backbone-pos 0.7.1

Point of sale — cashier session, ticket + multi-tender; orchestrates billing (revenue) + payment (settlement), posts no GL directly
Documentation
# Codegen policy for pos.
#
# `user_owned` globs are hand-written files that live inside generator-owned trees but are
# NOT schema-derived. `metaphor schema generate [--force]` skips them wholesale (never reads,
# merges, or deletes them). Everything else in src/ is regenerated from schema/models.
#
# Re-exports/declarations that must sit alongside generated code live inside
# `// <<< CUSTOM ... // END CUSTOM` markers (service/mod.rs, presentation/http/mod.rs, lib.rs)
# and are preserved by the marker mechanism, not listed here.
#
# Add your hand-authored services, handlers, tests, and docs below as you write them.

user_owned:
  # The deliberate, published integration surface a composing service depends on. Hand-authored;
  # gathers the public API under one namespace so consumers don't reach into the DDD layer tree
  # (council 2026-07-26, Contract Seat). The `pub mod integration;` declaration sits in a CUSTOM
  # block in lib.rs.
  - "src/integration.rs"
  - "src/application/service/pos_events.rs"
  - "src/application/service/pos_ports.rs"
  - "src/application/service/pos_write_service.rs"
  - "src/application/service/pos_cart_pricing.rs"
  # The write surface, chunked out of pos_write_service.rs. Each is an `impl PosWriteService` block;
  # the shared vocabulary (input structs, outcomes, errors) stays in pos_write_service.rs.
  - "src/application/service/pos_sale.rs"
  - "src/application/service/pos_tender.rs"
  - "src/application/service/pos_recognition.rs"
  - "src/application/service/pos_drawer.rs"
  - "src/application/service/pos_receipt.rs"
  # The server-owned ticket computation shared by ring + offline sync (document-grade tax
  # through PosTaxComputePort, register-config cash rounding), the offline sync verb itself,
  # and the manager-PIN credential path (argon2 hash + attempt counters + lockout).
  - "src/application/service/pos_compute.rs"
  - "src/application/service/pos_sync.rs"
  - "src/application/service/pos_manager_pin.rs"
  # Restaurant lane + scheduler: the order-level discount resolution/fold (rate always from the
  # tenant's master, folded before the tax compute) and the old-session alert handler behind the
  # module's one scheduled job (per-company claim under the pickup lock + once-only latch).
  - "src/application/service/pos_discount.rs"
  - "src/application/service/pos_session_alert.rs"
  # Own the hand-written POS SQL that the write service orchestrates (the ticket header + lines, the
  # tender re-sum, the recognition read + its at-most-once billing link and draft->paid flip, the
  # returns mirror, the drawer reads, the close). Declared here — not renamed with a `_custom` suffix —
  # so the generator skips them wholesale; this declaration is what makes editing them legitimate.
  - "src/infrastructure/persistence/pos_invoice_repository.rs"
  - "src/infrastructure/persistence/pos_invoice_item_repository.rs"
  - "src/infrastructure/persistence/pos_payment_repository.rs"
  - "src/infrastructure/persistence/pos_profile_repository.rs"
  - "src/infrastructure/persistence/pos_opening_entry_repository.rs"
  - "src/infrastructure/persistence/pos_closing_entry_repository.rs"
  - "src/infrastructure/persistence/pos_cash_movement_repository.rs"
  # The manager-PIN repository carries the credential SQL (upsert hash, attempt counters,
  # lockout) — owned like the other hand-written repos above. The DTO is owned to keep the
  # argon2 hash and the attempt-source IP out of every generated response surface.
  - "src/infrastructure/persistence/pos_manager_pin_repository.rs"
  # Sibling files adding hand-written methods to GENERATED repositories (the module's sanctioned
  # custom-code convention): table/discount identity reads for the write path's validation.
  # Their `mod` + re-export declarations sit in a CUSTOM block in persistence/mod.rs.
  - "src/infrastructure/persistence/pos_table_repository_custom.rs"
  - "src/infrastructure/persistence/pos_discount_repository_custom.rs"
  - "src/presentation/dto/pos_manager_pin_dto.rs"
  - "src/presentation/http/guarded_routes.rs"
  # The composer-installed request-pool shim the write service and event stores resolve
  # their database through (ADR-0029 pool law): hand-written, never schema-derived.
  - "src/request_pool.rs"
  # The event-store and snapshot-store implementations carry hand-edited pool resolution
  # (rpool, ADR-0029 pool law) outside their marker blocks, so the generator must skip
  # them wholesale.
  - "src/infrastructure/event_store/event_store.rs"
  - "src/infrastructure/event_store/snapshot_store.rs"
  - "tests/pos_golden_cases.rs"
  - "tests/integrity_probes.rs"
  - "tests/retail_sale_seam.rs"
  - "tests/pos_cash_movement.rs"
  - "tests/pos_receipt.rs"
  # Offline-sync + manager-PIN + document-grade tax behavior tests, and the shared in-test port
  # fakes + DB seeders they all use.
  - "tests/pos_sync_ui.rs"
  # Tenancy posture pin (ADR-0029): armed RLS flags + zero module policies + default-deny
  # for a plain NOBYPASSRLS role + the ambient org scope driving module reads. Succeeded
  # the company-era fence tests (company_guard / open-session-rls / sync-outbox-rls),
  # which retired with the module's own tenancy.
  - "tests/tenancy_posture_probe.rs"
  - "tests/pos_manager_pin.rs"
  - "tests/pos_tax_compute.rs"
  # Restaurant-lane behavior (seating, transfer, one draft per table, server-priced order
  # discounts) and the old-session alert scheduler handler.
  - "tests/pos_restaurant.rs"
  - "tests/pos_session_alert.rs"
  - "tests/support/**"
  # Hand-written migration the generator cannot re-derive from the schema: the
  # company-fence (ADR-0014) strict re-statement of the live RLS policies on all
  # seven pos tables. Unlisted, a `--force` regen can drop it — the same
  # protection payment's and promo's fence migrations carry in their manifests.
  - "migrations/20260823100000_company_fence_strict.up.sql"
  - "migrations/20260823100000_company_fence_strict.down.sql"
  # Hand-written fence for the tables added later (manager PINs, floor plans,
  # tables, discounts): the module-level RLS migration only covers the tables that
  # existed when it shipped, so tables added after it get their strict fence here.
  - "migrations/20260823100005_fence_manager_pins_floor_plans_tables_discounts_company_rls.up.sql"
  - "migrations/20260823100005_fence_manager_pins_floor_plans_tables_discounts_company_rls.down.sql"
  # Hand-written ALTER migrations for the tables that shipped with a create
  # migration the generator treats as immutable history — offline-sync identity
  # (client uuid on ticket/line/tender), restaurant seating (table ref + course
  # grouping + one draft per table), the one-open-session-per-register partial
  # unique, the profile's cash rounding configuration, and the register's
  # document-grade tax template refs.
  - "migrations/20260824100000_add_client_uuid_sync_identity.up.sql"
  - "migrations/20260824100000_add_client_uuid_sync_identity.down.sql"
  - "migrations/20260824100010_add_pos_table_ref_and_course_grouping.up.sql"
  - "migrations/20260824100010_add_pos_table_ref_and_course_grouping.down.sql"
  - "migrations/20260824100020_enforce_one_open_session_per_profile.up.sql"
  - "migrations/20260824100020_enforce_one_open_session_per_profile.down.sql"
  # Re-key of the one-open-session-per-register unique from the register uuid alone
  # (global across tenants) to (company_id, pos_profile_id): the register slot belongs
  # to the tenant that owns the register, so a row carrying another tenant's register
  # uuid must not occupy it.
  - "migrations/20260825100000_scope_open_session_unique_to_company.up.sql"
  - "migrations/20260825100000_scope_open_session_unique_to_company.down.sql"
  - "migrations/20260824100030_add_cash_rounding_to_pos_profiles.up.sql"
  - "migrations/20260824100030_add_cash_rounding_to_pos_profiles.down.sql"
  - "migrations/20260824100040_add_tax_template_refs_to_pos_profiles.up.sql"
  - "migrations/20260824100040_add_tax_template_refs_to_pos_profiles.down.sql"
  # Hand-written tenancy strip (ADR-0029): drops every company-fence artifact from the
  # pos tables — company-leading indexes/uniques (their org-scoped re-declarations live
  # in the composing service's tenancy decorator), the company isolation policies, and
  # the company_id columns — behind a decorator-first ordering guard. RLS enable/force
  # flags stay armed with zero policies: the decorator's half-fence.
  - "migrations/20260912100000_strip_tenancy.up.sql"
  - "migrations/20260912100000_strip_tenancy.down.sql"
  - "scripts/**"
  # Hand-authored behavior (services + their HTTP surface). Examples:
  # - "src/application/service/onboarding_service.rs"
  # - "src/presentation/http/guarded_routes.rs"

  # Behavior tests (the golden cases / oracle) + BDD features.
  - "tests/features/**"
  # - "tests/*_golden_cases.rs"
  # - "tests/integrity_probes.rs"

  # Hand-authored module documentation.
  - "docs/**"