Skip to content

Add scoped register-close summaries, Inbox and notification schedules - #1020

Closed
sridharkalaibala wants to merge 13 commits into
codex/business-approval-alertsfrom
codex/business-close-summaries
Closed

sridharkalaibala wants to merge 13 commits into
codex/business-approval-alertsfrom
codex/business-close-summaries

Conversation

@sridharkalaibala

@sridharkalaibala sridharkalaibala commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Owners can configure a summary after each register session closes. The server discovers recent closes without an open phone, requests bounded calculations from the assigned desktop, and persists private Inbox entries before advancing scan checkpoints. This is explicitly a register-session summary, not a restaurant-wide close report.

Adds verified refund-session attribution, strict close fingerprints, Community publication/recovery, ACL-scoped reads, mutually exclusive daily/close schedule modes, quiet hours, revision-bound deduplication and generic push delivery. Reads and pending push retries recheck live scope and source; legacy clients cannot overwrite close schedules. Missing or ambiguous financial data is unavailable, never an invented zero, and completeness stays false.

Validation: 64 relevant real-Mongo/HTTP/cross-repository integration tests, 14 source/metrics/scheduling unit tests and 24 repository claims/sync classification checks pass. Targeted lint/formatting, attribution and generated API consistency pass. OpenAPI retains 14 existing ambiguous-path warnings. The related refund controller/service/repository suite previously passed 337 tests. No CI expansion.

Companion Gateway: https://github.com/Posnic/Gateway/pull/26
Companion mobile: Posnic/posnic-business#15 Stacked on the approval-alerts branch.

Remaining release gates: immutable financial history/source completeness, qualified language review, real-provider/physical-device push, deployment and production signing. Push tests use a fake transport; this PR does not deploy servers.

Dependency follow-up: the API lockfile now resolves ip-address 10.7.2, fixing GHSA-rpw4-54j3-4h4q and GHSA-2vr4-cq9g-pvrc without widening dependency ranges or suppressing advisories. The production advisory and dependency declaration checks pass locally. An isolated install verified the patched IPv6 link-local/NAT64 classifiers and express-rate-limit IPv4/IPv6 subnet keys; the shared root POS node_modules was not modified.

@sridharkalaibala

Copy link
Copy Markdown
Contributor Author

The complete Business companion stack, including this change, is integrated into develop through #1023. All checks, including CodeQL, passed before merge. Closing this superseded stacked PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant