MEMBERS-IDENTITY-001G: define consent-decision receipts#448
Conversation
✅ Deploy Preview for luminous-fox-7c393f ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
SELF-REVIEW COMPLETE at exact head Reviewed the GitHub diff and confirmed exactly four owned paths. The contract remains pure, unused, no-authority, bounded to one latest receipt, latest-retry-idempotent, strict about track/revision/latest-receipt binding, and composed with #370 only through the separate projector. No runtime import, Rules, package, endpoint, provider, persistence, migration, deployment, or production-data path was added. Adversarial review findings were fixed: negative-zero revision aliasing, indirect import-scan evasions, all-history wording overclaim, missing head-authenticity warning, diagram call conflation, and officer terminology. Security/architecture, test/reliability, and officer/privacy reviewers each re-reviewed the final diff and reported no findings. Hosted CI run https://github.com/Run-MPRC/Run-MPRC.github.io/actions/runs/29916395606 passed all five blocking jobs at this exact head, including the named frontend Jest, Functions test, Rules emulator, concurrency emulator, and artifact-safety steps. The Netlify deploy preview succeeded; it is not production publication. Header/pages checks skipped because those surfaces did not change. GitHub requires another-account approval and does not allow the PR author to satisfy that review state. The user explicitly requested self-review and merge when no issues remain. With the exact diff reviewed, three independent adversarial reviews clean, and every blocking hosted check green, this PR is ready for the documented administrator merge override. No protected release will be requested. |
Defines a bounded, provider-neutral technical consent-decision receipt contract without changing any live member, officer, Firebase, or provider behavior.
Officer impact: None yet. Officers gain a source-review guide for made-up technical receipt examples only; signup, membership, discounts, Google, WhatsApp, Strava, officer screens, and live accounts are unchanged.
Officer documentation:
docs/officers/EVENTS_SHOP_MEMBERS.md— added theConsent-decision receipts — SOURCE ONLY, UNUSEDprocedure, separate-call diagram and text alternative, prerequisites, limits, proof, undo, and escalation.Deployment evidence: Source commit
af53cf72be14b9ace8faa43e34fafda302cab625was pushed for review. Local Node 20 and Java 17 checks passed. Code is not merged at PR creation. The website was not published;runmprc.comwas not checked; Firebase was not deployed; no outside provider was configured or contacted; no production data was read or changed; no migration or live behavior was verified. Demo-only emulator results are test evidence, not deployment evidence.Closes #447
Parent #81 remains open.
Outcome
membershipConsentReceipt.js.grantedorwithdrawnreceipt under exact track, revision, latest-receipt, command, and policy bindings.classifyConsentStatecontract in a separate call with the caller-supplied required policy version.grantsAuthority: falseon every head, receipt, append result, and composed consent disposition.SYSTEM_DESIGN.md§8.0j and the matching officer future-state procedure.Security and scope review
Test evidence
RED proof before implementation:
npm --prefix functions run test:run -- --runInBand membershipConsentReceipt.test.jsfailed because./membershipConsentReceiptdid not exist.Final environment:
20.19.517.0.19Final results:
demo-rules-testonly.demo-pay002b2-testonly.git diff --check: passed.Self-review
Three independent adversarial reviews covered security/architecture, test/reliability, and officer/privacy wording. Findings were fixed and re-reviewed:
0and-0cannot masquerade as an exact retry;.js, and directoryindex.jsimports;All three final re-reviews report no remaining findings.
Residual risk
This is source-only design evidence. It stores nothing and cannot prove informed/legal consent, notice delivery, actor authority, provider acceptance, canonical history, deployment, or live behavior. Parent #81 remains incomplete until the named policy, authorization, persistence, uniqueness, migration, provider, deployment, and production-verification boundaries are separately approved and delivered.