Skip to main content

Open questions

These items could not be settled from the code that was read on 2026-10-01 (backend commit b5bd463f). Do not turn them into requirements.

Product intent​

  1. What a wallet token costs, and when it is refunded if a label or a sync fails.
  2. Whether an inactive subscription blocks HTTP or only the sync scheduler.
  3. Whether CUSTOM channels are a supported selling mode or a seed placeholder.
  4. Whether coupons are enforced on order create. Models exist. No coupon controller was found.
  5. Which order transitions operators may click, versus system-only edges such as DISPUTED back to PENDING.
  6. Restock rules on return completion versus ReturnItemGrade.
  7. Whether GST e-invoice IRN is in scope. EInvoiceStatus exists. No GSTN client was found.
  8. Settlement match tolerance, and what reconciled means financially.
  9. COD remittance ownership versus marketplace settlement.
  10. Amazon AFN is CHANNEL_FULFILLED when the channel descriptor is afn or fba (and the other partner descriptors in fulfillment-mode.util.ts). That mode does not reserve owned stock. Whether the warehouse UI still shows a worksheet for it is a product question. The code path is What an order status does to fulfillment.
  11. Commercial meaning of StockOwnership.
  12. Why CANCELLED can go to REFUNDED while several earlier statuses cannot.

Operations​

  1. Node version in CI and production (>=24 engines versus README 20+).
  2. How DEAD outbox rows are replayed.
  3. How a SUSPENDED channel returns to ACTIVE, and who may do it.
  4. Partitioned tables and retention inside PartitionMaintenanceService.
  5. Production replica counts, and whether deploy enforces a single scheduler.
  6. Whether pgBackRest and WAL backups are live.
  7. migrate:laravel safety.
  8. Release and tag process for the three apps.
  9. Swagger JSON path. The code does not override jsonDocumentUrl. Confirm GET /docs-json on a running API.

Bull Board path is known: /admin/queues.

Security​

  1. Password hash algorithm per flow. argon2 and bcryptjs are both dependencies.
  2. Which courier webhooks verify signatures. WhatsApp and the Shopify path were specifically noted.
  3. Where the Stripe secret for WhatsApp is stored in deployed config.
  4. Whether every raw SQL statement filters tenantId.
  5. MCP websocket authentication on port 3002.
  6. Network policy for unauthenticated /metrics.
  7. Whether the permissions default-allow is accepted, or some controllers are missing decorators by mistake.

Code ambiguities​

  1. WalletListener comment says do not rethrow. The code rethrows.
  2. Two order state machine files. They match today and can drift.
  3. isValidOrderTransition and the return helper return true when the current status is null.
  4. return.status.changed and return.stock.restored have no listener.
  5. MidNightScheduleWorker only logs.
  6. Courier codes NIP, PIK, SHYP, ARMX, AMZ have no strategy class.
  7. StockMovement unique key includes createdAt.
  8. Inventory quantity formula in stock-sync.service.ts is not written up at line level.
  9. Order create idempotency key.
  10. Whether shipment webhooks and the 3-hour poller dedupe the same scan.
  11. Order state machine header comment omits statuses the map allows. The map wins.
  12. Which address validation statuses block fulfillment.
  13. Ledger uniqueness for one wallet token debit.

Archive docs under docs/archive/ and AI_CONTEXT.md are not a complete description of worker.module.ts. The agent context file does not mention webhook processors, webhook health, or the WhatsApp catalog queue.