23 lines
1.7 KiB
Markdown
23 lines
1.7 KiB
Markdown
# Business Rules
|
|
|
|
## Durable Rules
|
|
|
|
- Production data backend selection is explicit and fail-closed: a PostgreSQL configuration failure must never silently fall back to local JSON.
|
|
- Billing amounts use integer-fen arithmetic; wallet balance enforcement and ledger insertion happen inside the PostgreSQL `billing_post_wallet_entry` function.
|
|
- Job claiming uses the PostgreSQL `claim_generation_jobs` function (`FOR UPDATE SKIP LOCKED`, lease, stale recovery); Go process-local locks must never replace it.
|
|
- Ordinary members cannot submit generation when the organization balance is insufficient; submission is rejected before provider dispatch.
|
|
- Super administrators calculate and record generation cost without checking, freezing, or refunding organization quota.
|
|
- All new organization balance entries are organization-owned; generation charge/refund entries keep member attribution for consumption reporting.
|
|
- Logged-in users may change their own password; account management and organization member actions require admin roles.
|
|
- Public `/api/v1` access authenticates with API keys and stays outside browser SSO middleware; API data is partitioned by the API account owner.
|
|
- Database schema changes stay versioned and checksummed in `database/migrations/`; the initial production schema is created by manually executing the SQL files plus application-role grants (no migration Job pod), and schema changes must never run inside long-lived pod startup.
|
|
- Generated and uploaded assets remain runtime/object-storage state; PostgreSQL does not make them shared for horizontal scaling.
|
|
|
|
## Open Questions
|
|
|
|
- The exact public `/api/v1` compatibility promise to preserve for external consumers.
|
|
|
|
## Last Reviewed
|
|
|
|
2026-08-14
|