You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Purchase approve and direct execute map every failure to 409, partial runs mint no revocation token, and the approved state is claimable by more than one path.
approvePurchaseViaSession (internal/api/handler_purchases.go:730) returns 409 for any approve error (:786). ApproveAndExecute (internal/purchase/approvals.go:307) would need to return the row, as RunPlannedPurchaseNow (:331) now does (fix(api): map run-now failures by cause and stamp its audit fields #495).
directExecutePurchase (internal/api/handler_purchases.go:3057) returns 409 for every error (:3090) and stamps ExecutedAt (:3069) before the claim, so a refused direct execute leaves executed_at on a row that never ran.
Partial runs (partially_completed) mint no revocation token and send no executed email. This is also true on main.
Approve and run-now execute while the row is still approved. claimAndExecute (internal/purchase/manager.go:177, SQS path) and the stranded-approved recovery can also claim approved. Pre-existing race; needs a separate check.
Failure scenario
A direct execute refused by a policy check returns 409 with the wrong semantics and leaves executed_at set. A run that ends partially_completed cannot be revoked by token and the approver gets no email.
Approve and direct execute return the matching status class per error, executed_at is only set after a successful claim, partial runs mint a revocation token and send the email, and the approved-row claim race has a test or a documented single claimer.
Summary
Purchase approve and direct execute map every failure to 409, partial runs mint no revocation token, and the
approvedstate is claimable by more than one path.Location (origin/main 496d9d7)
approvePurchaseViaSession(internal/api/handler_purchases.go:730) returns 409 for any approve error (:786).ApproveAndExecute(internal/purchase/approvals.go:307) would need to return the row, asRunPlannedPurchaseNow(:331) now does (fix(api): map run-now failures by cause and stamp its audit fields #495).directExecutePurchase(internal/api/handler_purchases.go:3057) returns 409 for every error (:3090) and stampsExecutedAt(:3069) before the claim, so a refused direct execute leavesexecuted_aton a row that never ran.partially_completed) mint no revocation token and send no executed email. This is also true on main.approved.claimAndExecute(internal/purchase/manager.go:177, SQS path) and the stranded-approved recovery can also claimapproved. Pre-existing race; needs a separate check.Failure scenario
A direct execute refused by a policy check returns 409 with the wrong semantics and leaves
executed_atset. A run that endspartially_completedcannot be revoked by token and the approver gets no email.Context
Related: #260, #415, #386.
Acceptance
Approve and direct execute return the matching status class per error,
executed_atis only set after a successful claim, partial runs mint a revocation token and send the email, and the approved-row claim race has a test or a documented single claimer.