1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
# Codegen policy for pos.
#
# `user_owned` globs are hand-written files that live inside generator-owned trees but are
# NOT schema-derived. `metaphor schema generate [--force]` skips them wholesale (never reads,
# merges, or deletes them). Everything else in src/ is regenerated from schema/models.
#
# Re-exports/declarations that must sit alongside generated code live inside
# `// <<< CUSTOM ... // END CUSTOM` markers (service/mod.rs, presentation/http/mod.rs, lib.rs)
# and are preserved by the marker mechanism, not listed here.
#
# Add your hand-authored services, handlers, tests, and docs below as you write them.
user_owned:
# The deliberate, published integration surface a composing service depends on. Hand-authored;
# gathers the public API under one namespace so consumers don't reach into the DDD layer tree
# (council 2026-07-26, Contract Seat). The `pub mod integration;` declaration sits in a CUSTOM
# block in lib.rs.
- "src/integration.rs"
- "src/application/service/pos_events.rs"
- "src/application/service/pos_ports.rs"
- "src/application/service/pos_write_service.rs"
- "src/application/service/pos_cart_pricing.rs"
# The write surface, chunked out of pos_write_service.rs. Each is an `impl PosWriteService` block;
# the shared vocabulary (input structs, outcomes, errors) stays in pos_write_service.rs.
- "src/application/service/pos_sale.rs"
- "src/application/service/pos_tender.rs"
- "src/application/service/pos_recognition.rs"
- "src/application/service/pos_drawer.rs"
- "src/application/service/pos_receipt.rs"
# The server-owned ticket computation shared by ring + offline sync (document-grade tax
# through PosTaxComputePort, register-config cash rounding), the offline sync verb itself,
# and the manager-PIN credential path (argon2 hash + attempt counters + lockout).
- "src/application/service/pos_compute.rs"
- "src/application/service/pos_sync.rs"
- "src/application/service/pos_manager_pin.rs"
# Restaurant lane + scheduler: the order-level discount resolution/fold (rate always from the
# tenant's master, folded before the tax compute) and the old-session alert handler behind the
# module's one scheduled job (per-company claim under the pickup lock + once-only latch).
- "src/application/service/pos_discount.rs"
- "src/application/service/pos_session_alert.rs"
# Own the hand-written POS SQL that the write service orchestrates (the ticket header + lines, the
# tender re-sum, the recognition read + its at-most-once billing link and draft->paid flip, the
# returns mirror, the drawer reads, the close). Declared here — not renamed with a `_custom` suffix —
# so the generator skips them wholesale; this declaration is what makes editing them legitimate.
- "src/infrastructure/persistence/pos_invoice_repository.rs"
- "src/infrastructure/persistence/pos_invoice_item_repository.rs"
- "src/infrastructure/persistence/pos_payment_repository.rs"
- "src/infrastructure/persistence/pos_profile_repository.rs"
- "src/infrastructure/persistence/pos_opening_entry_repository.rs"
- "src/infrastructure/persistence/pos_closing_entry_repository.rs"
- "src/infrastructure/persistence/pos_cash_movement_repository.rs"
# The manager-PIN repository carries the credential SQL (upsert hash, attempt counters,
# lockout) — owned like the other hand-written repos above. The DTO is owned to keep the
# argon2 hash and the attempt-source IP out of every generated response surface.
- "src/infrastructure/persistence/pos_manager_pin_repository.rs"
# Sibling files adding hand-written methods to GENERATED repositories (the module's sanctioned
# custom-code convention): table/discount identity reads for the write path's validation.
# Their `mod` + re-export declarations sit in a CUSTOM block in persistence/mod.rs.
- "src/infrastructure/persistence/pos_table_repository_custom.rs"
- "src/infrastructure/persistence/pos_discount_repository_custom.rs"
- "src/presentation/dto/pos_manager_pin_dto.rs"
- "src/presentation/http/guarded_routes.rs"
# The composer-installed request-pool shim the write service and event stores resolve
# their database through (ADR-0029 pool law): hand-written, never schema-derived.
- "src/request_pool.rs"
# The event-store and snapshot-store implementations carry hand-edited pool resolution
# (rpool, ADR-0029 pool law) outside their marker blocks, so the generator must skip
# them wholesale.
- "src/infrastructure/event_store/event_store.rs"
- "src/infrastructure/event_store/snapshot_store.rs"
- "tests/pos_golden_cases.rs"
- "tests/integrity_probes.rs"
- "tests/retail_sale_seam.rs"
- "tests/pos_cash_movement.rs"
- "tests/pos_receipt.rs"
# Offline-sync + manager-PIN + document-grade tax behavior tests, and the shared in-test port
# fakes + DB seeders they all use.
- "tests/pos_sync_ui.rs"
# Tenancy posture pin (ADR-0029): armed RLS flags + zero module policies + default-deny
# for a plain NOBYPASSRLS role + the ambient org scope driving module reads. Succeeded
# the company-era fence tests (company_guard / open-session-rls / sync-outbox-rls),
# which retired with the module's own tenancy.
- "tests/tenancy_posture_probe.rs"
- "tests/pos_manager_pin.rs"
- "tests/pos_tax_compute.rs"
# Restaurant-lane behavior (seating, transfer, one draft per table, server-priced order
# discounts) and the old-session alert scheduler handler.
- "tests/pos_restaurant.rs"
- "tests/pos_session_alert.rs"
- "tests/support/**"
# Hand-written migration the generator cannot re-derive from the schema: the
# company-fence (ADR-0014) strict re-statement of the live RLS policies on all
# seven pos tables. Unlisted, a `--force` regen can drop it — the same
# protection payment's and promo's fence migrations carry in their manifests.
- "migrations/20260823100000_company_fence_strict.up.sql"
- "migrations/20260823100000_company_fence_strict.down.sql"
# Hand-written fence for the tables added later (manager PINs, floor plans,
# tables, discounts): the module-level RLS migration only covers the tables that
# existed when it shipped, so tables added after it get their strict fence here.
- "migrations/20260823100005_fence_manager_pins_floor_plans_tables_discounts_company_rls.up.sql"
- "migrations/20260823100005_fence_manager_pins_floor_plans_tables_discounts_company_rls.down.sql"
# Hand-written ALTER migrations for the tables that shipped with a create
# migration the generator treats as immutable history — offline-sync identity
# (client uuid on ticket/line/tender), restaurant seating (table ref + course
# grouping + one draft per table), the one-open-session-per-register partial
# unique, the profile's cash rounding configuration, and the register's
# document-grade tax template refs.
- "migrations/20260824100000_add_client_uuid_sync_identity.up.sql"
- "migrations/20260824100000_add_client_uuid_sync_identity.down.sql"
- "migrations/20260824100010_add_pos_table_ref_and_course_grouping.up.sql"
- "migrations/20260824100010_add_pos_table_ref_and_course_grouping.down.sql"
- "migrations/20260824100020_enforce_one_open_session_per_profile.up.sql"
- "migrations/20260824100020_enforce_one_open_session_per_profile.down.sql"
# Re-key of the one-open-session-per-register unique from the register uuid alone
# (global across tenants) to (company_id, pos_profile_id): the register slot belongs
# to the tenant that owns the register, so a row carrying another tenant's register
# uuid must not occupy it.
- "migrations/20260825100000_scope_open_session_unique_to_company.up.sql"
- "migrations/20260825100000_scope_open_session_unique_to_company.down.sql"
- "migrations/20260824100030_add_cash_rounding_to_pos_profiles.up.sql"
- "migrations/20260824100030_add_cash_rounding_to_pos_profiles.down.sql"
- "migrations/20260824100040_add_tax_template_refs_to_pos_profiles.up.sql"
- "migrations/20260824100040_add_tax_template_refs_to_pos_profiles.down.sql"
# Hand-written tenancy strip (ADR-0029): drops every company-fence artifact from the
# pos tables — company-leading indexes/uniques (their org-scoped re-declarations live
# in the composing service's tenancy decorator), the company isolation policies, and
# the company_id columns — behind a decorator-first ordering guard. RLS enable/force
# flags stay armed with zero policies: the decorator's half-fence.
- "migrations/20260912100000_strip_tenancy.up.sql"
- "migrations/20260912100000_strip_tenancy.down.sql"
- "scripts/**"
# Hand-authored behavior (services + their HTTP surface). Examples:
# - "src/application/service/onboarding_service.rs"
# - "src/presentation/http/guarded_routes.rs"
# Behavior tests (the golden cases / oracle) + BDD features.
- "tests/features/**"
# - "tests/*_golden_cases.rs"
# - "tests/integrity_probes.rs"
# Hand-authored module documentation.
- "docs/**"