You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 437190c
Browse filesBrowse the repository at this point in the historyBrowse files
fix(purchases): record partial success and stamp target account on history (closes#642, #646) (#650)
* fix(purchases): record partial success and stamp target account on history
Partial-failure runs (some recs commit, others fail) were marked the whole
execution "failed" and skipped the success notification despite real
commitments written to purchase_history with Purchased=true, inviting a
re-approve that double-buys the already-purchased recs (#642). The
single-account path also stamped the ambient AWS host account on history
regardless of the resolved target account or provider (#646).
- #642: introduce a "partially_completed" outcome. When at least one rec
committed, never mark the row "failed"; record partially_completed, send
the confirmation for the recs that purchased, and surface the row in
History (flagged IsAuditGap so its execution-level dollars are excluded -
the committed dollars come from the per-rec purchase_history rows). Applies
to both the single-account path (via a partialPurchaseError sentinel that
finalizeExecution maps) and the multi-account fan-out path.
- #642 frontend: on a partial fan-out failure, name the buckets that created
pending executions so the still-actionable requests are not silent orphans;
add a distinct "Partial" history badge.
- #646: resolve the target account's ExternalID from the resolved account and
stamp that on purchase_history, falling back to the ambient AWS STS identity
only when no target account can be identified. Fixes assume-role AWS and
direct-execute Azure/GCP stamping.
Regression tests: single-account + multi-account partial success
(partially_completed status + notification sent), correct account stamping
for AWS and Azure, History row synthesis with dollar-exclusion, and the
fan-out partial toast naming submitted buckets.
Closes#642Closes#646
* fix(purchases): error when target account is unresolved, never fall back to ambient
When a single-account purchase resolves a concrete cloudAccountID but
GetCloudAccount returns a nil account (the account does not exist),
resolveSingleAccountProvider returned (nil, "", nil). The caller then
treated the empty target ID as "truly ambient" and fell back to the host
AWS STS identity, purchasing and stamping purchase_history against the
wrong account (#646).
Surface a descriptive error instead so the caller's no-ambient-fallback
contract holds once a target account is known. Add a regression test
covering the not-found path.
assert.NotEqual(t, "failed", row.Status, "a partial run with real commitments must never read as failed (double-spend hazard)")
575
+
assert.Contains(t, row.StatusDescription, "partially completed", "the partial outcome must be surfaced to the user")
576
+
assert.True(t, row.IsAuditGap, "partial row must carry IsAuditGap so its execution-level dollars are excluded")
577
+
assert.Equal(t, 1, resp.Summary.TotalCompleted, "money was committed, so it counts as completed")
578
+
assert.Equal(t, 0.0, resp.Summary.TotalUpfront, "partial row must not contribute execution-level dollars (committed dollars come from purchase_history rows)")
0 commit comments