The frontend scales rec counts client-side then sends capacity_percent as an audit-only field (frontend/src/recommendations.ts:3113-3124, app.ts:340-352); the backend explicitly ignores it for math (handler_purchases.go:1044-1048). Because the backend never cross-checks that the scaled counts match the recorded percent, the audit record can claim e.g. "50% capacity" while the recs sum to 100%. The audit trail for a financial action can be wrong.
Fix: either validate that capacity_percent is consistent with the summed counts at submit time (reject/warn on mismatch), or derive it server-side from the counts rather than trusting the client value.
Dedup: no existing issue. New. Surfaced in the purchase-workflow trace.
The frontend scales rec counts client-side then sends
capacity_percentas an audit-only field (frontend/src/recommendations.ts:3113-3124,app.ts:340-352); the backend explicitly ignores it for math (handler_purchases.go:1044-1048). Because the backend never cross-checks that the scaled counts match the recorded percent, the audit record can claim e.g. "50% capacity" while the recs sum to 100%. The audit trail for a financial action can be wrong.Fix: either validate that
capacity_percentis consistent with the summed counts at submit time (reject/warn on mismatch), or derive it server-side from the counts rather than trusting the client value.Dedup: no existing issue. New. Surfaced in the purchase-workflow trace.