Connect business approvals to verified till checkout and receipt recovery - #1013
Closed
sridharkalaibala wants to merge 4 commits into
Closed
sridharkalaibala wants to merge 4 commits into
sridharkalaibala wants to merge 4 commits into
Conversation
This was referenced Sep 28, 2026
Contributor
Author
|
The complete Business companion stack, including this change, is integrated into develop through #1023. All checks, including CodeQL, passed before merge. Closing this superseded stacked PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Discount approvals now reach the authenticated desktop checkout through a verified installation boundary. The cashier requests a server-priced bill, the owner approves it, and checkout rechecks the actual final pricing before consuming a single-use execution permit and saving an immutable receipt. A retry returns the existing sale; a consumed permit cannot authorize a second writer.
Cloud tills use fresh Gateway device checks and five-second, exact-operation tenant grants. Explicit Community mode uses a server-owned installation identity and the same decision ledger/checkout guard. Cloud pairing never falls back to a local ledger. Current cashier generation, branch membership and sales access are rechecked, alongside the approving owner's session/policy at execution.
Durable receipt-only recovery uses the existing desktop timer, examines at most four due commands, and never invokes a sale writer. Cloud acknowledgement waits for the matching sale receipt to arrive through ordinary synchronization. Missing receipts stay unresolved instead of triggering another sale. Cashier UI, operator resolution of missing receipts, broader bill combinations and native qualification remain open; the production feature flag must stay disabled.
Validation: 147 sales controller tests; 90 sale/pricing/validation/route unit tests; 30 real-database access, ledger, device and reporting tests; eight outbox/recovery/controller-to-Mongoose checkout integration cases; 50 language catalogue checks and five sync-classification tests. The companion Gateway contract suite passes seven cases, including delayed receipt sync and actual owner authentication. Relevant lint passes with existing legacy warnings only; formatting, generated API docs (737 endpoints), diff checks and human attribution pass. No CI expansion or production deployment.
Stacked on #1012. Companion Gateway branch: codex/business-device-bridge.