Skip to content

docs: retire thirteen stale claims found re-verifying the skills, and make the route probe self-checking - #255

Merged
stephane-segning merged 4 commits into
masterfrom
docs/retire-stale-claims-2026-09-23
Sep 24, 2026
Merged

stephane-segning merged 4 commits into
masterfrom
docs/retire-stale-claims-2026-09-23

Conversation

@stephane-segning

Copy link
Copy Markdown
Contributor

Why

Re-verifying the vpay-skills against b747e5d5 on 2026-09-23 (vaam-apps/vpay-skills#24 and #25) turned up 14 claims in vpay's own docs, doc comments and test titles. Each was checked against the tree. 13 were real; one (item 3) was not. Every correction keeps what the text said before, with a date, following #243's precedent.

The one code change

The route-probe test missed a model. MODEL_TABLES in vpay-db/src/schema.rs listed 19 tables and omitted manual_payments (migration 0049, #251).

  • It is now 20 (model, table) pairs.
  • The test first compares the list against the schema's own generated model list, in both directions, so the next model can't be left out silently. Deleting the ManualPayment pair makes it fail.
  • The doc figure "seventy-six" is now 160 (20 models × 2 paths × 4 methods). That is arithmetic, not a measurement.

The corrections

# Where Before → after
2 dashboard layout.test.tsx (plus AGENTS.md, dashboard README, globals.css, Storybook preview) "the only theme @vaam-apps/ui compiles" → one of two (dark, light, since 0.1.2). The test now reads both names from the package's theme.css
3 checkout a11y-gate.test.ts Not real. It names no version. The dashboard copy's "0.1.2" is history: where the SideNav bug was found
4 docs/flows/provider-port.md 6 of 9 trait methods → all 9 (account_holder_name, payer_fields, code added)
5 model.rs, payment_intents.rs, webhooks.rs doc comments intent object "twelve keys" → thirteen (the pin test already asserts 13)
6 dashboard README "two" BFF handlers → six, with the table filled in
7 merchant-auth/resource-contract.md "the only DELETE" → one of three; the 15 invoice and invoice-item routes listed
8 InvoiceStatus diagram, void_in_tx draft → void → draft → DELETE; void is open only
9 schemas/vpay.cstack header (and README, infrastructure.md) "FIVE models" → 14 of 20 models, 36 generated statements
10 the CrateStack registry page a verbatim move, so not rewritten; a dated snapshot banner gives today's figures
11 docs/flows/errors.md two-leaf exit chain → StartupError, ConfigError, SigningKeyError, DbError
12 docs/flows/stripe-sdk-compat.md customer on intent create "dropped" → stored since 2026-09-06 (0fc5dcf)
13 docs/sdks/parity.md gap ledger Flutter "compiled by nobody" → macOS only; iOS built and run on a Simulator since 2026-09-16 (as reported then, not re-run)
14 root README.md (3 places), open_migrated_database "both binaries" → one binary, several modes (since #77, 2026-09-07)

Evidence: docs/status/verification/2026-09-23-skills-reverification.md.

Verification

Not done

  • Other "both binaries" mentions are left (nextest.toml, .env.example, ci.yml, xtask, Cargo.toml comments, vpay-api/src/lib.rs:34, vpay-server/src/main.rs:492). Migration 0045's "nineteen-name" comment is also left, because migrations are checksummed.
  • Follow-ups: add customer to the stripe-js PaymentIntent type (only its comment is corrected), and have the route-probe test also check each table name against the generated model definitions.
  • just ci as one recipe; storybook, e2e and the citation check were not run.
  • No skills change: nothing that triggers one moved.

🤖 Generated with Claude Code

Stephane Segning Lambou and others added 2 commits September 23, 2026 23:07
… the route probe against the schema

Fourteen claims a vpay-skills re-verification found against b747e5d, each
re-checked on master (9184e42) and corrected in place with its date.
Thirteen were real; one (checkout's a11y-gate.test.ts naming
@vaam-apps/ui 0.1.2) was not — that file names no version.

The one code change: vpay-db's
no_generated_model_route_is_mounted_only_the_one_procedure_is listed
nineteen model tables and had missed manual_payments (migration 0049,
#251). It now lists twenty (model, table) pairs and first compares the
model column with cratestack_schema::MODELS, in both directions, so the
next model cannot be missed silently. Deleting the ManualPayment pair
fails it. The dashboard layout test's "only theme" title is corrected and
the case now reads @vaam-apps/ui's two registered themes off theme.css.

The rest are docs and doc comments: provider-port.md's six-of-nine
methods (payer_fields, account_holder_name, code), the thirteen-key
payment_intent called twelve, the dashboard BFF's six handlers called two,
"the only DELETE" of three, a draft -> void edge that never existed,
vpay.cstack's "FIVE models" of fourteen (36 statements), a dated snapshot
banner on the 2026-09-10 registry, errors.md's four-leaf exit-code chain,
customer stored on intent create since 2026-09-06, Flutter iOS no longer
"compiled by nobody" in the parity ledger (macOS still is), and "both
binaries" in the README and open_migrated_database.

Evidence: docs/status/verification/2026-09-23-skills-reverification.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Stephane Segning Lambou and others added 2 commits September 24, 2026 09:52
…r flags in touched files

Both pre-date this PR: cratestack-what-runs-through-it.md was split out
verbatim (#129) with h1 followed by h3/h4, and two fences carried no language.
Headings shift up one level (text unchanged, so anchors are unaffected) and the
fences are marked `text`. Checked with markdownlint-cli 0.49.0 and CI's config.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@stephane-segning
stephane-segning merged commit 1d20640 into master Sep 24, 2026
19 checks passed
@vaam-apps vaam-apps Bot mentioned this pull request Sep 24, 2026
stephane-segning added a commit to vaam-apps/vpay-skills that referenced this pull request Sep 25, 2026
4f245ba moved refunds, deliveries and customers to "since 2026-09-13",
after vpay's README (vaam-apps/vpay#255), which dates them by f9c7d2cd,
the slice branch's commit (2026-09-13 23:07). None of the three was on
master that day. The route files first appear on master's first-parent
line at 690fede7 (2026-09-14 10:31), and f9c7d2cd itself arrived with
vaam-apps/vpay#174 (2026-09-14 11:46); checkouts arrived with #174 too.
VERSIONING.md dates a route by when master has it, so the text #24
carried, "the four added 2026-09-14", was right and is restored, with a
note on why the README says otherwise.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
s-segning pushed a commit to vaam-apps/vpay-skills that referenced this pull request Sep 26, 2026
…fda09 (#27)

* docs(vpay-dashboard): reconcile #24 and #26, restamp against vpay f68fda09

#24 (written against vpay b747e5d5 and @vaam-apps/ui 0.2.4) merged three
minutes after #26 (which briefed 0.4.0 as vaam-apps/vpay#258 ships it), and
the textual merge left what-a-screen-may-show.md contradicting itself. Fixed:

- the "Re-checked against 0.2.4 ... do not drop the suppression" paragraph
  sat after "fixed in 0.4.0, #258 dropped the suppression". The SideNav
  landmark defect is now one dated history: 0.1.2, reported as ui#16,
  0.2.4 read, 0.3.0 measured, fixed in 0.4.0. The spent advice is struck.
- the merge artifact "25 stories (counted 2026-09-23) bound to the same"
  running into "33 stories as of #258" is gone: 33 at f68fda09, 25 from
  2026-09-13 through b747e5d5.
- "@vaam-apps/ui is ^0.2.4 since 2026-09-23" is struck: ^0.4.0 since
  vpay#258 (2026-09-25).
- the component list is one current list read off f68fda09's imports, with
  both earlier versions struck and explained in order.

Re-verified SKILL.md and both reference pages against vpay master
f68fda09 (2026-09-25) and moved all three stamps there. Found false beyond
the merge, each struck or dated with its prior text kept:

- SKILL.md: "There is deliberately no current password field". Wrong since
  2026-09-10 (vpay#97); the form and the server require it.
- SKILL.md: "There is no Sign out in the nav". Wrong since 2026-09-14;
  SideNav's accountSlot carries SignedInBar, at every width since #258.
- SKILL.md: all four later BFF handlers dated 2026-09-14; three are
  2026-09-13.
- SKILL.md: staff add "sets password_change_required". A credential's
  must_change since migration 0044 (vpay#168, 2026-09-13).
- read-seam-and-bff.md: MODEL_TABLES "[&str; 19]" without manual_payments.
  Closed by vpay#255 (2026-09-24): twenty pairs, checked against
  cratestack_schema::MODELS.
- read-seam-and-bff.md: the README's handler lead-in and layout table
  "still" say two. Fixed by vpay#255; only its test count lags.
- what-a-screen-may-show.md: layout.test.tsx "still titled 'the only
  theme'". Retitled by vpay#255.

Also added: the optional VPAY_DASHBOARD_PUBLIC_ORIGIN, the merchant being
one tap away below 640px, and 29 dark / 4 light stories. The mutation table
is marked re-read, not re-run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(vpay-dashboard): give the More sheet's date its referent

"in SideNav's More sheet since (2026-09-25)" had lost the thing it was
dated from. It is since vaam-apps/vpay#258 merged, which is how the Sign
out paragraph below phrases the same fact.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(vpay-dashboard): date the four later BFF handlers by master again

4f245ba moved refunds, deliveries and customers to "since 2026-09-13",
after vpay's README (vaam-apps/vpay#255), which dates them by f9c7d2cd,
the slice branch's commit (2026-09-13 23:07). None of the three was on
master that day. The route files first appear on master's first-parent
line at 690fede7 (2026-09-14 10:31), and f9c7d2cd itself arrived with
vaam-apps/vpay#174 (2026-09-14 11:46); checkouts arrived with #174 too.
VERSIONING.md dates a route by when master has it, so the text #24
carried, "the four added 2026-09-14", was right and is restored, with a
note on why the README says otherwise.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(vpay-dashboard): the forced password change is refused per route, not centrally

The page said ADR-0017 decision 1 "refuses every authenticated route" to
a session whose password must change, and 4f245ba added that
vpay_api::staff::password_change_required "is the check". At f68fda09
only GET /dash/v1/oauth/authorize refuses on it (staff/oauth.rs). GET
/dash/v1/staff/session and POST /dash/v1/staff/totp answer
password_change_required: true, and the dashboard's gateFor redirects.
The predicate's own doc says it is deliberately not folded into
load_session, and neither load_session nor authenticated_session reads
it. An agent adding a staff route on the page's word would add no check.
The ADR's wording is struck and the per-route truth is stated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(vpay-dashboard): measure the unregistered-theme question instead of reading it

The page recorded "an unregistered data-theme should no longer render
unthemed" as read from theme.css and unmeasured, with vpay's
layout.test.tsx header and README answering the other way. Measured
2026-09-25 in headless Chromium (Playwright 1.63.0): @vaam-apps/ui
0.4.0's built dist/styles/theme.css, composed as the dashboard's
app/globals.css does, compiled with tailwindcss 4.3.3 and daisyUI 5.7.28
(vpay's lockfile pins at f68fda09). data-theme="nonsense" and
"corporate" computed --color-base-100 #0a0b0d, --surface-3 #1c1f25 and
a body background of rgb(10, 11, 13), identical to "dark" and to no
attribute, under prefers-color-scheme light and dark; "light" gave
#fcfcfd. 0.1.2's theme.css gave daisyUI's colours dark too, with the
package's --surface-3 unset. So vpay's two sentences are wrong, and the
page now says so, with the method and its limits (a bare page, not the
app's own build).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(vpay-dashboard): list what the dashboard README still gets wrong

"The README's properties are all still right; only its test count lags"
was restamped against f68fda09 and is false there, and was at b747e5d5.
The README still says staff add "sets password_change_required" (a
credential's must_change since 0044, vpay#168), that there is no current
password field (one since vpay#97, 2026-09-10) and no Sign out in the
nav (one since 2026-09-14), that every authenticated route refuses a
must-change session, that an unknown data-theme renders completely
unthemed, a pages table with none of the four list screens, and
"Contrast checking" among what the app cannot do although the Storybook
axe run has checked color-contrast since vpay#171. SKILL.md called the
README the best companion with no warning; it now points at the list.
The old sentence is struck, not overwritten.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(vpay-troubleshooting): the dashboard has built deliveries and checkouts lists since 2026-09-14

references/dashboard.md, stamped d3a8810b (2026-09-16), said webhooks and
checkout sessions "are not built, and the navigation does not link to
them". At d3a8810b DASH_RESOURCES already routed /deliveries and
/checkouts (with /refunds and /customers), all on master since
2026-09-14 (690fede7, vaam-apps/vpay#174). The claim was false at its own
stamp and contradicts vpay-dashboard, so it is struck and dated; the stamp
does not move. vpay's docs/runbooks/demo/dashboard-sign-in.md, the page's
source, still says it at f68fda09.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant