Add scoped register-close summaries, Inbox and notification schedules - #1020
Closed
sridharkalaibala wants to merge 13 commits into
Closed
sridharkalaibala wants to merge 13 commits into
sridharkalaibala wants to merge 13 commits into
Conversation
This was referenced Sep 29, 2026
Contributor
Author
|
The complete Business companion stack, including this change, is integrated into develop through #1023. All checks, including CodeQL, passed before merge. Closing this superseded stacked PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Owners can configure a summary after each register session closes. The server discovers recent closes without an open phone, requests bounded calculations from the assigned desktop, and persists private Inbox entries before advancing scan checkpoints. This is explicitly a register-session summary, not a restaurant-wide close report.
Adds verified refund-session attribution, strict close fingerprints, Community publication/recovery, ACL-scoped reads, mutually exclusive daily/close schedule modes, quiet hours, revision-bound deduplication and generic push delivery. Reads and pending push retries recheck live scope and source; legacy clients cannot overwrite close schedules. Missing or ambiguous financial data is unavailable, never an invented zero, and completeness stays false.
Validation: 64 relevant real-Mongo/HTTP/cross-repository integration tests, 14 source/metrics/scheduling unit tests and 24 repository claims/sync classification checks pass. Targeted lint/formatting, attribution and generated API consistency pass. OpenAPI retains 14 existing ambiguous-path warnings. The related refund controller/service/repository suite previously passed 337 tests. No CI expansion.
Companion Gateway: https://github.com/Posnic/Gateway/pull/26
Companion mobile: Posnic/posnic-business#15 Stacked on the approval-alerts branch.
Remaining release gates: immutable financial history/source completeness, qualified language review, real-provider/physical-device push, deployment and production signing. Push tests use a fake transport; this PR does not deploy servers.
Dependency follow-up: the API lockfile now resolves ip-address 10.7.2, fixing GHSA-rpw4-54j3-4h4q and GHSA-2vr4-cq9g-pvrc without widening dependency ranges or suppressing advisories. The production advisory and dependency declaration checks pass locally. An isolated install verified the patched IPv6 link-local/NAT64 classifiers and express-rate-limit IPv4/IPv6 subnet keys; the shared root POS node_modules was not modified.