"
- "src/application/service/schedule_write_service.rs"
- "src/application/service/sms_status_webhook_service.rs"
- "src/application/service/gc_service.rs"
- "src/application/service/attachment_write_service.rs"
- "src/application/service/message_query_service.rs"
- "src/application/service/channel_query_service.rs"
- "src/application/service/recipient_query_service.rs"
- "src/application/service/chatter_acl.rs"
- "src/application/service/thread_chatter_service.rs"
# Increment-2 repositories (SQL lives here, not in services).
- "src/infrastructure/persistence/channel_repository.rs"
- "src/infrastructure/persistence/channel_member_repository.rs"
- "src/infrastructure/persistence/schedule_repository.rs"
- "src/infrastructure/persistence/webhook_repository.rs"
- "src/infrastructure/persistence/chatter_repository.rs"
# Increment-2 HTTP surface (generated CRUD untouched).
- "src/presentation/http/thread_routes.rs"
- "src/presentation/http/channel_routes.rs"
- "src/presentation/http/guest_routes.rs"
- "src/presentation/http/presence_routes.rs"
- "src/presentation/http/attachment_routes.rs"
- "src/presentation/http/webhook_routes.rs"
- "src/presentation/http/public_routes.rs"
- "src/presentation/middleware/**"
# SSE realtime (ADR-0017 carrier semantics; BUS-B2 channel validation).
- "src/realtime/**"
# --- messaging increment-3 hand-written behavior (gateway core) ---------------
# Outbound SMTP port + the inbound webhook service (MAIL-M26/M27/M28; the
# transports themselves live in the composing app — the module holds ports,
# selection ladder, and the one-tx inbound pipeline MAIL-B2/B6).
- "src/application/service/mail_ports.rs"
- "src/application/service/mail_server_query_service.rs"
- "src/application/service/mail_inbound_service.rs"
# MAIL-B7 relay consumer (promoted from backbone-messaging-app): the
# previous-address security email on UserEmailChanged.
- "src/application/service/relay_b7.rs"
- "src/infrastructure/persistence/smtp_selection_repository.rs"
- "src/infrastructure/persistence/inbound_repository.rs"
- "src/presentation/http/inbound_routes.rs"
# --- gateway transport adapters (promoted from backbone-messaging-app) -------
# The SMTP port impl (over backbone-email, `gateway-smtp` feature) and the
# IAP-shaped HTTP JSON SMS provider (`gateway-sms-http`). Feature-gated; see
# src/infrastructure/gateway/.
- "src/infrastructure/gateway/**"
# --- phone-validation opener (user-owned) -------------------------------------
# The E.164 sanitize contract: the recipient-candidate port (PhoneBookPort +
# the fail-closed slot), the typed formatter service (E164Number /
# phone_format / the first-valid-wins walk), and the phone.blacklist verbs
# (canonical upsert add, archive remove, point/batch membership checks).
# Declared BEFORE any file lands (regen-safety contract).
- "src/application/service/phone_ports.rs"
- "src/application/service/phone_validation_service.rs"
- "src/application/service/phone_blacklist_write_service.rs"
# NOTE: the verb repository sits at phone_blacklist_verb_repository.rs — a
# name DISTINCT from the generated per-entity repository
# (phone_blacklist_repository.rs, emitted for the PhoneBlacklist entity);
# the module rule requires the split, and a user_owned entry on the
# generated path would suppress the entity repository itself.
- "src/infrastructure/persistence/phone_blacklist_verb_repository.rs"
# --- email-blacklist verbs (user-owned) ----------------------------------------
# The mail.blacklist sanctioned write path: the same add/remove/membership
# verb shape as the phone side, extended with the opt_out_reason_id column
# (email lowercased on write — the documented app-layer case-fold).
# Declared BEFORE any file lands (regen-safety contract).
- "src/application/service/mail_blacklist_write_service.rs"
# Distinct name from the generated per-entity repository
# (mail_blacklist_repository.rs, emitted for the MailBlacklist entity) for
# the same reason as the phone side above.
- "src/infrastructure/persistence/mail_blacklist_verb_repository.rs"
# Behavior tests (the golden cases / oracle) + BDD features.
- "tests/behavior_tests.rs"
- "tests/behavior/**"
- "tests/features/**"
# Hand-authored module documentation.
- "docs/**"