docs: retire thirteen stale claims found re-verifying the skills, and make the route probe self-checking - #255
Merged
Conversation
… the route probe against the schema Fourteen claims a vpay-skills re-verification found against b747e5d, each re-checked on master (9184e42) and corrected in place with its date. Thirteen were real; one (checkout's a11y-gate.test.ts naming @vaam-apps/ui 0.1.2) was not — that file names no version. The one code change: vpay-db's no_generated_model_route_is_mounted_only_the_one_procedure_is listed nineteen model tables and had missed manual_payments (migration 0049, #251). It now lists twenty (model, table) pairs and first compares the model column with cratestack_schema::MODELS, in both directions, so the next model cannot be missed silently. Deleting the ManualPayment pair fails it. The dashboard layout test's "only theme" title is corrected and the case now reads @vaam-apps/ui's two registered themes off theme.css. The rest are docs and doc comments: provider-port.md's six-of-nine methods (payer_fields, account_holder_name, code), the thirteen-key payment_intent called twelve, the dashboard BFF's six handlers called two, "the only DELETE" of three, a draft -> void edge that never existed, vpay.cstack's "FIVE models" of fourteen (36 statements), a dated snapshot banner on the 2026-09-10 registry, errors.md's four-leaf exit-code chain, customer stored on intent create since 2026-09-06, Flutter iOS no longer "compiled by nobody" in the parity ledger (macOS still is), and "both binaries" in the README and open_migrated_database. Evidence: docs/status/verification/2026-09-23-skills-reverification.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts: # docs/status/README.md
This was referenced Sep 23, 2026
Merged
…r flags in touched files Both pre-date this PR: cratestack-what-runs-through-it.md was split out verbatim (#129) with h1 followed by h3/h4, and two fences carried no language. Headings shift up one level (text unchanged, so anchors are unaffected) and the fences are marked `text`. Checked with markdownlint-cli 0.49.0 and CI's config. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts: # docs/status/README.md
stephane-segning
added a commit
to vaam-apps/vpay-skills
that referenced
this pull request
Sep 25, 2026
4f245ba moved refunds, deliveries and customers to "since 2026-09-13", after vpay's README (vaam-apps/vpay#255), which dates them by f9c7d2cd, the slice branch's commit (2026-09-13 23:07). None of the three was on master that day. The route files first appear on master's first-parent line at 690fede7 (2026-09-14 10:31), and f9c7d2cd itself arrived with vaam-apps/vpay#174 (2026-09-14 11:46); checkouts arrived with #174 too. VERSIONING.md dates a route by when master has it, so the text #24 carried, "the four added 2026-09-14", was right and is restored, with a note on why the README says otherwise. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
s-segning
pushed a commit
to vaam-apps/vpay-skills
that referenced
this pull request
Sep 26, 2026
…fda09 (#27) * docs(vpay-dashboard): reconcile #24 and #26, restamp against vpay f68fda09 #24 (written against vpay b747e5d5 and @vaam-apps/ui 0.2.4) merged three minutes after #26 (which briefed 0.4.0 as vaam-apps/vpay#258 ships it), and the textual merge left what-a-screen-may-show.md contradicting itself. Fixed: - the "Re-checked against 0.2.4 ... do not drop the suppression" paragraph sat after "fixed in 0.4.0, #258 dropped the suppression". The SideNav landmark defect is now one dated history: 0.1.2, reported as ui#16, 0.2.4 read, 0.3.0 measured, fixed in 0.4.0. The spent advice is struck. - the merge artifact "25 stories (counted 2026-09-23) bound to the same" running into "33 stories as of #258" is gone: 33 at f68fda09, 25 from 2026-09-13 through b747e5d5. - "@vaam-apps/ui is ^0.2.4 since 2026-09-23" is struck: ^0.4.0 since vpay#258 (2026-09-25). - the component list is one current list read off f68fda09's imports, with both earlier versions struck and explained in order. Re-verified SKILL.md and both reference pages against vpay master f68fda09 (2026-09-25) and moved all three stamps there. Found false beyond the merge, each struck or dated with its prior text kept: - SKILL.md: "There is deliberately no current password field". Wrong since 2026-09-10 (vpay#97); the form and the server require it. - SKILL.md: "There is no Sign out in the nav". Wrong since 2026-09-14; SideNav's accountSlot carries SignedInBar, at every width since #258. - SKILL.md: all four later BFF handlers dated 2026-09-14; three are 2026-09-13. - SKILL.md: staff add "sets password_change_required". A credential's must_change since migration 0044 (vpay#168, 2026-09-13). - read-seam-and-bff.md: MODEL_TABLES "[&str; 19]" without manual_payments. Closed by vpay#255 (2026-09-24): twenty pairs, checked against cratestack_schema::MODELS. - read-seam-and-bff.md: the README's handler lead-in and layout table "still" say two. Fixed by vpay#255; only its test count lags. - what-a-screen-may-show.md: layout.test.tsx "still titled 'the only theme'". Retitled by vpay#255. Also added: the optional VPAY_DASHBOARD_PUBLIC_ORIGIN, the merchant being one tap away below 640px, and 29 dark / 4 light stories. The mutation table is marked re-read, not re-run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(vpay-dashboard): give the More sheet's date its referent "in SideNav's More sheet since (2026-09-25)" had lost the thing it was dated from. It is since vaam-apps/vpay#258 merged, which is how the Sign out paragraph below phrases the same fact. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(vpay-dashboard): date the four later BFF handlers by master again 4f245ba moved refunds, deliveries and customers to "since 2026-09-13", after vpay's README (vaam-apps/vpay#255), which dates them by f9c7d2cd, the slice branch's commit (2026-09-13 23:07). None of the three was on master that day. The route files first appear on master's first-parent line at 690fede7 (2026-09-14 10:31), and f9c7d2cd itself arrived with vaam-apps/vpay#174 (2026-09-14 11:46); checkouts arrived with #174 too. VERSIONING.md dates a route by when master has it, so the text #24 carried, "the four added 2026-09-14", was right and is restored, with a note on why the README says otherwise. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(vpay-dashboard): the forced password change is refused per route, not centrally The page said ADR-0017 decision 1 "refuses every authenticated route" to a session whose password must change, and 4f245ba added that vpay_api::staff::password_change_required "is the check". At f68fda09 only GET /dash/v1/oauth/authorize refuses on it (staff/oauth.rs). GET /dash/v1/staff/session and POST /dash/v1/staff/totp answer password_change_required: true, and the dashboard's gateFor redirects. The predicate's own doc says it is deliberately not folded into load_session, and neither load_session nor authenticated_session reads it. An agent adding a staff route on the page's word would add no check. The ADR's wording is struck and the per-route truth is stated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(vpay-dashboard): measure the unregistered-theme question instead of reading it The page recorded "an unregistered data-theme should no longer render unthemed" as read from theme.css and unmeasured, with vpay's layout.test.tsx header and README answering the other way. Measured 2026-09-25 in headless Chromium (Playwright 1.63.0): @vaam-apps/ui 0.4.0's built dist/styles/theme.css, composed as the dashboard's app/globals.css does, compiled with tailwindcss 4.3.3 and daisyUI 5.7.28 (vpay's lockfile pins at f68fda09). data-theme="nonsense" and "corporate" computed --color-base-100 #0a0b0d, --surface-3 #1c1f25 and a body background of rgb(10, 11, 13), identical to "dark" and to no attribute, under prefers-color-scheme light and dark; "light" gave #fcfcfd. 0.1.2's theme.css gave daisyUI's colours dark too, with the package's --surface-3 unset. So vpay's two sentences are wrong, and the page now says so, with the method and its limits (a bare page, not the app's own build). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(vpay-dashboard): list what the dashboard README still gets wrong "The README's properties are all still right; only its test count lags" was restamped against f68fda09 and is false there, and was at b747e5d5. The README still says staff add "sets password_change_required" (a credential's must_change since 0044, vpay#168), that there is no current password field (one since vpay#97, 2026-09-10) and no Sign out in the nav (one since 2026-09-14), that every authenticated route refuses a must-change session, that an unknown data-theme renders completely unthemed, a pages table with none of the four list screens, and "Contrast checking" among what the app cannot do although the Storybook axe run has checked color-contrast since vpay#171. SKILL.md called the README the best companion with no warning; it now points at the list. The old sentence is struck, not overwritten. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(vpay-troubleshooting): the dashboard has built deliveries and checkouts lists since 2026-09-14 references/dashboard.md, stamped d3a8810b (2026-09-16), said webhooks and checkout sessions "are not built, and the navigation does not link to them". At d3a8810b DASH_RESOURCES already routed /deliveries and /checkouts (with /refunds and /customers), all on master since 2026-09-14 (690fede7, vaam-apps/vpay#174). The claim was false at its own stamp and contradicts vpay-dashboard, so it is struck and dated; the stamp does not move. vpay's docs/runbooks/demo/dashboard-sign-in.md, the page's source, still says it at f68fda09. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Re-verifying the vpay-skills against
b747e5d5on 2026-09-23 (vaam-apps/vpay-skills#24 and #25) turned up 14 claims in vpay's own docs, doc comments and test titles. Each was checked against the tree. 13 were real; one (item 3) was not. Every correction keeps what the text said before, with a date, following #243's precedent.The one code change
The route-probe test missed a model.
MODEL_TABLESinvpay-db/src/schema.rslisted 19 tables and omittedmanual_payments(migration0049, #251).(model, table)pairs.ManualPaymentpair makes it fail.The corrections
layout.test.tsx(plusAGENTS.md, dashboard README,globals.css, Storybook preview)dark,light, since 0.1.2). The test now reads both names from the package'stheme.cssa11y-gate.test.tsdocs/flows/provider-port.mdaccount_holder_name,payer_fields,codeadded)model.rs,payment_intents.rs,webhooks.rsdoc commentsmerchant-auth/resource-contract.mdDELETE" → one of three; the 15 invoice and invoice-item routes listedInvoiceStatusdiagram,void_in_txdraft → void→draft → DELETE;voidisopenonlyschemas/vpay.cstackheader (and README,infrastructure.md)docs/flows/errors.mdStartupError,ConfigError,SigningKeyError,DbErrordocs/flows/stripe-sdk-compat.mdcustomeron intent create "dropped" → stored since 2026-09-06 (0fc5dcf)docs/sdks/parity.mdgap ledgerREADME.md(3 places),open_migrated_databaseEvidence:
docs/status/verification/2026-09-23-skills-reverification.md.Verification
just verify(15 gates),just fmt,just clippy,just lint-web: clean.just test-doc: 124 passed, 1 ignored (an existing README doctest).just test-web: 1,506 passed, 2 skipped (the Storybook-build checks, which skip without a build).vpay-dblib 129/129 after mergingmaster. Earlier,vpay-core+vpay-api+vpay-db723/723.webhooksrun hit 3 "fan-out job is claimable" failures. That is the clock-skew cause test: read "now" off the database in fixtures that Postgres' now() judges #254 removed, and this branch now contains test: read "now" off the database in fixtures that Postgres' now() judges #254.Not done
nextest.toml,.env.example,ci.yml, xtask,Cargo.tomlcomments,vpay-api/src/lib.rs:34,vpay-server/src/main.rs:492). Migration0045's "nineteen-name" comment is also left, because migrations are checksummed.customerto the stripe-jsPaymentIntenttype (only its comment is corrected), and have the route-probe test also check each table name against the generated model definitions.just cias one recipe; storybook, e2e and the citation check were not run.🤖 Generated with Claude Code