soldi build log
Daily ledger of vertical slices shipped toward the PRD MVP. Each entry is the slice that landed, the verification evidence, and what's queued next.
2026-06-01 direction change: adopting the
closer — v2prototype design system and expanding scope to Comps + Pipeline + Sequences. Seedocs/ROADMAP.md,docs/DESIGN_SYSTEM.md, anddocs/SPEC_{COMPS,PIPELINE,SEQUENCES}.md. Next build slice is the design-system migration (foundation), then the 3 new pages. Historical only: Zak's pinned July 13 v60 mock and July 15 parity checklist supersede that buyer-surface direction for the MVP.
2026-07-26 — Systemic responsive pass merged and hosted-proved
- Market, My Leads, Territories, Activity, and invoice summaries now switch from wide tables to compact cards at and below
768px; My Leads' table fills its desktop container and Billing/Activity cap at900pxon wide screens. - Territory bid, cap, weekly-cap, choice, and removal controls now reserve
44px. Territory and request-refund dialogs cap at600px; the Territory sheet remains a phone-only bottom sheet below641px. - The tablet shell retains its balance pill. Activity keeps details and right-aligned money in distinct grid areas. Invoice rows carry explicit mobile labels instead of forcing a
640pxhorizontal table. - True zero inventory now says
New leads are on the way., explains the live shelf is empty, and links toView Territories; filtered-empty behavior still offers Clear filters. - Exact-hosted visual inspection of the preceding share fix caught a clipped third action despite zero document overflow. The responsive candidate places Call/Text together and gives Share its own full-width row at and below
768px. - The required make-it-sexy pass favored truthful hierarchy, actionable empty-state copy, and balanced controls over decorative motion. The make-it-simpler pass kept one shared
768pxboundary, reused existing cards/drawers, and added no dependency or parallel component. - Focused proof passed 87 tests. Full root verification passed 101 app files / 926 tests, TypeScript, production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions.
- PR #310 normally merged as exact two-parent main
2d08757e50c529a9138cd89ccf195d2e4b637743. The protected migration boundary was a no-op through0043; exact source tree5938674ff07894fe46b418c73783708565e13261and assetsb675c22a95e26ac8d51cbca2075e88d51013f7876d5eed15dc3072fcd2ce9741deployed as7a2b8c28-8c8c-4333-9e9f-f1345845ec6b/ versioncd72c388-bcd4-4c86-8259-f2d2804d4735. - The authenticated hosted matrix passed twice across five routes and
390x844,768x1024, and1440x900: 15 / 15 route-width rows, zero document overflow, console errors, failed application API responses, card-boundary misses, sub-44px Territory controls, ledger/invoice alignment misses, dialog width/centering failures, or Share-action clipping. - Visual review after animations settled confirmed the phone Share drawer, tablet Market/My Leads/Territories/Activity/Billing surfaces, and the full-width desktop My Leads table. Zak received the exact demo link for his physical-iPhone pass.
Next up: collect Zak's physical-iPhone acceptance and fix forward on any device-only finding. Production remains untouched and separately gated by live Stripe onboarding plus a freshly authorized retained-production D1 rehearsal/rollback for the exact promotion candidate. Durable receipt: artifacts/soldi-completion-2026-07/shots/responsive-hosted-receipt-2d08757-20260726.md.
2026-07-26 — Share/login stragglers merged and hosted-proved
- PR #309 normally merged as exact main
2ea307d106e04a7a3e9785ad10f57a3c604ab130. - The protected staging controller found no pending migration through
0043and deployed exact source tree1452a8c3f6bdc7531763172ba50b1d59dc891cdf/ assetsf64816ebbc56bd55600acce741ab86e42d186b327cccfb7319539c19417472e7as deployment58500d27-e0b6-4c7c-9254-7299c9594d49/ version2fe9909b-7eaf-42d4-bb8e-8ea64ae71703. - Hosted
390x844,768x1024, and1440x900proof retained Forgot password, removed the logged-out protected-Market loop, and rendered owned-lead share previews as4bd SFR; all three had no document overflow, console errors, or failed API responses. - Visual inspection caught one separate mobile Share-drawer clipping defect that automated document-width checks did not see. It is included in the next responsive PR rather than hidden by this receipt.
Next up: land and host-prove the responsive batch, then hand Zak the exact staging link for physical-iPhone acceptance. Production is untouched.
2026-07-26 — Share-label and logged-out navigation stragglers
- Owned-lead share formatting now canonicalizes literal imported
SfrasSFR, matching the already-approvedsingle_familyshare payload without rewriting stored lead data. - The logged-out login page no longer offers
Back to Open Market. The Market root is protected, so that link only returned the buyer to the same authentication redirect. Forgot password remains available. - The make-it-sexy review found no responsible visual embellishment to add to a two-line removal/casing correction; the make-it-simpler pass confirmed that deleting the misleading link is the smallest truthful interaction.
- Focused proof passed 10 tests. Full root verification passed 101 app files / 925 tests, TypeScript, production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. Local login rendering at
390x844,768x900, and1440x900had no horizontal overflow, retained Forgot password, and had no Market-loop link.
Next up: normally merge the source PR, deploy its exact merge to protected staging, and repeat the login/share proof against the hosted Worker before handing Zak the link. Production is untouched.
2026-07-26 — M8 staging inventory restoration live and hosted-proved
- Read-only protected-staging D1 proof found nine retained legacy staging fixture leads and thirteen attached economic references. All available inventory lacked a latest verified-consent row, so M8 correctly hid it from Market and Territory availability.
- The existing reseed controller correctly refused to delete or replace referenced rows. A new receipt-bound
m8-plan/m8-applypath instead preserves every retained wallet, purchase, refund, and portfolio row; adds four isolatedexample.testfixture leads; and attaches explicit synthetic staging-only consent evidence to a nine-lead QA shelf. - The target shelf is exactly three Cold, three Warm, and three Hot leads across four approved situations and varied ages. The controller is fixed to
soldi-staging, rejects partial/colliding/economically referenced target state, uses one D1 batch, and is idempotent. Production fixture exclusion remains unchanged. - PR #307 normally merged as exact two-parent main
82117c664b79c02475669797d00461b3a3686108. Protected staging had no pending migration through0043and deployed that exact merge as versionc576c94b-bd47-47c5-ae68-e5c69c07e6f4/ deployment8901eb9f-ceb8-45d3-b917-cf1cb08aaade. - Receipt-bound apply/readback produced exactly nine marketable leads with a 3/3/3 Cold/Warm/Hot split, four situations, and five distinct age dates. Wallet transactions
66, purchases27, refund requests/outcomes7/1, and portfolios36were unchanged; production was not touched. - Hosted Market and Territories passed
390x844,768x900, and1440x900with no document overflow, console errors, or failed responses. Market showed all nine Buy actions; phone controls were 44px high. The pass also confirmed the already-open systemic issue that desktop/tablet Territory steppers remain 24–30px. - Focused staging controls passed 67 tests / 292 assertions. Full root verification passed 101 app files / 923 tests, TypeScript, production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. Durable receipt:
artifacts/soldi-completion-2026-07/shots/m8-staging-inventory-hosted-receipt-20260726.json.
Next up: land the SFR owned-share label and remove the logged-out Open Market loop, then close the six-part tablet/desktop responsive pass. Zak can resume his physical-iPhone Market/Territory pass against https://staging.soldi.cc.
2026-07-25 — Production Stripe activation blocker isolated
- A read-only provider audit opened the Soldi Stripe account's live Workbench URL for account
acct_1TtjDjPuLV917S5K. Stripe redirected it to the/test/route, labeled the accountSandbox/Test mode, and kept live profile creation behindVerify your business. - The existing sandbox destination
Soldi stagingremains active athttps://staging.soldi.cc/api/v1/webhooks/stripewith the expected three events. No provider configuration was changed. - Cloudflare production secret-name readback shows both
STRIPE_SECRET_KEYandSTRIPE_WEBHOOK_SECRET; values were never read or persisted. Public production base health returns200, while/api/v1/health/striperemains404on the legacy Worker. - The durable, secret-free read-only receipt is
artifacts/soldi-completion-2026-07/shots/m9-production-stripe-readiness-audit-20260725.json.
Next up: Cam must complete Stripe's business verification and live-profile onboarding with the business representative, tax, and payout details. After that, configure and receipt the live Soldi webhook, statement descriptor, and receipt emails before any production promotion. Production remains HOLD.
2026-07-25 — Exact M8 staging Stripe acceptance and replay
- A fresh non-demo staging buyer began with the normal
$500promotional signup credit, then created a genuine$1,000Stripe-hosted Checkout against exact sandbox accountacct_1TtjDjPuLV917S5K. - Checkout
cs_test_a1PRk3fe834jgvgZUjZgKhd5r61nevObzYueMCdEtjokrtfZpYyEBHE3oE, PaymentIntentpi_3TwzX7PuLV917S5K0IErxjpN, and signed eventevt_1TwzX9PuLV917S5KjpxoMvikbind the payment to exact staged application1c142547, assets57efda7c…, Worker6fba2fcd…, and deploymentca805c8b…. - The signed webhook created one immutable
stripe_verified_fundingwallet row for exactly100000purchased cents. The buyer moved from total/promotional/purchased50000/50000/0to150000/50000/100000, with no bonus or hold. - An explicit Stripe Workbench resend reached
https://staging.soldi.cc/api/v1/webhooks/stripe; exact Worker6fba2fcd…returned200. Post-replay D1 still contained one processed event, one economic claim, one funding-evidence row, and one$1,000Stripe ledger row. No secret or raw signed payload was persisted. - The closed schema-1 receipt is
artifacts/soldi-completion-2026-07/shots/m8-stripe-acceptance-20260725.json.
Next up: obtain Zak's physical-iPhone pass, run a freshly authorized retained-production-copy rehearsal through 0043 with temporary-only rollback/deletion, prove production Stripe/webhook configuration, and assemble signed external acceptance. Production remains HOLD.
2026-07-25 — M8 consent truth normally merged and protected-staging live
- PR #303 passed hosted CI and normally merged exact source head
b30b327fbafd7f874ac84ec1b409dd407378a0fbover base37495a2de617445667d82774a505c38c0de947d8as two-parent main1c142547dec54923d7c154b610fa3e0152011bed. - The protected migration controller found only
0043_consent_truth.sqlpending, recorded a Time Travel bookmark, applied it, and read back no pending migration. Users35, wallet transactions64, market purchases27, portfolios36, and leads99were identical before/after. Migration receipt SHA-256 is266bb4fd6bff17b1da71f8a52caac7fb2f0bbbf556e018e331ebf685fb7276f8. - The protected deploy controller uploaded exact source tree
4818722d74931f524cdf0ee644847389bf1653dband assets57efda7c213b796133387369494f1ee0f2376a8c17ec373860b90ebbef35321das Worker6fba2fcd-3b21-4fc8-b654-3795bd3f2867/ deploymentca805c8b-7fc6-4555-83d3-da261599a0f7. Live base/Stripe health agree on full SHA and sandboxacct_1TtjDjPuLV917S5K. - Authenticated Market, My Leads, Activity, Territories, Billing, and Settings passed
1440x900and390x844with no horizontal overflow, clipped visible controls, console errors, or>=400application requests. Hosted Admin rendered the M8 missing-evidence and manual-attestation states at390x844; the temporary demo-admin flag returned to0and its total/purchased708000cents plus held/promotional0remained unchanged. - Fair Home Cash built
966pages and uploaded1,195assets as code version44fc9887-771c-4594-abfc-71de90f78137. Although Wrangler's route-update call returned Cloudflare10000, provider readback proved deployment4191ff34-c639-4621-b6f9-e79f73b21da7, the enabled apex domain, and the exact five-minute schedule. - Because live FHC forwards to production Soldi while production Soldi remains pre-M8, only
FHC_INGEST_SECRETwas removed. Secret-change versionb4252ade-8dbe-4ec6-bb44-d201ac02ea29/ deployment024200b9-9b48-40e9-9c11-cd73607c3cd8preserves KV, Resend, domain, schedule, and the new verifier. Valid leads remain persisted/alerted and forwards remain pending without retry exhaustion. Non-writing live probes returned400 missing_consent_evidenceand400 invalid_consent_disclosure.
Next up: rebind exact-candidate Stripe acceptance, run the retained-production-copy rehearsal through 0043 with temporary-only rollback/deletion, obtain physical-iPhone and signed external acceptance, then promote production. Restore the FHC bridge secret only after production Soldi runs M8 and prove one-time queue reconciliation.
2026-07-25 — M8 consent-truth candidate (local source and browser proof)
- Exact base/main is
37495a2de617445667d82774a505c38c0de947d8; the source candidate iscodex/consent-truth-20260725. Protected staging remains exact M7 application53172e598a5539be7d36f3cd9d0178370109dda1through applied0042; migration0043_consent_truth.sqlhas not yet been applied or hosted. 0043adds explicitverified/attested/missingevidence state, disclosure version/hash, and the latest-overall consent index. Historical thin rows stay nonmarketable; only explicitadmin_manual_attestationhistory becomes attested.- FHC now verifies a real checked, exact allowlisted English/Spanish disclosure before storage, captures disclosure hash plus IP/user agent or approved provider tokens, rejects forged/missing evidence, and keeps a durable retry/reconciliation pointer without exhausting it while the bridge secret is unconfigured.
- Admin manual intake records an honest operator attestation and stays unavailable for sale. CSV “verified” rows require TrustedForm or Jornaya evidence. Approval, Market, bulk, Territory, Package, bid, auction buy-now, and scheduled auction settlement all require the latest consent row to be complete and verified.
- Purchased-lead responses expose a compact owner-only intake record with status, source, method, captured time, disclosure version, and a lawful-basis reminder. They do not expose pre-purchase provenance or claim TCPA authorization.
- Root verification passed 101 files / 923 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. FHC passed 566 tests, built 966 pages, and audited with 0 blockers and 12 pre-existing thin-content warnings.
- Exact local browser QA passed the new Admin and dossier states at
1440x900,390x844, and320x844: zero document overflow, clipped active-dialog controls, console errors, or failed application reads. The 320px Admin attestation card remained fully usable.
Next up: open the ready normal-merge PR with Zak as reviewer, merge after CI/QA, apply sole pending 0043 through the protected-staging controller, and rerun authenticated hosted proof. Production remains HOLD for final-candidate retained-production rehearsal/rollback, live Stripe, physical-iPhone, and signed external acceptance.
2026-07-25 — M7 protected-staging deployment and authenticated readback
- PR #301 normally merged source head
dd44cd576d9edd8b31019e55ed202595213b2dbeover base7678d449b97bfd4f440f79363d04907e2e8a4da7as exact two-parent application authority53172e598a5539be7d36f3cd9d0178370109dda1. This is the deployed application authority; a later docs-only receipt descendant is not. - Protected staging applied its sole pending migration,
0042_admin_financial_resolution.sql; post-apply pending migrations are empty. The pre-apply Time Travel bookmark receipt hash is616cbef0756295a50dea4597646270f6b64ed8fd11bb36572ead6cdc11a0c8e1. The exact source-tree, assets, and migration digests are52aecf63915f09ee08ac2cb576d324c57f068938,e08c0dc436284e5c351c5a56b2184e9820c0a07b84135b4c56fba6fdd33102ab, anda3f4d17c6f9610b0deb29a54e0c89fe5c29e80399196b37009e30dae1df6779c. - Cloudflare readback identifies Worker
93bf0d59-a716-4460-a521-5add5e8e94d7, deployment4e74a35f-6d5d-4944-b8f0-9c46fbb8f016, and version tagv60-53172e598a55-92a496717b2e-f0945ce6dc1b42b785b6d4805b1045a1. Live health and Stripe health bind the runtime to test accountacct_1TtjDjPuLV917S5K. - Authenticated Admin exact buyer lookup passed and returned immutable ledger/reversal arrays; it made no credit or resolution mutation. The temporary staging demo-admin flag was restored to
0; balances remained total/purchased708000cents and held/promotional0. - Admin visual QA at
1440x900,390x844, and320x844had no overflow, rendered buyer evidence, retained 44px mobile controls, sent 24 requests all2xx/302, and logged no console errors. The six buyer routes at those same viewports had no overflow, signed-out/fatal state, console errors, or>=400response among 49 preserved requests. Local/tmpscreenshots are operator-local evidence, not durable repository artifacts.
Next up: close the remaining consent/provider/UI and owner-decision blockers, bind the resulting exact merge as the final candidate, and only then run the final production-data rehearsal/rollback plus physical-iPhone/external acceptance. Broad production promotion remains HOLD.
2026-07-24 — M7 admin financial resolution source candidate (local only)
- Exact current main/base is
7678d44; the source candidate is oncodex/admin-financial-resolution-20260724and has not merged, applied migration0042, or changed protected staging. Historical protected staging remains exact application003c744through migration0041; no hosted, staging, or production deployment claim is made by this entry. - Forward migration
0042_admin_financial_resolution.sqladds the operator-financial action, immutable completion/audit, terminal reversal-resolution, and later-provider-event quarantine records. The admin surface requires an exact buyer email or ID lookup; it does not enumerate or fuzzy-search buyers. - A correcting credit is positive-only, explicitly split, idempotent, and indivisible from its immutable wallet ledger and audit artifacts. Terminal reversal resolution is permitted only for an active case whose stored Stripe event ID and terminal status exactly match the selected provider evidence; request-key reuse replays the original result and conflicting reuse fails closed.
- Only a won dispute releases the case's held funds. Lost disputes and closed refunds release zero; any unresolved exposure keeps the account paused. Later provider events for a resolved case are quarantined rather than reopening or mutating the immutable resolution.
- A first-arriving terminal dispute event never creates a synthetic hold:
wonrecords zero outstanding exposure without pausing, whilelostrecords the full outstanding exposure and pauses without a hold. This closes the provider-ordering case before operator resolution. - Local QA passed the complete 101 app files / 914 tests, production controls 21 / 21 with 123 assertions, and exact Chrome/Playwright checks at
1440x900,390x844, and320x844with no document overflow, console errors, or failed requests; the exact buyer lookup path was exercised. This is local source/test/browser evidence only, not a hosted receipt.
Next up: independently review and normally merge this source candidate before any migration-first protected-staging run. Broad production promotion remains HOLD.
2026-07-24 — Refund gaming and genuine signed dispute replay pass
- On exact protected-staging application
003c744, client-supplied refund counters/timestamps and contactcreatedAtreturned400; non-owner evidence returned404; one idempotency replay returned the same attempt; and six real server-written Call/Text attempts compressed into about 1.4 seconds still returned409 refund_touchpoint_gate_not_metwith zero elapsed days. D1 retained exactly six eligible/distinct attempts and zero refund request/claim. - A fresh staging Investor with the normal
$500promotional signup credit completed one genuine$1,000Stripe-hosted sandbox Checkout using the provider's fraudulent-dispute test card. Checkoutcs_test_a1m84ta3ll9mTiCklgiUF1W2Rw7Dy0Nt7HtE9fN7Ys8qQMTr03DtANCLVKfunded PaymentIntentpi_3Twwr6PuLV917S5K2FpphlwWexactly once. - Dispute event
evt_1Twwr9PuLV917S5Kmy1dCL5Pinitially received retryable503while funding authority converged, then Stripe automatically retried to200. It created one active fraudulent dispute, paused the buyer, held exactly$1,000purchased exposure, left the unrelated$500promotional balance available, and recorded no outstanding exposure. - Four manual signed Stripe Workbench resends returned
200. Final D1 state remained one funding claim/evidence/deposit, one reversal case/event/hold,balance=150000,held=100000, purchased$1,000, promotional$500, andaccount_paused=1. - The browser session was signed out and no cookie/password/secret/raw-payload artifact was persisted. Public copy delta: none. Durable receipt:
artifacts/soldi-completion-2026-07/shots/refund-dispute-redteam-hosted-receipt-20260724.md. - Final repository proof passed 98 app files / 893 tests, TypeScript, Vite, transparent-brand audit, production controls 21 / 21 with 123 assertions, docs build 10 internal + 2 client docs + index, readiness JSON validation, and diff hygiene.
Next up: publish the docs-only receipt, then close production Stripe/admin/consent configuration and final-candidate rehearsal/device gates. Broad production promotion remains HOLD.
2026-07-24 — Production demo access revoked on the deployed legacy runtime
- A fail-closed production probe found that the static-brand production runtime still exposed
demo@soldi.cc / soldidemo,/api/v1/auth/demo, and already-issuedU_SEED_GHOSTsessions. Production health had no source SHA, so provider history was reconciled to static-social source55efa35922e9df2be159e0de28587f8e90ef386b. - A production-only emergency snapshot was cut from that exact live source. Commit
f429daac23dafb782ba36ce9a9d03faa5e4cfbc0blocks current and legacy demo emails before login D1 access, removes canonical/query-flag demo login, and rejects both seeded demo user IDs through ordinary and admin session guards before D1. - Focused proof passed 42 tests / 117 assertions. The complete historical runtime passed 34 files / 270 tests, TypeScript, Vite production build, Wrangler dry-run, and diff hygiene. Independent Terra/high review found no remaining direct session-verification bypass.
- Cloudflare uploaded no changed asset files and activated the Worker-only fence as version
12a6b797-7d38-4aaf-85c0-bb1b2aaa0ce8/ deployment181a0528-37a4-43a1-bf59-f007a3f298f2. No migration, secret, Stripe configuration, D1 correction, UI bundle, or public copy changed. - Hosted proof returned
401 invalid_credentialswith no cookie for the demo login,404 not_found/no-storewith no cookie for/auth/demo,{"user":null}for a session issued before the fix, and401 unauthorizedfor both a buy mutation and admin read using that session. Health remained200. - The pre-fix cookie artifact was deleted and verified absent. Historical demo wallet/ledger rows remain inert production audit history pending a separately authorized data-correction decision.
Next up: publish the docs-only receipt, then execute refund-attempt gaming and a genuine signed charge.dispute.created freeze/replay. Broad production promotion remains HOLD.
2026-07-24 — Exact-staging two-buyer race and PII preview pass
- Created one unmistakably synthetic
$150open-market lead and two fresh staging-only Investor accounts on exact staged application003c744. Each account started with the normal server-recorded$500promotional balance; no production or provider payment was touched. - Before purchase, both Market payloads contained the lead's price/status but none of its seeded seller address, name, phone, or email keys or values.
- Simultaneous authenticated buys returned one
201 purchasedand one409 lead_unavailable. D1 contains exactly one sold lead, purchase, portfolio, immutable$150debit, completed fulfillment claim/completion, and batch guard. The winner has$350, one win, and one spend; the loser remains$500, zero wins, and zero spend. - Winner replay returned
200 already_owned; loser replay remained409; purchase/portfolio/debit/claim/completion counts stayed exactly one. - All staging cookie jars and transient response/status artifacts were deleted and verified absent. Synthetic economic rows remain only in isolated staging as auditable red-team evidence.
- Public copy delta: none. This closes Zak's two-buyer/same-lead and pre-purchase PII cases for exact staged
003c744; production-demo isolation, refund gaming, signed dispute creation, device, and production gates remain open.
Next up: publish the docs-only receipt, then execute production-demo isolation and the remaining provider/refund cases. Production remains HOLD.
2026-07-24 — FHC five-minute alert control live and provider-proved
- Ready PR #296 requested
killerabbasi, passed hosted FHC CI, and normally merged exact head41c95804471189aa5fd928027a789e96c9af2697overe60cc994d0e0e78e8bb9556587565e92615b3b49as two-parent main6a20c11ac285c2fbbd184882997b6a0a5106825e. - A clean exact-main deploy uploaded the 966-page FHC build and activated Worker version
e714d690-3bdc-4d2d-bc23-95b323848d60at 100% through deploymente06561d3-effc-46b3-9241-f199fad60674. Wrangler's final zone-route call returned Cloudflare10000, but provider deployment readback and the live domain's new authenticated-endpoint401prove the existing custom domain advanced. - The upload did not apply the new cron. The Workers Scripts schedules API accepted
*/5 * * * *and an immediate readback returned that exact trigger. - One synthetic Cameron-only KV lead/pointer produced a pre-SLA
sentreceipt at03:20:22Z, ownercamolechowski@gmail.com, retry count0, and provider messagecffb7af8-d167-47ce-8b3e-8362ba86f56a; Resend reportsdelivered. - Reinserting only the pending pointer caused the next cron to clean it without changing the provider message or retry count, proving the terminal hosted path does not resend. The synthetic lead, pending pointer, and receipt were deleted and verified absent.
- Public copy delta: none. The subsequent human
pending_reviewowner/SLA remains open, as do Zak's remaining money-path red-team, device, final-candidate, rehearsal/rollback, and production gates.
Next up: publish this docs-only hosted receipt, send Zak the exact live link/version evidence, then continue the remaining adversarial cases. Production remains HOLD.
2026-07-24 — Signed refund replay, hosted password recovery, and FHC alert control
- Reconciled current source
e60cc994d0e0e78e8bb9556587565e92615b3b49as a docs-only descendant of staged application003c744fe332594d3f2d6b1619aade3178ab07c8; no Worker upload or migration was needed for these provider/hosted checks. - A real
$2,500Stripe sandbox refund generatedcharge.refundedeventevt_3TwumGPuLV917S5K0mGdlCMQ. The staging webhook had onlycheckout.session.completedenabled, so the provider correctly showed zero deliveries and D1 remained unchanged. The endpoint was narrowed to the three event types the Worker actually handles: Checkout completion, refund, and dispute creation. - Two signed Dashboard resends returned
200. The first created one active refund case/event, paused the isolated buyer, kept purchased/promotional/held/total wallet values at zero, and recorded$2,600outstanding exposure including the full$100bonus. An authenticated purchase then returned403 account_paused; the lead stayed available with no purchase or debit. The second resend left exactly one case/event and unchanged wallet/outstanding state. - A fresh staging-only account using Cameron's controlled Gmail alias completed the hosted password-recovery loop: register
201, generic request202, real email fromSoldi <account@notify.soldi.cc>, canonical staging fragment link, reset200, and new-password login200. The one-time token and temporary response artifacts were deleted immediately. - The FHC source candidate now writes a durable PII-free
alert:<lead-id>receipt for every contactable lead, binds owner/SLA/attempt/retry/provider state, uses a stable 24-hour Resend idempotency key, and reconciles a bounded expiring pending-alert index from a native Cloudflare five-minute cron. Retries are paced to the five-minute boundary, record an explicit SLA-breach timestamp, and become a durable observableexhaustedstate after six unsuccessful attempts instead of silently aging out. The authenticated operator route returns aggregate counts only. - FHC focused proof is 12 tests / 56 assertions; its complete workspace is 559 tests / 5,259 assertions; the fresh 966-page build and launch audit pass with 0 blockers and the 12 pre-existing thin-page warnings. Wrangler dry-run compiles the scheduled Worker. Root verification remains 98 files / 893 tests, TypeScript, Vite, the transparent-brand audit, and production controls 21 / 21 with 123 assertions. This source control is not live until its ready PR normally merges and exact merged FHC Worker deploys.
- These are exact staged/provider receipts plus local FHC source proof, not production authorization. Remaining same-lead race, production-demo isolation, refund-gaming, actual dispute creation, PII masking, physical-iPhone, final-candidate rehearsal/rollback, and external acceptance stay open.
Next up: independently review, normally merge, deploy, and hosted-prove the FHC alert control, then continue the remaining red-team cases. Production remains HOLD.
2026-07-24 — Protected-staging money red team and wallet-race hotfix merged
- The protected migration controller applied
0040_atomic_auction_buy_now.sqlthen0041_stripe_reversal_response.sqlto D1soldi-stagingunder a Time Travel bookmark, verified retained data, and deployed exact clean mainc6eb03b558330e04d51d8edb3726aad5d2cdf763as deployment44f21e4d-f287-44f6-a8c2-6622206ed605/ Worker33b77ce9-e6bc-438c-9f62-69c47c8b1680. Health, migration tip, and Stripe test accountacct_1TtjDjPuLV917S5Kagree. - A genuine hosted Stripe Checkout credited
$2,500principal plus the advertised$100deposit bonus exactly once. Multiple signed Dashboard resends ofevt_1TwumIPuLV917S5KSo7xwjppreturned200; one processed event/economic claim, two immutable funding rows, and all wallet totals remained unchanged. - An isolated same-buyer/two-different-Warm-lead race started with exactly one lead's balance. One purchase/debit/ownership committed, the other rolled back, and the wallet remained non-negative; the loser nevertheless returned
500because the intentional completion-guard failure had no same-lead purchase row for the existing recovery branch. - The source fix maps only the exact
lead_fulfillment_batch_guards.lead_idnon-null conflict to409 purchase_state_changed; unknown database errors still rethrow. It adds fake-D1 classification coverage, a real-SQLite same-buyer/different-lead regression proving one economic outcome, and an approved-refund regression proving no lead relist/status mutation. - Focused proof passes 3 files / 22 tests. Full root verification passes 98 files / 893 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. No buyer-facing UI or public copy changed, so the UI polish and screenshot workflow is not applicable.
- Ready PR #294 requested
killerabbasi, passed hostedchangesandbun verify, and normally merged exact head7bf9ec1523fc0d1c850f4d1b7607772603e5d3eeoverc6eb03bas two-parent main003c744fe332594d3f2d6b1619aade3178ab07c8. - The protected controller confirmed no pending migration after
0041, then deployed exact merge003c744as deployment5521e77a-ebf0-4aae-8c81-53bc4fd76f8c/ Workere2d5c349-a806-46e6-b6ce-deab9e87592a. The hosted rerun returned one201and one409, zero remaining wallet, one sold and one available lead, and exactly one purchase/portfolio/immutable debit. Health and Stripe identity bind the exact merge and expected sandbox account.
Next up: complete the remaining money red team, password-reset delivery, FHC queue ownership/alerts, hosted browser matrix, and physical-iPhone proof. Production remains HOLD.
2026-07-24 — Stripe reversal-response and economic pause merged
- Started from exact docs-only main
ed25da4161ce78b239e4bc6c666f42548a5a1ad7over merged application authorityd61d0b80ecc0fa95f6d7e48e1a1eb90b83a12ebcin isolated branchcodex/chargeback-m6-20260724. Protected staging remains historicale10a72566b76f5fc004c41d057fdfe751f82fb52; no Cloudflare, D1, Stripe dashboard, staging, or production mutation occurred. - Forward migration
0041_stripe_reversal_response.sqladds bounded funding evidence plus append-only dispute/refund case and event state. Checkout funding records name/email/phone/country/postal-code evidence atomically with the existing event/economic claim, wallet credit, and immutable ledger rows; raw Stripe payloads are not stored. - After existing signature verification,
charge.dispute.createdand cumulativecharge.refundedbind only through persistedpayment_intent_id. Wrong mode/currency/amount is acknowledged without mutation; missing schema or funding authority and stale atomic races remain retryable. - A dispute pauses the buyer and holds currently available credited exposure. A refund pauses the buyer and reverses available promotional/purchased cents without making any wallet component negative. Partial events include proportional deposit-bonus exposure; a full refund removes the full principal and full associated bonus. Unavailable remainder persists explicitly as
outstanding_cents, and cumulative deltas carry prior outstanding exposure forward. - Exact wallet-state and cumulative-provider compare-and-swap predicates plus a final non-null batch guard make stale snapshots roll back. A buyer with an active reversal case cannot self-unpause; an explicit operator-resolved state preserves a future safe resume seam. Package activation, candidate/final delivery, renewal, bid placement, and scheduled auction selection/debit/portfolio writes all fail closed across pause races.
- The controller authority is now 41 migrations total: production's retained baseline remains 24 applied (
0001–0024), and the next rehearsal expects 17 pending (0025–0041). Deployment order is0040, then0041, then the exact merged Worker. - Final focused proof passes 6 files / 93 tests plus TypeScript and diff hygiene. Full root proof passes 98 files / 891 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. This backend-only slice changes no buyer-facing copy or UI, so the UI polish/screenshot workflow is not applicable.
- Ready PR #292 contained immutable application commit
09b48cc34097f1aa8c13851199302f2562cbfcbaplus receipt-only descendants, withkillerabbasirequested and public copy deltanone. Exact final headd5477c8243e97e8f384d989318cf43c4fdecca0apassed hostedchangesandbun verify, then normally merged as exact two-parent mainca97b1342d3712d49db47fd0468936cdcb74749f(ed25da4+d5477c8). Migration-first protected staging and every provider/device receipt remain open.
Next up: mint a fresh migration-first protected-staging receipt for exact merged main ca97b13, applying 0040 then 0041 before the Worker, and run signed sandbox dispute/refund plus authenticated browser and physical-iPhone acceptance. Terminal dispute resolution and admin treatment of outstanding exposure remain explicit follow-ups; production stays HOLD.
2026-07-24 — Server-authoritative refund window merged
- PR #289 normally merged M4 as exact main
d0bb9e4dd235a5b73b51d6e10233de4176b8ef2e; protected staging remains historicale10a72566b76f5fc004c41d057fdfe751f82fb52and no provider, D1, Stripe, staging, or production mutation occurred. - M5 preserves the reason-independent minimum of six owner-scoped, server-written Call/Text attempts spanning 72 hours. The strict request body still rejects client counts, timestamps, and upload/proof fields; email, pre-purchase, malformed, and future attempt evidence cannot authorize a refund.
- The refund route now derives an inclusive rolling seven-day window from the owned portfolio's persisted
purchased_atplus the Worker clock. Missing, malformed, future, and older-than-seven-day purchase timestamps fail closed before source-debit resolution or any refund write. - The only buyer-copy delta is the rejected-request message
The 7-day refund window for this lead has closed.No proof-upload UI, table, bucket, binding, or retention obligation was added. - Focused proof passes 3 files / 25 tests plus TypeScript. Full root proof passes 96 files / 874 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21 / 21 with 123 assertions. The required polish workflow still cannot parse its pre-existing top-level ECMAScript-module
return; manual make-it-sexy review plus three native make-it-simpler lanes found no unresolved P0–P2 in the exact changed source. - PR #290 requested
killerabbasi, passed hostedchangesplusbun verify, and normally merged as exact two-parent maind61d0b80ecc0fa95f6d7e48e1a1eb90b83a12ebc(d0bb9e4+ reviewed head367e838). Protected staging and every provider remain untouched.
Next up: continue M6 dispute/chargeback response as the next source blocker. Migration 0040 still must precede the next protected-staging Worker deployment; M3 provider receipt, M4 retained production demo history, and all hosted/promotion gates remain separate.
2026-07-24 — Production demo isolation candidate
- Started from exact normal main merge
289b877bf9a45d5a63b4c4c92694c691c921ba87in isolated branchcodex/production-demo-isolation-20260723; the root checkout and protected staging were not mutated. Protected staging remains exacte10a72566b76f5fc004c41d057fdfe751f82fb52. - One fail-closed environment authority now permits fixture data only in explicit
development,test, orstaging. Production/auth/demoreturns404before D1,?demo=1cannot mint a session, current and legacy demo credentials return generic401, and already-signed sessions for either demo identity resolve to no user. - Market list/direct-buy/bulk-buy exclude all six canonical v60 IDs, legacy
L_MKT_*IDs, andseed://source/landing provenance outside trusted fixture environments. Scheduled restock no-ops there even if auctions are later enabled. - Non-interactive economic paths reject both
U_DEMO_V60andU_SEED_GHOST: Stripe webhooks acknowledge them as ignored without a claim/credit, auction settlement cannot select their bids, Territory allocation skips their orders, Package renewal/routing skips their subscriptions and orders, and production Package-readiness excludes their Package/Territory demand plus fixture/seed supply. - Existing fixture-dependent SQLite tests now opt into
APP_ENVIRONMENT=testexplicitly. Focused route/SQLite coverage includes auth/session, Market single/bulk purchase, Stripe, settlement, Territory, Package renewal/routing/readiness, and scheduler behavior, with explicit staging preservation checks. Full app proof passes 96 files / 868 tests plus TypeScript. - This backend-only candidate changes no buyer UI or public copy, so no application screenshot recapture or post-change UI polish is applicable. A fresh direct Zak-message lookback found no newer product request after his July 23 master packet and exact-SHA re-audit.
- The source patch makes the historical production demo balance economically unreachable but does not rewrite retained D1 history. A separate production-only, before/after-receipted correction is still required before claiming the stored balance itself is zero.
Next up: complete root/docs/control verification and independent review, publish one ready PR with killerabbasi requested, and merge normally after CI. Then proceed to M5 server-authoritative refund eligibility. Migration 0040 still must precede the next protected-staging Worker deployment.
2026-07-23 — Buy-now atomicity and truthful Stripe bonus ledger candidate
- Started from exact normal merge/staged baseline
e10a72566b76f5fc004c41d057fdfe751f82fb52in isolated branchcodex/money-blockers-atomicity-20260723. Zak's source audit identified a real auction buy-now race: the route pre-read state and then unconditionally batched bid, debit, sold state, and ownership writes. - Forward migration
0040_atomic_auction_buy_now.sqladds one immutable claim per auction/lead plus a final commit guard. Every bid, promotional-first debit, sold-auction mutation, portfolio, own-hold conversion, and exact displaced-leader release is conditional on that claim; the guard aborts the entire D1 batch unless all economic artifacts agree. Same-winner retries return the original portfolio without charging again, while another buyer receives409. - Stripe funding already had same-batch event/economic claims, signed-event validation, and exactly-once replay recovery on
e10a725; those invariants were preserved. The advertised promotional amount now writes a distinct immutabledeposit_bonuscredit beside the principal Stripe deposit in the same batch. Invoice funded totals include both rows and same-timestamp Activity ordering is deterministic. - Fresh real-SQLite proof starts two buyers from the same pre-claim state and gets exactly one
201, one409, one debit/portfolio/claim/guard, correct aggregate balance, and no negative wallet. Additional cases prove own-held affordability, exact displaced-leader release identity, same-winner idempotent retry, and total rollback after an injected portfolio-write failure. Focused money/read-model proof passes 6 files / 44 tests plus TypeScript. - Three independent native reviews found and closed winner retry, budget/pause compare-and-swap, exact release-row binding, invoice funding aggregation, and ledger-order issues. Migration review found no backfill rewrite or D1 SQL blocker. Operational order is strict: apply
0040before deploying the Worker; code-first rollout intentionally fails buy-now closed with503 auction_buy_now_schema_not_ready. - This candidate changes no buyer-facing copy or UI and therefore needs no screenshot/deck recapture or post-change UI polish. No Cloudflare, D1, Stripe provider, staging, or production mutation occurred.
Final proof passes 95 files / 849 tests, TypeScript, Vite production build, transparent-brand audit, production controls 21 / 21 with 123 assertions, docs build (10 internal + 2 client docs + index), release-readiness JSON parse, and diff hygiene. The production rehearsal controller now pins 40 total migrations and the exact 16-migration 0025–0040 pending set.
Next up: publish one ready PR with killerabbasi requested and merge normally after CI. The future protected-staging rollout must migrate before Worker upload and mint fresh exact-merge concurrency/Stripe/hosted receipts; production remains separate. Then continue Zak's ordered M4/M5 money blockers.
2026-07-23 — Hosted 320px Market/Territory target hotfix
- PR #286 merged normally as
73153a87ed7f046b91f828e1e07d177332c581cd; protected staging deployed that exact merge as deployment8df8e4b4-d200-487f-8346-4d1dde0d0334, Worker versionb1d8488d-259f-4181-a65e-46670d0ccc6b. Health and Stripe-health readback matched the full SHA/version and the expected Stripe sandbox account. - Authenticated hosted QA found three bounded CSS defects at 320px despite clean document width: the Package recommendation actions were 42px, Territory bid steppers could flex below 44px, and the desktop Remove cell leaked through a more-specific
!importanttable rule. A same-row bid/cap arrangement was also too crowded at the narrowest viewport. - The isolated hotfix restores 44px recommendation and bid targets, hides Remove with a specificity-safe selector, changes the 120px card ceiling to a content-safe minimum, and stacks bid/cap controls only at
max-width:340px. The 390px card retains the compact two-row hierarchy. - Fresh local authenticated automation passed 22 route/viewport rows with no application failures. Rendered 320px inspection shows separated bid and weekly-cap rows, no clipping or overlap, and 44px controls. Three native Terra/high reviews were clean on reuse and efficiency; the quality review's 320px geometry concern directly produced the stacked narrow-screen revision.
- Final proof passed 93 files / 842 tests, TypeScript, Vite production build, brand audit, production controls 21 / 21 with 123 assertions, docs build (10 internal + 2 client docs + index), release JSON parse, and diff hygiene. The required polish workflow remains blocked before execution by its existing top-level-return parser defect; manual/native review and rendered inspection completed instead.
Next up: publish and merge the ready hotfix PR with killerabbasi requested, deploy its exact normal-merge SHA through protected staging, repeat hosted 320/390 QA, and send Zak that exact link/SHA for the physical-iPhone pass.
2026-07-23 — Zak final mobile, Package, refund-gate, and legal candidate
- PR #286's local candidate preserves exact staged baseline
ea9c091a43bae4ce5706d6ef5b07b79e5b87d327while closing Zak's latest phone and money-trust findings. The shared mobile navigation, dense Market/My Leads/Territories/Activity/Wallet hierarchy, owned-share privacy default, session resiliency, fund-and-return flow, and buyer-facing ledger copy remain intact. - Refunds now use the locked original touchpoint design for all nine reasons: no uploads or proof storage, at least six server-tracked Call/Text attempts across three days on the purchased portfolio, the exact work-first copy before unlock, a required reason, optional details, and no economic/refund write on a gate failure. Transaction eligibility and pending state are portfolio-scoped and use set-based summaries instead of per-row correlated scans.
- Wallet visibly discloses the full Package commitment as
$5,000/moand25 Hot leads at $200 eachon phone. Terms, Privacy, and Acceptable Practices remove draft/placeholders/Wyoming residue and consistently use Illinois formation, Cook County,support@soldi.cc, the Soldi/Fair Home Cash mailing address, July 22, 2026 dates, and the drafted$50,000cap. - Focused proof passes 8 files / 53 tests. The complete pre-documentation gate passes 93 files / 842 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21/21. Local browser proof covers 22 authenticated route/viewport rows at 320×844, 390×844, and 1440×900 plus the phone refund sheet and all three legal pages with no overflow, console/page/application-network failures, native selects, undersized controls, or sub-16px inputs. Receipts are under
/tmp/soldi-zak-final-browser-proof-v2/. - The required repository polish workflow was attempted but cannot parse under Bun because
.claude/workflows/post-change-polish.jscontains a top-level ECMAScript-modulereturn; native Make it Sexy / Make it Simpler reviews and rendered visual inspection were completed instead, and the tooling failure is recorded rather than mislabeled green. Zak confirmed the item-40/package/legal direction and instructed the team to finish exact SHA plus staging receipts before triaging his separate safeguard red-team packet.
Next up: final exact-tree verify, ready PR receipt/reviewer/CI, normal merge, protected-staging deploy and hosted 320/390/1440 proof, then send Zak the exact SHA/link for his physical-iPhone pass. Production remains separate.
2026-07-22 — Exact mobile candidate staged; 320px Wallet label follow-up
- PR #284 merged normally as
9203b5c2f677f62542a8c87146aac02775b2d572(parentsb0974b2/a40c16c). No migrations were pending through0039; protected staging deployment71936e79-fb82-4243-9578-174255e057cf/ Worker versione0935b95-7069-4f07-832a-0103ef29f227serves that exact merge with test Stripe accountacct_1TtjDjPuLV917S5K. - Its receipt-bound non-mutating Territory plan proved exactly three marker rows, zero order references, and zero Orange/Will/Dallas competitors. The guarded apply produced exact Orange/Will/Dallas shapes at positions
1,1,1; wallet/purchase/refund/outcome/portfolio counts stayed24/6/5/1/15, and all prior lead/economic history remained. - Authenticated hosted Market/My Leads/Territories/Activity/Wallet/Settings sweeps at 320, 390, and 1440 pixels had exact document width, no horizontal overflow, no console errors, and no failed app requests. The stricter 320px Wallet capture found only
Pay per leadellipsizing; a one-rule candidate reallocates existing grid space and proves all three choice labels unclipped. The complete gate passes 85 files / 791 tests, TypeScript, Vite, brand audit, production controls 21/21 (123 assertions), docs build, and diff hygiene; three independent reviews are clean.
Next up: full gate, ready follow-up PR, exact merge/redeploy, hosted label/share readback, then Zak's physical-iPhone pass.
2026-07-22 — Territory target-context collision correction
- PR #283 merged normally as
b0974b2cae192e2f2f2fbe4a30cd228e5440acfd; protected staging deployed that exact merge after a no-op migration receipt. The first receipt-boundterritory-planmade no write and refused because another buyer already owns an active Broward FL Territory, proving the target-context guard works against live drift. - The correction replaces only the proposed Broward target with Orange County FL; Will IL and Dallas TX remain. Existing Essex and Broward orders stay untouched. Exact-shape readback and wrong-but-distinct rejection continue to bind every marker ID's name and filters.
- Verification is green: focused controller 21/21 tests (117 assertions), full app 85 files / 791 tests, TypeScript, Vite, brand audit, production controls 21/21 (123 assertions), docs build, and diff hygiene. Independent exact-candidate review returned READY with no P0-P2 finding.
Next up: repeat the focused/full gates and exact review, normally merge, mint a new exact-merge receipt, rerun the non-mutating plan, then apply only if it proves collision-free.
2026-07-22 — History-safe staging Territory refresh follow-up
- PR #282 merged normally as exact main
4da97bd45e3491fe3073610541289a4bb186b4caafter hosted CI and exact-candidate review. Protected staging migration readback was a no-op through0039; deploymenta570bdfa-e50d-4cc0-8fc2-a35139359dcb/ Worker versionb7038a04-d136-40d0-b95f-258b9e1e1559now serves that exact merge. - The guarded v1→v2 demo-seed dry-run refused with
demo_seed_fixture_has_economic_history, correctly preserving one purchased/portfolio-backed legacy fixture lead. Read-only D1 proof found three marker-owned legacy Territory orders with zerolead_allocation_claimsand zeroportfoliosreferences, plus one unrelated retained Essex order. - This follow-up adds a separate receipt-bound
territory-plan/territory-applypath. It updates only the exact three marker-owned, unreferenced legacy Territory rows in one guarded D1 batch; leads and all economic tables remain untouched. Broward FL, Will IL, and Dallas TX avoid the retained Essex context and must read back as the exact per-ID names/filters in three position-1 partitions. Focused proof passes 21/21 tests (117 assertions), including economic-history preservation, wrong-but-distinct target rejection, and before/after ledger equality. The complete gate passes 85 files / 791 app tests, TypeScript, Vite build, brand audit, and 21/21 production controls (123 assertions); docs rebuilt and exact-candidate review returned READY with no remaining P0–P2. No follow-up D1 mutation has run yet.
Next up: exact-head review, ready PR/CI/normal merge, fresh exact-merge staging receipt, Territory plan/apply, and hosted 320/390/1440 QA before Zak receives the link.
2026-07-22 — Zak iPhone final-polish + owned-share candidate (local; not deployed)
- Re-read Zak's direct-message rows
280385–280388and verified no newer direct Soldi instruction supersedes them. The phone bottom rail now owns Market, My Leads, Territories, Activity, and Wallet; the avatar menu contains only Refunds, Settings, and Sign out; and/transactionspresents the single visible label Activity without changing its route or ledger API. - Settings now defaults to one compact Account card with an on-demand profile editor, truthful non-control security copy, tight Notifications/Lead delivery status rows, and Retake setup. It removes the duplicate Payment & Budget shortcut, duplicate default name/email fields, disabled two-step toggle, and disabled delivery-radio affordances. Wallet removes only the Monthly budget UI while retaining all backend cap fields/APIs/enforcement; it shows balance in exactly the top bar and wallet hero, preserves a 44px Add funds control, and fixes the clipped Three ways to buy heading. Market uses the tighter subtitle and compact dismissible Package recommendation without changing readiness or pricing.
- My Leads adds owned-lead Share actions to list and board cards. The launch flow loads the owner-scoped lead detail, then shares exact address, property line, estimated value, and Google Maps URL through Web Share with clipboard fallback.
Include seller contactis off on every open; phone/email/name are absent until explicitly enabled. Load failure closes the sheet with a truthful error. Masked/referral sharing, Apple Pay, and post-call prompting remain in Zak's explicit post-launch sequence. - The receipt-bound staging demo seed advances from marker v1 to v2 and will replace only the exact marker-owned, history-free fixture with three distinct county-only rows (Essex NJ, Will IL, Dallas TX). The controller treats both
upgradeand legacy cleanup as real transactional mutations, locks three distinct counties at positions1,1,1, and preserves wallet/purchase/refund/portfolio counts. No remote D1 mutation has run yet. - Focused source proof passes, the corrected seed controller passes 19/19 tests (99 assertions), and the final root gate passes 85 files / 791 tests, TypeScript, Vite production build, transparent-brand audit, and production controls 21/21 (123 assertions). Exact-candidate review also closed truthful legacy-cleanup receipts and a board-card keyboard bubbling edge case before returning READY. A temporary QA-only
.dev.varssymlink was removed after the path-fence correctly rejected it; the clean rerun passed. Docs rebuilt 10 internal + 2 client docs + index and diff hygiene passed. Local authenticated Chrome at 390×844 proves no document overflow, no sub-44px visible links/buttons on Settings/Wallet, no fake Settings toggles/radios, no Monthly budget copy, exactly two visible balance values, an unclipped Three ways heading, matching Activity tab/page title, the three-link avatar menu, and owned-share privacy default/reset. Browser-captured share payloads prove seller contact absent by default and present only after opt-in. Fresh local screenshots are indocs/shots/*final-polish-local-20260722.png.
Next up: rerun the complete root gate after the final Settings compaction/docs update, publish one ready PR with killerabbasi requested, normally merge after exact-head/CI QA, then deploy and v1→v2 reseed protected staging through fresh exact-merge receipts. Hosted 320/390/1440 QA and Zak's physical-iPhone auth/password-reset/share pass remain separate; production is not implied.
2026-07-22 — PR #270 real-app port staged; footer touch-target correction
- PR #280 passed hosted CI and independent exact-head review against Zak's PR #270 source, then merged normally as
eb9ef536fba7c87fb09e266d574f7277fcc83876with parents04cb71b71bd1af506608046bc80f3fa5914b0b2dand reviewed head8fee43b2cca8805441edd98f76611292f970076a. A fresh protected-staging migration receipt bound to that merge found no pending migrations through0039and made no D1 mutation. Provider deploymente4f12efc-d5a1-4f57-84be-67e9634d4b22/ Worker version68d882d6-1839-463e-a0da-2c29d8383928serves the exact merge atstaging.soldi.cc; health and Stripe readback prove the expected SHA and test accountacct_1TtjDjPuLV917S5K. - Hosted 320×844, 390×844, and 1440×900 automation found no page overflow, console errors, font failures, or broken images on My Leads, Territories, Transactions, or desktop Billing. It also found one bounded shared-shell defect: the five mobile footer legal/support anchors were visually readable but below the locked 44px target. This follow-up makes the mobile footer nav full-width and gives every link a centered 44×44 minimum target; it changes no copy, route, API, D1, Stripe, wallet, Package, or desktop behavior.
- The focused Layout regression passes 2/2 tests. The repository polish runner was attempted and still fails before execution on its existing Bun 1.3.0 top-level-return error; explicit make-it-sexy review and independent reuse, quality/accessibility, and efficiency reviews all returned clean.
Next up: run the full root gate, land this bounded follow-up through a ready PR, mint a fresh receipt for its normal merge, redeploy protected staging, and repeat hosted acceptance before sending Zak the link for his physical-iPhone pass. Production remains separate.
2026-07-22 — Zak PR #270 exact mobile-mock port (local candidate; not deployed)
- Reconciled GitHub PR #270 at exact head
a29e9c74d27e8d62a5a8f3e6697d6e9a5e16a8f2and used its sole file,previews/soldi-mobile-preview.html, as the phone visual authority. The real app now carries the mock's compact balance/add/avatar top bar, translucent five-tab rail, searchable separated My Leads cards, labeled Territory cards, two-column transaction ledger, centered wallet balance, compact funding controls, collapsed phone budget editor, and three-way-buy rows. The preview itself remains a mock and is not routed or shipped as product code. - Real behavior wins where the static mock is illustrative: lead search/stage/call/export, Territory bid/cap/remove/search, refund actions, Stripe Checkout/card management, budget editing, Package status/payment recovery, invoices, and desktop layouts remain usable. Runtime balances, rows, prices, position, readiness, and recovery state come from the existing APIs; no example value was copied into product state. The only visible copy additions are
Balance,Available balance,Call, andEdit budget; no pricing, Package, Stripe, wallet, D1, or worker contract changed. - Focused proof passed 7 files / 55 tests plus TypeScript and diff hygiene. The full root gate then passed 85 files / 785 tests, TypeScript, production Vite build, transparent-brand audit, and production controls 21/21 (123 assertions); docs rebuilt 10 internal + 2 client docs + index. Authenticated local-Worker browser proof at exact 320x844, 390x844, and 1440x900 found
scrollWidth === innerWidthon My Leads, Territories, Transactions, and Billing. The one 320px My Leads filter item outside the viewport is contained inside the intentional horizontal chip rail; the document itself does not overflow. Fresh 390px captures are indocs/shots/*pr270-port-local-20260722.png. The repository workflow-only polish runner was attempted and stopped on its existing Bun 1.3.0 top-level-return syntax error; explicit make-it-sexy review plus independent reuse, quality, and efficiency reviews found and closed desktop budget access, mobile Package recovery, search preservation, accessible call names, duplicate ledger dividers, and brittle selector issues.
Next up: finish full verification and exact-head review, open one ready PR with killerabbasi requested, merge after QA, mint a fresh exact-merge staging migration receipt, deploy protected staging, rerun hosted 320/390/desktop acceptance, and send Zak the staging link for his physical-iPhone pass. Production remains a separate evidence-bound decision.
2026-07-22 — Zak photo-reference mobile hierarchy pass (local candidate; not deployed)
- Started from exact main
75ed453d27b00e0f9fd7c87fb8de228e3db29714in an isolated worktree and treated Zak's four physical-iPhone photos as temporary layout authority while final mocks remain pending. My Leads now restores the phone title/count/export hierarchy and uses named card fields; Territories uses an inline Add action and compact county/status/bid/cap/remove card; Transactions reads as a dense two-column ledger; Payment & Budget leads with the real available balance and condenses the existing fund, budget, and three-way-buy controls. The three ways to buy remain expanded by default on phones while Invoices stays collapsible. The shared phone shell is opaque and compact, retains the avatar/account disclosure, five-tab rail, and all existing routes, and no longer lets the floating support launcher cover phone actions. - This pass changes no Stripe, wallet, budget, pricing, Package, lead-stage, Territory mutation, D1, or desktop contract. It deliberately does not relabel historical Territory counters as current-week facts. The only buyer-facing copy addition is the mobile label
Available balance; My Leads title/count/export were restored, and Add funds visually condenses to+only at 360px and below while retaining its accessible name and route. - Focused UI verification passed 7 files / 53 tests; the complete root
bun run verifygate exited 0 (TypeScript, full app tests, production Vite build, transparent-brand audit, and production controls), docs rebuilt 10 internal + 2 client docs + index, and diff hygiene passed. Authenticated local-Worker Chrome proof at 320×844, 390×844, and 1440×900 found zero document overflow on My Leads, Territories, Transactions, and Billing; all visible primary phone controls in the checked selector set were at least 44px; console errors were empty; and all application fetches returned 200. Four 390px viewport captures plus a full-page Billing capture are recorded indocs/shots/; the amended Billing readback provesLead packageopen,Invoicesclosed, andThree ways to buyrendered. The repository workflow-only polish runner was attempted and failed before execution on its existing Bun 1.3.0 top-level-return syntax error; three explicit reuse/quality/efficiency reviews plus the manual token, hierarchy, motion, and simplification pass were completed instead. This is local browser/source evidence, not hosted staging or physical-iPhone acceptance.
Next up: obtain independent exact-head review and hosted CI, send Zak the copy delta, then normally merge and deploy the resulting exact main to protected staging for authenticated phone/desktop QA. Final mocks may supersede spacing/tokens without changing these preserved behavior contracts.
2026-07-21 — Territory phone-card spend-cell specificity correction (local follow-up)
- Browser QA of exact protected-staging merge
bc93cbaa0c4da3b5469eaa7ea242aab70ccdbf2ffound the phone card's intended hidden desktop-onlySpent · 7 dayscell still visible as a stranded, unlabeled$0. The generic mobile.terr-tab td { display:block!important }rule has higher specificity than.terr-week-cell { display:none!important }; the follow-up scopes the hide rule as.terr-tab .terr-week-celland locks that selector in the existing source regression. - The correction changes no copy, desktop presentation, pricing, Territory mutation, D1, or Stripe behavior. Focused Territory verification passed 1 file / 12 tests and TypeScript passed. The default-parallel full app run hit seven unrelated resource-contention timeouts at 778/785; every affected file passed immediately with one worker (5 files / 54 tests). Production build, brand audit, production controls 21/21 (123 assertions), docs build (10 internal + 2 client docs + index), and diff hygiene passed.
Next up: independently review and normally merge this two-line specificity correction, redeploy exact main to protected staging, then repeat real-width card/navigation QA before requesting Zak's physical-iPhone retest.
2026-07-21 — Zak physical-iPhone navigation and Territory card follow-up (local; not deployed)
- Started from exact main
061380b272bd2d85859e7aaf07e6ff85839fed4din the isolatedcodex/zak-mobile-feedback-20260721worktree. The phone avatar menu now exposes My Leads, Transactions, and Refunds before its existing Settings/Sign out controls, but only below 641px; desktop rail and account menu behavior stay unchanged. - Phone Territory rows now use a compact named-grid card: county/state with status and server position, labeled 44px bid and weekly-cap controls, and a restrained text Remove action. The prior desktop spend cell remains unchanged, the card never renders a raw territory ID, and search copy is now
County or state. Removal now requires a named confirmation before the existing API call; no API, D1, pricing, bid, or cap semantics changed. - Focused
TopNav/Territoriesverification passed 2 files / 15 tests with TypeScript. Vite build, brand audit, production controls 21/21 (123 assertions), docs build (10 internal + 2 client docs + index), andgit diff --checkpassed. Two default-parallel full-suite reruns reached 784/785 and 783/785 before unrelated resource-contention timeouts; every named timeout passes in isolation. The required post-change-polish runner remains blocked before execution by Bun 1.3.0's existing top-level-return syntax error; a manual v60 token, motion/reduced-motion, and simplification pass was completed instead. This is local source evidence only, not hosted CI, staging, or a physical-iPhone retest.
Next up: independently review this exact local commit, then merge/stage normally before requesting a fresh physical-iPhone/Safari follow-up. No provider, D1, Stripe, deployment, push, PR, merge, or message action occurred.
2026-07-21 — PR #274/#275 exact-main protected-staging release evidence (staging; not production)
- PR #274 merged normally as
7dda4f7efcdcd7ab6fbf07193cc5eec7fabdb433; PR #275 then merged normally as currentmainfe6ff71e26f915167db6ba4c89440a53e2af481e. Independent exact reviews returned READY with no P0–P3 findings. Combined deterministic source proof was 85 files / 782 tests, TypeScript, Vite production build, transparent-brand audit, production controls 21/21 (123 assertions), docs clean, andgit diff --check. - Protected staging applied only
0039_package_readiness_v4.sql(migration receipt:/var/folders/q8/6s5j8ycx0m9b7zcgm3l40xkw0000gn/T/soldi-staging-migration-boundary-HcBtMj/migration-fe6ff71e26f915167db6ba4c89440a53e2af481e.json) and deployed the exact SHA (deployment receipt:/var/folders/q8/6s5j8ycx0m9b7zcgm3l40xkw0000gn/T/soldi-staging-deployment-receipt-1ovY6U/deploy-fe6ff71e26f915167db6ba4c89440a53e2af481e.json). Provider readback binds deployment25bdefe6-0edd-41e7-98d3-08b6b0693a42, Workercb6c6d2d-093f-4ec6-8267-e4d1d289c084, tagv60-fe6ff71e26f9-9980e7a81e06-c2ca28e8707c4cbbb0c292b0634da231, and assets SHA-2568cb85a53f3c80c25ed8c3d61e463efb11c6ace59bcf23283d91285fade678dcd. Health was exact five times; served staging Stripe sandbox identity was exactacct_1TtjDjPuLV917S5Kin test mode. - The first real v4 scheduler decision
package-reserve-v4:staging:2026-06-22:2026-07-22recorded demand/committed0, supply5,ready=1,reserve_satisfied. It was scheduler-produced: no manual readiness row and no wallet, Package, or lead mutation occurred. - Authenticated fairhomecash Chrome QA covered all six v60 buyer screens—Market, My Leads, Territories, Transactions/Activity, Billing, and Settings—at
1440x900,390x844, and320x844: no document overflow; primary phone controls at least 44px; five 49px bottom tabs; correct price colors; desktop bottom navigation hidden; and the Package panel saysPackage ready to start. The 320px My Leads tier row intentionally uses horizontal scrolling (288pxclient,319pxscroll) so Cold remains reachable. Zak received the exact link/SHA/version and copy boundary and was asked for a physical-iPhone pass. - Separate Fair Home Cash Stripe readback found sandbox
acct_1TsllIR34twH5OTZand liveacct_1Tsll8J1YBgaOKuA; both are distinct from staging's older Soldi sandbox. The live account remains onActivate your account/Verify your businessonboarding. No Stripe provider setting changed. Public production health is legacy (/api/v1/health200 without SHA/version;/api/v1/health/stripe404), and the source-only production plan receipt is/var/folders/q8/6s5j8ycx0m9b7zcgm3l40xkw0000gn/T/soldi-production-plan-mi9JZu/production-plan-fe6ff71e26f915167db6ba4c89440a53e2af481e.json(config5a8126684eb8adde212365759da82702ccae75833e6e1693258db0bc7c35cbdc, assets8cb85a53f3c80c25ed8c3d61e463efb11c6ace59bcf23283d91285fade678dcd, diff9d23708444bd0340da9267e7e2ba3a1b428da6c310f442a97b9314421f21a603).
Next up: production remains HOLD pending fresh explicitly authorized production-D1 copy rehearsal through 0025–0039 plus Time Travel rollback and temporary-D1 deletion; Cameron's legal/business onboarding completion and explicit confirmation that the new FHC organization is canonical before production keys/webhook wiring; exact live Stripe/webhook proof; physical-iPhone acceptance; signed external acceptance; and action-time promotion authorization. Reference-only PR #270 remains unmerged. Ordinary UI defects are fix-forward only.
2026-07-21 — PR #275 exact-head mobile review repair (local; not deployed)
- Terra/high reviewed exact PR #275 head
ef56534e446d4d538afcc535714aec547ec8a1acand found no backend, Stripe, pricing, or Package-semantic delta, but requested two P2 My Leads display corrections: the new mobile seller suffix rendered by default on desktop beside the existing Seller column, and the mobile Price cell'sfont-size:0hid the amount while leaving only the Package badge visible. - The repair makes
.ml-mobile-sellerdesktop-hidden and phone-visible, and renders the compact phone Price cell at 12px. Source assertions lock the desktop-hidden seller contract, visible phone price rule, and absence of the zero-font-size regression. - Focused exact repair proof passed 5 files / 44 tests, TypeScript, and
git diff --check. This is local source evidence; independent exact-head rereview, hosted CI, authenticated staging, and physical-iPhone proof remain separate.
Next up: commit and push the repair, obtain the same reviewer's exact-head rereview and fresh hosted CI, then merge normally if clean.
2026-07-21 — Package v4 merged; mobile fidelity PR candidate ready
- PR #274 passed hosted CI and independent Terra/high exact-head review with no P0–P3 findings, then merged normally as
7dda4f7efcdcd7ab6fbf07193cc5eec7fabdb433(parentsdda7d318682cc0350df0ec555d85b3e3c9ab201dand reviewed headdfb82bdcbfce039bc915d0479bdf0ab1da874f6d). Exact ancestry was verified after fetchingorigin/main. - The mobile branch already descends from the reviewed PR head, so its diff against merged main remains only the two mobile commits plus their additive proof documentation. No reimplementation, squash, or source conflict is required.
Next up: publish the ready mobile PR with killerabbasi requested, run independent exact-head UI review and hosted CI, merge normally, then deploy only the resulting exact main merge SHA to protected staging.
2026-07-21 — Combined Package v4 + Zak mobile fidelity candidate (local; not deployed)
- Rebased the two mobile-fidelity commits onto exact reviewed Package v4 PR #274 head
dfb82bdcbfce039bc915d0479bdf0ab1da874f6d. The resulting exact local head is44ed7c1d8e8ae0f6d4409928577b3d0964446f58; the Package v4 migration/runtime/control history and both mobile commits remain distinct and attributable. - Resolved only the additive
BUILD_LOG.mdrebase conflict by retaining both workstream entries. No worker, migration, Package, Stripe, pricing, or copy semantics changed during the rebase. - Exact combined proof passed the complete deterministic app suite 85 files / 782 tests, TypeScript, Vite production build, transparent brand-asset audit, production controls 21/21 (123 assertions), docs build (10 internal + 2 client docs + index), and
git diff --check. No provider, D1, Stripe, deployment, GitHub mobile PR, funded Package, or message action occurred.
Next up: merge independently reviewed PR #274 after hosted CI, publish this mobile branch as a separate ready PR with Zak requested, then deploy only the final normal-merge main SHA to protected staging for 0039, scheduler-produced v4 readiness, and authenticated desktop/phone QA.
2026-07-21 — Package readiness denominator v4 (local source candidate; not deployed)
- Added forward-only
0039_package_readiness_v4.sql; it creates new v4 decision, state, and activation-reservation tables without copying or mutating the deployed v3 evidence. Package runtime authority, schema checks, billing/renewal reserve predicates, paid-cycle guard, and router eligibility/completion now accept only literalpackage-reserve-v4/scheduled-package-readiness-v4state. - Corrected the supply denominator to only PPC
$250investor candidates. Any missing or unparseable timestamp within that candidate set fails closed in both recomputation and the immediate pre-debit reservation predicate; noncandidate PPC rows remain retained and do not poison supply. SQLite regressions preserve the bad same-window v3 decision while allowing a corrected v4 ready decision, reject cross-environment/v3 reservation authority, and prove five candidates plus six noncandidate PPC rows returns5/reserve_satisfied. - Advanced protected staging and production controller inventory to exactly 39 files, 24 applied, and 15 pending through
0039; hostile partial, advanced, malformed, and action-time authorization gates remain. Focused Package SQLite/scheduler tests pass 5 files / 92 tests; staging control passes 60/60 (237 expectations) and production control 21/21 (123 assertions). The default parallelbun run verifyencountered four asynchronous UI failures/timeouts under resource contention, so it is not recorded as green; the exact committed SHA passed the full app suite serially (85 files / 781 tests) plus TypeScript, Vite production build, brand audit, docs build (10 internal + 2 client docs + index), and diff hygiene. The four affected UI files also pass when rerun in isolation. No provider, D1, deploy, GitHub, message, or Package wallet action occurred.
2026-07-21 — Zak mobile fidelity pass 2 (local source candidate; not deployed)
- Post-commit corrective pass: the first fidelity commit compacted several new phone controls below the locked
44pxhit target. The local follow-up restores 44px minimum width/height for compact-shell balance/Add funds/account controls, Billing Manage cards and referral, My Leads stage/Call/search controls, and Territory top Add, bid/cap, weekly-cap, remove, county/state choice, and search controls. Density remains in typography and gaps, not shrunken touch boxes. Focused source tests passed 4 files / 38 tests; the one root verifier was not rerun after four unrelated UI failures/timeouts under concurrent load (81 files / 773 tests passed, including the repaired suite). This remains local source proof only. - Built directly above exact PR #273 head
57189577e0e2e5c6ad57d54bb0c74b00c032ee8ein an isolated worktree. The app-only pass adds persistent phone tabs for Market, My Leads, Territories, Activity, and Wallet; retains compact real-balance and Add funds header actions; and moves phone referral access into Wallet so it no longer consumes the shared utility row. - Market's canonical tier prices now carry their tier colors ($250 Hot orange, $150 Warm green, $90 Cold amber). My Leads suppresses page-header and desktop-only control overhead on phones, uses a denser row hierarchy, and adds a per-card stage sheet while retaining desktop select controls. Territories no longer displays raw internal IDs and its phone cards/sheet prioritize county/state, bid, cap, market context, and live position. Billing keeps Stripe, custom budget/cap, Package, and invoices intact while removing Manage-cards layout dead space and keeping Add funds primary.
- Focused app UI coverage passed 7 files / 68 tests. Local source captures at 390×844 and 320×844 showed
scrollWidth === viewport, five non-truncated bottom-tab labels with 49px targets, and the tier price colors. Those captures used a local mocked session/feed for geometry only; they are not hosted or payment-flow proof. The post-change polish helper remains syntactically blocked by its existing top-level return error, so the manual token/reduced-motion/simplification pass is recorded inplatform-completion.md.
Next up: complete exact-candidate verification and normal review. Fresh authenticated hosted browser and physical iPhone/Safari acceptance still remain release gates; no provider, Stripe, deployment, merge, or message action occurred.
2026-07-21 — Package fulfillment readiness v3 (local source candidate; not deployed)
- Added forward-only
0038_package_readiness_v3.sql: v2 readiness evidence remains immutable, while v3 decisions, state, and activation reservations are keyed to literalstagingorproduction. Unknown/unset environments fail closed; a production decision cannot consume a staging state or reservation. Billing rechecks v3 readiness immediately before activation writes and wallet debit, and router eligibility/completion joins the current environment only. - Rendered protected staging with exactly one
* * * * *readiness schedule and literalPACKAGE_READINESS_SCHEDULER_ENABLED=true. Production source declares the same variable as literalfalse; this is source capability only, not authorization to activate production Package routing. Do not manually insert a readiness/state row. The next safe step is an authorized staging migration/deploy, inspection of a real v3 decision, then a disposable-account funded Package activation/idempotency/My Leads proof. - Corrected the MVP delivery contract: Package routing and delivery records now use only
in_app, and active/inactive Billing copy says that verified Hot leads land in My Leads. Removed the prior email/webhook/CSV claim; the mobile/leadslabel is now My Leads. No transport/provider was added and no copy claims one exists. - Focused Package/Billing/Router/MobileNav tests passed 6 files / 89 tests; staging controller/migration/authority/demo proof passed 60 tests / 237 expectations; the exact full app gate passed 85 files / 776 tests, TypeScript, Vite, and brand audit. The TopNav test was synchronized to its already-rendered My Leads link. Docs built 10 internal + 2 client docs + index and
git diff --checkpassed. The mandatory UI polish runner remains blocked before execution by its existing top-levelSyntaxError: Illegal return statement; Billing and MobileNav received manual v60-token/responsive/reduced-motion review. No provider, D1, Stripe, deployment, merge, or message occurred. - Integrated above merged V4 main
fbb919b: production control now requires exact0038/ 14-pending inventory and the reviewed one-minute staging schedule. Static staging receipts derive current config/migration/live-readback/provider digests; all pre-existing hostile partial/advanced/malformed inventory and action-time authorization checks remain. Focused production controls pass 21/21 (123 assertions). - Independent exact-head review caught that the shared production one-minute cron would still call the disabled readiness function and write an immutable disabled decision. The fix preserves renewal/allocation recovery on that shared cron but skips readiness recomputation entirely unless the literal environment-aware scheduler flag is enabled; a direct production regression proves no v3 readiness decision/state write SQL is prepared. The repaired exact candidate passes 85 files / 777 tests, TypeScript, Vite, brand audit, production controls 21/21 (123 assertions), docs build, and diff hygiene.
- PR #273 merged normally as exact main
dda7d318and deployed to protected staging through only migration0038; health and Stripe identity bind Worker version11624327-bbdb-45d8-bae2-bccaffdfcede. The first real scheduled decision safely returned not-ready: five valid Hot/PPC investor rows were poisoned by six retained PPC rows at other prices or the retired Agent vertical. The fix-forward source removes that out-of-contract all-PPC poison query, retains strict demand/integer checks, and adds a mixed-PPC SQLite regression (3 files / 41 tests). No staging row was edited or manually inserted and no Package wallet mutation occurred.
Next up: independently review and merge the denominator repair, redeploy exact main, and wait for a safe scheduler-produced decision before the disposable funded Package lifecycle proof. Production remains HOLD until the candidate-bound data-safety and money-path evidence exists.
2026-07-21 — Production action-time authorization V4 (local control-only)
- Current exact base is normal
origin/mainmergebfd335935de789bc7ef9da876443f7801651488b. The former V3 GitHub-review condition was mechanically impossible after that normal merge because GitHub can review a PR head but cannot attach the demanded V3 review to the post-merge candidate SHA. production:promotenow ends with the exact literalSOLDI_PRODUCTION_GO_V4, not pull/review IDs. After every rehearsal, rollback, staging/provider, Stripe exact-once, hosted QA, physical-iPhone, external-acceptance, expected-preflight, and pending-migration receipt has passed closed-schema validation, the controller mints a schema-4 authorization valid at most 15 minutes and no later than the earliest underlying 24-hour evidence expiry. It binds the exact candidate/config/assets/migration and canonical digest of all validated evidence, then validates again inside the maintenance fence before bookmark/migration.- V4 is explicitly an operator action-time confirmation, not an independent cryptographic approval. The fixed-key signed external-acceptance packet, real-production-copy rehearsal + temporary-D1 Time Travel rollback, expected retained-data preflight, maintenance fence, bookmark/migration proof, and no-automatic-restore policy are unchanged.
github-approval.mjsis unreferenced by runtime and retained solely for historical parser coverage. - Independent review held first on a freshness time-of-check/time-of-use gap and current-document V3 contradictions, then held the first repair because a manually extended local
expiresAtwas not compared with the bound evidence clock. Validation now independently requires bothnow < evidenceExpiresAtandauthorization.expiresAt <= evidenceExpiresAt, so inside-fence revalidation fails before bookmark even if the unsigned operator-local timestamp is altered. Current readiness/Roadmap describe V4 and 13 pending migrations through0037; append-only historical V3 entries remain intact. The final corrected head passes 85 files / 773 tests, TypeScript, Vite, brand audit, and production controls 21/21 (123 assertions); docs build, diff hygiene, and exact-head rereview follow. No Cloudflare, D1, Stripe, GitHub, deployment, account, email, or message action occurred.
Next up: keep production HOLD until fresh exact-candidate staging/provider, Stripe replay, hosted six-screen, physical iPhone, signed external acceptance, and separately authorized real-production-copy rehearsal/rollback evidence exist. Only then may a named operator provide V4 at action time.
2026-07-21 — PR #269 exact-head review repair (local, exact-main candidate)
- Preserved both normal PR #271 buyer-mobile history and PR #269 account-recovery history while moving the three recovery commits onto exact
origin/maina0804f29e81d286bb9e322b18c9420c59e4d226b. No merge, deploy, provider, D1, account, email, or reviewer-state mutation occurred. - Corrected the staging-controller P1:
tools/staging/migrate.mjsnow imports canonicalREQUIRED_SECRET_NAMESfromtools/staging/control.mjs.tools/staging/migrate-input.test.mjsdirectly invokes onlystagingMigrationInput, proves the validated input has the canonical five required secret names and exact 37-file inventory, and cannot reach authority/provider work. - Corrected the visible walkthrough spelling only:
genericly→generically. There is no UI behavior, status, screenshot, or product/runtime copy delta beyond that documentation-only typo. - Stabilized
app/worker/auth-login.test.tsonly: immediate same-usercreateSessionTokencalls could share the same millisecond and therefore produce identical signed payloads/derived CSRF values. The fixture gives the deliberately stale token a+1msissued time and asserts both session and CSRF tokens differ; production auth code and behavior are unchanged. - Exact-main evidence passed: direct migration-input 1/1, staging controller/authority/demo 60/60, recovery/auth/security/client 63/63, production controller 20/20 (112 assertions), docs build 10 internal + 2 client docs + index, and exact root
bun run verify85 files / 773 tests with TypeScript, Vite, brand audit, and production control green.
Next up: independent exact-head review, then separately authorized protected-staging migration/deployment receipts and hosted/browser/physical-iPhone evidence. Production remains HOLD.
2026-07-21 — Zak mobile polish (local, ready for review)
- Exact base is current
origin/main0758d195260f041a59392ea30a193ec985987464; the bounded follow-up changes only buyer-route presentation and focused tests. Nopreviews/, worker, auth/session, provider, D1, staging, or production files changed. - Read PR #270 body and exact preview-only head
a29e9c74d27e8d62a5a8f3e6697d6e9a5e16a8f2read-only as the current phone interaction/layout authority; it is not merged and its mock file is untouched. - Open Market now follows its dense phone-ledger direction: tier dot, city, readable tier/situation/county/freshness metadata, price, and independently visible
44pxBuy target in a compact row. - My Leads now follows its no-filter-wall direction: Tier remains a one-handed rail, while one Stage control opens the responsive drawer as a phone bottom sheet and Package stays adjacent. The former per-row phone stage-chip rail is replaced by one full-width
44pxnative selector, so Under Contract/Closed/Dead cannot be clipped inside a390pxviewport. Desktop keeps the pre-existing status/package controls; behavior, counts, Package gating, and stage filtering are unchanged. - Transactions keeps the existing ledger hierarchy but uses a narrower phone grid,
44pxdate-range/Add-funds controls, and44pxinline refund/resend actions. Territory phone rows reserve a full bid row and Remove clearance at320px; the county-picker result card and bottom-sheet action area are tighter without changing the county-only or3 / 5 / 10contracts. - Payment & Budget now keeps the three deposit choices in one touch-safe phone row above the full-width Add funds target, places custom budget, reset day, and Save in one reachable phone row, and collapses its real Package and Invoice sections behind
52pxphone summaries. That turns the initial wallet/budget transaction path into the first screen instead of the staged base's2570pxpage, without removing any control or changing integer-cents math, deposit bonuses, Stripe Checkout/portal wiring, or44pxtransaction targets. - Correction to that phone-disclosure description: the first candidate only synchronized the disclosures when entering desktop, so a portrait → landscape → portrait transition could leave both open.
BillingDisclosurenow derives both disclosures from the current media-query result on every breakpoint event; a deterministic matchMedia regression covers mobile → desktop → mobile and verifies an in-place phone toggle still works. No Package, Invoice, Stripe, cents, backend, token, or visible-copy contract changed. - Follow-up evidence supersedes the preceding 82 / 748 count for this branch: focused Billing passed 2 files / 17 tests, the five changed buyer routes passed 5 files / 60 tests, and exact root
bun run verifypassed 82 files / 749 tests, TypeScript, Vite buildindex-C9Id425m.js, the brand audit, and production controls 17 / 100. No deploy, provider/D1/Stripe action, merge, or message occurred. - Fresh authenticated staging QA at exact base
0758d19supplied two acceptance targets: clipped My Leads stage chips at390x844and a2570pxBilling page. This candidate addresses both in source, but no current-candidate authenticated browser session/screenshot exists. The direct current-source probe was discarded after provinglocalhost:5173served another worktree; physical iPhone/Safari acceptance remains open. - The exact parallel root
bun run verifycompleted but hit six unrelated UI loading timeouts (77/82 files, 742/748 tests). A retained sequential session then passed the complete app suite 82/82 files, 748/748 tests, followed by TypeScript, Vite build, brand audit, and root production controls 17/17. The mandated post-change workflow remains syntactically blocked by its existing top-level return; manual make-it-sexy/make-it-simpler review retained existing v60 tokens, reduced-motion behavior, and minimal page-scoped geometry. - Mobile-only visible copy delta: Stage is appended to the selected stage control and sheet rows; Tier, Status, and Delivery labels are no longer visually shown on phone; Payment & Budget adds
Lead package/Compare ways to buy or manage your planandInvoices/Downloads and wallet activityas collapsed phone summaries. It also adds the accessible group nameDeposit amount. No product claim, price, tier, situation, legacy-surface, or desktop-visible v60 copy changed. Intentional #270 deviations: no five-tab mock navigation because the real six-route app includes Settings and current route/accessibility behavior; no fake Wallet/Territory data or altered Stripe/money paths; and real Package/Invoice controls are collapsed on phone, not omitted to force the mock's static zero-scroll claim. No merge, deploy, or message occurred.
Next up: PR #271 is ready with killerabbasi requested; after its normal merge, bind the merge SHA to fresh protected-staging authenticated browser screenshots and a physical iPhone/Safari retest before advancing any release gate.
2026-07-21 — Account recovery (local, ready for review)
- Built from exact pre-merge
origin/main0758d195260f041a59392ea30a193ec985987464without querying, resetting, merging, or deleting any real account, password, session, or D1 data. This source-only candidate adds actual account recovery rather than the prior support-only placeholder. - The Worker generates a random 256-bit capability, stores only its SHA-256 digest for 30 minutes, consumes it atomically, and updates
users.password_changed_aton success so all earlier sessions are invalid. A reset does not create a replacement login session. - Valid recovery requests return the same immediate generic
202before account lookup, token work, Resend I/O, or cleanup runs inexecutionCtx.waitUntil; email/IP limits use HMAC-derived scopes. Missing provider configuration creates no token, provider failure deletes the issued token, and logs contain only a fixed failure label plus HTTP status. - Resend delivery uses
RESEND_API_KEYplus separateRESEND_PASSWORD_RESET_FROM=Soldi <account@notify.soldi.cc>bindings. The possibly Fair Home Cash-brandedRESEND_DEFAULT_FROMis deliberately unused. The local source run sent no email and did not read or alter provider state. - Added
/forgot-passwordand fragment-token/reset-passwordv60 pages. Both guarded client mutations preflight same-origin/auth/mebefore POST, preserving the existing origin/CSRF protection through the Safari missing-companion race. - Direct recovery tests cover hash-only storage, replay, expiry, enumeration, rate limits, missing provider, Resend success/failure, delivery cleanup, redacted logs, immediate public response/background completion, and client preflight ordering. The compact source capture proves layout/copy only, not hosted delivery.
- The mandated post-change polish runner remains blocked by its existing top-level
SyntaxError: Illegal return statement; recovery UI was manually reviewed for v60 tokens and reduced-motion behavior. No deploy or provider/data mutation occurred.
Next up: rebase this candidate onto the current normal main merge, then under separate explicit deployment authorization set RESEND_API_KEY for both Worker environments and perform the staging-only delivered-email, replay/expiry, session-revocation, and physical Safari acceptance.
2026-07-21 — Buyer mobile-responsive remediation (local, ready for review)
- Rebased the isolated buyer-UI branch onto the normal auth-merged
mainSHA6e27a0480746a013621ddf61b280d45c759c64b9; no auth, session, login, worker, provider, staging, or production files changed in this follow-up. - The evidence-backed changes keep the mobile utility/referral row within
320pxwithout a help-launcher collision, make Add funds and mobile drawer rows at least44px, make Territory package choices and weekly-cap controls at least44px, and contain wide Billing invoice tables in their own horizontal scroll region rather than clipping the document. - Rebased changed-surface Vitest passed (8 files / 50 tests locally; an independent root rerun reported 8 files / 46 tests for its selected surface). A prior idle full
bun run verifypassed: 82 app files / 747 tests, TypeScript, production Vite build, brand audit, production controls 17 / 100, and repository checks. A later concurrent root full run reached 79/82 files / 744/747 tests before three unrelated five-second UI-test timeouts (BuyerScreens preference prefill, Territory modal minimum bid, Billing Package activation); without changing timeouts, isolated recovery passed those exact files 3 / 28. Treat that later run as load-induced and do not substitute it for the already-valid full proof. The configured post-change polish workflow could not run because.claude/workflows/post-change-polish.jsthrows top-levelSyntaxError: Illegal return statement; independent make-it-sexy review found no token/copy drift and make-it-simpler found the patch minimal. - Current-source local Chrome checks at exact
390x844and320x844report no document overflow (scrollWidth === viewport), a44pxhelp launcher, and an in-flow referral/help utility row. Console output was empty and all loaded application requests were successful; the aborted initial/auth/merequest was superseded by a200retry. Local existing-account authentication remains blocked by the app's intentional CSRF-origin policy, so these are source-shell checks rather than authenticated buyer-route acceptance. - Product copy delta: none. The prior protected-staging/mobile capture and
998186ereceipts are historical after both auth and this UI change; no deck screenshot is presented as current authenticated-candidate proof. No merge or deploy occurred.
Next up: merge the reviewed PR normally, bind its exact merge SHA to fresh protected-staging authenticated six-screen browser checks, then repeat the complete physical iPhone/Safari path (dynamic toolbar, keyboard, safe area, existing-account login, funding/budget, Territory modal/drawer, and invoice table) before advancing any release gate.
2026-07-21 — Existing-account login repair (local, ready for review)
- Zak's physical-iPhone report found a distinct gap from the fresh-signup path: his existing staging account correctly returns
email_takenon registration, but its login reaches the generic protected failure. No real account, password, session, or D1 row was inspected, reset, or deleted. - The repair preserves exact-origin and session-bound login CSRF. Before the guarded login POST, the SPA makes same-origin
GET /auth/me; a valid oldsoldi_sessioncan thereby receive a replacement readablesoldi_csrfcompanion instead of weakening the worker guard. Direct route coverage first proves a valid old session plus stale CSRF remains403 csrf_token_rejected, then proves/auth/merefresh and authenticated login succeeds. verifyPasswordnow safely rejects malformed/partial PBKDF2 fields (invalid base64, unexpected lengths, or unsafe iteration count) asfalse. The login route therefore returns the existing generic401 invalid_credentialsresponse, emits no auth cookies, and never exposes parser/WebCrypto failures or account-state detail.- Source verification passed focused auth/session/security 4 files / 44 tests and the full app Vitest suite in four executable shards: 82 files / 746 tests. TypeScript, production Vite build, brand audit, production-control 17 tests / 100 assertions, docs build (10 internal + 2 client docs + index), readiness-JSON parsing, and
git diff --checkalso passed. Expected forced rollback/compensation and jsdom diagnostics remain test fixtures, not failures. - Historical
008119d/staging records are now explicit: they prove the fresh-account/browser path and the now-closed replay retry (evt_1TvN7mPuLV917S5KpzdFdzuV→200, one event/claim/immutable ledger row; receipt3a8c11cfc40d35733bea6d8c841e25eb41fdb2a8714e4db04c621475174b57fd) but cannot authorize this next runtime merge. Zak's approval is good to go; a later controller must bind it mechanically to new candidate evidence. The readiness JSON has no current candidate. Product UI copy delta: none; walkthrough and readiness wording now disclose the existing-account gap and fresh proof requirement. No deploy, provider, or staging mutation occurred.
Next up: merge the reviewed PR normally, then make its exact merge SHA the new candidate; run protected-staging migration/deploy and existing-account browser/iPhone proof before treating authentication or any prior staging receipt as current.
2026-07-20 — Fresh-signup repair staged and hosted new-account QA
- PR #264 merged normally as exact two-parent
mainSHA008119d88aee92bcd4db6be19c1275ff1ece54c5after green GitHub CI and final Terra/high READY review. The source gate remained 81 files / 743 tests, TypeScript, Vite, brand audit, production controls 17 / 100, docs build, and diff hygiene. - Cloudflare authority initially failed closed at
staging_authority_routes_failed. The already-persistedmaster-camo-dev-workers-tokenwas the actual caller; it received only asoldi.ccpolicy for Workers Routes, DNS, and Zone read/write. No secret was copied, rotated, printed, or written to a temporary file. bun run staging:migrateminted a retained-data-safe no-op receipt through0036with no pending/applied migrations and no D1 mutation. Receipt-boundbun run staging:deploythen published deployment9e784f30-33a7-4223-89aa-debe717b8682, Worker versionfad2c237-5465-496e-ab67-0d1b6b0db92a, tagv60-008119d88aee-a87e093d2375-3f2570bcf95b4d898e758e4cf50ceb45, and assets SHA-256bd215b5b9c8a3621444bf0ba46f0be44e8d480ddbfd57b991a19ab326637240eatstaging.soldi.cc.- Connected FHC Chrome QA signed out of the prior seeded account and created a unique staging-only user without
?demo=1. Registration survived reload; all six setup steps plus final completion saved; Settings returned the new identity; Refunds rendered the honest no-requests state; and Add Funds created a$1,000Checkout on exact sandbox accountacct_1TtjDjPuLV917S5K. - The authorized Stripe test card completed that Checkout. The signed webhook path credited the wallet from
50,000to150,000cents; D1 records oneprocessed_stripe_eventsrow, onestripe_economic_claimsrow, and one immutablestripe_verified_fundingledger entry for100,000purchased cents and zero promotional cents. Explicit provider-event resend is still open because the locally authenticated Stripe CLI is expired and the connected dashboard session cannot accessacct_1Ttj…; no acceptance receipt claims the replay check yet. - Exact
390x844Billing, Settings, and Refunds checks each reportedscrollWidth === clientWidth === 390and zero application console errors. Billing's repaired layout was visually inspected. This is hosted browser proof, not a physical iPhone/Safari receipt. - Exact-candidate production planning also completed without remote mutation: config SHA-256
47f0cb4d90cb5b3790bf2abe03374ce0deb2788ec94ffc598874e2387ee97eba, assets SHA-256bd215b5b9c8a3621444bf0ba46f0be44e8d480ddbfd57b991a19ab326637240e, and redacted-diff SHA-256095ea307e28b66f3b2c78e6e7f4b87e0e5f808b2570106dc45b1b5e41ed9ccc7. - Public copy delta: NONE. Production remains HOLD for explicit Stripe idempotency replay, real-production-copy migration rehearsal and tested rollback, Zak's exact-iOS physical retest, signed external acceptance, retained-data comparison, GitHub V3 approval, and
SOLDI_PRODUCTION_GO_V3.
Next up: Zak repeats the brand-new-account path on his physical iPhone and reports exact iOS plus checklist results. In parallel, perform a controlled resend of the already-processed signed Stripe event from the correct sandbox account, then run the separately authorized production export → temporary-D1 create/import/migrate/Time-Travel restore/verify/delete rehearsal rather than stopping work on those independent gates.
2026-07-20 — Physical-iPhone fresh-signup acceptance failed; production remains held
- Zak's later iPhone 15 test supersedes the earlier positive 390px report below. He registered a brand-new personal account rather than using the seeded demo flow; setup-quiz save, Add funds, refund/status loading, and Settings data failed on iOS Safari.
- The demo-account and automated responsive passes remain useful UI evidence but do not prove registration cookie persistence, new-account provisioning, zero-row states, or authenticated mutations after a fresh signup. Physical-iPhone and external acceptance are open/failed, not cleared.
- Repair is isolated on branch
codex/fresh-signup-ios-fix-20260720from documentation-only mainf72036de31722ff6d10022073666534fed18f836. Protected staging still serves application SHA6a69948a28fec11e6369bda4d60274fa8c0976a1; production was not promoted. - The repair changes production cookies from
SameSite=None; Secureto first-partySameSite=Lax; Secure, requires login/registration to confirm cookie-backed/auth/meserver truth before exposing authenticated UI, makes that response explicitly private/no-store, and fences bootstrap/refresh/logout/unmount races. New Vitest coverage exercises fresh registration, stale bootstrap, logout authority, and unmount cleanup. - The new-account database transaction was already atomic; no seed or synthetic empty-state workaround was added. The shared failure shape was the browser session handoff, which the seeded demo path could not expose.
- Three independent Terra/high tmx review lanes checked correctness, reuse, behavioral UI polish, and simplification. The final exact-diff rereview returned READY with focused auth/session proof 44 / 44; public-copy delta is none.
- Frozen install and the final release gate passed: TypeScript, production Vite build, brand audit, 81 app test files / 743 tests, production controls 17 tests / 100 assertions, recursive docs build 10 internal + 2 client docs + index, readiness-JSON parse, and diff hygiene.
- Zak was texted at
+17739974600only, told that the prior acceptance interpretation was withdrawn, and asked for the exact iOS version. He will receive a new exact-SHA/version staging link only after the fresh-account repair and hosted QA are complete.
Next up: land the reviewed repair through a ready PR, deploy the exact normal merge to protected staging, run a brand-new-account hosted journey, and require another brand-new iPhone signup pass before reopening external acceptance or V3 promotion sequencing. The Stripe provider receipt and real-production-copy rehearsal/rollback remain separate exact-candidate gates.
2026-07-20 — Zak physical-iPhone acceptance reconciled to exact current staging
- Fresh fetch proved clean exact
origin/main6a69948a28fec11e6369bda4d60274fa8c0976a1. Livestaging.soldi.cchealth returns that exact SHA and Worker version91cb1189-bb6c-432c-938a-4c2624f347dd; Stripe health returns test mode and sandbox accountacct_1TtjDjPuLV917S5K. - The current protected deployment is
e29aa900-9aae-4021-b123-2abcf2600522with assets SHA-2564528644d752255131db2796138209f35a5162d46d639af371c7c1b2b2e11669f. The receipt-bound staging migration remained a no-op through0036; no staging schema/data mutation occurred in this reconciliation. - Zak reported a clean physical-iPhone 390px pass for the six screens, test purchase, lead drawer, and tap-to-call. This records stakeholder visual/interaction acceptance from his side. The schema-1 gate remains open until he supplies the exact approved iPhone model, exact iOS version, and explicit all-pass confirmation for
login,wallet-funding,market-purchase,territory-package-routing,payment-budget, andsettings, and the closed content-bound device-session artifact/receipt is generated and validated. - Zak's statement that external acceptance is clear "from my side" is not substituted for the source-required fixed-key schema-3 Ed25519 attestation. He committed to paste
SOLDI_PRODUCTION_GO_V3same-day after receiving the exact-serving-SHA production-go packet. - The authenticated
fairhomecash.comChrome profile is prepared at the exact$1,000staging sandbox funding action. No Checkout session, card submission, wallet credit, or provider mutation has occurred in this reconciliation. - Canonical readiness, JSON state, roadmap, walkthrough, and the living implementation note now name
6a69948a…/e29aa900…/91cb1189…rather than stale candidate identifiers. Production remains HOLD. - Verification passed: frozen install unchanged; TypeScript; Vite production build; brand audit; 80 app test files / 739 tests; production controls 17 tests / 100 assertions; recursive docs build 10 internal + 2 client docs + index; JSON parse and
git diff --check.
Next up: after owner action-time confirmation, complete the Stripe Checkout/signed-webhook/typed-ledger/idempotency receipt. Separately authorize the production D1 export plus disposable D1 create/import/migrate/restore/delete rehearsal, then finish the physical/external receipts and send Zak the bound V3 packet.
2026-07-19 — Mobile Billing merged and live on protected staging
- PR #261 passed GitHub CI with Zak requested and merged normally as exact
c579b8181f9fb7defda11e649906aee6925d5f45(parentsa120d715d517343a12c0ffe3da56f6a8036e9eeeand024ff759d1859019d323ef5bf8795193e61d9c03). - The authorized
fairhomecash.comChrome profile rolledcamo-soldi-dns-key; account-owned verification and fixed-target account/zone/routes/domain/D1 preflight passed. The secret stayed mode 0600 in/private/tmpfor this bounded run and is deleted afterward, per owner direction. bun run staging:migrateproved all 36 migrations through0036_investor_only_market.sqlalready applied, created the required Time Travel bookmark, and reportedplannedPending: [],appliedThisRun: [],noOp: true,remoteMutation: false. Private migration receipt SHA-256:f28f92446dcb39197b2f169294f5f7f619803b342380d77c6315c6d76743c091.- Receipt-bound
bun run staging:deploycreated deployment97388909-09ef-4bec-8849-a4f6968734ec, Worker version603962af-92a0-4f83-9394-920c989eed5a, version tagv60-c579b8181f9f-3dedd61b1353-0915d45499f14705b1cce745601e13dd, and assets SHA-2564528644d752255131db2796138209f35a5162d46d639af371c7c1b2b2e11669f. Deployment receipt SHA-256:7c6113f4040f0c94dd9ba5c1218800462d370f87ef5e5ce5442ff01099945ff5. - Staging health binds exact SHA/version/environment. Stripe health binds the same SHA/version, test mode, and account
acct_1TtjDjPuLV917S5K. - Authenticated Chrome and independent Terra/high both returned READY at exact
390x844and375x812: no horizontal overflow, interactive overlap, undersized required control, console error, or failed application request. Package selection enabled Add funds; a budget preset updated the editor; no financial/card/budget submission occurred. Screenshot:/private/tmp/soldi-staging-billing-390x844-c579b818.png. docs.soldi.ccdeployed as version9d8ceab0-3cde-4f94-8de2-7aa57a687cea; hosted screenshot bytes match the exact local artifact. Visible public-copy delta is none; accessibility-copy delta remains the current-section announcement.- Production runtime was not promoted. UI-bug tolerance does not waive the real-production-copy rehearsal, tested rollback, hosted Stripe ledger journey, physical-iPhone, external acceptance, retained-data comparison, Zak V3 approval, or
SOLDI_PRODUCTION_GO_V3gates.
Next up: merge this receipt correction, redeploy docs, then execute the production-copy rehearsal/rollback and physical-iPhone evidence chain before the V3 production decision.
2026-07-19 — Mobile Billing overlap and clipping repair (local candidate)
- An owner-supplied
390x844staging screenshot falsified the prior mobile pass: clean document width did not detect the fixed support launcher covering the$20,000budget preset, truncatedPayment & Budgetroute context, or cramped desktop-shaped funding/budget controls. - The bounded repair starts from clean canonical
origin/maina120d715d517343a12c0ffe3da56f6a8036e9eee. At phone width the redundant current-page Add funds header CTA is hidden, the full active route label fits, funding choices use a balanced two-column/full-width composition, budget presets use three equal 44px targets, the editor becomes two fields plus a full-width Save, and Manage cards clears the control grid. - The closed mobile support launcher is now an in-flow 44px utility-row button instead of a content-obscuring fixed overlay. Opening support still presents the support panel; desktop retains the fixed launcher.
- The reusable UI validator now supports required-count
no-overlap,no-clipped-text, andcenter-hit-targetsassertions and includes both375x812and the exact reported390x844Billing viewports, preventing the earlier vacuous width-only pass. - Focused Vitest is green at 4 files / 23 tests. Local Chrome DevTools proof at both phone sizes recorded
scrollWidth === innerWidth, full untruncated route text, one visible support target, zero support/control intersections, zero blocked Billing target centers, zero clipped named controls, and zero error-console output. Final screenshot:docs/shots/v60-payment-budget-mobile-20260719.png; prior capture preserved underdocs/shots/before/. - Full verification initially exposed an accidental control-test coupling: the checked-in fixed-key Ed25519 signature included the mutable live
app/distdigest, so any valid UI rebuild failed CI despite the operational verifier behaving correctly. The positive signature vector is now immutable, current app assets remain separately bound through the staging deploy test, and the real wrapper rejects an unsigned mutable candidate before any provider call. No verifier override was added andrun.mjscannot import the test-only post-validation orchestration seam. - Final local verification passed TypeScript, Vite production build, brand audit, 80 app test files / 739 tests, production controls 17 tests / 100 assertions, recursive docs build (10 internal + 2 client docs + index), and
git diff --check. Terra/high returned READY for both the final mobile/UI evidence and the production-control decoupling, with no actionable P0–P2 findings. - Visible public-copy delta is none. Accessibility-copy delta: the navigation trigger now announces its current section. No provider, D1, Stripe, staging, production, or messaging mutation occurred in this local slice.
Next up: complete full root/docs verification and independent exact-diff review, then open the ready PR with Zak requested. After normal merge, mint a fresh exact-head staging migration/deploy receipt and repeat authenticated hosted 390x844 proof before any production decision.
2026-07-19 — exact current main live on protected staging
- Freshly fetched
origin/mainand the clean deployment worktree both resolved to exact90d35121e963747383d250bb04393edbb0d0fd07. The fixed-target Cloudflare credential passed exact account authority after rotation; no secret was printed or committed. bun run staging:migrateproved all migrations through0036_investor_only_market.sqlalready applied onsoldi-staging, retained scalars unchanged,plannedPending: [],appliedThisRun: [],noOp: true, and no D1 schema/data mutation. The controller still created its required Time Travel safety bookmark. Its private receipt SHA-256 is21e308b50d8497b5f16d320b79f17958b1e3f478f30b56470c07c8a9d34d5f4f.- Receipt-bound
bun run staging:deploycreated deploymenta35ff8a6-ac73-42fc-a531-8a32fc02cd9d, Worker versionfc7ac530-7269-4b00-a2c6-099c20625002, release tagv60-90d35121e963-4a71ef193c13-0e4e4b4db5b846cdabbd3fe0e30d53a4, and assets SHA-256f56c593c631e603fea9260cab594b5f51b4c39330287705d73f669441141dd90. Deployment receipt SHA-256 is055f5a882bb5da54a9f799c819753b44a7c3626c81b06264a724eb77c3736157. - Staging health binds the exact environment/SHA/version. Stripe health binds the same SHA/version, test mode, and Soldi sandbox account
acct_1TtjDjPuLV917S5K. The demo-seed dry-run refuseddemo_seed_fixture_has_economic_history; no fixture apply/cleanup followed. - Independent Terra/high Chrome DevTools QA saved exact
1440x900and390x844staging/production captures. Both origins passed Soldi branding, Open Market, removed-cruft, and page-level overflow checks. Staging unauthenticated/marketresolves to/; production mobile retains contained horizontal scrollers without document overflow. Receipt:/tmp/soldi-tmx-hosted-visual-qa-20260719.md. - Root verification passed 81 files / 740 tests, TypeScript, Vite production build, brand audit, and production controls 15 tests / 120 assertions. Public-copy delta is none.
- Production runtime was not promoted. The already-approved static brand release remains healthy at
app.soldi.cc; full runtime stays HOLD for the real-production-copy rehearsal, tested Time Travel rollback, authenticated Stripe and hosted journey proof, physical iPhone, external acceptance, retained-data comparison, Zak V3 approval, andSOLDI_PRODUCTION_GO_V3.
Next up: merge this receipt documentation with Zak requested, deploy docs, then complete the remaining production V3 evidence without the generic app deploy path. Persist the rotated Cloudflare token into its approved 1Password item and remove the temporary protected copy after readback.
2026-07-19 — hostile staging migration-controller remediation (source-only)
- The fixed external-acceptance verifier was rotated to key ID
soldi-production-external-acceptance-v2after the prior temporary private key proved unavailable. A deterministic schema-3 fixture now uses a static signature verified by the fixed checked-in public key; executable validation accepts no verifier-key override. The matching private half is mode 0600 outside the repository and must be transferred to an approved 1Password item, read back, and removed from temporary storage before any real acceptance or V3 request. Until then production remains HOLD. - The final hostile rereviews found the installed-toolchain escape in both
.bin/wranglerconsumers: each was hashed/executed without proving its symlink target remained in the frozen snapshot. Migration and deploy now recursively validate the installed tree while allowing only contained symlinks, resolve Wrangler to a regular executable inside the snapshot, and reject launcher or dependency escapes before bookmark, D1 readback/mutation, or upload. The active production runbook now names the required v2 acceptance key and its custody HOLD; the CLI emits unsigned canonical bytes without embedding private-key operating instructions. - Completed the uncommitted controller remediation without changing application/UI/public copy.
staging:deployvalidates local evidence, runs fixed-target authority preflight before snapshot/install/build, then obtains fresh fixed-target D1 migration inventory plus retained-scalar readback immediately before upload. The live readback is the deploy-time safety authority; the private migration receipt SHA-256 is an audit binding, not provider attestation. - Schema-3 deployment evidence now closes and recursively canonical-JSON hashes
migrationReceiptSha256andmigrationLiveReadbackSha256; both feed the provider release digest, so stale/forged receipt identity or altered live response hashes/semantic values fail closed. Extracted Git source is fenced before install andapp/distafter build, while valid installed-dependency symlinks are deliberately not rejected by a post-install whole-snapshot walk. - Migration preparation validates prospective success before cleanup, then removes and verifies the disposable snapshot before it writes or exposes success. Forced cleanup failure yields only a secret-free
cleanup-failedfailure receipt and no success callback. Local negative tests cover preflight order, receipt/live-D1 drift, digest alteration, source/asset symlinks, installed-dependency symlink tolerance, and cleanup failure. - Validation passed:
bun run test:staging58 tests / 230 assertions,bun run test:production-control15 tests / 120 assertions, andbun run verify81 app test files / 740 tests plus the same production-control suite;bun run build:docsproduced 10 internal + 2 client docs + index.git diff --checkpassed. The scoped secret-shape scan found only deliberately rejected fixture strings, never credential material. - This is local source/test proof only: no Cloudflare/provider, D1, migration, staging deployment, hosted acceptance, production action, commit, push, PR, or merge occurred. Public-copy delta is none; production remains HOLD.
Next up: retain this uncommitted exact diff for independent review, then obtain separately authorized final-candidate provider/readback/hosted evidence.
2026-07-19 — final social-brand refresh combined with release controls (source-only)
- Verified the downloaded transparent logo byte-matches canonical
app/public/brand/soldi-logo.pngat SHA-25630adbc8f75f5bf1377c3f7b1714be1ae505a9d43dc3b9113ff92c805f31bd630; the corrected favicon ZIP-derived ICO/PNG/Apple/PWA family and all app logo paths are unchanged. - Used the four new owner references to generate four text-free background directions, selected the neutral dark marketplace/grid/house signal, and produced visually inspected opaque 1200x630 and 1200x1200 finals. The exact transparent wordmark and existing
Exclusive Seller Lead Marketplacedescriptor were overlaid deterministically, so public-copy delta is none. - Added
app/brand-source/social/as immutable source authority.brand:generatebyte-copies approved composites into public deploy paths instead of re-rendering with machine-specific fonts; the brand audit locks four source hashes, source/deploy equality, dimensions/opacity, metadata order, and?v=20260719-2. Raw source plates remain outsidedist. - Merged source-only production evidence hardening
f06959de58f39aadbd0fda7bfb22c4fe84b68170above PR #253's merged-main authority4b541310b178845af9a62b27b02d1b9521dca037, creating one combined review branch. Full root verification passes 81 files / 740 tests, TypeScript, Vite production build, brand audit, and production control 12 tests / 60 assertions; staging control passes 12 tests / 51 assertions and docs build produces 10 internal + 2 client docs + index. - No TSX/UI layout changed, so the mandatory UI polish workflow is not applicable. The walkthrough decisions are updated without recapturing app screenshots because the rendered application screens are byte-unchanged. No provider, D1, Stripe, staging, crawler-cache, or production mutation occurred.
Next up: independent exact-head source/browser review, one ready PR with Zak requested, then normal merge. Only that future merge SHA may receive fresh rehearsal/rollback, protected-staging, Stripe, hosted/crawler, physical-iPhone, external V3, and production receipts; production remains HOLD.
2026-07-19 — P1 final production-control evidence hardening (source-only)
- Hardened
production:promoteto require, before snapshot, fence, bookmark, migration, or production provider work, a schema-3 protected-staging deployment receipt plus separate exact-account Stripe and hosted-QA receipts. The staging validator/revalidator is reused rather than copied: it bindssoldi-staging,staging.soldi.cc, isolated D1, exact candidate tree/assets/migrations, version/deployment, required secret names, zero schedules, disabled workers.dev/previews, and exact custom domain. - Stripe evidence is no longer a generic pass boolean: it requires sandbox
acct_1TtjDjPuLV917S5K, Checkout/payment-intent and signed webhook IDs, typedstripe_fundingledger ID, exact safe-integer cents arithmetic, explicit replay with zero duplicate ledger rows, and all named checks. Hosted QA now requires desktop and exact390x844results for six named routes with zero overflow, console/page errors, and failed HTTP requests. Physical-iPhone and external acceptance must share the exact staging version and deployment; external schema 2 canonically binds all four receipt hashes while the 13-line V3 review stays unchanged. - Focused source proof:
bun test tools/production/control.test.mjspassed 12 tests / 60 assertions andbun test tools/staging/control.test.mjspassed 12 tests / 51 assertions after a production build. The test fixture covers a complete valid receipt chain plus missing/malformed/stale linkage, wrong account/version/deployment, replay failure, secret-field rejection, incomplete/erroring QA, digest tamper, and failed staging live revalidation before production calls. - Corrected the runbook’s stale rehearsal schema 3 / rollback schema 1 descriptions to schema 4 / schema 2 and documented the fixed ten-argument private input order. No app/UI copy, migration, provider, browser, Stripe, D1, messaging, staging, or production mutation occurred; public-copy delta is none.
Next up: exact-head review and normal merge of the control hardening. A future final main merge must still produce every fresh private receipt and V3 approval before promotion; production remains HOLD.
2026-07-19 — final social branding live without v60 runtime promotion
- Ready PR #257 merged into exact production lineage as
55efa35922e9df2be159e0de28587f8e90ef386bafter exact-head Terra/high static-only GO. The upload changed exactly/index.html,/brand/soldi-social-card.png, and/brand/soldi-social-square.png; no Worker, migration, D1, Stripe, route, cron, favicon, logo, manifest, JS, or CSS source changed. - Cloudflare version
36200b71-70b9-411d-b0b0-04f7d9ef4243, deploymenta4080af8-9102-4906-a3a1-5f2c33b2f981serves the sevenv=20260719-2metadata references. Ordinary/Facebook/Twitter/Slack HTML parity, source-equal 1200x630/1200x1200 PNGs, transparent live logo/favicon, unchanged bundle hashes, provider topology, cron, and/api/v1/healthpass. - Desktop and 390x844 screenshots were inspected; the mobile Market list remains within the page and exposes its wider table through
overflow-x:auto. Public-copy delta is none. This static release satisfies no full-v60 promotion gate; production remains HOLD for the exact final candidate's rehearsal, rollback, protected staging, Stripe, physical-iPhone, external acceptance, Zak approval, andSOLDI_PRODUCTION_GO_V3receipts.
Next up: mint the full V3 receipt chain for the final normal main merge; do not invoke the generic app deploy or reuse these branding receipts as runtime-promotion authority.
2026-07-19 — buyer iteration merged into the final release PR
- PR #254 final head
d5be95f8eae34cd9a99b441bd90133fda7c9e191repaired the five-market/Illinois Package-routing P1 and merged normally into PR #253 as3c97dc29f8be0080387a098f1d2d2742539f8faf(parents2ebc53aandd5be95f). - Verification passed focused 2 files / 42 tests, full app 81 files / 740 tests, TypeScript, production Vite build, final Sol/medium review with no P0–P2, and an isolated true
390x844touch/iPhone-UA browser run across eight mobile/desktop journeys. The run recorded zero horizontal overflow, console/page errors, and HTTP>=400responses. - This follow-up changes only launch-control documentation, including the walkthrough's release-status decisions. No screenshot was recaptured because the application UI and its existing acceptance captures are unchanged. Earlier July migration-rehearsal, rollback, staging, and Stripe receipts remain historical but are stale for the final production candidate. That candidate is created only by PR #253's future normal merge to fresh
origin/main. - The first independent Sol/medium control review correctly held the documentation successor: the canonical current-state table still mentioned PR #196/
e97cfd3as operative, V1 as conditionally requestable, and only three hard gates. The repair makes all those references historical and requires the full V3 gate set; no application or provider state changed. - The bounded rereview then found two remaining control-only gaps: the operative sequence still named PR #196, and the JSON omitted explicit external-acceptance, retained-data-comparison, Zak-approved-V3, and V3-only-token gates. The final correction moves the sequence to PR #253 and makes those states first-class while marking old
eaf68ccprovider/fixture receipts historical. - The current table and JSON now also label the isolated backend, provider, demo-seed, and Stripe proofs historical, with exact final-candidate reruns open. This prevents a passing July receipt from being mistaken for a current promotion input.
- Closed old PR #180 as superseded by #253; its selectively harvested payment/import/refund/staging semantics remain in the additive v60 train, but its older UI shell and launch authority will not merge. The canonical order now mints the two-parent main candidate first, then performs rehearsal/rollback, protected-staging reseed/Stripe/hosted/physical/external proof, V3 approval, and production promotion for that one SHA.
Next up: rerun CI and exact-head review on the documentation successor, merge PR #253 normally, then create fresh final-SHA receipts for the 12-migration real-production-copy rehearsal, Time Travel rollback, protected staging, physical iPhone, external acceptance, and V3 approval. Production remains HOLD.
2026-07-18 — supplied transparent favicon pack (ready source; not deployed)
- Replaced the earlier opaque small-icon family with the exact supplied files from
~/Downloads/soldi-brand-assets/soldi-favicon.zip. The active ICO, 16/32/48 PNG, Apple-touch, and 192/512 PWA outputs contain real zero-alpha pixels; the genericMyWebSitemanifest was excluded. - The audit now binds every direct deploy output to the checked-in source bytes and compares generated 16/32/48 PNGs against decoded source-ICO RGBA pixels. Four adversarial fixture tests prove rejection of a recolored PWA icon, a different valid transparent ICO, and a modified ICO-derived child PNG, while
brand:faviconremains deterministic without social-card inputs. - Local verification passed 80 test files / 730 tests, TypeScript, Vite build, pre/post-build brand audit, and diff hygiene. No TSX changed, so the UI polish workflow was not applicable; the walkthrough layout and screenshots remain current.
- Public-copy delta is none. This source follow-up does not change the production JS/CSS bundle, money path, database, API behavior, or any release gate. The retained-production rehearsal, tested Time Travel rollback, and physical-iPhone pass remain mandatory before any
SOLDI_PRODUCTION_GO_V1request or full v60 promotion.
Next up: final exact-patch review, ready PR with Zak requested, merge after CI, then a static-only hosted favicon refresh that preserves the current production runtime. Full v60 promotion remains separately held.
Production receipt
- PR #250 passed hosted CI and merged as
d1bc152828fb784a324c5514c819b0ba61b68226. Exact production-lineage hotfix9baf86fdeployed as Worker version62d84152-c5bf-4b8b-adfc-5c49022fed1a, deploymentcb1e573b-ffae-48d4-b9e7-6fd387c4370d. - Hosted ordinary/Facebook/Twitter HTML is byte-identical and advertises
v=20260719. Every active ICO/PNG/Apple/PWA/manifest byte matches source, MIME/dimensions pass, and every icon has real transparent pixels. The manifest has no generic identity or unsafe maskable claim. - Production application JS/CSS remain exact
2770c9f4…671e/35857dc8…cdb;app/src,app/worker, Wrangler config, D1, Durable Object bindings, cron, and four secret names are unchanged. Health returns 200. - Zak received PR #250, exact head, no-copy-delta, verification, and the unchanged three production-go gates. This receipt still does not authorize full v60 promotion.
2026-07-18 — Soldi digital branding live as static-only production hotfix
- Production before release was exact July 9 source
04728d2ee4aa553ddf79a86a96f62eba9404847f, Worker version55190601-0e74-406f-aee1-4f0bda417147, JS/assets/index-CU_EN45X.js, CSS/assets/index-BIrG5Bbu.css, and no Open Graph metadata. Rebuilding that source reproduced the served HTML and bundle names exactly. - Full merged
mainwas not uploaded: remote readback found 12 unapplied production D1 migrations (0025through0036). Instead, exact hotfix65ec6b06001c6f58d028e7faec127002e7919f7fadds only PR #246's metadata/favicon/logo/social assets to the proven production source. The inherited 33-file / 264-test suite, TypeScript, Vite, current 17-raster brand audit, and diff hygiene passed; JS/CSS hashes remained unchanged. - Cloudflare version
52b0854d-f81c-4b85-aee8-5af39f7c1ec4, deploymentbb4b0d6d-009f-4e7a-9c5d-7da5b6d31e66, is live. The Worker script etag remains exactc2b631e9d99c0c986d2eb2981d9ae6e76ca81a2013832413ecef6428d6db13de; D1/Durable Object bindings, cron, and all four secret names are preserved. - Hosted ordinary/Facebook/Twitter HTML is byte-identical and exposes the ordered 1200x630 plus 1200x1200 images. Every social/logo/favicon hash matches source; MIME/dimensions pass;
/api/v1/healthis 200; the existing JS/CSS hashes remain2770c9f4…671e/35857dc8…cdb. Zak received the cache-busted app, card, square, and favicon URLs plus the full-v60 migration boundary.
Next up: rehearse and apply the 12 production migrations under the production controller before promoting the complete merged v60 runtime. This static release does not claim that promotion.
2026-07-18 — PR #246 digital-brand merge receipt (docs-only)
- Ready PR #246 final head
36bada001959ab53cd04e2e6e573c03ddc03afb5passed hosted GitHub CI and merged tomainasfb3feeb078f18dcf6dfc68ad0445d5c99a6e9c8d. Zak (killerabbasi) was requested as reviewer and separately texted the exact merge, no-copy-delta, and QA status at+17739974600. - This closeout reconciles the current roadmap, readiness packet, copy ledger, and implementation note/index to merged-source truth. It changes no app source, public copy, provider state, or deployed asset.
Next up: an authorized production deployment must separately prove served MIME/dimensions/hash, favicon cache refresh, and third-party social previews; no provider or deployment action occurred in this docs-only closeout.
2026-07-18 — Supplied Soldi digital brand pack (source correction; not deployed)
- Reconciled
~/Downloads/soldi-brand-assets/against exactorigin/main5d1a755814ba58e1cfcaa249cd4d655647ed488f. The supplied transparent logo is already the immutable checked-in source byte-for-byte (30adbc8f…), so the real app logo remains unchanged rather than being redrawn. - Promoted the supplied circular
S(104c107f…) to the small-format identity authority and regenerated opaque 16/32/48/180/192/512, maskable, three-frame ICO, Apple-touch, and conventional root fallback outputs. Versioned icon discovery is deliberate because browser favicon caches survive same-path deploys. - Recreated the supplied thumbnail direction as exact opaque 1200x630 and 1200x1200 outputs using the current v60 Open Market capture. The sheet's stale
The PPL Marketplace, Probate, and trust-badge copy did not ship; the establishedExclusive Seller Lead Marketplacedescriptor remains the only discovery copy. The full no-copy-change disclosure is appended todocs/plans/soldi-brand-assets-copy-ledger-20260716.md. - Extended the deterministic audit to bind all three supplied source hashes, 17 raster dimensions/alpha contracts, favicon aliases/ICO frames, manifest, ordered Open Graph images, absolute Twitter metadata, Worker asset configuration, and built copies.
bun run verifynow runs that audit automatically. The first GitHub run passed 726 tests/build but exposed a runner-portability defect (identifyabsent); the corrected required audit reads PNG/ICO headers in pure Node, while ImageMagick remains local-generation-only. Generated PNG metadata is stripped and consecutive fixed-input renders are byte-identical.
Next up: exact-head review and one ready PR with Zak requested. After merge, an authorized production deployment must separately prove served MIME/dimensions/hash, favicon cache refresh, and third-party social previews; no provider or deployment action occurred in this source session.
2026-07-17 — Protected staging, real Stripe funding, and hosted v60 acceptance
- Corrected and provider-proved the
camolechowski@gmail.comCloudflare token against the exact Soldi account, Workers, D1, zones, routes, and custom domain. Deployed the exact PR #196 train repeatedly through the fail-closed controller; the final pre-ledger receipt was572a3c2b1543e39726837e45cd9fdae6ae8faca0, deployment5f15e35f-d66e-4ac4-8712-b29fb12e9675, Worker version92cd0c4d-34f8-42b1-a734-05b08c205591, and app-assets digest019480da8baa1bef274e0c730553a894c807abf8a2db557aff992a70add9df12. - Repaired Wrangler JSON-prefix/readback compatibility and moved remote seed mutations to Cloudflare D1's transactional batch endpoint. A hostile staging sentinel proved rollback. The receipt-bound fixture is idempotent at nine marked leads, three ranked Territories, 12 available leads (4 Cold / 4 Warm / 4 Hot), zero collisions/legacy/economic references, and unchanged purchase/refund/portfolio counts.
- Completed a real
$1,000Stripe sandbox Checkout and webhook. The demo wallet moved from$5,510to$6,510; Transactions shows the typed Stripe funding row and running balance; the wallet ledger count moved from 9 to 10 exactly once. - Hosted QA covered the six v60 screens at desktop and exact emulated
390x844: correct headings, 390/390 width, no forbidden old-app copy, no failed requests, and no console errors. QA found and corrected Territory rank display; active rows now showPosition #1/#2/#3, while null/paused rows retainPosition unavailable. Focused proof passed 2 files / 14 tests; full proof passed 79 files / 726 tests, TypeScript, Vite, docs build, JSON, and diff hygiene. - Replaced the canonical artifact's self-staling docs-head literal with a durable authority rule: immutable runtime-bearing
e97cfd3plus assets digest are tracked in source; the exact final PR head must equal app health, Stripe health, and the private provider receipt and is recorded on PR #196 after the last deploy. - Deployed FHC exact merged
main6615f94as Worker versionec6c985b-44c6-412b-bb8e-174c839db198; 966 pages built, sampled English/Spanish routes returned 200, and the challenged fabricated-voice phrases were absent from live Chicago/Miami/South Side HTML. Deployed Elite Flippers exact merged0d898d0as Worker version86cb3b77-ae54-4c6f-8868-1c97c9ba4220; apex/www returned 200, live HTML was byte-identical to the prerender, and every requested numeric/risk claim was absent.
Next up: deploy this final self-resolving ledger head, record the immutable receipt on PR #196, finish Terra/high exact-head review and physical-iPhone confirmation, then run the separately gated retained-production rehearsal before any production promotion.
2026-07-17 — FHC #236 merged and reconciled into the v60 launch train
- Final-reviewed Zak's FHC PR #236 exact head
f6647d2958fb8c8bc5cedc68ef03b4120b597f14: 966 pages / 255 Spanish twins, FHC audit 0 blockers, FHC 547/547, targeted guard 67/67, root app 354/354, clean diff/worktree. Corrected only the live PR-body scope/count wording; no additional product-copy edit was made. PR #236 merged tomainas6615f94d51757f9afee12f5857e3249e43cf14ae. - Reconciled that exact main advance into PR #196's exact
4fe5959train by normal two-parent merge7c0e4e6ce48bb4e80cdc44c3b92e908b12cc87f8; no conflicts, squashes, rebases, or dropped Zak history. Integrated proof passed root 79 files / 725 tests, FHC 547/547, FHC build/audit, staging dry-run, and diff hygiene. - Exact deploy payloads are prepared for FHC
6615f94, Elite0d898d0, and the reconciled Soldi staging train. No provider upload occurred: the named 1Password item still returned the rejected Cloudflare token (code1000), and the only connected Chrome extension profile was the unrelatedflowsystems.liveaccount.
Next up: replace/verify the exact-account credential, push the train reconciliation, deploy and publicly verify Elite + FHC, then deploy the exact Soldi train to protected staging with its provider receipt and complete hosted acceptance. Soldi production remains HOLD behind retained-data rehearsal and promotion gates.
2026-07-16 — PR #245 operator-authority wording P2 correction (docs-only)
- Independent rereview found no code defect in fixed-zone head
2a54e84; it found an overbroad documentation implication. Workers Scripts Edit + Workers Routes Edit is only the fixed-zone read-only preflight scope, not the full staging operator token or authority set. Zone Read remains absent; fixed detail remainsGET /zones/22dfb4f39d708e227c63dbc9d344e955with exact id/name/account validation. - Camo is the authorized Cloudflare and Stripe provider operator. The full staging operator sequence still separately requires repository-mandated DNS Edit/custom-domain authority for domain operations and scoped D1 Edit for Time Travel bookmarks, remote migrations, and staging data actions. Neither is implied by a passing preflight; actual execution waits for scoped-token verification and an explicit receipt-bearing run.
- No code behavior changed. Documentation/JSON/hygiene and existing focused/full gates were rerun; no Cloudflare, D1, Stripe, browser, provider, deploy, or external message action occurred.
Next up: independent exact-head review. A future authorized operator must satisfy the separately scoped authority requirements and mint a complete provider receipt; ff75918 remains uploaded-without-receipt and unaccepted.
2026-07-16 — PR #245 fixed-zone authority P2 correction (source-only handoff)
- Independent review correctly held exact PR #245 head
9699268e1c21b463d2a0b759df617c19de1795d8: the first fail-before-upload preflight usedGET /zones?name=soldi.cc, which would require Zone Read and exceeded the prescribed deploy-token authority. The deploy token remains limited to Workers Scripts Edit + Workers Routes Edit; Zone Read is not added. - The preflight now reads only fixed known zone detail
GET /zones/22dfb4f39d708e227c63dbc9d344e955, then requires that returnedid,name: soldi.cc, andaccount.id: 2fb55b3d56fa4a0cb926515ecd0b1a6fare exact before it reads that same fixed zone's Workers Routes endpoint or accepts thestaging.soldi.cc/soldi-stagingcustom-domain attachment. This reverses the earlier name-resolution decision append-only; it removes the unnecessary scope while strengthening target identity. - Fake-only coverage rejects wrong fixed zone id/name/account, malformed zone envelope, and fixed-zone HTTP/auth failure along with the existing code-10000 routes, missing-token, malformed-routes, and wrong-domain failures. Frozen focused proof passed
bun run test:staging34 tests / 121 expectations andbun run test:production-control17 tests / 62 expectations. Full root/docs/hygiene proof is recorded with the exact follow-up head; no Cloudflare, D1, Stripe, browser, provider, route, bookmark, seed, deployment, or production call occurred.
Next up: exact-head review of the narrowed token contract. Any future authorized staging retry still must pass the fixed-zone read-only preflight and mint a complete provider receipt; the existing ff75918 upload remains unaccepted.
2026-07-16 — Staging authority fail-before-upload repair (source-only handoff)
- The clean exact candidate
ff75918b5f1f336c65d2d7c3648be6765ee7fcc0encountered a real staging authority failure: Wrangler uploaded and activated Cloudflare versioncf78dc65-c0b7-4022-a7a6-676344efad47, then its required zone Workers Routes read failed with API code10000under--domain staging.soldi.cc. No deployment receipt was minted. Public health reported exactff75918; served Stripe identity was test accountacct_1TtjDjPuLV917S5K; served social-card source hash, manifest, and meta matched source. Those facts prove only an uploaded-but-unaccepted hosted version, not deploy acceptance. tools/staging/authority-preflight.mjsnow performs a fixed-target read-only Cloudflare preflight before the exact-Git snapshot, frozen install/build, temporary config write, or Wrangler executor. It requires a non-empty token, exact account2fb55b3d56fa4a0cb926515ecd0b1a6f, onesoldi.cczone bound to that account, a successful read of that exact zone's Workers Routes endpoint, and onestaging.soldi.cccustom-domain object attached tosoldi-stagingand the resolved zone. HTTP/auth failure, malformed envelope, missing/ambiguous/wrong account/zone/domain/service, or missing token stops before an upload; no preflight endpoint writes or persists a token/value.- Fake-only adversarial coverage reproduces the routes API
10000failure and proves no snapshot/executor upload follows. It also rejects absent token, ambiguous/wrong zone, malformed routes envelope, and wrong domain service; the healthy deployment fixture proves all four authority reads precede snapshot creation and Wranglerdeploy.bun run test:stagingpassed 31 tests / 117 expectations;bun run test:production-controlpassed 17 tests / 62 expectations; root verification passed 79 files / 725 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index. JSON, diff, conflict, and clean-worktree gates remain recorded with this handoff.
Next up: independent exact-head review and an explicitly authorized protected-staging retry with a token that passes the new read-only authority gate. A seed run, final browser evidence, physical iPhone evidence, provider receipt, hosted acceptance, and every production action remain open; no provider call was made in this repair lane.
2026-07-16 — PR #243 D1 invariant-envelope P2 repair (source-only handoff)
- Independent Terra/high rereview held exact head
78b198fbecause the old invariant parser accepted the syntactically valid empty-results envelope and emitted[0,0,0,0]assertions. The defect was reproduced locally with the fake-only rehearsal executor before repair; no provider operation was used. - Replaced recursive result discovery with one strict documented D1 execute envelope:
success:true, finite non-negativemeta.duration, exactly one result set, empty foreign-key rows, and exact scalar{count:0}rows for wallet, NULLproperty_identity_key, and duplicate-key checks. The duplicate query now wrapsGROUP BY/HAVINGin an outer count, so healthy zero duplicates proves one scalar row. Applied migration readback now queries the fixedd1_migrationstable and requires the complete ordered{name,status:"applied"}inventory; filename containment and unsupportedmigrations list --jsonare gone. - Fake-only regressions reject reviewer-empty, missing, duplicate, multirow, wrong-alias/type/status, nested-result, positive-count,
success:false, and malformed-metadata envelopes while retaining fixed-account cleanup, GitHub approval, and structured Time Travel coverage. Frozen install was unchanged; production control passed 17 tests / 62 expectations; staging controller/demo-seed 24 tests / 105 expectations; root verification 79 files / 725 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; JSON, diff, and conflict scans passed.
Next up: push the exact repair head, refresh the PR provenance, and stop for a new exact-head Terra/high rereview. No rehearsal, provider, Cloudflare, D1, Stripe, bookmark, export, deploy, merge, or external message is authorized.
2026-07-16 — PR #243 exact d80 train integration (source-only handoff)
- Normally merged exact reviewed train
d80f2e0a3438b152c62193b1911c99c53d64d434into prior PR #243 head151e49fa9eb7d0d55cb525a608e4988cff86e08aas93b638c889a0c2535d69198ba24fcec2081e0fb6. Parents are preserved in that order; conflicts were restricted to shared append-only release documents and resolved as an additive union. - The train retains reviewed Hosted-QA/funding and canonical-brand source together with prior Package, seed, and production-control histories.
tools/production/**is byte-identical to151e49f; no production-controller semantics changed. Frozen install was unchanged; production control passed 14 tests / 36 expectations; staging control/demo-seed 24 tests / 105 expectations; root verification 79 files / 725 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; JSON, diff, and conflict scans passed. No deployment, rehearsal, provider, Cloudflare, D1, Stripe, bookmark, migration, cleanup, or external message occurred.
Next up: push the exact head, refresh PR provenance, then stop for independent exact-head review.
2026-07-16 — PR #243 hardened production-control integrated handoff (source-only)
- Integrated the exact requested launch train
cfbc5cd713c8d402e1017ecea51a55fe86e16f9das mergeb9b8f95e9ff4e5128221e373d8beef23be9ae5da, retaining its Package identity protection and staging demo-seed code/docs while preserving the production-only controller policy. - Repaired every Terra HOLD seam: immutable external GitHub
APPROVEDproduction-go review authority with strict SHA/config/diff binding and a maximum 24-hour submitted-to-expiry window; private fixed-account D1 config on create/info/delete; immediate cleanup-target assignment after create; local-export erasure plus escalation even on remote delete failure; zero-NULL/duplicate property identity checks; and exact structured temporary-only Time Travel restore/post-restore proof. - Source-only verification after the merge: frozen install unchanged; production controller 14 tests / 36 expectations; staging controller/demo-seed 24 tests / 105 expectations; root
bun run verify77 files / 711 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; JSON parse andgit diff --checkpassed. No Cloudflare, D1, Stripe, bookmark, export, migration, restore, deploy, remote cleanup, or token operation occurred.
Next up: push the final integrated head and stop at independent exact-head review. Private retained-data rehearsal, fresh production bookmark, hosted acceptance, and promotion remain separately authorized future work.
2026-07-16 — Production-control and retained-data preflight lane (source-only)
- Added a production-specific
tools/production/controller rather than extending staging policy. It permits only canonical checked-in Workersoldi,app.soldi.cc, production D1soldi, canonical cron/workers.dev/binding intent, and a clean exact full SHA. It path-fences private plan/receipt artifacts, recomputes current config/assets/migrations, renders a redacted config diff, and requires an externally fetched, exact-commit GitHubAPPROVEDproduction-go review from immutable Zak user id236636852/killerabbasiincamolechowski/soldi; a local deploy operator cannot mint authority with JSON/token text. - The retained-data rehearsal deliberately uses the safe D1 model: private
wrangler d1 export soldi --remote, then fixed-account config-fenced temporary D1 creation/info confirmation before import, complete migration/invariant/readback proof (including zero NULL/duplicate property keys), and structured Time Travel restore plus post-restore readback only on that temporary target. Nested cleanup erases raw local export even if remote delete fails, emits an escalation, and fails closed. It requires acknowledgement that export blocks database requests, does not claim D1 clone/fork support, and contains no production source restore path. - The eventual upload takes a frozen exact Git snapshot, rebuilds, compares snapshot/current-worktree digests, and requires post-upload authority for exact Worker version/deployment, complete bindings/plain-text vars, secret names, custom domain, zero routes, workers.dev, and cron. Rehearsal, bookmark, upload, provider, migration, export, cleanup, Stripe, and deployment operations were not executed in this source lane.
- Local repair proof includes untrusted GitHub reviewer/repository/binding, future/unbounded/expired attestation, wrong account, create-then-info failure cleanup, delete failure/raw-export erasure, null property key, structured rollback, post-restore drift, and provider drift regressions. Final integrated verification is recorded only after the required exact train merge. The production runbook is
docs/runbooks/v60-production-control.md; it cites current Cloudflare Time Travel and import/export limits.
Next up: independent review of this source-only control lane; only after review and explicit owner/operator approvals may the private real-data rehearsal and the separately gated hosted-acceptance sequence be scheduled.
2026-07-16 — Exact PR #242 train merge into canonical-brand branch (local; review handoff pending)
- Fetched and verified
origin/orchestrator/marketplace-v60-20260713/mergeexactly at94757fbe1622d7b91458f8200a936595622c5eb4, then normally merged it into the PR #244 brand branch as67d98eac09903df2818a59cbf8cda05ba2ebc053. Conflict resolution preserves both PR #242 hosted-QA/funding source/readiness records and canonical-brand copy/audit records append-only. - Every checked public brand artifact and direct mark-rendering source is unchanged from
9a9e69b:app/public/brand/**, favicon, manifest,Logo, TopNav, and Login. The sole overlapping consumer-file delta is PR #242's independentLayoutsupport-clearance import/style and its test; itsLogoJSX/source/alt/dimensions are unchanged. No logo asset, metadata, or generator behavior was modified. - Frozen install, focused 3 files / 4 tests, and root
bun run verify79 files / 725 tests with TypeScript and Vite passed. Docs build 10 internal + 2 client docs + index, the deterministic brand audit, exact brand-identity diff, manifest JSON, conflict-marker/diff checks, and public.DS_Storescan passed. No deploy, provider mutation, migration, or PR merge occurred.
2026-07-16 — Canonical Soldi brand assets (local source; independent review pending)
- Added immutable
app/public/brand/soldi-logo.png, whose audit-enforced byte SHA-256 is30adbc8f75f5bf1377c3f7b1714be1ae505a9d43dc3b9113ff92c805f31bd630(separate ImageMagick pixel signature9a8c70fae8d1dafb86ca91cb3b181767cf76c05237db0d8e18c16030a42f1dad). The supplied 1536x1024 RGBA source was copied byte-identically and is never redrawn, recolored, or recompressed. - Replaced real app company-mark treatments in the shared desktop/mobile navigation, Login, support panel, and footer with one accessible
Logocomponent. The app retained existing v60 geometry/tokens and motion behavior; source tests plus local 1440px and emulated 390px browser inspection found no horizontal overflow or logo distortion. - Added derived alpha-preserving mark/dot assets, opaque 1200x630 discovery card, favicon/Apple/PWA/maskable icon set, manifest, complete route-agnostic canonical/Open Graph/Twitter/JSON-LD metadata, and a deterministic audit that also checks the
app/distCloudflareASSETSsource configuration and built copies. The exact old-to-new public-copy ledger for Zak isdocs/plans/soldi-brand-assets-copy-ledger-20260716.md; it introduces no price, Package, auction, testimonial, or Fair Home Cash claim. - Regeneration deliberately requires
SOLDI_BRAND_FONTinstead of hardcoding macOS Verdana. The checked-in rendered assets are cross-platform deploy artifacts, but regeneration is only deterministic for a caller-supplied exact font binary; it is not claimed cross-platform. No deploy, host/cache-header claim, FHC, or preview change occurred. - After the brand commit, normal merge
fa53e0cintegrated exact traincfbc5cd713c8d402e1017ecea51a55fe86e16f9d, retaining the Package owner-bound readiness, staging reseed, runbook, deck, and append-only documentation changes. TheSoldi homelink now has its ownflex min-h-11 min-w-11target around the unchanged 40px image; fresh local browser measurements were70.95×44pxat both 1440px and 390px, with mobilescrollWidth=390. - Final local proof on the merged target-corrected head passed frozen install, the focused 3-file/4-test brand/layout suite, root
bun run verify78 files / 712 tests with TypeScript and Vite, docs build 10 internal + 2 client docs + index, the deterministic brand audit, manifest JSON, diff/conflict checks, and noapp/public/.DS_Store. Local Vite preview returnedimage/pngfor the card andapplication/manifest+jsonfor the manifest; it is source/browser evidence, not a hosted cache-header claim. Independent review is next; no deploy occurred.
2026-07-16 — PR #242 additive exact-train integration (local; independent rereview pending)
- Additively merged exact
origin/orchestrator/marketplace-v60-20260713/mergeheadcfbc5cd713c8d402e1017ecea51a55fe86e16f9dinto PR #242 as two-parent commitf477c67b9f6a1c1c79aeda2c1c03e67ac3847e0c, retaining its approved Package readiness/copy and staging demo-seed code/documentation. Conflict resolution was limited to shared append-only release records; inheritedapp/src/pages/Market.tsxandapp/src/pages/Market.test.tsxwere not modified by PR #242. - Train-relative source fence passed:
git diff --name-only cfbc5cd...HEADcontains the PR #242 mobile/payment/security/doc delta only; explicitgit diff --exit-codefor both Market files passed and no Package or seed source path appeared. - Combined focused proof passed 7 app files / 79 tests plus TypeScript; inherited staging controller/demo-seed proof passed 24 tests / 105 expectations. Root
bun run verifypassed 78 files / 724 tests with TypeScript and Vite; docs rebuilt 10 internal + 2 client docs + index;git diff --checkpassed. No deployment, provider, D1, or merge to the base train occurred.
2026-07-16 — PR #242 Terra fixture/cache hardening (local; independent rereview pending)
- Exact Terra review held PR #242 head
4beb007for two source-contract defects: omittedAPP_ENVIRONMENTplus a loopback request URL could mint local fixture funds, and authenticated funding-capability responses carried no cache boundary. The original mobile support geometry and configured-Stripe direct Checkout corrections remain intact. - Centralized trusted local-fixture authority in
isTrustedLocalFixtureEnvironment: only literalAPP_ENVIRONMENT=developmentortestqualifies. Payment capability and fixture deposit use that environment-only predicate and do not inspect request URL or Host. Undefined, unknown, staging, and production report capabilityunavailableand each deposit attempt returns503 stripe_not_configuredwith no D1 batch. - Funding capability now sends
Cache-Control: no-storeandVary: Cookiefor authenticated 200, unauthenticated 401, and wallet-schema-not-ready 503 responses.Vary: Cookieis retained defensively even withno-storebecause authentication changes the valid response boundary. - Focused proof passed 4 files / 50 tests plus TypeScript: explicit development/test fixture success, four non-trusted environment capability/deposit regressions across loopback URLs, configured Stripe, and cache headers on 200/401/schema-503. Root
bun run verifypassed 78 files / 715 tests with TypeScript and Vite;bun run build:docsrebuilt 10 internal + 2 client docs + index;git diff --checkpassed. Source repair commit99fadee02af9b5df635b2177a3f4f699a018a77dwas pushed, and PR #242's body was refreshed with exact provenance and test evidence; independent rereview remains next. No deployment, provider, D1, or merge occurred.
2026-07-16 — Hosted-QA P1/P2 source repair (local; independent review pending)
- Worked from exact hosted-QA source
4578d7ba10a08135cd10bd6fc97dd04c45e2c6c7in isolated branchorchestrator/soldi-final-wave/hosted-qa-fixes. The staging receipt proved two source defects only: at effective 500px CSS width the fixed support control covered the Territory+ Add More Territoriesaction, and normal Add funds first produced a same-origin/payments/deposit409 before starting Stripe Checkout. - Mobile support now shares a single 44px fixed-action contract with the Territory button: the launcher and open support panel sit above the bottom primary action by 16px at the mobile breakpoint, including the safe-area inset. Desktop coordinates and v60 visual tokens remain untouched. A pure geometry regression proves non-overlap at both the observed 500x844 and required 390x844 CSS widths; layout tests pin the rendered CSS contract.
- Added authenticated
GET /payments/funding-capability. It returnsstripewhen the configured provider route is available,local_fixtureonly for an unconfigured localhost development request, andunavailablefor unconfigured hosted requests. Billing now starts the existing idempotent/wallet/checkoutroute directly for Stripe and uses/payments/depositonly for an explicitly confirmed local fixture; wallet crediting remains webhook/ledger owned. No Stripe, Cloudflare, D1, or deployment operation occurred. - Focused source proof passed 5 files / 30 tests, including configured-Stripe direct Checkout and unconfigured local-fixture paths. Final root verification passed 78 files / 708 tests with TypeScript and Vite; docs built 10 internal + 2 client docs + index;
git diff --checkpassed. Commit/push and non-draft reviewer handoff remain next. Protected-staging true-390 pointer and zero-failed-request evidence must be rerun after an independently reviewed deployment; this local record does not claim it.
2026-07-16 — PR #241 Terra P3 runbook contract correction (source-only)
- Final Terra rereview held one documentation P3: the hosted-gate runbook still said revalidation config must be byte-identical to the receipt. Corrected it to the implemented contract: derive the checkout root from
main, validate withrenderStagingConfig(input, derivedRoot), canonicalize only local source paths, compare canonical text/digest before provider calls, and keep all non-path semantics exact. No runtime, migration, fixture, or hosted boundary changed. bun run verifypassed 77 files / 702 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index;git diff --checkpassed. Exact-head PR-body provenance refresh, push, and a new independent-review handoff follow. No Cloudflare, Stripe, remote D1, deployment, migration, Time Travel, or hosted command is authorized or executed.
2026-07-16 — PR #241 Terra hostile-reseed repair (source-only; exact-head review pending)
- Terra/high held PR #241 at
540183426887b38d38e812cc904f9093730d2b82: receipt revalidation incorrectly compared checkout-specific absolute config paths, the reseed trusted the receipt-provided asset digest, a post-preflight collision could commit a partial fixture set, cleanup could not recover that partial set, and the PR body named the runtime parent rather than the PR head. No hosted command was run while repairing those findings. - The staging deployment receipt now stores a canonical semantic configuration, normalizing only local source paths. The reseed command rebuilds the exact Git candidate with frozen install/build and independently compares its asset digest before provider or D1 access. A direct second-clean-worktree regression proves a controller-style receipt reaches only mocked provider/D1 dry-run readback; a substituted digest fails before either call.
- Apply and cleanup now use
BEGIN IMMEDIATEpost-lock guards. Conditional plain inserts prevent all fixture writes when a lead collision, competing Territory, context drift, or economic reference appears after preflight; the command then fails through its readback contract. Conditional marker-bound cleanup preserves ledger truth, blocks a post-preflight economic reference, and safely removes an old partial marked set without deleting an unmarked colliding row. - Focused
bun run test:stagingpassed 24 tests / 105 expectations against fresh0001–0036migrations, including three two-connection hostile races, cleanup race/recovery, canonical cross-worktree receipt revalidation, and asset-digest early refusal. Frozen install made no changes;bun run verifypassed 77 files / 702 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index;git diff --checkpassed. Exact-head review handoff remains required before a new PR review; no Cloudflare, Stripe, remote D1, deployment, migration, Time Travel, or hosteddry-run/apply/cleanupoccurred.
2026-07-16 — Receipt-bound staging demo-data reseed (source-only)
- Added
bun run staging:demo-seedas the only checked-in staging demo-data operator path. It requires the exact private deployment receipt for the same clean full SHA and live-revalidates the receipt's Worker version, full binding topology/plain-text values, secret names, zero cron, disabled workers.dev/previews, andstaging.soldi.ccbefore it can form a remote D1 command. The target is fixed tosoldi-staging/ isolated D1516586fe-4d84-4f41-a27a-96bf9d0697c2; production worker/host/D1 names and ids fail closed. - The deterministic marker-owned fixture adds nine reserved-fictional Investor leads: exactly three each Cold/Warm/Hot and all four current situations. Together with the canonical three v60 leads it requires a 10–12 available-lead Market. Three marker-owned
U_DEMO_V60Essex/NJ pre-foreclosure Territories exercise rank positions1/2/3and$250top-bid context. No new migration, old taxonomy, gamer payload, production fixture, or target override was introduced. dry-runis readback-only.applyandcleanuprequire literal confirmation; complete fixture reruns do not write, partial/colliding state fails, and cleanup deletes only exact marker-bound IDs. Wallet transaction, Market purchase, refund request/outcome, and portfolio snapshots must be unchanged; any fixture economic reference blocks cleanup instead of deleting history.- Local proof passed
bun run test:staging(17 tests / 73 expectations) with real fresh migrations0001–0036for fixture idempotency, exact tier/situation count, reserved-contact/current-taxonomy checks, Territory positions/top bid, production/non-staging refusal, ledger preservation, and cleanup scope. Fullbun run verifypassed 77 files / 702 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; JSON parse andgit diff --checkpassed. No deployment receipt was created or read, no Cloudflare/Stripe/D1 call occurred, and no hosted staging apply/cleanup was attempted. - Next: after an explicit staging execution authorization, create a fresh Time Travel bookmark, deploy the exact committed head through the existing controller, run the receipt-bound dry-run/readback, and only then consider the separately-confirmed apply. Hosted execution remains outside this source PR.
2026-07-16 — Exact staging control and Stripe mode fence (pre-deployment)
- Created
codex/staging-control-4219195from exact launch train421919505086994a19bbff71a9f4c805845e21c9. The standalone controller accepts onlysoldi-staging,staging.soldi.cc, isolated D1516586fe-4d84-4f41-a27a-96bf9d0697c2, test-mode Stripe, auctions off, cron off, Package scheduler absent, workers.dev/previews off, and a clean full Git SHA. It builds an exact private Git snapshot and provider-reads the unique Worker version/deployment, secret names, domain, subdomain, and schedule state. - Added staging health provenance using Cloudflare version metadata and a staging-only sanitized Stripe
/v1/accountidentity surface. Added a defense-in-depth Stripe provider-mode guard: staging plustestaccepts onlysk_test_; production plusliveaccepts onlysk_live_. A mismatch fails before funding-intent persistence and inside the shared provider request helper, covering Customer, Checkout, and Portal. - Terra/high's first exact-head review correctly held the child: mutable Stripe metadata was not identity authority, operational deploy/readback used the worktree Wrangler instead of the frozen snapshot, and the deploy function had no fixed receipt-producing command. The repair binds staging to immutable Stripe account
acct_1TtjDjPuLV917S5K, rejects a provider key when environment/mode is unbound, addsno-storeto staging provenance health, uses and hashes the snapshot Wrangler for upload and immediate provider readback, and adds override-freebun run staging:deploywith a private full receipt. - Provider preparation touched staging only: removed its inherited one-minute cron and attached
staging.soldi.ccas custom-domain id166ab9a82dc54d854123fb840fc6e3a1ace30de4. Read-only staging D1 preflight found migrations through0031, no malformed/Agent profiles, invalid wallet rows, duplicate non-null property keys, or Package state/cycles. Production Worker and D1 were untouched. - In Stripe's Soldi sandbox, active webhook destination
we_1TtjFvPuLV917S5KUEdwTcNVnow targets canonicalhttps://staging.soldi.cc/api/v1/webhooks/stripeinstead of the former workers.dev review URL. No buyer-visible copy or production Stripe resource changed. - After PR #233 merged as train
6916b0f, staging Time Travel bookmark00000006-00000000-000050ab-7ddf723e2eab88f63ddc2d6bdc85b1a5was recorded and remote migrations0032–0036applied cleanly to isolated D1516586fe-...; nothing remains pending, wallet/property/foreign-key checks are clean, and available Agent plus legacy-distress rows are zero. The first exact deploy failed closed before upload because strict Wrangler saw the provider-managed domain and public workers.dev/previews as dashboard drift. The signed-in Cloudflare UI then disabled workers.dev and previews; this follow-up repeats fixed--domain staging.soldi.ccon the strict deploy command so the existing required domain is explicit rather than contradictory. - PR #234 merged as train
c9ae348, but its retry also stopped before upload: Wrangler--strictrejects the expected new full-SHA/account-id variables themselves, so no genuine release can pass it. The bounded correction removes only--strict. Terra/high then held #235 because Wrangler could delete unconfigured dashboard variables before the receipt inspected them; later probes found preserved JSON, partial-topology bypasses, and a provider-only forged live-revalidation path. The repair adds fixed--keep-vars, requires the exact uploaded version's complete binding name/type topology plus all plain-text values to equal the rendered allowlist, and validates the complete receipt plus byte-identical config before any later provider revalidation. Preserved JSON, unknown types, malformed entries, duplicates, collisions, and forged receipt/config substitutions now prevent authority. Fixed domain/config/snapshot/toolchain inputs and unique version/deployment, secret-name, zero-cron, disabled workers.dev/preview, and exact custom-domain readback remain. - Post-repair proof passed: Stripe/provenance/identity focused Vitest 39 tests; staging controller 12 tests / 46 expectations; full app 77 files / 696 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; fresh local migrations 0001–0036. The staging D1 is already migrated through
0036; pending gates are exact child rereview/merge, exact Worker deployment/readback, Access policy, served Stripe identity plus Checkout/webhook, desktop/mobile hosted QA, and only then production consideration. - Terra/high approved exact #235 head
8fb0da6with zero P0–P3 findings; it merged as train6961cd0. A narrowly scoped Workers Scripts/Workers Routes token then produced deployment5db67132-5025-4455-807d-472677bfcc1aand Worker version7af1e587-af64-429d-9474-222089debe6b; no-store health serves exact SHA6961cd0atstaging.soldi.cc. Stripe key/account-id readback is correct, but the unactivated sandbox stores its provider-owned name insettings.dashboard.display_namewhilebusiness_profile.nameis null. A bounded fail-closed fallback child is in verification; Checkout/webhook and hosted browser acceptance remain open, and production remains untouched. - Terra/high held the first fallback head on three P2 edge cases despite green tests: empty primary names suppressed fallback, whitespace-only names were accepted, and documented-null
settingsrejected a valid primary name. The correction trims both candidates, treats blank as absent, accepts nullable settings, and pins all three failures; no deployment or merge occurred at the held head. - The corrected #238 head passed fresh Terra/high with zero P0–P3 findings, merged as
91b51c5, and deployed as Worker versioncc341282-8506-4a3d-88ca-31f806ec52cc. General health proved that exact SHA, while Stripe health stayed 503. Stripe request logs showed the Worker used the correct test key and receivedGET /v1/account200; direct shape readback proved the standalone sandbox omitsbusiness_profileentirely. A one-field optional-schema follow-up with an exact omitted-field regression is now required before the next deploy; production remains untouched.
2026-07-16 — v60 Package identity-bound readiness correction (local; final rereview pending)
- Final Terra/high rereview held exact PR #240 head
b1f1b14on one P2 only: a resolved U1 ready status had no owner, so React's anonymous/U2 pre-effect render could expose ready-only Package copy before cleanup. The correction stores{ userId, status }and derives readiness only for a current authenticated matching owner plus literalfulfillmentReady=true; existing AbortController cleanup remains the transport fence. - New Market regressions directly prove U1-ready cache fails closed for anonymous and U2 before effects, exercise U1-ready -> anonymous and U1-ready -> U2 pending UI transitions, and hold a late U1 completion until U2 resolves. Every hero, recommendation/action, Hot-modal, and unlocked-lead delivery/action literal remains absent until the U2-owned ready response arrives.
- Required make-it-sexy and make-it-simpler reviews were completed directly in this pane under Cam's no-normal-subagent rule. The established v60 visual treatment required no cosmetic change; the cache remains a single-consumer local state seam with no shared extraction warranted. Frozen install; the reviewer-aligned 100 tests / 8 files; full
bun run verify77 files / 711 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; andgit diff --checkpassed. PR/report refresh, exact-head commit/push, and final rereview remain next. No deploy, merge, Cloudflare, Stripe, or D1 mutation occurred.
2026-07-16 — v60 Package copy and qualityScore P2 correction (local; superseded review head)
- Independent review of PR #240 exact head
219396bheld four P2 defects: the successful direct-purchase dialog bypassed readiness, same-user server revocation could leave ready copy cached, the two retained AdminqualityScorecontracts had no server field, and the new mobile Package link lacked a 44px target. Market.tsxnow passes literal readiness into the unlocked-lead dialog, so its automatic-delivery claim andSee the packageaction render only whilefulfillmentReady===true. Package status is cleared synchronously after purchase and on visible-window return, then re-fetched; paired focus/visibility signals coalesce into one request while the existing identity abort fence remains. False, loading, and error direct-purchase reveal regressions assert no delivery claim/action.- The protected
/admin/leads/pendingand/admin/supply-funnelSQL selections and response mappers now returnl.quality_scoreasqualityScore; real route-response tests pin both fields. Buyer Market/auction mapper omission regressions remain unchanged. The recommendation Link has explicitmin-h-11and a focused assertion for the locked 44px mobile target. - Required polish was completed directly in this pane: the existing v60 refined/dark visual system, scoped banner hierarchy, reduced-motion modal path, and existing responsive layout already fit this corrective change, so make-it-sexy made no additional cosmetic edit. Direct make-it-simpler review found no reusable hook/extraction or quality cleanup; it did add immediate clear plus coalesced resume revalidation to prevent duplicate transport. A normal-agent attempt was terminated under Cam's later no-normal-subagent constraint; its output was not used.
- Verification passed: frozen install; reviewer-aligned Market/readiness/mapper/Admin suite 95 tests / 8 files; full
bun run verify77 files / 706 tests, TypeScript, and Vite; docs build 10 internal + 2 client docs + index; andgit diff --check. The built recommendation class is.min-h-11{min-height:calc(var(--spacing) * 11)}with--spacing:.25rem, a 44px target at the locked 390px width. Final PR/body/report refresh, commit/push, and a new exact-head review handoff remain next. No deploy, merge, Cloudflare, Stripe, or D1 mutation occurred.
2026-07-16 — PR #232 purchaser-role authority repair (local; merge held pending review)
- Hostile review reproduced a real direct-Market defect in an authoritative disposable D1: manually forcing an authenticated
buyer_profile.verticaltoagentstill returned201and created a purchase for a valid Investor lead. The preceding Investor-only closure had fenced lead inventory but not purchaser authority; its broader “cannot list or buy” statement is superseded by this correction. - Added a shared persisted-vertical gate for authenticated Market list, direct buy, and server bulk. Missing, malformed, array-shaped, and non-Investor profiles fail closed; valid retained Investor rows stay routable even if old preference data does not meet the newer profile-write schema. List returns its existing empty shape; direct/bulk return existing generic
409 lead_unavailable, preventing eligibility disclosure. Direct transactional claim and purchase predicates repeat the JSON-valid Investor requirement;0033batch-trigger enforcement remains intact. - Added direct fake-route, authoritative SQLite retained-profile, and atomic-bulk SQLite route coverage. Forced Agent direct/bulk attempts leave market purchases, batch ledger, fulfillment claims, wallet/balance counters, and selected lead availability unchanged. This change neither enables buyer bulk UI nor changes canonical Cold/Warm/Hot price behavior or the removed Hot discount copy.
- Verification passed: frozen install; focused 4 files / 32 tests; full
bun run verify75 files / 685 tests with TypeScript and Vite; fresh local D1 migrations 0001–0036; docs build 10 internal + 2 client docs + index; FHC 480 tests / 13 files, 966 generated pages, build, and audit; and scoped changed-file/added-line secret, conflict-marker, JSON, and diff checks. Commit, push, and PR #232 body refresh are next. No deploy, remote migration, PR merge, or message occurred.
2026-07-16 — Exact c8a46c3 train merge for Investor-only closure
- Committed the bounded Investor-only Market closure on original exact base
f61a0085f04efcb2f710c18129a8c401d3b30c79as3c95c8d, then fetched and verifiedorigin/orchestrator/marketplace-v60-20260713/mergeexactly matched requiredc8a46c3d476e2c4b315b95ad587d4fe5f21cd352before a normal merge. Shared conflicts were limited toBUILD_LOG.md, the implementation-note index, and the v60 note; resolution retained both the incoming FHC/current-main receipts and this closure append-only. - Post-merge proof passed: root
bun run verify75 files / 684 tests, TypeScript, and Vite; fresh local D1 migrations 0001–0036; docs build 10 internal + 2 client docs + index; FHC 480 tests / 13 files, 966 generated pages, build, and audit. Scoped added-diff/changed-file secret scanning, JSON, conflict-marker, and diff checks remain required before push. No Soldi deployment, remote migration, PR merge, or message occurred.
2026-07-16 — Investor-only Market and Hot-copy closure (local child)
- Created clean branch
codex/zak-handoff-closure-20260716from exact trainf61a0085f04efcb2f710c18129a8c401d3b30c79. Added forward-only0036_investor_only_market.sql: it normalizes valid retained Agent profiles to Investor pluswholesalerand retires only Agent inventory that remains Market-available. No historical migration was rewritten. - Buyer profile writes now reject Agent. Market list uses literal
vert = 'investor'; direct buy's preflight and transactional claim/purchase predicates and the server-only bulk helper independently require Investor. Retained Agent sessions, malformed legacy profiles, and future direct Agent writes cannot create a route to Agent inventory. SQLite proofs cover0035 -> 0036retained profile/lead conversion plus foreign-key integrity, authenticated Agent-profile rejection, list exclusion, direct-buyinvalid_lead_state, and no balance/purchase mutation. - Removed the active Open Market
Hot leads at $200, not $250recommendation, its$200hero/modal claims, and dead state/CSS while bulk remains disabled. The rendered copy test asserts no Hot-discount phrase and canonical direct Hot$250price coverage remains. Removed unused client-onlyAuthUser.heldBalancecompatibility type and its fixture residue; production source had no consumer. post-change-polish.jswas not run: this pane has no Workflow API runner, and its agent stages conflict with the explicit solo instruction. Both make-it-sexy and make-it-simpler instructions were read and applied manually toMarket.tsxandMarket.styles.ts; retained responsive/reduced-motion behavior and removal-only scope meant no cosmetic addition was warranted. Frozen install, focused 5 files / 43 tests, fresh local migrations 0001–0036, and rootbun run verify75 files / 684 tests (TypeScript and Vite) passed. Expected resilience stderr remained non-failing coverage. No deploy, remote migration, PR, merge, or message occurred.
2026-07-16 — v60 train reconciliation of FHC PR #231 production receipt (no Soldi deployment)
- Normal merge carries exact
origin/main962abd97518c8e67c7671ab6b9f068299deae438into the v60/payment/import/package-reserve train after its prior100b253reconciliation. It preserves the FHC receipt for deployed source100b253/ Workerc5786384, the route/artifact-only boundary, and issue links: freshness is deferred under #229 to 2026-08-31; missing Workers Routes token scope is tracked by #230. - This merge changes no Soldi app runtime, v60 UI, migration, Stripe configuration, or deployment state. FHC is independently live; the Soldi train remains unhosted and requires protected exact-SHA staging, Stripe sandbox, retained-data/migrations, hosted desktop/mobile acceptance, Zak final review, and explicit production promotion.
- Verification for this reconciliation: root
bun install --frozen-lockfile; app/rootbun run verify75 files / 682 tests, TypeScript, and Vite; FHC 480 tests / 13 files, build/audit, provenance 103/0, offline source links 8/8; fresh local D1 migrations0001–0035; docs build 10 internal + 2 client docs + index; JSON, conflict-marker, diff, and secret scans passed. The earlier nonexistentscripts/provenance-check.tsinvocation is command-error non-evidence; the correctdata/provenance.ts --checkpassed.
2026-07-16 — FHC production deployment receipt for exact 100b253 (live)
- Production serves exact source
100b253a3cefe29fbf482244f603046cfa0a48baon Cloudflare Worker versionc5786384-4ba6-4b0b-bf14-979f30b81de4. Supplied live probes passed: apex200;www301to apex; canonical/esdirect200with self-canonical HTML;/es/307to/es; and a Spanish twin200. - The supplied artifact receipt proves live
/es,sitemap.xml, andsitemap-es.xmlSHA-256 values equal the exact local artifacts. The deployed sitemap counts are 957 full URLs and 256 Spanish URLs. This is deployed artifact and route proof, not evidence that Google discovered, crawled, or indexed every URL. - Pre-deploy evidence: FHC 480/480 across 13 files; audit zero blockers with 12 existing thin-page warnings; provenance 103/103 comparisons; offline links 8/8; and public-output smoke passed. No public copy, data, route membership, FHC-10, or provider configuration delta was introduced by this deployment.
- Wrangler uploaded and deployed the Worker successfully. Its attempted custom-route rewrite then returned Cloudflare authorization code
10000because the token lacks Workers Routes permission; issue #230 tracks that token follow-up. The existing configured apex/www routes stayed attached and the live route/artifact probes above prove the new version is serving. - Freshness enforcement remains deferred pre-September work under issue #229, due 2026-08-31, and is not shipped or implied by this receipt. Receipt-lane verification: docs build 10 internal + 2 client docs with all walkthrough images resolving; root
bun run verify354/354 across 37 files plus typecheck/production build; andgit diff --check. No additional deployment or provider call occurred in this documentation lane; ready-PR/reviewer handoff follows without merge. - Committed and pushed the receipt source as
9e2aa60bc8879ea4e1245058bb52f9f1c33a0156; ready PR #231 is open againstmainwithkillerabbasirequested as reviewer. No merge occurred.
2026-07-16 — v60 train reconciliation of FHC #225/#226/#228 source truth (not deployed)
- Normal merge brings exact
main100b253a3cefe29fbf482244f603046cfa0a48bainto the v60/payment/import/package-reserve train. It retains the train's append-only Package/UI ledger and incorporates the FHC Spanish-hub sequence: #225 adds a generated/eshub for 255 existing Spanish twins; #226 emits flatdist/es.htmlso/esis canonical/direct200in local Worker proof; #228 restores the Soldi funnel asset while retaining the FHC hub capture separately. - Current source truth: the canonical sitemap gains one
/esroute (956 → 957); this is source membership only, not hosted serving, deployment, or Google crawl/indexing proof. FHC #220/#222 link-health and #223 registry work remain source-control evidence. PR #214 is independently live on FHC; no Soldi staging or production deployment occurred here. - Exact #228 documentation truth is retained:
docs/shots/funnel-mockup.pngwas restored byte-for-byte from pre-#225main4dc59090b3adbe78abedd20ca31283dc35e8251a(SHA-256f47cf22117d90232f6b5a3e21882d4f2f49f6326d3282b1a0f4171dc5bb199fe), whiledocs/shots/fhc-es-hub-local-20260716.png(SHA-256081b713c9865f0ae160fe8ed5d0e10a556ae157d2c775e1dcc311b3500e0e8eb) is expressly local source evidence. The former CSV gap remains fail-closed on v60/PR #196 exact6d251c7e6aa27d327bf60952e67e1bab181a7027, with local Worker-backed proof and immutable receipts; it is source/train proof, notmain, hosted, or live. - Current FHC source receipt for #228 is 966 generated pages, 255 Spanish twins, 1,193 files, 967 recursive HTML, audit, provenance
--check103 comparisons/0 disagreements, and offline source links 8/8. These are local build/source checks, not hosted evidence. - This reconciliation preserves every train-side ledger record and treats the incoming FHC historical entries as source-history evidence through parent
100b253; the current roadmap, walkthrough, and implementation-notes index now carry the reconciled source/deployment truth without retroactively changing historical receipts.
2026-07-16 — Package reserve v2 corrected owner ruling (local child)
- Created isolated child branch
codex/package-reserve-v2from exact train8d19f446e56f054732af99ab7c4f41a0c8ac76d0; highest prior migration was0034, so forward-only0035_package_reserve_v2.sqlis unambiguous. It archives immutable v1 readiness/state/reservation evidence, installspackage-reserve-v2authority and v2 reservation/paid-cycle triggers, and makes v1 incapable of authorizing a new fulfillment action. - The scheduler, reservation projection, and live activation guard now agree: each
active,max_bid_cents >= 25000Territory contributes6 * weekly_cap, regardless of filters;weekly_cap=0fails closed; each active or cancel-at-period-end Package contributes 25; and PPC supply is leads created in-window regardless of market status. Territory create/update defaults to and requires finite integer cap>=1; it is deliberately one-sided, so a Territory can stop a new Package sale but reserve never blocks Territory create/raise. - Focused local proof currently covers cap
3 -> 18,5 -> 30,10 -> 60, unbounded cap, statuses, package cancellation status, PPC/market-status supply semantics, daily decision replay, one-sided exactpackage_reserve_not_readyrollback, route validation, v1/v2 authority separation, and the truthfulWeekly lead capUI label. Full verification, docs build, source scans, commit, and push remain; no deploy, PR, or message occurred. - Final local receipt: focused 5 files / 70 tests; root
bun run verify75 files / 681 tests, TypeScript, and Vite; fresh local D1 migrations0001–0035; docs build 10 internal + 2 client docs + index; JSON/diff/conflict and added-secret scans passed. The current post-v2 build is initial JavaScript 422.60 kB / 133.94 kB gzip with deferred Leaflet 150.05 kB / 43.58 kB gzip, superseding the earlier current-byte receipt by one gzip byte while preserving it as dated history. No deploy, PR, or message occurred. - Retained-data hostile correction: the first
0035draft had not recreated v1 fulfillment authority triggers after renamingpackage_fulfillment_state. The follow-up restores their original insert/update authority predicates onpackage_fulfillment_state_v1. A retained v1 decision/state/reservation created on0034and then migrated in place rejects an attacker state mutation withpackage_readiness_authority_required; decision and reservation mutation remain rejected by their immutable triggers. Final follow-up verification is recorded with its commit; no deploy, PR, or message occurred. - Retained-data final receipt: focused 2 files / 31 tests and root
bun run verify75 files / 682 tests passed with TypeScript and Vite; fresh local migrations0001–0035passed again. This supersedes the preceding child receipt's 681-test count without rewriting history. Docs/integrity checks and commit/push follow; no deploy, PR, or message occurred.
2026-07-16 — PR #196 P3 configured UI count supersession
- The immediately following P3 receipt is preserved as historical append-only evidence, including its original 6 files / 31 tests statement. That historical count is superseded only by this dated correction.
- Re-running its exact configured six-file UI command reports 6 files / 37 tests. The Package HANDOFF sentinel remains 1/1 and the previously recorded full
bun run verifyresult remains 75 files / 669 tests. - This is a documentation-only release-truth correction: no runtime, user-visible copy, deployment, or release action changed.
2026-07-16 — PR #196 review P3 reproducibility truth correction
- Corrected only append-only release documentation in the train worktree. The prior 6-files/52 focused receipt lacked a recorded reproducible command and is explicitly non-authoritative.
- The authoritative configured UI command reports 6 files / 31 tests; the Package HANDOFF sentinel reports 1/1; full
bun run verifyremains 75 files / 669 tests. No runtime or copy changes were made. - No deployment occurred. Package reserve, exact-SHA staging, hosted acceptance, Stripe, and other owner gates remain unchanged.
2026-07-16 — train merge of exact main PR #223 (source truth; not deployed)
- Train branch fast-forwarded to
7710eed3955a6c3643c67c3a19c2df2d6a859ebband merged exactorigin/main4dc59090b3adbe78abedd20ca31283dc35e8251anormally with--no-ff --no-commit; this receipt preserves the Package/UI train history and the merged FHC #220/#222/#223 source-only truth. - FHC #220/#222 link-health and #223 sitemap-registry changes remain independently source-verified, not deployment proof. No runtime behavior was changed by this merge.
2026-07-16 — v60 mobile P1 target and Market confirmation-footer repair
- Repaired the hostile-review mobile P1s on exact branch head
bd681b9: the phone navigation trigger, authenticated account menu, referral pill, support launcher, support links, and support-close control now have effective 44px targets only at the mobile breakpoint. The existing desktop v60 geometry and all buyer-visible copy remain unchanged. - Reworked only the mobile Market purchase-sheet structure: details scroll in a body container and the existing confirmation action stays in a dedicated sticky bottom footer with a 44px action. A live local browser catch also showed the support launcher immediately closing through its outside-click listener; the opener now stops that opening event while outside-click dismissal still works.
- Fresh exact-worktree local captures at 390x844 are
docs/shots/v60-market-mobile-sticky-confirm-20260716.png,docs/shots/v60-mobile-targets-support-20260716.png, anddocs/shots/v60-mobile-account-target-20260716.png. Computed local boxes recorded 44px targets, aposition:sticky390px-wide purchase footer, andscrollWidth: 390; this is not hosted/protected-staging acceptance. Focused regression proof passed 4 files / 18 tests; rootbun run verifypassed 75 files / 668 tests, TypeScript, and Vite; docs built 10 internal + 2 client docs + index; release JSON, conflict-marker scan, andgit diff --checkpassed. Commit/push are next; no deployment, PR, merge, or message occurred.
2026-07-16 — v60 mobile P3 current-byte and support-focus repair
- A hostile rereview first corrected current build truth to 422.45 kB / 133.92 kB gzip. The final exact P3 build, after support-focus restoration, emits initial JavaScript 422.60 kB / 133.95 kB gzip; deferred Leaflet is 150.05 kB / 43.58 kB gzip. Earlier dated
422.09 / 133.84entries are historical measurements and remain append-only; the final P3 value is the current receipt. - Support now explicitly preserves internal dialog clicks, dismisses on an outside click, and restores focus to the existing
Need help?launcher after dismissal. No buyer-visible wording, desktop token, deployment, PR, or provider behavior changed. - Cleanup correction: an orphaned exact-worktree Wrangler chain survived the prior cleanup despite no public 8793 listener. It and all remaining DevTools daemons were terminated; final command/cwd, 8793/5183 listener, and DevTools-daemon scans are empty. Focused proof passed 4 files / 19 tests; root
bun run verifypassed 75 files / 669 tests, TypeScript, and final Vite bytes above. Docs/JSON/diff/conflict scans, commit, and push are next.
2026-07-16 — v60 UI normal integration of merged Package HANDOFF train
- Began a normal merge from pushed mobile UI head
c33a90f29bbf5b7da74801a389425d348b57740ewith exact incomingorigin/orchestrator/marketplace-v60-20260713/merge222030507ed3428af48c098c2979a9e4ac871377. The incoming merge contains PR #221's Package HANDOFF boundary child; it is merged into the train, not an open PR. The child adds the exact owner-block sentinel plus UTC-window and atomic-bulk rollback regressions, while leaving Territory-cap normalization owner-pending. - This is a source-only normal merge: no
app/srcUI source enters from the incoming range, Package0033and contact evidence0034retain their order, and no deployment occurred. Final verification/commit/push remain pending.
2026-07-16 — Package HANDOFF sentinel hostile-review repair
- Restored the reviewer-detached worktree to branch
codex/v60-package-reserve-handoff-boundariesat exact pushed childae489252b0e021d754bf4fae5ed4cc298f3611c6. The former whole-document, whitespace-normalized threshold scan could pass when a duplicate≥$250string existed outside the locked owner block. - The sentinel now locates the exact
Locked. Supply-reserve gate for Package activation:opening and subsequent## Implementation statusheading, extracts only that interval, and compares it with a checked-in exact multiline expectation. This includes the owner’s literal line wrapping and final blank line, so byte drift, deletion, or relocation outside that bounded block fails. No runtime Package, Territory, pricing, routing, migration, or UI behavior changed; Territory normalization remains blocked on Zak’s ruling. - Verification passed: focused 3 files / 23 tests plus app TypeScript; root
bun run verifypassed 72 files / 652 tests, TypeScript, and Vite build;bun run build:docsbuilt 10 internal + 2 client docs;git diff --checkpassed. Root opened PR #221 for this branch, added Zak as reviewer, and texted him the PR/copy delta. PR #221 is not merged and nothing is deployed.
2026-07-16 — Package reserve locked handoff and boundary proof prepared
- Created isolated branch
codex/v60-package-reserve-handoff-boundariesfrom exact v60 train head80f809e0b1e8362e99e8f598db21a569a4e0716d. The Package reserve handoff underdocs/content/owners/zak/now carries the exact owner-supplied locked block fromLocked. Supply-reserve gate for Package activation:throughThis matches HANDOFF's 60% cap.; its existing title and separate implementation-status section remain outside the block. - Added test-only protection for the literal
territory bids that cover Hot, ≥$250threshold (with whitespace normalization only in the assertion because the locked source wraps that phrase across two lines), UTC start-inclusive/end-exclusive readiness and activation-reservation regressions, and afailBatchStatementContaining = 'INSERT INTO market_purchases'bulk fault proving rollback restores the pre-existing fixture baseline with no new debit, batch, purchase, claim, portfolio, lead, or buyer-counter state. - Verification passed: focused 3 files / 23 tests plus app TypeScript;
bun run build:docsbuilt 10 internal + 2 client docs; full rootbun run verifypassed 72 files / 652 tests, TypeScript, and Vite build;git diff --checkpassed. The known resilience-test stderr is expected forced-failure coverage, not a suite failure. A separate non-runtime child commit contains only this handoff/proof/docs slice. No Package/Territory reserve arithmetic, normalization, migration, routing, pricing, UI, deployment, PR, or owner message occurred. - Next up: wait for Zak’s Territory normalization ruling, then add one shared, fail-closed territory-demand contract to both scheduler readiness and transactional prospective-reserve enforcement; do not infer a
weekly_capmoney rule before that lock.
2026-07-16 — FHC PR #219 merged into the Package #218 train
- Began a normal merge from exact Package train
0b86a6945439ee1447d77851e86d1b576cbb44dcand exact FHC PR #219d06e30936220729bb73881efbc276766e3c92952. Packageapp/and migration0033are conflict-free; #219 contributes only FHC source/guard/data/report paths and shared documentation. - Shared ledger/index/roadmap/walkthrough conflicts were resolved additively: Package #218 history remains intact, the restored #217
fhc-10plan remains verbatim and planning-only, and #219's nine strict guard/source paths match exactd06e309. The complete FHC subtree intentionally retains two preexisting v60 canonical-acquisition additions insrc/soldi-ingest*, which #219 did not touch. #219 remains source-only with no FHC deployment or public-output claim. Verification passed: rootbun run verify71 files / 648 tests, TypeScript, and Vite; FHC 457 tests / 10 files, fresh 965-page build, and audit; docs build, release JSON parse, Package/FHC/path/hash identity checks, conflict-marker scan, andgit diff --check. Commit, push, and PR #196 observation are pending. No deployment, provider action, PR merge, or Zak message occurred.
2026-07-16 — Package branch normal merge of exact FHC/train head
- Merged exact
origin/orchestrator/marketplace-v60-20260713/merge61598bc57d5282b644c64a68cce7fe9f92ccf9bfnormally into the Package repair heada5f5773a881b8b74eacb775abd03f0c8be8f5a8f. Only shared ledgers/index/implementation-note history conflicted; their resolutions retain Package sessions plus FHC PR #214/#216 train history and Zak's verbatim, planning-only FHC-10 restoration from #217. App code and migration paths had no semantic conflict. - Post-merge proof passed: Package-focused 10 files / 117 tests plus app TypeScript; root
bun run verify71 files / 648 tests, TypeScript, and Vite build; FHC 447 tests, a fresh 965-page build, and audit; docs built 10 internal plus 2 client docs; release-readiness JSON parsed; conflict-marker and diff checks passed. No deployment, PR merge, or Zak message occurred. - Next up: commit/push this normal merge for PR #218 re-review. Package remains held behind protected exact-SHA staging proof; FHC #217 remains planning-only.
2026-07-16 — Package strict staged-gate P1 closure locally verified
- Second hostile review of
fb97d99found a missing/unknown environment could accept a forged staged-ready row, whilewriteCycledisabled its reserve predicate outside exact staging.packageFulfillmentReadynow permits Package only whenAPP_ENVIRONMENTis literalstaging,PACKAGE_READINESS_SCHEDULER_ENABLEDis literaltrue, and the attested staged-ready row exists. Undefined, arbitrary, test, development, and production all fail closed. - Removed the transaction's environment-dependent reserve toggle: every billing/renewal path that passes the strict shared gate executes live supply/demand/prospective-cap SQL. The SQLite helper now explicitly opts Package tests into staging and installs canonical fixed-window Hot/PPC supply; it does not create a runtime test bypass.
- Added forged-ready no-mutation regressions for undefined, arbitrary, literal test, production, staging-missing-scheduler, and staging-false-scheduler configurations. Each leaves zero Package cycle, activation reservation, and wallet debit. An unset-environment due renewal preserves its current/predecessor cycle, one reservation, one debit, and balance; unset-environment routing creates no Package delivery or fulfillment claim and resolves to Open Market. Valid staging start/renewal proof remains covered. Focused Package plus shared-helper regression proof passed 10 files / 117 tests with app TypeScript. Full root
bun run verifypassed 71 files / 648 tests, TypeScript, and Vite build; expected forced-failure/resilience stderr was exercised test coverage, not a verification failure. No remote migration, deployment, PR, merge, or Zak message occurred. bun run build:docsbuilt 10 internal plus 2 client docs andgit diff --checkpassed.- Next up: commit/push and stop for rereview.
2026-07-16 — Package renewal reserve P1 closure locally verified
- Exact-head hostile review of
e40cf4ffound that the activation-reservation SQL could count a renewing Package as existing paid demand and add prospective+25. At 50 current Hot/PPC leads (capacity 30), that could compute 50 and reject a valid one-Package renewal. The reservation now excludes only the exact(user_id, predecessor_cycle_id)passed by the authorization predicate, so the renewal records its post-renewal 25-lead commitment while a start still counts all existing commitments. - Added staging-mode end-to-end SQLite proof: one active 25-lead Package at 50 supply, readiness recomputed for the due window, one paid successor/current subscription, successor reservation
25/50, two Package charges total, and no extra cycle/debit after a delayed replay. Corrected the stale Wrangler comment: production explicitly bindsAPP_ENVIRONMENT=production; undefined remains defensive fixture fail-closed behavior. - Focused Package reserve/billing/cancellation/successor proof passed 4 files / 30 tests with app TypeScript. Final root
bun run verifypassed 71 files / 640 tests, TypeScript, and Vite build; expected forced-failure/resilience stderr was exercised test coverage, not a verification failure. No remote migration, deployment, PR, merge, or Zak message occurred. bun run build:docsbuilt 10 internal plus 2 client docs andgit diff --checkpassed.- Next up: commit/push the corrected Package branch and stop for rereview.
2026-07-16 — Package hostile-review closure rebased over backend integrity
- Rebasing
codex/v60-package-readiness-atomic-marketfrom heldee77ddbonto exact merged backend-integrity head6f38cc1930f7c0f4638355ac6eb9a01e5692802dpreserved target0032_v60_data_integrity.sqland renamed the forward Package/Market migration to0033_package_readiness_and_market_batches.sql. No historical or merged migration was rewritten. - Package activation now creates an immutable
package_activation_reservationsrow in the same D1 batch before a cycle can transition from pending to paid. Its SQL rechecks the exact staged readiness authority, current 30-complete-UTC-day Hot/PPC denominator, valid current paid commitments, and prospective+25against the locked 60% cap. The paid-cycle trigger rejects a transition without the reservation, so two starts against 50 current Hot/PPC leads admit one 25-lead Package and roll the other transaction back with no partial charge or ownership. - Added immutable update/delete guards for
package_readiness_decisions; recomputation rechecks the literal scheduler binding before publishing state.package-router.tsnow shares billing's production/staging scheduler gate before Package eligibility or fallback evaluation, so a production copied/stale ready row cannot route Package inventory and routes through normal Market fallback instead. - Rebased the atomic 2–25 lead Market path onto the merged canonical Investor-only bucket contract. The batch guard and preflight now reject a pre-existing Market owner as well as claims/auctions; canonical Cold/Warm/Hot prices remain
$90/$150/$250, Hot remains full price, and only the documented aggregate Cold/Warm ladder affects a batch total. Bulk remains independently mergeable, non-blocking, and UI-disabled. - Focused real-SQLite proof passed 4 files / 54 tests: reserve overcommit race, scheduler disable during recomputation and before activation write, production stale-ready routing, immutable decision mutation/delete rejection, bulk replay/concurrency/insufficient-funds/already-owned, billing, and routing. App TypeScript and
git diff --checkpassed. No migration was applied remotely, no Worker deployed, no PR opened, and Zak was not messaged. - Final root
bun run verifypassed 71 files / 639 tests, TypeScript, and Vite build;bun run build:docsbuilt 10 internal plus 2 client docs andgit diff --checkpassed. Expected forced-failure/resilience stderr was exercised test coverage, not a verification failure. - Next up: push for hostile re-review. Package still needs protected exact-SHA staging scheduler/readiness/start/renew/delivery proof. Bulk UI remains disabled until reset-isolated hosted atomic purchase proof and UI-lane evidence.
2026-07-15 — Package reserve gate and atomic Market batch backend locally verified
- Added unapplied migration
0032_package_readiness_and_market_batches.sql. Package reserve records immutable, auditable staging decisions with the 30 complete UTC-day window, committed Hot demand (25 leads per active Package), observed Hot/PPC supply, result, and reason. Missing calendar days contribute zero; malformed PPC supply or Package state fails closed. The only enabling authority is the Worker scheduled callerscheduled-package-readiness-v1; production now declaresAPP_ENVIRONMENT=productionand remains disabled by default, while staging still requires an explicitPACKAGE_READINESS_SCHEDULER_ENABLED=truebinding before it can create a ready state. - Added backend-only
POST /api/v1/market/leads/purchasefor 2–25 selected leads with an idempotency key. It claims all leads, creates one immutablemarket_batchwallet debit, and then completes ownership, portfolios, delivery, and fulfillment guards in one D1 batch. A database trigger rejects incomplete, duplicate, stale, non-canonical, wrong-vertical, already-claimed, unaffordable, or budget-breaking batches before any partial economic state can commit. Canonical per-lead prices remain Cold$90, Warm$150, Hot$250; only PR #193's documented Cold/Warm 3+/5+/10+ ladder affects the aggregate batch total, so Hot remains full price. - Focused real-SQLite proof passed Package policy/replay/scheduled-caller, Package routing, legacy direct Market, and bulk concurrency/replay/insufficient-balance/already-owned cases. After control PR #213 merged, the lane fast-forwarded to exact head
515a0a807ec677eada43ed0736f35d182ee13b74, preserved its readiness artifacts, and reran rootbun run verify: 69 files / 595 tests, TypeScript, and Viteassets/index-BiQwcHs_.js;git diff --checkpassed. Expected forced-failure test stderr remained non-failing test evidence. - No migration was applied remotely, no Worker was deployed, and no buyer UI, checkbox behavior, Hot-full-price copy, or bulk tier-tease copy changed. Bulk backend is independently mergeable but is not a promotion gate; Package reserve remains a promotion gate.
- Next up: on a protected staging environment serving the exact commit, apply
0032, set the staging-only readiness binding, run the scheduled caller against real auditable supply without fabricating data, and prove Package start/renew/delivery remain disabled until the recorded 60% reserve passes. Run reset-isolated batch purchase/replay/concurrent-buyer proof there before any UI bulk activation.
2026-07-16 — Zak FHC editorial-plan restoration reconciliation
- Created a normal merge from exact train
dc3a193f89a77befedd9b185dc13efb24d8029a3and exactorigin/mainPR #2171d1af89cb73d21d8f9ad572a155c7da59b979d60. The only incoming source file issites/fhc-pages/reports/fhc-10-editorial-plan.md; its post-merge SHA-256 matches exactorigin/main, so the restored plan is verbatim. - Recorded #217 as planning-only context in current readiness and the append-only train note/index. It changes no FHC/Soldi code, launch gate, provider state, or deployment authority. Verification passed: root
bun run verify69 files / 627 tests, TypeScript, and Vite; FHC 447 tests, fresh 965-page build, and audit; docs build, release JSON parse, verbatim-plan hash comparison, conflict-marker scan, andgit diff --check. Push and PR #196 observation are pending. No deployment occurred.
2026-07-16 — marketplace v60 master-train reconciliation
- Fast-forwarded the master train to exact remote
6f38cc1930f7c0f4638355ac6eb9a01e5692802d, then created a normal merge with exactorigin/main00c296ab297a80299f1ea6230bfa18e1d0d794c6. The merge retains all v60 backend-integrity/master-readiness sessions and imports PR #214's live FHC code plus PR #216's Zak freshness/superseded-claims reports and FHC CIbun teststep. - Resolved shared docs additively:
BUILD_LOG.mdand implementation-note history were not rewritten; the v60 walkthrough retains its six-screen candidate and restores the live FHC seller-funnel slide with current #214/#216 status.CURRENT_MVP_READINESS.mdandrelease-readiness.jsonmark only the completed FHC current-main integration PASS; all Soldi staging, Stripe, retained-data, hosted-final-SHA, review, and promotion gates remain held. - Verification passed: root
bun run verify69 files / 627 tests, TypeScript, and Vite; FHC 447 tests, fresh 965-page build, and audit; docs build, release JSON parse, conflict-marker scan, andgit diff --check. The normal-merge commit is created; push and PR #196 check observation are pending. No deployment occurred.
2026-07-16 — consolidated MVP launch-control reset
- Reconciled Zak's authoritative 2026-07-16 Soldi handoff and locked follow-up rulings into
docs/plans/mvp-build-public-release/CURRENT_MVP_READINESS.md, the packet's human/machine decision surfaces, and the living v60 implementation note. Older July 6 beta status is explicitly historical. - Closed the retracted missing-transaction finding, approved Agent-mode and two-step-sign-in deviations, made bulk non-blocking but visibly gated, locked budget presets plus flexible controls, and defined Make offer as an editable calculator-prefilled activity/stage transition.
- Started five pinned Terra/high implementation lanes plus a direct-chat-only iMessage monitor and a separate
imsg stream --lookbackimprovement lane. No group chat, database migration, Stripe mutation, DNS change, or deployment occurred. - Confirmed both production
soldiandsoldi-stagingexpose active D1 Time Travel bookmarks. Restore retention/drill, exact served-SHA provenance, protected staging, Stripe sandbox acceptance, retained-data preflight, hosted desktop/mobile QA, and rollback proof remain launch gates. - Verification on exact control base
52040eb:bun install --frozen-lockfile;bun run verifypassed 67 files / 588 tests, TypeScript, and Viteassets/index-BiQwcHs_.js; packet JSON andgit diff --checkpassed. - Next: merge the readiness-control PR into #196, land and adversarially review the UI/data/Package/provenance children, land/deploy the separate current-main FHC integration, configure protected exact-SHA staging, and promote only after the canonical acceptance packet is green.
2026-07-15 — v60 backend/data integrity lane locally verified
- Added forward migration
0032_v60_data_integrity.sql: it archives/redacts synthetic placeholder contacts, canonicalizes the four buyer situations without renaming legacy IDs, and seeds the fictional Investor-onlyU_DEMO_V60profile. - Reconciled the demo statement exactly:
$5,000.00funding less$90.00 + $150.00 + $250.00typed Open Market purchases equals$4,510.00; every pre-owned demo lead has a typed purchase, portfolio/stage, delivery, and ledger row. No activation rows are seeded. - Removed current worker output/generation for quality, held balance, live-transfer/recording, and source-bucket residue; locked refunds to the nine approved shared enum values; exposed Territory position; and rejected Hot claims under
$250. - Verification after the target-head integration: focused 8 files / 130 tests, final disposable local D1 migrations
0001–0032with0placeholders /451000demo cents /3purchases /0activation rows /0recording-note residue, and rootbun run verify68 files / 592 tests, TypeScript, Viteassets/index-BdJy0tCO.js; docs build passed. No deployment or remote D1 operation occurred.
2026-07-16 — v60 buyer marketplace deployed to staging for Zak review
- Stood up the
soldi-stagingreview environment: addedenv.stagingtoapp/wrangler.jsonc(workersoldi-staging, workers.dev only, no soldi.cc route) bound to an isolated remote D1 (soldi-staging, id516586fe…). Never touches prod workersoldi/ prod D1 /app.soldi.cc. - The pre-provisioned staging D1 carried a drifted double migration lineage (old
0026_refund_transaction_integrityetc. layered under the current v60 names →0029collided onrefund_request_claims, demo user absent). Recreated the throwaway scratch DB clean and applied 0001–0031 fresh: 10 users, 65 leads,demo@soldi.ccrestored. - Built the merge tip (
3aa9251) in an out-of-repo sandbox (repo node_modules are macOS-owned), deployedwrangler deploy -e staging→ version5dc8894e. Secrets set on-e staging: SESSION_SECRET (fresh), FHC_INGEST_SECRET, Stripe test-mode placeholders (STRIPE_EXPECTED_MODE=test). - Live proof at
https://soldi-staging.camolechowski.workers.dev:/api/v1/health200; anon/auth/me{user:null};/auth/demo302 → session; authed/auth/me=demo@soldi.cc($1,000 wallet);/market/leads11 rows with source-based pricing;/pipelinestaged cards + seller contact. Browser: Open Market + Payment & Budget render Zak'sf8b192b1:1 — tier pills, $90/$150/$250 in-table, deposit bonus tiers, three-ways-to-buy; Package shows gated ("Activation opens after automatic fulfillment routing is installed"). Zero console errors. - Still gated before real buyers (unchanged): supply-reserve Package activation, server-atomic bulk
buy, delivery dispatch — all render disabled/parked. Auctions/realtime parked (
AUCTIONS_ENABLED=false). - Sent Zak (DM only) the staging URL + demo login to confirm his UI + backend wiring. Not merged to
main; prodapp.soldi.ccuntouched.
2026-07-15 — Zak v60 six-screen fidelity correction
The shipping app now ports the pinned f8b192b v60 buyer mock as one cohesive product instead of translating it through the older app shell. The buyer contract is Open Market, Payment & Budget, My Leads, Transactions, Territories, and Settings with literal v60 colors/type/density, the compact navigation and help/referral utilities, canonical four-situation vocabulary, fixed Cold/Warm/Hot pricing, and no public competition, retired buyer-route, or realtime-buyer layer. Direct legacy URLs redirect into the v60 spine and the corresponding public worker endpoints were removed.
The port preserves backend truth: My Leads has ownership-scoped persisted notes and real event history plus revenue and wholesale calculations, and its Package tag/filter derives from an ownership-matched package_deliveries record in the real pipeline response; Territories shows real situation-scoped trailing-30-day classified volume and the highest active bid. Zak's PR #209 locks Package eligibility at committed Hot demand no greater than 60% of 30 complete Hot/PPC supply days, with each Package counting 25 and cold-start missing days counting zero. Activation stays unavailable until that rule and the staged caller are implemented/proven. Transactions Resend, Settings notification/delivery/test-lead controls, and multi-lead purchase remain explicitly unavailable pending their delivery or atomicity contracts. Zak received the buyer-visible copy/functional delta before merge.
Verification: mandatory Sol/medium and Terra/high polish/simplify passes completed; focused Package attribution proof passed 5 files / 31 tests, including real SQLite Package routing into the authenticated pipeline. The first full-range exact review then rejected candidate 6dcc205 for two blank mobile receipts, legacy buyer client/taxonomy contracts, situation-insensitive Territory context, and stale Package-policy docs. The remediation passed 9 files / 60 tests, app TypeScript, client-vocabulary and <400 scans, then final bun run verify passed 66 files / 582 tests, TypeScript, and Vite assets/index-C58kQCpa.js; bun run build:docs built 10 internal + 2 client docs + index; git diff --check passed. Local browser QA covered all six routes at 1440×900 and 390×844 with no page overflow, retired visible/accessibility vocabulary, or console errors. The two mobile receipts were recaptured after the source graph settled, and a measured 390px mock comparison additionally corrected the Open Market table from forced horizontal scrolling to the mock's natural clipped composition before accepting the final image. Twelve dated local candidate captures live under docs/shots/v60-*-20260715.png; they are evidence for this branch, not deployed proof.
Next: commit the exact candidate, obtain fresh exact-head Sol/medium and Terra/high read-only verdicts, open the single ready PR against the v60 launch train with killerabbasi requested, and merge after QA. Promotion remains frozen until canonical staging is provisioned at the exact merged SHA and passes reset-isolated Stripe, import, purchase, refund, security, desktop, and mobile acceptance.
2026-07-15 — Admin import and Package routing exact-review remediation
- Remediated committed import/routing head
a82abe06c763de235d374e982037c46d03f1d939without amending it. Sol/medium and Terra/high had rejected that head for D1 resource exhaustion at 100 rows, Package terminal replay, and a Territory-priority race; the fixes remain a separate follow-up commit. - Replaced unbounded per-row duplicate/price-band reads and five writes per row with set-based preflight plus a nine-statement
json_each()transaction. The maximum-size regression imports 100 rows with at most 16 total test-D1 operations. Raw JSON is streamed and rejected before parse above the worst-case envelope for the decoded 1 MB CSV limit. - Package reservation, completion, and Market fallback now atomically exclude every currently eligible Territory order using the canonical active/account/wallet/budget/week/bid/filter contract. Package buyers must also satisfy the complete canonical investor profile. Terminal Package allocation replays the same portfolio without requiring a Territory standing-order ID.
- Added forced post-reservation rollback, repeated Admin approval, malformed Package profile, newly eligible Territory, expired processing/finalizing recovery, terminal replay, and no-Market-leakage real-SQLite coverage. Recovery now permits an expired
finalizingno-winner claim to resume the Package/Market waterfall while protecting debited/committing Territory money states. - UI success and refresh are separate truths: a committed receipt remains successful if the Admin queue refresh fails, with one distinct reload advisory. The inline confirmation no longer claims modal semantics. Direct UI proof passed 7/7; focused backend proof passed 5 files / 25 tests.
- Real Worker-backed local browser QA passed the non-mutating Admin interaction at 1440×900 and 390×844: keyboard confirmation/Cancel, exact sample preservation, zero import batches, and no overflow. The fresh dated screenshot is
docs/shots/admin-supply-import-20260715.png. - The same browser pass found a separate staging blocker: with the required default
AUCTIONS_ENABLED=false, the global ticker repeatedly opens the parked floor WebSocket, producing 15 HTTP 410 console errors. AnAUCTIONS_ENABLED=trueisolation control made the Admin pages console-clean, but does not replace the default-off finding; a narrow client-socket child must land before hosted zero-console acceptance. - Fresh bootstrap applied migrations
0001–0031; rootbun run verifypassed 59 files / 553 tests, TypeScript, and Viteassets/index-Mb9NuFr6.js;git diff --checkpassed. The Admin identity fence is deliberately scoped to Admin CSV, andpackage_fulfillment_stateremains disabled pending supply-reserve policy and staged-caller proof. - Follow-on exact review found three P1 seams in that proof: SQLite's ASCII-only
lower()diverged from JavaScript for valid Unicode Territory filters, finite raw/full-width historical candidate expansion was not complete NFKC duplicate safety, and stalefinalizingrecovery trusted a persisted Territory order without rechecking its current bid/filter/economic eligibility. - Corrected migration
0031in place because it remains unshipped. Leads and Standing Orders now persist application-owned NFKC/case match keys. Package reservation, completion, and Market fallback use one shared current-Territory SQL expression; inspection and reproduced failure proved its lead-ID placeholder preceded the weekly-cap time placeholder, so shared bind helpers now follow the actual SQL order. Legacy uncanonicalized Territory rows fail closed rather than leak to Package/Market. - Every current lead ingress writes one canonical
property_identity_key. Admin CSV compares that indexed key directly and stops before writes if any historical lead lacks one, avoiding incomplete compatibility-form enumeration while keeping the returned legacy probe bounded to one row. - Expired
finalizingrecovery now revalidates the persisted order against current filter, bid, wallet, monthly budget, and weekly cap before debit. An invalid winner is released toprocessing, then the current winner is selected or the Package/Market waterfall resumes; existingdebitedandcommittingsafety remains unchanged. Real-SQLite proof covers bid, wallet, budget, cap, filter, no-winner, concurrent replacement, and protected money-moved recovery. - Root review caught and removed an ASCII post-insert trigger that lowercased raw Territory values without application-equivalent trim/whitespace collapse, then tightened the existing-row migration backfill to printable, already-trimmed ASCII with no doubled spaces. Missing or unsafe keys remain null and fail closed. Final focused proof passed 7 files / 52 tests, including post- and pre-
0031whitespace rows with zero Package/Market writes and unchanged ownership. Fresh bootstrap applied0001–0031; fullbun run verifypassed 60 files / 572 tests, TypeScript, and Viteassets/index-Mb9NuFr6.js; docs built 10 internal + 2 client docs + index. Migration0030retained SHA-2565f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6; diff, secret, staging, and under-400-line hygiene passed. No app UI changed, so the existing dated Admin screenshot remains accurate; no deploy, commit, push, remote database, or Stripe operation ran. - Exact-head follow-up at
63d69769f0bd57cdc2f6bce0c0a11fb72e109045removed raw state from Package eligibility and candidate binding. Reservation and completion now compare validated buyer markets to persistedterritory_state_key; lower, mixed-case, surrounding-whitespace, and full-width raw states all Package-deliver and terminally replay with zero Market reservation/decision. - Property identity is now a compact canonical JSON tuple rather than delimiter concatenation. Migration
0031safe-backfills that exact encoding, deliberately aborts on safe-key duplicate groups, and creates a partial unique index over every non-null key. The fence is global across FHC, manual, and CSV writers; route conflicts return honest409responses, and a failed signed FHC duplicate releases its unused event claim. Unsafe/null history retains the explicit Admin-import backfill gate. - Production/staging gate: run the read-only admitted-subset duplicate preflight before
0031; after application, use application-owned NFKC code to backfill remaining null keys under the unique index, resolve every surfaced collision, and prove zero null keys before Admin import can proceed. Package fulfillment remains disabled independently. - Final proof passed the exact prior seven-file selection at 61/61 tests (up from 52), then root
bun run verifyat 60 files / 581 tests, TypeScript, and Viteassets/index-BNeffjG7.js. Fresh local bootstrap applied0001–0031; the resulting database had the partial unique fence and zeropackage_fulfillment_staterows. Docs built 10 internal + 2 client docs + index. Migration0030retained SHA-2565f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6; diff, secret, and under-400-line changed-source checks passed. No commit, push, deploy, remote mutation, or staged change occurred. - R5 exact review closed the signed FHC idempotency gap. Migration
0031deletes historical event rows with no durable lead, then adds explicitprocessing|completedstate with surviving history defaulted completed. New claims are processing; the lead/consent/audit transaction completes the exact event as its final statement. Completed replay requires its lead, while concurrent/fresh processing and unreconciled orphans return retryable409, never a phantom ID. - Every claimed lead-batch exception now attempts exact processing-claim cleanup. Property conflicts retain honest
409; other pre-commit failures rethrow only after release, and after-commit ambiguity preserves the completed event because its lead exists. A conservative 10-minutereceived_atlease reclaims only exact stale processing rows without a lead; fresh, invalid-timestamp, and durable-lead claims fail closed. Real-SQLite proof covers concurrent replay → first rollback/cleanup → same-event success, completed replay, after-commit ambiguity, historical/post-migration orphans, and fresh/stale/durable lease behavior. - R5 final proof passed the exact seven-file selection at 65/65 tests, fresh bootstrap applied
0001–0031, and rootbun run verifypassed 60 files / 585 tests, TypeScript, and Viteassets/index-BNeffjG7.js. Docs built 10 internal + 2 client docs + index; migration0030retained SHA-2565f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6; diff, secret, staged, and changed-source line hygiene passed. No commit, push, deployment, or remote action occurred. - Reconciled the import candidate with launch-train parent
0e73669452c702ec44206b103471e87066763c9a, preserving the independently reviewed realtime remediation and both append-only histories. Post-mergebun run verifypassed 64 files / 611 tests, TypeScript, and Viteassets/index-DawYam7T.js; docs built 10 internal + 2 client docs + index and staged diff hygiene passed. No hosted or deployment claim is implied. - Final exact-review remediation replaces the signed-event zero-change completion update with an immutable
fhc_ingest_completionsgeneration guarded by migration triggers. The assertion is the final statement in the lead/consent/audit D1 batch: an owner superseded after live stale-lease takeover raisesfhc_ingest_ownership_lostand rolls back all success writes; the valid owner completes exactly once and later replays200 duplicate:true. Completion identity is(event_id, lead_id), preserving immutable old proof while allowing the existing completed-orphan reconciliation path to reclaim an event under a new lead generation. - Expired
processingandfinalizingTerritory recovery now carries persistedacquisition_sourceinto source-filter matching. Real SQLite proves PPC/organic-as-inbound produces one Territory debit/delivery and zero Package/Market reservation or decision rows. - Red-first proof failed the live takeover and both source-filter recovery cases, and separately reproduced the first completion schema stranding completed-orphan reclaim. Final focused proof passed 7 files / 69 tests; fresh bootstrap applied
0001–0031with zero fulfillment/enabled rows, zero property-key nulls, the partial unique property index, and the completion ownership trigger. Rootbun run verifypassed 64 files / 615 tests, TypeScript, and Viteassets/index-DawYam7T.js. The earlier realtime ledger line and blank separators were restored byte-for-byte to the launch-train parent. - Final r7 review found no runtime, migration, or money-path defect. Terra/high returned READY after an additional three-generation completed-orphan probe; Sol/medium rejected only the strict file-hygiene gate because candidate-owned
admin-territory-allocation.test.tswas exactly 400 lines, and reported two stale-doc nits. The narrow follow-up compacted one adjacent pair of test-harness fields to 399 lines without changing coverage, dated the changed Supply Side PRD 2026-07-15, and replaced the walkthrough's already-completed socket source task with the remaining exact-SHA zero-network/console-noise acceptance gate. - Post-correction proof passed the exact 7-file / 69-test selection and root 64-file / 615-test verify, TypeScript, Vite
assets/index-DawYam7T.js, and the 10 internal + 2 client docs + index build. The complete candidate line scan now tops out at 399 lines,0030retains SHA-2565f50c65cd754f122f13ba9f2a6619d277529e3fe80d7b987ee7df7237ef728b6, and diff/secret-shape hygiene passed. Direct make-it-sexy then make-it-simpler review preserved the existing walkthrough visual system and reduced the correction to one current acceptance sentence; no app or public seller/buyer copy changed. - Next: fresh exact-head review/CI. Keep Package fulfillment disabled until the supply-reserve policy and staged-caller proof are resolved; the default-off client floor socket is closed by the separately merged realtime remediation below.
2026-07-15 — Exact-head realtime review remediation 2
- Started clean from committed local-source head
f25eb5a85038fb0f00b294506bb5b750999e5475and implemented every P1/P2 in the Sol and Terra exact-head rejection receipts without touching the server gate. Capability checks now retain only one concurrent in-flight request; every new room/topic effect and every reconnect obtains a fresh parsed health result, and only literal booleanauctionsEnabled: truecan construct a socket. - Bound connection truth, event history, and the WebSocket reference to the exact topic key. A topic change immediately exposes Checking/Linking with empty events, rejects sends through the prior room's socket, and resets ChatPanel messages, presence, hello seeding, and draft state. Drafts intentionally survive capability/socket transitions within one auction but clear when
auctionIdchanges to prevent cross-room intent leakage. - Chat is sendable only when capability is enabled and the exact-topic socket reports open. Checking, connecting, degraded, and parked inputs/buttons are disabled;
sendreturns acceptance and a failed/racing delivery leaves the draft intact. - Deleted the unused fabricated
MOCK_TICKERfixture. The ticker marquee now exists only while connected and only after verified floor frames arrive; Checking, Parked, and Linking retain their neutral status messages, while an open room with no verified events saysNo auction activity yet. - Exact visible copy deltas: checking composer
Message the room…→Checking chat availability…; enabled/connecting composer →Connecting to auction chat…; enabled/degraded composer →Reconnecting to auction chat…; open/no-event ticker →No auction activity yet.ParkedAuction chat is paused., ticker Checking/Parked/Linking/Live labels, and their existing status sentences remain unchanged. - Direct make-it-sexy review preserved Zak's font, token, density, status-frame, spring, and reduced-motion language with no redesign. Direct make-it-simpler reuse/quality/efficiency review removed the now-dead fixture, retained the shared
apiGet('/health')owner, coalesced only concurrent checks, keyed state instead of adding caller-specific gates, and added no recurring polling or redundant work. - Verification: focused capability/realtime/chat/ticker proof passed 4 files / 26 tests. Full
bun run verifypassed 58 files / 549 tests, TypeScript, and Viteassets/index-CBSuz7Uh.js; docs build and diff hygiene passed. Final secret-shape and changed TypeScript/TSX line gates also passed. - Next: exact-head rereview, then exact-served-SHA staging/browser proof. No commit, push, deploy, remote mutation, or hosted claim occurs in this remediation.
2026-07-15 — Default-off realtime remediation after polish/simplification review
- Read the mandatory reuse, quality, and efficiency receipts before editing the uncommitted realtime gate. Replaced its second raw
fetchpipeline with the sharedapiGet<unknown>('/health')boundary; the capability reader now owns only literal-true interpretation, fail-closed rejection handling, and shared request lifecycle. - Corrected compatibility truth: a room starts and remains
connectingwhile the health capability is unresolved, so existing status-only consumers such as ChatPanel renderLinking/loading rather than a falseOfflinestate. Resolved false/unavailable capability remainsdegradedand constructs no socket. - Reconnect now centrally revalidates the shared capability before constructing another WebSocket. A previously true long-lived tab converges to parked when a subsequent health result is false; simultaneous callers share the in-flight refresh instead of fanning out health reads.
- Ran the required direct make-it-sexy review before the direct make-it-simpler review under the no-subagent constraint. The ticker retains its existing restrained, reduced-motion-safe presentation and accessible status region; the remediation introduces no decorative visual churn. Simplification retained the distinct capability/status states because deployment authority and socket health are separate, and made the retry test deterministic.
- Zak-facing visible copy now stays exact: ticker uses
Checking/Checking auction activity status.,Parked/Buyer auction activity is paused.,Linking/Auction activity is linking., andLive/Auction activity is live.. Parked chat usesParked,Auction chat is parked., andBuyer auction activity is paused.; its composer placeholder becomesAuction chat is paused.and is disabled without clearing a typed draft. The priorOffline,Room offline., andReconnecting to the floor…wording remains only for a real degraded socket after capability has been enabled. - Verification: focused capability/realtime/ticker/chat proof passed 4 files / 16 tests. Full
bun run verifypassed 58 files / 539 tests, TypeScript, and Viteassets/index-D83LrtWy.js;bun run build:docspassed andgit diff --checkwas clean. No commit, push, deploy, remote, or screenshot recapture occurred. - Next: root review/commit integration, then repeat default-off and true-to-false reconnect browser/network proof against the exact served staging SHA. No hosted claim is made by this local receipt.
2026-07-15 — Default-off realtime client capability gate
- Started from exact v60 integration head
771d1f122a4a6e6c37a7e1005bfe6ff9ed371ab2oncodex/v60-realtime-default-off. The server-side410and exact-stringAUCTIONS_ENABLEDcontract remain unchanged. - Added one cached
/api/v1/healthcapability read shared by alluseRoomcallers. Only an OK payload with literalauctionsEnabled: truepermitsnew WebSocket; false, absent, malformed, non-OK, and rejected health reads all park floor and auction sockets before construction. - Kept enabled realtime reconnect/history behavior intact and made pending-health/unavailable lifecycle cancellation-safe. A health result arriving after unmount cannot update state or open a late socket.
- The global ticker remains in the layout but hides seeded auction activity until capability is proven. Default-off and indeterminate states now show a neutral
Parked/Buyer auction activity is paused.state instead of browser handshake errors or promotional copy. - The repo's historical polish workflow could not run as written because it delegates to agents and its four local group skill directories are absent. A direct make-it-sexy pass retained the established refined ticker, tokens, layout, and reduced-motion behavior; the required subsequent direct make-it-simpler pass removed disabled-state marquee work and found no further justified abstraction.
- Focused capability/realtime/ticker proof passed 3 files / 10 tests. Full
bun run verifypassed 57 files / 533 tests, TypeScript, and Viteassets/index-TybY-1Xh.js; every touched TypeScript/TSX file is under 400 lines andgit diff --checkpassed. Local browser evidence showed one health request, visible parked copy, and no/api/v1/rt/*request for the isolated page. No commit, push, deployment, PR, or remote application-service mutation occurred. - Next: root review/commit integration, then repeat the default-off browser console/network check at the exact served staging SHA. The enabled-path unit proof is green; no hosted or deployed claim is made here.
2026-07-15 — Package final correction: exact successor ancestry and replay truth
- Continued the uncommitted correction above rejected Package head
29e4d7aoncodex/v60-persisted-package-billing; no prior commit was amended and no remote, deployment, commit, or push occurred. - Added nullable unique
package_cycles.predecessor_cycle_id, populated only from the expected subscription cycle in renewalwriteCycleand protected by cycle immutability. All three early successor settlement authorization boundaries and migration0030's economics trigger now require the persisted predecessor link, same user, exact observed/end-to-successor-start boundary, and predecessor due at settlement time. - Added real SQLite adversarial coverage for foreign, mismatched, self/non-adjacent, future-due, and same-user exact-boundary look-alike intents; none can settle or mint a shortfall credit. The legitimate predecessor remains recorded and the one-delivery renewal-before-intent race credits only
$4,800before successor cancellation. - Added direct absent-readiness proof for renewal and delivery; structured 402 Package start envelopes now survive the API boundary and Billing distinguishes immutable
payment_requiredreplay from later active or cancellation-pending current truth without a false activation/Add $0claim. - Split scheduled, Market, and settlement test responsibilities into small fixture/case modules; the strict base-to-working-tree TypeScript/TSX line gate is rerun at closeout. The direct make-it-sexy then make-it-simpler pass kept the existing refined Billing system, focus trap/return-to-opener, reduced-motion behavior, and state-specific truthful copy.
- Fresh bootstrap first encountered local SQLite
SQLITE_IOERR_SHMSIZEwith only 121 MiB free; after ignored reproducible state/cache cleanup, a fresh retry applied migrations0001–0030. Corrected focused proof passed 13 files / 84 tests; fullbun run verifypassed 54 files / 523 tests, TypeScript, and Viteassets/index-Bwbik46R.js. Docs/diff/count gates follow this entry.
2026-07-15 — Persisted Package billing and shared fulfillment ownership
- Added migration
0030_persisted_package_billing.sql: immutable Package cycles useUNIQUE(user_id, period_start), unique request and wallet identities, fixed 500,000-cent/25-lead economics, Package-specific schema readiness, and completion guards whose explicitNOT NULLkeys make any zero-row D1 batch roll back. - Added D1-backed
GET /package,POST /package/start, andPOST /package/cancel. Activation and each deterministic UTC anniversary spend promotional funds first, preserve one immutable debit split, clamp the original anchor to short-month last days, create no entitlement onpayment_required, and keep cancellation effective at the current paid period end with no refund. - Wired Package renewal into the scheduled worker independently of the default-off auction paths. Renewal and cancellation contend on the same subscription status/current-period-end predicate, so overlap cannot both advance the subscription.
- Added database-wide
lead_fulfillment_claimsownership used by direct Market, Territory, and Package. The explicit Package delivery seam accepts trusted already-classified Hot/PPC supply, stays within the paid cycle and 25-lead quota, creates portfolio/stage/general delivery/Package attribution, and never incrementsbudget_spent. Automatic selection, fabrication, and import remain outside this child. - Replaced localStorage Package state and Billing's optimistic wallet debit with typed server calls and explicit loading, active, cancellation-pending, and payment-required UI truth. The required UI polish and simplification passes ran directly because this lane prohibited subagents; the existing production screenshot was not recaptured because this branch is not deployed and the walkthrough now labels it source/local-test only.
- P1 correction: every paid cycle now records one completion-guarded settlement before renewal or due cancellation can advance. The automatic credit is
(25 - delivered_count) * $200; it reverses the unused original debit tail purchased-first and then promotional, writes one immutablepackage_shortfallwallet reference, and records a durable zero-credit outcome after all 25 deliveries. Concurrent/repeated settlement cannot double-credit. Client request keys and billing completions are scoped by authenticated user instead of globally. - P1 verification: fresh local bootstrap applied migrations
0001–0030; focused proof passed 8 files / 75 tests; fullbun run verifypassed 47 files / 508 tests, TypeScript, and Viteassets/index-DAahTaMR.js. Docs build andgit diff --checkpassed. - Final response-loss recovery: Package start retains one browser idempotency key across ambiguous retries, refreshes D1 truth after a lost response, and preserves a concurrent
cancel_at_period_endresult. Terra/high reran the required sexy-then-simpler gate; focused Billing passed 10/10 and finalbun run verifypassed 47 files / 510 tests, TypeScript, and Viteassets/index-B9z8NYv_.js; docs build and diff hygiene passed. - Exact-head review rejected immutable head
29e4d7acb73f1ec1a89a0019c02aaee42f5a2518for four P1s: due cancellation could lose to renewal and report plain active state; migration0030did not bridge recoverable pre-existing Territory debits; automatic fulfillment had no installed caller despite purchasable UI promises; and Billing could not restart a fundedpayment_requiredbuyer. Sol also identified mutable idempotency replay semantics as P2. - The correction persists cancellation intent and reconciles both race orderings, including immediately crediting/canceling a successor that renewed first. Migration
0030now bridgesdebitedto shared claimed ownership and committed/allocated recovery to completed ownership with exactterritory:<claim_token>fencing, while aNOT NULLpreflight aborts unsupported or ownerless legacy state. - Migration
0030createspackage_fulfillment_stateempty. GET reportsfulfillmentReady=false; activation, renewal, explicit delivery, and Billing charging fail closed until the Admin CSV/routing child installs the actual caller and inserts the enabled row. Funded buyers can start a new immutable cycle frompayment_required; old request replays retain their original 402/201 outcome regardless of later subscription/readiness state. - Correction verification: fresh bootstrap applied
0001–0030; focused upgrade/race/cross-channel/route/security/Billing proof passed 12 files / 103 tests. Terra/high then ran the mandatory make-it-sexy group followed by make-it-simpler directly on the corrected Package UI/API files; the dialog now traps forward/reverse focus, closes consistently, and returns focus to its opener. Focused Billing passed 11/11. The final corrected and polished tree passed 49 files / 517 tests, TypeScript, and Viteassets/index-7kTP1dMe.js; all touched TypeScript/TSX files remain at or below 400 lines. - Docs built 10 internal plus 2 client documents and the index;
git diff --checkpassed. A rootbun testattempt was discarded because it bypassed the configured Vitest/Node-SQLite runner. No remote service, push, deploy, PR, or screenshot recapture ran; corrections remain separate from the immutable rejected implementation commit. - Baseline before edits passed 46 files / 489 tests, TypeScript, and production build. Fresh local bootstrap applied migrations
0001–0030; final focused proof passed 8 files / 66 tests; fullbun run verifypassed 47 files / 499 tests, TypeScript, and Viteassets/index-Bnw2mWu_.js; docs build andgit diff --checkpassed. Expected forced rollback/compensation stderr, the pre-existing duplicateSO_1Territory key warning, and Vite's bundle-size advisory remain non-failing diagnostics. No commit, push, deployment, remote D1/Stripe access, or other remote mutation ran. - Next: Admin CSV/import integrity, then route only trusted classified Hot/PPC supply into the explicit Package delivery seam before exact-SHA staging acceptance.
2026-07-14 - Wallet subledger and exact-refund integrity child
- Started from exact v60 master
5ae63047773a561da57df9c26d4832449a5b3c1doncodex/v60-wallet-refund-integrity. The resolved contract is promotional-first spending, no MVP promo expiry, and exact reversal of the original purchased/promotional debit split. - Added migration
0029_wallet_subledger_refund_integrity.sql.users.balanceremains the public total, purchased plus promotional components must reconcile to it, and held balance must remain covered. Historical totals are preserved exactly as purchased/zero promotional because older provenance cannot be reconstructed; historical ledger rows receive conservative splits and are sealed immutable. - Classified new money at its trusted source: signup and the server-snapshotted verified Stripe funding bonus are promotional; verified Stripe principal and localhost-only fixture deposits are purchased. Checkout fails closed before provider work when the complete wallet schema marker is absent, and signed provider replay retains its existing unique economic fences.
- Ported direct Market and Territory allocation to promotional-first component debits. Market claims the exact observed component snapshot so a concurrent Stripe credit makes the stale attempt retry instead of spending purchased funds ahead of promo. Territory persists a token-owned pending ledger/debit split, compensates only while unsealed, records durable commit completion, and seals the row before final allocation.
- Bound each eligible refund request to exactly one proven Market/Territory debit. Foreign-key-safe parent-first creation is serialized by a partial unique pending-portfolio index. Approval permanently records one portfolio/source-debit outcome and restores the original split once; decline completion is constraint-backed. Unresolved historical provenance remains declineable but cannot mint funds.
- Code-first rollout is fail-closed: registration, provider/local wallet funding, Market purchase, Territory entry, refund request, and Admin refund decision return retryable
503 wallet_schema_not_readyuntil the exact marker and every required table/column exist. Read-only Admin refund listing and Stripe Portal access remain available. - Remote preflight was read-only. Staging had zero invalid user/hold rows, unknown wallet types, duplicate economic references, duplicate approved/pending refunds, or in-flight Stripe sessions. Production predates migrations
0025–0028; its two repeatedstripereference groups are known legacy fixture groupings, not provider economic replay. Every query reportedchanged_db: false. - Fresh local bootstrap applied migrations
0001–0029. Real SQLite with foreign keys enabled proved all seeded historical rows sealed, UPDATE/DELETE rejected, parent-before-claim accepted, and a second pending refund rejected and rolled back. Sol's first immutable-head audit then reproduced a committed-before-seal Territory deletion window missed by Terra's initial approval. The narrowed trigger now permits compensation deletion only before durable commit completion; real-schema proof covers pending deletion, committed deletion rejection, the sole seal transition, and sealed UPDATE/DELETE rejection. Focused wallet/refund proof passed 50/50; finalbun run verifypassed 46 files / 489 tests, TypeScript, and the production Vite build;git diff --checkpassed. - Sol/medium completed the required walkthrough make-it-sexy pass, splitting dense wallet/refund proof into shorter fact-preserving bullets; the direct Terra/high make-it-simpler pass found no further safe compression. Docs build and file-scoped diff check passed. No app UI changed, so the existing Billing/Admin screenshots remain accurate and were not recaptured.
- No remote D1 migration, Stripe mutation, deployment, commit, push, or PR publication ran during implementation. Next: exact-head Sol/Terra review, ready child PR with Zak requested, then persisted
$5,000Package billing.
2026-07-14 - Buyer-auction mutations parked for MVP
- Started from exact clean base
b1b870931916f6fa1b107246fcf7ea22fd985a64oncodex/v60-park-auction-mutations. The product decision is explicit: buyer auctions are post-MVP, so this slice parks their mutation reachability rather than repairing or broadening auction economics. - Added one exact-string
AUCTIONS_ENABLEDpolicy. Onlytrueenables it; missing,false,TRUE,1, whitespace, and other malformed values remain off. Disabled bid and buy-now POSTs return410 { error: "feature_unavailable" }at the Worker boundary before browser/session auth, request parsing, D1, wallet, ledger, portfolio, or realtime work. - Closed every P0 alias from Terra's read-only plan: cron, exported settlement/restock helpers, Worker WebSocket dispatch, direct
routeRealtime, andbroadcastToRoomall fail closed before D1 or Durable Object access./api/v1/healthexposes onlyauctionsEnabled: boolean; no raw binding value is returned. - Preserved read-only auction GETs, auction/bid tables, Durable Object classes/bindings, realtime event code, archived
A_MARKET_SENTINEL, direct Market purchase, and Territory allocation. No UI or migration changed, and no cleanup/deletion path was added. - Read-only production D1 preflight: 27 active, 3 discount, 2 ended-sold, and 1 archived sentinel auction; zero active/discount auctions have bids; two users have 21,500 held cents but neither is a leader on a current lot; 14 portfolios use the sentinel. The stale holds pre-exist and require separate reconciliation, not writes in this slice.
- Read-only staging D1 preflight: one archived auction, zero active lots with bids, zero held balances, and zero sentinel portfolios, but lookup of
A_MARKET_SENTINELreturned no row. Staging reset/provisioning must restore the sentinel before Market/Territory testing. Every production and staging query reportedchanged_db: false. - Operational gate: default-off can strand existing leader holds because bid/buy-now/settlement are all parked; re-enabling can make the next cron immediately settle overdue lots and charge held winners. Reconciliation of stale holds/lots/timestamps is a separate reviewed operator action; this slice performs no cleanup writes.
- Evidence: frozen install and baseline full verify passed 43 files / 410 tests, TypeScript, and Vite. Final post-Terra gate, enabled-mode, realtime, Market-sentinel, and Territory-sentinel coverage passed 8 files / 98 tests; full verify passed 44 files / 442 tests, TypeScript, and Vite
assets/index-COujzqxe.js. Docs build and diff check passed. Sol/medium completed the mandatory walkthrough make-it-sexy pass and corrected one stale wallet-status sentence; Terra/high completed make-it-simpler with no further edit. Expected forced rollback/compensation stderr, the pre-existing duplicateSO_1test key, and the Vite bundle advisory remain non-failing diagnostics. No commit, push, PR, deploy, remote write, or secret mutation ran. - Next: complete the local closure gates and exact diff receipt. Before any staging acceptance run, rebuild/reset staging through the canonical migrations so
A_MARKET_SENTINELexists; before any eventual auction re-enable, audit and reconcile overdue lots and holds explicitly.
2026-07-14 - Atomic direct Market purchase child slice
- Started from exact clean base
f4c9a8ec8d3eb6e6b79207b680ea8b4ba7c1f88foncodex/v60-atomic-market-purchase; read PR #180 commit47e4393only as semantic prior art and did not cherry-pick or merge it. - Added migration
0028_atomic_market_purchases.sql: one immutable unique claim per direct-Market lead binds authenticated buyer, canonical acquisition/tier, ruled server price, portfolio, and delivery channel. A partial unique Market-ledger index adds a second durable double-charge fence. - Reworked
POST /market/leads/:id/buyso request bodies cannot supply buyer/tier/price, canonical acquisition sets Cold$90/ Warm$150/ Hot$250, vertical/account/balance/budget/state are rechecked inside the claim, and one D1 batch owns sold state, wallet debit, ledger, portfolio/stage, and delivery. Same-buyer retries return the existing outcome; competing buyers receive409. - Public Market list/count truth now matches charge truth: pending/unclassified, invalid stored-readiness-price, any auction-owned/history row, and non-
open_marketTerritory-claim rows are excluded; returnedmarketPriceCentsis derived from canonical acquisition. The same ownership fences are repeated in purchase preflight and the atomic claim. Terra/high caught that checking only active/discount auctions left anended_soldcross-channel double-sale path because buy-now does not updateleads.market_status; the corrected invariant rejects every auction row without rebuilding the parked auction product. - Read-only migration preflight against production D1
soldifound 11 historical Market ledger rows and 0 duplicatereference_idgroups; staging D1soldi-stagingfound 0 Market rows and 0 duplicates. Both queries reportedchanged_db: false, so the partial unique Market-ledger index has current-data deployment proof as well as fresh-schema proof. - Refreshed
docs/walkthrough.htmlso the wallet release slide no longer calls atomic Market purchase unbuilt: it now labels the child implemented and fresh-local-D1 proven but not merged/deployed, and carries forward wallet/refund, Package, parked-auction, and exact-SHA staging gates. - Evidence: frozen install green; initial Market/security/rules suite 102/102; post-review cross-channel suite 42/42; fresh isolated local D1 applied migrations
0001–0028and exposed the claim table plus both indexes; post-remediationbun run verifypassed 43 files / 410 tests, TypeScript, and Viteassets/index-COujzqxe.js; docs build andgit diff --checkpassed. - No UI, FHC, Package, refund, import, auction behavior, deploy, remote D1, Stripe, commit, push, or PR mutation. Next after verification: wallet purchased/promotional subledgers and exact refund integrity remain separate children.
2026-07-14 - PR #196 reconciled with live FHC main
- Fast-forwarded the master worktree to exact remote PR #196 security head
408e801, whose GitHub CI passed app verify and FHC audit, then normally merged currentorigin/main184a7a7after PR #199/receipt PR #201. - Product, Worker, migration, FHC source, and asset trees merged without conflict. Resolved only
BUILD_LOG.md, the implementation-note index, and walkthrough copy; both append-only histories remain intact. - Walkthrough resolution preserves all three truths: FHC is live under the resolved mixed model, Comps is post-MVP, and current Stripe test-mode transport is proven while PR #196 provider/CSRF hardening and the remaining atomic money/Package/staging gates are not deployed.
- Zak received the complete C55-C64 copy disclosure and ledger link in short messages verified in the Messages database after three longer package writes truncated.
- Merged-tree gates passed: app 41 files / 400 tests plus typecheck and Vite
assets/index-COujzqxe.js; FHC 42 tests, 965 pages / 255 Spanish twins, recursive 966-HTML audit at 0 blockers / 0 warnings; docs build and diff check green. - No Soldi app deploy, remote D1 write, Stripe mutation, or DNS change occurred. Next: complete merged-tree gates, push PR #196, then cut atomic Market purchase as the next ready child PR.
2026-07-13 - Master train reconciled with main PR #161
- Re-read ready PR #196 and all comment/review surfaces (none present), then PR #161's body and full Zak supersession chain. The governing instruction remains
f8b192b/ build v60: CHOOSE Cold/Warm/Hot, SUBSCRIBE to 25 delivered Hot leads for$5,000, and OWN through a tier-covering Territory bid; PR #193 is the real app. - Fetched exact
origin/maind2d8173572c39d706fc3e03b45c8ce6cd0dd2cbaand began a normal non-rebase merge into exact train head8f57b8f3f012d7649bdd6c3ab20d6312a9dea49d. The train already containedf8b192bthroughe9017e6, so Git reported no conflicts and no product-content delta. - Retained the byte-identical v60 preview twins at SHA-256
fbe6ed23b8507617a910068f3c1c3e7ca1293af80ea67fcee1bc4e687938c58cplus every reviewed PR #197 Stripe and PR #198 acquisition/Territory migration, worker, API, test, and note. No app UI or preview file was hand-edited. - Verification on the reconciled tree: focused acquisition/Territory/Market/UI suites 202/202; disposable local D1 applied migrations
0001–0027and exposed the funding/allocation tables plus unique Territory outcome indexes; fullbun run verify39 files / 381 tests, TypeScript, Viteassets/index-LfcA747C.js; docs build and diff check passed. Expected adversarial-test stderr, the existing duplicateSO_1test key, and the Vite bundle advisory remain non-failing diagnostics. - Both-parent comparison found integration documentation as the only final-tree delta from the train parent. Relative to main, the retained product delta is the reviewed PR #197/#198 backend; both preview twins are unchanged against both parents.
- No PR merge, deploy, remote D1/Stripe write, or external message. Next: execute PR #196's remaining economic and operational launch gates in focused planes.
2026-07-13 - PR #198 P1 rereview compensation ownership fix
- Terra/high found a second-await race in the finalization error path: compensation published takeover-eligible
finalizing, then an unguarded helper could refund/decrement after a new owner took over and debited. - Consolidated finalization compensation into one D1 batch. Cleanup, aggregate reversal, lead reset, standing-order weekly/spend reversal, wallet credit, and the final transition to retryable
finalizingall require the same lead ID, claim token, and expected status. The claim remains non-takeover-eligible until wallet/order reversal is complete; the unguarded release helper was removed. - Added deterministic A/B scheduling: A fails finalization and compensates, B takes over/debits/allocates, then A resumes. B retains balance/budget
85000/15000, order count/spend1/15000, and exactly one ledger/portfolio/delivery/counter outcome. - Evidence: focused Territory/Admin/ingest/rules 160/160, canonical acquisition 11/11, FHC payload 3/3; fresh disposable migrations 0001–0027 plus claim table/index query; full
bun run verify39 files / 381 tests, TypeScript, Viteassets/index-LfcA747C.js. Docs build and diff check are publication gates. The forced failure test emits its expected error; the duplicateSO_1test key and bundle-size advisory are unchanged. - No deploy, remote D1/Stripe write, or secret access. Next: push PR #198 and request Terra/high rereview.
2026-07-13 - Marketplace v60 canonical acquisition plane
- Added migration
0026_canonical_lead_acquisition.sql: rawleads.sourceremains campaign/manual provenance, while constrainedleads.acquisition_sourcestores onlycold,organic,ppc, or explicitpending. No source-string inference runs; only the 18 code-owned v60 fixture IDs are classified. - Made FHC/HMAC ingest pending-only and non-allocating. Authenticated Admin manual/review boundaries accept only the exact canonical enum, omission defaults pending, and campaign-like/near-miss values return
400without writes. - Propagated raw and canonical attribution separately through Admin pending/supply-funnel, Market, and owned-lead APIs. Tier filters/counts use canonical acquisition only; pending rows have no tier and direct Market purchase returns
409before any wallet/portfolio write. - Admin CSV import is not present on this launch train and was not imported from the stale integration branch. Market charging, territories, Package, refunds, deposit bonuses, and product UI were unchanged.
- Evidence: local D1 migrations through
0026; local counts cold/organic/ppc6/6/6and historical pending47; focused acquisition/worker suite91/91; FHC payload suite3/3; fullbun run verify38files /374tests plus TypeScript and Viteassets/index-LfcA747C.js;bun run build:docs;git diff --check. Only the pre-existing duplicateSO_1Territories test-key warning remained. No deploy or remote D1/Stripe write ran. - Published implementation commit
a60ead9in ready PR #198, targetingorchestrator/marketplace-v60-20260713/merge. - Next: land this focused PR, then implement atomic server-authoritative Market purchase as a separate plane.
2026-07-13 - PR #197 synced to Zak-audited launch train
- Fetched and merged launch-train head
e6ac7c1into the Stripe-integrity branch after the full Zak PR/comment audit and territory-allocation terminology correction advanced the target. - Resolved
BUILD_LOG.md, the implementation-note index, andmarketplace-v60-mvp-buildout.mdconflicts by preserving both histories: the newest Zak corpus audit remains intact and precedes the append-only Stripe P1 and initial implementation sessions. - Accepted the incoming ROADMAP and alignment-matrix corrections. The merge introduced no product-code edit; the staged delta from pre-merge PR #197 is documentation-only.
- Evidence on the merged tree: focused Stripe/client suite 32/32;
bun run verify38 files / 371 tests plus TypeScript and Viteassets/index-B7oeNN0b.js;git diff --checkclean. Only the pre-existing duplicateSO_1Territories test-key warning remained. No deployment, remote D1 mutation, or Stripe write ran.
2026-07-13 - Zak v60 contract audit + first backend integrity plane
- Read every recent Zak-authored PR body and all issue comments, reviews, inline comments, and current heads. The marketplace contract is PR #161's final
v60 supersedes everything abovecomment plus merged PR #193; #160/#162/#168/#176–#179/#194 are FHC-only, and no hidden review thread changes the marketplace direction. - Corrected a dangerous terminology ambiguity: the buyer-facing Standing Orders/auto-buy product remains deleted, while territory allocation retains the legacy
standing_orderspersistence internally. Backend plans now say territory allocator rather than implying the dead product should return. - Kept Admin CSV import in the operational MVP sequence. It is separate from the parked buyer
+ Add leadaffordance and is required to load saleable inventory. - PR #197 selectively ports Stripe wallet-funding intent/economic replay integrity onto the launch train. Its first adversarial review caught an ambiguous-retry defect; head
631feccreuses an amount-scoped implicit request key after failure, rotates after valid success or amount change, and protects newer state from late responses. - Evidence at PR #197 head
631fecc: 32 focused Stripe/client tests; 38 files / 371 tests plus TypeScript and Vite build; local migrations through0025;git diff --checkclean. No UI, remote D1, Stripe account, or deployment changed. - Next: current-head adversarial merge verdict, then canonical fail-closed acquisition, atomic Market purchase, territory enforcement, deposit/promo subledger, refunds, Admin CSV import, and persisted Package behavior as focused PRs into the master launch train.
2026-07-13 - PR #197 P1: amount-scoped Checkout retry key
- Adversarial review found that Billing's one-argument
walletCheckout(amountCents)call generated a fresh UUID per attempt. After an ambiguous first response, a second click could therefore create a second payable hosted Checkout Session despite the server-side intent controls. - Moved implicit retry-key lifecycle into the API client without touching
Billing.tsxor any visual/UI file: a failed or ambiguous call retains one key for that amount, a valid session response clears it, and an intentional amount change replaces it. Cleanup compares both amount and key so a late older success cannot clear newer pending state. - Explicit
requestIdbehavior is unchanged and bypasses implicit state. - Evidence: focused Stripe/client suite 32/32; final
bun run verifypassed 38 files / 371 tests, TypeScript, and Viteassets/index-B7oeNN0b.js;git diff --checkclean. Only the pre-existing duplicateSO_1Territories test-key warning remained. No deployment, remote D1 mutation, or Stripe write ran.
2026-07-13 - Marketplace v60 Stripe funding integrity
- Semantically replayed only the Stripe economic-integrity seam from PR #187 (
fd39972,f6c2950) and PR #181 (3083fc0) onto launch-train based5108de; the old integration branch was not merged and its Market, refund, Admin CSV, Package, and UI work was excluded. - Added local migration
0025_stripe_economic_payment_integrity.sql: each wallet-funding request now binds user, integer-cent amount, USD currency, expected test/live mode, caller retry key, provider idempotency key, hosted Checkout Session, and PaymentIntent to one server-owned intent. - Hosted Stripe Checkout and Portal behavior remains intact. Checkout requests carry a stable Stripe
Idempotency-Key; caller retries reuse the stored session, while reuse with changed economics fails with409. - Signed paid-Checkout webhooks now match stored economics and atomically write the event claim, unique economic claim, PaymentIntent binding, wallet balance, and ledger row. Same-event replay, distinct-event Checkout/PaymentIntent replay, and persistence-failure retry cannot double-credit.
- Evidence: focused Stripe/client suite 29/29; fresh local-only D1 migrations 0001–0025 applied successfully; final
bun run verifypassed 38 files / 368 tests, TypeScript, and Viteassets/index-DnXY520a.js;git diff --checkclean. Only the pre-existing duplicateSO_1Territories test-key warning remained. No remote D1/Stripe write or deployment ran.
2026-07-16 — FHC fabricated city-data review follow-up verification (pushed branch; not deployed)
- The hostile-review repair passed focused negative proof: five independently fixed
CitySchemaunknown-key payloads reject, fixed source/claim sentinels pass, and legitimate renderedbuyer:disclosure copy is explicitly allowed by the rendered-claim scanner. This separates the strict source boundary from generated-copy scanning without weakening either. - Evidence: FHC
bun test456/456 across 10 files; clean build 965 generated pages / 255 Spanish twins; independent root audit rerun took ~60.7 seconds and passed 630 pages / 966 recursive copy-policy HTML / 102 thin-gate diffs with 0 blockers and 0 warnings; provenance--check103 rows / 0 disagreements; offline links 8/8 cached URLs healthy; root verify 37 files / 354 tests + production build; docs build 10 internal + 2 client docs;git diff --checkpassed. - Two clean post-repair manifests have the same 1,191-file aggregate SHA-256
aaab2b6b437b6f6941c2ef7ac0732ca9ffab1b2e012641aa1a55c4d9870fd51cas the pre-removal receipt. Public FHC output remains byte-identical. No PR, merge, deployment, or Zak message was performed.
2026-07-16 — FHC fabricated city-data review follow-up (pushed branch; not deployed)
- Hostile review blocked pushed
codex/fhc-remove-dead-fabricated-city-datahead5c078cafon two integrity gaps, not public copy:CitySchemasilently stripped unknown keys, and the broad guard/test/audit marker catalogue could self-mask if edited with a restored payload. - The narrow follow-up makes
CitySchemastrict and adds five fixed negative payload cases (buyer,socialProofCount,reviewCount,testimonials,toastActivities). It also adds fixed, local audit/test sentinels for those five keys and representative fabricated persona, reviewer, volume, activity, and closing claims, independent of the broad catalogue.FHC_REVIEW_COUNTSremains untouched. - The source-only branch was already pushed at
5c078caf; this follow-up remains un-deployed and does not alter Zak's restoredfhc-10plan. Final follow-up commit/push and clean-output evidence are recorded indocs/implementation-notes/fhc-dead-fabrication-removal.md.
2026-07-16 — FHC current-state correction
- Current shipped truth supersedes stale walkthrough/current-status language: PR #214 is merged and live as
2f5e618on Cloudflare FHC Worker versionad00e313-b824-4bd0-9883-b09b8f85f3fbat 100%. #216 and #217 are merged tomain; Always Use HTTPS and apex/www redirects were verified. - The new
codex/fhc-remove-dead-fabricated-city-databranch is a source-only cleanup from the #217 merge. It is not deployed and carries zero public FHC output delta. This correction does not rewrite historical entries below or alter Zak's restoredfhc-10plan.
2026-07-16 — FHC dead fabricated city-data removal (local branch; not deployed)
- Created
codex/fhc-remove-dead-fabricated-city-datain the isolated/private/tmp/soldi-fhc-dead-fabrication-removalworktree from the exact PR #217 mergeorigin/main1d1af89cb73d21d8f9ad572a155c7da59b979d60; the earlier FHC reconciliation worktree was not touched. - Removed the dormant fabricated social-proof payload at the
CityDataschema/data/generator boundary: counts, buyer persona/quote/track-record fields, curated testimonials, toast activities, their two hand-authored fixtures, and the now-dead persona/avatar/testimonial/toast generator helpers. Deleteddata/testimonials-curated.tsrather than leaving disconnected fabricated material in the tree. The approved mixed direct-purchase/partner copy model and the separate realFHC_REVIEW_COUNTSinjection remain unchanged. - Added a source-and-fresh-dist audit gate plus unit regression coverage for all retired fields, 15 buyer personas, 75 curated reviewer names, fabricated volume/dollar values, and concrete activity claims. It fails if a boundary field, the curated payload module, or a known false claim returns to source or generated HTML.
- Pre- and post-change clean full-
dist/manifests are byte-identical: 1,191 files, aggregate SHA-256aaab2b6b437b6f6941c2ef7ac0732ca9ffab1b2e012641aa1a55c4d9870fd51c. There is no FHC generated-copy or asset delta. Final verification and push evidence are recorded indocs/implementation-notes/fhc-dead-fabrication-removal.md. - Next: review the committed local branch and open a PR only with owner approval; no PR, merge, deployment, or external message was performed in this slice.
2026-07-16 — FHC post-#214 docs and CI follow-up
- Zak approved #214's implementation substance after comparing it with his branch, then identified two real follow-ups: the required freshness/superseded-claims documentation from
dce35f8was absent, and the path-filteredFHC audit when changedjob ran build/audit without executing the regression suite. - Cherry-picked Zak-authored
dce35f8, preservinground3-freshness-scope.mdandsuperseded-claims.mdwith a dated current-status addendum. The unrelated 401-linefhc-10-editorial-plan.mdremains in exact commit history but is not published as current truth because its connector-only and zero-closings/pre-launch assumptions require a future FHC-10 rebase. Addedbun testto the existing FHC CI job before build/audit. - Reproduced the test-count discrepancy instead of guessing. Exact
dce35f8passes 526 tests across six files; exact merged #214 passes 447 across eight. The four new integrity test files are byte-identical and contribute the same 400 tests. The difference is the policy model: Zak's stale connector-onlycopy-policy.test.tshas 123 tests, while current main's approved mixed direct-purchase/partner version has 36, a deliberate reduction of 87; current main adds five heading and three embed tests. Therefore526 - 87 + 8 = 447. - Accepted Zak's wording correction: the conditional-offer scanner is a regression tripwire for enumerated constructions and disclaimers, not a semantic guarantee against arbitrary novel phrasing. Corrected the historical parser spec and internal source comments to the approved mixed direct-purchase/partner model; no public copy changed.
- Next: exact-head full verification and hostile review, ready follow-up PR with Zak requested, then merge after CI. No provider setting, Worker code, generated page, or live copy changes in this slice.
2026-07-15 - Fair Home Cash heading scanner hardening (local integration branch; not deployed)
- Review found that the initial heading scanner's paired-tag regex did not recognize legal whitespace in
</script >,</style >, or</template >; fake headings in those inert regions could therefore distort the result. Replaced it with a token/state parser that recognizes whitespace-close forms, keeps script/style raw text opaque, and handles nested template/script/style regions. - Added two adversarial fixtures: exact whitespace-closing forms prove inert fake headings are ignored, while a nested inert region followed by a visible
h3proves a realh1 → h3skip cannot be bypassed. The scanner unit suite now has 5 cases and the full FHC suite is 447 tests. - Deleted the ignored generated
sites/fhc-pages/dist/directory and rebuilt from the current source before audit. Fresh output: 965 generated pages / 255 Spanish twins, 966 recursive HTML files, and 0 skipped heading levels under the hardened scanner. No copy or CSS source changed in this corrective commit. - Evidence: FHC
bun test447/447; FHC audit passed; provenance--check103 compared rows / 0 disagreements; offline link health 8 cached URLs / 0 failures; rootbun run verifypassed typecheck, 37 files / 354 tests, and production build; docs build passed 10 internal + 2 client docs;git diff --checkpassed. The follow-up was committed and pushed without opening a PR. No deployment was requested or performed.
2026-07-15 - Fair Home Cash heading-order review reversal (local integration branch; not deployed)
- An independent exact-SHA review found no P0/P1 issues but reopened the previously pushed FHC reconciliation for a P2: #208's accessibility claim lacked a generated-corpus heading-order gate. The review reported 94 affected pages in the 966-page corpus. A deterministic pre-fix scan of
74e7383found 93 affected pages: 51 calculatorh1 → h3skips and 42 statich2 → h4skips; no nested language twin failed. The count discrepancy is recorded rather than concealed. - Added
heading-order.tsplus unit coverage and madeaudit.tsscan every recursively collected built HTML file. It ignores only non-rendered scripts, styles, comments, and inert templates; there are no page or component exemptions. Any upward jump larger than one level is a launch blocker. - Repaired the 50 state calculator template outputs, the Illinois calculator, and all 42 affected static sources by changing heading elements and their matching CSS selectors together. Visual CSS and visible copy are unchanged. The rebuilt 966-file corpus has 0 skipped heading levels.
- Evidence: FHC
bun test445/445; FHC build 965 pages / 255 Spanish twins; recursive heading probe 966 HTML / 0 skips; FHC audit passed; provenance--checkpassed 103 compared rows / 0 disagreements; offline link health passed 8 cached URLs / 0 failures. Rootbun run verifypassed typecheck, 37 files / 354 tests, and production build; docs build passed 10 internal + 2 client docs;git diff --checkpassed. Commit and push remain in this session. No deployment or PR was requested or performed.
2026-07-15 - Fair Home Cash Zak PR reconciliation (local integration branch; not deployed)
- Created
integrate/fhc-zak-reconcilefrom exactorigin/main184a7a7f0f04b9dd6d54cf13301530eb2b662444; no stale FHC branch was merged as-shaped. The provenance audit read every body, commit, issue comment, inline comment, and review for Zak PRs #194, #199, #208, #209, and #211. All five had zero submitted GitHub issue comments, review comments, and reviews at inspection time. - Kept the current owner-approved mixed model from #199 and the 2026-07-16 consolidated handoff: Fair Home Cash may directly buy qualifying houses and may work with partners; offer outcomes remain conditional. #194/#199 are already ancestors of the requested base. #208/#209/#211 forked before that correction, so only non-conflicting work was selectively integrated.
- Preserved Zak-authored citation/source-link, conditional-offer, monetary-rounding, provenance, and link-health commits where safely reusable. Rebuilt #208's CSP/accessibility work on current main: ordinary responses now deny framing while the explicit calculator embeds retain their deliberate framing exception. Corrected Illinois market citations and the stale 50-day median to the cited May 2026 27-day figure; added the missing conditional-policy word counter exposed by the imported test suite.
- #209's source-map concept was ported as a current
docs/content/SOURCE_OF_TRUTH.md; its stale connector-only model, ungated-offer assertion, inherited code, local Desktop paths, and stale launch claims were not carried forward. The full copy/provenance delta and conflict record are indocs/implementation-notes/fhc-zak-integration.md. - Local evidence: FHC
bun testpassed 442 tests;bun run buildgenerated 965 pages / 255 Spanish twins with 258 provenance facts (153 sourced, 105 derived) and 103 independently compared values;bun run auditpassed. Rootbun run verifypassed typecheck, 37 test files / 354 tests, and production build;bun run build:docsbuilt 10 internal + 2 client docs;git diff --checkpassed. The integration branch was committed and pushed without opening a PR; no deployment was requested or performed.
2026-07-14 - PR #199 merged and Fair Home Cash best-site wave live
- Merged Zak's PR #199 to
mainas8abfe6bb98bf554fe10ce3246dd01fe901d0a84eafter immutable-head Sol approval and GitHub CI. The release preserves Zak's43ca26fbest-site wave and records all later owner/reviewer copy changes as C55-C64/A12-A14. - Deployed the exact merged tree to
fhc-pages; Worker version8b16585d-dd35-4f26-acc4-fb26b7f3a488is active. Rollback target is6f180e61-f7bc-4eaa-98e4-8a5605e041e3. - Live proof passed:
www301 preserves path/query at apex; representative FAQ, selling-cost report, Chicago neighborhood, EN/ES divorce, and PNG favicon routes return 200;/offerserves the final conditional reassurance. - Live framing policy passed: ordinary pages and ordinary calculator views are
SAMEORIGIN; only generated calculator?embed=1and the dedicated Illinois embed allowframe-ancestors *. - Refreshed the walkthrough truth surface: Comps is explicitly post-MVP, the FHC mixed model and live receipt replace the obsolete unresolved-model warning, and Stripe's proven test-mode transport is separated from the still-open atomic-wallet/refund/Package semantics. Sol/medium make-it-sexy and Terra/high make-it-simpler reviews passed; only
buyer floor->buyer marketplacewas additionally changed. - Wrangler uploaded 1,159 changed assets and activated the version, then exited 1 on the redundant custom-domain route update because the current token lacks Zone Workers Routes permission (Cloudflare code 10000). Deployment-list and hosted probes prove activation; no DNS or route mutation was needed.
- Next: send Zak the explicit C55-C64 copy/live receipt, then continue the v60 master train with atomic Market purchase, exact refund integrity, Admin CSV import, wallet subledgers, persisted Package billing, and staging adversarial QA. Comps remains outside the MVP.
2026-07-14 - PR #199 Zak exact-head release reconciliation (not deployed)
- Cameron resolved the engineering identity premise: Fair Home Cash may directly buy some houses while other transactions may use partners, so Zak's first-person
we buy housesvoice is not inherently dishonest. The team will not repeat the obsolete blanket non-buyer objection. - Reconciled Zak's three post-R6 commits at exact PR head
8eba975: closing-cost hero/CTA/number formatting (0068beba), market overlay and ballpark formatting (c8628a9b), and the full schema/meta/wizard/EN/ES buyer-network-language removal (8eba9756). No public wording was changed by Codex in this pass. - Expanded the durable copy ledger from stale C01-C40/A01-A10 to C01-C49/A01-A11, explicitly separating Codex's earlier reconciliation from Zak's latest public changes and audit expansion.
- Evidence at
8eba975: FHC 126/126 tests; build 940 generated pages / 255 Spanish twins; audit 0 blockers / 0 warnings across 941 recursive HTML; root verify 37 files / 354 tests plus production build;git diff --checkclean. Independent tmx Sol/medium and Terra/high desktop/mobile exact-head reviews are in flight. - No merge or deploy has occurred. Zak received a verified acknowledgment naming the exact head and promising the ledger plus live proof after deployment.
2026-07-14 - PR #199 R6 bounded classifier correction (not deployed)
- Corrected Terra's exact 14-case matrix: six explicit EN/ES negations now allow, while eight acquire/determiner/joint-subject direct-buyer claims block on disclosure routes.
- Consolidated direct principal-purchase matching through the bounded classifier so negation is evaluated once; retained seller-to-FHC grammar separately. Added
n't/cannot,tampoco/jamás, English acquire forms,my/our/any, Spanishmi/mis, and joint-subject handling that still allows independent partners as the actual purchaser. - Added the 14 exact cases plus seven close controls across visible/JSON-LD/meta. Rebuilt disclosures stayed clean, so public copy remains exactly C01-C40 and enforcement/test wording advances only to A10.
- Evidence: 123/123 focused policy cases; FHC 126/126 total tests; build 940 generated pages / 255 Spanish twins; audit 0 blockers / 0 warnings across 941 HTML; independent exact matrix 8/8 blockers and 6/6 allowances in all three layers; 3/3 close blockers, 4/4 close allowances, and 11/11 non-disclosure boundaries; root verify 37 files / 354 tests plus production build.
- No public page, form, consent,
/api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text/contact, or subagent use occurred.
2026-07-13 - PR #199 R5 disclosure purchase-claim classifier (not deployed)
- Terra's R4 release rereview confirmed every earlier attack and gate, then proved seven natural disclosure-only bypasses across English
about/ready/looking/poisedpurchase intent and Spanish recent/near-future word order. - Replaced the enumerated intent/periphrastic regex with a bounded, readable subject -> purchase verb -> determined seller-property classifier. It permits ordinary tense, intent, and adverb phrases while rejecting negation, independent actors, editorial explanation, and request-through-FHC bridges; invocation remains limited to the four disclosure routes.
- Added all seven Terra literals verbatim across visible/JSON-LD/meta, eleven close future/recent/adverbial/comparison EN/ES attacks, and eight neutral boundary controls. The rebuilt disclosure corpus stayed clean, so public copy remains exactly C01-C40 and enforcement/test wording advances only to A09.
- Evidence: 102/102 focused policy cases; FHC 105/105 total tests; build 940 generated pages / 255 Spanish twins; independent 62/62 attacks across all three layers, 20/20 neutral allowances, and 62/62 non-disclosure boundaries; inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks; audit 0 blockers / 0 warnings; root verify 37 files / 354 tests plus production build. The inherited duplicate
SO_1key and Vite chunk-size warnings remain non-blocking. - No public page, form, consent,
/api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text/contact, or subagent use occurred.
2026-07-13 - PR #199 R4 disclosure intent/periphrastic repair (not deployed)
- Terra's release review confirmed every prior P1 closure and gate, then found four disclosure-only direct-principal gaps: first-person/named
going to buy, named purchase intent, and named-FHC Spanishacaba de comprar. - Added a separate, seller-specific disclosure matcher for English going/planning/plan/intend/expect/aim buy/purchase forms and named/first-person-plural Spanish recent-purchase forms. Generic industry copy, independent-buyer copy, offer math, request-through-FHC, and non-disclosure routes remain explicitly preserved.
- Added four exact R4 fixtures across visible/JSON-LD/meta, fourteen close EN/ES blockers, and four neutral controls. All authored and built disclosures stayed clean, so public copy remains exactly C01-C40 and enforcement/test wording advances only to A08.
- Evidence: 76/76 focused policy cases; FHC 79/79 total tests; build 940 generated pages / 255 Spanish twins; independent inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks; audit 0 blockers / 0 warnings; root verify 37 files / 354 tests plus production build. Inherited duplicate
SO_1key and Vite chunk-size warnings remain non-blocking. - No public page, form, consent,
/api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text/contact, or subagent use occurred.
2026-07-13 - PR #199 final bounded disclosure-grammar hardening (not deployed)
- Terra's final rereview confirmed the prior public-copy reconciliation, FAQ/JSON-LD parity, recursive artifact counts, and audit, then found five direct disclosure-only grammar bypasses:
We buy your house,We purchase your property, named-FHC future purchase, and two ordinary Spanish purchase/sale forms. - Extended only the disclosure-route strict matcher with seller-specific buy/purchase auxiliary, contraction, tense, progressive, indirect-object, and Spanish person/conjugation forms. Generic
we buy houses, neutral offer-math/request language, and independent-buyer EN/ES examples remain explicitly allowed. - Added Terra's five attacks verbatim, ten close grammar blockers, four new neutral allowances, and authored-source regressions for About, Privacy, Terms, and legitimacy. No rebuilt disclosure blocker appeared, so public copy remains exactly C01-C40; enforcement/test wording advances only to A07.
- Evidence: 54/54 focused policy cases; FHC 57/57 total tests; build 940 generated pages / 255 Spanish twins; independent inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks; audit 0 blockers / 0 warnings; root verify 37 files / 354 tests plus production build. Inherited duplicate
SO_1key and Vite chunk-size warnings remain non-blocking. - No public page, form, consent,
/api/offer-request, ingest, nurture, secret, or Wrangler behavior changed. No deploy, merge, text, or subagent use occurred.
2026-07-13 - PR #199 second rereview: legitimacy disclosure identity repair (not deployed)
- Reconciled six authored occurrences on
/is-fair-home-cash-legit: the visible body/FAQ and FAQPage JSON-LD now describe offers as requested through Fair Home Cash or received by the seller, rather thanour written offer,our offers,sell to us, or anoffer from Fair Home Cash. - Hardened the shared copy policy with a disclosure-aware direct-principal family covering the reported EN forms plus reasonable EN/ES sale-to-FHC, named-buyer, and first-party-offer equivalents in visible, JSON-LD, and meta/OG layers. Connector disclosures remain allowed; neutral
offer-math, requested-offer, and seller-received-offer wording has explicit allowance coverage. - Verification: FHC
bun test35/35 (32 policy + 3 ingest), build 940 generated pages / 255 Spanish twins, independent artifact inventory 941 HTML / 2,755 description tags / 952 JSON-LD blocks, audit 0 blockers / 0 warnings across all 941 HTML, and rootbun run verify37 files / 354 tests plus production build. Root verify retained the unrelated duplicateSO_1React-key warning and Vite chunk-size warning. - Durable Zak handoff now contains C01-C40 public copy deltas and A01-A06 audit/test wording at
docs/implementation-notes/fhc-copy-identity-audit-ledger.md; operator twin remains/tmp/soldi-v60-20260713-pr199-copy-delta.md. - No lead form, consent,
/api/offer-request, ingest, nurture, secret, or Soldi-firewall behavior changed. No deploy, merge, or text was performed; PR rereview and any deployment remain root-owned.
2026-07-12 - Marketplace v51 source-priced money foundation (local only)
- Started
feat/marketplace-v51-foundationin an isolated worktree at immutable base6a21f4a; the concurrentfeat/fhc-seo-wave3worktree andsites/fhc-pages/were not touched. - Added one shared integer-cent marketplace rules module: strict
cold/organic/ppcclassification,$90/$150/$250flat pricing, Cold+Warm-only bulk tiers, territory bid-versus-bucket eligibility, package shortfall returns, deposit minimum/bonuses, and budget new-spend versus prepaid-fulfillment behavior. - Removed the unused frontend freshness/quality variable-pricing formula and replaced its facade with the locked shared rules.
- Review caught and prevented unsafe partial integration: FHC currently persists raw page/campaign slugs in
leads.source, so strictorganic|ppc|coldfiltering would hide valid leads and cannot truthfully distinguish paid versus organic. The temporary Open Market/UI wiring was reverted before closeout. - Evidence: baseline
bun run verify264/264; all 24 local D1 migrations; finalbun run verify34 files / 331 tests plus typecheck/build after the review-driven revert;git diff --checkclean. - Deliberately deferred: define/migrate canonical acquisition attribution, then wire ingest, Admin approval, Open Market, and territory allocation together while removing price bands/overrides/discounts and Standing Order auto-buy. No commit, push, PR, merge, or deploy in this slice.
2026-07-10 - FHC deploy: EHO official mark (PR #165) + export hardening (PR #164) live
- Merged PR #165 (official HUD Equal Housing Opportunity mark in all 9 footer
sources +
checkEhoMarkaudit hard-gate; branch also carried main's three pending app commits — nav blob fix, PR-#161 port, copy edits). Gates before merge:bun run verify264/264 tests, build 540 pages, audit LAUNCH READY. - Deployed
fhc-pages(version 556a8ca1, 100%): live footer serves the EHO mark;/api/export/customer-matchnow 401s both unauthenticated AND the old?key=form — Bearer header required (PR #164's change is now live). Known benign routes-attach auth error on deploy; worker activated regardless. - Zak texted the go-live + the new curl auth form.
- Later same day: merged PR #162 (ultra-QA — IL calc favicon/logo + lead-loss, gclid coverage, ES exit/thank-you, API hardening: nosniff on json(), 256KB body guard, KV try/catch). Zak's AI had re-synced it with main; verified the Bearer-only export and EHO audit gate survived. Gates green (540 pages, audit 0 blockers, 264 tests). Deployed (version 1bb1fba9 — note: first deploy attempt built from a stale local main missing #162, caught and redeployed). Live-verified: calc favicon=1, home gclid=2, nosniff header on export 401. Queued: Search Console TXT verification (CF token lacks DNS scope — dashboard paste needed), sitemap submit, GBP setup (blocked on John).
- Evening: Google Search Console verification shipped (PR #166) — verification HTML file (worker serves the exact .html path with 200; the assets layer 307s *.html to extensionless) + google-site-verification meta tag on all templated pages. Deployed; GSC now shows VERIFIED OWNER on the https://fairhomecash.com/ URL-prefix property. Discovered the property already had sitemap.xml submitted (Jun 26, Success, 536 discovered) and 330 pages indexed — indexing was already live. Users: camolechowski + FHC Support. Remaining: favicon-in-SERP watch item (data-URI icon may need a hosted /favicon.png), GBP verification blocked on John's entity docs.
- Night: Cam's SERP screenshot confirmed the generic-globe favicon → shipped hosted /favicon.svg linked from all 540 pages + embed page (was data-URI, which Google ignores); deployed and live-verified (200 + link on home). Tracking ground truth corrected: GA4 G-3553MET586 was ALREADY the build default and receiving traffic — the audit placeholder warnings are Meta pixel only. Meta pixel/dataset remains the single missing ID, blocked on Meta Business login + suspected restriction. State documented in sites/fhc-pages/CLAUDE.md (tracking & search section), internal ADS-ACCOUNTS.md, and agent memory.
2026-07-09 - FHC /offer wizard hotfix (post-PR-#160 review)
- Multi-agent review of PR #160 (already merged + deployed) surfaced two live
funnel bugs on
/offer: Enter in a step-1 field implicitly submitted the form and validated the hidden step-2 inputs (silent dead-end, no feedback), and the wizard emittedminor-repairs/2-3-monthswhere every state-page wizard emitslight-repairs/60-days— forking the Gold-Tier taxonomy by landing page. Fixed both (keydown guard advances the wizard; values aligned)- post-change-polish pass. Verified: build 540 pages, audit 0 blockers,
wizard driven in Chrome against built dist (blocked-with-errors + advance
paths both green). Queued from review, non-blocking: Customer Match export
KV scan won't survive ~1000+ leads (sequential gets, subrequest cap);
EXPORT_KEYsecret turned out to already be set — endpoints are live.
- post-change-polish pass. Verified: build 540 pages, audit 0 blockers,
wizard driven in Chrome against built dist (blocked-with-errors + advance
paths both green). Queued from review, non-blocking: Customer Match export
KV scan won't survive ~1000+ leads (sequential gets, subrequest cap);
- Follow-up (same day): Customer Match export hardened — per-lead KV gets
batched 50 at a time via Promise.all (was one sequential round-trip per
lead), email/phone hashes parallelized, and auth moved from
?key=query param (leaked EXPORT_KEY into access logs) toBearerheader, matching/api/deal-close. Verified against wrangler dev: 401 without auth AND with the old query param, 3 seeded leads export a CSV whose hashes byte-match locally computed SHA-256 of the normalized email/+1-phone. Still one subrequest per lead — a?since=cursor or rolling snapshot is the real fix past ~1000 leads. Deployed 2026-07-10 with PR #165.
2026-07-08 - Ads-launch package on fhc-ops + deck refresh + polish commit
/ads-launch/(new, fhc-ops): the full launch checklist for both brands — Abdullah doc list (entity docs, EIN, proof of address, gov ID, payment instruments, GBP-viable address), state-of-play table, minimum / job-well-done / OCD tiers per brand-platform with owner tags, blast-isolation rule (no shared MCC/BM across FHC↔EF), and the MCP automation path (Meta official MCP turnkey; Google Ads MCP gated on Basic-Access developer token — apply early). Fed by 3 Exa research lanes (Google, Meta, MCPs)./client-onboarding/(new, fhc-ops, fable-authored): repeatable new-client walkthrough — shared intake phase + Track A (paid ads) + Track B (organic engine at scale), 52 steps each tagged auto/assisted/human. Scorecard: 20 auto / 19 assisted / 13 human → 75% agent-touchable; productization shortlist included.- Stale-state fixes:
/fhc-ads-accounts/updated — FB page + FHC ad account + pixel now exist under FHC's own Business account (cleaner than the planned Velli-BM account); hub index gained cards for both new pages. - Polish: two post-change-polish runs on all touched ops-fhc pages (scroll reveals,
card spotlights, interactive checkboxes, dead-CSS pruning); app gates stayed green
(264 tests,
index-BneVUYIn.js). Earlier app polish pass committed (20125b7). - Deck/docs: walkthrough gained a setup-quiz slide + segmented-Market rewrite with fresh live shots; ROADMAP marks segmentation/quiz/nav DONE (0b606d9).
2026-07-08 - Zak's PR #160 merged + live: FHC ads-launch polish
- Zak's
feat/fhc-ads-launch-polishreviewed, conflict-resolved, merged (e980cc3), deployed. His branch predated main's mobile/i18n/meta/Ads-tag passes → 12 conflicts across 9 files. Union resolutions: kept main'sdisplay=optionalfonts + standardized 44px header logo + ES lang-toggle; took his unified 24px favicon, header phone link, and 2-step offer wizard. - What his PR ships: 2-step /offer wizard with Gold-Tier fields (condition, timeline,
occupancy, price expectation), auth-gated
/api/export/customer-match(SHA-256-hashed Email,Phone CSV for Ads/Meta audiences) +/api/deal-closeoffline-conversion capture (both fail-closed onEXPORT_KEY), lead-store fail-loud when KV missing, Terms rewritten to pure lead-gen entity language (attorney-brief aligned), Fraunces brand font, exit-form consent validation, ES translations. During resolution I extended his new wizard fields into the ES layer (data-es on labels/options, lang-aware step labels) and de-duplicated the merged fullname block. - Proof: build 540 / audit
LAUNCH READY/ 3 worker tests green / AW+GA4 coverage 536/536 intact. Live: wizard blocks empty Continue, advances filled, ES toggle translates new fields, zero console errors;/termsserves the new language; export endpoint 401s on bad key. - Needs Cam:
wrangler secret put EXPORT_KEY --config sites/fhc-pages/wrangler.jsonc(from repo root) before the Customer Match export / deal-close endpoints are usable.
2026-07-07 - Zak's #147 mockup port DEPLOYED to app.soldi.cc
- The three merged port lanes (PRs #157/#158/#159) were sitting on main undeployed — Cam (rightly) flagged the live Market page unchanged. Root cause: I finished the merge + local QA, then context-switched to the ops split without running the deploy endgame.
- Shipped: migration
0024_buyer_segmentation.sqlapplied to remote D1 (5 commands ✅),bun run deploy:appafter a green gate (33 files / 264 tests,index-Dpe-t3MH.js). - Live proof: guest
/marketserves the investor view — SOURCE control (Inbound 10 / Cold-call 4), situation tabs, per-leadvert/source/sourceBucket, zero listing-lead leaks, masked addresses, consolidated nav (Reports/palette gone). First curl showed the old bundle: CDN-cached index.html, cache-busted fetch = new hash. - Still owed: walkthrough deck + shots refresh, ROADMAP touch, polish pass on merged files.
2026-07-07 - FHC Google Ads base tag live site-wide (AW-18306794294)
- Cam created the FHC Google Ads account under the new Fair Home Cash Workspace (AJ/Google-assisted setup). The base tag needed deploying on fairhomecash.com.
- Wiring:
FHC_GOOGLE_ADS_ID(documented inanalytics.env.examplebut never consumed) now flows throughbuild.ts→ theanalytics.etapartial (city/state/homepage), the three inline-gtag templates (situation, IL-situation, state calculators), and the static-page copy loop — one extragtag('config','AW-…')on the already-loaded gtag.js, under the existing Consent Mode v2 defaults. Live ID is the build fallback; env overrides. - Proof: build 540 pages, audit
LAUNCH READY — no blockers, dist coverage GA4 536 / AW 536 / gap 0; deployed (worker upload green, known benign route-attach 401) and live-verified on/,/thank-you,/sell-my-house-fast-chicago,/sell-house-during-divorce-illinois,/illinois-foreclosure-deadline-calculator. - Queued next: GA4 property move (personal → Workspace via GA "Move property" — ID
stays
G-3553MET586, zero site changes), Ads↔GA4 link, import estimator/lead-form conversions. Plan of record:fhc-ops→/fhc-ads-accounts/.
2026-07-07 - Zak mockup port lane B2: nav simplified, Refunds merged, Billing compacted
- Branch-local mockup-port slice implemented on
port/nav-simplifyagainstdocs/plans/zak-mockup-port/SPEC.md§3. My Leads now exposesLeads,Transactions, and oneRefundsentry;/refundsis the live merged page, while/request-refundand/refund-statusnow redirect there./reportsredirects to/billing, and Reports leaves both desktop/mobile nav. - Payment & Budget now matches the mockup's compact single-screen shape without changing payment APIs: Add funds + Monthly budget form the two-card top row, Account status stays full width, and the old invoice generator/table moved into a new Invoices card styled after the mockup's
invstrip. Card management stayed available by folding Stripe portal access into the Add Funds card instead of keeping a separate Payment Methods panel. - Mockup cleanup items landed: the mounted
CommandPaletteand ⌘K/search affordance are removed; legacyReports.tsx,RequestRefund.tsx,RefundStatus.tsx, andCommandPalette.tsxwere deleted after import checks; live-transfer UI copy/badges were removed from the buyer dossier and the dead frontend field references were trimmed while worker/database columns remain untouched. - Proof:
bun run verifyfrom the worktree root passed — appvitestgreen at 33 files / 256 tests, thenvite buildproduceddist/assets/index-Cnm1Uoj6.jsanddist/assets/index-Bpp2jD8Z.css. - Still owed before any live claim: walkthrough/deck screenshot refresh against the new
/refundsand Billing routes, then the usual approval-gated merge/deploy proof.
2026-07-07 - Signup 500 root-caused: register made atomic, ledger repaired, worker logs on
- Cam's live signup failed (console:
POST /api/v1/auth/login401 + a rendered 500). Evidence trail: hiscam@velli.ccrow existed with NOsignup_bonuswallet row —/auth/registerran its two INSERTs as separate.run()calls, and a failure between them left a half-created account and threw an unhandled 500 (rendered ashttp_500). The 401 was him signing in before the account existed (the page opens on the Sign in tab). - Fixes: the users + wallet_transactions INSERTs now land in one
DB.batch()(atomic); unknown error codes render friendly copy instead of rawhttp_500;observability.enabledturned on for workersoldiso the next prod 500 is diagnosable after the fact. - Data repair: inserted the missing Welcome-bonus ledger row for
cam@velli.cc(WT_REPAIR_79a5e19e…, ledger now consistent with the $500 balance); removed the two repro accounts created during diagnosis. - Proof: new route test
auth-register.test.tsasserts both INSERTs share one batch (fails against the old code); verify 31/251 green.
2026-07-07 - previews/ ⇄ app/ boundary made explicit after Zak's "changes missing" confusion
- Zak's simplify+condense session (PR #147) edited the
previews/mockup and he expected app.soldi.cc to change. Audit confirmed every Zak PR is live on its intended surface — #147 was preview-only by its own description; the mockup→app port is un-started work. - Guardrails committed to main (2280609): "previews/ is mock-ups ONLY" rule in root
CLAUDE.md+AGENTS.md(Codex reads AGENTS.md) and a STOP block atoppreviews/CLAUDE.md.
2026-07-07 - Flat-glass prod regression fixed: backdrop-filter restored in built CSS (PR #155)
- Cam flagged the login page looking like a void. Root cause: hand-authored
-webkit-backdrop-filterduplicates next to the standard property make Lightning CSS (Tailwind v4 pipeline) DROP the standard declaration from the minified build — every.glass/.glass-panelsurface shipped with computedbackdrop-filter: nonein production. Dev builds are unminified, so vite-dev QA never saw it — the bug predates this week (visible in Zak's screenshots). - Fix: author the standard property only; the pipeline emits prefixed + standard correctly.
Restores frost on login card, nav glass, and drawers app-wide. Polish pass consolidated the
token block to
@theme static+:rootaliases (values byte-identical, verified on built dist). - Proof: verify 30/250 green; built-dist QA computed
blur(18px) saturate(1.7); deployed workerd8ccd6a0; live/loginre-screenshot (live-login-glass-20260707.png). - Process fix: visual QA must run against the BUILT dist (wrangler dev on
app/distor the live URL), nevervite dev— minifier-only regressions are invisible in dev.
2026-07-07 - Public shop window live: masked browse, address = paid unlock, de-distressed copy (PR #154)
- Server-side leak closed:
/api/v1/market/leadsand/api/v1/auctions*were serving the full street address unauthenticated in production — the "exact address unlocks on purchase" promise was client-side only. Pre-purchase SELECTs/DTOs are now city/county/zip-level; the exact address + owner identity is served exclusively by the ownership-gated/leadsroutes post-purchase. Regression test pins the public payload AND the SQL (noaddress/owner_name). - Guests can browse:
/marketrenders logged-out (masked rows, Sign in/Sign up nav); guest Buy →/login; buying still requires auth + funded wallet (401/402/403/409 gates unchanged). Cam's model: auth wall on the data, not on the window-shopping. - De-distressed public copy: tab title → "soldi — Exclusive Seller Lead Marketplace"; login subtitle → "Sign in to claim exclusive seller leads."; Floor hero → "exclusive off-market seller leads".
- Proof: verify 30 files / 250 tests + polish-pass browser QA green; deployed worker
76ccf00f(bundleindex-BHEss8Gd.js); live: unauth market/auctions payloads carry zero address keys, guest UI shows Sign in/Sign up + masked rows (live-guest-market-20260707.png), authed demo pipeline card still returns the owned address. make-it-sexy/simpler pass applied (Market live-floor kicker, phase transitions, LeadDetail lock note). - In flight: Sequences engine PR #152 (32f/256t green) + Comps live-provider PR #153 (32f/260t
green) from the Codex gpt-5.4 lanes — both merge-gated; migration
0024_*number collision noted on both (second to merge renumbers to 0025).
2026-07-07 - BETA DEPLOY: mobile shell + Realtime Wave 3 live on app.soldi.cc (B6-B12 green)
- The held deploy shipped. After Zak flagged app.soldi.cc as stale, Cam directed the mac session to
finish the handoff-dossier runbook (
previews/soldi-mvp-handoff.html§08 /BETA_READINESS.md§2). Pre-deploy gate: in-repobun run verifygreen (30 files / 249 tests, buildassets/index-D9NHprHQ.js).bun run deploy:app→ worker version9c8b6452-1a0e-4ccd-b799-53dfc0344418; live bundle hash matches the local build; DO migrationv1applied (AUCTION_ROOM/FLOOR_FEED live); remote D1 clean at0023. - Post-deploy battery green (B9): health/auth/authz, Market 3 rows, Pipeline staged counts,
Territories standing-order 25000→26000→25000 round-trip, deposit 409
stripe_checkout_required, zero 5xx. - Realtime proven live (B10):
wss://…/api/v1/rt/floor101 +helloevent with sold-history; LIVE floor ticker streaming in the browser; Room presence panel on/lead/:id. Spec correction: plain GET/api/v1/rt/floor404s by design — onlyUpgrade: websocketrequests route to the DO (app/worker/index.ts); the runbook's "plain GET → 200" probe was wrong. - Mobile shell proven live (B11): 375×812 production shots of Market/Leads/Territories/Billing/
Settings —
scrollWidth=375everywhere, console clean, chrome 132.5px; drawer opens grouped, navigates + closes on tap (artifacts/soldi-completion-2026-07/shots/live-*-20260707.png). - Deck refreshed (B12): realtime slide gets a real production screenshot; new "Mobile shell" slide
with the live 375px shot (
docs/walkthrough.html,docs/shots/*-20260707.png). - Two Codex gpt-5.4 lanes launched (tmx, worktrees) on the remaining red engines:
feat/sequences-send-engine(SPEC_SEQUENCES §Implementation plan) andfeat/comps-live-provider(SPEC_COMPS §Implementation plan, mock-default until keys exist). PRs to follow; no merge/deploy without approval. - Still on Cam (unchanged): D1 duplicate Stripe Customer, D4
admin@soldi.ccrotation, D5 test-mode ratification, D6 Zak "Text 2"; ops/previews surface deploys from the 07-07 entry below also remain approval-gated.
2026-07-07 - New ops/ surface: growth/ads/client briefs isolated off preview.soldi.cc
- New fifth deploy surface
ops/(workergrowth-ops-74b4, static assets, workers.dev only — no custom domain by design): the growth-side material previously served from preview.soldi.cc moved here, restoring the brand firewall in both directions (no FHC/client strategy on a soldi.cc host, no Soldi on FHC). Readable paths replace hash dirs:/fhc-growth/,/growth-ops-dossier/,/fhc-affiliate/(draft, first deployable home),/google-call/,/aj/,/elite-flippers-meta/,/elite-flippers-launch/,/agent-ads/— grouped by concern on a new root index (FHC growth · Google · Elite Flippers × Meta · Agent ops). The unguessable hostname is the access control; everything stays noindexed. - Single-copy model on ops/: no working-copy⇄deployed-copy twins —
public/<slug>/index.htmlis the only copy (drift-by-design eliminated for the moved docs; verified all 13 previews twins byte-identical before the move, so nothing was lost). Internal cross-links between the moved docs rewritten to the new slugs; stale "keep byte-identical twin" footer fixed in/agent-ads/. - previews/ slimmed to Soldi-only: root index now Product / Network / Dev docs (Market mocks, research,
affiliate, MVP handoff, Stripe runbook); Strategy-&-briefs section gone.
previews/CLAUDE.mdrewritten (Soldi-only rule, corrected stale "root 404s" note, full twin list incl. the previously undocumentedmarketplace-client/mkt-d64dc6e2+ dev-doc pairs). - Wiring + docs: root
package.jsongainsopsworkspace +deploy:ops; surface maps updated inREADME.md,CLAUDE.md,AGENTS.md; live pointers updated indocs/implementation-notes/{fhc-organic-growth, meta-ads-elite-flippers}.md,docs/content/ROADMAP.md,docs/content/fhc/launch/README.md,sites/fhc-pages/docs/GO-LIVE-RUNBOOK.md(dated history left as-is). Public docs reference the surface only as "unlisted growth-ops" — the hostname never appears on a published page. - Not deployed yet (deploys are approval-gated): needs
bun run deploy:ops(first deploy mints the workers.dev URL) +bun run deploy:previews(removes the moved files from the soldi.cc host). Old preview.soldi.cc brief URLs will 404 after that — resend the new links to anyone holding them.
2026-07-06 - Wave 2 C+D: repo slash-commands, live-proof tooling, CI budget cut
.github/workflows/ci.ymlrewritten: dorny/paths-filter job-level gating (no-checkout API filter job), concurrency cancellation, bun install cache, fetch-depth:0 removed. Measured baseline 61 billable min / last 30 PR pushes (avg 2.03/push; 20 of 30 were docs/previews-only paying for app verify + fhc setup-burn); estimated post-fix ~40-43 min (-30-35%), docs-only pushes 2→1 min. Branch protection is plan-gated (403) so job-level skips can't brick required checks; job names preserved. Validated via action-validator + js-yaml (no PR run possible from sandbox — eyeball the first real run).- New
.claude/commands/(six quirk-encoding runbooks + index) andtools/repo/(live-proof.sh,beta-gates.sh). live-proof tested on all four surfaces (previews 6/6 sha256, fhc correctly flagged the known live-drift post lag-retry); beta-gates scoreboard matches BETA_READINESS and proved the.envtoken reads remote D1 (B8 probe: no unapplied migrations). - Note:
docs/implementation-notes/wave2-tooling-ci.md. Next up: watch the first PR run of the new workflow; wire ui-validate verdicts into beta-gates when the harness lands; flip the pre-shell bundle baseline after B7.
2026-07-06 - Beta-readiness spec + docs completeness pass (stream A, docs-only)
- Authoritative beta spec:
docs/plans/mvp-build-public-release/BETA_READINESS.md— testable "beta-ready" definition B1-B15 (B1/B2/B14 already MET), the mac-session deploy runbook (375px proof gates for Market/Leads/Territories/Billing/Settings,bun run deploy:app, the deliberate mobile-shell + Realtime-Wave-3 DO-migration coupling, post-deploy battery incl.GET /api/v1/rt/floor404→200realtime room), rollback notes (fix-forward via git revert;wrangler rollbackmay be blocked across the DO migration; additive DO safe to leave), and beta-tester onboarding (demo vs real accounts, test-card funding, 10-flow exercise list, known limitations). Planning packet refreshed around it (open-decisions.md,release-readiness.json,README.md). - Post-MVP slices specced to implementation-ready:
SPEC_SEQUENCES.md§Implementation plan (send engine: Resend REST viafetch—@velli/email-relayis not a repo dependency; claim-before-send idempotency, 50/tick rate cap,SEQUENCES_SEND_ENABLEDkill switch, unique (enrollment, step) index, full test plan; schema0007+ cron already exist) andSPEC_COMPS.md§Implementation plan (CompsProviderseam, ATTOM+Anthropic pipeline, first-party cost/latency, honest fallback-to-mock; human prerequisite: procureATTOM_API_KEY+ANTHROPIC_API_KEY— neither exists anywhere). - Docs truth pass:
SHARE_WITH_ZAK.mdno longer lists realtime as live buyer product (moved to "built NOT deployed" with the deploy pointer) and now carries the Zak "Text 2" DRAFT behind two named gates (P2 decided; shell proof + deploy);/auth/me200-{"user":null}ADR added toDECISIONS.md(deliberate SPA bootstrap,auth.ts:174, live-verified); ROADMAP "Where we are" records the shell landing + beta spec; TESTING_PLAN's stale "Stripe unproven" gap closed (dated) and the shell-proof gap added. New decision surfaced for Cam: ratify Stripe test mode for the beta (D5). - Handoff artifacts refreshed (both twins byte-identical, HTML-parse checked):
soldi-mvp-handoff.html§03 now carries 5 decisions with next-action/unblocks/safe-default and §04/§06/§08 point at the beta spec;stripe-payments-runbook.html§05 gains the safe default + test-mode-for-beta note. - Verification: docs-only diff (no app source);
bun run build:docsgreen (10 internal + 2 client docs); live spot-probes re-confirmed bundleassets/index-CXgZFR3a.js,rt/floor404,/auth/menull-user. - Next: mac session executes BETA_READINESS §2; Cam clears §5 (D1-D6); then beta invites + Text 2.
2026-07-06 - FHC go-live runbook, engineering specs, Deadline-H1 unification (stream B)
- NEW
sites/fhc-pages/docs/GO-LIVE-RUNBOOK.md: the single authoritative 11-step launch sequence — Cam tokens → build+audit gate (warnings 529→~0 once the pixel is real) → deploy (exit-1 domain-attach benign) → curl live-proof battery → IndexNow → GSC staged calendar (priority wk1 / states wk2 / situations wk3 / cities+static wk4) → Bing → GBP → Velli → tracking verification, each step with owner/preconditions/command/success-check/rollback. - NEW
docs/content/fhc/launch/specs/(5 + index): Spanish /es/ landers (M), server-side Meta CAPI (S-M, ships dark), true per-page sitemap lastmod (M, input-hash manifest), internal-link classes 2-3 (S), 4-engine GEO citation tracker (M). - Code: unified the 50 generated calculators' "Foreclosure Timeline Calculator" H1/i18n/embed/ICS strings + JSON-LD app name to "Deadline" (drift from the meta pass — title, slug, ES dict, and the handcrafted IL flagship already said Deadline); rebuild + audit identical before/after (528 pages, 0 blockers, 529 warnings).
- Truth pass:
sites/fhc-pages/CLAUDE.md(page count 263→540 files/528 audited; privacy-placeholder note replaced with the live Chicago-address fact),RESUME-2026-06-18.mdmarked SUPERSEDED, Velli backlink doc status banner,fhc-growth-handoffartifact twins refreshed (Cam switch table, spec pointers, runbook links) and kept byte-identical. No deploys, no submissions.
2026-07-06 - Ads & analytics ops: EF launch gates + weekly-report spec (stream C)
- Tightened Elite Flippers Meta launch docs to deadline-ready.
previews/{,public/}elite-flippers-meta-plan.html: G0-G6 gate sequence (launch-ready = G0-G5, launched = G6), 10-item credential handoff with Business Manager paths + verify commands, first-campaign spec, Housing split into a classification decision (the efm strategy doc says EF coaching is NOT Housing — open G0 call for Cam) + CLI-flag verification (official command reference re-fetched: flag absent from docs; on-Mac--helpcheck is the hard precondition; Marketing API fallback documented). previews/{,public/}agent-ads-ops.html: weekly report v1 spec (GCP service-account runbook, runReport proof, metrics,/ads-weekly/dated-snapshot convention, 6 done-criteria), honesty flags expanded (incl. Special Ad Audiences likely discontinued 2023; unofficialmeta-ads-clipackage footgun).docs/implementation-notes/meta-ads-elite-flippers.mdupdated with blocker-by-owner table (Cam vs Abdullah) + today's session entry. Twins byte-identical; zero live mutations.
2026-07-06 - Four handoff artifacts indexed + deployed to preview.soldi.cc
- Deployed the preview surface with the day's four new static artifacts indexed under
Dev docson the preview root:/soldi-mvp-handoff.html(MVP completion dossier),/stripe-payments-runbook.html(payments decision-of-record + operator runbook),/fhc-growth-handoff.html(FHC organic action board + link-engine runbook),/agent-ads-ops.html(agent-run ads/analytics tooling plan). The amended growth-ops dossier (/gops-74b478ea/Cloudflare hype-ledger update) shipped in the same upload. - Deploy:
npx -y wrangler@4 deploy --config previews/wrangler.jsonc(run outside the repo per the linux-sandbox node_modules constraint), Worker versionaf2a8ef3-d95d-47a6-96a4-4f9d71d4884b, 6 new/modified assets uploaded. - Live proof: all five changed pages plus the root index fetched with
curl -sLand SHA-256-matched byte-for-byte against the localpreviews/public/twins (one transient cache mismatch on first read of/soldi-mvp-handoff.html; re-fetch +diffconfirmed identical). - This closes the 2026-07-06 dual-lane pass (Soldi MVP completion + FHC organic growth, entries below). Approval-gated next actions live in the artifacts: app deploy (mobile shell + Wave 3 DO migration, after mac-side screenshot proof), FHC redeploy + IndexNow/GSC/Bing submissions, P2 duplicate-Customer decision, Meta pixel + verification tokens.
2026-07-06 - FHC organic growth: meta pass, internal-link engine, growth handoff artifact
- Meta-length pass (fhc): all 34 over-length titles + 66 over-length descriptions fixed at the source —
calculator-state.eta(new{State} Foreclosure Deadline Calculator | Fair Home Cashtitle + fixed ≤155-char description; the old one interpolatedrules.process, up to 552 chars for Oregon),situation-templates.ts(stop-foreclosure title/desc, divorce desc — patterns length-checked programmatically across all 51 state names),il-situations.ts(3 IL deep-page descs).bun run audit: 629 → 529 warnings, 0 blockers; every remaining warning is theFHC_META_PIXEL_IDplaceholder awaiting Cam's real pixel ID. - Verification-tag readiness:
google-site-verification/facebook-domain-verification/ newmsvalidate.01(FHC_BING_VERIFICATION) render only when their env token is set — no more emptycontent=""tags; calculator pages previously had none at all. Verified both ways (token set → renders on all page types; unset → absent). - Branded self-hosted OG card:
og:image/twitter:imagesitewide →/og-card.jpg(1200×630, 80 KB, composited from the existingfhc-cover.pnghero + brand marks — no new photography), replacing hotlinked unsplash cards;og:image:width/height/altadded; hero rendering untouched. - Embedding internal-link engine:
sites/fhc-pages/tools/internal-links.ts— embeds all 531 indexable dist pages (text-embedding-3-small, sha256 resumable cache), similarity minus the 7,543 existing links, ranked recs attools/output/internal-link-recs.{json,md}. Cold run 602,630 tokens ≈ $0.012 / 5 s; warm rerun 0.8 s. First wired class: every state calculator now links its state's stop-foreclosure guide (top systematic gap, sim ~0.91 × 50 states; guide already linked back) — 2 links/page in dist, audit stays 0 blockers. - Strategy/truth pass: dossier hype-ledger Cloudflare pay-per-crawl entry amended (dated) for the 2026-07-01 Cloudflare pivot in both twins (
previews/gops-dossier.html,previews/public/gops-74b478ea/index.html, kept byte-identical);docs/content/fhc/launch/README.mdcorrected with a dated banner (todos 01/02 done 2026-06-26; "Search Console — DONE" was overstated — nothing has ever been submitted). New note:docs/implementation-notes/fhc-organic-growth.md. - Handoff artifact:
previews/fhc-growth-handoff.html(+ byte-identical deployable twin inpreviews/public/) — live-state snapshot with probe evidence, done-matrix, the organic action board (owner/effort/impact/next command per item), frontier-strategy ranking incl. debunked items (llms.txt as lever, blanket crawler blocking), Cam-blocked list, env quirks, this-week list. Cross-links the dossier, Elite Flippers plan, and agent-ads-ops. Not deployed/indexed — orchestrator owns that. - Approval-gated, prepared + dry-run-verified, NOT executed: fhc redeploy (
wrangler deploy --dry-rungreen, 561 assets — live pages still serve the OLD titles and 404 on /og-card.jpg until Cam approves); IndexNow submit (bun run indexnowdry-run: 137 priority URLs, key live + byte-matched today); GSC staged sitemap submission (priority sitemap first); Bing Webmaster; Velli placements (docs/content/research/velli-fhc-backlinks-2026-06.md). - Verification evidence: rebuild 540 files/1.7 s; audits before/after in this entry; live probes 2026-07-06 (
curl -sL) — homepage 200, IndexNow key byte-match, Nebraska calc live title = old 76-char version (drift proof that a deploy is owed). - Next: Cam's five switches (pixel ID, 3 verification tokens, GBP claim, Velli access, counsel); approved redeploy + IndexNow/GSC/Bing chain; agent lanes — next link classes (city metro clusters, situation cross-links), true per-page sitemap lastmod, Agent-class bot access check, hyper-local situation×neighborhood batch, /es/ landers.
2026-07-06 - MVP completion pass: mobile buyer shell, payments decision, docs truth pass, handoff artifacts
- Payments decision settled and recorded: stay Stripe; Clerk Billing rejected — confirmed by Cam 2026-07-06, matching the research conclusion (Clerk Billing wraps Stripe, adds +0.7%/txn, Plan-ID-only checkout, no escrow/payout primitives, would entangle live PBKDF2 auth). ADR added to
docs/content/DECISIONS.mdwith reversal condition and sources. - Docs truth pass:
SHARE_WITH_ZAK.mdpayments bullet and client-session line no longer claim Stripe is parked (it went live 2026-07-03, P1 GREEN + full B7 battery perartifacts/soldi-completion-2026-07/COMPLETION_TRACKER.md);docs/content/ROADMAP.mdstale "hard proof gap"/"waits on secrets" wording superseded by a dated P1/P2 paragraph;docs/implementation-notes/README.mdcorrected (lead-consent-audit → shipped,/adminrouted atapp/src/App.tsx:50; mvp-ship-loop → superseded);mvp-ship-loop.mdcarries an explicit superseded-by-platform-completion banner. - Mobile buyer shell (last open MVP code gap) implemented: new
app/src/layouts/MobileNav.tsxphone drawer (≤640px) — compact current-section button opens a grouped menu (Market / My Leads / Account / Admin) with the disabled Floor pill inside the menu; TopNav phone chrome is one 52px row; ScoreboardBar becomes a one-line scrollable status strip (kill-switch first). Tablet 641–920px keeps the segmented rail; desktop unchanged. First-viewport chrome at 375px drops from ~264px to ~130px by CSS accounting. - Verification: sandbox linux copy (fresh
bun install)bun run verifygreen — typecheck, 30 files / 245 tests (5 new MobileNav tests), buildassets/index-CFrs7sov.js. In-repotsc -bgreen after porting. In-repo tests/build remain blocked by the known macOS-native binary mismatch (environment artifact, not code). No headless Chrome in this sandbox — 375px screenshot proof, deck/walkthrough refresh, and the owner-approved app deploy remain for a mac-side session (that deploy also applies Realtime Wave 3's DO migration). - Live QA battery (non-destructive, demo account,
curl -sL): 21/21 probes passed onapp.soldi.cc— health + bundleassets/index-CXgZFR3a.js(no drift), auth 200/401, market rows + dossier contacts, Territories standing-order round-trip restored, pipeline stage counts, Billing 409stripe_checkout_required→/wallet/checkoutstripe_liveURL (not visited), admin 403/401 boundaries, realtime 404 as expected. Informational only: unauthenticated/auth/mereturns 200{"user":null}by design; Market filters are client-side;/user/preferencesis PATCH-only. Zero 5xx. - Handoff artifacts authored (editing + deployable twins, not yet indexed/deployed — orchestrator owns that):
previews/soldi-mvp-handoff.html(status board, decisions, QA record, environment quirks, this-week list) andpreviews/stripe-payments-runbook.html(integration map with file:line pointers, production state, operating/testing procedures, P2 options, Connect roadmap), cross-linked. - Next: Cam's P2 duplicate-Customer decision (minutes); mac session for mobile-shell screenshot proof + deck refresh + approved app deploy; then Zak "Text 2".
2026-07-06 - Elite Flippers Meta plan published to preview surface
- Added the Elite Flippers Meta Ads launch-control artifact to the deployable preview static tree as
previews/public/elite-flippers-meta-plan.html. The top-levelpreviews/elite-flippers-meta-plan.htmlremains the editing copy. - Indexed the artifact on the live preview root under a new
Dev docsgroup with the path/elite-flippers-meta-plan.html. - Verification before deploy:
bun installhad no changes;bun run verifypassed 29 test files / 240 tests and builtassets/index-CXgZFR3a.js; local headless Chrome renderedpreviews/public/index.htmland the public plan page. - Deployment:
bunx wrangler deploy --dry-run --config previews/wrangler.jsoncread 19 static assets successfully, thenbun run deploy:previewsuploaded/index.htmland/elite-flippers-meta-plan.htmlto Worker version0f6ddaf6-843c-4eab-a24b-7c287c0f8e00onpreview.soldi.cc. - Live proof:
https://preview.soldi.cc/elite-flippers-meta-plan.html?cb=20260706-metabyte-for-byte matched local SHA-25651a88de6aa112572fdd9e8fe7a18167b89ea0c3c9404dbb4660d997f3ebc68a2;https://preview.soldi.cc/?cb=20260706-metacontains theDev docscard and link. The plural hostpreviews.soldi.ccdoes not resolve; the configured custom domain is singularpreview.soldi.cc. - Next: continue the Meta account credential handoff; no Meta auth or ad-account mutation has occurred.
2026-07-06 - Elite Flippers Meta Ads CLI foundation and static plan
- Installed Meta's official
meta-adsCLI version1.1.0in an isolated Python 3.13 virtual environment at/Users/cameronolechowski/.codex/tools/meta-ads-venvafter confirming the default Python 3.14 could not install the package because Meta's current PyPI wheels target CPython 3.12/3.13. - Verified the CLI command surface locally:
meta --versionreturned1.1.0,meta ads --helpexposed campaign/ad set/ad/creative/catalog/dataset/insights commands, andmeta auth statuscorrectly reported unauthenticated untilACCESS_TOKENis provided. - Added preview-only static artifact
previews/elite-flippers-meta-plan.htmlfor Abdullah Ghaffar's Elite Flippers brand. The artifact tracks setup gates, account prerequisites, read-only proof commands, paused-draft campaign posture, Meta housing special-category review, operating rules, and a launch sequence from account ground truth through human activation. - Created implementation note
docs/implementation-notes/meta-ads-elite-flippers.mdand indexed it. The note records the credential-safe posture, open questions, and the decision not to use unofficial similarly named Meta CLI packages. - Verification:
bun installcompleted with no changes;bun run verifypassed 29 test files / 240 tests and builtassets/index-CXgZFR3a.js. Headless Chrome rendered the static artifact at desktop and mobile widths; final mobile proof is/tmp/elite-flippers-meta-proof/mobile-final6.png. - Next: Cam needs to provide or create a dedicated Meta system-user token plus Elite Flippers
AD_ACCOUNT_ID,BUSINESS_ID, Page/Instagram asset, pixel/dataset ID, destination URL, and launch budget/approval rules before any authenticated CLI read or paused campaign draft.
2026-07-03 - F4 live QA: mobile Territories density fix
- Cam's narrow
/territoriesscreenshot exposed a second mobile failure that the priorscrollWidth === innerWidthproof missed: the shell no longer overflowed, but the actual Territories table began roughly1007pxbelow the top of a 375px viewport, leaving the first screen dominated by chrome, copy, and tall stat cards. - PR #139 tightened the mobile Territories composition without touching standing-order data wiring: phone-width copy is tighter, the duplicate top Add button is hidden at <=640px, and mobile stats use compact two-column tiles instead of four full-width cards.
- Verification: local
bun run verifypassed 29 files / 240 tests and builtassets/index-CXgZFR3a.js; PR CI passedbun verifyand conditional FHC audit. UI file line counts remain under 400:Territories.tsx367 lines,Territories.parts.tsx393 lines. - App deploy succeeded as Worker version
8a2ae336-4aa9-427e-9da6-76764da39707. Freshness proof:https://app.soldi.cc/territoriesHTML returnedcf-cache-status: HITbut referencedassets/index-CXgZFR3a.js; live asset SHA-256 matched localapp/dist/assets/index-CXgZFR3a.js. - Live browser proof: at 375px,
/territoriesrenderedscrollWidth=375, activeTerritoriesfirst, duplicate top Add hidden, two-column stat tiles, 4 table rows, and table top648px; at 711px,scrollWidth=711, activeTerritoriesfirst, table top679px. Both proof runs returned no Chrome DevTools error-console output. - Evidence:
artifacts/soldi-completion-2026-07/shots/mobile-territories-density-receipt-20260703.txt,mobile-territories-density-live-375-20260703.png, andmobile-territories-density-live-711-20260703.png. - Next: P2 still waits on the historical duplicate Stripe test Customer cleanup/acceptance decision; do not send Text 2 yet.
2026-07-03 - F4 live QA: demo wallet held-balance normalization
- F4 wallet sanity found the demo buyer had a legitimate positive Stripe-funded wallet balance but a corrupted negative hold: remote D1 showed
demo@soldi.ccatbalance=11700,held_balance=-73000, and no active winning auctions. Because available funds are computed asbalance - held_balance, Billing showed available funds above wallet balance. - PR #135 fixed the invariant without editing wallet balance:
publicUserandcurrentUsernow clamp negative held balances on read, and migration0023_normalize_negative_held_balances.sqlnormalizes persistedheld_balance < 0rows to zero. - Verification: focused
cd app && bun run test worker/users.test.tspassed 1 file / 2 tests; fullbun run verifypassed 29 files / 240 tests and builtassets/index-BeilEzBd.js. CI passedbun verifyin 57s and conditional FHC audit in 8s. - Remote migration
0023_normalize_negative_held_balances.sqlapplied. D1 proof now showsdemo@soldi.ccwithbalance=11700,held_balance=0, andavailable=11700; negative-held users are0; active demo winning holds are0; migration list shows no unapplied migrations. - App deployed Worker version
6edcb9ec-f07a-481d-a9fe-eb2a52edaa7e. Live Billing proof via?demo=1renderedPayment & Budget,WALLET BALANCE $117,$117 available, Add funds,scrollWidth=1280, and browser error logs[]. - Freshness:
https://app.soldi.cc/billingHTML returnedcf-cache-status: HITbut referencedassets/index-BeilEzBd.js; live asset SHA-256 matched localapp/dist/assets/index-BeilEzBd.js. - Evidence:
artifacts/soldi-completion-2026-07/shots/f4-demo-wallet-held-normalization-d1-20260703.txt,f4-demo-wallet-held-normalization-live-proof-20260703.json,f4-demo-wallet-held-normalization-live-billing-20260703.png, andf4-demo-wallet-held-normalization-freshness-20260703.txt. - Next: continue F4 cleanup/export and keep P2 open until Cam decides how to handle the historical duplicate Stripe test Customer; do not send Text 2 yet.
2026-07-03 - F4 live QA: proof-ghost cleanup checkpoint
- Exported the remote D1 database before cleanup to
/tmp/soldi-remote-d1-export-before-f4-cleanup-20260703.sql(local-only, not committed because it contains contact data). SHA-256:55a02074440f88004b0d0bbbe1fd5bdde0bb89f06ca233933d824f82e3366664. - Cleanup candidates were queried by explicit proof/test IDs and sources before mutation. The cleanup removed two disposable proof users, their two signup wallet rows, nine stale proof/test leads, nine lead-consent rows, four review rows, and five FHC ingest-event rows.
- Preserved the three
f4_demo_inventoryleads because they are explicitly synthetic demo inventory for live Market filter proof, with555-01xxphones and@example.comemails. Also preserved the Stripe-funded C1 owned proof portfolio/lead so the bought-lead proof remains renderable. - Post-cleanup D1 proof:
remaining_disposable_users=0,remaining_deleted_proof_leads=0,f4_demo_inventory_available=3, andc1_owned_proof_portfolios=1. - Evidence:
artifacts/soldi-completion-2026-07/shots/f4-d1-cleanup-checkpoint-20260703.txtandf4-proof-ghost-cleanup-20260703.txt. - Next: commit cleanup evidence and continue F4 formal live proof; P2 still waits on the duplicate Stripe test Customer decision.
2026-07-03 - F4 live QA: post-cleanup browser proof
- Re-ran the key buyer-parity F4 proof against live
app.soldi.ccafter the held-balance fix and proof-ghost cleanup. - Market proof: live
/market?demo=1served the 3 explicitf4_demo_inventoryrows; distress filters changed row counts as expected (Probate=1,Divorce=1,All=3); Map mode rendered an honestMAP VIEW / Coming soonstate with the visible lead list instead of a dead fake map; browser errors were0. - Leads proof: live
/leads?demo=1rendered 24 owned rows,unnamedFields=0, row click opened the dossier drawer, and browser errors were0. - Territories proof: live
/territories?demo=1rendered 4 active rows,unnamedFields=0, and the Cook pre-foreclosure controls persisted through reload. The reversible test changed$250/weekly cap10to$255/11, confirmed after reload, then restored to$250/10and confirmed after reload; browser errors were0. - Mobile proof: 375px Market, Leads, and Territories all had
scrollWidth=375,unnamedFields=0, and browser errors0. - Evidence:
f4-post-cleanup-market-proof-20260703.json,f4-post-cleanup-leads-proof-20260703.json,f4-post-cleanup-territories-persist-proof-20260703.json,f4-post-cleanup-mobile-proof-20260703.json, plus matching screenshots underartifacts/soldi-completion-2026-07/shots/. - Next: P2 remains IN_PROGRESS on the historical duplicate Stripe test Customer decision; do not send Text 2 yet.
2026-07-03 - F4 live QA: Billing checkout-return guard
- The legitimate Stripe wallet-normalization pass credited the demo wallet but exposed a real Billing return bug: the
/billing?checkout=successredirect produced a blank Billing screenshot with repeated React max-update-depth errors. - Patched
app/src/pages/Billing.tsxso the checkout-return handler is idempotent peruserId:location.searchand depends on stable session fields (session.user?.id,session.refresh) instead of the whole session context object. - Added
app/src/pages/Billing.test.tsxto pin the return behavior: Stripe success refreshes the session once, strips the query back to/billing, and keeps the page rendered. - Verification: focused Billing Vitest passed 1 file / 1 test; full
bun run verifypassed 28 files / 238 tests and builtassets/index-BeilEzBd.js. - PR #133 passed CI (
bun verifyand conditional FHC audit), merged at0247406, and deployed as Worker version17316e33-ad7d-47cf-94f4-cb898f71e5a7. - Live freshness:
https://app.soldi.cc/billingHTML returnedcf-cache-status: HITbut referenced freshassets/index-BeilEzBd.js. Live/billing?checkout=successproof via demo auth cleaned the URL to/billing, renderedPayment & Budget, Wallet balance, and Add funds, hadscrollWidth=1280, and browser error logs 0. - Evidence:
artifacts/soldi-completion-2026-07/shots/f4-billing-checkout-success-live-proof-20260703.jsonandf4-billing-checkout-success-live-fixed-20260703.png. - Next: continue the wallet-normalization evidence path and D1 Stripe deposit/event proof; do not send Text 2 yet.
2026-07-03 - F4 live QA: narrow buyer shell breakpoint fix
- Cam's
/territoriesscreenshot exposed a live narrow-viewport failure band: the app was wider than the old760pxphone breakpoint, so desktop nav/scoreboard/ticker rules still applied and clipped the first viewport. - Patched the shared buyer shell only:
TopNav,ScoreboardBar, andLiveTickernow use their compact rules through920px. This makes the active route deterministic, pushes disabled Floor out of the first narrow view, hides the Coming Soon badge in compact mode, wraps utility chips, and keeps the ticker stable. - Verification:
bun run verifypassed 27 files / 237 tests and builtassets/index-CLEnGqU2.js. Local worker proof at 375px, 711px, and 880px showedscrollWidth === innerWidth, active tabTerritories, disabled Floor ordered after real tabs,soonBadgeDisplay=none, no unnamed fields, and zero browser error logs. - PR #131 passed CI (
bun verify56s; conditional FHC audit 10s), merged at244d976, and deployed as Worker version1843183a-3df3-47d0-9667-008de97f8341. - Live freshness:
https://app.soldi.cc/territoriesHTML returnedcf-cache-status: HITbut referenced freshassets/index-CLEnGqU2.js. Live browser proof at 375px, 711px, and 880px showedscrollWidth === innerWidth, active tabTerritories, disabled Floor ordered after real tabs,soonBadgeDisplay=none, no unnamed fields, and zero browser error logs. - Evidence:
artifacts/soldi-completion-2026-07/shots/f4-narrow-shell-local-proof-20260703.json,f4-narrow-shell-live-proof-20260703.json, and matching local/live screenshots. - Next: resume wallet-normalization/Billing checkout-success debugging; do not send Text 2 yet.
2026-07-03 - F4 live QA: Leads field-name regression fixed
- F4 browser QA found a real form-safety regression on live
/leads: 24 owned-lead status selects rendered with aria labels but no stablename/idon both desktop and 375px. - PR #129 fixed
app/src/pages/Leads.tsxby naming each status selectleadStatus-${portfolioId}. No data wiring, stage movement, money movement, or layout changed. - Verification: focused BuyerScreens Vitest passed 1 file / 5 tests; full
bun run verifypassed 27 files / 237 tests and builtassets/index-DIJ4pPnC.js. CI passedbun verifyin 56s and conditional FHC audit in 11s. - App deployed Worker version
0ec15132-96f6-4354-9f0e-0e8040a07296. Live/leadsservedassets/index-DIJ4pPnC.js; desktop and 375px re-proof both showedunnamedFields=0, 24 named selects, zero console/page/network errors, and mobilescrollWidth=375. - Evidence:
artifacts/soldi-completion-2026-07/shots/f4-leads-field-name-fix-local-20260703.txt,f4-live-leads-field-names-proof-20260703.json, and the matching desktop/mobile screenshots. - Remaining F4 blockers: demo wallet is still negative and must be normalized via legitimate flows; proof-ghost cleanup/export still needs to run; P2 still waits on the duplicate Stripe test Customer decision.
2026-07-03 - Mobile shell active-nav live hotfix
- Cam's follow-up
/territoriesmobile screenshot showed the earlier shell patch still had a failure mode: if the horizontal rail did not scroll the active item into view, disabledFloorplusComing Soondominated the first viewport. - PR #127 fixed that by making mobile CSS order the active nav item first, pushing disabled Floor to the end of the rail, hiding the Floor
Coming Soonbadge on mobile, and forcing the mobile ticker to truncate withtext-overflow: ellipsisinstead of hard-cutting at the right edge. - Verification: local
bun run verifypassed 27 files / 237 tests and builtassets/index-B3bTEkHq.js; CI passedbun verifyin 56s and conditional FHC audit in 8s. - App deployed Worker version
b557de2f-4589-4173-806c-9fb679dbcc2f. Custom-domain HTML still returnedcf-cache-status: HIT, but served the freshassets/index-B3bTEkHq.js; live asset response was HTTP 200 withcf-cache-status: MISS. - Live authenticated 375px proof on
https://app.soldi.cc/territoriespassed:scrollWidth=375, active tabTerritoriesat17px, disabled Floor at488px,soonBadgeDisplay=none, tickertextOverflow=ellipsis, zero console messages, and zero 4xx/5xx responses. Evidence:artifacts/soldi-completion-2026-07/shots/mobile-shell-active-nav-receipt-20260703.txtandmobile-shell-territories-active-nav-live-375-20260703.png. - Next: resume F4/P2 platform-completion proof. Do not send Text 2 yet.
2026-07-03 - Stripe Customer reuse fix and F2 proof progress
- F1 is now GREEN: Cam completed the Stripe sandbox setup,
wrangler secret list --config app/wrangler.jsoncshowsFHC_INGEST_SECRET,SESSION_SECRET,STRIPE_SECRET_KEY, andSTRIPE_WEBHOOK_SECRET, and dashboard webhook delivery later proved 200 OK tohttps://app.soldi.cc/api/v1/webhooks/stripe. - F2 gate/checkout/webhook proof progressed: authenticated
/payments/depositnow returns409 stripe_checkout_required;/wallet/checkoutreturns a hostedhttps://checkout.stripe.com/...URL; hosted Checkout credited the demo wallet by $10; D1 shows the wallet deposit and processed Stripe event; dashboard resend stayed idempotent with no double credit. - Portal proof found a real defect: the first live Checkout + Portal attempt left two Stripe test Customers for
demo@soldi.cc. PR #123 fixed the app by creating/reusing the persisted Stripe Customer before hosted Checkout and passing that customer into the Checkout Session. CI passedbun verifyand conditional FHC audit; app deployed Worker versioncce7cd23-4fcc-4ffa-9821-5d43446c1636. Post-fix live checkout proof did not create a third Customer. - Re-ran C1 with Stripe-funded balance using a clearly synthetic lead:
L_MR5KWTP2_284F9705005DC4F926B4821Fat999 Proof Battery Ln, $10 price, sourcesession_proof_admin. Live admin API created/approved it; live Market API bought it as demo; D1 shows the $10 Stripe deposit followed by the $10 market charge, plus portfolioPF_MR5KWU4V_1D042A330C2173FCFFDD0C38, stage, and delivery rows. Clean browser proof renders the dossier contact fields with zero app console errors. - Verification: PR #123 local
bun run verifypassed 27 files / 237 tests and builtassets/index-DwGNid5v.js; CIbun verifypassed; live Billing desktop and 375px in-app browser proof servedassets/index-DwGNid5v.js,scrollWidth=375on mobile, and error logs[]. - Next: P2 remains IN_PROGRESS until Cam approves deleting the older pre-fix duplicate Stripe test Customer or explicitly accepts the final receipt calling it out as a documented pre-fix artifact. Do not send Text 2 yet.
2026-07-03 - Platform completion mobile shell hotfix local proof
- Cam's live
/territoriesmobile screenshot exposed a shared shell regression: compressed top nav, clipped budget row, and ticker text landing mid-word before the Territories content. - Locally patched the shared buyer shell only: mobile
TopNavnow uses a brand/account row plus masked horizontal tab rail with the active tab scrolled into view,ScoreboardBarwraps chips instead of clipping them,LiveTickerstops the marquee on narrow screens and ellipsizes one stable item, and the main layout uses tighter mobile padding with global x-overflow clamped. - Verification:
bun run verifypassed 27 files / 235 tests and builtassets/index-BQWg1Ans.js. Local authenticated 375px browser proof on/territoriesshowedscrollWidth=375, active tabTerritories, clean app console after excluding Vite/dev favicon/local websocket noise, and screenshotartifacts/soldi-completion-2026-07/shots/mobile-shell-territories-local-auth-375-masked-20260703.png. - PR #121 merged at
8a0d9ac; CI passedbun verifyand conditional FHC audit. App deployed Worker version3cb9f0d5-b65f-4e1a-a53d-f11a9e880403; livehttps://app.soldi.cc/territoriesservedassets/index-DwGNid5v.js, matching local. Live authenticated 375px proof passed withscrollWidth=375, active tabTerritories, account shell present, no console messages, no 4xx/5xx responses, and screenshotartifacts/soldi-completion-2026-07/shots/mobile-shell-territories-live-auth-375-20260703.png. - Next: return to the P2 Stripe checkout proof lane.
2026-07-03 - Platform completion F3: review fixes local proof
- Final-session F3 review lanes completed under
tmxand wrote three evidence reports: correctness/money, security/authz, and UX/consistency. Reports are saved underartifacts/soldi-completion-2026-07/shots/f3-review-*.md. - Fixed the first confirmed money defects locally. Buy-now now counts the current high bidder's existing hold toward affordability and reduces that held balance when converting to the full buy-now charge. Cron settlement now claims the auction row first and only writes debit/charge/portfolio rows when that guarded claim changes exactly one row.
- Tightened
IngestLeadSchema.equityPctto0..100, matching Admin manual supply validation. - Removed dishonest buyer UI affordances found by the UX lane: the Market "Just claimed" ticker no longer fabricates purchases from available leads, standing-order copy describes max-price auto-claim behavior, Territories now says "Active" instead of unsupported "Top-Bid", and the dead webhook button was removed.
- Verification: targeted tests passed 3 files / 38 tests; full
bun run verifypassed 27 files / 233 tests with bundleassets/index-CEhm0lL1.js. This slice is not yet deployed or live-reproved; next is PR, CI, merge, app deploy, and live Market/Territories/API proof. - PR #118 merged at
0fee781; CI passedbun verifyand conditional FHC audit. App deployed Worker version93f01214-f5aa-4c97-bffd-8b62528b16f8. Liveapp.soldi.ccserved bundleassets/index-CEhm0lL1.js; desktop and 375px Market/Territories proof showed no fake "Just claimed", no unsupported "Top-Bid", no dead webhook button, and zero console messages. Screenshots and receipt:artifacts/soldi-completion-2026-07/shots/f3-live-and-security-receipt-20260703.txt. - Started second F3 security hardening slice for the remaining R2 findings: password changes now invalidate old session cookies, and FHC ingest requires timestamped HMAC plus
x-fhc-idempotency-keywith D1 replay tracking. Also fixed the live mobile shell regression Cam flagged on/territories: top nav now wraps into a controlled horizontal tab rail, scoreboard chips stop clipping, and the ticker has stable mobile height. Verification: focused app tests passed 4 files / 53 tests; FHC sender test passed 1 file / 3 tests; fullbun run verifypassed 27 files / 235 tests with bundleassets/index-CzzPzi4x.js;cd sites/fhc-pages && bun run auditpassed 528 pages / 0 blockers. Needs PR, remote D1 migration 0022, app deploy, FHC deploy, and live signed-replay/mobile proof. - PR #119 merged at
bdb6ed5; CI passedbun verifyand conditional FHC audit. Remote D1 migration0022_ingest_idempotency_and_session_revocation.sqlapplied andbunx wrangler d1 migrations list soldi --remote --config app/wrangler.jsonclater returned no unapplied migrations. App code deployed as Worker version789051be-446b-4fce-bc07-a61be4cd85cf; current app/FHC versions are secret-change versions after a same-value FHC ingest secret rotation for proof (8ef6d0c7...app,68c81094...FHC). - Live F3 proof is now GREEN.
app.soldi.ccservedassets/index-Bu2BmY1K.js, matching local. 375px Market and Territories browser proof showed document width 375, stacked nav/scoreboard/ticker/main shell, and zero console messages. Live password-change proof registered disposablef3-session-revoke-1783118924@example.com, changed its password, proved the old cookie returneduser=null, the new cookie worked, old password login failed 401, and new password login worked 200. - Live FHC security proof passed after rotation: custom-domain FHC form submission forwarded to Soldi post-rotation, and direct signed replay event
f3-security-replay-1783119111883created exactly one lead, then returned duplicate receipts on second/third same-key POSTs; D1fhc_ingest_eventsandleadscounts confirmed idempotency. Evidence is appended inartifacts/soldi-completion-2026-07/shots/f3-live-and-security-receipt-20260703.txtplus focused receiptsf3-password-session-live-20260703.txt,f3-signed-replay-live-20260703.txt, andf3-fhc-post-rotation-forward-proof-20260703.txt.
2026-07-03 - Platform completion D: docs/deck refresh local proof
- Started D on
codex/d-docs-bracketafter Q merged. Coordination checks:gh pr listshowed only draft PR #77 with empty checks;imsg read +17739974600 --since 2hshowed no visible Zak messages. Baselinebun install && bun run verifypassed 26 files / 230 tests with bundleassets/index-CdT_flXp.js. - Refreshed
docs/shots/from evidence-backed live captures:buyer-market-20260703.png,buyer-leads-20260703.png,buyer-territories-20260703.png,buyer-billing-20260703.png,admin-refund-queue-20260703.png,settings-20260703.png, andadmin-supply-20260703.png. - Updated
docs/walkthrough.htmlso the deck now shows current buyer parity shots, Payment & Budget cleanup, a live Settings slide, separate Admin supply and Admin refunds slides, and parked-Stripe wording. It no longer claims hosted Stripe checkout is proven while worker secrets/webhook are absent. - Rewrote
SHARE_WITH_ZAK.mdas a current proof-posture ledger: live buyer/admin/settings surfaces, parked Stripe B7 proof, deterministic Comps provider, parked Sequences send-engine, no seller payout/status rails, and the two growth specs as backlog items. - Truth pass:
docs/content/ROADMAP.mdnow records D in progress and updates the hard proof gap to 2026-07-03.docs/content/prd/SUPPLY_SIDE.md,CONSENT_MODE_ENHANCED_CONVERSIONS.md, andGOOGLE_ADS_OFFLINE_CONVERSIONS.mdwere checked and still match the evidence posture. - Verification:
bun run build:docspassed (10 internal + 2 client docs + index), fullbun run verifypassed 26 files / 230 tests with bundleassets/index-CdT_flXp.js, and a local rendered walkthrough check athttp://127.0.0.1:8801/walkthrough.htmlshowed 19 slides, refreshed screenshots loaded, and zero console errors. Evidence:artifacts/soldi-completion-2026-07/shots/d-docs-refresh-local-receipt-20260703.txt. - PR #116 merged at
383d490after CI passedbun verifyand conditional FHC audit. Docs deployed with Worker versionf3866350-7cd4-441e-b82f-c3ddbc9b33f4. - Live custom-domain proof initially hit stale Cloudflare cache, then clean
https://docs.soldi.cc/walkthroughrevalidated to the new deck. Browser proof showed 19 slides, current Market/Billing/Settings/Admin supply/Admin refund screenshots, parked-Stripe text, and zero console errors. Evidence:artifacts/soldi-completion-2026-07/shots/d-docs-refresh-live-receipt-20260703.txt. - Next: keep the platform-completion loop open on P1/P2 unless Cam accepts the parked Stripe terminal state; do not send Zak wrap text yet.
2026-07-03 - Platform completion Q: Admin field identifiers local fix
- Started the adversarial Q live pass with a surface matrix that defines unit/integration/programmatic/E2E validation and success criteria for Billing, Settings, Territories, Admin supply/pricing/funnel, FHC ingest, payout posture, and the parked Stripe blocker.
- Q browser proof on live Admin correctly authenticated as
admin@soldi.ccand fetchedGET /api/v1/admin/supply-funnelwith HTTP 200, but Chrome DevTools surfaced 61 Admin form fields withoutidornameattributes because every pending lead card repeats a price input. - Added stable
nameattributes to per-lead price inputs, manual lead intake fields, and the batch-discount field. No Admin behavior, pricing math, money movement, or API contracts changed. - Verification: focused Admin tests passed 4 files / 17 tests; full
bun run verifypassed 26 files / 230 tests with bundleassets/index-N5KLlJ4g.js. This fix still needs PR, deploy, and clean live Admin desktop + 375px re-proof before Q can continue. - Continued Q on Settings: live
/settingspersisted demo buyer preferences, but DevTools found 18 unnamed Settings fields plus verbose password warnings because the password inputs were not inside a form. Wrapped Profile, Security, and Buyer Preferences in real submit forms and added stable input/checkbox names, then added the visually hidden autocomplete username field Chrome expects in password-change forms. Focused Settings tests passed 3 files / 11 tests; fullbun run verifypassed 26 files / 230 tests with bundleassets/index-Bd2PU3o4.js. This Settings fix still needs PR, deploy, and clean live Settings re-proof. - Continued Q on Territories: live
/territoriesfound unnamed search, weekly-cap, and modal fields before modal proof. Added stable names to the search input, per-order weekly-cap inputs, and the modal Field/Select helpers without changing Standing Order behavior. Focused buyer-screen tests passed 1 file / 5 tests; fullbun run verifypassed 26 files / 230 tests with bundleassets/index-CdT_flXp.js. This Territories fix still needs PR, deploy, and clean live Territories/modal proof. - Continued Q on supply data: remote D1 had 33 legacy/imported leads with
market_status='available'butmarket_price_cents IS NULL. The Market API filters out unpriced rows, but the stored status was still dishonest. Added migration0021_unpriced_available_back_to_review.sqlto move unpriced available rows back topending_review. This still needs PR, remote D1 migration apply, and D1 proof that unpriced available rows are zero. - Q is GREEN after PRs #109-#114. Latest live app proof used Worker version
5eebc802-dc70-4d3c-a3e7-40de88461852and bundleassets/index-CdT_flXp.jswith a matching local/live hash. Browser proof covered Billing, Settings, Territories modal, and Admin supply/pricing/funnel on desktop and/or 375px with zero console messages and unnamed fields. Remote D1 migration0021_unpriced_available_back_to_review.sqlapplied;unpriced_available=0. Evidence:artifacts/soldi-completion-2026-07/shots/q-live-qa-receipt-20260703.txt.
2026-07-03 - Platform completion P3/G2: Billing field-name fix
- Live Billing proof for P3/G2 confirmed the deployed page no longer rendered the fake card selector, auto-reload checkbox, or local editable card rows, and
POST /api/v1/payment-methodsreturned 410payment_methods_deprecated. - Chrome DevTools also surfaced an accessibility issue: the three Billing numeric inputs did not expose stable
idornameattributes. Added stable identifiers to Add funds amount, monthly budget, and budget reset day before marking P3/G2 green. - PR #107 merged at
65ec9f9; app deployed version36d92928-d55f-463b-b547-0d63bd22a39dwith bundleassets/index-Bc0yNyU9.js. The served JS hash matched local despite HTML/assetcf-cache-status: HIT. - Clean live browser re-proof on
app.soldi.cc/billingshowed no removed decorative controls, stable input identifiers, portal-only card management, and zero render console messages on desktop + strict 375px viewport. Route proof still returns 410 for localPOST /api/v1/payment-methods, and/wallet/portalreturns the expected fixture portal while Stripe secrets remain absent. Evidence:artifacts/soldi-completion-2026-07/shots/p3-payment-cleanup-live-receipt-20260703.txt. P3/G2 are GREEN.
2026-07-03 - Platform completion P3/G2: payment cleanup local proof
- Started P3 on
codex/p3-payment-cleanup. Billing no longer renders a fake card selector or auto-reload checkbox in Add Funds. Add Funds now takes only an amount, uses the existing demo instant-credit path when Stripe secrets are absent, and uses hosted Checkout when Stripe is configured. - Replaced the fake auto-reload control with one honest low-balance nudge derived from the real available wallet balance. Payment Methods now opens Stripe's hosted portal for card management instead of rendering editable local card rows.
- Deprecated the dead demo-token
POST /api/v1/payment-methodsroute with HTTP 410payment_methods_deprecated; the route no longer stores fake card data. Checkout/Portal/webhook code remains intact, and no live-mode or money-out rails were added. - Verification: focused P3 tests passed 2 files / 3 tests; full
bun run verifypassed 26 files / 230 tests with bundleassets/index-D7YdzdI1.js.Billing.parts.tsxdropped from 427 to 372 lines. Evidence:artifacts/soldi-completion-2026-07/shots/p3-payment-cleanup-local-receipt-20260703.txt. P3/G2 still need PR, deploy, and live browser proof before GREEN.
2026-07-03 - Platform completion G1: Settings local proof
- Started G1 on
codex/g1-settings-hub. Added a real Settings hub at/settings, reachable from the account menu and command palette. The page has only backed controls: profile name/email, password change, buyer preferences, Payment & Budget link, and sign out. - Added authenticated account mutations under
/api/v1:PATCH /user/profileenforces email uniqueness;POST /user/passwordverifies the current password, stores a new PBKDF2 hash, and rotates the signed session cookie;PATCH /user/preferencesstores normalized JSON arrays inusers.preferred_statesandusers.preferred_distress_types. - Buyer preferences are consumed by the Territories "Add More Territories" flow: saved state/type defaults prefill the Standing Order modal instead of becoming dormant profile data.
- Verification: focused G1 tests passed 3 files / 11 tests; full
bun run verifypassed 25 files / 229 tests with bundleassets/index-Dx2mbBwv.js. Evidence:artifacts/soldi-completion-2026-07/shots/g1-settings-local-receipt-20260703.txt. - PR #104 merged at
d8820ea, then app deployed versione0f655f7-32a5-479a-b05b-cbfff367bf19. Live browser proof registered a disposable buyer, saved profile/email, changed password (old login 401, new login 200), saved TX + Probate preferences, proved the Territories modal defaulted to Statewide TX / Probate, and captured zero console errors on desktop + 375px. Remote D1 proof shows the updated user row. Evidence:artifacts/soldi-completion-2026-07/shots/g1-settings-live-receipt-20260703.txt. G1 is GREEN.
2026-07-03 - Platform completion A4 GREEN: seller payouts spec-only
- Closed A4 as a spec-only predicate.
docs/content/prd/SUPPLY_SIDE.mdsection 7 documents seller payouts as PENDING_CAM and explicitly forbids Stripe Connect, bank onboarding, identity, payouts, refund-to-card, or money-out tables in this program. - Tracker PENDING_CAM ask #2 keeps Decision #0 open: pure lead marketplace vs principal/committed-offer posture gates seller payout semantics.
- Verification grep over
app/migrations,app/worker, andapp/srcfound no seller payout, Stripe Connect account, bank-account, identity, external-account, or money-out implementation. The only app-side hit was a generic Transactions styling comment. Evidence:artifacts/soldi-completion-2026-07/shots/a4-payout-spec-receipt-20260703.txt.
2026-07-03 - Platform completion A3 GREEN: Admin supply funnel live proof
- PR #101 merged at
c9c4b91, addingGET /api/v1/admin/supply-funnelplus the Admin supply-funnel panel. The route returns captured/scored/priced/reviewed/listed/sold-or-expired counts and recent lead drill-in rows with source, consent, quality, review status, current price, and price history. - App deployed version
72448e73-1d5b-454e-a852-be64b818bbd4. Live API proof asadmin@soldi.ccreturned 52 captured, 52 scored, 15 priced, 2 reviewed, 0 listed, and 13 sold/expired leads; unauthenticated access returned 401. Remote D1 aggregate query matched those counts. - Chrome DevTools browser proof logged into
app.soldi.cc/adminas admin and captured the new Supply funnel section plus drill-in rows and price history. Screenshot:artifacts/soldi-completion-2026-07/shots/a3-supply-funnel-admin-20260703.png. Receipt:artifacts/soldi-completion-2026-07/shots/a3-live-supply-funnel-receipt-20260703.txt. A3 is GREEN.
2026-07-03 - Platform completion A3: Admin supply funnel local proof
- Started A3 on
codex/a3-supply-funnel. AddedGET /api/v1/admin/supply-funnelin a separate route module soadmin-leads.tsstays below the file-size limit. The endpoint returns captured/scored/priced/reviewed/listed/sold-or-expired counts plus recent lead drill-in rows with source, consent evidence, review status, current price, and price history fromaudit_log. - Added a compact Admin supply-funnel panel above manual intake: lifecycle tiles and a wide operational table. The UI stays admin-only and does not introduce seller-facing promises, testimonials, or public status language.
- Seller-facing status remains parked in
docs/content/prd/SUPPLY_SIDE.md: future tokenized neutral states only, with payout/offer language blocked until Decision #0 is resolved. - Verification: focused A3 tests passed 2 files / 7 tests; root
bun run verifypassed 23 files / 222 tests with bundleassets/index-CWo7ymPN.js. A3 still needs PR, deploy, and live browser/API/D1 proof before GREEN.
2026-07-03 - Platform completion A2 GREEN: table-backed Admin supply proof
- PR #99 merged at
685083e, addinglead_price_bands, table-backed price resolution, Admin manual-intake integration, and FHC ingest default pricing while keeping unpriced bridge leads inpending_review. - Remote D1 migration
0020_lead_price_bands.sqlapplied successfully;lead_price_bandscontains 10 rows andPB_IL_COOK_PRE_FORECLOSURE_HIGHprices at 25000 cents. App deployed versionfdc8a493-7412-4d46-abd6-2181259a3e8a. - Live proof as
admin@soldi.cccreated synthetic leadL_MR4Q0GW8_68C114C7F56DD8EC3B3E9334without an explicit price; API returnedmarketPriceCents=25000,marketStatus=pending_review, andpriceBandId=PB_IL_COOK_PRE_FORECLOSURE_HIGH. Admin then saved override price 17000, approved to Market, verified Market visibility at 17000, batch-discounted to 15300, verified Market visibility at 15300, and rejected the proof lead for cleanup. - Remote D1 proof shows the lead row has
price_band_id=PB_IL_COOK_PRE_FORECLOSURE_HIGHandprice_band_source=lead_price_bands; audit rows exist forlead.manual_create,lead.price_update,lead.approve,lead.discount_apply, and cleanuplead.reject. Evidence:artifacts/soldi-completion-2026-07/shots/a2-table-bands-live-receipt-20260703.txt. A2 is GREEN.
2026-07-03 - Platform completion A2: table-backed price bands correction
- A2 fidelity audit found the prior live proof exercised Admin manual intake, price override, approve-to-Market, batch discount, and audit rows, but the default "price band" came from an in-code formula rather than the goal-required table-backed bands.
- Added
app/migrations/0020_lead_price_bands.sqlwith active state/metro/distress/default bands and seeded defaults. Addedapp/worker/price-bands.tsto resolve the best matching band by state, metro, distress type, value range, and equity range, with the old deterministic formula retained only as a migration-missing fallback. - Admin manual intake now uses the table resolver when an operator does not provide
marketPriceCents; FHC ingest also applies a default band price when the bridge omits price, while keeping those leadspending_reviewand out of Standing Order auto-allocation until Admin review. - Verification: focused route tests passed 33 tests / 74 assertions; root
bun run verifypassed 22 files / 221 tests with bundleassets/index-DGvE8OuP.js;bun run build:docsandgit diff --checkpassed. Migration SQL applied cleanly in an in-memory Bun SQLite check and seeded 10 bands; local Wrangler migration execution was SIGKILLed before output, so remote migration still needs direct proof before A2 returns to GREEN.
2026-07-03 - Platform completion A2: Admin supply controls local-complete
- Continued A2 on
codex/admin-supply-batch. Addedapp/worker/routes/admin-supply.tsfor Admin-only manual lead intake and batch discounts, mounted under/api/v1/admin/leads/*. - Manual intake inserts a lead, consent attestation, and audit row in one D1 batch. If an override price is absent, it applies a deterministic price band from estimated value, equity, and distress type; every price remains integer cents and the lead stays
pending_reviewuntil reviewed. - Batch discount accepts up to 50 lead IDs, skips sold/rejected/clawed-back/unpriced rows, updates priceable rows, and writes one
lead.discount_applyaudit row per update. - Admin UI now includes a compact manual intake panel plus batch discount control above the review queue, alongside the previously landed per-lead price save and safe approve-to-available rail.
- Verification: focused Admin tests passed 3 files / 16 tests;
bun run verifypassed 22 files / 221 tests with bundleassets/index-DGvE8OuP.js;bun run build:docsandgit diff --checkpassed; touched files remain <400 lines. A2 still needs PR, deploy, and live proof before GREEN.
2026-07-03 - Platform completion A2: Admin pricing controls local proof
- Started A2 on
codex/admin-pricing-controls. Added an audited admin pricing mutation for leads (POST /api/v1/admin/leads/:id/pricing) that accepts integer-centmarketPriceCents, rejects sold/rejected/clawed-back leads, updates price fields, and writeslead.price_updatein the same D1 batch. - Admin approval now only flips a lead to
market_status='available'when the lead already has a non-null market price. Unpriced FHC bridge leads can still be reviewed, but they remain out of Market until priced. - The Admin lead review card now includes a compact price input + Save price action and disables Approve for unpriced rows. UI polish was kept inside existing Admin card/button/tokens; the local
.claudeWorkflow DSL is not directly runnable from this Codex tool surface, so the mandatory make-it-sexy/make-it-simpler pass was applied manually against the touched Admin files. - Verification: focused Admin tests passed 2 files / 13 tests;
bun run verifypassed 21 files / 218 tests with bundleassets/index-CwRNFhJm.js;bun run build:docsandgit diff --checkpassed. A2 remains IN_PROGRESS because manual add-lead, price bands, discount batch, deploy, and live proof are not in this slice.
2026-07-03 - Platform completion A1: FHC ingest bridge local proof
- Built the first FHC -> Soldi bridge slice on
codex/fhc-ingest-bridge:app/worker/routes/ingest.tsnow accepts omittedmarketPriceCentsand stores those leads asmarket_status='pending_review', skipping Standing Order auto-allocation until Admin pricing/review work makes the lead marketable. - Added the FHC-side mapper/signer (
sites/fhc-pages/src/soldi-ingest.ts) and wired complete, consented offer requests to post signed JSON tohttps://app.soldi.cc/api/v1/ingest/leadswhenFHC_INGEST_SECRETis present. Partial/no-consent records remain in the existing KV/email flow. - Added a dry-run-first KV backlog drain (
sites/fhc-pages/scripts/drain-leads-to-soldi.ts) usingsoldi-drain:<lead-key>markers for idempotency. Local proof is captured inartifacts/soldi-completion-2026-07/shots/a1-local-bridge-receipt-20260703.txt: focused ingest tests passed 31 tests, FHC mapper tests passed 3 tests, drain--limit=0smoke passed, rootbun run verifypassed 21 files / 215 tests, and FHC build/audit generated 539 pages with 0 blockers. - A1 is now GREEN. PR #95 merged at
fbcdab4; matchingFHC_INGEST_SECRETis set on app + FHC workers; app deployed versiona02eceff-0d69-4662-8bae-18711826889f; FHC uploaded versiona419b369-1923-4cfc-be56-355c272ace2e(custom-route update still exits with token permission code 10000 after upload, but the live custom domain served the worker). Live URL-encoded FHC submissions created Soldipending_reviewrows withmarket_price_cents=null, Admin pending queue returned them, and the cutoff backlog apply forwarded 2 pre-bridge records while marking 20 pre-bridge records with 0 remaining forwardable. Redacted evidence:artifacts/soldi-completion-2026-07/shots/a1-live-bridge-receipt-20260703.txt.
2026-07-03 - Platform completion A0: supply-side PRD (PR #93)
- Added
docs/content/prd/SUPPLY_SIDE.md, the spec bridge between Fair Home Cash capture and Soldi supply/admin work. It reconciles the live HMAC ingest route, current Admin review console,.wrkts/supplier-adminprior art, andLEAD_FUNNEL.mdDecision #0. - Recommended defaults are now explicit: FHC bridge plus admin manual intake, price bands plus admin override, admin-first supply visibility, and seller payouts as spec-only/PENDING_CAM until Cam chooses pure marketplace vs principal/committed-offer posture.
- Registered the PRD in the docs build as
/prd-supply-side. No runtime app/FHC behavior changed in this slice;FHC_INGEST_SECRET, bridge forwarding, migrations, and live proof are A1/A2 work. Verification: localbun run build:docspassed 10 internal + 2 client docs, localbun run verifypassed 21 files / 213 tests, and GitHub CI passed on PR #93.
2026-07-02 — FHC: stealth hero restored per founders' locked playbook (PR #90)
- Zak's PR #90 restored the bold "We Buy Houses in {state}. Cash. As-Is." hero on state/city/
homepage — per the pre-existing locked decision (
internal/legal/DECISIONS-LOCKED.md, 6/26: "Bold 'We Buy Houses For Cash' hero stays") and Terms §2 DRAFT, which is engineered for it (lead-gen disclosure + the principal is an active cash buyer who may purchase-and-assign). Provenance note: this is the founders' documented risk call on DRAFT terms — counsel has not yet answered the brief; the PR's "attorney-approved" framing was corrected in the merge. - Hard lines all held (verified live): fabrication bans stay in the audit and pages (no fake testimonials/stats/track record), "flat marketing fee" + "independent cash buyers" disclosure copy stays visible, TCPA consent intact, calculators + non-IL guides remain educational. Conflict with #89 resolved (audit regex → fabrication-only). Deployed + live-verified.
- Follow-up in the same push: ES i18n dict brought into lockstep with #90's EN changes (how1p, finalP/finalCta — "Compramos casas…" now mirrors the EN stealth voice).
2026-07-02 — FHC: nationwide funnel in honest connector voice (Option 1)
- Founders aligned (texts + session): ship #86's nationwide funnel, cut the false buyer-identity copy. Landed as one integration branch: #86 (guides + i18n + flips) + #87 (two-way audit + educational hardening) + a same-day connector-voice rewrite across state/city/IL templates, meta/OG, JSON-LD, and the EN/ES dictionaries (consent line now translated). Fabrications deleted from rendered surfaces: fake testimonials w/ Google/BBB attributions, "480 homes / $96M+" track record, activity toasts, foundingDate 2019, first-person purchase histories in hand-written content. No guarantees or 24-hour offer promises anywhere (no buyer SLA exists).
- Schema: RealEstateAgent → LocalBusiness; honest Organization/Service descriptions; educational pages still emit no business/offer nodes. Audit now ENFORCES the honest voice sitewide (three layers: visible / JSON-LD / meta+OG, EN+ES) + requires the "independent cash buyers" disclosure anchor on funnel pages; the old stealth-voice rule (which required the false voice) is gone. First enforcement run caught 917 violations; driven to zero.
- Carve-outs pending counsel (MARS / §2945-family): 50 state calculators + non-IL guides stay zero-solicitation educational. 539 pages built, audit LAUNCH READY (0 blockers, 528 audited).
2026-07-02 — FHC: PR #86 triage + educational-posture hardening
- Zak's PR #86 flips
transactional = trueon all 50 state pages + the homepage before counsel has answered the expansion brief. Five-lens Workflow review (claims / statutes / content / tech / SEO) synthesized intoartifacts/soldi-fhc-ship-2026-06/PR86_TRIAGE.md: a 16-finding triage table, Paths A/B/C, and 7 new counsel questions (incl. MARS/Reg O). Recommendation: A → C — hold the flip, make IL-only actually true, rewrite to honest connector voice, then expand state-by-state as counsel clears. Content lens: only 49 of the 196 new guides (foreclosure) are unique statute-driven bodies; the other 147 are token-swap near-duplicates. - Hardening landed on
triage/pr86-proposal: two-way audit (educational pages now FORBID funnel markers and solicitation across visible text / JSON-LD / meta+OG — the first run surfaced 101 blockers on main), guide CTA strip, educational FAQ-schema mirror + RealEstateAgent/Service/ $0-Offer nodes dropped from educational@graphs, all 50 calculator funnels gated (offer box, soft capture with auto-consent=on, sticky + exit popups), homepage/where-we-buy fully educational, non-IL foreclosure-guide titles de-solicited. - Verification: 343 pages rebuilt;
bun run auditLAUNCH READY (0 blockers) under the hardened gate; IL funnel surfaces unchanged (offer form + RealEstateAgent verified present on IL pages). Still open: 204 city pages remain ungated (policy-module decision), Path C voice rewrite, guide-merge decision on #86.
2026-07-01 — Live C2 admin refund re-proof
Re-proved C2 against hosted app.soldi.cc on a fresh branch/worktree. Baseline bun install && bun run verify
passed with 21 test files / 211 tests and Vite build index-BzIT9cCX.js; wrangler whoami confirmed the
Cloudflare token is scoped to account 2fb55b3d56fa4a0cb926515ecd0b1a6f.
The dedicated admin@soldi.cc account already existed from the earlier live signup proof, so a fresh same-email
registration would be duplicate-blocked rather than a valid new signup. D1 proof still shows the admin user row,
the signup-bonus wallet transaction, and admin=1 after the authorized idempotent elevation command.
As demo@soldi.cc, the browser created a real product touchpoint on PF_SEED_02 through the live Pipeline
stage-change route, then submitted refund RR_MR2TUOLY_64BD4671E40942561A9697EC for L_MIA_TAXLIEN_05 through
RefundModal. As admin@soldi.cc, the Admin queue showed that fresh request plus seeded RR_MKT_03; approval
credited the demo wallet by 21000 cents, moved balance to -29400, marked the refund approved, and marked
PF_SEED_02 refunded.
Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/c2-refresh-*: Admin registration/elevation D1 proof,
buyer stage-touchpoint proof, RefundModal and pending-row proof, Admin queue before/after screenshots, approval JSON,
D1 wallet proof, buyer Refund Status screenshot/API proof, replay 409 proof, and non-admin 403 proof.
Next: C2 remains green. B7 remains blocked on Stripe worker secrets plus dashboard webhook proof; do not deploy
sites/fhc-pages.
2026-07-01 — FHC attorney brief for nationwide expansion questions
Added artifacts/soldi-fhc-ship-2026-06/ATTORNEY_BRIEF_FHC_EXPANSION.md, a counsel-facing brief that freezes the
current FHC fact pattern: Fair Home Cash LLC as the Illinois consumer entity, nationwide educational calculator/statute
pages, the PR #73 Illinois-only transactional funnel gate, no non-IL PII capture, TCPA/TrustedForm on the IL form, and
the privacy draft's flat per-lead lead-generation posture. The brief asks counsel for three concrete sign-offs:
direct-buyer state expansion requirements, lead-generation/broker-license posture for flat buyer-paid marketing fees,
and the consent/privacy/schema disclosure stack. It also includes the requested nine-state appendix from
sites/fhc-pages/data/foreclosure-rules.ts, with solicitation-statute items explicitly marked verify.
Verification: bun install && bun run verify passed from the isolated .wrkts/attorney-brief worktree before
final commit work: 21 test files / 211 tests passed + Vite build index-BzIT9cCX.js. No deploy was run; this was
a docs-only counsel-prep lane. Next up: counsel returns the state matrix and approved disclosure/fee structure before
any non-Illinois funnel capture is enabled.
2026-07-02 — Fixed the deck's demo login: navigations never reached the worker
The walkthrough deck's ?demo=1 auto-login has been silently broken in production: with
not_found_handling: single-page-application, the static-asset layer serves index.html for any
browser NAVIGATION (Sec-Fetch-Mode: navigate) to a non-asset path without invoking the worker —
so the demo middleware never ran and deck iframes landed on /login. Proven side-by-side: plain
curl to /api/v1/auth/demo → worker 302; navigate-header curl to the same URL → cached SPA HTML
(cf-cache-status: HIT). Two-part fix, both merged + deployed: PR #83 adds a canonical
GET /api/v1/auth/demo?next=<path> (Cache-Control: no-store, open-redirect-guarded + unit-tested;
walkthrough liveSrc now uses it), and PR #84 sets run_worker_first: ["/api/*", "/webhooks/*"]
so the worker owns API paths for all request modes. Browser proof: navigating the demo URL lands
authed on /market as demo@soldi.cc, zero console errors —
shots/demo-login-fixed-market-authed-20260702.png. Also this session: parity-safe polish pass
over 18 UI files (PR #82, 213 tests green) merged + deployed.
2026-07-01 — Landed Zak's PR #73: nationwide FHC calculators + guides (IL-gated funnel)
Merged Zak's feat/fhc-nationwide-calculators-guides (#73) as-is plus two review commits pushed to his branch
(f509d7c, e6cb959): swapped the hardcoded fasthomecash.us canonical/og/JSON-LD/mailto references for
config.domain on all 50 generated state calculator pages, extended audit.ts per-page coverage to those pages
(previously excluded by the legacy IL-calculator filter), removed the unattributed exit-popup testimonial, and gated
the transactional funnel (We-Buy-Houses hero, lead form, phone CTAs, exit popup) to Illinois only — non-IL state
pages are educational (calculator + statutes + market data + sources) pending counsel on foreclosure-consultant
statutes. PR #74 fixed CI to build FHC before auditing and wired sites/fhc-pages into root Bun workspaces so clean
installs resolve eta. Verification: build 343 pages, audit LAUNCH READY, fasthomecash 0 in source+dist, firewall
\bsoldi\b 0, CA page has 0 funnel markers vs IL 14; both GitHub checks green pre-merge. NOT yet deployed —
bun run deploy:fhc awaits Cam's approval. Attorney follow-ups: nationwide funnel expansion state-by-state; the
pre-existing nationwide areaServed schema question.
2026-07-01 — Closeout hardening: CI, Wrangler 4, docs screenshots, growth specs
Added a GitHub Actions CI workflow for every pull request into main: one job runs bun install && bun run verify,
and a second reported job runs the FHC audit only when sites/fhc-pages/** changes. This closes the gap where this
session's PRs merged with an empty statusCheckRollup. PR #70 landed the workflow, then dummy PR #71 proved the
checks report on GitHub: bun verify and FHC audit when changed both completed SUCCESS; #71 was closed unmerged.
Aligned deploy tooling on repo-pinned Wrangler 4 by upgrading root/app/FHC manifests and lockfiles to Wrangler
4.106.0. The FHC workspace also had a tracked broken self-referential node_modules symlink; it was removed so
cd sites/fhc-pages && bun install can work normally in CI.
Refreshed docs/shots/ from live app.soldi.cc after the buyer/admin parity work: Market table, Leads, Territories,
Payment & Budget, and Admin refund queue. The walkthrough now marks Payment & Budget and Admin refund queue as live
where evidence supports it, while keeping Stripe checkout/webhook proof explicitly pending. Zak's two parked growth
asks are now backlog PRDs: Consent Mode v2 / enhanced conversions, and Google Ads offline conversion imports keyed on
lead-quality outcomes.
Verification: bun run verify -> 21 test files / 211 tests passed + Vite build index-BzIT9cCX.js;
bun run build:docs -> 9 internal + 2 client docs + index; bun run build:fhc -> 288 pages generated; FHC audit ->
0 blockers. Wrangler 4 dry-runs passed for app, docs, previews, and FHC; receipts are under
artifacts/soldi-fhc-ship-2026-06/shots/closeout-wrangler4-*.
Still blocked: B7 is not green. bunx wrangler@4 secret list --config app/wrangler.jsonc still shows only
SESSION_SECRET, so Text 2 and MVP_SHIPPED_PROOF_DELIVERED remain gated on Cam setting STRIPE_SECRET_KEY,
STRIPE_WEBHOOK_SECRET, and proving the Stripe dashboard webhook.
2026-07-01 — Adversarial live QA for buyer parity, preview scrub, and D1 parity
Ran the retro-style hosted QA pass against app.soldi.cc, not local. Desktop and 375px mobile browser proof covered
/market, /leads, and /territories: distress filters changed the live lead rows, the Standing Order banner and
Just claimed ticker rendered, owned-lead rows opened the dossier drawer, and the Territory bid stepper fired a live
PUT /api/v1/standing-orders/:id and persisted across reload. The pass found real issues: the Market "map" was a
decorative fake map despite no map provider being configured, the Territories table had no weekly-cap edit control,
and Market could log a console error for an abort-like fetch during route changes.
Patched the findings in the buyer screens. Market Map is now an honest no-provider "Map view coming soon" state with
the live lead list still usable for buying, Territories rows now have weekly-cap decrement/input/increment controls
wired through the existing integer/Zod PUT /standing-orders/:id route, and abort-like Market/Scoreboard route-change
fetches no longer log console errors.
Verification: Baseline bun install && bun run verify -> 21 test files / 210 tests passed + Vite build
index-BFVM8eKn.js. Focused post-fix cd app && bun run test -- src/pages/BuyerScreens.test.tsx -> 4 pass.
Full post-fix bun run verify -> 21 test files / 211 tests passed + Vite build index-BzIT9cCX.js;
bun run build:docs also passed. First post-deploy browser proof on app Worker version
4c9bc62c-c444-41fa-8354-adbb2091374a confirmed the Market coming-soon map, dossier drawer, and persisted
weekly-cap edit, then exposed one remaining ScoreboardBar route-change console error; that cleanup is included here.
Remote D1 ledger query shows migrations 0001 through 0019_market_portfolio_stages.sql applied. Served preview
https://preview.soldi.cc/mkt-d64dc6e2/ hash matches both local twin files; served-HTML PII audit found only reserved
555-010-01xx fixtures and @example.com emails, with no non-example emails, street addresses, or proper-name hits.
Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/liveqa-*.
Final merge/deploy proof: PR #68 merged at 0c416d7, app Worker version
61ce08a4-0fa6-4596-b859-45fae1a99c4c deployed assets/index-BzIT9cCX.js, and docs Worker version
7b0a6013-e514-4da4-a4ce-50bdb715975c deployed the updated log. The final hosted browser pass on
app.soldi.cc desktop and 375px mobile recorded consoleErrors: [] and pageErrors: []: Market filters changed
rows 3 -> 2, the Map state had 0 fake pins and a coming-soon message, Leads rows opened the dossier drawer,
and Territories bid + weekly-cap controls both sent live PUT /api/v1/standing-orders/SO_MKT_01 200 responses and
persisted through reload. Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/liveqa-final-*.
Next: B7 remains pending on Stripe worker secrets plus dashboard webhook proof. Do not send Text 2 until B7 is green and C1 can be re-run as Stripe-funded instead of fixture-funded.
2026-07-01 — Live C2 admin refund proof
Created the dedicated production admin@soldi.cc account through the normal live registration UI, after adding an
explicit .gitignore rule for artifacts/soldi-fhc-ship-2026-06/.admin-credentials.local. The generated password is
stored only in that ignored local file and should be rotated by Cam. Registration proof covered /auth/register 201,
browser /auth/me, the remote D1 user row, and the signup bonus wallet transaction before the account was elevated to
admin=1.
Then proved C2 live end to end. As demo@soldi.cc, the browser RefundModal submitted pending refund
RR_MR2MW1FT_9EF23ACE815B8065666DAA7D for PF_SEED_04 / L_ATL_PREFCL_10; the request cleared the touchpoint gate
from existing portfolio actions. As admin@soldi.cc, the live Admin queue showed that fresh request plus seeded
RR_MKT_03, and approving the fresh request credited the buyer wallet by 11100 cents, changed the refund to
approved, and marked the portfolio refunded.
Verification: bun install && bun run verify -> 21 test files / 210 tests passed + Vite build
index-BFVM8eKn.js. Evidence is under artifacts/soldi-fhc-ship-2026-06/shots/: registration screenshots/JSON,
c2-admin-registration-d1-proof-20260701.txt, c2-admin-elevation-d1-proof-20260701.txt,
c2-demo-refund-request-browser-proof-20260701.json, live Admin queue screenshots before/after approval,
c2-approved-refund-wallet-d1-proof-20260701.txt, and c2-demo-refund-status-approved-20260701.png.
Idempotency/authorization checks passed live: replaying the approval returned 409 refund_already_decided, and
authenticated demo GET /api/v1/admin/refunds?status=pending returned 403 forbidden.
Next: B7 remains pending on Stripe worker secrets plus dashboard webhook proof. Do not send Text 2 until B7 is green and C1 can be re-run as Stripe-funded instead of fixture-funded.
2026-07-01 — Walkthrough buyer-screen refresh
Refreshed the docs walkthrough around the buyer-facing screens that changed in the mockup parity pass. The old
Auction Floor slide is now a live Buyer Market slide with the current masked fixed-price lead table framing, and the
deck now includes dedicated My Leads and Territories slides using the current browser-captured screenshots from the
deployed buyer parity work. This keeps /walkthrough from describing the old card grid or hiding the new Leads and
Territories surfaces.
Verification: bun run build:docs -> 7 internal + 2 client docs + index. Local generated-docs browser QA on
http://127.0.0.1:8801/walkthrough.html confirmed the Market slide renders, Leads uses
/shots/buyer-leads-20260701.png, and Territories uses /shots/buyer-territories-20260701.png; proof screenshot:
artifacts/soldi-fhc-ship-2026-06/shots/walkthrough-buyer-slides-local-20260701.png.
Next: deploy docs after merge, then leave the remaining MVP terminal state on B7 Stripe secrets/webhook and the production admin user needed for live C2 approval proof.
2026-07-01 — Admin refund queue readiness for C2
Added the missing Admin refund review surface around the existing refund decision route. Admins can now fetch
GET /api/v1/admin/refunds?status=..., see pending and recently resolved refund requests with buyer/lead context,
amount, reason/detail, touchpoint count, and status, then approve or decline from the Admin page through the existing
POST /admin/refunds/:id/decide path. This does not elevate any production user or complete live C2 proof; it makes
the queue ready for the seeded pending RR_MKT_03 once a real admin account exists.
Verification: PR #63 merged at af1fd63; cd app && bun run test -- worker/admin-refunds.test.ts src/pages/Admin.test.tsx -> 9 pass; bun run verify -> 21 test files / 210 tests passed + Vite production
build index-BFVM8eKn.js. Local browser QA used http://localhost:8787/admin?demo=1 with only the local Miniflare
demo user elevated to admin; screenshots saved at
artifacts/soldi-fhc-ship-2026-06/shots/c2-admin-refund-queue-local-20260701.png and
artifacts/soldi-fhc-ship-2026-06/shots/c2-admin-refund-queue-mobile-local-20260701.png. Browser proof saw Admin,
RR_MKT_03, Approve, and Decline visible with no console errors. Deploy proof: app Worker version
a5c6dc40-9dc2-4fbc-be17-f5bc40673e68; docs Worker version 0ac5abbd-23e8-4bea-bf65-b652547385a0;
app.soldi.cc serves assets/index-BFVM8eKn.js; /api/v1/health returned 200; unauthenticated
/api/v1/admin/refunds?status=pending returned 401; docs /build-log and /roadmap render the C2 readiness entry.
Next: keep C2 as partial until production has an admin user. Then prove approve/decline live against
RR_MKT_03 or a fresh refund and confirm the buyer Refund Status/wallet ledger update.
2026-07-01 — Buyer mockup parity: Market, Leads, Territories + testing plan
Ported the remaining old buyer app screens to the reviewed previews/marketplace-client.html mockup while keeping
the live data contracts intact. Market now renders the masked lead table with distress tabs, Grid/Map toggle,
Standing Order banner, "Just claimed" ticker, masked address copy, and the existing fetchMarketLeads /
buyMarketLead flow. My Leads now points to a dedicated /leads owned-leads table instead of the Pipeline kanban;
the table uses the existing pipeline/lead ownership APIs and keeps row click wired to the lead dossier drawer.
Territories now renders a PL-style standing-order table with real bid steppers through updateStandingOrder, search,
pagination, row removal, and a three-section Add More Territories modal.
Also added docs/content/TESTING_PLAN.md and published it through the docs build as /testing-plan.html, defining
unit, integration, programmatic, and e2e success criteria for app, docs, previews, and FHC surfaces.
Verification: PR #61 merged at e528696; bun install -> no changes; cd app && bun run test -- src/pages/BuyerScreens.test.tsx worker/pipeline.test.ts -> 21 pass; bun run verify -> 21 test files / 208 tests passed + Vite production
build index--WTSuKDJ.js; bun run build:docs -> 7 internal + 2 client docs. Local browser QA used
http://localhost:8787 after applying local D1 migrations and demo login, with desktop/mobile screenshots saved under
artifacts/soldi-fhc-ship-2026-06/shots/buyer-*20260701.png for Market, Market map, Leads, Leads drawer,
Territories, Territories modal, and mobile views.
Deploy proof: app Worker version df2009c1-0bef-4c5f-ba85-0e24f2b486b6; docs Worker version
d9e4c2fc-d983-4777-ab69-78c9ab5892fe; app.soldi.cc serves assets/index--WTSuKDJ.js; /api/v1/health
returned 200; docs.soldi.cc/testing-plan, /build-log, and /roadmap render the new entries.
Next: refresh the live walkthrough screenshots, then return to the hard MVP blockers: Stripe worker secrets/dashboard webhook for B7 and a live admin user for C2 refund approval proof.
2026-07-01 — Market buy now reaches Pipeline + C1 fixture proof
Finished the C1 browser pass for fixed-price Market buying and fixed the gap it exposed. The demo buyer bought
L_MKT_09 after a no-secret fixture wallet top-up; D1 had the portfolio and wallet charge, and GET /leads/L_MKT_09
returned buyer-only seller contact data, but /pipeline did not show the lead because POST /market/leads/:id/buy
created portfolios without the matching portfolio_stages row. Market purchases now create an initial new
stage row, and migration 0019_market_portfolio_stages.sql backfills any existing portfolios missing one.
Verification: cd app && bun run test -- worker/market.test.ts -> 1 pass; bun run verify -> 20 test files /
204 tests passed + Vite production build index-s8UTI49q.js; bunx wrangler@4 deploy --config app/wrangler.jsonc --dry-run passed; remote D1 migration 0019_market_portfolio_stages.sql applied; app Worker deployed as
29899a5d-3834-4b4d-946a-49f9d9d62b2a; live health 200 and app.soldi.cc serves assets/index-s8UTI49q.js.
Browser proof as demo@soldi.cc showed /api/v1/pipeline?filter=all includes L_MKT_09 in stage new and captured
artifacts/soldi-fhc-ship-2026-06/shots/c1-pipeline-lead-contact-L_MKT_09-20260701.png with seller contact details.
Next: C1 is green only as fixture-funded proof. B7 still needs Stripe worker secrets + dashboard webhook before claiming real Stripe-funded checkout, and C2 still needs a live admin account for refund approval proof.
2026-07-01 — Auction settlement C3 audit + D1 timestamp fix
Verified the cron settlement path against the MVP C3 predicate and fixed one subtle D1 time bug. settleDueAuctions
now selects due auctions with datetime(end_time) <= datetime(?) instead of raw string comparison, so D1's
space-separated datetime() values cannot sort as due before their actual time. Added worker-level settlement tests
covering unsold marking, winner hold-to-charge conversion, wallet charge ledger rows, portfolio creation, floor sold
event emission, and displaced-bidder hold release at bid time via releaseOutbidLeader.
Verification: cd app && bun run test -- worker/settlement.test.ts -> 10 pass; bun run verify ->
19 test files / 203 tests passed + Vite production build index-BgL_jj_a.js. No deck screenshots were refreshed
because this patch changes cron/query correctness only, not a rendered UI surface.
Next: ship the C3 patch; B7 remains blocked on Stripe worker secrets + dashboard webhook, and live C2 proof still needs an admin account.
2026-07-01 — Billing Add funds now falls through to Stripe Checkout test mode
Wired the Billing page's Add funds flow to the real wallet checkout contract without touching live Stripe.
The client still calls POST /payments/deposit first; demo/local mode keeps the existing instant-credit path,
while Stripe-configured mode branches only on 409 stripe_checkout_required and then calls POST /wallet/checkout.
The returned deterministic fixture/stub session is shown in Billing as a Stripe test checkout state, with navigation
restricted to same-origin relative URLs. The old hand-entered Add card form was removed from the visible Billing UI
so card collection is no longer fabricated on-page.
Verification: bun test src/lib/__tests__/payments.test.ts -> 2 pass; bun run typecheck clean;
bun run verify -> 16 test files / 182 tests passed + Vite production build;
grep -rn "api.stripe.com" app/src app/worker returned no matches; git diff --check clean. Docs build was
attempted after the walkthrough copy update, but this isolated worktree is missing the declared marked
package and the prompt forbids bun install, so bun run build:docs is deferred until dependencies are
available.
Next: owner-approved deploy only when the integrated app branch is ready; subscriptions/tiers remain product design work.
2026-06-30 — Visible per-state statute strip on city pages + LIVE
Shipped audit Fix #2 from the #39 growth research (B2 "answer-first / quotable data"): a visible
per-state legal-facts strip on every city page, rendered from data/states.ts (foreclosure process,
typical timeline, redemption period, effective property-tax rate + national rank, transfer-tax note,
and a § Key legal fact callout). It surfaces the per-state statute data that was already the site's
real moat but invisible to readers + answer engines. On-brand (Fraunces serif, terracotta accent,
soft-shadow card); on IL pages it renders above the existing .aeo-il cost module. Additive,
+57 lines to template/city-page.eta, zero page loss.
Verification: bun run build:fhc → 357 pages, 0 errors; bun run audit → LAUNCH READY, 0
blockers; strip live on a non-IL page (Phoenix: "Non-judicial · Redemption period · Effective
property tax") and an IL page (Chicago: statute strip + .aeo-il both); brand firewall 0 soldi
(only the whitelisted "Soldiers Field" landmark on rochester-mn). Squash-merged #40 → main
(2f33553); bun run deploy:fhc (worker uploaded clean; expected exit-1 on the domain-attach,
apex already bound) — confirmed live via curl on fairhomecash.com (the brand-new module serving
proves the deploy landed regardless of the stale deployments list record).
Also confirmed this pass: llms.txt (B7) is already generated + live (generateLlmsTxt()
in build.ts:773 → /llms.txt 200) — no new work; a redundant static/llms.txt I'd started was
reverted. Corrected the sites/fhc-pages/CLAUDE.md moat line (real moat = hand-written per-city
Local Insight + per-state statute data + the IL AEO calculator/module; computeVariant() only
reword-rotates the hero, cosmetic). /where-we-buy confirmed 200 (the llms.txt link is valid).
PR #3 (Comps V2) stays parked for separate review.
Next: Fix #1 (197-page scaffolding diversify — regenerates live content, awaits Cam's nod); the Soldi app's stale "Floor" → Market/Shop framing bridge (surfaced by the overnight spec loop); [NEEDS CAM] human plays (GBP, Reddit, digital PR, YouTube). RED-tier tactics remain off-limits.
2026-06-27 — Zak's IL-AEO layer integrated onto main SEO foundation + LIVE
Combined Zak's IL-AEO branch (zak/fhc-nj-fixes) additively onto main's SEO foundation — a
confirmed joint call (no SEO removed; both bodies of work ship whole). Zak's branch was cut from an
old base predating the @graph/situation/sitemap layer, so a raw merge read as destructive;
hand-ported in an isolated worktree instead (11-agent ultracode workflow: 3 implementers → gate →
5 adversarial reviewers → repair → re-gate). Live on the apex:
- Zak's 10 AEO features — IL foreclosure-deadline calculator; IL cash-vs-agent
.aeo-ilmodule (IL-gated, sourced figures + estimated-cost disclaimer); 4 deep state-level IL situation pages (buildIlSituationPages, coexisting with main's ~70 broad situation×geo via rename toil-situations.ts/il-situation-page.eta— disjoint routes, zero collision); one-question wizard; mobile sticky/cta bars;withSecurityHeaders; 400/hasSignalguards; click-to-call (773) 997-4600; IL tax fixes (2.07%, Cook $0.25 / Chicago $5.25) + lead-alert IL field union. - Interlinked IL geo pages ↔ the 4 deep pages + calculator (depth feeds breadth's authority).
- Stripped a LIVE FTC fabrication —
recentPurchases"Homes we bought this month" cards (invented transactions + stock photos) on Chicago/FL, pre-existing in main, now removed. - Terms arbitration venue → Cook County, IL (provisional +
TODO(legal), #30).
Verification: audit LAUNCH READY (368 pages, zero page loss); 6 reviewer blockers fixed +
independently re-verified; kill-greps (soldi / since-2019 / fabrication) 0; single @graph per page.
Squash-merged #36 → main (4ee6816); bun run deploy:fhc (worker uploaded clean; expected exit-1 on
the domain-attach, apex already bound). Live E2E: 4 IL pages + calculator 200 (were 404); Chicago
aeo-il + phone + interlinks live; fabrication + soldi 0. Spec/lanes:
docs/content/research/fhc-integration-2026-06/{SPEC,INVESTIGATION}.md.
Next (needs Cam): verify fairhomecash.com in Resend → set LEAD_REPLY_FROM to activate seller
auto-reply (#37); CF Email Routing for optout@/legal@/hello@ rights channels (#29); counsel
confirm venue (#30); real Meta Pixel id (#27).
2026-06-26 — fairhomecash.com LIVE + organic-levers round (IndexNow, @graph, sitemap-index)
Deployed fairhomecash.com (worker fhc-pages, olelabs; domain bound via account API) and shipped
the first no-ad-spend organic-levers round (ultracode workflow: 5 Exa research lanes → opus plan →
senior-engineer implement → 4 adversarial reviewers → 0 must-fix). Live on the apex:
- IndexNow — committed key
048b…fabserved at the apex;scripts/indexnow-ping.ts(bun run indexnow --submit) POSTed 105 priority URLs → IndexNow 202 (Bing + Yandex), bypassing Bing's broken Webmaster UI entirely. - Entity
@graph— FAQPage + HowTo folded INTO the@graph(verbatim-equal to visible copy), standalone blocks removed; segmented sitemap-index (states/cities/situations/static children); reciprocal hub↔spoke nearby-markets on every city page; gate-safe optional reviewer Person node (emitted only with a realFHC_REVIEWER_NAME— never fabricated). - Search Console — property auto-verified via the live GA4 tag;
sitemap.xmlsubmitted, 332 pages discovered. GA4G-3553MET586confirmed (stream = fairhomecash.com); Consent Mode v2 default-denied, sometrics.soldi.cc(first-party, unfiltered) is the measurement source of truth.
Verification: build 333 pages deterministic / audit exit 0 / firewall clean / legal pages
byte-identical. Apex 200; key file 200; sitemap-index + 5 children 200; FAQPage in @graph. Merged
to main via #22. Plan/research: docs/content/research/organic-levers-2026-06/PLAN.md.
Next (needs Cam): GBP claim + sameAs profiles; real reviewer name for the byline; GA4 consent
call; GSC indexation data before scaling page volume.
2026-06-26 — Monorepo consolidated → main; soldi surfaces deployed; analytics wired
Adopted the monorepo (#16) and stacked this session's work onto it, then one clean fast-forward to main (PR #14 — no conflicts, no legal content lost):
- Consolidated the metrics dashboard, GA4 wiring, and platform-roadmap/research docs onto
the monorepo+SEO head (
integration/monorepo-consolidation): metrics →tools/metrics, GA4 re-ported onto the SEO'dsites/fhc-pagestemplates (off the legal pages), docs →docs/. - Merged to main via #14 (release/fhc-launch FF'd to integration; release→main FF). #17–#21 closed as consolidated-into-main; #16 auto-merged.
- Deployed soldi surfaces (olelabs acct):
app.soldi.cc(soldi1c06d72e),docs.soldi.cc(soldi-docs7a1a31c8),preview.soldi.cc(soldi-preview66e70750);metrics.soldi.cc(soldi-metrics) live from the prior deploy. - GA4
G-3553MET586wired (Consent Mode v2 default-denied + first-party beacon → metrics.soldi.cc); begins firing once fhc-pages deploys.
Verification: app bun run verify (112/112 tests); fhc-pages build 333 pages / audit 0
blockers / LAUNCH READY; all surfaces return 200. FHC apex DEPLOYED (Cam's go): fairhomecash.com
live (worker fhc-pages, olelabs; domain bound via account API PUT /workers/domains, zone
e70054044e07286f6136729ce2f3054a). 333 pages resolve; robots.txt Allow: / + AI crawlers
(GPTBot/Perplexity/ClaudeBot); both sitemaps 200; GA4 G-3553MET586 firing; /collect beacon →
metrics.soldi.cc (202); lead alerts (RESEND_API_KEY) → camolechowski@gmail.com. Privacy page
keeps the as-if-registered draft placeholders (noindex) — fill once the LLC is formed. Next (Cam):
Google Search Console verify + sitemap submit, Bing Webmaster, GA4 mark conversions, Google Business Profile.
2026-06-25 — FHC SEO/GEO optimization, round 1 (PR stacked on #16)
Researched the field (8 Exa lanes → docs/content/research/seo-2026-06/) + a staged opus
plan (00-OPTIMIZATION-PLAN.md), then implemented the high-confidence on-site lanes on
sites/fhc-pages/:
- Entity graph (
data/seo-schema.ts, NEW): consolidated the flat JSON-LD into one cross-linked@graph— Organization#org← RealEstateAgent#business← Service ← WebPage ← BreadcrumbList (Home>State>City) — with@id/sameAs(placeholders pending GBP/social) and build-deriveddateModified/lastModifiedMonth(replaces the hardcoded2026-06-07). Single brand-firewall string point. - City + state templates: a direct-answer-first "answer box" under the H1 (40–60
words, variant-rotated across 5 frames so the 263 pages are no longer byte-identical —
the previously-dead variant system is now live); emit the
@graph; state-page schema parity; hero LCP preload +fetchpriority+ image dimensions; State breadcrumb tier; fixed the brokenhref="sell.html"link that shipped on 255 pages. - build.ts: explicit AI-crawler robots stanzas (GPTBot/OAI-SearchBot/PerplexityBot/
ClaudeBot/Google-Extended/Bingbot/Applebot…) + a new
dist/llms.txtindex. - audit.ts hardened: catches non-root-relative broken links, asserts
@graph+@id, asserts no hardcodeddateModified. src/index.ts: edgeCache-Control(immutable assets, short HTML). - No fabricated reviews / AggregateRating (P0 legal gate respected). Brand firewall intact.
Verification: bun run build = 263 pages; bun run audit = exit 0, LAUNCH READY, 0
blockers; every dist/ soldi hit confirmed legit (the intentional "d/b/a Soldi" legal
disclosure + the "Soldiers Field" landmark) — zero leaks in the new SEO surfaces.
Note for Cam: during the auto fix-loop an agent briefly stripped the "Fair Home Cash LLC d/b/a Soldi" disclosure from the static legal pages to satisfy an over-strict verify check — reverted; legal pages are untouched by this PR (the firewall's soldi check is a non-blocking warning, so the disclosure is fine).
Deferred to a follow-up (staged in the plan): the situation×geo new page type
(/sell-{situation}-{city}), the content-generator change, and the off-site backlog
(GBP/NAP + real sameAs URLs, backlinks, AI-citation monitoring).
2026-06-25 — lead-engine doc reskinned onto docs.soldi.cc (PR 16, fast-follow)
- Built Zak's "Lead Engine — How It Was Built" writeup as a Soldi-dark page
(
docs/lead-engine.html), reskinned from the FHC navy/orange original into the closer-v2 system (Instrument Serif/Fraunces,--bull/--accent/--gold, grid texture). A confident, understated, blueprint-proof overview (per Cam): keeps the $0-lead proof + a plain description of how the system works, but (a) omits the implementation specifics (file names, page-variation mechanism, schema/stack/build details) so a client can't hand it to an LLM and rebuild it, and (b) drops the "this is hard / nobody can replicate it" framing — the dedicated moat section was cut for reading as defensive, and the difficulty-bragging was dialed back so the proof does the talking. (Two earlier cuts — dense-technical, then over-insistent — were revised to this.) Wired intodocs/build.ts(copied todist/lead-engine.html), served unlisted atdocs.soldi.cc/lead-engine. - Entrance is CSS-only (visible-by-default
risekeyframe, reduced-motion safe) — the initial IntersectionObserver version left below-fold content atopacity:0for full-page captures / no-JS / SEO; replaced it and dropped the script (simpler + robust). Removed one dead CSS class.
Verification: bun run build:docs green (dist/lead-engine.html, 22.7 KB); deployed
soldi-docs (version 27ed2b14+); live QA via chrome-devtools — full doc renders, zero
console errors.
Next up: optional — link it under an "Internal" nav group; fold the source PDF's exact NJ figures if any change. fhc-pages deploy still held behind the P0 legal gate.
2026-06-25 — monorepo restructure: app/ · docs/ · previews/ · sites/fhc-pages/
- Reorganized the repo into a Bun monorepo with four top-level deploy surfaces, each a
workspace (or independent project), so every surface maps cleanly to its domain:
app/→ app.soldi.cc ·docs/→ docs.soldi.cc ·previews/→ preview.soldi.cc ·sites/fhc-pages/→ fairhomecash.com. All via history-preservinggit mv(492 renames). Worker names + live domains unchanged → no redeploy needed, nothing breaks live. - The app moved wholesale into
app/(src/worker/migrations/public/index.html + all build config +.dev.vars). Only literal edit:wrangler.jsonc $schema→../node_modules. - Docs collision resolved:
tools/cloud-docs/*→docs/; the repo-root markdown KB →docs/content/;client/questionnaire.html→docs/questionnaire.html.docs/build.tsrewired (SURFACE/REPO_ROOT/DOCS=content). previews/(wastools/soldi-preview) andsites/fhc-pages/(wastools/fhc-pages, kept independently installed to preserve its Soldi-free brand firewall) relocated;$schemadepths +.claude/launch.json+ the.claude/workflows/*.jspaths repointed.- Root is now a bun-workspace orchestrator (
workspaces: [app, docs, previews]+deploy:*scripts that run from root so the shared.envtoken resolves). NewREADME.md;CLAUDE.md+AGENTS.mdrewritten to the monorepo map; a per-workspaceCLAUDE.mdadded to each surface. - Stashed Zak's "Lead Engine — How It Was Built" PDF + a content-upgrade brief at
docs/content/lead-engine/for the fast-follow.
Verification: bun run verify green (112 tests, build ok); bun run build:docs (6 internal
- 2 client docs) and
bun run build:fhc(263 pages) both build in their new homes; all four surfaces passwrangler deploy --dry-run(app/docs/fhc with bindings, previews assets-only). No live deploy.
Next up: PR 16 — reskin + content-upgrade of the Lead Engine doc onto docs.soldi.cc (see
docs/content/lead-engine/BRIEF.md). After merge + approval: redeploy each surface from root.
2026-06-04 — B+C drill-downs live; production floor fix (expired auctions) + self-heal; Sequences hidden
- B+C drill-downs shipped + deployed (
app.soldi.cc): reusable portalDetailDrawer→ PropertyDetail (Pipeline cards + Portfolio rows) + BuyerProfile (Leaderboard rows); Pipeline drag-to-move + drawer stage-edit via owner-scopedPUT /portfolios/:id/stage(action-logged, idempotent no-op) +movePipelineStageclient. All three drawers render-checked; polished. - Same-day UI fixes (live): Comps ARV-band de-collision + comp cards; Pipeline dead-button
cleanup (Filter removed, Add-lead toast); Portfolio range-toggle pill alignment; ChatPanel
portal-to-body + inline
position:fixed(drawer was trapped inline under a transformed ancestor); StageFunnel "Offer Out" crop. Deck: all 8 screenshots recaptured + funnel slide added. - Production "no properties" fix — root cause was NOT the bindings (D1 connected, all data intact).
The 32 seeded auctions had expired (seeded days earlier; the every-minute cron settled them all →
the Floor shows only
active/discount→ empty). Fix: (1) revived the auctions to live with fresh end-times; (2) self-heal —worker/scheduled.tsrestockDemoFloorre-rolls ended-unsold auctions back to live each cron tick, so the demo floor never silently empties again. - Sequences hidden + disabled (owner decision — see
docs/DECISIONS.md): removed from the nav + ⌘K command palette;/sequencesredirects to the Floor. It's a read-only seeded view (send-engine unbuilt) → not demo-ready. Backend routes + seeded data left intact; fully reversible.
Verification: bun run verify green (112 tests, build ok); live checks — Floor renders 32 lots,
?demo=1 auto-login 302 valid, /auth/me + /pipeline authed return data (8 demo portfolios, 6 stages,
35 comps). Deployed: app → app.soldi.cc; deck → docs.soldi.cc/walkthrough.
Next up: Sequences cron send-engine (then un-hide); live Comps provider (Lofty/ATTOM+AI); B/C fast-follows (buyer-profile detail endpoint for by-distress/recent-wins/badges); demo ROI seed realism.
2026-06-02 — Wave 3 (realtime): Durable-Object live bids + chat, sub-market houses, CountdownTimer perf
Built the ENRICHMENT_PLAN "realtime wave" end-to-end — local-only; app deploy HELD
(DO-migration hazard below). 5 phases, each verified + smoke-proven + committed:
- P0 — Realtime backbone (
c43f401):RealtimeRoomDurable Object (one class, two bindingsAUCTION_ROOM+FLOOR_FEED) on the WebSocket Hibernation API; pureworker/realtime/events.ts(RealtimeEvent union + ring/presence/mappers, +7 tests); the WS upgrade is handled in a fast-path before Hono/cors (worker/index.ts) so the 101 passes unmodified;worker/routes/realtime.ts=routeRealtime+ non-throwingbroadcastToRoom.wrangler.jsoncgains the DO bindings + migration tagv1(new_sqlite_classes:["RealtimeRoom"]). Smoke: WShello/presence/pongonwrangler dev. - P2 — Live bids + real ticker (
663b39b,6475990):bid.ts/buynow.ts/scheduled.tsbroadcastbid/soldto the auction + floor rooms viac.executionCtx.waitUntil(can never fail a bid/settlement).src/lib/realtime.tsuseRoomlayers WS over the surviving 5s poll (graceful degradation → the un-deployed live app is unaffected). LeadDetail live-reload, LiveTicker real floor feed, PriceDisplay flash-on-increase. Smoke: a real bid POST propagated to both rooms. - P3 — Live chat (
279a0e1,007e82d): per-auctionChatPanel(right-slide glass, live presence count, history seed + deduped append,ready-gated loading) on the auction room; LeadDetail "Room" toggle (socket only while open). Smoke: 2-tab echo + presence=2. - P4 — CountdownTimer perf (
d9fde70): per-instancesetInterval(1000)→ one shareduseNow()ticker (useSyncExternalStore); ~30 Floor countdowns share one timer. - P1 — Sub-market Auction Houses (
561c815,4f65e2d):/market/:idpage (metroLabel-encoded id) reusing AuctionGrid + scoped KpiBar; AuctionCard city-click enters a metro's house (Floor chip-filter preserved). Frontend-only.
Every UI phase ran the mandatory make-it-sexy → make-it-simpler pass (incl. LeadDetail split
449→296 via new LeadDetailDealSheet; a11y labels on chat/bid inputs).
Verification: bun run verify green after every phase — typecheck clean, 109 tests
(102 + 7 realtime), build ok (~635kB / 191kB gz). Local WS smokes (P0/P2/P3) on wrangler dev;
chrome-devtools render-checks on each polished page.
⚠️ DEPLOY HAZARD — DO migration pending: wrangler.jsonc now declares RealtimeRoom +
migration tag v1, so the next wrangler deploy of the soldi worker applies that DO
migration to app.soldi.cc (intentional — that deploy is what makes realtime live). Until
then the live app is unchanged (WS connects fail → clients fall back to the poll / mock ticker).
db:reset:local clears only D1, not DO storage — rm -rf .wrangler/state/v3/do before a clean
local reseed.
Next up: owner-approved app deploy to make realtime live + recapture the deck shots for the
realtime surfaces; optional server ?market= param + tags[]; manualChunks for the >500 kB bundle.
2026-06-02 — Sexy-everywhere: Motion + ⌘K + Sonner + OKLCH/glass + per-page enrichment
Worked the make-it-sexy group skills into EVERY page (then make-it-simpler). 20-agent workflow: Foundation → 9 pages (sexy+enrich) → simpler → verify.
- Deps added:
motion(motion/react),sonner,cmdk. App wrapped in<MotionConfig reducedMotion="user">+ a global Sonner<Toaster>. - ⌘K command palette (
src/components/CommandPalette.tsx, cmdk + Motion + glass): navigate to any page + quick actions; ⌘K hint chip in TopNav. - index.css (additive): OKLCH elevation ramp
--elev-0..3+.glass(specular, fallbacks) + CLS guards (scrollbar-gutter: stable, media aspect-ratio). - Per-page enrichment + Motion: Floor cards now data-rich ($/sqft, equity bar, mortgage, year, quality-breakdown spark, distress detail, distress-tinted spine, quality-tier ring) + sort (6-way) + distress + equity-tier filters; Lead detail gained media placeholder, Seller Motivation card, $/sqft+equity tiles, quality bars, bid-history sparkline, optimistic bidding; Portfolio Capital Flow viz + count-ups + 167×/+2400% ROI; Pipeline/Comps/Sequences/Leaderboard/Activity/Login all got Motion entrance/stagger/hover + count-ups + richer viz. Marketplace split into Marketplace.tsx + MarketplaceParts.tsx + FloorControls.tsx + AuctionCardMeta.tsx (all < 400 lines). format.ts gained pricePerSqft/sortAuctions/equityTier/qualitySpark/etc.
Fixes during QA
- vite.config.ts: added
resolve.dedupe: ['react','react-dom']— Motion pulled a 2nd React copy into the Vite dev optimizer → "Invalid hook call" crashes. (Rollup prod build was unaffected, but this fixesvite dev.) - AuctionCard spine: moved from
::afterto::before— it collided with the global.sheenhover-shine (::after, skewed), which skewed the distress spine into a diagonal streak across every card. Now a clean left-edge bar; sheen works on hover.
Verification: bun run verify → typecheck clean · 102 tests · build green
(JS 615kB / gzip 186kB incl. motion/cmdk/sonner). Browser-QA'd all pages (Floor cards,
Lead, Comps, Portfolio, ⌘K palette) — no console errors (only browser-extension noise),
no artifacts after the spine fix. Deployed: app → app.soldi.cc (new bundle); deck →
docs.soldi.cc/walkthrough with all 8 screenshots recaptured (the "after" set).
Known minor: Comps ARV-band comp-dot labels bunch when sale prices cluster (cosmetic); JS chunk > 500kB (Vite warning) — could add manualChunks/LazyMotion later.
Next up: Comps ARV-label de-collision + a manualChunks split; then realtime
(Durable-Object live bidding/chat) + Sequences send-engine per ENRICHMENT_PLAN.md.
2026-06-01 — Finalization: Comps + Sequences built, all pages wired, zero disabled tabs
Client-ready pass. Every nav tab is now a real, working, live-data page — no disabled flags, no mock/placeholder data.
- Comps (
/comps, new) —0006_comps.sql(comp_queries/comparables/arv_estimates),worker/comps.tsdeterministic provider + ARV/70%-rule math (+15 tests),routes/comps.ts(POST /comps/run, GET /user/comps/history),src/pages/Comps.tsx(ARV band + confidence + 70% offer marker + AI deal-read + 5 comp cards). PropStream replacement; mock provider swaps to Lofty/ATTOM+AI behind the same contract. - Sequences (
/sequences, new) —0007_sequences.sql(4 tables + rich seed: 3 sequences/steps/enrollments/messages),routes/sequences.ts,src/pages/Sequences.tsx(cadence list + step timeline + engagement stats). Follow Up Boss replacement (read view). - Portfolio wired →
routes/portfolio.tsreal KPIs (spend/assigned/net ROI/win rate)- Recent Wins, 30D/90D/YTD/All. Leaderboard wired →
routes/leaderboard.ts+0008_leaderboard_seed.sql(9 ranked buyers, podium, streaks). Activity wired →routes/activity.tsreal bid/win/listing events (5s poll).
- Recent Wins, 30D/90D/YTD/All. Leaderboard wired →
- Integration:
TopNavrenamed to Floor,soonLinks/disabled tabs DELETED, Comps + Sequences added as real NavLinks; routes inApp.tsx; 5 routes mounted inworker/index.ts. Final nav: Floor · Pipeline · Comps · Sequences · Activity · Portfolio · Leaderboard. - QA fixes (browser pass, all 8 pages): Activity actor-less rows now read
"New listing — …" (was a bare "listed" with a missing-name gap); Floor "MARKETS"
label no longer clipped to "KETS" (moved outside the scroll/edge-fade);
0009_demo_polish.sqlpulls the assigned deal into the window + stamps its $22K fee so Portfolio shows +2400% ROI / 17% win and Pipeline Assigned MTD 1 · $22,000 (were $0 / −100%). - Deployed: remote D1 migrated 0005–0009; app redeployed (
app.soldi.cc/ workers.dev) — all 5 new endpoints 200. Deck refreshed: Comps/Sequences slides flipped from "coming soon" → live, all 8 "after" screenshots recaptured totools/cloud-docs/shots/, redeployed (docs.soldi.cc/walkthrough).
Verification: bun run verify → typecheck clean · 102 tests · build green;
migrations 0001–0009 apply; browser QA of all 8 pages; zero soon/disabled in TopNav.
Next up: Sequences cron send-engine (Resend); Comps live provider (Lofty/ATTOM+AI);
realtime (Durable-Object live chat + Kalshi-style bid animations) per ENRICHMENT_PLAN.md.
2026-06-01 — Floor: Auction Floor rename + geo sub-markets + KPI bar + wider seed
Turned the flat slice-01 feed into a navigable trading floor. Renamed the public
page to Auction Floor (page <h1>; nav label Floor; route stays /,
file stays src/pages/Marketplace.tsx). Added a client-derived geo sub-market
layer over the existing feed — no API change: GET /api/v1/auctions already
returns the full embedded lead with city/state, so metros are a pure
projection.
- Geo filtering — canonical
metroLabel(lead)→"City, ST"(src/lib/format.ts) drives all three entry points: theMarketschip strip (shown when >1 metro, counts track the active status tab — filters compose), a clickable city on each card (.ac-geo,onSelectMetro;preventDefaultso it doesn't open the lead), and a?market=deep-link (URL is the source of truth viauseSearchParams;replace-writes, deletes param onAll, self-heals toAllwhen the active metro leaves the cohort). GridcohortKey=`${tab}|${market}`so any filter change re-runs the entrance cascade. - KPI bar (
KpiBar) — four tiles over the full active cohort: Total Volume, Avg Price, Hot (quality ≥ 80), Markets (distinct metro count). INTEGER cents viaformatPrice;tnumfigures. - Wider seed (
migrations/0005_floor_seed.sql) — +20 leads / +20 auctions (8 new metros: LA, Brooklyn, Tampa, Charlotte, Las Vegas, Denver, Cleveland, San Antonio + extras in Chicago/Phoenix/Atlanta). AdditiveINSERT OR IGNORE, D1 separate-modifier datetimes, 2 discount lots. - PRD:
docs/prd/AUCTION_FLOOR.md.
Verification evidence
$ bun run test → 87 passed (7 files)
pricing 8 · bidding 20 · mappers 8 · settlement 7
format 16 · pipeline 14 · auth 14
$ bun run build (tsc -b && vite build) → clean
67 modules · index.js 296.94 kB (gzip 91.87) · index.css 58.02 kB (gzip 11.13)
$ rm -rf .wrangler/state/v3/d1 && bun run db:migrate:local
0001…0005 all ✅ (0005_floor_seed applies clean)
$ wrangler d1 execute soldi --local --command "SELECT … FROM auctions/leads"
→ feed_count (status IN active,discount) : 32
total_auctions : 32
distinct_markets : 15
total_leads : 33
Floor count is now 32 active auctions across 15 metros (was 12 in slice 01). All touched files <400 lines; no comments on untouched code; no new secrets; not deployed.
Next up
Re-capture .qa-walkthrough/ Floor screenshots (geo strip + KPI bar are the new
"after"), refresh the walkthrough deck's Floor frame, then start the per-metro
"auction house" drill-down (/market/:metro) or live bid animations per
docs/ENRICHMENT_PLAN.md.
2026-06-01 — Ops: deck iframe-default, demo auto-login, AGENTS/CLAUDE, enrichment review
- app.soldi.cc custom domain added (by owner via dashboard) → app live there + workers.dev.
- Deck now defaults to the live iframe for public pages (Floor, Lead); authed pages
(Pipeline, Portfolio) default to the populated screenshot + "Open live ↗" (new tab).
Deck embeds the
workers.devorigin (reliable in cross-origin iframes; the just-addedapp.soldi.ccwas blank in-iframe — custom-domain edge still settling). ?demo=1auto-login added to the worker (logs in the seeded demo account, redirects clean) for first-party "Open live" links. Session cookie switched toSameSite=None; Securefor iframe embedding (demo posture — revisit CSRF for prod). 87 tests green (updated cookie test). Note:?demo=1only fires on non-asset routes (Static Assets serve/before the worker), which is fine — authed deep-links (/pipeline etc.) are non-asset.- AGENTS.md + CLAUDE.md added: bracket every workstream with a start (read ledger, bootstrap+verify) and end (verify → refresh deck+screenshots+docs → redeploy → flag stale) discipline; sexy+simplify mandatory; infra/demo quick-ref.
- Enrichment review (
soldi-enrichment-reviewworkflow, 25 agents: 9 page reviews → 59 subcomponent deep-dives) → synthesized todocs/ENRICHMENT_PLAN.md: per-page beef-ups/metrics/layout-fixes/standalone-verdict/seed plan; cross-cutting (geo sub-markets /"auction houses", Durable-Object live chat, Kalshi-style live bid animations); notable fixes (CountdownTimer per-instance setInterval perf bug; QualityBadge/HotBadge DRY). Comps + Sequences confirmed present in v2 prototype + specs (not lost) — queued to build. - Before/after baseline:
.qa-walkthrough/screenshots = "before"; re-capture after enrichment.
2026-06-01 — Ops: live app deploy + interactive walkthrough deck
Live app deployed (first remote deploy, explicit owner approval): created remote
D1 soldi (d7b25c82…), wired into wrangler.jsonc, applied migrations 0001–0004
- seed to
--remote, set remoteSESSION_SECRET, deployed →https://soldi.camolechowski.workers.dev(workers_dev:true; cron settlement live). Verified: health OK, 12 auctions from remote D1, SPA 200, logindemo@soldi.cc/soldidemo. Theapp.soldi.cccustom domain failed (API token lacks Workers-Routes perm on the soldi.cc zone — error 10000); add via dashboard or a zone-scoped token later.
Interactive walkthrough deck → https://docs.soldi.cc/walkthrough (path on
the existing soldi-docs static-assets worker). tools/cloud-docs/walkthrough.html:
a self-contained 13-slide presenter deck — intro + one slide per page (Floor, Bidding,
Pipeline, Portfolio, Leaderboard, Activity, Comps, Sequences, Accounts, Admin) +
consolidated decisions + roadmap. Per slide: status badge (live/seeded/soon/planned),
"what it does", a "Decisions we need from you" callout, and a media pane that shows
the captured screenshot with a ▶ Go live toggle that swaps in a live <iframe> of
the deployed app (+ "Open in new tab"). Toolbar/keys: L live, D spotlight
decisions, N presenter notes, A annotate (drop/drag/type sticky notes, saved to
localStorage — the "superimpose content" layer); ←/→ + number-key nav + slide rail.
Screenshots from the QA walkthrough agent (shots/) baked into the build.
Verified live: /walkthrough 200, shots 200, Go-live iframe loads the real marketplace.
Caveat: authed pages (Pipeline/Portfolio) inside the cross-origin iframe render logged-out (SameSite=Lax session cookie isn't sent third-party) — use each slide's "Open in new tab ↗" for authed interaction (demo login). Floor/Lead are fully interactive in-iframe (public).
2026-06-01 — Slice 05: Pipeline board (read-only CRM kanban)
What shipped
migrations/0003_pipeline.sql— reconcilesportfolios.statusto the 6-stage enum (new | contacted | offer | under-contract | assigned | dead; legacyfollow_up/under_contract/convertedmapped over), addsportfolio_stages(1:1,current_stage/stage_entered_at/next_action_*/offer_sent_amount_cents/assignment_*/stale_days_threshold) +portfolio_actions(activity log) +portfolios.next_action_due_at(indexed). Seeds ~6 demo portfolios forU_SEED_GHOSTspread across stages (incl. a stale "offer" 18d row, an under-contract, an assigned) with matching stage + action rows.worker/pipeline.ts— pure aggregation (no D1):groupCardsByStage(all 6 stages always present, fixed order),computeKpis(leadsInPipe excl. dead, underContract count+gpCents, assignedMtd, conversionPct guarded against /0, avgStageAgeDays, staleCount),applyFilter,isStale(per-row threshold),rowToCard,buildPipeline.worker/pipeline.test.ts(+14 tests).worker/routes/pipeline.ts—GET /pipeline?filter=…:currentUsergate (401), Zodfilterenum (400 on bad value), joinsportfolios ⨝ portfolio_stages ⨝ leadsfor the session user,stage_age_dayscomputed viajulianday('now') - julianday(stage_entered_at)in SQL (never client-parsed). Mounted inworker/index.tsviaapi.route('/', pipelineRoutes).- Frontend:
fetchPipeline()+ Pipeline DTO types insrc/lib/api.ts;relativeDue()(today/overdue/future/none) insrc/lib/format.ts(+4 tests);src/pages/Pipeline.tsx6-column kanban (6→3 @1300px scoped<style>, stage-colored left borders, KPI row, filter chips w/ counts, card next-action/offer/progress,.skeleton+ empty + error states);/pipelineroute inApp.tsx; Pipeline promoted fromsoonLinksto a realNavLinkinTopNav(Comps/Sequences still disabled).
Verification
$ bun run verify → typecheck clean · Tests 87 passed (87) · build green
(69 prior + 14 worker/pipeline.test.ts + 4 new relativeDue cases)
worker/pipeline.test.ts: grouping (6 stages, empty stages count:0),
KPIs (dead excluded, gpCents, assignedMtd, conversionPct no NaN on empty),
applyFilter (due_today/overdue/stale_14d/under_contract; all = identity),
per-row stale threshold.
As-built divergence from PRD: third stage key shipped as offer
(display "Offer Out"), not the PRD's offer-sent, consistently across the enum,
migration, and API DTO. under_contract filter key unchanged. docs/prd/FEATURE.md
updated to SHIPPED + reconciled.
Demo access: migrations/0004_demo_login.sql sets the seeded board owner
(U_SEED_GHOST) to demo@soldi.cc / soldidemo (PBKDF2 hash computed via
worker/auth.ts) so the populated Pipeline is reachable in the demo — /pipeline
is gated to the logged-in user, so a fresh signup sees an empty board.
Independently re-verified: 87 tests, typecheck/build green, 0001–0004 apply
clean, GET /pipeline returns all 6 stages + KPIs, kanban screenshot confirmed.
Process note: this slice was the first run of the reusable
.claude/workflows/feature-lifecycle.js (discover→plan→build/verify→sexy→
simplify→confirm→document). args did not reach the script, so the Discover
phase read docs/ROADMAP.md and self-selected Pipeline — a useful robustness
property, but pass-args propagation should be confirmed for targeted runs.
Next up: Pipeline writes (slice 3) — PUT /portfolios/:id/stage (drag-drop
moves) + POST …/actions + next-action edits, with the sequence-enrollment
event hook the portfolio_actions table was scaffolded for.
2026-06-01 — Slice 04: Keystone — cron auction resolution + buy-it-now
What shipped
worker/settlement.ts— puresettleOutcome({status,endTimeIso,nowMs,topBid})→skip | sold | unsold(usesparseDbTime).settlement.test.ts(+7 tests).worker/scheduled.ts—settleDueAuctions(env,now)+ exportedscheduled()handler; cron["* * * * *"]in wrangler.jsonc. Settles auctions pastend_time: SOLD → statusended_sold+ winning ids, converts leader hold→charge (held_balance/balancedown,total_spent/leads_wonup, streak bump),wallet_transactions 'charge', insertsportfoliosrow; UNSOLD →ended_unsold. Status-guarded UPDATEs (idempotent) + per-auction try/catch (resilient).worker/routes/buynow.ts—POST /auctions/:id/buy-now: instant settlement (insert is_buy_now bid, release prior leader hold, charge buyer, ended_sold, portfolio row). Errors 401/404/409/402.- Frontend:
buyNow()in api.ts; LeadDetail "Buy it now" button enabled withsubmitBuyNow(mirrors submitBid; toast + balance refresh). Skeleton extracted to keep the file < 400 lines.
Verification
$ bun run verify → typecheck clean · Tests 69 passed (69) · build green
# wrangler dev --test-scheduled on :8787 (fresh bootstrap)
buy-now A_CHI_TAXLIEN_03 → bought:true, status ended_sold; buyer 50000→39200,
totalSpent 10800, leadsWon 1, streak 1; portfolios row (status 'new') created.
real bid 13835 (held 13835) → force end_time past → /__scheduled trigger →
auction ended_sold (winning_user_id set); buyer 39200→25365, held→0,
totalSpent 24635, leadsWon 2, streak 2; portfolios=2. Idempotent on re-run.
Next up: Portfolio KPIs + weekly Leaderboard from D1 (now that settlement populates real data); then CI + a Playwright bid/buy-now e2e.
2026-06-01 — Ops: cloud-docs response persistence (KV)
Added KV-backed submission capture to the soldi-docs worker:
- KV namespace
RESPONSES(29c8518…) bound intools/cloud-docs/wrangler.jsonc. - Worker:
POST /api/responsesstores{id, submittedAt, country, userAgent, answers}underresp:<id>;GET /api/responses[/:id]lists/fetches. All open (light, non-confidential — no auth, no token to paste). Everything else → assets. - Questionnaire: added a "Submit to soldi →" button that POSTs the export object
to
/api/responses(graceful fallback to local download when offline). - Verified live: POST→
{ok,id}, list/by-id round-trip (country US, answers intact), invalid JSON→400, open GET→200. Read responses:curl https://soldi-docs.camolechowski.workers.dev/api/responses.
Docs IA + custom domain: home is now a client-doc index ("Released to you" =
Product Direction; "Internal references" = roadmap/specs/build-log). The
questionnaire is served at the clean path /product-direction (old
/questionnaire.html 307→redirects). Custom domain docs.soldi.cc added to
the worker (routes custom_domain; soldi.cc is an active zone on the account) —
workers.dev URL still serves too.
2026-06-01 — Ops: reproducible setup + codebase-wide simplify (round 2)
Setup hardened: pinned wrangler dev to :8787; added bootstrap
(reset+migrate+seed), start (build+dev), verify (typecheck+test+build),
db:reset:local. Clean-slate bootstrap → verify → start proven: health OK,
12 auctions from D1, SPA 200.
Simplify round 2 (8 agents, disjoint lanes incl. worker):
worker/index.ts402→36 lines, split intoworker/routes/{auctions,bid,auth}.ts- shared
worker/users.ts(UserRow/publicUser/USER_SELECT_SQL/currentUser);currentUser(c)takes the Context directly; STATUS_WHERE map; deduped bids SQL; removed dead SessionVars.
- shared
- frontend: deduped
FeedState,QUALITY_ROWSmap, hoisted per-render consts,StatusDotprimitive,postJsonhelper in api.ts,run()helper in session.tsx, deleted deadformatPriceDelta. index.css: removed 23 dead back-compat aliases (verified zero orphaned utility usages acrosssrc/).- Verified: typecheck clean · 62/62 tests · build green · 0 orphaned classes ·
login + marketplace screenshots confirm no visual regression. Snapshot:
.backup_src_round2.tgz.
2026-06-01 — Ops: UI polish pass + cloud docs deployed
Polish workflow (25 agents): per-page apply of the make-it-sexy sub-skills
(cutting-edge-ux-patterns, fluid-micro-interactions, high-end-ui-assembly,
modern-visual-aesthetics; rsc-streaming-architectures correctly skipped for a
Vite SPA) then make-it-simpler, then a final unscoped DRY pass. Net: micro-
interactions/reveal staggers, deduped FeedState/SectionHeading/Collapse,
DRYed bid-reload + min-bid rounding, null-safe badges. No new deps; index.css
frozen except the solo final pass. Verified: typecheck clean · 62/62 tests ·
build green · screenshot. Pre-pass snapshot at .backup_src_phaseUX.tgz.
Cloud docs deployed → tools/cloud-docs/ (Workers Static Assets). build.ts
renders docs/*.md + BUILD_LOG.md → soldi-branded HTML and folds in the client
questionnaire. Live (personal CF account, creds from .env):
https://soldi-docs.camolechowski.workers.dev (routes: /roadmap, /design-system,
/spec-comps, /spec-pipeline, /spec-sequences, /build-log, /questionnaire.html).
Gotcha: an assets-only Worker (no
main) returned a persistent edgeerror 1105/ 503 on workers.dev despite a successful upload and an enabled subdomain. Fix: add a minimalmainentry (src/index.ts→env.ASSETS.fetch(req)) with anASSETSbinding — the canonical Workers-Static-Assets form. Use this in thetools/wrangler template.
2026-06-01 — Phase A: Design-system migration (closer-v2 reskin, still "soldi")
What shipped (foundation written inline; 4 page-restyles fanned out in parallel)
src/index.css— rewrote@theme+:rootto the closer-v2 metallic palette (bull/bear/warn/hot/accent-lavender/gold + surface/text/border tiers), added Fraunces/Instrument Serif/Hanken Grotesk/JetBrains Mono tokens, the 56px grid wash (body::before), new shadows/radii, keyframes (price-flash, urgent-pulse, reveal-up), and a button variant system (.btn-primarynow bull,.btn,.btn-ghost,.btn-danger,.pill,.chip,.qscore). Old token names kept as aliases so utilities keep resolving during the migration. No Robinhood green.index.html— swapped font<link>to Fraunces/Instrument Serif/Hanken Grotesk/ JetBrains Mono; body bg#0B0D0E.- Restyle agents (disjoint files): shell (TopNav wordmark = "soldi" in
Instrument Serif + bull dot; tab-bar nav with disabled Comps/Pipeline/Sequences
"soon" tabs; LiveTicker; Layout), floor+cards+ui (Marketplace "The floor",
AuctionCard/Grid, QualityBadge→
.qscoreconic circle, PriceDisplay/Countdown/ HotBadge/DistressTag), lead-detail (bidding panel — logic preserved), and portfolio+misc (Portfolio/Leaderboard/Activity/Login). - Name stays "soldi" everywhere (worker, package, wordmark). Only "closer" reference left is an internal doc comment noting the prototype's origin.
Verification (commands + key output)
$ bun run typecheck → tsc -b clean
$ bun run test → Test Files 5 passed (5) · Tests 62 passed (62) (logic intact)
$ bun run build → ✓ built; dist/assets/index-*.css 35.00 kB
# wrangler dev :8787 + chrome-devtools screenshots:
# / (marketplace) → soldi wordmark, tab bar, "The floor" (Fraunces),
# conic quality circles, distress/equity/age chips,
# mono prices, bull quick-bid buttons.
# /lead/A_PHX_PROBATE_07 → Instrument Serif address, Fraunces section heads,
# bid input prefilled to min ($250), bull "Sign in to
# bid" CTA, restyled bid history. Bidding UI intact.
Next up
Phase B — fan out the 3 new pages (Pipeline read · Comps UI+mock · Sequences
read) per docs/ROADMAP.md, each with its own migration + Hono route + page,
worktree-isolated, verified per vertical.
2026-06-01 — Slice 03: Bidding end-to-end (increments, holds, anti-snipe)
What shipped
worker/bidding.ts— pure, unit-testable rules:minBidIncrement($5 or 5%, whichever greater),minNextBid,applyAntiSnipe(final-2-min window → +2min, max 5 extensions),validateBid, andparseDbTime(normalizes SQLite's space-separateddatetime()output to ISO-UTC).worker/index.ts—POST /api/v1/auctions/:id/bid: auth-gated, Zod body, loads auction + current leader, validates, applies anti-snipe, and writes atomically viaDB.batch— insert bid, bumpcurrent_price/bid_count/end_time/snipe_extensions, place the new leader's hold, release the prior leader's hold, and recordhold/releasewallet_transactions. Returns the refreshed auction +extendedflag. Error map: 401 unauthorized, 404 not_found, 409 auction_ended/already_leading, 422 bid_too_low, 402 insufficient_funds.worker/bidding.test.ts— 20 unit tests (increment floor/percent, snipe window/boundary/cap/ended, db-time parsing both formats, all validation paths).src/lib/api.ts—placeBid()helper.src/pages/LeadDetail.tsx— live bid form (input prefilled to min next bid), error-code→toast mapping, "Extended! 2:00 added" toast on anti-snipe, 5s auction polling (PRD §12), balance refresh after a successful bid.
Verification (commands + key output)
$ bun run typecheck → tsc -b clean (exit 0)
$ bun run test → Test Files 5 passed (5) · Tests 62 passed (62)
$ bun run build → ✓ 62 modules transformed; built in ~0.6s
# local D1 + wrangler dev on :8787 (after rm -rf .wrangler/state/v3/d1
# && bun run db:migrate:local && bun run db:exec:local migrations/0002_seed.sql)
POST /auctions/A_CHI_PREFCL_01/bid (no auth) → 401
POST … {amount:13000} (< minNext 13335) → 422 bid_too_low
POST … {amount:60000} (> available 50000) → 402 insufficient_funds
POST … {amount:13335} (valid, bidder A) → 201 currentPrice 13335, bidCount 6
POST … {amount:15000} (A already leader) → 409 already_leading
GET /auth/me (A) → heldBalance 13335, balance 50000
POST … {amount:15000} (bidder B outbids A) → 201
GET /auth/me (A) → heldBalance 0 | (B) → heldBalance 15000 (prior hold released)
wallet_transactions(A) → hold 13335 then release 13335 (reference A_CHI_PREFCL_01)
# anti-snipe: forced A_DAL_CODE_09 end_time to +60s, bid as B
POST … {amount:7850} → {extended:true}; end_time 04:14:51 → 04:16:51 (+2:00); snipe_extensions 0→1
Gotcha caught during verify
D1's datetime() returns space-separated timestamps (2026-06-01 04:13:27, no
T, no Z), which Date.parse turns to NaN in workerd. First anti-snipe
test silently failed (extended:false, no extension) AND the auction_ended
guard would never trip (NaN <= now is false). Added parseDbTime to normalize
both SQLite and ISO formats; re-verified the extension fires (+2min, ext 0→1).
Next up
Design-system migration (foundation slice) per docs/DESIGN_SYSTEM.md — port
the closer v2 tokens/typography/components into index.css + index.html and
restyle the existing pages, no data changes. Then the 3 new pages (Pipeline,
Comps, Sequences) per docs/ROADMAP.md Phase B.
2026-05-29 — Slice 01: Marketplace feed end-to-end from D1
What shipped
migrations/0002_seed.sql— 13 leads + 12 auctions across IL/FL/AZ/TX/GA/CA, all distress types, quality 34–91, freshness from 15min to 32h old, 1 discount auction, 1 placeholder user, 5-bid history on the Phoenix probate auction. All times anchored todatetime('now', ...)so "ending soon"/"new" tabs stay realistic across runs.worker/mappers.ts— snake_case D1 row → camelCase frontendAuctionDTO with nestedleadandbids[], includingQualityBreakdownJSON parsing guarded by Zod and a fallback for malformed JSON. SharedAUCTION_SELECT_SQLfor list + detail.worker/index.ts—GET /api/v1/auctions?status=active|discount|all&limit=N(Zod-validated query) andGET /api/v1/auctions/:idreturning the auction with full bid history joined tousers.display_handle. Proper 404 for unknown ids.worker/mappers.test.ts— 8 unit tests covering the row→DTO mapping, JSON parse fallbacks, discount flags, status coercion, bid attachment.src/lib/api.ts— tiny typed fetch helpers (fetchAuctions,fetchAuction) with AbortSignal support.src/pages/Marketplace.tsx— replacesMOCK_AUCTIONSwith live API. Loading skeleton, error card, empty-tab card. Tab filters now run against real D1 data.src/pages/LeadDetail.tsx— fetches the single auction by id, renders a bid history panel when present, loading/error/missing states.
Verification (commands + key output)
$ bun run typecheck
$ tsc -b
# (clean)
$ bun run build
$ tsc -b && vite build
✓ 60 modules transformed.
dist/index.html 0.82 kB │ gzip: 0.46 kB
dist/assets/index-Cf1hfNuH.css 23.05 kB │ gzip: 5.25 kB
dist/assets/index-CLIXHb-m.js 252.42 kB │ gzip: 79.57 kB
✓ built in 574ms
$ bun run test
Test Files 3 passed (3)
Tests 28 passed (28)
Local D1 + wrangler dev smoke (after rm -rf .wrangler/state/v3/d1 && bun run db:migrate:local):
$ curl -sS http://localhost:8788/api/v1/health
{"ok":true,"service":"soldi","time":"2026-05-30T04:13:07.901Z"}
$ curl 'http://localhost:8788/api/v1/auctions?status=all&limit=100' → count: 12
A_CHI_TAXLIEN_03 Chicago, IL q=62 price=$54 ends 04:54 (ending-soon)
A_PHX_TAXLIEN_13 Phoenix, AZ q=80 price=$29 status=discount
A_CHI_PREFCL_01 Chicago, IL q=87 price=$127
A_PHX_PROBATE_07 Phoenix, AZ q=89 price=$238
A_MIA_DIVORCE_06 Miami, FL q=81 price=$172
A_DAL_ABSENTEE_08 Dallas, TX q=65 price=$62
A_ATL_PREFCL_10 Atlanta, GA q=76 price=$111
A_CHI_PROBATE_02 Chicago, IL q=78 price=$142
A_MIA_TAXLIEN_05 Miami, FL q=91 price=$210
A_HOU_PROBATE_11 Houston, TX q=83 price=$132
A_SPRING_VACANT_04 Springfield,IL q=34 price=$25
A_DAL_CODE_09 Dallas, TX q=70 price=$69
$ curl http://localhost:8788/api/v1/auctions/A_PHX_PROBATE_07
bids: 5 (PhoenixVolume @ $190 → $205 → $218 → $225 → $238)
qualityBreakdown: {equity:25, motivation:25, propertyValue:20, contactQuality:12, dataCompleteness:7}
$ curl /api/v1/auctions/does_not_exist → HTTP 404 {"error":"not_found"}
$ curl '/api/v1/auctions?status=discount' → count: 1 (A_PHX_TAXLIEN_13)
$ curl / → HTTP 200, <title>soldi - Distressed Property Lead Auctions</title>
$ curl /lead/A_CHI_PREFCL_01 → HTTP 200 (SPA fallback)
Gotcha caught during verify
First seed run inserted only 9/12 auctions silently. Root cause: SQLite
datetime() takes modifiers as separate arguments — '+23 hours 30 minutes'
is not a valid single modifier and returns NULL, which then violated
end_time NOT NULL under INSERT OR IGNORE. Fixed three rows to use
datetime('now','+23 hours','+30 minutes') form. Re-applied migrations after
wiping .wrangler/state/v3/d1; now 12/12.
Next up
Auth + identity (the second slice that unlocks bidding, watching, portfolio,
wallet). Concretely: a register/login pair on /api/v1/auth, password hashing
with the Web Crypto API (PBKDF2 — no node bcrypt in Workers), a signed
session cookie or short JWT, a useSession() hook, and a GET /user/profile
endpoint backed by the existing users row. The bidding slice depends on
having a user_id to charge/hold against.
2026-05-30 — Slice 02: Auth + identity end-to-end
What shipped
worker/auth.ts— Web Crypto PBKDF2-SHA256 password hashing (100k iterations, 16-byte salt, 32-byte hash; stored aspbkdf2$<iters>$<salt-b64>$<hash-b64>), constant-time compare, HMAC-SHA256-signed session token (<body-b64>.<sig-b64>, 30-day TTL, expiry embedded in payload),buildSessionCookie/clearSessionCookie/readSessionCookiehelpers (HttpOnly,SameSite=Lax), andgenerateId/generateHandleFromNamehelpers.worker/types.ts—Envnow carriesSESSION_SECRET. Local secret in.dev.vars(gitignored), required by both/auth/registerand/auth/login.worker/index.ts— five new endpoints under/api/v1:POST /auth/register(Zod-validated{email, password>=8, name}, 409 on dup email, sets cookie, also writes awallet_transactionssignup_bonusrow crediting the $500 demo balance).POST /auth/login(verifies hash, updateslast_active_at, sets cookie, 401 on bad creds).POST /auth/logout(clears cookie).GET /auth/me(returns{ user | null }, never 401 — used by the session hook on every page load).GET /user/profile(401 if unauth; returns the same public-user shape).- Shared
USER_SELECT_SQL+publicUser()redactpassword_hashand other internal flags before returning to the client.
worker/auth.test.ts— 14 unit tests: salting, wrong-password, malformed-hash, token round-trip, tampered body, foreign secret, expired token, malformed token, cookie shape, cookie clear, cookie read, id uniqueness, handle suffix.src/lib/api.ts—fetchMe/login/register/logouttyped helpers withcredentials: 'same-origin'and a sharedreadErrorthat pulls the API's{ error }code out of the body.src/lib/session.tsx—SessionProvider+useSession()hook with{ user, loading, error }state pluslogin/register/logout/refreshactions; auto-fetches/auth/meon mount.src/pages/Login.tsx— dark Robinhood-style login + register form (toggleable,?mode=registerdeep-link), inline error mapping for the API error codes (invalid_credentials,email_taken,invalid_body,server_misconfigured), accent-glow focus rings.src/layouts/TopNav.tsx— replaces the mock balance + initials chip with the real session. Shows a loading shimmer while/auth/meresolves, a real balance pill + initials button (with a popover forSign out) once authed, andSign in/Sign uplinks when not authed.src/App.tsx— wraps the router in<SessionProvider>and adds the/loginroute.
Verification (commands + key output)
$ bun run typecheck
$ tsc -b
# (clean — exit 0, no output)
$ bun run test
Test Files 4 passed (4)
Tests 42 passed (42)
$ bun run build
✓ 62 modules transformed.
dist/index.html 0.82 kB │ gzip: 0.46 kB
dist/assets/index-DGVY73fC.css 27.88 kB │ gzip: 5.92 kB
dist/assets/index-DD7iVCN9.js 260.12 kB │ gzip: 81.49 kB
✓ built in 593ms
Local wrangler dev smoke (after wiping .wrangler/state/v3/d1 and
re-running bun run db:migrate:local). The dev server bound to a
random port (59545) this run — wrangler@3.114.17 no longer pins
to 8788; check the boot banner.
$ curl /api/v1/auth/me → {"user":null}
$ curl /api/v1/user/profile → HTTP/1.1 401 Unauthorized
$ curl POST /auth/register {bad} → HTTP/1.1 400 Bad Request
(Zod issues for email/password/name)
$ curl POST /auth/register → HTTP/1.1 201 Created
{cam@soldi.test, hunter222, "Cam Olechowski"}
Set-Cookie: soldi_session=…; HttpOnly; SameSite=Lax; Max-Age=2592000
{user.id: U_MPT9JLPC_…, displayHandle: CamOlechowsk7389,
balance: 50000, heldBalance: 0, createdAt/lastActiveAt set}
$ curl /auth/me (with cookie) → {user: {…full profile…}}
$ curl /user/profile (with cookie) → HTTP/1.1 200 OK
$ curl POST /auth/register {dup} → HTTP/1.1 409 Conflict {"error":"email_taken"}
$ curl POST /auth/login {wrong pw} → HTTP/1.1 401 Unauthorized {"error":"invalid_credentials"}
$ curl POST /auth/login {correct} → HTTP/1.1 200 OK + Set-Cookie + updated last_active_at
$ curl POST /auth/logout → HTTP/1.1 200 OK + Set-Cookie: …; Max-Age=0
$ curl /auth/me (post-logout) → {"user":null}
$ curl /api/v1/auctions?status=all&limit=200 → count: 12 (slice 01 still green)
$ curl / and /login → HTTP/1.1 200 OK (SPA + fallback intact)
$ wrangler d1 execute soldi --local --command \
"SELECT type, amount, description FROM wallet_transactions WHERE user_id = 'U_…';"
→ {type: 'credit', amount: 50000, description: 'Welcome bonus'}
Gotcha caught during verify
Wrangler 3.114 no longer defaults wrangler dev to port 8788 — it
picks a random ephemeral port (this run: 59545) and prints it in the
boot banner. The first curl against the assumed 8788 failed
("Couldn't connect"). Pulled the port out of the wrangler stdout
([wrangler:inf] Ready on http://localhost:59545) before re-running
the smoke battery. Worth pinning dev.port in wrangler.jsonc on a
later polish slice so the port stops moving between runs.
Next up
Bidding — the slice that finally turns soldi into an auction house.
Concretely: POST /api/v1/auctions/:id/bid with Zod-validated amount,
PRD §8 increment table enforcement, balance + held-balance accounting
(reserve the new highest bid, release the prior leader's hold), PRD §9
anti-snipe (+30s if the bid lands in the last 30s, capped at 12
extensions / 6 min), insert into bids, update auctions
current_price / bid_count / end_time / snipe_extensions, and
return the refreshed auction. Frontend: a bid input + submit on
LeadDetail wired through the session, optimistic bid-history
prepend, balance refresh, and error toasts for the failure modes
(insufficient_funds, bid_too_low, auction_ended,
unauthorized). Tests: a worker-side unit test for the increment +
anti-snipe rules.
2026-06-09 — fhc-pages: Fast Home Cash landing page generator (launch-ready)
- New
tools/fhc-pages/: programmatic generator for fasthomecash.us — 51 state hubs + 200 city pages (incl. Chicago South Side / West Side / South Suburbs deep pages for the primary IL market), built with Bun + ETA + Zod, served by a dedicated Cloudflare Worker (port 8790, separate from the soldi app). - Lead capture: 3-step hero form + 2-step exit-intent popup, both POSTing
occupancy/reason/listed_status + condition/timeline/ownership + TCPA consent
- utm/landing-page tags to /api/offer-request. Meta Pixel + GA4 events wired (PageView → AddToCart → Lead).
- Content: hand-written human-voice "Local Insight" for all IL/TX/FL pages; generated first drafts elsewhere. Hand-curated, visually-reviewed photography for the 24 focus pages; style-matched photo pools everywhere else.
bun run audit: launch gate checking SEO (unique titles/descriptions, canonicals, JSON-LD, sitemap), tracking, compliance links, TCPA consent, internal links, image liveness (--images), and brand safety (zero "Soldi" references — these pages must read as a standalone buyer).docs/LAUNCH-PLAYBOOK.md: full Meta/Google/SEO/compliance launch sequence, incl. Housing special-ad-category handling and week-by-week first campaigns.- Deploy needs env vars (FHC_META_PIXEL_ID, FHC_GA4_ID, verification tags); audit blocks deploys with placeholder IDs. Not deployed yet — local verify only, per repo policy.
2026-07-07 — Wave-2 Bucket B: programmatic UI validation harness + all three user-facing surfaces green
- Crash recovery: Docker VM died (disk full) mid-wave; all 16 local commits
survived, orphaned work checkpointed, scratchpad Playwright env survived
(rebuild recipe now in
tools/ui-validate/README.md). tools/ui-validate(B0): headless-Chromium harness — overflow / console / CLS / tap-target / chrome-height / computed-style assertions + screenshots, presets per surface, runs in-sandbox. Replaces "mac screenshot session" evidence with reproducible programmatic proofs.- App B3–B5 (B1): 32/32 assertions at 375×812 on Market/Leads/Territories/
Billing/Settings vs local wrangler dev (chrome 132px ≤ 150), scripted B4
drawer proof 8/8, B5 tablet/desktop clean → BETA_READINESS B3–B5
[MET]; D2 app-deploy decision now waits on Cam only. Found + fixed en route: session cookie hardcodedSameSite=None; Secure(dropped over local http; prod cookie byte-identical after fix, +4 tests, verify 249 green). - FHC responsive pass (B2): live 375px overflow on 4 template classes (+99px
header CTA stack, +12px nowrap badges/CTAs), font-swap CLS 0.15–0.19, tap
targets down to 21px → all fixed in templates/statics, empirically verified
zero hit-area overlaps. Deployed: live
fhcpreset 133/133 (was 119/133; audit 0 blockers). Follow-up flagged: font preload net for display=optional. - Previews: agent-ads-ops font-swap CLS 0.31–0.35 → 0 via display=optional, deployed f7c0082d, live 15/15.
2026-07-10 (late night) — Zak's SEO PR #168 shipped + Meta pixel LIVE (PR #169)
- PR #168 (Zak) merged + deployed: SEO waves 1-2 (robots Disallow /api/ + /collect, sitemap noindex cleanup, 301 /sell.html→/, per-state geo.region, city-meta dedupe, CLS/touch fixes) + 9 new content pages (/about, /resources hub + 5 guides, 2 comparison pages) + FAQ truth-sync. Gates: 549 pages, audit LAUNCH READY, firewall clean (only Soldiers Field). Live-verified: /about 200, robots + redirect + US-CO geo tag confirmed at edge.
- GSC: Validate Fix started on Not found (404) + Blocked (4xx) buckets; homepage re-index requested (favicon nudge). Indexed 330 / not-indexed 25.
- Meta pixel DONE: Cam created dataset "Fair Home Cash" 2141308983102237
(Velli business, Account Quality clean — no restriction found). Deployed via
env, then PR #169 baked it as the
metaPixelIdbuild default (mirrors ga4Id). Live-verified fbq init on home/city/situation pages. Audit placeholder warnings gone. All FHC tracking IDs are now build defaults.
2026-07-10 (later) — CAPI + Google Ads conversion wired (PRs #170, #171)
- Meta CAPI (PR #170): worker
src/capi.tssends server-side Lead to dataset 2141308983102237 (hashed em/ph/fn+ln-from-fullname/ct/zp/country + UA); every offer-form success path now generates a shared event_id (FormData + fbq eventID) so Meta dedups pixel vs CAPI; thank-you page-load Lead removed (was double- counting with submit-time Lead). Inert until META_CAPI_TOKEN secret is set — token generated in Events Manager, Cam pastes (agent guardrail blocks handling). - Google Ads conversion (PR #171): created "FHC - Offer Request" in the LIVE account 215-505-5201 (Submit lead form, primary, static $125, count one) and wired AW-18306794294/o0eXCJapnc4cELaGrplE into /thank-you. Live-verified. Blind-spend gap closed (campaign had only 1 impression since Jul 7).
- GA4↔Ads: already linked Jul 7 (Completed, personalized ads enabled) — no action needed. EXPORT_KEY secret confirmed present. CID 445-354-3394 = stub, 215-505-5201 = live (conflict resolved).
- AJ (Google rep) email logged: FHC must declare Housing category (limits audience targeting; customer match/remarketing/custom segments still OK); Demand Gen video suggested. Elite Flippers unreliable-claims warnings are Zak/Abdullah's lane.
2026-07-11 (early AM) — buyer-photo hotfix + polish + CAPI live (PRs #174, #175)
- Zak's "broken" report: state/city buyer photos rendered 320x1200 strips — wave-2 width/height attrs became a UA height:1200px hint that beat the CSS aspect-ratio (width was overridden, height wasn't). Fix: height:auto on .buyer-photo in both templates (PR #174), live-verified 320x427.
- Post-change polish (mandatory workflow) on both templates (PR #175): micro-interactions + simplify, reduced-motion guards, no new deps; gates green (549 pages, audit 0, app 264/264), deployed + edge-verified.
- META_CAPI_TOKEN set — piped from Cam's 1Password item via op CLI straight into wrangler secret (token never entered the transcript). End-to-end verify: labeled test lead through live form → worker log shows _eventId stored, CAPI call ran, zero [capi] errors. EM chart lags ~30 min (and check the date range — picker was set to Jun 12–Jul 9, excludes today).
- GBP guidance: business type = Service business only (visits customers, address hidden). Housing declaration: no self-serve UI exists — Google's classifier flags first; watch Admin → Policy → Ads.
2026-07-11 — Zak's Wave 3-4.5 loaded PR shipped (PR #176)
- 912 pages live (540→912): 255 /es/ Spanish pages (reciprocal hreflang en/es/x-default verified live), 51 housing-market + 51 closing-cost data pages, glossary hub, property-type hubs, FB sameAs, 272 unique metas.
- Worker: 9-tag lead taxonomy + junk-phone hardening (_suspect flag), soldi-ingest tax-delinquent mapping fix (occupancy/ownership no longer dropped), soft-lead nurture drip (Day 0 fires on enrollment NOW; Day 3/7 wait on a daily cron → /api/nurture-tick, Bearer EXPORT_KEY, 401 verified). ⚠ CAN-SPAM ops rule: reply-based unsubscribe — check the lead inbox daily while drips run. Cron wiring is Cam's call (options doc'd in src/nurture.ts).
- Pre-merge verification: audit 0, firewall clean, and ALL of tonight's work preserved in the built output (pixel, AW tag, buyer-photo fix, sameAs).
2026-07-11 (PM) — Zak's scaled-content protection shipped (PR #177)
- Google scaled-content-abuse mitigation: 300 boilerplate thin pages (inherited/divorce/fire-damaged families × 50 states × EN+ES) now noindex,follow + excluded from every sitemap. Reversible via THIN_TIER_REASONS flag in build.ts. Thin-flagged share of indexable pages 42.8% → 6.8% (Zak's shingle scanner).
- Foreclosure family + IL funnel + all city/state/market/closing-cost/glossary/ hub pages UNTOUCHED and indexable (machine-verified both directions).
- audit.ts hardened: noindex is now a hard blocker anywhere outside the thin families, with EN+ES sitemap-consistency gates — a future build can't silently noindex a hub/funnel page.
- Closing-costs enriched ~150 → 640+ sourced words/page (masked similarity 1.0 → 0.45); TN/VT/MS/WY transfer-tax fixes.
- Pre-merge verify: gates green (912 pages, audit 0/0), noindex placement audited (only thin+404+embed+legal+thank-you), tonight's tracking/fixes (pixel/AW/photo/hreflang/sameAs) all preserved. Live-verified: thin page 200+noindex+out-of-sitemap, money pages 200+indexable.
2026-07-12 — Zak's trust cluster + brand unification shipped (PR #178)
- "Make it finished" batch (917 pages, 4 Fable-authored commits): 50 stop-foreclosure guides enriched 210 → 440-580 words (per-state statute/ redemption/timeline data from foreclosure-rules.ts); 6 new trust surfaces live — /reviews (zero fake stars), /is-fair-home-cash-legit, /avoiding- we-buy-houses-scams, /sellers-bill-of-rights (site-wide footer link), /transaction-history (noindex proof ledger), 3-way net table on /how-we-make-offers. "Your numbers in {State}" cost strips on all 50 states.
- Brand unification: ONE canonical house+door logo on 915/918 pages (+ logo.svg schema asset); og:image + twitter cards + apple-touch-icon site-wide; llms.txt trust pages.
- Premium EN↔ES toggle v2 (View Transitions API): imagery frozen across the swap (browser-measured height delta 0, zero src changes), pill glide, reduced-motion instant, 62/62 form radios survive.
- 3 new permanent audit gates: shingle-similarity thin-page gate (boilerplate can't ship again), brand-invariants gate (logo signature/og:image/apple- touch/aspect-ratio-height-auto), merge-leak detection — all negative-tested.
- Pre-merge verify: gates green (build 917, audit 0/0 + new gates), firewall clean (only "Soldiers Field"), diff 48 files all FHC-scoped (no secrets). #177 protection intact (50 non-IL states × 3 families still noindex + out of sitemap; IL enriched as money market). Live-verified: 4 trust pages 200, /reviews "Zero Fake", enriched TX guide 200 w/ statute content, thin page 200+noindex, logo.svg + apple-touch-icon 200. Deploy: worker uploaded (route- attach 401 benign, routes pre-exist), new pages confirmed live at edge.
- Completes AJ's "landing pages squared away" gate → ads relaunch unblocked (RSA pack is with Zak).
2026-07-13 — PR #199 identity-copy rereview repair ready (not deployed)
- Replaced PR #199's new direct-principal wording (
Fair Home Cash makes...,we are a "we buy houses" operation, property-specificwe buy...) with neutral seller-benefit copy: request/get written cash offers, no fees, and a seller-controlled decision. EN, authored ES, visible FAQ, JSON-LD, statics, and generated template mirrors were updated together. - Removed previously missed connector mechanics from non-disclosure calculator,
market, closing-cost, and Illinois-situation pages. About, Privacy, Terms, and
is-fair-home-cash-legitremain the sanctioned disclosure layer and were not edited. Lead forms, consent,/api/offer-request, ingest, and nurture behavior were unchanged. - Replaced the non-recursive 630-
pageFilescopy check with a shared policy that scans all 941 built HTML artifacts, including registered statics and 255 ES twins, across visible, JSON-LD, and meta/OG layers. Added 16 negative/allowance fixtures for EN, ES,FHC, static/generated layers, and disclosure carve-outs. - Post-merge verification:
bun testinsites/fhc-pages19/19 (16 policy + 3 ingest);bun run build:fhc940 pages / 255 ES twins;bun run audit0 blockers, 0 warnings with recursive copy count 941; rootbun run verify37 files / 354 tests + production build; no PR-relative lead-form behavior diff; FHC Soldi firewall clean;git diff --checkclean. - Current-main proof: fetched
origin/mainat exact SHAd2d8173(merged PR #161) and preserved both histories in merge commit9c48345(parents27ff137+d2d8173) before the post-merge gates above. Root verify emitted one non-blocking duplicate React key warning from the current-mainTerritories.test.tsx; all 354 assertions passed. - Durable copy handoff: complete C01-C34 before/after ledger plus A01-A04 audit
message deltas at
docs/implementation-notes/fhc-copy-identity-audit-ledger.md; root-operator twin at/tmp/soldi-v60-20260713-pr199-copy-delta.md. - No deploy was run. Root owns rereview, deploy, live proof, and the post-deploy text to Zak.
2026-07-12 — Zak's intelligence wave shipped (PR #179)
- Data-first wave (931 pages, 3 commits): built off real distress data (DePaul-IHS / ILFLS / ATTOM / Cook Pappas) + live SERP analysis so pages target where foreclosure distress and search demand actually overlap.
- Chicago intent cluster (4 pages, 1,900-2,300w, 1.7-3.5% overlap): /cash-home-buyers-chicago, /sell-house-as-is-chicago, /sell-house-fast- chicago-suburbs (re-aimed at southern Cook), /we-buy-condos-chicago. Ads note: repoint the we-buy-houses ad group here, NOT the national homepage.
- 4 collar-county foreclosure-timeline hubs (Will/Kane/Lake/DuPage) with county-real mediation/court facts (honest DuPage no-mediation note); south- suburb seller pages Harvey/Dolton/Calumet City (Cook tax-delinquency moat: scavenger sale, 38,765 forfeited certificates, sale-in-error losses, cited).
- /illinois-foreclosure-timeline: 3,236w staged article (the format that wins "how long does foreclosure take in illinois"), funnels into the calculator. Roundups upgraded to named entries + published methodology.
- Money-market re-index: 'inherited' family REMOVED from thin-tier noindex after passing the validation scanner (median 352 est-unique words ≥ 300, masked-Jaccard 0.835 ≤ 0.85) → +100 indexable pages, now in sitemaps. 'divorce' re-scanned same day and FAILED (285uw / 0.878) → stays noindex+ out-of-sitemap until a researched legal layer earns it. Thin tiers 300→200.
- New permanent audit gate: static-page substance floor (every indexable static ≥ 400 visible words + exactly 1 h1 + canonical) — closes the blind spot where Phase-B statics bypassed all content gates.
- Pre-merge verify: gates green (build 931, audit 0/0 LAUNCH READY, 90 pages shingle-diffed incl. now-indexable inherited), firewall clean, diff 31 files all FHC-scoped (no secrets/internal). Live-verified at edge: 14 new pages 200 w/ full content + single h1 + index,follow; inherited TX index,follow +in- sitemap, divorce TX noindex +out; IL timeline article live; logo + apple- touch 200. Deploy: worker uploaded (route-attach 401 benign, routes pre- exist). Zak runs the GSC request-indexing plan on the new pages next.
2026-07-13 — Zak's parity + mobile + photos wave shipped (PR #194)
Third FHC wave off the same feat/fhc-seo-wave3 branch (re-synced on main after #179). 75 files, +2343/-149, three commits. Build 940 pages, audit 0/0 LAUNCH READY. Merged bc66503, deployed + edge-verified.
- Parity wave (fb9e2ee): we-buy-houses keyword family — /we-buy-houses- chicago (3252w), /we-buy-houses-illinois (3033w), /we-buy-houses-near-me (3009w) — owns the 2nd keyword family competitors split across two brands. 6 indexed single-question FAQ pages (faq-*.html) w/ valid QAPage structured data (Question + acceptedAnswer + mainEntity) targeting question SERPs. Published offer range (up to 85% of market value) + Fair Offer Guarantee on /how-we-make-offers — the TPBC "publish your math" play. Proof-ledger anatomy on /transaction-history, stays noindex,follow until deal #1.
- Mobile perfection pass (5a404df): 22 CSS/template fixes from a 2-inspector 390px + 360px phone audit + end-to-end thumb-test of the money flow. HIGH: closing-costs calculator card overflow (min-width:0), invisible ES toggle knob on cold /es/ loads, ES cost table rendering in English, 16px input floor (kills iOS focus-zoom on the address field — verified 9 inputs @16px on state pages), scroll-padding-top so wizard Qs clear the sticky header. All CSS-level; form logic untouched — money flow verified intact (offerForm, 9 reason radios, gclid all present on sell-my-house-fast-illinois).
- Self-hosted Chicago photos (9b40061): 17 license-verified images now served from /images/ (hero-chicago-rooftops, aerial-logan-square, two-flats, etc.); IL/Chicago/national heroes + /offer swapped off hotlinked Unsplash → faster LCP + Google Images eligibility. audit.ts gained an asset-href gate (any /images/*.jpg href must resolve in dist, else BLOCKER) — negative-tested, all 17 resolve. New FHC_REVIEW_COUNTS env (analytics.env.example): review strip is stripped from dist while unset → no fabricated review counts ever ship (verified: reviews page shows zero visible counts).
- Pre-merge verify: build 940 exit 0, audit 0/0 (asset-gate + 9 new statics now
under the ≥400w substance floor, still 0 blockers), firewall clean (shipped
dist Soldi-free), diff 75 files all FHC-scoped no secrets, both flagged JS
items confirmed untouched. Edge-verified: 3 we-buy-houses pages + 6 FAQ pages
- how-we-make-offers all 200 w/ full content + 1 h1 + index,follow (2 FAQ pages caught mid-propagation across PoPs, settled on recheck); self-hosted heroes 200; transaction-history noindex; reviews honest. Deploy: 951 files uploaded (route-attach 401 benign as always).
- Left for Cam's call (JS-level, Zak deliberately untouched): (1) mid-wizard
sticky "Get My Cash Offer" bar targets the hidden address field → dead tap;
fix = retarget or hide during wizard. (2) localhost testing fires real
GA4/Meta pixel events → one-line hostname guard keeps test noise out of funnel
data. (3) Non-blocking follow-up I flagged: 581 templated pages (closing-costs
- non-IL states) still hotlink images.unsplash.com — pre-existing, the swap only covered the approved Chicago/IL heroes.
- Zak's next: GSC request-indexing on the 9 new URLs + the launch kit (HARO, video, profiles, RSA relaunch → repoint we-buy-houses ad group to /cash-home-buyers-chicago). Cam's outstanding: www DNS + Always-HTTPS toggle.
- PR #193 (buyer marketplace v60, app money surface) intentionally NOT merged/deployed here — frontend-complete but backend-stubbed, overlaps Cam's own open #180 (payments/lead-import). Held for Cam's sequencing call.
2026-07-13 — PR #193 merged + PR #194 flagged items fixed (PR #195)
Same-day follow-through on Cam's calls from the #193/#194 review.
- PR #193 merged (
e4727f1) per Cam: land Zak's v60 frontend now, integrate the real backend on top next. Post-mergebun run verifywent RED — 5 Billing tests (localStorage.clear is not a function): vitest's jsdom env exposeslocalStorageas a bare object with no Storage methods, and #193's new Billing.test.tsx (green on its old base) assumed jsdom provided one. Fixed with a self-contained localStorage stub in Billing.test.tsx mirroring BuyerScreens (d22c9d5). Main green again: typecheck + 354 tests + build, exit 0. Handoff prompt for the backend-integration agent written todocs/notes/marketplace-backend-integration-handoff.md(money model =app/shared/marketplace-rules.ts; stubs =app/src/lib/api/{package,market,leads}.ts; harvest Cam's #180 + Stripe branches; note HANDOFF.md isn't in-repo, spec lives indocs/implementation-notes/mkt-*.md). - PR #195 shipped (
73c1bf2) — the two items Zak flagged for Cam in #194:- Non-prod analytics guard — new
partials/notrack-guard.eta, included before the Meta Pixel in all 7 page templates. On non-prod hosts (localhost / preview / *.workers.dev) it sets the GA4 + Google Adsga-disableopt-out flags, pre-stubsfbqso the Meta bootstrap bails (no pixel / PageView), and flags the first-party beacon (__FHC_NOTRACK→/collectPOST inpartials/analytics.etano-ops). The guard branches at runtime onlocation.hostname; the shipped HTML is identical everywhere, so prod (fairhomecash.com) early-returns and tracking fires untouched. - Sticky CTA dead-tap —
city-page.eta:syncSticky()hides#stickyCtawhile the wizard is past step 1 (the 'Get My Cash Offer' bar was focusing the hidden#addressfield). Hooked into showStep + init. Form logic + money flow untouched.
- Non-prod analytics guard — new
- Gates: build 940, audit 0/0 LAUNCH READY, firewall clean (new partial Soldi-free), money flow intact (offerForm + 9 reason radios). Deployed + edge-verified: guard present (ga-disable ×2) + prod IDs live (GA4 G-3553MET586, Meta 2141308983102237, fbq init, gtag config) on state + city pages; sticky fix live on city pages (syncSticky ×3, onStep1). Deploy: 886 files uploaded (route-attach 401 benign).
- Still open (non-blocking): 581 templated pages (closing-costs + non-IL states) still hotlink images.unsplash.com — pre-existing; #194's swap covered only the approved Chicago/IL heroes. Flagged to Zak as a follow-up.
2026-07-13 — Marketplace v60 Phase 0 alignment gate
- Reconciled the attached v60 handoff, the byte-identical marketplace mock twins, current
mainat9a1b7fa, migrations0001–0024, the shared marketplace rules, and the diverged PR #180 integration branch. - Published
docs/plans/marketplace-v60-alignment-matrix.mdwith all six screens classified as mock/app/real-or-stub/verdict, plus dependency-safe implementation slices. - Found a blocking economic-spec contradiction: the checked-in mock has
$500editable funding, auto-reload, and a$1,500activation deposit, but no Package/bonus/tier system; the handoff requires$1,000minimum funding, bonus tiers, Warm/Hot/Cold pricing, and a real$5,000Package while also saying the mock wins. - Parked buyer auction UI, buyer manual lead entry, recurring Package automation, and expanded refund automation in the roadmap without deleting load-bearing auction persistence, Admin supply intake, or the current refund request path.
- Verification before and after Phase 0:
bun install && bun run verifypassed 37 test files / 354 tests, TypeScript, and Vite buildassets/index-CPWAyJ6J.js;bun run build:docsbuilt 10 internal + 2 client docs + index. The pre-existing duplicateSO_1React-key warning remains in the Territories test. No product code, migration, remote operation, Stripe operation, or deploy ran. - Next up: owner selects the economic-spec authority and Package charge model; then replay Stripe economic-intent integrity as the first independently proven backend slice.
2026-07-13 — Marketplace v60 provenance correction and unblock
- Reopened the Phase 0 gate after the owner clarified that Zak had just demonstrated Package plus Hot/Warm/Cold. GitHub and Git history proved that the preview files on
mainwere stale at July 5, while Zak's PR #161 advanced the same two files through v40/v41/v44/v45 tobuild v60atf8b192bon July 13. - PR #161's v60 comment explicitly supersedes prior versions and points to Zak-authored, merged PR #193 (
e4727f1) as the real-app port. The current product contract is therefore Cold$90/ Warm$150/ Hot$250,$1,000minimum funding with$100/$300bonuses,$5,000wallet-funded Package for 25 delivered Hot leads at$200, and$150+tier-covering Territory bids. - Merged PR #161's eight-commit two-file preview lineage into the launch train. Both twins are 2,518 lines, byte-identical, stamped
build v60, and SHA-256fbe6ed23b8507617a910068f3c1c3e7ca1293af80ea67fcee1bc4e687938c58c. - Resolved Package activation to an atomic server-side wallet debit after separately proven Stripe wallet funding. No dedicated Package Checkout will be invented.
- Corrected
docs/plans/marketplace-v60-alignment-matrix.md, the roadmap, and implementation notes. No app runtime code, migration, Stripe operation, remote service, or deploy changed in this correction. - Verification:
bun run verifypassed 37 files / 354 tests, TypeScript, and Viteassets/index-CPWAyJ6J.js; merged preview inline JavaScript passednode --check; twins passedcmp;git diff --checkpassed. The pre-existing duplicateSO_1Territories test warning remains. There is no rootbuild:previewsscript. - Next up: Stripe economic-intent integrity as the first focused PR into master #196, followed by canonical acquisition and atomic Market purchase.
2026-07-13 - PR #198 Terra P1 Territory handoff correction
- Preserved pending-only FHC and raw source provenance, but changed approved/priced exact Admin classification to claim and run the retained Territory priority allocator before a true no-match becomes Open Market inventory. Shared
territoryBidCanClaimLeadenforces$150coverage for Cold/Warm and$250for Hot; the deleted buyer-facing auto-buy UI remains deleted. - Added migration
0027_territory_allocation_claims.sqlfor one leased/tokenized allocation owner and unique sold portfolio/ledger outcomes. Processing, finalizing, and debited crash states resume with the persisted review ID; debit/cap/state transitions are one D1 batch; final lead/claim CAS and every counter/ledger/portfolio/delivery write require the same token. A durable inconsistentcommittingstate fails closed for operator repair. - Restored reachable end-to-end economics tests: no-match availability, guarded-debit failure, cap-race refund, concurrent/repeated Admin review, exactly-once sold delivery, crash recovery before/after debit, and token takeover immediately before finalization with zero stale-owner writes.
- Evidence: focused Territory/Admin/ingest/rules suite
159/159; fresh disposable local D1 migrations0001–0027succeeded andlead_allocation_claimsschema was queried; fullbun run verifypassed 39 files / 380 tests, TypeScript, and Viteassets/index-LfcA747C.js;bun run build:docsandgit diff --checkpassed. Only the pre-existing duplicateSO_1Territories test-key and bundle-size warnings remained. No deployment, remote D1/Stripe write, or secret access ran. - Next: Terra/high rereview of PR #198, then keep direct Market purchase and later economic planes isolated.
2026-07-14 — Marketplace v60 live-readiness consolidation
- Mined Codex sessions
019f5ee8-88d9-7ef3-a1ce-d250debb4fd7and019f5cc3-299b-7ee3-b92d-b1ea06034c4f, then reconciled the generated findings against current PR metadata, exact branch heads, deployments, source, and Zak's latest iMessage. The repeated third session ID was a duplicate. - Corrected the generated synthesis: PR #198 is complete, exact-head Terra-approved at
548736e, and integrated into master PR #196. PR #196 is ready/non-draft, clean, and CI-green at3c997b5. - Reclassified PR #180 as a semantic source rather than a merge candidate. It is conflicting against a pre-v60 base, but contains independently reviewed Market transaction, Admin CSV/import-integrity, refund-integrity, exact-SHA health, staging-control, and browser-harness seams. Ports must preserve #197/#198, start migrations after current
0027, and land as focused ready PRs to #196. - Confirmed new work still required: distinct purchased/promo credit accounting and a persisted wallet-funded Package lifecycle. Confirmed Territory
$150plus tier-coverage enforcement already exists and needs an end-to-end audit/closure rather than a rebuild. - Confirmed hosted truth remains NO-GO:
staging.soldi.ccdoes not resolve, the existing isolated staging D1 is not a deployed environment, current/healthreturns SPA HTML, andapp.soldi.ccpredates #196. - Confirmed FHC PR #199 moved after R6 to Zak head
8eba975; its body/copy ledger are stale and require current-head reconciliation, full gates, independent review, merge, deploy, and live proof. Sent Zak a verified acknowledgment that names the exact head and promises explicit copy accounting plus post-deploy proof; no live claim was made. - Published the complete operator synthesis and queue prompts at
/tmp/mine-codex/soldi-live-readiness/INSIGHTS.mdand refreshed the marketplace v60 implementation note/index/roadmap. No product code, migration, remote database, Stripe mutation, merge, or deploy occurred; no walkthrough screenshot changed because no deployed product state changed. - Verification at #196 head
3c997b5:bun install --frozen-lockfilemade no changes;bun run verifypassed 39 files / 381 tests, TypeScript, and Viteassets/index-LfcA747C.js. Expected forced Territory failure stderr, duplicateSO_1key warning, and Vite bundle advisory remain non-failing diagnostics. - Next: release FHC #199 at one reviewed exact head; merge resulting main into #196; port Market purchase, Admin CSV, and refund seams; implement promo/Package economics; then provision protected cron-off staging and run four reset-isolated Sol/Terra desktop/mobile receipts before production.
2026-07-14 — Marketplace v60 hosted security boundary
- Added exact same-origin CORS and defense-in-depth CSRF for cookie-authenticated unsafe methods. Login/register remain unauthenticated bootstrap routes; Stripe webhook and FHC ingest retain their signed server-to-server boundaries. Existing sessions receive a session-derived CSRF companion cookie from
/auth/me. - Removed hosted fixture fail-open behavior: missing Stripe configuration returns
503instead of minting wallet funds, and missingFHC_INGEST_SECRETreturns503instead of accepting unsigned leads. Both fixtures remain available only on localhost development requests. - Upgraded Hono from
^4.6.14to^4.12.25(lockfile4.12.30), clearing the direct Hono runtime advisory. Remainingbun auditfindings belong to the Vitest/jsdom/Vite development chain; do not expose dev servers. - Full
bun run verifypassed 41 files / 400 tests, TypeScript, and Viteassets/index-COujzqxe.js;bun run build:docsandgit diff --checkpassed. Route-level proof now covers cross-origin login/register with an existing session, same-origin tokenized bootstrap, old-session CSRF refresh, invalid/expired-session login recovery, signed Stripe/FHC exemptions, same-origin preflight, and both auth cookies. The transport-onlyComps.parts.tsxchange has no rendered UI delta; tmx exact-head polish/security rereview is the publication gate. - Next: publish a ready child PR to #196, request Zak, merge after QA, then close atomic Market purchase before wallet subledgers, import/refund, and Package renewal.
- Terra/high exact-commit review rejected the first candidate on login CSRF and deck truth: login/register bypassed the global guard entirely, allowing cross-origin session replacement, and the deck marked undeployed train behavior
live. The corrected guard applies exact Origin/Referer to all browser mutations, permits tokenless same-origin bootstrap only before a session exists, and preserves signed Stripe/FHC server exemptions. Focused security/payment/ingest/client tests now pass 18/18; the walkthrough uses an amber plan badge and explicitly separates current production from the undeployed train.
2026-07-14 — PR #199 newest-head reconciliation before release
- Rebased the release work normally onto Zak's newest
43ca26fbest-site wave. Preserved the 18 new FAQ pages, 50-state selling-cost report, local photo catalog, calculator embeds, 102 re-indexed EN/ES divorce pages, six Chicago neighborhood pages, and favicon work as the source base. - Corrected the now-confirmed mixed business model in About, Privacy, Terms, and legitimacy copy: Fair Home Cash may buy a qualifying house directly or may involve an independent buyer, and it is the buyer only when named in the purchase contract. Direct
we buylanguage remains valid. - Qualified unconditional offer outcomes across generated city/state/national copy and authored public pages.
If the property is a fit, you may receivereplaces universalyou get/comes backresults; the 24-hour offer aspiration remains conditional. Zak's newest changes are C50-C54; owner-directed changes are C55-C59/A12. - Replaced the obsolete never-a-buyer classifier with a mixed-model policy: connector mechanics remain blocked outside disclosure pages, while universal purchase/offer guarantees and fabricated track record remain blocked everywhere relevant.
- Sol/medium's immutable raw-head review rejected
43ca26fon three P1s and one adjacent P2: third-party embed snippets were defeated by globalX-Frame-Options: SAMEORIGIN; the authored Illinois calculator full form displayed click-consent but submitted no consent field, so signed Soldi forwarding dropped it; public disclosures andllms.txtdescribed incompatible models; and embed mode hid nonexistent.rel-linksinstead of the real.xlinksblock. - Corrected all four above Zak's intact wave. Explicit embed responses now use
frame-ancestors *without XFO while ordinary pages retainSAMEORIGIN; embed topbar/related links are hidden; Illinois offer submissions carry consent/source provenance;llms.txtuses the same conditional mixed model as the legal pages (C59). - Sol/medium's first corrected-head review rejected
aabdb98on two more P1s plus one ledger P2: any ordinary route could become frameable by appending?embed=1, and 24 FAQ plus 51 state-page results still promised an offer. The final correction restricts the frame exception to real calculator routes, tests the negative path, conditions the complete missed offer corpus, strengthens exact grammar fixtures, and scopes the stale ledger claim as historical. These changes are C60-C63/A13. - Sol/medium's
3b3754drereview closed those exact findings but rejected the still-unrecognized automatic-offer results in/offer, all state heroes, form success states, and residual authored pages. C64/A14 conditions the full EN/ES result corpus and teaches the recursive audit the exactwe make,expect ... with your offer, andoffer arrivesbypasses; the stronger audit then surfaced and closed three adjacent authored statements. - Sol's next exact-head pass approved the complete result corpus with no P0/P1 and identified one localized
/offerreassurance P2. The sentence now preserves the real decision order: request a review; if an offer is received, then decide. - Evidence so far: focused FHC/ingest/embed tests 42/42; build 965 pages / 255 Spanish; recursive audit 966 HTML with 0 blockers / 0 warnings; root verify 37 files / 354 tests plus TypeScript/Vite; docs build and diff check green. Final immutable-head tmx review, normal push, PR-body refresh, merge, deploy, live proof, and Zak C55-C64 copy notification remain before the release is complete.
2026-07-15 — v60 Admin import and Package routing child (local proof complete; not deployed)
- Started at exact
9a9525fd26095b0f4e98403a6bac4dd275cd05a0in the isolatedcodex/v60-admin-import-package-routingworktree. Added an initial0031_admin_import_package_router.sqldraft, strict 24-column Admin CSV parser/route, immutable raw-CSV idempotency receipt, NFKC identity fence, and persisted disabled-routing decision before a no-match becomes Market availability. package_fulfillment_stateremains untouched and no0032exists. The unresolved supply-reserve ratio and no staged caller proof keep activation/renewal fail-closed.- Replaced the stale JavaScript candidate authority with one Package D1 batch whose first
INSERT ... SELECTpersists the deterministic eligible buyer reservation; fulfillment claim, sold lead, portfolio/stage/delivery, Package delivery, exact cycle/user counters, completion guards,resolved_channel='package', and immutable terminal receipt follow from that reservation. The identical SQL predicate is re-used by an immutable Market-fallback reservation, preventing Market availability while a qualifying Package buyer exists. No Package wallet or buyer-budget debit occurs. - Admin imports now use pending/completed batch receipts with counted identity/consent/audit/row completion enforcement, immutable batch/row/identity receipts, raw source plus canonical acquisition, NFKC duplicate detection, idempotency replay/conflict handling, and all-or-nothing D1 writes.
0030was restored byte-for-byte after a migration-immutability correction;resolved_channelremains exclusively in new0031, with a pre-0031 Territory compatibility fallback. - Evidence: fresh local migrations
0001–0031; parser plus real-SQLite Package routing/upgrade, two-buyer fairness, concurrent replay, Admin import route, and Idempotency-Key boundary suites passed; fullbun run verify58 files / 539 tests, TypeScript, and Vite buildassets/index-B3nOIi7c.js;bun run build:docs;git diff --check; and touched TypeScript line audit all passed. Expected forced rollback/compensation stderr and the existing duplicateSO_1React-key warning remain non-failing test diagnostics. No remote mutation, commit, push, or deploy occurred.
2026-07-15 — v60 six-screen final local acceptance corrections
- Preserved Zak's pinned v60 mock as the visual/token authority and kept staging/promotion frozen. The second exact-range review rejected stale zoomed Settings/Territories receipts and residual public em-dash copy; both mobile receipts were recaptured at true 390px width, the browser title now uses the mock's middle dot, and the Worker transaction presentation boundary normalizes historical em dashes to colons without rewriting ledger rows.
- Root original-resolution review rejected the first replacement Transactions mobile receipt even though the automated geometry lane accepted it: Territory attribution stacked vertically, Resend overlapped it, and amount/balance clipped. The row now uses the mock's equal two-column mobile grid, keeps attribution and money in separate tracks, and places actions on a dedicated full-width row while preserving the desktop flex composition and existing v60 tokens.
- Independent Sol/medium browser proof measured two equal 155px tracks at 390px, one-line Territory attribution, zero overlap, fully contained amount/balance, 390/390 page width, no console errors, no forbidden checklist vocabulary, and no public em dash. Root re-inspected the 390×844 and 1440×900 PNGs at original resolution and accepted them.
- Final local gate passed 67 files / 586 tests, TypeScript, Vite
assets/index-BiQwcHs_.js, 10 internal + 2 client docs + index,git diff --check, and the strict<400touched-source rule. No deploy, remote database mutation, Stripe mutation, or production claim occurred. - Next: commit one immutable head; require fresh full-range Sol/medium and Terra/high zero-finding verdicts; then open the single ready PR into the launch train, request
killerabbasi, send Zak the two added punctuation deltas, merge after QA, and keep staging as the next separate promotion gate. - Immutable R5 rejected
acf40c9on three stale/zoomed desktop receipts and contradictory Territory transaction detail. Sol otherwise found no code/API/security/money/taxonomy defect. Terra's additional public-auction-API finding was false and formally withdrawn afterapp/worker/index.tsplus the exact 404 worker test were rechecked. - Payment & Budget, Settings, and Territories desktop evidence was replaced at true 1440px CSS scale. Root caught and rejected a browser-selection race that briefly put Open Market into the Settings PNG, then used a new isolated context to prove route, H1, DPR/scale, 1440/1440 width, fonts, API readiness, copy, and console state immediately before the accepted Settings/Territories writes.
- Standing-order transactions now project generic
Territory leaddetail and use the joined lead only forvia your X County territory, preventing contradictory historical county text without mutating immutable ledger storage. Unit, real-SQLite, component, and desktop/mobile browser proof cover the mismatch and clean two-column geometry. - Reconciled the apparent four-situation/Agent conflict by the checklist's own authority declaration: the named byte-identical v60 mock is the acceptance standard and deliberately implements Agent listing-intent tabs, so "4 ONLY" governs Investor mode rather than deleting the mock-backed Agent branch. Zak was asked to correct this interpretation during PR review if needed.
- R6 full gate passed 67 files / 588 tests, TypeScript, Vite
assets/index-BiQwcHs_.js, 10 internal + 2 client docs + index, diff/secret hygiene, and the strict<400changed-source rule. No deployment, remote database mutation, Stripe mutation, or hosted claim occurred. - Final all-12 root inspection caught the accepted Territories desktop receipt at a nonzero horizontal scroll position even though its document-width assertion was clean. It was recaptured at explicit
scrollX=0after route/H1, 1440×900 viewport, DPR 1, 1440/1440 width, loaded-font, forbidden-copy, and console checks; the replacement was re-inspected at original resolution. - Ready PR #210 opened at
2e3fbf0, requested Zak, and disclosed the complete copy/functional delta plus Agent-mode interpretation before merge. The child exposed no GitHub checks, so it merged after the exact local gate as launch-train head0552cc2; master PR #196's body was reconciled and itschanges,FHC audit when changed, andbun verifychecks passed. No deployment or remote service mutation occurred.
2026-07-15 — Marketplace v60 backend integrity adversarial correction
- Reopened
codex/v60-marketplace-backend-integrityafter reviewer reproduction: production accepted the newly seeded fictional contact48 Juniper Lane/Avery Collins/+1-202-555-0175because only legacy placeholder fragments were guarded. The shared guard now rejects all six normalized v60 address/name/phone triples only when all three fields match, covering signed FHC ingest, Admin manual entry, Admin CSV import, and a post-seed D1BEFORE INSERTtrigger. This is fictional test data only; no real personal data was added. - Extended the existing backend
0032_v60_data_integrity.sql(no new migration number) to recompute non-nullleads.territory_distress_keyafter taxonomy conversion and to rebuild non-null, structurally safestanding_orders.filter_match_jsonfrom rewrittenfilter_json. This closes the reviewer P1 where a migrated Probate order and a new Inherited order could land in separate TerritoryRANK()partitions and both display position 1. Null unsafe-history keys remain fail closed. - Regression evidence: the focused production-guard / ingress / real-SQLite migration suite passed 5 files / 66 tests, including all six markers in every ingress path and direct D1 writes; its Territory route regression proves migrated/new Inherited orders report positions 1 and 2. A fresh disposable local D1 applied migrations
0001–0032and returned zero legacy placeholders, six v60 seed leads, three typed purchases, 451,000 balance cents, 49,000 purchase-debit cents, zero activation rows, and zero staleprobatelead/match keys. Rootbun run verifypassed 69 files / 624 tests, TypeScript, and Viteassets/index-BdJy0tCO.js;bun run build:docsandgit diff --checkpassed. Expected forced rollback stderr from existing Admin-import idempotency tests and the Vite chunk-size advisory remain non-failing. No deploy, remote D1 change, Stripe operation, PR, or merge occurred. - Next: commit/push this correction, preserve backend
0032, and have the package branch rebase and claim0033after backend merge.
2026-07-15 — Marketplace v60 production fixture-exposure P0 closure
- Reviewer correctly found that rejecting future fixture writes did not protect the six fictional leads inserted by
0032itself. The Market route now excludes their canonical migration IDs from list/count results outside explicit fixture environments, rejects direct buy requests before any account/claim/ledger write, and repeats the exclusion in the atomic claim/purchase SQL. - Wrangler production has no
APP_ENVIRONMENTvariable while staging explicitly declares one. The guard now permits fixture data only for explicitdevelopment,test, orstaging; undefined, production, and unknown values fail closed. The production config deliberately remains unset so a missing binding cannot make fixtures sellable. No environment-file values were read into this record. - Focused direct proof against a fully migrated SQLite database passed for both explicit production and undefined binding: Market listed zero fixture rows, a direct fixture buy returned
409 lead_unavailable,market_purchasesremained zero for the fixture, and the buyer balance did not change. Focused fixture/ingress/Market tests passed 7 files / 81 tests; rootbun run verifypassed 69 files / 627 tests, TypeScript, and Viteassets/index-BdJy0tCO.js. The prior fresh disposable local D10001–0032migration invariants remain unchanged because this P0 closes runtime exposure/claim boundaries rather than changing migration content. Expected forced rollback/resilience stderr and the Vite chunk-size advisory remain non-failing. No deploy, remote database mutation, Stripe operation, PR, or merge occurred.
2026-07-16 — Marketplace v60 buyer API quality-score P2 cleanup
- Exact-head review found optional
qualityScorestill present in buyer-facing response contracts despite the Worker DTOs omitting it. Removed the residue fromPipelineCard,OwnedLead, andMarketLead, and removed the typed buyer fixture values.LeadDossierkeeps its existing breakdown visualization but no longer renders a nonexistent numeric score. - Scope stayed intentionally narrow: no Package pricing seam, migration number/content, Admin API contract, environment binding, deployment, PR, or remote mutation changed. Focused buyer API/mapper/route/component proof passed 8 files / 36 tests with TypeScript; root
bun run verifypassed 69 files / 627 tests, TypeScript, and Viteassets/index-BYdWsLVy.js;bun run build:docsandgit diff --checkpassed.
2026-07-16 — v60 mobile-primary UI follow-up (local only)
- Recorded Zak's nine 390px mobile gates in the parity checklist, MVP readiness control, QA matrix, implementation index/note, and exact copy delta. Desktop remains the
f8b192bparity surface; no PR, deployment, or message to Zak occurred. - At <=640px, Open Market renders true cards with bottom-row Buy actions; My Leads uses labeled one-tap stage pills and direct
?lead=routing; seller numbers/emails aretel:/mailto:links; drawers, refund, Package, and Territory dialogs are bottom sheets; mobile controls meet 44px and confirm areas remain sticky. Root visual QA caught the dossier footer gap and it was corrected before closure with stickyCall sellerplus direct stage pills. - Local browser proof used fresh exact-worktree sessions: Worker
8793(localstagingD1 after migrations0001–0034,SESSION_SECRETloaded from the designated ignored source) and Vite5183with explicit API proxy. The six refreshed 390×844 captures live underdocs/shots/v60-*-mobile-20260716.png;v60-refund-mobile-20260716.pngadds the refund-sheet record. Browser checks observed390/390document width, three mobile Market cards with desktop table hidden, deep-link drawer, direct phone/email links, six sticky footer pills, and no horizontal overflow. This is local staging-fixture evidence, not hosted proof. - Performance: React route lazy boundaries reduced the initial Vite entry to 422.09 kB / 133.84 kB gzip; Leaflet remains deferred at 150.05 kB / 43.59 kB gzip. The owner prohibited internal subagents, so
post-change-polish.jswas intentionally not invoked; the implementation note records the solo four-lens make-it-sexy and make-it-simpler review for every changed production TSX. - Territory visual QA rejected the empty
0 of 0capture. A strictly local staging fixture was created through the authenticated local Worker helper (201); the replacementv60-territories-mobile-20260716.pngshows a populated 390×844 bid sheet (3 leads · 30d,$175, cap4, worst case$700/week) and its stickyAdd territoryconfirmation. The global help widget had intercepted that action through a parent stacking context, soTerritoryModalnow portals todocument.body; runtime proof hasscrollWidth: 390and the bottom-right hit target isAdd territory, not help. The original literal staging Worker correctly rejected the Vite proxy with403 csrf_origin_rejected. Owner-directed harness-only retry stopped that Worker and relaunched the same local D1 process withbun run dev:worker -- --port 8793 --env staging --var APP_ENVIRONMENT:development; after browser re-auth, the same visible UIPOSTreturned201, closed the sheet, added a third local order, and showed existing toastTerritory added/NJ Pre-foreclosure is active.(v60-territories-mobile-success-20260716.png). No source/security config, migration, remote D1, deployment, or hosted claim changed; this is local development-origin evidence only.
2026-07-16 — Final v60 UI normal train integration (local verification pending)
- Started from pushed UI/refund candidate
2afc8083c7d18b63a5539c02d23dc311c241fc51, fetchedorigin/orchestrator/marketplace-v60-20260713/merge, and verified its exact head80f809e0b1e8362e99e8f598db21a569a4e0716dbefore a normal merge. Its first parent is Package/FHC train0b86a6945439ee1447d77851e86d1b576cbb44dc;6f38cc1930f7c0f4638355ac6eb9a01e5692802dis an ancestor. - Preserved forward migration ownership: Package remains
0033_package_readiness_and_market_batches.sql; the authenticated contact-attempt evidence migration remains0034_contact_attempt_evidence.sql. The evidence route accepts only idempotent owner-scopedcall/text/emailevents and the refund route derives the soleNo response after attemptsgate from durable timestamps (12 attempts across at least four days), never client counters/timestamps. - The incoming range contains no
app/srcTS/TSX path and no UI conflict. Documentation was the only conflict surface, resolved additively. Therefore no post-change-polish invocation is appropriate: no touched TSX exists; v60 token fidelity will be proven by parent-tree/source-gate checks without aesthetic drift. - Verification: six-screen desktop/mobile component plus refund/contact/security suite passed 18 files / 103 tests; root
bun run verifypassed 74 files / 660 tests, TypeScript, and Viteassets/index-BLSJB_33.js; FHC passed 457 tests, a fresh 965-page build, and audit; docs built 10 internal + 2 client docs + index. Release-readiness JSON,0033/0034order, nine-reason cardinality, public DTO, must-gone, conflict-marker, and staged/working diff checks passed. The stagedapp/srctree is unchanged from UI first parent, so no TSX post-change-polish invocation was required. Expected forced rollback/compensation test stderr, jsdomwindow.scrollTo, and Vite's chunk-size advisory remain non-failing diagnostics. No PR, deploy, Stripe action, or Zak message occurred.
2026-07-17 — Exact staging receipt and seed JSON-prefix repair
- Connected the authorized FHC Chrome profile, verified Cloudflare identity
camolechowski@gmail.com, and corrected account tokencamo-soldi-dns-keywith account Workers Scripts Write plus D1 Write while retaining exact Soldi/FHC zone route and DNS authority. Account-token, Workers Scripts, D1,soldi.cc, Workers Routes, andfairhomecash.comprovider probes all passed. - Deployed exact clean PR #196 head
9de10efd56515af4105e7d9fef2c8aa05bd86354to protectedstaging.soldi.cc. The controller minted private receiptdeploy-9de10efd56515af4105e7d9fef2c8aa05bd86354.jsonfor deployment5e97d0c3-5ca8-4acc-a1fc-1c3679809ed5, version99fe7fd5-61c7-4f7f-8a4d-58d2af2a0175, domain166ab9a82dc54d854123fb840fc6e3a1ace30de4, migration tip0036, and test Stripe accountacct_1TtjDjPuLV917S5K. Five cache-busted health probes and three Stripe probes matched the exact SHA/version/account after edge propagation. - The receipt-bound seed dry-run made no write and stopped on
demo_seed_d1_json_invalid. Direct read-only reproduction showed Wrangler--jsonnow writes the exact prefix├ Checking if file needs uploading\n│\nbefore a valid JSON envelope. The parser now strips only that exact normalized prefix and continues rejecting arbitrary leading output. - Verification: focused staging seed 13 tests / 60 expectations; root
bun run verify79 files / 725 tests, TypeScript, and Viteindex-DLsEdVY6.js;git diff --checkpassed. This source repair changes the candidate SHA, so a new exact-head deployment receipt, seed dry-run/apply/readback, hosted browser QA, retained-production rehearsal, and production promotion remain pending.
2026-07-17 — Transactional protected-staging seed closure
- Wrangler file mode was proven unsuitable for the guarded transaction: it returns upload statistics instead of SELECT rows and rejects explicit
BEGIN IMMEDIATEon remote D1. The controller now reserves Wrangler for exact readback and sends apply/cleanup through Cloudflare's fixed account/database D1 batch endpoint. A hostile live staging batch inserted a unique sentinel and then failed; provider failure plus zero-sentinel readback proved rollback. - Exact clean
eaf68cc7fab6dbf9d8eed1d26dd32e23fd66334edeployed tostaging.soldi.ccas deployment8724fb36-79ec-411d-91b9-d2144ce1c394, version38c3cf05-a472-453e-be2b-36294969ae1e, with receiptdeploy-eaf68cc7fab6dbf9d8eed1d26dd32e23fd66334e.json. Time Travel bookmark00000028-00000000-000050ab-075a56a3f89deb2873308b04a3108e80preceded mutation. - The receipt-bound apply created exactly nine marked leads (3 Cold / 3 Warm / 3 Hot) and three ranked Territories for 12 available total. Wallet transactions remained 9, Market purchases 4, refund requests 5, refund outcomes 1, and portfolios 13. There were zero collisions, legacy situations, fixture economic references, or unmarked demo Territories. The next receipt-bound dry-run returned
already_seeded. - Verification: focused staging seed 17 tests / 81 expectations; root
bun run verify79 files / 725 tests, TypeScript, and Viteindex-DLsEdVY6.js;git diff --checkpassed. Next: redeploy the documentation receipt head, prove served SHA plus seed idempotence, then run hosted desktop/mobile/Stripe acceptance and independent Terra/high review. Production remains held.
2026-07-17 — Hosted Stripe proof and Territory-rank correction
- Documentation head
4ea90eb38a831d346ba4dc4a8cb5d1f8ba37e3dedeployed to protected staging as deploymenta82b9f28-1c29-46cb-8668-e6c9b4e34563/ version1412ed64-bea4-4fb0-a76b-61babf71895a. Three health reads, Stripe identity, and receipt-boundalready_seededreadback matched the exact served head. - The connected FHC Chrome session completed a real
$1,000Stripe sandbox Checkout with the standard success card. Stripe returned to canonical staging; webhook processing raised demo wallet balance from$5,510to$6,510; Transactions shows the new typed Stripe funding row and exact running balance. - Hosted desktop inspection covered Open Market, My Leads, Transactions, Territories, Payment & Budget, and Settings. All six had exact headings, no horizontal overflow, and none of the checklist's leaderboard/gamer/Comps/Sequences/legacy-taxonomy vocabulary. The pass caught one real blocker: Territory rows hardcoded
Position unavailableeven though the list API computes rank; mutation responses also dropped rank after create/update. - The bounded correction renders
Position #Nfrom the server rank, preserves the unavailable fallback for null/paused rows, factors one ranked SQL projection across list/create/update, and proves bid updates return the recalculated position rather than internal priority. The buyer copy delta is exactlyPosition unavailable→Position #Nwhen rank exists and must be disclosed to Zak. Focused UI/real-SQLite proof passed 2 files / 14 tests; root verification passed 79 files / 726 tests, TypeScript, and Viteindex-CrvajqBf.js. Exact-head deploy, mobile rerun, and final rereview remain next; production stays held. - Exact correction head
e97cfd34a6a42103fa68c6bee7317c1f634ab7a8then deployed asb09fec39-9da9-41da-a7c1-add9109db7fe/c59aad85-f18d-443e-9b3b-8e39b5869099. Its receipt-bound readback returnedalready_seeded, positions1,2,3, 12 available, and wallet count 10 reflecting only the just-proven Stripe funding; Market purchases 4, refund requests 5, refund outcomes 1, and portfolios 13 remained unchanged. - Connected FHC Chrome desktop verified visible
Position #1/#2/#3, 1728/1728 width, and no application console errors. Chrome DevTools emulation then checked all six routes at exact390x844: each had the correct H1, 390/390 document width, no leaderboard/gamer/Comps/Sequences/legacy-taxonomy copy, no console errors, and no request status >=400. A physical iPhone and independent exact-head rereview remain open; production stays held.
2026-07-18 — Zak buyer-app iteration (source-only stacked review)
- Started from exact PR #253 head
2ebc53a096ef9055c1a392900fe7df71f1f42b05in isolated branchcodex/zak-buyer-ui-iteration; no accepted release receipt or deployed runtime was edited in place. - Implemented Zak's written 7/18 contract: tier-only Market/My Leads filtering, truthful Package gating, expanded owned-lead dossier and real Offer Out mutation, six-question buyer setup, county-only server-enforced Territories, complete Settings profile/gates, and a non-fabricated
$250/$250referral popup. - Preserved Cold
$90, Warm$150, Hot$250, Package$5,000/25 Hot leads, wallet/Stripe behavior, and the 12-migration inventory. No provider, D1, Stripe, staging, or production mutation occurred. - Mandatory Terra/high UI polish passed 8 files / 74 tests; the retained-Territory follow-up polish passed 2 UI files / 13 tests plus TypeScript and removed a stored legacy-name leak. Final root
bun run verifypassed 81 files / 736 tests, TypeScript, the production Vite build, brand audit, and 11 production-control tests / 46 assertions. Expected forced-failure diagnostics and jsdom's existingwindow.scrollTowarning remained non-failing. - Copy delta is recorded at
/tmp/soldi-zak-ui-copy-delta.md. The promised clickable prototype has not arrived. This UI change deliberately requires fresh migration-rehearsal, Time Travel rollback, protected-staging, hosted, and physical-iPhone receipts before any production-go request. - Follow-up read-only production D1 aggregates resolved the retained-Territory question: 4 total/active, 4 situation-filtered, 3 exact-county, 1 no-county, 2 with other hidden constraints, 1 affected buyer; both responses reported
changed_db: false, 0 writes. The PR now labels those rows as limited prior scope, disables bid/cap changes, preserves filter bytes, excludes them from county-wide competition, and rejects malformed filters from allocation. No migration or retained-data write occurred; any later cleanup remains a separate reviewed operator action.
2026-07-19 — PR #254 Package profile-routing P1 repair (commit 496976a, source-only)
- Corrected the 2026-07-18 preservation claim: at exact reviewed head
82da27976c91e21c04cec1ad30868a841aa2de58, the valid client/schema defaultNJ/NY/TX/FL/ILwas not Package-eligible because reservation/completion admitted only one to four markets and had no Illinois canonical mapping. Numeric$5,000/ 25-Hot-lead constants were unchanged, but delivery behavior was not preserved, so the head correctly remained HOLD. - The bounded working-tree repair defines
NJ/NY/TX/FL/ILonce inapp/shared/buyer-profile.ts; the client default, Worker Zod schema, Package admission cardinality/allowlist, and canonical lowercase matching consume that authority. No price, quota, reserve policy, wallet/Stripe path, migration, retained Territory, FHC, legal copy, or unrelated UI changed. - Real-SQLite proof now drives both an Illinois-only profile and the exact five-market default through a persisted Package reservation, completed fulfillment claim, single delivery, terminal
package_completeddecision, and zero Market fallback. Malformed JSON, unsupported markets, duplicate markets, and the prior invalid play/volume/budget cases remain fail closed. - Verification: focused Package routing/recovery passed 2 files / 42 tests; full app Vitest passed 81 files / 740 tests; standalone
bun run typecheckpassed; productionbun run buildpassed withindex-DK46W7Zq.js. Final root verification and diff hygiene are recorded in the implementation note and/tmp/soldi-pr254-package-routing-fix-receipt.md. Root reviewed and committed the bounded repair as496976a; no deploy or remote service/data access occurred, and fresh exact-head review remains required after the documentation follow-up lands.
2026-07-19 — Final production-evidence P2 remediation (source-only)
- Reversed the independent Terra review's four P2 findings in
tools/production/**andtools/staging/**: every persisted/input promotion receipt now has a closed exact-key shape and recursive secret-material guard; schema-4 rehearsal (including export), schema-2 rollback, schema-3 staging, Stripe, hosted QA, physical iPhone, and external acceptance fail before a snapshot/executor on extra or bearer/API-key/private-key/Stripe-secret/webhook-secret-shaped content. - Hosted desktop proof is now exactly
1440x900;1280x720is an explicit hostile rejection. Physical iPhone proof is constrained to the documented approved iPhone/iOS tuple, complete six-step checklist, and digest-bounddevice-session://soldi-v60/...locator. External acceptance is schema 3 and verifies a fixed-key detached Ed25519 signature over canonical acceptance bytes with a fixed key ID and immutable locator scheme; the new local-only payload command gives the real operator exact signing bytes without storing private key material. - Focused proof passed
bun run test:production-control(14 tests / 93 assertions, including the real local acceptance-payload CLI path) andbun run test:staging(39 tests / 145 assertions). This source correction does not mint a real rehearsal, staging, Stripe, device, external-signature, or provider receipt. Production remains HOLD pending a future normal-merge candidate and all real V3 gates.
2026-07-19 — Production-evidence P2 rereview reversal (source-only)
- Reversed the three remaining Terra P2 findings without touching
app/srcorapp/worker: physical-iPhone evidence now contains a closed canonicaldeviceSessionArtifact; its SHA-256 must equal the receipt field and appear indevice-session://soldi-v60/sha256/<digest>, with artifact/tester/device/iOS/checklist mismatches rejected before snapshot or executor work. This is inspectable operator evidence content, explicitly not device-provider attestation. - Detached external signatures now require canonical unpadded base64url exactly, 64 decoded Ed25519 bytes, and encode round-trip before fixed-key verification. Hostile padded, whitespace, standard-base64, and junk signatures fail before production calls.
acceptance-payloadnow reads Git source state only for actions that require it. Its focused CLI test runs from a copied archive root with no.git; the real post-commit archive proof remains required before release handoff.- Local verification passed production controls 14 tests / 116 assertions, staging controls 39 tests / 145 assertions, full app 81 files / 740 tests plus TypeScript/Vite/brand audit, docs 10 internal + 2 client docs + index, JSON parsing, and diff hygiene.
2026-07-19 — PR #255 Linux CI brand-generator correction (source-only)
- Exact head
09246a5failed only GitHub Actions run29685869734/ job88189904428: the focused favicon fixture restored the approved social cards but omitted the checked-in mark/dot, causing the full generator to invoke macOS-availablemagick; Ubuntu had no such executable. The social-copy path itself did not require ImageMagick. - Removed that stale fallback. Full generation now treats the reviewed
soldi-logo-mark.pngandsoldi-dot.pngas required portable authority beside the logo and source social cards. The focused positive test isolatesPATHto Node only, so it proves no host image tool is needed; existing missing logo/wide/square source hostile cases remain. - Focused favicon proof passed twice (4 tests each); production controls passed 14 tests / 116 assertions, staging controls 39 tests / 145 assertions, full verification 81 files / 740 tests plus TypeScript/Vite/brand audit, docs 10 internal + 2 client docs + index, JSON parsing, and diff hygiene. Docker has no local Linux Bun image, so the intentionally Node-only PATH test is the executed Linux-compatible reproduction.
- No supplied transparent logo/favicon, approved Open Graph bytes, metadata, public copy, or application/worker source changed. This fixes CI determinism only; production remains HOLD.
2026-07-19 — PR #255 CI-correction documentation P3 close (docs-only)
- The CI portability correction is already committed locally as exact
02d9ba6e8575975d018d647c91df8adc1d29b0fband its hostile rereview is READY. The preceding implementation-note future-tense “commit next” instruction is historical/stale; the actual next step is to push this exact head and obtain green GitHub Linux CI. This docs-only clarification changes no source, asset, provider state, or production gate; production remains HOLD.
2026-07-19 — PR #255 CI documentation handoff correction (docs-only)
- The preceding docs-only commit advanced the branch, so reviewed CI-fix
02d9ba6is a parent rather than the push target. Push the resulting current exact branch head after this docs-only commit and obtain green GitHub Linux CI. No source, asset, provider state, or production gate changed; production remains HOLD. - Source controls remain reviewable only. No production, staging, provider, device, signature-provider, GitHub, deploy, or message action occurred. Production remains HOLD.
2026-07-19 — PR #255 production-control CI clock correction (source-only)
- GitHub Actions rerun
29686311048/ job88191061211at exact783ed04864161f919beab51acc668f478d0f4e9fpassedapp/scripts/favicon-assets.test.mjson Ubuntu, confirming the prior portability correction. The later root production-control phase alone failed 10/14 tests withproduction_rehearsal_receipt_stale_or_invalidatpromotion.mjsfresh(). - The test fixture validated against fixed
2026-07-19T12:00:00.000Zbut generated rehearsal cleanup/rollback timestamps from the runner wall clock. Once CI reached the phase more than the permitted one-minute future skew later, strict freshness correctly rejected those self-inconsistent fixtures. runProductionRehearsalForTestnow permits an explicit fixture clock while defaulting to the existing real wall clock; production execution and its 24-hour freshness policy are unchanged. The fixture pins producer/validator time, asserts both generated timestamps, accepts exactly 24 hours old evidence, and rejects a hostile 24-hours-plus-one-millisecond receipt.- This is a local source/test correction only. No brand source/deploy bytes, public copy, app/worker behavior, provider, staging, or production state changed. Production remains HOLD pending the unchanged real final-merge-SHA receipts and V3 authorization.
2026-07-19 — Staging migration receipt controller (source-only)
- Closed the reviewed-controller direct-Wrangler staging-migration gap with
bun run staging:migrate, fixed solely to account2fb55b3d56fa4a0cb926515ecd0b1a6fand D1soldi-staging/516586fe-4d84-4f41-a27a-96bf9d0697c2. It requires a clean freshly fetched two-parentorigin/mainmerge, strict fixed account/zone/domain/D1 read-only authority before snapshot/config/Wrangler work, one private frozen snapshot/toolchain hash, a fresh Time Travel bookmark, strict complete remote migration inventory, retained-data scalars, pending-only apply, and complete post readback. - The private
0600closed-schema receipt is secret-free and binds SHA/tree/parents/canonical config/toolchain/migration hashes and tip/fixed target/bookmark and response hashes/pre-post state/applied set/nonce/cleanup. It records no-op current inventory too. It never restores automatically after a failure; the recorded bookmark is only an incident boundary, not rollback authorization. bun run staging:deploy -- <private-migration-receipt-path>now securely validates the matching fresh receipt before any authority fetch or deploy executor, creates an exact frozen snapshot solely to bind the Wrangler binary, and rechecks receipt tree against the upload snapshot. Source tests cover wrong target/account, malformed envelopes, unknown/gapped/duplicate inventory, stale/substituted/secret-shaped receipts, symlink fences, retained-data loss, no-op, pending order, failure after bookmark, and no-deploy-before-validation.- Evidence:
bun run test:staging51 tests / 200 assertions;bun run test:production-control15 / 120; rootbun run verify81 files / 740 tests with TypeScript/Vite/brand audit; docs build 10 internal + 2 client docs + index; source-onlybun run staging:dry-run; andgit diff --checkpassed. Baseline frozen install initially hit Bun sandbox tempAccessDenied, but later Bun test/build commands completed. No provider, D1, bookmark, migration, deploy, credentials, push, PR, or hosted action ran. Public copy delta: NONE. Production remains HOLD.
2026-07-19 — Staging migration controller hostile closure (source-only)
- Replaced shallow receipt validation with schema-2 closed nesting for inventories, retained scalar names/values, response hashes, migration files, and explicit
plannedPending/appliedThisRun/postPendingsemantics. Exact receipt parents now come from the candidate's two-parent Git row; deployment recomputes the receipt-bound frozen Wrangler SHA-256 before any Cloudflare request or upload. - After a valid Time Travel bookmark, the controller writes a private O_EXCL/0600 boundary outside its disposable snapshot before the first later provider command. Provider failure during pre-inventory, apply, post-inventory, or post-retained-data persists a separate secret-free failure receipt with boundary digest, safe phase/error-code classification, and
restoreAuthorized:false; no restore is attempted. The success receipt binds the same boundary. - Source proof passed
bun run test:staging51 tests / 200 assertions,bun run test:production-control15 / 120, rootbun run verify81 files / 740 tests,bun run build:docs10 internal + 2 client docs + index, andgit diff --check. The hostile self-review found no upload bypass, stale-evidence, provider-partial-failure, private-file/symlink, or wrong-target P0/P1/P2. No provider, credential, bookmark, migration, deployment, push, PR, or hosted action occurred; public copy delta remains NONE.