1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
# Codegen policy for payroll.
#
# `user_owned` globs are hand-written files that live inside generator-owned trees but are
# NOT schema-derived. `metaphor schema generate [--force]` skips them wholesale (never reads,
# merges, or deletes them). Everything else in src/ is regenerated from schema/models.
#
# Re-exports/declarations that must sit alongside generated code live inside
# `// <<< CUSTOM ... // END CUSTOM` markers (service/mod.rs, presentation/http/mod.rs, lib.rs)
# and are preserved by the marker mechanism, not listed here.
#
# Add your hand-authored services, handlers, tests, and docs below as you write them.
user_owned:
- "src/application/service/payslip_pdf.rs"
- "tests/common/mod.rs"
# The hand-owned request-pool shim (tenant pool resolution): dropped by
# the regenerator unless declared here.
- "src/request_pool.rs"
- "src/application/service/payroll_events.rs"
- "src/application/service/payroll_gl.rs"
- "src/application/service/payroll_remittance.rs"
- "src/application/service/payroll_write_service.rs"
# The approved-timesheet input port (provenance for slip overtime lines).
- "src/application/service/timesheet_port.rs"
- "migrations/20260920093000_slip_source_refs.up.sql"
- "migrations/20260920093000_slip_source_refs.down.sql"
- "src/application/service/statutory_calcs.rs"
# Where a slip's overtime hours come from — attendance owns the time_debt semantics; the pool
# default mirrors its exported read so payroll works standalone.
- "src/application/service/overtime_port.rs"
# Where a slip's employee-side tax facts come from — the employee module owns them; the pool
# default mirrors its exported read so payroll works standalone.
- "src/application/service/employee_inputs_port.rs"
# The guarded HTTP composition: entity reads + structure/component CRUD + the validated run
# verbs. No generic run/slip/slip-line mutation reaches the wire.
- "src/presentation/http/guarded_routes.rs"
# ADR-005 consumers: lifecycle event handlers (idempotent inbox consumers).
- "src/application/service/offboarding_settlement_handler.rs"
- "src/application/service/onboarding_enrolled_handler.rs"
- "src/application/service/hire_compensation_handler.rs"
- "src/application/service/promotion_salary_handler.rs"
# Own the hand-written payroll SQL (the structure/run/slip writes, the run roll-up, the deduction
# grouping the salary journal is built from, and the at-most-once GL post gate) that the write service
# orchestrates. Declared here — not renamed with a `_custom` suffix — so the generator skips them
# wholesale; this declaration is what makes editing them legitimate.
- "src/infrastructure/persistence/payroll_entry_repository.rs"
- "src/infrastructure/persistence/salary_component_repository.rs"
- "src/infrastructure/persistence/salary_slip_line_repository.rs"
- "src/infrastructure/persistence/salary_slip_repository.rs"
- "src/infrastructure/persistence/salary_structure_repository.rs"
# As-of resolver over the effective-dated statutory parameter tables (the five seeded global
# masters). Not schema-derived — no entity, no CRUD surface.
- "src/infrastructure/persistence/statutory_params_repository.rs"
- "tests/integrity_probes.rs"
- "tests/payroll_gl_seam.rs"
- "tests/payroll_golden_cases.rs"
- "tests/payroll_hr_seam.rs"
- "scripts/**"
# Hand-authored behavior (services + their HTTP surface). Examples:
# - "src/application/service/onboarding_service.rs"
# - "src/presentation/http/guarded_routes.rs"
# Behavior tests (the golden cases / oracle) + BDD features.
- "tests/features/**"
# - "tests/*_golden_cases.rs"
# - "tests/integrity_probes.rs"
# Hand-authored migrations (the tenancy strip — the strip's ordering guard is
# hand-authored logic, not schema-derived emission).
- "migrations/20260911100000_strip_tenancy.up.sql"
- "migrations/20260911100000_strip_tenancy.down.sql"
# Hand-authored module documentation.
- "docs/**"